Changelog

SophMate plugin changelog

Track tagged SophMate WordPress plugin releases, shipped product capabilities, requirements, security notes, and upgrade guidance.

Product 1.3.0

SophMate 1.3.0 Release

New social media integration, workflow AI creation enhancements, editor copilot and bug fixes

Added

  • Social media workflow integrations — Added first-class Facebook Pages, Instagram professional accounts, X, and YouTube connections with multi-account OAuth, signed webhook delivery and polling reconciliation, normalized engagement events, metric-threshold triggers, and provider-specific publishing, reply, moderation, and YouTube video-management actions. Social writes use exact approval previews, encrypted credentials and payloads, durable scheduled/resumable jobs, quota and spend controls, idempotent workflow continuation, privacy export/erasure, and canonical downstream resource links. All four providers, both social triggers, and all twelve actions are available by default without social rollout flags; activation still fails closed when credentials, scopes, account capabilities, quotas, scheduler health, or required provider reviews are missing.
  • Workflow AI V3 contract-guided generation and execution — Replaced model-authored workflow JSON and whole-plan repair loops with atomic intent requirements, versioned capability contracts, typed semantic ports, constraint-solved candidate graphs, bounded opaque decisions, application-allocated configuration slots, deterministic compilation, and a requirement-level proof ledger. AI generation now runs as a durable, resumable V3 job with artifact-local checkpoints and dependency-aware validation; recipes are searchable guidance only, and uncontracted capabilities are excluded instead of guessed. New and edited AI workflows execute immutable compiled plans through contract-native preflight, typed action outcomes, fail-fast control flow, and a durable per-step ledger, while AI Workers receive only live policy-authorized tools and cannot publish unverified downstream output. Activation recompiles and rechecks volatile dependencies atomically, and the legacy synchronous endpoint is now a deprecated adapter over V3 with no V2 fallback.
  • Editor Copilot — Replaced the generic post/page action-card sidebar with a unified, editor-native AI copilot for Gutenberg posts and pages. The document-scoped panel supports briefs, outlines, drafting, selected-text and single/multi-block rewriting, title/excerpt/slug alternatives, structural edits, editorial and accessibility reviews, SEO and internal-link guidance, publish packs, personas, brand guidance, Knowledge Base grounding, and integrated Image Studio handoff. AI edits arrive as typed, block-aware proposals with before/after previews, granular apply/discard/refine controls, target hashes, stale-change detection, partial-conflict handling, local-only application, transaction receipts, and conflict-safe reversion; SophMate never autosaves or publishes accepted changes. Editor sessions resume per user and document under existing retention and privacy controls while remaining isolated from normal Copilot history, and long-document work includes visible scope, budget, progress, cancellation, and provider-safe structured-response validation.
  • Added a verified Telegram Operator Site Manager workflow template that starts disabled, requires explicit administrator account linking, blocks customer and anonymous access, uses a dedicated credential reference, and routes requests through an inline AI Worker with a reviewable site/store tool allowlist, live WordPress capabilities, approval-policy enforcement, protected Telegram replies, and safe Copilot recipe guidance.
  • Production-grade Copilot reasoning — Added a provider-neutral reasoning kernel for Copilot and workflow AI Workers that moves complex requests through structured understanding, authoritative local capability discovery, evidence-backed research, contract construction, deterministic schema compilation, semantic and security validation, mocked simulation, and independent completion verification before proposing or activating work. Reasoning depth can be selected per conversation or left on the default Auto mode, where the governed reasoning session chooses how deeply to investigate from the full request context instead of using a brittle deterministic depth router; the selected mode is persisted for that conversation, and the last-used mode becomes the default for new conversations. External integrations fail closed when evidence, provider capabilities, required tools, or configuration are unavailable; recipes are exposed only as searchable examples and adaptation guidance rather than brittle executable solutions. Governed retries use structured diagnostics, and user-visible readiness artifacts expose sources, assumptions, setup requirements, validation results, and blockers without storing or revealing private chain-of-thought.
  • Added governed workflow-reasoning rollout controls (enabled, stable actor canary, redacted shadow, and fail-closed off) plus phase-level workflow and AI Worker telemetry containing only identifiers/fingerprints, decisions, counts, validation codes, token usage, and latency. Existing workflows are unaffected by rollback, and external or high-assurance requests never fall through to legacy best-guess generation.
  • Added provider-state parity for governed reasoning: official OpenAI models use Responses streaming with strict function schemas and encrypted opaque continuation replay, Anthropic preserves signed thinking/tool continuation while enforcing compatible required-tool policy, and Gemini uses native Interactions Google Search with direct HTTPS citations, search-call/result proof, domain enforcement, and fail-closed evidence handling.
