[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f40qpNdChw-uamAdEOuMu2EVQ820fNSqXrdIN3u8jbzg":3,"$fd64VOIE5sTjs88sVeVSmRwCKTLG47Lk_g7vqsBB2Y74":133,"$fnbwjW_aY5Gs9GgOkE6zb_-fbp0LEsoDrSxnNh1ukywc":138},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":36,"analysis":26,"fingerprints":26},"kagivault","Kagivault","0.1.2","miya","https:\u002F\u002Fprofiles.wordpress.org\u002Fpresents111\u002F","\u003Cp>Kagivault is an encrypted vault for the \u003Cstrong>WordPress 7.0 AI Connectors API\u003C\u002Fstrong>. Out of the box, WordPress stores the API keys you configure on \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Connectors\u003C\u002Fstrong> (OpenAI, Anthropic, Google, OpenRouter, and any other AI provider registered with the AI Client) as plaintext rows in the \u003Ccode>wp_options\u003C\u002Fcode> table. Anyone with database access — backups, leaked dumps, host migration files — can read them.\u003C\u002Fp>\n\u003Cp>Kagivault wraps each AI Connectors key with \u003Cstrong>XChaCha20-Poly1305 (authenticated encryption)\u003C\u002Fstrong> and protects the data-encryption key with a \u003Cstrong>vault password derived through Argon2id\u003C\u002Fstrong>. The vault password is never persisted, and the vault automatically re-locks after a short, configurable idle timeout. Unlock from the admin UI, and the WordPress AI client transparently sees the decrypted keys — no other plugin changes required.\u003C\u002Fp>\n\u003Ch4>Highlights\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Drop-in encryption for every AI Connectors provider (\u003Ccode>connectors_ai_*_api_key\u003C\u002Fcode> rows)\u003C\u002Fli>\n\u003Cli>Vault password unlock with idle-timeout auto-lock\u003C\u002Fli>\n\u003Cli>Recovery key as a parallel unlock path\u003C\u002Fli>\n\u003Cli>Optional: link a WordPress login password so signing in automatically unlocks the vault\u003C\u002Fli>\n\u003Cli>Easy-mode initialization — no separate vault password to remember if you just want one-click setup\u003C\u002Fli>\n\u003Cli>Transparent for the core WP AI client and the Connectors admin page\u003C\u002Fli>\n\u003Cli>Versioned blob format for future cipher upgrades\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Requirements\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>WordPress 7.0 or newer (uses the Connectors API introduced in 7.0)\u003C\u002Fli>\n\u003Cli>PHP 8.3 or newer\u003C\u002Fli>\n\u003Cli>PHP sodium extension with \u003Cstrong>XChaCha20-Poly1305 AEAD\u003C\u002Fstrong> (\u003Ccode>sodium_crypto_aead_xchacha20poly1305_ietf_encrypt\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>PHP sodium extension with \u003Cstrong>Argon2id\u003C\u002Fstrong> (\u003Ccode>SODIUM_CRYPTO_PWHASH_ALG_ARGON2ID13\u003C\u002Fcode>, requires libsodium 1.0.13+)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The bundled sodium extension shipped with PHP 8.3+ on most platforms (Debian\u002FUbuntu \u003Ccode>php-sodium\u003C\u002Fcode>, RHEL \u003Ccode>php-sodium\u003C\u002Fcode>, Alpine \u003Ccode>php-sodium\u003C\u002Fcode>, Windows official builds) includes both capabilities. The plugin refuses to activate and surfaces a clear admin notice if either is unavailable.\u003C\u002Fp>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>Kagivault does NOT:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Send any data to external servers\u003C\u002Fli>\n\u003Cli>Track users\u003C\u002Fli>\n\u003Cli>Use cookies for tracking\u003C\u002Fli>\n\u003Cli>Share data with third parties\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Kagivault DOES:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Process and store encrypted API keys locally on your server (\u003Ccode>wp_options\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>Keep the data-encryption key only in a short-lived transient that expires after the configured idle timeout\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>For support, bug reports, or feature requests:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Website: https:\u002F\u002Fgithub.com\u002Fbenridane\u002Fkagivault\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Development\u003C\u002Fh3>\n\u003Cp>Development happens on GitHub. Pull requests welcome!\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Follow WordPress coding standards\u003C\u002Fli>\n\u003Cli>All code must pass \u003Ccode>wp plugin check kagivault\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n","Encrypts WordPress AI Connectors API keys (OpenAI, Anthropic, Google, OpenRouter) at rest with XChaCha20-Poly1305 + Argon2id.",0,154,"2026-06-06T11:54:00.000Z","7.0.2","7.0","8.3",[18,19,20,21,22],"ai","ai-connectors","api-keys","connectors","encryption","https:\u002F\u002Fgithub.com\u002Fbenridane\u002Fkagivault","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fkagivault.0.1.2.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},"presents111",2,30,94,"2026-08-29T13:44:10.818Z",[37,63,86,104,118],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":47,"num_ratings":48,"last_updated":49,"tested_up_to":50,"requires_at_least":51,"requires_php":16,"tags":52,"homepage":58,"download_link":59,"security_score":60,"vuln_count":61,"unpatched_count":11,"last_vuln_date":62,"fetched_at":27},"cryptx","CryptX","4.0.11","Ralf Weber","https:\u002F\u002Fprofiles.wordpress.org\u002Fd3395\u002F","\u003Cp>No more SPAM by spiders scanning your site for email addresses. With CryptX you can hide all your email addresses, with and without a mailto-link, by converting them using javascript or UNICODE.\u003C\u002Fp>\n\u003Cp>CryptX protects your email addresses from spambots while keeping them readable and functional for your visitors. The plugin automatically detects email addresses in your content and encrypts them using various methods including JavaScript encryption, Unicode conversion, and image replacement.