WordPress for Cowork — Changelog
WordPress for Cowork runs on your own WordPress site. From v8.5.9 you connect Claude by pasting your site’s address into Claude and signing in to your own website — there is no file to download. Releases before v8.5.9 describe downloading a connector file, and releases before v7.0.0 describe an even earlier setup. Those steps no longer apply; the older entries are kept as a record, not as instructions.
v8.9.3 — 2026-09-29
- Clearer wording: the plugin details now explain that “Tested up to: 7.1” is the version of WordPress the plugin is tested on, not the plugin’s own version.
v8.9.2 — 2026-09-29
- Safer restores: a backup made by an older version is now also refused for pages that hold a shortcode (for example the WooCommerce My account page), not just for pages built with blocks, so it can’t blank them out.
- If a restore finds a page that was already damaged by an older restore, it now tells you which page, so you can have it rebuilt.
- A restore can now be undone: every page or post it changes appears in Claude’s list of changes and can be put back one at a time.
v8.9.1 — 2026-09-28
- Wording: your licence is limited by the number of people who use it, not by computers or websites. The Cowork screen and the plugin details now say so.
v8.9.0 — 2026-09-28
- Fixed: restoring a backup no longer flattens your page layouts. Backups now keep the full block layout of every page and post, so a restored page stays editable in the block editor. Backups made by older versions are still accepted, but any page they would have flattened is skipped and named in the result instead of being overwritten.
- Backups now include your site design too: global styles, custom CSS, customised templates and template parts, and navigation menus.
- When Claude adds custom CSS that repeats rules already on your site, it now warns you, so styles don’t quietly pile up.
- Every tool is now labelled read-only or write, so Claude can group them in the connector’s permission settings.
v8.8.9 — 2026-09-28
This release also brings the changes from 8.8.6 to 8.8.8, which were never released on their own.
- Connecting is simpler. The Cowork screen shows one clear way to connect: copy your site’s web address and paste it into Claude. The steps match what Claude shows today (Add custom connector, Continue, Add). You never need to download anything into Claude.
- A tip to set the connector’s tool permissions to Always allow, so Claude doesn’t stop to ask at every step.
- The Cowork screen now tells you when Claude is connected by web address.
- Automatic updates are switched on when you first activate the plugin, so new versions install themselves. The Cowork screen shows whether they are on, and you can turn them off on the Plugins screen.
- Undo covers site-wide design: ask Claude to undo a change to your colours and fonts, custom CSS, a template, a header or footer, or a navigation menu.
- Clearer descriptions for the template, template part, navigation and menu lists.
v8.8.5 — 2026-09-24
- Ask Claude which version you have. “What version of WordPress for Cowork do I have, and is there an update?” now gets a proper answer, including what the update server last offered.
- “Any updates available?” always checks fresh, instead of sometimes giving an answer up to 12 hours old.
- Experimental, off unless you switch it on under Cowork > Safety: Claude is told when an update adds new tools, so you don’t have to refresh the connector.
v8.8.4 — 2026-09-23
This release also brings everything built in 8.6.1 to 8.8.3, listed below it.
- Deleting a post category, tag or menu item now asks for confirmation first, like every other permanent delete.
- Adding site-wide CSS that is already there no longer adds a second copy.
- Menus made the classic way now show in the menu list on block themes too.
- When Claude reads a post or page it also gets the block layout, so edits keep the page’s structure.
- New: delete a shipping zone, and remove a custom field from a user or a category (all confirmed first).
- After updating, if Claude doesn’t list the new abilities, open your site’s connector in Claude and choose “Refresh tools list”.
Included from 8.8.0 to 8.8.3
- More than 200 things Claude can do on your site.
- Undo. Every change Claude makes is recorded, and a change to a page, post or product can be put back exactly as it was. There is also a log of everything Claude has changed, when, and whether it worked.
- Updates. Claude can update plugins, themes and WordPress itself, taking a full backup first every time.
- Clear the cache, read the error log, and send a test email when the site’s emails are not arriving.
