TalktoMonitor connects your WordPress site to the TalkToWP platform for continuous AI-powered health monitoring.
Local security and health scanning run on your own site and need no account at all. Plain-English explanations, AI diagnostics, and the hosted dashboard are produced on the TalkToWP servers and require a free TalkToWP account. See the External services section below for exactly what is sent, when, and under which terms. TalkToWP receives nothing until you save a TalkToWP API key; the WordPress.org checksum API is contacted automatically, with or without a key, to check core file integrity.
Once connected, TalkToWP watches your site around the clock and uses AI to:
What data is collected?
The plugin transmits technical metrics — WordPress version, PHP version, active plugins, available updates, database health, server memory usage, error log counts, and security scan results — and, in some cases, small pieces of your site’s content: recent PHP error-log lines, the usernames and registration dates of administrator accounts flagged as unrecognised, and post IDs, titles and short excerpts from database scan findings. Error-log lines can contain server file paths and occasionally values from the request that caused the error. The External services section below lists exactly what is sent.
Features include:
This plugin is the site-side agent for TalkToWP, a hosted WordPress monitoring
service operated by Beyondt Consultancy & Services Pvt. Ltd. Local security
scanning and site health checks run entirely on your own server and require no
account. Plain-English explanations, AI diagnostics, and the hosted dashboard are
produced on the TalkToWP servers and require a free TalkToWP account.
1. TalkToWP (app.talktowp.com) — required for AI diagnostics and the dashboard
What it is used for: storing and analysing your site’s health data, generating the
AI diagnostics and incidents shown in your TalkToWP dashboard, and sending alerts.
Nothing is transmitted to TalkToWP until you paste a TalkToWP API key on
Settings TalkToWP and save. Removing the key stops all transmission to
TalkToWP. (The plugin’s local security scans still run without a key — see
item 2 below for the one request they make regardless of account status.)
Once a key is saved, the plugin sends:
POST https://app.talktowp.com/api/plugin/heartbeat — every 3 minutes viaPOST https://app.talktowp.com/api/plugin/health — once daily via WP-Cron, andPOST https://app.talktowp.com/api/plugin/uninstall — once, when you delete theThe daily snapshot contains the following in addition to technical metrics:
The plugin does not deliberately collect passwords or visitor data, but anything
an error-log line happens to contain is sent with it. The plugin never reads
wp-config.php, .env files, or private keys.
The plugin registers three REST routes under /wp-json/talktowp/v1/:
health-data (GET) — returns the same technical snapshot described above. Itreset-homepage-hash (POST) — fetches your homepage, stores a new fingerprint ofpush-now (POST) — sends a fresh health snapshot to TalkToWP and, when the
request asks for it, first runs a new security scan and stores the result.
health-data and reset-homepage-hash require your API key in an X-API-Key
request header. push-now requires an HMAC-SHA256 signature derived from your API
key, with a ±5-minute window and replay protection. The only things these routes
write are the plugin’s own options in your WordPress database, such as the
homepage fingerprint and the last scan result. None of them install, update,
activate or deactivate anything, and none modify plugin, theme, core or any other
site files.
Service terms: https://app.talktowp.com/terms
Privacy policy: https://app.talktowp.com/privacy
2. WordPress.org checksum API (api.wordpress.org) — automatic, no account required
What it is used for: the core file integrity scan. To tell whether a WordPress
core file has been modified, the plugin fetches the official checksums for your
WordPress version from
https://api.wordpress.org/core/checksums/1.0/?version=&locale=en_US
and compares them against the files on disk locally. This runs as part of the
daily local security scan whether or not a TalkToWP API key is saved.
What is sent and when: your WordPress version number only, at most once per day
(the response is cached in a transient). No site URL, no personal data. This is
the same WordPress.org service that WordPress core itself uses.
WordPress.org privacy policy: https://wordpress.org/about/privacy/