=== WP Debug Toolkit Pro ===
Contributors: wpdebugtoolkit
Tags: debug, debugging, development, error logging, log viewer, error monitor, debug logs, wp-config, error handling, php errors
Requires at least: 5.6
Tested up to: 6.4
Requires PHP: 7.4
Stable tag: 1.2.3
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Advanced debugging toolkit for WordPress that enhances the development experience with a beautiful log viewer and powerful error management tools.

== Description ==

**WP Debug Toolkit Pro** is an essential monitoring suite for WordPress agencies and developers. It gives you complete visibility into your site's health, database performance, and error logs—even when WordPress is completely broken.

Instead of relying on fragile plugins that crash when your site does, WP Debug Toolkit uses a hybrid architecture (Plugin + Standalone Viewer) to ensure you always have access to critical debug data.

### Key Features

* **Error Log Viewer (Standalone)** - A high-performance log reader that runs independently of WordPress. Debug White Screen of Death (WSOD) issues instantly without FTP/SSH.
* **Query Viewer** - Filesystem-based database monitoring with zero "Observer Effect." Identify slow queries and N+1 patterns without slowing down your site.
* **Email Alerts** - Proactive notifications for critical errors. Includes a dual-channel delivery system (native mail fallback) to ensure you know about crashes before your clients do.
* **Emergency Recovery** - The Standalone Viewer works even if the database is down, allowing you to identify the culprit plugin/theme immediately.
* **Professional Reporting** - White-label email alerts with custom branding for your agency clients.
* **One-Click Debug Mode** - Enable/disable debugging constants safely without touching `wp-config.php`.
* **Smart Filtering** - Advanced search operators (`+include -exclude`) to cut through log noise.
* **Modern React UI** - Fast, responsive interfaces that make debugging feel like a modern workflow.

### Perfect For

* **Agencies** managing multiple client sites who need proactive monitoring
* **Developers** who need deep technical insights without database overhead
* **Site Owners** who want peace of mind knowing their site is being watched 24/7

### Live Demo & Documentation

See the full feature breakdown at [wpdebugtoolkit.com](https://wpdebugtoolkit.com).



== Installation ==

1. Upload the `wpdebugtoolkit` folder to the `/wp-content/plugins/` directory
2. Activate the plugin through the 'Plugins' menu in WordPress
3. Access WP Debug Toolkit from the WordPress admin menu and activate the license key
4. Install the standalone viewer with one click from the plugin's interface
5. Start using the powerful debugging tools!

== Frequently Asked Questions ==

= Is this plugin free? =

There is a free version planned, but at the moment there is only a Premium (paid) licensed version.

= Will this plugin slow down my site? =

No. Unlike other debugging tools that write logs to your database (bloating it and slowing down queries), WP Debug Toolkit uses filesystem logging for its Query Viewer. This ensures zero database overhead and minimal impact on your site's performance.

= What happens if my site crashes (WSOD)? =

This is where WP Debug Toolkit shines. Because the **Standalone Viewer** runs as a separate React application (independent of WordPress core), you can access it directly via its URL even if your WP Admin is inaccessible. You can see the fatal error log immediately without needing FTP/SSH. If you have the email alerts enabled, you'll also receive an email with a WP Recovery URL you can use to regain access to your site.

= Is it safe to use on a production site? =

Yes. The tools are explicitly designed for production monitoring with a "security-first" architecture:
1. **Query Viewer:** Uses filesystem logging to avoid database strain.
2. **Viewer App:** Protected by a secure, standalone authentication system (independent of WP users) and strict path validation.
3. **Debug Mode:** You can toggle debug logging on/off instantly as needed.
4. **Security In Mind:** Rate-limited login attempts and customizable session timeouts to prevent brute-force attacks, and more. 

= Can I use this on a local development environment? =

Absolutely! WP Debug Toolkit is designed to work seamlessly in local development environments like XAMPP, Local by Flywheel, DevKinsta, Docker etc.

= Does this plugin modify my wp-config.php file? =

Yes, when you enable or disable debugging features, WP Debug Toolkit safely modifies your wp-config.php file to add the necessary constants. It creates a backup before making any changes.


== Changelog ==

= 1.2.3 =
* Security: Fixed an authentication bypass affecting all REST API endpoints that responded to unauthenticated requests.

