PluginProbe
MxChat – AI Chatbot & Content Generation for WordPress / 3.2.0
MxChat – AI Chatbot & Content Generation for WordPress v3.2.0
3.2.21 3.2.20 3.2.19 3.2.18 3.2.17 3.2.16 3.2.15 3.2.14 3.2.12 3.2.13 3.2.11 3.2.10 3.2.9 3.2.8 3.2.7 3.2.6 3.2.5 3.2.4 3.2.3 3.2.2 3.2.1 2.0.3 2.0.4 2.0.5 2.0.6 All 152 releases
← All changes | mxchat-basic.php +32 -560 3.2.173.2.0 View file →
@@ -2,9 +2,9 @@
2 2 /**
3 3 * Plugin Name: MxChat
4 4 * Plugin URI: https://mxchat.ai/
5 5 * Description: AI chatbot for WordPress with OpenAI, Claude, xAI, DeepSeek, live agent, PDF uploads, WooCommerce, and training on website data.
6 - * Version: 3.2.17
6 + * Version: 3.2.0
7 7 * Author: MxChat
8 8 * Author URI: https://mxchat.ai
9 9 * License: GPLv2 or later
10 10 * License URI: https://www.gnu.org/licenses/gpl-2.0.html
@@ -23,16 +23,8 @@
23 23
24 24 if (!defined('MXCHAT_VERSION')) {
25 25 $plugin_data = get_file_data(__FILE__, array('Version' => 'Version'), 'plugin');
26 26 $version = $plugin_data['Version'];
27 - // MXCHAT_BASE_VERSION: the plain header version, stable across requests even in
28 - // dev mode. Use it for anything PERSISTED or COMPARED (the stored
29 - // mxchat_plugin_version option and the migration gate in
30 - // mxchat_check_for_update). MXCHAT_VERSION keeps the time() suffix in dev for
31 - // ASSET cache-busting only — persisting the suffixed value made the version
32 - // comparison churn every request, re-running the full activation/migration
33 - // suite per page load on dev installs.
34 - define('MXCHAT_BASE_VERSION', $version);
35 27 if (MXCHAT_DEV_MODE) {
36 28 $version .= '.' . time();
37 29 }
38 30 define('MXCHAT_VERSION', $version);
@@ -37,27 +29,8 @@
37 29 }
38 30 define('MXCHAT_VERSION', $version);
39 31 }
40 32
41 -/**
42 - * Honest, versioned User-Agent for MXChat remote-content ingestion fetches
43 - * (Knowledge Base PDF import, URL import, sitemap / website crawl).
44 - *
45 - * WAF rulesets (SiteGround/ModSecurity, Wordfence, Cloudflare managed rules)
46 - * flag stale spoofed-browser UAs as scrapers and return 403 — which silently
47 - * broke the single most common KB source: self-hosted media on the site's own
48 - * domain. A truthful crawler identifier is the industry norm for well-behaved
49 - * bots and lets a site owner allowlist "MXChatBot" in their WAF. Filterable so
50 - * a locked-down host can supply a different string without a code change.
51 - */
52 -if (!function_exists('mxchat_ingest_user_agent')) {
53 - function mxchat_ingest_user_agent() {
54 - $version = defined('MXCHAT_VERSION') ? MXCHAT_VERSION : '1.0';
55 - $ua = 'MXChatBot/' . $version . ' (+https://mxchat.ai/bot)';
56 - return apply_filters('mxchat_ingest_user_agent', $ua);
57 - }
58 -}
59 -
60 33 function mxchat_load_textdomain() {
61 34 $domain = 'mxchat';
62 35 $locale = determine_locale();
63 36
@@ -73,84 +46,8 @@
73 46 }
74 47 add_action('init', 'mxchat_load_textdomain');
75 48
76 49 /**
77 - * One-time migration: gemini-3-pro-preview was shut down by Google on March 9, 2026.
78 - * Existing installs with the dead ID get auto-remapped to gemini-3.1-pro-preview
79 - * (Google's official migration target) the first time admin_init fires after update.
80 - */
81 -add_action('admin_init', function () {
82 - if (get_option('mxchat_gemini_3_remap_done')) {
83 - return;
84 - }
85 - $opts = get_option('mxchat_options');
86 - if (is_array($opts) && isset($opts['model']) && $opts['model'] === 'gemini-3-pro-preview') {
87 - $opts['model'] = 'gemini-3.1-pro-preview';
88 - update_option('mxchat_options', $opts);
89 - }
90 - if (is_array($opts) && isset($opts['content_model']) && $opts['content_model'] === 'gemini-3-pro-preview') {
91 - $opts['content_model'] = 'gemini-3.1-pro-preview';
92 - update_option('mxchat_options', $opts);
93 - }
94 - update_option('mxchat_gemini_3_remap_done', 1);
95 -});
96 -
97 -/**
98 - * One-time migration: the Grok 2 family was retired by xAI (grok-2, grok-2-1212,
99 - * grok-2-latest, grok-2-vision-1212 all return 400 "Model not found"). Existing
100 - * installs with the dead ID get auto-remapped to grok-4-1-fast-non-reasoning
101 - * (modern, fast, broadly available) the first time admin_init fires after update.
