=== CodeFaeries Store Sentinel ===
Contributors: lwsdevelopers
Tags: woocommerce, activity log, order tracking, store monitoring, security
Requires at least: 6.0
Tested up to: 7.0
Stable tag: 1.0.5
Requires PHP: 7.4
License: GPL-2.0-or-later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

WooCommerce early warning system — monitors critical store actions and surfaces them in a chronological activity feed.

== Description ==

CodeFaeries Store Sentinel is a WooCommerce activity monitor that tracks critical store events and presents them in a clean, chronological feed. Know immediately when orders are trashed, deleted, or change status — and when products disappear from your catalog.

**Requires WooCommerce** — Store Sentinel is purpose-built for WooCommerce stores. It is built and tested against WooCommerce 7.9 and later; on activation the plugin checks that WooCommerce is active, not which version it is.

= Key Features =

* **Chronological Activity Feed** — All critical WooCommerce events in one timeline, sorted newest-first
* **Order Tracking** — Monitor order trashed, permanently deleted, and status change events
* **Product Tracking** — Monitor product trashed and permanently deleted events
* **Severity Levels** — Events classified as info, warning, or critical for quick visual scanning
* **Filters** — Filter by event type, severity level and date range, with Today / 7d / 30d presets, free-text search, user ID and object ID
* **Event Details** — Click any event to see full context: order totals, old and new status, product info, the source of the change and the plugin behind it, the acting user, and a status history merging Sentinel events with WooCommerce order notes
* **Dashboard Widget** — At-a-glance today's stats on the WordPress dashboard
* **HPOS-Native** — Built for WooCommerce High-Performance Order Storage from day one
* **Privacy-First** — Customer emails are partially masked and client IPs are stored only as a salted hash
* **GDPR Tools** — Personal-data exporter, eraser, and a suggested privacy policy section
* **Automatic Cleanup** — Daily cron removes events older than the retention period (configurable from 7 days to unlimited; 7-day default)
* **Multisite Support** — Works on multisite networks with per-site data isolation
* **Developer Friendly** — Filters and actions for every event, severity, and query

= In Store Sentinel Pro =

Anomaly detection, email alerts (immediate / hourly / daily digest), webhook
notifications, scheduled email reports, advanced filters (source, object type,
saved per-user presets), CSV export and additional event types (customers,
coupons, shipping) are part of **Store Sentinel Pro**, distributed separately
from codefaeries.com. The free plugin exposes documented hooks that Pro builds
on. Retention is not one of them: the free plugin already offers unlimited
retention.

= Tracked Events =

* **Order trashed** (warning) — Order moved to trash
* **Order deleted** (critical) — Order permanently deleted
* **Order status changed** (info) — Order status transition (e.g., processing to completed)
* **Product trashed** (warning) — Product moved to trash
* **Product deleted** (critical) — Product permanently deleted
* **Order meta deleted** (warning) — Order metadata removed; off by default, enable it on the General tab

== Installation ==

1. Upload the `codefaeries-store-sentinel` folder to the `/wp-content/plugins/` directory, or install directly through the WordPress plugin screen.
2. Activate the plugin through the 'Plugins' menu in WordPress.
3. Ensure WooCommerce is installed and active.
4. Navigate to **Store Sentinel** in the admin menu to view the activity feed.

== Frequently Asked Questions ==

= Does this plugin require WooCommerce? =

Yes. Store Sentinel is a WooCommerce-specific monitoring tool, built and tested against WooCommerce 7.9 and later. If WooCommerce is not active, the plugin will show an admin notice and remain inactive; it does not check which version of WooCommerce is installed.

= Is it compatible with HPOS (High-Performance Order Storage)? =

Yes. Store Sentinel is built HPOS-native from the ground up: it works through WooCommerce order objects and HPOS-compatible hooks. On stores still using the legacy post-based order storage it falls back to reading wp_postmeta, which is what those stores require.

= How long are events retained? =

Events are retained for 7 days by default; the retention period is configurable on the Settings → Data & Privacy tab. A daily cron job automatically removes older events to keep the database lean.

= What happens to my data if I deactivate the plugin? =

By default, deactivation only clears the cron schedule and all event data is preserved, so reactivating gives you your full history back. Data is only removed when you **delete** (uninstall) the plugin. The one exception is the **Delete all event data when the plugin is deactivated** option on Settings → Data & Privacy, off by default: with it on, deactivation drops the events table and all options.

