=== AI Engine - The Chatbot, AI Framework & MCP for WordPress ===
Contributors: TigrouMeow
Tags: ai, chatbot, mcp, claude, openai
Donate link: https://www.patreon.com/meowapps
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 8.1
Stable tag: 3.8.3
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

AI meets WordPress. Your site can now chat, write poetry, solve problems, and maybe make you coffee.

== Description ==

**AI Engine connects WordPress with AI models.** One install, stable connectors for every major AI provider: OpenAI, Anthropic, Google, Mistral, and more. Build intelligent chatbots, generate content, create AI forms, and automate tasks. All from your WordPress dashboard.

Take the tour at [vibewithwp.ai](https://vibewithwp.ai/): what AI Engine does, how the MCP server works, and how it compares to the alternatives. Please make sure you read the [disclaimer](https://meowapps.com/ai-engine/disclaimer/). For more information, check the official website of [AI Engine](https://meowapps.com/ai-engine/).

== Quick Intro ==

Hello! ☀️ I built AI Engine to bring OpenAI, Anthropic, and other AI models into WordPress. Create chatbots that understand your content, generate posts in your voice, translate instantly, create images, or build custom AI tools.

For developers: [internal APIs](https://ai.thehiddendocs.com/php-functions/), [REST endpoints](https://ai.thehiddendocs.com/public-rest-api/), [function calling](https://ai.thehiddendocs.com/function-calling/), and [MCP support](https://ai.thehiddendocs.com/mcp/). Build AI features, automate workflows, or create SaaS applications on WordPress.

There is also a Workspace: a full-screen AI chat inside wp-admin, with every model you configured, and free apps for [iPhone](https://apps.apple.com/app/workspace-for-wordpress/id6794717714) and [Android](https://play.google.com/store/apps/details?id=com.meowapps.workspace) so you can keep working on your site from your phone. Details on [workspace.press](https://workspace.press/).

Feeling overwhelmed? 🤪 Start simple: Create a chatbot. Then connect [Claude Code](https://ai.thehiddendocs.com/mcp/mcp-server-claude-code/), [Claude](https://ai.thehiddendocs.com/mcp/mcp-server-claude/), [ChatGPT](https://ai.thehiddendocs.com/mcp/mcp-server-chatgpt/), or [OpenClaw](https://meowapps.com/openclaw-wordpress-mcp/) through MCP, giving AI direct access to your site. Desktop clients can connect via OAuth: users just paste the MCP URL, sign in to WordPress, and approve. No shared token to manage. Add [SEO Engine](https://wordpress.org/plugins/seo-engine/) and watch it manage SEO in ways you never imagined. You can even connect AI Engine to multiple WordPress sites and manage them all through conversation.

You'll be having a blast before you've explored everything. You'll probably spot bits of AI Engine in plenty of other AI plugins, code and UI alike. Flattering, really... or fishy? 🤣 But only AI Engine keeps pushing forward with real care for its community, a drive toward perfection, and the patience to get the details right.

== Core Modules ==

🤖 **Chatbots**
Create chatbots for your visitors, with five built-in themes (including the new Glass), realtime audio, file uploads, discussions, and conversation memory. Every theme can be restyled, and every text the chatbot says can be translated.

🖥️ **Workspace** (with free [iPhone](https://apps.apple.com/app/workspace-for-wordpress/id6794717714) and [Android](https://play.google.com/store/apps/details?id=com.meowapps.workspace) apps)
A full-screen AI chat inside your WordPress admin: every model you configured, conversation history and folders, a prompt library, image generation, web search, and hands-on access to your site through the MCP tools. It also runs on your phone and tablet, through [Workspace for WordPress](https://workspace.press/).

🎨 **Content & Media**
Write posts in the Content Studio, create and edit images in the Image Studio, compare models side by side in the Playground, and use Copilot in the WordPress editor to correct, enhance, translate, or rewrite text.

📝 **AI Forms**
Build custom AI-powered forms that handle text, images, audio, or file uploads. Create advanced apps with conditional logic.

🧠 **Knowledge & Embeddings**
Create embeddings and build knowledge bases from PDFs. Connect with Pinecone, Chroma, Qdrant, or OpenAI Vector Store for semantic search.

🔧 **Function Calling**
Connect AI to WordPress functions, WooCommerce, appointments, or custom APIs. Let AI interact with your site's data and services in real-time.

🛡️ **Security & Moderation**
IP banning, word filtering, and content moderation to keep your AI interactions safe.

