=== YourWebsiteCare Monitor ===
Contributors: yourwebsitecare
Tags: monitoring, uptime, broken links, forms, website care
Requires at least: 6.0
Tested up to: 6.9
Requires PHP: 7.4
Stable tag: 0.1.6
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Keep money pages honest: WordPress checks homepage + same-site URLs for status, links, forms, SEO, CTAs. Optional alerts. Not site-wide crawl.

== Description ==

**YourWebsiteCare Monitor** helps owners, marketers, and agencies answer a simple question: *Are our most important pages actually working?* It uses WordPress-native HTTP requests and practical HTML heuristics—no extra dashboards, no visitor or form data collection.

**What it does well**

* Always checks **HTTP status** for your **homepage** and every **Extra page** URL you list (contact, pricing, booking, checkout paths, etc.).
* Optional diagnostics you can turn on or off: **security headers** (HTTPS), **SEO** basics (meta description, canonical), **HTML / content** red flags, **mobile viewport** meta, **builder or diagnostic junk** in output, **forms** (submit control and action URL), **form length / friction** vs. a threshold you set, **navigation** link targets, **internal link spot-checks** (capped per page), **CTA** keyword matching on links and buttons, and **slow response** hints from the server-side fetch.

**What it is not**

This version does **not** use browser automation: it does not execute JavaScript, submit forms, crawl your entire site recursively, or replace Core Web Vitals lab tests. It does not use Python, Playwright, Selenium, or Composer dependencies.

**Scope**

The plugin loads HTML for the homepage and each same-host URL or path you configure (up to your plan’s maximum). When internal link checks are enabled, it requests up to your **internal link cap** of same-site targets found in the HTML of each loaded page, in document order. That cap is **per monitored page**, not “every URL on the site,” and there is no automatic sitemap- or database-driven discovery of all WordPress content.

**Checks include**

* HTTP status for the homepage and each configured extra URL (always on)
* Optional: security headers on HTTPS, SEO meta description and canonical, HTML quality hints, mobile viewport meta, builder/diagnostic leftovers, internal link spot-checks (capped), forms, form friction (field count), navigation href sanity
* Optional: CTA keyword matching for links and buttons (off by default)
* Optional: slow server-side response thresholds (off by default)

Browser-like checks are clearly scoped as lightweight HTTP/HTML heuristics in this MVP. Deeper browser-based checks may be handled later through an external service, which is not included in this release.

== Developer Notes ==

YourWebsiteCare Monitor intentionally stays small and suitable for shared WordPress hosting. Browser-based checks should not run inside WordPress; if added later, they should be handled by a separate external service and surfaced back to WordPress as lightweight diagnostic metadata.

== Installation ==

1. Upload the `yourwebsitecare-monitor` folder to `/wp-content/plugins/`.
2. Activate "YourWebsiteCare Monitor" from the WordPress Plugins screen.
3. Open "YourWebsiteCare" in the WordPress admin menu.
4. Add any important paths or URLs under Extra pages (URLs) if you need more than the homepage, review optional diagnostics, then click "Run check now" for the first check.

== Frequently Asked Questions ==

= Does it crawl my entire WordPress site? =

No. Each run loads the homepage plus only the same-host URLs or paths you list in settings (within the configured maximum). Internal link checks, when enabled, follow up to your configured cap of same-site links from each of those loaded pages, in HTML order. Pages that are never linked early from those entry points, or never listed, are not automatically fetched.

= What does the internal link cap mean? =

It limits how many internal anchor targets the plugin will GET from each monitored page during one run. It is not a promise to validate every URL on the site, and it is not the same as the total number of WordPress pages on the site.

= Does YourWebsiteCare Monitor use real browser automation? =

No. This version uses lightweight HTTP and HTML heuristics only. It does not run JavaScript, hover menus, click buttons, submit forms, use Playwright, or use Selenium.

