{"id":355851,"date":"2026-08-21T08:05:17","date_gmt":"2026-08-21T08:05:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/harperflow\/"},"modified":"2026-08-21T20:30:43","modified_gmt":"2026-08-21T20:30:43","slug":"harperflow","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/harperflow\/","author":23551279,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.5.0","stable_tag":"1.5.0","tested":"7.1","requires":"5.6","requires_php":"7.2","requires_plugins":null,"header_name":"HarperFlow","header_author":"HarperFlow","header_description":"Exposes HarperFlow article metadata (SEO title\/description, FAQ, TL;DR, GEO signals) to the WordPress REST API and (optionally) styles HarperFlow-authored posts. Thin by design \u2014 your posts publish and render natively without it; this plugin only adds the extras.","assets_banners_color":"e7f1e9","last_updated":"2026-08-21 20:30:43","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/www.harperflow.io\/docs\/connect-wordpress","header_author_uri":"https:\/\/harperflow.io","rating":0,"author_block_rating":0,"active_installs":0,"downloads":37,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.5.0":{"tag":"1.5.0","author":"thefamoushesham","date":"2026-08-21 20:30:43"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3658491,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3658491,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3658491,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3658491,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.5.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3659002,"resolution":"1","location":"assets","locale":"","width":2400,"height":1620},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3659002,"resolution":"2","location":"assets","locale":"","width":2400,"height":1620},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3659002,"resolution":"3","location":"assets","locale":"","width":1500,"height":2777}},"screenshots":{"1":"The HarperFlow panel inside wp-admin \u2014 plugin status, one-click sign-in to your dashboard, and every published article tracked with its content type and topic cluster.","2":"Connecting takes one step \u2014 paste the pairing code from your HarperFlow dashboard; no passwords or API keys to manage.","3":"What a published HarperFlow article looks like on your site \u2014 a featured image, a styled comparison table, a TL;DR summary, an FAQ, and JSON-LD schema, engineered to be cited by AI search."}},"plugin_section":[],"plugin_tags":[569,529,1643,2591,186],"plugin_category":[49,55],"plugin_contributors":[276790],"plugin_business_model":[],"class_list":["post-355851","plugin","type-plugin","status-publish","hentry","plugin_tags-automation","plugin_tags-content","plugin_tags-faq","plugin_tags-geo","plugin_tags-seo","plugin_category-maps-and-location","plugin_category-seo-and-marketing","plugin_contributors-thefamoushesham","plugin_committers-thefamoushesham"],"banners":{"banner":"https:\/\/ps.w.org\/harperflow\/assets\/banner-772x250.png?rev=3658491","banner_2x":"https:\/\/ps.w.org\/harperflow\/assets\/banner-1544x500.png?rev=3658491","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/harperflow\/assets\/icon-128x128.png?rev=3658491","icon_2x":"https:\/\/ps.w.org\/harperflow\/assets\/icon-256x256.png?rev=3658491","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/harperflow\/assets\/screenshot-1.png?rev=3659002","caption":"The HarperFlow panel inside wp-admin \u2014 plugin status, one-click sign-in to your dashboard, and every published article tracked with its content type and topic cluster."},{"src":"https:\/\/ps.w.org\/harperflow\/assets\/screenshot-2.png?rev=3659002","caption":"Connecting takes one step \u2014 paste the pairing code from your HarperFlow dashboard; no passwords or API keys to manage."},{"src":"https:\/\/ps.w.org\/harperflow\/assets\/screenshot-3.png?rev=3659002","caption":"What a published HarperFlow article looks like on your site \u2014 a featured image, a styled comparison table, a TL;DR summary, an FAQ, and JSON-LD schema, engineered to be cited by AI search."}],"raw_content":"<!--section=description-->\n<p>HarperFlow (https:\/\/harperflow.io) auto-publishes AI-written, GEO-optimized articles\nto your WordPress site. Your posts publish and render natively in your theme <strong>without\nthis plugin<\/strong> \u2014 it is entirely optional. Installing it adds the extras WordPress core\nhas no home for:<\/p>\n\n<ul>\n<li><strong>SEO title &amp; description<\/strong> \u2014 written into Yoast or Rank Math when present, or\nemitted by the plugin itself when no SEO plugin is active.<\/li>\n<li><strong>Self-contained HarperFlow article components<\/strong> \u2014 preserves the renderer's\ninline-styled feature header, table of contents, comparison cards, promotional\nCTAs, and author cards on REST writes for HarperFlow-authored posts only.<\/li>\n<li><strong>Styled TL;DR box<\/strong> and <strong>FAQ accordion<\/strong> \u2014 rendered from HarperFlow's structured\nmetadata, scoped only to HarperFlow-authored posts so the rest of your site is\nuntouched.<\/li>\n<li><strong>FAQPage structured data (JSON-LD)<\/strong> \u2014 improves visibility in Google and AI answer\nengines.