Yak Event Hooks

Описание

Stop hand-copying data between WordPress and your automation tools. Yak Event Hooks fires a webhook whenever an event happens on your site, carrying a clean JSON payload with everything your workflow needs — no API keys, no accounts, no third-party servers.

Developed by YakWP. See the plugin homepage for documentation and downloads.

Point it at any endpoint that accepts a JSON POST — n8n, Zapier, Make, IFTTT, your own server, or a cloud automation — and instantly start workflows on:

Posts
* Published — share to social, email subscribers, summarize with AI, republish elsewhere.
* Updated — send diffs, updated titles or URLs to downstream systems.
* Trashed / Deleted — clean up records, sheets, or external feeds.

Comments
* Added — forward new comments (author, content, post) to Slack, ticketing, or AI-reply pipelines.
* Status changed — approve/unapprove/spam moderation notifications.
* Deleted — keep moderation logs in sync.

Media
* Uploaded — every new attachment (image, file) with dimensions, size, and URL — perfect for image pipelines.

Users
* Registered — new-user signups (username, email, role) for membership/CRM automation.

Payload example (post published):

`

{
«event»: «publish»,
«post_id»: 42,
«title»: «How to automate WordPress»,
«slug»: «automate-wordpress»,
«url»: «https://example.com/automate-wordpress»,
«post_type»: «post»,
«status»: «publish»,
«old_status»: «draft»,
«new_status»: «publish»,
«author»: «Oliver»,
«categories»: [«Automation»],
«tags»: [«webhook»],
«timestamp»: «2026-09-05 12:00:00»
}
`

Your webhook URL is all it needs. Each event is toggleable, so you only send what you want.

Two things worth knowing

Requests never hold up your site. Payloads are queued and sent after the page response has been handed to the visitor, so a slow or unreachable endpoint cannot stall an editor save. On hosts with a request-finish function (PHP-FPM, LiteSpeed) the plugin still records the real HTTP status. On other hosts the send is fire-and-forget and the log says so honestly.

You can prove a payload came from your site. Add a shared secret and every request carries an HMAC-SHA256 signature of the raw body plus a timestamp:

`

X-Yak-Signature: sha256=<hmac_sha256(timestamp + «.» + raw_body, secret)>
X-Yak-Timestamp: 1789813016
X-Yak-Delivery: 4f1c…-uuid
X-Yak-Site: https://example.com/
`

Sign the timestamp with the body and reject anything older than a few minutes — that kills replay attacks. Verify with a constant-time comparison before you parse the JSON. Each site should carry its own secret: one shared key across many sites means one compromised site can forge events for all of them.

Is the event list enough to tell a real publish from a scheduled one?

Every post status transition carries both sides of the change (old_status and new_status), so a workflow can tell a brand-new post from a scheduled post flipping over (future publish), or a draft being published. Comment status events carry the same pair.

Made by YakWP

Developed and maintained by YakWP. YakWP also makes a free AI chatbot plugin for WordPress that answers your visitors’ questions right on your site — pair it with Yak Event Hooks so your site not only fires workflows but also talks to every visitor automatically.

Features

  • Fires on post lifecycle (publish/update/trash/delete), comments (added/status/deleted), media uploads, and new-user registrations.
  • Works with any post type (posts, pages, custom types) and filters events by selected post types.
  • Optional excerpt and full-content fields in the post payload.
  • Optional HMAC-SHA256 signing of every payload, per site, with replay protection via a signed timestamp.
  • Non-blocking delivery: events are sent after the response, so a slow endpoint never delays a save.
  • Post status transitions include old_status and new_status.
  • Cool-down timer prevents repeat firing during rapid saves.
  • Test button — send a sample payload to verify your endpoint before trusting it live.
  • Delivery log — see every send, its HTTP status, and any errors, right in wp-admin.
  • REST API — read and update settings remotely (/wp-json/yak-event-hooks/v1/settings, /log).
  • Lightweight: one HTTP request per event, no database tables, no scheduled tasks, no external services.
  • No retry queue: if the endpoint is unreachable the send is logged and not repeated. Build the retry on the receiving side if you need delivery guarantees.

Privacy

No data ever leaves your site except the JSON payload you asked us to send to your own webhook URL. There are no analytics, no tracking, and no third-party requests.