102 - */
103 -add_action('admin_init', function () {
104 - if (get_option('mxchat_grok_2_remap_done')) {
105 - return;
106 - }
107 - $opts = get_option('mxchat_options');
108 - if (is_array($opts) && isset($opts['model']) && $opts['model'] === 'grok-2') {
109 - $opts['model'] = 'grok-4-1-fast-non-reasoning';
110 - update_option('mxchat_options', $opts);
111 - }
112 - if (is_array($opts) && isset($opts['content_model']) && $opts['content_model'] === 'grok-2') {
113 - $opts['content_model'] = 'grok-4-1-fast-non-reasoning';
114 - update_option('mxchat_options', $opts);
115 - }
116 - update_option('mxchat_grok_2_remap_done', 1);
117 -});
118 -
119 -/**
120 - * One-time migration: Anthropic retired the Claude 4 (2025-05-14) snapshots on
121 - * June 15, 2026 — claude-opus-4-20250514 and claude-sonnet-4-20250514 now return
122 - * an API error. Existing installs with a dead ID get auto-remapped to the current
123 - * equivalents Anthropic recommends (Opus 4.8 / Sonnet 4.6) the first time admin_init
124 - * fires after update. Mirrors the gemini-3-pro-preview / grok-2 rescues above.
125 - */
126 -add_action('admin_init', function () {
127 - if (get_option('mxchat_claude_4_retire_remap_done')) {
128 - return;
129 - }
130 - $map = array(
131 - 'claude-opus-4-20250514' => 'claude-opus-4-8',
132 - 'claude-sonnet-4-20250514' => 'claude-sonnet-4-6',
133 - );
134 - $opts = get_option('mxchat_options');
135 - if (is_array($opts)) {
136 - $changed = false;
137 - if (isset($opts['model']) && isset($map[$opts['model']])) {
138 - $opts['model'] = $map[$opts['model']];
139 - $changed = true;
140 - }
141 - if (isset($opts['content_model']) && isset($map[$opts['content_model']])) {
142 - $opts['content_model'] = $map[$opts['content_model']];
143 - $changed = true;
144 - }
145 - if ($changed) {
146 - update_option('mxchat_options', $opts);
147 - }
148 - }
149 - update_option('mxchat_claude_4_retire_remap_done', 1);
150 -});
151 -
152 -/**
153 50 * Exclude MxChat assets from caching plugin optimizations
154 51 *
155 52 * This prevents issues with WP Rocket, LiteSpeed Cache, Autoptimize, WP Super Cache,
156 53 * W3 Total Cache, SG Optimizer, and similar plugins that may break the chatbot by
@@ -353,80 +250,20 @@
353 250 $rejected[] = 'wp-admin/admin-ajax.php';
354 251 return $rejected;
355 252 });
356 253
357 -// ── Page-cache bypass for chat AJAX (companion to the 3.2.6 nonce-race hotfix)
358 -// Each cache plugin gets its own filter export so that visitors hitting an
359 -// edge-cached page never receive cached chat-AJAX responses. The chat send /
360 -// stream send / file upload all POST to /wp-admin/admin-ajax.php with
361 -// `action=mxchat_*`. Without these exports, a cache plugin can stale a response
362 -// and break the per-session nonce flow on the first message.
363 -
364 -// WP Rocket — `rocket_cache_reject_uri` takes a flat array of regex strings.
365 -add_filter('rocket_cache_reject_uri', function($uris) {
366 - if (!is_array($uris)) $uris = array();
367 - $uris[] = '/wp-admin/admin-ajax\.php\?action=mxchat_.*';
368 - return $uris;
369 -});
370 -
371 -// LiteSpeed Cache — `litespeed_cache_no_cache_for_request` short-circuits
372 -// caching when the request matches our chat-AJAX pattern.
373 -add_filter('litespeed_cache_no_cache_for_request', function($no_cache) {
374 - if ($no_cache) return $no_cache;
375 - if (!empty($_SERVER['REQUEST_URI']) &&
376 - strpos($_SERVER['REQUEST_URI'], '/wp-admin/admin-ajax.php') !== false &&
377 - !empty($_REQUEST['action']) &&
378 - strpos((string) $_REQUEST['action'], 'mxchat_') === 0) {
379 - return true;
380 - }
381 - return $no_cache;
382 -});
383 -
384 -// W3 Total Cache — `w3tc_pgcache_request_skip_uri` flips page-cache off when
385 -// the URI matches.
386 -add_filter('w3tc_pgcache_request_skip_uri', function($skip) {
387 - if ($skip) return $skip;
388 - if (!empty($_SERVER['REQUEST_URI']) &&
389 - strpos($_SERVER['REQUEST_URI'], '/wp-admin/admin-ajax.php') !== false &&
390 - !empty($_REQUEST['action']) &&
391 - strpos((string) $_REQUEST['action'], 'mxchat_') === 0) {
392 - return true;
393 - }
394 - return $skip;
395 -});
396 -
397 -// FlyingPress — `flying_press_cacheable` takes a boolean and is run per
398 -// request. Same pattern as LiteSpeed / W3TC.
