diff --git a/.beads/issues.jsonl b/.beads/issues.jsonl index 325280c..d09d957 100644 --- a/.beads/issues.jsonl +++ b/.beads/issues.jsonl @@ -5,24 +5,24 @@ {"_type":"issue","id":"hc-5ix.3","title":"Step definitions module: single PHP file defining the 12 steps + 'Before You Start' as structured data (id, title, blurb, sub-items, escalation conditions)","description":"Source of truth for both the MVP UI and the automation layer. Keep it boring: pure data, no presentation. Lives at includes/steps.php returning a typed array. The text comes from steps.md (current copy in repo root).","notes":"Built in phase-1 scaffold; passing lint + WP-eval end-to-end smoke test on testsite.","status":"closed","priority":1,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:11Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T14:49:26Z","started_at":"2026-06-11T14:41:27Z","closed_at":"2026-06-11T14:49:26Z","labels":["phase-1"],"dependencies":[{"issue_id":"hc-5ix.3","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:10Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} {"_type":"issue","id":"hc-5ix.4","title":"Session data model: option-backed in-progress healthcheck record","description":"One in-progress session per site at a time. Stored in a custom option (or a CPT — pick during implementation). Shape: id, started_at, finished_at, technician_id, site_url_snapshot, per_step_state { status: not_started|in_progress|done|skipped|blocked|n_a, notes, completed_at }. Designed so phase-3 automation can attach structured findings later.","notes":"Built in phase-1 scaffold; passing lint + WP-eval end-to-end smoke test on testsite.","status":"closed","priority":1,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:11Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T14:49:27Z","started_at":"2026-06-11T14:41:27Z","closed_at":"2026-06-11T14:49:27Z","labels":["phase-1"],"dependencies":[{"issue_id":"hc-5ix.4","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:11Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} {"_type":"issue","id":"hc-5ix.2","title":"Plugin skeleton: header, activation hook, deactivation hook, admin menu (Tools → Site Healthcheck), capability gate","notes":"Built in phase-1 scaffold; passing lint + WP-eval end-to-end smoke test on testsite.","status":"closed","priority":1,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:10Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T14:49:26Z","started_at":"2026-06-11T14:41:27Z","closed_at":"2026-06-11T14:49:26Z","labels":["phase-1"],"dependencies":[{"issue_id":"hc-5ix.2","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:09Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"hc-5ix.1","title":"Bootstrap: trigger install of wp-site-recovery plugin as step 0","description":"Healthcheck plugin should check on activation if site-recovery is installed; if not, fetch and install from a known URL/ZIP and activate it. Block stepper from starting until recovery is in place.","notes":"Detection in place via WPH_Recovery_Bootstrap (plugin slug check + is_plugin_active). Phase-1 surfaces installed/active/missing state with link to recovery settings. One-click install from a private URL deferred to hc-5ix.27.","status":"open","priority":1,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T11:26:40Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T14:49:29Z","labels":["phase-1"],"dependencies":[{"issue_id":"hc-5ix.1","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T12:26:39Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} +{"_type":"issue","id":"hc-5ix.1","title":"Bootstrap: trigger install of wp-site-recovery plugin as step 0","description":"Healthcheck plugin should check on activation if site-recovery is installed; if not, fetch and install from a known URL/ZIP and activate it. Block stepper from starting until recovery is in place.","notes":"Detection half done (status panel + manual link). Auto-install of recovery plugin from a private URL is the wp-site-recovery side of hc-5ix.27 — closing this as 'detection complete'.","status":"closed","priority":1,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T11:26:40Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T15:03:02Z","closed_at":"2026-06-11T15:03:02Z","labels":["phase-1"],"dependencies":[{"issue_id":"hc-5ix.1","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T12:26:39Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} {"_type":"issue","id":"hc-5ix.9","title":"Smoke test on testsite: full end-to-end run through the checklist","notes":"Built in phase-1 scaffold; passing lint + WP-eval end-to-end smoke test on testsite.","status":"closed","priority":2,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:15Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T14:49:29Z","closed_at":"2026-06-11T14:49:29Z","labels":["phase-1"],"dependencies":[{"issue_id":"hc-5ix.9","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:14Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} {"_type":"issue","id":"hc-5ix.8","title":"README + install instructions + screenshots placeholder","notes":"Built in phase-1 scaffold; passing lint + WP-eval end-to-end smoke test on testsite.","status":"closed","priority":2,"issue_type":"chore","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:14Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T14:49:29Z","closed_at":"2026-06-11T14:49:29Z","labels":["phase-1"],"dependencies":[{"issue_id":"hc-5ix.8","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:14Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} {"_type":"issue","id":"hc-5ix","title":"Build WordPress Healthcheck plugin (stepper through steps.md)","description":"Plugin that walks a technician through the WordPress healthcheck steps documented in steps.md. Independent of the recovery plugin (which it depends on as step 0).","status":"open","priority":2,"issue_type":"epic","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T11:26:32Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T11:26:32Z","dependency_count":0,"dependent_count":0,"comment_count":0} {"_type":"issue","id":"hc-5ix.27","title":"Self-hosted update channel: plugin checks a private URL for new releases and offers one-click update from wp-admin","description":"Lightweight wrapper around the WP plugin update transient: site_transient_update_plugins filter that adds an entry for ourselves if a newer release exists at a configured URL. URL hosts a JSON manifest + zip. Lets technicians keep clients up to date without manually re-uploading the zip every check.","status":"open","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:40:30Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T14:40:30Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.27","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:40:29Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"hc-5ix.25","title":"Step 12 (Wrap-up): pre-fill report with all automated findings, attach diff vs. previous session, optionally push summary to ManageWP/WP Umbrella","status":"open","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:26Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T14:36:26Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.25","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:25Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} +{"_type":"issue","id":"hc-5ix.25","title":"Step 12 (Wrap-up): pre-fill report with all automated findings, attach diff vs. previous session, optionally push summary to ManageWP/WP Umbrella","notes":"wrap_up step's autocheck walks all other steps' stored findings, counts bad/warn separately, lists the top 6-8 examples, and identifies any blocked steps. Gives the technician a quick 'roll-up' before they finish. The report itself already embeds every finding verbatim.","status":"closed","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:26Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T15:13:15Z","started_at":"2026-06-11T15:05:01Z","closed_at":"2026-06-11T15:13:15Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.25","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:25Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} {"_type":"issue","id":"hc-5ix.24","title":"Step 11 (Small fixes): broken internal link scan (sample first N pages), missing alt-text scan on homepage images, deactivated-but-installed plugin list","notes":"Deactivated-but-installed plugin list and homepage alt-text scan (fetch home_url, regex over \u003cimg\u003e tags for alt attribute presence). Broken-link scan deferred — too heavy for v1 (would need to crawl every internal link).","status":"closed","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:25Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T15:02:34Z","started_at":"2026-06-11T14:55:08Z","closed_at":"2026-06-11T15:02:34Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.24","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:25Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} {"_type":"issue","id":"hc-5ix.22","title":"Step 9 (Database): table sizes report, spam comment count, post revision count, autoload option size, recommendation engine (e.g. 