=== Easily manage all your WordPress code ===
Requires at least: 5.6
Requires PHP: 7.4
Tested up to: 7.1
Stable tag: 1.4.1

WPCodeBox is a complete WordPress snippet manager. With WPCodeBox you can manage all of your site's code without touching functions.php.

== Description ==

= WPCodeBox - Complete WordPress Snippet Manager =

WPCodeBox is a complete WordPress snippet manager. With WPCodeBox you can manage all of your site's code without touching functions.php.

== Changelog ==

= 1.4.1 (Released on Sep 22nd 2026) =

* Fix: Generated MCP configurations now use a stable server name based on each site's URL, including subsites and different ports. Setup prompts preserve other sites' connections and check for existing names before adding a server.
* Fix: MCP setup prompts now include the selected client's configuration and explain how to set up Claude Desktop when the assistant cannot access local files. Added JSON merge instructions and local credential guidance instead of promising automatic setup.
* Improvement: PHP snippets set to "Manual (On Demand)" now show a small play badge on their icon in the editor sidebar and Snippet Manager.
* Fix: Editing a snippet from the Snippet Manager now opens the requested snippet instead of restoring the previous selection, including when local and cloud lists finish loading in either order.
* Fix: Restored the public PHP API's execution-by-ID behavior for integrations such as WP All Import. `Api::runSnippet()` can again execute Function Editor snippets set to "Do not run", so import helper functions are available without changing existing snippets. The editor Run endpoint and MCP run tool continue to require "Manual (On Demand)" snippets.
* Fix: Local folder drag-and-drop order now saves when the drag ends, including drops onto titles or icons. Cloud folder IDs are excluded from local saves, the editor keeps its folder state synchronized, and failed saves show an error and reload the saved order.
* Fix: Fixed the Safe Mode link on the fatal-error screen.
* Fix: External-token execution now respects safe mode. Newly generated Functionality Plugins also use the improved recovery URL handling.
* Fix: Fatal errors in callbacks registered by snippets can now be attributed after the initial snippet execution has finished, so the responsible snippet is disabled on shutdown. Unrelated failures are not attributed to the last snippet that ran, and direct snippet errors retain their editor line numbers.
* Fix: MCP `wpcodebox_list_snippets` now includes every snippet in its flat `snippets` array, including snippets inside folders. The folder index remains available, and snippet `folderId` values are returned as integers.
* Fix: MCP calls now preserve actionable errors for missing snippets, permissions, invalid hooks and conditions, invalid folder names, and snippets that cannot be run on demand. Unexpected internal exception details remain hidden.


= 1.4.0 (Released on Sep 8th 2026) =

* New Feature: **Snippet Manager** — a dedicated library view for browsing, searching, filtering, organizing, and bulk-managing snippets. Switch between it and the classic editor from the toolbar; the selected view is remembered across reloads. A read-only Cloud section lists cloud folders and snippets with one-click download to local.
* New Feature: **Tags** — assign tags to snippets, search and filter by tag or "Untagged", customize tag colors per browser, and edit tags from either the Snippet Manager or EditSnippet sidebar.
* New Feature: **Bulk and drag-and-drop workflows** — select all/none or multiple snippets with a live selection count, then move, tag, enable, disable, or delete them together. Cards can be moved to folders or manually reordered with optimistic UI updates; `/` focuses search and `Esc` clears selection.
* New Feature: **More ways to find snippets** — sort by Manual order, Name, or Last modified in both manager and classic sidebar; filter by type, tag, enabled/disabled/errored status, and whether conditions are set. Errored cards show a warning badge and error tooltip. Search is debounced and case-insensitive across snippet fields and tags.
* New Feature: **Duplicate snippets in the Snippet Manager** — copy code, placement, conditions, and tags into the same folder as a disabled "Copy of …" snippet.
* Improvement: With Manual sort active, All Snippets and Cloud All group cards by folder and show loose snippets under "No folder". Cards now show last-modified timestamps, open in the editor on double-click, and use the styled app dialog for delete confirmation.
* Improvement: Snippet Manager icons, filters, dark-mode borders, and the upward-opening Move picker now match the rest of the editor. Folder moves/reorders update instantly, a duplicate-load guard prevents runaway reloads, and plugin-page CSS loads early to prevent the white-line/unstyled-content flash.