399 -add_filter('flying_press_cacheable', function($cacheable) {
400 - if (!$cacheable) return $cacheable;
401 - if (!empty($_SERVER['REQUEST_URI']) &&
402 - strpos($_SERVER['REQUEST_URI'], '/wp-admin/admin-ajax.php') !== false &&
403 - !empty($_REQUEST['action']) &&
404 - strpos((string) $_REQUEST['action'], 'mxchat_') === 0) {
405 - return false;
406 - }
407 - return $cacheable;
408 -});
409 -
410 254 // Include classes with error handling
411 255 function mxchat_include_classes() {
412 256 $class_files = array(
413 - 'includes/class-mxchat-model-catalog.php',
414 - 'includes/class-mxchat-live-agent-schedule.php',
415 - 'includes/class-mxchat-tool-registry.php',
416 257 'includes/class-mxchat-integrator.php',
417 258 'includes/class-mxchat-admin.php',
418 259 'includes/class-mxchat-public.php',
419 260 'includes/class-mxchat-utils.php',
420 261 'includes/class-mxchat-user.php',
421 - 'includes/class-mxchat-privacy.php',
422 262 'includes/class-mxchat-meta-box.php',
423 263 'includes/class-mxchat-chunker.php',
424 264 'includes/class-mxchat-word-handler.php',
425 265 'includes/class-mxchat-content-generator.php',
426 - 'includes/class-mxchat-cache-purge.php',
427 - 'includes/class-mxchat-editor-assistant.php',
428 - 'includes/class-rest-api.php',
429 266 'admin/class-ajax-handler.php',
430 267 'admin/class-pinecone-manager.php',
431 268 'admin/class-knowledge-manager.php'
432 269 );
@@ -438,43 +275,8 @@
438 275 } else {
439 276 //error_log('MxChat: Missing class file - ' . $file);
440 277 }
441 278 }
442 -
443 - // Register the native function-calling admin-post save handler (a41dee).
444 - if (class_exists('MxChat_Tool_Registry')) {
445 - MxChat_Tool_Registry::init();
446 - }
447 -
448 - // GDPR: register with WP's personal-data export/erase tools (b81e42).
449 - if (class_exists('MxChat_Privacy')) {
450 - MxChat_Privacy::init();
451 - }
452 -
453 - // Editor Assistant — free, OFF-by-default block-editor AI actions (plan-8cb0cb).
454 - // init() wires REST + streaming AJAX + sidebar enqueue ONLY when the
455 - // mxchat_editor_assistant_enabled option is 'on'; otherwise zero footprint.
456 - if (class_exists('MxChat_Editor_Assistant')) {
457 - MxChat_Editor_Assistant::init();
458 - }
459 -
460 - // Admin pages that aren't classes (procedural include).
461 - if (is_admin()) {
462 - $admin_api_page = plugin_dir_path(__FILE__) . 'includes/admin-api-page.php';
463 - if (file_exists($admin_api_page)) {
464 - require_once $admin_api_page;
465 - }
466 - // f7c7d4 renamed this file admin-dashboard-page.php → admin-onboarding-page.php.
467 - // The require MUST live here (admin bootstrap) and not just inside
468 - // mxchat_add_plugin_page() on the admin_menu hook — admin_menu does NOT
469 - // fire on admin-ajax.php requests, so the wizard's AJAX handlers
470 - // (plan-905439: mxchat_onboarding_kb_status / save_step / mark_step /
471 - // auto_graduate + the f7c7d4 dismiss handler) would never register.
472 - $admin_onboarding_page = plugin_dir_path(__FILE__) . 'includes/admin-onboarding-page.php';
473 - if (file_exists($admin_onboarding_page)) {
474 - require_once $admin_onboarding_page;
475 - }
476 - }
477 279 }
478 280
479 281 /**
480 282 * Lazy-load the PDF parser library only when needed.
@@ -806,33 +608,8 @@
806 608 update_option('mxchat_content_type_migration_version', '2.5.6');
807 609 }
808 610
809 611 /**
810 - * 3.2.4: Backfill the active embedding model option for installs that already
811 - * have KB content but no stamped model. The mismatch warning compares this
812 - * against the user's currently selected model — no per-row column needed.
813 - */
814 -function mxchat_backfill_active_embedding_model() {
815 - global $wpdb;
816 -
817 - if (get_option('mxchat_active_embedding_model', '') !== '') {
818 - return;
819 - }
820 -
821 - $kb_table = $wpdb->prefix . 'mxchat_system_prompt_content';
822 - if ($wpdb->get_var("SHOW TABLES LIKE '{$kb_table}'") !== $kb_table) {
823 - return;
824 - }
825 -
826 - $kb_count = (int) $wpdb->get_var("SELECT COUNT(*) FROM {$kb_table}");
827 - if ($kb_count > 0) {
828 - $options = get_option('mxchat_options', array());
829 - $current_model = $options['embedding_model'] ?? 'text-embedding-ada-002';
830 - update_option('mxchat_active_embedding_model', $current_model, false);
831 - }
832 -}
833 -
834 -/**
835 612 * 2.5.2: Create queue processing tables for reliable background processing
836 613 */
837 614 function mxchat_create_queue_tables() {
838 615 global $wpdb;
@@ -904,34 +681,8 @@
904 681 dbDelta($sql);
905 682 }
906 683
907 684 /**
908 - * Create per-session satisfaction ratings table (v3.2.6)
909 - * Stores one 👍/👎 rating + optional feedback per chat session.