- Redirects (with the Redirection plugin, or on its own), and reading messages from Contact Form 7, WPForms and Gravity Forms.
- Shop: refunds (always confirmed first, and a partial refund asks which items go back into stock), phone and manual orders, products with sizes, colours and other options, reviews, payment methods on and off, and shipping classes.
- Customer lists show each customer’s order count and total spent, and lists with more than 100 items no longer get cut short.
Included from 8.7.0
- Shop: order notes (private, or emailed to the customer), sales reports and best sellers, a low-stock list, customers and their order history, product categories and tags, attributes like Size and Colour, shipping zones and costs, tax rates, and duplicating a product.
- Site: write comments, work with any kind of category or custom field, save sections as reusable patterns, duplicate a post or page, restore from the trash, pick a featured image from your Media Library, change a page’s template, set your Privacy Policy page, and hide or show the site to search engines while you build it.
- Fixed: asking Claude to “add a note” to an order used to replace the note your customer typed at checkout. It now adds a proper order note.
- Anything that deletes something permanently asks for confirmation first.
Included from 8.6.1
- Claude follows this site’s safety rules automatically when you connect by address: ask before deleting, publishing or changing prices, back up before big changes, and check its work before saying it is done.
v8.6.0 — 2026-09-18
- A clearer approval screen. When you connect, your own website now shows its name, icon and address, and says plainly what Claude will and will not be able to do. Your password is never sent to Claude or to us, the connection can do nothing your own account cannot already do, and you can undo it at any time from either end.
- Safer if you run more than one website. Every tool now carries the name of the website it belongs to, so Claude cannot mix up two of your sites. The Cowork page also tells you exactly what to name each connection.
- Tested up to WordPress 7.1.
v8.5.9 — 2026-09-18
- Connect by address instead of a downloaded file. Copy the address from your Cowork page, paste it into Claude under Customize → Connectors → Add custom connector, and sign in to your own website to approve it. Nothing to download and nothing to install into Claude.
- Updating the plugin no longer breaks your connection. The address never changes, so you will not need to download or reconnect anything after an update.
- A “Run the check” button on the Cowork page. If a connection will not work, it tests every step from your site’s side and tells you which one failed — including whether Claude ever reached your website at all.
Also in this release — fixes built in two earlier test versions that were never released on their own:
- Restoring from a backup no longer crashes your site. Asking to restore only part of a backup — just your pages, say — could produce “There has been a critical error on this website” instead. That’s the one thing you do when something has already gone wrong, so it had to be right. It now understands either way of asking, and tells you if you name something it doesn’t recognise instead of quietly restoring nothing.
- Claude no longer tells you it can’t change your theme when it can. Installing a theme came with a note claiming theme switching was blocked by safe mode. It never was.
- Installing a plugin you already have now says so. You used to get a failure message about your web host’s download speeds, which had nothing to do with it.
- Claude can now delete a menu it created. Block menus could be made but never removed, so a menu created by mistake stayed on your site for good. There’s now a proper way to remove one — and it refuses if the menu is still being used by your header or footer, and tells you which, rather than quietly leaving a blank space where your navigation was.
- Asking “which of my images are missing alt text?” now gets a useful answer. The image list didn’t include alt text at all, so Claude couldn’t tell you which images needed it, let alone fix them. It can now, and the site audit lists the specific images rather than just counting them.
- Installing a plugin no longer sometimes looks like it failed when it worked. If a plugin printed anything while being switched on, it garbled Claude’s reply — so you’d be told something went wrong on an install that had actually succeeded. Any plugin on your site could do this to any request; it can’t now.
- Deleting something gives you a straight answer. Deleting a page used to reply with the entire contents of the page you’d just deleted. Every kind of delete now answers the same short way, and says whether it went to the trash and how to get it back.
- “Add a product called Blue Widget for £9.99” now just works. Claude used to refuse unless you also gave it a product description — so it either had to stop and ask, or make up sales copy for a product it knew nothing about and save that to your shop. Name and price are enough now.