Скриншоты

Установка

  1. Upload the yak-event-hooks folder to /wp-content/plugins/ or install via Plugins → Add New.
  2. Activate the plugin.
  3. Go to Settings → Yak Event Hooks.
  4. In n8n (or your automation tool), add a Webhook node, enable it, and copy the full URL.
  5. Paste the URL into the plugin, tick the events you want, and save.
  6. Use the Send Test Payload Now button to confirm the connection.

Часто задаваемые вопросы

Do I need an API key or account?

No. You only need the webhook URL of your own endpoint.

Does it only work with n8n?

No. It works with any endpoint that accepts a JSON POST — n8n, Zapier, Make, IFTTT, webhooks.dev, or your own server.

Which events are supported?

Post published, updated, trashed, and permanently deleted; comment added, comment status changed, comment deleted; media (attachment) uploaded; and new user registered. Every event is toggleable.

Which WordPress versions are supported?

WordPress 5.0 and later, including the latest releases. PHP 7.4 or higher.

Does sending a webhook slow down my editor?

No. Events are queued during the request and delivered on shutdown, after the response has gone out. In the default background mode a stalled endpoint costs your editors nothing. If you need the delivered HTTP status inline (debugging a broken endpoint), switch Delivery to synchronous — that is the old behaviour.

How does the receiver verify a payload really came from my site?

Set a shared secret of 16+ characters and the request carries X-Yak-Signature: sha256=HMAC-SHA256(timestamp + "." + raw body). Compute the same HMAC over the exact raw bytes you received (do not re-serialize the JSON — key order and escaping will differ), compare with a constant-time function, and reject timestamps that are not recent. Use a different secret per site.

Can I clear the secret through the REST API?

GET /wp-json/yak-event-hooks/v1/settings never returns the secret. A PUT with an empty secret leaves the stored one untouched; send clear_secret: true to actually remove it.

Отзывы

Нет отзывов об этом плагине.

Участники и разработчики

«Yak Event Hooks» — проект с открытым исходным кодом. В развитие плагина внесли свой вклад следующие участники:

Участники

Перевести «Yak Event Hooks» на ваш язык.

Заинтересованы в разработке?

Посмотрите код, проверьте SVN репозиторий, или подпишитесь на журнал разработки по RSS.

Журнал изменений

1.3.0

  • Changed: payloads are queued and delivered on shutdown instead of inline, so a slow endpoint no longer stalls the request that triggered the event (an editor save could previously wait up to the full request timeout — twice over when a publish fired both the publish and update events).
  • Added: optional HMAC-SHA256 signing. With a shared secret set, every request carries X-Yak-Signature, X-Yak-Timestamp, X-Yak-Delivery (UUID) and X-Yak-Site headers. The signature covers the timestamp and the raw body, so replays can be rejected.
  • Added: old_status and new_status on post status transitions, so publish can be distinguished from a scheduled post flipping over. Comment status events already carried both.
  • Added: Delivery setting (background / synchronous) and a Request timeout field.
  • Added: shared-secret field with a Generate button (16+ characters enforced).
  • Changed: the REST settings endpoint no longer returns the secret; empty secret on PUT means «unchanged», clear_secret: true clears it.
  • Changed: the delivery log shows whether a payload was signed and whether the response was awaited («sent» vs a confirmed HTTP code).

1.2.0

  • Rebranded to «Yak Event Hooks» (new permalink yak-event-hooks) per the WordPress.org naming guidelines — the «Webhook Events» name was too generic.
  • Added the plugin owner (oliverdj123) to the Contributors list.
  • Settings keys, REST namespace, and admin menu slug updated to match the new name.

1.1.0

  • Added: comment events (added, status changed, deleted).
  • Added: media upload event (new attachment added).
  • Added: new-user registration event.
  • Expanded event coverage beyond posts.

1.0.3

  • Maintenance: PCP clean-up — removed a direct database call, removed a translator placeholder, bumped «Tested up to» to WP 7.1.

1.0.2

  • Added: «Settings» quick-link in the plugin’s row on the Plugins screen.

1.0.1

  • Added: authenticated REST endpoints (/wp-json/yak-event-hooks/v1/settings and /log).

1.0.0

  • Initial release.