910 - */
911 -function mxchat_create_session_ratings_table() {
912 - global $wpdb;
913 - $charset_collate = $wpdb->get_charset_collate();
914 -
915 - $table_name = $wpdb->prefix . 'mxchat_session_ratings';
916 - $sql = "CREATE TABLE $table_name (
917 - id bigint(20) unsigned NOT NULL AUTO_INCREMENT,
918 - session_id varchar(255) NOT NULL,
919 - bot_id varchar(50) NOT NULL DEFAULT 'default',
920 - rating_value tinyint(1) NOT NULL,
921 - rating_feedback text DEFAULT NULL,
922 - created_at datetime NOT NULL,
923 - PRIMARY KEY (id),
924 - UNIQUE KEY session_id (session_id),
925 - KEY bot_id (bot_id),
926 - KEY created_at (created_at)
927 - ) $charset_collate;";
928 -
929 - require_once(ABSPATH . 'wp-admin/includes/upgrade.php');
930 - dbDelta($sql);
931 -}
932 -
933 -/**
934 685 * 2.5.2: Fix URL column size to support long URLs (especially with UTF-8 encoding)
935 686 * This fixes "url, source_url. The supplied values may be too long" errors
936 687 */
937 688 function mxchat_fix_url_column_size() {
@@ -1002,43 +753,18 @@
1002 753 $migrated = true;
1003 754 $migration_message = 'Your chatbot model has been automatically updated from Claude Haiku 3.5 to Claude Haiku 4.5 due to Anthropic deprecating the older model.';
1004 755 }
1005 756
1006 - // Migrate deprecated GPT-4 series and GPT-3.5 Turbo to GPT-5.6 Sol.
1007 - // (Previous target gpt-5.1-chat-latest itself retires 2026-08-10 — never
1008 - // migrate onto a model that is already on a deprecation list.)
757 + // Migrate deprecated GPT-4 series and GPT-3.5 Turbo to GPT-5.1 Chat Latest
1009 758 if (in_array($current_model, array('gpt-4o', 'gpt-4.1-2025-04-14', 'gpt-4-turbo', 'gpt-4', 'gpt-3.5-turbo'), true)) {
1010 - $options['model'] = 'gpt-5.6-sol';
759 + $options['model'] = 'gpt-5.1-chat-latest';
1011 760 $migrated = true;
1012 761 $migration_message = sprintf(
1013 - 'Your chatbot model has been automatically updated from %s to GPT-5.6 Sol due to OpenAI deprecating older models.',
762 + 'Your chatbot model has been automatically updated from %s to GPT-5.1 Chat Latest due to OpenAI deprecating older models.',
1014 763 $current_model
1015 764 );
1016 765 }
1017 766
1018 - // Migrate the gpt-5.x-chat-latest aliases OpenAI retires on August 10, 2026.
1019 - // Replacement per OpenAI's deprecations page: gpt-5.6-sol (plan e46b8f).
1020 - if (in_array($current_model, array('gpt-5.1-chat-latest', 'gpt-5.3-chat-latest'), true)) {
1021 - $options['model'] = 'gpt-5.6-sol';
1022 - $migrated = true;
1023 - $migration_message = sprintf(
1024 - 'Your chatbot model has been automatically updated from %s to GPT-5.6 Sol because OpenAI retires the GPT-5.x Chat Latest models on August 10, 2026.',
1025 - $current_model
1026 - );
1027 - }
1028 -
1029 - // The content generator has its own model option — same retirement applies.
1030 - if (isset($options['content_model'])
1031 - && in_array($options['content_model'], array('gpt-5.1-chat-latest', 'gpt-5.3-chat-latest'), true)) {
1032 - $old_content_model = $options['content_model'];
1033 - $options['content_model'] = 'gpt-5.6-sol';
1034 - $migrated = true;
1035 - $migration_message = trim($migration_message . ' ' . sprintf(
1036 - 'Your content generation model has also been updated from %s to GPT-5.6 Sol for the same OpenAI retirement.',
1037 - $old_content_model
1038 - ));
1039 - }
1040 -
1041 767 // Migrate deprecated GPT-4o Mini and GPT-4.1 Mini to GPT-5 Mini
1042 768 if (in_array($current_model, array('gpt-4o-mini', 'gpt-4.1-mini'), true)) {
1043 769 $options['model'] = 'gpt-5-mini';
1044 770 $migrated = true;
@@ -1047,21 +773,8 @@
1047 773 $current_model
1048 774 );
1049 775 }
1050 776
1051 - // Migrate retired DeepSeek ids to DeepSeek V4 Flash — the vendor removed
1052 - // deepseek-chat and deepseek-reasoner on 2026-07-24 (hard cutoff, every
1053 - // request 400s). V4 Flash is DeepSeek's designated successor for the
1054 - // legacy deepseek-chat alias.
