{"id":311005,"date":"2026-06-26T06:49:51","date_gmt":"2026-06-26T06:49:51","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/acrossai-abilities-manager\/"},"modified":"2026-09-21T05:50:48","modified_gmt":"2026-09-21T05:50:48","slug":"acrossai-abilities-manager","status":"publish","type":"plugin","link":"https:\/\/br.wordpress.org\/plugins\/acrossai-abilities-manager\/","author":15295430,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.0.35","stable_tag":"0.0.35","tested":"7.0.5","requires":"6.9","requires_php":"8.1","requires_plugins":null,"header_name":"AcrossAI Abilities Manager","header_author":"raftaar1191","header_description":"Manage and customize the abilities of AcrossAI on your WordPress site. Tailor the AI's capabilities to suit your needs, enhancing user experience and engagement.","assets_banners_color":"fdfdfe","last_updated":"2026-09-21 05:50:48","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/github.com\/acrosswp\/acrossai-abilities-manager","header_plugin_uri":"https:\/\/acrossai.co\/","header_author_uri":"https:\/\/profiles.wordpress.org\/raftaar1191\/","rating":0,"author_block_rating":0,"active_installs":20,"downloads":1427,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.0.1":{"tag":"0.0.1","author":"raftaar1191","date":"2026-06-26 06:49:29","revision":3586852},"0.0.10":{"tag":"0.0.10","author":"raftaar1191","date":"2026-07-18 00:50:18","revision":3612106},"0.0.11":{"tag":"0.0.11","author":"raftaar1191","date":"2026-07-18 15:51:33","revision":3612771},"0.0.12":{"tag":"0.0.12","author":"raftaar1191","date":"2026-07-18 16:15:59","revision":3612787},"0.0.13":{"tag":"0.0.13","author":"raftaar1191","date":"2026-07-20 03:01:52","revision":3614043},"0.0.14":{"tag":"0.0.14","author":"raftaar1191","date":"2026-07-20 03:08:58","revision":3614045},"0.0.15":{"tag":"0.0.15","author":"raftaar1191","date":"2026-07-20 19:33:50","revision":3616130},"0.0.17":{"tag":"0.0.17","author":"raftaar1191","date":"2026-07-25 15:38:31","revision":3622584},"0.0.18":{"tag":"0.0.18","author":"raftaar1191","date":"2026-07-27 09:05:53","revision":3624246},"0.0.19":{"tag":"0.0.19","author":"raftaar1191","date":"2026-07-31 07:41:16","revision":3629582},"0.0.2":{"tag":"0.0.2","author":"raftaar1191","date":"2026-07-02 12:04:52","revision":3593974},"0.0.20":{"tag":"0.0.20","author":"raftaar1191","date":"2026-08-02 14:45:00","revision":3631858},"0.0.21":{"tag":"0.0.21","author":"raftaar1191","date":"2026-08-08 09:21:59","revision":3638558},"0.0.22":{"tag":"0.0.22","author":"raftaar1191","date":"2026-08-10 18:14:44","revision":3640993},"0.0.23":{"tag":"0.0.23","author":"raftaar1191","date":"2026-08-11 09:38:46","revision":3641623},"0.0.24":{"tag":"0.0.24","author":"raftaar1191","date":"2026-08-12 17:51:24","revision":3643839},"0.0.25":{"tag":"0.0.25","author":"raftaar1191","date":"2026-08-13 13:28:41","revision":3645467},"0.0.26":{"tag":"0.0.26","author":"raftaar1191","date":"2026-08-13 19:38:26","revision":3646090},"0.0.27":{"tag":"0.0.27","author":"raftaar1191","date":"2026-08-13 20:23:39","revision":3646142},"0.0.29":{"tag":"0.0.29","author":"raftaar1191","date":"2026-08-18 09:29:25","revision":3652373},"0.0.3":{"tag":"0.0.3","author":"raftaar1191","date":"2026-07-02 12:30:19","revision":3594026},"0.0.30":{"tag":"0.0.30","author":"raftaar1191","date":"2026-08-19 13:19:05","revision":3654660},"0.0.31":{"tag":"0.0.31","author":"raftaar1191","date":"2026-08-26 17:33:00","revision":3667538},"0.0.32":{"tag":"0.0.32","author":"raftaar1191","date":"2026-08-27 21:06:10","revision":3669524},"0.0.33":{"tag":"0.0.33","author":"raftaar1191","date":"2026-08-27 21:40:21","revision":3669542},"0.0.34":{"tag":"0.0.34","author":"raftaar1191","date":"2026-09-18 19:56:02","revision":3702724},"0.0.35":{"tag":"0.0.35","author":"raftaar1191","date":"2026-09-21 05:50:48","revision":3704896},"0.0.4":{"tag":"0.0.4","author":"raftaar1191","date":"2026-07-03 22:38:31","revision":3595583},"0.0.5":{"tag":"0.0.5","author":"raftaar1191","date":"2026-07-04 01:29:09","revision":3595636},"0.0.6":{"tag":"0.0.6","author":"raftaar1191","date":"2026-07-13 14:09:04","revision":3606181},"0.0.7":{"tag":"0.0.7","author":"raftaar1191","date":"2026-07-13 18:14:55","revision":3606552},"0.0.8":{"tag":"0.0.8","author":"raftaar1191","date":"2026-07-17 00:32:32","revision":3610859},"0.0.9":{"tag":"0.0.9","author":"raftaar1191","date":"2026-07-17 16:29:43","revision":3611804}},"upgrade_notice":{"0.0.35":"<p>BREAKING - the <code>backups\/*<\/code> abilities added in 0.0.34 are replaced by <code>updraftplus\/*<\/code> and <code>all-in-one\/*<\/code>. Anything holding a <code>backups\/<\/code> slug needs updating; there are no aliases. The backup abilities are now two tabs, one per plugin, matching how every other integration works: each offers only what its plugin can actually do rather than advertising everything and reporting absence when you try to use it. Also fixes restoring, which never worked outside the admin screens in 0.0.34 - it checked the filesystem using a function WordPress only loads inside wp-admin, so every restore request failed on that line before checking anything. If you rely on restoring from UpdraftPlus through this plugin, this release is the one that makes it work. Nothing else changes; existing abilities, overrides and access rules are unaffected.<\/p>","0.0.34":"<p>BREAKING - abilities now require administrator rights unless a rule says otherwise. If anyone below administrator drives this site through an AI client, they lose access on update until an administrator grants it: set a rule on the individual ability under User Access, or move the site-wide floor with the <code>acrossai_default_ability_capability<\/code> filter. This closes a real hole - measured on one site, three installed abilities had no permission check at all, two were open to any logged-in subscriber, and one that writes content was open at contributor level. Otherwise additive: 19 new tabs and around 400 new abilities, including WooCommerce, backups, Yoast SEO, LiteSpeed Cache and Contact Form 7. Existing abilities, overrides and access rules are unaffected.<\/p>","0.0.21":"<p>Bumps the <code>wpboilerplate\/wpb-access-control<\/code> composer dependency from <code>^2.0.0<\/code> to <code>^3.1.0<\/code> \u2014 two library releases in one hop. v3.0.0 removed two plugin-dependent providers (<code>BuddyBossProfileTypeProvider<\/code>, <code>MemberPressMembershipProvider<\/code>) that were extracted into a separate add-on (<code>acrossai\/user-access-pro<\/code>); this plugin uses only the core <code>AccessControlManager<\/code> + <code>RuleTable<\/code> classes, so no consumer code change is required. v3.1.0 adds a new &quot;Any logged-in user&quot; option to the Access Control dropdown (backed by a new <code>authenticated<\/code> sentinel rule type), and renames &quot;Everyone (no restriction)&quot; \u2192 &quot;Public (no login required)&quot; for clarity. Existing rules unaffected. Safe upgrade from 0.0.20.<\/p>","0.0.20":"<p>Routes the access-control library-missing warning through the new shared AcrossAI notice hub (<code>acrossai_notices<\/code> filter shipped by <code>acrossai-co\/main-menu<\/code> 0.0.30). Instead of a raw wp-admin banner on every screen, the notice now appears on the new AcrossAI \u2192 Notices submenu (with a count bubble on the menu label) and as a single top-of-page summary banner (&quot;AcrossAI has N notifications for your attention \u2014 View notices \u2192&quot;) whose dismissal persists per user until the notice set changes. The fail-open semantics and message copy are unchanged. No breaking changes; existing abilities unaffected. Safe upgrade from 0.0.19.