3.8.3 (2026/10/01)
- Add: Abilities to MCP, so tools registered by plugins through the WordPress Abilities API work over MCP and in Workspace, appear in MCP Logs, and are labelled Ability or Native in the renamed MCP Tools & Abilities list.
- Add: Cached tokens are now counted and priced at the cached rate for OpenAI, Anthropic, DeepSeek, OpenRouter and Claude Fable 5, and Insights shows cached tokens per query.
- Add: OpenAI requests carry a prompt cache key per chatbot, so repeated prompts and tools are billed at the cached rate.
- Add: A reply cut by Max Tokens now ends with a short notice instead of stopping mid-sentence, in chatbots and forms.
- Add: A chatbot limited to one file shows the attached file name and a remove button before sending, like the multi-file mode.
- Add: Prices for Gemini text models, so their queries are costed and dollar limits apply to them.
- Add: The mwai_openrouter_body filter, to add any OpenRouter parameter to a request, such as provider routing.
- Update: The MCP settings were reorganized, with the Connect card filling its block, Connections and MCP Settings under it, tool sets and WordPress abilities under the tools list, and the bearer token masked in the Claude Code commands.
- Update: The Files Manager lists files uploaded by every user and guest instead of only your own, and expired files are cleaned up every hour instead of once a day.
- Update: New chatbots start with their texts in the site language instead of always in English, existing chatbots are untouched.
- Update: OpenRouter requests are attributed to AI Engine instead of each site, and the existing filters still let a site credit itself.
- Update: Workspace chats are grouped under Today and Yesterday in the user timezone instead of UTC.
- Fix: The Editor Assistant no longer fails with Feedback session expired after applying edits, saved queries no longer store API keys, and it now sees paragraphs edited after the page loaded.
- Fix: Claude, Gemini and other non-OpenAI chatbots on an OpenAI Vector Store now receive the matching knowledge instead of an empty context.
- Fix: Non-streamed errors from OpenRouter, Mistral, OVH and custom providers are shown as a message instead of raw JSON.
- Fix: Gemini replies cut by Max Tokens end with the notice instead of an empty-reply error, and Gemini errors wrapped in a list are readable.
- Fix: Picking an environment without a model now asks for one instead of sending another provider's default model and failing with a 404.
- Fix: An AI Form repeated on a page answers in its own copy, and a streamed form error no longer floods the PHP log.
- Fix: GPT-6 Astra can generate images, its model entry was missing the image generation tool.
- Fix: Uploads that fail now say why, with the size limit when the file is too large, instead of an unknown error or a wrong invalid file type message.
- Fix: An empty completion request is refused before reaching the provider, and Suggest Synonyms without a selection returns a clear error instead of a fatal.
- Fix: MCP tool failures, like a missing post, reach the AI as a readable tool error instead of a protocol error.
- Fix: ChatGPT MCP connections no longer drop when several of its sessions share one connection, and revoking an app disconnects all of its sessions at once.
- Fix: When AI Engine manages the WordPress Connectors, an empty key no longer wipes a saved one, and keys already saved in WordPress are reused.
- Fix: Syncing a single post that gets skipped (ignored, language filter, or filtered out) now says why instead of doing nothing.
- Fix: Copying a masked MCP command by hand copies the real token, and Knowledge asks to pick an environment instead of showing the first-run screen.
- Fix: On touch screens the Stop button works with a single tap, while a quick double tap on Send still cannot cancel the message.
- Fix: A failed license check shows the real reason straight away, and a successful retry no longer keeps saying the Pro version is disabled.
- Fix: Two PHP warnings on every logs request when Insights is off.
3.8.2 (2026/09/25)
- Add: Connect an AI assistant card in the MCP settings, which checks the host, guides you through Claude, ChatGPT or Claude Code step by step, and confirms the connection works.
- Add: The license section now names the actual problem (server unreachable, not activated on this site, expired) instead of an unknown error, and lets you copy the diagnosis for support.
- Update: The MCP settings and the readme now state that connections are direct, with no relay, no fee or cap, and credentials staying on the site.