- Menu lists are readable again instead of a wall of internal WordPress data.
v8.5.6 — 2026-09-17
- The Cowork page now tells you whether Claude has actually connected. Until now it only said your site was set up — which is about your server, not about whether Claude ever reached it. So the one step that can fail silently, importing the connector into Claude and restarting it, gave you nothing to go on. You’ll now see either “Claude last connected 5 mins ago”, or a plain warning that it hasn’t connected yet, with the most common reason: Claude wasn’t fully quit and reopened.
v8.5.5 — 2026-09-17
- Setting up is now three numbered steps, and they’re the right ones. The Cowork page used to say “drag the file into Claude Desktop”, which isn’t how Claude takes a plugin, and it never mentioned that you must fully quit and reopen Claude afterwards. Both are fixed, and the page now tells you how to check it worked.
- Downloading a second connector asks first. It always replaced the one before it and stopped that one working — now it warns you before it does, instead of in small print afterwards.
- If setup fails, you get a message to send your host. Instead of being told a folder isn’t writable and left to work out what that means, there’s now a ready-written note you can copy and forward.
- The page is shorter. Safety details, site health and the manual connect-code method are tucked away until you want them, so the setup steps aren’t buried.
- The licence button now says what it does — and, more usefully, says that it won’t fix a broken Claude connection and points you at the thing that will.
v8.5.4 — 2026-09-17
- Claude can no longer disconnect itself by accident. Asking Claude to remove or switch off “the WordPress for Cowork plugin” used to be carried out literally, which deleted your licence and the connection along with it. Claude now refuses and points you to the Plugins screen if you really mean to.
- Plugins Claude installs now activate first time. After installing a plugin, Claude sometimes could not activate it because the two steps named the plugin differently. Any of the usual spellings now work, so “install WooCommerce and turn it on” does exactly that.
v8.4.9 — 2026-08-26
- Claude can now see the page it just built. Until now it could save a page and confirm the save worked, but it had no way to look at the result — so a hero band with nothing inside it, or columns full of empty paragraphs, would save perfectly and be reported back to you as a finished design. Claude now fetches the live page the way a visitor gets it and checks what actually rendered: the headings, the sections, the images, and how much real text is on the page. If it comes back empty, Claude fixes it instead of telling you it is done.
- /wp-design now checks its own work. It builds the page, looks at it, and only then shows it to you. It will still ask how it looks — it can tell that a page has content, not that the content is beautiful.
v8.4.8 — 2026-08-14
- Fixed: “design my page” and “restyle my site” could come back refused. The
/wp-designand/wp-themecommands were telling Claude to use a tool that safe mode blocks — so on a normal install, with safe mode on as recommended, the two things the plugin is most used for could fail for no visible reason. Both now use the supported route, which works with safe mode left on. You should never have to turn safe mode off to design a page. - Fixed: a caching plugin could make a working connection look broken. Right after you activate, a caching plugin (LiteSpeed, WP Rocket and others) could still be serving the “not found” it stored from before the plugin was set up — so Claude could not reach a site that was working perfectly. The plugin now clears the cache after setting itself up, and marks its own address as never-cacheable.
- /wp-status now tells you more. It reports your WordPress and PHP versions, your theme, your permalink setting, and — most useful — whether safe mode is on. Safe mode is the usual reason a request comes back refused, and it was the one thing the command never mentioned.
v8.4.7 — 2026-08-13
- Claude now knows how to make your site look like something. Asking for a site that looks like a particular brand or website used to change only the colours and fonts — which, on a homepage that is really your blog, just gives you a recoloured blog. Claude now builds the page first (hero, sections, call to action, real words), makes it your homepage, and then applies the design across every page.
