{"id":330717,"date":"2026-10-08T09:20:48","date_gmt":"2026-10-08T09:20:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/talktomonitor\/"},"modified":"2026-10-08T09:20:35","modified_gmt":"2026-10-08T09:20:35","slug":"talktomonitor","status":"publish","type":"plugin","link":"https:\/\/twd.wordpress.org\/plugins\/talktomonitor\/","author":23502172,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.6.1","stable_tag":"1.6.1","tested":"7.1.3","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"TalktoMonitor - AI-Powered Diagnostics & Troubleshooting","header_author":"TalkToWP","header_description":"Monitors your WordPress site health and sends data to TalkToWP for AI-powered diagnostics and recommendations.","assets_banners_color":"c7d3e2","last_updated":"2026-10-08 09:20:35","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/app.talktowp.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":23,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.6.1":{"tag":"1.6.1","author":"talktowp","date":"2026-10-08 09:20:35","revision":3734110}},"upgrade_notice":{"1.6.1":"<p>The site health preview now works without a TalkToWP account, and the uploads directory is resolved entirely through wp_upload_dir(). No action needed.<\/p>","1.6.0":"<p>First release on WordPress.org.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.gif":{"filename":"icon-128x128.gif","revision":3734110,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.gif":{"filename":"icon-256x256.gif","revision":3734110,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3734110,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3734110,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.6.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3734110,"resolution":"1","location":"assets","locale":"","width":1267,"height":823},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3734110,"resolution":"2","location":"assets","locale":"","width":1347,"height":872},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3734110,"resolution":"3","location":"assets","locale":"","width":1200,"height":791},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3734110,"resolution":"4","location":"assets","locale":"","width":1623,"height":826},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3734110,"resolution":"5","location":"assets","locale":"","width":1637,"height":865}},"screenshots":{"1":"Overview \u2014 the local checks that need attention, each with a plain-English explanation of what it means.","2":"Security \u2014 the full local scan: core file integrity, injected plugin and theme files, database injections and admin accounts.","3":"Diagnostics \u2014 server environment, PHP version, memory limit, disk use and database table health.","4":"The TalkToWP dashboard \u2014 problems found across every connected site, ranked by severity.","5":"AI Chat \u2014 ask about any problem and get step-by-step instructions for fixing it."}},"plugin_section":[],"plugin_tags":[284963,5603,247,600,151481],"plugin_category":[54],"plugin_contributors":[284964],"plugin_business_model":[],"class_list":["post-330717","plugin","type-plugin","status-publish","hentry","plugin_tags-ai-diagnostics","plugin_tags-monitoring","plugin_tags-performance","plugin_tags-security","plugin_tags-site-health","plugin_category-security-and-spam-protection","plugin_contributors-talktowp","plugin_committers-talktowp"],"banners":{"banner":"https:\/\/ps.w.org\/talktomonitor\/assets\/banner-772x250.png?rev=3734110","banner_2x":"https:\/\/ps.w.org\/talktomonitor\/assets\/banner-1544x500.png?rev=3734110","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/talktomonitor\/assets\/icon-128x128.gif?rev=3734110","icon_2x":"https:\/\/ps.w.org\/talktomonitor\/assets\/icon-256x256.gif?rev=3734110","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/talktomonitor\/assets\/screenshot-1.png?rev=3734110","caption":"Overview \u2014 the local checks that need attention, each with a plain-English explanation of what it means."},{"src":"https:\/\/ps.w.org\/talktomonitor\/assets\/screenshot-2.png?rev=3734110","caption":"Security \u2014 the full local scan: core file integrity, injected plugin and theme files, database injections and admin accounts."},{"src":"https:\/\/ps.w.org\/talktomonitor\/assets\/screenshot-3.png?rev=3734110","caption":"Diagnostics \u2014 server environment, PHP version, memory limit, disk use and database table health."