[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgMJd7yc7cL9LHm7mUJNivv-_f_glQZGL8kOOfAuBJTc":3},{"slug":4,"display_name":4,"profile_url":5,"plugin_count":6,"total_installs":7,"avg_security_score":8,"avg_patch_time_days":9,"trust_score":10,"computed_at":11,"plugins":12},"codevera","https:\u002F\u002Fprofiles.wordpress.org\u002Fcodevera\u002F",2,0,100,30,94,"2026-08-28T23:30:11.839Z",[13,34],{"slug":14,"name":15,"version":16,"author":4,"author_profile":5,"description":17,"short_description":18,"active_installs":7,"downloaded":19,"rating":7,"num_ratings":7,"last_updated":20,"tested_up_to":21,"requires_at_least":22,"requires_php":23,"tags":24,"homepage":30,"download_link":31,"security_score":8,"vuln_count":7,"unpatched_count":7,"last_vuln_date":32,"fetched_at":33},"codevera-ai-access-control","Codevera AI Access Control","1.1.4","\u003Cp>WordPress 7.0 introduced the Abilities API. Any active plugin can register an ability and the WordPress AI feature can then invoke it, consuming whatever credits or tokens your AI provider charges per call. By default every registered ability is exposed, and there is no built-in way to see what is exposed or to limit it.\u003C\u002Fp>\n\u003Cp>Codevera AI Access Control adds a single settings screen that lists every plugin which has registered AI abilities, grouped by source plugin, and lets you allow or block each plugin as a whole or each individual ability.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>How it works:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>The plugin watches every call to \u003Ccode>wp_register_ability()\u003C\u002Fcode> and records which plugin made the call.\u003C\u002Fli>\n\u003Cli>The Settings -> Codevera AI Access screen groups those abilities by source plugin so you can see at a glance what is exposed.\u003C\u002Fli>\n\u003Cli>Untick a plugin or a single ability and save. From the next request onwards, the AI feature can no longer see or invoke it.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>Free:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Per-plugin and per-ability granular controls\u003C\u002Fli>\n\u003Cli>Automatic detection of newly installed plugins that register AI abilities, with an in-admin notification so you can review them\u003C\u002Fli>\n\u003Cli>Tamper-detect signature on the saved settings, with a fail-closed mode that blocks every non-core ability if the settings option is modified outside the plugin\u003C\u002Fli>\n\u003Cli>Filter-level enforcement that neutralises a blocked ability before WordPress constructs it, plus a registry sweep that removes blocked abilities from the listings\u003C\u002Fli>\n\u003Cli>Self-check that re-attaches the enforcement hooks on init, admin_init and rest_api_init if another plugin removes them\u003C\u002Fli>\n\u003Cli>Search and filter inside each plugin card so large registries stay readable\u003C\u002Fli>\n\u003Cli>No external requests, no telemetry, no licence checks\u003C\u002Fli>\n\u003Cli>Works on multisite (per-site settings)\u003C\u002Fli>\n\u003Cli>Translation ready\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Works well for:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Sites where editorial staff use the WordPress AI feature and you want strict control over what context the AI can pull in\u003C\u002Fli>\n\u003Cli>Agency sites where new plugins are installed regularly and you want to review their AI exposure before letting them in\u003C\u002Fli>\n\u003Cli>Privacy-sensitive sites that need an explicit allow list of which plugins may expose data to an AI provider\u003C\u002Fli>\n\u003Cli>Compliance-driven environments that need an auditable record of which plugins have been allowed to register AI abilities\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Under the hood:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Uses only the official Abilities API surface: \u003Ccode>wp_register_ability_args\u003C\u002Fcode>, \u003Ccode>wp_abilities_api_init\u003C\u002Fcode>, \u003Ccode>wp_unregister_ability\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Source attribution from \u003Ccode>debug_backtrace()\u003C\u002Fcode> of the file that called \u003Ccode>wp_register_ability\u003C\u002Fcode>, normalised to a plugin slug\u003C\u002Fli>\n\u003Cli>HMAC-SHA256 signature on the settings option, keyed to a \u003Ccode>CVAIAC_SECRET\u003C\u002Fcode> constant or \u003Ccode>AUTH_SALT\u003C\u002Fcode> fallback\u003C\u002Fli>\n\u003Cli>No frontend assets shipped, all code runs in admin and on the AI Abilities REST routes\u003C\u002Fli>\n\u003Cli>No database tables, just two options in \u003Ccode>wp_options\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services & Privacy\u003C\u002Fh3>\n\u003Cp>This plugin does not contact any external service. It reads only local WordPress data. No telemetry, no analytics, no licence checks, no remote update checks beyond what WordPress core itself performs.\u003C\u002Fp>\n\u003Cp>The plugin stores two options in the \u003Ccode>wp_options\u003C\u002Fcode> table:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>cvaiac_settings\u003C\u002Fcode> – your allow and block selections, signed with an HMAC-SHA256 signature\u003C\u002Fli>\n\u003Cli>\u003Ccode>cvaiac_ability_sources\u003C\u002Fcode> – a map of ability name to source plugin slug, populated automatically as plugins register their abilities\u003C\u002Fli>\n\u003Cli>\u003Ccode>cvaiac_schema_version\u003C\u002Fcode> – an integer that records the storage format version, used for migration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>No personal data, no visitor data, and no AJAX requests to remote services.