TalktoMonitor – AI-Powered Diagnostics & Troubleshooting

Description

TalktoMonitor connects your WordPress site to the TalkToWP platform for continuous AI-powered health monitoring.

Local security and health scanning run on your own site and need no account at all. Plain-English explanations, AI diagnostics, and the hosted dashboard are produced on the TalkToWP servers and require a free TalkToWP account. See the External services section below for exactly what is sent, when, and under which terms. TalkToWP receives nothing until you save a TalkToWP API key; the WordPress.org checksum API is contacted automatically, with or without a key, to check core file integrity.

Once connected, TalkToWP watches your site around the clock and uses AI to:

  • Detect and explain plugin conflicts, PHP errors, and security threats
  • Monitor performance, uptime, and SSL certificate health
  • Identify SEO spam injections and hidden malicious links
  • Scan for unauthorized admin accounts and changed homepage content
  • Send email alerts when critical issues are found

What data is collected?

The plugin transmits technical metrics — WordPress version, PHP version, active plugins, available updates, database health, server memory usage, error log counts, and security scan results — and, in some cases, small pieces of your site’s content: recent PHP error-log lines, the usernames and registration dates of administrator accounts flagged as unrecognised, and post IDs, titles and short excerpts from database scan findings. Error-log lines can contain server file paths and occasionally values from the request that caused the error. The External services section below lists exactly what is sent.

Features include:

  • Adaptive heartbeat monitoring (3-minute lightweight pulse + daily full snapshot)
  • Security scan: SEO spam, hidden links, suspicious admin accounts, homepage integrity
  • Google PageSpeed Insights integration (via TalkToWP dashboard)
  • Plugin vulnerability detection
  • WP-Cron health monitoring
  • AI Chat: ask questions about your site in plain English
  • Debug log detection, with copyable wp-config.php instructions when it’s off

External services

This plugin is the site-side agent for TalkToWP, a hosted WordPress monitoring
service operated by Beyondt Consultancy & Services Pvt. Ltd. Local security
scanning and site health checks run entirely on your own server and require no
account. Plain-English explanations, AI diagnostics, and the hosted dashboard are
produced on the TalkToWP servers and require a free TalkToWP account.

1. TalkToWP (app.talktowp.com) — required for AI diagnostics and the dashboard

What it is used for: storing and analysing your site’s health data, generating the
AI diagnostics and incidents shown in your TalkToWP dashboard, and sending alerts.

Nothing is transmitted to TalkToWP until you paste a TalkToWP API key on
Settings TalkToWP and save. Removing the key stops all transmission to
TalkToWP. (The plugin’s local security scans still run without a key — see
item 2 below for the one request they make regardless of account status.)

Once a key is saved, the plugin sends:

  • POST https://app.talktowp.com/api/plugin/heartbeat — every 3 minutes via
    WP-Cron. Sends a timestamp, the change in PHP error count, memory usage
    percentage, a hash representing your plugin/theme/core versions, and the HTTP
    status code of your own homepage.
  • POST https://app.talktowp.com/api/plugin/health — once daily via WP-Cron, and
    also when you save your API key, press “Test Connection”, switch themes, or
    update WordPress core. Sends your site URL and the full technical snapshot:
    WordPress and PHP versions, active plugins and themes with their versions,
    available updates, database size and table status, server memory and disk usage,
    error-log line counts and recent error-log lines, WP-Cron status, SSL certificate
    status, and security scan results. The next paragraphs list the parts of that
    snapshot that are more than counts. You can inspect the exact payload before it
    is ever sent using the “Preview Data Sent for Analysis” button on the settings page.
  • POST https://app.talktowp.com/api/plugin/uninstall — once, when you delete the
    plugin. Sends only your site URL, so TalkToWP can close open incidents and mark
    the site as disconnected.