<\/li>\n<\/ul>\n\n<p>How it works:<\/p>\n\n<ol>\n<li>Registers HarperFlow post meta (<code>_hf_*<\/code>) with <code>show_in_rest<\/code> so HarperFlow can\nwrite SEO\/FAQ\/TL;DR data over the REST API.<\/li>\n<li>Re-exposes Yoast \/ Rank Math SEO meta over REST when those plugins are active\n(they hide those keys from REST by default).<\/li>\n<li>Serves <code>GET \/wp-json\/harperflow\/v1\/health<\/code> so HarperFlow can detect the plugin and\nwhich SEO engine is live.<\/li>\n<li>Preserves HarperFlow-rendered article HTML with a narrow KSES allowlist. Scripts,\niframes, event handlers, and unsafe URL schemes are still stripped.<\/li>\n<li>Adds a <strong>HarperFlow<\/strong> menu in wp-admin: connection status, the HarperFlow articles\npublished to this site (with their content type + topic cluster), and a link into\nthe full HarperFlow dashboard (autopilot, scheduling, veto inbox, GEO reports).<\/li>\n<\/ol>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects your site to HarperFlow, a third-party Software-as-a-Service\nplatform (https:\/\/harperflow.io) that writes and publishes articles to your site.\nThe plugin communicates with two HarperFlow hosts:<\/p>\n\n<ul>\n<li><strong>api.harperflow.io<\/strong> \u2014 the HarperFlow API.<\/li>\n<li><strong>app.harperflow.io<\/strong> \u2014 the HarperFlow web dashboard (opened in your browser).<\/li>\n<\/ul>\n\n<p><strong>What is sent, and when:<\/strong><\/p>\n\n<ul>\n<li><strong>On Connect<\/strong> (you paste a pairing code and click Connect): your site URL, your\nWordPress username, and a WordPress Application Password the plugin mints for\nHarperFlow are sent to <code>api.harperflow.io<\/code> so HarperFlow can publish to your site.\nNothing is sent until you initiate the connection.<\/li>\n<li><strong>On \"Open HarperFlow Dashboard (SSO)\"<\/strong> (you click the button): your site host\n(used as your HarperFlow account identifier) and an HMAC-signed timestamp are sent\nto <code>api.harperflow.io<\/code> to mint a one-click sign-in link, then your browser opens\n  app.harperflow.io.<\/li>\n<li><strong>On HarperFlow article writes<\/strong>: HarperFlow calls this site's REST API (authenticated\nwith the Application Password above) to publish or update its own articles. This\nplugin sends nothing outbound here; it only receives and stores the article data.<\/li>\n<\/ul>\n\n<p>No data is transmitted for visitors of your site, and nothing is sent in the\nbackground without an action you took. Use <strong>Disconnect<\/strong> at any time to revoke the\nApplication Password and clear the stored credentials.<\/p>\n\n<p>By connecting, you agree to HarperFlow's Terms of Service\n(https:\/\/www.harperflow.io\/terms-of-service) and Privacy Policy\n(https:\/\/www.harperflow.io\/privacy-policy).<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Download <code>harperflow.zip<\/code>.<\/li>\n<li>In your WordPress admin, go to <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong>.<\/li>\n<li>Choose <code>harperflow.zip<\/code> and click <strong>Install Now<\/strong>, then <strong>Activate<\/strong>.<\/li>\n<li>Go to <strong>HarperFlow<\/strong> in your wp-admin menu.<\/li>\n<li>In your HarperFlow dashboard, add this WordPress site and copy the <strong>pairing code<\/strong>.<\/li>\n<li>Paste the code into <strong>Connect to HarperFlow<\/strong> and click <strong>Connect<\/strong>.<\/li>\n<\/ol>\n\n<p>That's it. One click links this site to your HarperFlow account \u2014 you never create or\ncopy a password. The plugin mints a WordPress Application Password for HarperFlow\nautomatically, registers the site, and enables one-click sign-in back to your dashboard.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"how%20do%20i%20connect%20my%20site%20to%20harperflow%3F\"><h3>How do I connect my site to HarperFlow?<\/h3><\/dt>\n<dd><p>Install and activate the plugin, open <strong>HarperFlow<\/strong> in your wp-admin menu, then paste the\n<strong>pairing code<\/strong> from your HarperFlow dashboard into <strong>Connect to HarperFlow<\/strong> and click\nConnect. The plugin does the rest.<\/p><\/dd>\n<dt id=\"do%20i%20need%20to%20create%20an%20application%20password%20myself%3F\"><h3>Do I need to create an Application Password myself?<\/h3><\/dt>\n<dd><p>No. The plugin creates a WordPress Application Password named \"HarperFlow\" for you, using\nWordPress core, and sends it securely to HarperFlow during the one-click connect. You never\ncreate or copy a password. Application Passwords require WordPress 5.6+ and HTTPS; if they\nare disabled on your site, the plugin tells you and you can connect from the HarperFlow\ndashboard instead. Use <strong>Disconnect<\/strong> to revoke that password at any time.<\/p><\/dd>\n<dt id=\"do%20my%20articles%20still%20publish%20without%20this%20plugin%3F\"><h3>Do my articles still publish without this plugin?<\/h3><\/dt>\n<dd><p>Yes. Posts publish and render in your theme either way. Without the plugin, the SEO\ntitle\/description and the dedicated styled FAQ\/TL;DR sections are not added \u2014 but the\nFAQ and TL;DR text is inlined into the post body, so no information is lost.<\/p><\/dd>\n<dt id=\"does%20it%20touch%20the%20rest%20of%20my%20site%3F\"><h3>Does it touch the rest of my site?