{"id":349327,"date":"2026-08-21T02:42:48","date_gmt":"2026-08-21T02:42:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/asb-smart-flow\/"},"modified":"2026-08-22T16:11:43","modified_gmt":"2026-08-22T16:11:43","slug":"asb-smart-flow","status":"publish","type":"plugin","link":"https:\/\/fao.wordpress.org\/plugins\/asb-smart-flow\/","author":23542924,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.26.0","stable_tag":"2.26.0","tested":"7.0.4","requires":"6.6","requires_php":"7.4","requires_plugins":null,"header_name":"ASB Smart Flow","header_author":"Asobit LLC","header_description":"AI-assisted writing and a one-handed mobile admin UI for WordPress. Free and complete: generate, rewrite, summarize and proofread posts with your own OpenAI \/ Gemini \/ Claude key (BYOK), passkey (WebAuthn) login, and a fast smartphone admin. Integrates with the ASB plugin family (PWA Engine \/ Calendar Advance \/ LINE Notification \/ Post Thumbnail).","assets_banners_color":"595a5b","last_updated":"2026-08-22 16:11:43","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/asb-smart-flow\/","header_author_uri":"https:\/\/asobit.jp\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":92,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.24.4":{"tag":"2.24.4","author":"asobit","date":"2026-08-21 02:42:26"},"2.25.0":{"tag":"2.25.0","author":"asobit","date":"2026-08-22 03:24:25"},"2.26.0":{"tag":"2.26.0","author":"asobit","date":"2026-08-22 16:11:43"}},"upgrade_notice":{"2.26.0":"<p>Adds an AI revision button to each text block on the PC editor, and a &quot;choose the parts&quot; list on the mobile composer. Nothing you already use changes.<\/p>","2.24.0":"<p>Internal prefix rename (<code>asb_sf_<\/code> \u2192 <code>asbsmfl_<\/code>) requested by the WordPress.org review team. Settings, passkeys and the <code>[asb-img]<\/code> shortcodes already in your posts are migrated automatically. Only custom code hooking <code>asb_sf_*<\/code> filters needs updating.<\/p>","2.23.0":"<p>Security hardening. Note: AI access now defaults to administrators only \u2014 if your authors used AI and you never saved the &quot;Permissions &amp; AI&quot; tab, re-delegate the AI role there once after updating.<\/p>","2.20.0":"<p>Voice dictation, on-phone comment moderation, and offline draft protection. Also fixes the newest OpenAI models. Safe update.<\/p>","2.11.0":"<p>Consistent cross-promotion sidebar (constant layout; Pro siblings now show a review card). Safe update.<\/p>","2.0.0":"<p>ASB Smart Flow is now 100% free \u2014 all previous Pro features ship in this build. Existing license activation is cleared automatically on upgrade.<\/p>","1.15.0":"<p>Plugin renamed to ASB Smart Flow. Existing settings and credentials are migrated automatically on first activation \u2014 no manual steps required.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3658034,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3658034,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3658034,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3658034,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.24.4","2.25.0","2.26.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3658034,"resolution":"1","location":"assets","locale":"","width":780,"height":1688},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3658034,"resolution":"2","location":"assets","locale":"","width":780,"height":1688},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3658034,"resolution":"3","location":"assets","locale":"","width":780,"height":1252},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3658034,"resolution":"4","location":"assets","locale":"","width":780,"height":1600},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3658034,"resolution":"5","location":"assets","locale":"","width":780,"height":1938},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3658034,"resolution":"6","location":"assets","locale":"","width":780,"height":2618}},"screenshots":{"1":"The mobile dashboard with post stats and recent posts.","2":"New Post screen with featured-image preview and media tools.","3":"AI Writer sheet \u2014 mode, instructions, reference material, length and tone.","4":"AI writing result with title suggestions and a body preview.","5":"AI settings \u2014 bring your own OpenAI \/ Gemini \/ Claude key.","6":"ASB plugin family integrations."