POM AI
Changelog
Changelog
All notable changes to POM AI are documented in this file.
Changes pending release tag
-
fix: Let article image prompts determine the visual medium instead of forcing a web-illustration preset, and include saved art direction alongside the writing context when automatic images are enabled.
-
docs: Explain how automatic article images follow the business profile and saved visual identity.
-
fix: Keep enabled WooCommerce description tools under Products for multisite super administrators without stored catalog capabilities on the current site, preserving Tools access for delegated editors.
-
docs: Clarify where to find enabled catalog tools for regular catalog users, multisite super administrators and delegated editors.
-
fix: Limit image generation and editing to 2560 pixels per edge, removing 4K and oversized Google 2K aspect ratios from selection and request validation.
-
fix: Read server-calculated writing input counts without requiring the account service to return its private prompt.
-
docs: Explain how Short and direct respects the requested length, explicit preferences and saved brand voice.
-
docs: Update image model, resolution, quality and credit-estimate guidance.
-
feat: Add Nano Banana, Sunburst and Flare image choices with provider-specific resolution and quality controls shared by generation and editing.
-
fix: Keep image credit estimates aligned with the selected provider, aspect ratio and quality, and reject malformed model choices before generation.
-
fix: Keep editorial catalog tools in a stable administration menu and reject oversized metadata and translation-estimate selections before object lookups.
-
fix: Serialize long-post generation, save content with workflow progress, and preserve editor changes and publication state during retries.
-
fix: Render valid article image URLs and respect sites that disable native image blocks.
-
fix: Use optional POM Theme field definitions and native WooCommerce variation persistence for product translations.
-
perf: Replace broad synchronous media scans with resumable site-scoped batches, targeted cache invalidation, retained originals and resume or stop controls.
-
fix: Count MCP requests atomically, limit authentication work before verification and bound repeated denial logs.
-
perf: Paginate Polylang content discovery and bound indexed OAuth cleanup, including abandoned client registrations.
-
fix: Report OAuth storage failures, preserve serialized image-reference data and handle translation request errors safely in the interface.
-
docs: Update editorial permissions, translation compatibility, recovery workflows and image-reference coverage.
-
fix: Enforce object-level permissions for translation and image metadata, preserve theme-independent translation, and bound remote image downloads.
-
build: Include official WordPress MCP Adapter 0.6.1 and the shared Jetpack autoloader in the complete POM AI package.
-
feat: Automatically use native MCP on WordPress 6.9+ without a separate plugin or transport toggle, retaining the WordPress 6.8 transport and existing authorization boundaries.
-
docs: Update site, multisite and skill connection instructions for the bundled adapter and session migration.
-
feat: Deliver the bundled site-authoring skill through a read-only MCP tool on individual-site and account connections, with versioned manifests and verified file transfers.
-
build: Keep the same reviewed skill files in the plugin and optional download, using one shared package allowlist.
-
docs: Make prompt-based installation the primary onboarding path and explain using skill 1.5.0 directly in clients without persistent skill storage.
-
fix: Refuse executable shortcode and block attribute fragments that would otherwise bypass HTML filtering before native rendering.
-
fix: Restrict MCP execution to the reviewed authoring catalog, require real JSON booleans, and block user administration, protected metadata and permission settings across both transports.
-
fix: Apply the installation's KSES rules to privileged HTML writes and encoded builder content, and reject executable source in HTML and CSS.
-
feat: Allow selecting existing theme scripts for editable content and archive, single and feed templates without exposing script creation or modification.
-
fix: Preserve omitted template assets, store native editor-compatible selections and validate complete content models before writing.
-
fix: Pin validated public image destinations to the WordPress cURL transport and reject redirects, private addresses and oversized downloads.
-
docs: Update MCP setup, security and metadata references, and publish authoring skill 1.4.1 with existing-script reuse and account-administration boundaries.
-
docs: Update the portable authoring skill to 1.4.0 with native header variants, a one-row reusable-block footer, complete component CSS editing and concise template-linked stylesheets; prohibit custom site JavaScript across access paths.
-
build: Include the focused managed theme CSS reference in the portable authoring skill package.
-
feat: Add explicitly authorized Unlimited multisite delegation for block discovery and revisioned page operations through the main-site native MCP connection.
-
fix: Keep delegated subsites independent of the main site's service license and recheck one-use request binding, OAuth revocation, network policy and destination identity before execution.
-
docs: Explain activating destinations without local MCP credentials, network-only permissions, supported page operations and access revocation.
-
chore: Record delegated multisite isolation, native ability execution and standalone transport verification with the account-service dependency and rollout boundaries.
-
chore: Record real native/standard transport verification, Gutenberg save fidelity, visitor filtering and cleanup of the isolated block-authoring site.
-
fix: Reject non-string content before legacy write payload coercion so both transports return controlled authoring errors.
-
fix: Report Classic Builder availability from the theme's native enablement helper instead of shortcode registration or autoloaded builder classes.