  • Added governed long-tail integration contracts with actor-bound review artifacts, official-document evidence import, SSRF-safe connection probes, explicit operator approval, versioned conformance checks, and fail-closed activation. Workflow generation and activation now also bind referenced tools, playbooks, Knowledge Base collections, nested workflows, provider capabilities, and external protocol metadata to live catalogs so stale or unauthorized resources cannot execute after validation.
  • Telegram polling/webhook workflows and verified account access — Added dedicated Telegram Updates (Polling), Telegram Updates (Webhook), and Send Message workflow capabilities. Polling uses durable update_id cursors and per-bot leases; webhook delivery uses a separately stored secret token, verified inbound headers, public-HTTPS readiness checks, ownership-safe setWebhook/deleteWebhook lifecycle management, and durable idempotent queue acknowledgement. Both modes share retry handling, safe reply chunking, bounded conversation memory, account linking, and a separate “More triggers” workflow-picker section. Telegram workflows support private, single-use account linking for customers through WordPress sign-in and for a selected administrator through a short-lived /link CODE; linked identities are revalidated against live WordPress users and capabilities, constrained by the workflow tool allowlist and approval policy, and can inspect or revoke access with /whoami and /unlink. Added customer-scoped account and order tools, public storefront search, encrypted credential references, activation readiness gates, active-link management, audit events, abuse controls, and WordPress privacy export/erasure support.
  • Added Plain Text, Telegram Markdown V2, and Telegram HTML formatting choices to the Send Telegram Message workflow action. The connector sends only official parse_mode values and safely falls back to plain text solely after a definitive Telegram entity-parse rejection, preserving delivery without hiding authentication, routing, or transport failures.
  • Durable Telegram conversation supervisor — Replaced workflow-wide flat transcript memory with encrypted bot/chat/user sessions, ordered turns, database leases, duplicate coalescing, queued delivery, typed current-turn interpretation, open-intent lifecycles, and application-owned outcomes. Historical requests can no longer authorize new writes; follow-ups resolve opaque, reauthorized action/resource receipts and use exact live read tools such as sophmate.content.posts.get instead of replaying mutations. Telegram now sends immediate typing state, persists editable progress/final delivery IDs, supplies fallback replies without disguising failed workflow runs, records exact action disposition from execution results, redacts message and identity data from run context, and includes conversation inspection, reset, cancellation, privacy export/erase, retention purge, and reconciliation-safe retry APIs.
  • Added inline AI Worker execution as the fast default for short governed workflow work, including write tools executed as the current verified WordPress identity. Reads execute directly, while every mutation passes through action-plan governance: Suggest mode queues approval, Auto mode applies the site's policy, and an explicit workflow bypass can waive only human approval matching. Durable Background Task execution remains available for long-running or bulk work and blocking approvals.
  • AI Worker workflow action — Added a high-risk, durable action for complex multi-step AI work that exceeds Generate AI Content and AI Decision. AI Worker pauses and resumes its parent workflow exactly once through Background Tasks, supports inherited or explicit models, token and step budgets, queued or blocking approvals, optional Knowledge Base retrieval, text or schema-bound structured results, and stable downstream output with usage, artifacts, action plans, and warnings. Its Copilot-equivalent web, file, MCP, custom, read, and governed write tools are constrained by per-workflow selected or confirmed snapshot-based all current policies, rechecked against live permissions before dispatch, and protected by existing approval, privacy, budget, ancestry, and audit controls. The workflow builder includes a searchable risk-aware tool picker, snapshot refresh and compatibility warnings, side-effect-free simulation, package import/export support, task progress and deep links in run history, and clear recovery behavior for approvals, provider issues, budget pauses, cancellation, and invalid structured output.
  • Added the feature-flagged sophmate.web.capture multimodal tool for bounded visual inspection of anonymous public HTTPS pages, with Cloudflare Browser Rendering BYOK support, a disclosed WordPress.com mShots fallback, shared URL hardening, encrypted temporary artifacts, model-capability filtering, settings controls, compact evidence cards, and untrusted-visual prompt-injection defenses.
  • Added an explicit Save capture action that securely promotes an unexpired website screenshot into private encrypted Copilot image files, including multi-tile full-page saves, provenance-based idempotency, authenticated preview/download controls, and conversation-scoped authorization without exposing temporary artifact references.
  • Added an opt-in, Pro-only SophMate MCP Server for securely connecting Claude Code and other remote MCP clients to site-scoped SophMate tools, with Streamable HTTP, OAuth 2.1 and expiring personal tokens, connection-specific tool allowlists and permissions, read-only and all-tools snapshot presets, rate limits, audit/privacy controls, action-plan-governed write operations, and a separately confirmed administrator-only mode for always executing while bypassing human approval policy.

Fixed

  • Fixed every unscheduled social publishing action — including publishing a post to a Facebook Page — failing immediately with validation_error / Expected type "string", got "null". Social workflow actions now omit the optional scheduled_at tool input for immediate publication instead of sending a null placeholder, the social tool declares that field with a single supported type, and tool input schemas reject unsupported JSON Schema type unions at registration time rather than silently narrowing them to string.
  • Fixed connected Facebook, Instagram, X, and YouTube workflows remaining disabled because reviewed contracts were not registered for facebook.graph-api, instagram.graph-api, x.api, or youtube.data-api. SophMate now ships current, evidence-backed contracts for every built-in social workflow action; dedicated social connectors validate their encrypted connection authentication without being mistaken for hand-authored generic webhooks, and native Facebook post scheduling follows Meta's documented 30-day maximum.
  • Fixed inline AI Worker runs failing after successful tool execution merely because a provider returned plain text, fenced JSON, direct schema data, or top-level transport fields instead of the preferred JSON envelope. Output transport is now recovered losslessly while configured structured schemas remain authoritative, ambiguous mappings still fail closed, and completed tools are never replayed during formatting recovery. Capability retrieval and runtime guidance also preserve the exact requested WordPress resource type so content-post requests are not substituted with adjacent Site Editor template operations.
  • Fixed Telegram AI Worker follow-ups losing their prior exchange or the exact governed proposal behind an assistant reply. Polling and webhook conversations now carry bounded, redacted, role-preserving history through inline and background workers; delivered assistant turns retain only typed, opaque action-plan references, which are reauthorized against the current owner and workflow and resolved from the authoritative repository on the next turn. Follow-ups such as “show me its content” can therefore display the exact pending draft without repeating the write or misrepresenting it as live content; stale approval status is refreshed, secrets remain redacted, and durable delivery recovery writes conversation memory idempotently. Auto reasoning and bounded tool retrieval evaluate the unresolved conversation rather than only the latest short reply; authorized tools remain available when a routing pass flags possible ambiguity; delegated creative details use reversible defaults such as an unpublished post draft; and V3 records conversation context as a typed runtime binding instead of compiling it into an instruction string.
  • Audited workflow runs end to end and corrected inline AI Worker execution, telemetry, persistence safety, and recovery UX. Broad operator tool access now sends a bounded capability window to the provider and expands on demand through the same fully authorized catalog, reducing a representative Telegram turn from 20,878 to 1,897 input tokens without removing any permitted tool. Future runs persist exact execution-call counts and executed action-plan provenance, preserve partial-effect and reconciliation state when output validation fails after a tool succeeds, never publish failed AI Worker output to downstream ports, and stop unhandled failures truthfully. Historical AI Worker token records receive a conservative call-count fallback, failed runs identify downstream actions that were never executed, and replay now requires an explicit side-effect warning confirmation. Action-plan and run persistence now redact credentials embedded in legacy runtime URLs, with a bounded Pro/Lite migration removing historical Telegram token copies.
  • Fixed OpenAI inline AI Workers failing before execution when an authorized tool intentionally accepted dynamic object keys. The Responses adapter now keeps strict function calling for losslessly closed schemas and explicitly uses non-strict calling only for open-map tools, preserving their registered contract while SophMate continues to reauthorize and validate every tool invocation locally.
