Live Previews 1.0.0-RC1
Pre-release
Pre-release
·
47 commits
to develop
since this release
First release candidate of Live Previews: safe-to-share, time- and
usage-limited preview links that let a reviewer without a WordPress account view
a draft. Published for internal testing ahead of 1.0.0.
Requires WordPress 6.9 or later and PHP 8.2 or later. Designed for WordPress VIP
but runs on any host.
Added
- Generate a safe-to-share preview link for a draft from the block editor, reusing WordPress's own preview flow so a logged-out reviewer sees the draft as it will publish. (#9, #10)
- Set how long each link lasts, from a configurable, filterable set of expiration options, including an optional effectively-indefinite lifetime. The editor pre-selects 8 hours, changeable with the
live_previews_default_expirationfilter. (#10, #17) - Limit a link by the number of distinct viewers, including one-time and unlimited links; crawler and unfurler requests never spend a view. (#11)
- Manage a post's preview links from the editor — see each link's usage and time remaining, identify it by a token hint, and revoke it. (#12, #17)
- Audit and revoke every preview link on the site from a top-level Preview Links screen, with per-page screen options and contextual help. (#34)
- Show a friendly notice when a link has expired, been revoked, or been exhausted, while unknown links stay a plain 404 so drafts cannot be enumerated. How much of the reason is disclosed is filterable, for sites that would rather say less. (#15, #31)
- Sweep expired and revoked links automatically after a retention period, so a reviewer returning to a stale link is told why it stopped working rather than seeing a 404. The period is set from the VIP Dashboard through the optional
dead_link_grace_periodvalue and overridden by thelive_previews_dead_link_grace_periodfilter, falling back to 21 days whenever the value is absent or unusable — a blank field never means "delete links the moment they expire". (#32) - Create and list preview links through the Abilities API, so MCP clients, the AI Client, and the abilities REST runner mint links under the same rules as the editor. (#28, #30)
- Report whether the cleanup sweep is scheduled and actually running, as a Site Health check under Tools → Site Health.
- Ship translatable strings with a bundled POT, so the plugin can be localised without a WordPress.org language pack.
Security
- Store only a hash of each token, enforce every link limit server-side, and keep drafts visible to link holders alone — preview requests are also marked no-index so a shared link cannot be indexed by search engines. (#18)
Notes for VIP
- Every value in
VIP_LIVE_PREVIEWS_CONFIGis optional. Defining the constant is what enables the integration;dead_link_grace_periodis the only value the plugin reads, and it runs on its built-in defaults without it. (#35) - VIP support links in contextual help appear only on VIP-hosted sites, where VIP support can answer them; elsewhere they point at the plugin's own support channel. (#35)