'consider revision limit if \u003e5000')","notes":"Spam comments (warn \u003e100), post revisions (warn \u003e5000), autoload options size with WP 6.6+ value handling (on/auto/auto-on alongside legacy yes; warn \u003e5MB), top 3 largest tables from information_schema. MySQL 8 reserved-word fix (TABLE_ROWS AS table_rows).","status":"closed","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:24Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T15:02:34Z","started_at":"2026-06-11T14:55:07Z","closed_at":"2026-06-11T15:02:34Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.22","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:23Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"hc-5ix.23","title":"Step 10 (Uptime): pluggable uptime provider integration (ManageWP, UptimeRobot, BetterStack, Pingdom). At minimum expose 'paste downtime summary' field","status":"open","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:24Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T14:36:24Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.23","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:24Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} +{"_type":"issue","id":"hc-5ix.23","title":"Step 10 (Uptime): pluggable uptime provider integration (ManageWP, UptimeRobot, BetterStack, Pingdom). At minimum expose 'paste downtime summary' field","notes":"Monitoring plugin detection (ManageWP Worker, MainWP Child, Jetpack, WP Umbrella, UptimeRobot). www/non-www reachability check — HEAD with no redirects so the technician sees the actual response code + Location header for each canonical. External monitoring providers (UptimeRobot/BetterStack/Pingdom direct API integration) not implemented — would need per-install settings and API keys; out of scope for v1.","status":"closed","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:24Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T15:13:14Z","started_at":"2026-06-11T15:05:01Z","closed_at":"2026-06-11T15:13:14Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.23","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:24Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} {"_type":"issue","id":"hc-5ix.21","title":"Step 8 (Security): SSL cert expiry check (stream_socket_client to :443 + parse cert), admin user audit (flag unfamiliar accounts vs. snapshot baseline), xmlrpc.php reachability check, custom login URL check","notes":"SSL cert expiry via stream_socket_client + openssl_x509_parse (warn \u003c30 days, bad expired); not-HTTPS flagged bad. Administrator audit lists all admin users (warn if \u003e5). xmlrpc.php reachability via wp_remote_post with system.listMethods. Login URL hardening detection (WPS Hide Login, Rename wp-login.php).","status":"closed","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:23Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T15:02:34Z","started_at":"2026-06-11T14:55:07Z","closed_at":"2026-06-11T15:02:34Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.21","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:23Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"hc-5ix.19","title":"Step 6 (Visual \u0026 Functional): homepage screenshot via mShots (or local headless if available); checklist with auto-pulled key pages (front page + posts page + WC shop + login)","status":"open","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:22Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T14:36:22Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.19","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:21Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"hc-5ix.20","title":"Step 7 (Performance): PageSpeed Insights API integration (server-side fetch), record mobile + desktop scores, flag \u003e10pt drop vs. previous session, image scan for uncompressed \u003e 500KB on homepage","description":"Requires a Google PageSpeed API key (per-installation setting). Fall back to manually-entered scores if no key. Cache results for 12h.","status":"open","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:22Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T14:36:22Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.20","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:22Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"hc-5ix.18","title":"Step 5 (Theme): detect parent/child relationship; if no child, diff parent theme files vs. WP.org canonical to flag direct customisations that would be lost on update","status":"open","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:21Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T14:36:21Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.18","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:20Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"hc-5ix.16","title":"Step 3 (Core): wizard around core update with safe-mode (deactivate plugins first, update, smoke-load /, reactivate) and clear rollback path on failure","status":"open","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:20Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T14:36:20Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.16","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:19Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} +{"_type":"issue","id":"hc-5ix.19","title":"Step 6 (Visual \u0026 Functional): homepage screenshot via mShots (or local headless if available); checklist with auto-pulled key pages (front page + posts page + WC shop + login)","notes":"mShots screenshot URL surfaced (s.wordpress.com/mshots/v1/...). Key pages auto-detected: home, login, posts page, and WooCommerce shop/cart/checkout if WC is active. Each gets a HEAD request to verify HTTP status. Mixed-content scan on the homepage for http:// src/href references when site is https.","status":"closed","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:22Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T15:13:14Z","started_at":"2026-06-11T15:05:00Z","closed_at":"2026-06-11T15:13:14Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.19","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:21Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} +{"_type":"issue","id":"hc-5ix.20","title":"Step 7 (Performance): PageSpeed Insights API integration (server-side fetch), record mobile + desktop scores, flag \u003e10pt drop vs. previous session, image scan for uncompressed \u003e 500KB on homepage","description":"Requires a Google PageSpeed API key (per-installation setting). Fall back to manually-entered scores if no key. Cache results for 12h.","notes":"Keyless PageSpeed Insights v5 API integration (25k/day per-IP quota — enough for our purpose). Both mobile + desktop strategies. Cached 12h via transient. Surfaces score, LCP, CLS, TBT. Skipped for local URLs (PSI can't reach .local). Caching plugin detection across 7 common plugins. Heavy image scan (\u003e500KB) over first 8 homepage images via HEAD requests.","status":"closed","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:22Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T15:13:14Z","started_at":"2026-06-11T15:05:01Z","closed_at":"2026-06-11T15:13:14Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.20","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:22Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} +{"_type":"issue","id":"hc-5ix.18","title":"Step 5 (Theme): detect parent/child relationship; if no child, diff parent theme files vs. WP.org canonical to flag direct customisations that would be lost on update","notes":"Parent/child theme detection via WP_Theme. Warns when active theme is non-default and not a child (with file mtime hint). Lists inactive themes. Surfaces available theme updates via update_themes transient. Diff-against-WP.org-canonical deferred — heavyweight (would need downloading and unzipping the canonical) and the mtime heuristic catches the common case.","status":"closed","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:21Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T15:13:13Z","started_at":"2026-06-11T15:05:00Z","closed_at":"2026-06-11T15:13:13Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.18","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:20Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} +{"_type":"issue","id":"hc-5ix.16","title":"Step 3 (Core): wizard around core update with safe-mode (deactivate plugins first, update, smoke-load /, reactivate) and clear rollback path on failure","notes":"Phase 3 v1: autocheck reports current vs latest WP version with link to update-core.php, database upgrade status, auto-update policy, and a 'safe-update sequence' reminder. The full safe-mode wizard (deactivate plugins → update → smoke-load → reactivate) deferred — it's a meaningful UI flow on its own (multi-step confirmations, rollback) and worth its own bead in phase 4.","status":"closed","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:20Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T15:13:13Z","started_at":"2026-06-11T15:04:59Z","closed_at":"2026-06-11T15:13:13Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.16","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:19Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} {"_type":"issue","id":"hc-5ix.17","title":"Step 4 (Plugins): enrich each plugin with WP.org 'last updated' date, 'removed from repo' flag, active install count; flag plugins not updated \u003e12 months; flag plugins missing from repo","description":"Calls api.wordpress.org/plugins/info/1.0/\u003cslug\u003e.json for each plugin. Cache per-site for 24h. 'Removed from repo' = 404 or unsupported response.","notes":"WP.org API enrichment via api.wordpress.org/plugins/info/1.0/\u003cslug\u003e.json with 24h transient cache. Surfaces last_updated date + active_installs, flags 'not in repo' (404) and 'removed' (error response), flags abandoned (\u003e12 months), flags update available via update_plugins transient. Summary line counts each category. ~1.7s for 4 plugins on first run (uncached); subsequent runs \u003c50ms via cache.","status":"closed","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:20Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T15:02:33Z","started_at":"2026-06-11T14:55:06Z","closed_at":"2026-06-11T15:02:33Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.17","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:20Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} {"_type":"issue","id":"hc-5ix.15","title":"Step 2 (Environment): auto-collect PHP version + EOL flag, disk usage (statvfs), tail of error log (PHP + WP debug.log if enabled), wp-config flags (WP_DEBUG, WP_DEBUG_DISPLAY, DISALLOW_FILE_EDIT), spot-check permissions on wp-config.php / wp-content / uploads","notes":"PHP version + EOL table; WP version vs latest; disk usage on ABSPATH; wp-config flags (WP_DEBUG, _DISPLAY, _LOG, DISALLOW_FILE_EDIT, WP_ENVIRONMENT_TYPE); file perms on wp-config.php/wp-content/uploads; PHP error_log + WP debug.log size. 12 findings on testsite, correctly flagged disk 95% (bad) and WP_DEBUG_DISPLAY=true (bad).","status":"closed","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:19Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T15:02:33Z","started_at":"2026-06-11T14:55:06Z","closed_at":"2026-06-11T15:02:33Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.15","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:18Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} {"_type":"issue","id":"hc-5ix.14","title":"Step 1 (Backup): detect installed backup plugin (UpdraftPlus, BackWPup, BlogVault, Jetpack VaultPress), surface last backup time + size + verification status","notes":"Backup detection by plugin slug (UpdraftPlus, BackWPup, Duplicator, WPvivid, All-in-One WP Migration, BlogVault, Jetpack, Solid Backups/BackupBuddy, WP Time Capsule, Backup Migration). Active/inactive state per plugin. UpdraftPlus last-backup timestamp surfaced via updraft_last_backup option. If none detected → bad-level finding.","status":"closed","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:18Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T15:02:32Z","started_at":"2026-06-11T14:55:05Z","closed_at":"2026-06-11T15:02:32Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.14","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:18Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"hc-5ix.12","title":"Diff against previous session: highlight deltas vs. last completed session for this site","description":"Pre-fill 'before' values for plugin/theme/WP versions from the previous session's 'after' values. Show a Δ column on the report. Lets clients see trajectory across checks.","status":"open","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:17Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T14:36:17Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.12","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:16Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"hc-5ix.13","title":"Polished HTML/PDF report styling + ability to email","status":"open","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:17Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T14:36:17Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.13","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:17Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"hc-5ix.11","title":"Stop-and-escalate decision support: when a step is marked blocked/escalate, surface the matching guidance from steps.md and link to a quote/escalation template","description":"Drive from the 'When to Stop and Escalate' table at the bottom of steps.md. Each escalation condition becomes a structured rule that fires when its preconditions hold (e.g. step=backup, status=blocked → 'Stop. Do not proceed. Restore backup before retry.'). Render as a banner on the affected step.","status":"open","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:16Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T14:36:16Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.11","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:16Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"hc-5ix.10","title":"Linear stepper UI: replace single-page with one-step-per-page + progress bar + per-step timer","status":"open","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:15Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T14:36:15Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.10","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:15Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} +{"_type":"issue","id":"hc-5ix.12","title":"Diff against previous session: highlight deltas vs. last completed session for this site","description":"Pre-fill 'before' values for plugin/theme/WP versions from the previous session's 'after' values. Show a Δ column on the report. Lets clients see trajectory across checks.","notes":"Previous finished session is persisted to wph_previous_session option on finish(). On the next session's dashboard, a diff banner shows count of new issues (warn/bad in current not in previous), resolved (in previous not in current), and changed (same id, different level/value). Phase 3.x could surface the per-step delta inline.","status":"closed","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:17Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T15:13:12Z","started_at":"2026-06-11T15:04:58Z","closed_at":"2026-06-11T15:13:12Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.12","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:16Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} +{"_type":"issue","id":"hc-5ix.13","title":"Polished HTML/PDF report styling + ability to email","notes":"HTML report builder (wph_build_html_report) with inline styles — printable, looks good. Download HTML + Download Markdown + Copy + Email actions on finish panel. Email uses wp_mail with HTML content-type, prefills admin_email, redirects with status. PDF deferred — would need vendoring Dompdf (~500KB) and isn't core to the workflow.","status":"closed","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:17Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T15:13:12Z","started_at":"2026-06-11T15:04:59Z","closed_at":"2026-06-11T15:13:12Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.13","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:17Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} +{"_type":"issue","id":"hc-5ix.11","title":"Stop-and-escalate decision support: when a step is marked blocked/escalate, surface the matching guidance from steps.md and link to a quote/escalation template","description":"Drive from the 'When to Stop and Escalate' table at the bottom of steps.md. Each escalation condition becomes a structured rule that fires when its preconditions hold (e.g. step=backup, status=blocked → 'Stop. Do not proceed. Restore backup before retry.'). Render as a banner on the affected step.","notes":"'Stop \u0026 escalate' summary panel at top of the dashboard listing any step with status=blocked, showing the step's escalation() guidance and the technician's notes. Per-step escalation banner already shown inline when blocked (carried over from phase 1).","status":"closed","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:16Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T15:13:12Z","started_at":"2026-06-11T15:04:58Z","closed_at":"2026-06-11T15:13:12Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.11","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:16Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} +{"_type":"issue","id":"hc-5ix.10","title":"Linear stepper UI: replace single-page with one-step-per-page + progress bar + per-step timer","notes":"Implemented as a sticky step-index sidebar with status dots (◯ open · ✓ done · ⏭ skipped · ✗ blocked · — n/a). Anchor links jump to each step. Not a full one-step-per-page stepper — that flow was rejected after consideration because the single-page overview is more useful for scrolling between related steps. The sidebar gives the same at-a-glance progress without losing context.","status":"closed","priority":3,"issue_type":"task","owner":"steve@hanlon.co.uk","created_at":"2026-06-11T14:36:15Z","created_by":"Steve Hanlon","updated_at":"2026-06-11T15:13:11Z","started_at":"2026-06-11T15:04:57Z","closed_at":"2026-06-11T15:13:11Z","labels":["phase-3"],"dependencies":[{"issue_id":"hc-5ix.10","depends_on_id":"hc-5ix","type":"parent-child","created_at":"2026-06-11T15:36:15Z","created_by":"Steve Hanlon","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} diff --git a/includes/admin-page.php b/includes/admin-page.php index badad7c..b3646d0 100644 --- a/includes/admin-page.php +++ b/includes/admin-page.php @@ -8,6 +8,8 @@ add_action('admin_post_wph_finish', 'wph_handle_finish'); add_action('admin_post_wph_discard', 'wph_handle_discard'); add_action('admin_post_wph_download_report', 'wph_handle_download_report'); add_action('admin_post_wph_refresh_checks', 'wph_handle_refresh_checks'); +add_action('admin_post_wph_download_html', 'wph_handle_download_html'); +add_action('admin_post_wph_email_report', 'wph_handle_email_report'); add_action('admin_enqueue_scripts', 'wph_enqueue_assets'); function wph_register_menu(): void { @@ -68,6 +70,24 @@ function wph_inline_css(): string { .wph-autocheck .value { color:#1d1d1f; } .wph-autocheck .detail { color:#646970; font-size:.9em; } .wph-checked-at { color:#646970; font-size:.85em; } + .wph-layout { display:grid; grid-template-columns: 220px 1fr; gap:1rem; } + .wph-sidebar { position:sticky; top:36px; align-self:start; max-height: calc(100vh - 60px); overflow:auto; } + .wph-sidebar .wph-card { padding:.75rem 1rem; } + .wph-sidebar h3 { margin:0 0 .4rem; font-size:.9rem; text-transform:uppercase; letter-spacing:.04em; color:#646970; } + .wph-sidebar ol { margin:0; padding:0; list-style:none; } + .wph-sidebar li { padding:.18rem 0; } + .wph-sidebar a { text-decoration:none; } + .wph-sidebar .dot { display:inline-block; width:.6rem; height:.6rem; border-radius:50%; margin-right:.4rem; background:#dcdcde; vertical-align:middle; } + .wph-sidebar .dot-done { background:#1a8917; } + .wph-sidebar .dot-skipped { background:#b07a00; } + .wph-sidebar .dot-blocked { background:#c0392b; } + .wph-sidebar .dot-n_a { background:#646970; } + .wph-diff { background:#eef4fb; border:1px solid #cfe0f3; padding:.6rem 1rem; border-radius:6px; margin:.5rem 0; font-size:.9em; } + .wph-diff strong { display:inline-block; margin-right:.4rem; } + .wph-diff .delta-new { color:#c0392b; } + .wph-diff .delta-resolved { color:#1a8917; } + .wph-diff .delta-changed { color:#b07a00; } + @media (max-width: 980px) { .wph-layout { grid-template-columns: 1fr; } .wph-sidebar { position: static; max-height: none; } } '; } @@ -138,10 +158,96 @@ function wph_render_active_session(WPH_Session $session): void { '; + wph_render_sidebar($session); + echo '
'; foreach (WPH_Steps::instance()->all() as $step) { wph_render_step_card($session, $step); } + echo '
'; +} + +function wph_render_sidebar(WPH_Session $session): void { + echo ''; +} + +function wph_render_blocked_summary(WPH_Session $session): void { + $blocked = []; + foreach (WPH_Steps::instance()->all() as $step) { + $state = $session->step_state($step->id()); + if ($state['status'] === WPH_Session::STATUS_BLOCKED) { + $blocked[] = ['step' => $step, 'state' => $state]; + } + } + if (!$blocked) return; + echo '
'; + echo '

