Capveriq helps WordPress administrators find out why a user cannot access an admin page or perform an action.
Instead of editing roles blindly, Capveriq inspects roles, effective capabilities, registered admin-menu requirements, mapped capabilities and temporary runtime permission traces.
Capveriq is a diagnostic tool and does not automatically modify user permissions.
The problem Capveriq is built for
You have probably seen these messages:
A menu item disappears. A plugin screen becomes unavailable. A user has what looks like the correct role and is still denied. Role editors show you capability checkboxes, but they do not tell you why the request failed.
Capveriq answers a different question: which capability did the page require, does this user have it, and did anything change the decision at runtime?
What Capveriq examines
map_meta_cap API.user_has_cap filter.Honest diagnostics
Results use Confirmed, Likely, Possible or Unknown confidence labels. Capveriq does not present inference as proof. When evidence is insufficient it reports Inconclusive and recommends Live Trace.
Read-only by design
Capveriq never adds, removes or edits roles, capabilities or users. It reads, explains and reports.
Local only
Diagnostics run locally. Capveriq uses no external API, telemetry, remote fonts, account or licence key.
$menu and $submenu data.user_has_cap and map_meta_cap observation that never alters permission results.The trace expires automatically. Nothing about your site’s permissions is changed at any point.
Capveriq stores diagnostic data in your own WordPress database and sends nothing to any external service.
Capveriq never stores passwords, cookies, authorization headers, API keys, application passwords, nonce values, payment data, POST form contents, private messages or any credential from wp-config.php.
Trace events record the capability being checked, the mapped capabilities, the result, the request path and context, and the classified source file where one can be determined. Absolute server paths are reduced to site-relative paths such as wp-content/plugins/example/file.php, so hosting account names and home directories are never displayed.
With Privacy-safe Reports enabled (the default), exported reports mask the site domain, identify users by ID rather than by email address, and exclude server paths, IP addresses and authentication information.
Trace sessions and denied access records are pruned automatically using the retention period you configure, while the denied log also respects its maximum record count. You can clear trace data, the denied access log or all diagnostic data at any time from Capveriq > Settings. Capveriq integrates with WordPress personal data export and erasure tools for diagnostic records associated with registered users, and removes those records when the related WordPress user is deleted. When Delete Data on Uninstall is enabled, all Capveriq tables and options are removed when the plugin is deleted.
Diagnostic data lives in three custom tables created with dbDelta():
{prefix}capveriq_sessions{prefix}capveriq_events{prefix}capveriq_deniedWhen Live Trace is off, Capveriq performs no debug_backtrace() calls, no reflection on hook callbacks and no trace database writes, and it loads no frontend CSS or JavaScript. Deep tracing runs only for requests made by the single selected target user while a session is active and within the configured event limit.
Known limitations
user_has_cap processing, Capveriq reports that the state changed and lists the registered callbacks separately. It does not claim which callback was responsible.