=== EarlyGoose ===
Contributors: dimax1984
Tags: code quality, file integrity, troubleshooting, site health, monitoring
Requires at least: 6.6
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Find WordPress code and setup issues, check file integrity, and get a detailed report with clear next steps. No account required.

== Description ==

EarlyGoose helps you find code and configuration issues that can break your WordPress site, slow it down, or cause unexpected behaviour. Scan your site and get a report that explains the findings and helps you decide what needs attention.

Use it to review a site before a handover, assess maintenance work, or investigate the condition of an existing installation.

= What the plugin checks =

* **File integrity:** compares WordPress core and supported WordPress.org plugins with official checksums for the installed versions. Reports modified, missing and unexpected files within the areas checked.
* **Code quality:** checks the active theme, its parent theme, installed plugins and must-use plugins for potentially problematic code patterns. This includes commercial and custom code.
* **Site configuration:** identifies configuration issues and highlights relevant facts about your WordPress setup.

Findings are grouped by code ownership and prioritised by severity, with file locations and explanations where available. The report distinguishes problems you can address from issues to raise with a plugin author. You can also email it to your developer.

**Scans run on your server, with no account required.** The plugin fetches reference checksums from WordPress.org. Your code and results stay on your site unless you choose to email a report.

== Installation ==

1. Install and activate EarlyGoose.
2. Open **EarlyGoose** in your WordPress admin.
3. Select **Scan this site** and keep the page open until the scan finishes.

= Rebuilding the JavaScript =

The plugin zip includes `src/`, `package.json`, `package-lock.json`, and `tools/`. From the plugin directory run `npm ci` then `npm run build` to regenerate `build/`.

== Frequently Asked Questions ==

= Is the plugin free to use? =

Yes. No account, subscription or payment is required. There is no trial period or scan limit.

= Does it check custom themes and plugins? =

Yes. The plugin checks code in your active theme, its parent theme and installed plugins. This includes commercial, custom and must-use plugins.

Checking for file changes is separate from checking code for issues. File comparisons cover WordPress core and supported WordPress.org plugins. They do not cover themes or plugins from other sources. Those can still be checked for code issues.

= Is it safe to scan my live site? =

The scan only reads and reports. It does not change your files, content or site settings, or apply fixes. It saves its report and scan data in the WordPress database. Scanning uses server resources, so on busy sites or limited hosting plans, run it during a quieter period.

= Does it run automatically or keep a history? =

No. You start each scan yourself. The latest report replaces the previous one. Earlier reports are not kept.

= Can I share the report? =

Yes. Select **Email report**, choose up to five recipients and add a note if needed. Your site's mail system sends the report. Reports can include file paths, code excerpts and site settings. Share them only with people you trust.

= Is this a security scanner? =

No. EarlyGoose finds code and setup issues that can break your site, slow it down or cause unexpected behaviour. Some findings may also affect security, but EarlyGoose does not replace a malware scanner, vulnerability assessment or firewall.

= Does a report with no findings mean my site has no problems? =

No. It means the scan found no issues in the areas it checked. Some files, themes or plugins may have been skipped, or their files could not be compared with an official release. Review the coverage information too. A report with no findings is not a guarantee that the site is error-free or secure.

= What happens when I uninstall the plugin? =

Deleting the plugin through WordPress removes its saved report, settings, caches and scheduled tasks. It does not delete your site's files or content. Email a copy of the report first if you want to keep it.

= What license applies to the plugin? =

The plugin uses GPLv2 or later. You may use, study, modify and redistribute it under that license.

== Screenshots ==

1. Start a scan and see what the plugin checks, with answers to common questions.
2. Scan findings grouped by code ownership and prioritised by severity.
3. An expanded finding with an explanation, affected files and recommended next steps.
4. Good to know: relevant facts about updates, administrator accounts and site settings.
5. File integrity coverage, showing which files were compared and where no published reference is available.
6. Email a report to your developer or other recipients, with an optional note.

== External services ==

= WordPress.org checksums =

During a scan, the standalone plugin requests core checksums from `api.wordpress.org/core/checksums/1.0/` using the WordPress version and locale, and plugin checksums from `downloads.wordpress.org/plugin-checksums/` using each eligible plugin's slug and version.

These requests do not upload file contents or reports. They use the WordPress HTTP API, whose default User-Agent includes the WordPress version and site URL. The receiving server also sees the request's source IP address.

[WordPress.org privacy policy](https://wordpress.org/about/privacy/)

= Monitoring: optional paid service =

Monitoring is an optional paid [EarlyGoose service](https://earlygoose.com). It adds scheduled scans, scans after enabled site changes, finding history, email alerts and a dashboard for multiple sites. It also provides server-side file comparisons, AI-assisted code analysis and package reviews, email delivery checks and optional WooCommerce order-status monitoring.

