Skip to content

ConfigOps 0.5.1 ​

Released 2026-08-24. This maintenance release lets authorized tools inspect ConfigOps evidence and validate restore eligibility without granting them a generic settings writer or automated restore apply.

Agent-readable operations ​

  • Eight site-scoped native WordPress Abilities expose state, capture discovery, bounded mutation evidence, named Change Session control, and read-only restore planning.
  • Machine-readable JSON wp configops commands execute the same application services with explicit WordPress capability checks.
  • Responses use versioned envelopes, immutable site scope, bounded schemas, behavioral annotations, and machine-readable failure codes.
  • Restore planning runs the real site, active-capture, reference, filtered-read, autoload, current-state, adapter, and verified-key checks without changing WordPress state.

Compatibility fixes ​

  • WP-CLI observations no longer disappear when the optional global --user argument is omitted; shell-authorized commands record actor ID 0.
  • Site and network undo refuse the write when a pre_* filter or path-relevant missing-row default virtualizes the target. Normal post-read transforms such as Yoast's option_wpseo remain conflict-checked instead of being refused solely because a hook is registered.
  • Large-network activation avoids a synchronous all-site loop. Existing sites provision idempotently when they next load ConfigOps.

Human authorization boundary ​

Agent clients can read evidence, control named Change Sessions when granted that capability, and validate a proposed restore. ConfigOps 0.5.1 does not expose generic option writes, raw SQL, plugin installation, or automated restore apply. Applying an undo remains an explicit wp-admin action.

Release evidence ​

  • Complete plugin build, UI budget, runtime policy, PHP parser, unit, adversarial, WordPress integration, WP-CLI, Multisite, and exact-adapter gates.
  • Desktop and mobile documentation plus site and Network Admin browser checks.
  • Deterministic release metadata and WordPress.org payload validation.

Local evidence. Explicit limits. No account required.