v0.9.0
First release on the 0.9 line. Feature-complete pre-store-prep; a dedicated v0.10.x phase will handle the permissions audit, bundle identifier change, and store listing assets before the v1.0 directory release.
Highlights
- Account menu in the popup header. A circular avatar button opens an account dropdown with the logged-in user's display name, role (Super Admin / Administrator / Editor / etc.), profile link, and Gravatar shortcut when applicable. Sourced from the WordPress admin bar.
- Extension options page at
chrome://extensions→ Details → Extension options (Safari: Settings → Extensions → preferences pane). Browser-wide defaults: "Hide admin bar by default" (global override of the per-site toggle), "Show site information panel (experimental)," and "Clear all data." - Admin bar shown by default. New WordPress sites now show the admin bar unless explicitly toggled off in the popup (or globally hidden via "Hide admin bar by default" on the new options page). Closes the muscle-memory concern from #6.
- Toolbar icon redesigned for contrast on any browser chrome. Full-bleed colored circles with a white W: WordPress blue when logged in, dark gray when logged out, dark gray with a diagonal slash for non-WP pages. The opaque background keeps the icon legible against dark Chrome themes, Firefox themes, and so on.
- Site Information panel is now an experimental opt-in. Asset-path plugin detection is inherently lossy — duplicates from plugins with multiple asset paths, mu-plugins and drop-ins leaking through. The panel is off by default; enable it in the options page if you want it.
Smaller but worth knowing
- Admin bar hide is now self-attributed in the inspector (
/* hidden by the WordPress Browser Extension */) and via aconsole.infoline, so a hidden admin bar is traceable to its source. - Site Information plugin list no longer flickers during the REST load (#7).
- Plugin homepage URLs from REST are scheme-validated before being opened — rejects
javascript:/data:smuggled through a plugin'sPlugin URIheader.
Under the hood
- Popup bundle migrated from
10up-toolkitto@wordpress/scripts. - REST root from
<link rel="https://api.w.org/">is now origin-validated; previously a hostile page could redirect the extension's authenticated REST calls (with cookies and the WP nonce attached) off-origin. - Admin bar profile link is origin- and path-validated before navigation.
Known limitations
- Safari toolbar icon — full-color rendering (#15). Safari template-renders extension toolbar icons; all three states show as the same system tint with only the slash distinguishing "not a WordPress site." Investigating workarounds in v0.9.1.
- Safari mobile preview window sizing in fullscreen Spaces (#13). Use Safari outside of fullscreen mode if the mobile preview window opens at the wrong size.
Install
Chrome / Edge
- Download
wordpress-browser-extension-0.9.0-chrome.zipand unzip. chrome://extensions→ enable Developer mode → Load unpacked → select the unzipped folder.
Safari (ad-hoc signed; tier 2 of the four distribution tiers — see SAFARI.md)
- Download
wordpress-browser-extension-0.9.0-safari.zipand unzip. - Drag
WordPress Browser Extension.appto Applications. - First launch: right-click the app → Open → confirm the Gatekeeper warning. (macOS shows the warning because the build is ad-hoc signed, not signed with an Apple Developer ID — distributable beta status, not a tampered binary.)
- Quit the launched container app.
- Safari → Settings → Extensions → enable WordPress Browser Extension.
- If Safari refuses to enable an unsigned extension, turn on Safari → Develop → Allow Unsigned Extensions. This resets each Safari quit.
For development builds (clone + Xcode), see SAFARI.md.
Roadmap
See ROADMAP.md for the v0.9.1, v0.10.x, and v1.0 plans.