Plugin Changelog

Site Agent

WordPress MCP tools that connect an AI client to your site, with staged edits and per-password limits.

Latest
0.2.0
Releases
6
Updated

Showing 1–6 of 6 releases

Stable

Site Agent 0.2.0

Makes code changes recoverable, errors actionable and going live explicit, and adds the publishing and file tools agents were missing.

  • Changes 7
Read full notesHide notes

Makes code changes recoverable, errors actionable and going live explicit, and adds the publishing and file tools agents were missing.

  • PHP file writes, moves and deletes are syntax- and compile-checked, then the site is loaded with WordPress's edit-scrape check and a change that causes a fatal error is reverted.
  • Tool errors include the real message and line. PHP execution rejects exit and die and reports wp_die(), indirect exits and fatal errors as tool errors.
  • Edits to published, private or scheduled posts are saved as autosaves for review unless a status is passed. Scheduling requires a future date. Titles keep tag-like text and percent sequences.
  • Content writes accept terms, featured images, slugs, publish dates and SEO meta. New tools list terms, import media with alt text, update media, and create, delete or move source files; must-use plugins are reachable and credential files are blocked by name.
  • Each Application Password can be limited to some tool groups. The audit history records targets, the password used and denied calls. Diagnostics and a Test connection button explain connection failures.
  • URL credentials are removed before dispatch, WP-CLI @aliases are rejected, and SITE_AGENT_ALLOW_EXECUTION=false blocks source editing, PHP and WP-CLI.
  • Updates use WordPress's Update URI hook, cache failed checks, and keep validated metadata when the store is unreachable during an upgrade. Signed-package verification ships without an enforcing key.

Validation: 59 WordPress integration tests / 383 assertions on PHP 8.3 and 8.5 locally and on the CI matrix, 9 converter tests, PHP syntax and coding standards, runtime and translation freshness, an HTTP MCP smoke test on disposable WordPress including a real fatal-change rollback, and both release ZIPs.

The companion archive is separate from the installable WordPress ZIP. Site Agent does not implement OAuth.

Stable

Site Agent 0.1.5

Adds inline documentation to Tools > Site Agent for connecting with an authenticated MCP URL. The guide covers enabling URL authentication, creating a dedicated Application Password, generating and copying the endpoint, credential…

Read full notesHide notes

Adds inline documentation to Tools > Site Agent for connecting with an authenticated MCP URL. The guide covers enabling URL authentication, creating a dedicated Application Password, generating and copying the endpoint, credential privacy, revocation, and client compatibility. It shows a site-specific placeholder URL without displaying real credentials.

Validation: 33 WordPress integration tests / 144 assertions, 7 converter tests, PHP syntax and coding standards, runtime and translation freshness, disposable WordPress rendering, and both release ZIPs.

The companion archive is separate from the installable WordPress ZIP. Site Agent does not implement OAuth. ChatGPT web compatibility with credential-bearing URLs has not been verified.

Stable

Site Agent 0.1.4

Adds opt-in URL authentication to the Site Agent MCP endpoint for compatible clients that cannot send custom Authorization headers.

Read full notesHide notes

Adds opt-in URL authentication to the Site Agent MCP endpoint for compatible clients that cannot send custom Authorization headers.

Enable URL authentication under Tools > Site Agent, save, then use the converter's new Copy authenticated endpoint button. The URL's auth query parameter contains Base64-encoded username and Application Password credentials. Standard and URL-safe Base64 are accepted; the copy action handles URL encoding and existing plain-permalink query parameters.

Authentication uses WordPress's native Application Password validator on every request. Administrator and enabled-tool checks remain enforced; account passwords, invalid/revoked credentials, conflicting identities and unrelated REST routes are rejected. The mode defaults off, respects emergency disable and HTTPS requirements, and marks MCP responses private/no-store.