- Fix: A site that cannot reach the license server no longer hangs the admin for minutes: connection diagnostics run once instead of once per URL, and the license check times out after 20 seconds instead of 45.
- Fix: MCP connections no longer break when a client, such as ChatGPT, reuses a refresh token that was already replaced.
- Fix: Chatbots with streaming disabled no longer slide the window up when a reply starts, which hid the Glass header and could make the page jump.
- Fix: Add-ons now keep their own visitor params as sent; only denied keys are matched by their canonical name and only messages is folded into one key.
3.8.1 (2026/09/24)
- Fix: Security: visitors could override a chatbot's or form's model, instructions or environment with renamed parameters. Fixed, and the Advisor widget now escapes its output.
- Add: Glass, a new chatbot theme with colored light under frosted glass, a dark and a light mode, and a mode that follows the visitor's device.
- Update: Every chatbot theme was polished: proper headings, lists and tables in replies, an empty state that introduces the bot, message actions beside the bubble, and a message field that keeps its height on every WordPress theme.
- Update: Timeless and Messages have refreshed defaults (larger text, rounder corners, a white pane), and Messages drops its bubble tails. Customized themes keep their own values.
- Update: Redesigned the dashboard's AI Visibility card, with visits, score and the top AI companies from SEO Engine, and an example you can hide when it is not installed.
- Add: Templates in the Content Studio, shared with the classic generator.
- Add: Every text the chatbot says on its own can be translated or changed with the mwai_chatbot_texts filter, plus a new Empty State Hint parameter.
- Update: Pictures sent by visitors appear as a photo card, and message actions can be reached with the keyboard.
- Update: The mwai_image MCP tool accepts an aspect ratio, and images requested without a size are now square instead of 21:9 on Gemini.
- Update: Workspace now tells you when your site refuses a rename, a delete or a save, instead of failing silently.
- Update: Deleting or resetting a chatbot, a theme or a template now asks first.
- Fix: Embeddings were skipped on pages made with a page builder (Breakdance, Oxygen, Bricks...).
- Fix: Models of a Custom (OpenAI-compatible) environment could not receive images.
- Fix: The discussions list with several lists on one page, empty discussions, and its menu while scrolling.
- Fix: The admin crashed when a chatbot's ID was changed, and a crash in one settings tab no longer locks the whole screen.
- Fix: Stopped or edited Workspace replies no longer come back duplicated.
- Fix: A streamed reply was rebuilt when it finished, reloading its images.
- Fix: Dev Tools no longer polls the server every second while open.
3.8.0 (2026/09/18)
- Add: Models API Pro module, so coding agents and OpenAI-compatible apps can use your site's AI models with one key, with usage tracked in Insights.
- Add: Editor Access for MCP, letting Editors connect with their own account and work on content only.
- Update: Rebuilt the Images, Playground and Content screens as studios, with image versions and brush edits, side-by-side model comparison, a guided brief-to-draft flow and shared presets.
- Update: Knowledge sync now reports why posts were skipped instead of only the count.
- Update: Excluded notes, archives and the Brewfile from the released package.
- Add: Paste a file into the chatbot to upload it, and hover the reply timer to stop a response in progress.
- Fix: Daily, weekly and monthly limits in Absolute mode no longer trip early.
- Fix: Image, media and post creation routes now check permissions before acting.
- Fix: Listing chatbots no longer fatals on the free plugin when a chatbot uses functions.
3.7.8 (2026/09/13)
- Add: Redesigned Dashboard with a providers bento, weekly usage card, daily ideas and an AI visibility card, plus a slimmed Modules tab.
- Add: MCP tools to install and update plugins and themes from the WordPress.org directory.
- Add: GPT Image 2.5 Sunburst and Flare with the new quality levels.
- Fix: Workspace module no longer switches itself off on sites without a Pro licence.
- Fix: OpenAI Vector Store no longer retrieves knowledge twice on the default environment, now passes Max Results to file_search, and repairs old vectors tables missing columns.
- Fix: Uploaded files stay in context on later turns with Claude and other stateless providers.