-
build: Include the focused native block-editor reference in the portable authoring skill download.
-
docs: Update the portable authoring skill to 1.3.0 with contextual POM block discovery, native browser serialization, shortcode carrier guidance and explicit editor-save verification.
-
fix: Build the MCP operation catalog after active-theme setup so real HTTP connections discover theme settings and content-model tools before the native adapter initializes.
-
fix: Route authoring instructions to the target editor while preserving existing Classic Builder documents and block pages containing POM shortcodes.
-
feat: Expose contextual WordPress block catalogs, native attribute schemas and server-side block validation through both MCP transports and WordPress abilities.
-
fix: Restrict POM authoring to theme-owned shortcodes and its permitted block palette, including enabled POM text extensions, and enforce that policy in content writes.
-
fix: Distinguish legacy shortcode rendering from an available classic editor and report JavaScript serialization requirements for native blocks.
-
feat: Expand the portable site-authoring skill with concrete visual direction, native POM design mapping and evidence-based refinement across pages, listings and mobile states.
-
build: Include focused visual-system and design-review references in the installable authoring skill.
-
docs: Explain focused design requests, native styling scope and the evidence expected from a visual review.
-
docs: Distinguish registered shortcodes from complete parameter schemas and explain bounded local or remote recovery when authoring discovery is incomplete.
-
docs: Require direct inspection of enlarged text and archive density after native rendering, including clipping that document-width checks do not detect.
-
chore: Record the independent visual comparison, portable package verification and cleanup of the isolated authoring sites.
-
docs: Explain account agent revocation and OAuth exchange recovery.
-
fix: Preserve encoded OAuth callback, resource and scope parameters when authorization first requires WordPress login.
-
fix: Show each OAuth consent scope on its own line without displaying HTML markup.
-
feat: Expose owner-scoped OAuth agent listing and revocation while serializing token exchange so credential rotation cannot restore removed agent access.
-
fix: Reject malformed OAuth token fields and avoid returning credentials that were not persisted.
-
chore: Record account federation verification, isolated-site cleanup and scoped integration review.
-
fix: Report temporary credential-storage failure instead of confirming an OAuth revocation that could not be persisted.
-
docs: Teach the portable authoring skill to select account-enrolled destinations, inspect nested results and preserve native plan recovery; document individual OAuth revocation.
-
fix: Keep federated write locks scoped to the destination connection, report canonical site URLs and refresh OAuth revocation routes without a database migration.
-
feat: Support revoking one OAuth token grant through the standard revocation protocol without resetting other MCP connections.
-
feat: Allow site-owned account catalogs to reuse POM AI OAuth and the native MCP transport while withholding local tools, resources and prompts.
-
feat: Include the authenticated actor and granted scopes in native connection discovery for explicit remote-site enrollment.
-
chore: Record shared-skill packaging, actual Claude Code and Codex discovery, native authoring validation and disposable-site cleanup.
-
fix: Require the native WordPress privacy-management capability when assigning or clearing a privacy page, including multisite network restrictions.
-
fix: Generate facet-owned listings without the unsupported negative pagination checkbox value so their source passes the native builder validator.
-
docs: Clarify that form embedding must be validated against the refreshed active-form picker, while draft-only work retains its proposed source.
-
docs: Explain installing, invoking, updating and removing the shared authoring skill, including remote-site requirements and draft/publication boundaries.
-
build: Package the shared authoring skill from reviewed sources in every plugin build and offer its portable ZIP from the MCP settings panel.
-
feat: Add a shared POM Site Authoring skill for Claude Code and Codex with progressive design guidance, native authoring recipes and explicit plan recovery workflows.
-
docs: Record remote website assembly, browser and transport verification, scoped permissions and recovery procedures in the private phase-3 review.
-
fix: Reject ambiguous template references in website plans and document native template, stylesheet and form-field contracts.
-
feat: Allow reviewed site plans to apply global POM CSS and clear the connected site's POM Cache after generating assets.
-
fix: Return a controlled upgrade response for malformed form configuration and include website authoring contracts and plans in discovery guidance.
-
fix: Serialize MCP writes per site, reuse the lock for nested plan steps, and fingerprint managed template and stylesheet sources during conflict checks.
-
fix: Refresh rewrite rules on the next WordPress request after MCP content-model changes, when the new content types and taxonomies are registered.
-
fix: Require stable component identifiers in plans, bound settings fingerprint work, and retain uncertain status when native asset generation reports failure.
-
fix: Discover native reserved form field names and avoid loading broad settings editors for groups with dedicated authoring operations.
-
docs: Explain typed settings, filterable listings, native forms and navigation, and resumable website plans with their permissions and recovery limits.
-
fix: Read both native form configuration storage formats and preserve the originally reviewed configuration version during saves.
-
fix: Follow native POM Forms administrator permissions and recover interrupted draft creation without duplicating the form.
-
feat: Create draft POM Forms and edit their layouts, messages, notification routes and activation through native schemas and versioned saves.
-
feat: Expose nested font-family settings using native field definitions and generate responsive listing column attributes.
-
feat: Run versioned website plans one prepared step at a time, with owner-bound journals, dependency references, conflict detection, persisted checkpoints and explicit recovery of interrupted content writes.
-
feat: Create saved public-content queries, configure facet contexts, advance the native indexer, and assemble web_listings with existing feed templates through MCP.
-
fix: Preserve existing repeater metadata during typed authoring and return normalized multiple-choice and numeric settings.
-
feat: Add native menu creation, location assignment and site-page configuration, plus revision-checked content authoring with explicit slug conflicts.
-
feat: Add typed POM settings contracts and revision-checked patches with in-memory previews, bounded repeater inputs and managed content files.
-
docs: Distinguish OAuth operation scopes from native transport access and document nested batch validation.
-
docs: Record complete native-catalog verification, real client compatibility, minimum-version coverage and the website-authoring follow-up contract in private engineering notes.
-
docs: Document native transport selection, sessions, errors, rate accounting and rollback, and correct API key service-user access and batch-preview guidance.
-
fix: Advertise optional native site identity only at the tool-call level, where the connected site is verified.
-
feat: Show native transport dependency and service-user requirements in the MCP settings panel, and optionally verify the discovered site UUID on tool calls.
-
fix: List coupons through bounded WordPress queries and WooCommerce coupon objects, and handle extra arguments on native operations with empty schemas without runtime exceptions.
-
feat: Expose the existing MCP tools, resources and prompts through private WordPress abilities and the official MCP Adapter, with a site-level transport switch and standard-mode rollback.
-
feat: Describe native tool inputs for WordPress content, media, navigation, POM Theme settings and WooCommerce catalog operations while preserving established operation names and payloads.
-
fix: Keep WooCommerce variation batch previews read-only even when a nested row requests a write.
-
fix: Clarify API key service-user capabilities and require an authenticated WordPress actor for native adapter sessions.
-
feat: Add an opt-in, site-scoped WordPress Abilities API and official MCP Adapter pilot for authenticated site discovery and native page creation, reading and updates.
-
fix: Preserve OAuth challenges, operation scopes, content-write gates and actor isolation in the native MCP pilot, with explicit dependency checks and fail-closed startup.
-
docs: Clarify MCP schema rediscovery and structured results, and record the native integration contract and manual verification outside public documentation.
-
build: Exclude private engineering notes from release packages and source archives.
-
feat: Assign the first generated article image as the featured image while retaining its inline placement, with retry-safe saving and no additional image charge.
-
docs: Clarify shared writing profiles, reasoning and web-research usage, cache pricing, and the difference between conservative estimates and measured credit charges.
-
feat: Add WooCommerce-only category and product description tools with Basic, Pro and Pro + internet profiles, individual prompts, catalog-wide selection, resumable batches and replace, append or prepend modes.
-
feat: Generate short product descriptions capped at 50 words, configurable long descriptions or both while preserving unrelated product data and protecting concurrent edits.
-
docs: Explain WooCommerce description workflows, credit estimates, selection limits and safe catalog updates.
-
feat: Add OpenAI quality profiles, optional web research, 100,000-character briefs and saved, resumable website-copy projects with editable plans, per-page progress and protected draft recovery.
-
fix: Render generated page plans safely, require page-editing permission for website-copy operations and stop repeating the website overview in legacy page prompts.
-
docs: Explain website-copy limits, estimates, saved plans, pause/resume behavior and manual draft review.
-
fix: Make the long-post image count produce the selected number of section images instead of treating it as an optional maximum.
-
feat: Recommend Markdown for structured business profiles, provide a downloadable ChatGPT-ready profile prompt, and expand the field guidance with more detailed examples.
-
build: Require the downloadable business-profile Markdown prompt in every production release package.
- Changes included in version 0.2.0.
New features
- Replace the long-post screen with a recoverable staged workflow UI that offers Standard, Pro and Pro + internet profiles, optional automatic images, live per-stage progress, retry and cross-page resume controls, automatic SEO handoff, and draft or scheduled publication.
- Complete persistent long-post orchestration by advancing image generation, SEO metadata and publication as separate saved operations after article sections, with media placement receipts and publication deferred until the article is complete.
- Add a persistent long-post workflow service that snapshots generation context, advances research, planning and individual structured sections with replay-safe step IDs, prevents concurrent requests and rebuilds draft content from completed HTML and image-slot blocks without duplicate appends.
- Add a shared SEO service that estimates and generates metadata through the structured long-post API, avoids charges when no supported provider is active, and rollback-safely writes titles, descriptions and focus keywords to Yoast SEO and Rank Math.
- Allow the complete 50,000-character structured business profile to reach relevant requests and expand the long-post prompt to 100,000 characters for full reference articles, with coordinated validation and longer request timeouts.
- Replace the single long business description with a translatable ten-section profile capped at 50,000 characters, including detailed modal guidance, aggregate client/server validation and legacy-value migration.