}},"plugin_section":[],"plugin_tags":[83,2353,434,841,4895],"plugin_category":[],"plugin_contributors":[276744],"plugin_business_model":[],"class_list":["post-349327","plugin","type-plugin","status-publish","hentry","plugin_tags-admin","plugin_tags-ai","plugin_tags-dashboard","plugin_tags-mobile","plugin_tags-smartphone","plugin_contributors-asobit","plugin_committers-asobit"],"banners":{"banner":"https:\/\/ps.w.org\/asb-smart-flow\/assets\/banner-772x250.png?rev=3658034","banner_2x":"https:\/\/ps.w.org\/asb-smart-flow\/assets\/banner-1544x500.png?rev=3658034","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/asb-smart-flow\/assets\/icon-128x128.png?rev=3658034","icon_2x":"https:\/\/ps.w.org\/asb-smart-flow\/assets\/icon-256x256.png?rev=3658034","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/asb-smart-flow\/assets\/screenshot-1.png?rev=3658034","caption":"The mobile dashboard with post stats and recent posts."},{"src":"https:\/\/ps.w.org\/asb-smart-flow\/assets\/screenshot-2.png?rev=3658034","caption":"New Post screen with featured-image preview and media tools."},{"src":"https:\/\/ps.w.org\/asb-smart-flow\/assets\/screenshot-3.png?rev=3658034","caption":"AI Writer sheet \u2014 mode, instructions, reference material, length and tone."},{"src":"https:\/\/ps.w.org\/asb-smart-flow\/assets\/screenshot-4.png?rev=3658034","caption":"AI writing result with title suggestions and a body preview."},{"src":"https:\/\/ps.w.org\/asb-smart-flow\/assets\/screenshot-5.png?rev=3658034","caption":"AI settings \u2014 bring your own OpenAI \/ Gemini \/ Claude key."},{"src":"https:\/\/ps.w.org\/asb-smart-flow\/assets\/screenshot-6.png?rev=3658034","caption":"ASB plugin family integrations."}],"raw_content":"<!--section=description-->\n<p>ASB Smart Flow turns the WordPress admin into a fast, one-handed mobile experience and adds an AI authoring workflow. Visit <code>\/mobile-admin\/<\/code> on a phone and you get a native-feeling SPA instead of the cramped default wp-admin. Every feature ships in one free build \u2014 no paid tier, no license activation.<\/p>\n\n<h4>Everything you get<\/h4>\n\n<ul>\n<li><strong>Bottom tab bar<\/strong> \u2014 [Home] [New Post] [Media] [Settings] reachable with your thumb.<\/li>\n<li><strong>Mobile-optimised uploader<\/strong> \u2014 camera + multi-select, with on-device resize\/compression before upload to save bandwidth.<\/li>\n<li><strong>AI authoring (BYOK)<\/strong> \u2014 generate, rewrite, summarise, proofread and suggest titles with your own API key for OpenAI, Google Gemini, or Anthropic Claude. No data passes through our servers; the request goes directly from your WordPress site to the provider you selected.<\/li>\n<li><strong>Partial revision<\/strong> \u2014 ask for a change instead of a rewrite. The AI proposes edits paragraph by paragraph; you keep or skip each one, and everything you did not accept stays exactly as you wrote it.<\/li>\n<li><strong>Quick Post and templates<\/strong> \u2014 fill-in-the-blank post templates with writing-style presets and quick instructions, all editable from the AI tab.<\/li>\n<li><strong>Emoji tray + snippets<\/strong> \u2014 insert favorite emoji and reusable boilerplate (signature, hours, hashtags\u2026) with one tap.<\/li>\n<li><strong>Passkey login (WebAuthn \/ FIDO2)<\/strong> \u2014 sign in with Face ID \/ fingerprint on your phone from <code>\/mobile-admin\/login<\/code>. On desktops, <code>wp-login.php<\/code> gains a passkey button when the computer has a built-in authenticator (Touch ID \/ Windows Hello); otherwise you sign in with your normal WordPress password.<\/li>\n<li><strong>Voice dictation<\/strong> \u2014 tap the microphone in the composer and speak; the transcript drops in at the caret, and one tap has the AI tidy it into clean prose (BYOK).