{"id":351461,"date":"2026-08-17T13:50:19","date_gmt":"2026-08-17T13:50:19","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/api-analyzer-endpoint-diagnostics-tool\/"},"modified":"2026-08-17T13:50:09","modified_gmt":"2026-08-17T13:50:09","slug":"blockrush-api-request-diagnostics","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/blockrush-api-request-diagnostics\/","author":23542755,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.4.8","stable_tag":"1.4.8","tested":"7.0.4","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"Blockrush API Request Diagnostics","header_author":"Blockrush","header_description":"Observe, analyze, and troubleshoot outbound WordPress HTTP API calls without storing usable credentials.","assets_banners_color":"","last_updated":"2026-08-17 13:50:09","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/blockrush.app\/product\/wordpress-plugin-api-analyzer\/","header_author_uri":"https:\/\/blockrush.app\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":43,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.4.8":{"tag":"1.4.8","author":"blockrush","date":"2026-08-17 13:50:09"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3651243,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3651243,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.4.8"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3651243,"resolution":"1","location":"assets","locale":"","width":1600,"height":857},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3651243,"resolution":"2","location":"assets","locale":"","width":1600,"height":857},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3651243,"resolution":"3","location":"assets","locale":"","width":1600,"height":857},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3651243,"resolution":"4","location":"assets","locale":"","width":1600,"height":857},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3651243,"resolution":"5","location":"assets","locale":"","width":1600,"height":857},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3651243,"resolution":"6","location":"assets","locale":"","width":1600,"height":857}},"screenshots":{"1":"Overview analytics with request volume, traffic health, and recent calls grouped by destination.","2":"All outbound calls with successful-call and error filters plus latency and transfer details.","3":"Destination analytics with call totals, latency, error rate, and last-seen activity.","4":"Calls over time with useful periods, summary totals, and chronological activity.","5":"Free capture settings with protected credentials and adjustable retention and body-size controls.","6":"The Export tab showing the optional Pro upgrade for filtered CSV and JSON diagnostics."}},"plugin_section":[],"plugin_tags":[1556,23519,947,5603,286],"plugin_category":[45,54],"plugin_contributors":[276106],"plugin_business_model":[],"class_list":["post-351461","plugin","type-plugin","status-publish","hentry","plugin_tags-api","plugin_tags-diagnostics","plugin_tags-http","plugin_tags-monitoring","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_category-security-and-spam-protection","plugin_contributors-blockrush","plugin_committers-blockrush"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/blockrush-api-request-diagnostics\/assets\/icon-128x128.png?rev=3651243","icon_2x":"https:\/\/ps.w.org\/blockrush-api-request-diagnostics\/assets\/icon-256x256.png?rev=3651243","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/blockrush-api-request-diagnostics\/assets\/screenshot-1.png?rev=3651243","caption":"Overview analytics with request volume, traffic health, and recent calls grouped by destination."},{"src":"https:\/\/ps.w.org\/blockrush-api-request-diagnostics\/assets\/screenshot-2.png?rev=3651243","caption":"All outbound calls with successful-call and error filters plus latency and transfer details."},{"src":"https:\/\/ps.w.org\/blockrush-api-request-diagnostics\/assets\/screenshot-3.png?rev=3651243","caption":"Destination analytics with call totals, latency, error rate, and last-seen activity."},{"src":"https:\/\/ps.w.org\/blockrush-api-request-diagnostics\/assets\/screenshot-4.png?rev=3651243","caption":"Calls over time with useful periods, summary totals, and chronological activity."},{"src":"https:\/\/ps.w.org\/blockrush-api-request-diagnostics\/assets\/screenshot-5.png?rev=3651243","caption":"Free capture settings with protected credentials and adjustable retention and body-size controls."},{"src":"https:\/\/ps.w.org\/blockrush-api-request-diagnostics\/assets\/screenshot-6.png?rev=3651243","caption":"The Export tab showing the optional Pro upgrade for filtered CSV and JSON diagnostics."}],"raw_content":"<!--section=description-->\n<p>Blockrush API Request Diagnostics gives administrators and WooCommerce store managers a fast, private\nview of outbound requests made through the WordPress HTTP API.