=== AI Web Command ===
Contributors: site-agent
Tags: rest api, wordpress management, security, ai assistant, woocommerce
Requires at least: 6.0
Tested up to: 6.6
Requires PHP: 7.4
Stable tag: 0.14.19
License: GPLv2 or later

AI Web Command is a secure capability-based WordPress execution layer for approved AI assistants.

== Description ==

Site Agent exposes a controlled WordPress REST API under `/wp-json/site-agent/v1/` for site inspection, controlled core and theme updates, allowlisted site settings, classic menus, category and tag operations, plugin management, pages, posts and safe custom post types, media metadata, structured Elementor and Gutenberg block edits, managed snippets, diagnostics, cache operations, Yoast and Rank Math SEO metadata, JSON-LD schema, site SEO audits, WordPress security posture and reversible hardening, WooCommerce catalog creation and editing, bounded batch price/stock updates, variations, product attribute updates, stock, product categories, sales, orders and shipment-tracking reads, plus Community AI reply context, response policies, insights, moderation, and reviewed batch replies. Version 0.9 also introduces the premium AI Chat configuration and live widget preview; a visitor widget may only be enabled with an active entitlement and a locally encrypted bring-your-own API key.

It is not a remote shell and does not expose arbitrary PHP, shell, SSH, SQL, or filesystem access.

== Changelog ==

= 0.14.19 =
* Uses a short-lived SaaS entitlement for the paired WordPress site instead of a default-active demo license.
* Adds signed license updates and checks the active license before remote agent operations.

= 0.14.18 =
* Adds one-click SaaS pairing from WordPress with a 10-minute, single-use code.
* Requires explicit approval before enabling remote access or management permissions.
* Issues a revocable, scoped credential to the SaaS after pairing.

= 0.14.17 =
* Adds a dedicated Saved chats tab with readable transcripts, follow-up filters, pagination, resolve and permanent deletion.
* Improves conversation storage error reporting and retention on admin access.
* Returns preview and editor links after creating an Elementor or WPBakery page.

= 0.13.0 =
* Adds optional local conversation retention, human follow-up queue, token and estimated-cost metrics, and layered anti-abuse limits.

= 0.12.0 =
* Adds a dedicated Managed Snippets wp-admin screen between Site Agent and AI Chat.
* Requires reviewed dry-runs and explicit confirmation for remote snippet creation, updates, and deletion.

= 0.11.0 =
* Adds secure OpenAI Responses, Anthropic Messages, and Google Gemini server-side adapters for visitor chat.
* Adds a connection test gate, private instructions, local knowledge retrieval, a public widget, input limits, nonce checks, honeypot protection, and per-IP rate limiting.

= 0.10.0 =
* Adds direct token generation to the operations dashboard.
* Adds local Pages, Posts, and WooCommerce Products knowledge scanning with source counts and a last-scan timestamp.
* Improves the AI Chat activation toggle and preview controls.

== Installation ==

1. Upload the `site-agent-commercial` folder to `wp-content/plugins/`.
2. Activate AI Web Command.
3. Open `AI Web Command` in wp-admin.
4. Enable remote access.
5. Generate a credential with only the permissions needed for that site.

== Security ==

Use HTTPS. Tokens are shown once, stored hashed, and can be revoked. Every protected request must include token, timestamp, and nonce headers.

== Documentation ==

See the `docs/` directory, especially `CODEX-INTEGRATION.md`.

== Deployment ==

See `docs/DEPLOYMENT.md` and `docs/TESTING.md` before using Site Agent on production websites.
