Skip to content

Releases: bfrye26/performance-console

Performance Console 3.0.4

Choose a tag to compare

@bfrye26 bfrye26 released this 05 Oct 18:18
7d449cb

A full source audit of Performance Console. No SQL injection, auth bypass or IDOR was found. The defects below are crash, correctness and cost issues.

Existing regression suites pass: 33/33 PHP cases and 7/7 JS cases (5 upstream plus 2 new guards added here). CI is green on PHP 7.4, 8.2, 8.3, 8.4 and Node 22.

Fatal error on hosts without mbstring

19 unguarded mb_substr() calls in the profiler, database health, admin and CLI raised a fatal error the moment they truncated SQL, a file path or an error message. mbstring is optional and is not installed everywhere; CI only ever installed it, which is why this was never caught. All call sites now route through PFC_Utils::truncate(), which falls back to substr().

If you run sites without the mbstring extension, this release fixes a crash that could take down the admin page and CLI.

Halved finding write load

PFC_Utils::issue() did a SELECT and then an INSERT or UPDATE per finding. It is now one INSERT ... ON DUPLICATE KEY UPDATE: a 200-finding scan issues 200 statements instead of 400, and two concurrent requests can no longer both decide a finding is new. The upsert confirms the issue_key UNIQUE index first and falls back to the original read-then-write when it is absent, so occurrence counts cannot silently stop accumulating.

RUM no longer costs every visitor 12 KB

The sampling decision ran in rum.js, so the 8.8 KB web-vitals bundle plus rum.js were enqueued for every anonymous page view while roughly 99.5% of visitors returned immediately. It also multiplied two independent gates (the server sample rate and a client-side roll), so the configured RUM rate was never the rate actually delivered.

The decision now happens server-side with a marker cookie so it survives a page-cache hit, plus pfc_rum_sampled and pfc_rum_rate filters. rum.js honours doNotTrack and Global Privacy Control before collecting anything, retries a rejected beacon once, refreshes the token before expiry, and reports the largest observed value per metric rather than the last.

After upgrading, purge your page cache so visitors receive the new script wiring.

Correctness fixes

  • MariaDB: $wpdb->db_version() returns 5.5.5 on MariaDB because the raw server string is 5.5.5-10.4.28-MariaDB. Comparing that against MariaDB thresholds is always false, so online InnoDB index and table rebuild was permanently unavailable on MariaDB 10.x while the report blamed an "old or unrecognized" server. This is the most consequential fix in the release.
  • Auto-increment exhaustion could only ever fire for one column type: a 1e9 pre-gate ran before the per-type maximum was known, making the tinyint, smallint, mediumint and even bigint branches unreachable. Narrow keys that actually overflow — the ones that stop inserts — are now reported.
  • Frontend stylesheet inventory missed every stylesheet emitted by WordPress core because the regex required href before rel. Bare (unquoted) width, height and loading attributes are now accepted too.
  • RUM percentile: metric_percentile() returned the 600000 ms ingest clamp for the final histogram bucket, so every sample above 10 seconds was reported as exactly ten minutes.
  • Retention: the autoload sample ledger and the change log were the only two stores with no bound; both are now pruned.
  • WP-CLI: --keep-index was never mapped, which made drop_duplicate_index unreachable from the command line even though the admin plan tells large-table operators to use it. Failed repairs also exited 0 with a green "Success" line; they now exit non-zero.
  • REST: ?deep=false started a deep scan, and a missing autoload parameter silently disabled autoload.
  • Jobs: unescaped _ in SHOW TABLES LIKE, and a failed Action Scheduler count was coerced to 0 and reported as a healthy empty queue.
  • Admin UI: a failed backup left the button disabled with no way to retry, and a proxy or WAF error page produced Unexpected token '<' instead of an actionable message.
  • RUM ingest: the signed payload is validated before the rate limit is charged, so a crawler behind a shared NAT address can no longer exhaust the budget real visitors need.

Known remaining items

The backup path has data-integrity risks, and the repair engine has safety-gate gaps, that need a live MySQL/MariaDB to validate safely. They are documented in full in the README rather than silently changed. The most serious is silent column omission in insertable_columns(), which can export a table with zero rows while still certifying the dump as verified.

The plugin also remains diagnostic-only: no object cache, page cache, asset optimisation, Heartbeat or revision control. That is a scope decision rather than an oversight, and is recorded as such.

Install

Download performance-console-3.0.4.zip below and upload it, or replace an existing install. Existing data, settings, diagnostic history and backups are preserved.