<\/p>","0.0.19":"<p>Adds a blue promotional callout on the ability edit form (MCP Exposure section) that advertises the sibling AcrossAI MCP Manager plugin when it is not installed \/ active. The callout links to the AcrossAI Add-ons page for install and to acrossai.co\/mcp-manager\/ for more info. Fully suppressed when the AcrossAI MCP Manager plugin is active. Also bumps the <code>acrossai-co\/main-menu<\/code> composer dependency from 0.0.27 to 0.0.29 \u2014 0.0.28 refreshes the Add-ons page baseline catalogue (AcrossAI Abilities Manager + AcrossAI MCP Manager + AI Connectors) with shared brand icon, <code>contain<\/code>-fitted icon boxes, fixed 3-column grid layout, and a new optional <code>learn_more_url<\/code> field; 0.0.29 reworks the card action states so active add-ons render a non-clickable &quot;\u25cf Running&quot; pill (deactivation stays in Plugins \u2192 Installed Plugins) and installed non-wp.org add-ons now show an in-page Activate button instead of always linking out. No breaking changes; existing abilities unaffected. Safe upgrade from 0.0.18.<\/p>","0.0.18":"<p>New third-party integration framework (Feature 060) with Advanced Custom Fields as the first concrete integration \u2014 flip one toggle on the new &quot;Acf&quot; tab of the Ability Library page to enable ACF&#039;s AI abilities without editing code. Also new: extensibility surface so other AcrossAI plugins can add their own cards to an integration&#039;s tab, filterable capability check for the toggle (via <code>acrossai_integration_toggle_capability<\/code>), and audit action (<code>acrossai_integration_toggle_denied<\/code>). Fixes a sparse-storage bug that could silently strip the integration ON state. Bumps the <code>acrossai-co\/main-menu<\/code> composer dependency from 0.0.23 to 0.0.27 to land two WordPress.org plugin directory guideline #8 fixes: the Consultations submenu now uses an external-link CTA instead of an embedded Calendly iframe, and the Add-ons page install action is now WordPress.org-only (non-wp.org cards render as external &quot;Get add-on \u2197&quot; links opening the vendor&#039;s site in a new tab). No breaking changes; existing abilities unaffected. Safe upgrade from 0.0.17.<\/p>","0.0.17":"<p>BREAKING \u2014 every ability slug has been renamed. Namespace shortens from <code>acrossai-abilities-manager\/<\/code> to <code>acrossai\/<\/code>; suffixes flip to verb-first form (e.g. <code>site-title-get<\/code> \u2192 <code>get-site-title<\/code>, <code>theme-activate<\/code> \u2192 <code>activate-theme<\/code>). External callers (custom code, saved MCP client configs, ACL entries created outside the plugin&#039;s UI, scripts calling <code>\/wp-json\/wp-abilities\/v1\/abilities\/acrossai-abilities-manager\/\/run<\/code>) must update their slug references to <code>\/wp-json\/wp-abilities\/v1\/abilities\/acrossai\/\/run<\/code>. No backwards-compatibility aliases; no automatic data migration \u2014 clear pre-existing overrides + ACL rules keyed on old slugs from the admin UI and re-add them under the new names. Also new: 7 Recovery Mode abilities (detect recovery, list paused plugins\/themes, unpause, exit URL, fatal-error log filter) and <code>core\/reinstall-wp-core<\/code>. 162 PHP class files renamed to match slugs (internal-only; PSR-4 autoload picks up automatically). PHP 8.1+ \/ WP 6.9+ floor unchanged.<\/p>","0.0.15":"<p>UI-only release. Replaces the Custom Abilities Bulk Actions dropdown (Publish \/ Unpublish \/ Delete) with Site Access, MCP Exposure, User Access, and Overrides operations that match the per-row edit drawer. Row-level checkbox now works on every ability regardless of Source. Reuses existing REST endpoints; no new database tables, no new endpoints, no PHP changes, no dependency changes, no permission changes. Also fixes a bug that stored composer User Access rule keys with the ability slug&#039;s <code>\/<\/code> character stripped when applied via the (new) bulk path. Safe upgrade.<\/p>","0.0.14":"<p>wp.org assets only. Refreshes the banner artwork and renames both banner files from <code>banner{width}x{height}.png<\/code> to the WP.org-canonical <code>banner-{width}x{height}.png<\/code> (the 0.0.13 filenames were not being auto-detected by the plugin directory). No plugin code touched; no REST, DB, or capability changes. Safe upgrade.<\/p>","0.0.13":"<p>Docs + wp.org assets only. Adds <code>specs\/054-ability-gap-audit\/<\/code> (a reference audit of abilities that external AI-tool inventories expect but the plugin does not yet expose) and commits the previously-untracked <code>.wordpress-org<\/code> banner (1544\u00d7500 + 772\u00d7250) and a sixth screenshot covering the Settings page. No functional changes; no REST, DB, or capability changes; no code touched under <code>includes\/<\/code> or <code>src\/<\/code>. Safe upgrade.\nAdds 31 new abilities across 10 domains (187 \u2192 218). Two new categories join the Ability Library: Admin Menu (5 abilities) and Content Search (11 abilities). Introduces two option-backed data stores: a lifecycle event log for plugin\/theme activate\/deactivate\/update timestamps, and an internal-link suggestion queue capped at 500 entries. Zero new REST endpoints, zero new capability requirements beyond the operation-specific caps already enforced by WP core (moderate_comments, upload_files, edit_others_posts). Zero external HTTP; zero new database tables. No breaking changes to existing abilities. Safe upgrade.<\/p>","0.0.12":"<p>Adds a third ability to the Core tab \u2014 <code>wp-core-rollback<\/code> \u2014 that rolls back WordPress core to an earlier version via WP core&#039;s <code>Core_Upgrader::upgrade()<\/code>, the same class the dashboard uses for forward updates. Requires both <code>manage_options<\/code> and <code>update_core<\/code>; honours <code>DISALLOW_FILE_MODS<\/code>; refuses when the target version isn&#039;t strictly older than the currently-installed version. Introduces the plugin&#039;s first outbound HTTP request (to <code>api.wordpress.org\/core\/version-check\/1.7\/<\/code>), rate-bounded to at most one request per day per locale per site via a site-transient cache. No breaking changes; no database, REST, or capability changes to existing abilities. Safe upgrade.<\/p>","0.0.11":"<p>Adds two WordPress-core-scoped abilities under a new &quot;Core&quot; tab in the Ability Library \u2014 <code>wp-core-update-check<\/code> (report availability) and <code>wp-core-update<\/code> (apply via <code>Core_Upgrader<\/code>). The update ability requires both <code>manage_options<\/code> and <code>update_core<\/code>; honours <code>DISALLOW_FILE_MODS<\/code>; multisite-guarded. Also changes backup filenames from <code>backup-{type}-{slug}-{random}.zip<\/code> to <code>{slug}-{unix-timestamp}-{ms}.zip<\/code> \u2014 human-readable and time-sortable, but predictable (directory listing remains disabled on the backups dir). Existing backups continue to work; the filename change only affects new backups. No breaking changes; no database, REST, or capability changes to existing abilities. Safe upgrade.<\/p>","0.0.10":"<p>Bugfix release. <code>Create_Zip_Backup<\/code> with <code>include_hidden=false<\/code> was silently descending into hidden directories and archiving their contents in 0.0.9 (only the top-level <code>.git\/<\/code> etc. entry was skipped, not the files beneath it). Fixed to check every segment of each entry&#039;s relative path. Regenerate any <code>include_hidden=false<\/code> archives created on 0.0.9 if their source tree contained hidden directories. No breaking changes; no database, REST, or capability changes. Safe upgrade.