Title: Borges Bibliography Builder
Author: Dan Knauss
Published: <strong>4 مايو، 2026</strong>
Last modified: 26 سبتمبر، 2026

---

البحث عن الإضافات

![](https://ps.w.org/borges-bibliography-builder/assets/banner-772x250.png?rev=3522167)

![](https://ps.w.org/borges-bibliography-builder/assets/icon.svg?rev=3522167)

# Borges Bibliography Builder

 بواسطة [Dan Knauss](https://profiles.wordpress.org/dpknauss/)

[تنزيل](https://downloads.wordpress.org/plugin/borges-bibliography-builder.1.7.0.zip)

 * [تفاصيل](https://ar.wordpress.org/plugins/borges-bibliography-builder/#description)
 * [المراجعات](https://ar.wordpress.org/plugins/borges-bibliography-builder/#reviews)
 *  [التنصيب](https://ar.wordpress.org/plugins/borges-bibliography-builder/#installation)
 * [التطوير](https://ar.wordpress.org/plugins/borges-bibliography-builder/#developers)

 [الدعم](https://wordpress.org/support/plugin/borges-bibliography-builder/)

## الوصف

Named for Jorge Luis Borges (1899–1986), the Argentine writer and librarian known
for stories about infinite libraries, imaginary books, and labyrinths of knowledge,
Borges Bibliography Builder brings order to scholarly references in WordPress.

The **Borges Bibliography Builder** transforms DOI(s), PubMed/PMID records, BibTeX,
CSL-JSON, manual entries, and supported free-text citations into a semantically 
rich, deduplicated, auto-sorted reference list with RIS export for citation managers.

**One-click import.** Paste a DOI and Crossref resolves the metadata instantly. 
Paste a PubMed/PMID identifier and Borges resolves it through an authenticated WordPress
REST proxy to NCBI/PMC citation metadata. Paste BibTeX or formatted citations for
books, articles, chapters, webpages, reviews, and theses.

**Nine citation styles.** Choose from Chicago Notes-Bibliography, Chicago Author-
Date, APA 7, MLA 9, Harvard, Vancouver, IEEE, OSCOLA, and ABNT (Associação Brasileira
de Normas Técnicas / NBR 6023:2018) — all with automatic sorting per style rules.

**Portable.** Static HTML output survives plugin deactivation. No shortcodes. No
database tables.

**Accessible by default.** Semantic list markup, keyboard-operable editing and entry
reordering (Alt+Arrow for numeric styles), visible focus, and optional Block Accessibility
Checks integration (requires that plugin at version 4.0 or later) help your bibliographies
meet accessibility expectations.

**Reference-manager friendly.** Export and reuse your bibliography in common research
workflows. Borges supports CSL-JSON, BibTeX, BibLaTeX, RIS, DOI links, JSON-LD, 
and optional COinS metadata for compatibility with tools such as Zotero, Mendeley,
EndNote, JabRef, BibDesk, and other citation managers.

**Reader-facing cite & export.** Optionally add a per-entry Cite / Export panel 
to the published bibliography: a static, JavaScript-free disclosure under each entry
with the citation text and one-click downloads in RIS, CSL-JSON, BibTeX, and BibLaTeX.
Off by default; enable it per block.

**Try it first.** Launch a disposable demo in [WordPress Playground](https://playground.wordpress.net/?blueprint-url=https://raw.githubusercontent.com/dknauss/Borges/main/playground/blueprint.json)
before installing it on your site.

**Translation-ready.** Plugin interface strings use the `borges-bibliography-builder`
text domain, and official WordPress.org language packs are generated as community
translations are approved on translate.wordpress.org.

**Support development.** If Borges saves you time by bringing order to your citations
and joy to your heart, you can [sponsor the author](https://github.com/sponsors/dknauss)
to support ongoing maintenance.

### Performance & Footprint

Borges is a static-output block. Formatted bibliography HTML, JSON-LD, and COinS
are baked into your post content when you save, so the citeproc formatting engine
and the DOI/PubMed lookups run **only in the editor** — never on the front end.

What this means for a published page:

 * **Zero added database queries** — no matter how many bibliographies or citations
   the page contains. Query load does not grow with your content.
 * **No `render_callback`, no REST calls, no shortcodes** on the front end. Output
   is static HTML from the block’s `save()`.
 * **No long-lived settings** — the plugin registers no settings or autoloaded options,
   no custom tables, no custom post types, and no cron events. Editor-time PMID 
   and formatting results are cached in the object cache and in short-lived, non-
   autoloaded transients, written only while editing. DOI imports are deduped in
   a browser-session cache, not stored server-side.
 * **Tiny front-end payload** — only a small view script (~1.4 KB, with no dependencies)
   and stylesheet (~2.9 KB) load, and only on pages that actually contain a bibliography.

Installed footprint is roughly **1.9 MB** (the bundled citeproc-php formatting engine,
translations, and editor/front-end assets account for the total). The latest v1.6.0
downloadable ZIP is **499,681 bytes** (about 488 KB compressed).

Because output is static, your bibliographies remain intact as plain HTML even if
the plugin is deactivated.

### Known Limitations

**OSCOLA grouped bibliography** — OSCOLA convention requires the bibliography to
be divided into source-type groups (cases, legislation, books, articles, online 
sources). Borges currently renders a single alphabetized list regardless of style.
A dismissible notice in the editor explains this when OSCOLA is selected. Grouped-
bibliography support is planned for a future release.

### Development

Full developer documentation, source code, issue tracker, and contribution guidelines
are on GitHub:

[https://github.com/dknauss/Borges](https://github.com/dknauss/Borges)

Bug reports, feature requests, and pull requests are welcome. See CONTRIBUTING.md
in the repository for development setup, coding standards, and the PR process.

### External Services

This plugin connects to fixed scholarly metadata services only when you explicitly
add an identifier in the block editor — no citation data is sent automatically or
in the background. No account or API key is required for any of the supported DOI,
PMID, PMCID, arXiv, or ISBN lookups.

**DOI metadata**

DOI input connects to the **Crossref REST API** (https://api.crossref.org/) to resolve
citation metadata.

 * Crossref service: https://www.crossref.org/
 * Crossref REST API documentation: https://api.crossref.org/swagger-ui/index.html
 * Crossref privacy policy: https://www.crossref.org/privacy/
 * Crossref terms of service: https://www.crossref.org/terms/

**PubMed/PMID and PubMed Central/PMCID metadata**

PubMed/PMID and PubMed Central/PMCID input connects through the plugin’s authenticated
WordPress REST proxy to the **NCBI/PMC Literature Citation Exporter** CSL endpoints.
The proxy uses a fixed upstream host and validates the identifier as numeric before
making the outbound request. Only the identifier is sent.

 * NCBI APIs: https://www.ncbi.nlm.nih.gov/home/develop/api/
 * NCBI/PMC Literature Citation Exporter: https://pmc.ncbi.nlm.nih.gov/api/ctxp/
 * NLM Web Policies: https://www.nlm.nih.gov/web_policies.html

**arXiv metadata**

arXiv IDs, arxiv.org links, and arXiv DOIs connect through the plugin’s authenticated
WordPress REST proxy to the **arXiv API** (https://export.arxiv.org/api/query). 
The proxy uses a fixed upstream host and validates the arXiv ID pattern before making
the outbound request. Only the arXiv ID is sent.

 * arXiv API: https://info.arxiv.org/help/api/index.html
 * arXiv API Terms of Use: https://info.arxiv.org/help/api/tou.html
 * arXiv privacy policy: https://info.arxiv.org/help/policies/privacy_policy.html

**ISBN metadata**

ISBN input connects through the plugin’s authenticated WordPress REST proxy to **
Open Library** (https://openlibrary.org), run by the Internet Archive: its ISBN 
edition endpoint (https://openlibrary.org/isbn/) for the book record and its search
API (https://openlibrary.org/search.json) for author names. If Open Library has 
no record or cannot be reached, the proxy falls back to the **Google Books API**(
https://www.googleapis.com/books/v1/volumes). All upstream hosts are fixed, and 
the ISBN checksum is verified before any outbound request. Only the ISBN is sent.

 * Open Library Books API (ISBN endpoint): https://openlibrary.org/dev/docs/api/
   books
 * Open Library Search API: https://openlibrary.org/dev/docs/api/search
 * Internet Archive terms of use: https://archive.org/about/terms.php
 * Google Books APIs: https://developers.google.com/books
 * Google APIs Terms of Service: https://developers.google.com/terms
 * Google Privacy Policy: https://policies.google.com/privacy

## لقطات الشاشة

[⌊Front-end bibliography output with hanging indents, italic titles, and linked 
DOIs, styled by the active theme.⌉⌊Front-end bibliography output with hanging indents,
italic titles, and linked DOIs, styled by the active theme.⌉[

Front-end bibliography output with hanging indents, italic titles, and linked DOIs,
styled by the active theme.

[⌊Discover the Bibliography block in the block inserter by searching for "Bibliography."⌉⌊
Discover the Bibliography block in the block inserter by searching for "Bibliography.
"⌉[

Discover the Bibliography block in the block inserter by searching for “Bibliography.”

[⌊Paste DOIs, PubMed/PMID identifiers, BibTeX, CSL-JSON, or free-text citations 
into the import form; hover any entry to reveal copy, edit, and delete actions.⌉⌊
Paste DOIs, PubMed/PMID identifiers, BibTeX, CSL-JSON, or free-text citations into
the import form; hover any entry to reveal copy, edit, and delete actions.⌉[

Paste DOIs, PubMed/PMID identifiers, BibTeX, CSL-JSON, or free-text citations into
the import form; hover any entry to reveal copy, edit, and delete actions.

[⌊Switch to Manual Entry to build a citation field by field — Publication Type, 
Author, Title, Container, Publisher, Year, Pages, DOI, and URL.⌉⌊Switch to Manual
Entry to build a citation field by field — Publication Type, Author, Title, Container,
Publisher, Year, Pages, DOI, and URL.⌉[

Switch to Manual Entry to build a citation field by field — Publication Type, Author,
Title, Container, Publisher, Year, Pages, DOI, and URL.

[⌊Correct imported or free-text citations in place with the structured field editor—
fix individual fields without retyping the whole entry.⌉⌊Correct imported or free-
text citations in place with the structured field editor — fix individual fields
without retyping the whole entry.⌉[

Correct imported or free-text citations in place with the structured field editor—
fix individual fields without retyping the whole entry.

[⌊For numbered styles such as IEEE and Vancouver, reorder entries with the up and
down controls (or Alt+Arrow keys) to set citation numbering.⌉⌊For numbered styles
such as IEEE and Vancouver, reorder entries with the up and down controls (or Alt
+Arrow keys) to set citation numbering.⌉[

For numbered styles such as IEEE and Vancouver, reorder entries with the up and 
down controls (or Alt+Arrow keys) to set citation numbering.

[⌊Choose the citation style and visible heading and toggle metadata output — JSON-
LD, COinS, CSL-JSON, and the per-entry Cite / Export panel — from the block settings
sidebar.⌉⌊Choose the citation style and visible heading and toggle metadata output—
JSON-LD, COinS, CSL-JSON, and the per-entry Cite / Export panel — from the block
settings sidebar.⌉[

Choose the citation style and visible heading and toggle metadata output — JSON-
LD, COinS, CSL-JSON, and the per-entry Cite / Export panel — from the block settings
sidebar.

[⌊Export the whole bibliography from the sidebar: copy as plain text, or download
CSL-JSON, BibTeX, BibLaTeX, or RIS.⌉⌊Export the whole bibliography from the sidebar:
copy as plain text, or download CSL-JSON, BibTeX, BibLaTeX, or RIS.⌉[

Export the whole bibliography from the sidebar: copy as plain text, or download 
CSL-JSON, BibTeX, BibLaTeX, or RIS.

[⌊Readers can expand the per-entry Cite / Export panel on the published page to 
copy a citation or download it as RIS, CSL-JSON, BibTeX, or BibLaTeX.⌉⌊Readers can
expand the per-entry Cite / Export panel on the published page to copy a citation
or download it as RIS, CSL-JSON, BibTeX, or BibLaTeX.⌉[

Readers can expand the per-entry Cite / Export panel on the published page to copy
a citation or download it as RIS, CSL-JSON, BibTeX, or BibLaTeX.

## المكوّنات

تقدّم هذه الإضافة مكوّن واحد (1).

 *   Bibliography A scholarly bibliography block. Add DOI(s), PubMed/PMID or PMCID
   records, arXiv IDs, ISBNs, BibTeX entries, and supported citations to build a
   semantically rich, auto-sorted reference list.

## التنصيب

 1. Upload the plugin files to `/wp-content/plugins/borges-bibliography-builder/`, 
    or install directly through the WordPress plugin screen.
 2. Activate the plugin through the ‘Plugins’ screen in WordPress.
 3. Add the “Bibliography” block to any post or page.
 4. Paste DOI(s), PubMed/PMID identifiers, BibTeX, CSL-JSON, or supported citations
    for books, articles, chapters, and webpages — or add citations manually.

## الأسئلة المتكررّة

### Which translations are available?

The WordPress.org plugin page’s Languages list is the canonical list of currently
published language packs. English (US) is the source language and is not counted
as a translated locale; other locales appear after their Stable plugin translations
are approved on translate.wordpress.org and a language pack is generated.

The package includes seed PO/MO files for translator review and import in French(`
fr_FR`), German (`de_DE`), Dutch (`nl_NL`), Swedish (`sv_SE`), Spanish (`es_ES`),
Italian (`it_IT`), Portuguese (`pt_PT`), Polish (`pl_PL`), Russian (`ru_RU`), Japanese(`
ja`), Simplified Chinese (`zh_CN`), Korean (`ko_KR`), Serbian (`sr_RS`), Croatian(`
hr`), Brazilian Portuguese (`pt_BR`), Hindi (`hi_IN`), Bengali (`bn_BD`), Tamil (`
ta_IN`), and Telugu (`te`). These files cover plugin interface strings only and 
should not be read as official WordPress.org language-pack availability.

### What citation input formats does the Borges Bibliography Builder support?

Bare DOIs, DOI URLs, PubMed/PMID identifiers, PubMed Central PMCIDs, arXiv IDs and
links, ISBNs, BibTeX and BibLaTeX, CSL-JSON, manual citation entries, and supported
formatted citations for books, articles, chapters, webpages, reviews, and theses/
dissertations. Free-text citations that include an inline DOI or labeled PMID are
routed through the DOI/PubMed resolvers before falling back to the heuristic parser.
RIS is supported as an export format, not as an import format. You can paste multiple
entries at once, up to 50 per paste, and each bibliography holds up to 200 citations
in total.

### Does the ABNT style implement NBR 6023:2018?

Yes. The ABNT option targets Associação Brasileira de Normas Técnicas bibliography
formatting under NBR 6023:2018, uses the `pt-BR` locale, and defaults new ABNT bibliographies
to the heading `Referências`. Always verify institutional or journal-specific ABNT
variants before submission.

### What happens if I deactivate the Borges Bibliography Builder?

Your bibliographies remain fully readable. The block uses static HTML output, so
all formatted citations stay in your post content.

### What happens if I delete the Borges Bibliography Builder?

Your bibliographies stay in your posts — they are saved as static HTML, not in a
database table the plugin owns. When you delete the plugin, Borges removes only 
its own cached lookup data (transient and object-cache entries) and leaves your 
content untouched.

### Does the Borges Bibliography Builder work with Zotero, Mendeley, EndNote, and other citation managers?

Yes. Borges is built around portable bibliography formats rather than lock-in. Zotero
can use DOI links, BibTeX, RIS, CSL-JSON, and optional COinS metadata. Mendeley 
and EndNote are best supported through BibTeX/RIS exports, with DOI-backed entries
also friendly to browser importers. JabRef, BibDesk, and LaTeX/Biber workflows can
use UTF-8 BibTeX or BibLaTeX. CSL-JSON is available for citeproc and scholarly data
workflows.

### Why would I enable CSL-JSON?

Enable CSL-JSON if you want your bibliography data to be reusable by scholarly tools,
scripts, or services without scraping the visible citation text.

### Can I export the bibliography data?

Yes. In the editor you can download the whole bibliography as CSL-JSON, BibTeX, 
BibLaTeX, or RIS, copy any single citation, or copy the full bibliography as plain
text. You can also enable a per-entry Cite / Export panel that places the same RIS,
CSL-JSON, BibTeX, and BibLaTeX downloads — plus the citation text — directly on 
the published page for your readers. The reader-facing panel is static and JavaScript-
free and is off by default.

### Can I access bibliography data via API?

Yes. The plugin exposes read-only REST endpoints at `/wp-json/bibliography/v1/posts/
<post_id>/bibliographies` and `/wp-json/bibliography/v1/posts/<post_id>/bibliographies/
<index>` (or the block’s `bibliographyId` in place of the index). Published posts
are readable publicly; non-public posts require permission to edit the post. The
single-bibliography route also supports `format=json`, `format=text`, and `format
=csl-json`. Users who can edit the post can also validate a bibliography’s entries,
list likely duplicates, and preview it in another citation style (`/validate`, `/
duplicates`, and `/preview?style=` under the block’s index or `bibliographyId`);
none of these saves anything. Editor-only authenticated endpoints handle CSL formatting
and PubMed/PMID resolution; they do not persist citations by themselves. A site 
can also opt in to write routes that add, change, remove, and reorder citations,
change block settings, and switch the citation style over REST. They are off unless
a developer enables them with the `bibliography_builder_enable_write_routes` filter;
see `docs/rest-write-routes.md` in the GitHub repository.

### Does the Borges Bibliography Builder work on WordPress Multisite?

Yes. Borges works on WordPress Multisite, including network activation. If you encounter
issues on a specific network configuration, please report them.

### What PHP and WordPress versions are supported?

PHP 7.4+ and WordPress 6.4+. Borges Bibliography Builder is tested up to WordPress
7.1.

### Does Borges work with the Block Accessibility Checks plugin?

Yes, and the integration is entirely optional. When Block Accessibility Checks 4.0
or later is active, the Bibliography block registers four authoring-time checks:
an error when the block contains no citations, and warnings for a missing heading,
for citations whose link text is a bare URL or DOI, and for having every machine-
readable metadata output disabled. You can adjust each check’s severity, or turn
it off, from the Block Accessibility Checks settings screen.