SHA-256: CD2475CEBA4A8366C6AD965A603099F76B54A3F4AD6EEFEA6ABDAF683E3A37AB

Performance Console 3.0.0

Choose a tag to compare

@bfrye26 bfrye26 released this 04 Oct 17:06

Renamed to Performance Console

WP Performance Inspector is now Performance Console (performance-console). The plugin has never been published on WordPress.org, so this release also changes the text domain and all code prefixes from wpi_/WPI_ to pfc_/PFC_.

  • Existing installs upgrade in place: on activation the plugin renames its seven tables, options, transients, maintenance cron event and MU bootstrap from wpi_* to pfc_*. Nothing is deleted. Diagnostic history is preserved, and pre-rename backup files remain downloadable and verifiable.
  • The old admin.php?page=wpi admin links redirect to the new page=pfc screens, including view and section deep links.
  • The WP-CLI command remains wp performance; command syntax is unchanged.
  • The REST namespace is now pfc/v1, signed-diagnostic request parameters use pfc_*, the save-capture cookie is pfc_capture_save, and diagnostic response headers are X-PFC-*. Purge page caches after deploying so cached pages pick up the new RUM script.

Verification

  • All 33 PHP regression tests pass, including the new legacy migration map, MU bootstrap cleanup, uninstall coverage and legacy backup acceptance tests.
  • All 5 RUM JavaScript tests pass; the committed web-vitals bundle matches a fresh build.
  • PHP lint passes for every plugin file, including uninstall.php.
  • CI: Regression tests passed on main for this release.

performance-console-3.0.0.zip is a runtime-only archive; its SHA-256 is 4D3BD8586D5B71101F88DA511C4F37B276B0F51739FB0A7B8B2BC59537B88BE8.

WP Performance Inspector 2.2.1

Choose a tag to compare

@bfrye26 bfrye26 released this 30 Sep 13:48

Responsive and lifecycle fixes

Patch release fixing the admin horizontal scrollbar and the audit's highest-value lifecycle items.

  • Fixed the 20px horizontal overflow on every admin screen: the full-bleed background keeps its left bleed without extending past the viewport on the right.
  • Uninstalling now removes all plugin data and files: the seven custom tables, wpi_* options and transients, the maintenance cron event, the generated MU bootstrap, and plugin-created backups.
  • Removed two unconditional database reads from normal requests: the MU sampler loads wpi_secret only for signed diagnostics or save captures, and wpi_db_version is autoloaded for existing sites on upgrade.
  • MU bootstrap installation is now atomic (staging file plus rename), so an interrupted write cannot leave a truncated file in mu-plugins.
  • REST autoload changes now share the Repair Centre's protected-option list; blogname, admin_email, roles and widget options can no longer be toggled through REST only.

Verification

  • All 28 PHP regression tests pass, including new tests for lazy secret loading, shared autoload protection, atomic install, and uninstall coverage.
  • All 5 RUM JavaScript tests pass; the committed web-vitals bundle matches a fresh build.
  • PHP lint passes for every plugin file, including uninstall.php.
  • Horizontal overflow measured at 0px (was 20px) in a headless browser at desktop and mobile widths.

WP Performance Inspector 2.2.0

Choose a tag to compare

@bfrye26 bfrye26 released this 30 Sep 13:33

Measurement and verification foundation

This release makes incident resolution and recommendations evidence-driven rather than assumed.

  • Rechecks no longer resolve incidents when scans skip checks, probes fail, or a matching successful save has not been demonstrated.
  • Uses one sampling decision per request and disables leftover MU tracing when the regular plugin is inactive.
  • Early bootstrap and the profiler share the tested save-request matcher, which records write and response outcomes.
  • Bundles web-vitals 6.2.1 locally, separates metric generations, and labels the RUM reporting window and bucket estimates.
  • Adds optional content assertions to plugin impact tests, sampling coverage gates to autoload reviews, and clearer evidence and measurement limits.
  • Detects same-size backup modifications before repair authorization and distinguishes integrity checks from restore testing.
  • Avoids treating future scheduled jobs or missing persistent caching as proven performance faults.
  • Adds PHP and JavaScript regression tests with a PHP 7.4-8.4 CI matrix.

Verification

  • PHP lint passed for every plugin PHP file.
  • All 24 PHP tests pass.
  • All 5 RUM JavaScript tests pass.
  • The committed web-vitals bundle matches a fresh build.

WP Performance Inspector 2.1.1

Choose a tag to compare

@bfrye26 bfrye26 released this 04 Sep 13:33

Slow Save Profiler workflow polish

This patch release completes the save-capture interface introduced in 2.1.0.

