Log High TTFB
Monitors front-end TTFB metrics via the browser and stores slow requests for analysis.
by Mateusz Zadorożny · github.com/mateusz-zadorozny/log-high-ttfb · website
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/mateusz-zadorozny/log-high-ttfb/archive/refs/heads/master.zipReadme
Log High TTFB
Log High TTFB records front-end TTFB directly from the browser and stores the measurements in a custom WordPress table for later analysis. The plugin classifies good (<800 ms), warning (>=800 ms), and slow (>=1800 ms) requests, exposes the data in the WordPress admin, and can send a weekly email digest of the worst pages.
Features
- Measures TTFB in the browser via
PerformanceObserverwith timing fallbacks and posts results through a hardened REST endpoint. - Persists all requests (URL, severity, TTFB, device category, browser, role, Cloudflare country, referrer, cookies/query param keys) inside a dedicated database table created on activation.
- Adds a "TTFB Monitor" admin menu with:
- Logs list table (searchable/filterable) for individual request records.
- Insights dashboard summarising the previous 7 days, including totals, per-page p95 (no query strings) sorted from worst to best, top 50 slow hits, and similarity groupings by URL, query params, and cookies.
- Settings page to enable/disable the weekly digest and configure recipients.
- Schedules a weekly cron event (
log_high_ttfb_weekly_summary) that sends a text email at 08:00 site time with totals and the worst pages by p95 for the prior week. - Includes nonce-based REST protection plus authentication fallbacks for logged-in sessions to avoid false negatives during admin usage.
Installation
- Copy the plugin folder into
wp-content/plugins/log-high-ttfb. - Run
composer installif you want development dependencies (PHPUnit/polyfills). - Activate Log High TTFB from the WordPress Plugins screen. Activation will:
- Create the
{$wpdb->prefix}log_high_ttfbtable viadbDelta(). - Schedule the
log_high_ttfb_weekly_summarycron hook for the next 08:00 run.
- Create the
Configuration & Usage
- Visit TTFB Monitor → Settings to enable the weekly digest and enter one or more comma-separated recipient emails. Saving the setting will schedule/clear the cron event accordingly.
- Use TTFB Monitor → Logs to review captured requests. Filter by severity using the dropdown or search by URL.
- Use TTFB Monitor → Insights for a last-7-days overview with per-page p95 (worst first) plus similarity groupings that mirror the weekly email.
- The front-end script is automatically enqueued on non-admin views. It sends exactly one payload per page view.
REST Endpoint
- Namespace:
log-high-ttfb/v1 - Route:
POST /wp-json/log-high-ttfb/v1/log - Required headers:
Content-Type: application/jsonX-Log-High-Ttfb-Nonce: plugin nonce generated server-side.X-WP-Nonce: standardwp_restnonce for authenticated users (automatically provided by the plugin script).
- Sample payload:
{
"ttfb": 2010,
"url": "https://example.com/page/",
"timestamp": "2025-09-17T16:12:20.546Z",
"queryParamKeys": ["utm_source", "utm_medium"],
"cookieNames": ["woocommerce_cart_hash", "wordpress_logged_in_"],
"deviceType": "desktop",
"browser": "Chrome",
"referrer": "https://example.com/prev/"
}
The REST controller will classify each entry as good (<800 ms), warning (>=800 ms), or bad (>=1800 ms) and enrich it with role, country (Cloudflare CF-IPCountry), and timestamps before saving.
Cron & Email Summary
- Hook:
log_high_ttfb_weekly_summary - Scheduled automatically on activation (next 08:00 site time). You can inspect with:
wp cron event list | grep log_high_ttfb_weekly_summary
- Manual trigger for testing:
wp cron event run log_high_ttfb_weekly_summary - Email includes:
- Counts of good, warning, and slow requests from the prior week.
- Per-page p95 and p50 (query strings removed), sorted from worst to best, capped at 15 rows.
Database Schema
Created table wp_log_high_ttfb (prefix varies) stores:
| Column | Type | Notes |
|---|---|---|
id |
BIGINT UNSIGNED PK | Auto increment |
recorded_at |
DATETIME | Stored in UTC |
ttfb_ms |
MEDIUMINT UNSIGNED | Rounded milliseconds |
category |
VARCHAR(20) | good, warning, or bad |
url |
TEXT | Fully-qualified URL |
query_params |
TEXT (JSON) | Unique query param names |
cookies |
TEXT (JSON) | Unique cookie names |
user_role |
VARCHAR(100) | guest for unauthenticated visitors |
country |
VARCHAR(10) | ISO code (when provided by Cloudflare) |
device_type |
VARCHAR(20) | desktop, mobile, or tablet |
browser |
VARCHAR(100) | Parsed browser label |
referrer |
TEXT | Referrer URL (if present) |
Development Notes
- PHP lint:
php -l log-high-ttfb.php includes/*.php - JS is plain ES5 to maximise compatibility; rebuild is not required after edits—just clear caches.
- PHPUnit config (
phpunit.xml.dist) and Yoast polyfills are included for future automated tests, though no suites ship by default. - When testing in browsers, perform a hard refresh to ensure the latest nonce-bearing script is loaded.
Troubleshooting
- REST 403 Invalid security token: confirm both nonces are present. Logged-in users receive a fallback that checks
is_user_logged_in(), but cached pages may need a refresh to pick up new scripts. - Cron missing: toggle the email setting off/on to reschedule, or run
wp cron event schedule log_high_ttfb_weekly_summary now weeklymanually. - Activation failure: ensure the WordPress REST API base classes are available (WP 5.0+ recommended).
License
Distributed under the same terms as WordPress (GPLv2 or later).