- Compile a bounded tool-specific business context for writing, landing, image, metadata and context-aware translation requests while preserving the short translation description.
- Raise the image metadata batch limit to 48, load 24 attachments per page, and support Shift-click range selection in the media picker.
- Add the
pom_ai_transcribe_audioAJAX bridge so prompt dictation completes: it verifies the nonce, requiresedit_postsorupload_files, validates duration, size and real audio type, and forwards the recording to the account transcription service. - Add the
pom_ai_dictation_max_file_sizeandpom_ai_dictation_allowed_mime_typesfilters, mirroring the account limits locally so oversized or unsupported recordings fail before upload. - Warn in the POM AI MCP settings panel when pretty permalinks are not configured, because the discovery and OAuth endpoints are rewrite rules that return 404 while the MCP endpoint keeps answering.
- Report
permalinks_enabledfrom the MCP status endpoint so clients and health checks can detect the same condition.
Fixed
- Require settings and per-post capabilities at the remaining profile and legacy long-post write boundaries, and keep the new character-limit paths functional when PHP's optional mbstring extension is unavailable.
- Preserve image-generation receipts on both the article and imported attachment so a failed article-meta write can recover without purchasing the same image again, reject trashed workflow drafts, and normalize AJAX error status metadata.
- Validate editable image attachments before improvement or background removal, remove local hard-coded source-image overrides, keep provider failures private, and make image credit estimates include the same profile context and style as execution.
- Enforce the aggregate 50,000-character business-profile limit even on partial settings submissions by including the stored values of omitted profile sections.
- Enforce the same five-minute scheduling lead time in the long-post interface and server-side workflow validation, and explain the WP-Cron dependency before users schedule publication.
- Process image metadata batches sequentially with real per-image progress, isolated failures, and paced requests so large selections do not overwhelm the account WAF.
- Route shared license validation through the account server configured by
POM_AI_API_DOMAINand narrowly accept its self-signed certificate in local environments so locally issued keys work with local POM AI services. - Send dictated audio base64-encoded in a form-encoded body instead of a multipart upload. Signed POM AI requests are verified over the exact request body, and PHP leaves the raw input stream empty for
multipart/form-data, so a multipart recording could never satisfy the account signature check. - Stop
wp_update_postandwp_update_pageunpublishing content. The shared payload builder applied its draft default on updates as well as creations, so updating a published post or page without an explicitstatusargument silently moved it to draft. The default now applies only when creating. - State the replace-by-default behavior in the
wp_add_post_termstool description. MCP clients read tool descriptions to decide how to call a tool, and the previous wording did not say that the call removes every existing term of that taxonomy unlessappendis true. - Stop
wp_update_optiondisabling autoload on the options it writes. It passedfalseas the autoload argument, which rewrites the autoload column, so updating the site title, tagline, posts per page or date formats removed them from the autoloaded set and added a query per option on every request. - Resolve the
pom://theme/templates/{archive,single,feed}MCP resources against POM Theme's numbered documentation directories. The lookup only checkeddocs/templates/, while the theme ships the references indocs/08-templates/, so all three resources silently served a two-line fallback stub instead of the theme's merge-tag documentation.
Changed
- Centralize Gemini image generation, credit estimation and validated WordPress media imports in a shared service used by the existing image tools and ready for long-post workflows.
- Keep the landing-page generator dormant by removing it from tool settings and preventing its menus and AJAX actions from registering while preserving the implementation for a future restoration.
Documentation
- Explain that scheduled long posts require a working WP-Cron or server cron runner and may remain queued when scheduled tasks are delayed.
- Document the current long-post profiles, first-step estimate, persistent progress and recovery, automatic image and SEO stages, cost shape, and scheduled-publication behavior.
- Document structured profile setup, tool-specific context selection, privacy, translation limitations, image guidance and input-cost behavior.
- Document sequential image metadata processing, Shift-click selection, 24-item picker pages, and the new 48-image batch limit.
- Add the documentation manifest that defines article order for POM Docs Sync.
- Give every POM AI documentation directory, article, and asset a globally unique product-scoped name and update all internal links.
- Enforce numbered documentation topics with no root Markdown files and complete index pages for every topic directory.
- Rewrite the
22-mcp-resourcesthrough26-helpchapters as distinct, code-verified guides to MCP resources, prompt recipes, boundaries, developer contracts, and troubleshooting. - Reorganize and expand public AI and MCP documentation under numbered POM Docs Sync terms.
- Clarify that public documentation must be reader-focused and exclude internal operational material.
- Standardize numbered screenshot placeholders for public Markdown documentation.
- Rewrite the
01-start-herechapter as distinct, code-verified articles covering the product model, requirements, installation, interface locations, a first task, the setup checklist, transmitted data, review obligations, and updates and support. - Rewrite the
02-license-and-domainschapter as distinct, task-oriented articles covering license activation, single-site and multisite scopes, subsite service licenses, the network update license, shared-subscription use, domain authorization and limits, domain removal, key rotation, and license error codes. - Correct the documented settings path to Settings > POM AI and replace the internal request-signing description in the licensing chapter index with reader-facing licensing guidance.
