{"id":311005,"date":"2026-06-26T06:49:51","date_gmt":"2026-06-26T06:49:51","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/acrossai-abilities-manager\/"},"modified":"2026-09-28T18:13:56","modified_gmt":"2026-09-28T18:13:56","slug":"acrossai-abilities-manager","status":"publish","type":"plugin","link":"https:\/\/haz.wordpress.org\/plugins\/acrossai-abilities-manager\/","author":15295430,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.0.40","stable_tag":"0.0.40","tested":"7.1.2","requires":"6.9","requires_php":"8.1","requires_plugins":null,"header_name":"AcrossAI Abilities Manager","header_author":"raftaar1191","header_description":"Manage and customize the abilities of AcrossAI on your WordPress site. Tailor the AI's capabilities to suit your needs, enhancing user experience and engagement.","assets_banners_color":"fdfdfe","last_updated":"2026-09-28 18:13:56","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/acrossai.co\/abilities-manager\/","header_plugin_uri":"https:\/\/acrossai.co\/abilities-manager\/","header_author_uri":"https:\/\/profiles.wordpress.org\/raftaar1191\/","rating":0,"author_block_rating":0,"active_installs":20,"downloads":1618,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.0.1":{"tag":"0.0.1","author":"raftaar1191","date":"2026-06-26 06:49:29","revision":3586852},"0.0.10":{"tag":"0.0.10","author":"raftaar1191","date":"2026-07-18 00:50:18","revision":3612106},"0.0.11":{"tag":"0.0.11","author":"raftaar1191","date":"2026-07-18 15:51:33","revision":3612771},"0.0.12":{"tag":"0.0.12","author":"raftaar1191","date":"2026-07-18 16:15:59","revision":3612787},"0.0.13":{"tag":"0.0.13","author":"raftaar1191","date":"2026-07-20 03:01:52","revision":3614043},"0.0.14":{"tag":"0.0.14","author":"raftaar1191","date":"2026-07-20 03:08:58","revision":3614045},"0.0.15":{"tag":"0.0.15","author":"raftaar1191","date":"2026-07-20 19:33:50","revision":3616130},"0.0.17":{"tag":"0.0.17","author":"raftaar1191","date":"2026-07-25 15:38:31","revision":3622584},"0.0.18":{"tag":"0.0.18","author":"raftaar1191","date":"2026-07-27 09:05:53","revision":3624246},"0.0.19":{"tag":"0.0.19","author":"raftaar1191","date":"2026-07-31 07:41:16","revision":3629582},"0.0.2":{"tag":"0.0.2","author":"raftaar1191","date":"2026-07-02 12:04:52","revision":3593974},"0.0.20":{"tag":"0.0.20","author":"raftaar1191","date":"2026-08-02 14:45:00","revision":3631858},"0.0.21":{"tag":"0.0.21","author":"raftaar1191","date":"2026-08-08 09:21:59","revision":3638558},"0.0.22":{"tag":"0.0.22","author":"raftaar1191","date":"2026-08-10 18:14:44","revision":3640993},"0.0.23":{"tag":"0.0.23","author":"raftaar1191","date":"2026-08-11 09:38:46","revision":3641623},"0.0.24":{"tag":"0.0.24","author":"raftaar1191","date":"2026-08-12 17:51:24","revision":3643839},"0.0.25":{"tag":"0.0.25","author":"raftaar1191","date":"2026-08-13 13:28:41","revision":3645467},"0.0.26":{"tag":"0.0.26","author":"raftaar1191","date":"2026-08-13 19:38:26","revision":3646090},"0.0.27":{"tag":"0.0.27","author":"raftaar1191","date":"2026-08-13 20:23:39","revision":3646142},"0.0.29":{"tag":"0.0.29","author":"raftaar1191","date":"2026-08-18 09:29:25","revision":3652373},"0.0.3":{"tag":"0.0.3","author":"raftaar1191","date":"2026-07-02 12:30:19","revision":3594026},"0.0.30":{"tag":"0.0.30","author":"raftaar1191","date":"2026-08-19 13:19:05","revision":3654660},"0.0.31":{"tag":"0.0.31","author":"raftaar1191","date":"2026-08-26 17:33:00","revision":3667538},"0.0.32":{"tag":"0.0.32","author":"raftaar1191","date":"2026-08-27 21:06:10","revision":3669524},"0.0.33":{"tag":"0.0.33","author":"raftaar1191","date":"2026-08-27 21:40:21","revision":3669542},"0.0.34":{"tag":"0.0.34","author":"raftaar1191","date":"2026-09-18 19:56:02","revision":3702724},"0.0.35":{"tag":"0.0.35","author":"raftaar1191","date":"2026-09-21 05:50:48","revision":3704896},"0.0.36":{"tag":"0.0.36","author":"raftaar1191","date":"2026-09-21 10:37:56","revision":3705392},"0.0.37":{"tag":"0.0.37","author":"raftaar1191","date":"2026-09-21 16:12:56","revision":3705920},"0.0.38":{"tag":"0.0.38","author":"raftaar1191","date":"2026-09-21 18:38:57","revision":3706150},"0.0.39":{"tag":"0.0.39","author":"raftaar1191","date":"2026-09-28 17:01:11","revision":3717635},"0.0.4":{"tag":"0.0.4","author":"raftaar1191","date":"2026-07-03 22:38:31","revision":3595583},"0.0.40":{"tag":"0.0.40","author":"raftaar1191","date":"2026-09-28 18:13:56","revision":3717729},"0.0.5":{"tag":"0.0.5","author":"raftaar1191","date":"2026-07-04 01:29:09","revision":3595636},"0.0.6":{"tag":"0.0.6","author":"raftaar1191","date":"2026-07-13 14:09:04","revision":3606181},"0.0.7":{"tag":"0.0.7","author":"raftaar1191","date":"2026-07-13 18:14:55","revision":3606552},"0.0.8":{"tag":"0.0.8","author":"raftaar1191","date":"2026-07-17 00:32:32","revision":3610859},"0.0.9":{"tag":"0.0.9","author":"raftaar1191","date":"2026-07-17 16:29:43","revision":3611804}},"upgrade_notice":{"0.0.37":"<p>Fixes the UpdraftPlus and All-in-One WP Migration tools being offered on sites without those plugins installed - they appeared in the tool picker and in what a new MCP server starts with, unlike every other per-plugin toolset. The tools themselves were never broken and still work exactly as before when their plugin is active. If a server already has one of them and the plugin is not installed, &quot;Reset to Type Defaults&quot; clears it. No other changes.<\/p>","0.0.36":"<p>No breaking changes - every addition here is optional and defaults to what the plugin did before. Worth updating for three things. Listing posts, pages or custom post type items no longer forces the whole post body down the wire: pass fields: &quot;summary&quot; for titles, dates, slugs and a content size instead, measured 36x smaller on ten real posts. The block outline reported the wrong total when truncated - asking for 3 blocks of a 40-block post said &quot;total: 3&quot; - which is now the true match count with a separate &quot;returned&quot; alongside. And Site Health results can be read as plain text with format: &quot;text&quot; rather than WordPress core&#039;s own markup. Also adds a check that every ability declares whether it reads, destroys or can be repeated, since an AI client treats a missing flag as &quot;not destructive&quot;.<\/p>","0.0.35":"<p>BREAKING - the <code>backups\/*<\/code> abilities added in 0.0.34 are replaced by <code>updraftplus\/*<\/code> and <code>all-in-one\/*<\/code>. Anything holding a <code>backups\/<\/code> slug needs updating; there are no aliases. The backup abilities are now two tabs, one per plugin, matching how every other integration works: each offers only what its plugin can actually do rather than advertising everything and reporting absence when you try to use it. Also fixes restoring, which never worked outside the admin screens in 0.0.34 - it checked the filesystem using a function WordPress only loads inside wp-admin, so every restore request failed on that line before checking anything. If you rely on restoring from UpdraftPlus through this plugin, this release is the one that makes it work. Nothing else changes; existing abilities, overrides and access rules are unaffected.<\/p>","0.0.34":"<p>BREAKING - abilities now require administrator rights unless a rule says otherwise. If anyone below administrator drives this site through an AI client, they lose access on update until an administrator grants it: set a rule on the individual ability under User Access, or move the site-wide floor with the <code>acrossai_default_ability_capability<\/code> filter. This closes a real hole - measured on one site, three installed abilities had no permission check at all, two were open to any logged-in subscriber, and one that writes content was open at contributor level. Otherwise additive: 19 new tabs and around 400 new abilities, including WooCommerce, backups, Yoast SEO, LiteSpeed Cache and Contact Form 7. Existing abilities, overrides and access rules are unaffected.<\/p>","0.0.21":"<p>Bumps the <code>wpboilerplate\/wpb-access-control<\/code> composer dependency from <code>^2.0.0<\/code> to <code>^3.1.0<\/code> \u2014 two library releases in one hop. v3.0.0 removed two plugin-dependent providers (<code>BuddyBossProfileTypeProvider<\/code>, <code>MemberPressMembershipProvider<\/code>) that were extracted into a separate add-on (<code>acrossai\/user-access-pro<\/code>); this plugin uses only the core <code>AccessControlManager<\/code> + <code>RuleTable<\/code> classes, so no consumer code change is required. v3.1.0 adds a new &quot;Any logged-in user&quot; option to the Access Control dropdown (backed by a new <code>authenticated<\/code> sentinel rule type), and renames &quot;Everyone (no restriction)&quot; \u2192 &quot;Public (no login required)&quot; for clarity. Existing rules unaffected. Safe upgrade from 0.0.20.<\/p>","0.0.20":"<p>Routes the access-control library-missing warning through the new shared AcrossAI notice hub (<code>acrossai_notices<\/code> filter shipped by <code>acrossai-co\/main-menu<\/code> 0.0.30). Instead of a raw wp-admin banner on every screen, the notice now appears on the new AcrossAI \u2192 Notices submenu (with a count bubble on the menu label) and as a single top-of-page summary banner (&quot;AcrossAI has N notifications for your attention \u2014 View notices \u2192&quot;) whose dismissal persists per user until the notice set changes. The fail-open semantics and message copy are unchanged. No breaking changes; existing abilities unaffected. Safe upgrade from 0.0.19.<\/p>","0.0.19":"<p>Adds a blue promotional callout on the ability edit form (MCP Exposure section) that advertises the sibling AcrossAI MCP Manager plugin when it is not installed \/ active. The callout links to the AcrossAI Add-ons page for install and to acrossai.co\/mcp-manager\/ for more info. Fully suppressed when the AcrossAI MCP Manager plugin is active. Also bumps the <code>acrossai-co\/main-menu<\/code> composer dependency from 0.0.27 to 0.0.29 \u2014 0.0.28 refreshes the Add-ons page baseline catalogue (AcrossAI Abilities Manager + AcrossAI MCP Manager + AI Connectors) with shared brand icon, <code>contain<\/code>-fitted icon boxes, fixed 3-column grid layout, and a new optional <code>learn_more_url<\/code> field; 0.0.29 reworks the card action states so active add-ons render a non-clickable &quot;\u25cf Running&quot; pill (deactivation stays in Plugins \u2192 Installed Plugins) and installed non-wp.org add-ons now show an in-page Activate button instead of always linking out. No breaking changes; existing abilities unaffected. Safe upgrade from 0.0.18.