Skip to content

Normalize to the Prolific plugin standard (1.1.0) - #2

Open
millertchris wants to merge 7 commits into
mainfrom
normalize/2026-10
Open

millertchris wants to merge 7 commits into
mainfrom
normalize/2026-10

Conversation

@millertchris

Copy link
Copy Markdown
Contributor

Normalizes BetterStack Logger to the Prolific plugin standard (slug betterstack-logger, version 1.1.0).

What changes

  • Standard header: Requires at least 6.5, Requires PHP 8.4, GPL-2.0-or-later, Text Domain betterstack-logger, Update URI on the license server.
  • Updates via plugin-update-checker v5.7 (Composer) from api.prolificdigital.io; bundled update-checker copies and GitHub-token code removed.
  • ABSPATH guards, translations loading, readme.txt / CHANGELOG / LICENSE / .distignore / phpcs config.
  • Shared CI and release workflows from prolific-digital/.github.
  • 1 security fix(es) — see the fix(security) commits and the CHANGELOG Security section.

Before merging: repo renames and the license-server registry deploy go out together, and releases are tagged after merge. See CHANGELOG.md for upgrade notes (e.g. re-activation after a main-file rename).

Commits
  • build: install plugin-update-checker via Composer and update from the license server
  • chore: adopt the Prolific plugin header and bump to 1.1.0
  • feat: remove settings on uninstall
  • docs: add CHANGELOG, replace GPL-3.0 LICENSE with GPL-2.0, update readme.txt for 1.1.0
  • chore: add phpcs ruleset and .distignore
  • ci: call the shared Prolific plugin CI and release workflows
  • fix(security): verify TLS for BetterStack requests and sanitize the token

🤖 Generated with Claude Code

millertchris and others added 7 commits September 29, 2026 20:20
… license server

Adds composer.json/composer.lock with yahnis-elsts/plugin-update-checker ^5.7 and includes/update-checker.php, which checks api.prolificdigital.io using the PROLIFIC_LICENSE_KEY_BETTERSTACK_LOGGER constant or the prolific_license_key filter. vendor/ is gitignored.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Standard header (WordPress 6.5+, PHP 8.4+, GPL-2.0-or-later, Update URI) with a BETTERSTACK_LOGGER_VERSION constant. The WPINC guards become the one-line ABSPATH guard, and translations load from languages/. The Short Description and Tags header lines are dropped (tags live in readme.txt).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Deletes betterstack_api_key, betterstack_error_logging_enabled and betterstack_event_logging_enabled.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…dme.txt for 1.1.0

readme.txt is rewritten in WordPress.org format, and README.md gains updates, stored-data, development and release sections.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…oken

create_log_entry() called wp_remote_post() with sslverify => false, so
log messages and the Bearer source token could be intercepted by anyone
on the network path. The override is removed and WordPress's default
certificate verification applies. It was the plugin's only wp_remote_*
request.

register_setting() now sanitizes betterstack_api_key (Bearer token
characters only, via sanitize_text_field) and stores the two logging
checkboxes only as "yes" or "". The token was already escaped with
esc_attr() on the settings screen.

Adds tests/security/tls-and-token.php (wp eval-file), which captures
the request args through http_request_args with a mocked
pre_http_request, and checks sanitizing and escaping.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant