Codevera AI Access Control
by codevera 0 (0 reviews)

Codevera AI Access Control

Decide which plugins are allowed to expose their abilities to the WordPress AI feature. Block any plugin, or any single ability, with one click.

Codevera AI Access Control ranks #57,379 among WordPress.org plugins with 0+ active installations, is #3,908 of 4,482 in the Security category, and was last updated May 13, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7.0.4 (Current: 7.1)
v1.1.4 Current Version v1.1.4
Updated 4 months ago Last Update on 13 May, 2026
Refreshed 12 hours ago Last Refreshed on
#3,908 of 4,482 in Security
View on WordPress.org
Rank
#57,379
-4092 this week
Active Installs
0+
-100%
KW Avg Position
112
1 worse
Downloads
210
+3 today
Support Resolved
0%
No change
Rating
0%
Review 0 out of 5
0 (0 reviews)

Next Milestone 10

Total Progress 20%
0+ 10+
31,566
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 8 more installs to reach 10+

Rank Changes

48,743 52,892 57,041 61,190 65,339 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
48,457 53,226 57,995 62,763 67,532 31-08-2026 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
Current #57,379
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
0 10 31-08-2026 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

0.0
0 reviews
Overall 0%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about Codevera AI Access Control

No. It reads only local WordPress data and never contacts any third-party service. No telemetry, no analytics, no licence checks.
No. It stores only your allow and block selections and a short list of plugin and ability identifiers in the WordPress options table.
Two layers. First, on the wp_register_ability_args filter at the highest priority, the plugin rewrites the execute_callback and permission_callback of any blocked ability to return a cvaiac_blocked WP_Error. This neutralises the ability before WordPress even constructs it. Second, on the wp_abilities_api_init action at the highest priority, the plugin walks the registry and calls wp_unregister_ability() on anything blocked, so it disappears from the listings entirely.
You can block individual core abilities, but the WordPress core group as a whole cannot be blocked. Blocking individual core abilities can prevent the AI feature from working correctly, so do it with care.
The settings option is stored as a JSON payload with an HMAC-SHA256 signature, keyed to a CVAIAC_SECRET constant or AUTH_SALT. Each time the plugin reads the option, the signature is recomputed and checked. If it does not match, the plugin enters fail-closed mode and blocks every non-core ability until an administrator re-saves the settings through the UI. A red banner appears on the settings screen explaining what happened.
A malicious or buggy plugin running on the same site can call update_option( 'cvaiac_settings', array() ) to wipe your block list. With tamper detect, that write produces an invalid signature, the plugin notices, and the AI feature loses access to every plugin's abilities until you investigate and re-save.
A determined plugin with code execution on the same site can in principle override the pre_option_cvaiac_settings filter, remove the enforcement hooks, or read CVAIAC_SECRET from wp-config.php to forge a valid signature. This plugin defends against opportunistic interference, not against a fully hostile plugin in the same PHP process. Treat it as a policy and tamper-detect tool, not a security boundary. The safest practice is still to only install plugins you trust.
Yes. Settings are stored per-site, so each sub-site can have its own allow and block list.
Yes. Blocked abilities are unregistered from the registry, so the WordPress core REST run endpoint cannot find or execute them.
All of the plugin's options are deleted by uninstall.php. No data is left behind.

Sign In / Register

You need to sign in or register to use this feature.