<\/li>\n<li><strong>Comment moderation<\/strong> \u2014 approve, unapprove, reply to, and trash comments right from the phone (for accounts that can moderate).<\/li>\n<li><strong>Offline draft protection<\/strong> \u2014 the composer keeps a local backup of unsent edits on the device and offers to restore it after a dropped connection or an accidental close.<\/li>\n<li><strong>Body images + <code>[asbsmfl-img]<\/code> \/ <code>[asbsmfl-gallery]<\/code> shortcodes<\/strong> \u2014 insert images and multi-column galleries at the cursor from the toolbar, then adjust each image's width (100 \/ 50 \/ 33 \/ 25%) and caption from the \"Body images\" panel.<\/li>\n<li><strong>PC desktop AI<\/strong> \u2014 the same AI editor lives in a \"\u2728 AI Writer\" meta box on the post edit screen and on the AI tab in wp-admin.<\/li>\n<li><strong>Site accent color<\/strong> \u2014 set a per-site identification color reflected on headers and primary buttons (preset palette + free-form hex).<\/li>\n<li><strong>Hamburger drawer<\/strong> \u2014 quick links to the parts of wp-admin you rarely touch.<\/li>\n<li><strong>Auto-redirect (optional)<\/strong> \u2014 mobile visitors hitting wp-admin get sent into the mobile UI.<\/li>\n<li><strong>QR code for the mobile URL<\/strong> \u2014 Settings \u2192 General shows a QR code and PNG download so you can hand off the mobile link from desktop.<\/li>\n<li><strong>English + Japanese UI<\/strong> \u2014 the React app and admin screens are fully translated; other locales fall back to English.<\/li>\n<li><strong>HTTPS only<\/strong> \u2014 the plugin refuses to operate on insecure origins.<\/li>\n<\/ul>\n\n<h4>ASB plugin family integration<\/h4>\n\n<p>ASB Smart Flow auto-detects sibling plugins and surfaces their per-post toggles in a \"\ud83d\udce2 Delivery &amp; Integrations\" accordion on the new-post screen:<\/p>\n\n<ul>\n<li><strong>ASB PWA Engine<\/strong> \u2014 push notification toggle, per-post.<\/li>\n<li><strong>ASB Calendar Advance<\/strong> \u2014 show on calendar \/ Google Calendar button.<\/li>\n<li><strong>ASB LINE Notification<\/strong> \u2014 LINE push, with image \/ thumbnail \/ image-first toggles.<\/li>\n<li><strong>ASB Post Thumbnail Pro<\/strong> \u2014 per-post enable \/ disable override.<\/li>\n<li><strong>Jetpack Publicize<\/strong> \u2014 detected when active.<\/li>\n<\/ul>\n\n<p>These integrations work with both the free and Pro versions of each sibling plugin. The Pro tiers of those plugins add scheduling, image automation, and other extras \u2014 see https:\/\/shop.asobit.jp\/ if you want to extend the workflow further.<\/p>\n\n<h4>AI and data flow<\/h4>\n\n<p>ASB Smart Flow only calls AI providers when <strong>you<\/strong> add an API key (in the plugin, or site-wide via WordPress 7.0's Settings \u2192 Connectors) and press Generate. Free without any key means zero outbound HTTP.<\/p>\n\n<p>AI is <strong>administrator-only by default<\/strong>. Since the requests spend the site owner's API key, other roles can use AI only after an administrator explicitly delegates it on the \"Permissions &amp; AI\" tab.<\/p>\n\n<ul>\n<li>Your API key is encrypted at rest on your own site (AES, key derived from your site's <code>AUTH_KEY<\/code> secret) and is never sent anywhere except the provider you chose.<\/li>\n<li>When you press \"Generate\", the post content \/ instructions \/ selected style are sent <strong>directly from your WordPress install<\/strong> to the provider endpoint (<code>api.openai.com<\/code>, <code>generativelanguage.googleapis.com<\/code>, or <code>api.anthropic.com<\/code>). Each provider's privacy policy applies to that data.<\/li>\n<li>Asobit LLC does not receive or proxy any AI request.<\/li>\n<\/ul>\n\n<h4>External services<\/h4>\n\n<p>The plugin contacts external services only when you enable or use the corresponding feature. With none of them in use it makes zero outbound calls.