- Rewrite the
03-creditschapter as distinct articles covering the credit unit, what does and does not consume credits, estimates and confirmation, balances, insufficient-credit errors, batch consumption order, subscription and top-up sources, expiration, usage history, charge review, and plan sizing. - Rewrite the
04-writing-toolschapter around the four real writing tools, documenting the long-form outline-then-sections flow, the editable landing and site-wide plans, and the paragraph assistant's three content-creation modes. - Rewrite the
05-translationchapter for the Polylang-based workflow, including the per-post buttons, the bulk analyze-and-translate screen, placeholder-based formatting preservation, and the untranslated-excerpt limitation. - Rewrite the
06-image-toolschapter, documenting the reference-image numbering, the 24-image metadata batch limit, and that replacing an original rewrites site-wide references and permanently deletes the source attachment. - Rewrite the
08-promptschapter, documenting prompt-template append behavior, the six template contexts and their aliases, and the MCP prompts published by the server. - Rename
05-translation/pom-translate-integration.mdtopolylang-integration.mdbecause the translation tool integrates with Polylang, not POM Translate. - Rewrite the
07-dictation-and-transcriptionchapter to cover the dictation control, browser permissions, transcription limits, credit cost, audio privacy and troubleshooting. - Rewrite the
09-mcp-start-herechapter with the connection path, the four-check security model (scopes, WordPress capabilities, write gates, input schemas), the capability map, and reference pages for the MCP, status, discovery and OAuth endpoints. - Record that MCP API key authentication is permanently read-only, that all four write gates default to closed, and that MCP operations consume no POM AI credits.
- Correct the README claim that a configured service user enables MCP API key writes. API key auth carries the fixed scopes
mcp:readandwp:content:read, so no write tool can run under it; the service user only widens what it may read. - Document the MCP write rate ceiling in the README and in the settings field description: writes use the configured read limit or 20, whichever is lower, and OAuth registration and token requests are fixed at 5 per minute.
- Rewrite the
10-mcp-workflowschapter as task sequences built on the read-check-validate-write-verify shape, covering content, media, taxonomies, comments, menus, options, POM Theme settings and templates, POM Cache, and the WooCommerce catalog, variations and coupons. - Record the MCP option write allowlist (
blogname,blogdescription,posts_per_page,date_format,time_format), the remote media limits (10 MB, no redirects, no private hosts, raster images only), and that product deletion is not exposed while variation and coupon deletion are. - Rewrite the
11-mcp-authoring-toolschapter as a reference for the seven read-only authoring tools, covering their two scope groups, the normalized shortcode attribute schema, the discouraged-shortcode replacements, merge tag syntax including the%%…%%attribute form, and the error and warning taxonomy of both validators. - Rewrite the
12-mcp-wordpress-content-toolschapter as a reference for the thirteen post and page tools, covering the public-post-type restriction, the read capability asymmetry between published and unpublished items, listings omitting content, the 1–100per_pageclamp, and the dry-run shapes. - Rewrite the
13-mcp-wordpress-media-toolschapter as a reference for the eight media tools, covering theupload_filesrequirement on reads, the double extension-and-content validation on uploads, the four constraints on remote URL fetching, that omittingmedia_idremoves a featured image, and that attachment deletion is permanent on sites withoutMEDIA_TRASH. - Rewrite the
14-mcp-wordpress-taxonomy-toolschapter as a reference for the eleven taxonomy tools, covering the replace-by-default assignment behavior, that term reads need no WordPress capability while term meta needsmanage_categories, that term listings return no total, that term listings expose no hierarchy, and the credential-name guard on meta keys. - Correct three tool names that did not exist in the
22-mcp-resourcesand24-mcp-boundarieschapters:pom_theme_get_settingtopom_theme_get_settings_values,wp_set_featured_mediatowp_set_featured_image, andpom_cache_cleartopom_cache_clear_site_cache. - Correct the WooCommerce boundary note, which listed product categories among the covered tools. Categories are a replace-by-default field on the product create and update tools; no tool lists, creates or renames a product category.
- Rewrite the
18-mcp-woocommerce-coupon-toolschapter as a reference for the seven coupon tools, covering theedit_shop_couponscapability that differs from the product tools while the scope and write gate are shared, that only eight coupon fields are writable through MCP so minimum spend and per-user limits are unreachable, that the listing omitsdate_expiresso expiry cannot be audited from it, that trashed coupons keep their codes reserved, thatwc_delete_coupon's dry run does not verify the coupon exists, and thatwc_empty_coupon_trashpurges permanently in batches of 100. - Rewrite the
19-mcp-pom-theme-setting-toolschapter as a reference for the thirteen setting, CSS and asset tools, covering that reads neededit_theme_optionswhile writes needmanage_options, thatpom_theme_get_statusis the only tool registered when POM Theme is unavailable, that the writable-field allowlist contains two fields by default plus dynamic CPT layout fields, that JavaScript writes are refused unconditionally, that CSS validation blocks only PHP and</style>so invalid CSS is stored, and that the batch tool's owndry_runoverwrites each entry's. - Rewrite the
20-mcp-pom-theme-template-toolschapter as a reference for the seven template tools, covering the archive/single/feed split, that templates render nothing until assigned, that template markup is genuinely validated against the per-type merge tag catalog, that deleting a template leaves its assignment dangling, that acpt_singleassignment reports success without changing anything when no POM Theme post type row matches, and thatpom_theme_configure_content_modelis not atomic so a later-stage failure leaves earlier stages written. - Rewrite the
21-mcp-pom-cache-toolschapter for the two cache tools, documenting that cache clearing is behind no write gate, that both tools are registered even when POM Cache is absent, thatinclude_jsondefaults to true, thatdeletedis true when either purge succeeds sohtml_deletedmust be read separately, and that the cache statistics are reset regardless of the purge outcome. - Rewrite the
17-mcp-woocommerce-product-toolschapter as a reference for the sixteen catalog tools, covering the sharedmanage_woocommerce/edit_productspermission model and the catalog write gate, thatpriceis computed and onlyregular_priceandsale_priceare writable, that product listings return no total and cap at 100 whilewc_get_store_statssupplies the counts, that no tool deletes a product, thatcategoriesand the product attribute set both replace rather than append, that variation listings omit stock, thatwc_get_product_variationsreturns an empty list for a missing or non-variable product, thatwc_batch_update_variationsis a non-atomic loop whose per-entrydry_runoverrides the batch-level one and which silently skips entries without anid, and that no tool can add terms to an attribute. - Rewrite the
16-mcp-wordpress-site-and-menu-toolschapter as a reference for the twelve site, menu and SEO tools, covering the three different permission models, the read and write option allowlists, the recursive redaction in plugin settings reads, that menu item deletion is permanent and orphans children, and that the SEO tools write Yoast and Rank Math keys without detecting which plugin is active. - Rewrite the
15-mcp-wordpress-comment-and-meta-toolschapter as a reference for the seven comment tools and three post meta tools, covering themoderate_commentsrequirement on comment reads, theedit_postrequirement on meta reads, how the four moderation actions differ in reversibility and spam-filter feedback, that created comments are attributed to the acting user, and that post meta has no revision history.
Build
- Synchronize the recursive POM Knowledge Markdown tree to
wp-content/docs/pom-knowledgeduring local release builds while excluding hidden and non-Markdown files. - Update POM Framework so managed file reads are cached per request and OPcache remains an optional acceleration layer.
- Changes included in version 0.1.1.
Breaking changes
- Replaced the legacy public/private API key pair with the single POM AI product license key; legacy keys are no longer sent or accepted.
New features
- Added mandatory per-site POM AI licenses on multisite: each subsite (including third-party sites) must explicitly authorize its domain with a license whose account supplies the credits; plugin updates keep using the network license managed from the main site.
- Added the network-aware missing/invalid license admin notice and subscription cost info on the License tab.
- Added the shared POM Framework license field (save, masked display, revalidate, unlink) to the AI settings License tab.
- Sent
X-POM-License-KeyandX-POM-Domainheaders on every account API request.
Fixed
- Updated license guidance to list the canonical Single, Agency, and Unlimited POM AI plans.
- Added an always-visible multisite subsite license message explaining the main-site activation and network-license requirements for automatic updates.
- Stopped recommending or generating the retired listings shortcode and aligned POM authoring guidance with
web_listingsand its faceted-search mode. - Prevented duplicate monthly subscription credit batches from stacking in account balances.
Security
- Signed every POM AI request with timestamp, nonce, exact-body HMAC, and the shared product license key, and moved fallback updates exclusively to licensed v2 tokens with SHA-256 verification.
Changed
- Removed the unused account-side development copy so POM Standard remains the only account.pom.es POM AI implementation.
Documentation
- Required complete production-facing documentation maintenance and the canonical access-denying
.htaccessin repository agent guidance. - Replaced the completed client migration runbook with a permanent licensing, multisite, and verification reference, corrected setup/FAQ guidance, and removed placeholder links.
- Documented the client/account ownership boundary and direct migration to the shared single-license protocol.
- Standardized pending and historical release notes under the current categorized changelog format.
- Updated the release procedure to require dated changelog headings.
Build
- Centralized plugin documentation under
wp-content/docs/pom-aiduring local release builds and excluded thedocstree from ZIP artifacts. - Sourced manifest release notes from versioned changelog sections and rejected invalid changelog structures during builds.
- Accepted mandatory ISO release dates in versioned changelog headings when generating manifests.
- Pruned repository metadata from Composer dependencies before packaging production ZIPs.