The daily snapshot contains the following in addition to technical metrics:

  • Up to 20 recent PHP error-log lines, each cut to 500 characters, plus fatal-error
    lines that name an active plugin. These lines are sent as they appear in your
    log, so they can contain server file paths and occasionally values from the
    request that caused the error.
  • The usernames and registration dates of administrator accounts the scan flags as
    unrecognised. Administrator email addresses are not sent.
  • For database scan findings in posts: the post ID, the post title, and an excerpt
    of up to 120 characters of the post content. For findings in wp_options: the
    option name and a SHA-256 hash of the matched text, not the value itself.
  • For SEO-spam and hidden-link findings: post IDs and SHA-256 hashes of the
    matched text.

The plugin does not deliberately collect passwords or visitor data, but anything
an error-log line happens to contain is sent with it. The plugin never reads
wp-config.php, .env files, or private keys.

The plugin registers three REST routes under /wp-json/talktowp/v1/:

  • health-data (GET) — returns the same technical snapshot described above. It
    changes nothing.
  • reset-homepage-hash (POST) — fetches your homepage, stores a new fingerprint of
    its text in place of the old one, and clears the recorded “homepage changed”
    time, so the homepage-change check starts again from the current page.
  • push-now (POST) — sends a fresh health snapshot to TalkToWP and, when the
    request asks for it, first runs a new security scan and stores the result.

    health-data and reset-homepage-hash require your API key in an X-API-Key
    request header. push-now requires an HMAC-SHA256 signature derived from your API
    key, with a ±5-minute window and replay protection. The only things these routes
    write are the plugin’s own options in your WordPress database, such as the
    homepage fingerprint and the last scan result. None of them install, update,
    activate or deactivate anything, and none modify plugin, theme, core or any other
    site files.

Service terms: https://app.talktowp.com/terms
Privacy policy: https://app.talktowp.com/privacy

2. WordPress.org checksum API (api.wordpress.org) — automatic, no account required

What it is used for: the core file integrity scan. To tell whether a WordPress
core file has been modified, the plugin fetches the official checksums for your
WordPress version from
https://api.wordpress.org/core/checksums/1.0/?version=&locale=en_US
and compares them against the files on disk locally. This runs as part of the
daily local security scan whether or not a TalkToWP API key is saved.

What is sent and when: your WordPress version number only, at most once per day
(the response is cached in a transient). No site URL, no personal data. This is
the same WordPress.org service that WordPress core itself uses.

WordPress.org privacy policy: https://wordpress.org/about/privacy/

Screenshots

Installation

  1. Download the plugin ZIP from the WordPress.org plugin directory or your TalkToWP account.
  2. In your WordPress admin, go to Plugins > Add New > Upload Plugin and upload the ZIP file.
  3. Click Activate Plugin.
  4. You will be redirected to Settings > TalkToWP automatically.
  5. Log in (or sign up) at app.talktowp.com to get your API key.
  6. In the TalkToWP dashboard, add your site and copy the API key.
  7. Paste the API key into the plugin settings page and click Save Settings.

Monitoring begins immediately after saving.

FAQ

How does monitoring work?

The plugin collects health data on a 3-minute heartbeat and sends a full snapshot once daily. TalkToWP’s AI analyzes the data, detects anomalies, and creates incidents when issues are found.

Where do I find my API key?

Log in to your TalkToWP dashboard, go to Sites, click your site, then open Site Settings. Your API key is listed there.

What data is sent to TalkToWP?

Technical site health data: WordPress and PHP versions, active plugins and themes, available updates, database size, memory usage, error-log line counts, and security scan results. Some of it is more than counts. The daily snapshot includes up to 20 recent PHP error-log lines, each cut to 500 characters, plus fatal-error lines that name an active plugin. Those lines are sent as they appear in your log, so they can contain server file paths and occasionally values from the request that caused the error. Administrator usernames and registration dates are sent for accounts the scan flags as unrecognised; administrator email addresses are not. Database scan findings include post IDs, post titles and an excerpt of up to 120 characters of post content; for findings in wp_options, only the option name and a SHA-256 hash of the matched text are sent, not the value. The plugin does not deliberately collect passwords or visitor data, but anything an error-log line happens to contain is sent with it. Nothing is sent to TalkToWP until you save a TalkToWP API key on the Settings tab. You can preview the exact payload at any time from the Settings tab.

