OpenStation
wp-admin forgets. OpenStation doesn’t. You know the moment. You’re deep in a post and you need one image from the Media Library. You click over, find it, click back, and everything you had going is gone. Your scroll position, your half-typed thought, the three other things you had queued up in your head. That’s not a bug you hit. That’s the design. wp-admin shows you one screen at a time, and every navigation throws the last one away. It has worked this way since 2003, like a fridge that empties itself every time you close the door. WordPress has rebuilt almost everything else. The editor, the site editor, the patterns, the styles. The admin’s one-screen-at-a-time model is the layer nobody touched. OpenStation touches it. Install it and admin screens become draggable, resizable windows. Edit a post while the Media Library sits open next to it. Drag an image from one window straight into the other. Keep comments open in the corner. Reload the browser and your window layout — open pages, positions, sizes, and window states — comes back where you left it. OpenStation itself is free, GPL, and opt-in per user. One click in the admin bar turns it on for you. One click turns it off. Nobody else on your site sees anything change, and deactivating the plugin restores the classic admin exactly. No Core patches and no lock-in. Optional AI providers may charge for their service. Built and maintained by Automattic, the company behind WordPress.com, Jetpack, WooCommerce, and Tumblr. Work on more than one thing at once Admin pages open as windows, including pages added by most other plugins. Drag them, resize them, snap them, tile them, minimize them to a taskbar. The admin menu becomes a dock of icons. Two editors open at once is one click away. Never lose your place Moving between open windows leaves each page in place. Across reloads, OpenStation remembers your open pages, window positions, sizes and states, virtual desktops, and focus. Closing a window with unsaved changes warns you first. A desk you can actually put things on Drop posts, media, and links right onto the wallpaper. Sort them into folders. Trash them to a Trash that actually holds things. The stuff you’re working on this week can just sit out where you can see it. One desktop per job Virtual desktops, the way your operating system does them. One for writing. One for the store. One for comment triage. One for that redesign you keep poking at. Switch between them without closing anything. Find anything with Cmd+K The full WordPress command palette, plus slash commands from your plugins, all under one keystroke. Turn on the optional AI assistant and you can ask it things like “which post had the comment asking for the recipe?” and it searches your own content to answer. (Requires an AI provider configured in Settings → Connectors on WordPress 7.0+. Details under “External services” below.) See how your site fits together The Corkboard is an interactive, zoomable map of how your posts, pages, and products link to each other. Pan around it. Find the orphans. Find the hubs. Running a store? Orders, Products, Coupons, and Customers become browsable folders with stock and sale ribbons. Open a customer to see their lifetime spend and what they buy most. Follow a product to its buyers, or a coupon to who redeemed it. Make it yours Wallpapers, from color presets to animated scenes to your own photo. Live widgets pinned to the desktop: drafts, stats, recent comments, a focus timer. Uploadable desktop themes, including a built-in Legacy theme that brings the old WordPress blue back in one click. And Mio, a soft-body desk companion that drifts across your wallpaper and gets bumped around by your windows. Off by default. You’ll turn it on. For developers Extend OpenStation through documented PHP and JavaScript APIs. Register windows, icons, wallpapers, widgets, commands, and settings tabs through stable openstation_register_* PHP APIs and a typed JavaScript API; customize dock items through documented hooks; add AI tools with the WordPress Abilities API. Copy-paste examples live in the developer docs on GitHub. External services No external service is required for OpenStation’s desktop interface. The optional AI Assistant and two user-initiated enrichment features make the external requests described below. AI Assistant The optional AI Assistant sends data to the AI provider you configure in WordPress’s Settings → Connectors (for example OpenAI, Anthropic, or Google). Generation is routed through WordPress 7.0’s built-in AI Client, which supplies the credentials stored in Connectors. The plugin never handles an API key itself. With no provider configured in Connectors, no external AI requests are made. When the AI Assistant is enabled and a user invokes it (via Cmd+K or the slash-command palette): What is sent: the user’s prompt, the conversation history for the active session, and tool-call metadata. The plugin’s built-in tools (search_posts, search_pages, search_comments) run WordPress’s native keyword search and may include excerpts of the matching posts/pages/comments in tool results, which are then sent back to the