Repository navigation
WP.org review compliance + AI connector fixes - #227
Conversation
Address the WordPress.org plugin directory pre-review for "agentic-admin". Ownership: submit as an individual (Author "Marcel Schmitz", Contributors "schmitzoide", Author URI to the WP.org profile) instead of the "Pluginslab" entity, so no trademark/domain ownership check applies. Prefix: drop the "wp" prefix flagged as reserved/common. Constants WP_AGENTIC_ADMIN_* -> AGENTIC_ADMIN_*, namespace/class WPAgenticAdmin -> AgenticAdmin, JS global wpAgenticAdmin -> agenticAdmin, ability IDs and REST namespace wp-agentic-admin/* -> agentic-admin/*, CSS classes, phpcs prefix allow-list, and the webpack chunk global (package.json name -> agentic-admin). Main file renamed wp-agentic-admin.php -> agentic-admin.php to match the slug; .distpackage and Playground blueprints updated. Other flagged items: Plugin URI 404 -> GitHub repo; NVD terms URL /general/ -> /developers/terms-of-use; admin menu position 3 -> null (appended to bottom). sw-loader.php direct access left intentional (documented). Verified: 96 unit tests pass, production build OK, composer lint exit 0, lint-js 0 errors. Version stays 0.11.0 (submission was pended, not published). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
WordPress.org plugin review (manual pass) plus AI Connector bug fixes. Review fixes: - Trialware (Guideline 5): remove the LABS opt-in gate; delete write-file and content-generate abilities; promote discover/run-plugin-ability to core so the third-party Plugin Abilities platform ships fully enabled. - Unsafe SQL: remove the query-database ability (LLM-authored arbitrary SQL). - cURL: drop the curl SSE path in the LLM proxy; use the WP HTTP API only. - Direct file access: serve the service worker through admin-post.php (WordPress loaded) and delete sw-loader.php. - Generic prefixes: rename the stray wpaa_ transient and error codes to agentic_admin_. - File locations: use WPMU_PLUGIN_DIR and WPINC instead of hardcoded paths; the remaining ABSPATH/WP_PLUGIN_DIR uses are read-only core/plugin scans. - Source/build: document the voy-search wasm and build steps in the readme. The Transformers.js embedding library stays a documented opt-in CDN service (bundling it pulls in an ONNX runtime that does not bundle cleanly). AI Connector fixes (pre-existing bugs): - is_connected and the chat "configured" check used AiClient isProviderConfigured(), which is non-deterministic and made the connector list flap to "none configured" and return spurious 400s. Replaced with a deterministic credential-presence check. - Surface WP 7.0's connector-approval gate as an actionable message pointing to Tools -> AI Connector Approval instead of a raw network error. Verified: composer lint 0, lint-js 0, 91 unit tests pass. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The inline plugin activate/deactivate buttons (ActionButton + INVERSE_ACTIONS in MessageItem) were fed only by the content-generate auto-insert path, which was removed during the WP.org trialware cleanup. Nothing populated message.actions anymore, leaving stateless dead buttons. Remove ActionButton, the inverse-action map, the messageActions rendering, and the now-unused onAction plumbing (MessageList, ChatContainer handleAction + toolRegistry/executeAbility imports). Plugins are still activated/deactivated via natural language. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
ivdimova
left a comment
There was a problem hiding this comment.
Review
Overall this is a well-reasoned PR — the connector bug fix and WP.org compliance work are solid. A few things to address before merging:
🔴 Settings data loss on upgrade
ARCHITECTURE.md notes the settings option key changes from wp_agentic_admin_settings → agentic_admin_settings, but there is no migration in activate(). Existing users who upgrade will silently lose all saved settings (model selection, endpoint URL, API keys, etc.).
Needs a migration in activate():
$old = get_option( 'wp_agentic_admin_settings' );
if ( $old && ! get_option( 'agentic_admin_settings' ) ) {
update_option( 'agentic_admin_settings', $old );
}🟡 Broken indentation in class-llm-proxy.php — proxy_streaming()
After removing the cURL block the remaining code has inconsistent indentation — if ( \is_wp_error( $response ) ) is at 1 tab instead of 2, and flush() is over-indented. The PR description says composer lint passed; worth re-running against this file specifically since WPCS can miss whitespace-only diffs in some configurations.
🟡 Broken repo URLs in docs
Several docs were updated to reference pluginslab/agentic-admin but the GitHub repo is still pluginslab/wp-agentic-admin:
ONBOARDING.md:git clone https://github.com/pluginslab/agentic-admin.git→ 404README.md: Playground badge URL →pluginslab/agentic-admin/main/.playground/blueprint.json→ badge broken
These should stay as pluginslab/wp-agentic-admin until the repo is actually renamed on GitHub.
✅ What looks good
is_connector_configured()is a clean fix — deterministic credential-presence check, well-commented rationale for replacingisProviderConfigured()- WP 7.0 approval gate: catching "not been approved" and returning a 403 with
approval_urlin the error body is great UX admin_post_agentic_admin_sw+admin_post_nopriv_agentic_admin_swpair is correct — SW must be accessible to unauthenticated browser fetches- All
WP_Errorcodes consistently renamedwpaa_*→agentic_admin_* - Rate limiter transient key renamed (
wpaa_conn_rl_→agentic_admin_conn_rl_) discover-plugin-abilitiesandrun-plugin-abilitypromoted to core (no longer behind the LABS gate)phpcs.xml.distcorrectly drops the legacyWP_AGENTIC_ADMINandWPAgenticAdminprefixes
Minor
.release-notes/0.11.0.md comparison table has a copy-paste typo — the "before" column for the function prefix row reads agentic_admin_ (blocked) instead of wp_agentic_admin_ (blocked).