- Update: The transcription and image edit API endpoints now check the caller can read the supplied attachment.
- Update: Smart Search returns embedded pages and custom post types instead of only posts, and the debug info shows the min score and number of posts found.
3.7.7 (2026/09/08)
- Add: Local Memory now stores the shortcuts and blocks of the last reply, so they persist after a reload.
- Fix: Pairing failures that consumed the token now ask the user to generate a new code.
- Fix: Connection test no longer always reports success.
- Fix: Gemini no longer offers Live-only models as chatbots.
- Fix: Function calling on Google's Standard API.
- Fix: AI Copilot no longer stretches paragraphs to the full editor width.
- Update: Workspace is now described as available on both iOS and Android in the readme and admin.
3.7.6 (2026/09/05)
- Add: Support for GPT-6 Astra, including its max reasoning level.
- Fix: Temperature is no longer sent to models that reject it.
- Update: The reasoning dropdown now only shows levels supported by the selected model.
3.7.5 (2026/09/03)
- Add: Claude Fable 5.1 to the Anthropic models.
- Fix: Anthropic now caps max_tokens to the model's limit instead of returning a 400 error.
- Fix: Provider errors with a flat body (such as Mistral) and any 4xx/5xx status now show the actual error message.
- Update: Removed the Assistants module following OpenAI's shutdown.
- Update: Transcription now uses gpt-transcribe, and Opus 4.1 has been removed.
- Update: Built-in tools that can't be used with Chat Completions are now reported in the logs instead of being dropped silently.
3.7.4 (2026/09/01)
- Fix: Sending a message after a client-side JS function call no longer fails with an invalid_request_error.
- Fix: MCP OAuth login redirects are no longer cached by page caches and served to the wrong visitor.
- Fix: Plugin file tools no longer report a refusal as a missing directory.
- Update: The "Done!" placeholder for client-side function calls is now translatable and filterable.
3.7.3 (2026/08/26)
- Fix: Chatbots using the default environment and model are no longer excluded from the function calling list.
- Fix: Vision now detects image types from the file contents instead of the extension, so images served through a CDN work.
- Fix: Magic Wand can read the selected text again in the iframed block editor of WordPress 7.1, re-enabling Suggest Synonyms.
- Update: Completed steps in the Setup Assistant now collapse to a single line.
3.7.2 (2026/08/20)
- Fix: Editor Assistant endpoints accepted a nonce any visitor could generate, allowing anyone to run AI queries on the site's provider account (reported by Abdullah Kareem via WPScan).
- Fix: A crafted URL could escape the uploads folder and send any server-readable file to the AI provider (reported by Jashid Sany via WPScan).
- Fix: Editor Assistant now works for admin-equivalent accounts whose role isn't literally administrator.
- Fix: Embeddings sharing the same reference no longer stay stuck, and a single unprocessable vector no longer blocks the maintenance queue.
- Fix: A temperature of 0 is no longer treated as unset and stripped from the request.
- Fix: Image-only replies from GPT-5 models no longer show "medium" as the answer text.
- Update: Claude Sonnet 5 pricing ($2/$10 is now permanent), dashboard wording, and tested with WordPress 7.1.
- 🎵 Discuss with others about Ai Engine on the Discord.
- 🌴 Keep us motivated with a little review here. Thank you!
- 🥰 If you want to help us, check our Patreon. Thank you!
- 🚀 Click here to vote for the features you want the most.
3.7.1 (2026/08/14)
- Add: WPML support in the MCP server, mirroring the Polylang tools.
- Add: SEO section in the Modules tab, with robots.txt access for AI crawlers and live stats when SEO Engine is installed.
- Update: MCP self-test now detects AI-crawler blocking, nested .htaccess files and www mismatches, and logs every OAuth authorize refusal.
- Update: Internal errors are now hidden behind a filterable public message, and AI Forms no longer show provider errors to visitors.
- Update: Shared dashboard synced with the new Board and the AI site analysis.
- Fix: The mwai_mcp_mutate hook now fires on deletions, so cache purges hooked to it run.
