Basicrum is a privacy-first Real User Monitoring integration for WordPress. It loads the bundled Boomerang library, tags WordPress and WooCommerce page types, and sends performance beacons to a configured hosted or self-hosted Basicrum collector.
The installable plugin lives in plugins/basicrum/. Build release artifacts through the repository tooling instead of zipping the source directory directly.
- New installations require an external consent decision before monitoring by default.
- Immediate monitoring remains an explicit administrator choice.
- Query-string redaction is available but disabled by default.
- Basicrum contributes editable disclosure text to the WordPress Privacy Policy Guide.
- Basicrum does not display a consent popup, choose a legal basis, or make a site compliant by itself.
The complete webmaster-facing behavior and consent instructions live in the WordPress plugin readme. Privacy review evidence and unresolved decisions are tracked under docs/audits/.
| Path | Purpose |
|---|---|
plugins/basicrum/ |
Installable plugin source |
tools/ |
Setup, test, and release scripts |
docker/ |
Local WordPress and WooCommerce environments |
tests/javascript/ |
Browser tests for loaders, consent adapters, and settings |
examples/integrations/ |
Consent-tool integration examples |
docs/audits/ |
Privacy and operator-experience audit records |
docs/acknowledgments.md |
External ideas and references that informed the implementation |
wordpress-org-assets/ |
WordPress.org directory artwork |
.agents/skills/ |
Repeatable Basicrum development workflows for coding agents |
Docker, Docker Compose, and Make are required. From the repository root:
cp .env.example .env
make upWordPress is available at http://localhost:9080/. The local administrator credentials are admin / basicrum-dev-password. Use make down to stop the stack without deleting its data, or make clean to reset it.
Run make help for every available command. Common checks are:
make lint
make analyse
make unit
make js-test
make package-smokeSee AGENTS.md for repository invariants, the complete check suite, and the project-specific skills used to change privacy, settings, consent, page-type detection, CI, and releases.
make package creates release/basicrum.zip and its SHA-256 checksum from a temporary production Composer install. make package-smoke installs that ZIP into clean WordPress and checks activation, the administration page, frontend loading, and PHP logs.
The plugin header version, BASICRUM_VERSION, WordPress Stable tag, top changelog version, and v<version> release tag must match.
To publish a stable release, push its version tag after the required checks pass:
git tag -a vX.Y.Z -m "Basicrum vX.Y.Z"
git push origin vX.Y.ZThe tag workflow verifies the version, runs the release tests, builds and smoke-tests the installable ZIP, and only then creates the GitHub Release with basicrum.zip and basicrum.zip.sha256. Do not create the GitHub Release or upload the ZIP manually.
Read CONTRIBUTING.md before opening a pull request. Report suspected vulnerabilities privately according to SECURITY.md, not through a public issue.
Basicrum-owned code is available under the GNU General Public License version 2 or later. Bundled third-party software retains its upstream license; see the plugin's third-party notices.
Thank you to everyone who contributes to Basicrum. This grid is generated from GitHub's contributor data.