* New Feature: **MCP / AI Access** — connect compatible AI clients to list, search, and read snippets, folders, tags, and revisions, and explicitly opt in to create, update, enable/disable, run, or delete operations. Read tools are the default when MCP is enabled; write and execute tools remain off until an administrator enables them. The standalone MCP endpoint accepts Application Password authentication only, requires `manage_options`, applies the per-tool allowlist and input validation, rate-limits calls, and audit-logs every request.
* New Feature: **MCP snippet placement and conditions** — create/update tools accept validated `hooks` and condition-builder groups. Agents can select the named UI insertion points or raw actions, use multiple placements for JS/CSS/HTML, and configure editable Location, URL, content, taxonomy, user, device, time, and weekday rules; Custom PHP conditions remain unavailable to agents.
* New Feature: **WordPress Abilities API support** — all 14 tools are registered under the `wpcodebox` category on WordPress 6.9+, with `readonly` and `destructive` annotations and core `wp-abilities/v1` discovery/execution routes. Both surfaces share the tool catalog, per-tool allowlist, input validation, `manage_options` capability check, and audit log. Unlike the standalone MCP endpoint, core Abilities REST also permits nonce-protected cookie authentication as well as Application Passwords and does not use WPCodeBox's MCP rate limiter. Disabled tools return a clear administrator-enable message.
* Fix: Abilities registered for WordPress 6.9+ now carry MCP channel metadata, so AI clients connecting through core's ability-based MCP adapters see exactly the tools an administrator enabled instead of every registered ability. The execution-time allowlist check still gates each call.
* Improvement: MCP settings provide ready-to-copy Claude Desktop, Cursor/VS Code, and Claude Code configurations, plus higher-contrast dark-mode styling, a write-tool warning, and bulk enable/disable controls.
* Fix: MCP tool names now use Anthropic-compatible underscores such as `wpcodebox_list_snippets`; saved allowlists using the former slash names are recognized and migrated. Reported by a customer in June 2026.
* Fix: The MCP endpoint responds at `plugins_loaded` so canonical/multilanguage plugins cannot redirect the request before the client receives it.
* Fix: Missing or quarantined MCP tool files are skipped instead of taking WordPress into recovery mode, and each skipped tool is logged once per occurrence until restored. Reported by RC testers on Cloudways.
* Improvement: The MCP run tool and in-app Run button now use one canonical one-shot PHP execution path. It strips only a leading PHP open tag, preserves embedded `<?php` text, rejects non-one-shot snippets, and always cleans up its output buffer after missing snippets or thrown errors.

* New Feature: **Runtime PHP error detection** — hook-time fatal errors are caught, attributed, recorded, and disable the affected snippet without white-screening the site. Exceptions are recorded but leave the snippet enabled, while shutdown handling attributes otherwise uncatchable fatal errors to the executing snippet. This replaces WordPress recovery-mode emails for caught snippet errors with an in-app error state.
* Improvement: Repeated identical snippet exceptions no longer rewrite the snippet row or duplicate the PHP error-log entry on every occurrence; a changed message or editor line is still recorded immediately.
* New Feature: The same runtime guard is generated into standalone **Functionality Plugin** files, where snippet failures are written to the PHP error log without crashing the site even when WPCodeBox is deactivated.
* Fix: Runtime error line numbers now point to the matching editor line for named hooks, external triggers, snippets without an opening tag, and snippets with leading blank lines.
* Fix: External-trigger PHP snippets that end in HTML mode now generate parseable wrappers in both normal and Functionality Plugin execution.
* Fix: Failed saves now show a "The snippet was NOT saved" toast. Incomplete/truncated save requests and null database updates are rejected instead of blanking a snippet, and empty revisions cannot be reverted over working code. Previously stored revisions remain available for recovery.
* Improvement: Saves upload only fields the server needs instead of revision history and previous run output, avoiding multi-megabyte requests for large snippets.