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Automatic Email Detection\u003C\u002Fstrong> – Finds and encrypts email addresses in posts, pages, comments, and widgets\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multiple Encryption Methods\u003C\u002Fstrong> – JavaScript, Unicode, image replacement, and custom text options\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Widget Support\u003C\u002Fstrong> – Works with text widgets and other widget content\u003C\u002Fli>\n\u003Cli>\u003Cstrong>RSS Feed Control\u003C\u002Fstrong> – Option to disable encryption in RSS feeds\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Whitelist Support\u003C\u002Fstrong> – Exclude specific domains from encryption\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Per-Post Control\u003C\u002Fstrong> – Enable\u002Fdisable encryption on individual posts and pages\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Shortcode Support\u003C\u002Fstrong> – Use \u003Ccode>[cryptx]email@example.com[\u002Fcryptx]\u003C\u002Fcode> for manual encryption\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Template Functions\u003C\u002Fstrong> – Developer-friendly functions for theme integration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"http:\u002F\u002Fweber-nrw.de\u002Fwordpress\u002Fcryptx\u002F\" title=\"Plugin Homepage\" rel=\"nofollow ugc\">Plugin Homepage\u003C\u002Fa>\u003C\u002Fp>\n","No more SPAM by spiders scanning your site for email addresses!",10000,284032,88,19,"2025-12-18T08:01:00.000Z","6.9.5","6.7",[53,54,55,56,57],"antispam","email-encryption","mail","privacy","spam-protection","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcryptx\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcryptx.4.0.11.zip",99,1,"2025-12-04 20:35:36",{"slug":64,"name":65,"version":66,"author":67,"author_profile":68,"description":69,"short_description":70,"active_installs":71,"downloaded":72,"rating":73,"num_ratings":74,"last_updated":75,"tested_up_to":76,"requires_at_least":77,"requires_php":78,"tags":79,"homepage":83,"download_link":84,"security_score":85,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"wp-pgp-encrypted-emails","WP PGP Encrypted Emails","0.8.0","Meitar","https:\u002F\u002Fprofiles.wordpress.org\u002Fmeitar\u002F","\u003Cp>WP PGP Encrypted Emails can automatically sign and encrypt any email that WordPress sends to your site’s admin email address or your users’s email addresses. You give it a copy of the recipient’s OpenPGP public key and\u002For their S\u002FMIME certificate, and it does the rest. You can even automatically generate an OpenPGP signing keypair for your site to use.\u003C\u002Fp>\n\u003Cp>Encrypting outgoing emails protects your user’s privacy by ensuring that emails intended for them can be read only by them, and them alone. Moreover, signing those emails helps your users verify that email they receive purporting to be from your site was \u003Cem>actually\u003C\u002Fem> sent by your server, and not some imposter. If you’re a plugin or theme developer, you can encrypt and\u002For sign \u003Cem>arbitrary data\u003C\u002Fem> using this plugin’s OpenPGP and S\u002FMIME APIs, which are both built with familiar, standard WordPress filter hooks. This enables you to develop highly secure communication and publishing tools fully integrated with your WordPress install. See the \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ffabacab\u002Fwp-pgp-encrypted-emails\u002F#readme\" rel=\"nofollow ugc\">\u003Ccode>README.markdown\u003C\u002Fcode>\u003C\u002Fa> file for details on cryptographic implementation and API usage.\u003C\u002Fp>\n\u003Cp>\u003Cem>Donations for this and my other free software plugins make up a chunk of my income. If you continue to enjoy this plugin, please consider \u003Ca href=\"https:\u002F\u002Fwww.paypal.com\u002Fcgi-bin\u002Fwebscr?cmd=_donations&business=TJLPJYXHSRBEE&lc=US&item_name=WP%20PGP%20Encrypted%20Emails&item_number=wp-pgp-encrypted-emails&currency_code=USD&bn=PP%2dDonationsBF%3abtn_donate_SM%2egif%3aNonHosted\" rel=\"nofollow ugc\">making a donation\u003C\u002Fa>. 🙂 Thank you for your support!\u003C\u002Fem>\u003C\u002Fp>\n\u003Cp>Plugin features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Processes \u003Cem>all\u003C\u002Fem> email your site generates, automatically and transparently.\u003C\u002Fli>\n\u003Cli>Configure outbound signing: sign email sent to \u003Cem>all\u003C\u002Fem> recipients, or just savvy ones.\u003C\u002Fli>\n\u003Cli>Per-user encryption keys and certificates; user manages their own OpenPGP keys and S\u002FMIME certificates.\u003C\u002Fli>\n\u003Cli>Compatible with thousands (yes, thousands) of third-party contact form plugins.\u003C\u002Fli>\n\u003Cli>Full interoperability with all standards-compliant OpenPGP and S\u002FMIME implementations.\u003C\u002Fli>\n\u003Cli>Options to enforce further privacy best practices (e.g., removing \u003Ccode>Subject\u003C\u002Fcode> lines).\u003C\u002Fli>\n\u003Cli>Fully multisite compatible, out of the box. No additional configuration for large networks!\u003C\u002Fli>\n\u003Cli>No binaries to install or configure; everything you need is in the plugin itself.\u003C\u002Fli>\n\u003Cli>Bells and whistles included! For instance, visitors can encrypt comments on posts so only the author can read them.