  • Completed the Workflow AI V3 production audit across generation, readiness, activation, and runtime: asynchronous draft responses now use a stable success envelope; only compiled V3 artifacts can be persisted; typed configuration slots resolve against the live encrypted credential store; protocol evidence is evaluated across the complete contract graph; advisory identity requirements no longer become activation blockers; and activation fingerprints ignore cosmetic metadata while still rejecting real concurrent semantic changes. Generic Telegram chat requests no longer inherit workflow-construction instructions as AI Worker duties or silently expand into operator/private tools, task-understanding artifacts are recovered locally instead of entering brittle whole-plan repair loops, generated replies bind to the guaranteed AI Worker output port, and webhook bot connections remain distinct from signing-secret slots with clear setup guidance.
  • Fixed Copilot Telegram operator workflows being rejected as “changed after validation” after an administrator intentionally selected required operator-only linking and an all-current AI Worker tool snapshot. Governed drafts now retain a non-secret projection of every non-editable executable field plus per-worker tool-policy fingerprints, allowing activation to prove that only approved setup and coupled operator tool-policy fields changed. Broad tool expansion remains limited to mandatory administrator-only bots, and activation refreshes simulation and tool/resource contract proofs only after live owner, identity, authorization, provider, schema, Telegram, and approval-policy validation succeeds.
  • Fixed recurring AI_WORKER_TOOL_IDENTITY_SCOPE_MISMATCH failures in AI-generated Telegram workflows. Copilot now keeps generic “chat with my site/store” requests public unless private or administrative access is explicit, validates identity against the complete authorized tool index, stages account-linking, tool-access-mode, and individual tool repairs so their contracts cannot conflict, and repairs only the offending tool through a strict enum of identity-eligible registered replacements with semantic descriptions. If no suitable tool exists, generation stops immediately with account-access guidance instead of spending repair attempts, widening linking permissions, or returning a retry loop. The independent verifier also re-reviews a MISSING_TRIGGER claim when it conflicts with an exact compiled trigger and verified trigger-requirement proof, while persistent contradictions still fail closed.
  • Eliminated remaining bounded-output failures in governed workflow generation: truncated parameter plans now retry from the complete typed contract with preserved binding authority and a larger bounded allowance; field repairs use small diagnostic-local schemas with exact value kinds, enums, node IDs, and JSON pointers; singleton protocol values are completed from the registered contract; and duplicate requirement bookkeeping is canonicalized without weakening credential or semantic checks. Telegram operator drafts now repair mandatory administrator linking and broad-management tool mode before presentation, disable customer self-linking by default, and snapshot every exact generation-time authorized tool with its catalog fingerprint and timestamp.
  • Made AI workflow creation converge on exact governed contracts instead of cycling through opaque retries: task understanding now aggregates credential-slot and requirement/assertion relationship defects and repairs only those fields; the compiler reports every assignment type mismatch with its node, JSON pointer, target type, allowed value kinds, and schema constraints; capability validation can patch safe schema-backed values such as required enums and missing array items without regenerating unrelated configuration; and contradictory completion-verifier verdicts receive one bounded independent correction pass. The default-model Telegram operator-management request now compiles, validates, simulates, proves every requirement, and stops only for the intentionally unresolved bot credential.
