=== Wahab133 Media Maintainer ===
Contributors: wahab133
Tags: image optimization, webp, avif, media library, performance
Requires at least: 6.2
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 7.1.9
License: GPL-2.0-or-later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Optimize WordPress media locally with WebP/AVIF conversion, SVG tools, selective workflows, audits, ALT tools, and safe duplicate cleanup.

== Description ==

Wahab133 Media Maintainer is a local media optimization and maintenance toolkit for WordPress. It is designed to keep Media Library attachment relationships intact while giving administrators explicit control over optimization and cleanup actions.

Key features:

* Optimize selected images, page-used images, or the Media Library.
* Convert eligible JPEG/PNG images to WebP and, when supported by the server, AVIF.
* Balanced, visual-protection, and strict image profiles with a configurable sub-100 KB target.
* Preserve generated WordPress image dimensions to reduce browser upscaling and blur risk.
* Minify existing SVG attachments conservatively without rewriting path geometry.
* Scan pages and common WordPress storage locations for local media references.
* Generate or improve ALT text only when the administrator enables and runs the ALT features.
* Preview exact duplicate usage, migrate known WordPress database references to a keeper attachment, record an old-to-new recovery mapping during quarantine, verify remaining references, and only then allow explicit permanent cleanup.
* Review unused Media Library images before moving them to the plugin's safety-trash workflow.
* Optional local first-party visitor/performance analytics, disabled by default.
* Optional Google PageSpeed Insights tests, run only after an administrator clicks a PageSpeed test action.

Fresh installations do not automatically optimize newly uploaded images, generate ALT text, enable analytics, or delete WordPress's original-image backup. Those behaviors require administrator choice in the plugin settings or an explicit optimization action.

The plugin cannot guarantee that every detailed image will be both visually lossless and below 100 KB. Visual-protection mode keeps quality and dimensions above configured safety floors instead of forcing destructive compression.

== Installation ==

1. Back up the site before bulk media changes.
2. Upload the plugin ZIP through Plugins > Add Plugin > Upload Plugin, or copy the plugin folder into `/wp-content/plugins/`.
3. Activate Wahab133 Media Maintainer.
4. Open Wahab133 Media in the WordPress admin menu.
5. Review Settings before enabling automatic upload optimization, ALT automation, analytics, original-image cleanup, or bulk operations.
6. Test a small set of selected images before running site-wide optimization.

== Frequently Asked Questions ==

= Does the plugin upload my images or videos to an external optimization service? =

No. Image and SVG processing runs on the WordPress server using WordPress/PHP image and filesystem APIs available on that server. Media files are not sent to an external optimization service by these features.

= Can every image be reduced below 100 KB without quality loss? =

No. File size depends on dimensions, detail, transparency, codec support, and acceptable quality. The strict profile prioritizes the configured target. Visual-protection mode prioritizes image clarity and dimension safety when the target would require destructive changes.

= Does WebP or AVIF conversion change the attachment ID? =

No. The plugin is designed to keep the existing WordPress attachment ID and update attachment metadata and known local references when a serving filename changes.

= Does SVG optimization sanitize unsafe SVG uploads? =

No. The SVG tool is a conservative minifier, not a security sanitizer or SVG upload-enabler. It only operates on existing Media Library SVG attachments and refuses SVGs containing script elements.

= Does this release run operating-system commands for video compression? =

No. Version 7.1.9 intentionally does not execute local shell commands. The WordPress.org build focuses on image, SVG, ALT, audit, storage, analytics, and duplicate-maintenance workflows.

= How does duplicate cleanup avoid broken images? =

The plugin previews exact duplicate groups, chooses a keeper, migrates known WordPress database references one duplicate at a time, and records the old attachment ID/URLs plus keeper mapping as soon as the duplicate enters quarantine. The redundant attachment and its files remain intact during quarantine. A separate verification also checks for remaining database and read-only filesystem references; permanent cleanup stays blocked until verification passes and the administrator explicitly selects the item for final cleanup.

= Is local visitor analytics enabled automatically? =

No. It is disabled by default. If an administrator enables it, the plugin creates a random first-party browser identifier, hashes the identifier before database storage, and records local page-view/performance measurements. It does not send this analytics data to an external analytics service.

== External services ==

Wahab133 Media Maintainer can use the Google PageSpeed Insights API only when an administrator explicitly starts a Google PageSpeed test from Site Speed Lab.