Base64 is reversible. Credential-bearing URLs may appear in browser history, proxy/server logs or client configuration. Use a dedicated, revocable Application Password and keep the complete URL private. The client must support Streamable HTTP/MCP and preserve the query on each request. This is not an OAuth implementation or a guarantee of compatibility with every client.

Validation: 33 WordPress integration tests / 144 assertions, 7 converter tests, real headerless local HTTP initialization and tool discovery, route isolation, invalid-credential rejection, cache headers, session termination, coding standards and package checks.

Stable

Site Agent 0.1.3

Adds the optional Site Agent companion package, with WordPress workflow instructions, the approved icon and a credential-free MCP connection. The companion covers site inspection, raw-content audits, draft preparation, hash-checked edits…

  • Changes 2
Read full notesHide notes

Adds the optional Site Agent companion package, with WordPress workflow instructions, the approved icon and a credential-free MCP connection. The companion covers site inspection, raw-content audits, draft preparation, hash-checked edits and the developer tools enabled on the connected WordPress site.

Two separate ZIPs are provided:

  • site-agent-0.1.3.zip: installable WordPress plugin, also delivered through FluentCart automatic updates.
  • site-agent-companion-0.1.3.zip: companion package for compatible ChatGPT/Codex hosts. Do not upload this ZIP to WordPress.

Both companion manifests now use version 0.1.3. The compatibility manifest points to the included mcp.json; the standalone ZIP includes the complete GPL license. Packaging validation is part of CI.

Authentication still requires a compatible private connection using a WordPress Application Password and Basic Authorization header. This release does not add OAuth or claim authenticated ChatGPT web connectivity. Existing WordPress functionality, runtime dependencies and access controls are unchanged.

Validation: 24 WordPress integration tests / 106 assertions, 6 converter tests, PHP/JavaScript syntax, coding standards, translation and generated-runtime freshness, companion metadata/reference checks and ZIP verification.

Stable

Site Agent 0.1.2

Adds a credential converter beside the MCP connection instructions. Enter your WordPress username and a dedicated Application Password, then copy the Base64 token, full Basic Authorization value or complete MCP configuration.

Read full notesHide notes

Adds a credential converter beside the MCP connection instructions. Enter your WordPress username and a dedicated Application Password, then copy the Base64 token, full Basic Authorization value or complete MCP configuration.

Conversion stays in the browser. The helper accepts grouped Application Passwords and UTF-8 usernames, masks generated tokens and clears sensitive values when inputs change or the page is left. Site Agent does not submit or store converter credentials.

Validation: 24 WordPress integration tests with 106 assertions; 6 converter tests; JavaScript syntax, WordPress coding standards, PHP lint, translation freshness and package checks. Rendered-browser checks covered exact encoding, masking, copy controls and clearing. The official MCP runtime pin and access settings are unchanged.

Stable

Site Agent 0.1.1

Site Agent connects MCP-compatible clients directly to WordPress, with ten named tools for content, source inspection, source editing, PHP execution and foreground WP-CLI.

Read full notesHide notes

Site Agent connects MCP-compatible clients directly to WordPress, with ten named tools for content, source inspection, source editing, PHP execution and foreground WP-CLI.

Access starts disabled. Tool groups are independent opt-ins; developer execution is full-privilege access and is not sandboxed.

This public release adds free FluentCart update-license activation, encrypted site-bound credentials, protected package downloads, fresh download URLs for single/bulk upgrades, and extracted plugin identity checks. Licensing controls automatic updates only; all functionality remains available without activation.

The bundled official WordPress MCP Adapter is the upcoming 0.7.0 prerelease at a pinned source commit, with PHP MCP Schema 0.2.0. No Novamira application code, assets or dependencies are included.

Requires WordPress 6.9+ and PHP 8.0+. PHP 8.0, 8.3 and 8.5 CI passed, including 24 integration tests and 106 assertions. Use the complete release ZIP below; it includes the scoped official runtime.

Product and free update license: https://gauravtiwari.org/product/site-agent/