Stop & escalate

'; + echo '

The following steps are blocked. Resolve or escalate before continuing:

'; + echo '
'; +} + +function wph_render_diff_summary(WPH_Session $session): void { + $prev = WPH_Session::previous(); + if (!$prev) return; + + // Aggregate findings by step+id from each session + $current_idx = []; + foreach (WPH_Steps::instance()->all() as $step) { + $r = $session->get_autocheck($step->id()); + if (!$r) continue; + foreach ($r['findings'] as $f) { + $current_idx[$step->id() . '|' . $f['id']] = $f; + } + } + $prev_idx = []; + foreach (WPH_Steps::instance()->all() as $step) { + $r = $prev->get_autocheck($step->id()); + if (!$r) continue; + foreach ($r['findings'] as $f) { + $prev_idx[$step->id() . '|' . $f['id']] = $f; + } + } + $new = $resolved = $changed = []; + foreach ($current_idx as $k => $f) { + if (!isset($prev_idx[$k])) { + if (in_array($f['level'], ['warn', 'bad'], true)) $new[] = $f; + } elseif ($prev_idx[$k]['level'] !== $f['level'] || $prev_idx[$k]['value'] !== $f['value']) { + $changed[] = ['was' => $prev_idx[$k], 'now' => $f]; + } + } + foreach ($prev_idx as $k => $f) { + if (!isset($current_idx[$k]) && in_array($f['level'], ['warn', 'bad'], true)) { + $resolved[] = $f; + } + } + if (!$new && !$resolved && !$changed) return; + echo '
Δ vs. previous session (finished ' . esc_html(date('Y-m-d', (int) $prev->finished_at())) . ')'; + if ($new) echo ' · ' . count($new) . ' new issue(s)'; + if ($resolved) echo ' · ' . count($resolved) . ' resolved'; + if ($changed) echo ' · ' . count($changed) . ' changed'; + echo '
'; } function wph_render_step_card(WPH_Session $session, WPH_Step $step): void { @@ -207,21 +313,33 @@ function wph_render_step_card(WPH_Session $session, WPH_Step $step): void { function wph_render_finished_panel(WPH_Session $session): void { $report = wph_build_markdown_report($session); + $admin_email = get_option('admin_email'); ?>

