PluginProbe
OpenStation: Desktop Windows, Dock & Virtual Desktops for WP Admin / 1.1.12
OpenStation: Desktop Windows, Dock & Virtual Desktops for WP Admin v1.1.12
1.1.12 1.1.11 1.1.10 1.1.9 1.1.8 1.1.7 1.1.6 1.1.5 1.1.4 1.1.3 1.1.2 1.1.1 1.1.0 1.0.1 1.0.0 0.9.8 0.9.7 0.9.6 0.9.4 0.9.5 0.9.3 0.9.2 0.9.1 0.9.0 0.8.9 All 36 releases
← All changes | readme.txt +138 -4 1.1.6 → 1.1.12 View file →
@@ -3,9 +3,9 @@
3 3 Tags: admin, dashboard, desktop, productivity, ai
4 4 Requires at least: 6.0
5 5 Tested up to: 7.1
6 6 Requires PHP: 7.4
7 -Stable tag: 1.1.6
7 +Stable tag: 1.1.12
8 8 License: GPLv2 or later
9 9 License URI: https://www.gnu.org/licenses/gpl-2.0.html
10 10
11 11 A windowed workspace for wp-admin. Open posts, media, and settings side by side, with a dock, virtual desktops, and a Cmd+K palette.
@@ -67,9 +67,9 @@
67 67 Extend OpenStation through documented PHP and JavaScript APIs. Register windows, icons, wallpapers, widgets, commands, and settings tabs through stable `openstation_register_*` PHP APIs and a typed JavaScript API; customize dock items through documented hooks; add AI tools with the WordPress Abilities API. Copy-paste examples live in the [developer docs on GitHub](https://github.com/WordPress/openstation/tree/trunk/docs).
68 68
69 69 = External services =
70 70
71 -No external service is required for OpenStation's desktop interface. The optional AI Assistant and two user-initiated enrichment features make the external requests described below.
71 +No external service is required for OpenStation's desktop interface. The optional AI Assistant, two user-initiated enrichment features, an optional feedback form on deactivation and an optional one-time feedback form for active users make the external requests described below.
72 72
73 73 **AI Assistant**
74 74
75 75 The optional AI Assistant sends data to the **AI provider you configure in WordPress's Settings → Connectors** (for example OpenAI, Anthropic, or Google). Generation is routed through WordPress 7.0's built-in AI Client, which supplies the credentials stored in Connectors. The plugin never handles an API key itself. With no provider configured in Connectors, no external AI requests are made.
@@ -76,9 +76,9 @@
76 76
77 77 When the AI Assistant is enabled and a user invokes it (via Cmd+K or the slash-command palette):
78 78
79 79 * **What is sent:** the user's prompt, the conversation history for the active session, and tool-call metadata. The plugin's built-in tools (`search_posts`, `search_pages`, `search_comments`) run WordPress's native keyword search and may include excerpts of the matching posts/pages/comments in tool results, which are then sent back to the provider as part of the agentic loop.
80 -* **When it is sent:** on user-initiated AI requests, and (if an administrator enables "Score new comments with AI") on comment-save hooks for spam analysis. Posts, pages, and taxonomy terms are not sent automatically.
80 +* **When it is sent:** on user-initiated AI requests only. Nothing is sent automatically — posts, pages, comments and taxonomy terms are never analyzed in the background.
81 81 * **Why it is sent:** to obtain model completions and tool-call decisions that drive the AI Assistant.
82 82 * **Who provides the service:** whichever provider you configured in Settings → Connectors. Which provider (and endpoint) receives the data depends entirely on that configuration. Review the chosen provider's own terms and privacy policy (e.g. OpenAI, Anthropic, or Google).
83 83
84 84 **URL shortcut favicons**
@@ -84,8 +84,26 @@
84 84 **URL shortcut favicons**
85 85
86 86 When an authorized user creates a desktop shortcut to an external URL, OpenStation asks that URL for its page HTML and favicon so the shortcut can display the site's icon. The request is made from your WordPress server and sends the requested URL, the server's IP address, an OpenStation user-agent string, and normal HTTP request metadata to the operator of that site. This happens only when a user creates the shortcut. The destination site's terms and privacy policy apply.