1055 - if (in_array($current_model, array('deepseek-chat', 'deepseek-reasoner'), true)) {
1056 - $options['model'] = 'deepseek-v4-flash';
1057 - $migrated = true;
1058 - $migration_message = sprintf(
1059 - 'Your chatbot model has been automatically updated from %s to DeepSeek V4 Flash because DeepSeek retired its older API models on July 24, 2026.',
1060 - $current_model
1061 - );
1062 - }
1063 -
1064 777 if ($migrated) {
1065 778 update_option('mxchat_options', $options);
1066 779 update_option('mxchat_model_migrated_notice', true);
1067 780 update_option('mxchat_model_migration_message', $migration_message);
@@ -1086,46 +799,8 @@
1086 799 delete_option('mxchat_model_migration_message');
1087 800 }
1088 801 }
1089 802
1090 -/**
1091 - * Persistent admin notice when the provider rejected the configured model
1092 - * (model_not_found / no access). Set by mxchat_friendly_chat_error() in the
1093 - * integrator whenever a chat request fails on a model-access error — including
1094 - * requests from anonymous visitors, which is the case that otherwise stays
1095 - * invisible to the site owner for weeks (plan e46b8f).
1096 - *
1097 - * Deleted after render so it re-arms on the next failed chat: the notice keeps
1098 - * reappearing until the model is fixed, then stops on its own.
1099 - */
1100 -function mxchat_show_model_access_notice() {
1101 - if (!current_user_can('manage_options')) {
1102 - return;
1103 - }
1104 - $notice = get_option('mxchat_model_access_notice');
1105 - if (!is_array($notice) || empty($notice['model'])) {
1106 - return;
1107 - }
1108 - $settings_url = admin_url('admin.php?page=mxchat-max');
1109 - ?>
1110 - <div class="notice notice-error is-dismissible">
1111 - <p>
1112 - <strong><?php esc_html_e('MxChat: your AI model is being rejected by the provider', 'mxchat'); ?></strong><br>
1113 - <?php
1114 - printf(
1115 - /* translators: 1: model id, 2: provider name */
1116 - esc_html__('Chat requests using the model "%1$s" are failing because %2$s reports it as unavailable on your API key (it may have been retired). Visitors may be seeing errors instead of replies.', 'mxchat'),
1117 - esc_html($notice['model']),
1118 - esc_html(!empty($notice['provider']) ? $notice['provider'] : __('the AI provider', 'mxchat'))
1119 - );
1120 - ?>
1121 - <a href="<?php echo esc_url($settings_url); ?>"><?php esc_html_e('Choose a different model in MxChat Settings', 'mxchat'); ?></a>
1122 - </p>
1123 - </div>
1124 - <?php
1125 - delete_option('mxchat_model_access_notice');
1126 -}
1127 -
1128 803 function mxchat_activate() {
1129 804 global $wpdb;
1130 805 $charset_collate = $wpdb->get_charset_collate();
1131 806
@@ -1193,11 +868,8 @@
1193 868
1194 869 // Create transcript translations table
1195 870 mxchat_create_translations_table();
1196 871
1197 - // Create per-session satisfaction ratings table (v3.2.6)
1198 - mxchat_create_session_ratings_table();
1199 -
1200 872 // Ensure additional columns in system prompt table
1201 873 $existing_system_columns = $wpdb->get_results("SHOW COLUMNS FROM $system_prompt_table");
1202 874 if (!empty($existing_system_columns)) {
1203 875 $existing_system_column_names = array_column($existing_system_columns, 'Field');
@@ -1240,17 +912,13 @@
1240 912
1241 913 // Run migration for existing installations
1242 914 mxchat_migrate_pinecone_roles_add_bot_id();
1243 915
1244 - // 3.2.4: Backfill active embedding model option (replaces 3.2.3 column-based tracking)
1245 - mxchat_backfill_active_embedding_model();
1246 -
1247 916 // Setup cron jobs
1248 917 mxchat_setup_cron_jobs();
1249 918
1250 - // Update version (stable base version — never the dev time()-suffixed one,
1251 - // or the check_for_update comparison would churn every request)
1252 - update_option('mxchat_plugin_version', MXCHAT_BASE_VERSION);
919 + // Update version
920 + update_option('mxchat_plugin_version', MXCHAT_VERSION);
1253 921
1254 922 //error_log("MxChat: Activation function completed");
1255 923 }
1256 924
@@ -1265,35 +933,28 @@
1265 933 if (defined('DISABLE_WP_CRON') && DISABLE_WP_CRON) {
1266 934 // Set flag to use fallback system
1267 935 update_option('mxchat_use_fallback_rate_limits', true);
1268 936 update_option('mxchat_next_rate_limit_check', time() + 3600);
1269 - // Deliberately NO early return (plan-bc08a6): transcript cleanup below
1270 - // must still be scheduled. DISABLE_WP_CRON only changes HOW cron events
1271 - // execute (a server-side runner hitting wp-cron.php instead of loopback
1272 - // spawns) — scheduling still just writes the cron option. The old early
1273 - // return here meant a deactivate/reactivate cycle on a DISABLE_WP_CRON
1274 - // site permanently lost the transcript cleanup event while the retention
1275 - // setting still claimed to be active.