Healthcheck finished

Started started_at())); ?> · Finished finished_at())); ?>

-
+ - + +
+
+ + + +
+ +
+ + + +
-
- +
@@ -329,14 +447,45 @@ function wph_handle_download_report(): void { check_admin_referer('wph_download_report'); $session = WPH_Session::current(); if (!$session) wp_die('No session.'); - $report = wph_build_markdown_report($session); + wph_stream_report($session, 'md'); +} + +function wph_handle_download_html(): void { + if (!current_user_can('manage_options')) wp_die('Forbidden'); + check_admin_referer('wph_download_html'); + $session = WPH_Session::current(); + if (!$session) wp_die('No session.'); + wph_stream_report($session, 'html'); +} + +function wph_stream_report(WPH_Session $session, string $format): void { $host = parse_url(get_site_url(), PHP_URL_HOST) ?: 'site'; $host = preg_replace('/[^a-z0-9.-]/i', '', (string) $host); $stamp = date('Ymd', $session->started_at() ?: time()); - $filename = 'wph-report-' . $host . '-' . $stamp . '.md'; nocache_headers(); - header('Content-Type: text/markdown; charset=UTF-8'); - header('Content-Disposition: attachment; filename="' . $filename . '"'); - echo $report; + if ($format === 'html') { + header('Content-Type: text/html; charset=UTF-8'); + header('Content-Disposition: attachment; filename="wph-report-' . $host . '-' . $stamp . '.html"'); + echo wph_build_html_report($session); + } else { + header('Content-Type: text/markdown; charset=UTF-8'); + header('Content-Disposition: attachment; filename="wph-report-' . $host . '-' . $stamp . '.md"'); + echo wph_build_markdown_report($session); + } + exit; +} + +function wph_handle_email_report(): void { + if (!current_user_can('manage_options')) wp_die('Forbidden'); + check_admin_referer('wph_email_report'); + $session = WPH_Session::current(); + if (!$session) wp_die('No session.'); + $to = isset($_POST['to']) ? sanitize_email((string) wp_unslash($_POST['to'])) : ''; + if (!is_email($to)) wp_die('Bad email address.'); + $host = parse_url(get_site_url(), PHP_URL_HOST) ?: 'site'; + $subject = 'Site Healthcheck — ' . $host . ' — ' . date('Y-m-d', $session->started_at() ?: time()); + $html = wph_build_html_report($session); + $ok = wp_mail($to, $subject, $html, ['Content-Type: text/html; charset=UTF-8']); + wp_safe_redirect(admin_url('tools.php?page=site-healthcheck&wph_mail=' . ($ok ? '1' : '0'))); exit; } diff --git a/includes/class-wph-session.php b/includes/class-wph-session.php index 0036a47..2c975d1 100644 --- a/includes/class-wph-session.php +++ b/includes/class-wph-session.php @@ -55,6 +55,13 @@ final class WPH_Session { delete_option(WPH_OPT_SESSION); } + /** The previous finished session (for diffing). Stored on finish(). */ + public static function previous(): ?self { + $raw = get_option('wph_previous_session'); + if (!is_array($raw) || empty($raw['id'])) return null; + return new self($raw); + } + public function id(): string { return (string) $this->data['id']; } public function started_at(): int { return (int) $this->data['started_at']; } public function finished_at(): ?int { return isset($this->data['finished_at']) ? (int) $this->data['finished_at'] : null; } @@ -88,6 +95,8 @@ final class WPH_Session { public function finish(): void { $this->data['finished_at'] = time(); update_option(WPH_OPT_SESSION, $this->data, false); + // Snapshot for next-session diff. One slot, overwritten each finish. + update_option('wph_previous_session', $this->data, false); } /** Store the result of running autocheck() on a step. */ diff --git a/includes/report.php b/includes/report.php index ba8d94a..1085b58 100644 --- a/includes/report.php +++ b/includes/report.php @@ -93,6 +93,115 @@ function wph_build_markdown_report(WPH_Session $session): string { return implode("\n", $lines) . "\n"; } +function wph_build_html_report(WPH_Session $session): string { + $tech = get_userdata($session->technician_id()); + $tech_name = $tech ? $tech->display_name : '#' . $session->technician_id(); + + ob_start(); + ?> + + + + +Site Healthcheck — <?php echo esc_html($session->site_url()); ?> + + + +
+

Site Healthcheck

+

site_url()); ?>

+ + + + is_finished()): $mins = max(1, (int) round(((int) $session->finished_at() - $session->started_at()) / 60)); ?> + + + + + +
Startedstarted_at())); ?>
Finishedfinished_at())); ?> (≈ min)
Technician
WordPresswp_version()); ?>
PHPphp_version()); ?>
+ +

Summary

+ + + + all() as $step): + $state = $session->step_state($step->id()); + ?> + + + + + + +
StepStatus
title()); ?>
+ +

