=== Help4 CDN ===
Contributors: help4
Tags: cdn, waf, security, cache, performance
Requires at least: 6.5
Tested up to: 6.8
Requires PHP: 8.3
Stable tag: 0.2.1
License: Proprietary

Connects WordPress to the Help4 CDN, GeoDNS, proxy, and WAF control plane.

== Description ==

Help4 CDN provides the WordPress-side controls needed to operate a Help4-protected site without installing separate cache and firewall administration plugins.

Cache and performance controls:

* Clear the current page, homepage, selected URLs, or the entire domain across assigned POPs.
* Automatically invalidate affected pages, archives, feeds, taxonomies, and related URLs after content changes.
* Clear compatible WordPress caches when an administrator requests a full cache clear.
* Integrates with WordPress object cache, W3 Total Cache, WP Rocket, WP Super Cache, Autoptimize, LiteSpeed Cache, and SiteGround Optimizer.
* Configure browser cache behavior and view HTTP/2, gzip, and Brotli transport state.

Security controls:

* Run the managed Help4 website scan and review site-scoped CDN/WAF events.
* Verify WordPress core files against official WordPress checksums.
* Review recent login, user, theme, and plugin administration activity.
* Review hardening checks without changing WordPress files automatically.
* Select WAF sensitivity and managed bot or under-attack modes where entitled.
* Configure Enterprise IP, country, ASN, User-Agent, and path allow/block rules.
* Manage canonical HTTPS, HSTS, frame, referrer, CSP, Permissions-Policy, COOP, and CORP edge headers.

All state-changing administrator actions require the manage_options capability and a WordPress nonce. Control-plane requests remain scoped to the registered Help4 site ID and its credentials.

== Installation ==

1. Upload the plugin ZIP from Plugins > Add New > Upload Plugin.
2. Activate Help4 CDN.
3. Open Help4 CDN in WordPress administration.
4. Allow the plugin to synchronize the site entitlement.
5. Configure only the controls available to the active Help4 plan.

== Changelog ==

= 0.2.1 =

* Restricted JSON cache-purge requests to normalized local site paths.
* Stopped rendering stored Help4 API credentials back into WordPress settings HTML.
* Added a short remote security-summary cache to keep the administration screen responsive.
* Removed the obsolete X-Frame-Options ALLOW-FROM choice.

= 0.2.0 =

* Added administrator and admin-bar cache clearing for current page, homepage, selected paths, and the full domain.
* Added selective automatic cache invalidation for WordPress content, comments, terms, menus, themes, plugins, and optimization changes.
* Added compatible origin cache clearing for common WordPress cache plugins.
* Added managed site scanning, official WordPress core integrity checks, hardening status, and security event views.
* Added WAF/bot controls and Enterprise access allow/block lists.
* Added canonical edge security-header controls and transport-optimization visibility.

= 0.1.3 =

* Added Help4 licensing, delivery-profile synchronization, cache integration, and update support.
