=== TalktoMonitor - AI-Powered Diagnostics & Troubleshooting ===
Contributors: talktowp
Tags: monitoring, site health, security, AI diagnostics, performance
Requires at least: 5.8
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.6.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

AI-powered WordPress health monitoring. Detects issues, explains them in plain English, and helps you fix them fast.

== Description ==

**TalktoMonitor** connects your WordPress site to the [TalkToWP](https://app.talktowp.com) platform for continuous AI-powered health monitoring.

Local security and health scanning run on your own site and need no account at all. Plain-English explanations, AI diagnostics, and the hosted dashboard are produced on the TalkToWP servers and require a free TalkToWP account. See the **External services** section below for exactly what is sent, when, and under which terms. TalkToWP receives nothing until you save a TalkToWP API key; the WordPress.org checksum API is contacted automatically, with or without a key, to check core file integrity.

Once connected, TalkToWP watches your site around the clock and uses AI to:

* Detect and explain plugin conflicts, PHP errors, and security threats
* Monitor performance, uptime, and SSL certificate health
* Identify SEO spam injections and hidden malicious links
* Scan for unauthorized admin accounts and changed homepage content
* Send email alerts when critical issues are found

**What data is collected?**

The plugin transmits technical metrics — WordPress version, PHP version, active plugins, available updates, database health, server memory usage, error log counts, and security scan results — and, in some cases, small pieces of your site's content: recent PHP error-log lines, the usernames and registration dates of administrator accounts flagged as unrecognised, and post IDs, titles and short excerpts from database scan findings. Error-log lines can contain server file paths and occasionally values from the request that caused the error. The **External services** section below lists exactly what is sent.

**Features include:**

* Adaptive heartbeat monitoring (3-minute lightweight pulse + daily full snapshot)
* Security scan: SEO spam, hidden links, suspicious admin accounts, homepage integrity
* Google PageSpeed Insights integration (via TalkToWP dashboard)
* Plugin vulnerability detection
* WP-Cron health monitoring
* AI Chat: ask questions about your site in plain English
* Debug log detection, with copyable wp-config.php instructions when it's off

== External services ==

This plugin is the site-side agent for **TalkToWP**, a hosted WordPress monitoring
service operated by Beyondt Consultancy & Services Pvt. Ltd. Local security
scanning and site health checks run entirely on your own server and require no
account. Plain-English explanations, AI diagnostics, and the hosted dashboard are
produced on the TalkToWP servers and require a free TalkToWP account.

**1. TalkToWP (app.talktowp.com) — required for AI diagnostics and the dashboard**

What it is used for: storing and analysing your site's health data, generating the
AI diagnostics and incidents shown in your TalkToWP dashboard, and sending alerts.

Nothing is transmitted to TalkToWP until you paste a TalkToWP API key on
Settings → TalkToWP and save. Removing the key stops all transmission to
TalkToWP. (The plugin's local security scans still run without a key — see
item 2 below for the one request they make regardless of account status.)

Once a key is saved, the plugin sends:

* `POST https://app.talktowp.com/api/plugin/heartbeat` — every 3 minutes via
  WP-Cron. Sends a timestamp, the change in PHP error count, memory usage
  percentage, a hash representing your plugin/theme/core versions, and the HTTP
  status code of your own homepage.
* `POST https://app.talktowp.com/api/plugin/health` — once daily via WP-Cron, and
  also when you save your API key, press "Test Connection", switch themes, or
  update WordPress core. Sends your site URL and the full technical snapshot:
  WordPress and PHP versions, active plugins and themes with their versions,
  available updates, database size and table status, server memory and disk usage,
  error-log line counts and recent error-log lines, WP-Cron status, SSL certificate
  status, and security scan results. The next paragraphs list the parts of that
  snapshot that are more than counts. You can inspect the exact payload before it
  is ever sent using the "Preview Data Sent for Analysis" button on the settings page.
* `POST https://app.talktowp.com/api/plugin/uninstall` — once, when you delete the
  plugin. Sends only your site URL, so TalkToWP can close open incidents and mark
  the site as disconnected.

