=== PressConduit ===
Contributors: pcdesigns
Tags: mcp, ai, divi, bricks, wordpress, claude, chatgpt
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 0.30.5
License: GPLv2 or later

The conduit between AI assistants and your WordPress site.

== Description ==

PressConduit connects MCP-compatible AI assistants to a WordPress site that
uses Divi or Bricks Builder. It includes relay pairing, bearer-token auth, tool
registry, audit log, snapshots, live reload, updates, WordPress tools, media
tools, file tools, admin tools, and WooCommerce tools.

PressConduit detects the active builder and exposes only that builder's tool
surface:

* Divi sites get the Divi-native tool surface from Divi Conduit.
* `bricks_status` — detect Bricks and report available Bricks capabilities.
* `bricks_docs` — curated Bricks Builder documentation with optional relay
  read mode for allowlisted Bricks docs URLs.

Future builder-native write tools should stay builder-specific and should use the
official builder documentation before mutating builder data.

== Not affiliated with Divi or Bricks ==

Divi and Bricks are trademarks of their respective owners. PressConduit is an
independent product by PC Designs.

== Changelog ==

= 0.31.17 - 2026-09-28 =
* New: the site now tells your PressConduit dashboard how it is doing, instead of the dashboard having to ask. Every 15 minutes, and the moment something changes (a plugin or theme updated, activated or switched, WordPress updated, or a new update appears), the site sends a small status report: WordPress, PHP and theme versions, plugin and theme names and versions, which updates are waiting, and administrator usernames and emails. Nothing about your content, orders or customers is sent, and it never receives commands this way. The Updates page in the dashboard reads these reports, so new updates and problems show up within minutes, and a site that stops reporting is flagged. A site owner can switch it off with the pcd_pc_heartbeat_enabled filter. It also asks WordPress to re-check for updates every 10 minutes, keeping premium plugins' updates (Divi and others) that WordPress.org does not know about.

= 0.31.16 - 2026-09-25 =
* New: one-click login from your PressConduit dashboard. Open a site there and press "Log in to wp-admin". The site hands back a link that works once and expires in 60 seconds, then signs in the administrator PressConduit was paired with and lands in wp-admin. It is a private route your account's connection can use, not a tool, so an AI assistant can never make a login link. It can be switched off on a site with the pcd_pc_allow_one_click filter.
* New: the site page in your dashboard can now show which themes have an update, and update them. New tool: wp_theme_update (previews first, updates only when confirmed). wp_theme_list now includes update_available for each theme.
* New: wp_site_info now reports core_update, the newer WordPress version WordPress itself says is available (or nothing when the site is current), so the dashboard's "WordPress is behind" note comes from the site instead of a guess.

= 0.31.15 - 2026-09-24 =
* New: Fluent Forms tools (15): forms, one form in full, where a form is used, spam-protection and integrations audits, entry counts (no personal data), global settings, and (each backs up first) notification, confirmation, field update and add, form create (draft), duplicate, publish or unpublish. New: FluentCRM tools (15): status and health, settings (no secrets), lists, tags, custom fields, campaigns, automations, masked contact lookup and search, list and tag counts, integrations, and create list, create tag, rename segment and switch an automation on or off (publishing one with an email step needs an extra confirmation). Never sends email or changes a contact. New: GiveWP tools (15): status, health check, forms, campaigns, donation and recurring totals (aggregates only), email settings, gateway and pages status without keys, and update, create (draft), publish or unpublish and duplicate a donation form. Never touches donations, donors or gateway settings. New: Eventin tools (15): status, events, health check, schedules, speakers (names only), attendee counts, settings without keys, and create (draft), update, tickets, duplicate, publish or unpublish and schedule update. New: SearchWP tools (10): status, engine, test search and explain (no logging), stats, live search settings, weights, add a searchable field, synonyms, and rebuild the index (heavy, double confirmation). New: security and admin plugin status (10): one combined overview plus Patchstack, Sucuri, WP 2FA (counts), roles, Admin Menu Editor, WP Umbrella and SiteGround status, and SiteGround security and cache toggles that check the front end after the change.
* Change: the WooCommerce tools were rebuilt after their first test on a real store. Removed: woo_order_refund (it recorded a refund without returning any money) and woo_customer_get (personal data). Fixed: woo_coupon_list (it called a function WooCommerce does not have), woo_product_list (on_sale and category by id), order date ranges, woo_stock_update, woo_sales_report and duplicate-SKU crashes. Safer: order details and lists no longer return customer names, emails or addresses unless the owner turns that on; changing an order's status previews first, refuses "refunded", and sends no customer email; notes are private only; shipping edits are limited to core methods (Flexible Shipping and other add-ons are never touched); coupon and product writes validate their input, default to draft, and need confirmation. Undo now works for products, coupons and shipping zones and methods. New: woo_health_check, woo_hpos_status, woo_order_counts, woo_low_stock_report, woo_product_audit, woo_coupon_audit, and woo_bulk_price_update, woo_bulk_stock_update and woo_bulk_product_status (preview first, apply only with the preview token, undoable).
* Fix: the generic post tools refuse WooCommerce orders (they hold customer data and live in custom tables). Every tool call is now wrapped so an error in a plugin becomes a clean tool error instead of crashing the request. The file reader and file search refuse credential and backup files (Wordfence config and logs, .env and key files, SQL dumps, archives).
* Fix: the generic option reader no longer returns secrets. Whole credential options (WP Umbrella's, GiveWP's and Eventin's settings) are blocked, names containing licence, webhook, stripe or paypal are blocked, and any nested value whose key looks like a secret, token, password, API key or licence is shown as [redacted].
* Fix: the generic post-meta tool refuses to overwrite structured data (serialized arrays) with plain text, which corrupted Eventin's tickets and schedules.
* New: undo for plugin database tables (Fluent Forms, FluentCRM, Give, Eventin, SearchWP rows), and plugins now clear their caches after an undo.

