Skip to content

Releases: biscuitstudios/bs-site-report

v0.1.2

Choose a tag to compare

@github-actions github-actions released this 22 Sep 20:15
  • Security hardening: the updater now pins its download URL to this plugin's
    own GitHub repository. find_zip_asset() used to hand the WordPress upgrader
    whatever browser_download_url the GitHub API returned, and that URL becomes
    code the upgrader installs. Not a reachable bug, because GitHub only ever
    returns repo-hosted asset URLs, but it is the one path where a wrong
    assumption about a response would be arbitrary code. The fallback branch is
    pinned too, because it was a second way in.
  • sslverify is now explicit on the GitHub API call. WordPress defaults it to
    true, so nothing changes today, but a filter on a site could flip it and
    nothing here would notice.

Full Changelog: v0.1.1...v0.1.2

v0.1.1

Choose a tag to compare

@github-actions github-actions released this 22 Sep 18:46
  • Fix: a throwing Independent Analytics no longer kills the whole payload.
    Its bundled database layer opens its own connection rather than going
    through $wpdb, so it can throw where $wpdb would not. Nothing caught it,
    and one vendor being down meant no report at all rather than a report with
    one section marked unavailable. The analytics section now degrades to
    available:false with the reason attached.
  • Fix: the analytics adapter no longer falls back to zeros. An all-zero month
    is indistinguishable from a real quiet month by the time it reaches a
    client's page, and a vendor returning an unreadable shape is a schema
    change rather than a site with no visitors. Both now report unavailable.
  • New: tests/test-analytics.php, 17 assertions against a stubbed vendor that
    throws, returns garbage, returns null and behaves. Added to CI.

Full Changelog: v0.1.0...v0.1.1

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 22 Sep 18:05
  • First build. Logs every plugin, theme and core version change as it happens,
    with the version before and after, into its own table.
  • Two observers on updates, not one. The WordPress upgrader hooks are precise
    and know who did it; a twice-daily version sweep catches anything applied
    over SSH, by WP-CLI, or by the host's own tooling. A twelve hour window drops
    the double when both see the same update.
  • The first sweep records nothing and stores a baseline instead, so activation
    day does not report an install event for every plugin already on the site.
  • Reads Independent Analytics through its three documented PHP functions only,
    never its tables.
  • Counts Gravity Forms entries through GFAPI, last twelve months against the
    prior twelve.
  • Counts accounts by capability rather than by role name, because Biscuit sites
    carry custom roles.
  • Structure scan over the site's own published URLs: heading order, landmarks,
    alt text, structured data, page descriptions. Its user agent says "bot" so
    Independent Analytics ignores it and the scan cannot inflate the site's own
    visitor numbers.
  • Anything not measured is reported as null with a reason, never as zero. A
    zero and an unknown render identically and only one of them is true.
  • Self-updating from GitHub Releases, ported from bs-maintenance.

Full Changelog: https://github.com/biscuitstudios/bs-site-report/commits/v0.1.0