{"id":367603,"date":"2026-09-16T18:13:48","date_gmt":"2026-09-16T18:13:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/stackfirefly\/"},"modified":"2026-09-16T18:13:20","modified_gmt":"2026-09-16T18:13:20","slug":"stackfirefly","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/stackfirefly\/","author":23564551,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.24.9","stable_tag":"0.24.9","tested":"7.1","requires":"6.5","requires_php":"7.4","requires_plugins":null,"header_name":"StackFirefly","header_author":"StackFirefly","header_description":"Connects WordPress to StackFirefly for minimized, deterministic reliability monitoring.","assets_banners_color":"","last_updated":"2026-09-16 18:13:20","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/stackfirefly.com","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":43,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.24.9":{"tag":"0.24.9","author":"stackfirefly","date":"2026-09-16 18:13:20","revision":3699103}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3699103,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3699103,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.24.9"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[2679,5603,247,600,286],"plugin_category":[45,54,59],"plugin_contributors":[281118],"plugin_business_model":[],"class_list":["post-367603","plugin","type-plugin","status-publish","hentry","plugin_tags-debugging","plugin_tags-monitoring","plugin_tags-performance","plugin_tags-security","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_category-security-and-spam-protection","plugin_category-utilities-and-tools","plugin_contributors-stackfirefly","plugin_committers-stackfirefly"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/stackfirefly\/assets\/icon-128x128.png?rev=3699103","icon_2x":"https:\/\/ps.w.org\/stackfirefly\/assets\/icon-256x256.png?rev=3699103","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p><strong>Find WordPress problems that uptime monitoring misses.<\/strong><\/p>\n\n<p>Firefly Agent connects WordPress to the StackFirefly monitoring service. A website can be online while scheduled tasks, email delivery or background requests are failing. StackFirefly brings those observations together so you can investigate issues and track recovery.<\/p>\n\n<p><strong>A StackFirefly account and connection to the external service are required.<\/strong> Service availability and allowances depend on your account plan. Review current plans at https:\/\/stackfirefly.com\/pricing before connecting. This plugin is the local connector; monitoring history, incident correlation and AI-assisted diagnosis run in the hosted service.<\/p>\n\n<h4>Monitoring<\/h4>\n\n<ul>\n<li>PHP and browser JavaScript errors, with sanitized diagnostic details and traces where available.<\/li>\n<li>WP-Cron execution, WooCommerce Action Scheduler jobs, and REST\/AJAX connectivity.<\/li>\n<li>User-requested email tests and configured monitoring email tests.<\/li>\n<li>Component inventories for server-side checks against known plugin\/theme vulnerabilities.<\/li>\n<li>Bounded WordPress core\/uploads file scans and privacy-minimized configuration change summaries.<\/li>\n<li>Security-header checks and Lighthouse\/PageSpeed performance history provided by the hosted service.<\/li>\n<\/ul>\n\n<p>AI-assisted suggestions use collected evidence; they are not proof of a cause or recovery. This plugin does not automatically repair your site, edit configuration files or update other plugins. Available evidence varies by error, connection and site configuration.<\/p>\n\n<p>WordPress Multisite is supported through network activation. Pair the main website, then choose which subsites to monitor in StackFirefly. Initial discovery supports up to 100 websites. Selected websites use individual site allowances; shared core\/configuration findings appear on the main website.<\/p>\n\n<h4>From an error to a next step<\/h4>\n\n<p>Repeated reports are grouped into issues so you can review available evidence, follow recent changes, and record your investigation. Acknowledgements, reported fixes and verified recovery stay distinct. Deterministic checks establish recovery; an AI suggestion does not mark a problem as fixed.