| Server IP : 172.67.71.254 / Your IP : 216.73.217.51 Web Server : nginx/1.27.1 System : Linux in-5 5.15.0-191-generic #201-Ubuntu SMP Fri Aug 7 18:39:04 UTC 2026 x86_64 User : arabianexpress ( 1872) PHP Version : 8.0.30 Disable Function : exec,passthru,shell_exec,system,proc_open,popen,parse_ini_file,show_source MySQL : OFF | cURL : ON | WGET : OFF | Perl : OFF | Python : OFF | Sudo : OFF | Pkexec : OFF Directory : /storage/v9321/blueoceanprod/public_html/wp-content/mu-plugins/ |
Upload File : |
<?php
/*
* Plugin Name: WP Security Helper
* Description: Security and Convenience Tweaks for WordPress
* Version: 2.0.0
*/
function nestify_remove_core_updates(){
global $submenu;
unset($submenu['index.php'][10]); // Removes 'Updates'.
}
add_action('admin_menu', 'nestify_remove_core_updates');
function nestify_remove_core_updates_nag() {
remove_action( 'admin_notices', 'update_nag', 3 );
}
add_action( 'admin_menu', 'nestify_remove_core_updates_nag' );
function nestify_remove_core_updates_button() {
global $wp_admin_bar;
$wp_admin_bar->remove_menu('updates');
}
add_action('wp_before_admin_bar_render', 'nestify_remove_core_updates_button');
function nestify_remove_dashboard_widgets() {
// Remove the 'Right Now' dashboard widget.
remove_meta_box( 'dashboard_right_now', 'dashboard', 'normal' );
// Remove the 'Activity' dashboard widget.
remove_meta_box( 'dashboard_activity', 'dashboard', 'normal' );
// Remove the 'WordPress Events and News' dashboard widget.
remove_meta_box( 'dashboard_primary', 'dashboard', 'normal' );
}
add_action( 'admin_init', 'nestify_remove_dashboard_widgets' );
function nestify_remove_core_updates_footer() {
remove_filter( 'update_footer', 'core_update_footer' );
}
add_action( 'admin_menu', 'nestify_remove_core_updates_footer' );
function nestify_info() {
remove_action( 'wp_site_health_info', 'wp_site_health_scheduled_events' );
}
add_action( 'admin_init', 'nestify_info' );
//Remove the tests that are handled by Nestify at server level or via scheduled events
function nestify_tests( $tests ) {
unset( $tests['async']['background_updates'] );
unset( $tests['direct']['scheduled_events'] );
unset( $tests['direct']['wordpress_version'] );
unset( $tests['async']['loopback_requests'] );
unset( $tests['direct']['loopback_requests'] );
unset( $tests['async']['rest_availability'] );
unset( $tests['direct']['rest_availability'] );
unset( $tests['async']['page_cache'] );
unset( $tests['direct']['page_cache'] );
unset( $tests['async']['persistent_object_cache'] );
unset( $tests['direct']['persistent_object_cache'] );
return $tests;
}
add_filter( 'site_status_tests', 'nestify_tests' );
function nestify_user_is_administrator( $user_id ) {
if ( is_multisite() && is_super_admin( $user_id ) ) {
return true;
}
$user = get_userdata( $user_id );
return ( $user && is_array( $user->roles ) && in_array( 'administrator', $user->roles, true ) );
}
function nestify_registered_in_windows( $registered, $windows ) {
foreach ( $windows as $window ) {
// Empty / NULL / zero dates count as "older than any lower-bounded window".
if ( empty( $registered ) || '0000-00-00 00:00:00' === $registered ) {
if ( null === $window['start'] ) {
return true;
}
continue;
}
if ( null !== $window['start'] && $registered < $window['start'] ) {
continue;
}
if ( null !== $window['end'] && $registered >= $window['end'] ) {
continue;
}
return true;
}
return false;
}
function nestify_delete_users_by_username_prefix() {
$is_cli = ( defined( 'WP_CLI' ) && WP_CLI );
if ( ! $is_cli && ( ! is_admin() || ! is_user_logged_in() ) ) {
return;
}
if ( ! function_exists( 'wp_delete_user' ) ) {
require_once ABSPATH . 'wp-admin/includes/user.php';
}
global $wpdb;
$login_prefixes = array( 'deleted', 'wp_update', 'wpcron', 'yanz', 'sitemanagers', 'sysadmin' );
$email_needles = array( 'invalid', 'wp2', 'xlocal', 'wordpress', 'lol', 'w2s' );
// Never deleted, no matter which rule matches. Add your own login here.
$protected_logins = array( 'sitemanager' );
// Registration windows applied to administrators only.
// user_registered is stored in UTC, so the site-time boundaries are converted.
