v1.1.8
2 October 2026

Every Speed Doctor action now checks its own security token and your permission. Scans measure exactly as before.

  • Request values are read through WordPress's own sanitizers.
  • The measurement loader accepts a scan token only for the exact page it was issued for, and refuses any request whose address it cannot read whole.
  • Uninstalling one copy of the plugin while another copy is active no longer stops with an error.
v1.1.7
29 September 2026

Multisite: only network administrators measure network-activated plugins, and slow pages get a timeout that fits them.

What's new in 1.1.7

  • Multisite: network-activated plugins are measured only by a network administrator, a scheduled scan or a WP-CLI scan. A site administrator's diagnosis covers the site's own plugins, so it can never load the site without a plugin the network requires, and never lists what the network runs.
  • Once a page's own time is known, each further request to it may take up to three times that (between 10 and 30 seconds), so a slow page no longer holds a diagnosis for half a minute per request.
v1.1.6
29 September 2026

Fewer invented results on noisy hosts, a broken page no longer blames every plugin, and the loader refreshes itself after updates.

What's new in 1.1.6

  • Verdicts are more honest on noisy hosts: a difference smaller than the server's own noise is never reported as a cost, a result needs at least four timings on each side, and a plugin that looks costly but is not yet certain gets extra timings before the verdict.
  • A page that fails with every plugin loaded no longer blames every plugin, and a page cache, a rate limit or a single hiccup no longer condemns a plugin or drops a page.
  • The measurement loader refreshes itself after a plugin update, a loader you removed stays removed, and measurement pages are never stored by a page cache.
  • Signed measurement requests are bound to the exact address and query, accept GET only, expire within five minutes, and are signed with the site's security keys as well as the stored secret.
  • Sites served over https with an http stored address, or with a separate WordPress address, are measured from WP-CLI and scheduled scans again.
  • Plugins that depend on several others are grouped with all of them; the asset audit counts render-blocking assets more accurately and sizes symlinked folders.
  • The Assets and Database tabs say when something could not be read instead of showing a healthy zero, and the change column compares wp-admin as well.
  • A diagnosis that cannot be saved is reported as an error, two cannot start at once, and uninstall deletes data only when the opt-in really says yes.
v1.1.5
25 September 2026

More accurate results when a plugin breaks a page, and network plugins are measured.

What's new in 1.1.5

  • A page failure is blamed on the plugin that was left out, so one plugin no longer spoils the results for others.
  • A missing loader stops the scan with a clear reason instead of reporting All clear.
  • Network-activated plugins are measured on multisite.
  • The Database tab attributes more options to the plugins that own them.
  • Uninstall runs per site on multisite.
v1.1.4
25 September 2026

More honest verdicts, and scans you can resume or cancel.

What's new in 1.1.4

  • Results the timings can't settle are shown as Inconclusive instead of low impact, and a page that wasn't measured is named.
  • Plugins that couldn't be measured are retried and reported, not called harmless.
  • Scans can be resumed after a reload and cancelled.
  • Only assets loaded on your pages count toward the badge.
  • Some earlier verdicts may change when viewed after the update.
v1.1.3
24 September 2026

Translation-ready throughout.

What's new in 1.1.3

  • Every screen, email and alert is now translatable, so community translations from translate.wordpress.org cover the whole plugin. Counts use proper plural forms, and numbers and dates follow your site's language.
  • Scan dates and owner labels follow your site's language.
v1.1.2
24 September 2026

Dragon Speed Doctor Pro is now available: scheduled and after-update scans, a 12-month history and confirmed slowdown alerts.

  • New: a pointer to Dragon Speed Doctor Pro. An "Upgrade to Pro" link on the Plugins screen, a one-line pointer at the foot of the Speed Doctor screen, and a single dismissible note after a few diagnoses. All three disappear when Pro is active.
  • Nothing in the free plugin is locked, limited or changed. Diagnoses work exactly as before.
v1.1.1
24 September 2026

A small reliability update: no more PHP warnings when a diagnosis could not measure wp-admin.

