Chimy's AI Coding Lab

Description

Chimy’s AI Coding Lab is the platform core of the WP Maker plugin series: module management, unified REST API, security hardening, and ACF infrastructure. A modern React-based SPA admin is built in and replaces the native WordPress admin experience within its own menu, so no separate admin plugin is required. Advanced capabilities (image/media optimization, AI, authentication, data synchronization, batch processing, etc.) are provided by dedicated standalone plugins in the wp-maker-* series.

Some features have been split into standalone plugins (wp-maker-* series) that can be installed on demand; they are currently hosted on Gitee and will be listed on the official WordPress.org directory progressively.

Core Capabilities

  • Modular platform — manifest.json-driven module discovery, registration, and enablement management; both built-in modules and external plugins can register
  • Built-in SPA admin — React-based modern admin with content management, media library, comments, users, plugins, appearance, and settings; served from the bundled build/ directory over the wpmaker/v1/admin/* REST API
  • Admin customization — post editor (wpautop, featured images), general options (site icon), and media upload enhancements (SVG/JSON, WebP, renaming) are provided by the wp-maker-site plugin (site & optimization module)
  • Application support — private-site APIs, CORS support; WatermelonDB sync is provided by the standalone wp-maker-system plugin
  • Local avatars — preset SVG avatars available on the profile page
  • Security — malicious request blocking, SQL injection protection, XSS protection, directory traversal protection, login rate limiting, XML-RPC disabling; one-click temporary shutdown from the SPA dashboard

Modular Architecture

All modules are described by manifest.json with metadata and SPA menu configuration, managed by ModuleManager.

External plugins can register via ModuleManager:

\WPMaker\Core\ModuleManager::registerModulePath( __DIR__ );

REST API Namespaces

  • wpmaker/v1/admin/* — platform administration (options, modules, system, network, categories, comments, users, etc.)
  • wpmaker/v1/sync/* — WatermelonDB data sync (pull/push, provided by the standalone wp-maker-system plugin)
  • wpmaker/v1/sites/* — private-site APIs

Dependencies

  • Batch queue — provided by the standalone wp-maker-system plugin (with Action Scheduler), not distributed with this plugin

Technical Requirements

  • PHP 7.4 or higher
  • WordPress 6.0 or higher

External services

This plugin does not contact any external service on its own. Previous versions optionally fetched a component catalog from Gitee inside the Case Portal; that feature has been removed.

Privacy

This plugin does not collect user data, does not perform remote telemetry, and does not send any information to the author’s server.

  • CORS — cross-origin response headers are configured to support app requests; no data is actively sent out

All external interactions are enabled explicitly by the site administrator; the plugin itself has no phone-home behavior.

Screenshots

Installation

  1. Upload the plugin folder to the /wp-content/plugins/ directory
  2. Activate «Chimy’s AI Coding Lab» in the WordPress Plugins menu
  3. Open the «WPMaker» top-level menu to use the built-in SPA admin

FAQ

Where can I find documentation and support?

Documentation is available at https://aiwp.pro. For support, please use the WordPress.org support forum for this plugin.

Is Multisite supported?

Yes. Network-level plugin management and network admin entries are provided.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Chimy's AI Coding Lab” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.7.14

  • The admin SPA (formerly the standalone wp-maker-admin plugin) is now built in: runtime (AdminSpa), REST endpoints, local avatars, manifest, and bundled build/ assets
  • Removed the Case Portal/Case Guide showcase pages
  • Cleaned up legacy mappings for discontinued content types (reward, book, chat_group, wp_app)

1.7.13

  • Case Portal catalog refreshed: icon and type mappings updated; discontinued entries (wp-maker-chat, wp-maker-network, wp-maker-wpopt-integration, wp-maker-baidu-tongji) pruned
  • Case Portal now features entries for the core platform (chimys-ai-coding-lab) and the resource host (wp-maker-resource)
  • ContentController and CaseGuide refinements
  • Release pipeline automation improvements across packaging and deployment scripts
  • Readme updated with accurate screenshots and external-service wording for the WordPress.org directory

1.7.5

  • Manifest path resolved via plugin_dir_path() instead of a brittle relative dirname() traversal
  • User deletion now requires the target-specific delete_user capability
  • Remote address (REMOTE_ADDR) is sanitized before use in rate-limit transients and the 404 log