<\/p>","0.0.18":"<p>New third-party integration framework (Feature 060) with Advanced Custom Fields as the first concrete integration \u2014 flip one toggle on the new &quot;Acf&quot; tab of the Ability Library page to enable ACF&#039;s AI abilities without editing code. Also new: extensibility surface so other AcrossAI plugins can add their own cards to an integration&#039;s tab, filterable capability check for the toggle (via <code>acrossai_integration_toggle_capability<\/code>), and audit action (<code>acrossai_integration_toggle_denied<\/code>). Fixes a sparse-storage bug that could silently strip the integration ON state. Bumps the <code>acrossai-co\/main-menu<\/code> composer dependency from 0.0.23 to 0.0.27 to land two WordPress.org plugin directory guideline #8 fixes: the Consultations submenu now uses an external-link CTA instead of an embedded Calendly iframe, and the Add-ons page install action is now WordPress.org-only (non-wp.org cards render as external &quot;Get add-on \u2197&quot; links opening the vendor&#039;s site in a new tab). No breaking changes; existing abilities unaffected. Safe upgrade from 0.0.17.<\/p>","0.0.17":"<p>BREAKING \u2014 every ability slug has been renamed. Namespace shortens from <code>acrossai-abilities-manager\/<\/code> to <code>acrossai\/<\/code>; suffixes flip to verb-first form (e.g. <code>site-title-get<\/code> \u2192 <code>get-site-title<\/code>, <code>theme-activate<\/code> \u2192 <code>activate-theme<\/code>). External callers (custom code, saved MCP client configs, ACL entries created outside the plugin&#039;s UI, scripts calling <code>\/wp-json\/wp-abilities\/v1\/abilities\/acrossai-abilities-manager\/\/run<\/code>) must update their slug references to <code>\/wp-json\/wp-abilities\/v1\/abilities\/acrossai\/\/run<\/code>. No backwards-compatibility aliases; no automatic data migration \u2014 clear pre-existing overrides + ACL rules keyed on old slugs from the admin UI and re-add them under the new names. Also new: 7 Recovery Mode abilities (detect recovery, list paused plugins\/themes, unpause, exit URL, fatal-error log filter) and <code>core\/reinstall-wp-core<\/code>. 162 PHP class files renamed to match slugs (internal-only; PSR-4 autoload picks up automatically). PHP 8.1+ \/ WP 6.9+ floor unchanged.<\/p>","0.0.15":"<p>UI-only release. Replaces the Custom Abilities Bulk Actions dropdown (Publish \/ Unpublish \/ Delete) with Site Access, MCP Exposure, User Access, and Overrides operations that match the per-row edit drawer. Row-level checkbox now works on every ability regardless of Source. Reuses existing REST endpoints; no new database tables, no new endpoints, no PHP changes, no dependency changes, no permission changes. Also fixes a bug that stored composer User Access rule keys with the ability slug&#039;s <code>\/<\/code> character stripped when applied via the (new) bulk path. Safe upgrade.<\/p>","0.0.14":"<p>wp.org assets only. Refreshes the banner artwork and renames both banner files from <code>banner{width}x{height}.png<\/code> to the WP.org-canonical <code>banner-{width}x{height}.png<\/code> (the 0.0.13 filenames were not being auto-detected by the plugin directory). No plugin code touched; no REST, DB, or capability changes. Safe upgrade.<\/p>","0.0.13":"<p>Docs + wp.org assets only. Adds <code>specs\/054-ability-gap-audit\/<\/code> (a reference audit of abilities that external AI-tool inventories expect but the plugin does not yet expose) and commits the previously-untracked <code>.wordpress-org<\/code> banner (1544\u00d7500 + 772\u00d7250) and a sixth screenshot covering the Settings page. No functional changes; no REST, DB, or capability changes; no code touched under <code>includes\/<\/code> or <code>src\/<\/code>. Safe upgrade.\nAdds 31 new abilities across 10 domains (187 \u2192 218). Two new categories join the Ability Library: Admin Menu (5 abilities) and Content Search (11 abilities). Introduces two option-backed data stores: a lifecycle event log for plugin\/theme activate\/deactivate\/update timestamps, and an internal-link suggestion queue capped at 500 entries. Zero new REST endpoints, zero new capability requirements beyond the operation-specific caps already enforced by WP core (moderate_comments, upload_files, edit_others_posts). Zero external HTTP; zero new database tables. No breaking changes to existing abilities. Safe upgrade.<\/p>","0.0.12":"<p>Adds a third ability to the Core tab \u2014 <code>wp-core-rollback<\/code> \u2014 that rolls back WordPress core to an earlier version via WP core&#039;s <code>Core_Upgrader::upgrade()<\/code>, the same class the dashboard uses for forward updates. Requires both <code>manage_options<\/code> and <code>update_core<\/code>; honours <code>DISALLOW_FILE_MODS<\/code>; refuses when the target version isn&#039;t strictly older than the currently-installed version. Introduces the plugin&#039;s first outbound HTTP request (to <code>api.wordpress.org\/core\/version-check\/1.7\/<\/code>), rate-bounded to at most one request per day per locale per site via a site-transient cache. No breaking changes; no database, REST, or capability changes to existing abilities. Safe upgrade.<\/p>","0.0.11":"<p>Adds two WordPress-core-scoped abilities under a new &quot;Core&quot; tab in the Ability Library \u2014 <code>wp-core-update-check<\/code> (report availability) and <code>wp-core-update<\/code> (apply via <code>Core_Upgrader<\/code>). The update ability requires both <code>manage_options<\/code> and <code>update_core<\/code>; honours <code>DISALLOW_FILE_MODS<\/code>; multisite-guarded. Also changes backup filenames from <code>backup-{type}-{slug}-{random}.zip<\/code> to <code>{slug}-{unix-timestamp}-{ms}.zip<\/code> \u2014 human-readable and time-sortable, but predictable (directory listing remains disabled on the backups dir). Existing backups continue to work; the filename change only affects new backups. No breaking changes; no database, REST, or capability changes to existing abilities. Safe upgrade.<\/p>","0.0.10":"<p>Bugfix release. <code>Create_Zip_Backup<\/code> with <code>include_hidden=false<\/code> was silently descending into hidden directories and archiving their contents in 0.0.9 (only the top-level <code>.git\/<\/code> etc. entry was skipped, not the files beneath it). Fixed to check every segment of each entry&#039;s relative path. Regenerate any <code>include_hidden=false<\/code> archives created on 0.0.9 if their source tree contained hidden directories. No breaking changes; no database, REST, or capability changes. Safe upgrade.<\/p>","0.0.9":"<p>Adds eight new abilities: six under FileManager for zip-based backup \/ restore workflows (<code>zip-create<\/code>, <code>zip-upload<\/code>, <code>zip-extract<\/code>, <code>zip-download<\/code>, <code>zip-list<\/code>, <code>zip-delete<\/code>) plus <code>plugin-update<\/code> and <code>theme-update<\/code> that finally let AI clients apply pending WordPress core updates through the Abilities API. All new abilities enforce <code>manage_options<\/code>; mutating abilities additionally honour <code>DISALLOW_FILE_MODS<\/code>. Zip extraction rejects zip-slip archives (any entry containing <code>..<\/code>, an absolute path, a backslash, or a null byte). Zip uploads are validated for the <code>PK<\/code> magic signature before finalization. A new <code>wp-content\/uploads\/acrossai-backups\/<\/code> directory is created on first use, hardened with an <code>.htaccess<\/code> that blocks PHP execution but permits <code>.zip<\/code> downloads (required so the URLs returned by <code>zip-create<\/code> remain reachable). No breaking changes to existing abilities, REST endpoints, capability requirements, or database schema. Safe upgrade.<\/p>","0.0.8":"<p>IMPORTANT: this release <strong>removes the Freemius integration entirely<\/strong> \u2014 the plugin no longer sends any data to Freemius and no longer offers a Connect \/ Login \/ Buy affordance on the Add-ons page. If you previously connected a Freemius account tied to this plugin, that connection is now inert; stale <code>fs_*<\/code> or <code>freemius_*<\/code> rows in <code>wp_options<\/code> are safe to delete manually. Also: the Add-ons page now shows only free WordPress.org companion plugins (and no longer lists this plugin itself); the Library page compacts its title + bulk-action buttons onto one horizontal row; and <code>acrossai-co\/main-menu<\/code> bumps <code>0.0.14 \u2192 0.0.23<\/code>. No breaking changes to REST endpoints, capability requirements, or database schema. Safe upgrade.<\/p>","0.0.7":"<p>Adds Library page bulk Enable All \/ Disable All buttons scoped to the active tab, URL-synced tabs (<code>?tab=<\/code>) for deep-linkable views, and a readonly ability preview on disabled cards. No breaking changes; no database schema changes; no new REST endpoints; no new capability requirements. <code>mode<\/code> and per-slug selections are preserved through disable \/ enable cycles. Safe upgrade.<\/p>","0.0.6":"<p>IMPORTANT: this release absorbs the companion <code>acrossai-core-abilities<\/code> plugin \u2014 deactivate and uninstall that plugin after upgrading to avoid duplicate ability registrations. BREAKING for downstream integrators: 17 category slugs rebranded <code>acrossai-core-abilities-<\/code> \u2192 <code>acrossai-abilities-manager-<\/code> and 176 ability slugs <code>acrossai-core-abilities\/<\/code> \u2192 <code>acrossai\/<\/code>; update any MCP\/REST\/WP-CLI callers that referenced the legacy slugs. Ability payload shapes and permission callbacks unchanged. Also promotes Themes \/ Blocks \/ Plugins \/ Users \/ Database \/ Cron \/ Cache \/ File Manager to their own Library page tabs, bumps <code>acrossai-co\/main-menu<\/code> to <code>0.0.14<\/code>, and rotates Freemius credentials.<\/p>","0.0.5":"<p>Dependency-only release: refreshes the bundled <code>acrossai-co\/main-menu<\/code> package to <code>0.0.11<\/code>. No functional changes to this plugin. Safe upgrade.<\/p>","0.0.4":"<p>IMPORTANT for add-on developers: Library display fields <code>sub_group<\/code>, <code>sub_group_label<\/code>, and <code>tab_group<\/code> must now be nested under <code>$args[&amp;#039;meta&amp;#039;][&amp;#039;acrossai&amp;#039;]<\/code> when calling <code>wp_register_ability()<\/code>. The old top-level shape is silently dropped \u2014 cards will render without their sub-group heading or custom tab placement until you migrate. End users and site administrators are not affected; no data migration, no DB or REST changes. Also swaps the WordPress.org plugin icon to an SVG and drops the directory banners.<\/p>","0.0.3":"<p>Fixes the 0.0.2 activation error on WordPress.org installs \u2014 the release ZIP now includes the Composer autoloader. No functional or user-facing changes vs 0.0.2. If you hit the &quot;Composer autoloader is missing&quot; error on 0.0.2, delete the plugin folder and reinstall 0.0.3.<\/p>","0.0.2":"<p>IMPORTANT: (1) This release does NOT migrate Access Control rules from previous versions. If you had configured any Access Control rules on abilities, audit and reconfigure them after upgrading. Pre-existing rules remain in the database (in the orphaned <code>{prefix}wpb_access_control<\/code> table) but are no longer applied. (2) Ability execution logging has been removed \u2014 the Logs admin page is gone; ability-execution denials are no longer recorded by this plugin. Install a compatible logging plugin if you need this signal.