3.7.0 (2026/08/03)
- Fix: Qdrant collections were always created with 1536 dimensions regardless of the embedding model, and default dimensions are now read from the right place.
- Update: Embedding dimensions are no longer locked for OpenAI-compatible models, as that size is only a guess.
- Fix: The MCP access level no longer restricts OAuth connections, and the setting is no longer hidden behind the bearer token.
- Fix: MCP connections no longer drop at random when the client refreshes its access token.
- Update: Credited Revanth Hari Narayana Matte (via WPScan) for reporting the security issues fixed in 3.6.4 and 3.6.6.
3.6.9 (2026/08/01)
- Fix: Crash when clicking quickly through discussions, and slow image checks writing into the wrong message.
- Fix: MCP token refresh being rejected on servers that pass Basic credentials to PHP instead of forwarding the header.
- Fix: Stored chat messages could run scripts when an admin opened a discussion.
3.6.8 (2026/08/01)
- Fix: Workspace mobile app connection on servers that don't expose the Authorization header, with clearer pairing errors.
- Fix: A Context Max Length of zero no longer empties posts, which blocked embeddings sync and blanked chatbot context.
- Update: Transcription now defaults to gpt-4o-mini-transcribe instead of whisper-1.
- Update: The mobile connection warning links to the troubleshooting page instead of showing the htaccess snippet.
- Add: Logging on the MCP OAuth token endpoint for failing refreshes.
3.6.7 (2026/07/31)
- Add: Workspace is officially launched on iOS.
- Update: OpenAI pricing for GPT-5.6 Terra and Luna following the July 30 cut, and corrected o3 which was priced 7.5x too high.
- Update: Removed the leftover mcp.js relay and its documentation, and corrected the MCP header comment that still mentioned SSE and OAuth.
- Add: getDiscussion() to the PHP API, to read a stored discussion without using $mwai_core.
3.6.6 (2026/07/30)
- Update: Minimum PHP version is now 8.1, declared in the plugin header so WordPress blocks activation on older versions.
- Fix: Push All no longer exhausts the memory limit on large sites; post content is now checked in chunks.
- Fix: Long Japanese and Chinese posts no longer produce empty content, which left their embeddings stale.
- Fix: Hardened the REST endpoints against client-supplied file paths and API keys, corrected the MCP OAuth route match and guest session cookie, and stopped the chatbot key reaching Editors.
- Fix: The mwai_mcp_callback filter now receives five arguments from both the Workspace and the MCP endpoint.
- Add: CSV and JSON export for the Query and MCP logs, honouring the active filters and sort.
- Fix: Chatbot input is no longer hidden behind the mobile keyboard in fullscreen, and shortcuts are now chips that don't inherit the site's button styles.
3.6.5 (2026/07/28)
- Add: Elapsed time counter on the AI Forms submit button, matching the chatbot.
- Add: Note in the Sync panel that the Sync filters are shared by all environments.
- Fix: Three security issues reported by WPScan (key disclosure to editors, guessable guest sessions, audio transcription file read).
- Fix: Streaming requests now respect MWAI_SSL_VERIFY and verify TLS certificates (reported by Mohammed Abd Alrahman).
- Fix: Recurring tasks no longer stay parked after repeated failures, so discussions and logs cleanups run again.
- Fix: Administrator-equivalent accounts (custom roles with manage_options) are no longer refused at the MCP OAuth consent screen.
- Fix: A custom JavaScript filter that crashes no longer breaks the chatbot, and raw JavaScript errors are no longer shown to visitors.
- Fix: The embeddings environment Type field no longer shows "Select" for the Internal (WordPress DB) environment.
- Fix: The Web Search button now appears in the Workspace composer when pinned.
- Update: Push All now respects the Sync category and language filters, so it no longer seeds posts Sync would not maintain.
- Update: Workspace is now available to everyone; Knowledge, MCP Servers and Functions stay Pro.
- Update: Removed the unused module_addons and module_blocks option defaults.
For older releases, see changelog.txt.