=== SecureShield — WordPress Security & Login Protection ===
Contributors: hirecode
Tags: security, login protection, two factor authentication, brute force, firewall
Requires at least: 5.8
Tested up to: 6.6
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Lightweight WordPress security plugin. Stop brute-force attacks, enable email 2FA, hide wp-login.php, and monitor all login activity — all from one beautiful dashboard.

== Description ==

**SecureShield** is a lightweight, beautifully designed WordPress security plugin that protects your site's login page without slowing it down.

= ✅ Free Features =

* **Login Attempt Limiting** — Lock out IPs after too many failed attempts (configurable)
* **Email 2FA (OTP)** — Send a 6-digit one-time password to verify logins
* **Login Activity Log** — Full table of every login attempt with IP, time, and status
* **Custom Login URL** — Hide `/wp-login.php` behind any custom slug
* **IP Blocklist** — Block specific IPs, CIDR ranges, or wildcards
* **Security Health Dashboard** — Visual 0–100 security score with actionable fix buttons
* **Email Alerts** — Get notified when an IP is locked out
* **CSV Export** — Download your login log for auditing

= 🚀 Upgrade to HireCode Pro =

* Google Authenticator / TOTP 2FA
* Country-based geo-blocking
* Real-time threat intelligence feeds
* File integrity monitoring
* On-demand malware scanner
* Automated weekly PDF security reports
* Basic Web Application Firewall (WAF)
* 24/7 expert monitoring by the HireCode team
* Priority support (24-hour response)

**[Get HireCode Pro →](https://hirecode.in/pro)**

= Why SecureShield? =

Most security plugins are bloated and slow. SecureShield is different:

* **Lightweight** — Zero unnecessary database queries on the front end
* **Clean UI** — Premium admin interface built with modern design principles
* **No tracking** — We never collect or transmit your site data
* **WordPress standards** — Follows all WordPress coding standards, uses nonces, sanitizes all inputs

== Installation ==

1. Upload the `secureshield` folder to `/wp-content/plugins/`
2. Activate the plugin through the **Plugins** menu in WordPress
3. Go to **SecureShield → Dashboard** to see your security score
4. Go to **SecureShield → Settings** to configure protection

== Frequently Asked Questions ==

= I forgot my custom login URL. How do I log in? =

Access `/wp-login.php` — it will show a 404. Use FTP or your hosting file manager to temporarily deactivate SecureShield by renaming the plugin folder, then re-login via the standard URL.

= Is the free version genuinely useful? =

Yes. The free version provides real protection: login rate limiting, email 2FA, activity logging, and a custom login URL are all fully functional and protect against the most common WordPress attacks.

= Does it work with WooCommerce? =

Yes. The custom login URL feature is compatible with WooCommerce's account login flow.

= Will it conflict with other security plugins? =

SecureShield is designed to be lightweight and non-conflicting. However, running two login-limiter plugins simultaneously may cause unexpected behavior.

= Is my data shared with HireCode? =

No. All data (login logs, settings) is stored exclusively in your WordPress database. Nothing is sent to external servers.

== Screenshots ==

1. Security Health Dashboard with animated score ring
2. Login Activity Log with color-coded status badges
3. Settings — Login Protection tab
4. Settings — Two-Factor Authentication tab
5. Upgrade to Pro page

== Changelog ==

= 1.0.0 =
* Initial release
* Login attempt limiting with configurable lockout
* Email OTP two-factor authentication
* Login activity log with CSV export
* Custom login URL (hide wp-login.php)
* IP blocklist with CIDR and wildcard support
* Security health score dashboard
* Email alerts on lockout
* HireCode Pro upsell page

== Upgrade Notice ==

= 1.0.0 =
Initial release of SecureShield by HireCode.
