Phase 3 v1: autocheck framework + six step automations

Infrastructure:
- WPH_Step::autocheck($session_state) returns an array of findings
  shaped {id, level: ok/warn/bad/info, label, value, detail}.
- WPH_Session stores results keyed by step id (persisted in the option-
  backed session).
- WPH_Step::has_autocheck() reflection check so the UI only renders the
  panel for steps that implement automation.
- 'Run checks' / 'Refresh' button per step, admin-post handler runs
  autocheck() and stashes the result on the session.
- Findings rendered as a coloured table on the step card; included
  verbatim in the Markdown report with status icons.

Step automations implemented:
- Step 1 (Backup): detection of 11 known backup plugins by slug;
  active/inactive state; UpdraftPlus last-backup timestamp.
- Step 2 (Environment): PHP version + EOL, WP version vs latest, disk
  usage, wp-config flags, file perms on wp-config/wp-content/uploads,
  error-log sizes.
- Step 4 (Plugins): WP.org API enrichment with 24h transient cache —
  last_updated, active_installs, abandonment flag, removed-from-repo
  flag, update-available count. Summary line at the top.
- Step 8 (Security): SSL cert expiry via stream_socket_client +
  openssl_x509_parse, administrator audit, xmlrpc reachability, login
  URL hardening detection.
- Step 9 (Database): spam comments, post revisions, autoload size (WP
  6.6+ value handling), top 3 largest tables.
- Step 11 (Small fixes): deactivated-but-installed plugin list,
  homepage alt-text scan.

Smoke-tested on testsite — all six steps return findings with
correctly-classified levels. Report regenerated with automated findings
section.
This commit is contained in:
2026-06-11 16:02:34 +01:00
parent 8de7cad0de
commit 0d51fc3b59
11 changed files with 646 additions and 9 deletions

View File

@@ -16,4 +16,51 @@ return new class extends WPH_Step {
'Clearing accumulated spam comments',
];
}
public function autocheck(array $session_state): array {
$f = [];
// Deactivated-but-installed plugins
if (!function_exists('get_plugins')) require_once ABSPATH . 'wp-admin/includes/plugin.php';
$inactive = [];
foreach (get_plugins() as $file => $meta) {
if (!is_plugin_active($file)) $inactive[] = ($meta['Name'] ?? $file);
}
$f[] = $this->finding(
'inactive_plugins',
count($inactive) > 0 ? 'info' : 'ok',
'Deactivated-but-installed plugins',
(string) count($inactive),
$inactive ? implode(', ', array_slice($inactive, 0, 10)) . (count($inactive) > 10 ? ' …' : '') : ''
);
// Homepage alt-text scan
$url = home_url('/');
$resp = wp_remote_get($url, ['timeout' => 6]);
if (is_wp_error($resp)) {
$f[] = $this->finding('homepage_alt', 'warn', 'Homepage alt text', 'fetch failed', $resp->get_error_message());
} else {
$body = (string) wp_remote_retrieve_body($resp);
$imgs = 0;
$missing = 0;
if (preg_match_all('/<img\b[^>]*>/i', $body, $matches)) {
foreach ($matches[0] as $tag) {
$imgs++;
if (!preg_match('/\salt\s*=\s*"[^"]+"/i', $tag) && !preg_match('/\salt\s*=\s*\'[^\']+\'/i', $tag)) {
$missing++;
}
}
}
$level = $missing > 0 ? 'warn' : 'ok';
$f[] = $this->finding(
'homepage_alt',
$level,
'Homepage alt text',
$missing . ' missing of ' . $imgs . ' image(s)',
$missing ? 'Empty/missing alt attributes hurt accessibility and SEO.' : ''
);
}
return $f;
}
};