1.7.4

  • Case Portal styles/scripts now loaded via the WordPress enqueue API (admin_enqueue_scripts + wp_add_inline_style/script)
  • User management hardening: role validation on creation, promote_user requirement for role assignment, and target-specific edit_user checks on user updates
  • All global classes prefixed with CHIMAICO_ and the no-ACF fallback option keys changed to chimaico_options_ (unique naming per WordPress.org guideline)

1.7.3

  • Refactored the codebase: core logic consolidated under includes/ (REST controllers, Case Portal showcase, module manager)

1.7.2

  • Removed all Composer dependencies; the plugin now has zero third-party runtime dependencies
  • Case Portal repositioned as a pure showcase: per-card download buttons removed, documentation links only
  • Admin copy refined to be user-facing (catalog status, update button, no download-oriented wording)

1.7.1

  • Added the Case Portal: a top-level admin menu (no WP Maker Admin required) listing the catalog of plugins/themes/Apps developed by Chimy’s AI Coding Lab, with documentation links
  • Added on-demand guidance: a dismissible admin notice and a «Current site suggestions» block in the Case Portal that only list missing core companion plugins (Admin/Auth/App/Sync/AI); the guidance disappears once they are enabled
  • Case Portal menu is not registered when wp-maker-admin is active, since the SPA Plugin Center provides the entry
  • Case Portal catalog is fetched from Gitee only on an explicit admin action (the «Update catalog» button), never automatically
  • Removed the custom plugin updater; plugin updates are handled by the official WordPress.org channel

1.6.6

  • Removed the native Plugin Center admin page; the entry now converges into the SPA (System Management Plugin Center) when wp-maker-admin is active
  • Update notifications only appear when wp-maker-admin is active and redirect to the SPA Plugin Center
  • Reorganized and documented the bundled nginx security rules

1.6.5

  • Added PluginUpdater: Tools WP Maker Plugin Center with version comparison against the version manifest
  • New REST API endpoints: GET wpmaker/v1/admin/updates, POST wpmaker/v1/admin/updates/apply
  • One-click updates: download zip verify (folder name + manifest.json) backup and replace, with automatic rollback on failure
  • Admin notification when plugin updates are available
  • Packaging pipeline: OUT_DIR environment variable support; zip top-level folder now matches the plugin folder name

1.6.4

  • Dashboard overview enhancements: content trend statistics and uploads size in ContentController
  • Improved WP_DEBUG toggle error handling in SystemController
  • Other maintenance updates

1.6.3

  • Deployment and packaging scripts streamlined to the core plugin list (basic, admin, auth, app, ai)

1.6.2

  • Version bump to align the plugin header; no functional changes

1.6.1

  • Security hardening: escaped security error output; replaced unlink()/date()/mt_rand() with WordPress-native functions
  • WP_Filesystem-based writability check for wp-config.php (Plugin Check compliance)
  • Input handling: wp_unslash() for server variables with justified suppressions for security-context checks
  • Removed manual load_plugin_textdomain() (WordPress.org loads translations automatically)
  • readme.txt fully translated to English
  • Plugin URI updated to https://aiwp.pro

1.6.0

  • Streamlined admin customization: removed avatar, privacy menu, site health, and other features already replaced by the SPA
  • Image optimization (WebP conversion, rename modes, quality) now uses ACF configuration
  • Security switch moved from the Admin Bar to the SPA dashboard (REST API + Switch)
  • Settings pages support a no-ACF fallback: OptionsController parses acf-json and reads/writes the options table directly
  • Batch processing queue split into the standalone wp-maker-system plugin (with Action Scheduler)
  • WatermelonDB data sync split into the standalone wp-maker-system plugin

1.5.3

  • Synced manifest.json and index.php version numbers
  • Improved the modular loading chain and delayed registration for external modules
  • Optimized ACF field-group auto-loading and configuration reading

1.5.2

  • Enhanced REST API security (IP whitelist, anonymous comment control, route blocking)
  • Improved the image optimization batch queue
  • Added Feishu visitor notifications and FluentChat Feishu notifications

1.5.0

  • Refactored into a modular platform core framework
  • Introduced ModuleManager and FeatureRegistry
  • Added WatermelonDB sync protocol support