<\/p>\n\n<h4>Connect your AI assistant with MCP<\/h4>\n\n<p>Connect StackFirefly to ChatGPT, Claude, Codex or another compatible remote MCP client. Your assistant can review selected sites' issues, available evidence, recent changes and Lighthouse results without copying reports between tools.<\/p>\n\n<p>Choose the workspace, sites and permissions. Connections are read-only by default. Optional permissions allow issue acknowledgements, reported-fix notes and verification requests, not changes to WordPress. Revoke access in StackFirefly at any time; newly added sites are not shared automatically.<\/p>\n\n<p>This optional hosted-service feature requires manual setup and an AI account that supports remote MCP connections. It is separate from StackFirefly's built-in AI diagnosis. Setup guide: https:\/\/stackfirefly.com\/docs#ai-connections<\/p>\n\n<h4>External services and data<\/h4>\n\n<p><strong>StackFirefly<\/strong> \u2014 https:\/\/stackfirefly.com<\/p>\n\n<p>Pairing explicitly connects the site to StackFirefly over HTTPS. Before pairing, the plugin does not upload monitoring telemetry. Clicking the account\/setup link passes the site's home URL, WordPress installation URL and display name to StackFirefly to prefill setup. Paired sites send authenticated heartbeats (normally every five minutes) and bounded batches of observations; inventory is sent periodically or when changes are detected. Retries are bounded. Reliable scheduled delivery requires working WordPress cron or a host-managed cron runner.<\/p>\n\n<p>Data may include site URLs and name, Agent\/platform versions, PHP and web-server information, installed component names\/slugs\/versions and update state, status codes and timings, scheduler counts\/ages, sanitized error messages, relative file\/asset paths and line numbers, bounded stack frames, safe public page paths, third-party resource hostnames, file fingerprints and recognized configuration-setting change categories. Browser collection is served locally, is rate-limited and does not create visitor tracking identifiers. Requested PHP traces are bounded and omit function arguments.<\/p>\n\n<p>Passwords, API secrets, cookies, authorization headers, form contents, order\/customer records, raw request bodies and complete response bodies are not intentionally collected. File contents and private configuration values stay on the site. Diagnostic sanitization limits the detail available; not every error includes a trace or page location.<\/p>\n\n<p>StackFirefly uses this data for monitoring, issue history, notifications and requested diagnosis. Its external probes request configured public pages. Performance tests, when requested or scheduled in the service, submit the public test URL to Google PageSpeed Insights. The plugin itself does not call Google PageSpeed Insights. AI-provider processing is described in the service privacy notice. If you authorize an external AI client through MCP, the selected monitoring context is shared with that client under your chosen permissions and the AI provider's own terms and privacy settings. MCP tools do not return Agent credentials or pairing keys; the plugin does not connect to those AI clients directly.<\/p>\n\n<ul>\n<li>StackFirefly terms: https:\/\/stackfirefly.com\/terms<\/li>\n<li>StackFirefly privacy: https:\/\/stackfirefly.com\/privacy<\/li>\n<li>Google terms: https:\/\/policies.google.com\/terms<\/li>\n<li>Google privacy: https:\/\/policies.google.com\/privacy<\/li>\n<\/ul>\n\n<p><strong>WordPress.org checksum service<\/strong> \u2014 https:\/\/api.wordpress.org\/core\/checksums\/1.0\/<\/p>\n\n<p>After pairing, WordPress's checksum API may be used during scheduled core integrity checks. WordPress version and locale are sent to retrieve reference checksums. WordPress.org receives the requesting server's connection metadata. No local file contents are sent to that service.<\/p>\n\n<ul>\n<li>WordPress.org privacy: https:\/\/wordpress.org\/about\/privacy\/<\/li>\n<li>WordPress.org terms: https:\/\/wordpress.org\/about\/terms-of-service\/<\/li>\n<\/ul>\n\n<h4>Updates<\/h4>\n\n<p>The WordPress.org package uses native WordPress plugin updates. Earlier direct-download packages use StackFirefly's signed release channel. Both use the same plugin folder and saved connection settings. Do not delete\/uninstall the old plugin to migrate; use WordPress's upload-and-replace flow using the directory package. See the FAQ.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate Firefly Agent. For Multisite, network-activate it.