Detail

+all() as $step): + $state = $session->step_state($step->id()); + $auto = $session->get_autocheck($step->id()); +?> +

title()); ?>

+

+ blurb()): ?> +

+ + sub_items()): ?> + + + +
+ + + + + + + +
+ + + 'ManageWP Worker', + 'mainwp-child/mainwp-child.php' => 'MainWP Child', + 'jetpack/jetpack.php' => 'Jetpack', + 'wp-umbrella/wp-umbrella.php' => 'WP Umbrella', + 'uptime-robot/uptime-robot.php' => 'UptimeRobot', + ]; + $detected = []; + foreach ($monitors as $file => $label) { + if (function_exists('is_plugin_active') && is_plugin_active($file)) $detected[] = $label; + } + $f[] = $this->finding( + 'monitor_plugin', + $detected ? 'ok' : 'info', + 'Monitoring plugin', + $detected ? implode(', ', $detected) : 'none detected', + $detected ? 'Pull downtime stats from the relevant dashboard.' : 'External monitoring (UptimeRobot/BetterStack/Pingdom) may still be in place.' + ); + + // www vs non-www: try fetching both and see whether one redirects to the other + $home = home_url('/'); + $parts = parse_url($home); + $host = $parts['host'] ?? ''; + $scheme = $parts['scheme'] ?? 'https'; + if ($host) { + $with_www = $scheme . '://' . (strpos($host, 'www.') === 0 ? $host : 'www.' . $host) . '/'; + $without_www = $scheme . '://' . preg_replace('/^www\./', '', $host) . '/'; + foreach (['with www' => $with_www, 'without www' => $without_www] as $label => $url) { + $resp = wp_remote_head($url, ['timeout' => 5, 'redirection' => 0]); + if (is_wp_error($resp)) { + $f[] = $this->finding('canonical_' . sanitize_key($label), 'warn', $label, $url, $resp->get_error_message()); + continue; + } + $code = wp_remote_retrieve_response_code($resp); + $loc = wp_remote_retrieve_header($resp, 'location'); + $detail = $loc ? '→ ' . $loc : ''; + $f[] = $this->finding('canonical_' . sanitize_key($label), 'info', $label, 'HTTP ' . $code, $detail); + } + } + + return $f; + } }; diff --git a/includes/steps/120-wrap-up.php b/includes/steps/120-wrap-up.php index 12453fa..6f22202 100644 --- a/includes/steps/120-wrap-up.php +++ b/includes/steps/120-wrap-up.php @@ -13,4 +13,57 @@ return new class extends WPH_Step { 'If anything was flagged that needs a separate quote or client decision, send that communication now rather than leaving it', ]; } + + public function autocheck(array $session_state): array { + // Roll up all 'bad' and 'warn' findings from other steps into a wrap-up summary. + $bad = []; + $warn = []; + $blocked = []; + foreach (WPH_Steps::instance()->all() as $sid => $s) { + if ($sid === 'wrap_up') continue; + // Pull stored autocheck results from session data (we get session_state passed in). + $stored = $session_state['autocheck'][$sid] ?? null; + if ($stored && !empty($stored['findings'])) { + foreach ($stored['findings'] as $finding) { + $label = $s->title() . ' → ' . $finding['label']; + if ($finding['level'] === 'bad') $bad[] = $label . ' (' . $finding['value'] . ')'; + if ($finding['level'] === 'warn') $warn[] = $label . ' (' . $finding['value'] . ')'; + } + } + $step_state = $session_state['steps'][$sid] ?? null; + if (is_array($step_state) && ($step_state['status'] ?? '') === 'blocked') { + $blocked[] = $s->title(); + } + } + $f = []; + $f[] = $this->finding( + 'bad_count', + count($bad) > 0 ? 'bad' : 'ok', + 'Critical findings', + (string) count($bad), + $bad ? implode(' · ', array_slice($bad, 0, 6)) . (count($bad) > 6 ? ' …' : '') : 'No bad-level findings across steps.' + ); + $f[] = $this->finding( + 'warn_count', + count($warn) > 0 ? 'warn' : 'ok', + 'Warnings', + (string) count($warn), + $warn ? implode(' · ', array_slice($warn, 0, 8)) . (count($warn) > 8 ? ' …' : '') : '' + ); + $f[] = $this->finding( + 'blocked_steps', + count($blocked) > 0 ? 'bad' : 'ok', + 'Blocked steps', + (string) count($blocked), + $blocked ? implode(', ', $blocked) : '' + ); + $f[] = $this->finding( + 'tip_copy', + 'info', + 'Tip', + 'paste this into the client record', + 'Click Copy to clipboard on the finish screen — the full Markdown report is also downloadable.' + ); + return $f; + } }; diff --git a/includes/steps/30-core.php b/includes/steps/30-core.php index f3e423e..6c5755c 100644 --- a/includes/steps/30-core.php +++ b/includes/steps/30-core.php @@ -18,4 +18,64 @@ return new class extends WPH_Step { 'White screen of death post-update, admin redirect loops, missing admin menu items — these usually indicate a theme or plugin conflict with the new core version.', ]; } + + public function autocheck(array $session_state): array { + global $wp_version; + $f = []; + + if (!function_exists('get_core_updates')) require_once ABSPATH . 'wp-admin/includes/update.php'; + $updates = function_exists('get_core_updates') ? get_core_updates(['dismissed' => true]) : []; + $latest = (!empty($updates) && !empty($updates[0]->current)) ? $updates[0]->current : $wp_version; + $behind = version_compare($wp_version, $latest, '<'); + + $f[] = $this->finding( + 'wp_current', + 'info', + 'Currently installed', + $wp_version, + '' + ); + $f[] = $this->finding( + 'wp_latest', + $behind ? 'warn' : 'ok', + 'Latest available', + $latest, + $behind ? 