{"id":368369,"date":"2026-09-23T18:36:13","date_gmt":"2026-09-23T18:36:13","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/request-inspector\/"},"modified":"2026-09-23T18:43:10","modified_gmt":"2026-09-23T18:43:10","slug":"traffic-warden","status":"publish","type":"plugin","link":"https:\/\/dsb.wordpress.org\/plugins\/traffic-warden\/","author":23565422,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.0.0","stable_tag":"2.0.0","tested":"7.1.2","requires":"6.6","requires_php":"8.1","requires_plugins":null,"header_name":"Traffic Warden","header_author":"Hammad Farooq Meer","header_description":"Inspect sanitized WordPress HTTP requests, database queries and PHP diagnostics in your dashboard.","assets_banners_color":"608ead","last_updated":"2026-09-23 18:43:10","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/hammadmeer.netlify.app","rating":0,"author_block_rating":0,"active_installs":0,"downloads":64,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.0.0":{"tag":"2.0.0","author":"hammadfarooqmeer","date":"2026-09-23 18:43:10","revision":3709973}},"upgrade_notice":{"1.0.0":"<p>When replacing a Request Inspector development build, deactivate it before activating TraceSleuth. Do not uninstall the old build with data deletion enabled: both use the existing diagnostic data. Existing REST integrations must use tracesleuth\/v1; the CLI command is wp tracesleuth.<\/p>","0.3.0":"<p>Recording starts disabled. Review diagnostic data policy before enabling capture.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3711878,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3711878,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3711878,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3711878,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3710007,"resolution":"1","location":"assets","locale":"","width":1650,"height":2066},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3710007,"resolution":"2","location":"assets","locale":"","width":1650,"height":649},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3710007,"resolution":"3","location":"assets","locale":"","width":1650,"height":2214},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3710007,"resolution":"4","location":"assets","locale":"","width":1650,"height":1283},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3710007,"resolution":"5","location":"assets","locale":"","width":1650,"height":1838}},"screenshots":[]},"plugin_section":[],"plugin_tags":[153,2679,2275,23519,947],"plugin_category":[59],"plugin_contributors":[282337],"plugin_business_model":[],"class_list":["post-368369","plugin","type-plugin","status-publish","hentry","plugin_tags-database","plugin_tags-debugging","plugin_tags-developer","plugin_tags-diagnostics","plugin_tags-http","plugin_category-utilities-and-tools","plugin_contributors-hammadfarooqmeer","plugin_committers-hammadfarooqmeer"],"banners":{"banner":"https:\/\/ps.w.org\/traffic-warden\/assets\/banner-772x250.png?rev=3711878","banner_2x":"https:\/\/ps.w.org\/traffic-warden\/assets\/banner-1544x500.png?rev=3711878","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/traffic-warden\/assets\/icon-128x128.png?rev=3711878","icon_2x":"https:\/\/ps.w.org\/traffic-warden\/assets\/icon-256x256.png?rev=3711878","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/traffic-warden\/assets\/screenshot-1.png?rev=3710007","caption":""},{"src":"https:\/\/ps.w.org\/traffic-warden\/assets\/screenshot-2.png?rev=3710007","caption":""},{"src":"https:\/\/ps.w.org\/traffic-warden\/assets\/screenshot-3.png?rev=3710007","caption":""},{"src":"https:\/\/ps.w.org\/traffic-warden\/assets\/screenshot-4.png?rev=3710007","caption":""},{"src":"https:\/\/ps.w.org\/traffic-warden\/assets\/screenshot-5.png?rev=3710007","caption":""}],"raw_content":"<!--section=description-->\n<p>Traffic Warden provides a native administration dashboard for local diagnostics. Historical recording is disabled on activation; live inspection is enabled by default for authorized accounts. Administrators choose recording scope, retention, body capture and access permissions.<\/p>\n\n<p>Features include searchable captures, incoming\/outgoing correlation, caller attribution, sanitized JSON\/form bodies, SQL timing and duplicate groups, shutdown fatal PHP errors, short-lived targeted capture, pagination and bounded cleanup.<\/p>\n\n<p>Live Inspector adds an optional WordPress toolbar and lazy React dock with 17 current-request panels. Live inspection is enabled by default for authorized accounts on supported administration and frontend pages. Site and account settings can disable it; existing saved choices are preserved on upgrade. Live snapshots are private to the current account\/session\/site, expire after ten minutes and do not enable historical recording. Captured contents are not embedded in page markup or saved to browser storage. Admission and reads are bounded; delayed cleanup can delay physical removal after expiry. No second plugin or database drop-in is installed. Readable source is included; this readme describes activation and privacy.<\/p>\n\n<p>Hook occurrence\/registration inspection, a shared-origin timeline, sanitized JSON\/HAR\/SQL\/body exports, POSIX cURL copying, CIDR\/proxy rules, restricted redaction patterns, audit records, saved scopes, local sharing, comparison, component reports, regression review and permission-protected WP-CLI commands are included. Callback execution timings remain unavailable. HAR network phases are explicitly marked as projections. Saved scopes never bypass capture retention.<\/p>\n\n<p>Advanced replay is disabled by default and limited to explicitly confirmed safe-method public HTTPS requests on staging with an exact hostname allowlist. Synthetic EXPLAIN is limited to a restricted read-only grammar and a MariaDB per-statement timeout adapter. No captured SQL is automatically executed and redacted credentials are never reconstructed.<\/p>\n\n<p>Database timings require SAVEQUERIES to be explicitly enabled outside this plugin. Detailed database and stack collection requires WP_DEBUG when the production guard is enabled. Traffic Warden does not enable global query logging itself.