<\/p>\n\n<h4>Highlights<\/h4>\n\n<ul>\n<li>Groups calls by third-party destination.<\/li>\n<li>Expands destination groups into their individual recent calls.<\/li>\n<li>Tracks request volume, success rate, response time, transfer size, and source.<\/li>\n<li>Filters all calls by success, error, time, HTTP status, destination, URL, and source.<\/li>\n<li>Organizes calls chronologically with last-5-minute, last-hour, today, this-week, date-range, and exact custom periods.<\/li>\n<li>Opens a detailed request\/response inspector.<\/li>\n<li>Produces a copyable, credential-safe cURL command for support and diagnostics.<\/li>\n<li>Fully suppresses recognized credentials before storage so Free never retains usable secrets.<\/li>\n<li>Adjustable local log retention and body-size limits, with conservative defaults of one day and 64 KB.<\/li>\n<li>Responsive, keyboard-accessible UI with no external JavaScript dependencies.<\/li>\n<\/ul>\n\n<h3>Capture scope<\/h3>\n\n<p>Blockrush API Request Diagnostics observes requests made through WordPress HTTP API functions such as\n    wp_remote_get() and <code>wp_remote_post()<\/code>. This includes WordPress core and most\nwell-behaved plugins, including WooCommerce extensions.<\/p>\n\n<p>Calls made directly through raw cURL, sockets, or third-party SDK transports that\nbypass the WordPress HTTP API cannot be observed from a WordPress plugin without\nunsafe system-level interception.<\/p>\n\n<h3>Privacy and security<\/h3>\n\n<p>Recognized API keys, tokens, passwords, authorization headers, client secrets,\nconsumer credentials, signatures, and URL credentials are fully suppressed\nbefore a log is inserted. Blockrush API Request Diagnostics does not\nretain an unmasked copy.<\/p>\n\n<p>Request bodies are captured by default with a 64 KB maximum. Authorized users\ncan adjust that limit in Settings. Response bodies are disabled by default.\nHeaders, status, duration, and byte size remain available when response bodies\nare disabled.<\/p>\n\n<p>Only administrators and WooCommerce users with <code>manage_woocommerce<\/code> can access\nthe dashboard, settings, and call details. All actions use WordPress nonces.\nFiltered CSV and JSON exports are available through API Analyzer Pro.<\/p>\n\n<p>Blockrush API Request Diagnostics stores logs only in the site's own WordPress database. The plugin\ndoes not send logs, telemetry, or personal information to Blockrush or any\nother external service.<\/p>\n\n<p>Because request bodies can contain customer or visitor information chosen by\nother plugins, site owners should review their privacy obligations and retention\nsettings before enabling capture on a production site. Blockrush API Request Diagnostics provides\nsuggested text in WordPress's Privacy Policy Guide.<\/p>\n\n<h3>External services<\/h3>\n\n<p>Blockrush API Request Diagnostics does not contact an external service on its own. It does not send\ndata to Blockrush, load remote assets, collect telemetry, or operate a\nhosted component.<\/p>\n\n<p>The plugin observes outbound WordPress HTTP API calls initiated by WordPress\ncore, themes, and other plugins. The destinations and information sent in those\ncalls are controlled by the software that initiated them, not by Blockrush API Request Diagnostics.\nSite owners should review the terms and privacy policies of those services\nseparately.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>blockrush-api-request-diagnostics<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install its ZIP.<\/li>\n<li>Activate Blockrush API Request Diagnostics in WordPress.<\/li>\n<li>Open <strong>API Analyzer<\/strong> in the WordPress admin menu.<\/li>\n<li>Generate normal store traffic, or use an integration's test-connection action.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"can%20the%20copied%20curl%20command%20be%20run%20as-is%3F\"><h3>Can the copied cURL command be run as-is?<\/h3><\/dt>\n<dd><p>No. Credentials are deliberately suppressed. Replace suppressed values with\nvalid secrets in a secure local environment before replaying the request.<\/p><\/dd>\n<dt id=\"does%20pausing%20capture%20affect%20existing%20logs%3F\"><h3>Does pausing capture affect existing logs?<\/h3><\/dt>\n<dd><p>No. It stops new capture only. Existing logs remain until their retention period\nexpires, an authorized user clears them, or the plugin is deleted.<\/p><\/dd>\n<dt id=\"what%20happens%20on%20uninstall%3F\"><h3>What happens on uninstall?<\/h3><\/dt>\n<dd><p>Deleting the plugin through WordPress removes its custom table, settings, and\nscheduled cleanup event. Deactivation alone retains data.<\/p><\/dd>\n<dt id=\"does%20blockrush%20api%20request%20diagnostics%20contact%20blockrush%3F\"><h3>Does Blockrush API Request Diagnostics contact Blockrush?<\/h3><\/dt>\n<dd><p>No. Blockrush API Request Diagnostics has no hosted service, telemetry, tracking pixel, remote assets,\nor update service outside WordPress.org. It observes calls initiated by WordPress\nand other installed plugins and stores the resulting diagnostic logs locally.