- Claude will also now tell you plainly that it cannot see the finished page, and ask you how it looks, rather than claiming a design is finished when it has only checked that the styles saved.
v8.4.6 — 2026-08-13
- Connect as many sites as you like, and switch between them by name. Every site’s connector is now named after that site, so two sites no longer clash in Claude Desktop. Each one also adds its own command — type
/yoursite-comand everything after that goes to that site. Install once per site; no swapping files to change site. - Your connector’s description now shows the site’s domain, so you can tell them apart at a glance.
v8.4.5 — 2026-08-12
- Fixed: removing your site-wide custom CSS silently did nothing. Asking to clear it reported success while the CSS stayed on every page. Clearing now works, and if a request would change nothing you are told so instead of being told it worked.
v8.4.3 — 2026-08-12
- Switching theme now works with safe mode on. Changing your site’s whole look is one of the main reasons people use this, and safe mode was standing in front of it. A theme change deletes nothing — your posts, pages, products and settings are untouched — and it is undone by switching back, so it no longer needs to be blocked. Claude still asks before doing it, and now tells you which theme you were on before so you can go straight back if you don’t like it.
- Added a note on how to use safe mode. While you are setting the site up or making big changes, turn it off. Once the site looks how you want it, switch it back on and leave it on — ordinary day-to-day work never needs it off.
v8.4.2 — 2026-08-12
- Corrected the Safety panel. It listed “restoring a backup” as something safe mode blocks. That has not been true since restore was deliberately allowed — blocking it would have blocked your recovery route at the exact moment you needed it. The panel now also mentions that safe mode refuses a permalink structure which would give every post the same URL, which it has always done but never said.
v8.4.1 — 2026-08-12
- Fixed: switching theme never worked. Asking Claude to activate a theme failed every time with a “no route” error. It now switches the theme properly, and checks afterwards that the switch really happened before telling you it did. (Safe mode still holds this back unless you turn safe mode off.)
- Fixed: deleting a plugin rejected the name the plugin list gave you. Listing your plugins reported a name that the delete tool then refused, while telling you to go and look it up in the list. Both forms are now accepted.
v8.4.0 — 2026-08-12
- New: seven shortcut commands in Claude Desktop. Alongside
/wp-status, your connector now includes/wp-list,/wp-publish,/wp-design,/wp-theme,/wp-comments,/wp-backupand/wp-restore— quick ways to list content, publish posts and products, build and restyle pages, moderate comments, and back up or restore your site. You can still do everything in plain language; these are just faster shortcuts. Download a fresh connector from wp-admin → Cowork to get them.
v8.0.3 — 2026-08-11
- Fixed: some actions reported success when they had failed. If WordPress refused something, that refusal was being passed back as a normal result — so Claude could tell you a file was deleted, or a plugin installed, when nothing had happened. Any refusal from WordPress is now reported as a failure, everywhere.
- Fixed: installing a plugin could say “installed” and install nothing. On hosting with a short download timeout, large plugins fail to download. The plugin now checks that the plugin is really there afterwards, and if it is not, tells you why and suggests uploading the zip by hand instead.
- Fixed: WooCommerce tools now say so when WooCommerce isn’t installed. They used to return an empty product with a blank name, or an error page, which read as real data.
- Fixed: deleting a media file never worked. Attachments have no trash, so the safety setting that sends things to the trash made media deletion impossible. Media now deletes properly, and asks you to confirm first because it cannot be undone.
- Fixed: bulk SEO updates silently did nothing if you used the same field names as the single-item tool. Both spellings now work, and an item with nothing to write is reported as an error rather than as updated.
- Fixed: your site’s timezone showed as blank in one place and correct in another.
- Fixed: the connection test showed a blank email address.
- Fixed: the user list left out roles entirely, so a role could be changed and never read back — and it carried a lot of internal data that did not belong in a chat.
- Fixed: deleting a comment returned the commenter’s IP address and email.