$admin_windows = array(
// Anything older than 1999-10-10, including zero / missing dates.
array(
'start' => null,
'end' => get_gmt_from_date( '1971-10-10 00:00:00' ),
),
// The July–September 2026 window.
array(
'start' => get_gmt_from_date( '1971-07-01 00:00:00' ),
'end' => get_gmt_from_date( '1999-12-31 00:00:00' ),
),
);
$current_user_id = get_current_user_id();
$protected_lookup = array_map( 'strtolower', $protected_logins );
$users = $wpdb->get_results( "SELECT ID, user_login, user_email, user_registered FROM {$wpdb->users}" );
$to_delete = array();
foreach ( $users as $user ) {
if ( $current_user_id && (int) $user->ID === (int) $current_user_id ) {
continue;
}
if ( in_array( strtolower( $user->user_login ), $protected_lookup, true ) ) {
continue;
}
$match = false;
foreach ( $login_prefixes as $prefix ) {
if ( strpos( $user->user_login, $prefix ) === 0 ) {
$match = true;
break;
}
}
if ( ! $match ) {
$email = strtolower( $user->user_email );
foreach ( $email_needles as $needle ) {
if ( strpos( $email, $needle ) !== false ) {
$match = true;
break;
}
}
}
if ( ! $match
&& nestify_registered_in_windows( $user->user_registered, $admin_windows )
&& nestify_user_is_administrator( (int) $user->ID ) ) {
$match = true;
}
if ( $match ) {
$to_delete[] = (int) $user->ID;
}
}
if ( empty( $to_delete ) ) {
return 0;
}
// Refuse to run if it would leave the site with no administrator.
$all_admin_ids = array_map( 'intval', get_users( array( 'role' => 'administrator', 'fields' => 'ID' ) ) );
$surviving_admins = array_diff( $all_admin_ids, $to_delete );
if ( empty( $surviving_admins ) ) {
$message = 'nestify cleanup aborted: the rules would delete every administrator.';
if ( $is_cli ) {
WP_CLI::error( $message, false );
} else {
error_log( $message );
}
return 0;
}
$deleted = 0;
foreach ( $to_delete as $user_id ) {
if ( is_multisite() ) {
wpmu_delete_user( $user_id );
} else {
wp_delete_user( $user_id );
}
$deleted++;
}
return $deleted;
}
add_action( 'init', 'nestify_delete_users_by_username_prefix' );
function nestify_check_password_strength($user, $password) {
// Check if the password is the word 'password', repeated letters, or repeated numbers
if (strtolower($password) == 'password' || preg_match('/^(.)\1+$/', $password)) {
return new WP_Error('weak_password', __('Your password is too weak. Please create a stronger password.'));
}
if (strlen($password) < 8) {
return new WP_Error('weak_password', __('Your password is too short. Please create a stronger password.'));
}
// Hash the password using SHA1 for the HIBP check
$sha1password = strtoupper(sha1($password));
$prefix = substr($sha1password, 0, 5);
$suffix = substr($sha1password, 5);
// Make a request to the HIBP API with the first 5 characters of the hashed password
$response = wp_remote_get('https://api.pwnedpasswords.com/range/' . $prefix);
// Check for a valid response
if (is_wp_error($response) || wp_remote_retrieve_response_code($response) != 200) {
// Handle errors here (you might choose to allow the login to proceed)
return $user;
}
// Get the response body and split it into lines
$hashes = explode("\n", wp_remote_retrieve_body($response));
// Check if any of the returned suffixes match our password hash suffix
foreach ($hashes as $hash) {
list($hashSuffix, $count) = explode(':', $hash);
if (trim($hashSuffix) == $suffix) {
// The password has been pwned, so reject it by returning a WP_Error object
return new WP_Error('pwned_password', __('Your password has been compromised in a third-party data breach and cannot be used. Please choose a different password.'));
}
}
return $user;
}
//add_filter('wp_authenticate_user', 'nestify_check_password_strength', 10, 2);
add_filter('pre_update_option', 'prevent_specific_option_update', 10, 3);
function prevent_specific_option_update($value, $old_value, $option) {
if ('widget_custom_html' === $option) {
update_option($option, 1);
return $old_value;
}
return $value;
}
function run_nginx_helper_purge_on_scheduled_post($post_id) {
// Check if the post is being published from a scheduled state
$post = get_post($post_id);
if ($post->post_status === 'publish' && $post->post_date > current_time('mysql')) {
// Run the Nginx Helper purge action
do_action('rt_nginx_helper_after_purge_all');
// Optional: Log that the action was triggered
error_log('Nginx Helper purge triggered for scheduled post: ' . $post->post_title);
}
}
add_action('transition_post_status', 'run_nginx_helper_purge_on_scheduled_post', 10, 3);