provider as part of the agentic loop. When it is sent: on user-initiated AI requests, and (if an administrator enables “Score new comments with AI”) on comment-save hooks for spam analysis. Posts, pages, and taxonomy terms are not sent automatically. Why it is sent: to obtain model completions and tool-call decisions that drive the AI Assistant. Who provides the service: whichever provider you configured in Settings → Connectors. Which provider (and endpoint) receives the data depends entirely on that configuration. Review the chosen provider’s own terms and privacy policy (e.g. OpenAI, Anthropic, or Google). URL shortcut favicons When an authorized user creates a desktop shortcut to an external URL, OpenStation asks that URL for its page HTML and favicon so the shortcut can display the site’s icon. The request is made from your WordPress server and sends the requested URL, the server’s IP address, an OpenStation user-agent string, and normal HTTP request metadata to the operator of that site. This happens only when a user creates the shortcut. The destination site’s terms and privacy policy apply. WordPress.org plugin information When an authorized user opens or refreshes parts of OpenStation’s Plugins window, OpenStation may request public plugin details, update metadata, and review excerpts from WordPress.org. These requests send plugin slugs, the site’s locale, and normal HTTP request metadata to WordPress.org. This information is used only to display and manage plugins. Review the WordPress.org Privacy Policy. OpenStation’s OAuth relay does not contact a service by itself. Third-party plugins that configure the relay may contact their own providers and are responsible for disclosing those services. Credits OpenStation is brought to you by Automattic. The plugin is open source under GPLv2-or-later; contributions are welcome on GitHub. Third-party libraries The plugin bundles the following third-party JavaScript library, loaded on demand only when a feature that needs it is in use: PixiJS (MIT License) — used by the Corkboard window, built-in canvas wallpapers (e.g. the animated WordPress logo), the Mio desk companion, and the Inkfall typing game. PixiJS is loaded from the plugin’s own assets/vendor/ directory; no CDN requests are made. Data files The Inkfall game’s word list (assets/games/inkfall/words.txt) is generated from the following sources (attribution also ships in the file’s header): FrequencyWords by Hermit Dave (CC-BY-SA 4.0) — English word-frequency ranking derived from the OpenSubtitles corpus. english-words by dwyl (Unlicense) — used as a validity filter. LDNOOBW English list (CC-BY 4.0) — used as an exclusion filter.
Top keywords
- wordpress15×1.17%
- ai14×1.10%
- openstation13×1.02%
- open9×0.70%
- pages8×0.63%
- provider7×0.55%
- site7×0.55%
- window7×0.55%
- admin6×0.47%
- ai assistant6×0.47%
- assistant6×0.47%
- click6×0.47%
GuestDock
GuestDock is the most secure and feature-complete way to accept guest posts on WordPress. It creates a fully sandboxed contributor environment where guest authors get temporary, strictly limited, and completely isolated access to the WordPress backend — without ever seeing other users’ content, media, or site settings. Unlike the default WordPress contributor role, GuestDock enforces real isolation. Guest authors are completely siloed: they can only view, edit, and interact with their own posts and their own media uploads. No data leaks, no accidental exposure, and no security risks. Who is GuestDock for? GuestDock is the ideal guest post plugin for multi-author blogs, online magazines, news sites, content agencies, and any brand that needs to accept guest contributions without compromising WordPress security or editorial quality. ✨ Key Features Sandbox & Access Control True Sandbox Isolation — Guests are restricted at the query level via pre_get_posts, ajax_query_attachments, and REST API filters. They only see content they created. No other user’s drafts, media, or data is ever visible. Time-Limited Guest Access — Set exact expiration dates for every guest author. Accounts automatically lose access once the time is up — zero manual cleanup. Post Submission Limits — Control exactly how many posts each guest can submit. Prevent unlimited content flooding. Runtime Capability Enforcement — Belt-and-suspenders: even if another plugin grants capabilities, GuestDock’s runtime filter ensures guests cannot exceed their allowed permissions. Editorial Workflow Approval & Feedback System — Return posts to “Draft” with inline admin feedback notes. Guests see feedback on their dashboard and in the editor. Automatic email notifications keep everyone in the loop. Review Queue — Centralized queue with inline post preview, word count badges, QA status indicators, and direct edit links for efficient editorial review. Smart Submission Checklist — A live-updating Gutenberg sidebar panel replaces the old notice-based QA with a modern, visual experience. Color-coded checks for word count, featured image, excerpt, and external links — always visible while writing. Content Quality Enforcement — Block submission until guests meet minimum word