Repository navigation
Conversation
release: dev → main (v0.11 submission prep)
Address the WordPress.org plugin directory pre-review for "agentic-admin". Ownership: submit as an individual (Author "Marcel Schmitz", Contributors "schmitzoide", Author URI to the WP.org profile) instead of the "Pluginslab" entity, so no trademark/domain ownership check applies. Prefix: drop the "wp" prefix flagged as reserved/common. Constants WP_AGENTIC_ADMIN_* -> AGENTIC_ADMIN_*, namespace/class WPAgenticAdmin -> AgenticAdmin, JS global wpAgenticAdmin -> agenticAdmin, ability IDs and REST namespace wp-agentic-admin/* -> agentic-admin/*, CSS classes, phpcs prefix allow-list, and the webpack chunk global (package.json name -> agentic-admin). Main file renamed wp-agentic-admin.php -> agentic-admin.php to match the slug; .distpackage and Playground blueprints updated. Other flagged items: Plugin URI 404 -> GitHub repo; NVD terms URL /general/ -> /developers/terms-of-use; admin menu position 3 -> null (appended to bottom). sw-loader.php direct access left intentional (documented). Verified: 96 unit tests pass, production build OK, composer lint exit 0, lint-js 0 errors. Version stays 0.11.0 (submission was pended, not published). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
WordPress.org plugin review (manual pass) plus AI Connector bug fixes. Review fixes: - Trialware (Guideline 5): remove the LABS opt-in gate; delete write-file and content-generate abilities; promote discover/run-plugin-ability to core so the third-party Plugin Abilities platform ships fully enabled. - Unsafe SQL: remove the query-database ability (LLM-authored arbitrary SQL). - cURL: drop the curl SSE path in the LLM proxy; use the WP HTTP API only. - Direct file access: serve the service worker through admin-post.php (WordPress loaded) and delete sw-loader.php. - Generic prefixes: rename the stray wpaa_ transient and error codes to agentic_admin_. - File locations: use WPMU_PLUGIN_DIR and WPINC instead of hardcoded paths; the remaining ABSPATH/WP_PLUGIN_DIR uses are read-only core/plugin scans. - Source/build: document the voy-search wasm and build steps in the readme. The Transformers.js embedding library stays a documented opt-in CDN service (bundling it pulls in an ONNX runtime that does not bundle cleanly). AI Connector fixes (pre-existing bugs): - is_connected and the chat "configured" check used AiClient isProviderConfigured(), which is non-deterministic and made the connector list flap to "none configured" and return spurious 400s. Replaced with a deterministic credential-presence check. - Surface WP 7.0's connector-approval gate as an actionable message pointing to Tools -> AI Connector Approval instead of a raw network error. Verified: composer lint 0, lint-js 0, 91 unit tests pass. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The inline plugin activate/deactivate buttons (ActionButton + INVERSE_ACTIONS in MessageItem) were fed only by the content-generate auto-insert path, which was removed during the WP.org trialware cleanup. Nothing populated message.actions anymore, leaving stateless dead buttons. Remove ActionButton, the inverse-action map, the messageActions rendering, and the now-unused onAction plumbing (MessageList, ChatContainer handleAction + toolRegistry/executeAbility imports). Plugins are still activated/deactivated via natural language. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
… URLs) Resolves the four points from @ivdimova's review: - Settings data loss on upgrade: add idempotent maybe_migrate_settings() copying wp_agentic_admin_settings -> agentic_admin_settings (then drops the legacy key). Runs from both activate() and init() since the activation hook does not fire on WordPress.org auto-updates. - Fix broken indentation in class-llm-proxy.php proxy_streaming() left behind after the cURL block was removed. - Revert premature pluginslab/agentic-admin repo URLs back to pluginslab/wp-agentic-admin across 5 docs (repo not yet renamed). - Fix function-prefix typo in .release-notes/0.11.0.md comparison table (before column: wp_agentic_admin_). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Address ivdimova review nit on PR pluginslab#227 — git clone creates a wp-agentic-admin directory, so the cd line must match. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…-debrand-and-prefix-rename WP.org review compliance + AI connector fixes Carries all WordPress.org submission compliance work: de-brand to individual submission, full wp prefix strip, trialware removal, cURL and unsafe SQL removal, sw-loader.php deletion, plus AI connector approval/detection fixes. Refs pluginslab#228
Two concrete code changes flagged in review R agentic-admin/schmitzoide/1Jun26/T4: - uploads-scan.php: resolve .well-known via get_home_path() instead of ABSPATH, which is wrong on subdirectory installs where the site root (document root) differs from the WordPress core directory. Guards the wp-admin/includes/file.php require so get_home_path() is available in the ability's REST load path. - vector-store.js: pin the Transformers.js jsDelivr URL to @3.8.1 (was floating @3). Matches indexing-worker.js and makes the readme changelog claim accurate — a privacy-first plugin should not depend on a CDN range that can ship new code without a deliberate bump. Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Automated dependency upgrade by OrbisAI Security
8 of 14 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Upgrade protobufjs from 7.5.4 to 8.0.1, 7.5.5 to fix CVE-2026-41242.
Vulnerability
CVE-2026-41242package-lock.json(dependency:protobufjs)Description: protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields
Evidence
Scanner confirmation: trivy rule
CVE-2026-41242flagged this pattern.Changes
package.jsonpackage-lock.jsonBehavior Preservation
The change is scoped to 2 files on the vulnerable path; it only tightens handling of untrusted input and leaves valid inputs unaffected.
This change addresses a pattern flagged by static analysis. The code path handles user-influenced input and the fix reduces the attack surface against both manual and automated exploitation.
Automated security fix by OrbisAI Security