= 0.31.14 - 2026-09-24 =
* Change: "Allow file management" is now on by default. It stays off only where an administrator has switched it off in Settings.
* Change: the license key box is gone from Settings. Plans now come from your PressConduit account (sign in, add the site, the plan applies), so the page shows "Your plan" with your current plan and an "Open my account" button, "View plans" now goes to pressconduit.com/pricing, and the admin notice for unlicensed sites points to the account instead of asking for a key.

= 0.31.13 - 2026-09-24 =
* New: Bricks Builder tools (about 80 in total). Styling: global classes (list, read, create, update, delete, batch, categories, apply to elements, pseudo classes), theme styles (read, write with the conditions Bricks needs, which style applies to a page), colour palette with shades, design variables (rewritten: batch, rename, name and value checks), a brand-kit tool that seeds palette, type scale and spacing scale in one call, breakpoints, style manager, custom fonts with the font cache Bricks reads, and CSS status and rebuild. Structure: templates with display conditions, which template applies where, template settings, duplicate, trash, export and import (never overwrites the site palette), components (create, update and delete with digest and usage checks), page settings, turning Bricks on for a page or post type, header and footer switches, sidebars, saved queries, and the element manager. Dynamic: a list of the dynamic tags a site really has, a preview, a linter, query types, single-element edits, Bricks settings and maintenance mode (secrets and code settings never returned or written), forms (list, read submissions, configure with safety checks), interactions, popups, element conditions, a permissions audit and Bricks' own abilities status. Every write backs up first and undoes with pcd_snapshot_restore.
* Fix: bricks_page_write now checks element names, setting keys, class ids, dynamic tags and breakpoint suffixes, refuses code and script keys for users without unfiltered_html, never keeps or writes PHP or signatures, and refuses post types Bricks is not enabled on (bricks_page_enable turns it on). bricks_variables_write no longer writes unchecked names or values into the site CSS.
* Fix: undoing a change to a post meta value (page content, popup settings) no longer loses backslashes in CSS or JSON.
* New: bricks_build_guide, a Bricks playbook by topic (workflow, design system, structure with exact setting keys, responsive, templates, HTML to Bricks, sitemap, dynamic, safety, traps, checklist), written from a full site build.
* Fix: undoing a change to a Bricks option that did not exist before now deletes it instead of leaving an empty list (which had switched off Bricks' default hover styles).
* New undo type that restores only the specific Bricks settings that were changed, so licence and API keys are never copied into a backup.

= 0.31.12 - 2026-09-24 =
* New: Astra theme tools (36). Status; read, change, reset and look up the default of any Astra setting (arrays merge, unknown keys and bad colors are refused); the global palette (Astra keeps it in two places, both are written and checked against the front end); typography with a font-name check; per-page overrides (container, sidebar, hide title/header/footer, transparent header) for one page, many pages (dry run by default, capped at 100) or cleared, with Elementor's copy updated too; get and set pairs for layout, buttons, site title and logo, blog, breadcrumbs, scroll-to-top and transparent header; the header and footer builder (read the grids, change zones with a before/after preview, move one component, change one component's settings); the CSS Astra really outputs; and read-only lists for Astra Pro Custom Layouts, Pro modules and Elementor Header/Footer templates. Every write backs up first and undoes with pcd_snapshot_restore (per-page backups use a new restore type for Astra's page keys).

= 0.31.11 - 2026-09-24 =
* New: SureCart tools. SureCart keeps products, orders, customers, subscriptions, coupons and licenses in its own cloud, so the tools call SureCart's own PHP models. Read: store info (and whether this site really owns the connected store), products (with the linked WordPress post id and sync state), prices, orders, customers, subscriptions, licenses (keys masked) and activations, a license lookup by customer email or site URL, coupons, refunds, a sales report, processor and webhook status, integrations, a shortcode helper (which id each shortcode wants), sync status, sync one product and cache clear. Change, with a guard that refuses every write unless the connected SureCart account belongs to this site (a cloned or staging copy shares the live store): create and update products, add and change prices (confirm_id required), coupons and promotion codes (a limit or expiry is required), archive, update a customer, cancel a subscription and revoke or reinstate a license (confirm_id required). Each write saves a restore payload that pcd_snapshot_restore replays against SureCart. Also a bridge to SureCart's own built-in abilities. Never built: creating orders or refunds, charging, payouts, deleting customers, payment credentials.