= 1.2.2 =
* Fix: Viewer login failing on hosts that strip cookies from API responses
* Fix: Blocklist typo and missing entries left rate-limit.db, viewer-settings.db, and rate-limit.json readable via the file viewer endpoint
* Security: Global rate-limit floor on viewer auth — protects against rotating-IP brute-force attempts

= 1.2.1 =
* Fix: Plugin updates failing with "Unauthorized" for Early Supporter / legacy licenses
* Fix: open_basedir warnings flooding the PHP error log on non-Flywheel hosts with restrictive open_basedir

= 1.2.0 =
* New: Time-limited query recording with shareable URLs and automatic stop — record queries on demand instead of leaving capture always on
* New: Group duplicate log entries toggle with count badges in the viewer
* New: Performance warnings on Overview page when debug mode or query logging is enabled
* New: Proxy and CDN support — disable IP binding toggle for proxied environments, with Cloudflare and Akamai header detection
* New: Manage session IP binding from the WordPress admin Viewer Settings tab
* New: View and clear rate-limited IPs from the WordPress admin Viewer Settings tab
* New: Flywheel hosting compatibility
* New: wp-config.php writability diagnostics in Site Health with safe temporary permission elevation
* New: `wp dbtk api` command group — discover, list, show, search, call, edit, export, import, and bootstrap REST API endpoints from the terminal
* New: Semantic annotation layer for `wp dbtk api edit` — method-level descriptions, safety classification, auth notes, return-shape notes, tags, and verification markers; persisted across discovery rescans
* New: `wp dbtk api export` / `import` for portable annotation packs with merge and replace-source modes
* New: `wp dbtk api bootstrap` — generate a Markdown brief of a plugin's endpoints for fresh agent sessions
* New: `wp dbtk query-log start/stop/status/read` commands for recording control and query analysis from the terminal
* New: `wp dbtk log read` command for filtered debug log reading from the terminal
* New: `--summary` and `--memory` flags for `wp dbtk query-log read` — view per-page performance overview and memory usage from recordings
* New: `--profile` flag on `wp dbtk api call` with `full`, `queries`, and `summary` modes
* New: CLI documentation suite — setup guide, usage guide, command reference, AI assistant guide, REST endpoint profiling guide
* New: Q keyboard shortcut to open the query recording dialog, with a shortcut badge on the Record button
* New: Reinstall Viewer action on the Overview page — regenerates viewer files without re-prompting for password; bound to the I shortcut when the viewer is installed
* New: "Always Logging" warning pill with tooltip on the Database Queries card when SAVEQUERIES or enhanced logging is persistently enabled
* Improved: Lazy-load services — deferred to point-of-use instead of eager init on every request
* Improved: Cache health check results for 5 minutes with auto-invalidation on settings change
* Improved: Faster admin page loads — cache license API responses and pass initial settings inline to eliminate redundant API calls
* Improved: Settings now work on hosts with restrictive file permissions via automatic permission elevation and restore
* Improved: Actionable error messages for admin users when settings fail to save
* Improved: Replace SAVEQUERIES with filter-based query capture for safer API endpoint profiling
* Security: Harden standalone viewer — add execution guard, expand blocked files list, and add directory listing protection
* Security: Tighten wp-config backup file permissions to 0600
* Security: Strengthen encryption key generation in viewer manager
* Security: Improve HTTPS detection on local domains
* Security: Comprehensive security hardening: input validation and sanitization, API response hardening, session and CSRF improvements, data exposure prevention, and cleaner deactivation/uninstall lifecycle
* Fix: PHP 8.4 deprecation warning for E_STRICT constant in notifications mu-plugin
* Fix: Session IP binding failures behind load balancers and CDNs
* Fix: Viewer install no longer blocked by read-only wp-config.php
* Fix: Graceful degradation when wp-config.php is not writable
* Fix: Settings page showing the wrong status for debug, query logging, and other toggles
* Fix: File path detection showing empty in Settings when initial page data is used
* Fix: Viewer session authentication failing on local HTTP environments
* Fix: Viewer password status showing the wrong value on the Settings page
* Fix: Viewer settings modal not closing after a successful save
* Fix: Viewer theme out of sync between the sidebar toggle and the Settings modal
* Fix: Viewer sidebar "Keyboard Shortcuts" button now opens the shortcuts reference
* Fix: License activation state not syncing across admin sections without a page reload
* Fix: `wp dbtk query-log stop` no longer disables global query logging when ending a recording session; stats labels clarified to distinguish session totals from log totals