- Fixed: content statistics labelled a count of posts and pages as “posts”.
v8.0.2 — 2026-08-11 (cache clear no longer runs on failed changes)
- Fixed: the automatic cache clear ran even when a change had failed. Harmless, but it meant the site was being purged for no reason.
v8.0.1 — 2026-08-11 (SEO now explains what it can still do)
- When no SEO plugin is installed, Claude now tells you what it can do instead of just declining. Without one, WordPress builds the page title tag from the post title — so the post title is what search engines show, and Claude can edit that, along with slugs, headings and excerpts. That covers most of on-page SEO.
v8.0.0 — 2026-08-11 (works with the SEO plugin you already have; automatic cache clearing)
- SEO now works with the SEO plugin you already have. Yoast, Rank Math, SEOPress and Slim SEO are all supported, including their free versions. Previously the SEO tools only worked with Slim SEO — on any other site they reported success and changed nothing. Nothing to install and nothing to switch.
- If no supported SEO plugin is active, Claude now says so plainly instead of claiming to have saved something. WordPress has no field of its own for a meta title, so there is genuinely nowhere to put one.
- If two SEO plugins are active, Claude warns you — they compete over the title tag and the result is duplicate tags.
- Your page cache is cleared automatically after any change. WP Rocket, LiteSpeed, W3 Total Cache, WP Super Cache, WP Fastest Cache, Cache Enabler, Autoptimize, SiteGround Optimizer and Kinsta. Before this, a change could be saved correctly and you would still see the old page and assume it had failed.
- Fixed: the SEO summary counted the wrong field, so it under-reported how much of your site was optimised — even on Slim SEO.
v7.9.0 — 2026-08-11 (groundwork for SEO plugin support)
- Groundwork for the SEO plugin support released in 8.0.0.
v7.8.0 — 2026-08-11 (30 new tools — 74 to 104)
- 30 new tools — 74 to 104. Menu locations, revisions, block templates, widgets, permalinks, site icon and logo, diagnostics, and theme installation.
- Menus now actually appear on your site. Previously Claude could build a menu and fill it with links, but nothing attached it to a position in your theme — so the menu existed and was invisible. It can now list the positions your theme offers and assign a menu to one.
- Revisions. See every saved version of a post, read any of them, and roll back to one. The version that was live is kept, so a rollback is itself undoable.
- Block templates. List, read, create, edit and remove the templates a block theme uses for your homepage, single posts, archives and 404 page.
- Widgets and sidebars for classic themes: see what your theme offers and place or remove widgets.
- Permalinks. Change the URL structure of your posts. Safe mode refuses a structure that would give every post the same address.
- Site icon and logo can be set from anything in your media library.
- Editing without resending everything. Append or prepend to a post, or find and replace a phrase inside one, without Claude rewriting the whole page. Faster, and it cannot accidentally lose the parts it was not asked to change.
- Diagnostics. WordPress and PHP versions, pending updates, scheduled jobs, media missing alt text, SEO coverage, scheduled posts, and a broken-link scan.
- Content statistics — published counts by author and by month. This is not visitor traffic; WordPress core does not record any.
- Themes can be installed by name from the WordPress.org directory.
- Fixed: block templates created by earlier tooling were not linked to your active theme, so they were created successfully and then never used.
- Fixed: the installer looked for the bundled endpoint under the wrong filename in 7.7.0. On some sites WordPress also offered to activate the wrong file after upload, reporting “the plugin does not have a valid header” on a perfectly good install.
v7.7.0 — 2026-08-10 (menus become editable; categories and tags)
- Menus can be edited, not just viewed. Create menus, add pages or custom links, reorder them, nest them into dropdowns, and remove items. Previously the menu tool took no parameters at all and could only list what was there.
- Categories and tags can be renamed. Rename or re-slug a category, change its parent, and create, rename or delete tags. Only category creation existed before.
- 74 tools in total.
v7.6.0 — 2026-08-10 (18 new tools — 46 to 64)
- 18 new tools — 46 to 64. This release closes the gap between what the website promised and what the plugin could actually do.
- Media is no longer read-only. Upload files from a URL or directly, set alt text, captions and titles, and attach an image as a post’s featured image in the same step.
- Site-wide theming has a real tool at last. Set colours, typography and custom CSS across every page. Works on block themes via theme.json and on classic themes via Additional CSS, so “make my whole site look like this” works either way.