Resolves the four points from @ivdimova's review: - Settings data loss on upgrade: add idempotent maybe_migrate_settings() copying wp_agentic_admin_settings -> agentic_admin_settings (then drops the legacy key). Runs from both activate() and init() since the activation hook does not fire on WordPress.org auto-updates. - Fix broken indentation in class-llm-proxy.php proxy_streaming() left behind after the cURL block was removed. - Revert premature pluginslab/agentic-admin repo URLs back to pluginslab/wp-agentic-admin across 5 docs (repo not yet renamed). - Fix function-prefix typo in .release-notes/0.11.0.md comparison table (before column: wp_agentic_admin_). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Thanks for the thorough review @ivdimova — all four addressed in 451ba2c. 🔴 Settings data loss on upgrade — added an idempotent 🟡 🟡 Broken repo URLs — reverted Minor — release-notes typo — fixed; the "before" column now reads Re-requesting review when you have a moment 🙏 |
ivdimova
left a comment
There was a problem hiding this comment.
All four points from the previous review are addressed — thank you for the quick turnaround. LGTM with one tiny nit.
✅ Settings migration
maybe_migrate_settings() looks correct. The false !== $old / false === get_option( 'agentic_admin_settings' ) guards are tight, the old key is deleted after migration so subsequent calls are a no-op, and running it from both activate() and init() correctly covers the WP.org auto-update path (where the activation hook doesn't fire). Good call.
✅ LLM proxy indentation
proxy_streaming() indentation is clean throughout now.
✅ Repo URLs and release notes typo
All reverted/fixed correctly across ONBOARDING.md, README.md, UI-AUDIT-WP-7.0.md, 12-debugging-development.md, and the release notes table.
Minor nit (docs only)
In both ONBOARDING.md and docs/ai-fundamentals/12-debugging-development.md the clone URL was correctly reverted to pluginslab/wp-agentic-admin, but the cd line immediately after was not updated:
git clone https://github.com/pluginslab/wp-agentic-admin.git
cd agentic-admin # ← directory will be wp-agentic-admin after this clonegit clone creates a directory matching the repo name (wp-agentic-admin), so cd agentic-admin would fail. Should be cd wp-agentic-admin. Not a blocker for the WP.org submission but worth fixing before merge.
Address ivdimova review nit on PR #227 — git clone creates a wp-agentic-admin directory, so the cd line must match. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
window.wpAgenticLogLevel used the reserved `wp` prefix, the same class of issue the Plugins Team flagged on 28 May for the wpAgenticAdmin localize handle. The prefix rename in #227 missed it because it is set at runtime rather than declared in PHP. window.wpAgenticLogLevel -> window.agenticAdminLogLevel Also drops the redundant assignment before defineProperty, and clears the last "WP Agentic" branding strings from the SW console label and the SCSS headers, left over from the de-branding pass. Refs #228, #229
Audit before resubmission found the External services section describing
something the code does not do. Guideline 6 is the section under review,
so the disclosure has to match reality.
- CVE lookups were attributed to a `plugin-vulnerability-scan` ability
that does not exist anywhere in the codebase. NVD and MITRE are called
by `security-scan`, unconditionally, via
agentic_admin_scan_for_vulnerabilities() at security-scan.php:149.
- `core.svn.wordpress.org` was undisclosed. verify-core-checksums.php:273
fetches the original core file to build a diff when a checksum
mismatches. Now documented, including that the checksum list itself
comes from core's own get_core_checksums().
- Two absolute claims ("No admin data ever leaves your device", "no
admin data are sent to any server unless you enable the external LLM
provider") were contradicted by the section's own list a few
paragraphs below. Reworded to separate AI inference, which really is
local, from the public-data lookups a few abilities make.
- Dropped a changelog reference to sw-loader.php, removed in the same
release by #227.
Verified: every host the code contacts is now disclosed, and every
ability named in the section exists.
Readme only, no code change.
Refs #228
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Clears the WordPress.org plugin-directory review (multiple rounds) and fixes pre-existing AI Connector bugs found while testing.
WP.org review fixes
schmitzoide), not Pluginslab. Author/Contributors/URIs updated.wpprefix everywhere (AGENTIC_ADMIN_*, namespaceAgenticAdmin, JS globalagenticAdmin, ability IDs + REST namespaceagentic-admin/*). Main file renamed toagentic-admin.php.AGENTIC_ADMIN_ENABLE_LABSgate; deletedwrite-file+content-generate; promoteddiscover-plugin-abilities+run-plugin-abilityto core so the third-party Plugin Abilities platform ships fully enabled.query-database(LLM-authored arbitrary SQL).admin-post.php(WordPress loaded);sw-loader.phpdeleted.wpaa_→agentic_admin_;WPMU_PLUGIN_DIR/WPINCinstead of hardcoded paths.3→null, source/build documented in readme.AI Connector fixes (pre-existing bugs)
is_connectedand the chat "configured" gate used AiClientisProviderConfigured(), which is non-deterministic — caused "No AI Connectors configured yet" and spurious 400s even with a valid key. Replaced with a deterministic credential-presence check.Verification
composer lint0,lint-js0, 91 unit tests pass, production build OK. Anthropic connector verified end-to-end on a local WP 7.0 instance.🤖 Generated with Claude Code