= 0.31.10 - 2026-09-23 =
* New: the rest of the Rank Math tools (39). Read and export: seo_gaps_list (missing or duplicate titles and descriptions, noindex, too-long text across many posts), seo_scores_list, seo_head_get (the tags a page really outputs), title_preview, settings_export, identity_get, robots_txt_get, llms_txt_get, sitemap_status_get, indexnow_log_get, link_report_get, post_links_get, roles_get, import_detect, redirection_list and redirection_export, 404_list, analytics_get, site_audit_run, setup_guide, ability_list. Change (each backs up first and can be undone with pcd_snapshot_restore): titles_settings_set, general_settings_set, sitemap_settings_set (clears the sitemap cache), identity_set, settings_import (merge with a dry run by default), module_set, robots_txt_set, llms_txt_set, redirection_add, redirection_update, redirection_delete (trash by default), 404_clear, post_seo_bulk_set, roles_set, tools_run (safe actions only), indexnow_submit, sitemap_cache_clear, ability_run. Redirections, the 404 monitor, link counter, instant indexing, role manager and llms.txt need their Rank Math module on; the tools say so and rank_math_module_set turns it on. New undo types so redirection and 404-log changes can be restored.

= 0.31.9 - 2026-09-23 =
* New: Yoast SEO tools (20). Status; read and change a post's SEO (title, description, focus keyphrase, canonical, noindex and other robots, breadcrumb title, cornerstone, schema types, social); read and change a category or tag's SEO through Yoast's own class (it stores all of them in one option and resets any field you leave out, so the tool reads, merges and writes); read Yoast's site-wide settings with tokens and keys left out; change them from a safe list of keys with the sitemap cache cleared and rewrite rules flushed where needed; an SEO audit across many posts (missing or duplicate titles and descriptions, noindex, too-long titles); a bulk write of up to 20 posts; the tags a page actually outputs; Yoast's cached-data (indexables) status and rebuild; sitemap status and cache clear; llms.txt; stored scores; site identity and social profiles; and (Yoast SEO Premium only, experimental) redirect list, add and delete. Every write saves a backup first and can be undone with pcd_snapshot_restore.

= 0.31.8 - 2026-09-23 =
* New: rank_math_settings_get reads Rank Math's site-wide settings (general, titles and per-post-type templates, sitemap, instant indexing, active modules) with secrets left out. rank_math_post_schema_get and rank_math_post_schema_set read and change a post's schema (structured data): set the type, add, update or remove a schema, turn it off, or fall back to the post type's default.
* Fix: undoing a Rank Math SEO write with pcd_snapshot_restore now works. The write tools saved their backup as post_meta/term_meta, which the restore step did not know how to read, so restoring failed with "Cannot restore kind".

= 0.31.7 - 2026-09-23 =
* New: a "sitemap" playbook in divi_build_guide and elementor_build_guide. Turns a visual sitemap (Octopus.do, read through its connector or an exported XML file) into a starter site: every page as a draft with its SEO and layout built from the wireframe types, the page tree, and for Divi a header, footer and phone menu scoped to only those pages. Tested on a 25-page plan. Includes the block-to-layout map and the traps found on the way.
* Fix: elementor_page_from_spec now honors width and radius on a real image (a logo given "width":"150px" or "20%" used to come out full column width, because only the labeled-placeholder branch read width).

= 0.31.6 - 2026-09-22 =
* Fix: wp_customizer_list/wp_customizer_set (new in 0.31.5) pulled — crashed on Divi sites due to a theme/plugin class-loading order issue. Not registered until that's fixed and verified on a non-production install. No other change in this release; it exists to get every connected site back to one consistent, safe build.

= 0.31.5 - 2026-09-22 =
* New: wp_customizer_list and wp_customizer_set — the active theme's WordPress Customizer settings (Appearance → Customize): colors, background, header, site identity, and anything else the theme itself registers a control for. Reads the live registration the same way the Customizer screen does, so it works on any theme without a bundled catalog. Says plainly when the active theme is a block theme, since those usually keep colors and fonts in the Site Editor's Global Styles instead.

= 0.31.4 - 2026-09-22 =
* New: ACF field definition tools (acf_field_group_list, acf_field_group_get, acf_field_update, acf_field_choice_add, acf_field_choice_remove) — read and change a field's own choices, label, type and other settings directly through ACF's API, instead of reverse-engineering a field key from saved post values and writing a custom mu-plugin to change it.
* New: wp_file_grep searches file CONTENTS across themes/plugins/mu-plugins (optionally scoped to one, or including WordPress core) for a string or pattern in one call, instead of reading files one at a time to find where something comes from.
* New: sg_cache_purge purges SiteGround Optimizer's (Speed Optimizer) SuperCacher dynamic cache — the same as its admin-bar "Purge SG Cache" button — for sites on SiteGround hosting.
* Fix: wp_post_list now checks post_type against the site's actually-registered post types (including internal ones like acf-field-group or a builder's et_header_layout) and errors clearly if one isn't registered, instead of silently dropping the filter and returning an unfiltered list. It also accepts a comma-separated list to query more than one type at once.
* Fix: wp_file_list's non-recursive listing now includes subfolder names (it used to omit directories entirely, so there was no way to see what was there without recursing). wp_file_read/wp_file_list no longer wrongly refuse a path under a symlinked theme or plugin folder (a normal setup for a git-managed plugin or a local dev site) with a misleading "escapes the WordPress install" error.
* Fix: divi_layout_save's description and result now say plainly that none of its layout types — including "body", easy to mistake for page content — create a normal page with a URL; they're Theme Builder layouts that need a template assignment (divi_template_create) to appear anywhere. Use wp_post_create + divi_set_post_layout, or divi_page_from_spec, for an actual page.
* Elementor: a build playbook. New elementor_build_guide gives the AI a short, ordered guide (workflow, palette, structure, mobile, from-image, limits of free Elementor, done-checklist). New elementor_page_from_spec builds a whole Elementor page from a short JSON description (the same spec shape as divi_page_from_spec): it sets the Kit palette and fonts, writes real containers and widgets that point at those globals, stacks columns on phones and uses the Canvas template so a header and footer built inside the page work without Elementor Pro. Supports headings, eyebrows, text, buttons, images or placeholders, groups, icon lists, social icons, video placeholders and form-look fields (free Elementor has no form widget). The playbook also has a from-divi topic (how to rebuild a Divi page in Elementor faithfully: read the rendered page, map each part to a real widget, what cannot convert). Its first rule: on every Elementor site set the global colors and fonts (Elementor Kit, and the theme palette such as Astra's) to the brand palette before building any page.

