ChangeTrace
Incidents

Likely causes and confidence

How ChangeTrace ranks what probably caused an incident, what the confidence number means, and where it stops.

Within about half an hour of an incident opening, ChangeTrace looks back through the 24 hours before it and scores everything that changed.

What counts as a possible cause

Changes — the things that can cause an incident:

  • A plugin updated, activated, deactivated or deleted
  • The theme changed
  • WordPress core updated
  • The PHP version changed

Site-option edits and user-role changes are recognised by the scorer but the plugin does not yet report them, so they will not appear as causes today.

Errors — these are not causes themselves, but they raise a nearby change's score when they cluster right after it:

  • PHP errors and fatals
  • JavaScript errors
  • Failed outbound HTTP requests, and 500s from your own REST API
  • Failed EDD payments

A plugin update on its own is weak evidence. A plugin update followed six minutes later by a burst of JavaScript errors is a much stronger story, and scores accordingly.

How the ranking works

The model is plain and inspectable, not a black box. It weighs:

  • Timing — how close the change was to the moment things went wrong. Closer scores higher.
  • Error clustering — did errors appear right after this change?
  • Kind of change — a plugin update is a likelier culprit than a PHP version bump.
  • Isolation — one change in the window is more suspicious than one of fifteen.

Candidates below a minimum confidence are dropped entirely rather than padding the list with noise.

What confidence means

It is not a probability

Confidence reflects how strongly the available timing and correlated signals support this hypothesis — not statistical certainty.

85% confidence means the timing and surrounding signals line up unusually well. It does not mean an 85% chance this change caused the drop. A change can score high and be entirely innocent — if you updated three plugins at once, one of them gets the top slot on timing alone.

Why the list is sometimes short, or empty

One cause only. On the Free plan, correlation runs at basic depth — the single best candidate, without the supporting error chains. Paid plans get the full ranked list. Plans and limits →

"No hypotheses yet." Correlation runs every 30 minutes. Wait.

"Not attributed to a site change." An infrastructure outage. ChangeTrace deliberately refuses to blame a plugin for a DNS failure. Why →

Genuinely nothing changed. Sometimes sales drop and nothing on the site moved. That is a real answer, and a useful one — it points you at advertising, payment providers, or the outside world.

How to use a ranked list well

Start at the top, but do not stop there

Scan the whole list for something you recognise.

Rule things out on timing

The window is 24 hours before the incident. A change from three days ago is not in it.

Test the obvious

If a plugin update is top, roll it back on staging and see whether the symptom follows.

Remember what isn't tracked

ChangeTrace sees your WordPress site. It does not see your ad spend, your payment provider's outage, or your courier's website. If nothing on the list fits, look outside.

Observed versus interpreted

The page keeps these visually apart, and it is worth keeping them apart in your head too:

ObservedInterpreted
PanelsEvidence, Correlated sequence, Linked evidenceMost likely cause, Ranked causes, AI explanation
Marked withGreen checks"AI interpretation" badge
MeansThis happenedThis might explain it
{ }For developers

Window default is 24 hours before the anomaly, taken from details.anomalyAt if present, else the end of the evaluated day, else opened_at. Depth comes from the org plan — basic caps the list at one hypothesis and skips supporting-error chains, full is the whole ranked set. Cause and error event types are the underscore forms (plugin_updated, theme_changed, php_fatal, js_error, rest_5xx, …), which are the real contract with the plugin.

On this page