=== ViewMend Site Tracker ===
Contributors: phpner
Tags: website monitoring, change tracking, deployment, content updates
Requires at least: 6.4
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.1.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Connect WordPress to ViewMend for website change monitoring with content, plugin, theme, core, and cache event context.

== Description ==

ViewMend Site Tracker connects confirmed WordPress changes to the [ViewMend website change monitoring workflow](https://viewmend.com/site-tracker). It records events locally and delivers compact metadata through a durable background queue, so normal WordPress requests do not wait for the external service.

ViewMend handles the resource-intensive work on its own infrastructure: running audits, capturing screenshots, comparing pages, and storing monitoring reports and evidence. The WordPress plugin sends compact change events and brings site health, performance statistics, and findings into your admin dashboard. This keeps heavy audit processing and report storage off your WordPress hosting.

Use this WordPress connector to add publication, plugin, theme, WordPress core, and WP Rocket cache context to tracked website changes. When WordPress can identify the affected public page, the event includes its exact URL. ViewMend may match already tracked pages and queue a check when auto-check, page scope, credits, and queue state allow.

Timeline events and completed ViewMend checks help administrators investigate what happened around a release or content update. This plugin is an event connector, not a standalone crawler, rank tracker, backup tool, or replacement for ViewMend's page comparison and website change monitoring service.

= Supported WordPress changes =

* Public posts, pages, and products when they are published, meaningfully updated, or permanently deleted.
* Plugin installation, activation, deactivation, update, and deletion.
* Theme installation, activation, update, and deletion.
* Completed WordPress core updates.
* Confirmed full-domain and exact-URL WP Rocket cache purges.
* An explicit administrator connection test.

Autosaves, revisions, drafts, trash moves, comments, users, orders, customer records, media churn, and arbitrary option changes do not create events.

= How WordPress website change monitoring works =

1. WordPress confirms an enabled content, plugin, theme, core, or supported cache action.
2. The plugin creates one stable event ID and stores the compact event in its local queue.
3. A background worker delivers the event to ViewMend without delaying the originating WordPress request.
4. ViewMend records the Timeline context and returns delivery, matched-page, and queue status.
5. When the ViewMend integration permits it, selected tracked pages can be checked and the completed evidence reviewed in ViewMend.

For the wider release-verification workflow, see [post-deployment website monitoring](https://viewmend.com/articles/post-deployment-website-monitoring).

= Native WordPress controls and durable delivery =

The settings area separates Overview, Connection, Event rules, and Activity. Overview reads project health, findings, significant content changes, resource impact, and selected-page performance from ViewMend. It does not invent sample values when no completed check is available. Selecting a resource type loads the exact stored request URLs for that check without exposing the API token to browser JavaScript.

Each event category explains what is reported, what is excluded, what happens when it is disabled, and which exact actions can be selected. For example, plugin events can be limited to completed updates only.

ViewMend owns server-side event deduplication, tracked-page selection, queue ordering, credit checks, Tracker checks, Timeline markers, and before/after comparisons. This plugin does not reproduce those services inside WordPress.

The API token is stored separately with autoload disabled and is never displayed after saving. The plugin does not send post bodies, customer/order data, usernames, emails, cookies, IP addresses, or arbitrary settings.

ViewMend Site Tracker is a service connector. A ViewMend account and an existing Site Tracker integration are required before events can be delivered. See the External service section for exactly when the plugin contacts ViewMend and which data is sent.

== External service ==

This plugin connects to [ViewMend Site Tracker](https://viewmend.com/site-tracker) to deliver site-change events to the integration selected by the administrator and to read Tracker results for the administrator-only Overview. It does not contact ViewMend until an administrator explicitly configures an Integration ID and API token. After configuration, a request is made when the administrator opens or refreshes Overview, selects a stored resource type, queues a connection test, or when an enabled, supported WordPress action creates an event and the background queue processes it.

Requests contain a stable event ID, event type and time, a short change title and description, the configured public site URL and environment, exact affected public page URLs when WordPress can determine them, and minimal operational metadata such as WordPress/plugin/theme versions, public content type and numeric object ID, or the confirmed operation name. A WordPress administrative edit URL can be included as a reference for a public content event. The API token is sent only in the Authorization header. The plugin does not send post bodies, excerpts, usernames, email addresses, customer or order data, cookies, IP addresses, or arbitrary settings.

ViewMend receives and processes this information to record the event, match already tracked pages, conditionally queue Tracker checks, and return delivery and queue status. For Overview, ViewMend returns project health counts, findings, significant content changes, selected-page performance, resource URLs, MIME types, response status, transferred bytes, and request duration already collected by ViewMend checks. It does not return request or response headers, cookies, authorization values, or remote IP addresses to the plugin. Successful dashboard responses are cached in WordPress for up to five minutes. An accepted event does not guarantee that a check starts or completes. Use of the service is subject to the [ViewMend Terms of Service](https://viewmend.com/terms-of-service) and [ViewMend Privacy Policy](https://viewmend.com/privacy-policy).

== Installation ==

1. Upload and activate the plugin.
2. Open ViewMend from the main WordPress administration menu.
3. Follow the setup-guide link on the Connection screen and create WordPress credentials in the target ViewMend Tracker project.
4. Copy the Integration ID and one-time API token into WordPress > ViewMend > Connection.
5. Save and test the connection. The test creates a real ViewMend event.
6. Open Event rules and choose the confirmed WordPress operations that should create events.
7. Open Activity, confirm the local test row reaches Delivered, and inspect the queue state returned by ViewMend.

