| 开发者 | oliverdj123 |
|---|---|
| 更新时间 | 2026年9月20日 00:34 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
{
"event": "publish",
"post_id": 42,
"title": "How to automate WordPress",
"slug": "automate-wordpress",
"url": "https://example.com/automate-wordpress",
"post_type": "post",
"status": "publish",
"old_status": "draft",
"new_status": "publish",
"author": "Oliver",
"categories": ["Automation"],
"tags": ["webhook"],
"timestamp": "2026-09-05 12:00:00"
}
Your webhook URL is all it needs. Each event is toggleable, so you only send what you want.
Two things worth knowing
Requests never hold up your site. Payloads are queued and sent after the page response has been handed to the visitor, so a slow or unreachable endpoint cannot stall an editor save. On hosts with a request-finish function (PHP-FPM, LiteSpeed) the plugin still records the real HTTP status. On other hosts the send is fire-and-forget and the log says so honestly.
You can prove a payload came from your site. Add a shared secret and every request carries an HMAC-SHA256 signature of the raw body plus a timestamp:
X-Yak-Signature: sha256=<hmac_sha256(timestamp + "." + raw_body, secret)>
X-Yak-Timestamp: 1789813016
X-Yak-Delivery: 4f1c...-uuid
X-Yak-Site: https://example.com/
Sign the timestamp with the body and reject anything older than a few minutes — that kills replay attacks. Verify with a constant-time comparison before you parse the JSON. Each site should carry its own secret: one shared key across many sites means one compromised site can forge events for all of them.
Is the event list enough to tell a real publish from a scheduled one?
Every post status transition carries both sides of the change (old_status and new_status), so a workflow can tell a brand-new post from a scheduled post flipping over (future → publish), or a draft being published. Comment status events carry the same pair.
Made by YakWP
Developed and maintained by YakWP. YakWP also makes a free AI chatbot plugin for WordPress that answers your visitors' questions right on your site — pair it with Yak Event Hooks so your site not only fires workflows but also talks to every visitor automatically.
old_status and new_status./wp-json/yak-event-hooks/v1/settings, /log).yak-event-hooks folder to /wp-content/plugins/ or install via Plugins → Add New.No. You only need the webhook URL of your own endpoint.
No. It works with any endpoint that accepts a JSON POST — n8n, Zapier, Make, IFTTT, webhooks.dev, or your own server.
Post published, updated, trashed, and permanently deleted; comment added, comment status changed, comment deleted; media (attachment) uploaded; and new user registered. Every event is toggleable.
WordPress 5.0 and later, including the latest releases. PHP 7.4 or higher.
No. Events are queued during the request and delivered on shutdown, after the response has gone out. In the default background mode a stalled endpoint costs your editors nothing. If you need the delivered HTTP status inline (debugging a broken endpoint), switch Delivery to synchronous — that is the old behaviour.
Set a shared secret of 16+ characters and the request carries X-Yak-Signature: sha256=HMAC-SHA256(timestamp + "." + raw body). Compute the same HMAC over the exact raw bytes you received (do not re-serialize the JSON — key order and escaping will differ), compare with a constant-time function, and reject timestamps that are not recent. Use a different secret per site.
GET /wp-json/yak-event-hooks/v1/settings never returns the secret. A PUT with an empty secret leaves the stored one untouched; send clear_secret: true to actually remove it.
X-Yak-Signature, X-Yak-Timestamp, X-Yak-Delivery (UUID) and X-Yak-Site headers. The signature covers the timestamp and the raw body, so replays can be rejected.old_status and new_status on post status transitions, so publish can be distinguished from a scheduled post flipping over. Comment status events already carried both.clear_secret: true clears it.yak-event-hooks) per the WordPress.org naming guidelines — the "Webhook Events" name was too generic./wp-json/yak-event-hooks/v1/settings and /log).