<\/p>\n\n<ul>\n<li><strong>OpenAI (opt-in, BYOK)<\/strong> \u2014 <code>api.openai.com<\/code>. Sent: the prompt, post text, and any reference text\/images you attach, plus your own API key. Terms: https:\/\/openai.com\/policies\/ Privacy: https:\/\/openai.com\/policies\/privacy-policy\/<\/li>\n<li><strong>Google Gemini (opt-in, BYOK)<\/strong> \u2014 <code>generativelanguage.googleapis.com<\/code>. Sent: same as above. Terms: https:\/\/ai.google.dev\/gemini-api\/terms Privacy: https:\/\/policies.google.com\/privacy<\/li>\n<li><strong>Anthropic Claude (opt-in, BYOK)<\/strong> \u2014 <code>api.anthropic.com<\/code>. Sent: same as above. Terms: https:\/\/www.anthropic.com\/legal\/consumer-terms Privacy: https:\/\/www.anthropic.com\/legal\/privacy<\/li>\n<li><strong>Google Drive image import (opt-in)<\/strong> \u2014 when you import an image from Drive, your server downloads it from <code>drive.google.com<\/code> \/ <code>www.googleapis.com<\/code>. If you additionally configure a Google API key + OAuth client ID, the browser loads the Google Picker SDK from <code>apis.google.com<\/code> and <code>accounts.google.com<\/code> when the Drive picker is opened. Terms &amp; privacy: https:\/\/policies.google.com\/<\/li>\n<li><strong>Voice dictation<\/strong> \u2014 uses the browser's built-in Web Speech API. Depending on the browser\/OS, spoken audio may be processed by the browser vendor's speech service (e.g. Google on Chrome, Apple on iOS). Nothing is sent to Asobit LLC.<\/li>\n<\/ul>\n\n<h4>Source &amp; translation<\/h4>\n\n<ul>\n<li>The human-readable source of the compiled React app (<code>build\/index.js<\/code>) ships inside the plugin under <code>app-src\/<\/code>. Rebuild with <code>npm install &amp;&amp; npm run build<\/code> in the plugin directory (uses <code>@wordpress\/scripts<\/code>; Tailwind\/PostCSS configs are included).<\/li>\n<li>Translations: contributions welcome through the WordPress.org translate platform.<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>asb-smart-flow<\/code> directory to <code>\/wp-content\/plugins\/<\/code>, or install via Plugins \u2192 Add New.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Open <strong>ASB Smart Flow<\/strong> in the wp-admin sidebar and choose your accent color and auto-redirect preference.<\/li>\n<li>On your phone, visit <code>https:\/\/&lt;your-site&gt;\/mobile-admin\/<\/code>. (The Settings \u2192 General tab shows a QR code that opens this URL directly.)<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"who%20can%20use%20the%20mobile%20admin%3F\"><h3>Who can use the mobile admin?<\/h3><\/dt>\n<dd><p>Logged-in users with the <code>edit_posts<\/code> capability. You can change this with the filter <code>asbsmfl_required_capability<\/code>.<\/p><\/dd>\n<dt id=\"can%20i%20change%20the%20%60%2Fmobile-admin%2F%60%20url%3F\"><h3>Can I change the `\/mobile-admin\/` URL?<\/h3><\/dt>\n<dd><p>Not yet. Avoid creating a page with the slug <code>mobile-admin<\/code> to prevent a collision.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20make%20external%20network%20calls%3F\"><h3>Does the plugin make external network calls?<\/h3><\/dt>\n<dd><p>Only when you opt in. Without an AI key configured, the plugin's server-side code makes no outbound HTTP \u2014 except when you explicitly import an image from Google Drive, which downloads that file from Google. With an AI key, AI generate calls go directly to the provider you selected. See the \"External services\" section for the full list.<\/p><\/dd>\n<dt id=\"is%20https%20required%3F\"><h3>Is HTTPS required?<\/h3><\/dt>\n<dd><p>Yes. The plugin refuses to render on insecure origins, and passkey (WebAuthn) sign-in requires a secure context. (Smart Flow itself ships no Service Worker or push feature \u2014 those belong to the companion ASB PWA Engine plugin.)<\/p><\/dd>\n<dt id=\"which%20ai%20providers%20are%20supported%3F\"><h3>Which AI providers are supported?<\/h3><\/dt>\n<dd><p>OpenAI, Google Gemini, and Anthropic Claude. You choose one and supply your own API key (BYOK). On WordPress 7.0 and later, a key saved once under Settings \u2192 Connectors is picked up automatically, so you don't have to enter it in the plugin at all \u2014 a key entered in the plugin overrides the connector for Smart Flow only. The model picker offers a curated list of current models per provider, and you can also type any model ID manually.<\/p><\/dd>\n<dt id=\"where%20is%20my%20ai%20api%20key%20stored%3F\"><h3>Where is my AI API key stored?<\/h3><\/dt>\n<dd><p>Encrypted in the <code>wp_options<\/code> table on your own site, with a key derived from your site's <code>AUTH_KEY<\/code> secret. It's only decrypted in memory at request time. You can rotate or remove it from the AI tab at any time, and it is deleted when the plugin is uninstalled.<\/p><\/dd>\n<dt id=\"can%20i%20use%20this%20with%20translation%20plugins%3F\"><h3>Can I use this with translation plugins?<\/h3><\/dt>\n<dd><p>Yes. ASB Smart Flow loads its own <code>asb-smart-flow.pot<\/code> \/ <code>.po<\/code> \/ <code>.json<\/code> files from <code>languages\/<\/code> and respects <code>get_user_locale()<\/code>. The React bundle calls <code>wp.i18n.setLocaleData()<\/code> so per-user locales work in the mobile app too.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.26.0<\/h4>\n\n<ul>\n<li><strong>New: point at the part you want changed.<\/strong> Partial revision (2.25.0) already changed one part of a post and left the rest alone, but you had to describe which part in words \u2014 \"the second heading\" \u2014 and the AI had to find it. Now you can simply point. On the PC block editor every text block (paragraph, heading, list, quote) carries an AI button on its own toolbar: press it, say what should change, and only that block is rewritten. On the mobile composer, Partial revision offers the body as a numbered list of its parts \u2014 tap the ones to change, one or several.<\/li>\n<li>The blocks either side of the one you chose are shown to the AI as context but can never be changed by it, so \"add an example here\" reads naturally against what comes before and after while everything you did not select comes back exactly as you wrote it.<\/li>\n<li>Applying a block-level revision touches only that block, so anything you edited elsewhere while the dialog was open is left alone. A single instruction may legitimately return two paragraphs where there was one; that works.<\/li>\n<li>If the body changes after you have chosen the parts, the plugin says so and asks you to choose again rather than applying your choice to whatever now sits at those positions.<\/li>\n<li>Describing the place in words still works exactly as before, and remains the only way on the classic editor.<\/li>\n<\/ul>\n\n<h4>2.25.0<\/h4>\n\n<ul>\n<li><strong>New: partial revision.<\/strong> Until now every AI action handed back a whole new article, so accepting one meant throwing away the draft you already had. \"Partial revision\" (\u90e8\u5206\u4fee\u6b63) keeps your text as the base: describe what you want changed (\"make the second heading more concrete\", \"add a closing summary\"), and the AI proposes changes paragraph by paragraph instead of rewriting the post. Each proposal is shown as a card with your original text above and the suggestion below, and you keep or skip them one at a time. Anything you did not accept comes back exactly as you wrote it. Available in the mobile composer and in the \"AI Writer\" panel on the PC post editor.<\/li>\n<li>On the block editor, an untouched block keeps its own block type and settings \u2014 images, embeds, tables and lists you did not ask to change are not re-created as new blocks.<\/li>\n<li><strong>New: stop halfway and come back.<\/strong> Setting up an AI run is work of its own \u2014 a page to read, a file to read, half an instruction typed \u2014 and until now none of it survived. It lived only inside the AI panel, and WordPress refuses to save a post whose title and body are both empty, so closing the tab threw the whole set-up away without a word. The reference material and the instruction are now kept on the post itself, so an ordinary \"Save draft\" carries them along and reopening the post puts them back. When there is nothing in the post but the set-up, a \"Save as draft for now\" button appears in the AI panel: it lends the post a provisional name taken from your own instruction \u2014 so you can recognise it in the post list \u2014 and saves. A title you typed yourself is never touched. On the mobile composer, \"Save draft\" now accepts a post that has only an AI set-up in it, for the same reason.