= 0.31.3 - 2026-09-20 =
* Divi 5: the mobile audit and optimizer now catch rows with no width set (Divi's default 80% width leaves wide margins on a phone) and no longer report columns as unstacked when their phone width is already set in the place Divi reads. New divi_mobile_menu_create gives a header built from plain links or buttons a phone menu in one call: it reads the links, builds a slide-down panel (a canvas), adds a Menu button that shows only on tablet and phone, hides the original links there, and wires the click; desktop is unchanged. divi_migration_guide now has a section for rebuilding a whole site (code modules, CSS in the child theme, Divi 4 vs 5 HTML differences, dynamic content, addresses and links, schema and embeds, verification). The playbook's mobile topic gained lessons from fixing a live site: default row width, wrongly nested values, plugin shortcodes, and a safe routine for live sites.
* Fix: wp_option_get and wp_option_update no longer accept a missing key silently. Before, passing "name" instead of "key" used an empty key: a read returned false, and an update reported success while changing nothing. Both now require the option name (and accept "name" too), and the update reports the value it now holds.
* Fix: wp_file_write can now create a file in a new sub-folder inside a theme or plugin. It used to fail with "Resolved path escapes wp-content" whenever the folder did not exist yet.
* Fix: creating or replacing a Divi 5 page no longer refuses content just because the text mentions a Divi 4 shortcode (a page that documents Divi). Only real Divi 4 shortcode content is refused.
* wp_post_get also returns title_text, the title with HTML entities decoded, so copying a post with an apostrophe in its title does not double-encode it.

= 0.31.2 - 2026-09-20 =
* Divi 5: divi_page_from_spec builds a whole page from a short JSON description (sections, columns, headings, text, eyebrows, buttons, images or labeled placeholders, groups and card grids). It writes the real Divi blocks with columns that stack on tablets and phones and then runs the mobile optimizer, so a page that took hundreds of lines of block settings takes a few dozen. It can create a page or replace an existing page or Theme Builder layout. The playbook's from-image topic now builds with it.

= 0.31.1 - 2026-09-20 =
* Fix: restoring a page from a snapshot (pcd_snapshot_restore, and any undo that uses it) stripped backslashes from the saved content, which damaged escape sequences in Divi 5 block data (text showed up as "u003cp u003e"). The saved content is now written back exactly as it was.
* Divi 5: mobile checking and fixing. New divi_mobile_audit finds what breaks a page on tablets and phones (columns that never stack, headings and padding that stay desktop-sized, fixed widths wider than a phone, rows of items that cannot wrap, graphics placed with absolute position) and lists each with its path and fix. New divi_mobile_optimize applies those fixes in one undoable step. It only adds tablet and phone values, never changes the desktop design, and never overwrites a phone value that is already set. The playbook gained a "mobile" topic and a "from-image" topic (turning a screenshot or mockup into a finished page), and its checklist now requires the mobile pass and a phone-width screenshot. It also carries a tested recipe for a phone menu: a canvas holding the links, opened by a "Menu" button through a click interaction, with the plain links hidden on tablet and phone.
* Divi 5: a build playbook. New divi_build_guide gives the AI a short, ordered guide (workflow, structure, editing, styling, dynamic content, site-level work and a done-checklist) that points at the right tools, so pages come out with real modules, the site's own colors and fonts, and a check at each step. It includes a "second page" recipe (reuse the first page instead of rebuilding; second pages took about a quarter of the time in testing). It was tested by having an AI build two full homepages from mockups on a staging site, and its notes cover the traps found there (page-breaking value shapes, section spacing, overlapping cards, Theme Builder headers and footers).
* wp_post_create and wp_post_update now also accept the short names an assistant tends to use (status, title, content, excerpt, slug, parent). Before, a wrong name such as status was ignored without any error.
* divi_global_fonts_get and divi_customizer_list now say that an empty or "none" font means Divi's default font (Open Sans).