937 + return;
938 + }
939 +
940 + // Schedule the rate limit reset cron job
941 + $result = wp_schedule_event(time() + 300, 'hourly', 'mxchat_reset_rate_limits');
942 +
943 + if ($result === false) {
944 + // Fallback if scheduling fails
945 + update_option('mxchat_use_fallback_rate_limits', true);
946 + update_option('mxchat_next_rate_limit_check', time() + 3600);
1276 947 } else {
1277 - // Schedule the rate limit reset cron job
1278 - $result = wp_schedule_event(time() + 300, 'hourly', 'mxchat_reset_rate_limits');
1279 -
1280 - if ($result === false) {
1281 - // Fallback if scheduling fails
1282 - update_option('mxchat_use_fallback_rate_limits', true);
1283 - update_option('mxchat_next_rate_limit_check', time() + 3600);
1284 - } else {
1285 - // Clear fallback flags if cron scheduling succeeded
1286 - delete_option('mxchat_use_fallback_rate_limits');
1287 - }
948 + // Clear fallback flags if cron scheduling succeeded
949 + delete_option('mxchat_use_fallback_rate_limits');
1288 950 }
1289 -
1290 - // Schedule transcript cleanup if configured (bucket dropdown OR custom retention-days > 0)
951 +
952 + // Schedule transcript cleanup if configured
1291 953 $transcript_options = get_option('mxchat_transcripts_options', array());
1292 954 $cleanup_interval = isset($transcript_options['mxchat_auto_delete_transcripts']) ? $transcript_options['mxchat_auto_delete_transcripts'] : 'never';
1293 - $custom_retention = isset($transcript_options['mxchat_retention_days']) ? (int) $transcript_options['mxchat_retention_days'] : 0;
1294 -
1295 - if ($cleanup_interval !== 'never' || $custom_retention > 0) {
955 +
956 + if ($cleanup_interval !== 'never') {
1296 957 // Check if not already scheduled
1297 958 if (!wp_next_scheduled('mxchat_cleanup_old_transcripts')) {
1298 959 // Schedule to run daily at 3 AM
1299 960 $next_run = strtotime('tomorrow 3:00 AM');
@@ -1330,25 +991,17 @@
1330 991 return;
1331 992 }
1332 993
1333 994 $next_check = get_option('mxchat_next_rate_limit_check', 0);
1334 -
995 +
1335 996 if (time() >= $next_check) {
1336 - // Reuse the bootstrap's integrator — mxchat_init() creates the global on
1337 - // plugins_loaded (before this init-priority-5 callback), so it's always set
1338 - // here. Constructing a second MxChat_Integrator just to call one method
1339 - // re-registers every hook the plugin has (ajax pairs, wp_footer loader,
1340 - // rest_api_init, admin_init guard) on a duplicate instance for the rest of
1341 - // the request. Defensive construction only if the global is somehow unset.
1342 - // NOTE: MxChat_Integrator::check_fallback_rate_limits() is a second
1343 - // implementation of this same check — if either changes, change both.
1344 - global $mxchat_integrator;
1345 - $integrator = ($mxchat_integrator instanceof MxChat_Integrator)
1346 - ? $mxchat_integrator
1347 - : (class_exists('MxChat_Integrator') ? new MxChat_Integrator() : null);
1348 - if ($integrator && method_exists($integrator, 'mxchat_reset_rate_limits')) {
1349 - $integrator->mxchat_reset_rate_limits();
1350 - update_option('mxchat_next_rate_limit_check', time() + 3600);
997 + // Only run reset if the MxChat_Integrator class exists
998 + if (class_exists('MxChat_Integrator')) {
999 + $integrator = new MxChat_Integrator();
1000 + if (method_exists($integrator, 'mxchat_reset_rate_limits')) {
1001 + $integrator->mxchat_reset_rate_limits();
1002 + update_option('mxchat_next_rate_limit_check', time() + 3600);
1003 + }
1351 1004 }
1352 1005 }
1353 1006 }
1354 1007
@@ -1360,9 +1013,9 @@
1360 1013 global $wpdb;
1361 1014
1362 1015 try {
1363 1016 $current_version = get_option('mxchat_plugin_version', '0.0.0');
1364 - $plugin_version = MXCHAT_BASE_VERSION;
1017 + $plugin_version = MXCHAT_VERSION;
1365 1018
1366 1019 // Always ensure critical tables exist (even if version matches)
1367 1020 // This handles manual table deletion or fresh installs
1368 1021 $chat_table = $wpdb->prefix . 'mxchat_chat_transcripts';
@@ -1435,38 +1088,8 @@
1435 1088 delete_option('mxchat_email_null');
1436 1089 delete_option('mxchat_name_null');
1437 1090 }
1438 1091
1439 - // 3.2.4: Backfill active embedding model option for the warning UI
1440 - // (replaces the per-row column tracking from 3.2.3, which was reverted)
1441 - if (version_compare($current_version, '3.2.4', '<')) {
1442 - mxchat_backfill_active_embedding_model();
1443 - }
1444 -
1445 - // 3.2.15: Migrate retired DeepSeek ids (deepseek-chat / deepseek-reasoner
1446 - // were shut off at the vendor on 2026-07-24). The function is idempotent —
1447 - // it only rewrites models on its deprecation lists.
1448 - if (version_compare($current_version, '3.2.15', '<')) {
1449 - mxchat_migrate_deprecated_models();
1450 - }
1451 -
1452 - // 3.2.16: Migrate OpenAI ids retiring 2026-08-10 (gpt-5.1-chat-latest /
1453 - // gpt-5.3-chat-latest → gpt-5.6-sol per OpenAI's deprecations page).
1454 - // Idempotent — only rewrites models on the deprecation lists (e46b8f).
