=== Toorimichi ===
Contributors: michihiro0891
Tags: management, updates, multisite, dashboard, remote
Requires at least: 6.2
Tested up to: 7.0
Requires PHP: 7.4
Stable tag: 0.1.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Manage update status for multiple WordPress sites from a single dashboard, and update plugins, themes, and core right from there.

== Description ==

Toorimichi is a tool that consolidates update management for multiple WordPress sites into a single screen.

Install this plugin on each site, and you can check and update the status of all your sites from a dedicated dashboard (web app).

= Key Features =

* **Update status overview** — Shows whether core, themes, and plugins have updates available for each site
* **Update execution from the dashboard** — Complete updates on the spot, without visiting each site's admin screen
* **Post-update health check** — Automatically confirms the site is running correctly after an update
* **Update history** — Records when, what, and to which version each update was applied
* **Content health** — Shows the date of the last published post, number of stale posts, pending comments, and drafts
* **Environment info** — Retrieves SSL status, WP_DEBUG state, file edit permissions, DB version, and inactive plugin count
* **Per-site notes** — Attach memos and operational notes to each site
* **Domain expiry display** — Automatically fetched via RDAP API, or entered manually

= How it works =

1. Install this plugin on each WordPress site
2. Get a connection token from the plugin's settings screen
3. Register the site on the dashboard ([toorimichi.michiblog.website](https://toorimichi.michiblog.website))
4. Check the status of and update all your sites from the dashboard

= Security =

* Connection tokens are never stored in the browser (encrypted and stored server-side)
* Communication between the plugin and dashboard is protected by signatures (the token itself never travels over the wire)
* Dashboard login uses passkey authentication (Touch ID / Face ID)
* No information is returned to unauthenticated requests
* Post content and personal user data are never sent

= Who is this for? =

* Individuals or small businesses running two or more WordPress sites
* Anyone who tends to put off update management
* Anyone who doesn't need a highly complex management tool

== Installation ==

1. From the WordPress admin, go to Plugins → Add New and search for "Toorimichi" to install it
2. Activate the plugin
3. Go to Settings → Toorimichi and copy the connection token
4. Open the [Toorimichi dashboard](https://toorimichi.michiblog.website) and register the site

== Third Party Services ==

This plugin connects to an external service to function as a remote management tool.

= Toorimichi Dashboard (Cloudflare Workers) =

When a request is received from the Toorimichi dashboard, this plugin responds with site status information (WordPress version, plugin/theme versions, update availability, content statistics, and environment details). It also accepts update execution commands from the dashboard.

* Service URL: [https://toorimichi.michiblog.website](https://toorimichi.michiblog.website)
* Operated by: みちCOMPANY
* Privacy Policy: [https://michiblog.website/company/toorimichi-privacy-policy/](https://michiblog.website/company/toorimichi-privacy-policy/)
* Disclaimer: [https://michiblog.website/company/toorimichi-disclaimer/](https://michiblog.website/company/toorimichi-disclaimer/)

Communication occurs only when the dashboard sends authenticated requests to this plugin. No data is sent proactively from this plugin. All requests are verified using HMAC-SHA256 signatures; unauthenticated requests receive no information.

The dashboard stores the following data in Cloudflare Workers KV (encrypted):

* Site URL and name
* Connection token (AES-256-GCM encrypted)
* User memos and domain expiry dates
* Update history

= WordPress.org Plugin API =

This plugin uses the standard WordPress update check mechanism (`get_site_transient('update_plugins')` / `get_site_transient('update_themes')`) which communicates with the WordPress.org API to check for available updates. This is standard WordPress core behavior and is not specific to this plugin.

* Service URL: [https://api.wordpress.org](https://api.wordpress.org)
* Privacy Policy: [https://wordpress.org/about/privacy/](https://wordpress.org/about/privacy/)

== Screenshots ==

1. Dashboard showing the update status of all sites at a glance
2. Plugin settings screen (view and copy the connection token)

== Changelog ==

= 0.1.0 =
* Initial release
* Retrieve site info, update status, content health, and environment info
* Execute plugin, theme, and core updates
* Record update history
* HMAC-SHA256 signature authentication

== Upgrade Notice ==

= 0.1.0 =
Initial release.
