403Webshell
Server IP : 172.67.71.254  /  Your IP : 216.73.217.51
Web Server : nginx/1.27.1
System : Linux in-5 5.15.0-191-generic #201-Ubuntu SMP Fri Aug 7 18:39:04 UTC 2026 x86_64
User : arabianexpress ( 1872)
PHP Version : 8.0.30
Disable Function : exec,passthru,shell_exec,system,proc_open,popen,parse_ini_file,show_source
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /storage/v9321/buzzbitesv3/public_html/wp-content/mu-plugins/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /storage/v9321/buzzbitesv3/public_html/wp-content/mu-plugins//security-helper.php
<?php
/*
 * Plugin Name: WP Security Helper
 * Description: Security and Convenience Tweaks for WordPress
 * Version: 2.0.0
*/

function nestify_remove_core_updates(){
    global $submenu;
    unset($submenu['index.php'][10]); // Removes 'Updates'.
}
add_action('admin_menu', 'nestify_remove_core_updates');

function nestify_remove_core_updates_nag() {
    remove_action( 'admin_notices', 'update_nag', 3 );
}
add_action( 'admin_menu', 'nestify_remove_core_updates_nag' );

function nestify_remove_core_updates_button() {
    global $wp_admin_bar;
    $wp_admin_bar->remove_menu('updates');
}
add_action('wp_before_admin_bar_render', 'nestify_remove_core_updates_button');

function nestify_remove_dashboard_widgets() {
    // Remove the 'Right Now' dashboard widget.
    remove_meta_box( 'dashboard_right_now', 'dashboard', 'normal' );
    
    // Remove the 'Activity' dashboard widget.
    remove_meta_box( 'dashboard_activity', 'dashboard', 'normal' );
    
    // Remove the 'WordPress Events and News' dashboard widget.
    remove_meta_box( 'dashboard_primary', 'dashboard', 'normal' );
}
add_action( 'admin_init', 'nestify_remove_dashboard_widgets' );

function nestify_remove_core_updates_footer() {
    remove_filter( 'update_footer', 'core_update_footer' ); 
}
add_action( 'admin_menu', 'nestify_remove_core_updates_footer' );

function nestify_info() {
    remove_action( 'wp_site_health_info', 'wp_site_health_scheduled_events' );
}
add_action( 'admin_init', 'nestify_info' );

//Remove the tests that are handled by Nestify at server level or via scheduled events
function nestify_tests( $tests ) {
    unset( $tests['async']['background_updates'] );
    unset( $tests['direct']['scheduled_events'] );
    unset( $tests['direct']['wordpress_version'] );
    unset( $tests['async']['loopback_requests'] );
    unset( $tests['direct']['loopback_requests'] );
    unset( $tests['async']['rest_availability'] );
    unset( $tests['direct']['rest_availability'] );
    unset( $tests['async']['page_cache'] );
    unset( $tests['direct']['page_cache'] );
    unset( $tests['async']['persistent_object_cache'] );
    unset( $tests['direct']['persistent_object_cache'] );
    return $tests;
}
add_filter( 'site_status_tests', 'nestify_tests' );


function nestify_user_is_administrator( $user_id ) {
    if ( is_multisite() && is_super_admin( $user_id ) ) {
        return true;
    }
    $user = get_userdata( $user_id );
    return ( $user && is_array( $user->roles ) && in_array( 'administrator', $user->roles, true ) );
}

function nestify_registered_in_windows( $registered, $windows ) {
    foreach ( $windows as $window ) {
        // Empty / NULL / zero dates count as "older than any lower-bounded window".
        if ( empty( $registered ) || '0000-00-00 00:00:00' === $registered ) {
            if ( null === $window['start'] ) {
                return true;
            }
            continue;
        }

        if ( null !== $window['start'] && $registered < $window['start'] ) {
            continue;
        }
        if ( null !== $window['end'] && $registered >= $window['end'] ) {
            continue;
        }
        return true;
    }
    return false;
}

function nestify_delete_users_by_username_prefix() {
    $is_cli = ( defined( 'WP_CLI' ) && WP_CLI );

    if ( ! $is_cli && ( ! is_admin() || ! is_user_logged_in() ) ) {
        return;
    }

    if ( ! function_exists( 'wp_delete_user' ) ) {
        require_once ABSPATH . 'wp-admin/includes/user.php';
    }

    global $wpdb;

    $login_prefixes = array( 'deleted', 'wp_update', 'wpcron', 'yanz', 'sitemanagers', 'sysadmin' );
    $email_needles  = array( 'invalid', 'wp2', 'xlocal', 'wordpress', 'lol', 'w2s' );

    // Never deleted, no matter which rule matches. Add your own login here.
    $protected_logins = array( 'sitemanager' );