💡 **Advisor**
AI-powered recommendations and insights to help you set up and optimize your WordPress site.

🔌 **Developer Tools**
Internal APIs, REST endpoints, MCP support, and extensive hooks. Build AI-driven features, automate workflows, or create SaaS applications.

== 🖥️ Workspace (and its mobile apps) ==

A full-screen AI chat that lives in your WordPress admin, and now in your pocket too.

Every model you configured is one tap away, in the same conversation: start a thread on Claude, continue it on ChatGPT or Gemini, generate an image, search the web, then let it work on the site itself through the MCP tools, with an approval dialog before anything is changed.

**Workspace for WordPress** brings all of it to your phone and tablet, on the [App Store](https://apps.apple.com/app/workspace-for-wordpress/id6794717714) and [Google Play](https://play.google.com/store/apps/details?id=com.meowapps.workspace). You scan a QR code once to pair it with your site, no password typed on a phone keyboard, and the pairing is a revocable Application Password you can cut off at any time. Your conversations, folders and themes stay on your own site, and your API keys never leave it.

The app is free, the plugin is free, and there is no markup on anything: you pay your AI providers directly, at their price. Workspace is off by default: enable it under AI Engine → Settings → Modules, and the Workspace entry appears in your admin menu. More about it on [workspace.press](https://workspace.press/).

**Features:**

* Every provider in one thread, switchable per conversation
* Conversation history, folders, pins, and full-text search
* Prompt library, image generation, and web search
* Site actions through MCP, with approval before any change
* Attach files and save generated images to the Media Library
* Themes that sync across your devices through your WordPress account
* Requires iOS 17 or newer, or Android 8 or newer

== 🤖 Chatbots ==

Transform visitor interactions with intelligent, customizable chatbots.

**Features:**

* Five built-in themes: Timeless, Messages, ChatGPT, Foundation, and Glass, a frosted glass theme with a dark and a light mode
* A Themes editor for colors, fonts, and custom CSS
* Popup, inline, or fullscreen, with an optional macOS-style window
* Realtime audio conversations
* File and image uploads, several at once, or simply pasted
* Discussions list and conversation memory
* Every text translatable, and message actions reachable with the keyboard
* Cross-site embedding
* GDPR compliance tools

== 🎨 Content & Media ==

Create, refine, and visualize content with AI assistance.

**Studios:**

* Content Studio: from a brief to a full draft, with templates you can reuse
* Image Studio: generate images, keep every version, and edit them with a brush
* Playground: try a prompt on several models side by side

**Copilot (Magic Wand):**

* Correct grammar and spelling
* Enhance text for readability and quality
* Make text longer or shorter
* Translate text and full posts
* Generate content from scratch
* Multi-block support in the WordPress editor

**Image & Video Tools:**

* Create images from text prompts
* Generate videos with AI (Sora)
* Edit existing images with AI
* Vision AI for image analysis
* Automatic alt text generation

== 📝 AI Forms ==

Build powerful AI-driven forms and applications.

**Capabilities:**

* Text, image, audio, and file inputs
* Conditional logic and validation
* Custom AI-powered apps
* Multi-step workflows
* Result templates

== 🧠 Knowledge & Embeddings ==

Create intelligent knowledge bases and semantic search.

**Vector Databases:**

* Chroma, Qdrant, Pinecone
* OpenAI Vector Store
* Automatic synchronization
* Dimension validation

**Smart Features:**

* PDF import with auto-chunking
* AI-powered search (Simple, Context-Aware, Smart)
* Content classification
* Personalized recommendations

== 🔧 Developer Tools ==

Extend WordPress with AI capabilities.

**APIs:**

* Internal API for plugin integration
* REST API for external applications
* MCP (Model Context Protocol) support
* Function calling framework

**Integration:**

* Works with SEO Engine, Social Engine, Code Engine
* Media File Renamer support
* Custom shortcodes and hooks
* Extensive WordPress filters

**Resources:**

* [Code Examples & Customization](https://ai.thehiddendocs.com/examples/)

== MCP (Model Context Protocol) ==

AI Engine turns your WordPress site into an intelligent MCP server. AI agents like ChatGPT, Claude, Claude Code, and OpenClaw can connect directly, browse content, edit posts, manage media, and handle complex tasks through natural conversation.

**Direct and private.** AI apps connect straight to your site. There is no relay service in between, your credentials never leave WordPress, and the MCP server is free, with no monthly fee and no usage cap.