<\/li>\n<li>Open Settings \u2192 StackFirefly (Network Admin \u2192 Settings for Multisite).<\/li>\n<li>Click \"Connect to StackFirefly\" and keep the WordPress tab open.<\/li>\n<li>Sign in or create an account, verify your email, and approve the displayed website. Choose a workspace if prompted.<\/li>\n<li>Return to the WordPress tab. It connects automatically and shows an Open dashboard link.<\/li>\n<\/ol>\n\n<p>If you start in StackFirefly, save your website first, then follow the installation steps above. Your existing unpaired site is reused. Older installations can use \"Connect another way (pairing key)\". Connection requests expire after 30 minutes; start again if needed.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20work%20without%20a%20stackfirefly%20account%3F\"><h3>Does this work without a StackFirefly account?<\/h3><\/dt>\n<dd><p>No. Firefly Agent is a connector for the hosted monitoring service. Account plans and current allowances are listed at https:\/\/stackfirefly.com\/pricing.<\/p><\/dd>\n<dt id=\"is%20woocommerce%20required%3F\"><h3>Is WooCommerce required?<\/h3><\/dt>\n<dd><p>No. General WordPress checks work without WooCommerce. WooCommerce-specific observations require supported WooCommerce APIs.<\/p><\/dd>\n<dt id=\"does%20activation%20alone%20send%20site%20data%3F\"><h3>Does activation alone send site data?<\/h3><\/dt>\n<dd><p>No monitoring telemetry is uploaded until pairing. Opening the account\/setup link shares the website details shown in the plugin to prefill registration. Review them before continuing.<\/p><\/dd>\n<dt id=\"can%20i%20move%20from%20the%20direct-download%20plugin%20without%20reconnecting%3F\"><h3>Can I move from the direct-download plugin without reconnecting?<\/h3><\/dt>\n<dd><p>The directory package keeps stackfirefly\/stackfirefly.php and the existing settings, credentials and local queue. Upload the WordPress.org ZIP and choose to replace the installed version. Do not delete the plugin first: uninstall removes local connection data. Native WordPress updates apply after replacement. App-triggered updates from the private release channel are not available in the directory package.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20deactivate%20or%20uninstall%3F\"><h3>What happens if I deactivate or uninstall?<\/h3><\/dt>\n<dd><p>Deactivation stops the plugin's monitoring hooks and scheduled cycle while retaining local connection data for reactivation. Uninstall removes the local Agent connection and queue; it does not delete your StackFirefly account or hosted history. Manage or remove the site in StackFirefly separately.<\/p><\/dd>\n<dt id=\"where%20do%20i%20get%20help%3F\"><h3>Where do I get help?<\/h3><\/dt>\n<dd><p>Visit https:\/\/stackfirefly.com\/docs for setup guidance or https:\/\/stackfirefly.com\/contact for support. Do not post pairing tokens, credentials or unsanitized logs in public support threads.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.24.9<\/h4>\n\n<ul>\n<li>Configure smaller local file-scan batches and daily scanning windows from StackFirefly. Requires the matching app deployment and this Agent update.<\/li>\n<li>Preserve scan progress and respect selected hours for manual\/automatic rechecks. Short windows can delay findings and recovery verification; other monitoring continues.<\/li>\n<\/ul>\n\n<h4>0.24.8<\/h4>\n\n<ul>\n<li>Report bounded PHP statement edits with line ranges while keeping code, custom names and secrets local.<\/li>\n<li>Show approved literal memory limits and environment type. Requires the matching app update and two observed file versions; older details cannot be reconstructed.<\/li>\n<\/ul>\n\n<h4>0.24.7<\/h4>\n\n<ul>\n<li>Make pairing-key setup more visible and automatically show errors after a failed pairing attempt.<\/li>\n<li>Show a clear connection notice on the Plugins screen while unpaired and add a Settings action link.<\/li>\n<\/ul>\n\n<h4>0.24.6<\/h4>\n\n<ul>\n<li>Show actionable missing-encryption\/storage notices and guard unsupported runtimes.<\/li>\n<li>Enqueue connection scripts only on the Agent settings page.<\/li>\n<li>Avoid cache-provider calls during activation and before connection.<\/li>\n<\/ul>\n\n<h4>0.24.5<\/h4>\n\n<ul>\n<li>Allow quiet per-site multisite activation with a network-activation notice.<\/li>\n<li>Enforce browser request limits atomically and use WordPress file deletion helpers.