The daily snapshot contains the following in addition to technical metrics:

* Up to 20 recent PHP error-log lines, each cut to 500 characters, plus fatal-error
  lines that name an active plugin. These lines are sent as they appear in your
  log, so they can contain server file paths and occasionally values from the
  request that caused the error.
* The usernames and registration dates of administrator accounts the scan flags as
  unrecognised. Administrator email addresses are not sent.
* For database scan findings in posts: the post ID, the post title, and an excerpt
  of up to 120 characters of the post content. For findings in wp_options: the
  option name and a SHA-256 hash of the matched text, not the value itself.
* For SEO-spam and hidden-link findings: post IDs and SHA-256 hashes of the
  matched text.

The plugin does not deliberately collect passwords or visitor data, but anything
an error-log line happens to contain is sent with it. The plugin never reads
wp-config.php, .env files, or private keys.

The plugin registers three REST routes under `/wp-json/talktowp/v1/`:

* `health-data` (GET) — returns the same technical snapshot described above. It
  changes nothing.
* `reset-homepage-hash` (POST) — fetches your homepage, stores a new fingerprint of
  its text in place of the old one, and clears the recorded "homepage changed"
  time, so the homepage-change check starts again from the current page.
* `push-now` (POST) — sends a fresh health snapshot to TalkToWP and, when the
  request asks for it, first runs a new security scan and stores the result.

`health-data` and `reset-homepage-hash` require your API key in an `X-API-Key`
request header. `push-now` requires an HMAC-SHA256 signature derived from your API
key, with a ±5-minute window and replay protection. The only things these routes
write are the plugin's own options in your WordPress database, such as the
homepage fingerprint and the last scan result. None of them install, update,
activate or deactivate anything, and none modify plugin, theme, core or any other
site files.

Service terms: https://app.talktowp.com/terms
Privacy policy: https://app.talktowp.com/privacy

**2. WordPress.org checksum API (api.wordpress.org) — automatic, no account required**

What it is used for: the core file integrity scan. To tell whether a WordPress
core file has been modified, the plugin fetches the official checksums for your
WordPress version from
`https://api.wordpress.org/core/checksums/1.0/?version=<your WP version>&locale=en_US`
and compares them against the files on disk locally. This runs as part of the
daily local security scan whether or not a TalkToWP API key is saved.

What is sent and when: your WordPress version number only, at most once per day
(the response is cached in a transient). No site URL, no personal data. This is
the same WordPress.org service that WordPress core itself uses.

WordPress.org privacy policy: https://wordpress.org/about/privacy/

== Installation ==

1. Download the plugin ZIP from the WordPress.org plugin directory or your TalkToWP account.
2. In your WordPress admin, go to **Plugins > Add New > Upload Plugin** and upload the ZIP file.
3. Click **Activate Plugin**.
4. You will be redirected to **Settings > TalkToWP** automatically.
5. Log in (or sign up) at [app.talktowp.com](https://app.talktowp.com) to get your API key.
6. In the TalkToWP dashboard, add your site and copy the API key.
7. Paste the API key into the plugin settings page and click **Save Settings**.

Monitoring begins immediately after saving.

== Frequently Asked Questions ==

= How does monitoring work? =

The plugin collects health data on a 3-minute heartbeat and sends a full snapshot once daily. TalkToWP's AI analyzes the data, detects anomalies, and creates incidents when issues are found.

= Where do I find my API key? =

Log in to your [TalkToWP dashboard](https://app.talktowp.com/dashboard), go to **Sites**, click your site, then open **Site Settings**. Your API key is listed there.

= What data is sent to TalkToWP? =

Technical site health data: WordPress and PHP versions, active plugins and themes, available updates, database size, memory usage, error-log line counts, and security scan results. Some of it is more than counts. The daily snapshot includes up to 20 recent PHP error-log lines, each cut to 500 characters, plus fatal-error lines that name an active plugin. Those lines are sent as they appear in your log, so they can contain server file paths and occasionally values from the request that caused the error. Administrator usernames and registration dates are sent for accounts the scan flags as unrecognised; administrator email addresses are not. Database scan findings include post IDs, post titles and an excerpt of up to 120 characters of post content; for findings in wp_options, only the option name and a SHA-256 hash of the matched text are sent, not the value. The plugin does not deliberately collect passwords or visitor data, but anything an error-log line happens to contain is sent with it. Nothing is sent to TalkToWP until you save a TalkToWP API key on the Settings tab. You can preview the exact payload at any time from the Settings tab.

= Will this plugin slow down my site? =

No. The heartbeat is lightweight and runs on WP-Cron, which fires only when a visitor loads a page (or via a real server-level cron job). There is no frontend performance impact.

