=== Ropeline ===
Contributors: spooshx
Tags: security, login security, brute force, limit login attempts, login protection
Requires at least: 6.5
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 0.3.3
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

The velvet rope for your login. Stops password-guessing bots and botnets, without locking out real people.

== Description ==

Bots try to break into WordPress sites all day, mostly at the login. Ropeline stands at the door.

**Login.** Bots guess passwords thousands of times a day. Ropeline locks out an address after 5 wrong passwords in 15 minutes. Each lockout in the same day lasts longer: 15 minutes, then an hour, then a day. It covers wp-login.php, the WooCommerce My Account login, XML-RPC (including system.multicall, where one request can try hundreds of passwords) and application passwords.

Botnets spread their guesses over thousands of addresses to stay under limits like that, so Ropeline also watches each account. When one account fails 10 times in an hour from 3 or more addresses, it only opens on devices that have logged in before, for an hour. The real owner can always get in by resetting their password by email.

Password reset emails are limited too, so bots cannot flood anyone's inbox.

**Prove you're human (optional).** If a limit ever stops a real person, for example because a bot on the same Wi-Fi caused a lockout, they can pass a quick Cloudflare Turnstile check and carry on at once. Add your free Turnstile keys in Settings to switch it on.

**Learning mode.** For the first 7 days Ropeline only watches and records what it would have stopped, so you can check it will not get in anyone's way. Then it starts blocking.

**Plain English.** The Overview shows every failed login and lockout with its address, an "Always let in" button and a one-click Unlock box. A Dashboard widget sums up the week.

**Free, with no limits.** Everything above is in this plugin, free, with no trial and no account. It never contacts Ropeline.

**Ropeline Pro (optional, paid).** A separate add-on from [getropeline.com](https://getropeline.com/#pricing), with a 14-day free trial: leaked-password checks, hidden usernames, card-testing protection for WooCommerce checkout, fake-signup and spam blocking for comments, reviews and contact forms, verified AI-shopper checks, card-skimmer alerts, a weekly report and the Ropeline Network, where sites warn each other about the bots they stop. This plugin works fully without it.

== Installation ==

1. In WordPress, go to Plugins > Add New Plugin and search for "Ropeline". Or download the zip, then go to Plugins > Add New Plugin > Upload Plugin, choose the zip (don't unzip it first) and click Install Now.
2. Click Activate.
3. That's it. Ropeline starts in learning mode for 7 days: it records what it would stop without blocking anyone. Open Ropeline > Overview to see what it's watching, or click "Start blocking now" to skip the wait.

Step-by-step pictures, and how to add Ropeline Pro, are at [getropeline.com/install](https://getropeline.com/install).

== Screenshots ==

1. The Overview: bots stopped, and every failed login and lockout in plain English, with an "Always let in" button.
2. Settings: login protection and learning mode, with safe defaults.

== Frequently Asked Questions ==

= Will it block real people? =

It is built not to, and every block comes with a way out:

* For the first 7 days Ropeline only watches, so you can see exactly what it would have done before it does anything.
* The limit sits well above what a person does: 5 wrong passwords in 15 minutes.
* Someone's usual browser still logs in with the right password, even while their network is locked out because of a bot on the same Wi-Fi.
* Everyone else sees how long to wait and a "reset your password" link. Resetting lets them in at once.
* Messages say what happened and what to do: wait, reset the password, or try another connection.
* Add free Cloudflare Turnstile keys in Settings and anyone stopped by a limit can prove they're human and carry on at once.
* If someone contacts you, type their email or address into the Unlock box on the Ropeline screen, or click Unlock or "Always let in" next to them in Activity.

= I locked myself out. =

Use "reset your password" on the login page: it lets you in right away. If you can't, add `define( 'ROPELINE_OFF', true );` to wp-config.php, or rename the wp-content/plugins/ropeline folder. Either one stops all blocking at once and keeps your settings and history. Remove it once you're back in.

= Do I need WooCommerce? =

No. Ropeline works on any WordPress site. On WooCommerce stores it also protects the My Account login.

= My site is behind Cloudflare, a load balancer or another proxy. =

Cloudflare is recognised automatically: Ropeline checks that the connection really comes from one of Cloudflare's published addresses before it believes Cloudflare's visitor-address header, so nobody can fake it.

If your host puts its own load balancer in front of WordPress, Ropeline notices and shows a "Trust this proxy" button on its Overview. You can also list proxies under Settings > Trusted proxies. Settings shows the address Ropeline sees for you, so you can check it is right.

Headers like X-Forwarded-For are never believed from anywhere else, because anyone can type them.

= Does Ropeline send passwords anywhere? =

No. Passwords are checked by WordPress on your own server, as always. Ropeline only counts the failed tries.

= I use the WordPress mobile app or Jetpack. =

They keep working. Ropeline leaves XML-RPC on and counts failed XML-RPC logins toward lockouts, like any other login.

= Can I change the limits? =

The login limit is in Settings. Developers can also use the `ropeline_login_lockout_steps`, `ropeline_trust_cloudflare` and `ropeline_client_ip` filters.

= Is there a paid version? =

Yes: Ropeline Pro, a separate add-on with a 14-day free trial, from getropeline.com. It adds leaked-password checks, hidden usernames, checkout, signup, spam and AI-shopper protection, skimmer alerts, weekly reports and the Ropeline Network. If a trial or plan ends, Pro switches its features off and this plugin keeps protecting your logins as before.