Internal
- Deleted the local
pom_ai_api_keysoption automatically after the new license validates, leaving a non-secret migration marker. - Standardized incremental changelog maintenance and required
CHANGELOG.mdin release packages.
- Changes included in version 0.1.
Internal
- Established the existing release baseline before adoption of the incremental changelog workflow.
The entries below reconstruct unversioned or previously undocumented development before this repository adopted incremental release notes. Each active month consolidates its non-merge Git commits; merge-only, version-number-only, and internal tracking-only commits are omitted.
2026-06
New features
- Images: replaced references when replacing images.
Fixed
- Ai Translate: set Polylang language before translated terms. Set translated posts/products to the destination Polylang language before assigning translated taxonomy terms, so Polylang filters resolve categories in the target language.
- Framework: import framework classes consistently.
- Tinymce: open AI modal from separate editors.
- Releases: hardened private release publishing.
Security
- Security: POM Framework - Harden settings AJAX and dependency toolchain.
Changed
- Mcp: removed legacy iconpicker reference.
- Framework: POM Framework - Rename Pomatio Framework.
2026-05
New features
- Ai Mcp: added integrated MCP server.
- Added POM Cache tools to MCP for cache management.
- Ai Mcp: added MCP server settings to configuration and update access control.
- Mcp: added authoring context resources and validation.
- Mcp: improved MCP resources and prompts.
Fixed
- Ai Mcp: default OAuth DCR scopes for ChatGPT.
- Mcp: improved styling and layout of OAuth consent screen.
- Ai Mcp: accept missing OAuth resource from Codex.
- Account: aggregate domain allowances across active subscriptions.
Security
- Pom Form: updated pom-form reference and improve CSS class sanitization.
Documentation
- Updated AGENTS.md file.
2026-04
New features
- Implemented field persistence logic in Pomatio Framework to manage transient UI state.
- Pom Ai: migrated AI tools to GPT-5.4 and Gemini 3.1 image preview.
- Pom Translate: added translator notes to machine translation prompts.
- Merge Tags: pomatio Framework - Add robust nested merge tag parsing.
- Pom Form: added bulk open and close controls to repeaters.
Fixed
- Pom Ai: kept subscription credits active during delayed renewals.
- Pom Ai: reuse shared Responses parser for image metadata generation.
- Wines: improved local wine search matching.
- Openai: raise GPT-5 output token ceiling.
- Pom Form: contain CodeMirror horizontal overflow.
Security
- Pom Form: pomatio Framework - Apply WordPress file permissions to generated settings.
2026-03
New features
- Added prompt template manager. Added new reference images and per-image prompt for image improver tool.
- Added bulk wine creation feature from images and enhance AI wine filling functionality.
- Enhanced error handling and add detailed information for bulk wine creation process.
- Enhanced image processing by adding output directory handling and creating named temporary files.
- Added output format handling for image processing and enhance resizing functionality.
- Pom Ai: bg remover auto dimensions in target size.
- Improved AI fetching with AI.
Changed
- Pomatio Framework updated.
Documentation
- AGENTS.md update.
2026-02
Fixed
- Extract domain from url on domain adding on POM AI account.
- POM AI credits not being granted on subscription.
- POM AI Status detection was brittle (could return inactive even with a real subscription).
Changed
- Updated: improved plugin dashboard widget.
- Updated: Pomatio Framework.
Build
- Updated: Pomatio Framework and other vendor dependencies.
2026-01
New features
- Enhanced font management features in Pomatio Framework.
- AI: used gpt-5.2 for build-page generators.
- Enhanced AI text generation with improved AJAX handling and response extraction.
- Updated default word counts and add guidelines for content structure in prompt templates.
Fixed
- Improved shortcode handling and translation response validation in helpers.
- Ensured safe word count handling in createRepeaterItem function.
- Translate: handle WP_Error and chunk Google requests.
- Defer settings loading to init and improve settings definition handling.
Changed
- Refactored AI image generation and improvement prompts.
Build
- Composer updated.
2025-12
Fixed
- Handle product translation requests.
- Aligned woo term translations and short excerpts.
Build
- Composer updated, fixed product translating.
- Composer updated.
2025-11
New features
- Added google gemini image helper.
- Added Gemini image generation php function.
- Pom Account: used gemini for image generation.
- Image Tools: added support for expanded aspect ratios.
- Added images for radio tiles, removed post writer tool.
- Track AI credits with expiring batches.
- Surface credit breakdown in account dashboard.
- Landing Generator: stream section builds with progress.
- Admin: enhanced dashboard banner.
- Added plugin updater.
Fixed
- API: propagate remote errors.
- Propagate API failures to ajax handlers.
- Preserved prompt formatting.
- Hardened AI translate entity cloning.
- Improved WooCommerce translation coverage.
- Validate credit inputs and harden dashboard output.
- Prevented duplicated long post actions.
- Clamp long post word count.
- Hardened landing generator defaults and errors.
- Hardened image and translation helpers.