<\/li>\n<\/ul>\n\n<h4>0.24.4<\/h4>\n\n<ul>\n<li>Approve connections from WordPress without copying a key. Manual pairing remains available. Keep the WordPress tab open until connected.<\/li>\n<\/ul>\n\n<h4>0.24.3<\/h4>\n\n<ul>\n<li>Simplify setup to a pairing key. The StackFirefly service address is automatic and cannot be changed in the setup form.<\/li>\n<\/ul>\n\n<h4>0.24.2<\/h4>\n\n<ul>\n<li>Store database-error buffers encrypted in the runtime uploads directory, isolated per site. Single-site buffers migrate; old unscoped multisite buffers are retired.<\/li>\n<\/ul>\n\n<h4>0.24.1<\/h4>\n\n<ul>\n<li>Remove the duplicate optional author URL from plugin metadata for WordPress.org submission.<\/li>\n<\/ul>\n\n<h4>0.24.0<\/h4>\n\n<ul>\n<li>Guided account setup remembers website details through registration and workspace creation.<\/li>\n<\/ul>\n\n<h4>0.23.3<\/h4>\n\n<ul>\n<li>Exclude identifiable browser-extension failures and extension frames from new JavaScript reports. Website and third-party script errors remain monitored.<\/li>\n<li>Update the Agent to apply filtering; existing reports are unchanged.<\/li>\n<\/ul>\n\n<h4>0.23.2<\/h4>\n\n<ul>\n<li>Identify individual known wp-config constants and .htaccess directives that changed, including first declaration line numbers. Values and rule contents remain private.<\/li>\n<li>Finer comparisons start after this Agent observes both file versions; old reports cannot recover missing details.<\/li>\n<\/ul>\n\n<h4>0.23.1<\/h4>\n\n<ul>\n<li>Expand wp-config.php and .htaccess change summaries with safe setting and directive categories; private values and category hashes stay on the site.<\/li>\n<li>Allow requested PHP traces to wait up to 24 hours for one matching error, with capability negotiation for older Agents.<\/li>\n<\/ul>\n\n<h4>0.19.2<\/h4>\n\n<ul>\n<li>Adds content-free configuration change summaries for recognized settings and rule groups. Requires a backend accepting the optional configuration review fields.<\/li>\n<\/ul>\n\n<h4>0.19.1<\/h4>\n\n<ul>\n<li>Schedules a fresh bounded core integrity scan immediately after a completed WordPress core update.<\/li>\n<li>Leaves failed or non-core updater operations on the normal daily schedule.<\/li>\n<\/ul>\n\n<h4>0.19.0<\/h4>\n\n<ul>\n<li>Enumerates unexpected PHP-like files only inside the WordPress-owned wp-admin and wp-includes directories.<\/li>\n<li>Reports at most 50 safe core-relative identifiers with MD5 hashes and coarse metadata; never file contents or absolute paths.<\/li>\n<li>Keeps directory traversal resumable, bounded to two seconds and 10,000 entries, and reports incomplete work as unknown.<\/li>\n<\/ul>\n\n<h4>0.18.0<\/h4>\n\n<ul>\n<li>Adds privacy-minimized configuration security observations for wp-config.php, .htaccess, debug display, registration privileges, file editing, and update restrictions.<\/li>\n<li>Confirms file fingerprint changes in a second background cycle before server-side review or alert decisions.<\/li>\n<\/ul>\n\n<h4>0.17.0<\/h4>\n\n<ul>\n<li>Classify only strict, small directory-listing <code>index.php<\/code> placeholders locally without transmitting file contents.<\/li>\n<li>Keep server-side security decisions separate from the Agent's minimized content profile.<\/li>\n<\/ul>\n\n<h4>0.16.0<\/h4>\n\n<ul>\n<li>Adds a signed, bounded manual integrity rescan command.<\/li>\n<\/ul>\n\n<h4>0.15.0<\/h4>\n\n<ul>\n<li>Report up to 50 validated paths relative to <code>wp-content\/uploads<\/code> for detected PHP-like files.<\/li>\n<li>Continue excluding absolute server paths and file contents.<\/li>\n<li>Schedule a fresh uploads scan after upgrade so relative-path evidence does not wait for the next daily scan.<\/li>\n<\/ul>\n\n<h4>0.14.0<\/h4>\n\n<ul>\n<li>Resume bounded WordPress core and uploads scans across background cycles until their fixed scopes are complete.<\/li>\n<li>Report safe slice and cumulative progress without sending filenames, file contents, or absolute paths.<\/li>\n<\/ul>\n\n<h4>0.13.1<\/h4>\n\n<ul>\n<li>Recognize WordPress.org plugins when the core no-update record omits its optional ID.<\/li>\n<li>Classify explicit third-party update URIs without exposing the URI.<\/li>\n<\/ul>\n\n<h4>0.13.0<\/h4>\n\n<ul>\n<li>Add daily, read-only WordPress core checksum and uploads executable-file observations.<\/li>\n<li>Limit filesystem work to two seconds and 10,000 entries and report incomplete scans as unknown.