Pingvera

Description

Pingvera is a monitoring service for studios and agencies that maintain many
client websites. Unlike a plain uptime checker, it watches whether the client’s
business actually works — orders arrive, forms deliver, checkout runs — not
just whether the homepage returns 200. So you find out about a problem before the
client calls asking “why did the orders stop?”.

This plugin is the inside connector: it looks at the WordPress/WooCommerce site
from the inside and reports to your dashboard:

  • Commerce (WooCommerce): real-time order.created / order.failed events that feed a unified timeline and a business-anomaly detector (“orders dropped to zero while the site is up”), plus failed-order spikes, payment-gateway and checkout health, and a daily order-pipeline smoke run.
  • Inventory: WordPress core, PHP and database versions, active theme, plugins and their versions.
  • Updates: available core and plugin updates.
  • Security: predictable admin login name, debug mode left on, core file integrity (checksums), a malware scan, and new-administrator detection.
  • Performance: object cache presence, size of autoloaded options.
  • Availability: REST loopback, recent PHP fatal errors (a count only, never the log itself).
  • Configuration: WP-Cron mode and task lag; mail/SMTP.
  • Files: write permissions on wp-config.php.

What the plugin does NOT do: it opens no inbound ports, executes no remote
commands, and never transmits passwords, database contents, or visitor
personal data. All communication is outbound HTTPS to your own dashboard.

External services

This plugin is the connector for Pingvera, an external website-monitoring
service (https://pingvera.com). The plugin exists to send your site’s technical
health to your Pingvera dashboard, so using it requires that service. It talks to
the dashboard you configure — a hosted dashboard such as pingvera.com, or your
own self-hosted/on-prem instance — over outbound HTTPS only.

What is sent and when:

  • Pairing (once, when you click “Connect”): the one-time pairing code and your
    site URL are sent to obtain a scoped access token. Endpoint: /cms/v1/pair.
  • Sync (once an hour via WP-Cron, and on “Sync now”): technical health and
    inventory — WordPress, PHP and database versions; the active theme and the list
    of plugins with their versions; available updates; security, performance and
    configuration findings; WooCommerce order statistics and payment gateway /
    checkout status; and a count of recent PHP fatal errors. Endpoint: /cms/v1/sync.
    Passwords, database contents, post content and visitor personal data are never
    sent.
  • Real User Monitoring (only if enabled for your site in the dashboard): a small
    asynchronous script is loaded on the front end to collect anonymous Core Web
    Vitals (loading and interaction timings) of your own pages. Endpoint: /rum/v1/.
    No personal data is collected.
  • Business events (WooCommerce only, as they happen): when a new order is
    created or an order fails, the order ID, total, currency and status are sent
    so the dashboard can flag unusual patterns in real time. Endpoint: /cms/v1/event.
    No customer names, addresses, emails or payment details are sent.

Service provided by Pingvera:

  • Terms of Service: https://pingvera.com/terms.html
  • Privacy Policy: https://pingvera.com/privacy.html

Screenshots

Installation

  1. In the Pingvera dashboard, open your site and create a CMS installation (WordPress).
  2. Copy the one-time pairing code.
  3. In WordPress admin: Pingvera -> paste your dashboard URL and the code -> “Connect”.

After that the plugin syncs once an hour via WP-Cron. “Sync now” sends data immediately. “Disconnect” forgets the token and dashboard URL.

FAQ

Does the plugin send any personal data?

No. It sends technical health and inventory only. Passwords, database contents,
and visitor personal data are never transmitted.

Can Pingvera control my site remotely?

No. The connector is strictly one-way: it only sends data out over HTTPS. It
opens no inbound ports and executes no commands from the outside.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Pingvera” is open source software. The following people have contributed to this plugin.

Contributors

“Pingvera” has been translated into 1 locale. Thank you to the translators for their contributions.

Translate “Pingvera” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

0.4.9

  • Refreshed the plugin listing to lead with what sets Pingvera apart: WooCommerce
    order/business monitoring — a unified timeline and business-anomaly detection
    (“orders dropped to zero while the site is up”), so you learn about a problem
    before the client does. No code changes.

0.4.8

  • English base language with internationalization (i18n); Russian is now
    provided as a translation.

0.4.7

  • order.created is now sent on woocommerce_checkout_order_processed (order placed
    at checkout, totals already calculated) instead of woocommerce_new_order — the
    event carries the correct order total, and reflects a real customer purchase
    rather than an early draft with a zero total.

0.4.6

  • WooCommerce business events: sends order.created and order.failed events to
    the dashboard as they happen (order ID, total, currency, status only), so
    the unified timeline and business-anomaly detector see spikes and drops in
    real time rather than at the next hourly sync.

0.4.5

  • Malware scan: PHP files inside uploads, known web-shell filenames, and
    obfuscated code in recently modified wp-content files (budget-limited, so a
    large site’s hourly sync stays fast).
  • New-administrator detection: alerts once when an administrator account
    appears that wasn’t there before (a common compromise marker); the first
    run after install only records a baseline and does not alert.
  • Component slugs (core/theme/plugins) for matching against a vulnerability
    database on the dashboard side.

0.4.4

  • Documented the external Pingvera service in the readme: what data is sent, when,
    and links to the Terms of Service and Privacy Policy (directory requirement).

0.4.3

  • Distinct Plugin URI and Author URI in the plugin header (directory requirement).

0.4.2

  • Plugin Check: enqueued RUM script now carries an explicit version for cache
    busting. No functional changes.

0.4.1

  • Compliance with the official WordPress Plugin Check: output escaping,
    WP_Filesystem for file access, enqueued RUM script, and an English readme.
    No functional changes.

0.4.0

  • WooCommerce order monitoring: failed-order spikes against a 7-day baseline,
    order “drought” detection (stays quiet on low-volume stores), payment gateway
    configuration (no active gateway / live gateway left in test mode), and
    checkout page reachability (loopback).
  • Daily smoke run of the order pipeline (a service product and order, created
    without emails, stock changes or payment, then removed immediately).

0.2.0

  • Extended diagnostics: REST loopback, WP-Cron lag, wp-config permissions,
    SMTP/mail, WooCommerce (checkout page), core integrity via checksums (a sign
    of compromise), and a recent PHP fatal-error count.

0.1.0

  • First release: pairing by code, inventory, baseline findings (updates,
    security, performance, configuration), and a management screen.