= Does it request external websites? =

No for checks. Monitored URLs are restricted to the current site host or relative paths. External links are not followed for validation.

= Does it collect visitor data or form submissions? =

No. YourWebsiteCare Monitor stores only diagnostic metadata such as check type, URL, status, HTTP code, message, evidence, check time, and response time. It does not submit forms or store form field values.

= What is included? =

The plugin includes the homepage, up to 5 extra URLs you configure, manual/daily/weekly checks, email alerts, and configurable optional diagnostics. That is not a full-site crawl; add URLs for funnels you care about.

= What should I put in CTA keywords? =

After you enable the CTA links and buttons option under Optional checks, add one lowercase phrase per line. The checker looks for those substrings in link and button text on each page, then validates internal targets.

The plugin ships with a starter list (contact, booking, quotes, demos, sign-up, downloads, and similar). Trim it to phrases that actually appear on your theme (for example start your project if that is your hero button). Avoid very generic single words unless you need them; a shorter, site-specific list is easier to interpret than dozens of synonyms.

= Checks fail on Local WP / localhost with "URL is not safe to request" =

Enable `WP_DEBUG` in `wp-config.php` while developing. The plugin only relaxes host safety checks for the **same** hostname as your site URL (`home_url`), not for arbitrary internal targets.

== Privacy ==

The plugin stores plugin settings and the latest check results in the WordPress database (`wp_options`). Optional email alerts send diagnostic summaries (check type, URL, HTTP code, short message, evidence) to the address configured in settings. No visitor data, form field values, or off-site telemetry are collected. HTTP requests issued by checks target only the same host as the site (`home_url`), except mail transport for notifications uses your server’s configured email path (`wp_mail`).

== Security Notes ==

YourWebsiteCare Monitor is designed for normal shared WordPress hosting and uses WordPress native APIs where possible.

The plugin:

* Prevents direct file access in PHP files.
* Uses `manage_options` for admin actions.
* Uses nonces for manual checks and WordPress Settings API actions.
* Sanitizes settings input.
* Escapes admin output.
* Restricts monitored URLs to the current site host or relative paths.
* Skips external, tel, mailto, javascript, data, file, and ftp links for target checks.
* Avoids requests to localhost and private/local network addresses on production (when `WP_DEBUG` is off). With `WP_DEBUG` enabled, same-host checks are allowed so local `.local` sites and loopback URLs work.
* Does not perform POST requests.
* Does not submit forms.
* Does not execute JavaScript.
* Does not store secrets.

== Changelog ==

= 0.1.6 =

* Removed in-product references to a paid tier; schedule options are manual, daily, or weekly only.

= 0.1.5 =

* Clarified in the admin UI and readme that monitoring uses the homepage plus configured URLs only, and that the internal link cap applies per loaded page (first anchors in HTML order, not a crawl of every WordPress page).

= 0.1.4 =

* Expanded default CTA keyword examples for new installs; readme guidance on choosing keywords.

= 0.1.3 =

* Human-readable check names in the admin results table and email alerts.
* Settings toggles for optional diagnostics with sensible defaults (CTA keyword checks and slow-response rows off by default).
* Removed low-signal DOM heuristics (menu dropdown and dead booking/contact path checks).
* Clearer user-facing messages and readme alignment with current checks.

= 0.1.2 =

* Added security header heuristics on each successful page fetch (HTTPS: HSTS, X-Content-Type-Options nosniff, frame protection).
* Added basic SEO checks: meta description presence/length and canonical link element.

= 0.1.1 =

* Allow same-host monitoring when `WP_DEBUG` is true (local development, `.local` hostnames resolving to private IPs, loopback).

= 0.1.0 =

* Initial MVP release.
* Added homepage and custom URL checks.
* Added lightweight HTTP/HTML heuristics for CTA, forms, navigation, links, markup, plugin garbage, status codes, and server response time.
* Added WP-Cron scheduling, manual checks, and email-only notifications.