87 87
88 +**Deactivation feedback**
89 +
90 +When an administrator deactivates OpenStation, a dialog asks one optional question about why. Nothing is sent unless you click **Send and deactivate**; **Skip and deactivate** sends nothing, and both deactivate the plugin.
91 +
92 +* **What is sent:** the reasons you ticked, the optional details you typed, the OpenStation, WordPress and PHP versions, your site language, whether the site is a network, how long OpenStation was installed, whether anyone on the site had turned it on (how many people, and how many days after install the first one did), whether the person deactivating had it on, the number of active plugins, and where the dialog was shown. Nothing that identifies you or your site: no URL, no site id, no email, no user name, no plugin names, and no IP address is stored. Each submission carries a random id used only to ignore an accidental retry.
93 +* **When it is sent:** only when you click Send in the dialog shown on deactivation. There is no background ping.
94 +* **Why it is sent:** to learn what did not work so it can be fixed.
95 +* **Who provides the service:** the request goes from your server to [openstation.blog](https://openstation.blog/), the plugin's own site, operated by Automattic. Review the [Automattic Privacy Policy](https://automattic.com/privacy/). Site owners can turn the dialog off with the `openstation_deactivation_feedback_enabled` filter.
96 +
97 +**Usage feedback**
98 +
99 +After you have had OpenStation on for a week, a small card asks once whether you have two minutes to say how it is going. Answering **No thanks** sends nothing, and it never comes back. Saying yes opens a short form with three optional questions and an optional email field. Nothing is sent unless you click **Send**; **Cancel**, Escape and the close button send nothing.
100 +
101 +* **What is sent:** the answers you typed, the email address if you chose to type one (the field starts empty and is never filled in for you), your language, the OpenStation and WordPress versions, and how many days you have had OpenStation on. Nothing that identifies your site: no URL, no site id, no user name, and no IP address is stored. Without an email the submission is anonymous. Each submission carries a random id used only to ignore an accidental retry.
102 +* **When it is sent:** only when you click Send in the form. There is no background ping.
103 +* **Why it is sent:** to learn what works and what gets in the way. An email address, when given, is used only to follow up on the feedback.
104 +* **Who provides the service:** the request goes from your server to [openstation.blog](https://openstation.blog/), the plugin's own site, operated by Automattic. Review the [Automattic Privacy Policy](https://automattic.com/privacy/). Site owners can turn the prompt off with the `openstation_usage_feedback_enabled` filter.
105 +
88 106 **WordPress.org plugin information**
89 107
90 108 When an authorized user opens or refreshes parts of OpenStation's Plugins window, OpenStation may request public plugin details, update metadata, and review excerpts from WordPress.org. These requests send plugin slugs, the site's locale, and normal HTTP request metadata to WordPress.org. This information is used only to display and manage plugins. Review the [WordPress.org Privacy Policy](https://wordpress.org/about/privacy/).
91 109
@@ -123,9 +141,9 @@
123 141 Most plugin admin pages open as windows without special integration. Plugins that depend on running in the top-level browser context or use unusual navigation may need compatibility work. Plugins can also register their own native windows, widgets, and commands for a deeper integration.
124 142
125 143 = Does the plugin require an external service to function? =
126 144
127 -No. The desktop shell, windowing, dock, taskbar, virtual desktops, widgets, wallpapers, and extension APIs work without an external service. The optional AI Assistant requires a configured AI provider. OpenStation also makes limited, user-initiated requests to resolve URL-shortcut favicons and display WordPress.org plugin information. See "External services" in the description.
145 +No. The desktop shell, windowing, dock, taskbar, virtual desktops, widgets, wallpapers, and extension APIs work without an external service. The optional AI Assistant requires a configured AI provider. OpenStation also makes limited, user-initiated requests to resolve URL-shortcut favicons and display WordPress.org plugin information, offers an optional, one-click feedback form when you deactivate, and once asks active users whether they want to share feedback. See "External services" in the description.