**Account and connection.** An administrator must connect the site to an account with an eligible subscription or trial. Choose **Start monitoring** or **Connect this site**, sign in to EarlyGoose and complete the setup. See [plans and pricing](https://earlygoose.com/pricing). None of this is required to run the plugin's standalone scans.

**Code coverage.** Monitoring lets you turn code analysis off for individual plugins. This does not turn off file-integrity comparisons. Excluding code reduces coverage; it does not mean the code is safe.

**Data sent after connecting**

Starting a connection opens `app.earlygoose.com` with the site's admin URL and a temporary connection token. After approval, the plugin communicates with `api.earlygoose.com` and uploads requested files to service-provided storage URLs.

The service receives:

* **Site and scan data:** site URL, WordPress version, theme and plugin inventory, file paths, sizes and hashes, the scan trigger, and detector findings that may include line numbers, code excerpts and configuration observations.
* **Requested file contents:** specific files selected for comparison and analysis, including custom, commercial, modified or additional code. Files do not need a confirmed problem to be selected, and the first scan may require substantial uploads. Uploaded source and findings can contain personal information or credentials. The service uses Anthropic's API for file analysis, package reviews and site-level analysis, sending selected code, file paths, package details, analysis summaries and relevant technical context. Sensitive details are not guaranteed to be automatically removed.
* **Periodic status data:** normally every five minutes through WordPress scheduled tasks, the plugin sends site inventory and setup facts such as PHP and database versions, update settings and administrator counts.
* **Email checks:** when enabled or manually requested, test messages go through your site's mail system to EarlyGoose-controlled addresses received by Resend and, where configured, Postmark. These providers process the test message and delivery metadata, including sender and mail-server details. EarlyGoose records test timing and delivery outcomes. An enabled mail-failure monitor also reports that a send failed. It does not forward the failed email's body, subject or recipients.
* **WooCommerce monitoring:** when WooCommerce and the relevant monitors are enabled, aggregate counts indicating stuck pending orders or payment failures are sent. Individual order records, customer details and payment details are not sent by these monitors.
* **Report sharing and settings:** when used, recipient names and addresses, an optional report note, monitoring settings and finding actions are sent to the service. EarlyGoose sends shared reports through Resend and retains recipient details for suggestions. Reports can include file paths, code excerpts and configuration observations.

The plugin does not upload a database export and excludes `wp-config.php` from file uploads. It reads local database values to produce setup facts and WooCommerce counts. File uploads are limited to requested files within its scanning scope, but findings and source excerpts can reveal information from the files examined.

Authenticated exchanges are initiated by the plugin. When work is requested in the app, EarlyGoose may also send an empty request to `/wp-json/earlygoose/v1/wake` so the plugin checks in sooner. It carries no credentials or scan instructions. Blocking this request does not prevent the plugin from collecting work on its next check-in. Scheduled work depends on WordPress scheduling and may be delayed on sites with little traffic.

EarlyGoose uses Supabase infrastructure for its backend and file storage. Identical source files, fingerprints, comparison baselines and analysis results can be reused across sites. Observed custom or commercial code may contribute to a comparison baseline, which is distinct from an official release. Other customers are not given access to your account or downloads of your uploaded source files.

Stored source files are removed by scheduled cleanup when no site's recorded current files reference them and they are not needed by an unfinished scan or a site's latest failed scan. Disconnecting does not remove the site's last recorded state or history. Fingerprints, comparison baselines and cached analysis results are retained separately and are not automatically deleted with source files. See the privacy policy for retention, provider processing and deletion requests.

[Service](https://earlygoose.com) | [Terms](https://earlygoose.com/terms) | [Privacy policy](https://earlygoose.com/privacy)

[Anthropic commercial terms](https://www.anthropic.com/legal/commercial-terms) | [Anthropic privacy policy](https://www.anthropic.com/legal/privacy) | [Supabase privacy policy](https://supabase.com/privacy) | [Resend privacy policy](https://resend.com/legal/privacy-policy) | [Postmark privacy policy](https://postmarkapp.com/privacy-policy)

**Disconnecting, uninstalling and billing**

Disconnecting stops Monitoring and returns the plugin to standalone scanning. If paid access ends, the plugin returns to standalone scanning after receiving the updated status. Resuming Monitoring may require restoring the subscription and reconnecting the site.

Disconnecting or deleting the plugin does not cancel a subscription or delete data held by the service. Manage billing in the app or through Paddle. Use the app's site/account controls or contact EarlyGoose to request cloud-data deletion. See the [privacy policy](https://earlygoose.com/privacy) and [cancellation terms](https://earlygoose.com/terms#cancellation). Service subscription terms do not restrict your GPL rights in the plugin.

== Changelog ==

= 1.0.0 =
* Initial release with on-demand scanning, report sharing, and optional Monitoring.