= Is my data secure? =

All communication with TalkToWP uses HTTPS with SSL certificate verification. Your API key is unique to your site and can be regenerated at any time from the TalkToWP dashboard.

= Why does using TalkToWP require an account? =

It doesn't, for the local scanning and site health checks on this page — every panel here runs and displays fully without one. An account is only needed for what happens after that: TalkToWP's servers turn this site's raw findings into plain-English explanations, AI diagnostics, and the hosted dashboard, which is work this plugin cannot do by itself.

= Can TalkToWP change my site? =

Not in any way that affects your plugins, themes, WordPress core or files. The plugin registers three REST routes under /wp-json/talktowp/v1/. health-data (GET) returns the technical snapshot the plugin sends to TalkToWP and changes nothing. reset-homepage-hash (POST) fetches your homepage and stores a new fingerprint of its text in place of the old one, so the homepage-change check starts again from the current page. push-now (POST) sends a fresh health snapshot to TalkToWP and, when the request asks for it, first runs a new security scan and stores the result. health-data and reset-homepage-hash require your API key in an X-API-Key request header. push-now requires an HMAC-SHA256 signature derived from your API key, valid for five minutes and accepted only once. The only things these routes write are the plugin's own options in your WordPress database, such as the homepage fingerprint and the last scan result. None of them install, update, activate or deactivate anything, and none modify plugin, theme, core or any other site files.

= How do I disconnect this site from TalkToWP? =

Go to the Settings tab, clear the API Key field, and save. That immediately stops all transmission to TalkToWP; local scanning keeps running on this site as before.

= Why does the plugin source contain strings like eval(base64_decode( ? =

Those are malware signatures — the patterns the security scanner searches
for in your site's files and database. They are string literals compared
against other files' contents. The plugin never executes them.

= Why does the plugin source contain matches for <script> and <style>? =

Those are SQL `LIKE` clauses and regular expressions the security scanner uses to detect injected `<script>` and `<style>` markup hidden in your post content and database — patterns it searches for, not code it runs. All of the plugin's own CSS and JavaScript is loaded through WordPress's `wp_enqueue_style()` and `wp_enqueue_script()` functions; there is no inline `<style>` or `<script>` tag anywhere in the plugin.

= What plans are available? =

Paid plans are available for sites and agencies that need more than the free account provides. See app.talktowp.com for current plans.

= How do I uninstall the plugin? =

Deactivate the plugin, then click **Delete**. The plugin will automatically notify TalkToWP so open incidents are resolved and the site is marked as disconnected. All plugin options and transients are removed from your database on uninstall.

== Screenshots ==

1. Overview — the local checks that need attention, each with a plain-English explanation of what it means.
2. Security — the full local scan: core file integrity, injected plugin and theme files, database injections and admin accounts.
3. Diagnostics — server environment, PHP version, memory limit, disk use and database table health.
4. The TalkToWP dashboard — problems found across every connected site, ranked by severity.
5. AI Chat — ask about any problem and get step-by-step instructions for fixing it.

== Changelog ==

= 1.6.1 =
* The local health-data preview now works without a TalkToWP account.
* The uploads directory is resolved only through wp_upload_dir(), with no hardcoded fallback.
* The plugin display name is now TalktoMonitor.

= 1.6.0 =
* First release on WordPress.org.
* All security scans run and display locally, with or without a TalkToWP account. A free account adds plain-English explanations of the findings on the TalkToWP dashboard.
* The plugin is read-only. It reads your site's files, database and settings to scan them, and never writes to your plugins, themes, WordPress core or any other site file.
* Privacy: administrator email addresses are never sent. Database scan findings in wp_options send the option name and a SHA-256 hash of the matched text rather than the value itself.
* The privacy documentation, the FAQ and the External services section state everything the plugin sends, and describe all three REST routes accurately.
* TalkToWP appears as a dedicated tab on WordPress Site Health (Tools -> Site Health -> TalkToWP).
* Debug log detection is read-only, with copyable wp-config.php instructions instead of writing to the file.
* Includes an uninstall handler that removes every plugin option, transient and scheduled event on deletion.

== Upgrade Notice ==

= 1.6.1 =
The site health preview now works without a TalkToWP account, and the uploads directory is resolved entirely through wp_upload_dir(). No action needed.

= 1.6.0 =
First release on WordPress.org.