- Users. Create accounts, change roles, send password resets, and remove people with their posts reassigned rather than deleted. No password is ever set or shown in the conversation — WordPress emails them a link to choose their own.
- Scheduling actually schedules. Posts now take a date, and a future date sets the post to publish then. Slugs can be set on posts as well as pages.
- WooCommerce. Stock levels, SKUs, weight, dimensions, shipping class, product images and categories. Order status can be updated. And coupons exist — create, list, update and delete, with expiry dates, usage limits and product restrictions.
- Plugins can be installed by name from the WordPress.org directory, and removed.
- Site settings widened from just title and tagline to timezone, date and time format, posts per page, and which page is your homepage. Setting a homepage now switches the site to use it, rather than silently doing nothing.
- Fixed: settings could not be cleared, only changed — an empty value was indistinguishable from one you hadn’t sent. The tagline can now be blanked.
- Safe mode revised: deactivating a plugin is allowed again (it’s reversible in one command), while deleting one is now blocked, which is the thing you can’t undo. Deleting a user without saying where their posts should go is also refused.
v7.5.2 — 2026-08-10 (safety skill: what a theme is, and honesty rules)
- The safety skill in your connector now explains what a theme actually is: one shared set of design decisions applied to every page, defined once as CSS variables — not a styled landing page with the rest of the site left behind, and not a separate block of CSS per page. Per-page styles drift apart and produce a site that looks different depending on where you land.
- Claude now asks you to inspect an element and paste the tag when it needs a class name, rather than guessing selectors and changing your live site repeatedly hoping one of them matches.
- Added honesty rules: don’t claim something is done without checking, don’t describe a page that hasn’t been read, don’t state figures without a source, and don’t guess an ID. If a request could mean two things — “tidy up the blog” — ask which, rather than picking one and acting on it.
- A multi-step change now either finishes or gets put back. If it can’t finish, Claude tells you exactly which pages changed and which didn’t, rather than leaving you to work it out. A theme applied to three pages out of twelve looks broken in a way the original never did.
v7.5.0 — 2026-08-10 (safe mode, on by default)
- New: Safe mode, on by default. Claude can reach 46 tools on your site. Safe mode holds back the handful that could make your site unreachable or destroy something you cannot get back — changing your site address, the unrestricted API passthrough, deactivating plugins, switching theme, and restoring backups.
- Deleting posts, pages and comments now sends them to the trash rather than removing them permanently, so a mistake is recoverable.
- Everything else is unchanged. Writing and editing content, comments, products, categories and SEO all work exactly as before.
- You can turn safe mode off at Cowork → Safety if you specifically need those tools, or pin it with the WFC_SAFE_MODE constant in wp-config.php.
- The connector you download now carries a safety skill, so Claude asks before publishing, deleting, or changing prices on a live site, and reads changes back to confirm they actually landed rather than assuming.
v7.4.0 — 2026-08-10 (the plugin updates itself)
- New: the plugin now updates itself. Until this release there was no update mechanism at all, so the only way to move from one version to the next was to be sent a zip and re-upload it by hand. New versions now appear on the Plugins screen and install with one click, like any other plugin.
- Update checks are cached and fail open. If wordpressforcowork.com is slow or unreachable you simply see no update — your admin screens never hang and nothing on your site breaks.
- Corrected the documentation: there is no site limit on any plan. Earlier readmes referred to a “site allowance”, which was wrong.
v7.3.0 — 2026-08-08 (the full tool set arrives in the bundled endpoint)
- The bundled MCP endpoint is now the full 45-tool version, replacing the 5-tool core. Adds themes, menus, plugins, media, comments, categories, tags, users, SEO, backups, WooCommerce, and a wp_raw_api escape hatch. This brings v7 to feature parity with v6 — until now v7 could only read and write posts and pages.
