
Eyesite Monitor is a health and performance monitoring plugin for your WordPress site and WooCommerce store. It is a complete solution for agencies, freelancers and e-commerce owners that detects problems before your customers do. The plugin works on its own locally, and can optionally connect to the EyeSite service (eyesite.pl) for external 24/7 uptime monitoring and e-mail alerts.
Key features
- Store monitoring: Tracks payment errors, the cart, shipping problems and sales silence (no orders for an unusual period).
- Order anomalies: Intelligent detection of irregularities in order statuses based on a 30-day rolling average.
- Server monitoring: Checks site availability, disk space usage, memory (RAM) and that WP-Cron is running correctly.
- Google and AI visibility: Indexing blocks, sitemap, schema.org data, and whether AI assistants (ChatGPT, Claude, Perplexity) are allowed to read the site.
- Security: Warns when your WordPress version has publicly known security holes, tests SSL certificate validity, Cloudflare protection and two-factor authentication (2FA).
- Error reporting (JS & PHP tracking): Captures and logs critical JavaScript (front-end) and PHP errors, including contact-form submission errors.
External services
This plugin connects to the EyeSite service (https://eyesite.pl) to provide external uptime monitoring and e-mail alerts. The connection is entirely optional and only happens after you click the “Connect” button in the plugin panel. Without connecting, the plugin still works locally (the monitoring dashboard is available offline).
What data is sent, and when:
- When connecting (after you click “Connect”): your site URL, your site name, the monitoring endpoint URL (which contains the API token used to read status) and your administrator e-mail address (pre-filled on the connect page, editable) used for alert notifications. This data is sent to the connect page at https://eyesite.pl/connect.
- Periodically: the EyeSite monitoring backend requests your site’s public status endpoint (/?eyesite-api=check) to read health status (UP/DOWN and check results) and e-mails you on failure.
- Once a day: the plugin verifies the connection token by sending it to the EyeSite automation backend at https://n8n.bielecki.cloud/webhook/eyesite-verify.
- On disconnect: the plugin sends the token to https://n8n.bielecki.cloud/webhook/eyesite-disconnect.
- Uptime data (only when connected, fetched in the background): the plugin reads your site’s public uptime history from the EyeSite status page at https://status.eyesite.pl (the status page is identified by the slug assigned to your site when connecting). Only the slug is sent; nothing else.
- Feedback form (only when you submit it): the message, feedback type, your site URL, site name and administrator e-mail are e-mailed to the plugin author and also posted to https://n8n.bielecki.cloud/webhook/eyesite-feedback for logging. Nothing is sent unless you click “Send”.
- Page-speed check (opt-in, off by default): only after you enable “Pomiar szybkości strony” in the settings or click “Włącz pomiar prędkości” on the dashboard, the plugin sends your site’s public URL to the EyeSite automation backend at https://n8n.bielecki.cloud/webhook/eyesite-lighthouse, which queries the Google PageSpeed Insights API (https://developers.google.com/speed/docs/insights/v5/about) server-side and returns the performance score. It then repeats at most every 6 hours while you open the plugin dashboard. Only the public site URL is sent; no personal data. You can switch it off at any time in the settings. Google’s terms: https://developers.google.com/terms ; privacy: https://policies.google.com/privacy
- Audit and repair requests (only when you click “Zleć naprawę” or a free-audit button): your site URL, site name, administrator e-mail, the type of request, the problem description shown next to the button and the detected consent-mode status / names of tracking tags found on your home page are e-mailed to the plugin author (kontakt@eyesite.pl) using your site’s own mailer and also posted to https://n8n.bielecki.cloud/webhook/eyesite-audit-lead so that we can contact you about the request. Nothing is sent unless you click the button.
- Connection notice (only when you click “Connect”): the plugin author (kontakt@eyesite.pl) receives an e-mail with your site name, site URL and administrator e-mail, sent by your site’s own mailer, so that the service can be set up.
