PCP AI Reviewer Add-on
AI-assisted plugin review add-on for the WordPress Plugin Check plugin. Uses OpenRouter (default: Claude Opus 4.7).
by Copyright.sh / PCP AI Team · github.com/tymrtn/pcp-ai-addon
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/tymrtn/pcp-ai-addon/archive/refs/heads/main.zipAI-assisted triage and developer guidance layer on top of the Plugin Check (PCP) plugin.
Status
Current release: v0.3.1. Not yet submitted to WordPress.org — distributed via this GitHub repo.
What it does
- Runs five AI review passes (general, security, performance, accessibility, WP.org repo guidelines) alongside PCP's static checks.
- Evaluates every plugin against each of the 18 WordPress.org Detailed Plugin Guidelines — each category prompt cites the guidelines in scope and requires the AI to emit a per-rule
PASS/FAIL/UNCLEARverdict with evidence. FAILs surface as Plugin Check errors with a deep link to the guideline text. - Uses OpenRouter as the inference backend. Default model: Claude Opus 4.7 (
anthropic/claude-opus-4.7). Switchable in Settings to Sonnet 4.6, Haiku 4.5, GPT-5, Grok, or any custom OpenRouter slug. - Settings page at Settings → PCP AI Add-on for API key + model selection.
- Agent-addressable via a JSON REST endpoint and an MCP server (see Agent access below).
Requirements
- WordPress 6.3+ (6.5+ recommended)
- PHP 7.4+
- Plugin Check plugin active
- An OpenRouter API key (
OPENROUTER_API_KEYenv var, or paste it into the settings page — it's encrypted at rest with WP salts)
Installation
- Install and activate Plugin Check.
- Clone or download this repo into
wp-content/plugins/pcp-ai-addon/. - Activate PCP AI Reviewer Add-on from the Plugins screen.
- Provide your OpenRouter API key via
OPENROUTER_API_KEYenvironment variable, or Settings → PCP AI Add-on. - Run Plugin Check as usual — AI review results appear alongside the static findings.
Agent access
Every review the add-on produces is addressable from outside WordPress so coding agents can pull reviews into their own workflows.
REST (Markdown or JSON)
GET /wp-json/pcp-ai/v1/review?plugin=<slug-or-basename>[&format=md]
- Auth: WordPress cookie (for the UI) or an Application Password (for agents).
- Capability:
manage_options. - Default response is JSON; pass
format=mdfor a ready-to-paste Markdown review.
MCP server
POST /wp-json/pcp-ai/v1/mcp
A minimal JSON-RPC 2.0 Model Context Protocol server. Implements initialize, tools/list, and tools/call. Exposes a single tool:
pcp_ai.review— inputs{ plugin: string, no_cache?: boolean }, returns structured severity / summary / issues / recommendations plus a Markdown rendering.
Smoke-test with the MCP Inspector:
npx @modelcontextprotocol/inspector --cli https://your-site/wp-json/pcp-ai/v1/mcp \
-H "Authorization: Basic $(echo -n user:app-password | base64)"
This is the piece that lets agents that speak MCP — Claude Code, Cursor, Codex, @wporg/mcp — invoke an AI review as part of a larger submission or audit flow.
Versioning
Semantic versioning. Tags on the main branch are the authoritative release markers — see Releases for changelogs. readme.txt's Stable tag mirrors the latest release tag.
Security
- API key never appears in plugin source. It is loaded from environment or the WP options table (encrypted with WordPress salts).
- All admin and REST endpoints require
manage_optionscapability. - Plugin metadata is sanitized before LLM prompts (prompt-injection defense).
- Per-user rate limit (10 calls/minute) on LLM calls.
- Direct PHP access is blocked in every file.
License
GPL-2.0-or-later. See the plugin header for details.
Contributing
Issues and PRs welcome. This is an early-stage tool — expect rough edges.