- Its authentication was rewritten for the v7 model. The original authenticated against License Manager for WooCommerce and a device-cap heartbeat, both of which exist only on wordpressforcowork.com; on a customer’s own site every request would have failed. It now uses the Application Password the plugin generates for itself.
v7.2.2 — 2026-08-07 (connector filenames carry version and site)
- The downloaded connector is now named with its version and a short site tag, e.g. wordpress-for-cowork-7.2.2-u9-xrms.plugin. Previously every download was called wordpress-for-cowork.plugin, so a second download collided in the Downloads folder and nobody could tell which build they had.
v7.2.0 — 2026-08-07 (Download my Claude connector)
- New: “Download my Claude connector” button. The site now builds a connector file already personalised to itself, so there is nothing to copy, configure or install. One click in wp-admin, drag the file into Claude Desktop, done.
- The connector carries a literal endpoint URL rather than a placeholder. Cowork validates that URL before substituting variables, which is why every earlier version failed to install with “MCP server has invalid URL”.
- The manual connect code remains, demoted to a fallback.
v7.0.3 — 2026-05-29 (connect codes could never be generated)
- Fixed: the Application Passwords availability check tested a function that does not exist in WordPress core, so connect codes could never be generated. Affected every installation.
- Fixed: the bundled MCP endpoint reported a hardcoded version that could drift from the plugin’s. It now resolves the live version at request time.
v7.0.0 — 2026-05-29 (complete overhaul — the plugin runs on your own site)
- Complete overhaul. Self-install activation, Application Password self-generation, mu-plugin installer, a real working MCP endpoint (site info + posts/pages), one-time AES-256-GCM connect code with random reference codename, wp-admin page, and a multi-domain license client with weekly fail-open re-validation.
Earlier releases (v5.x)
Kept for reference. These entries describe the superseded setup flow — the slash commands and allowlist steps mentioned below are no longer part of the product.
v5.0.5 — 2026-04-30 (customer-facing — license-model rewrite + machine ID + update notices)
Changed
- Removed all subscription / trial / “seats used” language across
README.md,plugin.json,commands/wp-setup.md, andCONNECTORS.md. The plugin now correctly reflects the live one-time-purchase + 1-year-updates-included + optional yearly maintenance renewal model. Plans table replaced with current Solo $99 / Agency $399 / Enterprise from $414 pricing, “licenses included” framing, unlimited domains, 2 devices per user license. Stripe entry reframed from “subscription billing” to “checkout + optional yearly renewal.” - Dropped legacy CW-SOLO-* / WPCv3-* license-key format references from
wp-setup.mdstep 1. SKILL.md“How This Plugin Works” corrected from “shared-secret Bearer token” (v4.x stale wording) to “license-key Bearer token fromWORDPRESS_COWORK_KEY.”SKILL.mdslash-commands table entry for/wp-setupupdated from “Configure the shared secret” to “Activate your license key.”- Skill version bumped to 5.0.5.
Added
- Machine ID generation in
/wp-setupstep 2. A stable UUIDv4 is generated on first setup and reused on every subsequent run. Stored in~/.claude/plugin-config/wordpress-for-cowork.jsonalongside the license key. The license server uses this to recognize the device when checking the 2-device-per-user-license cap. Existingmachine_idvalues are preserved on re-runs. - Persistent state expanded. Config file now also tracks
last_setup_at,plugin_version, and aconnected_sitesarray that grows as additional sites are connected via/wp-setup. Re-running/wp-setuppreservesmachine_idandconnected_sites(only re-writeslicense_key,last_setup_at,plugin_version). - Update notice in
/wp-setupstep 3. Calls the public/wp-json/wpfc-release/v1/latestfeed, compares to the bundled plugin version, and surfaces a one-line notice if a newer version exists. Severity-aware wording (critical → install before continuing, high → install soon, otherwise → install when convenient). Fails silently if the feed is unreachable. maintenance_expired(403) error case inwp-setup.md— the plugin keeps working, but updates pause until renewal. Replaces the removed “trial expired” / “subscription lapsed” cases.config file at ~/.claude/plugin-config/wordpress-for-cowork.jsonexplicitly documented in the Notes section: license key + machine ID (UUIDv4) + last setup timestamp + plugin version + connected sites, mode 600.
