=== Prismalytics ===
Contributors: frankie73
Tags: analytics, seo, dashboard, statistics, google-analytics
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 8.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

One dashboard for Yandex Metrica, Yandex Webmaster, Google Analytics 4, and Search Console inside your WordPress admin.

== Description ==

Prismalytics brings four analytics systems into a single WordPress admin screen. Stop juggling tabs: Metrica visits and GA4 sessions appear in one table, and Yandex and Google search visibility share one view.

**Yandex Metrica**
* Visits, users, pageviews, bounce rate, and duration
* Traffic sources and search engines
* Top entry pages

**Yandex Webmaster**
* Search visibility trends for any period
* Top queries over 3+ months: impressions, clicks, CTR, average position
* Per-query yearly dynamics (click a query row)
* Site health: SQI (ИКС), indexed pages, issues
* Page history stored in a dedicated database table

**Google Analytics 4**
* Sessions, users, and engagement
* Sources and landing pages

**Google Search Console**
* Impressions, clicks, CTR, and average position (up to 16 months)
* Top queries and pages

**Overview**
* Four KPI strips with period-over-period deltas (▲/▼ %)
* Combined pages table: Metrica visits and GA4 sessions in one row
* Click any table header to sort
* Charts by day, week, and month

**Connect in minutes**
* Yandex — built-in app ID, no separate API registration
* Google — optional Prismalytics proxy quick connect, or your own Google Cloud project wizard
* Domain matching: highlights resources for the current site and blocks foreign domains and http/https or www mirrors

**Security**
* OAuth tokens encrypted with AES-256-GCM
* Encryption key auto-generated or set in wp-config.php
* No third-party data sharing of your analytics data; tokens stay encrypted in your database

**Performance**
* 12-hour report cache (transients)
* Nightly scheduled warmup
* Empty blocks hide automatically

= Languages =
Russian UI strings are included (`.pot` translation file ships with the plugin).

== External Services ==

This plugin connects to the following third-party services only after you connect an account and select a resource. OAuth tokens are stored encrypted in your WordPress database.

= Yandex Metrica API =
Description: Retrieves traffic statistics (visits, users, sources, pages) for the selected Metrika counter. Sends the Yandex OAuth access token and report API queries for the chosen counter and date range.
Privacy Policy: https://yandex.ru/legal/confidential/
Terms of Service: https://yandex.ru/legal/rules/

= Yandex Webmaster API =
Description: Retrieves search visibility, queries, pages, and site health data for the selected Webmaster host. Sends the Yandex OAuth access token and Webmaster API queries for the chosen host and date range.
Privacy Policy: https://yandex.ru/legal/confidential/
Terms of Service: https://yandex.ru/legal/rules/

= Google Analytics Data API =
Description: Retrieves GA4 sessions, users, engagement, sources, and landing pages for the selected property. Sends Google OAuth access/refresh tokens and Analytics Data / Admin API queries for the chosen property and date range.
Privacy Policy: https://policies.google.com/privacy
Terms of Service: https://policies.google.com/terms

= Google Search Console API =
Description: Retrieves Search Console impressions, clicks, CTR, average position, queries, and pages. Sends Google OAuth access/refresh tokens and Search Console API queries for the chosen site and date range.
Privacy Policy: https://policies.google.com/privacy
Terms of Service: https://policies.google.com/terms

= Optional: OAuth Proxy app.trustseo.ru =
Description: Optional “Prismalytics Quick Connect” that exchanges a Google authorization code so you do not need your own Google Cloud OAuth client. Used only if you explicitly choose this option. Sends a one-time authorization code and OAuth state to the proxy; the proxy returns tokens to your site.
Privacy Policy: https://trustseo.ru/tools/ua-wp/en-privacy-policy.html
Terms of Service: https://trustseo.ru/tools/ua-wp/en-terms-of-service.html

== Installation ==

1. Install via Plugins → Add New (upload the ZIP) or copy the `prismalytics` folder to `/wp-content/plugins/`.
2. Activate the plugin.
3. Open **Analytics → Settings** in the WordPress admin menu.
4. **Yandex:** click “Get token on Yandex”, allow access, paste the token, then select a Metrica counter and a Webmaster site.
5. **Google (recommended):** follow the “Your Google Cloud app” wizard — create a GCP project, save Client ID/Secret, then click “Connect Google”.
6. **Google (optional):** “Prismalytics Quick Connect” — no GCP project; code exchange runs on Prismalytics proxy servers and only tokens return to the site. See the Prismalytics privacy policy for details.
7. Enable or disable each of the four channels independently with the toggles in Settings.

== Frequently Asked Questions ==

= Google shows “This app isn’t verified”. Is that safe? =

Yes. This is normal for independent OAuth apps. Click Advanced, then “Go to … (unsafe)” and confirm. The app requests read-only analytics scopes (`analytics.readonly`, `webmasters.readonly`) and does not send your tokens to third parties when you use your own GCP credentials.

= Why is there a Prismalytics proxy for Google? =

It is optional. By default use the “Your Google Cloud app” wizard: your Client ID/Secret stay encrypted in WordPress and the redirect goes to your site.

“Prismalytics Quick Connect” is an explicit opt-in if you do not want to create a GCP project. The proxy exchanges the authorization code on Prismalytics proxy servers (Google secrets stay there) and returns only refresh/access tokens. Privacy policy: https://trustseo.ru/tools/ua-wp/en-privacy-policy.html

= Where are tokens stored? =

In the WordPress database, encrypted with AES-256-GCM. The encryption key is generated automatically; for stronger control define `PRISMALYTICS_ENCRYPTION_KEY` in `wp-config.php`.

= Why is the Webmaster “Pages with impressions” table empty? =

The Yandex API only returns page-level detail for the last 14 days. The plugin accumulates rows in its own table after install, so page history grows over time. Top queries remain available for longer periods from the API.

= The site is available on both http and https — which GSC property should I pick? =

Google treats them as separate properties. The plugin marks the protocol that matches the current site (“✔ THIS SITE”) and blocks selecting the mirror with a different protocol.

= Is the plugin free? =

Yes. All listed features are free with no paywall.

== Screenshots ==

1. Overview: four KPI strips with deltas and a combined pages table.
2. Connection settings: Yandex and Google, domain matching in resource lists.
3. Yandex tab: Metrica and Webmaster — summary, visibility trend, top queries.
4. Yearly search-phrase dynamics (click a query row).
5. Site health: SQI (ИКС), indexing, issues.
6. Google tab: GA4 and Search Console.
7. Charts by day, week, and month.

== Changelog ==

= 1.0.0 =
* Initial release: Yandex Metrica, Yandex Webmaster, Google Analytics 4, Google Search Console.
* Overview with deltas and matched Metrica/GA4 pages.
* Yearly phrase dynamics, site health (SQI), Webmaster history.
* Domain matching with mirror blocking; AES-256-GCM token encryption.
* Renamed to Prismalytics for WordPress.org review.
