=== Reviewer2 Tools Stack Signals ===
Contributors: reviewer2tools
Tags: abandoned plugins, plugin audit, plugin health, outdated plugins, site audit
Requires at least: 6.6
Tested up to: 7.0
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Review maintenance risk signals for installed plugins and themes in one dashboard.

== Description ==

Reviewer2 Tools Stack Signals helps site administrators review the maintenance state of installed plugins and themes.

It uses public information from WordPress.org to check items such as release activity, declared WordPress compatibility, directory status, and support activity. Results include an explanation and a confidence level so you can review the available evidence.

This plugin is not a security scanner. It does not detect vulnerabilities, malware, or modified files, and it does not decide whether a component is safe. A high score is a prompt to review the component, not proof of a security problem.

= Main features =

* An overview of current maintenance findings.
* A searchable and filterable list of installed plugins and themes.
* Detailed evidence for each score.
* Changes between completed audits.
* Manual source mapping for external and custom components.
* Print and CSV reports.
* Optional weekly email summaries, disabled by default.
* Site Health checks and WP-CLI commands.

Plugins and themes that do not use WordPress.org are shown as unrated when no suitable public maintenance data is available. You can set their source manually when needed.

== Using the results ==

Scores range from Low to Critical observed maintenance risk. They are based only on the information available for each component. Missing information is not treated as a negative result.

Open a component to see the evidence behind its score. Consider the component's purpose, vendor information, update process, and your own testing before taking action.

The plugin does not install, update, activate, deactivate, replace, or delete plugins and themes.

== External services ==

The plugin connects to the public WordPress.org plugin and theme API at `api.wordpress.org`.

For components that are known or suspected to be listed on WordPress.org, the plugin sends the directory slug during an audit. It uses the response to read the component's public directory information.

The site URL, post content, user data, and plugin settings are not included in these requests. Components identified as external or custom are not looked up on WordPress.org.

Audits may run on the weekly schedule or when an administrator starts one manually.

WordPress.org privacy policy: https://wordpress.org/about/privacy/

WordPress.org data protection information: https://wordpress.org/about/privacy/data-protection-additional-information/

For a verified WordPress.org plugin, the replacement research section may include a link to `mlscientist.com`. That site is contacted only when an administrator chooses to open the link. The link includes the verified directory slug and does not include the site URL or audit results.

No remote scripts, stylesheets, fonts, or images are loaded by the plugin.

== Privacy and data ==

Audit data is stored in the site's WordPress database. It covers installed software and its public maintenance information. The plugin does not collect visitor or customer data and does not create user profiles.

The optional email summary is sent with the site's WordPress mail configuration. It is disabled until an administrator enables it.

Audit history is retained according to the setting selected by an administrator. Deactivation does not remove audit data. Plugin deletion also keeps audit data unless the uninstall cleanup option is enabled first.

Suggested privacy-policy text is available through the WordPress privacy tools.

== Frequently Asked Questions ==

= Is this a security scanner? =

No. It reports maintenance signals from public data. It does not detect vulnerabilities, malware, or compromised files.

= Why is an external or premium plugin unrated? =

WordPress.org may not have public maintenance information for it. Check the vendor's documentation or release notes. You can also set the component's source manually.

= Why does a component have a high score? =

Open its detail screen to review the contributing signals. A high score may reflect older release activity, a compatibility declaration that has not been updated, directory status, or other maintenance evidence.

= What happens when WordPress.org cannot be reached? =

Unavailable data is not counted as a negative result. An incomplete audit does not replace the last completed audit used for comparisons.

= Will the plugin email me automatically? =

No. The weekly email summary is disabled by default. When enabled, it is sent after a completed scheduled weekly audit.

= Can it change or remove another plugin? =

No. All findings and replacement information are for review only.

= Does it work with multisite? =

Each site is audited separately. This version does not provide a network-wide dashboard.

= Where are the operational checks? =

Open **Tools > Site Health** and look for checks marked **Reviewer2 Tools Stack Signals**.

== Installation ==

1. Install and activate the plugin.
2. Open **Reviewer2 Tools Stack Signals > Overview**.
3. Select **Run scan** to create the first audit.
4. Review optional scheduling, email, retention, and report settings under **Reviewer2 Tools Stack Signals > Settings**.

Changes between audits appear after a second completed audit is available.

== Screenshots ==

1. Overview with the current maintenance score, findings, and next action.
2. Components list with search and filters.
3. Component details with score evidence and history.
4. Replacement research information for a component.
5. Print and CSV report options.
6. Settings for scheduled audits, email summaries, retention, reports, and privacy.

== Changelog ==

= 1.0.0 =
* First release.
* Plugin and theme maintenance audits with supporting evidence.
* Scheduled audits, change tracking, reports, and optional email summaries.
* Manual source mapping, Site Health checks, and WP-CLI support.

== Upgrade Notice ==

= 1.0.0 =
First release.
