Phase 3 v1: autocheck framework + six step automations

Infrastructure:
- WPH_Step::autocheck($session_state) returns an array of findings
  shaped {id, level: ok/warn/bad/info, label, value, detail}.
- WPH_Session stores results keyed by step id (persisted in the option-
  backed session).
- WPH_Step::has_autocheck() reflection check so the UI only renders the
  panel for steps that implement automation.
- 'Run checks' / 'Refresh' button per step, admin-post handler runs
  autocheck() and stashes the result on the session.
- Findings rendered as a coloured table on the step card; included
  verbatim in the Markdown report with status icons.

Step automations implemented:
- Step 1 (Backup): detection of 11 known backup plugins by slug;
  active/inactive state; UpdraftPlus last-backup timestamp.
- Step 2 (Environment): PHP version + EOL, WP version vs latest, disk
  usage, wp-config flags, file perms on wp-config/wp-content/uploads,
  error-log sizes.
- Step 4 (Plugins): WP.org API enrichment with 24h transient cache —
  last_updated, active_installs, abandonment flag, removed-from-repo
  flag, update-available count. Summary line at the top.
- Step 8 (Security): SSL cert expiry via stream_socket_client +
  openssl_x509_parse, administrator audit, xmlrpc reachability, login
  URL hardening detection.
- Step 9 (Database): spam comments, post revisions, autoload size (WP
  6.6+ value handling), top 3 largest tables.
- Step 11 (Small fixes): deactivated-but-installed plugin list,
  homepage alt-text scan.

Smoke-tested on testsite — all six steps return findings with
correctly-classified levels. Report regenerated with automated findings
section.
This commit is contained in:
2026-06-11 16:02:34 +01:00
parent 8de7cad0de
commit 0d51fc3b59
11 changed files with 646 additions and 9 deletions

View File

@@ -36,10 +36,23 @@ abstract class WPH_Step {
public function escalation(): ?string { return null; }
/**
* Phase 3 hook — return structured findings (php version, plugin update
* intel, etc.) for the technician to verify. Phase 1 returns nothing.
* Phase 3 hook — return an array of findings for the technician to verify.
* Each finding: ['id'=>str, 'level'=>'ok'|'warn'|'bad'|'info', 'label'=>str, 'value'=>str, 'detail'=>str].
* Override in subclasses. Default returns nothing.
*
* @return array<string,mixed>
* @return array<int,array<string,string>>
*/
public function autocheck(array $session_state): array { return []; }
/** Convenience finding builder for subclasses. */
protected function finding(string $id, string $level, string $label, string $value = '', string $detail = ''): array {
if (!in_array($level, ['ok', 'warn', 'bad', 'info'], true)) $level = 'info';
return compact('id', 'level', 'label', 'value', 'detail');
}
/** Returns true if any of this step's automation is implemented. Override or rely on autocheck() returning [] by default. */
public function has_autocheck(): bool {
$r = new ReflectionMethod($this, 'autocheck');
return $r->getDeclaringClass()->getName() !== WPH_Step::class;
}
}