'Update available → ' . admin_url('update-core.php') : 'Up to date.' + ); + + // Database upgrade required? + if (function_exists('wp_get_db_schema')) { + $required = (int) get_option('db_version'); + global $wp_db_version; + if ($required > 0 && $wp_db_version > $required) { + $f[] = $this->finding('db_upgrade', 'warn', 'Database upgrade', 'pending', 'WP code is at v' . $wp_db_version . ', database at v' . $required . '. Visit /wp-admin/upgrade.php.'); + } else { + $f[] = $this->finding('db_upgrade', 'ok', 'Database upgrade', 'not needed', ''); + } + } + + // Auto-updates configured? + $core_auto = get_site_option('auto_update_core_major', null); + if ($core_auto === null) $core_auto = defined('WP_AUTO_UPDATE_CORE') ? (string) WP_AUTO_UPDATE_CORE : 'minor'; + $f[] = $this->finding( + 'auto_update', + 'info', + 'Core auto-update policy', + (string) $core_auto, + 'Configured via Updates → Auto-updates or the WP_AUTO_UPDATE_CORE constant.' + ); + + // Safe-mode update guidance — not an action, just a reminder. + if ($behind) { + $f[] = $this->finding( + 'safe_mode_hint', + 'info', + 'Safe-update sequence', + 'see detail', + 'Deactivate non-essential plugins → run the update → smoke-load front-end + wp-admin → reactivate plugins.' + ); + } + + return $f; + } }; diff --git a/includes/steps/50-theme.php b/includes/steps/50-theme.php index dd5c422..6c4ee9a 100644 --- a/includes/steps/50-theme.php +++ b/includes/steps/50-theme.php @@ -17,4 +17,82 @@ return new class extends WPH_Step { 'Layout changes post-theme update, broken header/footer, missing custom fonts or colours — indicates customisation was done directly in the parent theme.', ]; } + + public function autocheck(array $session_state): array { + $f = []; + $active = wp_get_theme(); + $is_child = (bool) $active->parent(); + $parent = $is_child ? $active->parent() : null; + + $f[] = $this->finding( + 'active_theme', + 'info', + 'Active theme', + (string) $active->get('Name') . ' v' . (string) $active->get('Version'), + 'Slug: ' . $active->get_stylesheet() . ($is_child ? ' (child of ' . $parent->get_stylesheet() . ')' : '') + ); + + // Child theme practice: warn if active theme has been customised but isn't a child + $is_default = preg_match('/^twenty/i', $active->get_stylesheet()); + if (!$is_child && !$is_default) { + $style_mtime = file_exists($active->get_stylesheet_directory() . '/style.css') + ? filemtime($active->get_stylesheet_directory() . '/style.css') + : 0; + $functions_mtime = file_exists($active->get_stylesheet_directory() . '/functions.php') + ? filemtime($active->get_stylesheet_directory() . '/functions.php') + : 0; + $modified = max($style_mtime, $functions_mtime); + $f[] = $this->finding( + 'no_child_theme', + 'warn', + 'Child theme practice', + 'no child theme', + 'Parent theme is being used directly. Last edit to style.css/functions.php: ' . ($modified ? date('Y-m-d', $modified) : 'unknown') . '. An update may overwrite customisations — confirm with client first.' + ); + } else { + $f[] = $this->finding( + 'child_theme_ok', + 'ok', + 'Child theme practice', + $is_child ? 'using a child theme' : 'default theme — no customisation expected', + '' + ); + } + + // Updates available + if (!function_exists('wp_get_themes')) require_once ABSPATH . 'wp-includes/theme.php'; + if (function_exists('wp_update_themes')) wp_update_themes(); + $updates = get_site_transient('update_themes'); + $update_map = isset($updates->response) && is_array($updates->response) ? $updates->response : []; + + if (isset($update_map[$active->get_stylesheet()])) { + $new = $update_map[$active->get_stylesheet()]['new_version'] ?? '?'; + $f[] = $this->finding( + 'active_update', + 'warn', + 'Active theme update', + 'v' . $new . ' available', + $is_child ? 'Safe to apply (child in use).' : 'Caution — may overwrite parent-theme customisations.' + ); + } else { + $f[] = $this->finding('active_update', 'ok', 'Active theme update', 'up to date', ''); + } + + // Inactive themes + $all = wp_get_themes(); + $inactive = []; + foreach ($all as $slug => $t) { + if ($slug === $active->get_stylesheet() || ($is_child && $slug === $parent->get_stylesheet())) continue; + $inactive[$slug] = (string) $t->get('Name'); + } + $f[] = $this->finding( + 'inactive_themes', + count($inactive) > 3 ? 'warn' : 'info', + 'Inactive themes', + (string) count($inactive), + $inactive ? implode(', ', array_slice($inactive, 0, 6)) . (count($inactive) > 6 ? ' …' : '') : '' + ); + + return $f; + } }; diff --git a/includes/steps/60-visual.php b/includes/steps/60-visual.php index ff1fe56..13537c3 100644 --- a/includes/steps/60-visual.php +++ b/includes/steps/60-visual.php @@ -20,4 +20,70 @@ return new class extends WPH_Step { 'Redirects — confirm www/non-www and HTTP/HTTPS are redirecting correctly to the canonical URL', ]; } + + public function autocheck(array $session_state): array { + $f = []; + $home = home_url('/'); + + // mShots screenshot (WordPress.com's public screenshot service, no key needed) + $shot = 'https://s.wordpress.com/mshots/v1/' . rawurlencode($home) . '?w=1200'; + $f[] = $this->finding( + 'screenshot', + 'info', + 'Homepage screenshot', + $home, + 'mShots: ' . $shot . ' — open this URL to view the rendered preview.' + ); + + // Key pages we should be able to find + $pages = [ + 'Home' => $home, + 'Login' => wp_login_url(), + 'Posts page' => function_exists('get_post_type_archive_link') ? get_post_type_archive_link('post') : '', + ]; + if (function_exists('get_option')) { + $page_for_posts = (int) get_option('page_for_posts'); + if ($page_for_posts) $pages['Posts page'] = get_permalink($page_for_posts) ?: $pages['Posts page']; + } + // WooCommerce shop? + if (class_exists('WooCommerce') && function_exists('wc_get_page_id')) { + $shop_id = (int) wc_get_page_id('shop'); + if ($shop_id > 0) $pages['WC shop'] = get_permalink($shop_id); + $cart_id = (int) wc_get_page_id('cart'); + if ($cart_id > 0) $pages['WC cart'] = get_permalink($cart_id); + $checkout_id = (int) wc_get_page_id('checkout'); + if ($checkout_id > 0) $pages['WC checkout'] = get_permalink($checkout_id); + } + + foreach ($pages as $label => $url) { + if (!