<\/li>\n<li>Changed: the writing-style picker is no longer shown for Proofread and Partial revision on the PC editor. Both ignore it on purpose, so the control did nothing.<\/li>\n<li>Fixed: a stray \"\\n\" appeared in three places where a line break was meant \u2014 the confirmation asking whether to replace the body with the AI draft, and the two snippets that ship with the plugin (the sign-off and the reservation footer). The snippets put those two characters straight into your post. Sites that had already saved their AI settings get the two shipped snippets repaired automatically on update; a snippet you edited yourself is left exactly as you wrote it.<\/li>\n<\/ul>\n\n<h4>2.24.4<\/h4>\n\n<ul>\n<li>Fixed: the purchase and upgrade links all led to a page that does not exist. Nothing has been published to the shop yet, so every \"Upgrade to Pro\" \/ \"Purchase License\" button answered 404 \u2014 which reads as a broken plugin rather than an unfinished shop. Those links now stay off the screen until the product is actually on sale, while the wording that explains what a licence unlocks stays exactly where it was. The same rule now applies to the ASB family cards in the sidebar: a sibling is only shown once there is a page to send someone to.<\/li>\n<\/ul>\n\n<h4>2.24.3<\/h4>\n\n<ul>\n<li>Fixed: the mobile app address \/mobile-admin\/ (and its login page) stopped opening on sites that updated to 2.24.x in place \u2014 the address quietly redirected to the home page instead. WordPress caches the whole set of address rules and only rebuilds that cache when a plugin is activated or the Permalinks screen is saved; updating a plugin is neither, so the cached rule still pointed at the internal name the app had before 2.24.0. WordPress discarded the unknown name, the address resolved to nothing, and the visitor was sent to the front page with no error shown anywhere. The plugin now rebuilds that cache as soon as it notices the mismatch.<\/li>\n<\/ul>\n\n<h4>2.24.2<\/h4>\n\n<ul>\n<li>Fixed: the \"ASB family\" cards read the state of sibling plugins wrongly. A plugin that was installed but deactivated was shown as if it were not installed at all, and a Pro edition whose licence was not active was labelled FREE and offered for sale. Both now have their own card, with the right next step (activate the plugin \/ activate the licence).<\/li>\n<li>Fixed: siblings running a licensed Pro edition were dropped from the Dashboard family strip entirely, so an installed plugin looked missing. Every family plugin on the site is now listed.<\/li>\n<li>Added: ASB Smart Guide appears in the family cards on sites where it is installed.<\/li>\n<li>Fixed: the LINE Notification card listed \"messages with thumbnails\" as a free feature \u2014 sending the featured image is part of its Pro edition.<\/li>\n<li>Changed: family cards no longer link to WordPress.org pages or shop pages for plugins that are not published or on sale yet. Until each one goes live its card appears only on sites that already have it, as a plain status card.<\/li>\n<\/ul>\n\n<h4>2.24.1<\/h4>\n\n<ul>\n<li>Fix: Keep the sibling-plugin panels working after ASB PWA Engine 2.16.0, ASB Calendar Advance 2.14.0 and ASB LINE Notification 2.9.0 moved to their new prefixes. Their post meta, options and helper functions are now resolved at runtime, so Smart Flow works with either the old or the new version of each.<\/li>\n<\/ul>\n\n<h4>2.24.0<\/h4>\n\n<p>Internal rename requested by the WordPress.org plugin review team: every class, constant, option, hook, script handle and shortcode moved from the <code>asb_sf_<\/code> prefix to <code>asbsmfl_<\/code>, which is long enough to be collision-proof against the other 100,000 plugins in the directory. Behaviour is unchanged.