<\/p>","0.0.1":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon.svg":{"filename":"icon.svg","revision":3595583,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3614045,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3614045,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.0.1","0.0.10","0.0.11","0.0.12","0.0.13","0.0.14","0.0.15","0.0.17","0.0.18","0.0.19","0.0.2","0.0.20","0.0.21","0.0.22","0.0.23","0.0.24","0.0.25","0.0.26","0.0.27","0.0.29","0.0.3","0.0.30","0.0.31","0.0.32","0.0.33","0.0.34","0.0.35","0.0.36","0.0.37","0.0.38","0.0.39","0.0.4","0.0.40","0.0.5","0.0.6","0.0.7","0.0.8","0.0.9"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3614043,"resolution":"1","location":"assets","locale":"","width":3268,"height":1874},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3614043,"resolution":"2","location":"assets","locale":"","width":3268,"height":1874},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3614043,"resolution":"3","location":"assets","locale":"","width":3268,"height":1874},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3614043,"resolution":"4","location":"assets","locale":"","width":3268,"height":1874},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3614043,"resolution":"5","location":"assets","locale":"","width":3268,"height":1874},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3614043,"resolution":"6","location":"assets","locale":"","width":3268,"height":1874}},"screenshots":{"1":"The Abilities Manager admin page \u2014 searchable, sortable ability table.","2":"The edit drawer \u2014 tri-state override controls for each ability field.","3":"Bulk actions toolbar for allow\/disallow\/reset across multiple abilities.","4":"The Ability Library page \u2014 enable\/disable add-on ability groups.","5":"The Add-ons page \u2014 browse free companion plugins.","6":"Settings \u2014 Display (abilities-per-page) and Upload Media Abilities (allowed-MIME list + Add file types)."}},"plugin_section":[],"plugin_tags":[251511,148285,216196,229563,242115],"plugin_category":[],"plugin_contributors":[140910],"plugin_business_model":[],"class_list":["post-311005","plugin","type-plugin","status-publish","hentry","plugin_tags-abilities","plugin_tags-ai-assistant","plugin_tags-chatgpt","plugin_tags-claude","plugin_tags-mcp","plugin_contributors-raftaar1191","plugin_committers-raftaar1191"],"banners":{"banner":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/banner-772x250.png?rev=3614045","banner_2x":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/banner-1544x500.png?rev=3614045","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/icon.svg?rev=3595583","icon":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/icon.svg?rev=3595583","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/screenshot-1.png?rev=3614043","caption":"The Abilities Manager admin page \u2014 searchable, sortable ability table."},{"src":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/screenshot-2.png?rev=3614043","caption":"The edit drawer \u2014 tri-state override controls for each ability field."},{"src":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/screenshot-3.png?rev=3614043","caption":"Bulk actions toolbar for allow\/disallow\/reset across multiple abilities."},{"src":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/screenshot-4.png?rev=3614043","caption":"The Ability Library page \u2014 enable\/disable add-on ability groups."},{"src":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/screenshot-5.png?rev=3614043","caption":"The Add-ons page \u2014 browse free companion plugins."},{"src":"https:\/\/ps.w.org\/acrossai-abilities-manager\/assets\/screenshot-6.png?rev=3614043","caption":"Settings \u2014 Display (abilities-per-page) and Upload Media Abilities (allowed-MIME list + Add file types)."}],"raw_content":"<!--section=description-->\n<p><strong>AcrossAI Abilities Manager gives your WordPress site 357 ready-made abilities, and gives you control over every one of them.<\/strong><\/p>\n\n<p>An <em>ability<\/em> is a self-describing operation that WordPress 6.9's Abilities API lets a plugin register \u2014 something an AI assistant, a REST client or another plugin can discover and call. WordPress ships the API; almost nothing ships abilities. This plugin does: <strong>357 on any site, with no configuration<\/strong>, rising to <strong>over 800<\/strong> as it detects the plugins you already run.<\/p>\n\n<p>It is free, GPL, and works on its own. Pair it with an MCP server and your site becomes something Claude, ChatGPT, Cursor or any MCP-capable assistant can operate.<\/p>\n\n<h4>What Your Site Can Do, Out of the Box<\/h4>\n\n<ul>\n<li><strong>Content<\/strong> \u2014 posts, pages and any custom post type with meta and revisions; comments; media, categories and tags; and semantic search that proposes, reviews and applies internal links.<\/li>\n<li><strong>Blocks<\/strong> \u2014 edit a page's block tree without rewriting the page, build from patterns, generate sections and landing pages, and audit copy and design.<\/li>\n<li><strong>Appearance<\/strong> \u2014 theme.json and global styles, site-editor templates and parts, menus, widget areas, fonts, and site title, logo and icon.<\/li>\n<li><strong>Users<\/strong> \u2014 create and edit users, reset passwords, create roles, and grant or revoke individual capabilities.<\/li>\n<li><strong>Configuration<\/strong> \u2014 any option including values nested inside serialised arrays, permalinks, and which admin screen a setting lives on.<\/li>\n<li><strong>Database<\/strong> \u2014 schema and table sizes, index health, bloated autoloaded options, EXPLAIN on a slow query, table optimisation, and serialisation-safe search-and-replace.<\/li>\n<li><strong>Files<\/strong> \u2014 browse, read, write and delete inside an administrator-defined allowlist; zip backups; wp-config constants; the debug log.<\/li>\n<li><strong>Cron<\/strong> \u2014 every scheduled task, the overdue ones, running one on demand, and whether WP-Cron is firing at all.<\/li>\n<li><strong>Updates<\/strong> \u2014 plugins, themes and core; rollback; and verification against official checksums.<\/li>\n<li><strong>Diagnostics<\/strong> \u2014 Site Health, maintenance mode, recent fatal errors, and un-pausing what WordPress auto-disabled.<\/li>\n<li><strong>Cache<\/strong> \u2014 transients, object cache and rewrite rules.<\/li>\n<\/ul>\n\n<h4>A Dozen Tools, Not 357<\/h4>\n\n<p>An AI client is handed its tool list once, at connect time, and pays for it out of the model's context window on every conversation. Exposing 357 separate tools would flood it \u2014 most assistants degrade past a few dozen.<\/p>\n\n<p>So your MCP server groups them into <strong>toolsets<\/strong>, and a toolset is a <strong>single tool<\/strong> answering three actions: <code>discover<\/code> to list what it holds, <code>info<\/code> to read one ability's parameters, and <code>execute<\/code> to run it \u2014 the same three everywhere. AcrossAI MCP Manager provides that layer; this plugin provides the abilities.<\/p>\n\n<h4>Plugins You Already Run Get Their Own Toolset<\/h4>\n\n<p>Nineteen integrations ship with the plugin, each with its own page under https:\/\/acrossai.co\/integrations\/ \u2014 and each registers <strong>only when that plugin is active<\/strong>, so nothing appears for software you do not have, and each becomes one more dispatcher tool rather than a pile of loose ones.<\/p>\n\n<ul>\n<li><strong><a href=\"https:\/\/acrossai.co\/integrations\/elementor\/\">Elementor<\/a><\/strong> (89 abilities) \u2014 pages, templates, kits, global widgets, form submissions and its cache. A Pro subset needs Elementor Pro.<\/li>\n<li><strong><a href=\"https:\/\/acrossai.co\/integrations\/yoast-seo\/\">Yoast SEO<\/a><\/strong> (64) \u2014 titles and meta, indexing, breadcrumbs, the knowledge graph, social defaults and schema.<\/li>\n<li><strong><a href=\"https:\/\/acrossai.co\/integrations\/rank-math\/\">Rank Math<\/a><\/strong> (61) \u2014 on-page and site-wide SEO, redirections, schema, analytics and settings.<\/li>\n<li><strong><a href=\"https:\/\/acrossai.co\/integrations\/litespeed-cache\/\">LiteSpeed Cache<\/a><\/strong> (61) \u2014 purge by target, URL, post or taxonomy, and tune TTLs, exclusions and vary rules.<\/li>\n<li><strong><a href=\"https:\/\/acrossai.co\/integrations\/woocommerce\/\">WooCommerce<\/a><\/strong> (34) \u2014 catalogue, prices, stock, orders, customers and store health.<\/li>\n<li><strong><a href=\"https:\/\/acrossai.co\/integrations\/contact-form-7\/\">Contact Form 7<\/a><\/strong> (25) \u2014 forms, fields, both mail templates, tag validation and messages.<\/li>\n<li><strong><a href=\"https:\/\/acrossai.co\/integrations\/wpcode\/\">WPCode<\/a><\/strong> (24) \u2014 snippets of every type, where each is inserted, and its conditional logic.<\/li>\n<li><strong><a href=\"https:\/\/acrossai.co\/integrations\/cookieyes\/\">CookieYes<\/a><\/strong> (22) \u2014 declared cookies, consent categories, the banner, its languages and Google Consent Mode.<\/li>\n<li><strong><a href=\"https:\/\/acrossai.co\/integrations\/the-events-calendar\/\">The Events Calendar<\/a><\/strong> (18) \u2014 find, create, reschedule and trash events; manage venues and organizers.<\/li>\n<li><strong><a href=\"https:\/\/acrossai.co\/integrations\/event-tickets\/\">Event Tickets<\/a><\/strong> (16) \u2014 tickets, real capacity including shared pools, check-ins, orders and sales.<\/li>\n<li><strong><a href=\"https:\/\/acrossai.co\/integrations\/advanced-custom-fields\/\">Advanced Custom Fields<\/a><\/strong> (16) \u2014 field groups, and post types and taxonomies registered through ACF.<\/li>\n<li><strong>Site Kit by Google<\/strong> (14) \u2014 Search Console analytics, Analytics 4 reports, PageSpeed Insights and AdSense, plus what is actually connected.<\/li>\n<li><strong><a href=\"https:\/\/acrossai.co\/integrations\/loco-translate\/\">Loco Translate<\/a><\/strong> (14) \u2014 what can be translated, what is untranslated, and writing translations.<\/li>\n<li><strong><a href=\"https:\/\/acrossai.co\/integrations\/all-in-one-wp-migration\/\">All-in-One WP Migration<\/a><\/strong> (9) \u2014 what archives exist, how recent they are, and exporting or removing them.<\/li>\n<li><strong><a href=\"https:\/\/acrossai.co\/integrations\/updraftplus\/\">UpdraftPlus<\/a><\/strong> (8) \u2014 when a backup last ran, whether it worked, and what each set contains.<\/li>\n<li><strong><a href=\"https:\/\/acrossai.co\/integrations\/wp-mail-smtp\/\">WP Mail SMTP<\/a><\/strong> (4) \u2014 how the site sends mail, whether it can, and a real test send.<\/li>\n<li><strong><a href=\"https:\/\/acrossai.co\/integrations\/classic-editor\/\">Classic Editor<\/a><\/strong> (4) \u2014 the effective editor per post type, which layer decided it, and whether users may choose.<\/li>\n<li><strong>Akismet<\/strong> \u2014 spam figures and checking a comment. These abilities come from Akismet itself.