Chimy’s AI Coding Lab

Description

Chimy’s AI Coding Lab is the platform core of the WP Maker plugin series: module management, unified REST API, security hardening, and ACF infrastructure. A modern React-based SPA admin is built in and replaces the native WordPress admin experience within its own menu, so no separate admin plugin is required. The Plate-based rich text editor, batch processing queue, WatermelonDB data synchronization, WP-Cron management, Transients management, the site & optimization module (image compression, WebP generation, REST API access control, site icon), the authentication system (SPA login/registration, phone login, QR code login, password recovery), AI capabilities (service connectors, chat completion, vision/OCR, batch content completion, AI article generation), the app configuration APIs (feature toggles, navigation entries, version management), and app resource hosting are all built in. Since 2.0.0, every former wp-maker-* companion plugin has been merged into this single plugin.

No companion plugins are required: what used to ship as the wp-maker-* plugin series (admin SPA, authentication, app management, AI, system tools, site & optimization, rich text editor, resource hosting) is now delivered together in this one plugin.

Core Capabilities

  • Modular platform — manifest.json-driven module discovery, registration, and enablement management; both built-in modules and external plugins can register
  • Built-in SPA admin — Notion-style React admin with content management, saved database views, media library, comments, users, a command palette, and consolidated settings; served from the bundled build/ directory over the wpmaker/v1/admin/* REST API
  • Site & optimization built in — post editor (wpautop, featured images), site icon customization, media upload enhancements (SVG/JSON, renaming, EXIF stripping, dimension caps), image compression, WebP sidecar generation with front-end replacement, and IP-based REST API access control
  • Application support — private-site APIs (site creation/search/details), CORS support; WatermelonDB sync endpoints built in
  • Built-in editor & system tools — Plate full-screen rich text editor; batch processing queue with Action Scheduler (batching, progress tracking, cancel/retry), WP-Cron management, and Transients management
  • AI & app modules built in — AI service connectors with chat completion, vision/OCR, batch content completion, and AI article generation; app configuration APIs for the companion app (feature toggles, navigation entries, version management); app resource hosting with an apps directory and entry points
  • Local avatars — preset SVG avatars available on the profile page
  • Security — malicious request blocking, SQL injection protection, XSS protection, directory traversal protection, login rate limiting, XML-RPC disabling; one-click temporary shutdown from the SPA dashboard

Modular Architecture

All modules are described by manifest.json with metadata and SPA menu configuration, managed by ModuleManager.

External plugins can register via ModuleManager:

\WPMaker\Core\ModuleManager::registerModulePath( __DIR__ );

REST API Namespaces

  • wpmaker/v1/admin/* — platform administration (options, modules, system, network, categories, comments, users, etc.)
  • wpmaker/v1/sync/* — WatermelonDB data sync (pull/push, built in)
  • wpmaker/v1/sites/* — private-site APIs (built in)
  • wpmaker/v1/login, /register, /qr-login/*, /auth/* — authentication, QR code login, and token management (built in)

Dependencies

  • No required companion plugins — all former wp-maker-* companion plugins are built in. Custom code can hook into the batch processing queue via the wpmaker_batch_handle_* handlers
  • Bundled libraries: Action Scheduler, erusev/parsedown, chillerlan/php-qrcode

Technical Requirements

  • PHP 7.4 or higher
  • WordPress 6.0 or higher

External services

This plugin does not contact any external service on its own. Previous versions optionally fetched a component catalog from Gitee inside the Case Portal; that feature has been removed.

Privacy

This plugin does not collect user data, does not perform remote telemetry, and does not send any information to the author’s server.

  • CORS — cross-origin response headers are configured to support app requests; no data is actively sent out

All external interactions are enabled explicitly by the site administrator; the plugin itself has no phone-home behavior.

Screenshots

Installation

  1. Upload the plugin folder to the /wp-content/plugins/ directory
  2. Activate “Chimy’s AI Coding Lab” in the WordPress Plugins menu
  3. Open the “WPMaker” top-level menu to use the built-in SPA admin

FAQ

Where can I find documentation and support?

Documentation is available at https://aiwp.pro. For support, please use the WordPress.org support forum for this plugin.

Is Multisite supported?

Yes. Network-level plugin management and network admin entries are provided.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Chimy's AI Coding Lab” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

2.0.1

  • Admin SPA rebuilt around a Notion-style interface: unified sidebar with collapsible Content / Manage sections, expandable recent items per content type, favorites, a dedicated Trash page with restore and permanent delete, and a single Settings entry that gathers the configuration screens
  • Content lists are now saved database views — multiple view tabs per post type, filtering by taxonomy, author, date and any ACF field, sorting, visible properties, board grouping, infinite scroll with a running total, and inline row actions
  • New Cmd/Ctrl+K command palette: aggregated search across content, media and users, plus an AI command mode that turns a natural-language request into an operation plan validated against a server-side API allowlist
  • Local avatars: the Gravatar fallback has been removed — preset SVG avatars and a generated default avatar are now used across the SPA, the profile page and user lists
  • New REST endpoints: admin/command-search (grouped search results) and ai/command (AI operation planning); admin/list now accepts structured filters, and batch actions gained a restore action
  • Site icon is now exposed to the admin SPA
  • Streamlined admin navigation: the Appearance, Plugins, System, Modules, Plugin Center, Batch Progress, Navigation Config and APP Options screens were removed, and site plugin management moved under the network section

2.0.0

  • Single-plugin delivery completed: the remaining standalone plugins are now built in — AI (service connectors, chat completion, vision/OCR, batch content completion, AI article generation), app management hub (feature toggles, tab navigation, offline branding, version management), and app resource hosting (apps directory, entry points, resource service)
  • Feishu app credentials moved to a WordPress option (autoload disabled) with one-time file migration; the companion Node service pulls its configuration from a localhost-only REST endpoint
  • Removed the Support page from the admin SPA

1.11.0

  • The authentication module (formerly the standalone wp-maker-auth plugin) is now built in: SPA login page takeover on wp-login.php, account/email/phone password login, APP registration, QR code login (tickets, public tickets, claim), persistent token system with X-WPMaker-Auth header, password recovery, email verification, and auth settings

1.10.0

  • The site & optimization module (formerly the standalone wp-maker-site plugin) is now built in: site management endpoints (create/search/details/mine), image compression with EXIF stripping and dimension caps, WebP sidecar generation with front-end replacement and bulk optimization, IP-based REST API access control, and site icon customization