* Fix: **Functionality Plugin generation and ordering** — tokenizer-based HTML-mode detection no longer mistakes `?>` inside strings for a real close tag, Snippet Order is honored on every sync, and equal order/placement/priority ties fall back to creation order. Reported by Jean-Marc Czudek.
* Perf: Functionality Plugin bulk generation now reorders its include list once after all snippets are written instead of rereading and rewriting it after every snippet.
* Fix: Functionality Plugin Gutenberg CSS now evaluates its URL correctly; Gutenberg JavaScript runs; snippets also run in the Full Site Editor iframe; each editor stylesheet has a unique handle; and generated inline CSS/JS is escaped.
* Improvement: The Functionality Plugin settings dialog now uses the same sectioned layout, status toggle, and dark-mode styling as the MCP settings modal. Body text is legible in dark mode, the download button's icon no longer wraps onto its own line, and the duplicate-snippet-names warning is a proper alert listing the affected snippets instead of faint grey text.
* Fix: A failed Functionality Plugin enable/disable no longer leaves its dialog stuck on "Working…", and a failed download now reports the failure instead of throwing while reading the server's response.
* Fix: External JavaScript and CSS snippets now run at every selected insertion point in runtime and Functionality Plugin output, including special-hook remapping and each hook's selected priority.
* Fix: Generated Global CSS `<style>` tags no longer include the obsolete `type="text/css"` attribute; JavaScript output remains unchanged.
* Fix: CSS minification now shortens repeated-pair hex colors correctly (`#ffffff` to `#fff`, not `#ff`) and handles the full hexadecimal range. Reported by a customer after 1.3.1.
* Fix: Folder exports include their snippets and serialize folder IDs as numbers; folder imports create snippets in their destination in one request and refresh once at the end. Reported by Jason Janes @ RoatanYP.com.
* Fix: Sidebar folder drops keep the in-memory list synchronized, and updating a downloaded cloud snippet refreshes and displays its placement hooks correctly.
* Fix: Revision and AI execution timestamps use the WordPress timezone, locale, and DST-aware `wp_date()` formatting. Reported by Jayron Castro @ Kstros.com.
* Fix: **WordPress and other plugins' admin JavaScript no longer breaks on the WPCodeBox page.** The code editor loads as an AMD bundle whose loader installs a global `define()`, and WordPress' own scripts registered themselves with it instead of publishing the globals everything else expects — and because WordPress serves several of those scripts concatenated into a single file, the first collision aborted the rest of that file too. That left `wp.element`, `moment`, and `jQuery.hoverIntent` undefined, which broke the admin bar's hover menus and any plugin building on WordPress' React packages, Secure Custom Fields among them. The editor now initializes after WordPress has finished running its own scripts and releases the AMD marker once it is up, while keeping the loader available for the syntax-highlighting files it fetches on demand. Long-standing rather than new in 1.4.0, and only ever affected the WPCodeBox admin page.
* Internal: Added tag and bulk snippet REST endpoints plus optional `folderId` creation, Jest coverage for exports/search and the editor loader guard, and shared sorting/tag-color helpers between the manager and editor.

* Note for hosts/security tooling: if your malware scanner flags WPCodeBox's MCP files, whitelist `wp-content/plugins/wpcodebox2/src/Mcp/`.