<\/p>\n\n<ul>\n<li>Changed: the body-image shortcodes are now <code>[asbsmfl-img]<\/code> and <code>[asbsmfl-gallery]<\/code>. Posts that already contain the old tags are rewritten automatically on the first load after upgrading \u2014 nothing to do by hand.<\/li>\n<li>Changed: stored data moves to the new names on that same first load \u2014 settings, AI provider settings (your API key stays encrypted and readable), the passkey credentials table and the image-tray post meta.<\/li>\n<li>Changed: filters and actions were renamed to match, e.g. <code>asb_sf_required_capability<\/code> is now <code>asbsmfl_required_capability<\/code>. Custom code hooking into this plugin needs the new names; nothing else is affected.<\/li>\n<li>Fixed: the mobile admin skin printed its accent-colour CSS variables as a raw <code>&lt;style&gt;<\/code> tag instead of attaching them to its stylesheet with <code>wp_add_inline_style()<\/code>.<\/li>\n<li>Fixed: the shared helper trait declared class constants, which is a fatal error on PHP 7.4 through 8.1 \u2014 the versions this plugin says it supports.<\/li>\n<li>Fixed: the two globals the uninstall routine defines while walking a multisite network were missing the plugin prefix.<\/li>\n<li>Fixed: the multisite migration checked its \"already done\" flag before switching to each site, so on a network only the main site was ever migrated.<\/li>\n<li>Dev: table names in the migration and uninstall routines now go through the <code>%i<\/code> identifier placeholder instead of being interpolated.<\/li>\n<\/ul>\n\n<h4>2.23.1<\/h4>\n\n<ul>\n<li>Dev: all remaining inline <code>&lt;script&gt;<\/code> \/ <code>&lt;style&gt;<\/code> output now goes through <code>wp_register_*<\/code> + <code>wp_add_inline_*<\/code>, including the standalone mobile app shell, and script translations use <code>wp_set_script_translations()<\/code>.<\/li>\n<li>Dev: translations are delivered by WordPress language packs instead of a bundled catalogue, so the <code>languages\/<\/code> folder and <code>Domain Path<\/code> header were dropped from the package.<\/li>\n<li>Dev: the packaged <code>Stable tag<\/code> now follows the plugin version automatically, and two <code>$_GET<\/code> reads plus one interpolated table name were tightened.<\/li>\n<\/ul>\n\n<h4>2.23.0<\/h4>\n\n<p>Security-hardening release ahead of the WordPress.org submission.<\/p>\n\n<ul>\n<li>Security: the mobile dashboard now limits posts and counts to the signed-in user's own posts for accounts that cannot edit others' posts (Contributor \/ Author), and site-wide comment totals are only returned to accounts that can moderate.<\/li>\n<li>Security: the unauthenticated passkey sign-in endpoint (<code>\/webauthn\/login\/begin<\/code>) is now rate-limited per client and site-wide, answering HTTP 429 with a Retry-After header when flooded.<\/li>\n<li>Security: resource ceilings for imported content \u2014 Google Drive downloads are capped at 20 MB and 50 megapixels, Word (.docx) extraction rejects oversized archives before unpacking, PDF text extraction has a total decompression budget, and AI vision images are dimension-checked before decoding (with ImageMagick memory limits).<\/li>\n<li>Security: the AI settings endpoint is no longer readable by accounts that can neither use AI nor manage the settings, and its <code>canEdit<\/code> flag now honours the delegated settings role.<\/li>\n<li>Security: the passkey login cookie's Secure flag now follows the same HTTPS judgment used to allow the login, fixing sites behind TLS-terminating reverse proxies.<\/li>\n<li>Changed: <strong>AI is now administrator-only by default.<\/strong> Your API key is only spendable by other roles after you explicitly delegate on the \"Permissions &amp; AI\" tab. Sites that already saved a choice there are unaffected.<\/li>\n<li>Changed: the \"hide ASB family promotions\" switch is now available to every site (it previously required owning a Pro sibling plugin).