- Normalize generated image payloads.
- Respected table prefix for domain limits.
- Used max_completion_tokens for chat models.
- Pom Account: used standard text domain.
- Delay background removal deletion.
- Enforce image metadata limits and preserve fields.
- CSS fix.
- Settings: derive locale-based language labels.
- Persist landing generator AI context.
- Exclude vendor and node_modules from cs-fix.
- Honored top-up credits for standard orders.
- Process credits on all orders.
Changed
- Updated credits rates per tool.
- Improved image generator tools.
- Improved pom-account.
- Stop storing blog id in credit tables.
- Ignore /var folder and remove it from repo tracking.
- TinyMCE tool improvements.
- Dashboard improvements.
- Landing generator improvements.
- Improved my account endpoint.
- Improved translation prompt.
Documentation
- Document credit usage for pom account apis.
- Improved AGENTS.md.
Build
- Added releases workflows and scripts.
- Updated memory limit for composer stan command.
- Fixed composer cs errors.
- Composer updated.
Internal
- Added qa composer scripts.
- Stabilized phpstan.
- Added cs-fix command.
2025-10
New features
- Added remove bg tool.
- Added placeholder imagery to AI tool selection tiles.
- Added shared character limit handling to AI prompts.
- Added pom-pomstandard folder.
- Handle additional dictation audio MIME types.
- Expand allowed MIME types for audio transcription.
- Added reusable dictation component for admin prompts.
- Added voice dictation.
- Added direct generation option across AI tools.
- Added logging for AI credit consumption.
- Added usage logs table to account view.
- Account: auto-manage single-domain credits.
Fixed
- Fixed tile radio selection state in media tools.
- Fixed transcription request to send audio file data.
- Ensured credit renewals and account ux.
Security
- Enforce capabilities on ajax handlers.
- Changed permissions to edit_posts for getting credits.
Changed
- Updated pom-form.
- Moved wp core notices to an empty h1 for tidier look in wp admin.
- Moved each tool under corresponding submenus in wp admin.
- Refactored AI image generator admin UI.
- Removed modal from image generate tool.
- Refactored AI media tools to inline forms.
- Used tile layout for radio groups in image tools.
- Improved metadata row layout.
- Refine media picker layout and pagination.
- Removed unused previous page controls from image pickers.
- Used WP color picker for background selection.
- Refactored landing and long post tools to inline forms.
- Adjust progress display for structured tools.
- Deleted transcribe audio tool.
- Persist remaining credits across tools.
- Automate long post writer flow.
- Handle Safari dictation audio uploads.
- Improved audio mime detection for dictation uploads.
- Log credit movements for domain management.
Documentation
- Added AGENTS.md file.
Styles
- Improved styles.
Build
- Refactored AI texts generator to inline workflow.
2025-09
New features
- Updated pom-framework, added requires_initialization to false on main settings.
Changed
- Updated Pomatio Framework.
- Updated pom-form.
2025-08
New features
- Long posts writer tool for POM AI created.
Changed
- Updated translations.
Styles
- Moved bottom bar css to fenomenus.
2025-07
New features
- Added TODOs.
- Wines from image now allow to paste from Excel.
- New image improver tool.
- Added tool images and descriptions.
Changed
- Image generator now uses modern models.
- Applied maintenance updates to admin settings.
- Updated POM form.
- Updated settings.
- Improved UI.
- Moved AI wines from image to POM Restaurant Menus plugin.
Styles
- Minor admin CSS changes.
2025-06
New features
- Allowed editors to access AI tools.
- Added .gitignore.
Fixed
- Fixed translate with AI.
- Small fix for translating posts.
Changed
- Updated Pomatio Framework.
Styles
- Improved translate with AI styles.
2025-05
Changed
- Updated Pomatio Framework.
- Improvements to wine searcher.
2025-04
New features
- Added structured outputs for text generator.
- Added structured outputs for landing page generator.
Changed
- Updated POM AI API calls to account.pom.es.
- Improved text generator.
- The landing page generator now also designs.
- Translate with AI moved to POM AI plugin.
2024-10
New features
- Added appspec.yml file.
- Changed endpoints to work on production env, added transcibing AI tool.
- Improved text generator tool, added wines from image tool.
Fixed
- Temp debugging commit.
- POM AI debugging.
Changed
- Replaced local api endpoints by real production endpoints.
- Changed calculate credits API call from GET to POST.
- Changed calculate credits API call from POST to GET.
2024-09
New features
- New helpers: pom_ai_deduct_credits, pom_ai_get_site_credits, pom_ai_add_credits_to_site.
- Added image generator and image metadata generator.
Fixed
- Fixed modal for image generator module after image is generated.
Changed
- Translated admin menu links.
- Now all the prompts are generated with the Pomatio API.
- Now the api keys are stored as options in the site.
Documentation
- Added README.md.
Styles
- Unified repeated css in a shared css file, changed api keys to headers instead of body.
Internal
- Initial commit with base features.