  • Replaces the detached select and placeholder-like instruction cards with explicit manual-save and autosave controls.
  • Adds clear ready and armed states with task-specific guidance and an accessible three-step sequence.
  • Improves desktop and responsive layout, keyboard focus, supporting-text contrast, and content-safety messaging.
  • Preserves the one-request capture behavior and all existing profiling safeguards.

Verification

  • PHP lint passed for every plugin PHP file.
  • All 11 automated tests pass.
  • Ready, armed, and cancelled states were verified in the local WordPress admin UI.
  • The UI quality detector reports no issues.

WP Performance Inspector 2.1.0

Choose a tag to compare

@bfrye26 bfrye26 released this 04 Sep 13:25

WP Performance Inspector 2.1.0

This release adds a production-safe workflow for finding the causes of slow WordPress saves.

What changed

  • Arm a one-time capture for the next manual content save or autosave from Performance → Profiling.
  • Detect classic editor, block editor REST, Quick Edit, WooCommerce product, and custom-post-type saves.
  • Rank directly measured database and outbound HTTP work by plugin, theme, or WordPress core component.
  • Time save-specific hooks and show registered component suspects without overstating callback-level attribution.
  • Turn slow captures into incidents, and make Recheck now arm another real save instead of running a misleading read-only route probe.
  • Protect captures with a signed, HttpOnly, SameSite=Lax cookie that expires after ten minutes and disarms after one matching request.
  • Store safe request identifiers only—never post titles, content, custom-field values, or request bodies.

Safety and measurement notes

The profiler observes the administrator's real write once. It never replays a save or disables a plugin during a write. Diagnostic tracing adds overhead, so use the report to rank causes; use ordinary saves before and after a change to judge the clean user-facing improvement.

Verification

  • PHP lint passed for the plugin, MU bootstrap, and all included classes.
  • 11 regression tests passed.
  • Browser-tested arm, cancel, and captured-report states on WordPress 7.1.
  • Live local capture persistence, component attribution, hook collection, and synthetic telemetry cleanup verified.

WP Performance Inspector 2.0.1

Choose a tag to compare

@bfrye26 bfrye26 released this 04 Sep 12:58

WP Performance Inspector 2.0.1

This patch makes the Private Plugin Impact Test trustworthy under noisy local or production conditions.

  • Uses WordPress' saved server-side PHP duration instead of total loopback HTTP duration.
  • Correlates every request and database row with a signed probe UUID.
  • Verifies that the requested plugin exclusion reached WordPress before accepting a measurement.
  • Computes impact from five paired A/B deltas instead of subtracting two independent medians.
  • Reports the individual pair deltas, median absolute deviation, noise floor and repeatability verdict.
  • Labels recent request samples as all plugins or without plugin/file.php.

On the CGM test site, WooCommerce produced a repeatable positive PHP cost while CGM Scheduled Revisions correctly returned no repeatable cost. The previous profiler could misleadingly assign similar whole-request timing swings to both plugins.

WP Performance Inspector 2.0.0

Choose a tag to compare

@bfrye26 bfrye26 released this 04 Sep 04:25

WP Performance Inspector 2.0.0 turns raw diagnostic findings into a practical performance-incident workflow.

Highlights

  • Groups repeated evidence into incidents with confidence, occurrence counts, affected routes, and lifecycle history.
  • Adds one-click verify, recheck, snooze, resolve, reopen, and accepted-risk controls.
  • Preserves the clicked incident action while its form enters the busy state, fixing the Recheck now submission.
  • Adds signed route profiling and warm-up, alternating five-pair plugin impact experiments.
  • Adds route-aware p75 real-user monitoring with client-side sampling, rate limiting, and single-use tokens.
  • Adds representative route suites and configurable deep-scan URLs.
  • Removes idle database-daemon and expected diagnostic-probe false positives.
  • Loads diagnostic modules and dashboard data only when required.
  • Improves responsive behavior, keyboard focus, control sizing, and navigation semantics.
  • Fixes MariaDB-compatible primary-key discovery in resumable database backups.

Verification

  • PHP syntax validation passed for every plugin PHP file.
  • JavaScript syntax validation passed for all plugin scripts.
  • Six standalone regression tests passed.
  • Desktop and mobile WordPress admin workflows were exercised on a local test site.
  • Safe scan, signed five-run profiling, plugin A/B measurement, and RUM ingestion were verified.

Install wp-performance-inspector-2.0.0.zip through WordPress or extract it as wp-performance-inspector under wp-content/plugins.