Version 4.0 replaced the plugin’s registration API, so the integration requires 
4.0 or later. On Block Accessibility Checks 3.x the integration stays dormant and
no bibliography checks appear. Borges itself is unaffected and works normally whether
that plugin is outdated or not installed at all.

## المراجعات

لا توجد مراجعات لهذه الإضافة.

## المساهمون والمطوّرون

“Borges Bibliography Builder” هو برنامج مفتوح المصدر. وقد ساهم هؤلاء الأشخاص بالأسفل
في هذه الإضافة.

المساهمون

 *   [ Dan Knauss ](https://profiles.wordpress.org/dpknauss/)

لقد تم ترجمة ”Borges Bibliography Builder“ إلى لغة واحدة. شكراً إلى جميع [المُترجمين](https://translate.wordpress.org/projects/wp-plugins/borges-bibliography-builder/contributors)
لمُساهماتهم.

[ترجمة ”Borges Bibliography Builder“ إلى لغتك.](https://translate.wordpress.org/projects/wp-plugins/borges-bibliography-builder)

### مُهتم بالتطوير؟

[تصفّح الشفرة](https://plugins.trac.wordpress.org/browser/borges-bibliography-builder/)،
تحقق من [مستودع SVN](https://plugins.svn.wordpress.org/borges-bibliography-builder/)،
أو الاشتراك في [سجل التطوير](https://plugins.trac.wordpress.org/log/borges-bibliography-builder/)
بواسطة [RSS](https://plugins.trac.wordpress.org/log/borges-bibliography-builder/?limit=100&mode=stop_on_copy&format=rss).

## سجل التغييرات

#### 1.7.0

 * **Better formatting in every citation style.** All nine styles are rewritten 
   in full from their style manuals: Chicago (notes-bibliography and author-date),
   APA 7, MLA 9, Harvard, IEEE, Vancouver, OSCOLA, and ABNT. Entries now keep full
   given names, volume, issue, and pages, editors, translators, editions, and access
   dates, and follow each manual’s author-list and “et al.” rules. ABNT now prints
   in Portuguese, and Harvard uses British conventions. Existing bibliographies 
   keep their saved text until an entry is added or edited or the style is changed.
 * **Fixed: organization authors** (such as “Open Research Alliance”) no longer 
   vanish from formatted entries, and an entry after one shortened to “et al.” keeps
   the “and” before its last author.
 * **Fixed: “Attempt Block Recovery” in other languages.** A bibliography no longer
   opens as invalid when an editor using a different language from the one who saved
   it opens the post. Cite / Export labels are now translated for visitors as the
   page renders.
 * **Fixed: wrong translations.** In all 19 bundled translations, seven strings 
   such as “Copy citation” showed as “Add citations”. They now fall back to English
   until corrected.
 * **Fixed: whole `.bib` exports from reference managers.** Zotero abstracts with
   blank lines, JabRef comments and `@string` macros, and EndNote reference-type
   names no longer lose or garble records.
 * **Fixed: duplicated blocks** no longer share IDs with the original, and pasting
   CSL-JSON is rejected instead of producing a nonsense citation.
 * **New for developers: review and write routes.** Users who can edit a post can
   validate a bibliography, list likely duplicates, and preview it in another style
   over REST or as WordPress 6.9 abilities, without saving anything. Sites can also
   opt in to write routes that change citations, block settings, and the citation
   style over REST. They are off by default, preview every change first, and save
   through normal post revisions.
 * **Playground demo:** the live demos open on a page with copy-ready samples of
   every input format and three example bibliographies.

#### 1.6.0

 * **New: PubMed Central import.** Paste a PMCID (`PMC3531190`) and it is looked
   up through the same NCBI service as PubMed IDs.
 * **New: arXiv import.** Paste an arXiv ID, an arxiv.org link, or an arXiv DOI (`
   arXiv:1706.03762`, `10.48550/arXiv.1706.03762`) and it is looked up through the
   arXiv API. arXiv DOIs used to fail because Crossref doesn’t hold them.
 * **New: ISBN import.** Paste `ISBN 978-0-14-032872-1` or a labeled ISBN-10 and
   the book is looked up through Open Library, with Google Books as a fallback. 
   Checksums are verified before any lookup, and a Google result is used only if
   it carries the exact ISBN you pasted.
 * **New: BibLaTeX import** (`date`, `journaltitle`, `@online`, and similar) is 
   now covered by tests. Formatted citations that contain a PMCID, arXiv ID, or 
   labeled ISBN are looked up the same way as the bare identifier.
 * **New: WordPress Abilities (WordPress 6.9 and later).** Three read-only abilities
   let AI assistants and automation tools list a post’s bibliographies, export one
   as CSL-JSON or plain text, and check citation records, with the same permissions
   as the existing REST routes. Nothing can be changed through them.
 * **Fixed: invalid language tags on imported entries.** BibTeX `language` and BibLaTeX`
   langid` values such as `ngerman` were saved verbatim into the entry’s HTML `lang`
   attribute, which assistive technology cannot use. They now map to standard tags(`
   ngerman`  `de`); unknown values are left out. Already-saved entries are unchanged.
 * **Fixed: arXiv links from BibTeX.** arXiv preprints pasted as BibTeX or BibLaTeX
   now keep a link to the abstract page instead of dropping the eprint.
 * **Translations:** the translation template is back in sync with the plugin. A
   few help strings changed to name the new identifier types.
 * **Privacy:** the External Services section now also lists arXiv, Open Library,
   and Google Books. Each is contacted only from the editor, only when you paste
   that kind of identifier, and receives only the identifier.

