=== Upaccn PHP Upgrade Risk Audit ===
Tags: php, php compatibility, php upgrade, site health, developer tools
Requires at least: 6.9
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 0.1.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Choose a target PHP version and see which installed plugin or theme may block the upgrade. Local, read-only, and no shell access required.

== Description ==

Upaccn PHP Upgrade Risk Audit helps you answer one practical question before changing PHP on a WordPress site: **which installed plugin or theme could block this upgrade?**

Choose a target PHP version, select the components you want to inspect, and run a local static-analysis scan. Results are grouped by plugin or theme and summarized as **Ready**, **Review**, or **Blocked**, with the relevant file, line, compatibility rule, and finding available for technical review.

= Highlights =

* Scan installed plugins and themes against a selected PHP 8.x target.
* Runs locally inside WordPress. Source code is not uploaded to an external scanning service.
* Does not require `exec()`, `shell_exec()`, `proc_open()`, Composer, or command-line access on the host.
* Read-only: the plugin never edits the code it scans.
* Bounded AJAX batches reduce the risk of one long blocking web request.
* Clear per-component Ready / Review / Blocked verdicts.
* Technical findings include file, line, severity, rule, and message.
* Bundled vendor-code findings are identified separately.
* The checker excludes itself from scan targets to avoid self-referential findings from its bundled analysis engine.

= Important limitation =

Static analysis can identify known PHP compatibility patterns, but it cannot execute every runtime path and cannot guarantee that a site will work perfectly after an upgrade. Always validate the final PHP change on staging before changing production.

= Privacy =

Scanning and scan state stay on the WordPress installation. Upaccn PHP Upgrade Risk Audit does not upload plugin or theme source code and does not include telemetry in this version.

== Installation ==

1. Upload the plugin or install it from WordPress.org when available.
2. Activate Upaccn PHP Upgrade Risk Audit from the Plugins screen.
3. Go to **Tools → Upaccn PHP Upgrade Risk Audit**.
4. Choose the PHP version you plan to upgrade to.
5. Select the plugins/themes to inspect and click **Scan selected components**.

== Frequently Asked Questions ==

= Does this change my PHP version? =

No. It only analyzes source code. Changing the server PHP version remains a hosting/server operation.

= Does the scanner modify plugins or themes? =

No. Scans are read-only.

= Does it work when shell functions are disabled? =

Yes. The release package includes the scanner runtime and runs it in-process. It does not require shell execution.

= Can it scan premium or custom plugins? =

Yes, as long as the code is installed on the WordPress site and readable by WordPress. The scan does not depend on a public compatibility database.

= Why is Upaccn PHP Upgrade Risk Audit itself not in the component list? =

The scanner deliberately excludes itself. Its bundled PHP_CodeSniffer/PHPCompatibility engine is an analysis dependency and can generate self-referential findings that do not help you assess the rest of the site.

= Does a Ready result guarantee the PHP upgrade is safe? =

No. A Ready result means the static scanner did not find a known blocking pattern in the selected source. You should still test the actual upgrade on staging.

== Changelog ==

= 0.1.0 =
* Initial alpha with local plugin/theme scanning, PHP target selection, bounded processing, cancellation, and Ready / Review / Blocked results.