  • Fixed governed workflow repair blind spots by reporting all conflicting inactive value-source fields together, translating topology-domain invariants into exact repair operations, and using a diagnostic-local strict AI patch for missing message-driven goal/prompt bindings. Repairs remain allowlisted, model-authored, recompiled, and fail closed; repeated ambiguity now has clearer operator-facing guidance.
  • Fixed governed workflow composition so topology corrections cannot consume the parameter phase's repair allowance, low-confidence task contracts receive one bounded evidence-preserving correction path, the original field diagnostic survives exhausted repairs, and temporary provider outages are presented as retryable instead of configuration failures.
  • Made governed workflow drafting distinguish provider credential, quota, rate-limit, and network failures from workflow-validation failures, return recovery-appropriate HTTP statuses, and offer a direct AI Settings recovery action without accepting a partial draft.
  • Hardened Describe with AI workflow generation with field-level compiler diagnostics, capability-schema-aware bounded repair, canonical AI Worker output routing, and deterministic reconciliation of duplicate semantic-verifier claims. Exhausted repairs now identify the exact trigger or action configuration and show actionable remediation in the modal; delayed or approval-resumed runs with a terminal action failure are recorded as failed instead of completed.
  • Closed governed-draft replay and activation-time authorization gaps, including ambiguous workflow-create commit failures, unverified persisted owners, unavailable AI providers, unsupported structured-output endpoints, and malformed Telegram-like generic HTTP operations. Generic webhook secrets are now edited only as credential references, legacy literals are never displayed, and unsigned endpoints require an explicitly restrictive IP allowlist in both the editor and server readiness gate.
  • Made workflow approval mode and the Auto-mode site-policy bypass apply consistently to every inline and background AI Worker mutation, including custom tools that do not declare a tool-level approval requirement. The trusted workflow policy is snapshotted outside model input, action plans remain unlinked from Copilot conversations, and bypassed actions still enforce identity, capabilities, tool allowlists, validation, dry runs, hard safety blocks, execution checks, and audit metadata.
  • Corrected linked-customer Telegram order requests so verified identity is carried through Auto reasoning and tool planning, own-order questions use the intrinsically customer-scoped order tool without asking for an email address or order number, optional linking supports mixed public/customer bots, and internal WooCommerce checkout drafts are excluded from customer order results. Workflow readiness and the editor now block or clearly flag customer linking that has no customer-scoped capability.
  • Corrected Telegram AI Worker execution so harmless messages from unlinked identities can receive verified text-only replies when configured tools are not authorized, while live store claims still fail closed without evidence. Existing public bots can use the intrinsically public sophmate.store.products.search_public tool, and workflow validation now guides operators to the guaranteed AI Worker summary reply path.
  • Made MCP OAuth discovery work on Apache sites using plain WordPress permalinks, returned a directly reachable protected-resource metadata URL in authentication challenges, and prevented the settings UI from presenting a disabled server as ready to authenticate.
  • Rebuilt the MCP OAuth consent screen as a responsive, accessible WordPress-native authorization card with clear client, redirect, scope, tool-count, revocation, and signed-in-user context.
  • Made OAuth-created read-only MCP connections straightforward to widen with the same access presets as manual connections, including a single guarded workflow for applying an all-tools snapshot and administrator-confirmed approval bypass.
Product 1.2.0