},{"src":"https:\/\/ps.w.org\/talktomonitor\/assets\/screenshot-4.png?rev=3734110","caption":"The TalkToWP dashboard \u2014 problems found across every connected site, ranked by severity."},{"src":"https:\/\/ps.w.org\/talktomonitor\/assets\/screenshot-5.png?rev=3734110","caption":"AI Chat \u2014 ask about any problem and get step-by-step instructions for fixing it."}],"raw_content":"<!--section=description-->\n<p><strong>TalktoMonitor<\/strong> connects your WordPress site to the <a href=\"https:\/\/app.talktowp.com\">TalkToWP<\/a> platform for continuous AI-powered health monitoring.<\/p>\n\n<p>Local security and health scanning run on your own site and need no account at all. Plain-English explanations, AI diagnostics, and the hosted dashboard are produced on the TalkToWP servers and require a free TalkToWP account. See the <strong>External services<\/strong> section below for exactly what is sent, when, and under which terms. TalkToWP receives nothing until you save a TalkToWP API key; the WordPress.org checksum API is contacted automatically, with or without a key, to check core file integrity.<\/p>\n\n<p>Once connected, TalkToWP watches your site around the clock and uses AI to:<\/p>\n\n<ul>\n<li>Detect and explain plugin conflicts, PHP errors, and security threats<\/li>\n<li>Monitor performance, uptime, and SSL certificate health<\/li>\n<li>Identify SEO spam injections and hidden malicious links<\/li>\n<li>Scan for unauthorized admin accounts and changed homepage content<\/li>\n<li>Send email alerts when critical issues are found<\/li>\n<\/ul>\n\n<p><strong>What data is collected?<\/strong><\/p>\n\n<p>The plugin transmits technical metrics \u2014 WordPress version, PHP version, active plugins, available updates, database health, server memory usage, error log counts, and security scan results \u2014 and, in some cases, small pieces of your site's content: recent PHP error-log lines, the usernames and registration dates of administrator accounts flagged as unrecognised, and post IDs, titles and short excerpts from database scan findings. Error-log lines can contain server file paths and occasionally values from the request that caused the error. The <strong>External services<\/strong> section below lists exactly what is sent.<\/p>\n\n<p><strong>Features include:<\/strong><\/p>\n\n<ul>\n<li>Adaptive heartbeat monitoring (3-minute lightweight pulse + daily full snapshot)<\/li>\n<li>Security scan: SEO spam, hidden links, suspicious admin accounts, homepage integrity<\/li>\n<li>Google PageSpeed Insights integration (via TalkToWP dashboard)<\/li>\n<li>Plugin vulnerability detection<\/li>\n<li>WP-Cron health monitoring<\/li>\n<li>AI Chat: ask questions about your site in plain English<\/li>\n<li>Debug log detection, with copyable wp-config.php instructions when it's off<\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>This plugin is the site-side agent for <strong>TalkToWP<\/strong>, a hosted WordPress monitoring\nservice operated by Beyondt Consultancy &amp; Services Pvt. Ltd. Local security\nscanning and site health checks run entirely on your own server and require no\naccount. Plain-English explanations, AI diagnostics, and the hosted dashboard are\nproduced on the TalkToWP servers and require a free TalkToWP account.<\/p>\n\n<p><strong>1. TalkToWP (app.talktowp.com) \u2014 required for AI diagnostics and the dashboard<\/strong><\/p>\n\n<p>What it is used for: storing and analysing your site's health data, generating the\nAI diagnostics and incidents shown in your TalkToWP dashboard, and sending alerts.<\/p>\n\n<p>Nothing is transmitted to TalkToWP until you paste a TalkToWP API key on\nSettings \u2192 TalkToWP and save. Removing the key stops all transmission to\nTalkToWP. (The plugin's local security scans still run without a key \u2014 see\nitem 2 below for the one request they make regardless of account status.)<\/p>\n\n<p>Once a key is saved, the plugin sends:<\/p>\n\n<ul>\n<li><code>POST https:\/\/app.talktowp.com\/api\/plugin\/heartbeat<\/code> \u2014 every 3 minutes via\nWP-Cron. Sends a timestamp, the change in PHP error count, memory usage\npercentage, a hash representing your plugin\/theme\/core versions, and the HTTP\nstatus code of your own homepage.