  • Fixed: if wp-admin kept failing to load during a diagnosis, working out the results logged PHP warnings. An unmeasured page is now simply treated as inconclusive.
  • Fixed: the measurement loader could crash a page if another plugin asked it for measurement details on an ordinary request. It now answers "not a measurement request".
  • Changed: the results summary no longer shows a "0 low impact" badge.

Nothing to do after updating: the measurement loader refreshes itself on your next diagnosis.

v1.1.0
24 September 2026

Sites whose homepage redirects can now be diagnosed, and every diagnosis records what it measured.

  • Fixed: homepages that redirect. If your homepage sends visitors on to another page on the same site (a language version such as /en/, or a landing page), the preflight check used to fail with a message about firewalls. The doctor now follows up to three redirects within your site and measures the page they lead to.
  • Clearer messages when it can't measure. A homepage that redirects to a different site, redirects in a loop, or leads to a page that errors now gets a message that says exactly that.
  • Diagnoses remember more. Each one records the plugin, theme and WordPress versions it measured and your site's overall response time per page, ready for comparing diagnoses over time.

After updating, open Tools > Speed Doctor and press Update loader once (scans from WP-CLI do this automatically). Nothing else to do: settings and past diagnoses are kept.

For developers: new dragonspeeddoctor_tool_plugins filter and dragonspeeddoctor_verdict_details and dragonspeeddoctor_signed_request actions; dragonspeeddoctor_page_set and dragonspeeddoctor_scan_complete receive extra arguments. Details in the docs.

v1.0.7
23 September 2026

A clearer Doctor screen: install the loader, then run a diagnosis - two numbered steps, with your latest results summarised at the top.

What's new for you:

  • One guided card instead of two boxes. Step 1 installs the measurement loader (the scan needs it), step 2 runs the diagnosis and unlocks as soon as the loader is in place. Installing or removing the loader happens in place, with no page reload.
  • Your latest diagnosis at a glance. The Doctor tab now opens with the impact counts and the plugins that need attention, and Results starts with the same summary plus a Run again button.
  • The plugins worth acting on come first. On Results, low-impact plugins are folded into a collapsible section.
  • High ratings now explain themselves. When a plugin is rated High because of the scripts and styles it ships rather than its timing, the verdict now says how much it ships and how much of it is render-blocking.
  • Database tab: the autoload total is marked Healthy or Above 800KB.
  • Progress shows elapsed time, and your browser warns you before you leave the page mid-diagnosis.

Fixes:

  • A diagnosis interrupted by a dropped connection now picks up where it left off when you click Run diagnosis again, instead of being refused as "already running".
  • A loader install or removal that failed is now reported, with the reason.
  • If a request failed during a diagnosis, the Run diagnosis button stayed disabled until you reloaded the page.
  • An out-of-date loader is shown as Out of date with an Update button, including when the preflight check is the first to notice.
  • The Dragon Core mark was missing from the page title.

No settings or stored data change. Update and carry on - nothing to do afterwards.

v1.0.6
18 September 2026

Nothing changes in how the doctor works - this release adds an optional review request and tidies the WordPress.org listing.

Dragon Speed Doctor is now listed on WordPress.org, so this release adds two small things around that:

  • A review request, once you have results. After the doctor has finished a diagnosis, it may show a single notice on its own Tools screen asking for a WordPress.org review. It only appears on that screen, never anywhere else in wp-admin, and "No thanks" stops it for good ("Maybe later" hides it for a month).
  • Listing title and tags updated so people searching for what this plugin does can actually find it.

No changes to scanning, timings, verdicts, the asset audit or any setting. Existing sites can update with nothing to do afterwards.

v1.0.5
17 September 2026

A diagnosis no longer fails before it starts when two active plugins declare each other as a requirement.