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.4.8<\/h4>\n\n<ul>\n<li>Adopt a unique Blockrush-specific prefix for PHP classes, constants, functions, options, database tables, cron events, hooks, AJAX actions, and JavaScript globals.<\/li>\n<\/ul>\n\n<h4>1.4.7<\/h4>\n\n<ul>\n<li>Add an accessible Refresh stats control with progress feedback and an updated-at confirmation.<\/li>\n<\/ul>\n\n<h4>1.4.6<\/h4>\n\n<ul>\n<li>Make log retention and maximum body size adjustable in Free, with defaults of one day and 64 KB.<\/li>\n<li>Remove retention and body-size limits from Pro-only positioning.<\/li>\n<\/ul>\n\n<h4>1.4.5<\/h4>\n\n<ul>\n<li>Rename the public plugin and requested WordPress.org slug to Blockrush API Request Diagnostics.<\/li>\n<li>Keep the established API Analyzer dashboard menu label for existing administrators.<\/li>\n<\/ul>\n\n<h4>1.4.4<\/h4>\n\n<ul>\n<li>Move the export handler, CSV\/JSON streaming, and export database queries entirely into the separate Pro add-on.<\/li>\n<li>Keep Free credential masking permanently fully suppressive; first\/last-three previews now exist only in Pro.<\/li>\n<li>Move ignored-destination processing out of the Free package.<\/li>\n<li>Replace filter-gated paid implementations with complete Pro-owned services and neutral integration contracts.<\/li>\n<\/ul>\n\n<h4>1.4.3<\/h4>\n\n<ul>\n<li>Set conservative initial defaults of one-day log retention and a 64 KB capture-body limit.<\/li>\n<li>Reserve ignored destinations for licensed Pro users.<\/li>\n<li>Enforce edition limits in capture, cleanup, and settings requests\u2014not only in the interface.<\/li>\n<li>Harden nested XML and multipart credential suppression before storage.<\/li>\n<li>Move exports into a dedicated Export tab beside Destinations.<\/li>\n<\/ul>\n\n<h4>1.4.2<\/h4>\n\n<ul>\n<li>Bound recursive, oversized, and unterminated HTTP payload analysis before storage.<\/li>\n<li>Reapply credential redaction after extension filters and cap unmatched request markers in persistent workers.<\/li>\n<\/ul>\n\n<h4>1.4.1<\/h4>\n\n<ul>\n<li>Update public publisher branding to Blockrush.<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>Fully suppress recognized credential values in Free before database storage.<\/li>\n<li>Move identifiable first\/last-three credential previews to API Analyzer Pro.<\/li>\n<li>Move filtered CSV and JSON exports behind an active API Analyzer Pro license.<\/li>\n<li>Expand the Upgrade to Pro panel with accurate credential-preview and export benefits.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Add an Upgrade to Pro tab with a focused feature comparison and an explicit Blockrush purchase link.<\/li>\n<li>Add extension points for the separately installed API Analyzer Pro license.<\/li>\n<li>Remove protected-destination Redact\/Hide logic and rendering from Free; provide it only through the separately installed Pro add-on.<\/li>\n<li>Keep credential safety and all core diagnostics available without a license.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Add neutral extension hooks for separately packaged add-ons.<\/li>\n<li>Limit the complete free edition to 7 or 14-day log retention.<\/li>\n<li>Move advanced Speed Insights to the separately distributed API Analyzer Pro add-on.<\/li>\n<li>Keep credential safety and core capture, analytics, and filtering free.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Add an accessible header switch for instantly starting or pausing capture, with capture enabled by default.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Harden credential redaction for cookies, proxy authorization, XML\/SOAP, multipart forms, error messages, and additional token\/session field names.<\/li>\n<li>Bound stored headers and enforce payload limits at capture and database boundaries.<\/li>\n<li>Add action-specific nonces, CSV formula-injection protection, download hardening, and multisite uninstall cleanup.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release with grouped calls, call-status filters, chronological time analysis, and speed insights.<\/li>\n<\/ul>","raw_excerpt":"Analyze outbound third-party calls made through the WordPress HTTP API.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/351461","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=351461"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/blockrush"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=351461"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=351461"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=351461"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=351461"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=351461"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=351461"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}