= 0.31.0 - 2026-09-19 =
* Divi 5: edit one module at a time. New tools divi_module_get, divi_module_edit, divi_module_add, divi_module_delete, divi_module_move, divi_module_replace and divi_module_duplicate work on a single module by its tree path instead of resending the whole page. Each takes an undo snapshot, refuses unknown module names and misplaced children, and clears Divi's page cache.
* Divi 5: presets (saved styles). New tools divi_presets_list, divi_preset_get, divi_preset_create, divi_preset_update, divi_preset_set_default, divi_preset_delete and divi_preset_apply.
* Divi 5: module features. Loops (divi_loop_options, divi_loop_set, divi_loop_clear), dynamic content (divi_dynamic_sources, divi_dynamic_content_apply, divi_dynamic_content_clear), display conditions (divi_conditions_catalog, divi_conditions_set) and interactions (divi_interactions_catalog, divi_interaction_add, divi_interaction_remove).
* Divi 5: site-wide design data. New tools to delete a single global color or design variable (divi_global_color_delete, divi_variable_delete), read and change the global fonts (divi_global_fonts_get, divi_global_fonts_set), work with the Divi Library (divi_library_list, divi_library_get, divi_library_save, divi_library_apply, divi_library_delete) and list Theme Builder conditions (divi_tb_conditions_catalog).
* Divi 5: settings surfaces. New tools for page settings (divi_page_settings_get/set), Builder and performance settings (divi_builder_settings_get/set), Theme Options and Customizer settings (divi_theme_options_list/set), code injection (divi_code_injection_get/set), site-wide custom CSS (divi_custom_css_get/set), the Role Editor (divi_roles_get/set), custom fonts (divi_custom_fonts_list, divi_custom_font_add, divi_custom_font_remove), canvases (divi_canvas_list, divi_canvas_get, divi_canvas_create, divi_canvas_update, divi_canvas_delete) and responsive breakpoints (divi_breakpoints_get/set). Every value is checked before it is saved, and changes are undoable.
* Divi 5: the whole Theme Customizer. New divi_customizer_list and divi_customizer_set cover all 138 Customizer design settings (fonts, sizes, colors, header and menu bars, mobile, footer, buttons, blog) with each value checked against Divi's own ranges and choices.
* Divi 5: layout import. New divi_layout_import loads a Divi layout export (from Divi's Export button or divi_layout_export) into a page through Divi's own importer, bringing in images, presets and global colors. divi_layout_export now returns the export JSON itself (it used to return only a timestamp) and can embed images.
* Divi 5: Theme Builder export and import. New divi_theme_builder_export and divi_theme_builder_import move whole templates with their header, body and footer layouts, and where each applies, between sites. Imports create new templates and never overwrite; conditions tied to a specific post or term id are skipped and reported, and a failed import leaves nothing behind.
* Divi 5: Google settings (divi_google_settings_get and divi_google_settings_set): turn Google Fonts and the Maps script off or on, and set the Maps API key (never shown back in full).
* Divi 5: split testing results. New divi_split_tests_list, divi_split_test_results and divi_split_test_clear_stats show which pages have an A/B test, how each variant is doing on the goal, and let you wipe a test's collected numbers. Divi 5 itself has no screen for creating a new test, so these only see tests set up before.
* Divi 5: settings export and import. New divi_settings_export and divi_settings_import copy a site's Divi setup (Theme Options, Customizer, builder and performance settings, Role Editor, breakpoints, Google settings, custom CSS, global colors and design variables, optionally injected code) to another site. Each section is validated and undoable on its own; secrets are never exported.
* Divi 5: Divi Library packs. New divi_library_export and divi_library_import move library items between sites through Divi's own importer, keeping type, categories and global status.
* Divi 5: Divi AI Agent rules and commands (divi_ai_rules_list, divi_ai_rule_save, divi_ai_rule_delete, divi_ai_commands_list, divi_ai_command_save, divi_ai_command_delete).
* Fixed divi_global_colors_get, which returned the whole theme options record instead of just the color palette (on Divi 4 it now returns the palette plus the color settings). Fixed the site-wide custom CSS save undoing other Divi settings changed earlier in the same request.
* Fixed divi_variables_set: in its default merge mode it saved nothing, and the variables it did save were missing the id Divi needs to output their CSS.
* Fixed divi_global_template_get and divi_global_template_set, which used a setting Divi does not have. They now read and write the real default template and register it with the Theme Builder.
* Fixed the license notice staying up for hours after a site was connected: an "unlicensed" answer from the relay is now remembered for 10 minutes instead of 6 hours, and pairing clears it straight away.

= 0.30.6 - September 18, 2026 =
* Bumped "Tested up to" to 7.1 — clears the "has not been tested with your current version of WordPress" admin notice on current WordPress installs.

= 0.30.5 - September 18, 2026 =
* Connect to Conduit now opens in the same tab instead of a new one — matches the relay's /connect page, which was rebuilt to close a tab it no longer needs to.

= 0.30.4 - September 18, 2026 =
* Changed the default relay domain from mcp.pcdesignstx.com to www.pressconduit.com — the permanent brand domain, not an internal subdomain tied to one specific hosting setup. Existing sites pick this up automatically on their next update; the PCD_PC_DEFAULT_BACKEND_URL wp-config.php constant still overrides it if ever needed.

= 0.30.3 - September 17, 2026 =
* Added `page` to wp_post_list so it can walk past the first 100 results (also now returns total_found/total_pages) — previously per_page silently capped at 100 with no way to reach older posts.
* Added post_date/post_date_gmt to wp_post_create and wp_post_update so migrated content can keep its real publish date instead of landing with the current timestamp.

