Repository navigation
Conversation
Plugin Check scans vendor/ and its direct-file-access check does not recognise the namespaced \defined() form. Every src/V4/ file now guards with defined( 'ABSPATH' ); V1 and V2 are untouched. The isolation tests pin the new form. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Consent mode (V4\Insights) now sends only what the consent notice lists: site, WordPress version/memory limit/theme, PHP and database versions, server software, PHP memory limit, the active plugin list and meta. The admin and users blocks, debug mode, execution/upload limits and plugin counts are commercial only; V4\Integration keeps the full payload. Each active plugin entry carries `url` (Plugin URI header, esc_url_raw, '' when absent) in both modes. The notice's "What we collect" list matches the consent payload line for line, and notice `items` now replace the generic "Usage statistics" line instead of following it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
V4 only, changed in place (4.0.0 shipped today, no plugin uses it yet). V1 (
src/*.php) and V2 (src/V2) are byte-identical:git diff main -- src/V2 src/*.phpis empty.Payload
V4\Insights)V4\Integration)event,mode,token,plugin_version,plugin_statussite.url/name/locale/multisite/is_localwp.version/memory_limit/themewp.debug_modeserver.php_version/db_version/server_software/php_memory_limitserver.max_execution_time/upload_max_filesizeplugins.active[](slug,name,version, newurl)plugins.active_count/inactive_countadmin(email, name)userslicensemetaurlis the plugin'sPlugin URIheader throughesc_url_raw(),''when absent.Consent notice
"What we collect" now matches the consent payload line for line:
The generic "Usage statistics specific to {name}" line appears only when the plugin sends
metaand passes nonotice.items. Given items replace it.Plugin Check guard
Every
src/V4/file now guards withdefined( 'ABSPATH' )instead of\defined( 'ABSPATH' ). Plugin Check scansvendor/, and its direct-file-access check doesn't recognise the backslash form. The isolation tests now check for the new form.Server follow-up (not in this PR)
shazzad/plugin-repotrackcurrently cuts eachplugins.activeentry down toslug,nameandversion(docs/v4-api.md). Until the server keepsurl, it drops the value it receives. Every other field is optional on the server, andactive_countfalls back to the number of entries.Tests
composer test(PHP 8.3): 504 tests, 1542 assertions, OK (the 9 risky tests were already risky on main)php:7.4-cli vendor/bin/phpunit: same resulturlpresent in both modes; the notice list equals the consent payload; the meta line with items, without items, and with only invalid items; the optin body sent after Allow is the trimmed payload.🤖 Generated with Claude Code