=== Monster Cleanup ===
Contributors: monstercleanup
Tags: cleanup, storage, security, malware, media, database, integrity
Requires at least: 6.5
Requires PHP: 7.4
Stable tag: 1.1.0
License: GPLv2 or later

Recoverable WordPress security and storage cleanup with evidence, quarantine, verification, and Undo.

== Version 1.1 ==

Assessment is read-only. Cleanup actions run only after an administrator selects scopes and types CLEANUP. File actions go to private quarantine outside the public WordPress root; strongly matched spam goes to WordPress Trash.

The dashboard distinguishes active checks from unavailable layers. Monster Cleanup never treats a failed, unconfigured, or not-yet-implemented layer as a successful scan.

== Active features ==

* Chunked, resumable scan of the complete WordPress root.
* Weekly background assessments and on-demand admin assessments.
* Storage totals for uploads, generated-image candidates, backups, caches, logs, temporary files, plugins, themes, WordPress core, and other files.
* Confirmed image-family measurement using WordPress attachment metadata.
* Registered image-size inventory.
* Largest-file and largest-database-table reporting.
* Storage cost and backup-copy multiplier estimate.
* Local PHP and JavaScript risk scoring using combined location, loader, obfuscation, execution, duplicate-code, and recent-change indicators.
* Hidden PHP, PHP in uploads, unexpected root PHP, hidden companion loaders, remote includes, encoded payloads, and unsafe directory-permission signals.
* Official WordPress core checksum verification.
* Public CISA KEV catalog retrieval, schema validation, and freshness health.
* Plugin, theme, must-use plugin, and drop-in inventory.
* Privileged account and granted-capability inventory.
* WordPress cron hook, recurrence, interval, and argument hashes.
* Sensitive database-option hashes without exposing plaintext values.
* Strong-signal spam-content reporting with a separately approved, live-rescored Move to Trash action.
* Configurable public page and download response sampling.
* Explicit scan-confidence and intelligence-layer health.
* JSON evidence export.
* Incident Graph that connects related hashes and filenames, hidden loaders and companion files, installed components, new privileged accounts, new cron hooks, changed sensitive options, spam creation times, recurring files, outbound domains, supplied vulnerability matches, and public-page changes.
* Bounded incident clusters with an explainable risk score, plain-language narrative, evidence nodes, relationship confidence, recommended next actions, and a dated timeline.
* Previous-assessment drift detection for components, administrators, cron, sensitive options, and public response samples.
* Cleanup-ledger recurrence detection for files that return after removal.
* Explicit Incident Graph coverage gaps when intelligence or integrity layers are unavailable.
* Named evidence for executables that exceeded content-inspection limits or could not be read.
* Benign empty and comment-only index.php upload guards excluded from malware scoring.
* Cleanup Center with independent malware, spam, safe storage, expired-transient, obsolete-image-size, and backup scopes.
* Live revalidation of paths, hashes, malware evidence, spam evidence, component image sizes, and direct media references before action.
* Private forensic quarantine for high-confidence malware.
* Compressed quarantine for approved cache, log, temporary, and backup files.
* Removal of expired WordPress transient cache records.
* Removal of obsolete generated image sizes only when the size is no longer registered and no direct database reference remains.
* Public homepage and configured-target verification before and after cleanup.
* Automatic rollback when a previously working homepage fails after cleanup.
* Cleanup action ledger, configurable recovery retention, and one-click Undo.
* Optional automatic safe scopes after weekly assessments. Backups and media are never included unattended.
* Optional weekly email reports with explicit delivery failure recording.

== Externally signed integrity baseline ==

The included WP-CLI baseline engine builds a canonical manifest containing:

* Every file and directory path beneath the WordPress root.
* SHA-256 hashes for files and symlink targets.
* Numeric and resolved ownership, group, and permissions.
* Symlink targets without following them outside WordPress.
* WordPress, plugin, theme, must-use plugin, and drop-in versions.
* Active components.
* Administrator identities, roles, and granted capabilities.
* WordPress cron hooks, recurrence, interval, and hashed arguments.
* SHA-256 hashes of sensitive database options.

Only the canonical manifest digest and non-secret context are sent to the independent signer. The signer returns an Ed25519 signature, which Monster Cleanup verifies locally before accepting the baseline.