128 146
129 147 = Does it patch WordPress core? =
130 148
131 149 No. Every feature is wired through public WordPress actions and filters.
@@ -168,8 +186,124 @@
168 186 * **[english-words](https://github.com/dwyl/english-words)** by dwyl (Unlicense) — used as a validity filter.
169 187 * **[LDNOOBW English list](https://github.com/LDNOOBW/List-of-Dirty-Naughty-Obscene-and-Otherwise-Bad-Words)** (CC-BY 4.0) — used as an exclusion filter.
170 188
171 189 == Changelog ==
190 +
191 += 1.1.12 =
192 +* AI: repair the tl;dr and SEO Medic prompts, and drop dated prompting patterns
193 +* Agents: give Comment Concierge its thread tool back, clean up faces on a Core user delete, and fix AI docs drift
194 +* Agents: align get-post, get-media and the per-agent invoke gate with Core's read rules
195 +* WP Explorer: Drag photos and posts into an editor window again
196 +* Workspaces: Give each launch entry its own window back
197 +* Workspaces: Open the Publishing desk with the draft as the main window
198 +* Agents: show the copied prompt in Describe, and let the trail jump to any step
199 +* AI: default the output-token ceiling, fail truncated turns, and stop stuck tool loops
200 +* Site assistant: Open from the dock and always offer Ask AI
201 +* Agents: keep the brief's focus ring inside the wizard pane
202 +* Windows: Decode HTML entities in titles, names and user names across the shell, and fix the Orders list columns
203 +* Add WooCommerce order details to window titles
204 +* WP Explorer: List every attached image under Attached media
205 +* Windows: Rename 'Open in browser tab' to 'Open in classic wp-admin' and explain the ⋯ menu
206 +* Agents: Decode HTML entities in agent names
207 +* WP Explorer: Show who is editing a locked post
208 +* Windows: Keep a lone less-than sign in titles, names, Trash and comment excerpts
209 +* Feedback: Ask active users how OpenStation is going, once
210 +* First run: New users get a short guided tour of the desktop
211 +* First run: After installing, the Plugins screen and the Dashboard now show how to turn OpenStation on
212 +
213 += 1.1.11 =
214 +* Overview: Replace the dock tile icon with the brand widgets glyph
215 +* Workspaces: Only offer a template when its plugin is active
216 +* Admin bar: Remove the OpenStation actions, keep only the way in
217 +* Workspaces: Rename Overview to Workspaces
218 +* Agents: Keep the chat on the latest message across status repaints
219 +* Workspaces: Land on the new blank desk before the wizard opens
220 +* Workspaces: Rename a desk by double-clicking its name
221 +* Chromeless: Fit the boot SPA screens edge to edge again
222 +* WP Explorer: Show revision titles as text, not an avatar tag
223 +* Fix: Let Jetpack route its own Stats and Blaze links
224 +* User Edit: Add a View activity footprint button to the profile sidebar
225 +* Fix: Jetpack Stats v2 not loading properly
226 +* Drafts widget: Say why suggestions failed instead of "Could not get suggestions."
227 +* Desktop: Make the desk readable on light wallpapers
228 +* Session: Restore window titles in the current admin language
229 +* Fix mixed-field forms for OpenStation Studio apps
230 +* Recycle Bin: Fix 404 error on requests
231 +* Prevent bottom dock scroll item clipping
232 +* Os-button: forward a host aria-label onto the inner button so an icon-only button has a name
233 +* Make corner close button visible on touch devices.
234 +* Workspaces: Let the wizard's step trail jump to any step
235 +* App runtime: open_url honours native-window URL remaps before opening an iframe
236 +* Os-table: a slot-shaped cell value renders a named slot the light DOM fills
237 +* Resolve toggle visibility and spacing on tablet screens.
