|
| 1 | +# WordPress.org Submission Checklist (2026-07-19) |
| 2 | + |
| 3 | +Factuality and ambiguity audit of the submission surfaces (readme.txt, |
| 4 | +basicrum.php header, wordpress-org-assets, release ZIP) at version 0.0.8, |
| 5 | +ahead of the plugin-directory submission. Method: four auditors (line-by-line |
| 6 | +readme factuality vs code, current wp.org handbook requirements, two-persona |
| 7 | +ambiguity sweep, hands-on official readme validator + reviewer-style ZIP |
| 8 | +inspection); every non-clean verdict adversarially re-checked by two |
| 9 | +refuters. 84 claims audited: 52 clean, 24 upheld findings, 8 overturned. |
| 10 | + |
| 11 | +## 1. Blockers - must be resolved before submission |
| 12 | + |
| 13 | +- [x] RESOLVED 2026-07-20: user registered the wordpress.org account `basicrum`; readme.txt Contributors updated to `basicrum`. Original finding: Contributors username did not exist. The OFFICIAL wp.org readme |
| 14 | + validator returned verbatim: "The following contributors listed were |
| 15 | + ignored, as the WordPress.org user could not be found. tstoychev." |
| 16 | + Register the wordpress.org account with exactly that username (or change |
| 17 | + readme.txt line 2 to the registered account that will submit), and |
| 18 | + confirm profiles.wordpress.org/tstoychev resolves. (D1a, R02, B6) |
| 19 | +- [x] RESOLVED 2026-07-20: Boomerang BSD LICENSE.txt now ships at assets/js/boomr/LICENSE.txt; readme.txt Third-party section and THIRD-PARTY-NOTICES.txt name the source commit and repositories. UPGRADED 2026-07-20: build reproduced BYTE-IDENTICAL (SHA-256 90e8a1c8...) from basicrum/boomerang master commit ead2783a with Node 12 + npm ci + grunt clean build --build-flavor=cutting-edge --build-number=815; the in-file banner stamps parent commit 564759ed because the final continuity.js change was uncommitted at original build time - docs now state both hashes; tools/verify-boomerang-provenance.sh guards bundle/docs sync via make conventions. Original finding: human-readable source for the bundled Boomerang (guideline 4: |
| 20 | + reviewers require public, maintained access to source and build tools |
| 21 | + for minified files). assets/js/boomr/ ships only the .min.js; its header |
| 22 | + says "See the accompanying LICENSE.txt" and none accompanies it. Add to |
| 23 | + readme.txt (Development or Third-party section) and THIRD-PARTY-NOTICES.txt: |
| 24 | + the upstream repository, the exact source commit (the bundle header |
| 25 | + carries 564759ed70de7801bb64de5e2025fb6ac049ff5f), and the build |
| 26 | + procedure; ship Boomerang's BSD license text alongside the bundle. (B2) |
| 27 | +- [x] RESOLVED 2026-07-20: phpstan.neon.dist added to .distignore and the verify-release dev-file regex; ZIP rebuilt and verified clean. Original finding: dev file leaks into the ZIP: release/basicrum.zip contains |
| 28 | + basicrum/phpstan.neon.dist. Add it to plugins/basicrum/.distignore and |
| 29 | + to the verify-release.sh dev-file regex, rebuild. Plugin Check would |
| 30 | + flag it. (D2a, B7) |
| 31 | + |
| 32 | +## 2. Reviewer-flag items - fix to avoid review friction |
| 33 | + |
| 34 | +- [x] RESOLVED 2026-07-20: External services section added to readme.txt. Original: add an "External services" readme section in the current |
| 35 | + reviewer-requested format: name the service (operator-configured |
| 36 | + collector; basicrum.com hosted option), what data is sent and when |
| 37 | + (performance beacons: URLs, timings, page type, site id; IP and user |
| 38 | + agent visible to the collector), and links to the service terms/privacy |
| 39 | + pages. The FAQ covers parts of this but not in the expected form. (B4) |
| 40 | +- [x] RESOLVED 2026-07-20: "Does Basicrum set cookies?" FAQ added (RT named with attributes and lifetime; BA described as legacy removal); RT also named in the Privacy Policy Guide text (Privacy.php) with test assertions. Original: add a cookies FAQ: the readme never names the first-party RT and BA |
| 41 | + cookies the listing's own privacy story depends on ("Does Basicrum set |
| 42 | + cookies?" - names, purpose, consent-mode behavior, opt-out removal). |
| 43 | + (C10) |
| 44 | +- [x] RESOLVED 2026-07-20: changelog collapsed to a single first-release entry. Original: collapse the 0.0.8 changelog into a single first-release feature |
| 45 | + entry; the current six bullets describe diffs against never-published |
| 46 | + 0.0.x builds and can be misread as shipped-version history. Decide |
| 47 | + whether 0.0.7/0.0.6 entries stay (internal history) or fold in. (C13, |
| 48 | + C14) |
| 49 | +- [ ] Run Plugin Check against the BUILT release/basicrum.zip (not the |
| 50 | + repo tree) after the fixes and keep the output for the submission. (B7) |
| 51 | +- [ ] Tested up to 7.0: internally defensible (blocking CI rows for wp |
| 52 | + 7.0 exist; format correct - verdict overturned by refuters), but |
| 53 | + re-confirm on submission day that WordPress 7.0 is the current released |
| 54 | + stable. (R05) |
| 55 | + |