\u003C\u002Fli>\n\u003Cli>Built-in, customizable integration with popular third-party plugins, such as \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwoocommerce\u002F\" rel=\"ugc\">WooCommerce\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>Always \u003Cstrong>FREE\u003C\u002Fstrong>. Replaces paid email encryption “upgrades,” and gets rid of yearly subscription fees. (\u003Ca href=\"https:\u002F\u002Fwww.paypal.com\u002Fcgi-bin\u002Fwebscr?cmd=_donations&business=TJLPJYXHSRBEE&lc=US&item_name=WP%20PGP%20Encrypted%20Emails&item_number=wp-pgp-encrypted-emails&currency_code=USD&bn=PP%2dDonationsBF%3abtn_donate_SM%2egif%3aNonHosted\" rel=\"nofollow ugc\">Donations\u003C\u002Fa> appreciated!)\u003C\u002Fli>\n\u003Cli>And \u003Cem>more\u003C\u002Fem>, of course. 😉\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin works transparently for \u003Cem>all email\u003C\u002Fem> your site generates, and will also sign and encrypt outgoing email generated by other plugins (such as contact form plugins) or the built-in WordPress notification emails. All you have to do is add one or more OpenPGP keys or an S\u002FMIME certificate to the Email Encryption screen (WordPress Admin Dashboard &rarr; Settings &rarr; Email Encryption). Each user can opt to also remove envelope information such as email subject lines, which encryption schemes cannot protect. With this plugin, there’s no longer any need to pay for the “pro” version of your favorite contact form plugin to get the benefit of email privacy.\u003C\u002Fp>\n\u003Cp>Each of your site’s users can supply their own, personal OpenPGP public key and\u002For X.509 S\u002FMIME certificate for their own email address to have WordPress automatically encrypt any email destined for them. (They merely need to update their user profile.) They can choose which encryption method to use. Once set up, all future emails WordPress sends to that user will be encrypted using the standards-based OpenPGP or S\u002FMIME technologies.\u003C\u002Fp>\n\u003Cp>The OpenPGP-encrypted emails can be decrypted by any OpenPGP-compatible mail client, such as \u003Ca href=\"https:\u002F\u002Fgpgtools.org\u002F\" rel=\"nofollow ugc\">MacGPG\u003C\u002Fa> (macOS), \u003Ca href=\"https:\u002F\u002Fwww.gpg4win.org\u002F\" rel=\"nofollow ugc\">GPG4Win\u003C\u002Fa> (Windows), \u003Ca href=\"https:\u002F\u002Fwww.enigmail.net\u002F\" rel=\"nofollow ugc\">Enigmail\u003C\u002Fa> (cross-platform), \u003Ca href=\"https:\u002F\u002Fopenkeychain.org\u002F\" rel=\"nofollow ugc\">OpenKeychain\u003C\u002Fa> (Android), or \u003Ca href=\"https:\u002F\u002Fipgmail.com\u002F\" rel=\"nofollow ugc\">iPGMail\u003C\u002Fa> (iPhone\u002FiOS). For more information on reading encrypted emails, generating keys, and other uses for OpenPGP-compatible encryption, consult any (or all!) of the following guides:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fssd.eff.org\u002Fen\u002Fmodule\u002Fintroduction-public-key-cryptography-and-pgp\" rel=\"nofollow ugc\">The Electronic Frontier Foundation’s Surveillance Self-Defense guide to PGP\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fhelp.riseup.net\u002Fen\u002Fgpg-best-practices\" rel=\"nofollow ugc\">RiseUp.net’s OpenPGP best practices guide\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.openpgp.org\u002F\" rel=\"nofollow ugc\">OpenPGP.org\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The S\u002FMIME-encrypted emails can be decrypted by any S\u002FMIME-compatible mail client. These include \u003Ca href=\"http:\u002F\u002Fsiber-sonic.com\u002Fmac\u002FMailSMIME\u002F\" rel=\"nofollow ugc\">Apple’s Mail on macOS\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fsupport.apple.com\u002Fen-au\u002FHT202345\" rel=\"nofollow ugc\">iOS for iPhone and iPad\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fsupport.office.com\u002Fen-us\u002Farticle\u002FEncrypt-messages-by-using-S-MIME-in-Outlook-Web-App-2E57E4BD-4CC2-4531-9A39-426E7C873E26\" rel=\"nofollow ugc\">Microsoft Outlook\u003C\u002Fa>, \u003Ca href=\"http:\u002F\u002Fwww.claws-mail.org\u002Ffaq\u002Findex.php\u002FS\u002FMIME_howto\" rel=\"nofollow ugc\">Claws Mail for GNU\u002FLinux\u003C\u002Fa>, and more.\u003C\u002Fp>\n\u003Cp>For developers, WP PGP Encrypted Emails provides \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ffabacab\u002Fwp-pgp-encrypted-emails\u002Fblob\u002Fdevelop\u002FREADME.markdown#openpgp-api\" rel=\"nofollow ugc\">an easy to use API to both OpenPGP\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ffabacab\u002Fwp-pgp-encrypted-emails\u002Fblob\u002Fdevelop\u002FREADME.markdown#smime-api\" rel=\"nofollow ugc\">S\u002FMIME\u003C\u002Fa> encryption, decryption, and integrity validation operations through the familiar \u003Ca href=\"https:\u002F\u002Fcodex.wordpress.org\u002FPlugin_API\" rel=\"nofollow ugc\">WordPress plugin API\u003C\u002Fa> so you can use this plugin’s simple filter hooks to build custom OpenPGP- or S\u002FMIME-based encryption functionality into your own plugins and themes.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Disclaimer\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Security is a process, not a product. Using WP PGP Encrypted Emails does not guarantee that your site’s outgoing messages are invulnerable to every attacker, in every possible scenario, at all times. No single security measure, in isolation, can do that.\u003C\u002Fp>\n\u003Cp>Do not rely solely on this plugin for the security or privacy of your webserver. See the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwp-pgp-encrypted-emails\u002Ffaq\u002F\" rel=\"ugc\">Frequently Asked Questions\u003C\u002Fa> for more security advice and for more information about the rationale for this plugin.