SophMate 1.2.0 Release

New Copilot files, web search tools, new Gemini provider, and fixes.

Added

  • Copilot Files — Added a Pro-only, first-class file workspace for private AI-created and uploaded files, with encrypted storage, immutable revisions, provenance, scoped access grants, metadata and tag management, search and filtering, archive/trash lifecycle controls, authenticated previews and downloads, responsive desktop/mobile layouts, and accessible Markdown, CSV, JSON, TXT, PDF, and image rendering.
  • Added Copilot file tools for listing, searching, inspecting, and reading accessible files; privately creating Markdown, TXT, JSON, CSV, and PDF artifacts; and approval-governed metadata, sharing, status, and revision-restore operations. File contents are treated as untrusted input, reads are bounded, and encrypted keyword indexing avoids plaintext search indexes.
  • Added end-to-end chat integration for Copilot Files, including a searchable composer picker, combined five-file attachment limits, persisted attachment references, streamed and reload-safe artifact cards, authenticated preview/download actions, and cross-conversation file discovery instead of relying on conversation memory.
  • Added an opt-in, Pro-only SophMate MCP Server for securely connecting Claude Code and other remote MCP clients to site-scoped SophMate tools, with Streamable HTTP, OAuth 2.1 and expiring personal tokens, connection-specific tool allowlists and permissions, read-only and all-tools snapshot presets, rate limits, audit/privacy controls, action-plan-governed write operations, and a separately confirmed administrator-only mode for always executing while bypassing human approval policy.
  • Added current OpenAI GPT-5.6 variants and Claude Sonnet 5 to the Copilot model catalog; the current Gemini 3.5 Flash, 3.1 Pro, and 3.1 Flash-Lite family remains available.
  • Added a read-only sophmate.web.fetch AI tool for direct access to public HTTPS pages and textual APIs, with readable extraction, long-content chunking, link discovery, SSRF protection, bounded responses, and explicit untrusted-content labeling.
  • Added a provider-neutral sophmate.web.search AI tool backed by native OpenAI Responses or Anthropic server search, with ranked citations, domain/locale/recency controls, active encrypted-credential reuse, cache and rate controls, budget accounting, and a search-then-fetch workflow.
  • Added Google Gemini as a first-class LLM provider, with end-to-end support for provider setup, native streaming chat, structured output, tool calling, multimodal input, managed Agents, model selection, connection tests, and WordPress 7.0 Google connector credentials.
  • Added a WordPress-first Site mode for installations without an active, supported WooCommerce version, including a shared capability profile, dependency-aware tools and automations, goal-based onboarding, WordPress-native Quick Actions, Site Insights, Site Brief onboarding, site-care watchers, and compatibility metadata for App Center apps.

Changed

  • Made the sophmate.web.fetch AI-facing description explicitly instruct models to call it when users ask to fetch, open, read, inspect, or summarize a supplied website URL instead of searching for that URL.
  • Adapted Home, Status, Copilot, Insights, Quick Actions, Playbooks, Agents, Workflows, Watchers, App Center, Theme Assistant, Marketing, Personalization, and Settings to present WordPress features first and expose commerce only when WooCommerce is ready or the user intentionally looks for it.
  • Replaced missing optional-commerce error states with neutral, accessible dependency guidance and native WordPress plugin-management actions, while preserving blocked commerce configurations for automatic recovery after WooCommerce is reactivated.
  • Made WP-Cron a supported Site-mode background backend and reserved Action Scheduler requirements for workloads that genuinely need it.

Fixed

  • Added provider-specific compatibility for the newest models: GPT-5.6 uses max_completion_tokens while legacy-compatible and local models retain max_tokens, Claude 5 models omit unsupported sampling parameters and expose classifier refusals as content filtering, Gemini 3.5 omits legacy sampling parameters, and shut-down Gemini model IDs migrate to supported successors. Filtered responses now discard partial text and tool calls across stored, cached, and live-streamed output.
  • Hardened web fetch and search against recognizable credentials (including recursively encoded, nested, and parser-ambiguous query parameters), unsafe or looping redirects, multiplied request timeouts, known or heuristic binary payloads behind misleading content types, pathological HTML DOM breadth, cross-user/provider cache reuse and provider-configuration races, oversized structured or single-field responses and paused-turn replay state, omitted or failed-request usage accounting, mixed-answer refusals, incomplete provider responses, and Anthropic server-tool or paused-continuation failures returned with HTTP 200.
  • Corrected Gemini thinking-token accounting, safety-block handling, malformed function-call rejection, thought-signature preservation, Google API-key error classification, JSON Schema compatibility, and resolved-endpoint connection testing.
  • Prevented Site-mode pages, Copilot tool catalogs, slash commands, schedulers, hooks, direct deep links, and app runtimes from advertising or calling unavailable WooCommerce functionality.
  • Corrected Site-mode readiness and attention counts so an absent optional WooCommerce integration does not make an otherwise healthy SophMate installation appear broken.
Product 1.1.0

SophMate 1.1.0 Release

New long running background tasks from the Copilot conversation, and integration with WordPress 7.0 AI Connectors.