= 1.3.1 (Released on Feb 2nd 2025) =

* New Feature: Added optional capability for the AI model to execute code to retrieve the current WordPress context
* New Feature: Added support for up-to-date Gemini models
* New Feature: Added OpenRouter model integrations
* New Feature: Addded custom model option
* New Feature: Added an option to hide both panels using Ctrl + ~
* New Feature: Added a configurable setting for the number of revisions to save
* Fix: SCSS minification issues
* Fix: CSS minification incorrectly altering colors in some cases
* Fix: SCSS/CSS formatting replacing single quotes with double quotes


= 1.3.0 (Released on Jan 9th 2025) =

* New Feature: WPCodey AI Chat Integration (BYOK)
* New Feature: AI inline code modifications and generation
* New Feature: Nested CSS handling in the editor
* New Feature: Buttons to collapse the side panels
* New Feature: Added a clear search button
* Improvement: Improved plugin UI
* Improvement: Improved variable handling in the editor
* Improvement: Added revert revision button
* Improvement: Changed editor class names to avoid conflicts
* Improvement: Search also works in the snippet description
* Improvement: Open folders only if there are search results, and close them after
* Improvement: Various UI/UX improvements
* Bugfix: Saving on Safari only works the first time, then it throws an error
* Bugfix: CSS minifier incorrectly handles double quotes
* Bugfix: Formatting breaks when SCSS code contains comments
* Bugfix: Export file is empty when exporting a single snippet from a folder
* Bugfix: Removed unused JS libraries
* Bugfix: Deprecation warnings for latest PHP versions
* Housekeeping: Updated JS libraries to the latest versions
* Housekeeping: Started migrating the legacy code to modern React


= 1.2.1 (Released on Jul 8th 2025) =

* Bugfix: Bug when external CSS is rendered in the Functionality Plugin
* Bugfix: Missing collation from the revisions table causing issues in some cases
* Bugfix: Screen Options button sometimes appearis in the UI
* Bugfix: UI disappears in edge case when the Functionality Plugin is enabled

= 1.2.0 (Released on Jul 2nd 2025) =

* New Feature: Show snippet conditions overview on the snippet edit page
* New Feature: First version of the WPCodeBox API for 3rd party integrations
* Improvement: Show warning if the ZipArchive library is not installed and trying to generate plugins
* Improvement: FP Author URI hardcoded to wpcodebox.com
* Bugfix: "Current URL Is" condition throws error when the FP is enabled
* Bugfix: Generate plugin and FP Download not working correctly when plugin name is not "wpcodebox2"
* Bugfix: Error in logs when the FP is enabled and editing a snippet
* Bugfix: Warnings when the FP is enabled and temp folder is not writable
* Bugfix: Snippet description not updated until page refresh when downloading a snippet from the cloud
* Bugfix: Added the correct safe mode link on the WPCodeBox Error page
* Bugfix: Current user role condition error when the FP is enabled
* Bugfix: Invalid zip when generating plugins on certain server configs

= 1.1.1 (Released on May 22nd 2024) =

* New Feature: Show snippet conditions overview on the snippet edit page
* New Feature: First version of the WPCodeBox API for 3rd party integrations
* Improvement: Show warning if the ZipArchive library is not installed and trying to generate plugins
* Improvement: FP Author URI hardcoded to wpcodebox.com
* Bugfix: "Current URL Is" condition throws error when the FP is enabled
* Bugfix: Generate plugin and FP Download not working correctly when plugin name is not "wpcodebox2"
* Bugfix: Error in logs when the FP is enabled and editing a snippet
* Bugfix: Warnings when the FP is enabled and temp folder is not writable
* Bugfix: Snippet description not updated until page refresh when downloading a snippet from the cloud
* Bugfix: Added the correct safe mode link on the WPCodeBox Error page
* Bugfix: Current user role condition error when the FP is enabled
* Bugfix: Invalid zip when generating plugins on certain server configs

