Description
Chimy’s AI Coding Lab is the platform core of the WP Maker plugin series: module management, unified REST API, security hardening, and ACF infrastructure. A modern React-based SPA admin is built in and replaces the native WordPress admin experience within its own menu, so no separate admin plugin is required. Advanced capabilities (image/media optimization, AI, authentication, data synchronization, batch processing, etc.) are provided by dedicated standalone plugins in the wp-maker-* series.
Some features have been split into standalone plugins (wp-maker-* series) that can be installed on demand; they are currently hosted on Gitee and will be listed on the official WordPress.org directory progressively.
Core Capabilities
- Modular platform — manifest.json-driven module discovery, registration, and enablement management; both built-in modules and external plugins can register
- Built-in SPA admin — React-based modern admin with content management, media library, comments, users, plugins, appearance, and settings; served from the bundled build/ directory over the
wpmaker/v1/admin/*REST API - Admin customization — post editor (wpautop, featured images), general options (site icon), and media upload enhancements (SVG/JSON, WebP, renaming) are provided by the wp-maker-site plugin (site & optimization module)
- Application support — private-site APIs, CORS support; WatermelonDB sync is provided by the standalone wp-maker-system plugin
- Local avatars — preset SVG avatars available on the profile page
- Security — malicious request blocking, SQL injection protection, XSS protection, directory traversal protection, login rate limiting, XML-RPC disabling; one-click temporary shutdown from the SPA dashboard
Modular Architecture
All modules are described by manifest.json with metadata and SPA menu configuration, managed by ModuleManager.
External plugins can register via ModuleManager:
\WPMaker\Core\ModuleManager::registerModulePath( __DIR__ );
REST API Namespaces
wpmaker/v1/admin/*— platform administration (options, modules, system, network, categories, comments, users, etc.)wpmaker/v1/sync/*— WatermelonDB data sync (pull/push, provided by the standalone wp-maker-system plugin)wpmaker/v1/sites/*— private-site APIs
Dependencies
- Batch queue — provided by the standalone wp-maker-system plugin (with Action Scheduler), not distributed with this plugin
Technical Requirements
- PHP 7.4 or higher
- WordPress 6.0 or higher
External services
This plugin does not contact any external service on its own. Previous versions optionally fetched a component catalog from Gitee inside the Case Portal; that feature has been removed.
Privacy
This plugin does not collect user data, does not perform remote telemetry, and does not send any information to the author’s server.
- CORS — cross-origin response headers are configured to support app requests; no data is actively sent out
All external interactions are enabled explicitly by the site administrator; the plugin itself has no phone-home behavior.
Screenshots





Installation
- Upload the plugin folder to the
/wp-content/plugins/directory - Activate «Chimy’s AI Coding Lab» in the WordPress Plugins menu
- Open the «WPMaker» top-level menu to use the built-in SPA admin
FAQ
-
Where can I find documentation and support?
-
Documentation is available at https://aiwp.pro. For support, please use the WordPress.org support forum for this plugin.
-
Is Multisite supported?