\u003Cbr \u002F>\nIf you like this plugin, \u003Cstrong>please consider \u003Ca href=\"https:\u002F\u002Fwww.paypal.com\u002Fcgi-bin\u002Fwebscr?cmd=_donations&business=TJLPJYXHSRBEE&lc=US&item_name=WP%20PGP%20Encrypted%20Emails&item_number=wp-pgp-encrypted-emails&currency_code=USD&bn=PP%2dDonationsBF%3abtn_donate_SM%2egif%3aNonHosted\" rel=\"nofollow ugc\">making a donation\u003C\u002Fa> for your use of the plugin\u003C\u002Fstrong> or, better yet, contributing directly to \u003Ca href=\"http:\u002F\u002FCyberbusking.org\u002F\" rel=\"nofollow ugc\">my Cyberbusking fund\u003C\u002Fa>. Your support is appreciated!\u003C\u002Fp>\n\u003Ch4>Themeing\u003C\u002Fh4>\n\u003Cp>Theme authors can use the following code snippets to integrate a WordPress theme with this plugin.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>To link to a site’s OpenPGP signing public key: \u003Ccode>\u003C?php print admin_url( 'admin-ajax.php?action=download_pgp_signing_public_key' ); ?>\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Plugin hooks\u003C\u002Fh4>\n\u003Cp>This plugin offers additional functionality intended for other plugin developers or theme authors to make use of. This functionality is documented here.\u003C\u002Fp>\n\u003Ch3>Filters\u003C\u002Fh3>\n\u003Ch4>`wp_user_encryption_method`\u003C\u002Fh4>\n\u003Cp>Gets the user’s preferred encryption method (either \u003Ccode>pgp\u003C\u002Fcode> or \u003Ccode>smime\u003C\u002Fcode>), if they have provided both an OpenPGP public key and an S\u002FMIME certificate.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Optional arguments:\n\u003Cul>\n\u003Cli>\u003Ccode>WP_User\u003C\u002Fcode> \u003Ccode>$user\u003C\u002Fcode> – The WordPress user object. Defaults to the current user.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>`wp_openpgp_user_key`\u003C\u002Fh4>\n\u003Cp>Gets the user’s saved OpenPGP public key from their WordPress profile data, immediately usable in other \u003Ccode>openpgp_*\u003C\u002Fcode> filters.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Optional arguments:\n\u003Cul>\n\u003Cli>\u003Ccode>WP_User\u003C\u002Fcode> \u003Ccode>$user\u003C\u002Fcode> – The WordPress user object. Defaults to the current user.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>`openpgp_enarmor`\u003C\u002Fh4>\n\u003Cp>Gets an ASCII-armored representation of an OpenPGP data structure (like a key, or an encrypted message).\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Required parameters:\n\u003Cul>\n\u003Cli>\u003Ccode>string\u003C\u002Fcode> \u003Ccode>$data\u003C\u002Fcode> – The data to be armored.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>Optional parameters:\n\u003Cul>\n\u003Cli>\u003Ccode>string\u003C\u002Fcode> \u003Ccode>$marker\u003C\u002Fcode> – The marker of the block (the text that follows \u003Ccode>-----BEGIN\u003C\u002Fcode>). Defaults to \u003Ccode>MESSAGE\u003C\u002Fcode>, but you should set this to a more appropriate value. If you are armoring a PGP public key, for instance, set this to \u003Ccode>PGP PUBLIC KEY BLOCK\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Ccode>string[]\u003C\u002Fcode> \u003Ccode>$headers\u003C\u002Fcode> – An array of strings to apply as headers to the ASCII-armored block, usually used to insert comments or identify the OpenPGP client used. Defaults to \u003Ccode>array()\u003C\u002Fcode> (no headers).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Example: ASCII-armor a binary public key.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>$ascii_key = apply_filters('openpgp_enarmor', $public_key, 'PGP PUBLIC KEY BLOCK');\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>`openpgp_key`\u003C\u002Fh4>\n\u003Cp>Gets a binary OpenPGP public key for use in later PGP operations from an ASCII-armored representation of that key.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Required parameters:\n\u003Cul>\n\u003Cli>\u003Ccode>string\u003C\u002Fcode> \u003Ccode>$key\u003C\u002Fcode> – The ASCII-armored PGP public key block.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Example: Get a key saved as an ASCII string in the WordPress database option \u003Ccode>my_plugin_pgp_public_key\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>$key = apply_filters('openpgp_key', get_option('my_plugin_pgp_public_key'));\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>`openpgp_sign`\u003C\u002Fh4>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.gnupg.org\u002Fgph\u002Fen\u002Fmanual\u002Fx135.html#AEN152\" rel=\"nofollow ugc\">Clearsigns\u003C\u002Fa> a message using a given private key.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Required parameters:\n\u003Cul>\n\u003Cli>\u003Ccode>string\u003C\u002Fcode> \u003Ccode>$data\u003C\u002Fcode> – The message data to sign.\u003C\u002Fli>\n\u003Cli>\u003Ccode>OpenPGP_SecretKeyPacket\u003C\u002Fcode> \u003Ccode>$signing_key\u003C\u002Fcode> – The signing key to use, obtained by passing the ASCII-armored private key through the \u003Ccode>openpgp_key\u003C\u002Fcode> filter.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Example: Sign a short string.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>$message = 'This is a message to sign.';\n$signing_key = apply_filters('openpgp_key', $ascii_key);\n$signed_message = apply_filters('openpgp_sign', $message, $signing_key);\n\u002F\u002F $signed_message is now a clearsigned message\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>`openpgp_encrypt`\u003C\u002Fh4>\n\u003Cp>Encrypts data to one or more PGP public keys or passphrases.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Required arguments:\n\u003Cul>\n\u003Cli>\u003Ccode>string\u003C\u002Fcode> \u003Ccode>$data\u003C\u002Fcode> – Data to encrypt.\u003C\u002Fli>\n\u003Cli>\u003Ccode>array|string\u003C\u002Fcode> \u003Ccode>$keys\u003C\u002Fcode> – Passphrases or keys to use to encrypt the data.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Example: Encrypt the content of a blog post.