<\/p>","0.0.9":"<p>Adds eight new abilities: six under FileManager for zip-based backup \/ restore workflows (<code>zip-create<\/code>, <code>zip-upload<\/code>, <code>zip-extract<\/code>, <code>zip-download<\/code>, <code>zip-list<\/code>, <code>zip-delete<\/code>) plus <code>plugin-update<\/code> and <code>theme-update<\/code> that finally let AI clients apply pending WordPress core updates through the Abilities API. All new abilities enforce <code>manage_options<\/code>; mutating abilities additionally honour <code>DISALLOW_FILE_MODS<\/code>. Zip extraction rejects zip-slip archives (any entry containing <code>..<\/code>, an absolute path, a backslash, or a null byte). Zip uploads are validated for the <code>PK<\/code> magic signature before finalization. A new <code>wp-content\/uploads\/acrossai-backups\/<\/code> directory is created on first use, hardened with an <code>.htaccess<\/code> that blocks PHP execution but permits <code>.zip<\/code> downloads (required so the URLs returned by <code>zip-create<\/code> remain reachable). No breaking changes to existing abilities, REST endpoints, capability requirements, or database schema. Safe upgrade.<\/p>","0.0.8":"<p>IMPORTANT: this release <strong>removes the Freemius integration entirely<\/strong> \u2014 the plugin no longer sends any data to Freemius and no longer offers a Connect \/ Login \/ Buy affordance on the Add-ons page. If you previously connected a Freemius account tied to this plugin, that connection is now inert; stale <code>fs_*<\/code> or <code>freemius_*<\/code> rows in <code>wp_options<\/code> are safe to delete manually. Also: the Add-ons page now shows only free WordPress.org companion plugins (and no longer lists this plugin itself); the Library page compacts its title + bulk-action buttons onto one horizontal row; and <code>acrossai-co\/main-menu<\/code> bumps <code>0.0.14 \u2192 0.0.23<\/code>. No breaking changes to REST endpoints, capability requirements, or database schema. Safe upgrade.<\/p>","0.0.7":"<p>Adds Library page bulk Enable All \/ Disable All buttons scoped to the active tab, URL-synced tabs (<code>?tab=<\/code>) for deep-linkable views, and a readonly ability preview on disabled cards. No breaking changes; no database schema changes; no new REST endpoints; no new capability requirements. <code>mode<\/code> and per-slug selections are preserved through disable \/ enable cycles. Safe upgrade.<\/p>","0.0.6":"<p>IMPORTANT: this release absorbs the companion <code>acrossai-core-abilities<\/code> plugin \u2014 deactivate and uninstall that plugin after upgrading to avoid duplicate ability registrations. BREAKING for downstream integrators: 17 category slugs rebranded <code>acrossai-core-abilities-<\/code> \u2192 <code>acrossai-abilities-manager-<\/code> and 176 ability slugs <code>acrossai-core-abilities\/<\/code> \u2192 <code>acrossai\/<\/code>; update any MCP\/REST\/WP-CLI callers that referenced the legacy slugs. Ability payload shapes and permission callbacks unchanged. Also promotes Themes \/ Blocks \/ Plugins \/ Users \/ Database \/ Cron \/ Cache \/ File Manager to their own Library page tabs, bumps <code>acrossai-co\/main-menu<\/code> to <code>0.0.14<\/code>, and rotates Freemius credentials.<\/p>","0.0.5":"<p>Dependency-only release: refreshes the bundled <code>acrossai-co\/main-menu<\/code> package to <code>0.0.11<\/code>. No functional changes to this plugin. Safe upgrade.<\/p>","0.0.4":"<p>IMPORTANT for add-on developers: Library display fields <code>sub_group<\/code>, <code>sub_group_label<\/code>, and <code>tab_group<\/code> must now be nested under <code>$args[&amp;#039;meta&amp;#039;][&amp;#039;acrossai&amp;#039;]<\/code> when calling <code>wp_register_ability()<\/code>. The old top-level shape is silently dropped \u2014 cards will render without their sub-group heading or custom tab placement until you migrate. End users and site administrators are not affected; no data migration, no DB or REST changes. Also swaps the WordPress.org plugin icon to an SVG and drops the directory banners.<\/p>","0.0.3":"<p>Fixes the 0.0.2 activation error on WordPress.org installs \u2014 the release ZIP now includes the Composer autoloader. No functional or user-facing changes vs 0.0.2. If you hit the &quot;Composer autoloader is missing&quot; error on 0.0.2, delete the plugin folder and reinstall 0.0.3.<\/p>","0.0.2":"<p>IMPORTANT: (1) This release does NOT migrate Access Control rules from previous versions. If you had configured any Access Control rules on abilities, audit and reconfigure them after upgrading. Pre-existing rules remain in the database (in the orphaned <code>{prefix}wpb_access_control<\/code> table) but are no longer applied. (2) Ability execution logging has been removed \u2014 the Logs admin page is gone; ability-execution denials are no longer recorded by this plugin. Install a compatible logging plugin if you need this signal.<\/p>","0.0.1":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon.svg":{"filename":"icon.svg","revision":3595583,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3614045,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3614045,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.0.1","0.0.10","0.0.11","0.0.12","0.0.13","0.0.14","0.0.15","0.0.17","0.0.18","0.0.19","0.0.2","0.0.20","0.0.21","0.0.22","0.0.23","0.0.24","0.0.25","0.0.26","0.0.27","0.0.29","0.0.3","0.0.30","0.0.31","0.0.32","0.0.33","0.0.34","0.0.35","0.0.4","0.0.5","0.0.6","0.0.7","0.0.8","0.0.9"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3614043,"resolution":"1","location":"assets","locale":"","width":3268,"height":1874},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3614043,"resolution":"2","location":"assets","locale":"","width":3268,"height":1874},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3614043,"resolution":"3","location":"assets","locale":"","width":3268,"height":1874},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3614043,"resolution":"4","location":"assets","locale":"","width":3268,"height":1874},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3614043,"resolution":"5","location":"assets","locale":"","width":3268,"height":1874},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3614043,"resolution":"6","location":"assets","locale":"","width":3268,"height":1874}},"screenshots":{"1":"The Abilities Manager admin page \u2014 searchable, sortable ability table.","2":"The edit drawer \u2014 tri-state override controls for each ability field.","3":"Bulk actions toolbar for allow\/disallow\/reset across multiple abilities.","4":"The Ability Library page \u2014 enable\/disable add-on ability groups.","5":"The Add-ons page \u2014 browse free companion plugins.","6":"Settings \u2014 Display (abilities-per-page) and Upload Media Abilities (allowed-MIME list + Add file types)."}},"plugin_section":[],"plugin_tags":[251511,268952,1912,2353,174442],"plugin_category":[],"plugin_contributors":[140910],"plugin_business_model":[],"class_list":["post-311005","plugin","type-plugin","status-publish","hentry","plugin_tags-abilities","plugin_tags-ability-management","plugin_tags-access-control","plugin_tags-ai","plugin_tags-site-management","plugin_contributors-raftaar1191","plugin_committers-raftaar1191"],"banners":{"banner":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/banner-772x250.png?rev=3614045","banner_2x":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/banner-1544x500.png?rev=3614045","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/icon.svg?rev=3595583","icon":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/icon.svg?rev=3595583","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/screenshot-1.png?rev=3614043","caption":"The Abilities Manager admin page \u2014 searchable, sortable ability table."},{"src":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/screenshot-2.png?rev=3614043","caption":"The edit drawer \u2014 tri-state override controls for each ability field."},{"src":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/screenshot-3.png?rev=3614043","caption":"Bulk actions toolbar for allow\/disallow\/reset across multiple abilities."