= 0.30.1 - September 16, 2026 =
* Fixed a real bug reported from the field: a backup could hang forever at "running, stage: files, 0%" on a site with enough files (core + plugins + themes + uploads) that the file-listing scan alone outran the host's execution time limit — the whole scan ran synchronously in one shot with no way to pause it. It's now chunked and resumable like every other stage, picking back up exactly where it left off instead of restarting or dying.
* Fixed the resulting lockout: a dead job used to block every future backup on that site forever, since pcd_backup_delete refused anything marked "running" and only one job can run at a time. A job with no progress for 10 minutes now auto-clears itself, and pcd_backup_delete takes a force:true to cancel a job you can tell is dead sooner than that.

= 0.30.0 - September 16, 2026 =
* Added full-site backup: pcd_backup_start (database + uploads + plugins + themes + core, any combination, zipped) runs as a resumable background job so it survives past one request — pcd_backup_status to poll, pcd_backup_list, pcd_backup_download_url for a short-lived signed download link, pcd_backup_delete.
* Added pcd_backup_restore (destructive, confirm-gated): restores a completed backup's database and/or files back into the site, and can migrate to a new domain in the same pass — after the DB import it rewrites the old site URL throughout the whole database, serialize-safe, so widgets and page-builder content survive intact. pcd_backup_inspect looks inside a zip first (has a DB dump? which folders?) without touching anything.
* Added a manual upload path: a "Backups" tab in the PressConduit admin screen lets you drop in a .zip made elsewhere (another site, a different tool) — it shows up in pcd_backup_list tagged as uploaded, same as a self-made backup, ready to inspect and restore.
* Backup/restore is excluded from the WordPress.org (Lite) build, same as the file tools — a full DB + code export is more sensitive than what Lite already keeps out.
* wp_file_write and wp_file_edit now reach the WordPress root .htaccess via the exact path "../.htaccess" (no other root-level file is reachable this way) — previously unreachable through the file tools' wp-content sandbox. Writes go through the same WP_Filesystem path as every other file tool, with the path verified against realpath so nothing else can slip through.

= 0.29.16 - August 30, 2026 =
* Added WP Grid Builder tools: wpgb_status, wpgb_object_list/get/save/duplicate/delete (covers grids, cards, facets, and styles — WPGB's four custom-table object types), and wpgb_shortcode. Calls WPGB's own Database + Settings classes directly, same code its admin REST routes use, so writes go through its own sanitizer.
* Rebuilt the bundled Divi 5 module catalog against Divi 5.11.1 (was last built 2026-06-26 against an older release): 83 -> 89 modules, adding divi/charts, divi/payment-button, divi/post-filter, divi/post-filter-item, divi/imagely-gallery, and divi/gravity-forms. Fixed bin/build-divi5-catalog.mjs so the catalog's divi_version field actually reads the source theme's version instead of a hardcoded placeholder string.
* Added a `layout_systems` topic to divi5_docs covering Divi 5's Grid Editor (Section/Row/Column/Group CSS Grid layout, added in 5.9.0) — official Grid Editor reference, a CSS Grid deep-dive, a Grid Editor + Loop Builder tutorial, and the community Group-module reference covering its Block/Flex/Grid layout modes.

= 0.29.15 - August 26, 2026 =
* Elementor: added global-classes (list/create/edit/delete/apply), global-variables (list/create/edit/delete), and a style-schema discovery tool for the Atomic Widgets design-token layer. Added dynamic-tags (list/get/apply — binds a widget setting to live post/ACF/author/URL data) and interactions (read/add/delete scroll/hover/load animations on atomic widgets).
* Bricks: added bricks_variables_write (create/update/delete global CSS variables) — pairs with the existing bricks_globals_read.
* Added Kadence tools: kadence_status, kadence_blocks_catalog/schema (reads live from the WordPress block registry), kadence_settings_read/write (theme Customizer settings, verified against a live install's theme_mods storage).
* Added Rank Math SEO tools: rank_math_status, rank_math_post_seo_read/write, rank_math_term_seo_read/write (focus keywords, title/description, canonical, robots, social previews, primary category) — verified against a live post's postmeta before shipping.
* divi_module_catalog now merges in a live read of the WordPress block registry for third-party Divi 5 module plugins (e.g. Divi Supreme Pro's dsm/* modules) that aren't in the bundled Divi-core catalog, so they're discoverable without dedicated per-plugin code. divi_module_schema already read the live registry as its primary source, so third-party module schemas were already reachable by name — this closes the discovery gap.

= 0.29.14 - August 21, 2026 =
* Removed the Tools tab from the plugin's admin screen. It printed a plain-English table of every registered tool's name and description — a free recon list for anyone who could log into wp-admin, no source access needed. Connected AI clients still discover tools normally through the MCP connector; this only removes the redundant human-readable copy that sat in the admin UI.
* Added WooCommerce order notes and coupon management: woo_order_add_note, woo_coupon_list, woo_coupon_get, woo_coupon_update, woo_coupon_delete. Continues the broader push toward full WooCommerce coverage started in 0.29.13.

= 0.29.13 - August 19, 2026 =
* Added full WooCommerce shipping zone/method management: woo_shipping_zone_list/create/update/delete and woo_shipping_method_add/update/delete. First slice of a broader push toward full WooCommerce coverage.
* Added divi_html_conversion_guide and bricks_html_conversion_guide — step-by-step routines (mirroring divi_migration_guide) for converting a raw HTML mockup into NATIVE Divi modules or Bricks elements instead of dumping it into a Code module/element.
* Elementor: detect and report the data model (classic vs. Atomic Widgets) on read and write, warn on mixed-shape trees or Atomic elements written while the e_atomic_elements experiment is inactive, and clear Elementor's stale whole-document render cache (_elementor_element_cache) on every page_write so raw postmeta writes can't leave the live front-end showing old content.
* wp_post_create now auto-flags a new page/post as owned by the site's active builder (Bricks/Divi/Elementor) when the caller doesn't already pass that meta, so it doesn't sit invisible to its own builder waiting on a follow-up call that might get skipped.