**What AI Agents Can Do:**

* Create and edit posts
* Moderate comments
* Install and manage plugins
* Customize themes
* Check SEO and analytics
* Manage media files
* Run SQL queries
* Create images for your posts, in the shape you need
* Manage WooCommerce products, orders, inventory, and customers
* Handle Polylang and WPML translations

**Setup Guides:**

* [General MCP Overview](https://ai.thehiddendocs.com/mcp/)
* [MCP with ChatGPT](https://ai.thehiddendocs.com/mcp/mcp-server-chatgpt/)
* [MCP with Claude](https://ai.thehiddendocs.com/mcp/mcp-server-claude/)
* [MCP with Claude Code](https://ai.thehiddendocs.com/mcp/mcp-server-claude-code/)

**Plugin Integration:**

Other plugins add their features to the MCP system:

* [SEO Engine](https://wordpress.org/plugins/seo-engine/) - Let AI analyze and optimize your content, fix SEO issues, and manage meta data
* [Social Engine](https://wordpress.org/plugins/social-engine/) - AI can schedule posts, manage social media, and create social content
* [Code Engine](https://wordpress.org/plugins/code-engine/) - Give AI access to code snippets and custom functions

Plugins that register their features with the WordPress Abilities API, such as Easy Digital Downloads, can join too: turn on Abilities in the MCP settings and they become MCP tools, each one keeping its own permission checks.

AI Engine can also connect to external MCP servers, extending your chatbots with tools and services beyond WordPress.

**A note on safety and "full access":**

AI Engine's MCP tools are curated and permission-aware on purpose. They do not run arbitrary code, so your site stays safe even while an AI agent works on it.

Each person connects with their own WordPress account, so every action shows up under their name. Administrators get full access. Editors can connect too once you turn on Editor Access, limited to the content they can already edit in WordPress: settings, users, plugins, themes and deleting stay with administrators.

Some people have asked us to match tools like Novamira and give an AI agent full, unrestricted control of WordPress through arbitrary PHP execution. We will not add that to the official AI Engine plugin, because it is genuinely unsafe: it effectively turns your site into remote code execution. If you specifically want that Novamira-style power on a development or staging site, we made an optional companion plugin, [AI Engine YOLO](https://github.com/jordymeow/ai-engine-yolo), which brings the same unrestricted PHP execution and file access to AI Engine's MCP server. It is dangerous by design, switches itself off on production, and is offered on GitHub only. Please never run it on a live site.

== Pro Features ==

* **AI Forms**: Create dynamic forms that generate answers, images, or files using AI.
* **Embeddings & Vector Databases**: Build knowledge bases from your content and PDFs for semantic search.
* **Content-Aware**: Let AI use your post and page content as context for smarter responses.
* **Function Calling**: Connect AI to WordPress functions, WooCommerce, or any custom API.
* **Cross-Site Chatbots**: Embed your chatbots on external websites.
* **Editor Assistant**: An AI sidebar in the post editor that can read, rewrite, insert, and rearrange your content blocks through chained function calls.
* **Realtime Audio**: Voice-based conversations on OpenAI's GA Realtime API, with the latest voice reasoning capabilities.
* **Statistics & Usage Control**: Track usage, set limits per role, and monitor costs.
* **Extra MCP Tools**: Adds plugin, theme, database, Polylang, WPML, and WooCommerce management to the MCP server.
* **Models API**: Let coding agents and OpenAI-compatible apps use your site's AI models with one key, with usage tracked in Insights.
* **Priority Support**: Get faster help from the Meow Apps team.

== Why AI Engine? ==

**Native to WordPress**
Built specifically for WordPress with seamless integration. No clunky interfaces, just native WordPress experience.

**Flexible & Powerful**
Built-in connectors for OpenAI, Anthropic, Google, xAI (Grok), Mistral, Perplexity, OpenRouter, Replicate, Azure (OpenAI), plus a Custom (OpenAI-compatible) connector for Ollama, LM Studio, vLLM, llama.cpp, LocalAI, or any self-hosted server. Use the models that work best for you. Google (Gemini) runs on the new Interactions API by default, bringing stateful conversations, streaming with a live event log, function calling, and built-in Google Search and Google Maps grounding, with the classic API kept as a one-click fallback.

**Developer Friendly**
Clean APIs, extensive hooks, and MCP support. Build custom AI features or entire SaaS applications on WordPress.