1455 - if (version_compare($current_version, '3.2.16', '<')) {
1456 - mxchat_migrate_deprecated_models();
1457 - }
1458 -
1459 - // 3.2.17: Credential options must not autoload (af2400) — the two
1460 - // Pinecone-secret-holding rows were in alloptions, i.e. read into
1461 - // memory on every request including anonymous page views. Idempotent.
1462 - // Also carry the import modal's remembered ACF→PDF checkbox state
1463 - // into the new install-level option (11720c).
1464 - if (version_compare($current_version, '3.2.17', '<')) {
1465 - mxchat_fix_credential_option_autoload();
1466 - mxchat_migrate_acf_pdf_extraction_option();
1467 - }
1468 -
1469 1092 // Run full activation to ensure everything is up to date
1470 1093 mxchat_activate();
1471 1094
1472 1095 // Run migration functions
@@ -1489,67 +1112,8 @@
1489 1112 }
1490 1113 }
1491 1114
1492 1115 /**
1493 - * Credential options must never enter the autoloaded alloptions set.
1494 - * mxchat_prompts_options and mxchat_pinecone_addon_options can hold the
1495 - * Pinecone API secret; mxchat_options already stores its keys with autoload
1496 - * off and these two must match it. The filter covers every future
1497 - * add_option()/update_option() that creates the row — Settings API saves
1498 - * through options.php and WP-CLI included — on WP 6.6+; older cores are
1499 - * covered by the explicit autoload arguments at the plugin's own write
1500 - * sites plus the one-time migration below.
1501 - */
1502 -add_filter('wp_default_autoload_value', 'mxchat_credential_option_autoload_value', 10, 2);
1503 -function mxchat_credential_option_autoload_value($autoload, $option) {
1504 - if (in_array($option, array('mxchat_prompts_options', 'mxchat_pinecone_addon_options'), true)) {
1505 - return false;
1506 - }
1507 - return $autoload;
1508 -}
1509 -
1510 -/**
1511 - * One-time upgrade migration: flip the autoload flag on credential option
1512 - * rows that existing installs are already carrying autoloaded. Includes
1513 - * mxchat_adv_api_token (Advanced Content bearer token) — harmless no-op
1514 - * when that add-on is not installed, since missing rows simply don't match.
1515 - */
1516 -function mxchat_fix_credential_option_autoload() {
1517 - $keys = array('mxchat_prompts_options', 'mxchat_pinecone_addon_options', 'mxchat_adv_api_token');
1518 - if (function_exists('wp_set_option_autoload_values')) {
1519 - wp_set_option_autoload_values(array_fill_keys($keys, false));
1520 - return;
1521 - }
1522 - // Pre-WP-6.4 fallback: direct flip + cache invalidation.
1523 - global $wpdb;
1524 - $placeholders = implode(',', array_fill(0, count($keys), '%s'));
1525 - $wpdb->query($wpdb->prepare("UPDATE {$wpdb->options} SET autoload = 'no' WHERE option_name IN ($placeholders)", $keys));
1526 - wp_cache_delete('alloptions', 'options');
1527 - foreach ($keys as $key) {
1528 - wp_cache_delete($key, 'options');
1529 - }
1530 -}
1531 -
1532 -/**
1533 - * One-time carry of the import modal's remembered ACF→PDF checkbox state
1534 - * (mxchat_options['acf_pdf_extract_default'], written per-import until 3.2.16)
1535 - * into the new install-level option mxchat_acf_pdf_extraction (plan 11720c).
1536 - * Fresh installs and installs that never touched the checkbox default OFF,
1537 - * matching the setting's own "recommended only if…" guidance.
1538 - */
1539 -function mxchat_migrate_acf_pdf_extraction_option() {
1540 - if (get_option('mxchat_acf_pdf_extraction', null) !== null) {
1541 - return; // already set — never overwrite an owner's choice
1542 - }
1543 - $mxchat_options = get_option('mxchat_options', array());
1544 - if (is_array($mxchat_options) && array_key_exists('acf_pdf_extract_default', $mxchat_options)) {
1545 - update_option('mxchat_acf_pdf_extraction', !empty($mxchat_options['acf_pdf_extract_default']) ? '1' : '0', false);
1546 - unset($mxchat_options['acf_pdf_extract_default']);
1547 - update_option('mxchat_options', $mxchat_options);
1548 - }
1549 -}
1550 -
1551 -/**
1552 1116 * Ensure tables exist on every admin load for fresh installations
1553 1117 * This is a safety net for cases where activation hook doesn't fire
1554 1118 */
1555 1119 function mxchat_ensure_tables_exist() {
@@ -1724,9 +1288,8 @@
1724 1288 add_action('init', 'mxchat_check_fallback_rate_limits', 5);
1725 1289
1726 1290 // Add migration notice hook
1727 1291 add_action('admin_notices', 'mxchat_show_migration_notice');
1728 - add_action('admin_notices', 'mxchat_show_model_access_notice');
1729 1292
1730 1293 // Initialize classes with error handling
1731 1294 try {
1732 1295 // Initialize admin classes
@@ -1751,23 +1314,8 @@
1751 1314 if (class_exists('MxChat_Content_Generator')) {
1752 1315 new MxChat_Content_Generator();
1753 1316 }
1754 1317
1755 - // Initialize cache purge globally — settings writes can happen on any
1756 - // request type (admin screens, admin-ajax autosave, wp-cli), and the
1757 - // deferred-purge cron event fires on front-end requests.