<\/li>\n<li><strong>WPForms<\/strong> \u2014 read forms and statistics, create forms, change settings. Writes sit behind an admin switch, off by default.<\/li>\n<\/ul>\n\n<p>The two backup integrations are deliberate exceptions: they register whether or not their plugin is installed, so <em>\"is this site backed up?\"<\/em> can be answered <strong>\"no, there is no backup plugin here\"<\/strong> rather than having no tool to answer it.<\/p>\n\n<p>Third-party developers can register a toolset of their own through a filter, without touching this plugin.<\/p>\n\n<h4>More Integrations With AcrossAI Pro<\/h4>\n\n<p>The paid <a href=\"https:\/\/acrossai.co\/pricing\/\">AcrossAI Pro<\/a> add-on contributes <strong>276 further abilities<\/strong> through the same toolset mechanism, again only when the host plugin is active:<\/p>\n\n<ul>\n<li><strong>MailerPress<\/strong> (89 abilities) <em>(Pro)<\/em> \u2014 campaigns, contacts, lists, tags, templates, workflows and settings.<\/li>\n<li><strong>LearnDash<\/strong> (74) <em>(Pro)<\/em> \u2014 courses, lessons, quizzes, enrolment, progress, groups and reporting, plus the Certificates, Notifications and WooCommerce add-ons.<\/li>\n<li><strong>BuddyBoss<\/strong> (60) <em>(Pro)<\/em> \u2014 members, groups, activity, forums, messages, media, connections and moderation.<\/li>\n<li><strong>MailerPress Pro<\/strong> (28) <em>(Pro)<\/em> \u2014 segments, custom fields, webhooks, embed keys and email templates.<\/li>\n<li><strong>GeoDirectory<\/strong> (25) <em>(Pro)<\/em> \u2014 listings, locations, fields, pricing packages and directory pages.<\/li>\n<\/ul>\n\n<p>Everything else on this page is free.<\/p>\n\n<h4>Nothing Is Wide Open<\/h4>\n\n<p>Every ability runs WordPress's own capability check for the calling user, so reaching one through this plugin grants nobody anything they could not already do. On top of that:<\/p>\n\n<ul>\n<li>Roughly <strong>half the catalogue is annotated read-only<\/strong> and only about <strong>13% is flagged destructive<\/strong>, so a look-but-don't-touch surface is a matter of filtering, not trust.<\/li>\n<li>Higher-risk operations require an explicit <strong>confirmation flag<\/strong> before they run.<\/li>\n<li><strong>Search-and-replace is a dry run<\/strong> unless you say otherwise, and skips post GUIDs unless asked.<\/li>\n<li>File access is confined to an <strong>administrator-defined path allowlist<\/strong> \u2014 an empty write-allowlist means \"deny all writes\" \u2014 with a dangerous-extension blocklist and a maximum write size on top.<\/li>\n<li><strong>Secrets are redacted<\/strong> \u2014 database credentials and authentication salts are stripped out of file and debug-log reads.<\/li>\n<li>Database abilities never accept a raw table name; they work from a fixed allowlist of core tables.<\/li>\n<li>Any ability can be <strong>disallowed site-wide<\/strong>, and one you turn off is unregistered outright rather than merely hidden.<\/li>\n<\/ul>\n\n<h4>Full Control Over Every Ability<\/h4>\n\n<ul>\n<li><strong>Browse all abilities<\/strong> \u2014 a searchable, sortable, paginated table listing every registered ability with slug, provider, source and current status.<\/li>\n<li><strong>Toggle allow\/disallow<\/strong> \u2014 enable or disable any ability site-wide with a single click, saved instantly without a page reload.<\/li>\n<li><strong>Edit ability metadata<\/strong> \u2014 override <code>readonly<\/code>, <code>destructive<\/code>, <code>idempotent<\/code>, <code>show_in_rest<\/code>, <code>show_in_mcp<\/code>, <code>mcp_type<\/code> and <code>mcp_servers<\/code> per ability with a tri-state Yes \/ No \/ Inherit control, and reset any of it to registry defaults in one click.<\/li>\n<li><strong>Bulk actions<\/strong> \u2014 allow, disallow or reset up to 50 abilities at once.<\/li>\n<li><strong>Ability Library<\/strong> \u2014 enable or disable add-on ability groups from a dedicated page, with All\/Specific mode per group.<\/li>\n<li><strong>Add-ons page<\/strong> \u2014 browse companion plugins from wp-admin; WordPress.org-hosted ones install and activate in place.<\/li>\n<\/ul>\n\n<p>Overrides live in their own table. <strong>The ability registry is never modified<\/strong> \u2014 only fields that differ from registry defaults are stored, so removing the plugin leaves it exactly as found.<\/p>\n\n<h4>Reproduce a Plugin Conflict Without Breaking the Site<\/h4>\n\n<p><strong>Debugging \u2192 Conflict Testing<\/strong> toggles any plugin's <em>effective<\/em> active state <strong>without ever writing to <code>wp_options.active_plugins<\/code><\/strong> \u2014 reproduce a conflict for one browser session, then restore the site exactly by clearing a single JSON file.<\/p>\n\n<p>Seven abilities expose the same thing to a REST client or an AI assistant, so an assistant can bisect a conflict for you. Every activation is guarded by a WordPress-core-style sandbox probe, so a fatal-erroring plugin cannot leave the site where every page load dies \u2014 the override is refused instead.<\/p>\n\n<h4>Works With or Without an MCP Server<\/h4>\n\n<p>Abilities are the capability layer, not the connection. Every one is registered through WordPress 6.9's own Abilities API with <code>show_in_rest<\/code>, so it is reachable over the REST API and callable by any plugin the moment you activate this one. Nothing here is proprietary, and nothing is bound to a particular transport.<\/p>\n\n<p>That means anything which reads the Abilities API can expose these abilities \u2014 there is no lock-in:<\/p>\n\n<ul>\n<li><strong><a href=\"https:\/\/wordpress.org\/plugins\/acrossai-mcp-manager\/\">AcrossAI MCP Manager<\/a><\/strong> \u2014 the free MCP server this plugin is built alongside. Turns the toolsets into MCP tools with per-server curation and access control.<\/li>\n<li><strong>MCP Adapter<\/strong> \u2014 the WordPress MCP Adapter exposes registered abilities as MCP tools. When it is active, this plugin also lists its servers in the ability edit panel.<\/li>\n<li><strong>Any other consumer<\/strong> \u2014 another MCP server, a REST client, or a plugin calling the Abilities API directly. Abilities registered here are ordinary WordPress abilities, not a private format.<\/li>\n<\/ul>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li>WordPress <strong>6.9 or later<\/strong> \u2014 the Abilities API arrived in 6.9, and this plugin registers nothing without it<\/li>\n<li>PHP <strong>8.1 or later<\/strong><\/li>\n<li>No other plugin is required<\/li>\n<\/ul>\n\n<h4>Where To Read More<\/h4>\n\n<ul>\n<li><strong>The plugin<\/strong> \u2014 https:\/\/acrossai.co\/abilities-manager\/<\/li>\n<li><strong>Every ability, searchable<\/strong> \u2014 https:\/\/acrossai.co\/abilities\/ \u2014 one page per ability, rather than a list in a readme.<\/li>\n<li><strong>Integrations<\/strong> \u2014 https:\/\/acrossai.co\/integrations\/<\/li>\n<li><strong>Use cases<\/strong> \u2014 https:\/\/acrossai.co\/use-cases\/ \u2014 real jobs done through an AI assistant, start to finish.<\/li>\n<li><strong>Full changelog<\/strong> \u2014 https:\/\/acrossai.co\/changelog\/acrossai-abilities-manager\/ \u2014 including releases trimmed from the Changelog here for length.<\/li>\n<\/ul>\n\n<h3>External Services<\/h3>\n\n<p>This plugin's own code makes no external HTTP requests. Each connection below is triggered by a specific admin-only action, and is disclosed per the WordPress.org plugin directory guidelines. In every case the plugin sends no site content, user data or ability data.<\/p>\n\n<p><strong>1. Calendly (<code>calendly.com<\/code>)<\/strong> \u2014 a third-party scheduling service.\n<em>When:<\/em> never on render. The Consultations page loads no Calendly script, iframe, cookie or asset; Calendly is reached only if an administrator clicks \"Book a Consultation\", opening the booking page in a new tab.\n<em>Data:<\/em> only the browser's standard metadata (IP, User-Agent, referrer) on that click. Anything typed into Calendly's own form is processed by Calendly; this plugin never intercepts or stores it.\n<em>Note:<\/em> that page also references Google Fonts (<code>fonts.googleapis.com<\/code>), its only external asset.\n<em>Terms:<\/em> https:\/\/calendly.com\/pages\/terms \u00b7 <em>Privacy:<\/em> https:\/\/calendly.com\/pages\/privacy<\/p>\n\n<p><strong>2. WordPress.org plugin directory (<code>api.wordpress.org<\/code>, <code>downloads.wordpress.org<\/code>)<\/strong> \u2014 installs free companion plugins from the Add-ons page.\n<em>When:<\/em> only when an administrator with <code>install_plugins<\/code> clicks Install on a card sourced from WordPress.org, always through core's own <code>plugins_api()<\/code> and <code>Plugin_Upgrader<\/code>. Add-ons hosted elsewhere render as plain links; nothing is requested from those vendors.\n<em>Data:<\/em> core's standard plugin-API payload \u2014 site URL, WordPress version, PHP version, locale.\n<em>Terms:<\/em> https:\/\/wordpress.org\/about\/terms\/ \u00b7 <em>Privacy:<\/em> https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<p><strong>3. WordPress.org core version-check (<code>api.wordpress.org\/core\/version-check\/1.7\/<\/code>)<\/strong>\n<em>When:<\/em> only when an administrator invokes the <code>core\/rollback-wp-core<\/code> ability and the local cache has expired \u2014 at most once per day, per locale, per site.\n<em>Data:<\/em> core's standard version-check payload. Same terms and privacy policy as service 2.<\/p>\n\n<p><strong>4. YouTube walkthrough videos (<code>youtube-nocookie.com<\/code>, <code>youtube.com<\/code>)<\/strong> \u2014 short recordings embedded in the setup wizard, via YouTube's privacy-enhanced host.\n<em>When:<\/em> only on the wizard's own screens, gated on the <code>quick-connect<\/code> parameter and loaded nowhere else in wp-admin. Two screens autoplay, so YouTube is contacted on render; the rest show a local placeholder and embed only when play is pressed.\n<em>Data:<\/em> the browser's standard metadata plus a <code>Referer<\/code> limited to the site's origin, because a <code>strict-origin-when-cross-origin<\/code> policy keeps the wp-admin path private. No tracking cookies unless playback begins.\n<em>Avoiding it:<\/em> every embed is paired with a plain link, and the wizard is optional \u2014 every screen offers Exit setup.\n<em>Terms:<\/em> https:\/\/www.youtube.com\/t\/terms \u00b7 <em>Privacy:<\/em> https:\/\/policies.google.com\/privacy<\/p>\n\n<p><strong>5. GitHub (<code>github.com<\/code>)<\/strong> \u2014 the wizard links to MCP Adapter's latest release, which is distributed there rather than on WordPress.org.\n<em>When:<\/em> never on render; only if an administrator clicks the link. The plugin makes no request to GitHub and downloads nothing.\n<em>Data:<\/em> standard browser metadata only, as with any external link.\n<em>Terms:<\/em> https:\/\/docs.github.com\/site-policy\/github-terms\/github-terms-of-service \u00b7 <em>Privacy:<\/em> https:\/\/docs.github.com\/site-policy\/privacy-policies\/github-privacy-statement<\/p>\n\n<h3>Privacy Policy<\/h3>\n\n<p>This plugin does not itself collect, store, or transmit any user data to any third party.