},{"src":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/screenshot-4.png?rev=3614043","caption":"The Ability Library page \u2014 enable\/disable add-on ability groups."},{"src":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/screenshot-5.png?rev=3614043","caption":"The Add-ons page \u2014 browse free companion plugins."},{"src":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/screenshot-6.png?rev=3614043","caption":"Settings \u2014 Display (abilities-per-page) and Upload Media Abilities (allowed-MIME list + Add file types)."}],"raw_content":"<!--section=description-->\n<p>AcrossAI Abilities Manager gives site administrators full visibility and control over every ability registered via the WordPress Abilities API (<code>wp_get_ability()<\/code>).<\/p>\n\n<p><strong>Features:<\/strong><\/p>\n\n<ul>\n<li><strong>Browse all abilities<\/strong> \u2014 a searchable, sortable, paginated table listing every registered ability with slug, provider, source, and current status.<\/li>\n<li><strong>Toggle allow\/disallow<\/strong> \u2014 enable or disable any ability site-wide with a single click. Changes are saved instantly without a page reload.<\/li>\n<li><strong>Edit ability metadata<\/strong> \u2014 override <code>readonly<\/code>, <code>destructive<\/code>, <code>idempotent<\/code>, <code>show_in_rest<\/code>, <code>show_in_mcp<\/code>, <code>mcp_type<\/code>, and <code>mcp_servers<\/code> fields per ability using a tri-state system (Yes \/ No \/ Inherit from registry).<\/li>\n<li><strong>Reset overrides<\/strong> \u2014 restore any ability back to its registry defaults with one click.<\/li>\n<li><strong>Bulk actions<\/strong> \u2014 allow, disallow, or reset up to 50 abilities at once.<\/li>\n<li><strong>Ability Library<\/strong> \u2014 enable or disable add-on ability groups from a dedicated Library page, with All\/Specific mode controls per group.<\/li>\n<li><strong>Add-ons page<\/strong> \u2014 browse companion plugins from the WordPress admin. WordPress.org-hosted add-ons install \/ activate \/ deactivate in place; add-ons distributed elsewhere link out to the vendor's site so you can install them via Plugins \u2192 Add New \u2192 Upload Plugin.<\/li>\n<li><strong>MCP server list<\/strong> \u2014 view all registered MCP servers when the MCP Adapter plugin is active.<\/li>\n<li><strong>Debugging \u2192 Conflict Testing<\/strong> \u2014 toggle any installed plugin's <em>effective<\/em> active state without ever writing to <code>wp_options.active_plugins<\/code>. Seven WP Abilities API abilities (<code>acrossai\/conflict-test-list-plugins<\/code>, <code>-get-overrides<\/code>, <code>-set-override<\/code>, <code>-bulk-set-overrides<\/code>, <code>-clear-overrides<\/code>, <code>-deploy-mu-plugin<\/code>, <code>-remove-mu-plugin<\/code>) let a REST client, MCP AI client, or another plugin reproduce a plugin conflict for a browser session or a support call, then restore the site to its exact prior state by clearing one JSON file. Overrides cascade through WP 6.5+ <code>Requires Plugins:<\/code> headers by default. Every <code>active=true<\/code> write is guarded by a WordPress-core-style <code>plugin_sandbox_scrape<\/code> probe, so a broken plugin can never leave the site in a state where every subsequent page load fatals \u2014 the override is refused instead. Feature 061.<\/li>\n<\/ul>\n\n<p>All overrides are stored in a dedicated database table. The WordPress ability registry is never modified \u2014 only the fields that differ from registry defaults are persisted.<\/p>\n\n<p><strong>Security:<\/strong><\/p>\n\n<ul>\n<li>All endpoints require <code>manage_options<\/code> capability.<\/li>\n<li>All state-changing requests are protected by WordPress nonce verification.<\/li>\n<li>All input is sanitized; all output is escaped.<\/li>\n<\/ul>\n\n<p><strong>Third-party integrations (optional):<\/strong><\/p>\n\n<ul>\n<li><strong>MCP Adapter plugin<\/strong> \u2014 if active, the plugin displays a list of registered MCP servers inside the ability edit panel. No data is sent to any external service. The MCP Adapter plugin communicates only with your own WordPress installation.<\/li>\n<\/ul>\n\n<p>This plugin's own code makes no external HTTP requests. One admin-only surface can contact an external service on your behalf: the AcrossAI \u2192 Add-ons page installs WordPress.org-hosted companion plugins directly through WordPress core's own plugin installer (<code>api.wordpress.org<\/code> + <code>downloads.wordpress.org<\/code>). Add-ons registered with any other source (e.g. GitHub, Freemius) are shown as external \"Get add-on \u2197\" links that open the vendor's site in a new browser tab \u2014 the plugin does not download or install them itself. The AcrossAI \u2192 Consultations submenu renders a static call-to-action button that opens <code>calendly.com<\/code> in a new browser tab only after the administrator clicks it \u2014 no third-party asset is loaded inside wp-admin. Full disclosure \u2014 including what data is transmitted to each service and links to their terms + privacy policies \u2014 is in the <strong>External Services<\/strong> section below.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>This plugin connects to the following external services on your behalf. Each connection is triggered by a specific admin-only action and is disclosed here per the WordPress.org plugin directory guidelines.<\/p>\n\n<p><strong>1. Calendly external link (<code>calendly.com<\/code>)<\/strong><\/p>\n\n<p><em>What it is:<\/em> Calendly is a third-party scheduling service. The AcrossAI \u2192 Consultations submenu displays a static call-to-action button that links out to a Calendly booking page for AcrossAI consultations (\"Using AI in WordPress\").<\/p>\n\n<p><em>When it is contacted:<\/em> Never on page render. The Consultations submenu at <code>\/wp-admin\/admin.php?page=acrossai-consultations<\/code> is a self-contained wp-admin page \u2014 it does not load any Calendly script, iframe, cookie, or asset. Calendly is only contacted if the administrator explicitly clicks the \"Book a Consultation\" button, at which point their browser navigates directly to <code>https:\/\/calendly.com\/acrossai\/using-ai-in-wordpress<\/code> in a new tab (<code>target=\"_blank\" rel=\"noopener noreferrer\"<\/code>). This is identical to clicking any external hyperlink from an admin page.<\/p>\n\n<p><em>What is loaded on the Consultations page:<\/em> Nothing from Calendly. The page renders self-contained HTML + CSS. The only external asset referenced by the page is Google Fonts (Space Grotesk + IBM Plex Sans via <code>fonts.googleapis.com<\/code>) \u2014 permitted under the \"third-party CDNs beyond fonts\" carve-out in the WordPress plugin guidelines.<\/p>\n\n<p><em>What data is transmitted to Calendly:<\/em> Nothing by this plugin. If the administrator clicks the CTA button, their browser navigates directly to Calendly and sends standard browser metadata (IP address, User-Agent, referrer) to Calendly as with any external link. If the administrator then chooses to book a consultation on Calendly's own site, any information they enter into Calendly's booking form (name, email address, meeting preferences, etc.) is transmitted to and processed by Calendly. This plugin does not intercept, store, or forward that data.<\/p>\n\n<p><em>Terms of service:<\/em> https:\/\/calendly.com\/pages\/terms\n<em>Privacy policy:<\/em> https:\/\/calendly.com\/pages\/privacy<\/p>\n\n<p><strong>2. WordPress.org plugin directory (<code>api.wordpress.org<\/code> and <code>downloads.wordpress.org<\/code>)<\/strong><\/p>\n\n<p><em>What it is:<\/em> The Add-ons page (<code>\/wp-admin\/admin.php?page=acrossai-addons<\/code>) uses the WordPress.org plugin directory to install free companion plugins directly from wp-admin.