Skip to content

ConfigOps 0.6.0 ​

Released 2026-08-25. This release adds a tested WooCommerce contract, makes ordinary-plugin evidence more attributable, and lets a separately authorized agent acknowledge one guarded mutation undo without gaining a generic settings writer.

WooCommerce support ​

  • A dedicated adapter covers mapped core Options API settings across the WordPress.org-visible WooCommerce 10.3, 10.7, 10.9, and 11.0 lines.
  • General, product, inventory, account, shipping-display, tax-display, advanced, email, offline-payment, Point of Sale, performance, REST-cache, and feature-toggle settings receive tested names and restore boundaries.
  • BACS account records are removed before persistence. HPOS and Cost of Goods switches remain visible but non-restorable because reversing one option cannot reverse their data effects.
  • Each supported line installs a real public release, exercises save and undo, and compares the adapter with its published Settings API surface. A live policy gate rejects newly visible version lines without a contract.

Better evidence without an adapter ​

  • ConfigOps retains the responsible plugin slug and capture-time installed version when WordPress can resolve them.
  • Settings registered through the WordPress Settings API retain that ownership basis even when Core performs the final write.
  • Direct plugin, must-use plugin, or theme callers take precedence over registration attribution; malformed, removed, or ambiguous registrations fail closed.
  • Review uses recognizable source names and readable nested leaf labels while continuing to state that plugin-specific semantics are unverified.

Explicitly authorized agent undo ​

  • The new configops/apply-restore Ability and wp configops restore apply command undo one site mutation only.
  • The service user needs the separate configops_apply capability and must send the exact dangerouslyRunUndo: true or --dangerously-run-undo acknowledgement.
  • Apply repeats restore planning and the ordinary scope, conflict, reference, filtered-read, autoload, adapter, lock, audit, verification, and compensation checks.
  • The operation is destructive and non-idempotent. It does not accept a prior plan as authority and does not expose arbitrary options, SQL, code, plugin installation, whole-capture undo, or network undo.

Release evidence ​

  • Real WP Mail SMTP, Yoast SEO, and WooCommerce release contracts, published-settings-surface audits, and browser save/review/undo workflows.
  • Capability isolation, confirmation refusal, successful guarded apply, conflict, audit, and WP-CLI failure-path contracts.
  • The complete supported WordPress, PHP, database, Multisite, coverage, documentation, release archive, and WordPress Plugin Check gates.

Local evidence. Explicit limits. No account required.