<\/li>\n<li><code>POST https:\/\/app.talktowp.com\/api\/plugin\/health<\/code> \u2014 once daily via WP-Cron, and\nalso when you save your API key, press \"Test Connection\", switch themes, or\nupdate WordPress core. Sends your site URL and the full technical snapshot:\nWordPress and PHP versions, active plugins and themes with their versions,\navailable updates, database size and table status, server memory and disk usage,\nerror-log line counts and recent error-log lines, WP-Cron status, SSL certificate\nstatus, and security scan results. The next paragraphs list the parts of that\nsnapshot that are more than counts. You can inspect the exact payload before it\nis ever sent using the \"Preview Data Sent for Analysis\" button on the settings page.<\/li>\n<li><code>POST https:\/\/app.talktowp.com\/api\/plugin\/uninstall<\/code> \u2014 once, when you delete the\nplugin. Sends only your site URL, so TalkToWP can close open incidents and mark\nthe site as disconnected.<\/li>\n<\/ul>\n\n<p>The daily snapshot contains the following in addition to technical metrics:<\/p>\n\n<ul>\n<li>Up to 20 recent PHP error-log lines, each cut to 500 characters, plus fatal-error\nlines that name an active plugin. These lines are sent as they appear in your\nlog, so they can contain server file paths and occasionally values from the\nrequest that caused the error.<\/li>\n<li>The usernames and registration dates of administrator accounts the scan flags as\nunrecognised. Administrator email addresses are not sent.<\/li>\n<li>For database scan findings in posts: the post ID, the post title, and an excerpt\nof up to 120 characters of the post content. For findings in wp_options: the\noption name and a SHA-256 hash of the matched text, not the value itself.<\/li>\n<li>For SEO-spam and hidden-link findings: post IDs and SHA-256 hashes of the\nmatched text.<\/li>\n<\/ul>\n\n<p>The plugin does not deliberately collect passwords or visitor data, but anything\nan error-log line happens to contain is sent with it. The plugin never reads\nwp-config.php, .env files, or private keys.<\/p>\n\n<p>The plugin registers three REST routes under <code>\/wp-json\/talktowp\/v1\/<\/code>:<\/p>\n\n<ul>\n<li><code>health-data<\/code> (GET) \u2014 returns the same technical snapshot described above. It\nchanges nothing.<\/li>\n<li><code>reset-homepage-hash<\/code> (POST) \u2014 fetches your homepage, stores a new fingerprint of\nits text in place of the old one, and clears the recorded \"homepage changed\"\ntime, so the homepage-change check starts again from the current page.<\/li>\n<li><p><code>push-now<\/code> (POST) \u2014 sends a fresh health snapshot to TalkToWP and, when the\nrequest asks for it, first runs a new security scan and stores the result.<\/p>\n\n<p>health-data and <code>reset-homepage-hash<\/code> require your API key in an <code>X-API-Key<\/code>\nrequest header. <code>push-now<\/code> requires an HMAC-SHA256 signature derived from your API\nkey, with a \u00b15-minute window and replay protection. The only things these routes\nwrite are the plugin's own options in your WordPress database, such as the\nhomepage fingerprint and the last scan result. None of them install, update,\nactivate or deactivate anything, and none modify plugin, theme, core or any other\nsite files.<\/p><\/li>\n<\/ul>\n\n<p>Service terms: https:\/\/app.talktowp.com\/terms\nPrivacy policy: https:\/\/app.talktowp.com\/privacy<\/p>\n\n<p><strong>2. WordPress.org checksum API (api.wordpress.org) \u2014 automatic, no account required<\/strong><\/p>\n\n<p>What it is used for: the core file integrity scan. To tell whether a WordPress\ncore file has been modified, the plugin fetches the official checksums for your\nWordPress version from\n    https:\/\/api.wordpress.org\/core\/checksums\/1.0\/?version=&amp;locale=en_US\nand compares them against the files on disk locally. This runs as part of the\ndaily local security scan whether or not a TalkToWP API key is saved.<\/p>\n\n<p>What is sent and when: your WordPress version number only, at most once per day\n(the response is cached in a transient). No site URL, no personal data. This is\nthe same WordPress.org service that WordPress core itself uses.<\/p>\n\n<p>WordPress.org privacy policy: https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Download the plugin ZIP from the WordPress.org plugin directory or your TalkToWP account.<\/li>\n<li>In your WordPress admin, go to <strong>Plugins &gt; Add New &gt; Upload Plugin<\/strong> and upload the ZIP file.<\/li>\n<li>Click <strong>Activate Plugin<\/strong>.<\/li>\n<li>You will be redirected to <strong>Settings &gt; TalkToWP<\/strong> automatically.