<\/li>\n<li>Send only bounded relative core identifiers, site-scoped uploads path fingerprints, hashes, buckets, counts, and completeness; never file contents.<\/li>\n<\/ul>\n\n<h4>0.12.0<\/h4>\n\n<ul>\n<li>Add a bounded daily and change-sensitive WordPress, WooCommerce, plugin, theme, and MU-plugin inventory for centralized vulnerability matching.<\/li>\n<li>Report only safe type, slug, version, active\/update\/auto-update state, theme role, provenance, completeness, locale, and a stable inventory fingerprint.<\/li>\n<li>Keep advisory access, exact affected-range matching, severity, incidents, alerts, and recovery entirely on the StackFirefly server.<\/li>\n<\/ul>\n\n<h4>0.11.0<\/h4>\n\n<ul>\n<li>Add privacy-minimized plugin, theme, WordPress, WooCommerce, PHP, Firefly Agent, permalink, site-URL fingerprint, configuration-fingerprint, and administrator-count change history.<\/li>\n<li>Combine supported WordPress hooks with a bounded hourly inventory comparison so missed lifecycle hooks can be reconstructed without transmitting a complete inventory.<\/li>\n<li>Report only safe slugs, version\/state transitions, aggregate administrator counts, actor classes, and fingerprints; never raw hook arguments, account identities, option values, file contents, or secrets.<\/li>\n<\/ul>\n\n<h4>0.10.0<\/h4>\n\n<ul>\n<li>Keep bounded per-fingerprint PHP, database, and browser occurrence totals locally when daily telemetry budgets are exhausted.<\/li>\n<li>Delay and merge telemetry updates instead of treating transport suppression as lost evidence; report genuine coverage loss separately.<\/li>\n<li>Label PHP trace provenance as occurrence-time, embedded-stack, or shutdown fallback.<\/li>\n<\/ul>\n\n<h4>0.8.0<\/h4>\n\n<ul>\n<li>Aggregate recurring PHP warnings, notices, and deprecations using bounded category-specific thresholds without replacing handlers or enabling debug settings.<\/li>\n<li>Keep recurring evidence privacy-minimized and rate-limited; warnings may degrade a check while notices and deprecations remain advisory.<\/li>\n<\/ul>\n\n<h4>0.7.2<\/h4>\n\n<ul>\n<li>Retain a bounded non-IP third-party resource hostname and sanitized query-free pathname for failed scripts and stylesheets.<\/li>\n<li>Identify safe WordPress core, plugin, theme, and must-use-plugin asset paths for clearer deterministic diagnostics.<\/li>\n<\/ul>\n\n<h4>0.7.1<\/h4>\n\n<ul>\n<li>Load the minimized collector on eligible storefront pages for both signed-in and signed-out visitors, without collecting identity, session, cookie, request-body, or response-body data.<\/li>\n<li>Keep cached pages valid by obtaining the short-lived signed token from a no-store runtime endpoint, and purge supported page caches after activation, upgrade, deactivation, and pairing.<\/li>\n<\/ul>\n\n<h4>0.7.0<\/h4>\n\n<ul>\n<li>Add a lightweight self-hosted collector for minimized public-browser runtime, promise, resource-load, and bounded same-origin request failures.<\/li>\n<li>Exclude privileged administration and authentication surfaces and enforce signed short-lived collection tokens, strict schemas, privacy sanitization, aggregation milestones, and local rate\/telemetry budgets.<\/li>\n<\/ul>\n\n<h4>0.6.0<\/h4>\n\n<ul>\n<li>Capture bounded, locally sanitized PHP fatal and uncaught shutdown evidence for upload during the next healthy Agent cycle.<\/li>\n<li>Enforce per-site PHP error fingerprint and aggregate-event budgets without changing WordPress error handlers or sending during shutdown.<\/li>\n<\/ul>\n\n<h4>0.5.1<\/h4>\n\n<ul>\n<li>Fix signed synthetic email command verification.<\/li>\n<\/ul>","raw_excerpt":"Find WordPress problems uptime monitoring misses: errors, cron, email, security, performance and AI connections.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/367603","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=367603"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/stackfirefly"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=367603"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=367603"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=367603"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=367603"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=367603"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=367603"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}