Will this plugin slow down my site?

No. The heartbeat is lightweight and runs on WP-Cron, which fires only when a visitor loads a page (or via a real server-level cron job). There is no frontend performance impact.

Is my data secure?

All communication with TalkToWP uses HTTPS with SSL certificate verification. Your API key is unique to your site and can be regenerated at any time from the TalkToWP dashboard.

Why does using TalkToWP require an account?

It doesn’t, for the local scanning and site health checks on this page — every panel here runs and displays fully without one. An account is only needed for what happens after that: TalkToWP’s servers turn this site’s raw findings into plain-English explanations, AI diagnostics, and the hosted dashboard, which is work this plugin cannot do by itself.

Can TalkToWP change my site?

Not in any way that affects your plugins, themes, WordPress core or files. The plugin registers three REST routes under /wp-json/talktowp/v1/. health-data (GET) returns the technical snapshot the plugin sends to TalkToWP and changes nothing. reset-homepage-hash (POST) fetches your homepage and stores a new fingerprint of its text in place of the old one, so the homepage-change check starts again from the current page. push-now (POST) sends a fresh health snapshot to TalkToWP and, when the request asks for it, first runs a new security scan and stores the result. health-data and reset-homepage-hash require your API key in an X-API-Key request header. push-now requires an HMAC-SHA256 signature derived from your API key, valid for five minutes and accepted only once. The only things these routes write are the plugin’s own options in your WordPress database, such as the homepage fingerprint and the last scan result. None of them install, update, activate or deactivate anything, and none modify plugin, theme, core or any other site files.

How do I disconnect this site from TalkToWP?

Go to the Settings tab, clear the API Key field, and save. That immediately stops all transmission to TalkToWP; local scanning keeps running on this site as before.

Why does the plugin source contain strings like eval(base64_decode( ?

Those are malware signatures — the patterns the security scanner searches
for in your site’s files and database. They are string literals compared
against other files’ contents. The plugin never executes them.

Why does the plugin source contain matches for

Those are SQL LIKE clauses and regular expressions the security scanner uses to detect injected <script> and <style> markup hidden in your post content and database — patterns it searches for, not code it runs. All of the plugin’s own CSS and JavaScript is loaded through WordPress’s wp_enqueue_style() and wp_enqueue_script() functions; there is no inline <style> or <script> tag anywhere in the plugin.

What plans are available?

Paid plans are available for sites and agencies that need more than the free account provides. See app.talktowp.com for current plans.

How do I uninstall the plugin?

Deactivate the plugin, then click Delete. The plugin will automatically notify TalkToWP so open incidents are resolved and the site is marked as disconnected. All plugin options and transients are removed from your database on uninstall.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“TalktoMonitor – AI-Powered Diagnostics & Troubleshooting” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.6.1

  • The local health-data preview now works without a TalkToWP account.
  • The uploads directory is resolved only through wp_upload_dir(), with no hardcoded fallback.
  • The plugin display name is now TalktoMonitor.

1.6.0

  • First release on WordPress.org.
  • All security scans run and display locally, with or without a TalkToWP account. A free account adds plain-English explanations of the findings on the TalkToWP dashboard.
  • The plugin is read-only. It reads your site’s files, database and settings to scan them, and never writes to your plugins, themes, WordPress core or any other site file.
  • Privacy: administrator email addresses are never sent. Database scan findings in wp_options send the option name and a SHA-256 hash of the matched text rather than the value itself.
  • The privacy documentation, the FAQ and the External services section state everything the plugin sends, and describe all three REST routes accurately.
  • TalkToWP appears as a dedicated tab on WordPress Site Health (Tools -> Site Health -> TalkToWP).
  • Debug log detection is read-only, with copyable wp-config.php instructions instead of writing to the file.
  • Includes an uninstall handler that removes every plugin option, transient and scheduled event on deletion.