= 0.28.0 - August 2, 2026 =
* The specimen library now fetches from the PC Designs relay first (12h cache), falling back to the copies bundled in the plugin if the relay is unreachable — new or fixed specimens can ship without a plugin update. Fetch status is recorded in the pcd_pc_specimens_status option.
* Added 4 more Divi 5 specimens: text-masking, golden-ratio-hero, photo-background-hero, and tabs.

= 0.27.1 - August 2, 2026 =
* Added the email-popup specimen (Divi 5): a centered-modal email-capture popup with a working close interaction, dark overlay backdrop, and email form — built on Divi 5's Interactions system (module.decoration.interactionTarget/interactionTrigger/interactions), which is now confirmed settable via the same REST attribute editing every other specimen in this library uses.

= 0.27.0 - August 1, 2026 =
* Divi component library expanded: post-grid, header (with a Link/Dropdown submenu), footer, split-feature, and email-signup specimens, each shipped as a matched Divi 5 / Divi 4 pair (10 files total) so the AI can pull real, verified markup for these patterns on either engine.
* Updated the Divi 5 mastery notes and capture spec with the build findings behind those specimens: the full-bleed image sizing recipe (decoration.sizing, not advanced.sizing), the dropdown-content color-token fix needed for reliable rendering, a confirmed divi_capture tooling bug with Dropdown-nested children, and why the native Email Optin modules were skipped in favor of a plain contact-form for the signup specimen.

= 0.26.0 - August 1, 2026 =
* New security tooling, built out of a real incident: wp_file_delete (actual delete, not overwrite-with-stub), wp_file_scan_malware (severity-tagged backdoor/webshell pattern scan across themes, plugins, mu-plugins, uploads, and loose wp-content-root files, with plugin-impersonation detection and per-match file-owner/modified-time origin clues), wp_scan_db_malware (same patterns against wp_options values), wp_scan_cron_jobs (flags WP-Cron persistence hooks not tied to core or an active plugin), wp_security_triage (runs all of the above plus an admin-account list in one call), and wp_wordfence_login_log (opportunistic read of Wordfence's own login log, degrades gracefully if absent). Read access widened to wp-content/uploads for investigation. Security tooling now lives in its own file (class-pcd-pc-tools-security.php) to keep the WordPress tools file from growing indefinitely.

= 0.25.3 - July 11, 2026 =
* wp_post_create and wp_post_update now accept post_parent and menu_order, so the AI can build hierarchical content (Divi Docs Maker doc trees, child pages, and other hierarchical CPTs) and control sibling ordering. Updates snapshot the prior parent and order for undo.

= 0.25.2 - July 11, 2026 =
* Fixed: sites with no detected page builder (a block theme, a plain WordPress install, or a Bricks site before the theme is activated) registered zero tools, because the whole tool surface was gated behind Bricks/Divi detection. The generic WordPress, media, file, and admin tools now register on any site; only the Bricks and Divi tool sets stay gated behind their builder.

= 0.25.1 - July 11, 2026 =
* Fixed: on Bricks sites the plugin could register zero tools (empty Tools tab, and only the relay's 2 built-in tools in the AI client). Tool registration ran on plugins_loaded, before the Bricks theme and its post types finish loading, so builder detection failed and every tool was gated out. Registration now runs on init, where Bricks and Divi are reliably detected.
* Connection: added a note that the AI connector must be added from the same browser where the WordPress admin is open, since the connection is authorized through that browser's session. Adding it from a different browser fails with "No Conduit session in this browser."

= 0.25.0 - July 9, 2026 =
* New: automatic updates. PressConduit can now install its own updates in the background, so the plugin stays current with the relay without a manual click. Toggle it on the Settings tab (on by default). Updates that would require a newer WordPress or PHP version are never installed automatically.
* Changed: the update flow now tells WordPress the minimum WordPress version each release needs, so an incompatible build is held back instead of offered.
* Changed: the PressConduit admin now wears the PC Designs brand. Navy header with the gold PressConduit mark and a live version badge (was a static "MCP" chip), tabs that flow into a lighter workspace, and gold primary buttons. Only this plugin's pages are styled. The rest of your WordPress admin is untouched.

= 0.24.7 - July 1, 2026 =
* Security: the WordPress options tools now refuse to read or write any option whose name looks like a secret or credential (tokens, passwords, API keys, salts).
* Fixed the plugin author link in the plugin header.
* Snapshot-backed undo now covers page, layout, option, and post-meta changes, so any AI edit can be reversed.
* Divi 5: setting global colors through the plugin writes the native Divi 5 global-color store, so brand-color references (var(--gcid-...)) resolve correctly.
* Completed the Divi 5 specimen library (hero, feature grid, CTA, stats, testimonials, pricing, FAQ, and contact) that the AI copies and adapts instead of building common sections from scratch.