<\/p>\n\n<p>Several admin-only actions can cause external services to receive data \u2014 all are described in the External Services section above and are triggered only by an authenticated administrator:<\/p>\n\n<ul>\n<li>The AcrossAI \u2192 Consultations admin page displays a static call-to-action button. Merely loading the Consultations page sends no data to Calendly \u2014 no Calendly script, iframe, or asset is loaded inside wp-admin. If the administrator clicks the CTA button, their browser opens <code>calendly.com\/acrossai\/using-ai-in-wordpress<\/code> in a new tab, at which point standard browser metadata (IP, User-Agent, referrer) is sent to Calendly and Calendly's own privacy policy applies. If they then book a consultation on Calendly's site, information they enter into Calendly's form (name, email, meeting details) is transmitted to Calendly.<\/li>\n<li>Installing a WordPress.org-hosted add-on from the AcrossAI \u2192 Add-ons page contacts the WordPress.org plugin directory via WordPress core's own <code>plugins_api()<\/code> and <code>Plugin_Upgrader<\/code> (<code>api.wordpress.org<\/code> + <code>downloads.wordpress.org<\/code>). Add-ons distributed elsewhere (e.g. GitHub, Freemius) are rendered as external \"Get add-on \u2197\" links that open the vendor's site in a new browser tab \u2014 the plugin itself does not download or install those add-ons, so no request is sent to the vendor's servers from wp-admin. If the administrator clicks the external link, their browser navigates directly to the vendor and standard browser metadata (IP, User-Agent, referrer) is sent to the vendor as with any external hyperlink.<\/li>\n<li>Invoking the <code>core\/rollback-wp-core<\/code> ability contacts the WordPress.org core version-check API (a WordPress-core-hosted service) via the standard WordPress update API.<\/li>\n<\/ul>\n\n<p>No data is sent to any external server without an explicit administrator action.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>acrossai-abilities-manager<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> menu in WordPress.<\/li>\n<li>Navigate to <strong>AcrossAI Abilities Manager<\/strong> in the WordPress admin menu.<\/li>\n<\/ol>\n\n<p><strong>Quick Connect setup wizard:<\/strong><\/p>\n\n<p>On activation the plugin opens a short setup wizard once \u2014 how many abilities the site has, how to\nedit them, how to act on many at once, what they cover, and how to connect them to an AI assistant.\nIt does not open on sites already running AcrossAI MCP Manager, which provides its own wizard.<\/p>\n\n<p>The wizard is re-runnable at any time and is reachable from four places: <strong>AcrossAI \u2192 Quick\nConnect<\/strong> in the sidebar, the <strong>Quick Connect via AcrossAI<\/strong> entry in the admin toolbar, the\n<strong>Quick Connect via AcrossAI<\/strong> link on the Plugins screen, and a button under <strong>Setup<\/strong> on the\nAcrossAI \u2192 Settings \u2192 Abilities tab. Those entries are hidden when AcrossAI MCP Manager is active,\nto avoid two wizards competing for the same surfaces; the wizard itself stays reachable at\n    \/wp-admin\/admin.php?page=acrossai-abilities-manager&amp;quick-connect=1&amp;step=1.<\/p>\n\n<p><strong>Add-ons:<\/strong><\/p>\n\n<ol>\n<li>Go to <strong>AcrossAI \u2192 Add-ons<\/strong> to browse available companion plugins.<\/li>\n<li>All add-ons are free and hosted on WordPress.org; each card offers a one-click Install \/ Activate \/ Deactivate action via the standard WordPress plugin installer.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20this%20plugin%20free%3F\"><h3>Is this plugin free?<\/h3><\/dt>\n<dd><p>Yes, entirely, and under GPL. There is no paid tier of this plugin and no feature is held back.<\/p><\/dd>\n<dt id=\"what%20can%20an%20ai%20actually%20do%20once%20this%20is%20installed%3F\"><h3>What can an AI actually do once this is installed?<\/h3><\/dt>\n<dd><p>357 abilities on any site \u2014 content, blocks, appearance, users, configuration, database, files, cron, cache, updates and diagnostics \u2014 rising to over 800 as it detects plugins such as WooCommerce, Elementor, Rank Math, Yoast SEO, ACF and LiteSpeed Cache. Abilities are the capability layer; connecting an AI assistant to them needs a transport (see below).<\/p><\/dd>\n<dt id=\"why%20does%20my%20ai%20only%20see%20about%20a%20dozen%20tools%20when%20there%20are%20357%20abilities%3F\"><h3>Why does my AI only see about a dozen tools when there are 357 abilities?<\/h3><\/dt>\n<dd><p>That is deliberate, and it is what makes the catalogue usable. Your MCP server groups the abilities into toolsets, and each toolset is a single tool answering three actions \u2014 <code>discover<\/code> to list what it holds, <code>info<\/code> to read one ability's parameters, <code>execute<\/code> to run it. Exposing 357 separate tools would flood the model's context window, and most assistants degrade badly past a few dozen. Your AI reaches everything through those, drilling in only when it needs to.<\/p><\/dd>\n<dt id=\"does%20removing%20the%20plugin%20leave%20anything%20behind%3F\"><h3>Does removing the plugin leave anything behind?<\/h3><\/dt>\n<dd><p>The WordPress ability registry is never modified, so deactivating returns it exactly as it was. Overrides you set live in the plugin's own table; abilities registered by this plugin simply stop being registered.<\/p><\/dd>\n<dt id=\"do%20i%20need%20another%20plugin%20to%20use%20this%20with%20an%20ai%20assistant%3F\"><h3>Do I need another plugin to use this with an AI assistant?<\/h3><\/dt>\n<dd><p>For an AI client to reach these abilities over MCP, yes \u2014 you need an MCP server such as <a href=\"https:\/\/wordpress.org\/plugins\/acrossai-mcp-manager\/\">AcrossAI MCP Manager<\/a>, which is also free. This plugin works perfectly well without one: abilities are registered with <code>show_in_rest<\/code>, so they remain reachable over the WordPress REST API and callable by any plugin.<\/p><\/dd>\n<dt id=\"can%20an%20ai%20break%20my%20site%3F\"><h3>Can an AI break my site?<\/h3><\/dt>\n<dd><p>It can only do what you allow. Every ability runs WordPress's own capability check for the calling user, so nothing here grants extra privilege. Roughly half the catalogue is annotated read-only and only about 13% is flagged destructive; higher-risk operations require an explicit confirmation flag; search-and-replace defaults to a dry run; file access is confined to an administrator-defined path allowlist; and secrets such as database credentials and auth salts are stripped from file and log reads. Any ability you disallow is unregistered outright, not merely hidden.<\/p><\/dd>\n<dt id=\"does%20it%20need%20wordpress%206.9%3F\"><h3>Does it need WordPress 6.9?<\/h3><\/dt>\n<dd><p>Yes. The Abilities API arrived in WordPress 6.9, and this plugin registers nothing without it \u2014 the registration path is guarded, so an older site simply gets no abilities rather than an error.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20support%20multisite%3F\"><h3>Does this plugin support Multisite?<\/h3><\/dt>\n<dd><p>No. This plugin has not been tested on WordPress Multisite installations.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20modify%20the%20wordpress%20ability%20registry%3F\"><h3>Does this plugin modify the WordPress ability registry?<\/h3><\/dt>\n<dd><p>No. The plugin stores only overrides \u2014 fields that differ from the registry defaults. The ability registry itself (<code>wp_get_ability()<\/code>) is never modified.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20reset%20an%20override%3F\"><h3>What happens when I reset an override?<\/h3><\/dt>\n<dd><p>The override row is deleted from the database. The ability will inherit its values from the registry again.<\/p><\/dd>\n<dt id=\"what%20is%20the%20ability%20library%3F\"><h3>What is the Ability Library?<\/h3><\/dt>\n<dd><p>The Library page lets you enable or disable ability groups registered by add-on plugins. Each group shows an ON\/OFF master toggle and an All\/Specific mode selector. In Specific mode, individual ability slots can be toggled independently.<\/p><\/dd>\n<dt id=\"what%20is%20the%20mcp%20adapter%20integration%3F\"><h3>What is the MCP Adapter integration?<\/h3><\/dt>\n<dd><p>If the MCP Adapter plugin is active on your site, AcrossAI Abilities Manager will display the list of registered MCP servers in the ability edit panel. This is entirely optional \u2014 the plugin works without the MCP Adapter.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20make%20external%20http%20requests%3F\"><h3>Does this plugin make external HTTP requests?<\/h3><\/dt>\n<dd><p>The plugin's own code makes no external HTTP requests. Two admin-only surfaces trigger external connections on behalf of an authenticated administrator:<\/p>\n\n<ul>\n<li><strong>AcrossAI \u2192 Consultations<\/strong> submenu \u2014 renders a static call-to-action button that links to <code>https:\/\/calendly.com\/acrossai\/using-ai-in-wordpress<\/code> and opens in a new browser tab. The plugin does not load any Calendly script, iframe, or asset inside wp-admin. Calendly is only contacted if the administrator explicitly clicks the button \u2014 at which point their browser navigates directly to <code>calendly.com<\/code>, exactly as with any external hyperlink.<\/li>\n<li><strong>AcrossAI \u2192 Add-ons<\/strong> submenu \u2014 installs WordPress.org-hosted companion plugins in place through WordPress core's <code>plugins_api()<\/code> + <code>Plugin_Upgrader<\/code> (contacts <code>api.wordpress.org<\/code> + <code>downloads.wordpress.org<\/code>). Add-ons registered with any other source (e.g. GitHub, Freemius) render as external \"Get add-on \u2197\" links that open the vendor's site in a new browser tab \u2014 the plugin does not download or install those add-ons itself. Users install off-directory add-ons via WP admin's standard <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong> flow (or via the vendor's own installer once the paid plugin is activated).<\/li>\n<\/ul>\n\n<p>Full disclosure \u2014 including what data is transmitted, and links to each service's terms + privacy policy \u2014 is in the <strong>External Services<\/strong> section of this readme.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>Unreleased<\/h4>\n\n<p>(nothing yet)<\/p>\n\n<h4>0.0.40 - 2026-09-28<\/h4>\n\n<ul>\n<li><strong>Fixed: the plugin's Description was being truncated on WordPress.org.<\/strong> Every import reported \"The Description section is too long and was truncated. A maximum of 2,500 words is supported\" \u2014 a warning only the plugin's committers can see, so the listing was silently losing its tail for anyone reading it. The cause was not obvious: the Description itself was well inside the limit at around 1,800 words, but WordPress.org folds sections it does not recognise into the Description, and this readme carries two of them \u2014 External Services and Privacy Policy, both required disclosures totalling another 750. Together they crossed the limit. The Description is now tightened to 2,372 effective words with every point kept, leaving room for the next few releases, and neither disclosure was touched.