Description
Pingvera is a monitoring service for studios and agencies that maintain many
client websites. Unlike a plain uptime checker, it watches whether the client’s
business actually works — orders arrive, forms deliver, checkout runs — not
just whether the homepage returns 200. So you find out about a problem before the
client calls asking “why did the orders stop?”.
This plugin is the inside connector: it looks at the WordPress/WooCommerce site
from the inside and reports to your dashboard:
- Commerce (WooCommerce): real-time order.created / order.failed events that feed a unified timeline and a business-anomaly detector (“orders dropped to zero while the site is up”), plus failed-order spikes, payment-gateway and checkout health, and a daily order-pipeline smoke run.
- Inventory: WordPress core, PHP and database versions, active theme, plugins and their versions.
- Updates: available core and plugin updates.
- Security: predictable admin login name, debug mode left on, core file integrity (checksums), a malware scan, and new-administrator detection.
- Performance: object cache presence, size of autoloaded options.
- Availability: REST loopback, recent PHP fatal errors (a count only, never the log itself).
- Configuration: WP-Cron mode and task lag; mail/SMTP.
- Files: write permissions on wp-config.php.
What the plugin does NOT do: it opens no inbound ports, executes no remote
commands, and never transmits passwords, database contents, or visitor
personal data. All communication is outbound HTTPS to your own dashboard.
External services
This plugin is the connector for Pingvera, an external website-monitoring
service (https://pingvera.com). The plugin exists to send your site’s technical
health to your Pingvera dashboard, so using it requires that service. It talks to
the dashboard you configure — a hosted dashboard such as pingvera.com, or your
own self-hosted/on-prem instance — over outbound HTTPS only.
What is sent and when:
- Pairing (once, when you click “Connect”): the one-time pairing code and your
site URL are sent to obtain a scoped access token. Endpoint: /cms/v1/pair. - Sync (once an hour via WP-Cron, and on “Sync now”): technical health and
inventory — WordPress, PHP and database versions; the active theme and the list
of plugins with their versions; available updates; security, performance and
configuration findings; WooCommerce order statistics and payment gateway /
checkout status; and a count of recent PHP fatal errors. Endpoint: /cms/v1/sync.
Passwords, database contents, post content and visitor personal data are never
sent. - Real User Monitoring (only if enabled for your site in the dashboard): a small
asynchronous script is loaded on the front end to collect anonymous Core Web
Vitals (loading and interaction timings) of your own pages. Endpoint: /rum/v1/.
No personal data is collected. - Business events (WooCommerce only, as they happen): when a new order is
created or an order fails, the order ID, total, currency and status are sent
so the dashboard can flag unusual patterns in real time. Endpoint: /cms/v1/event.
No customer names, addresses, emails or payment details are sent.
Service provided by Pingvera:
- Terms of Service: https://pingvera.com/terms.html
- Privacy Policy: https://pingvera.com/privacy.html
Installation
- In the Pingvera dashboard, open your site and create a CMS installation (WordPress).
- Copy the one-time pairing code.
- In WordPress admin: Pingvera -> paste your dashboard URL and the code -> “Connect”.
After that the plugin syncs once an hour via WP-Cron. “Sync now” sends data immediately. “Disconnect” forgets the token and dashboard URL.
FAQ
-
Does the plugin send any personal data?
-
No. It sends technical health and inventory only. Passwords, database contents,
and visitor personal data are never transmitted. -
Can Pingvera control my site remotely?
-
No. The connector is strictly one-way: it only sends data out over HTTPS. It
opens no inbound ports and executes no commands from the outside.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Pingvera” is open source software. The following people have contributed to this plugin.
Contributors“Pingvera” has been translated into 1 locale. Thank you to the translators for their contributions.
Translate “Pingvera” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
0.4.9
- Refreshed the plugin listing to lead with what sets Pingvera apart: WooCommerce
order/business monitoring — a unified timeline and business-anomaly detection
(“orders dropped to zero while the site is up”), so you learn about a problem
before the client does. No code changes.
0.4.8
- English base language with internationalization (i18n); Russian is now
provided as a translation.
0.4.7
- order.created is now sent on woocommerce_checkout_order_processed (order placed
at checkout, totals already calculated) instead of woocommerce_new_order — the
event carries the correct order total, and reflects a real customer purchase
rather than an early draft with a zero total.
0.4.6
- WooCommerce business events: sends order.created and order.failed events to
the dashboard as they happen (order ID, total, currency, status only), so
the unified timeline and business-anomaly detector see spikes and drops in
real time rather than at the next hourly sync.
0.4.5
- Malware scan: PHP files inside uploads, known web-shell filenames, and
obfuscated code in recently modified wp-content files (budget-limited, so a
large site’s hourly sync stays fast). - New-administrator detection: alerts once when an administrator account
appears that wasn’t there before (a common compromise marker); the first
run after install only records a baseline and does not alert. - Component slugs (core/theme/plugins) for matching against a vulnerability
database on the dashboard side.
0.4.4
- Documented the external Pingvera service in the readme: what data is sent, when,
and links to the Terms of Service and Privacy Policy (directory requirement).
0.4.3
- Distinct Plugin URI and Author URI in the plugin header (directory requirement).
0.4.2
- Plugin Check: enqueued RUM script now carries an explicit version for cache
busting. No functional changes.
0.4.1
- Compliance with the official WordPress Plugin Check: output escaping,
WP_Filesystem for file access, enqueued RUM script, and an English readme.
No functional changes.
0.4.0
- WooCommerce order monitoring: failed-order spikes against a 7-day baseline,
order “drought” detection (stays quiet on low-volume stores), payment gateway
configuration (no active gateway / live gateway left in test mode), and
checkout page reachability (loopback). - Daily smoke run of the order pipeline (a service product and order, created
without emails, stock changes or payment, then removed immediately).
0.2.0
- Extended diagnostics: REST loopback, WP-Cron lag, wp-config permissions,
SMTP/mail, WooCommerce (checkout page), core integrity via checksums (a sign
of compromise), and a recent PHP fatal-error count.
0.1.0
- First release: pairing by code, inventory, baseline findings (updates,
security, performance, configuration), and a management screen.


