=== DevPulse ===
Contributors: sekolahcode
Tags: error-tracking, monitoring, performance, logging, debugging
Requires at least: 6.3
Tested up to: 6.9
Requires PHP: 7.4
Stable tag: 2.0.2
License: MIT
License URI: https://opensource.org/licenses/MIT

Real-time error tracking and performance monitoring for WordPress — self-hosted and free.

== Description ==

DevPulse is a self-hosted error tracking and performance monitoring plugin for WordPress, similar to Sentry but free and running on your own server.

**Features:**

* Captures PHP errors, warnings, notices, and fatal errors
* Captures unhandled exceptions automatically
* Frontend Core Web Vitals (LCP, INP, CLS, TTFB, page load) — real-user Lighthouse metrics
* Lightweight — the backend handler has zero JS footprint; the vitals bundle is ~4 KB deferred
* Configurable via the WordPress admin or `wp-config.php` constants
* Works with any self-hosted DevPulse server

**Privacy:** All error data is sent to your own server. Nothing leaves your infrastructure.

== Installation ==

1. Upload the `devpulse` folder to `wp-content/plugins/`
2. Activate the plugin through **Plugins → Installed Plugins** in the WordPress admin
3. Go to **Settings → DevPulse** and enter your server DSN

Alternatively, you can configure the plugin using constants in `wp-config.php` (see Configuration below).

== Configuration ==

You can configure the plugin via **Settings → DevPulse** in the WordPress admin, or by defining constants in `wp-config.php`:

    define( 'DEVPULSE_DSN',     'http://your-server:8000/api/ingest/YOUR_API_KEY' );
    define( 'DEVPULSE_ENV',     'production' );
    define( 'DEVPULSE_ENABLED', true );

Constants take precedence over admin settings.

**Running the DevPulse server:**

    docker compose up -d

See the [DevPulse GitHub repository](https://github.com/SekolahCode/devpulse) for full server setup instructions.

== Frequently Asked Questions ==

= Do I need a DevPulse account? =

No. DevPulse is entirely self-hosted. You run the server yourself using Docker.

= Is it compatible with WordPress Multisite? =

Single-site and network-activated usage is supported. Each site should have its own API key (project) on the DevPulse server.

= What happens when the DevPulse server is unavailable? =

Errors are captured with a short timeout (2 seconds by default) so your site is never slowed down if the server is unreachable.

== Screenshots ==

1. Settings page — enter your DSN and environment name.

== Changelog ==

= 2.0.2 =
* Fixed: the plugin version header and changelog had drifted out of sync
  with actual releases since 1.2.0 — this release reconciles them and
  documents what shipped in 2.0.0/2.0.1 below.

= 2.0.1 =
* Security: only trust the `X-Forwarded-For` header when `REMOTE_ADDR` is a
  known, configured trusted proxy — prevents client-supplied headers from
  spoofing the reported IP address on sites not behind a proxy.

= 2.0.0 =
* Security: the DSN's API key is no longer sent in the request URL — it's
  extracted and sent as an `X-API-Key` header instead, so it can no longer
  leak into server or CDN access logs.

= 1.2.0 =
* Added frontend Core Web Vitals collection (LCP, INP, CLS, TTFB, page load) via bundled browser SDK
* New "Frontend Performance Vitals" setting in wp-admin; can be disabled per-page with the `devpulse_enqueue_vitals` filter or via `define('DEVPULSE_TRACK_VITALS', false)` in wp-config.php

= 1.1.1 =
* Stability and compatibility improvements

= 1.0.0 =
* Initial public release — PHP error and exception capture, wp_die() and fatal error handlers, admin settings page

== Upgrade Notice ==

= 2.0.1 =
Security fix: only trust X-Forwarded-For from a configured trusted proxy. Recommended for all sites not running behind a reverse proxy/load balancer.

= 1.2.0 =
Adds real-user Core Web Vitals tracking. A lightweight JS bundle (~4 KB) is now injected on public pages by default. Disable it in Settings → DevPulse if not needed.