What's fixed in 1.0.5

  • Circular plugin requirements are measured as one group. If plugin A's Requires Plugins header names plugin B and B's names A (or a longer loop), the dependency grouping walked that loop until PHP ran out of memory and the diagnosis could not start. The chain is now walked without recursion, and every plugin in such a loop is measured together, the same way an add-on is measured with its parent.
  • Readme wording tidied.

No settings changes.

v1.0.4
12 September 2026

Asset sizes and plugin attribution are now correct on subdirectory, relocated wp-content and mixed-scheme sites, and the loopback base works on subdirectory installs.

What's fixed in 1.0.4

  • Asset sizes are no longer 0 for local files the doctor could not find. A script or style with a scheme-relative (//), http:// or document-relative address, a percent-encoded file name, a subdirectory install, or a wp-content folder outside the WordPress directory all reported 0 bytes. Every address is now resolved against the page it was found on, then located with the site path stripped and wp-content resolved to its real directory. Only files inside the WordPress and wp-content folders are ever read.
  • Plugins get credit for their own scripts. The asset table attributed a plugin's assets to "core/other" when the address differed from the site's wp-content URL in scheme, letter case or a www. prefix, or used ../ segments, which understated that plugin's page weight. Attribution now matches on the resolved host and path.
  • DRAGONSPEEDDOCTOR_LOOPBACK_BASE works on subdirectory installs. A base with a path, such as http://app-container/wp, was prefixed onto every request and produced /wp/wp/... 404s whose timings were recorded as page performance. The base is now used as an origin only (scheme, host, port); each request keeps its own path.
  • The loopback base is validated more strictly. IP literals must be a full dotted IPv4 or bracketed IPv6 address in a loopback, private or link-local range; integer, shorthand and public IPv6 forms are refused. A hostname is accepted only when every address it resolves to is in such a range, and a name that does not resolve is refused. Signed admin probes can never leave your infrastructure.
  • Setup is verified, retried and reported. Activation recorded the install as complete even when the scans table or the signing secret had not been stored. Both are now checked first; an incomplete install is retried on each admin page load and shown as an admin notice until it succeeds. Existing sites are checked once after updating.
  • A diagnosis that cannot be saved is reported as an error. If the scan could not be started, its progress saved or its results written, it appeared to start or finish normally. It now stops with a clear message.

No settings changes. If you use the loopback base with a path, it keeps working; the path is simply ignored.

v1.0.3
8 September 2026

Wording tidied across the readme and the plugin screens for clarity. No functional changes.

v1.0.2
30 August 2026

Housekeeping release: the readme changelog now covers 1.0.1, and code comments were tidied. No functional change.

= 1.0.2 =

  • Readme: changelog and upgrade notice now cover 1.0.1, which shipped without entries.
  • Code comments reworded to describe the filter hooks they document.
v1.0.1
23 August 2026

Safety fix: a measurement run can no longer accidentally leave other plugins deactivated, and stalled scans self-recover.

= 1.0.1 =

  • Safety: during a measurement request the active-plugins list can no longer be written back to the database, so a probe can never deactivate your other plugins.
  • Reliability: an abandoned scan is reclaimed after 15 minutes so it cannot block future scans; the measurement loader is refreshed before each run.
v1.0.0
22 August 2026

Find out which plugins are slowing your WordPress site — measured, not guessed.

Dragon Speed Doctor is the modern successor to the long-gone P3 Plugin Performance Profiler. Press one button and it times your site with each plugin briefly held out of internal test requests, then tells you in plain English what each one costs — on the front end and in wp-admin — alongside a per-plugin script and stylesheet weight audit and database-bloat signals. Visitors are never affected; only the doctor's own signed internal requests are measured.

  • Per-plugin timing attribution with honest confidence ranges (and an honest "inconclusive" when the server is too noisy).
  • Asset audit: what every plugin ships to your pages, with render-blocking flags.
  • Database signals: autoloaded-option weight and probable owners.
  • Plain-English verdicts with Low / Medium / High badges, plus before/after comparison across scans.
  • WP-CLI: wp speed-doctor scan. No external services — everything runs on your own server.