<\/p>\n\n<p><em>When it is contacted:<\/em> Only when an authenticated administrator (<code>install_plugins<\/code> capability) clicks the \"Install\" button on a card whose <code>source<\/code> is <code>wordpress.org<\/code>. Contact happens through WordPress core's own <code>plugins_api()<\/code> and <code>Plugin_Upgrader<\/code> \u2014 this plugin does not issue direct HTTP requests. Add-ons registered with any other source (e.g. <code>github<\/code>, <code>freemius<\/code>) are rendered as external \"Get add-on \u2197\" links that open the vendor's site in a new browser tab; the plugin does NOT download or install those add-ons itself, so no request is made to the vendor's servers from wp-admin.<\/p>\n\n<p><em>What data is transmitted:<\/em> The WordPress core plugin API request payload (site URL, WP version, PHP version, locale) as per WordPress core's standard update check protocol.<\/p>\n\n<p><em>Terms of service:<\/em> https:\/\/wordpress.org\/about\/terms\/\n<em>Privacy policy:<\/em> https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<p><strong>3. WordPress.org core version-check API (<code>api.wordpress.org\/core\/version-check\/1.7\/<\/code>)<\/strong><\/p>\n\n<p>Called only when an administrator invokes the <code>core\/rollback-wp-core<\/code> ability (registered under the Core category) and the local core-version cache has expired. Rate-bounded to at most one request per day per locale per site via a site-transient cache. This is a WordPress-core-hosted API \u2014 no data beyond the standard WordPress core version-check request payload is transmitted. Same wp.org terms + privacy policy as service #2 above.<\/p>\n\n<p><strong>4. YouTube walkthrough videos (<code>youtube-nocookie.com<\/code>, <code>youtube.com<\/code>)<\/strong><\/p>\n\n<p><em>What it is:<\/em> The Quick Connect setup wizard embeds short walkthrough recordings that explain how to\nedit an ability, how to use bulk actions, and how to reach abilities through the MCP Adapter's\ndefault server. Embeds use YouTube's privacy-enhanced host, <code>www.youtube-nocookie.com<\/code>.<\/p>\n\n<p><em>When it is contacted:<\/em> Only on the wizard's own screens, and never anywhere else in wp-admin \u2014 the\nwizard's assets are gated on the <code>quick-connect<\/code> request parameter and load on no other admin page.\nOn two of those screens the recording begins on its own, so YouTube is contacted when the screen\nrenders rather than on a click. On the remaining screens nothing is requested from YouTube until the\nadministrator presses play: a locally-hosted placeholder is shown first and the embed is inserted\nonly on that click.<\/p>\n\n<p><em>What data is transmitted:<\/em> Nothing by this plugin. Loading an embed causes the administrator's own\nbrowser to send standard metadata to YouTube (IP address, User-Agent) together with a <code>Referer<\/code>\nlimited to the site's origin \u2014 the <code>strict-origin-when-cross-origin<\/code> referrer policy means the\nwp-admin path and query string are never disclosed. The privacy-enhanced host does not set tracking\ncookies unless playback begins. This plugin transmits no site content, user data, or ability data to\nYouTube.<\/p>\n\n<p><em>Avoiding it entirely:<\/em> Every embed is paired with a plain external link, so the wizard remains\nusable when the embed is blocked by connectivity, a privacy tool, or a regional restriction. The\nwizard can also simply be skipped \u2014 it is optional and every screen offers Exit setup.<\/p>\n\n<p><em>Terms of service:<\/em> https:\/\/www.youtube.com\/t\/terms\n<em>Privacy policy:<\/em> https:\/\/policies.google.com\/privacy<\/p>\n\n<p><strong>5. GitHub release page (<code>github.com<\/code>)<\/strong><\/p>\n\n<p><em>What it is:<\/em> MCP Adapter is distributed from GitHub rather than the WordPress plugin directory. The\nwizard's adapter screen links to that project's latest release page so the administrator can\ndownload the plugin archive.<\/p>\n\n<p><em>When it is contacted:<\/em> Never on page render. The screen shows a plain link; GitHub is contacted\nonly if the administrator clicks it, at which point their browser navigates to\n    https:\/\/github.com\/WordPress\/mcp-adapter\/releases\/latest in a new tab. The plugin performs no\nHTTP request to GitHub and does not download or install anything from it.<\/p>\n\n<p><em>What data is transmitted:<\/em> Nothing by this plugin. Standard browser metadata only, as with any\nexternal hyperlink.<\/p>\n\n<p><em>Terms of service:<\/em> https:\/\/docs.github.com\/site-policy\/github-terms\/github-terms-of-service\n<em>Privacy policy:<\/em> https:\/\/docs.github.com\/site-policy\/privacy-policies\/github-privacy-statement<\/p>\n\n<h3>Privacy Policy<\/h3>\n\n<p>This plugin does not itself collect, store, or transmit any user data to any third party.<\/p>\n\n<p>Several admin-only actions can cause external services to receive data \u2014 all are described in the External Services section above and are triggered only by an authenticated administrator:<\/p>\n\n<ul>\n<li>The AcrossAI \u2192 Consultations admin page displays a static call-to-action button. Merely loading the Consultations page sends no data to Calendly \u2014 no Calendly script, iframe, or asset is loaded inside wp-admin. If the administrator clicks the CTA button, their browser opens <code>calendly.com\/acrossai\/using-ai-in-wordpress<\/code> in a new tab, at which point standard browser metadata (IP, User-Agent, referrer) is sent to Calendly and Calendly's own privacy policy applies. If they then book a consultation on Calendly's site, information they enter into Calendly's form (name, email, meeting details) is transmitted to Calendly.<\/li>\n<li>Installing a WordPress.org-hosted add-on from the AcrossAI \u2192 Add-ons page contacts the WordPress.org plugin directory via WordPress core's own <code>plugins_api()<\/code> and <code>Plugin_Upgrader<\/code> (<code>api.wordpress.org<\/code> + <code>downloads.wordpress.org<\/code>). Add-ons distributed elsewhere (e.g. GitHub, Freemius) are rendered as external \"Get add-on \u2197\" links that open the vendor's site in a new browser tab \u2014 the plugin itself does not download or install those add-ons, so no request is sent to the vendor's servers from wp-admin. If the administrator clicks the external link, their browser navigates directly to the vendor and standard browser metadata (IP, User-Agent, referrer) is sent to the vendor as with any external hyperlink.<\/li>\n<li>Invoking the <code>core\/rollback-wp-core<\/code> ability contacts the WordPress.org core version-check API (a WordPress-core-hosted service) via the standard WordPress update API.<\/li>\n<\/ul>\n\n<p>No data is sent to any external server without an explicit administrator action.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>acrossai-abilities-manager<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> menu in WordPress.<\/li>\n<li>Navigate to <strong>AcrossAI Abilities Manager<\/strong> in the WordPress admin menu.<\/li>\n<\/ol>\n\n<p><strong>Quick Connect setup wizard:<\/strong><\/p>\n\n<p>On activation the plugin opens a short setup wizard once \u2014 how many abilities the site has, how to\nedit them, how to act on many at once, what they cover, and how to connect them to an AI assistant.\nIt does not open on sites already running AcrossAI MCP Manager, which provides its own wizard.