= Does it work on multisite? =

Yes. Store Sentinel supports multisite with per-site activation. Each site has its own events table and settings. Uninstall cleans up all sites in batches.

= Can I extend it with custom events? =

Yes. Use the `codefaeries_store_sentinel_event_data` filter to modify event data before recording, or the `codefaeries_store_sentinel_should_record` filter to conditionally skip events. The `codefaeries_store_sentinel_event_recorded` action fires after each event is stored.

== Privacy ==

Store Sentinel records WooCommerce store events (order/product trashes,
deletions and status changes) to a custom table in your own database. Customer
emails captured in event context are partially masked, and client IP addresses,
when IP tracking is enabled, are stored only as a one-way SHA-256 hash salted
with your site's WordPress salt. The raw IP is never written to the database.

Two pieces of data about the person who acted are stored in clear: the display
name, login and role of the logged-in user behind the event, snapshotted so the
history survives that account being deleted; and, when IP tracking is enabled,
the browser user agent string, truncated to 255 characters. Both are exposed
through the personal-data exporter and removed by the eraser.

Store Sentinel does not phone home and does not send any data to external
services. All event data stays in your own database.

== Screenshots ==

1. Activity feed with chronological event timeline
2. Filter bar with event type, severity, and date range filters
3. Event detail modal showing full context
4. Dashboard widget with today's event summary

== Changelog ==

= 1.0.5 - 2026-10-02 =
* Improved: released together with Store Sentinel Pro 1.0.5, whose settings fixes need this version. Nothing changes in the free features.

= 1.0.4 - 2026-10-02 =
* Fixed: a retention period that is no longer offered (for example 180 or 365 days after Store Sentinel Pro is deactivated or its licence lapses) is kept when the settings are saved, instead of dropping to 7 days and letting the next cleanup delete older events.
* Fixed: choosing "Unlimited" retention shows its warning straight away, not only after saving.
* Fixed: the review request no longer appears right after activation; it waits the intended 14 days.
* Fixed: the "Get Support" and Store Sentinel Pro links lead to pages that exist.
* Improved: the Pro panel inside the plugin describes exactly what Store Sentinel Pro adds.

= 1.0.3 - 2026-07-03 =
* Fixed: permanently deleted orders were not being recorded because the deletion listener used an outdated hook name; order deletions are now captured correctly on HPOS stores.

= 1.0.2 - 2026-05-18 =
* Improved: Store Sentinel is now a focused free plugin — anomaly detection, email alerts, webhooks and scheduled reports moved to the separately distributed Store Sentinel Pro, with documented hooks so Pro builds cleanly on the free version.
* Compatibility: "Tested up to" bumped to WordPress 7.0.
* Code quality: passes WordPress Plugin Check cleanly.
* New: filter to exclude specific plugin slugs from event source detection (helps when third-party plugins clutter the backtrace).

= 1.0.1 =
* Internal: release packaging refreshed and CHANGELOG.md consolidated into this changelog.

= 1.0.0 =
First public release. Store Sentinel is a WooCommerce early-warning system: a chronological feed of critical store actions.

* Live activity feed with filters (event type, severity, date range) and pagination.
* Tracks orders (trashed, deleted, status changes, meta removal) and products (trashed, deleted).
* Severity levels — info, warning, critical — with a detail modal showing full context.
* Records the source of each action (Admin, REST API, WP-CLI, Cron, AJAX) and the actor (user, role, display name).
* Settings page for event toggles, retention, privacy, and data management.
* Dashboard widget showing today's activity.
* Daily automatic retention cleanup (7-day default, configurable).
* HPOS-native (WooCommerce 7.9+).
* Multisite-aware install and uninstall.
* Accessibility: focus-trapped modal, ARIA live regions, keyboard navigation.
* Extensible by developers via filters and actions.

== Upgrade Notice ==

= 1.0.4 =
Fixes a settings save that could shorten event retention to 7 days and delete older events. Recommended update.

= 1.0.3 =
Fixes order-deletion events not being recorded on HPOS stores. Recommended update.

= 1.0.2 =
Anomaly detection, email alerts, webhooks and scheduled reports are now part of the separate Store Sentinel Pro; the free plugin is leaner. Recommended update.

= 1.0.0 =
Initial release. WooCommerce early warning system with activity feed, event tracking, settings, and dashboard widget.