Unchanged
- Tool surface, endpoint URL, slash command set.
- Auth model (license-key Bearer via
WORDPRESS_COWORK_KEY). - Backup safety pre-flight prompt + server-side
-32099gate handling. - Security-plugin warning in
wp-setup.mdstep 5 (carried over unchanged from 5.0.4).
Notes / not in this release
- Server-side machine_id registration is not yet wired through
mcp__wordpress__wp_setup. The hosted MCP at wordpressforcowork.com needs to accept amachine_idparameter and use it when applying the 2-device cap. Until that lands server-side,machine_idis generated and persisted on the client only — the server still falls back to IP-based device tracking. Tracked separately. - wp-admin JS heartbeat (the original H8 / [16] task) is moot under the current hosted-MCP architecture — the customer’s WordPress site no longer runs any of our plugin code, so there’s no surface to attach a JS heartbeat to. The license server already gets a heartbeat on every tool call (it sees IP + timing per call), which covers the original goal.
v5.0.4 — 2026-04-30 (customer-facing — proactive security-plugin warning)
Added
commands/wp-setup.mdnow has a “Before you generate an Application Password” callout listing the most common WordPress security plugins (Wordfence, iThemes/Solid Security, Sucuri WAF, WP Cerber, managed-host firewalls) and the specific toggle to flip in each. Links to the full troubleshooting guide onwordpressforcowork.com/support/. This was the #1 cause of “plugin won’t connect” support tickets — now caught proactively before the user even tries.
Unchanged
- Tool surface, auth model, slash commands, endpoint URL, license-key flow.
v5.0.3 — 2026-04-30 (customer-facing — dead link cleanup)
Fixed
- Replaced two stale
/my-account/licenses/references incommands/wp-setup.mdwith the new/my-account/devices/portal URL. License Manager for WooCommerce free version doesn’t expose a/licenses/endpoint, so those links were dead 404s. - Reframed “seat limit” 403 guidance as “device limit” 403 to match the new license model: each license can be registered to 2 devices (laptop + desktop). Customer manages registered devices at
/my-account/devices/.
Unchanged
- Tool surface, auth model, slash commands, endpoint URL, license-key activation flow.
Known stale (still pending — tracked separately as H7 / [16b])
- README and wp-setup.md still reference subscriptions, “seats used”, trial expiration, and a CW-SOLO-* / WPCv3-* legacy license format. These need a wholesale rewrite to match the current one-time-purchase + maintenance + N-keys-per-tier + unlimited-domains model. Out of scope for this patch.
v5.0.2 — 2026-04-27 (customer-facing — backup-gate handling)
Added
wordpress-site-builderskill now handles server-side-32099 "Backup confirmation required"errors. New section in SKILL.md (after “Restoring later”) tells the skill to stop, surface the error to the user, and retry either after taking a fresh backup OR with_skip_backup_ack: trueonce the user opts to skip.
Why
The endpoint mu-plugin wpfc-backup-gate.php (deployed 2026-04-27) blocks destructive tool calls when the most recent on-disk backup is older than 60 minutes. The skill previously didn’t know about this error code and would have surfaced a raw JSON-RPC error to the user. With this update, the skill recognizes the gate, explains it, and routes the user to either take a backup or override.
Unchanged
- Tool surface, auth model, slash commands, Plans table, pricing.
- Endpoint URL.
v5.0.1 — 2026-04-27 (customer-facing — docs)
Fixed
- README pricing table. Removed stale “verify Enterprise pricing” caveat (Enterprise pricing is now stable). Restated Enterprise as per-seat with a 6-seat minimum and added the implied $45/mo / $450/yr floor. Added a one-line note about ~17% annual savings.
Unchanged
- Tool surface, auth model, commands, skill, endpoint URL.
- Live site pricing — README now matches the Plans page.
v5.0.0 — 2026-04-27 (customer-facing)
Customer-facing release alongside v4.x internal build
This is the customer-facing variant of the plugin. The v4