#### 1.5.1

 * **WordPress 7.1 support.** Verified against a 7.1 release candidate: the block
   registers and renders in the editor, which 7.1 now always runs inside an iframe,
   and bibliographies still format correctly in every citation style tested.
 * **Fixed: copying could report failure when copying was still possible.** Both**
   Copy citation** and **Copy bibliography** had a fallback for browsers without
   clipboard access, but only used it when that access was missing entirely — not
   when the browser offered it and then refused. A refusal now falls through to 
   the fallback instead of reporting failure.

#### 1.5.0

**Security release. Updating is recommended for all sites.**

 * Security: Fixed a denial-of-service weakness in the public bibliography REST 
   route, present in 1.4.2 and earlier. Reading a bibliography ran its stored citation
   text through WordPress tag stripping with no length limit, and past roughly 600
   KB that operation degrades badly — a single oversized value saved into a published
   post cost about 12 seconds of pinned CPU on every read, on a route that requires
   no login and can be requested repeatedly at no cost to the caller. Stored text
   is now truncated to 64 KB before stripping, so existing bibliographies still 
   render. This is the change that makes updating worthwhile.
 * Security: Applied the same 64 KB limit to citation text sent to the formatter
   endpoint, where any user who can reach the block editor could otherwise tie up
   a CPU core per request.

The three changes below are hardening. None of them was exploitable; each was a 
case where the plugin happened to be safe because of how some unrelated code was
written, which is a property that quietly stops holding when that code changes.

 * Hardening: Bibliography data in a post type registered as non-public is no longer
   readable without authentication. Published status alone previously satisfied 
   the check. Anyone able to edit the post still has access.
 * Hardening: Links generated from citation text are now restricted to `http` and`
   https`, and any other scheme renders as plain text. Nothing downstream would 
   have caught a `javascript:` link; the only thing preventing one was the URL-detection
   pattern requiring a literal `http(s)://` prefix, which a later improvement to
   that pattern could have removed.
 * Hardening: PubMed/PMID lookups now use WordPress’s safe HTTP client, so every
   redirect in the chain is validated against the site’s own network.
 * Escape two Unicode line-separator characters in the JSON-LD and CSL-JSON output
   blocks. Not a security issue — these blocks are never executed — but the characters
   terminate a line for a JavaScript parser and would break a consumer that evaluates
   a block instead of parsing it.
 * Update the Block Accessibility Checks (BAC) integration for BAC 4.0, which replaced
   the registration API and renamed its editor filter hooks. All four bibliography
   checks — empty bibliography, missing heading, raw URL link text, and all metadata
   outputs disabled — are now admin-configurable from BAC’s unified settings screen.
 * The BAC integration now requires Block Accessibility Checks 4.0 or later. On 
   BAC 3.x the integration stays dormant and no bibliography checks appear; Borges
   itself works normally whether BAC is outdated or not installed at all.
 * Add a regression test that validates every shipped bibliography markup format
   against the block’s own deprecation chain, guarding existing posts against “Attempt
   Block Recovery” prompts after an upgrade.
 * Fix the end-to-end test covering the Block Accessibility Checks integration, 
   which silently skipped itself and left the integration without real coverage.
 * Add a second WordPress Playground demo that boots the current development build
   alongside the released-version demo.
 * Add a scheduled monitor that verifies each Playground demo link stays reachable.
 * Publish hand-verified size, footprint, and runtime-overhead metrics, each paired
   with the command used to re-derive it, and add a continuous-integration check
   that fails when the recorded lines-of-code figures or the no-persistent-storage
   audit drift.