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>\u002F\u002F First, get the PGP public key(s) of the recipient(s)\n$ascii_key = '-----BEGIN PGP PUBLIC KEY BLOCK-----\n[...snipped for length...]\n-----END PGP PUBLIC KEY BLOCK-----';\n$encryption_key = apply_filters('openpgp_key', $ascii_key);\n$encrypted_post = apply_filters('openpgp_encrypt', $post->post_content, $encryption_key);\n\u002F\u002F Now you can safely send or display $encrypted_post anywhere you like and only\n\u002F\u002F those who control the corresponding private key(s) can decrypt it.\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>`openpgp_sign`\u003C\u002Fh4>\n\u003Cp>Signs a message (arbitrary data) with the given private key.\u003C\u002Fp>\n\u003Cp>Note that if your plugin uses the built-in WordPress core \u003Ccode>wp_mail()\u003C\u002Fcode> function and this plugin is active, your plugin’s outgoing emails are already automatically signed so you do not need to do anything. This filter is intended for use by plugin developers who want to create custom, trusted communiques between WordPress and some other system.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Required arguments:\n\u003Cul>\n\u003Cli>\u003Ccode>string\u003C\u002Fcode> \u003Ccode>$data\u003C\u002Fcode> – The data to sign.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>Optional arguments:\n\u003Cul>\n\u003Cli>\u003Ccode>OpenPGP_SecretKeyPacket\u003C\u002Fcode> \u003Ccode>$privatekey\u003C\u002Fcode> – The private key used for signing the message. The default is to use the private key automatically generated during plugin activation. The automatically generated keypair is intended to be a low-trust, single-purpose keypair for your website itself, so you probably do not need or want to use this argument yourself.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Example: Send a signed, encrypted JSON payload to a remote, insecure server.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>$comment_data = get_comment(2); \u002F\u002F get a WP_Comment object with comment ID 2\n\u002F\u002F Create JSON payload\n$json = array('success' => true, 'action' => 'new_comment', 'data' => $comment_data);\n$url = 'http:\u002F\u002Finsecure.example.com\u002F';\n$response = wp_safe_remote_post($url, array(\n));\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>`openpgp_sign_and_encrypt`\u003C\u002Fh4>\n\u003Cp>A convenience filter that applies \u003Ccode>openpgp_sign\u003C\u002Fcode> and then \u003Ccode>openpgp_encrypt\u003C\u002Fcode> to the result.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Required arguments:\n\u003Cul>\n\u003Cli>\u003Ccode>string\u003C\u002Fcode> \u003Ccode>$data\u003C\u002Fcode> – The data to sign and encrypt.\u003C\u002Fli>\n\u003Cli>\u003Ccode>string\u003C\u002Fcode> \u003Ccode>$signing_key\u003C\u002Fcode> – The signing key to use.\u003C\u002Fli>\n\u003Cli>\u003Ccode>array|string\u003C\u002Fcode> \u003Ccode>$recipient_keys_and_passphrases\u003C\u002Fcode> – Public key(s) of the recipient(s), or passphrases to encrypt to.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>`wp_openpgp_user_key`\u003C\u002Fh4>\n\u003Cp>Gets the user’s saved S\u002FMIME public certificate from their WordPress profile data, immediately usable in other \u003Ccode>smime_*\u003C\u002Fcode> filters.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Optional arguments:\n\u003Cul>\n\u003Cli>\u003Ccode>WP_User\u003C\u002Fcode> \u003Ccode>$user\u003C\u002Fcode> – The WordPress user object. Defaults to the current user.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>`smime_certificate`\u003C\u002Fh4>\n\u003Cp>Gets a PHP resource handle to an X.509 Certificate.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Required arguments:\n\u003Cul>\n\u003Cli>\u003Ccode>mixed\u003C\u002Fcode> \u003Ccode>$cert\u003C\u002Fcode> – The certificate, either as a string to a file, or raw PEM-encoded certificate data.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>`smime_certificate_pem_encode`\u003C\u002Fh4>\n\u003Cp>Encodes (“exports”) a given X.509 certificate as PEM format.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Required arguments:\n\u003Cul>\n\u003Cli>\u003Ccode>resource\u003C\u002Fcode> \u003Ccode>$cert\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>`smime_encrypt`\u003C\u002Fh4>\n\u003Cp>Encrypts a message as an S\u002FMIME email given a public certificate.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Required arguments:\n\u003Cul>\n\u003Cli>\u003Ccode>string\u003C\u002Fcode> \u003Ccode>$message\u003C\u002Fcode> – The message contents to encrypt.\u003C\u002Fli>\n\u003Cli>\u003Ccode>string|string[]\u003C\u002Fcode> \u003Ccode>$headers\u003C\u002Fcode> – The message headers for the encrypted part.\u003C\u002Fli>\n\u003Cli>\u003Ccode>resource|array\u003C\u002Fcode> \u003Ccode>$certificates\u003C\u002Fcode> – The recipient’s certificate, or an array of recipient certificates.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This filter returns an array with two keys, \u003Ccode>headers\u003C\u002Fcode> and \u003Ccode>message\u003C\u002Fcode>, wherein the message is encrypted.\u003C\u002Fp>\n\u003Cp>Example: send an encrypted email via \u003Ccode>wp_mail()\u003C\u002Fcode>. (You do not need to do this if the recipient is registered as your site’s user, because this plugin does that automatically. Only do this if you need to send S\u002FMIME encrypted email to an address not stored in WordPress’s own database.)