\u003C\u002Fp>\n\u003Cp>When the plugin is uninstalled, all three options are removed.\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>Email info@codevera.ai for support, bug reports, or feature requests. Include your WordPress version, PHP version, a list of other plugins that register AI abilities, and a description of the issue with steps to reproduce.\u003C\u002Fp>\n\u003Ch3>Technical Requirements\u003C\u002Fh3>\n\u003Cp>Minimum:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WordPress 7.0 (required for the Abilities API)\u003C\u002Fli>\n\u003Cli>PHP 7.4\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Recommended:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WordPress 7.0 or higher\u003C\u002Fli>\n\u003Cli>PHP 8.0 or higher\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Privacy & Security\u003C\u002Fh3>\n\u003Cp>The plugin does not collect or transmit any personal data. The settings option is stored locally and signed with an HMAC keyed to a site-specific secret. The source-tracker option contains only plugin slugs and ability names that are already public to any code running on the site.\u003C\u002Fp>\n\u003Cp>Form submissions use a nonce and require the \u003Ccode>manage_options\u003C\u002Fcode> capability. The enforcement hooks run on every request that loads the Abilities API, so blocking takes effect from the next request after a setting is saved.\u003C\u002Fp>\n\u003Cp>This plugin defends against opportunistic interference such as another plugin writing directly to the settings option, removing the enforcement hooks, or re-registering an ability that has already been blocked. It does not claim to be a security boundary against a fully hostile plugin that has code execution in the same PHP process. The safest practice is still to only install plugins you trust.\u003C\u002Fp>\n\u003Ch3>Links\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Website: https:\u002F\u002Fcodevera.ai\u003C\u002Fli>\n\u003Cli>Support: info@codevera.ai\u003C\u002Fli>\n\u003C\u002Ful>\n","Decide which plugins are allowed to expose their abilities to the WordPress AI feature. Block any plugin, or any single ability, with one click.",133,"2026-05-13T13:11:00.000Z","7.0.2","7.0","7.4",[25,26,27,28,29],"abilities","admin","ai","privacy","security","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcodevera-ai-access-control.1.1.4.zip",null,"2026-07-22T17:31:50.256Z",{"slug":35,"name":36,"version":37,"author":4,"author_profile":5,"description":38,"short_description":39,"active_installs":7,"downloaded":40,"rating":8,"num_ratings":41,"last_updated":42,"tested_up_to":43,"requires_at_least":44,"requires_php":23,"tags":45,"homepage":50,"download_link":51,"security_score":8,"vuln_count":7,"unpatched_count":7,"last_vuln_date":32,"fetched_at":33},"codevera-ai-content-explainer","Codevera AI Tooltip Explainer for Jargon and Confusing Terms","1.3.70","\u003Cp>Every day, visitors hit a word or concept they don’t understand and leave your site to search for it. They get distracted. They don’t come back.\u003C\u002Fp>\n\u003Cp>Codevera AI Content Explainer keeps them on the page.\u003C\u002Fp>\n\u003Cp>Highlight any text. Press explain. GPT-4.1 returns a clear, intelligent answer right there in a tooltip. No new tab. No Google. No lost reader.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>How it works:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Visitor highlights text they don’t understand\u003C\u002Fli>\n\u003Cli>An explain button appears next to the selection\u003C\u002Fli>\n\u003Cli>GPT-4.1 generates a clear explanation instantly\u003C\u002Fli>\n\u003Cli>The tooltip follows them around the page so they can keep reading\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>Free:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>OpenAI (GPT-4.1) — pre-configured and ready to go, no model selection needed\u003C\u002Fli>\n\u003Cli>Smart caching cuts API costs by up to 70%. Repeated questions cost nothing after the first request\u003C\u002Fli>\n\u003Cli>Rate limiting with separate buckets for logged-in and anonymous users\u003C\u002Fli>\n\u003Cli>Tooltip with full viewport boundary detection. It never clips off-screen\u003C\u002Fli>\n\u003Cli>Interface in 7 languages (English US\u002FUK, Spanish, German, French, Hindi, Chinese)\u003C\u002Fli>\n\u003Cli>See which terms your visitors ask about most\u003C\u002Fli>\n\u003Cli>Target specific page areas with CSS selectors. Include or exclude anything\u003C\u002Fli>\n\u003Cli>API keys encrypted and never exposed to the browser\u003C\u002Fli>\n\u003Cli>WCAG AA compliant with keyboard navigation and screen reader support\u003C\u002Fli>\n\u003Cli>GDPR compliant. Only the selected text leaves the server. Nothing is stored\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Need more? Pro plugin available separately\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A separate pro version at https:\u002F\u002Fwpaiexplainer.com\u002Fpro adds Claude and Gemini providers, bulk post scanning across your archive, full tooltip styling and an editable explanations dashboard. Pro is a separate download, not unlocked from this free plugin.