<\/li>\n<li><strong>The WordPress.org listing title now says what the plugin does.<\/strong> It read \"AcrossAI Abilities Manager\", which tells a search engine nothing, while the sibling plugins carry a descriptive title. It is now \"AcrossAI Abilities Manager \u2013 WordPress Abilities for Claude, ChatGPT &amp; Any AI Agent\". The name shown inside wp-admin is unchanged. The tags move from <code>abilities, mcp, access control, site management, ai<\/code> to <code>abilities, ai assistant, chatgpt, claude, mcp<\/code> \u2014 the terms people actually search, with <code>abilities<\/code> kept because it is the one word that distinguishes this plugin from an MCP server.<\/li>\n<li><strong>The listing no longer counts toolsets as this plugin's feature.<\/strong> It led with \"357 ready-made WordPress abilities across 14 toolsets\" and explained the toolset dispatch model as something this plugin gives you. That attribution is wrong: AcrossAI MCP Manager owns the toolset layer now. The counts of abilities stay, because those are what this plugin ships; the counts of toolsets are gone, and the explanation of why an AI sees a dozen tools instead of hundreds now credits the MCP server for the grouping. The per-plugin toolsets \u2014 Elementor, Rank Math, Site Kit, UpdraftPlus, All-in-One and the rest \u2014 are still described here, because they still come from this plugin and MCP Manager deliberately does not carry them. Nothing about the code changed in this release.<\/li>\n<li><strong>Tested up to WordPress 7.1, and the plugin's own one-line description rewritten.<\/strong> The header still described this as a way to \"manage and customize the abilities of AcrossAI \u2026 tailor the AI's capabilities\", which is what an AI settings panel does, not a plugin that ships 357 abilities. That line is what WordPress shows under the plugin name in wp-admin, so it now says what you actually get.<\/li>\n<li><strong>The listing now says plainly that this works with any Abilities API consumer, not just one MCP server.<\/strong> Every ability here is registered through WordPress 6.9's own Abilities API, so anything that reads that API can expose them \u2014 AcrossAI MCP Manager, the WordPress MCP Adapter, another MCP server, a REST client, or a plugin calling the Abilities API directly. That was previously one clause at the end of a paragraph; it is now three named routes and an explicit statement that nothing here is proprietary or bound to a particular transport.<\/li>\n<li><strong>The integration list is shorter, because each entry now links to its own page.<\/strong> Every integration gained a link in 0.0.39; the inline paragraph describing each one was then saying what the linked page says at length. Each is now a single line naming the area it covers.<\/li>\n<\/ul>\n\n<p>Verified: the Description parses at 2,372 of 2,500 words with the two unrecognised sections folded in, as WordPress.org counts them.<\/p>\n\n<h4>0.0.39 - 2026-09-28<\/h4>\n\n<ul>\n<li><strong>Fixed: asking All-in-One WP Migration for a backup told you to install UpdraftPlus.<\/strong> The All-in-One abilities detect their plugin correctly, but when it was missing they reported the failure using UpdraftPlus's error code and UpdraftPlus's message. So calling <code>all-in-one\/get-status<\/code> on a site without All-in-One named the wrong plugin \u2014 and following that advice installed the wrong plugin, after which the ability still failed. Worse for anything automated, both suites returned the same <code>updraftplus_missing<\/code> code, so a caller checking which plugin was absent could not tell them apart, which is the one question a typed error code exists to answer. All-in-One now returns <code>all_in_one_missing<\/code> and a message about its own archives and exports. Every guard in the plugin is now checked for a shared code, so this cannot recur quietly.<\/li>\n<li><strong>Rank Math SEO scores now record where they came from and when.<\/strong> Rank Math stores a score as a bare number, so nothing distinguished a score its own browser analyzer wrote months ago from one an AI client worked out this morning \u2014 and \"are these scores current?\" had no answer. <code>rank-math\/update-seo-scores<\/code> now stamps each score it writes with a timestamp and a source, and takes a new optional <code>source<\/code>: <code>agent<\/code> (the default, meaning an AI client graded the post against the rubric Rank Math's own <code>rank-math\/analyze-post-content<\/code> hands out) or <code>rank-math-analyzer<\/code> (a number Rank Math's client-side analyzer produced). The two do not always agree, and saying which one you have is the point. <code>rank-math\/audit-content-seo<\/code> reports both back as <code>seo_score_at<\/code> and <code>seo_score_source<\/code>. Scores Rank Math wrote itself report null for both, which is the honest answer rather than a guess. Nothing about the score itself changes, and the existing single-argument call still works.<\/li>\n<li><strong><code>rank-math\/audit-content-seo<\/code> can now audit an exact list of posts.<\/strong> It could sweep a post type or search for text, but there was no way to ask about five specific posts \u2014 which is exactly what you need before and after changing them. Pass <code>post_ids<\/code> and it reports on those posts, in the order you gave, all in one response. Because naming ids means naming the posts, it also stops applying the post\/page and published-only defaults that would quietly drop a draft or a custom post type and leave it looking like it did not exist, and it lists healthy posts alongside problem ones instead of returning a shorter list with no explanation. Passing <code>post_types<\/code>, <code>post_statuses<\/code> or <code>only_issues<\/code> yourself still overrides all of that, and a sweep with no <code>post_ids<\/code> behaves exactly as before.<\/li>\n<\/ul>\n\n<p>Verified against Rank Math 1.0.278.\n* <strong>New: a Site Kit by Google toolset \u2014 11 abilities under <code>site-kit\/*<\/code>.<\/strong> Site Kit connects a WordPress site to Search Console, Analytics 4, PageSpeed Insights, AdSense and Tag Manager, and until now none of that was reachable. <code>site-kit\/get-status<\/code> reports whether Site Kit is set up, whether the WordPress user making the call has connected their own Google account, which account that is, and what to do next. <code>site-kit\/list-modules<\/code>, <code>site-kit\/get-module-settings<\/code>, <code>site-kit\/set-module-state<\/code>, <code>site-kit\/get-sharing-settings<\/code> and <code>site-kit\/list-module-datapoints<\/code> cover the modules \u2014 which are on, which are fully configured, which Google property each points at, and who can see the data. <code>site-kit\/get-search-analytics<\/code> reads Search Console clicks, impressions, CTR and position by query, page, country, device or date; <code>site-kit\/get-analytics-report<\/code> runs GA4 reports; <code>site-kit\/get-pagespeed-insights<\/code> runs Lighthouse; <code>site-kit\/get-adsense-report<\/code> reads earnings. <code>site-kit\/get-module-data<\/code> reaches any read datapoint the named abilities do not cover. Everything is read through Site Kit's own module clients, so no request shape is reimplemented and no Google credential is ever returned. The toolset appears only when Site Kit is active, and like Rank Math's it is not in a new MCP server's default set \u2014 add it by hand or reach it through Integrations.\n* <strong>Site Kit abilities say whose problem it is when there is no data.<\/strong> Site Kit stores one Google token per WordPress user, so an administrator on a fully configured site can still see nothing because a colleague did the connecting. Four situations that all look like \"no data\" \u2014 Site Kit not set up, this user not connected, the module switched off, the module on but missing its property settings \u2014 each get their own error code and their own sentence naming who must do what. Search Console returning zero rows is reported as the ordinary result it usually is, with the two-day reporting lag named, rather than as a failure.\n* <strong>PageSpeed Insights returns a summary, not half a megabyte.<\/strong> Google's raw Lighthouse response for one page measured 529 KB \u2014 199 KB of it a base64 screenshot no assistant can display, and 315 KB of audit detail tables \u2014 which overflowed the reply before any of it could be read. <code>site-kit\/get-pagespeed-insights<\/code> now returns the category scores as percentages, the Core Web Vitals, any real-user field data Google holds for the URL, and just the audits that failed. Pass <code>detail: \"audits\"<\/code> for every audit's score without its tables, or <code>detail: \"full\"<\/code> for Google's whole response. The screenshot is dropped at every level. The ability also now says up front that a run takes ten to sixty seconds and can outlast a client's request timeout.\n* <strong>Site Kit settings can now be changed, not just read.<\/strong> The suite could report that a site sends its analytics to one Google property but could do nothing about it. <code>site-kit\/update-module-settings<\/code> writes them: which Analytics 4 property and measurement ID the site reports to, which Search Console property it reads, which Tag Manager container it uses, whether each module places its snippet, and who is excluded from tracking. Send only the keys you want changed. A key the module does not have is named back to you rather than silently dropped, which is what Site Kit's own writer does and the reason a typo used to look like success. The response reports each key's old and new value read back after the write, because every module runs its own sanitiser and what you asked for is not always what got stored. Confirm-gated, since switching a snippet off stops measurement on the live site immediately.\n* <strong>Changing a Site Kit connection setting moves who owns the module \u2014 and now says so.<\/strong> Site Kit silently reassigns a module's owner to whoever changes its property or account, and that owner's Google credentials are what serve the module's data to everyone reading a shared dashboard. The write reports when that happened instead of leaving it to be discovered. <code>ownerID<\/code> itself cannot be written by hand, and neither can any credential key \u2014 an ability that hides secrets on read should not let you set one.\n* <strong>New: read and change your Site Kit Key Metrics.