<\/p>\n\n<p>Capture starts after plugins load. Cached pages that bypass PHP, earlier bootstrap events and browser-side requests are outside coverage. General page output is not buffered; structured REST responses and WordPress HTTP API responses can be captured when body capture is enabled. Missing data is labelled explicitly.<\/p>\n\n<p>Privacy: diagnostic data stays in this site's database. No analytics or external service is contacted by the plugin. Bodies are off by default. Known credentials, SQL literals and common personal-data keys are removed before storage, but diagnostic content can still contain personal data. Restrict access and capture scope, and purge data after debugging. Retention defaults to seven days, 5,000 request rows and a 250 MB admission budget. WP-Cron performs bounded cleanup; delayed cron may delay physical removal. Deactivation stops collection. Uninstall retains data unless the administrator enabled deletion.<\/p>\n\n<p>Author: Hammad Farooq Meer - https:\/\/hammadmeer.netlify.app<\/p>\n\n<p>PHP diagnostics in 2.0.0 observe eligible fatal errors at shutdown after the collector starts. Nonfatal warnings, notices and deprecations are not intercepted. No error handler or reporting mask is installed or changed. A zero count does not prove absence of errors.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the traffic-warden directory to wp-content\/plugins, or install the release ZIP through Plugins &gt; Add New.<\/li>\n<li>Activate Traffic Warden.<\/li>\n<li>Open Traffic Warden &gt; Settings and select a recording mode before enabling capture.<\/li>\n<li>Reproduce the issue, inspect the capture, and disable recording when finished.<\/li>\n<\/ol>\n\n<h4>Upgrading from an earlier name<\/h4>\n\n<p>Deactivate the older plugin before activating Traffic Warden. Do not delete its data. Under Tools &gt; Traffic Warden migration, copy retained history in batches or start with empty history while keeping settings and account opt-outs. Back up the database first. Migration never copies live snapshots or access tickets. Alternatively run wp traffic-warden migrate --user= (add --url for each multisite site). New integrations use traffic-warden\/v1 and traffic_warden_* hooks; older aliases are not registered.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"why%20are%20database%20timings%20unavailable%3F\"><h3>Why are database timings unavailable?<\/h3><\/dt>\n<dd><p>Enable SAVEQUERIES in your own development configuration and enable database diagnostics in the plugin. Query logging has memory overhead independent of this plugin's bounded buffers.<\/p><\/dd>\n<dt id=\"does%20a%20zero%20count%20prove%20nothing%20happened%3F\"><h3>Does a zero count prove nothing happened?<\/h3><\/dt>\n<dd><p>No. Check collector availability, coverage, sampling and dropped-event indicators.<\/p><\/dd>\n<dt id=\"how%20is%20source%20provided%3F\"><h3>How is source provided?<\/h3><\/dt>\n<dd><p>Readable TypeScript and CSS are in admin\/src. The release includes build manifests and instructions in BUILD.txt. WordPress supplies React and the WordPress JavaScript APIs. Fonts are bundled locally under the SIL Open Font License.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Complete Traffic Warden identity, traffic-warden text domain, API and package.<\/li>\n<li>Removed custom nonfatal PHP-error capture and all error_reporting calls.<\/li>\n<li>PHP diagnostics now cover eligible shutdown fatal errors only; warnings, notices and deprecations are not collected.<\/li>\n<li>New isolated storage and explicit legacy migration; old plugin data is not deleted.<\/li>\n<li>Updated investigator artwork and retained private live inspection defaults.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Renamed to TraceSleuth \u2013 Request Diagnostics with the tracesleuth slug and text domain.<\/li>\n<li>Updated dashboard, toolbar, API routes, CLI command and supplied logo.<\/li>\n<li>Preserved existing captures, settings and account preferences from development releases.<\/li>\n<li>Corrected readme author encoding and submission metadata.<\/li>\n<\/ul>\n\n<h4>0.10.2<\/h4>\n\n<ul>\n<li>Fixed single-site deactivation and uninstall calling multisite-only functions.<\/li>\n<li>Restore the original site after network deactivation cleanup, including exceptional exits.<\/li>\n<li>Explicitly restrict recorder site switching to multisite.<\/li>\n<\/ul>\n\n<h4>0.10.1<\/h4>\n\n<ul>\n<li>Removed the unexpected root Markdown guide from the production package.<\/li>\n<li>Enabled live inspection by default for authorized accounts, preserving saved opt-outs.<\/li>\n<li>Replaced generic loaders with panel-specific skeleton layouts.<\/li>\n<\/ul>\n\n<h4>0.10.0<\/h4>\n\n<ul>\n<li>Integrated private Live Inspector toolbar and lazy React dock with 17 diagnostic panels.<\/li>\n<li>Per-account opt-in, ten-minute snapshots, session isolation and bounded collectors.<\/li>\n<li>Developer timers\/logs, lifecycle, assets, language, transient and capability observations.<\/li>\n<li>Independent live and history policies; no additional plugin or database drop-in.<\/li>\n<\/ul>\n\n<h4>0.3.0<\/h4>\n\n<ul>\n<li>Initial local request, HTTP, database and PHP diagnostic implementation.<\/li>\n<\/ul>\n\n<h4>0.9.0<\/h4>\n\n<ul>\n<li>Added hooks, timeline, portable traces, advanced policy, audit, local sessions, comparison, reports and CLI workflows.<\/li>\n<li>Added bounded structured text, concurrent admission checks and multisite lifecycle coverage.<\/li>\n<\/ul>","raw_excerpt":"Inspect local WordPress requests, outgoing HTTP calls, sanitized database queries and PHP diagnostics.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/368369","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=368369"}],"author":[{"embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/hammadfarooqmeer"}],"wp:attachment":[{"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=368369"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=368369"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=368369"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=368369"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=368369"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=368369"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}