**Real MCP, for Real WordPress**
You may have heard of MCP Adapter, built by the WordPress team primarily for their WordPress.com hosting service. It's essentially a thin layer on top of the REST API. AI Engine takes a different approach: its MCP tools are specifically crafted for AI agents, with rich context, smart defaults, and practical actions that go far beyond what a generic REST API wrapper can offer. And it works on any WordPress installation, regardless of your hosting provider. AI Engine also exposes its REST API as MCP tools if you want that, but the dedicated tools are where the real power is.

**Privacy First**
IP hashing, GDPR tools, secure file handling, and session-based tracking. You control your data.

**Constantly Evolving**
Weekly updates based on real user feedback. We listen, we improve.

== My Dream for AI ==

I am excited about AI, but I believe we need to use it with intention and clarity. Social media showed us how powerful tools can reshape our lives in ways we never expected, sometimes for the better, sometimes not. I want to avoid repeating those mistakes. AI should help us remove the meaningless, tedious work or enhance the work we enjoy. Modern tools should give us more time for what truly matters: spending beautiful moments with the people we love! 💕

== Installation ==

1. Upload `ai-engine` to `/wp-content/plugins/`
2. Activate through the 'Plugins' menu
3. Get an API key from OpenAI (or your preferred AI provider)
4. Add your API key in Settings (Meow Apps > AI Engine)
5. Start creating! 🚀

== Disclaimer ==

AI Engine is a plugin that helps you to connect your websites to AI services. You need your own API keys and must follow the rules set by the AI service you choose. For OpenAI, check their [Terms of Service](https://openai.com/terms/) and [Privacy Policy](https://openai.com/privacy/). It is also important to check your usage on the [OpenAI website](https://platform.openai.com/usage) for accurate information. Please do so with other services as well.

The developer of AI Engine and related parties are not responsible for any issues or losses caused by using the plugin or AI-generated content. You should talk to a legal expert and follow the laws and regulations of your country. AI Engine does only store data on your own server, and it is your responsibility to keep it safe. AI Engine's full disclaimer is [here](https://meowapps.com/ai-engine/disclaimer/).

== Compatibility ==

Please be aware that there may be conflicts with certain caching or performance plugins, such as SiteGround Optimizer and Ninja Firewall. To prevent any issues, ensure that AI Engine is excluded from these plugins.

== Screenshots ==

1. A chatbot on your site, here as a popup in the corner of a page. Give it a name, an avatar and a personality.
2. The same chatbot inline, with a dark theme. Themes are built in, and you can style your own.
3. Realtime: a voice conversation with the AI, with avatars and the live events feed.
4. Building a chatbot in the settings: pick the environment, the model, the context and the functions, and try it right there in the live preview.
5. The Content Generator: a whole post from a topic, sections first, then the content and the excerpt, all editable before it is published.
6. The Workspace: a full-screen AI chat inside wp-admin that can read and manage your site, with every model you configured.
7. Workspace on your phone: your site's AI on iPhone or Android. Every model, your keys, your site, with conversations kept on your own WordPress and image generation included.

== Frequently Asked Questions ==

= Why am I getting "Error 429: You exceeded your current quota"? =

This error comes from OpenAI's API, not AI Engine. Set up billing limits in your [OpenAI account](https://platform.openai.com/account/billing). Caching plugins can sometimes store error responses, so [clear your caches](https://ai.thehiddendocs.com/common-issues/exceeded-current-quota/) too.

= Who is AI Engine for, and how do I manage usage limits? =

AI Engine can be used by site owners, administrators, and visitors via chat widgets. To set query limits and prevent unlimited model runs, follow the [Managing Limits guide](https://ai.thehiddendocs.com/limits/).

= Does the chatbot support my language? =

AI models support many languages, but quality varies. There's no definitive list since models are constantly updated. Test your language in the AI Playground.

= How does MCP work, and what can I do with it? =

MCP (Model Context Protocol) exposes WordPress tools to AI agents. [Learn how to enable the MCP endpoint](https://ai.thehiddendocs.com/mcp/), choose which tools to expose, and secure them. You can manage posts, comments, users, media, and more. Administrators get full access, and you can also let Editors connect with their own account for content only.

= Does AI Engine work with WordPress AI (the AI plugin, Connectors and providers)? =

Yes, but you don't need it. AI Engine already does everything WordPress AI offers, and more: it connects to every major provider, and adds chatbots, AI Forms, embeddings, a dedicated MCP server with more than fifty tools, and usage insights. That's why we don't recommend installing the WordPress AI plugin alongside it. If you already use it, that's fine: we make sure both play nicely together. On the Connectors page, choose to let AI Engine manage your providers: the API keys you already saved there are reused, both screens stay in sync, and the AI features of WordPress run through AI Engine, so their usage shows up in its Insights.

