The website documents 7.3.4. The WordPress.org release is pending.
7.3.4
- Fixed cross-site origin caching for
/ai-discoverywithout changing its public URL.
7.3.3
- Added an ownership-safe
/ai-discoveryfallback for origins with unpurgeable path caches.
7.3.2
- Isolated APCu and shared object-cache entries across independent WordPress installations.
7.3.1
- Fixed the Advanced Cloudflare eligibility control fatal and confirmation-row visibility.
7.3.0
- Added opt-in, expiring redacted diagnostics/support bundles; renamed System Status to Debugging.
7.2.2
- Disabled Cloudflare mutations when proxy traffic is not detected, with an exact-host, page-scoped manual confirmation for advanced deployments.
7.2.1
- Fixed recoverable OAuth completion, canonical rule paths, and automatic browser-visible verification with per-resource diagnostics.
- Added Cloudflare execution proof and complete OAuth metadata cache bypass.
7.2.0
- Added public Cloudflare OAuth with PKCE, account consent, automatic combined rule installation, immediate token revocation, and no stored credential.
- Added a bounded open-source callback relay, ambiguity-safe zone selection, OAuth lifecycle status, and a one-time-token fallback.
- Added self-managed Cloudflare OAuth for organizations that want the callback, PKCE transaction, code exchange, and token revocation to remain on WordPress.
7.1.0
- Added System Status with stack detection and explicit optimization-utilization evidence.
- Added one-time-token Cloudflare header and cache-safety automation plus default-on LiteSpeed and APCu controls.
- Unified edge diagnostics with the static publication header contract and added scoped Cybermaps-only cache invalidation.
7.0.1
- Added ownership-safe
.well-knownfallbacks with explicit conformance status. - Unified OAuth metadata, bounded LLMS scans, and fixed duplicate-header diagnostics.
7.0.0
- Raised the minimum to WordPress 7.1 and added a native public Ability kernel shared by MCP, WebMCP, API Catalog, OpenAPI, and ARD discovery.
- Replaced nested well-known configuration with exact WordPress global rewrite rules, removed physical well-known defaults, and retained ownership-safe cleanup and public verification.
6.6.1
- Added automatic ownership-safe
/.well-known/routing for header-sensitive discovery endpoints on compatible Apache and LiteSpeed servers. - Added public GET/HEAD verification and explicit blocked-before-WordPress diagnostics without substituting wrong-MIME static files.
6.6.0
- Added enriched per-API RFC 9727/RFC 9264 Linksets and a public REST health endpoint.
- Added OAuth metadata, optional RFC 8628 device approval, and opt-in Auth.md without unsupported OIDC or fabricated JWKS claims.
- Added the experimental current MCP Server Card, draft ARD AI Catalog, and opt-in read-only WebMCP with explicit maturity guidance.
- Added server/cache/CDN rules and Configured, Advertised, Publicly verified, and canonical-interception diagnostics.
Earlier release history is included in changelog.txt.