1758 - if (class_exists('MxChat_Cache_Purge')) {
1759 - MxChat_Cache_Purge::init();
1760 - }
1761 -
1762 - // Initialize REST API globally — endpoints must be registered on
1763 - // every request (admin and frontend) so they're reachable via /wp-json/.
1764 - // Endpoints are auth-gated and locked until the site owner generates
1765 - // a token in MxChat → API Access.
1766 - if (class_exists('MxChat_Rest_Api')) {
1767 - new MxChat_Rest_Api();
1768 - }
1769 -
1770 1318 // Initialize public classes
1771 1319 if (class_exists('MxChat_Public')) {
1772 1320 $mxchat_public = new MxChat_Public();
1773 1321 }
@@ -1812,25 +1360,11 @@
1812 1360
1813 1361 mxchat_migrate_pinecone_roles_add_bot_id();
1814 1362 mxchat_migrate_add_content_type_column();
1815 1363 mxchat_migrate_add_translations_table();
1816 - mxchat_migrate_add_session_ratings_table();
1817 1364 }
1818 1365
1819 1366 /**
1820 - * Migration: Create per-session satisfaction ratings table (v3.2.6)
1821 - * For users upgrading from versions before 3.2.6
1822 - */
1823 -function mxchat_migrate_add_session_ratings_table() {
1824 - $migration_key = 'mxchat_session_ratings_table_created';
1825 - if (get_option($migration_key)) {
1826 - return;
1827 - }
1828 - mxchat_create_session_ratings_table();
1829 - update_option($migration_key, '3.2.6');
1830 -}
1831 -
1832 -/**
1833 1367 * Migration: Create transcript translations table (v3.0.4)
1834 1368 * For users upgrading from versions before 3.0.4
1835 1369 */
1836 1370 function mxchat_migrate_add_translations_table() {
@@ -1873,67 +1407,5 @@
1873 1407 return $schedules;
1874 1408 });
1875 1409
1876 1410 // Register deactivation hook
1877 -register_deactivation_hook(__FILE__, 'mxchat_deactivate');
1878 -
1879 -/**
1880 - * Per-session satisfaction rating: AJAX save handler (v3.2.6).
1881 - * Records one 👍/👎 + optional feedback per chat session. The UNIQUE KEY on
1882 - * session_id makes this naturally idempotent — only the first rating per
1883 - * session is stored; duplicate POSTs are silent no-ops.
1884 - */
1885 -function mxchat_save_session_rating() {
1886 - global $wpdb;
1887 -
1888 - $session_id = isset($_POST['session_id']) ? MxChat_Utils::sanitize_session_id(wp_unslash($_POST['session_id'])) : '';
1889 - $bot_id = isset($_POST['bot_id']) ? sanitize_text_field(wp_unslash($_POST['bot_id'])) : 'default';
1890 - $rating_raw = isset($_POST['rating']) ? (int) $_POST['rating'] : 0;
1891 - $feedback = isset($_POST['feedback']) ? sanitize_textarea_field(wp_unslash($_POST['feedback'])) : '';
1892 -
1893 - if ($session_id === '' || ($rating_raw !== 1 && $rating_raw !== -1)) {
1894 - wp_send_json_error(array('message' => 'invalid_input'), 400);
1895 - }
1896 -
1897 - if (strlen($feedback) > 1000) {
1898 - $feedback = substr($feedback, 0, 1000);
1899 - }
1900 -
1901 - $table_name = $wpdb->prefix . 'mxchat_session_ratings';
1902 - $existing = $wpdb->get_var($wpdb->prepare(
1903 - "SELECT id FROM $table_name WHERE session_id = %s LIMIT 1",
1904 - $session_id
1905 - ));
1906 -
1907 - if ($existing) {
1908 - if ($feedback !== '') {
1909 - $wpdb->update(
1910 - $table_name,
1911 - array('rating_feedback' => $feedback),
1912 - array('id' => (int) $existing),
1913 - array('%s'),
1914 - array('%d')
1915 - );
1916 - }
1917 - wp_send_json_success(array('updated' => true));
1918 - }
1919 -
1920 - $inserted = $wpdb->insert(
1921 - $table_name,
1922 - array(
1923 - 'session_id' => $session_id,
1924 - 'bot_id' => $bot_id !== '' ? $bot_id : 'default',
1925 - 'rating_value' => $rating_raw,
1926 - 'rating_feedback' => $feedback !== '' ? $feedback : null,
1927 - 'created_at' => current_time('mysql'),
1928 - ),
1929 - array('%s', '%s', '%d', '%s', '%s')
1930 - );
1931 -
1932 - if ($inserted === false) {
1933 - wp_send_json_error(array('message' => 'db_insert_failed'), 500);
1934 - }
1935 -
1936 - wp_send_json_success(array('saved' => true));
1937 -}
1938 -add_action('wp_ajax_mxchat_save_rating', 'mxchat_save_session_rating');
1939 -add_action('wp_ajax_nopriv_mxchat_save_rating', 'mxchat_save_session_rating');
1411 +register_deactivation_hook(__FILE__, 'mxchat_deactivate');