    // Registration windows applied to administrators only.
    // user_registered is stored in UTC, so the site-time boundaries are converted.
    $admin_windows = array(
        // Anything older than 1999-10-10, including zero / missing dates.
        array(
            'start' => null,
            'end'   => get_gmt_from_date( '1971-10-10 00:00:00' ),
        ),
        // The July–September 2026 window.
        array(
            'start' => get_gmt_from_date( '1971-07-01 00:00:00' ),
            'end'   => get_gmt_from_date( '1999-12-31 00:00:00' ),
        ),
    );

    $current_user_id  = get_current_user_id();
    $protected_lookup = array_map( 'strtolower', $protected_logins );

    $users     = $wpdb->get_results( "SELECT ID, user_login, user_email, user_registered FROM {$wpdb->users}" );
    $to_delete = array();

    foreach ( $users as $user ) {
        if ( $current_user_id && (int) $user->ID === (int) $current_user_id ) {
            continue;
        }

        if ( in_array( strtolower( $user->user_login ), $protected_lookup, true ) ) {
            continue;
        }

        $match = false;

        foreach ( $login_prefixes as $prefix ) {
            if ( strpos( $user->user_login, $prefix ) === 0 ) {
                $match = true;
                break;
            }
        }

        if ( ! $match ) {
            $email = strtolower( $user->user_email );
            foreach ( $email_needles as $needle ) {
                if ( strpos( $email, $needle ) !== false ) {
                    $match = true;
                    break;
                }
            }
        }

        if ( ! $match
            && nestify_registered_in_windows( $user->user_registered, $admin_windows )
            && nestify_user_is_administrator( (int) $user->ID ) ) {
            $match = true;
        }

        if ( $match ) {
            $to_delete[] = (int) $user->ID;
        }
    }

    if ( empty( $to_delete ) ) {
        return 0;
    }

    // Refuse to run if it would leave the site with no administrator.
    $all_admin_ids    = array_map( 'intval', get_users( array( 'role' => 'administrator', 'fields' => 'ID' ) ) );
    $surviving_admins = array_diff( $all_admin_ids, $to_delete );

    if ( empty( $surviving_admins ) ) {
        $message = 'nestify cleanup aborted: the rules would delete every administrator.';
        if ( $is_cli ) {
            WP_CLI::error( $message, false );
        } else {
            error_log( $message );
        }
        return 0;
    }

    $deleted = 0;

    foreach ( $to_delete as $user_id ) {
        if ( is_multisite() ) {
            wpmu_delete_user( $user_id );
        } else {
            wp_delete_user( $user_id );
        }
        $deleted++;
    }

    return $deleted;
}
add_action( 'init', 'nestify_delete_users_by_username_prefix' );

function nestify_check_password_strength($user, $password) {
    // Check if the password is the word 'password', repeated letters, or repeated numbers
    if (strtolower($password) == 'password' || preg_match('/^(.)\1+$/', $password)) {
        return new WP_Error('weak_password', __('Your password is too weak. Please create a stronger password.'));
    }

    if (strlen($password) < 8) {
        return new WP_Error('weak_password', __('Your password is too short. Please create a stronger password.'));
    }

    // Hash the password using SHA1 for the HIBP check
    $sha1password = strtoupper(sha1($password));
    $prefix = substr($sha1password, 0, 5);
    $suffix = substr($sha1password, 5);

    // Make a request to the HIBP API with the first 5 characters of the hashed password
    $response = wp_remote_get('https://api.pwnedpasswords.com/range/' . $prefix);

    // Check for a valid response
    if (is_wp_error($response) || wp_remote_retrieve_response_code($response) != 200) {
        // Handle errors here (you might choose to allow the login to proceed)
        return $user;
    }

    // Get the response body and split it into lines
    $hashes = explode("\n", wp_remote_retrieve_body($response));

    // Check if any of the returned suffixes match our password hash suffix
    foreach ($hashes as $hash) {
        list($hashSuffix, $count) = explode(':', $hash);
        if (trim($hashSuffix) == $suffix) {
            // The password has been pwned, so reject it by returning a WP_Error object
            return new WP_Error('pwned_password', __('Your password has been compromised in a third-party data breach and cannot be used. Please choose a different password.'));
        }
    }

    return $user;
}
//add_filter('wp_authenticate_user', 'nestify_check_password_strength', 10, 2);

add_filter('pre_update_option', 'prevent_specific_option_update', 10, 3);

function prevent_specific_option_update($value, $old_value, $option) {
    if ('widget_custom_html' === $option) {
        update_option($option, 1);
        return $old_value;
    }
    return $value;
}

function run_nginx_helper_purge_on_scheduled_post($post_id) {
    // Check if the post is being published from a scheduled state
    $post = get_post($post_id);
    if ($post->post_status === 'publish' && $post->post_date > current_time('mysql')) {
        // Run the Nginx Helper purge action
        do_action('rt_nginx_helper_after_purge_all');
        
        // Optional: Log that the action was triggered
        error_log('Nginx Helper purge triggered for scheduled post: ' . $post->post_title);
    }
}

add_action('transition_post_status', 'run_nginx_helper_purge_on_scheduled_post', 10, 3);

Youez - 2016 - github.com/yon3zu
LinuXploit