=== WebhookGuard — Retry, Log & Replay Native WooCommerce Webhooks ===
Contributors: lijnam
Tags: woocommerce, webhooks, webhook, retry, log
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 0.1.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Never lose a WooCommerce webhook: retry, log and replay every native delivery.

== Description ==

WooCommerce fires each native webhook once, redacts the payload from its own log, and silently disables the webhook after a handful of failures. WebhookGuard records every delivery attempt with the full payload, retries failures with exponential backoff and jitter, keeps the webhook active instead of letting it be disabled, and lets you replay any stored delivery from a filterable log. It is free, needs no external service, and works on the native webhooks you already run.

WebhookGuard sits beside the webhooks you already have. It does not replace them, it does not ask you to move your endpoints and it does not change the payload: it listens to WooCommerce's own delivery action, which fires after every attempt, and stores what core refuses to.

**What it records**

* Every delivery attempt — success or failure — with the webhook, topic, resource and event.
* The HTTP status, the round-trip duration and the endpoint response body.
* The exact request body that was sent, which WooCommerce only logs when `WP_DEBUG` is on.

**What it does with a failure**

* Schedules a retry with exponential backoff and jitter, re-sending the captured bytes.
* Keeps the webhook active while retries are owed, so an endpoint that is down for an hour does not cost you the webhook.
* Alerts the configured recipient by email, with a per-webhook cooldown so a flapping endpoint does not fill an inbox.
* Logs every failure with a filterable history and prunes old rows on a configurable retention window (30 days by default).

**Replay**

Any stored delivery can be re-sent with one click, or all failed deliveries for a webhook can be replayed in a bounded batch. The original `X-WC-Webhook-Delivery-ID` is reused so an idempotent endpoint can discard a duplicate, and the signature is recomputed from the webhook's current secret.

**Free and self-contained**

There is no licence key, no Pro edition, no external service and no telemetry. Updates come from the WordPress.org directory.

== Installation ==

1. Install the ZIP through **Plugins → Add New → Upload Plugin**, or extract the archive and upload the plugin folder to `/wp-content/plugins/`.
2. Activate the plugin through the **Plugins** screen in WordPress.
3. Open **WooCommerce → WebhookGuard** to review the delivery log, and its **Settings** child to change the retry, retention and alert options.

== Frequently Asked Questions ==

= Does this plugin require WooCommerce? =

Yes. The problem only exists in a store, so WebhookGuard observes WooCommerce's native webhook layer. Without WooCommerce the plugin loads safely, stays inert, registers none of the webhook hooks and writes nothing to the database; it shows one dismissible notice on its own Tools screen explaining that WooCommerce is missing.

= Does the plugin send my data anywhere? =

No. There is no licence server, no update server and no telemetry. The only outbound messages are the webhook retries and replays the plugin re-sends to the endpoint you already configured, and the failure alert email it sends with `wp_mail()` to the address you choose.

= Will a replay create duplicate records in my system? =

It can, which is why replay is always an explicit action by an administrator. The original `X-WC-Webhook-Delivery-ID` is reused on every retry and replay, so an endpoint that de-duplicates on that header will discard the duplicate. The payload is re-sent exactly as it was captured.

= Where are the retries stored? =

Each failed delivery is stored in the plugin's own table. A retry re-sends the captured bytes, so it still works after the source order or product has been edited or deleted, and it produces the same signed payload every time.

= Can I stop a webhook from being disabled? =

Yes. With **Keep webhooks active while retries are owed** turned on, the plugin raises the failure ceiling WooCommerce uses for automatic disabling. Turning it off restores WooCommerce's default behaviour.

= What happens to the log when I delete the plugin? =

Uninstalling removes the plugin's table, its options, its transient rows and the three per-webhook state keys it wrote. It never deletes a webhook, an order, a product or a customer.

== Screenshots ==

1. The delivery log with a failed order.created row expanded to show the full request payload and the Replay button.
2. The Settings screen showing retry attempts, backoff delays, keep-active, retention and the alert recipient.
3. A per-webhook failure summary with the retry state and the cooldown alert notice.

== Changelog ==

= 0.1.0 =
* Initial release.

== Upgrade Notice ==

= 0.1.0 =
* Initial release.