<\/p>\n\n<p>The wizard is re-runnable at any time and is reachable from four places: <strong>AcrossAI \u2192 Quick\nConnect<\/strong> in the sidebar, the <strong>Quick Connect via AcrossAI<\/strong> entry in the admin toolbar, the\n<strong>Quick Connect via AcrossAI<\/strong> link on the Plugins screen, and a button under <strong>Setup<\/strong> on the\nAcrossAI \u2192 Settings \u2192 Abilities tab. Those entries are hidden when AcrossAI MCP Manager is active,\nto avoid two wizards competing for the same surfaces; the wizard itself stays reachable at\n    \/wp-admin\/admin.php?page=acrossai-abilities-manager&amp;quick-connect=1&amp;step=1.<\/p>\n\n<p><strong>Add-ons:<\/strong><\/p>\n\n<ol>\n<li>Go to <strong>AcrossAI \u2192 Add-ons<\/strong> to browse available companion plugins.<\/li>\n<li>All add-ons are free and hosted on WordPress.org; each card offers a one-click Install \/ Activate \/ Deactivate action via the standard WordPress plugin installer.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20support%20multisite%3F\"><h3>Does this plugin support Multisite?<\/h3><\/dt>\n<dd><p>No. This plugin has not been tested on WordPress Multisite installations.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20modify%20the%20wordpress%20ability%20registry%3F\"><h3>Does this plugin modify the WordPress ability registry?<\/h3><\/dt>\n<dd><p>No. The plugin stores only overrides \u2014 fields that differ from the registry defaults. The ability registry itself (<code>wp_get_ability()<\/code>) is never modified.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20reset%20an%20override%3F\"><h3>What happens when I reset an override?<\/h3><\/dt>\n<dd><p>The override row is deleted from the database. The ability will inherit its values from the registry again.<\/p><\/dd>\n<dt id=\"what%20is%20the%20ability%20library%3F\"><h3>What is the Ability Library?<\/h3><\/dt>\n<dd><p>The Library page lets you enable or disable ability groups registered by add-on plugins. Each group shows an ON\/OFF master toggle and an All\/Specific mode selector. In Specific mode, individual ability slots can be toggled independently.<\/p><\/dd>\n<dt id=\"what%20is%20the%20mcp%20adapter%20integration%3F\"><h3>What is the MCP Adapter integration?<\/h3><\/dt>\n<dd><p>If the MCP Adapter plugin is active on your site, AcrossAI Abilities Manager will display the list of registered MCP servers in the ability edit panel. This is entirely optional \u2014 the plugin works without the MCP Adapter.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20make%20external%20http%20requests%3F\"><h3>Does this plugin make external HTTP requests?<\/h3><\/dt>\n<dd><p>The plugin's own code makes no external HTTP requests. Two admin-only surfaces trigger external connections on behalf of an authenticated administrator:<\/p>\n\n<ul>\n<li><strong>AcrossAI \u2192 Consultations<\/strong> submenu \u2014 renders a static call-to-action button that links to <code>https:\/\/calendly.com\/acrossai\/using-ai-in-wordpress<\/code> and opens in a new browser tab. The plugin does not load any Calendly script, iframe, or asset inside wp-admin. Calendly is only contacted if the administrator explicitly clicks the button \u2014 at which point their browser navigates directly to <code>calendly.com<\/code>, exactly as with any external hyperlink.<\/li>\n<li><strong>AcrossAI \u2192 Add-ons<\/strong> submenu \u2014 installs WordPress.org-hosted companion plugins in place through WordPress core's <code>plugins_api()<\/code> + <code>Plugin_Upgrader<\/code> (contacts <code>api.wordpress.org<\/code> + <code>downloads.wordpress.org<\/code>). Add-ons registered with any other source (e.g. GitHub, Freemius) render as external \"Get add-on \u2197\" links that open the vendor's site in a new browser tab \u2014 the plugin does not download or install those add-ons itself. Users install off-directory add-ons via WP admin's standard <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong> flow (or via the vendor's own installer once the paid plugin is activated).<\/li>\n<\/ul>\n\n<p>Full disclosure \u2014 including what data is transmitted, and links to each service's terms + privacy policy \u2014 is in the <strong>External Services<\/strong> section of this readme.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>Unreleased<\/h4>\n\n<p>(nothing yet)<\/p>\n\n<h4>0.0.35 - 2026-09-21<\/h4>\n\n<ul>\n<li><strong>The backup abilities are now two tabs, one per plugin.<\/strong> <code>UpdraftPlus<\/code> and <code>All-in-One WP Migration<\/code> each get their own tab, their own toolset and their own abilities, the same way Elementor, Rank Math, WPCode and every other integration works. 0.0.34 shipped them as a single \"Backups\" tab that reached both plugins through a shared layer; that made two genuinely different plugins look interchangeable and turned every real difference into a flag you had to go and check.<\/li>\n<li><strong>Each suite now offers only what its plugin can actually do.<\/strong> UpdraftPlus schedules backups and restores them, and stores no label - so it has no label ability. All-in-One labels its archives, and restoring belongs to their paid Unlimited Extension - so that ability asks the plugin and passes its own answer back, naming the manual import route, rather than refusing on its behalf.<\/li>\n<li><strong>Breaking: the <code>backups\/*<\/code> abilities are gone.<\/strong> They are replaced by <code>updraftplus\/*<\/code> and <code>all-in-one\/*<\/code>. Anything holding a <code>backups\/<\/code> slug needs updating; there are no aliases. The suite was one release old.<\/li>\n<li><strong>Fixed: restoring never worked outside the admin screens.<\/strong> The restore checked whether WordPress could write to the filesystem directly - the check that stops a restore dying half-way through - using a function WordPress only loads inside wp-admin. Every restore request therefore failed on that line before checking anything, whatever it was asked to do. This shipped in 0.0.34 and is fixed here.<\/li>\n<li><strong>The exposure check is shared and reports per plugin.<\/strong> Whether the web server will hand out a backup archive has nothing to do with which plugin wrote it, so that logic exists once - but each tab now reports on its own storage rather than on everything at once.<\/li>\n<\/ul>\n\n<h4>0.0.34 - 2026-09-18<\/h4>\n\n<p>The largest release so far: 25 features, 19 new tabs and around 400 new abilities. The theme is reach and honesty - most of the popular plugins a site actually runs can now be driven directly, each behind this plugin's own permission floor, and every ability that cannot do something says why and names the route that works instead.<\/p>\n\n<p><strong>Breaking changes<\/strong><\/p>\n\n<ul>\n<li><strong>Abilities now require administrator rights unless you say otherwise.<\/strong> If anyone below administrator drives this site through an AI client - a shop manager running a store, for example - they lose access on update until an administrator grants it. Set a rule on the individual ability under User Access, or move the site-wide floor with the <code>acrossai_default_ability_capability<\/code> filter.<\/li>\n<li><strong>Why: every plugin chose its own lock, and nobody was checking them.<\/strong> Measured across the abilities installed on one site: three registered with no permission check at all, two were open to any logged-in subscriber, and one that <em>writes content<\/em> was open at contributor level. This plugin now decides who may run an ability, whoever registered it.<\/li>\n<li><strong>Setting access used to be able to remove the lock.<\/strong> Choosing \"Everyone\" on an ability replaced its built-in check with one that allowed anybody - an action that reads as tightening actually opened the door. Access rules now sit on top of a floor that cannot be removed by accident.<\/li>\n<\/ul>\n\n<p><strong>New tabs<\/strong><\/p>\n\n<ul>\n<li><strong>Store (WooCommerce) - 34 abilities.