238 +* Notes: Say why converting a note to a post failed and keep the draft reachable
239 +* Say why a request failed, everywhere: shared REST error, failure mapper, toast tone
240 +* Workspaces: Repaint the desk you land on after deleting a workspace
241 +* Menus: Open a window per pick, and make a window's tabs its menu
242 +* Agents: store an answerless run as an error row so it is never replayed as the agent's turn
243 +* Performance: Serialize each script dependency's payload once, not once per entry
244 +* Developers: Let plugins track the desktop's network requests
245 +* Kit: <os-facts> + <os-fact>, and the three apps that hand-rolled it
246 +
247 += 1.1.10 =
248 +* Fix: drop a plugin zip into Core's upload box, not the Media Library dialog
249 +* Multisite: Open sites without OpenStation in a browser tab
250 +* Preferences: Open from the network admin shell
251 +* Network app: Open from a desktop icon instead of a dock tile
252 +* Highlight the best matching control in Preferences search
253 +* Fix: External apps work on activation without needing to refresh
254 +* Multisite: Drop Site Spaces from the Network Admin tile comments
255 +* Multisite: Route My Sites and network Sites links out of the window
256 +* Remove AI comment scoring from the shell
257 +* Add responsive grid, app frame, and resizable split layouts
258 +* Default theme: toning down accent
259 +* Separate hidden columns for posts and pages
260 +* Fix: keep metabox screens two-column down to 796px
261 +* Overview: Merge the two edit controls on desktop tiles
262 +* Plugins: Add AllTerrain MAIA to the Featured tab
263 +* Ask one optional question when OpenStation is deactivated
264 +* Plugins: Add a Plugin File Editor tab to the native Plugins window
265 +
266 += 1.1.9 =
267 +* Add saved Plugins table view and fix preserved table rendering
268 +* OS Settings: let a registered settings tab name its sidebar glyph
269 +* Fix timeout stalled plugin updates
270 +* Fix dock overlap on maximized and snapped windows
271 +* Posts: paint plugin columns on the writing-desk cards
272 +* My WordPress: gate the user dossier aggregates on the viewer
273 +* Add window-scoped MIO assistance and private Settings actions
274 +
275 += 1.1.8 =
276 +* Files: add uploaded files to the Media Library, and start a post or page from an image
277 +* Add minimize and restore dock animations.
278 +* Fix native app windows restoring the wrong saved instance
279 +* Fix Native Users tables action icons visibility
280 +* Add optimistic Trash updates and Explorer previews
281 +* Redesign native Plugins, Posts, Pages, and Users workspaces
282 +* Multisite: an OpenStation network of separate installs, with one switcher on every one
283 +* Add the data-model page and unbreak the wiki sync
284 +* Network: log in on arrival, mark external sites, and keep the switcher live
285 +* Harden stored-file cleanup and make presence updates atomic
286 +* Network: opt-in through an extended option, off by default
287 +* Fix agent request timeouts and stale Recycle Bin contents
288 +* Make preloading and shared cache opt-out Extended options
289 +* Post Stats: draw the chart chrome in tokens instead of hardcoded black
290 +* Preserve preferences on theme switch
291 +* Os-text-field: add hide-label so a compact field can have a name without a visible label
292 +* Widgets: raise the frame's chrome buttons to the 24px target-size floor
293 +* AI Copilot: keep password-protected posts out of the search abilities
294 +* Agents: seal password-protected posts in the get-post ability
295 +* AI Copilot: gate comment search on parent-post readability
296 +* My WordPress: scope the term-stats endpoint to posts the caller may read
297 +* AI Copilot: authorize the model-named entity id before building the entity card
298 +* My WordPress: gate the comment dossier on the window capability and parent-post readability
299 +
300 += 1.1.7 =
301 +* Files: paint a dropped folder's tile as soon as it exists
302 +* Shell: keep third-party scripts out of os-* fields and fixed panels out of the dynamic bar
303 +* Files: drop the marching-ants frame from the wallpaper drop highlight
304 +* WP Explorer: hover card off, preview pane only when open; Note Pad: drop the Public checkbox and Pin button
305 +* Admin bar: keep items the bar's height; shell starts below the bar's measured edge
172 306
173 307 = 1.1.6 =
174 308 * Fix: Script loading: read the concat blob's handle list, so a lazily-loaded package stops replacing wp.hooks
175 309 * Fix: Shell boot: a target is one-shot and must be a real page, so a reload stops opening an empty window