<\/li>\n<li>Fixed: the ASB Post Thumbnail link in the family sidebar pointed at a page that no longer exists; all family links now use their permanent URLs.<\/li>\n<li>Dev: JSON bootstrap payloads are HEX-escaped, unit-test files are excluded from the distribution, and the readme was aligned with the actual implementation.<\/li>\n<\/ul>\n\n<h4>2.22.3<\/h4>\n\n<ul>\n<li>Fix: several interface strings stayed in English on Japanese sites \u2014 the Google Drive picker status and its setup hints, the family integration heading, and the auto featured-image preview card. The strings were already translatable; their Japanese translations were simply missing from the bundled catalogue and have now been added (13 strings).<\/li>\n<\/ul>\n\n<h4>2.22.2<\/h4>\n\n<ul>\n<li>Fix: saving from the mobile composer could fail with \"you are not allowed to edit the ... custom field\" when a sibling plugin exposes read-only post meta over REST (e.g. LINE notification's send history). The composer now only submits custom fields shown in its own \"additional fields\" form instead of echoing back every field it loaded.<\/li>\n<\/ul>\n\n<h4>2.22.1<\/h4>\n\n<ul>\n<li>Tweak: admin radio buttons show the native WordPress selected dot again - the branded yellow dot clashed inside the blue control.<\/li>\n<\/ul>\n\n<h4>2.22.0<\/h4>\n\n<ul>\n<li><strong>Refreshed admin design.<\/strong> The settings screen now wears the Asobit corporate palette: a clean white canvas with neutral greys, a near-black header bar, and the brand yellow for primary buttons and active states (buttons invert to black on hover). Layout and behaviour are unchanged \u2014 colours only. The site accent preset still applies to the visitor-facing app and is not affected.<\/li>\n<\/ul>\n\n<h4>2.21.0<\/h4>\n\n<ul>\n<li><strong>New: WordPress 7.0 Connectors support.<\/strong> If your site already stores an AI provider key under Settings \u2192 Connectors (or in an environment variable \/ PHP constant), Smart Flow now uses it automatically \u2014 no need to paste the same key into the plugin. Both the desktop AI Provider tab and the mobile settings card show a \"Via WordPress Connectors\" state for such providers, and the tip text steers new setups toward managing keys in core. A key entered in the plugin still overrides the connector for Smart Flow only, and everything keeps working unchanged on WordPress below 7.0.<\/li>\n<li>Switching between OpenAI \/ Gemini \/ Claude keeps working exactly as before, whichever place each key comes from; the provider picker now also counts connector-backed providers as ready to use.<\/li>\n<\/ul>\n\n<p>Older entries: see <code>changelog.txt<\/code> inside the plugin folder.<\/p>","raw_excerpt":"A free, fully-featured mobile WordPress admin with AI authoring (BYOK), passkey login and tight integration with the ASB plugin family.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/fao.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/349327","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fao.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/fao.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/fao.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=349327"}],"author":[{"embeddable":true,"href":"https:\/\/fao.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/asobit"}],"wp:attachment":[{"href":"https:\/\/fao.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=349327"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/fao.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=349327"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/fao.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=349327"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/fao.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=349327"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/fao.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=349327"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/fao.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=349327"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}