<\/li>\n<li>Log in (or sign up) at <a href=\"https:\/\/app.talktowp.com\">app.talktowp.com<\/a> to get your API key.<\/li>\n<li>In the TalkToWP dashboard, add your site and copy the API key.<\/li>\n<li>Paste the API key into the plugin settings page and click <strong>Save Settings<\/strong>.<\/li>\n<\/ol>\n\n<p>Monitoring begins immediately after saving.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"how%20does%20monitoring%20work%3F\"><h3>How does monitoring work?<\/h3><\/dt>\n<dd><p>The plugin collects health data on a 3-minute heartbeat and sends a full snapshot once daily. TalkToWP's AI analyzes the data, detects anomalies, and creates incidents when issues are found.<\/p><\/dd>\n<dt id=\"where%20do%20i%20find%20my%20api%20key%3F\"><h3>Where do I find my API key?<\/h3><\/dt>\n<dd><p>Log in to your <a href=\"https:\/\/app.talktowp.com\/dashboard\">TalkToWP dashboard<\/a>, go to <strong>Sites<\/strong>, click your site, then open <strong>Site Settings<\/strong>. Your API key is listed there.<\/p><\/dd>\n<dt id=\"what%20data%20is%20sent%20to%20talktowp%3F\"><h3>What data is sent to TalkToWP?<\/h3><\/dt>\n<dd><p>Technical site health data: WordPress and PHP versions, active plugins and themes, available updates, database size, memory usage, error-log line counts, and security scan results. Some of it is more than counts. The daily snapshot includes up to 20 recent PHP error-log lines, each cut to 500 characters, plus fatal-error lines that name an active plugin. Those lines are sent as they appear in your log, so they can contain server file paths and occasionally values from the request that caused the error. Administrator usernames and registration dates are sent for accounts the scan flags as unrecognised; administrator email addresses are not. Database scan findings include post IDs, post titles and an excerpt of up to 120 characters of post content; for findings in wp_options, only the option name and a SHA-256 hash of the matched text are sent, not the value. The plugin does not deliberately collect passwords or visitor data, but anything an error-log line happens to contain is sent with it. Nothing is sent to TalkToWP until you save a TalkToWP API key on the Settings tab. You can preview the exact payload at any time from the Settings tab.<\/p><\/dd>\n<dt id=\"will%20this%20plugin%20slow%20down%20my%20site%3F\"><h3>Will this plugin slow down my site?<\/h3><\/dt>\n<dd><p>No. The heartbeat is lightweight and runs on WP-Cron, which fires only when a visitor loads a page (or via a real server-level cron job). There is no frontend performance impact.<\/p><\/dd>\n<dt id=\"is%20my%20data%20secure%3F\"><h3>Is my data secure?<\/h3><\/dt>\n<dd><p>All communication with TalkToWP uses HTTPS with SSL certificate verification. Your API key is unique to your site and can be regenerated at any time from the TalkToWP dashboard.<\/p><\/dd>\n<dt id=\"why%20does%20using%20talktowp%20require%20an%20account%3F\"><h3>Why does using TalkToWP require an account?<\/h3><\/dt>\n<dd><p>It doesn't, for the local scanning and site health checks on this page \u2014 every panel here runs and displays fully without one. An account is only needed for what happens after that: TalkToWP's servers turn this site's raw findings into plain-English explanations, AI diagnostics, and the hosted dashboard, which is work this plugin cannot do by itself.<\/p><\/dd>\n<dt id=\"can%20talktowp%20change%20my%20site%3F\"><h3>Can TalkToWP change my site?<\/h3><\/dt>\n<dd><p>Not in any way that affects your plugins, themes, WordPress core or files. The plugin registers three REST routes under \/wp-json\/talktowp\/v1\/. health-data (GET) returns the technical snapshot the plugin sends to TalkToWP and changes nothing. reset-homepage-hash (POST) fetches your homepage and stores a new fingerprint of its text in place of the old one, so the homepage-change check starts again from the current page. push-now (POST) sends a fresh health snapshot to TalkToWP and, when the request asks for it, first runs a new security scan and stores the result. health-data and reset-homepage-hash require your API key in an X-API-Key request header. push-now requires an HMAC-SHA256 signature derived from your API key, valid for five minutes and accepted only once. The only things these routes write are the plugin's own options in your WordPress database, such as the homepage fingerprint and the last scan result. None of them install, update, activate or deactivate anything, and none modify plugin, theme, core or any other site files.