-
Yes. Network-level plugin management and network admin entries are provided.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Chimy's AI Coding Lab” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Chimy's AI Coding Lab” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.7.14
- The admin SPA (formerly the standalone wp-maker-admin plugin) is now built in: runtime (AdminSpa), REST endpoints, local avatars, manifest, and bundled build/ assets
- Removed the Case Portal/Case Guide showcase pages
- Cleaned up legacy mappings for discontinued content types (reward, book, chat_group, wp_app)
1.7.13
- Case Portal catalog refreshed: icon and type mappings updated; discontinued entries (wp-maker-chat, wp-maker-network, wp-maker-wpopt-integration, wp-maker-baidu-tongji) pruned
- Case Portal now features entries for the core platform (chimys-ai-coding-lab) and the resource host (wp-maker-resource)
- ContentController and CaseGuide refinements
- Release pipeline automation improvements across packaging and deployment scripts
- Readme updated with accurate screenshots and external-service wording for the WordPress.org directory
1.7.5
- Manifest path resolved via plugin_dir_path() instead of a brittle relative dirname() traversal
- User deletion now requires the target-specific delete_user capability
- Remote address (REMOTE_ADDR) is sanitized before use in rate-limit transients and the 404 log
1.7.4
- Case Portal styles/scripts now loaded via the WordPress enqueue API (admin_enqueue_scripts + wp_add_inline_style/script)
- User management hardening: role validation on creation, promote_user requirement for role assignment, and target-specific edit_user checks on user updates
- All global classes prefixed with CHIMAICO_ and the no-ACF fallback option keys changed to chimaico_options_ (unique naming per WordPress.org guideline)
1.7.3
- Refactored the codebase: core logic consolidated under includes/ (REST controllers, Case Portal showcase, module manager)
1.7.2
- Removed all Composer dependencies; the plugin now has zero third-party runtime dependencies
- Case Portal repositioned as a pure showcase: per-card download buttons removed, documentation links only
- Admin copy refined to be user-facing (catalog status, update button, no download-oriented wording)
1.7.1
- Added the Case Portal: a top-level admin menu (no WP Maker Admin required) listing the catalog of plugins/themes/Apps developed by Chimy’s AI Coding Lab, with documentation links
- Added on-demand guidance: a dismissible admin notice and a «Current site suggestions» block in the Case Portal that only list missing core companion plugins (Admin/Auth/App/Sync/AI); the guidance disappears once they are enabled
- Case Portal menu is not registered when wp-maker-admin is active, since the SPA Plugin Center provides the entry
- Case Portal catalog is fetched from Gitee only on an explicit admin action (the «Update catalog» button), never automatically
- Removed the custom plugin updater; plugin updates are handled by the official WordPress.org channel
1.6.6
- Removed the native Plugin Center admin page; the entry now converges into the SPA (System Management Plugin Center) when wp-maker-admin is active
- Update notifications only appear when wp-maker-admin is active and redirect to the SPA Plugin Center
- Reorganized and documented the bundled nginx security rules
1.6.5
- Added PluginUpdater: Tools WP Maker Plugin Center with version comparison against the version manifest
- New REST API endpoints: GET wpmaker/v1/admin/updates, POST wpmaker/v1/admin/updates/apply
- One-click updates: download zip verify (folder name + manifest.json) backup and replace, with automatic rollback on failure
- Admin notification when plugin updates are available
- Packaging pipeline: OUT_DIR environment variable support; zip top-level folder now matches the plugin folder name
1.6.4
- Dashboard overview enhancements: content trend statistics and uploads size in ContentController
- Improved WP_DEBUG toggle error handling in SystemController
- Other maintenance updates
1.6.3
- Deployment and packaging scripts streamlined to the core plugin list (basic, admin, auth, app, ai)
1.6.2
- Version bump to align the plugin header; no functional changes
1.6.1
- Security hardening: escaped security error output; replaced unlink()/date()/mt_rand() with WordPress-native functions
- WP_Filesystem-based writability check for wp-config.php (Plugin Check compliance)
- Input handling: wp_unslash() for server variables with justified suppressions for security-context checks
- Removed manual load_plugin_textdomain() (WordPress.org loads translations automatically)
- readme.txt fully translated to English
- Plugin URI updated to https://aiwp.pro
1.6.0
- Streamlined admin customization: removed avatar, privacy menu, site health, and other features already replaced by the SPA
- Image optimization (WebP conversion, rename modes, quality) now uses ACF configuration
- Security switch moved from the Admin Bar to the SPA dashboard (REST API + Switch)
- Settings pages support a no-ACF fallback: OptionsController parses acf-json and reads/writes the options table directly
- Batch processing queue split into the standalone wp-maker-system plugin (with Action Scheduler)
- WatermelonDB data sync split into the standalone wp-maker-system plugin
1.5.3
- Synced manifest.json and index.php version numbers
- Improved the modular loading chain and delayed registration for external modules
- Optimized ACF field-group auto-loading and configuration reading
1.5.2
- Enhanced REST API security (IP whitelist, anonymous comment control, route blocking)
- Improved the image optimization batch queue
- Added Feishu visitor notifications and FluentChat Feishu notifications
1.5.0
- Refactored into a modular platform core framework
- Introduced ModuleManager and FeatureRegistry
- Added WatermelonDB sync protocol support
