=== ExploitShield Domain Monitor ===
Contributors: exploitshield
Tags: security, malware, bitcoin, blockonomics, domain monitoring
Requires at least: 6.0
Tested up to: 6.6
Requires PHP: 7.4
Stable tag: 1.6.4
License: GPLv2 or later

ExploitShield Domain Monitor connects WordPress to the ExploitShield Flask backend for Bitcoin-activated domain exploit monitoring.

== Description ==
The plugin creates a stable DNS TXT verification record, checks propagation, creates a Bitcoin payment order after domain ownership is confirmed, waits for backend confirmation, registers a domain-scoped plugin token, and displays threat-first monitoring results inside WordPress.

Version 1.6.4 replaces the Billing local verification test with internal WordPress REST dispatch, avoiding cURL certificate failures on self-signed local HTTPS while keeping the dashboard threat-first.

== Installation ==
1. Upload exploitshield-domain-monitor.zip from Plugins > Add New > Upload Plugin.
2. Activate the plugin.
3. Open ExploitShield > Settings.
4. Confirm the backend URL is https://web-md5.site.
5. Open Billing and click Start ExploitShield protection.
6. Add the displayed TXT record at your DNS provider and keep it in place.
7. Review the Verification Methods panel for DNS TXT, .well-known file, HTML meta tag, and manual admin fallback status. Use the copy buttons, verification-file download, and open-file helper when manual placement is required.
8. Click Check DNS and create Bitcoin order after propagation. If DNS is delayed, Flask also checks the plugin-published .well-known file and homepage meta tag.
9. After payment confirmation, register the plugin and refresh the dashboard.

== Threat Feature Help ==
Open ExploitShield > Help for plain-language explanations of suspicious JavaScript, iframe injection, eval and obfuscation, redirect intelligence, DNS sinkholes, WHOIS/RDAP age risk, antivirus scanners including ESET and Kaspersky, Snort IDS, proxy body capture, and IP intelligence.

== Security ==
The Blockonomics API key and checkout signing secrets stay on the Flask backend. WordPress stores the domain verification challenge, order token, and plugin-scoped bearer token after activation.