= Can I restrict the chatbot to answer only from my site content? =

You can't completely block the model's built-in knowledge, but you can [use smart prompts and embeddings](https://ai.thehiddendocs.com/restrict-chatbot-topics/) to steer conversations toward your content.

= The chatbot doesn't appear or looks odd on my site =

Check the [Common Issues guide](https://ai.thehiddendocs.com/common-issues/) for solutions to REST API problems, caching conflicts, nonce errors, and layout glitches.

= Where can I learn the basics and troubleshoot problems? =

Start with the [Basics guide](https://ai.thehiddendocs.com/basics/) for installation and key concepts. For specific issues, check [Common Issues](https://ai.thehiddendocs.com/common-issues/).

= How do I report security issues? =

Report security vulnerabilities through the [Patchstack Vulnerability Disclosure Program](https://patchstack.com/database/vdp/9e5fbbbc-964a-4204-8bc0-198f21284efd).

== Changelog ==

= 3.8.3 (2026/10/01) =
* Add: Abilities to MCP, so tools registered by plugins through the WordPress Abilities API work over MCP and in Workspace, appear in MCP Logs, and are labelled Ability or Native in the renamed MCP Tools & Abilities list.
* Add: Cached tokens are now counted and priced at the cached rate for OpenAI, Anthropic, DeepSeek, OpenRouter and Claude Fable 5, and Insights shows cached tokens per query.
* Add: OpenAI requests carry a prompt cache key per chatbot, so repeated prompts and tools are billed at the cached rate.
* Add: A reply cut by Max Tokens now ends with a short notice instead of stopping mid-sentence, in chatbots and forms.
* Add: A chatbot limited to one file shows the attached file name and a remove button before sending, like the multi-file mode.
* Add: Prices for Gemini text models, so their queries are costed and dollar limits apply to them.
* Add: The mwai_openrouter_body filter, to add any OpenRouter parameter to a request, such as provider routing.
* Update: The MCP settings were reorganized, with the Connect card filling its block, Connections and MCP Settings under it, tool sets and WordPress abilities under the tools list, and the bearer token masked in the Claude Code commands.
* Update: The Files Manager lists files uploaded by every user and guest instead of only your own, and expired files are cleaned up every hour instead of once a day.
* Update: New chatbots start with their texts in the site language instead of always in English, existing chatbots are untouched.
* Update: OpenRouter requests are attributed to AI Engine instead of each site, and the existing filters still let a site credit itself.
* Update: Workspace chats are grouped under Today and Yesterday in the user timezone instead of UTC.
* Fix: The Editor Assistant no longer fails with Feedback session expired after applying edits, saved queries no longer store API keys, and it now sees paragraphs edited after the page loaded.
* Fix: Claude, Gemini and other non-OpenAI chatbots on an OpenAI Vector Store now receive the matching knowledge instead of an empty context.
* Fix: Non-streamed errors from OpenRouter, Mistral, OVH and custom providers are shown as a message instead of raw JSON.
* Fix: Gemini replies cut by Max Tokens end with the notice instead of an empty-reply error, and Gemini errors wrapped in a list are readable.
* Fix: Picking an environment without a model now asks for one instead of sending another provider's default model and failing with a 404.
* Fix: An AI Form repeated on a page answers in its own copy, and a streamed form error no longer floods the PHP log.
* Fix: GPT-6 Astra can generate images, its model entry was missing the image generation tool.
* Fix: Uploads that fail now say why, with the size limit when the file is too large, instead of an unknown error or a wrong invalid file type message.
* Fix: An empty completion request is refused before reaching the provider, and Suggest Synonyms without a selection returns a clear error instead of a fatal.
* Fix: MCP tool failures, like a missing post, reach the AI as a readable tool error instead of a protocol error.
* Fix: ChatGPT MCP connections no longer drop when several of its sessions share one connection, and revoking an app disconnects all of its sessions at once.
* Fix: When AI Engine manages the WordPress Connectors, an empty key no longer wipes a saved one, and keys already saved in WordPress are reused.
* Fix: Syncing a single post that gets skipped (ignored, language filter, or filtered out) now says why instead of doing nothing.
* Fix: Copying a masked MCP command by hand copies the real token, and Knowledge asks to pick an environment instead of showing the first-run screen.
* Fix: On touch screens the Stop button works with a single tap, while a quick double tap on Send still cannot cancel the message.
* Fix: A failed license check shows the real reason straight away, and a successful retry no longer keeps saying the Pro version is disabled.
* Fix: Two PHP warnings on every logs request when Insights is off.

