=== Pingvera ===
Contributors: pingvera
Tags: monitoring, uptime, diagnostics, security, performance
Requires at least: 5.0
Tested up to: 7.0
Requires PHP: 7.2
Stable tag: 0.4.4
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Inside-out WordPress diagnostics for the Pingvera monitoring service. Sends site health to your dashboard over outbound HTTPS only.

== Description ==

Pingvera is a monitoring service for studios and agencies that maintain many
client websites. This plugin is the "level 3" connector: it looks at the site
from the inside and reports the following to your dashboard:

* Inventory: WordPress core, PHP and database versions, active theme, plugins and their versions.
* Updates: available core and plugin updates.
* Security: predictable admin login name, debug mode left on, core file integrity (checksums).
* Performance: object cache presence, size of autoloaded options.
* Availability: REST loopback, recent PHP fatal errors (a count only, never the log itself).
* Configuration: WP-Cron mode and task lag; mail/SMTP.
* Commerce: WooCommerce orders (failed-order spikes, order "droughts"), payment gateways, checkout reachability, a daily smoke run.
* Files: write permissions on wp-config.php.

What the plugin does NOT do: it opens no inbound ports, executes no remote
commands, and never transmits passwords, database contents, or visitor
personal data. All communication is outbound HTTPS to your own dashboard.

== Installation ==

1. In the Pingvera dashboard, open your site and create a CMS installation (WordPress).
2. Copy the one-time pairing code.
3. In WordPress admin: Pingvera -> paste your dashboard URL and the code -> "Connect".

After that the plugin syncs once an hour via WP-Cron. "Sync now" sends data
immediately. "Disconnect" forgets the token and dashboard URL.

== External services ==

This plugin is the connector for Pingvera, an external website-monitoring
service (https://pingvera.com). The plugin exists to send your site's technical
health to your Pingvera dashboard, so using it requires that service. It talks to
the dashboard you configure — a hosted dashboard such as pingvera.com, or your
own self-hosted/on-prem instance — over outbound HTTPS only.

What is sent and when:

* Pairing (once, when you click "Connect"): the one-time pairing code and your
  site URL are sent to obtain a scoped access token. Endpoint: /cms/v1/pair.
* Sync (once an hour via WP-Cron, and on "Sync now"): technical health and
  inventory — WordPress, PHP and database versions; the active theme and the list
  of plugins with their versions; available updates; security, performance and
  configuration findings; WooCommerce order statistics and payment gateway /
  checkout status; and a count of recent PHP fatal errors. Endpoint: /cms/v1/sync.
  Passwords, database contents, post content and visitor personal data are never
  sent.
* Real User Monitoring (only if enabled for your site in the dashboard): a small
  asynchronous script is loaded on the front end to collect anonymous Core Web
  Vitals (loading and interaction timings) of your own pages. Endpoint: /rum/v1/.
  No personal data is collected.

Service provided by Pingvera:

* Terms of Service: https://pingvera.com/terms.html
* Privacy Policy: https://pingvera.com/privacy.html

== Frequently Asked Questions ==

= Does the plugin send any personal data? =

No. It sends technical health and inventory only. Passwords, database contents,
and visitor personal data are never transmitted.

= Can Pingvera control my site remotely? =

No. The connector is strictly one-way: it only sends data out over HTTPS. It
opens no inbound ports and executes no commands from the outside.

== Changelog ==

= 0.4.4 =
* Documented the external Pingvera service in the readme: what data is sent, when,
  and links to the Terms of Service and Privacy Policy (directory requirement).

= 0.4.3 =
* Distinct Plugin URI and Author URI in the plugin header (directory requirement).

= 0.4.2 =
* Plugin Check: enqueued RUM script now carries an explicit version for cache
  busting. No functional changes.

= 0.4.1 =
* Compliance with the official WordPress Plugin Check: output escaping,
  WP_Filesystem for file access, enqueued RUM script, and an English readme.
  No functional changes.

= 0.4.0 =
* WooCommerce order monitoring: failed-order spikes against a 7-day baseline,
  order "drought" detection (stays quiet on low-volume stores), payment gateway
  configuration (no active gateway / live gateway left in test mode), and
  checkout page reachability (loopback).
* Daily smoke run of the order pipeline (a service product and order, created
  without emails, stock changes or payment, then removed immediately).

= 0.2.0 =
* Extended diagnostics: REST loopback, WP-Cron lag, wp-config permissions,
  SMTP/mail, WooCommerce (checkout page), core integrity via checksums (a sign
  of compromise), and a recent PHP fatal-error count.

= 0.1.0 =
* First release: pairing by code, inventory, baseline findings (updates,
  security, performance, configuration), and a management screen.
