Likely causes and confidence
How ChangeTrace ranks what probably caused an incident, what the confidence number means, and where it stops.
Within about half an hour of an incident opening, ChangeTrace looks back through the 24 hours before it and scores everything that changed.
What counts as a possible cause
Changes — the things that can cause an incident:
- A plugin updated, activated, deactivated or deleted
- The theme changed
- WordPress core updated
- The PHP version changed
Site-option edits and user-role changes are recognised by the scorer but the plugin does not yet report them, so they will not appear as causes today.
Errors — these are not causes themselves, but they raise a nearby change's score when they cluster right after it:
- PHP errors and fatals
- JavaScript errors
- Failed outbound HTTP requests, and 500s from your own REST API
- Failed EDD payments
A plugin update on its own is weak evidence. A plugin update followed six minutes later by a burst of JavaScript errors is a much stronger story, and scores accordingly.
How the ranking works
The model is plain and inspectable, not a black box. It weighs:
- Timing — how close the change was to the moment things went wrong. Closer scores higher.
- Error clustering — did errors appear right after this change?
- Kind of change — a plugin update is a likelier culprit than a PHP version bump.
- Isolation — one change in the window is more suspicious than one of fifteen.
Candidates below a minimum confidence are dropped entirely rather than padding the list with noise.
What confidence means
It is not a probability
Confidence reflects how strongly the available timing and correlated signals support this hypothesis — not statistical certainty.
85% confidence means the timing and surrounding signals line up unusually well. It does not mean an 85% chance this change caused the drop. A change can score high and be entirely innocent — if you updated three plugins at once, one of them gets the top slot on timing alone.
Why the list is sometimes short, or empty
One cause only. On the Free plan, correlation runs at basic depth — the single best candidate, without the supporting error chains. Paid plans get the full ranked list. Plans and limits →
"No hypotheses yet." Correlation runs every 30 minutes. Wait.
"Not attributed to a site change." An infrastructure outage. ChangeTrace deliberately refuses to blame a plugin for a DNS failure. Why →
Genuinely nothing changed. Sometimes sales drop and nothing on the site moved. That is a real answer, and a useful one — it points you at advertising, payment providers, or the outside world.
How to use a ranked list well
Start at the top, but do not stop there
Scan the whole list for something you recognise.
Rule things out on timing
The window is 24 hours before the incident. A change from three days ago is not in it.
Test the obvious
If a plugin update is top, roll it back on staging and see whether the symptom follows.
Remember what isn't tracked
ChangeTrace sees your WordPress site. It does not see your ad spend, your payment provider's outage, or your courier's website. If nothing on the list fits, look outside.
Observed versus interpreted
The page keeps these visually apart, and it is worth keeping them apart in your head too:
| Observed | Interpreted | |
|---|---|---|
| Panels | Evidence, Correlated sequence, Linked evidence | Most likely cause, Ranked causes, AI explanation |
| Marked with | Green checks | "AI interpretation" badge |
| Means | This happened | This might explain it |
{ }For developers
Window default is 24 hours before the anomaly, taken from details.anomalyAt if present, else
the end of the evaluated day, else opened_at. Depth comes from the org plan —
basic caps the list at one hypothesis and skips supporting-error chains, full is the whole
ranked set. Cause and error event types are the underscore forms
(plugin_updated, theme_changed, php_fatal, js_error, rest_5xx, …), which are the real
contract with the plugin.

