2026-10-05 ยท CPH Feedback Desk
A standalone WordPress plugin for private bug reports, existing-product feature requests and new-product proposals from customers and noncustomers.
What changed
- Provides an account-free feedback form and a private administrator queue. The product selector reads the site's published FluentCart catalog, or its WooCommerce catalog where that is the active store. Sites without either store can configure a local product list.
- Accepts new-product proposals separately from requests about an existing product. Only an administrator using a protected browser session can approve a proposal or change report status. Submissions do not automatically create products or authorize implementation.
- Adds screenshot and video evidence uploads, with a 200 MiB per-file ceiling and private storage outside the public website directory when configured. Also accepts HTTPS links to shared videos and documents without fetching their contents.
- Provides authenticated, read-only report and event feeds for assistants such as Taylor. Existing provisioned assistant credentials or administrator application passwords can read the feed over HTTPS; API credentials cannot approve requests.
- Records every report as an unverified public submission, returns a private reference, and protects repeated submissions with stable operation IDs. Uses bounded inputs, signed challenges, rate limits and transactional storage.
Verification
- Passed 78 PHP contract checks, 59 browser transport checks, 36 public markup checks, 21 store catalog checks, 34 administrator checks, 18 administrator client checks, 21 media checks and 26 read-only polling-helper checks.
- Passed 89 final isolated WordPress checks for transactional storage, permissions, simultaneous submissions, replay handling, catalog changes and rollback.
- Passed 33 genuine multipart WordPress checks, including acceptance of a 209,715,200-byte file and rejection of a file one byte over the limit. Authenticated binary download, association, exact retries and cleanup were verified.
- Live capabilities confirmed private uploads enabled at the 200 MiB limit. An existing assistant credential read both private feeds successfully, while anonymous report access was denied. Live browser verification found a theme paragraph contrast issue; the correction is tracked in 2026.10.05.006.
Rollout
Installed initially on CreatorPublishingHub.com and superseded there by 2026.10.05.006, which corrects a live theme paragraph contrast conflict. The original .005 standalone artifact and permanent notes are retained. Feedback uses the published FluentCart catalog. A separate verified store migration retained all four prior WooCommerce products as drafts. No installation on MatthewxMurphy.com or active Taylor monitoring schedule is claimed.
Updating
- Back up the selected plugin, affected site configuration and database before installation. Publish and verify this permanent version page before distributing the package.
- Install the separate cph-feedback plugin, create a page containing [cph_feedback], and add a support link. Review the private queue under Tools > CPH Feedback.
- For direct uploads, configure writable private storage outside the public web root and verify the host's PHP and request-size limits. Shared HTTPS evidence links are also supported. Preserve existing reports and private files during updates or rollback.
Scope and limitations
- Reports, uploaded evidence and customer relationships are unverified user submissions. The plugin does not execute report content, fetch submitted URLs, send email, enroll visitors in marketing or publish feedback.
- Approval records an administrator decision; it is not proof that a change was implemented or a promise of delivery. No store migration or payment configuration is included.
- File limits depend on the hosting configuration as well as the plugin ceiling. Basic abuse controls do not constitute CAPTCHA or malware scanning. Private files require an explicitly verified storage location.
- A read-only API and optional polling helper do not by themselves mean Taylor is monitoring or has reviewed a report. Each installation needs its own authorized reader configuration.