- E-mail delivery test (only when the site is connected to EyeSite): the plugin sends a short test e-mail from your site’s own mailer to probe@eyesite.pl. The message contains only a random token (no site data, no personal data). The plugin then asks https://n8n.bielecki.cloud/webhook/eyesite-mailprobe for the verdict (SPF/DKIM/DMARC result, blacklist status), sending only that token. The test runs when you click the test button on the e-mail card and automatically at most once a day while the site is connected; disconnecting stops it.
- WordPress security status (once a day): the plugin downloads the public list of WordPress releases from WordPress.org at https://api.wordpress.org/core/stable-check/1.0/ and compares it locally with the installed version, to warn you when your WordPress version has publicly known security holes. The request sends nothing about your site (no version, URL or token). This is the same WordPress.org API that WordPress itself uses; terms: https://wordpress.org/about/privacy/
- Known vulnerabilities in plugins and themes (opt-in, off by default): only after you enable “Sprawdzanie znanych luk we wtyczkach i motywach” in the settings, the plugin sends the list of installed plugin and theme slugs with their version numbers to the EyeSite automation backend at https://n8n.bielecki.cloud/webhook/eyesite-vulns once a day (and shortly after an update). The backend matches the list against a copy of the Wordfence Intelligence vulnerability database (https://www.wordfence.com/threat-intel/) and returns the matching records. No site URL, e-mail address, token or personal data is sent, and the list is not stored. Vulnerability data: Wordfence Intelligence, Copyright Defiant Inc., terms: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/
- Domain expiry check (opt-in, off by default): only after you enable “Sprawdzanie daty wygaśnięcia domeny” in the settings, the plugin sends your site’s registrable domain name (e.g. example.com) to the public RDAP service at https://rdap.org once a day and reads the registration expiry date and registrar. Nothing else is sent. RDAP.org terms and privacy: https://about.rdap.org/
AI visibility check (once a day): the plugin reads your own home page and /robots.txt, and requests the home page once more with the user agent string of an AI search bot (OAI-SearchBot) to see whether your server or firewall turns such bots away. These are requests to your own site only; nothing is sent to OpenAI, Anthropic or any other service.
Tracking tag detection (Google Tag Manager, Google Analytics, Meta Pixel, etc.), SSL certificate, SEO, checkout and hardening checks only read your own site (loopback requests to your home page, robots.txt, sitemap, cart and REST endpoints). The plugin does not load, call or send data to these services. The e-mail DNS check (SPF, DKIM, DMARC, MX) uses your server’s normal DNS resolver.
The EyeSite service (eyesite.pl) and its automation backend (n8n.bielecki.cloud) are provided by Bielecki Consulting. Terms of use and privacy policy:
- Terms of service: https://eyesite.pl/regulamin/
- Privacy policy: https://eyesite.pl/polityka-prywatnosci/
Privacy
Visitor data stays on your site. When a front-end error happens (a JavaScript error, a failed contact-form submission) or a WooCommerce cart is abandoned after a technical error, the plugin stores in your site’s own database: the error message, script source and stack trace, the page URL, browser and device type, the user-agent string and a random session identifier. For abandoned carts it also stores the cart total. It does not store IP addresses, form contents, cart contents or customer details, and none of this data is sent to EyeSite or any other service.
Cookie: in those situations only, the browser sets a first-party cookie eyesite_session holding a random identifier, valid for 30 minutes. It is used solely to group error reports from the same visit. It is not set on normal page views, so full-page caching is not affected. Treat it as a functional cookie in your consent banner.
Retention: records are deleted automatically after 60 days, resolved errors after 3 days. Uninstalling the plugin removes its tables and options.
The plugin adds a suggested paragraph to Settings -> Privacy -> Policy guide that you can copy into your privacy policy.
Screenshots

Dashboard view with system monitoring status tiles.

PHP error history.

List of recorded front-end errors with form context.