| 56 | +## 3. Ambiguity fixes - upheld copy issues |
| 57 | + |
| 58 | +- [x] RESOLVED 2026-07-20: FAQ reworded (hosted account is one way; self-hosted needs no account). Original: account FAQ answered "Yes." then contradicts |
| 59 | + itself: self-hosted collectors need no account. Reword: collector |
| 60 | + endpoint + Brum Site ID required; hosted account is one way to get |
| 61 | + them. (R24, C04) |
| 62 | +- [ ] Vocabulary bridge: the compliance FAQ says "immediate and |
| 63 | + consent-controlled loading" while the settings radios say "Monitor |
| 64 | + without consent" / "Require consent before monitoring". Bridge both |
| 65 | + vocabularies once, then use the radio labels. (C02) |
| 66 | +- [ ] Define the server-side nouns once: collector (receives beacons) vs |
| 67 | + backoffice (dashboard where the Brum Site ID lives) vs account (hosted |
| 68 | + option); "backoffice" is currently undefined jargon. (C15) |
| 69 | +- [ ] Disambiguate "Basicrum" = plugin vs company vs service in the |
| 70 | + query-string FAQ: data goes only to the operator-configured Beacon URL; |
| 71 | + the plugin makes no requests to basicrum.com. (C16) |
| 72 | +- [ ] HTTP Strictness FAQ still inverts the semantics (enabling |
| 73 | + "Strictness" relaxes enforcement). Rewrite the FAQ to lead with the |
| 74 | + default (auto-upgrade to HTTPS) and what the toggle actually allows; |
| 75 | + the label rename remains open from the operator-experience audit. (C08) |
| 76 | +- [ ] "eligible pages" in the contributed privacy-policy text |
| 77 | + (Privacy.php immediate-mode sentence) is undefined for site owners; |
| 78 | + spell out: frontend pages, admins excluded unless Track Admin Users. |
| 79 | + (C12) |
| 80 | +- [ ] Define "connected" CookieYes at first use (linked to the CookieYes |
| 81 | + web app so its browser consent API is present). (C07) |
| 82 | +- [ ] Replace "fails closed" jargon: "keeps monitoring switched off until |
| 83 | + its consent API reports a decision". (C19) |
| 84 | +- [ ] "How it works" step 2 orders enable-before-Site-ID, contradicting |
| 85 | + Installation steps 4-5 and triggering the enabled-but-inactive notice; |
| 86 | + align the order. (C22) |
| 87 | +- [ ] "after the configured Script Position" forward-references an |
| 88 | + undefined setting; name it: Basicrum > Performance > Script Position |
| 89 | + (header or footer). (C23) |
| 90 | + |
| 91 | +## 4. Optional but recommended |
| 92 | + |
| 93 | +- [ ] Screenshots: the section was correctly removed (no files existed), |
| 94 | + but an image-free listing forces users to imagine the settings-driven |
| 95 | + consent workflow. Capture screenshot-1..N.png using the exact current |
| 96 | + labels (Visitor Consent, Consent Tool Connection) and restore a |
| 97 | + matching section. (C24) |
| 98 | +- [ ] Spot-check the two basicrum.com URLs (home, /contact/) resolve; |
| 99 | + reviewers click them. (R45) |
| 100 | +- [ ] CookieYes "modern ... runtime" - one refuter pair split on this; |
| 101 | + consider "CookieYes 3.x" with a one-line legacy note for precision. |
| 102 | + (C06) |
| 103 | + |
| 104 | +## 5. Verified clean (highlights) |
| 105 | + |
| 106 | +- [x] Version consistency: header, BASICRUM_VERSION, Stable tag, top |
| 107 | + changelog all 0.0.8; no git tags, consistent with first release. (R07) |
| 108 | +- [x] Short description 95 chars (under 150), byte-identical to the |
| 109 | + header Description; privacy-first claim backed by defaults. (R09, C01 |
| 110 | + overturned) |
| 111 | +- [x] MIT license declared consistently (readme, header, LICENSE.md, |
| 112 | + composer.json); GPL-compatible; Boomerang BSD is GPL-compatible; |
| 113 | + THIRD-PARTY-NOTICES.txt scopes correctly. (R08, B1) |
| 114 | +- [x] All five tags valid and implemented; Requires at least 6.0 and |
| 115 | + Requires PHP 7.4 match headers, composer, and CI matrix. (R03, R04, R06) |
| 116 | +- [x] Feature claims verified against code: page-type values verbatim in |
| 117 | + PageTypeDetector.php with correctly hedged non-exhaustive lists; |
| 118 | + detection markers and version floors match ConsentIntegration.php; |
| 119 | + cache-plugin list matches Compatibility.php; guideline 7 satisfied |
| 120 | + (off by default, consent-controlled default). (R12-R15, B4-part) |
| 121 | +- [x] Plugin header complete: Requires at least, Requires PHP, Text |
| 122 | + Domain, Domain Path present; validator returned only the Contributors |
| 123 | + warning - readme parses cleanly otherwise. (D1a) |
| 124 | +- [x] ZIP contents otherwise reviewer-clean: no repo README, tests, |
| 125 | + docs/, node_modules, or scratch; readable+minified loader pairs and all |
| 126 | + five adapters present; production-only vendor/. (D2) |
| 127 | + |
| 128 | +## User-only actions before submission day |
| 129 | + |
| 130 | +1. Register/confirm the wordpress.org username matching Contributors. |
| 131 | +2. Re-confirm WordPress 7.0 is the current released stable. |
| 132 | +3. Verify basicrum.com pages linked from the listing are live. |
0 commit comments