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Works well for:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Technical documentation where jargon stops readers mid-article\u003C\u002Fli>\n\u003Cli>Medical or legal sites where specialist terms cost reader trust\u003C\u002Fli>\n\u003Cli>Online courses where confusion becomes drop-offs and cancellations\u003C\u002Fli>\n\u003Cli>News sites covering politics, finance, science, or law\u003C\u002Fli>\n\u003Cli>Any site where reader comprehension directly affects engagement\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Built for production:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Adds under 100ms to page load\u003C\u002Fli>\n\u003Cli>Hardened against XSS, CSRF and abuse out of the box\u003C\u002Fli>\n\u003Cli>Tested against WordPress core 5.0 and up\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services & Privacy\u003C\u002Fh3>\n\u003Cp>This plugin sends user-selected text to OpenAI to generate the explanation. No other external services are contacted by the plugin. No telemetry, no analytics, no licence checks.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>OpenAI (api.openai.com)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Privacy Policy: https:\u002F\u002Fopenai.com\u002Fprivacy\u002F\u003C\u002Fli>\n\u003Cli>Terms of Service: https:\u002F\u002Fopenai.com\u002Fterms\u002F\u003C\u002Fli>\n\u003Cli>What is sent: only the text the visitor selected\u003C\u002Fli>\n\u003Cli>Model: GPT-4.1\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>API keys are encrypted with WordPress salts and never exposed to the browser. Nothing is stored after the request completes.\u003C\u002Fp>\n\u003Cp>By using this plugin you agree to comply with OpenAI’s terms. You should let your visitors know that selected text is processed by an external AI service.\u003C\u002Fp>\n\u003Cp>If you install the separately distributed pro plugin from https:\u002F\u002Fwpaiexplainer.com\u002Fpro, additional providers (Anthropic Claude and Google Gemini) become available. Those services are documented inside the pro plugin and are not called by this free plugin.\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>Email info@codevera.ai for support, bug reports, or feature requests. Include your WordPress version, PHP version, theme name, active provider, and a description of the issue with steps to reproduce.\u003C\u002Fp>\n\u003Cp>Documentation is in the Help tab inside the plugin settings.\u003C\u002Fp>\n\u003Cp>We reply within 24-48 hours on business days.\u003C\u002Fp>\n\u003Ch3>Technical Requirements\u003C\u002Fh3>\n\u003Cp>Minimum:\u003Cbr \u002F>\n* WordPress 5.0\u003Cbr \u002F>\n* PHP 7.4\u003Cbr \u002F>\n* OpenAI API key\u003Cbr \u002F>\n* JavaScript enabled in the browser\u003C\u002Fp>\n\u003Cp>Recommended:\u003Cbr \u002F>\n* WordPress 6.0 or higher\u003Cbr \u002F>\n* PHP 8.0 or higher\u003Cbr \u002F>\n* HTTPS enabled\u003C\u002Fp>\n\u003Ch3>Privacy & Security\u003C\u002Fh3>\n\u003Cp>The plugin does not collect or store personal data. The only external request is the selected text sent to your chosen AI provider.\u003C\u002Fp>\n\u003Cp>API keys are encrypted with WordPress salts, stored in the database, and never sent to the browser. Only administrators can view or change them.\u003C\u002Fp>\n\u003Cp>No cookies. No analytics. No telemetry. AJAX requests use nonces and capability checks.\u003C\u002Fp>\n\u003Ch3>Credits\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>OpenAI, Anthropic, and Google for their APIs\u003C\u002Fli>\n\u003Cli>WordPress community for development standards and tools\u003C\u002Fli>\n\u003Cli>Beta testers for feedback during development\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Developers\u003C\u002Fh3>\n\u003Cp>The plugin dispatches three custom events on \u003Ccode>document\u003C\u002Fcode>:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>codeveraAIExpPopupOnOpen\u003C\u002Fcode> — tooltip opened\u003C\u002Fli>\n\u003Cli>\u003Ccode>codeveraAIExpPopupOnClose\u003C\u002Fcode> — tooltip closed\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ccode>codeveraAIExpExplanationLoaded\u003C\u002Fcode> — explanation rendered\u003C\u002Fp>\n\u003Cp>\u003Ccode>javascript\u003Cbr \u002F>\ndocument.addEventListener('codeveraAIExpExplanationLoaded', function(event) {\u003Cbr \u002F>\nconsole.log('Explanation loaded:', event.detail);\u003Cbr \u002F>\n});\u003C\u002Fcode>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>For hook and filter documentation, email info@codevera.ai.\u003C\u002Fp>\n\u003Ch3>Links\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Website: https:\u002F\u002Fwpaiexplainer.com\u003C\u002Fli>\n\u003Cli>Support: info@codevera.ai\u003C\u002Fli>\n\u003C\u002Ful>\n","AI tooltip plugin that turns jargon, abbreviations and confusing terms into plain English. Readers highlight any word, get an instant explanation.",563,3,"2026-05-16T19:47:00.000Z","6.9.5","5.0",[46,27,47,48,49],"accessibility","glossary","jargon","tooltip","https:\u002F\u002Fwpaiexplainer.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcodevera-ai-content-explainer.1.3.70.zip"]