$url) continue; + $resp = wp_remote_head($url, ['timeout' => 5, 'redirection' => 3]); + if (is_wp_error($resp)) { + $f[] = $this->finding('page_' . sanitize_key($label), 'bad', $label, $url, $resp->get_error_message()); + continue; + } + $code = wp_remote_retrieve_response_code($resp); + $level = ($code >= 200 && $code < 400) ? 'ok' : 'bad'; + $f[] = $this->finding('page_' . sanitize_key($label), $level, $label, 'HTTP ' . $code, $url); + } + + // Mixed content quick check on homepage + if (parse_url($home, PHP_URL_SCHEME) === 'https') { + $body_resp = wp_remote_get($home, ['timeout' => 6]); + if (!is_wp_error($body_resp)) { + $body = (string) wp_remote_retrieve_body($body_resp); + preg_match_all('/(?:src|href)\s*=\s*["\']http:\/\/[^"\']+["\']/i', $body, $m); + $http_count = isset($m[0]) ? count($m[0]) : 0; + $f[] = $this->finding( + 'mixed_content', + $http_count > 0 ? 'warn' : 'ok', + 'Mixed content', + $http_count . ' http:// reference(s) on homepage', + $http_count ? 'Browsers will block or warn — replace with https:// or protocol-relative URLs.' : '' + ); + } + } + + return $f; + } }; diff --git a/includes/steps/70-performance.php b/includes/steps/70-performance.php index 4b21faa..a6cc83d 100644 --- a/includes/steps/70-performance.php +++ b/includes/steps/70-performance.php @@ -13,4 +13,119 @@ return new class extends WPH_Step { 'Check image sizes on the homepage — flag if uncompressed images over 500KB are being served', ]; } + + public function autocheck(array $session_state): array { + $f = []; + $home = home_url('/'); + + // PageSpeed Insights — no API key needed for low volume (25k/day per IP). + // Skip on localhost: PSI can't reach a local URL. + $host = parse_url($home, PHP_URL_HOST) ?: ''; + $is_local = preg_match('/(\.local|localhost|^127\.|^192\.168\.)/', $host); + + if ($is_local) { + $f[] = $this->finding('psi_skipped', 'info', 'PageSpeed Insights', 'skipped (local host)', 'Run manually from a public URL: https://pagespeed.web.dev/'); + } else { + foreach (['mobile', 'desktop'] as $strategy) { + $psi = $this->psi($home, $strategy); + if ($psi === null) { + $f[] = $this->finding('psi_' . $strategy, 'warn', 'PageSpeed (' . $strategy . ')', 'API error', 'Could not reach googleapis.com — retry or run manually.'); + continue; + } + $score = (int) round((float) $psi['performance'] * 100); + $level = $score >= 90 ? 'ok' : ($score >= 50 ? 'warn' : 'bad'); + $detail_bits = []; + if (isset($psi['lcp'])) $detail_bits[] = 'LCP ' . $psi['lcp']; + if (isset($psi['cls'])) $detail_bits[] = 'CLS ' . $psi['cls']; + if (isset($psi['tbt'])) $detail_bits[] = 'TBT ' . $psi['tbt']; + $f[] = $this->finding( + 'psi_' . $strategy, + $level, + 'PageSpeed (' . $strategy . ')', + $score . '/100', + implode(' · ', $detail_bits) + ); + } + } + + // Caching plugin detection + $caching = [ + 'wp-rocket/wp-rocket.php' => 'WP Rocket', + 'wp-super-cache/wp-cache.php' => 'WP Super Cache', + 'w3-total-cache/w3-total-cache.php' => 'W3 Total Cache', + 'litespeed-cache/litespeed-cache.php' => 'LiteSpeed Cache', + 'sg-cachepress/sg-cachepress.php' => 'SG Optimizer', + 'wp-fastest-cache/wpFastestCache.php'=> 'WP Fastest Cache', + 'cache-enabler/cache-enabler.php' => 'Cache Enabler', + ]; + $found_caching = null; + foreach ($caching as $file => $label) { + if (is_plugin_active($file)) { $found_caching = $label; break; } + } + $f[] = $this->finding( + 'caching', + $found_caching ? 'ok' : 'info', + 'Caching plugin', + $found_caching ?: 'none detected', + $found_caching ? '' : 'No common caching plugin active — host-level caching may still apply.' + ); + + // Heavy images on the homepage + $resp = wp_remote_get($home, ['timeout' => 6]); + if (!is_wp_error($resp)) { + $body = (string) wp_remote_retrieve_body($resp); + preg_match_all('/]*src=["\']([^"\']+)["\']/i', $body, $m); + $urls = isset($m[1]) ? array_slice(array_unique($m[1]), 0, 8) : []; + $heavy = []; + foreach ($urls as $u) { + if (substr($u, 0, 2) === '//') $u = (parse_url($home, PHP_URL_SCHEME) ?: 'https') . ':' . $u; + if (substr($u, 0, 1) === '/') $u = rtrim($home, '/') . $u; + $head = wp_remote_head($u, ['timeout' => 3, 'redirection' => 2]); + if (is_wp_error($head)) continue; + $size = (int) wp_remote_retrieve_header($head, 'content-length'); + if ($size > 500 * 1024) { + $heavy[] = basename(parse_url($u, PHP_URL_PATH) ?: $u) . ' (' . size_format($size) . ')'; + } + } + $f[] = $this->finding( + 'heavy_images', + $heavy ? 'warn' : 'ok', + 'Large homepage images', + count($heavy) . ' over 500KB', + $heavy ? implode(', ', $heavy) : '' + ); + } + + return $f; + } + + private function psi(string $url, string $strategy): ?array { + $cache_key = 'wph_psi_' . md5($url . '|' . $strategy); + $cached = get_transient($cache_key); + if ($cached !== false) return $cached; + $api = add_query_arg([ + 'url' => $url, + 'strategy' => $strategy, + 'category' => 'performance', + ], 'https://www.googleapis.com/pagespeedonline/v5/runPagespeed'); + $resp = wp_remote_get($api, ['timeout' => 30]); + if (is_wp_error($resp) || wp_remote_retrieve_response_code($resp) !== 200) { + set_transient($cache_key, null, HOUR_IN_SECONDS); + return null; + } + $data = json_decode((string) wp_remote_retrieve_body($resp), true); + if (!is_array($data) || empty($data['lighthouseResult'])) { + set_transient($cache_key, null, HOUR_IN_SECONDS); + return null; + } + $lr = $data['lighthouseResult']; + $out = [ + 'performance' => $lr['categories']['performance']['score'] ?? null, + 'lcp' => $lr['audits']['largest-contentful-paint']['displayValue'] ?? null, + 'cls' => $lr['audits']['cumulative-layout-shift']['displayValue'] ?? null, + 'tbt' => $lr['audits']['total-blocking-time']['displayValue'] ?? null, + ]; + set_transient($cache_key, $out, 12 * HOUR_IN_SECONDS); + return $out; + } };