Add environment-backed configuration to wp-config.php:

    define( 'MONSTER_CLEANUP_SIGNER_URL', 'https://signer.example.com/v1/sign' );
    define( 'MONSTER_CLEANUP_SIGNER_TOKEN', getenv( 'MONSTER_CLEANUP_SIGNER_TOKEN' ) );
    define( 'MONSTER_CLEANUP_SIGNING_PUBLIC_KEY', getenv( 'MONSTER_CLEANUP_SIGNING_PUBLIC_KEY' ) );
    define( 'MONSTER_CLEANUP_STORAGE_DIR', dirname( ABSPATH ) . '/monster-cleanup-data' );

MONSTER_CLEANUP_SIGNING_PUBLIC_KEY is the base64-encoded raw 32-byte Ed25519 public key. Never install the private signing key in WordPress.

Create a baseline:

    wp monster-cleanup baseline-create

Verify the stored signature:

    wp monster-cleanup baseline-verify

Compare current state with the signed baseline:

    wp monster-cleanup baseline-check --format=json

== Visible but not active in 1.1.0 ==

The dashboard reports these layers as incomplete until their infrastructure is implemented and configured:

* Wordfence Intelligence V3.
* WPScan secondary intelligence.
* Installed-component correlation against the retrieved CISA Known Exploited Vulnerabilities catalog.
* ClamAV, freshclam, and YARA through the future server agent.
* Signed plugin and theme package integrity.
* Dead Monster external heartbeat.
* Multiple-region external checks.
* Account-wide storage and sibling-site scanning.
* Full staging Cleanup Simulator and visual regression service.

== Safety rules ==

* Filenames and modification dates are never treated as primary proof.
* One weak indicator creates a review signal, not an automatic malware conviction.
* Multiple independent indicators increase the risk score.
* Symbolic links are never followed.
* Scan errors and unreadable executable files degrade or fail scan confidence.
* Generated-image filename patterns are candidates; confirmed image derivatives are calculated separately.
* Strongly matched spam can be moved to Trash after live rescoring; it is never irreversibly deleted.
* WooCommerce is never removed merely because it appears or reappears.
* File actions require private recovery quarantine; newer live files are never overwritten during Undo.
* Malware quarantine requires multiple independent live signals and an unchanged SHA-256 hash.
* Automatic weekly cleanup never includes backups or image derivatives.

== Installation and internal test ==

1. Create a current hosting backup or manual restore point.
2. Upload the ZIP in Plugins > Add New > Upload Plugin.
3. Activate Monster Cleanup.
4. Open Monster Cleanup in the WordPress admin menu.
5. Add the site's important public URLs, such as its homepage, forms, service pages, checkout, or public downloads.
6. Enter storage-cost values only if known; zero leaves the cost estimate disabled.
7. Run a new assessment and keep the browser tab open for the first test.
8. Export the evidence JSON and review the Cleanup Center scopes.
9. Select only the approved scopes, type CLEANUP, and run the action.
10. Confirm the action ledger and public verification result. Use Undo during the configured retention period if necessary.

== Privacy ==

The internal preview stores scan state, the latest report, and compact action logs in non-autoloaded WordPress options. Recovery payloads and manifests are stored outside the public WordPress root with restrictive permissions. It does not transmit file contents. Configured public URLs are requested directly by the WordPress server. Core checksum retrieval contacts WordPress.org. The external signer receives only the signed-baseline digest, site hash, timestamp, and non-secret context.

== Changelog ==

= 1.1.0 =
* Added the Incident Graph, connected incident clusters, incident timeline, control-plane drift, recurrence evidence, domain relationships, and public-page change correlation.
* Added timestamps, authors, and domains to strongly matched spam evidence so coordinated campaigns can be grouped.
* Added bounded file paths, hashes, post IDs, and public verification evidence to future cleanup ledger entries.
* Raised the duplicate-code hash index limit from 5,000 to 50,000 executable hashes.
* Added named evidence for executable files that could not be content-inspected.
* Excluded conventional empty or comment-only index.php directory guards from malware findings without weakening analysis of executable index.php content.

= 1.0.1 =
* Treats cache, temporary, backup, media, or malware targets that legitimately disappear after assessment as recorded skips instead of stopping and undoing the entire cleanup run.
* Keeps unsafe paths, symlinks, changed malware evidence, and quarantine failures fail-closed.

= 1.0.0 =
* Added executable, recoverable cleanup actions, public verification, automatic rollback, Undo, retention, weekly automation, and email reporting.

= 0.1.0 =
* Initial internal read-only assessment build.