= 1.1.0 (Released on April 11th 2024) =

* New Feature: Export snippets to plugin
* New Feature: Possibility to download the Functionality Plugin
* New Feature: JSON Snippet support (for creating custom ACF Gutenberg Blocks)
* New Feature: Added “Do not render” option for CSS and JS snippets
* New Feature: Sign the code in the Functionality Plugin
* New Feature: Ability to white label the Functionality Plugin
* Improvement: Removed eval from custom conditions in the Functionality Plugin and the generated plugins
* Improvement: Removed snippet IDs from the Functionality Plugin
* Improvement: Functionality Plugin respects folder structure
* Improvement: Various Functionality Plugin improvements and cleanup of generated code
* Improvement: Added “Exactly Matches” option to the URL condition
* Improvement: Support for nested SCSS partials
* Improvement: Removed the auto-reload code from the Functionality Plugin and used it from WPCodeBox. This was breaking the FP when WPCodeBox was removed
* Improvement: Functionality Plugin revamp based on user feedback (bugfixes and improvements)
* Improvement: Add the ability to add API_KEY in wp-config.php file (define(‘WPCB_API_KEY’, ‘YOUR_API_KEY’);)
* Improvement: Disabled autocomplete in CSS comments
* Improvement: "Upload to cloud" changed to "Update&quot when the snippet is already saved to the cloud
* Improvement: Top bar text changes so it can fit on a single row, show the shortcuts in tooltips, and show the relevant key shortcuts based on OS (Cmd on Mac and Ctrl on PC)
* Improvement: Move external CSS and JS snippets to the Functionality Plugin when it is enabled instead of loading them from the wp-uploads folder
* Improvement: Updated the SCSS compiler library to the latest version
* Improvement: Namespaced the update library
* Improvement: On smaller displays, the repository buttons are not visible
* Improvement: Optimize repository calls only when the Repository is open
* Improvement: Added separate classes to the Cloud Snippet list so they can be customized using CSS (.cloud-snippet-list)
* Bugfix: Long snippet names caused snippets not to save
* Bugfix: Snippet toggles slow in some instances
* Bugfix: Issues with minifying and compiling SCSS introduced in the latest beta
* Bugfix: Enable/Disable toggles appearing for TXT snippets
* Bugfix: Functionality Plugin not updated when moving snippets to folders
* Bugfix: Extra spaces are present around HTML snippets that render using shortcodes
* Bugfix: "Invalid Archive&quot error when uploading WPCodeBox on WordPress v6.4.3
* Bugfix: Hook priority isn’t changeable
* Bugfix: AutomaticCSS autocompletion was not appearing when the line ends in something different than “color:”
* Bugfix: Don’t compile partials that are commented out
* Bugfix: When you download a Cloud Snippet, the description is not updated until a page refresh
* Bugfix: When you add more than one custom PHP condition, the condition editor won’t load for the 2nd one
* Bugfix: In some rare cases (probably when two users edit the snippet at the same time), an empty snippet is created that will break the UI and require deletion from the database
* Bugfix: When you download the UI settings from the cloud, the Codemap option is enabled, regardless of the state
* Bugfix: "Download/Upload from the cloud" is still visible in the context menu, even when using a read-only or disabled API key
* Bugfix: Condition builder appearing for SCSS partials
* Bugfix: PHP warning when Oxygen color list is empty
* Bugfix: Minification converts 0% to 0, but 0% is required for HSL CSS rendering
* Bugfix: External CSS files loaded incorrectly in some cases
* Bugfix: Date conditions don’t work in some cases
* Bugfix: admin_head not working for HTML snippets
* Bugfix: "Format Code" not working in SCSS partials
* Bugfix: When dragging a disabled snippet to a folder, the toggle in the UI shows it as enabled
* Bugfix: CSS Snippets not working in Functionality Plugin
* Bugfix: In Safari, the snippet status overlaps the save button
* Bugfix: When uploading a folder to the cloud, the snippets in the folder are duplicated
* Bugfix: Format code shortcut saves snippet instead of formatting the code
* Bugfix: PHP notice when running WP CLI commands