<\/p><\/dd>\n<dt id=\"how%20do%20i%20disconnect%20this%20site%20from%20talktowp%3F\"><h3>How do I disconnect this site from TalkToWP?<\/h3><\/dt>\n<dd><p>Go to the Settings tab, clear the API Key field, and save. That immediately stops all transmission to TalkToWP; local scanning keeps running on this site as before.<\/p><\/dd>\n<dt id=\"why%20does%20the%20plugin%20source%20contain%20strings%20like%20eval%28base64_decode%28%20%3F\"><h3>Why does the plugin source contain strings like eval(base64_decode( ?<\/h3><\/dt>\n<dd><p>Those are malware signatures \u2014 the patterns the security scanner searches\nfor in your site's files and database. They are string literals compared\nagainst other files' contents. The plugin never executes them.<\/p><\/dd>\n<dt id=\"why%20does%20the%20plugin%20source%20contain%20matches%20for%20%3Cscript%3E%20and%20%3Cstyle%3E%3F\"><h3>Why does the plugin source contain matches for <\/h3><\/dt>\n<dd><p>Those are SQL <code>LIKE<\/code> clauses and regular expressions the security scanner uses to detect injected <code>&lt;script&gt;<\/code> and <code>&lt;style&gt;<\/code> markup hidden in your post content and database \u2014 patterns it searches for, not code it runs. All of the plugin's own CSS and JavaScript is loaded through WordPress's <code>wp_enqueue_style()<\/code> and <code>wp_enqueue_script()<\/code> functions; there is no inline <code>&lt;style&gt;<\/code> or <code>&lt;script&gt;<\/code> tag anywhere in the plugin.<\/p><\/dd>\n<dt id=\"what%20plans%20are%20available%3F\"><h3>What plans are available?<\/h3><\/dt>\n<dd><p>Paid plans are available for sites and agencies that need more than the free account provides. See app.talktowp.com for current plans.<\/p><\/dd>\n<dt id=\"how%20do%20i%20uninstall%20the%20plugin%3F\"><h3>How do I uninstall the plugin?<\/h3><\/dt>\n<dd><p>Deactivate the plugin, then click <strong>Delete<\/strong>. The plugin will automatically notify TalkToWP so open incidents are resolved and the site is marked as disconnected. All plugin options and transients are removed from your database on uninstall.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.6.1<\/h4>\n\n<ul>\n<li>The local health-data preview now works without a TalkToWP account.<\/li>\n<li>The uploads directory is resolved only through wp_upload_dir(), with no hardcoded fallback.<\/li>\n<li>The plugin display name is now TalktoMonitor.<\/li>\n<\/ul>\n\n<h4>1.6.0<\/h4>\n\n<ul>\n<li>First release on WordPress.org.<\/li>\n<li>All security scans run and display locally, with or without a TalkToWP account. A free account adds plain-English explanations of the findings on the TalkToWP dashboard.<\/li>\n<li>The plugin is read-only. It reads your site's files, database and settings to scan them, and never writes to your plugins, themes, WordPress core or any other site file.<\/li>\n<li>Privacy: administrator email addresses are never sent. Database scan findings in wp_options send the option name and a SHA-256 hash of the matched text rather than the value itself.<\/li>\n<li>The privacy documentation, the FAQ and the External services section state everything the plugin sends, and describe all three REST routes accurately.<\/li>\n<li>TalkToWP appears as a dedicated tab on WordPress Site Health (Tools -&gt; Site Health -&gt; TalkToWP).<\/li>\n<li>Debug log detection is read-only, with copyable wp-config.php instructions instead of writing to the file.<\/li>\n<li>Includes an uninstall handler that removes every plugin option, transient and scheduled event on deletion.<\/li>\n<\/ul>","raw_excerpt":"AI-powered WordPress health monitoring. Detects issues, explains them in plain English, and helps you fix them fast.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/330717","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=330717"}],"author":[{"embeddable":true,"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/talktowp"}],"wp:attachment":[{"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=330717"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=330717"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=330717"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=330717"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=330717"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=330717"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}