=== Haq Security CVE Monitor ===
Contributors: haqsec
Tags: security, cve, vulnerability-scanner, security-audit, vulnerability-monitor
Requires at least: 5.8
Tested up to: 7.1
Stable tag: 1.0.2
Requires PHP: 7.4
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Real-time CVE vulnerability monitor and security auditing GUI dashboard for WordPress powered by Haq Security API.

== Description ==

Haq Security CVE Monitor connects your WordPress website directly to the Haq Security API platform to provide real-time CVE vulnerability monitoring, technology stack inventory extraction, and automated security scan auditing.

= Key Features =
* **Security Dashboard**: View your overall Security Grade, Risk Score, and vulnerability metrics in a clean WordPress Admin GUI.
* **Automated Scans**: Trigger security scans directly from WordPress Admin with live status polling.
* **Daily Automated Checks**: Enjoy peace of mind with daily scheduled scanning to automatically detect newly published CVEs and security threats on the Haq Security API platform.
* **Technology Stack Inventory**: View normalized software technology stacks detected on your domain.
* **CVE Vulnerability Advisories**: Track active CVE records, severity scores, and CVSS grades affecting your site.
* **Fully Free & Open Source**: No trialware, feature gating, or paywalls built into the plugin code.
* **WPCS & Security Compliant**: Strictly follows WordPress Coding Standards (WPCS), nonces, capability checks, and data sanitization.

== 3rd Party Service Disclosure ==

This plugin relies on the external 3rd party API service operated by Haq Security (`https://api.haqsecurity.com`) to execute security scans, extract technology stack inventories, and perform CVE vulnerability advisory lookups.

* **Service Domain**: https://api.haqsecurity.com
* **Provider**: Haq Security
* **Terms of Service**: https://haqsecurity.com/terms
* **Privacy Policy**: https://haqsecurity.com/privacy

== Installation ==

1. Upload the `haq-security-cve-monitor` directory to the `/wp-content/plugins/` directory.
2. Activate the plugin through the 'Plugins' menu in WordPress.
3. Navigate to 'Haq Security CVE Monitor' in the WordPress admin menu.
4. Accept the legal permission notice and register your target domain to start monitoring.

== Frequently Asked Questions ==

= Does this plugin scan unauthorized external domains? =
No. The plugin automatically locks target scanning to your auto-detected site URL (`get_site_url()`) and requires explicit confirmation of scanning authorization prior to executing any security audits.

= Are there any hidden fees or feature restrictions? =
No. All features included within the plugin interface are completely free and unrestricted.

== Changelog ==

= 1.0.2 =
* Added details about daily scheduled vulnerability checks conducted by the Haq Security API platform.

= 1.0.1 =
* Added scanner pipeline description and support contact details to overview dashboard.

= 1.0.0 =
* Initial production release of Haq Security CVE Monitor.