= 1.0.3 (Released on May 28th 2023) =

* Bugfix: Snippet order not preserved when reordering using drag and drop

= 1.0.2 (Released on May 24th 2023) =

* New Feature: Add "Unlink from Cloud" button to snippets context menu
* Bugfix: Autoreload not working when both WPCodeBox and WPCodeBox 2 are installed
* Bugfix: Snippets with very long descriptions not saved
* Bugfix: Snippets with many conditions not saved
* Bugfix: Folder order not preserved
* Bugfix: In some cases, deleting a cloud snippet causes a local error
* Bugfix: Plain text snippets causing errors in some cases
* Bugfix: In some rare cases, CSS and SCSS snippets can be saved with the plugins_loaded hook
* Bugfix: Functionality plugin generating errors in some cases


= 1.0.1 (Released on May 17th 2023) =

* Bugfix: Warning when both WPCodeBox and WPCodeBox 2 are installed
* Bugfix: Async and defer options not rendered on external JS tags
* Bugfix: Custom shortcode parameters are not passed to custom shortcodes
* Bugfix: Create/download from cloud not working for very large snippets
* Bugfix: Frontend header (After pagebuilders) hook not rendering JS and CSS snippets
* Bugfix: Deprecated notices in PHP 8.2 in the update library
* Bugfix: WPCodeBox error page is showing for non-WPCodeBox errors


= 1.0.0 (Released on May 10th 2023) =

* New Feature: Monaco Editor
* New Feature: Autocomplete for all WordPress actions & filters & Parameters
* New Feature: Functionality Plugin (Experimental)
* New Feature: WooCommerce hooks snippet insertion for HTML and PHP Snippets
* New Feature: Color picker for CSS/SCSS/LESS
* New Feature: SCSS Partials
* New Feature: Render PHP/HTML snippets using custom shortcodes
* New Feature: Actions and custom actions for rendering snippets
* New Feature: Option to render CSS/SCSS after page builders’ CSS
* New Feature: Show local variables in autocomplete
* New Feature: Save UI Settings to the cloud
* New Feature: Execute PHP snippets using a secure external URL
* New Feature: Collapse left/right panes using Ctrl + 1/Ctrl + 2
* New Feature: Added do not render to PHP snippets so they can be included via code
* New Feature: Emmet support
* New Feature: Oxygen Color Integration
* New Feature: Bricks Color Integration
* New Feature: Automatic CSS Integration
* New Feature: WordPress hooks and action reference on hover
* New Feature: Code map that can be disabled in settings
* New Feature: CSS Variables support and autocomplete
* New Condition: User logged in
* New Condition: User device (mobile/desktop)
* Improvement: Use custom tables to store data for better performance
* Improvement: Added info about safe mode on the error page
* Improvement: Show notice when Safe Mode is active
* Improvement: Added “Reload Local Snippets” button
* Improvement: Removed jQuery from Live Reload CSS
* Improvement: Close the context menu when clicking on another snippet
* Improvement: Added post name to the WPCodeBox custom post types
* Improvement: Removed arrow from priority input in Firefox
* Improvement: Complete backend rewrite for improved performance
* Improvement: Better error detection and handling
* Improvement: Add loader when running manual snippets
* Improvement: Allow the saving of SCSS/LESS snippets even if the compilation fails
* Improvement: Action/priority/shortcode are saved to the cloud
* Improvement: Set “plugins_loaded” as the default action for PHP snippets
* Improvement: Make the editor fill the height
* Improvement: Removed the plugins_loaded notice
* Improvement: Added wp_body_open hook
* Improvement: Fire wpcb_snippet_disabled action when a snippet is disabled
* Improvement: Small security improvements
* Bugfix: PHP Notice when using the post parent conditions for posts that don't have a parent
* Bugfix: When editing cloud snippets, the name is not updated in the list automatically
* Bugfix: The key is not checked on autoreload, causing compatibility issues with some plugins
* Bugfix: Snippet status not updated when downloading a snippet from the cloud
* Bugfix: Taxonomy “Is not” condition is not working correctly
* Bugfix: LESS is not working on PHP 8
* Bugfix: Current snippet is not always selected when refreshing the page
* Bugfix: Unsaved changes notification appears when there are no unsaved changes
* Bugfix: Delete snippets from the context menu doesn’t always work