\u003C\u002Fp>\n\u003Cpre>\u003Ccode>$cert = apply_filters( 'smime_certificate', get_option( 'my_plugin_smime_certificate' ) );\n$body = 'This is a test email message body.';\n$head = array(\n    'From' => get_option( 'admin_email' ),\n);\n$smime_data = apply_filters( 'smime_encrypt', $body, $head, $cert );\nif ( $smime_data ) {\n    wp_mail(\n        'recipient@example.com',\n        'Test message.',\n        $smime_data['message'], \u002F\u002F message is sent encrypted\n        $smime_data['headers']\n    );\n}\n\u003C\u002Fcode>\u003C\u002Fpre>\n","Signs and encrypts emails using PGP\u002FGPG keys or X.509 certificates. Provides OpenPGP and S\u002FMIME functions via WordPress plugin API.",400,26718,92,16,"2021-05-25T19:04:00.000Z","5.7.15","4.4","",[80,22,81,56,82],"email","pgp","security","https:\u002F\u002Fgithub.com\u002Ffabacab\u002Fwp-pgp-encrypted-emails","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-pgp-encrypted-emails.0.8.0.zip",85,{"slug":87,"name":88,"version":89,"author":90,"author_profile":91,"description":92,"short_description":93,"active_installs":94,"downloaded":95,"rating":25,"num_ratings":61,"last_updated":96,"tested_up_to":14,"requires_at_least":97,"requires_php":98,"tags":99,"homepage":78,"download_link":103,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"email-no-bot","Email No Bot – Prevent bots from detecting emails","0.0.3","Jose Mortellaro","https:\u002F\u002Fprofiles.wordpress.org\u002Fgiuse\u002F","\u003Cp>With Email No Bot humans will see the emails that you write using the \u003Ca href=\"https:\u002F\u002Fcodex.wordpress.org\u002FShortcode\" rel=\"nofollow ugc\">shortcode\u003C\u002Fa> [hide_email email=”example@mail.com”], but robots will not.\u003C\u002Fp>\n\u003Cp>The user will not be able to copy the email in the clipboard. If you think this is a problem, this plugin is not for you.\u003C\u002Fp>\n\u003Cp>Looking at the screen you can see the email, but if you inspect elements, instead of the email you will see something strange, and not predictable. That’s what a bot will also see.\u003C\u002Fp>\n\u003Cp>The output is something very random for the bot, and even if the code of this plugin is open source, no bot will be able to decrypt the email.\u003C\u002Fp>\n\u003Cp>There are amazing plugins for contact forms, but sometimes what you really need is just an email that people can use to contact you.\u003Cbr \u002F>\nContact forms are so popular because a bot will not be able to get your email, but if you have a way to prevent bots from getting your email, you can simply add it to your page without the need of a contact form. Your page will be lighter and simple.\u003C\u002Fp>\n\u003Cp>Email No Bot has no settings page, it doesn’t write anything in the database, and it doesn’t load any asset on frontend, it just provides a shortcode, that’s it.\u003C\u002Fp>\n\u003Ch3>How to encrypt an email with Email No Bot\u003C\u002Fh3>\n\u003Cp>To encrypt an email use the shortcode \u003Cstrong>[hide_email email=”example@mail.com”]\u003C\u002Fstrong>.\u003Cbr \u002F>\nOf course, replace example@mail.com with the email that you want to display.\u003Cbr \u002F>\nYou can see an example and see how it works on the blog post \u003Ca href=\"https:\u002F\u002Fjosemortellaro.com\u002Fprevent-bots-from-getting-emails-from-your-website\u002F\" rel=\"nofollow ugc\">Prevent bots from getting emais from your website\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Main features of Email No Bot\u003C\u002Fh3>\n\u003Cp>It obfuscate emails with 52 lines of code! The entire zip is less than 3 kB. No complicated settings, no database queries, no assets, nothing else than a shortcode. You will have no spam at zero cost in terms of performance. The weight of this plugin similar to the weight of \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fhello-dolly\u002F\" rel=\"ugc\">Hello Dolly\u003C\u002Fa>.\u003Cbr \u002F>\nYou can see here the \u003Ca href=\"https:\u002F\u002Fplugintests.com\u002Fplugins\u002Fwporg\u002Femail-no-bot\u002Flatest\" rel=\"nofollow ugc\">consumption of Email No Bot\u003C\u002Fa>. As you will see it’s not measurable.\u003C\u002Fp>\n\u003Ch3>Limitations of Email No Bot\u003C\u002Fh3>\n\u003Cp>The user will not be able to copy the email in the clipboard. But this is also what makes this plugin so powerful against spam bots.\u003C\u002Fp>\n\u003Ch3>Similar plugin to hide links\u003C\u002Fh3>\n\u003Cp>If you need something similar to hide links, you can try \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fhide-link\u002F\" rel=\"ugc\">Hide Link\u003C\u002Fa>\u003C\u002Fp>\n","Humans will see the email address on your page, but robots will not.",200,6774,"2026-05-21T09:09:00.000Z","4.6","7.4",[54,100,101,102,57],"email-obfuscation","no-bot","spam-email","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Femail-no-bot.0.0.3.zip",{"slug":105,"name":106,"version":107,"author":108,"author_profile":109,"description":110,"short_description":111,"active_installs":25,"downloaded":112,"rating":11,"num_ratings":11,"last_updated":113,"tested_up_to":14,"requires_at_least":15,"requires_php":114,"tags":115,"homepage":78,"download_link":117,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"disable-ai-for-security","Disable AI for Security","1.3.0","WPChef","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpchefgadget\u002F","\u003Cp>\u003Cstrong>Disable AI for Security\u003C\u002Fstrong> switches off the AI features introduced in WordPress 7.0 — quickly, cleanly, and without a single setting to configure.\u003C\u002Fp>\n\u003Cp>WordPress 7.0 introduces built-in AI connectors. They’re a great addition, but not every site needs them. If you prefer to keep your site lean and predictable, or your organization’s policy is to keep AI features off, this plugin gives you a simple one-click way to do exactly that.\u003C\u002Fp>\n\u003Cp>Just activate it. That’s it. There is no settings page, no configuration, and nothing to maintain — the plugin starts protecting your site the moment it’s enabled.