<\/strong> The catalogue, pricing, stock, orders, customers, coupons, tax, shipping and store settings, plus WooCommerce's own seven adopted into the same tab. Variable products can now be created at all, which WooCommerce's own abilities cannot do.<\/li>\n<li><strong>Backups - 9 abilities.<\/strong> Whether this site can be recovered: what exists, when it last ran and whether it worked, whether the archives are reachable over HTTP, and taking, labelling, deleting or restoring one. Works with UpdraftPlus and All-in-One WP Migration through one set of abilities.<\/li>\n<li><strong>Yoast SEO - 64 abilities<\/strong>, and Yoast's own two now have a home.<\/li>\n<li><strong>LiteSpeed Cache - 61 abilities.<\/strong><\/li>\n<li><strong>Contact Form 7 - 25 abilities<\/strong>, and <strong>WPForms'<\/strong> own abilities now have a home with an off switch for form writing.<\/li>\n<li><strong>WPCode - 24 abilities<\/strong>, adopting the five WPCode already had.<\/li>\n<li><strong>Cookie Consent - 22 abilities<\/strong>, with an honest account gate rather than silent failure.<\/li>\n<li><strong>The Events Calendar - 18 abilities<\/strong> and <strong>Event Tickets - 16<\/strong>, with capacity modelled and personal data gated.<\/li>\n<li><strong>Advanced Custom Fields - 16 abilities<\/strong>, joining the existing ACF tab.<\/li>\n<li><strong>Translations - 14 abilities.<\/strong><\/li>\n<li><strong>Email Delivery - 4 abilities<\/strong>, plus a home for the ones the mail plugin ships, and <strong>Akismet's<\/strong> own abilities adopted.<\/li>\n<li><strong>Classic Editor - 4 abilities<\/strong> for what nothing else can reach.<\/li>\n<\/ul>\n\n<p><strong>Safety<\/strong><\/p>\n\n<ul>\n<li><strong>Fixed: editing a WooCommerce product or order through the generic content tools silently corrupted the store.<\/strong> Writing a price through <code>content\/update-cpt-item<\/code> left the price the shop actually charges on the old value, and saving the product correctly afterwards did not repair it. Orders were worse: WooCommerce no longer keeps them in the posts table, so the write changed a row nothing reads and was later deleted. Both are now refused, naming the ability that does work.<\/li>\n<li><strong>A backup archive that anyone can download is a total compromise, and this now checks for it.<\/strong> Both backup plugins drop a .htaccess to prevent it; on nginx, IIS and Caddy that file is never read, so the protection is present, looks correct, and does nothing.<\/li>\n<li><strong>Restoring says plainly that it cannot be undone<\/strong>, and records what the site looked like beforehand so what was given up is visible.<\/li>\n<\/ul>\n\n<p><strong>The abilities screen<\/strong><\/p>\n\n<ul>\n<li><strong>Integration tabs are now named after the plugin they drive<\/strong>, and abilities registered by other plugins now belong to a toolset instead of vanishing into a catch-all.<\/li>\n<li><strong>One screen, one access model.<\/strong> The registration gate is gone; tabs were regrouped into task groups, and deep links to retired tabs fall back to \"All\".<\/li>\n<li><strong>Fixed: WPCode's own five abilities were never actually adopted<\/strong> into its tab - the prefix could not match.<\/li>\n<\/ul>\n\n<p>For the complete detail of this release - all 156 entries - and the full history of every earlier release, see changelog.txt inside the plugin, or\nhttps:\/\/github.com\/acrossaico\/acrossai-abilities-manager\/blob\/main\/changelog.txt<\/p>\n\n<h4>0.0.33 - 2026-08-28<\/h4>\n\n<p><strong>Release theme: closing the cheap-edit loop.<\/strong> A follow-up to 0.0.32 that closes the last two gaps between \"locate a block cheaply\" and \"modify it cheaply\". Two changes, both surgical and backwards-compatible.<\/p>\n\n<p><strong><code>return_content:false<\/code> default now covers the two block-tree writers.<\/strong> <code>blocks\/add-block<\/code> and <code>blocks\/update-post-block<\/code> gain the same <code>return_content:{boolean, default:false}<\/code> input as the six content writers (PR #152) and nine block-editor writers (PR #153). When false (default), the response's <code>block<\/code> object strips its <code>innerHTML<\/code>, <code>innerContent<\/code>, and <code>innerBlocks<\/code> \u2014 leaving <code>blockName<\/code>, <code>attrs<\/code>, and <code>path<\/code> \u2014 and <code>content_bytes<\/code> reports the saved <code>innerHTML<\/code> size. Container blocks (columns, cover, group) previously echoed their entire innerBlocks subtree; now they don't unless the caller passes <code>return_content:true<\/code>. BREAKING for callers reading <code>response.block.innerHTML<\/code> on these two abilities \u2014 pass <code>return_content:true<\/code> explicitly. Every other block-tree read\/write (mutate-block-tree, replace-block-text, remove-block, duplicate-block, move-block) already returned lightweight envelopes and is unchanged.<\/p>\n\n<p><strong><code>blocks\/get-post-blocks<\/code> gains scoping inputs.<\/strong> Three new optional inputs close the \"read one block's markup\" gap between <code>blocks\/get-post-blocks<\/code> (full tree, full content) and <code>blocks\/outline-post-blocks<\/code> (scoped but never returns content). <code>path: int[]<\/code> scopes the response to a subtree (uses the same raw parse_blocks() index scheme as add-block \/ update-post-block \/ remove-block, so returned paths interchange). <code>depth: integer<\/code> bounds descent below the subtree root (-1 unlimited, 0 subtree root only, N below). <code>include_html: boolean<\/code> (default true = backwards-compat) strips innerHTML + innerContent from every returned node when false. Backwards-compatible: existing callers passing only <code>post_id<\/code> see identical responses. An unresolvable <code>path<\/code> returns a standard error envelope with <code>error_code: invalid_path<\/code> naming which depth failed and how many blocks exist at that level.<\/p>\n\n<h4>0.0.32 - 2026-08-28<\/h4>\n\n<p><strong>Release theme: token-efficient AI callers.<\/strong> Two closely related shifts. First, response payloads shrink dramatically for the common \"small edit\" and \"just tell me the block structure\" intents. Second, ability descriptions gain author-declared hints pointing AI callers at cheaper sibling abilities when their intent maps to one. Every change is either strictly additive or opt-out only via an admin toggle \u2014 no ability's execute() behaviour changes.<\/p>\n\n<p><strong>Token-efficiency default for six content writers.<\/strong> <code>content\/create-page<\/code>, <code>content\/update-page<\/code>, <code>content\/create-post<\/code>, <code>content\/update-post<\/code>, <code>content\/create-cpt-item<\/code>, <code>content\/update-cpt-item<\/code> gain a new optional input <code>return_content:boolean, default:false<\/code>. When false (the default), the response's <code>page<\/code> \/ <code>post<\/code> \/ <code>item<\/code> object strips three large fields \u2014 <code>post_content<\/code>, <code>post_content_filtered<\/code>, <code>post_excerpt<\/code> \u2014 and adds <code>content_bytes:integer<\/code> so callers still see the saved payload size at a glance.<\/p>\n\n<p><strong>Why.<\/strong> A single-word edit on a ~97 KB page via <code>content\/update-page<\/code> previously round-tripped ~60 K LLM tokens (the caller sent the whole new body and the ability echoed the same body back). With this default, the echo drops to ~0 tokens \u2014 the caller pays only for the upload it already had to make. Fine-grained edits via <code>blocks\/update-post-block<\/code> remain ~10\u00d7 cheaper still because they never touch the surrounding content.<\/p>\n\n<p><strong>BREAKING for callers reading <code>response.page.post_content<\/code> (or <code>.post<\/code> \/ <code>.item<\/code> equivalents).