Added

  • Added WordPress 7.0 AI Connector credential detection for OpenAI and Anthropic, with automatic connector-key usage during setup/runtime and a SophMate key override option.
  • Added an auto-mode workflow option to bypass the site's approval policy for workflow tool actions, allowing trusted workflows to execute eligible tools without waiting for policy-based approval matches.
  • Long-Running Background Tasks — Copilot can now propose durable background tasks for work that exceeds a chat turn (translate all products, audit every order, bulk-create posts) and hand them to a tick-based runner built on Action Scheduler (WP-Cron fallback with watchdog). Includes: launch card in chat with per-task model/worker-model selection and a hard token budget cap; batched execution (compiled task program with per-chunk model calls and grouped bulk action plans) and exploratory execution (checkpointed agent loop with transcript compaction and circuit breakers); blocking and queued approval modes with apply-on-approve, rejection feedback, and a finishing/reconciliation phase; scoped pre-authorization grants (tool + quantity caps + risk ceiling bounded by the granting operator's own approval capability, never-grantable policy for critical/deletion/refund/bulk-email actions, supervised trust-ramp that auto-revokes on any rejection); pilot batch review; a SophMate > Tasks admin page (live activity feed, approvals with approve-all-of-type, grants panel, items with retry, final report, steering box, pending-attention menu badge); completion reports posted back to the originating conversation; per-task and site-budget enforcement with an interactive-chat reserve; audit events, GDPR export/erasure, retention purge, Site Health-style scheduler awareness, and wp sophmate task WP-CLI commands. Feature-flagged (background_tasks) and premium-gated.

Fixed

  • Reduced 128M memory-limit pressure by deferring admin REST route and scheduler bootstrap work, lazily resolving screen assets, adding opt-in runtime memory profiling, bounding list/export/support-bundle materialization, and checkpointing background batches before memory reserve exhaustion.
Launch 1.0.0

SophMate 1.0.0 Initial Plugin Release

SophMate 1.0.0 launches the WordPress AI copilot with approvals, playbooks, WooCommerce context, analytics, privacy tools, and diagnostics.

Added

SophMate 1.0.0 is the initial WordPress plugin release. It introduces the AI Copilot for natural-language WordPress and WooCommerce work, with conversation history, optional memory, @mentions, slash commands, and fullscreen admin chat. Teams can turn recommendations into approval-based action plans with risk levels, affected records, diff previews, and audit trails before anything changes on the site.

The release also includes Knowledge Base sources, tone guidance, built-in and custom playbooks, workflows, watchers, alerts, WooCommerce analytics, KPI reporting, top performers, WooCommerce assistant operations, Marketing Studio, Theme Assistant, image generation, and support reply drafting. Operators get diagnostics, support bundles, retention controls, Safe Mode, and WP-CLI tools for setup and maintenance.

Security and privacy

Version 1.0.0 ships with encrypted provider keys, capability-based access, nonce-protected REST endpoints, audit redaction, IP hashing, PII masking, and WordPress Privacy tools integration for export and erase requests. Start with Security and Key Rotation when credentials change, and use Diagnostics and Support when collecting safe support evidence.

Requirements

SophMate requires WordPress 6.0 or higher, PHP 8.2 or higher, and the OpenSSL extension for API key encryption. WooCommerce is optional, but required for commerce-specific products, orders, coupons, customers, and analytics workflows.

Upgrade notes

This is the first tagged V1 release. New installs should follow Install SophMate, then review CodeCanyon Licensing and Updates before production rollout.

Latest tutorials

Recent SophMate guides

Pro