\u003C\u002Fp>\n\u003Ch4>What it does\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Disables WordPress AI at the core level.\u003C\u002Fstrong> Core stops registering AI providers, rejects AI connectors, and won’t run AI prompts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Works for every role.\u003C\u002Fstrong> AI is turned off site-wide — for administrators, editors, authors, and everyone else. No exceptions, no per-user toggles.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hides the AI admin screens.\u003C\u002Fstrong> The Connectors and AI settings pages are removed from wp-admin, and direct links to them are blocked.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Shows a clear status badge.\u003C\u002Fstrong> A small green “AI Disabled” badge in the admin bar confirms protection is active.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why you’ll like it\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Zero configuration.\u003C\u002Fstrong> No setup, no options, no learning curve.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Works out of the box.\u003C\u002Fstrong> Protection is on the instant you activate.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight and focused.\u003C\u002Fstrong> It does one job and does it well.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Brought to you by the team behind \u003Cstrong>Limit Login Attempts Reloaded\u003C\u002Fstrong>.\u003C\u002Fp>\n","Turns off the WordPress AI connectors for security. Works instantly with no settings — AI is fully disabled for every user role.",287,"2026-06-17T07:48:00.000Z","7.2",[18,21,116,56,82],"disable-ai","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdisable-ai-for-security.1.3.0.zip",{"slug":119,"name":120,"version":121,"author":122,"author_profile":123,"description":124,"short_description":125,"active_installs":11,"downloaded":126,"rating":11,"num_ratings":11,"last_updated":127,"tested_up_to":14,"requires_at_least":15,"requires_php":98,"tags":128,"homepage":78,"download_link":132,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"chagency","Chagency","0.0.4","Jordy Meow","https:\u002F\u002Fprofiles.wordpress.org\u002Ftigroumeow\u002F","\u003Cp>\u003Cstrong>Chagency\u003C\u002Fstrong> is the first chatbot to ship directly on top of the new AI Client introduced in WordPress 7.0 — \u003Ccode>wp_ai_client_prompt()\u003C\u002Fcode>, Connectors, and the Abilities API. Every prompt flows through WordPress core, every provider is a Connector you already configured under \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Connectors\u003C\u002Fstrong>, and every action it exposes is a registered Ability that other plugins (and other AI agents) can call.\u003C\u002Fp>\n\u003Cp>There is no other plugin on wordpress.org that builds on \u003Ccode>wp_ai_client_prompt()\u003C\u002Fcode> today. Chagency is the reference case: a small, native chatbot that proves the framework works, ships zero vendor SDKs, and grows alongside the Abilities API into a real agent.\u003C\u002Fp>\n\u003Cp>It runs in the WordPress admin and, when you turn it on, on every page of your public site. The name (chat + ai + ency) is meant as a small bridge between the new AI primitives shipped with WordPress and the broader world of chat and agents. It starts as a chatbot today and turns into an agent tomorrow, without a rename.\u003C\u002Fp>\n\u003Ch3>🪨 Built on WordPress, period\u003C\u002Fh3>\n\u003Cp>Chagency relies entirely on what WordPress 7 ships in core:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>wp_ai_client_prompt()\u003C\u002Fcode>, the AI Client API.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wp_get_connectors()\u003C\u002Fcode>, the Connectors API.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wp_register_ability()\u003C\u002Fcode> \u002F \u003Ccode>wp_get_ability()\u003C\u002Fcode>, the Abilities API.\u003C\u002Fli>\n\u003Cli>\u003Ccode>@wordpress\u002Fcomponents\u003C\u002Fcode>, \u003Ccode>@wordpress\u002Felement\u003C\u002Fcode>, \u003Ccode>@wordpress\u002Fboot\u003C\u002Fcode>, the Gutenberg toolkit.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>That is the entire dependency surface. \u003Cstrong>No bundled AI vendor SDKs, no third-party JavaScript libraries beyond the Gutenberg stack, no telemetry, no phone-home.\u003C\u002Fstrong> The plugin stays small on purpose: fewer moving parts means less friction, fewer security holes, less to break when WordPress, browsers, or providers change.\u003C\u002Fp>\n\u003Cp>You will need at least one AI provider plugin (e.g. \u003Cem>AI Provider for Anthropic\u003C\u002Fem>, \u003Cem>AI Provider for Google\u003C\u002Fem>, \u003Cem>AI Provider for OpenAI\u003C\u002Fem>) to talk to a model. That is WordPress 7’s architecture: providers are separate plugins that register a Connector. They are not a Chagency dependency.\u003C\u002Fp>\n\u003Cp>💡 \u003Cstrong>Tip:\u003C\u002Fstrong> For the smoothest setup, install \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fai-engine\u002F\" rel=\"ugc\">AI Engine\u003C\u002Fa>. It registers every AI provider it manages as a Connector, so a single configuration covers all your WordPress 7 AI plugins (including Chagency). Every request then flows through one clean, unified system.\u003C\u002Fp>\n\u003Ch3>🪄 What you get\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>A floating chat panel pinned to the bottom-right of every page (admin and \u002F or public site, controlled by two independent toggles).