WordPress cron must run for background delivery. The plugin schedules near-term work and a recurring five-minute recovery event.

Multisite network activation is not supported. Activate and configure the plugin separately for each required site.

== Screenshots ==

1. The Overview brings together project health, tracked pages, critical findings, searchable issues, and issue trends.
2. Connection verifies the ViewMend integration and keeps the saved API token hidden while making settings easy to update.
3. Event rules let administrators choose the exact WordPress actions to report, including publication, meaningful updates, and permanent deletion.
4. Activity shows confirmed deliveries with exact affected URLs, matched pages, and the response returned by ViewMend.
5. Page insights combine performance history, Core Web Vitals, transferred resources, resource changes, and local event delivery health.

== Frequently Asked Questions ==

= Is this a standalone WordPress website monitoring plugin? =

No. The plugin is a WordPress event connector for ViewMend Site Tracker. It records when supported WordPress changes happen and sends their context to ViewMend. Website checks, selected-page monitoring, screenshots, reports, and comparisons remain ViewMend services.

= Can it track WordPress page changes? =

For a public post, page, or product, the plugin sends the exact affected permalink when WordPress can determine it. ViewMend can match that URL to an already tracked page and may queue a check when the integration configuration and account state permit it. Drafts, autosaves, revisions, trash moves, and protected content are excluded.

= Which site changes can it report? =

The plugin supports public content publication, meaningful updates and permanent deletion; plugin and theme lifecycle operations; completed WordPress core updates; confirmed WP Rocket cache purges; and an administrator connection test. Event rules can enable only the categories and exact operations you need.

= Do website checks run on my WordPress server? =

Audits, screenshot capture, and page comparisons run on ViewMend infrastructure, where monitoring reports and evidence are also stored. The plugin retrieves completed results for the administrator-only Overview, so your WordPress server does not perform that audit processing or store the full monitoring reports.

Some local work remains: recording events, delivering them in the background, and storing settings, bounded delivery history, and dashboard results cached for up to five minutes. External checks also request your pages and their resources. This design offloads the heavy processing, but does not mean zero server load.

= Does the plugin contact an external service? =

Yes. The plugin is a connector for ViewMend Site Tracker. It sends queued change metadata and reads Tracker dashboard results only after an administrator configures the ViewMend connection. The External service section lists the circumstances, transmitted and received fields, service link, terms, and privacy policy.

= Which cache plugins are supported? =

WP Rocket only. The plugin listens to documented WP Rocket post-purge hooks for full-domain and exact-URL cache clearing. It does not guess when another cache product has finished a purge.

= What happens when ViewMend is unavailable? =

Network errors, HTTP 429, and server errors use bounded exponential retry. Retry-After is respected up to six hours, and one logical event is attempted no more than six times automatically. Manual retry preserves the original event ID.

= What happens on deactivation or uninstall? =

Deactivation removes cron schedules and preserves all data. Uninstall also preserves data by default. An explicit setting can opt into removing ViewMend settings, the token, and local delivery history during uninstall.

== Privacy ==

The plugin sends public site and affected-page URLs, event timestamps/types/titles, field categories, and minimal WordPress/plugin/theme version or object identifiers. It excludes post bodies, excerpts, protected content, user/customer/order records, emails, cookies, IP addresses, and arbitrary option values.

The local queue stores the event payload, delivery state, attempts, selected redacted errors, HTTP status, and ViewMend response identifiers/state. Completed and failed history is bounded. A successful administrator dashboard response is stored as a WordPress transient for up to five minutes. The API token is stored in a separate non-autoloaded option and never stored in queue rows or sent to browser JavaScript.

== Changelog ==

= 1.1.0 =

* Added a ViewMend website monitoring dashboard with project health, tracked pages, findings, issue trends, and selected-page insights.
* Added searchable findings, severity filters, grouped duplicate issues, interactive performance history, and stored resource request details.
* Refreshed Overview, Connection, Event rules, and Activity with full-width responsive layouts, ViewMend branding, and corrected button icons and checkbox alignment.
* Simplified connection setup with a guide and Integration ID/API token fields, while keeping the saved token hidden and showing current authentication errors clearly.
* Improved Activity with event and URL search, status filters, pagination, exact affected URLs, and clearer delivery outcomes.
* Improved unsaved-change feedback, repeat-submit protection, dashboard cache handling, and the display of unavailable or partial results.
* Validated and bounded API responses, protected cached data from reflected credentials, and prevented invalid acknowledgements from marking events as delivered.
* Recognized ViewMend's server event IDs while preserving the original WordPress event ID for retries and duplicate deliveries.
* Paused queued deliveries without consuming retries when credentials are removed, and excluded failed or skipped updates and unconfirmed deletions from automatic events.
* Added five updated screenshots covering the dashboard, connection, event rules, activity, performance, and resources.

= 1.0.0 =

* Initial production release with durable delivery, recovery, observability, security controls, lifecycle handling, documented event adapters, external-service disclosure, and WordPress Privacy Policy Guide content.

== Upgrade Notice ==

= 1.1.0 =

Adds the ViewMend monitoring dashboard, interactive insights, clearer connection status, and searchable activity. Existing connection settings and event rules are preserved.
