| 开发者 | yodon |
|---|---|
| 更新时间 | 2026年10月1日 18:04 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
Authorization header. This plugin sidesteps all of that, and does a few things a username and password cannot:
autopress/v1:
GET /ping — connection check: publishing user, WordPress version, detected SEO plugin, upload limit and what the connection may do.GET /theme — the site's colours, fonts and content width from the active theme and Site Editor.POST /media — upload a JPEG, PNG, GIF, WebP or AVIF image into the media library.POST /post — create a post (draft, pending, scheduled, private or published), or update one it already created.GET / POST /categories — list categories; create one, or return the matching one if it already exists.GET /posts — a compact list of recent published posts, used for internal linking.POST /seo — write the SEO title, meta description and focus keyword into Yoast SEO or Rank Math.POST /translations — link posts as translations of one another on sites running Polylang.users/me. No other route on your site is affected.
Yes. The plugin is the WordPress half of the connection; the researching, writing and scheduling happen in BlogTend. On its own the plugin sits idle and does nothing. Starting is free and takes no card.
That is the thing worth being fussy about. Every article is written from research it actually fetched — the sources are listed in the post and re-checked at publish time — rather than from a model's memory. It arrives as structured blocks: tables where there is a choice to make, steps where there is a process, a real FAQ, a takeaways box. Judge it on the output: publish in draft mode first and read a couple before you let anything go live.
Google's guidance is about whether content is helpful and original, not about how it was produced. What gets penalised is mass-produced pages made only to game search. Which is exactly why BlogTend researches before it writes, cites what it used, skips topics you have already covered, and lets you hold everything for review. You are still the publisher — read what goes out.
No. Three modes: publish live on schedule, land in your WordPress Drafts for approval, or hold in BlogTend until you send it. Switch whenever you like.
Yes. It is an ordinary WordPress post. Edit, delete, re-categorise, change the featured image — exactly as you would with something you wrote.
The connector hands BlogTend your palette, fonts and content width from the active theme and Site Editor, and the article blocks are painted from those. That is what the GET /theme endpoint is for.
The plugin acts as the user selected under Publish as. That user needs to be able to publish posts, upload files and manage categories; any administrator, and usually any editor, already can. The connection can never do more than that user is allowed to, and it only applies to posts, media, categories, tags and the current-user endpoint.
Yes — point Publish as at a user with a narrower role. An Author can create and publish their own posts and upload images but cannot create categories, so category creation will be refused while everything else keeps working.
Settings → BlogTend → Regenerate. The previous token stops working immediately and the new one is shown once. Paste it into BlogTend to reconnect. Rotate it if you think it has been exposed, or when someone who had access to it leaves.
No. Only a hash of it is stored, so it cannot be recovered — generate a new one instead. The settings page shows the last four characters so you can tell which token a site is using.
Nothing leaves on its own. The plugin has no scheduled jobs and makes no outbound requests. It only answers requests that arrive with a valid token, and it answers with exactly what was asked for: the connection status, your categories, recent post titles and links, your theme's design tokens, and the IDs and URLs of content it just created.
Yoast SEO and Rank Math are written to directly. If neither is active, the SEO title, description and focus keyword are stored as post meta (_autopress_seo_title, _autopress_seo_desc, _autopress_seo_keyword) so a theme or another plugin can pick them up.
Some servers strip the Authorization header before PHP sees it. BlogTend also sends the token in an X-AutoPress-Token header, which is not affected, so this is rare. If you would rather fix the header, add this to your .htaccess above the WordPress rules:
SetEnvIf Authorization "(.*)" HTTP_AUTHORIZATION=$1
Usually, yes: the connector authenticates the request before those restrictions are evaluated. If a plugin blocks the REST API outright, allow the autopress/v1 routes in its settings.
BlogTend was previously called AutoPress. The REST namespace, header and option names kept the old identifier so that sites connected before the rename keep working without reconnecting.
This version replaces it. Activate BlogTend Connector and the old copy is deactivated automatically; your token and settings carry over, and you can delete the old plugin.
Yes. Each site in the network has its own token and publishing user under its own Settings → BlogTend.
yodon-connector folder so updates arrive as usual.file.php for the temporary file and sideload, image.php for attachment metadata); the unused media.php include is gone.yodon-connector, matching the plugin's name. An installed autopress-connector copy is deactivated automatically and its token keeps working.POST /post can now update a post it created: send id with any of title, content, status, excerpt, slug, date, categories, tags or featured_media. Publishing a draft and refreshing internal links no longer need the core endpoints.GET /theme endpoint: the site's palette, fonts and content width from the active theme and Site Editor global styles, so "match my site" works through the token alone.GET /ping now reports the upload size limit, locale, timezone, site languages (Polylang) and whether the publishing user may post unfiltered HTML.POST /post responses include the stored content, so the caller can tell whether anything was filtered out.admin-post.php and redirects, so refreshing the page can no longer regenerate a token by accident. Notices are dismissible.uninstall.php: deleting the plugin removes its options and transients.POST /translations for Polylang sites, and a lang parameter on POST /post.GET /ping reports whether the site is multilingual.POST /post, POST /media, GET/POST /categories and GET /posts.users/me. All other routes are untouched.X-AutoPress-Token fallback header.GET /ping health check and POST /seo metadata push.