= 0.23.1 =
* The Divi 5 specimen library now ships the full v1 set of eight verified section recipes: hero, feature-grid, final-cta, stats-band, testimonials, pricing, faq (accordion parent/child), and contact (contact-form parent/child). 0.23.0 shipped only hero and feature-grid.
* Every specimen's color references now carry an inline fallback (e.g. `var(--gcid-pcd-surface-dark, #26292F)`), so a section renders correctly even on a site whose brand palette has not been set up yet; the site's global colors still win when present.
* `divi_capture` portability lint adds an `empty-module` warning: a content module that round-trips with no configured attributes (a sign the editor emptied or dropped it on save) is now flagged instead of passing silently.
* The contact specimen documents its deployment requirements (insert via a raw post write rather than the page-creation controller, then clear the Divi static CSS cache) so its form fields are not stripped on insertion.

= 0.23.0 =
* New: built-in Divi 5 specimen library — verified, portable section recipes the AI copies and adapts instead of composing common sections from scratch. Surfaced via `divi_specimen_list` and `divi_specimen_get`; ships with `hero` and `feature-grid` to start. Each specimen carries its required color tokens, placeholder markers, and annotations describing which attributes are brand-variable vs structural.
* New: `divi_module_example` now points the AI at a matching library specimen when a site has no rich example of a requested module, instead of only asking the user to build one in the Visual Builder.
* New: capture tooling — `divi_layout_outline` maps a page's block tree; `divi_capture` slices out a section/row/group/module as portable block markup and runs a portability lint (theme-CSS classes, inline styles, hard-coded colors vs design-variable/global-color references, site-local presets, site-hosted media URLs, code-module escape hatches).
* New: `divi_variables_get` / `divi_variables_set` read and write Divi 5 Design Variables (numbers, strings, images, links, fonts, gradients) via the native GlobalData layer.
* Fixed: `divi_global_colors_set` now writes the Divi 5 global-color store (et_global_data) through GlobalData on D5 sites, so `var(--gcid-…)` references resolve. It previously wrote only the legacy Divi 4 option, which Divi 5 ignores.

= 0.22.6 =
* Fixed the AI self-update tools (`pcd_pc_check_update` / `pcd_pc_self_update`) checking the wrong product manifest. They omitted the product identifier, so the backend answered with the frozen divi-conduit release and the tools reported "already on the latest version" no matter how far behind the site was. The wp-admin update path was unaffected.

= 0.22.5 =
* Divi tool exposure is now strictly generation-specific. Divi 4 sites expose only the shortcode tool surface; Divi 5 sites expose only the native block, catalog, docs, outline, and capture surface.
* The active parent theme version is authoritative for Divi generation detection.
* Cross-generation module requests and layout content are rejected instead of converted or written through the other generation.
* Divi 5 operations no longer fall back to Divi 4 storage when the native Divi 5 controller is unavailable.

= 0.22.4 =
* Added an "Allow file management" opt-in (Settings tab, default off). Lets the AI file tools work on sites where `DISALLOW_FILE_EDIT` is set in wp-config.php — which otherwise strips the `edit_themes` capability from everyone and silently blocks file tools. When enabled, file tools run as the linked administrator; writes stay confined to themes/plugins/mu-plugins and PHP edits are still syntax-checked. Blocked file tools now return a clear message naming the cause (DISALLOW_FILE_EDIT) and how to enable access, instead of a bare "Missing capability".

= 0.22.3 =
* Divi 5 tools now recognize third-party/custom modules, not just core `divi/` blocks. The module catalog, schema, build, and block-format detection match any block registered under a Divi module category (module, structure, fullwidth-module, child-module) and treat vendor-namespaced names (e.g. `pcd/…`, `pac/…`) as real Divi 5 modules. Bare names still get the `divi/` namespace; already-namespaced names are used as registered.

= 0.22.2 =
* Fixed: pages created/written on Divi 5 sites now have the Divi Builder enabled automatically. Previously the Divi 5 `set_post_layout` path stored the layout but left the builder toggle off, so the page showed "Use The Divi Builder" and the Visual Builder opened empty. Builder-enable (`_et_pb_use_builder` + `_et_pb_built_for_post_type` + Divi's own enable routine) is now applied on every create/layout/enable path via a single shared helper.

= 0.22.1 =
* Fixed: the "My Plugins" menu no longer lists retired Divi Conduit / Bricks Conduit as permanent "(Not installed)" entries. PressConduit now registers only itself in the shared PC Designs menu; sibling products appear only when actually installed.

= 0.22.0 =
* wp_site_info now reports the active page builder (`builder`: divi | bricks | none) and its version, so connected AI clients know up front which builder a site runs and which tools/docs apply.

= 0.21.0 =
* Bricks: added the element schema + build tool surface — bricks_element_catalog and bricks_schema (read live from the Bricks element registry), bricks_page_read and bricks_page_write (read/write the element array in postmeta with id/parent/children normalization, snapshot-backed undo, and editor-mode handling), bricks_template_list, bricks_template_create, and bricks_globals_read (theme styles, global classes, components, variables, color palette, breakpoints).
* Bricks docs catalog rebuilt against validated Academy URLs with relay read mode.

= 0.20.5 =
* Initial PressConduit scaffold.
* Combined the Divi and Bricks Conduit tool surfaces under one plugin identity.
* PressConduit detects the active builder and only exposes Divi or Bricks tools.