\u003C\u002Fli>\n\u003Cli>A single settings page under \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Chagency\u003C\u002Fstrong>, with the bare minimum: where to show the chatbot, the chat title, the greeting, the system instruction, and the model preference.\u003C\u002Fli>\n\u003Cli>Live updates: flipping a toggle in Settings shows or hides the launcher immediately on the same page, no reload needed.\u003C\u002Fli>\n\u003Cli>Per-provider \u003Cstrong>Test\u003C\u002Fstrong> buttons that fire a canary prompt and report round-trip time.\u003C\u002Fli>\n\u003Cli>Conversation persistence in your browser’s localStorage, scoped per user.\u003C\u002Fli>\n\u003Cli>Placeholder expansion (\u003Ccode>{user_name}\u003C\u002Fcode>, \u003Ccode>{site_name}\u003C\u002Fcode>, \u003Ccode>{current_page}\u003C\u002Fcode>, \u003Ccode>{current_url}\u003C\u002Fcode>, \u003Ccode>{user_role}\u003C\u002Fcode>, \u003Ccode>{site_url}\u003C\u002Fcode>) so the assistant always knows who and where it is.\u003C\u002Fli>\n\u003Cli>Exposed as an Ability (\u003Ccode>chagency\u002Fsend-message\u003C\u002Fcode>) so other plugins, MCP clients, and AI agents can invoke Chagency directly.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🚀 Getting started\u003C\u002Fh3>\n\u003Col>\n\u003Cli>Install and activate \u003Cstrong>Chagency\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Install and configure at least one AI provider plugin under \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Connectors\u003C\u002Fstrong> (we recommend \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fai-engine\u002F\" rel=\"ugc\">AI Engine\u003C\u002Fa>, which exposes all its providers as Connectors at once).\u003C\u002Fli>\n\u003Cli>Click the chat launcher in the bottom-right of any admin page and start talking.\u003C\u002Fli>\n\u003Cli>Want it on the public site too? Open \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Chagency\u003C\u002Fstrong> and flip the second toggle.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>🙋 Frequently Asked Questions\u003C\u002Fh3>\n\u003Ch4>Why “Chagency”?\u003C\u002Fh4>\n\u003Cp>It’s a portmanteau of \u003Cem>chat\u003C\u002Fem>, \u003Cem>AI\u003C\u002Fem>, and a bit of \u003Cem>agent\u003C\u002Fem>. Not “agency” in the sense of a marketing shop. The plugin starts as a minimal chatbot for the new WordPress 7 AI framework and grows alongside the Abilities API into a true agent.\u003C\u002Fp>\n\u003Ch4>Does it need WordPress 7?\u003C\u002Fh4>\n\u003Cp>Yes. It uses \u003Ccode>wp_ai_client_prompt()\u003C\u002Fcode>, \u003Ccode>wp_get_connectors()\u003C\u002Fcode>, and the Abilities API, all added in WordPress 7.0. On older versions it refuses to boot and tells you why.\u003C\u002Fp>\n\u003Ch4>Which AI providers are supported?\u003C\u002Fh4>\n\u003Cp>Whatever you configure under \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Connectors\u003C\u002Fstrong>. Chagency is provider-agnostic. Anthropic, Google, OpenAI, or any third-party Connector are treated equally.\u003C\u002Fp>\n\u003Ch4>Can visitors on the front end use it?\u003C\u002Fh4>\n\u003Cp>Yes. Open \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Chagency\u003C\u002Fstrong> and turn on \u003Cem>Show on the public site\u003C\u002Fem>. The chat then appears for every visitor, signed in or not.\u003C\u002Fp>\n\u003Ch4>Does it store my conversations?\u003C\u002Fh4>\n\u003Cp>No. Conversations live only in your own browser (localStorage, per user). Hit \u003Cem>Reset\u003C\u002Fem> in the panel to clear them. Nothing is stored server-side.\u003C\u002Fp>\n\u003Ch4>Can I use it as a building block in my own plugin?\u003C\u002Fh4>\n\u003Cp>Yes. The \u003Ccode>chagency\u002Fsend-message\u003C\u002Fcode> Ability is registered on \u003Ccode>wp_abilities_api_init\u003C\u002Fcode> and can be called with \u003Ccode>wp_get_ability( 'chagency\u002Fsend-message' )->execute( array( 'message' => '...' ) )\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Ch3>Source code\u003C\u002Fh3>\n\u003Cp>The unminified React \u002F JavaScript source is shipped inside the plugin folder under \u003Ccode>src\u002F\u003C\u002Fcode>, alongside the compiled output in \u003Ccode>build\u002F\u003C\u002Fcode>. Public source repository: https:\u002F\u002Fgithub.com\u002Fjordymeow\u002Fchagency\u003C\u002Fp>\n\u003Cp>To rebuild from source:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>pnpm install && pnpm run build\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The build is \u003Ccode>@wordpress\u002Fscripts\u003C\u002Fcode> (webpack) with no custom plugins or transforms.\u003C\u002Fp>\n","The first chatbot built natively on the WordPress 7 AI Client. No bundled SDKs, no third-party JavaScript, no telemetry.",334,"2026-06-03T01:20:00.000Z",[129,130,18,131,21],"abilities","agent","chatbot","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fchagency.0.0.4.zip",{"error":134,"url":135,"statusCode":136,"statusMessage":137,"message":137},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fkagivault\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":32,"versions":139},[140,146],{"version":6,"download_url":24,"svn_tag_url":141,"released_at":26,"has_diff":142,"diff_files_changed":143,"diff_lines":26,"trac_diff_url":144,"vulnerabilities":145,"is_current":134},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fkagivault\u002Ftags\u002F0.1.2\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fkagivault%2Ftags%2F0.1.1&new_path=%2Fkagivault%2Ftags%2F0.1.2",[],{"version":147,"download_url":148,"svn_tag_url":149,"released_at":26,"has_diff":142,"diff_files_changed":150,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":151,"is_current":142},"0.1.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fkagivault.0.1.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fkagivault\u002Ftags\u002F0.1.1\u002F",[],[]]