= 3.8.2 (2026/09/25) =
* Add: Connect an AI assistant card in the MCP settings, which checks the host, guides you through Claude, ChatGPT or Claude Code step by step, and confirms the connection works.
* Add: The license section now names the actual problem (server unreachable, not activated on this site, expired) instead of an unknown error, and lets you copy the diagnosis for support.
* Update: The MCP settings and the readme now state that connections are direct, with no relay, no fee or cap, and credentials staying on the site.
* Fix: A site that cannot reach the license server no longer hangs the admin for minutes: connection diagnostics run once instead of once per URL, and the license check times out after 20 seconds instead of 45.
* Fix: MCP connections no longer break when a client, such as ChatGPT, reuses a refresh token that was already replaced.
* Fix: Chatbots with streaming disabled no longer slide the window up when a reply starts, which hid the Glass header and could make the page jump.
* Fix: Add-ons now keep their own visitor params as sent; only denied keys are matched by their canonical name and only messages is folded into one key.

= 3.8.1 (2026/09/24) =
* Fix: Security: visitors could override a chatbot's or form's model, instructions or environment with renamed parameters. Fixed, and the Advisor widget now escapes its output.
* Add: Glass, a new chatbot theme with colored light under frosted glass, a dark and a light mode, and a mode that follows the visitor's device.
* Update: Every chatbot theme was polished: proper headings, lists and tables in replies, an empty state that introduces the bot, message actions beside the bubble, and a message field that keeps its height on every WordPress theme.
* Update: Timeless and Messages have refreshed defaults (larger text, rounder corners, a white pane), and Messages drops its bubble tails. Customized themes keep their own values.
* Update: Redesigned the dashboard's AI Visibility card, with visits, score and the top AI companies from SEO Engine, and an example you can hide when it is not installed.
* Add: Templates in the Content Studio, shared with the classic generator.
* Add: Every text the chatbot says on its own can be translated or changed with the mwai_chatbot_texts filter, plus a new Empty State Hint parameter.
* Update: Pictures sent by visitors appear as a photo card, and message actions can be reached with the keyboard.
* Update: The mwai_image MCP tool accepts an aspect ratio, and images requested without a size are now square instead of 21:9 on Gemini.
* Update: Workspace now tells you when your site refuses a rename, a delete or a save, instead of failing silently.
* Update: Deleting or resetting a chatbot, a theme or a template now asks first.
* Fix: Embeddings were skipped on pages made with a page builder (Breakdance, Oxygen, Bricks...).
* Fix: Models of a Custom (OpenAI-compatible) environment could not receive images.
* Fix: The discussions list with several lists on one page, empty discussions, and its menu while scrolling.
* Fix: The admin crashed when a chatbot's ID was changed, and a crash in one settings tab no longer locks the whole screen.
* Fix: Stopped or edited Workspace replies no longer come back duplicated.
* Fix: A streamed reply was rebuilt when it finished, reloading its images.
* Fix: Dev Tools no longer polls the server every second while open.

= 3.8.0 (2026/09/18) =
* Add: Models API Pro module, so coding agents and OpenAI-compatible apps can use your site's AI models with one key, with usage tracked in Insights.
* Add: Editor Access for MCP, letting Editors connect with their own account and work on content only.
* Update: Rebuilt the Images, Playground and Content screens as studios, with image versions and brush edits, side-by-side model comparison, a guided brief-to-draft flow and shared presets.
* Update: Knowledge sync now reports why posts were skipped instead of only the count.
* Update: Excluded notes, archives and the Brewfile from the released package.
* Add: Paste a file into the chatbot to upload it, and hover the reply timer to stop a response in progress.
* Fix: Daily, weekly and monthly limits in Absolute mode no longer trip early.
* Fix: Image, media and post creation routes now check permissions before acting.
* Fix: Listing chatbots no longer fatals on the free plugin when a chatbot uses functions.