#### 1.4.2

 * Resolve DOI and labeled PMID identifiers embedded in free-text citation pastes
   through the existing CrossRef and PubMed resolver paths.
 * Fall back from embedded-identifier resolution to the heuristic free-text parser
   before showing unsupported-input guidance.
 * Add free-text sample documentation for supported embedded DOI/PMID citation inputs.
 * Stabilize numeric citation reorder E2E coverage against editor readiness races.
 * Clarify that RIS is supported for export, not import.

#### 1.4.1

 * Clean up after the plugin when it is deleted: uninstalling now removes the plugin’s
   cached data — the formatter and PubMed/PMID transients (across all sites on multisite)
   and its object-cache groups where the host supports it. Bibliography blocks already
   saved in your posts are left untouched.

#### 1.4.0

 * Add optional per-entry Cite / Export affordances to the public bibliography: 
   a static, no-JS `<details>` disclosure panel under each entry with the citation
   text and one-click downloads for RIS, CSL-JSON, BibTeX, and BibLaTeX. Enable 
   it per block with the new “Per-entry Cite / Export” toggle in the Metadata output
   panel; off by default.
 * Pre-compute BibTeX and BibLaTeX export data in the editor so the front-end downloads
   work without activating the plugin, and derive readable download filenames from
   each citation (for example, watson1953.ris).
 * Only pre-compute export data when the feature is enabled, so bibliographies that
   do not use Cite / Export incur no extra editor work.
 * Use a secure-context-safe helper for generating citation and bibliography IDs.
 * Remove a dead, never-loaded duplicate of the PMID resolver (includes/pmid.php)
   to eliminate a function-redeclare risk.
 * Fix DOI imports for works that Crossref labels with a non-standard type such 
   as “monograph” (common for university-press books), which previously failed to
   import; unrecognized types now map to a sensible CSL type or fall back gracefully
   instead of aborting the import.
 * Fix the default Chicago Notes-Bibliography style (and OSCOLA and MLA) dropping
   the publication year on every entry; those styles used an issued-date form the
   formatter does not render. All bundled styles now show the year, guarded by a
   regression test.
 * Title-case author names and titles that Crossref or PubMed return in ALL CAPS(
   e.g. “TURING” / “I.—COMPUTING MACHINERY AND INTELLIGENCE”) so they no longer 
   render shouting; already-cased text, initials, organizations, and non-Latin scripts
   are left untouched.

#### 1.3.4

 * Refresh the translation template and 19 seed PO/MO locale pairs from current 
   source strings.
 * Add i18n artifact validation to CI so POT, PO, MO, and public language-pack wording
   stay aligned.
 * Clarify that bundled seed language files are translator/import material and WordPress.
   org Languages remains canonical for official packs.
 * Update docs for the current maintenance state and archive historical planning
   notes out of active paths.

#### 1.3.3

 * Restore DOI imports in browser-based WordPress Playground by resolving DOI metadata
   through Crossref’s CORS-friendly CSL transform endpoint.
 * Serialize DOI lookups to respect Crossref’s public concurrency limit when multiple
   DOIs are pasted together.
 * Add a PubMed/PMID sample to the Playground starter content alongside DOI and 
   BibTeX examples.

#### 1.3.2

 * Add optional Block Accessibility Checks compatibility: soft-detects the BAC plugin
   and registers four editor checks (empty bibliography, missing heading, raw URL
   link text, all metadata disabled). Borges works normally when BAC is absent.
 * Harden Playwright E2E plugin-row locator to exclude WordPress update notice rows,
   fixing CI strict-mode violations.
 * Regenerate translation template (POT) with 81 strings, up from 41; covers PHP
   error messages, BAC check strings, BibLaTeX export labels, and citation reorder
   controls.
 * Extend banner generation script with locale and RTL support flags.

#### 1.3.1

 * Raise per-bibliography hard cap from 50 to 200 citations. Bibliographies between
   100 and 199 citations now show a dismissible editor notice warning about potential
   formatting slowness on shared hosting. The per-paste limit (50 entries) is unchanged.

#### 1.3.0

 * Enforce an explicit 50-citation total cap per bibliography block with inline 
   editor warnings, replacing the silent 51-entry formatter cliff.
 * Guard all async editor mutation flows (paste/import, manual add, delete, style
   switch, structured edit) against stale results from superseded in-flight format
   requests.
 * Remove redundant formatter call in the manual-entry add path; the merged bibliography
   is now formatted once instead of twice.
 * Prune non-runtime vendor documentation and images from the release zip and exclude
   composer.lock, reducing release package weight.
 * Cache successful PMID proxy responses and deduplicate pending DOI resolution 
   requests to reduce avoidable network traffic.
 * Refactor editor side-effects into focused hooks: useCitationImportActions, useManualCitationActions,
   and useBibliographyExportActions.
 * Extract PHP PMID resolver, cache, and permission logic into includes/pmid.php.

