ConfigOps 0.6.0
Released 2026-08-25. This release adds a tested WooCommerce contract, makes ordinary-plugin evidence more attributable, and lets a separately authorized agent acknowledge one guarded mutation undo without gaining a generic settings writer.
WooCommerce support
- A dedicated adapter covers mapped core Options API settings across the WordPress.org-visible WooCommerce 10.3, 10.7, 10.9, and 11.0 lines.
- General, product, inventory, account, shipping-display, tax-display, advanced, email, offline-payment, Point of Sale, performance, REST-cache, and feature-toggle settings receive tested names and restore boundaries.
- BACS account records are removed before persistence. HPOS and Cost of Goods switches remain visible but non-restorable because reversing one option cannot reverse their data effects.
- Each supported line installs a real public release, exercises save and undo, and compares the adapter with its published Settings API surface. A live policy gate rejects newly visible version lines without a contract.
Better evidence without an adapter
- ConfigOps retains the responsible plugin slug and capture-time installed version when WordPress can resolve them.
- Settings registered through the WordPress Settings API retain that ownership basis even when Core performs the final write.
- Direct plugin, must-use plugin, or theme callers take precedence over registration attribution; malformed, removed, or ambiguous registrations fail closed.
- Review uses recognizable source names and readable nested leaf labels while continuing to state that plugin-specific semantics are unverified.
Explicitly authorized agent undo
- The new
configops/apply-restoreAbility andwp configops restore applycommand undo one site mutation only. - The service user needs the separate
configops_applycapability and must send the exactdangerouslyRunUndo: trueor--dangerously-run-undoacknowledgement. - Apply repeats restore planning and the ordinary scope, conflict, reference, filtered-read, autoload, adapter, lock, audit, verification, and compensation checks.
- The operation is destructive and non-idempotent. It does not accept a prior plan as authority and does not expose arbitrary options, SQL, code, plugin installation, whole-capture undo, or network undo.
Release evidence
- Real WP Mail SMTP, Yoast SEO, and WooCommerce release contracts, published-settings-surface audits, and browser save/review/undo workflows.
- Capability isolation, confirmation refusal, successful guarded apply, conflict, audit, and WP-CLI failure-path contracts.
- The complete supported WordPress, PHP, database, Multisite, coverage, documentation, release archive, and WordPress Plugin Check gates.