<\/strong> Existing callers that need the saved content back \u2014 e.g. to diff against what they sent \u2014 must pass <code>return_content:true<\/code> explicitly. The three stripped fields remain queryable via <code>content\/get-page<\/code> \/ <code>content\/get-post<\/code> after the write.<\/p>\n\n<p><strong>Not affected.<\/strong> Every other content ability (get \/ list \/ delete \/ block-tree operations \/ meta ops) is unchanged. The block-tree writers (<code>blocks\/update-post-block<\/code>, <code>blocks\/add-block<\/code>, etc.) already returned just the modified block, not the whole page \u2014 nothing to strip.<\/p>\n\n<p><strong>Same default now applies to nine block-editor writers.<\/strong> <code>blocks\/create-block-pattern<\/code>, <code>blocks\/create-block-template<\/code>, <code>blocks\/update-block-template<\/code>, <code>blocks\/create-block-template-part<\/code>, <code>blocks\/update-block-template-part<\/code>, <code>blocks\/create-block-style-variation<\/code>, <code>blocks\/update-block-style-variation<\/code>, <code>blocks\/create-global-style<\/code>, and <code>blocks\/update-global-style<\/code> gain the same <code>return_content:boolean, default:false<\/code> input. Response objects (<code>pattern<\/code> \/ <code>template<\/code> \/ <code>part<\/code> \/ <code>variation<\/code> \/ <code>record<\/code>) strip the large <code>content<\/code> (pattern\/template\/template-part markup) or <code>data<\/code> (variation\/theme.json JSON) field by default and add <code>content_bytes:integer<\/code>. For <code>Variation_Db::to_row<\/code> and <code>Global_Styles_Db::to_row<\/code>, the writers now pass the caller's <code>$return_content<\/code> through instead of hardcoding <code>true<\/code> \u2014 the helpers skip <code>decode_content()<\/code> when the payload isn't wanted (CPU saving on the hot path). BREAKING for callers reading <code>response.pattern.content<\/code>, <code>response.template.content<\/code>, <code>response.part.content<\/code>, <code>response.variation.data<\/code>, or <code>response.record.data<\/code> \u2014 pass <code>return_content:true<\/code> explicitly. <code>blocks\/update-block-pattern<\/code> is unchanged \u2014 it already returned a lightweight location descriptor.<\/p>\n\n<p><strong>New ability <code>blocks\/outline-post-blocks<\/code>.<\/strong> Returns a flat, depth-first index of a post's block tree \u2014 canonical path, block type, child count, byte size, and a short text preview \u2014 without any block content. Cheap way for an LLM caller to locate a block before editing it: <code>blocks\/get-post-blocks<\/code> on a large page can be hundreds of kilobytes because it returns every block's full <code>innerHTML<\/code>; this ability returns kilobytes for the same post. Paths use the same raw-<code>parse_blocks()<\/code> index scheme as <code>Block_Tree<\/code>, so a path returned here is drop-in usable with <code>blocks\/add-block<\/code>, <code>blocks\/update-post-block<\/code>, and <code>blocks\/remove-block<\/code>. Paths are positional \u2014 a write can re-serialize the post and shift raw indices \u2014 so the response includes <code>post_modified_gmt<\/code> for staleness detection; re-outline after each write rather than caching paths. Filters (<code>block_names<\/code>, <code>contains<\/code>, <code>max_text<\/code>, <code>depth<\/code>, <code>include_attrs<\/code>, <code>max_results<\/code>) compose. <code>contains<\/code> matches only within the extracted text preview (up to <code>max_text<\/code> characters); raise <code>max_text<\/code> for deeper substring searches. Whitespace nodes (<code>parse_blocks<\/code> entries with null <code>blockName<\/code>) are excluded from output but still consume index positions \u2014 same convention <code>Block_Tree<\/code> already uses. <code>readonly<\/code>, <code>idempotent<\/code>, <code>non-destructive<\/code>.<\/p>\n\n<p><strong>New \u2014 Ability Suggestions framework (Feature 095).<\/strong> Ability authors can now declare a small list of other abilities an AI caller might use instead \u2014 a token-saving hint mechanism mirroring Feature 088's <code>suggested_plugins()<\/code>. Each ability class can override a new protected method <code>suggested_abilities()<\/code> returning <code>array&lt;int, array{slug: string, reason: string, saves?: string}&gt;<\/code>; entries surface under <code>args.meta.acrossai.suggested_abilities<\/code> on <code>mcp-adapter-get-ability-info<\/code> (not on discover-abilities \u2014 details-only surface, avoids discovery bloat). Hints are strictly advisory \u2014 nothing about the original ability's execution changes. Four initial ability overrides ship in this release: <code>content\/update-page<\/code>, <code>content\/update-post<\/code>, <code>content\/update-cpt-item<\/code> each suggest <code>blocks\/outline-post-blocks<\/code> + <code>blocks\/update-post-block<\/code> for narrow edits (~29K tokens saved on a 97 KB page); <code>blocks\/get-post-blocks<\/code> suggests <code>blocks\/outline-post-blocks<\/code> when only paths are needed (~28K tokens saved on the same page). New admin toggle \"Disable ability suggestions\" on the Abilities settings tab (between \"Plugin Suggestions\" and \"Uninstall Settings\") strips the field site-wide (option key <code>acrossai_disable_ability_suggestions<\/code>, default <code>0<\/code> = feature enabled). Uninstall cleans up the option when \"delete all data\" is on. An ability with no override produces a byte-identical payload to what it produced before Feature 095 \u2014 no schema drift, no phantom empty list.<\/p>\n\n<p><strong>Ten more <code>suggested_abilities()<\/code> overrides added to the Feature 095 hint catalog.<\/strong> <code>content\/get-page<\/code>, <code>content\/get-post<\/code>, <code>content\/get-cpt-item<\/code> each hint that <code>blocks\/outline-post-blocks<\/code> is far cheaper (~20\u00d7) when the caller only needs to locate a block or see the structure. <code>blocks\/read-theme-json<\/code> hints that <code>blocks\/get-style-guide<\/code> returns a normalized token summary (~5\u20138\u00d7) when the caller wants design tokens, not the raw spec. <code>options\/list-options<\/code>, <code>media\/list-media<\/code>, <code>users\/list-users<\/code>, <code>blocks\/list-block-templates<\/code>, <code>blocks\/list-block-patterns<\/code>, <code>blocks\/list-global-styles<\/code> each hint that their corresponding targeted-read siblings (<code>options\/get-option<\/code>, <code>media\/get-media<\/code>, <code>users\/get-user<\/code>, <code>blocks\/read-block-template<\/code>, <code>blocks\/read-block-pattern<\/code>, <code>blocks\/read-global-style<\/code>) are 5\u201330\u00d7 cheaper when the caller already knows the identifier \u2014 list is for discovery, get\/read is for retrieval.<\/p>\n\n<h4>Earlier releases<\/h4>\n\n<p>Every release before 0.0.32 is recorded in full in changelog.txt, shipped inside the plugin and readable at\nhttps:\/\/github.com\/acrossaico\/acrossai-abilities-manager\/blob\/main\/changelog.txt<\/p>","raw_excerpt":"Manage every WordPress ability registered on your site \u2014 view, search, override, and bulk-control ability metadata from a single admin page.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/311005","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=311005"}],"author":[{"embeddable":true,"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/raftaar1191"}],"wp:attachment":[{"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=311005"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=311005"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=311005"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=311005"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=311005"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=311005"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}