= 1.1.0 =
* New: Query Logger - Real-time database query monitoring with slow query detection and performance metrics
* New: Query Statistics Dashboard - Visual insights into query performance and component-level breakdowns
* New: N+1 Query Detection - Automatically identifies and highlights repeated queries with aggregate statistics
* New: Database query error logging with detailed error messages and filtering
* New: Query export to CSV, JSON, and TSV formats with accurate component attribution
* New: Dynamic query statistics that recalculate based on active filters
* New: WP-CLI commands for license activation, debug toggling, viewer setup, and log management (wp dbtk)
* New: Email notification system for error alerts with customizable templates
* New: Automatic log cleanup with delete/archive/truncate methods, size limits, and age-based rotation
* New: Viewer permissions health check with repair button in Site Health
* New: Viewer settings for query dashboard limit, tail scan MB, max entry MB
* New: PHP memory limit management (writes to wp-config.php)
* New: Upload limit controls via WordPress filters
* New: Settings UI redesign with modern tabbed interface
* New: Modular licensing system with grandfathered benefits for early adopters
* New: Oversized entry warnings and “Large” filter in Query Viewer
* Security: Query logs encrypted at rest
* Security: Password protection now mandatory for viewer (8-character minimum)
* Security: SQLite-based rate limiting with progressive brute-force protection
* Security: Enhanced session security with 30-minute timeout and IP binding
* Security: Strengthened path traversal prevention with expanded blocklist
* Security: Replaced exec() with token_get_all() for PHP syntax validation
* Security: Fixed wp-config.php case-sensitivity bypass vulnerability in viewer
* Security: Added protection for secure-debug.php (GridPane compatibility)
* Security: Scoped CORS headers to plugin endpoints only
* Security: Restricted wp-config backup file permissions
* Security: Hardened viewer config and auth files against direct access
* Security: Expanded viewer blocked files list with additional sensitive file patterns
* Security: Added directory listing protection for query log storage
* Improved: Production and performance warnings in setup wizard for debug mode and query logging
* Improved: “Install without tools” option to set up the viewer without enabling debugging tools
* Improved: Setup wizard defaults tools to disabled — users opt in consciously
* Improved: Viewer installer wizard with step-by-step guidance
* Improved: Redesigned crash recovery system with cleaner UI and granular plugin/theme controls
* Improved: License management moved to Settings page
* Improved: Targeted cache clearing (plugin-specific transients only)
* Improved: Enhanced output buffer management
* Improved: Better type safety and code quality across PHP and React code
* Added: Custom file paths configuration (DBTK_CONFIG_PATH, DBTK_LOG_PATH constants)
* Added: Error level selection in Settings (Debug, Info, Warning, Error)
* Added: Cache busting in Admin and Viewer apps
* Added: WordPress internationalization (wp-i18n) support
* Added: Psalm static analysis with type hints
* Added: Partner discounts page
* Fix: Query Viewer tail reader no longer returns 0 entries on huge final log line
* Fix: Viewer auth rate limiter fallback when PDO SQLite is unavailable
* Fix: Directory permission issues on restrictive servers (umask handling)
* Fix: Viewer installation on hosts where WordPress files are in subfolders
* Fix: Path validation now supports relative paths securely
* Fix: Health check now properly loads WordPress admin functions
* Fix: Admin CSS isolation prevents conflicts with other plugins
* Fix: Compatibility with UiPress Lite and WP Dark Mode
* Fix: wp-config.php duplicate constants when reinstalling viewer

= 1.0.1 =
* Added: Full GridPane hosting compatibility
* Fixed: Critical GridPane issue where uninstalling the plugin would break sites due to secure-debug.php dependency
* Fixed: Debug constants modification for non-standard wp-config.php structures
* Fixed: Log viewer access for logs stored outside the web root
* Improved: Simplified configuration file detection logic
* Improved: Better error messages for file permission issues

= 1.0.0 =
* Initial release

== Upgrade Notice ==

= 1.2.3 =
Security release — fixes an authentication bypass on the plugin's REST API endpoints. Update immediately.

= 1.2.2 =
Click "Reinstall Viewer" after upgrading to enable the new bearer-token auth fallback on caching hosts.

= 1.0.1 =
GridPane compatibility and debug constants fixes.

= 1.0.0 =
Initial release of WP Debug Toolkit Pro. Enjoy enhanced debugging capabilities for your WordPress site!

== Additional Resources ==

For more information, documentation and support, visit [https://wpdebugtoolkit.com](https://wpdebugtoolkit.com) 
