Aculect AI Companion

Changelog

0.5.3

  • Improved MCP workflow discovery so content and SEO workflows are derived from the enabled atomic abilities instead of requiring separate workflow toggles.
  • Improved read-only intelligence discovery so site, content, developer, brand, and capability context tools are available by default when OAuth read access allows them.
  • Added an MCP capability help directory so assistants can discover available abilities, workflows, intelligence surfaces, blockers, prompts, and suggested next actions.
  • Hardened durable intelligence memory writes so direct memory saves require review controls and normal learning suggestions use feedback submission.

0.5.2

  • Fixed MCP content scheduling so future post status and date metadata persist correctly.
  • Fixed missing or roleless MCP users so they resolve to a safe read-only ability policy.
  • Fixed MCP tool availability so OAuth scope blockers are reported before exposing tools unavailable to the connected client.
  • Added Cloudflare compatibility diagnostics for Bot Fight Mode and Flexible SSL/TLS connector issues.
  • Updated GitHub Actions for the Node 24 runtime.
  • Resolved an npm development dependency security alert.
  • Added an OAuth connector smoke gate for dynamic client registration and authorization redirects.
  • Bounded MCP PHPStan analysis into focused groups so release-readiness static analysis remains reliable.

0.5.1

  • Improved OAuth secret storage so sites without ACULECT_AI_COMPANION_ENCRYPTION_KEY automatically use a generated database-managed encryption key instead of blocking assistant authorization.
  • Updated diagnostics to warn, not fail, when OAuth secrets are encrypted with the database-managed fallback key.
  • Kept ACULECT_AI_COMPANION_ENCRYPTION_KEY as the strongest production option for storing the encryption key outside the database.

0.5.0

  • Refreshed the AI Companion admin experience with clearer navigation, connection guidance, diagnostics, activity, and changelog surfaces.
  • Added AI Activity logging.
  • Added role-specific MCP ability policy controls and per-user access pause controls.
  • Added per-connection write permission controls for trusted assistants.
  • Added Intelligence Layer.
  • Added block and pattern knowledge so assistants can understand available WordPress blocks and patterns without relying on custom HTML blocks.
  • Added settings import, export, and reset actions for safer configuration transfer and recovery.
  • Added an authenticated MCP tool manifest export for diagnosing client-specific tool discovery differences.
  • Added guided MCP content workflow tools for long-form post planning, draft creation, section-based post updates, and Rank Math SEO updates.
  • Added reviewed learning suggestions so assistants can report improvement opportunities for admin review.
  • Reduced unnecessary admin payload work for tab-specific data.
  • Refined Connections and Abilities list views with assigned-abilities modals, access-level controls, and desktop-friendly DataViews layouts.
  • Polished settings header spacing, tab navigation, Advanced layout, admin notices, loading states, and connector branding.
  • Hardened OAuth storage maintenance so repeated dynamic client registration is bounded without blocking valid connector retries.
  • Polished the connection access modal logo and form spacing.
  • Updated workflow tool availability so workflows only appear when the required underlying global abilities, role policy, and OAuth scopes allow them.
  • Added provider compatibility guards for MCP tool descriptors and schemas.
  • Expanded cleanup coverage for full uninstall data removal.
  • Expanded unit coverage for workflow tools, content intelligence indexing, activity logging, OAuth error handling, tool safety, and cleanup.

0.4.0

  • Added featured image, author, taxonomy, and supported SEO metadata controls to content workflows.
  • Added taxonomy term image assignment for supported content groups.
  • Expanded media workflows with media read, update, trash, attachment relationship, and safe physical filename rename actions.
  • Expanded comment workflows with richer filters and bulk moderation.
  • Added safe site health summaries and broader site management visibility.
  • Added dry-run previews and confirmation gates for higher-risk write actions.
  • Added role-based MCP connection entry points for non-admin users.
  • Added policy-controlled bridging for public WordPress Abilities registered by WordPress and other plugins.
  • Added Codex connector setup guidance.
  • Improved MCP list payloads with compact defaults and sparse field controls for lower-volume responses.
  • Modularized MCP tool definitions, schemas, scopes, read-only hints, and handlers to reduce drift as more tools are added.
  • Expanded test and CI coverage for MCP tools, permissions, safety controls, media workflows, and release packaging.

0.3.0

  • Added an AI Activity tab for reviewing write actions requested by connected AI assistants.
  • Added a Connections control to temporarily pause or resume AI access without disconnecting assistants.
  • Added connection diagnostics that check endpoint, OAuth, and MCP readiness from the settings screen.
  • Refreshed the settings screen header with Aculect branding and clearer AI agent connection messaging.
  • Added WordPress.org plugin icon, banner, branded screenshots, and a Playground preview blueprint for the plugin listing.
  • Improved action permission controls so AI tools only expose and run enabled, authorized abilities.
  • Added OAuth storage maintenance to clean up expired connection data.
  • Hardened media uploads from public URLs with stricter sideload safeguards.
  • Expanded connector flow, activity log, access control, media, OAuth, and diagnostics test coverage.
  • Fixed the Active Connections screen so the active access notice does not appear when no assistants are connected.

0.2.1

  • Fixed diagnostics logging when the logs table is missing but the saved diagnostics database version is current.
  • Added automatic repair for the diagnostics logs table during plugin boot.
  • Added Cloudflare troubleshooting guidance for Bot Fight Mode and Flexible SSL/TLS connection issues.
  • Clarified that Cloudflare Bot Fight Mode should remain disabled for the hostname used by the MCP connection URL because it can block setup and later tool calls.
  • Added unit coverage for diagnostics log table repair.

0.2.0

  • Added opt-in diagnostic logging for AI assistant connection flows.
  • Added an Advanced setting to enable diagnostics and a Logs tab that appears only when logging is enabled.
  • Added sanitized lifecycle and error logs for dynamic client registration, OAuth discovery, authorization, token exchange, and MCP authorization checks.
  • Added 30-day log retention, automatic pruning, pagination, and clear-log controls.
  • Hardened OAuth consent and authorization request handling with allowlisted, context-aware sanitization.
  • Added stricter validation for response type, resource, PKCE, scopes, redirect URI, and consent decisions.
  • Added unit coverage for diagnostic logging, redaction, repository behavior, and OAuth authorization parameter handling.

0.1.0

  • Connect a supported AI assistant by copying one connection URL from WordPress.
  • Approve each AI assistant in WordPress before it can access your site.
  • Choose which abilities your AI assistant can use after it is connected.
  • See connected AI assistants and disconnect them whenever needed.
  • Ask your AI assistant to help with content, comments, media, site information, plugins, and themes.
  • Added clearer privacy notes and extra safety checks for testing.

Plugin Website
Visit website

Author
Mehul Gohil
Version:
0.5.3
Last Updated
June 13, 2026
Requires
WordPress 6.5
Tested Up To
WordPress 6.9.4
Requires PHP
8.2

Share Post

Join our newsletter.

Get insights into what’s happening at ChangelogWP right in your inbox. We don’t believe in spam.