= 3.7.8 (2026/09/13) =
* Add: Redesigned Dashboard with a providers bento, weekly usage card, daily ideas and an AI visibility card, plus a slimmed Modules tab.
* Add: MCP tools to install and update plugins and themes from the WordPress.org directory.
* Add: GPT Image 2.5 Sunburst and Flare with the new quality levels.
* Fix: Workspace module no longer switches itself off on sites without a Pro licence.
* Fix: OpenAI Vector Store no longer retrieves knowledge twice on the default environment, now passes Max Results to file_search, and repairs old vectors tables missing columns.
* Fix: Uploaded files stay in context on later turns with Claude and other stateless providers.
* Update: The transcription and image edit API endpoints now check the caller can read the supplied attachment.
* Update: Smart Search returns embedded pages and custom post types instead of only posts, and the debug info shows the min score and number of posts found.

= 3.7.7 (2026/09/08) =
* Add: Local Memory now stores the shortcuts and blocks of the last reply, so they persist after a reload.
* Fix: Pairing failures that consumed the token now ask the user to generate a new code.
* Fix: Connection test no longer always reports success.
* Fix: Gemini no longer offers Live-only models as chatbots.
* Fix: Function calling on Google's Standard API.
* Fix: AI Copilot no longer stretches paragraphs to the full editor width.
* Update: Workspace is now described as available on both iOS and Android in the readme and admin.

= 3.7.6 (2026/09/05) =
* Add: Support for GPT-6 Astra, including its max reasoning level.
* Fix: Temperature is no longer sent to models that reject it.
* Update: The reasoning dropdown now only shows levels supported by the selected model.

= 3.7.5 (2026/09/03) =
* Add: Claude Fable 5.1 to the Anthropic models.
* Fix: Anthropic now caps max_tokens to the model's limit instead of returning a 400 error.
* Fix: Provider errors with a flat body (such as Mistral) and any 4xx/5xx status now show the actual error message.
* Update: Removed the Assistants module following OpenAI's shutdown.
* Update: Transcription now uses gpt-transcribe, and Opus 4.1 has been removed.
* Update: Built-in tools that can't be used with Chat Completions are now reported in the logs instead of being dropped silently.

= 3.7.4 (2026/09/01) =
* Fix: Sending a message after a client-side JS function call no longer fails with an invalid_request_error.
* Fix: MCP OAuth login redirects are no longer cached by page caches and served to the wrong visitor.
* Fix: Plugin file tools no longer report a refusal as a missing directory.
* Update: The "Done!" placeholder for client-side function calls is now translatable and filterable.

= 3.7.3 (2026/08/26) =
* Fix: Chatbots using the default environment and model are no longer excluded from the function calling list.
* Fix: Vision now detects image types from the file contents instead of the extension, so images served through a CDN work.
* Fix: Magic Wand can read the selected text again in the iframed block editor of WordPress 7.1, re-enabling Suggest Synonyms.
* Update: Completed steps in the Setup Assistant now collapse to a single line.

= 3.7.2 (2026/08/20) =
* Fix: Editor Assistant endpoints accepted a nonce any visitor could generate, allowing anyone to run AI queries on the site's provider account (reported by Abdullah Kareem via WPScan).
* Fix: A crafted URL could escape the uploads folder and send any server-readable file to the AI provider (reported by Jashid Sany via WPScan).
* Fix: Editor Assistant now works for admin-equivalent accounts whose role isn't literally administrator.
* Fix: Embeddings sharing the same reference no longer stay stuck, and a single unprocessable vector no longer blocks the maintenance queue.
* Fix: A temperature of 0 is no longer treated as unset and stripped from the request.
* Fix: Image-only replies from GPT-5 models no longer show "medium" as the answer text.
* Update: Claude Sonnet 5 pricing ($2/$10 is now permanent), dashboard wording, and tested with WordPress 7.1.
* 🎵 Discuss with others about Ai Engine on [the Discord](https://discord.gg/bHDGh38).
* 🌴 Keep us motivated with [a little review here](https://wordpress.org/support/plugin/ai-engine/reviews/). Thank you!
* 🥰 If you want to help us, check our [Patreon](https://www.patreon.com/meowapps). Thank you!
* 🚀 [Click here](https://trello.com/b/8U9SdiMy/ai-engine-feature-requests) to vote for the features you want the most.

= 3.7.1 (2026/08/14) =
* Add: WPML support in the MCP server, mirroring the Polylang tools.
* Add: SEO section in the Modules tab, with robots.txt access for AI crawlers and live stats when SEO Engine is installed.
* Update: MCP self-test now detects AI-crawler blocking, nested .htaccess files and www mismatches, and logs every OAuth authorize refusal.
* Update: Internal errors are now hidden behind a filterable public message, and AI Forms no longer show provider errors to visitors.
* Update: Shared dashboard synced with the new Board and the AI site analysis.
* Fix: The mwai_mcp_mutate hook now fires on deletions, so cache purges hooked to it run.