<\/strong> The row of tiles at the top of the Site Kit dashboard \u2014 new visitors, most popular content, top traffic source \u2014 was invisible here. <code>site-kit\/get-key-metrics<\/code> reports which tiles the current user has chosen, whether the row is hidden, and who set it up for the site; <code>site-kit\/update-key-metrics<\/code> changes them. The selection is stored per WordPress user, so both describe and change only the dashboard of the user making the call. The slug list lives in Site Kit's JavaScript and grows with ordinary releases, so an unrecognised tile is saved and flagged rather than refused \u2014 refusing would break on exactly the tiles a newer Site Kit just added. Not confirm-gated: it moves tiles on one admin screen and touches neither the site nor its measurement.<\/p>\n\n<p>Verified against Site Kit by Google 1.188.0 on a live site with Search Console, Analytics 4, Tag Manager and PageSpeed Insights connected.\n* <strong>The 27 Elementor design audits now actually examine the page.<\/strong> They were registered and callable, but the analysis inside each was never written: they returned a made-up score with no findings, wrapped in \"Ran audit: \u2026\" and a claim to be grounded in Elementor's official documentation. On a test page built as four identical 50\/50 sections carrying the same button, <code>audit-generic-layout-patterns<\/code> used to answer 100 out of 100. It now answers 46, and names the three reasons \u2014 four repeated 50\/50 rows, every row splitting evenly, and a stock split hero opening the page. All 27 are implemented against a shared model of the document, so every audit means the same thing by a row, a lane and a ratio.\n* <strong>The eleven design fixes now change the page, and say exactly what they changed.<\/strong> Each one is confirm-gated, writes through a single audited path, and returns every setting it touched with its previous value so a change can be put back by hand. Running one twice changes nothing the second time and does not re-save. The image-to-background conversion hides the original widget rather than deleting it, because that judgement is one you may want to reverse.\n* <strong>Fixed: <code>elementor\/evaluate-design<\/code> failed on every call, on every site.<\/strong> It returned two fields its own output schema did not declare, and the schema forbids undeclared fields, so it errored every time it was used \u2014 it had never worked. The same fault was then found in the individual audits, which return their evidence under a field the schema also did not declare. Both are fixed and both are now pinned by tests.\n* <strong><code>elementor\/evaluate-design<\/code> composes the audits it is supposed to.<\/strong> Its registry was only ever filled in by the test suite, so on a real site it aggregated nothing \u2014 a separate fault from the skeletons, and one that fixing them would not have touched. Audits now enrol themselves, and the aggregate reports 16 running on a typical page. The mutating abilities deliberately do not enrol: an aggregate that rewrote the document as a side effect of being asked a question would be indefensible.\n* <strong>Fixed a false positive found by building a good page rather than a bad one.<\/strong> The native-widget audit counted icon elements across a whole row, so the standard three-up feature grid \u2014 one icon box per column \u2014 was told to become an Icon List, which is a vertical list inside a single column and not the same thing at all. It now counts within each column. Advice that is wrong about correct work is how a tool teaches people to ignore it.\n* <strong>The aggregate score now says what it is.<\/strong> It is a mean across audits, so audits finding nothing pull it up and a page with real problems can still read in the eighties. The response now carries that caveat and the lowest individual score alongside the average, so the number is read rather than trusted.<\/p>\n\n<h4>0.0.38 - 2026-09-22<\/h4>\n\n<ul>\n<li><strong>Fixed: a toolset that happened to be empty disappeared from the tool list, and could never come back.<\/strong> An AI assistant is handed its list of tools once, when it connects, and there is no way to hand it a new one. A toolset holding nothing was left off that list \u2014 so on a site where every ability already had a home, the Other toolset was missing, the Tools tab said fourteen while the assistant was served thirteen, and reconnecting did not help because it was still empty at that moment. The built-in toolsets are now always offered, empty or not; calling an empty one answers with a message rather than an error. Toolsets belonging to a specific plugin are unchanged: they still appear only when their plugin is there, and the Integrations toolset still reaches them either way.<\/li>\n<li><strong>Fixed: the Integrations toolset could disappear too \u2014 the one thing that should never have.<\/strong> Integrations exists so an assistant can reach a plugin installed after it connected. Its contents come only from plugin toolsets, so on a site with none active it was empty and therefore absent, exactly when it was most needed. It is now always present.<\/li>\n<li><strong>Integrations and Other now say that their contents change.<\/strong> Both fill and empty as plugins and themes are activated, so an assistant that asked once and remembered the answer was wrong from the next activation onwards with nothing to tell it. Their listings now carry a <code>volatile<\/code> marker and a note to ask again. An empty one says the emptiness is about this moment rather than settled.<\/li>\n<li><strong>Fixed: Contact Form 7 mail tags written inside angle brackets were silently deleted.<\/strong> <code>From: [your-name] &lt;[your-email]&gt;<\/code> is how a From line is normally written in a plain-text mail body. Sanitising read <code>&lt;[your-email]&gt;<\/code> as an unknown HTML tag and removed it, taking the mail tag with it \u2014 the save reported success, and checking the template afterwards reported it <em>valid<\/em>, because the tag that would have been flagged was gone. The tag survives now. Sanitising itself is unchanged and still removes real HTML; only this one shape, a bare mail tag between angle brackets, is let through. Updating a mail template also now names any field whose stored content was altered, so nothing is dropped quietly again.<\/li>\n<li><strong>Fixed: a Contact Form 7 field option containing a space became several options.<\/strong> Contact Form 7 splits a field tag on spaces, so <code>placeholder:+44 7700 900000<\/code> arrived as three separate options and the field ended up with a placeholder of <code>+44<\/code>. Option values are now quoted the way choice values always were. An option with a space and no <code>key:<\/code> in front of it cannot be repaired, so it is refused with the offending text named rather than silently mangled.<\/li>\n<li><strong>Fixed: the Contact Form 7 field-type list advertised syntax that does not work.<\/strong> Contact Form 7 registers <code>text<\/code> and <code>text*<\/code> as separate types, and the list appended an asterisk to each \u2014 producing a duplicate row for every type and the string <code>text**<\/code>, which Contact Form 7 does not understand. There is now one row per type, showing a required form only where one genuinely exists: <code>submit<\/code> and the captcha fields have none. The list goes from 35 entries to 24.<\/li>\n<li><strong>Creating a Contact Form 7 form now accepts <code>template<\/code>, the name the other template abilities already use.<\/strong> Creating a form called the markup <code>form<\/code> while reading and replacing it called the same thing <code>template<\/code>, so anything that learned one name was rejected by the next. <code>template<\/code> works everywhere now, and <code>form<\/code> still works for anything already using it.<\/li>\n<li><strong>Enabling a Contact Form 7 autoresponder now warns when it would send to nobody.<\/strong> A form whose fields were rewritten keeps Contact Form 7's stock autoresponder, which is addressed to <code>[your-email]<\/code> \u2014 on a form without that field the reply goes nowhere, and the visitor still sees a success message. Switching the autoresponder on now reports any mail tag in it that matches no field, so the problem is visible at the moment it is created.<\/li>\n<\/ul>\n\n<h4>0.0.37 - 2026-09-21<\/h4>\n\n<ul>\n<li><strong>Fixed: the UpdraftPlus and All-in-One WP Migration tools were offered on sites without those plugins.<\/strong> Both appeared in an MCP server's tool picker, and in the set a new server starts with, whether or not the backup plugin was anywhere on the site. Every other per-plugin toolset \u2014 Elementor, Rank Math, LiteSpeed \u2014 already excluded itself; these two, added in 0.0.35, did not. The tools themselves were never broken: they are still registered when their plugin is active, still addable by hand, and still reachable through the Integrations toolset. What changes is that they are no longer part of what a new server is given by default. If a server already has one and the plugin is not installed, \"Reset to Type Defaults\" clears it.<\/li>\n<\/ul>\n\n<h4>0.0.36 - 2026-09-21<\/h4>\n\n<ul>\n<li><strong>Listing posts no longer forces you to download every body.<\/strong> <code>content\/list-posts<\/code>, <code>content\/list-pages<\/code> and <code>content\/list-cpt-items<\/code> returned every field of every item including the whole post_content \u2014 ten posts came to about 172 KB when almost all of it was content nobody had asked for yet. Pass <code>fields: \"summary\"<\/code> to get just what identifies an item: title, status, dates, slug, author, a trimmed excerpt, and content_bytes so you can size the follow-up read. Measured at 36-39x smaller. The default is unchanged, so nothing existing sees a difference.<\/li>\n<li><strong>Fixed: the block outline reported the wrong total.<\/strong> Asking for 3 blocks of a 40-block post reported <code>total: 3<\/code> \u2014 it counted what it returned rather than what matched, because it stopped walking the moment it had enough. It now reports <code>total: 40<\/code> with a new <code>returned: 3<\/code> alongside, so you can tell a small post from a truncated view of a large one. Each block also reports <code>subtree_bytes<\/code> next to <code>bytes<\/code>, which distinguishes a genuinely small block from a small wrapper around half the page.<\/li>\n<li><strong>Site Health results can now be read as text.<\/strong> The description and actions fields carry WordPress core's own markup \u2014 paragraph tags, icon spans that render as pictures and read as nothing, and screen-reader spans that repeat every link's text. Pass <code>format: \"text\"<\/code> for plain sentences with the link destinations kept. The default still returns the markup unchanged.<\/li>\n<li><strong>Every ability now has to say whether it reads, destroys, or can be repeated.<\/strong> Those three flags are how an AI client decides whether something is safe to try, safe to retry, and safe to run without asking, and a missing one reads as \"not destructive\" \u2014 the dangerous way to be wrong. Abilities missing them are now caught by the test suite, and reported on screen while <code>WP_DEBUG<\/code> is on. Nothing changes on a production site.