When this action is used, the plugin sends the same-site URL selected for testing, the selected mobile/desktop strategy, requested Lighthouse categories, locale, and an optional administrator-supplied Google API key to Google's PageSpeed Insights API. Google receives the network request from the WordPress server. No Media Library files or local visitor analytics records are sent by this feature.

Service information: https://developers.google.com/speed/docs/insights/v5/get-started
Google Terms of Service: https://policies.google.com/terms
Google Privacy Policy: https://policies.google.com/privacy

The plugin's internal page scanner and internal speed audit make server-side requests only to URLs on the same WordPress site and do not use a third-party service.


== Development source ==

Human-readable source files are included for every shipped asset. WordPress uses `assets/admin.min.css`, `assets/admin.min.js`, and `assets/tracker.min.js` in normal production mode and the readable `assets/admin.css`, `assets/admin.js`, and `assets/tracker.js` files when `SCRIPT_DEBUG` is enabled. The minified files can be regenerated from the readable source with standard CSS/JavaScript minifiers (for example Clean-CSS and Terser); no private source repository is required.

The plugin never rewrites JavaScript, JSON, HTML, or other generated code files in the uploads directory. Uploads-directory code scanning is read-only; supported page-builder cache APIs are used when a media URL change requires cached output to be regenerated.

== Privacy ==

Local visitor/performance analytics is disabled by default. When enabled by an administrator, a first-party browser cookie is used to distinguish anonymous daily visitors. The random browser identifier is HMAC-hashed before database storage. The analytics feature does not store IP addresses, referrer URLs, user-agent strings, email addresses, or WordPress account identifiers, and does not send the collected analytics data off-site.

WordPress privacy-policy helper text is registered in the Privacy settings screen when the plugin is active.

Google PageSpeed Insights is a separate optional external service described above and is contacted only after an administrator explicitly starts a PageSpeed test.

== Changelog ==

= 7.1.9 =
* Addressed remaining actionable third-party audit findings while preserving the official Plugin Check fixes.
* Added production minified assets with readable source files still included in the package.
* Added short-lived caching for PageSpeed, same-site discovery, and internal speed requests.
* Primed post-meta caches for loop-heavy admin/report workflows and isolated necessary live database scans.
* Cleaned admin accessibility/static-analysis findings, plugin headers, and coding-standard details.

= 7.1.8 =
* Removed shell-command video transcoding from the WordPress.org build.
* Replaced direct local file operations in key workflows with the WordPress Filesystem API.
* Added Multisite analytics-table initialization and admin accessibility labels.
* Refactored dynamic helper callbacks to explicit methods for clearer static analysis.

= 7.1.7 =
* Addressed Plugin Check internationalization findings by documenting formatted translation placeholders.
* Replaced the remaining discouraged file rename operation with the WordPress Filesystem API.
* Prepared dynamic database identifiers with `%i` and moved LIKE wildcards into prepared replacement parameters.
* Sanitized analytics request values and legacy URL request paths before use.
* Documented intentional live database scans/writes with narrow PHPCS annotations where object caching is not appropriate.
* Removed the discouraged execution-time extension call and tightened read-only admin query handling.

= 7.1.5 =
* Updated the plugin identity and text domain for the assigned `wahab-media-maintainer` slug.
* Replaced direct plugin-directory constants with paths resolved from the plugin file and WordPress APIs.
* Ensured duplicate quarantine migrates known references and persists recovery mappings before any later permanent cleanup.
* Removed direct rewriting of generated code files in uploads; builder-cache handling now uses supported APIs only.
* Kept privileged request handlers behind capability and nonce checks and moved the top-level admin menu to a lower position.
* Clarified that distributed JavaScript/CSS is human-readable source and requires no build step.

= 7.1.0 =
* Prepared the distribution for WordPress.org review with Abdul Wahab as the plugin author.
* Changed fresh-install defaults so automatic upload optimization, ALT automation, analytics, and original-image backup removal are opt-in.
* Added stricter uploads-directory validation before image, SVG, and video file mutation.
* Switched same-site page discovery to WordPress's SSRF-safe HTTP request helper.
* Hardened MP4 transcoding command execution and metadata update behavior.
* Added clear external-service and privacy documentation for Google PageSpeed Insights and optional local analytics.
* Retains selective/page-aware optimization, WebP/AVIF conversion, SVG minification, duplicate preview, quarantine, and verification workflows from 7.0.

== Upgrade Notice ==

= 7.1.7 =
Plugin Check cleanup release for the `wahab-media-maintainer` submission.