= 3.7.0 (2026/08/03) =
* Fix: Qdrant collections were always created with 1536 dimensions regardless of the embedding model, and default dimensions are now read from the right place.
* Update: Embedding dimensions are no longer locked for OpenAI-compatible models, as that size is only a guess.
* Fix: The MCP access level no longer restricts OAuth connections, and the setting is no longer hidden behind the bearer token.
* Fix: MCP connections no longer drop at random when the client refreshes its access token.
* Update: Credited Revanth Hari Narayana Matte (via WPScan) for reporting the security issues fixed in 3.6.4 and 3.6.6.

= 3.6.9 (2026/08/01) =
* Fix: Crash when clicking quickly through discussions, and slow image checks writing into the wrong message.
* Fix: MCP token refresh being rejected on servers that pass Basic credentials to PHP instead of forwarding the header.
* Fix: Stored chat messages could run scripts when an admin opened a discussion.

= 3.6.8 (2026/08/01) =
* Fix: Workspace mobile app connection on servers that don't expose the Authorization header, with clearer pairing errors.
* Fix: A Context Max Length of zero no longer empties posts, which blocked embeddings sync and blanked chatbot context.
* Update: Transcription now defaults to gpt-4o-mini-transcribe instead of whisper-1.
* Update: The mobile connection warning links to the troubleshooting page instead of showing the htaccess snippet.
* Add: Logging on the MCP OAuth token endpoint for failing refreshes.

= 3.6.7 (2026/07/31) =
* Add: Workspace is officially launched on [iOS](https://apps.apple.com/app/workspace-for-wordpress/id6794717714). 
* Update: OpenAI pricing for GPT-5.6 Terra and Luna following the July 30 cut, and corrected o3 which was priced 7.5x too high.
* Update: Removed the leftover mcp.js relay and its documentation, and corrected the MCP header comment that still mentioned SSE and OAuth.
* Add: getDiscussion() to the PHP API, to read a stored discussion without using $mwai_core.

= 3.6.6 (2026/07/30) =
* Update: Minimum PHP version is now 8.1, declared in the plugin header so WordPress blocks activation on older versions.
* Fix: Push All no longer exhausts the memory limit on large sites; post content is now checked in chunks.
* Fix: Long Japanese and Chinese posts no longer produce empty content, which left their embeddings stale.
* Fix: Hardened the REST endpoints against client-supplied file paths and API keys, corrected the MCP OAuth route match and guest session cookie, and stopped the chatbot key reaching Editors.
* Fix: The mwai_mcp_callback filter now receives five arguments from both the Workspace and the MCP endpoint.
* Add: CSV and JSON export for the Query and MCP logs, honouring the active filters and sort.
* Fix: Chatbot input is no longer hidden behind the mobile keyboard in fullscreen, and shortcuts are now chips that don't inherit the site's button styles.

= 3.6.5 (2026/07/28) =
* Add: Elapsed time counter on the AI Forms submit button, matching the chatbot.
* Add: Note in the Sync panel that the Sync filters are shared by all environments.
* Fix: Three security issues reported by WPScan (key disclosure to editors, guessable guest sessions, audio transcription file read).
* Fix: Streaming requests now respect MWAI_SSL_VERIFY and verify TLS certificates (reported by Mohammed Abd Alrahman).
* Fix: Recurring tasks no longer stay parked after repeated failures, so discussions and logs cleanups run again.
* Fix: Administrator-equivalent accounts (custom roles with manage_options) are no longer refused at the MCP OAuth consent screen.
* Fix: A custom JavaScript filter that crashes no longer breaks the chatbot, and raw JavaScript errors are no longer shown to visitors.
* Fix: The embeddings environment Type field no longer shows "Select" for the Internal (WordPress DB) environment.
* Fix: The Web Search button now appears in the Workspace composer when pinned.
* Update: Push All now respects the Sync category and language filters, so it no longer seeds posts Sync would not maintain.
* Update: Workspace is now available to everyone; Knowledge, MCP Servers and Functions stay Pro.
* Update: Removed the unused module_addons and module_blocks option defaults.

For older releases, see [changelog.txt](https://plugins.svn.wordpress.org/ai-engine/trunk/changelog.txt).