<\/h3><\/dt>\n<dd><p>No. The styling and the content additions only run on single posts that HarperFlow\nauthored (gated on a meta flag).<\/p><\/dd>\n<dt id=\"which%20seo%20plugins%20are%20supported%3F\"><h3>Which SEO plugins are supported?<\/h3><\/dt>\n<dd><p>Yoast SEO and Rank Math. HarperFlow writes the matching SEO meta when either is\nactive; otherwise the plugin emits a basic title and meta description itself.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.5.0<\/h4>\n\n<ul>\n<li>Docs: added an External Services disclosure (the third-party HarperFlow hosts this\nplugin talks to, exactly what data is sent, and when) and bumped Tested up to 7.0.<\/li>\n<li>i18n: user-facing admin and front-end strings are now translatable under the\n  harperflow text domain.<\/li>\n<li>Hardening: escapers are applied inline at every output site, and the FAQPage JSON-LD\nnow encodes with JSON_HEX_TAG so a <code>&lt;\/script&gt;<\/code> in a question can never break out.\nNo behavior change \u2014 lint\/robustness only.<\/li>\n<\/ul>\n\n<h4>1.4.2<\/h4>\n\n<ul>\n<li>Security: the \"Open dashboard (SSO)\" handshake now also refuses a non-https API URL, so\nthe signed request is only ever sent over https. Completes the https enforcement started\nin 1.4.1 (which covered the connect handshake and the Advanced override) by applying the\nsame guard to the third and last outbound call.<\/li>\n<\/ul>\n\n<h4>1.4.1<\/h4>\n\n<ul>\n<li>Security: the Advanced API URL override now requires https:\/\/ \u2014 a non-secure override\nis rejected at save time with a clear error, and the one-click connect refuses to send\nyour Application Password to a non-https API URL even if an old\/injected setting has\none (checked before minting the password, so nothing is created needlessly).<\/li>\n<li>Clarity: \"Treat this code like a password \u2014 don't share it\" warning next to the pairing\ncode field. Whoever redeems the code first links your site to their HarperFlow account.<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>New: true one-click connect. Enter the pairing code from your HarperFlow dashboard and\nclick Connect \u2014 the plugin mints a WordPress Application Password via core\n(WP_Application_Passwords) and registers this site automatically. You never create or\ncopy a password. Replaces the previous \"paste your SSO key\" step; the returned SSO\nsecret is stored in the same option, so the existing HMAC style-preservation, one-click\nSSO, and SEO features work unchanged.<\/li>\n<li>New: Disconnect button \u2014 revokes the HarperFlow Application Password and clears the\nstored SSO secret. Reconnect anytime with a fresh pairing code.<\/li>\n<li>Clear errors for the WordPress &lt; 5.6 \/ Application-Passwords-disabled cases (with a\nfallback to connecting from the HarperFlow dashboard).<\/li>\n<\/ul>\n\n<h4>1.3.1<\/h4>\n\n<ul>\n<li>Security: bind style-preservation to a per-site HMAC signature (sso_secret)\ninstead of the forgeable _hf_authored meta flag. Authors cannot inject inline\nCSS without a valid HarperFlow integration signature.<\/li>\n<li>Enhancement: allow color-mix(), clamp(), min(), max() CSS function values\nemitted by the adaptive renderer via the safecss_filter_attr_allow_css filter,\nwith a tight security guard blocking url(), expression(), and javascript:.<\/li>\n<li>Hardening: wrap wp_kses in try\/finally so an unexpected throw cannot leak the\nexpanded CSS allowlist into other filters in the same request.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>New: preserve HarperFlow's inline-styled article components on REST writes for\nHarperFlow-authored posts only, while keeping scripts, iframes, event handlers,\nand unsafe URL schemes stripped.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>New: one-click SSO from wp-admin \u2014 \u201cOpen HarperFlow Dashboard (SSO)\u201d signs you straight into your HarperFlow dashboard (no password). Paste the SSO key shown in the dashboard after connecting this site. Single-use, short-lived login tokens; minted server-to-server.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>New: HarperFlow admin dashboard page (wp-admin \u2192 HarperFlow) \u2014 connection status,\nrecent HarperFlow articles with their GEO metadata, and a link into the web\ndashboard. Read-only; never mutates site data. Purely additive over 1.0.0.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release: REST-exposed HarperFlow meta, Yoast\/Rank Math interop, health\nroute, scoped TL;DR + FAQ rendering, FAQPage JSON-LD.<\/li>\n<\/ul>","raw_excerpt":"Exposes HarperFlow article metadata (SEO, FAQ, TL;DR, GEO) to the REST API and optionally styles HarperFlow posts. Thin by design.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/355851","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=355851"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/thefamoushesham"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=355851"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=355851"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=355851"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=355851"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=355851"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=355851"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}