counts, upload a featured image, and provide a custom excerpt. Content & SEO Protection SEO & Spam Link Protection — Limit external links per post and automatically inject rel="nofollow sponsored" attributes to safeguard your site’s SEO authority. SEO Pre-Check Panel — Built-in Gutenberg sidebar SEO audit: focus keyword detection, heading structure analysis, image alt text coverage, meta description length check, and internal/external link ratio — all with a visual score. Category Locking — Restrict guest posts to specific pre-approved categories to maintain your site’s content organization. Gutenberg Block Restriction — Prevent script injection by denying dangerous blocks (Custom HTML, Shortcode, Code) while allowing access to all other Gutenberg blocks for full content creation. Fully customizable via the guestdock_denied_block_types filter. Media & Upload Security Media Upload Security — Strict MIME type validation (JPG, PNG, GIF, WebP only), configurable file size limits, double-extension checks, and per-user upload quotas with race condition protection. API & XML-RPC Hardening — Completely disables XML-RPC access and tightly secures REST API endpoints for guest accounts to prevent unauthorized programmatic access. Analytics & Reporting Analytics Dashboard — Per-guest metrics: posts submitted, approval rate, average word count. Overview cards showing total published posts, active guests, and performance trends. CSV Export — One-click export of all contributor analytics data for stakeholder reporting and content strategy. Admin Dashboard Widget — “GuestDock at a Glance” widget on the WordPress dashboard showing pending post count, active guest count, and recent submissions with one-click links to the Review Queue. Content Templates Post Templates — Admins create reusable content templates (e.g., “Product Review”, “How-To Guide”) with pre-filled structure. Guests select a template when starting a new post, ensuring consistent content format across all contributions. Template Selector Modal — Beautiful modal overlay intercepts the “Add New Post” button, presenting available templates and a “Start Blank” option. Guest Experience Guest Onboarding Modal — When a guest first logs in, a branded welcome overlay shows site-specific writing guidelines, content requirements summary, post allowance tracker, and a “Start Writing” call-to-action. Guest Contributor Profiles — Public author bio pages with custom bio, website, and social media links (X/Twitter, LinkedIn). Automatically displayed on author archive pages. Custom Writing Guidelines — Add editorial instructions that appear directly in the guest’s dashboard widget and post list page with smart dismissible notices. Admin Experience Admin Onboarding Wizard — First-time 4-step setup wizard: configure content rules, create your first invite, set up secure login, and copy the shortcode — all without leaving the page. Inline Guest Management — Edit expiration dates and post limits directly from the admin dashboard without opening each user profile. Safe Guest Removal — Delete guest accounts while safely reassigning their published posts to an administrator, preventing content loss. Automatically cleans up orphaned media. Auto Username Generation — Automatically generate clean usernames from email prefixes during guest creation. Integrations & Developer Tools REST API — Full REST API under guestdock/v1 namespace: list guests, get guest details, list submissions, view stats. All endpoints require manage_options authentication. Webhooks — Configure webhook URLs to receive POST notifications on guest.invited, post.submitted, and post.approved events. Compatible with Zapier, Make, Slack, and custom endpoints. Frontend Request Form — Use the [guestdock_request_form] shortcode to let visitors apply for guest author access directly from your site. Built-in honeypot and rate limiting for spam protection. Email Template Customization — Fully customize the subject and body of all 6 automated email types: Invitations, Feedback Notifications, Approval Confirmations, Submission Alerts, Request Confirmations, and Access Requests. Secure Login Integration — One-click install and activate AuthDock from within GuestDock for magic link authentication, eliminating password management for guest authors. 30+ Developer Hooks — Over 30 WordPress-style filters and actions across every plugin class for full extensibility, from capabilities and email notifications to validation rules and upload quotas. In-Plugin Help Center — Built-in “Help” and “Shortcode Reference” tabs for instant admin guidance — no external docs needed. Clean Uninstall — Proper uninstall.php removes all plugin data (options, user meta, post meta, custom post types, transients) when the plugin is deleted. Documentation & Resources For a complete step-by-step guide on how to use GuestDock, including setup instructions and workflows for both administrators and guest authors, please read our GuestDock User Guide. To learn more about the philosophy behind GuestDock and why it’s the most secure way to manage guest posts, check out our blog post: The Ultimate Way to Manage Guest Posts on WordPress.