= Will my antivirus or security plugin flag it? =

It shouldn't. Ropeline is plain, readable PHP: no encoded or hidden code, nothing that runs programs, and no files besides PHP, CSS and text. Every release is checked for the patterns malware scanners look for before it goes out.

== External services ==

Ropeline connects to one outside service, and only if you switch it on. It never contacts Ropeline itself.

**Cloudflare Turnstile** (challenges.cloudflare.com), only if you add Turnstile keys in Settings, and only when a visitor stopped by a limit opens the "prove you're human" page. That page loads Cloudflare's Turnstile script in the visitor's browser, and your site sends the one-time token and your secret key to Cloudflare to confirm it. [Terms](https://www.cloudflare.com/website-terms/), [Turnstile privacy addendum](https://www.cloudflare.com/turnstile-privacy-policy/).

== Privacy ==

Ropeline keeps a log of what it stopped and watched, with the visitor's IP address and, for failed logins, the username tried. The log is deleted after 30 days. Lockout counters expire within a day. When someone logs in, Ropeline sets a cookie (ropeline_device_ followed by the user's ID) that marks the browser as one they use, so it still works if their account is ever under attack; it holds a timestamp and a signature, nothing else, and lasts a year. Someone who passes the optional "prove you're human" check gets a ropeline_human cookie with a timestamp and a signature that lasts an hour. Nothing is sent to Ropeline.

== Changelog ==

= 0.3.3 =
* Smaller and simpler: login lockouts and botnet protection. Leaked-password checks and hidden usernames are now part of Ropeline Pro.

= 0.3.2 =
* Works on WordPress multisite networks, keeps an exact count when bots send many requests at the same moment, and shows its notices only on the Dashboard, Plugins, your profile and Ropeline's own pages.

= 0.3.1 =
* New: a "Start blocking now" button ends learning mode in one click.
* New: on WooCommerce stores, Ropeline warns you when a burst of failed payments looks like card testing, and links to what to do.
* Add-ons can tell Ropeline they guard checkout with the `ropeline_guards_checkout` filter.

= 0.3.0 =
* Ropeline is now a free plugin for the basics: login protection, leaked-password checks, hidden usernames and the "prove you're human" check. Checkout, signup, spam and AI-shopper protection, the skimmer watch, weekly reports and the Ropeline Network moved to the Ropeline Pro add-on.
* Nothing in the plugin looks like what malware scanners hunt for: no base64 functions, no encoded or hidden code.
* Add-ons can plug in through hooks: `ropeline_loaded`, `ropeline_known_bad`, `ropeline_doors`, `ropeline_setting_defaults`, `ropeline_setting_switches`, `ropeline_settings_sanitize`, `ropeline_settings_rows`, `ropeline_settings_after_form`, `ropeline_overview_top`, `ropeline_meter`, `ropeline_overview_notes`, `ropeline_notice`, `ropeline_under_attack` and `ropeline_privacy_paragraphs`.

= 0.2.0 =
* Login lockouts with escalating lengths, covering wp-login.php, WooCommerce, XML-RPC and application passwords.
* Botnet protection: an account under a distributed attack only opens on devices that logged in before.
* Password reset requests no longer reveal which accounts exist, and are limited per address and per account.
* IPv6 addresses are counted by /64 block, so bots cannot dodge limits by switching addresses inside their block.
* Works behind Cloudflare (detected automatically) and behind load balancers (one click to trust).
* Suggested wording for your privacy policy, under Settings > Privacy.
* A Dashboard widget with the week's numbers, an admin bar alert during a card-testing attack, and checks in Tools > Site Health.
* Leaked password check (Have I Been Pwned, k-anonymity).
* Signup protection: honeypot, timing check, throwaway email list, per-address limit.
* Checkout protection against card testing, with attack mode and an email alert.
* Comment, review and contact form protection (Contact Form 7 and WPForms).
* Verified AI shoppers (Web Bot Auth / RFC 9421).
* Username hiding and an option to turn off XML-RPC logins.
* Weekly email report and a card-fee savings estimate.
* Ropeline Network (opt-in): stores share the addresses of bots they stopped.
* Card skimmer watch: an inventory of checkout page scripts, with an email when a new one appears.
* Optional "prove you're human" check (Cloudflare Turnstile): people stopped by a limit get their own allowance for an hour. It never lifts the pause after declined cards.
* Ways in for real people: a customer's usual browser gets through a lockout with the right password, lockout messages link to password reset, and a WooCommerce password reset counts as well.
* An Unlock box for the store owner: type an email or address to clear its lockouts and counters.
* An emergency switch: `ROPELINE_OFF` in wp-config.php stops all blocking.
* Checkout pauses after 5 declined cards (was 3), with clearer messages for each kind of checkout block. Customers who create an account while ordering are not held to the sign-up limit.
* Attack mode can be switched off for headless stores.
* Forms that never show Ropeline's hidden field (some custom and AJAX forms) are no longer treated as bot submissions.
* Detects an untrusted proxy or CDN in front of the site and offers to trust it, so one lockout can't lock out every visitor.
* Compatible with WooCommerce's order tables (HPOS) and the checkout block. Tested from WordPress 6.5 and PHP 7.4 up to WordPress 7.1, PHP 8.4 and WooCommerce 11.1.

= 0.1.0 =
* First version: activity log, failed login watching, learning mode, settings.

== Upgrade Notice ==

= 0.3.3 =
Leaked-password checks and hidden usernames moved to Ropeline Pro.