<\/li>\n<li><strong>The transient and object-cache abilities now point at the page cache when there is one.<\/strong> Clearing transients is not what a visitor sees. On a site running LiteSpeed, these abilities now suggest <code>litespeed\/purge-cache<\/code> for that \u2014 and say nothing on sites without it, rather than naming an ability that is not there.<\/li>\n<\/ul>\n\n<h4>0.0.35 - 2026-09-21<\/h4>\n\n<ul>\n<li><strong>The backup abilities are now two tabs, one per plugin.<\/strong> <code>UpdraftPlus<\/code> and <code>All-in-One WP Migration<\/code> each get their own tab, their own toolset and their own abilities, the same way Elementor, Rank Math, WPCode and every other integration works. 0.0.34 shipped them as a single \"Backups\" tab that reached both plugins through a shared layer; that made two genuinely different plugins look interchangeable and turned every real difference into a flag you had to go and check.<\/li>\n<li><strong>Each suite now offers only what its plugin can actually do.<\/strong> UpdraftPlus schedules backups and restores them, and stores no label - so it has no label ability. All-in-One labels its archives, and restoring belongs to their paid Unlimited Extension - so that ability asks the plugin and passes its own answer back, naming the manual import route, rather than refusing on its behalf.<\/li>\n<li><strong>Breaking: the <code>backups\/*<\/code> abilities are gone.<\/strong> They are replaced by <code>updraftplus\/*<\/code> and <code>all-in-one\/*<\/code>. Anything holding a <code>backups\/<\/code> slug needs updating; there are no aliases. The suite was one release old.<\/li>\n<li><strong>Fixed: restoring never worked outside the admin screens.<\/strong> The restore checked whether WordPress could write to the filesystem directly - the check that stops a restore dying half-way through - using a function WordPress only loads inside wp-admin. Every restore request therefore failed on that line before checking anything, whatever it was asked to do. This shipped in 0.0.34 and is fixed here.<\/li>\n<li><strong>The exposure check is shared and reports per plugin.<\/strong> Whether the web server will hand out a backup archive has nothing to do with which plugin wrote it, so that logic exists once - but each tab now reports on its own storage rather than on everything at once.<\/li>\n<\/ul>\n\n<h4>0.0.34 - 2026-09-18<\/h4>\n\n<p>The largest release so far: 25 features, 19 new tabs and around 400 new abilities. The theme is reach and honesty - most of the popular plugins a site actually runs can now be driven directly, each behind this plugin's own permission floor, and every ability that cannot do something says why and names the route that works instead.<\/p>\n\n<p><strong>Breaking changes<\/strong><\/p>\n\n<ul>\n<li><strong>Abilities now require administrator rights unless you say otherwise.<\/strong> If anyone below administrator drives this site through an AI client - a shop manager running a store, for example - they lose access on update until an administrator grants it. Set a rule on the individual ability under User Access, or move the site-wide floor with the <code>acrossai_default_ability_capability<\/code> filter.<\/li>\n<li><strong>Why: every plugin chose its own lock, and nobody was checking them.<\/strong> Measured across the abilities installed on one site: three registered with no permission check at all, two were open to any logged-in subscriber, and one that <em>writes content<\/em> was open at contributor level. This plugin now decides who may run an ability, whoever registered it.<\/li>\n<li><strong>Setting access used to be able to remove the lock.<\/strong> Choosing \"Everyone\" on an ability replaced its built-in check with one that allowed anybody - an action that reads as tightening actually opened the door. Access rules now sit on top of a floor that cannot be removed by accident.<\/li>\n<\/ul>\n\n<p><strong>New tabs<\/strong><\/p>\n\n<ul>\n<li><strong>Store (WooCommerce) - 34 abilities.<\/strong> The catalogue, pricing, stock, orders, customers, coupons, tax, shipping and store settings, plus WooCommerce's own seven adopted into the same tab. Variable products can now be created at all, which WooCommerce's own abilities cannot do.<\/li>\n<li><strong>Backups - 9 abilities.<\/strong> Whether this site can be recovered: what exists, when it last ran and whether it worked, whether the archives are reachable over HTTP, and taking, labelling, deleting or restoring one. Works with UpdraftPlus and All-in-One WP Migration through one set of abilities.<\/li>\n<li><strong>Yoast SEO - 64 abilities<\/strong>, and Yoast's own two now have a home.<\/li>\n<li><strong>LiteSpeed Cache - 61 abilities.<\/strong><\/li>\n<li><strong>Contact Form 7 - 25 abilities<\/strong>, and <strong>WPForms'<\/strong> own abilities now have a home with an off switch for form writing.<\/li>\n<li><strong>WPCode - 24 abilities<\/strong>, adopting the five WPCode already had.<\/li>\n<li><strong>Cookie Consent - 22 abilities<\/strong>, with an honest account gate rather than silent failure.<\/li>\n<li><strong>The Events Calendar - 18 abilities<\/strong> and <strong>Event Tickets - 16<\/strong>, with capacity modelled and personal data gated.<\/li>\n<li><strong>Advanced Custom Fields - 16 abilities<\/strong>, joining the existing ACF tab.<\/li>\n<li><strong>Translations - 14 abilities.<\/strong><\/li>\n<li><strong>Email Delivery - 4 abilities<\/strong>, plus a home for the ones the mail plugin ships, and <strong>Akismet's<\/strong> own abilities adopted.<\/li>\n<li><strong>Classic Editor - 4 abilities<\/strong> for what nothing else can reach.<\/li>\n<\/ul>\n\n<p><strong>Safety<\/strong><\/p>\n\n<ul>\n<li><strong>Fixed: editing a WooCommerce product or order through the generic content tools silently corrupted the store.<\/strong> Writing a price through <code>content\/update-cpt-item<\/code> left the price the shop actually charges on the old value, and saving the product correctly afterwards did not repair it. Orders were worse: WooCommerce no longer keeps them in the posts table, so the write changed a row nothing reads and was later deleted. Both are now refused, naming the ability that does work.<\/li>\n<li><strong>A backup archive that anyone can download is a total compromise, and this now checks for it.<\/strong> Both backup plugins drop a .htaccess to prevent it; on nginx, IIS and Caddy that file is never read, so the protection is present, looks correct, and does nothing.<\/li>\n<li><strong>Restoring says plainly that it cannot be undone<\/strong>, and records what the site looked like beforehand so what was given up is visible.<\/li>\n<\/ul>\n\n<p><strong>The abilities screen<\/strong><\/p>\n\n<ul>\n<li><strong>Integration tabs are now named after the plugin they drive<\/strong>, and abilities registered by other plugins now belong to a toolset instead of vanishing into a catch-all.<\/li>\n<li><strong>One screen, one access model.<\/strong> The registration gate is gone; tabs were regrouped into task groups, and deep links to retired tabs fall back to \"All\".<\/li>\n<li><strong>Fixed: WPCode's own five abilities were never actually adopted<\/strong> into its tab - the prefix could not match.<\/li>\n<\/ul>\n\n<p>For the complete detail of this release - all 156 entries - and the full history of every earlier release, see changelog.txt inside the plugin, or\nhttps:\/\/github.com\/acrossaico\/acrossai-abilities-manager\/blob\/main\/changelog.txt<\/p>\n\n<h4>0.0.33 - 2026-08-28<\/h4>\n\n<p><strong>Release theme: closing the cheap-edit loop.<\/strong> A follow-up to 0.0.32 that closes the last two gaps between \"locate a block cheaply\" and \"modify it cheaply\". Two changes, both surgical and backwards-compatible.<\/p>\n\n<p><strong><code>return_content:false<\/code> default now covers the two block-tree writers.<\/strong> <code>blocks\/add-block<\/code> and <code>blocks\/update-post-block<\/code> gain the same <code>return_content:{boolean, default:false}<\/code> input as the six content writers (PR #152) and nine block-editor writers (PR #153). When false (default), the response's <code>block<\/code> object strips its <code>innerHTML<\/code>, <code>innerContent<\/code>, and <code>innerBlocks<\/code> \u2014 leaving <code>blockName<\/code>, <code>attrs<\/code>, and <code>path<\/code> \u2014 and <code>content_bytes<\/code> reports the saved <code>innerHTML<\/code> size. Container blocks (columns, cover, group) previously echoed their entire innerBlocks subtree; now they don't unless the caller passes <code>return_content:true<\/code>. BREAKING for callers reading <code>response.block.innerHTML<\/code> on these two abilities \u2014 pass <code>return_content:true<\/code> explicitly. Every other block-tree read\/write (mutate-block-tree, replace-block-text, remove-block, duplicate-block, move-block) already returned lightweight envelopes and is unchanged.<\/p>\n\n<p><strong><code>blocks\/get-post-blocks<\/code> gains scoping inputs.<\/strong> Three new optional inputs close the \"read one block's markup\" gap between <code>blocks\/get-post-blocks<\/code> (full tree, full content) and <code>blocks\/outline-post-blocks<\/code> (scoped but never returns content). <code>path: int[]<\/code> scopes the response to a subtree (uses the same raw parse_blocks() index scheme as add-block \/ update-post-block \/ remove-block, so returned paths interchange). <code>depth: integer<\/code> bounds descent below the subtree root (-1 unlimited, 0 subtree root only, N below). <code>include_html: boolean<\/code> (default true = backwards-compat) strips innerHTML + innerContent from every returned node when false. Backwards-compatible: existing callers passing only <code>post_id<\/code> see identical responses. An unresolvable <code>path<\/code> returns a standard error envelope with <code>error_code: invalid_path<\/code> naming which depth failed and how many blocks exist at that level.<\/p>\n\n<h4>Earlier releases<\/h4>\n\n<p>Every release before 0.0.33 is recorded in full at https:\/\/acrossai.co\/changelog\/acrossai-abilities-manager\/ and in changelog.txt, shipped inside the plugin.<\/p>","raw_excerpt":"357 ready-made WordPress abilities for Claude, ChatGPT and any AI agent \u2014 browse, override and control every one.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/311005","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=311005"}],"author":[{"embeddable":true,"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/raftaar1191"}],"wp:attachment":[{"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=311005"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=311005"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=311005"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=311005"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=311005"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=311005"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}