#### 1.2.0

 * Add BibLaTeX export from the editor exports panel.
 * Highlight 1.2.0 interoperability features, recent 1.1.x accessibility fixes, 
   and ABNT (Associação Brasileira de Normas Técnicas / NBR 6023:2018) support in
   the readmes and changelogs.
 * Add PMID input resolution through an authenticated WordPress REST proxy to the
   NCBI/PMC Literature Citation Exporter API.
 * Add manual reordering controls for numeric citation styles, including keyboard
   Alt+Arrow movement.
 * Reformat the full bibliography after citation mutations so cached display text,
   sort order, and metadata stay aligned.
 * Improve sort parity with style-family dispatch, author-date tie-breakers, and
   JS/PHP coordination fixtures.
 * Improve accessibility names for saved citation URL links and block toolbar controls.
 * Harden Playwright accessibility and Playground smoke tests for shared WordPress
   Playground servers.
 * Add compact matrix coverage for all nine styles, formatter output, export ordering,
   and PMID REST proxy regression before tagging 1.2.0.

#### 1.1.1

 * Fix Block Accessibility Checks (BAC) integration shipped in 1.1.0: register against
   the current BAC API, harden the soft opt-in, and load validation checks reliably
   so the `empty_bibliography` error and `heading_missing` warning fire as documented
   when the BAC plugin is active.
 * Fix editor focus-ring regression so keyboard focus on entry actions remains visible.
 * Fix Playground demo blueprint to install from the latest release zip rather than
   a stale path.

#### 1.1.0

 * Add optional Block Accessibility Checks (BAC) integration: when Troy Chaplin’s
   Block Accessibility Checks plugin is active, the bibliography block registers
   two authoring-time checks — an error if no citations have been added, and a warning
   if no heading is set so screen reader users navigating by heading can find the
   section.
 * No functional change when BAC is not installed.

#### 1.0.2

 * Fix browser-based WordPress Playground demos by explicitly enabling the Playground
   Intl feature in addition to the kitchen-sink PHP extension bundle.
 * Keep the GitHub demo blueprint and WordPress.org Preview blueprint aligned for
   Intl-enabled citation formatting, with regression coverage.
 * Clarify translation wording so the readme distinguishes bundled seed PO/MO files
   from official WordPress.org language packs.

#### 1.0.1

 * Fix Playground/editor bibliography formatting by using the WordPress REST API
   fetch helper for formatter requests.
 * Add the WordPress.org Preview blueprint at the documented assets path with the
   required PHP extension bundle for citation formatting.

#### 1.0.0

 * Initial public release as Borges Bibliography Builder.
 * Add references from DOIs, DOI URLs, BibTeX entries, supported formatted citations,
   or manual entry.
 * Format bibliographies in Chicago Notes-Bibliography, Chicago Author-Date, APA
   7, MLA 9, Harvard, Vancouver, IEEE, OSCOLA, and ABNT (Associação Brasileira de
   Normas Técnicas / NBR 6023:2018).
 * Automatically sort entries per style rules and skip duplicate manual or pasted
   entries.
 * Save static HTML output so bibliographies remain readable after plugin deactivation.
 * Output Schema.org JSON-LD by default, with optional COinS and CSL-JSON metadata
   layers.
 * Export CSL-JSON, UTF-8 BibTeX, and RIS; copy individual citations or the full
   bibliography as plain text.
 * Preserve Unicode quotation marks in BibTeX exports for Zotero, Mendeley, and 
   other citation-manager imports.
 * Provide reference-manager-friendly metadata and exports for Zotero, Mendeley,
   EndNote, JabRef, BibDesk, LaTeX, and CSL/citeproc workflows.
 * Improve accessibility with keyboard navigation, visible focus, block-local notices,
   semantic bibliography markup, and no deprecated bibliography-entry ARIA role 
   in newly saved output.
 * Provide read-only REST API endpoints for programmatic bibliography access.
 * Bundle seed interface locale files for translator review/import while using WordPress.
   org language packs as the canonical availability signal.
 * Harden the WordPress.org release package with third-party notices and Plugin 
   Check cleanup.
 * Standardize GitHub, Playground, and release-download links on the approved `borges-
   bibliography-builder` slug and zip name.
 * Add CI/runtime coverage for Multisite network activation and expanded PHP utility
   behavior.
 * Confirm compatibility wording through WordPress 7.0 testing.

## ميتا Meta

 *  Version **1.7.0**
 *  Last updated **قبل 3 أيام**
 *  Active installations **أقل من 10**
 *  WordPress version ** 6.4 أو أعلى **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 أو أعلى **
 *  Languages
 * [English (US)](https://wordpress.org/plugins/borges-bibliography-builder/) و 
   [Russian](https://ru.wordpress.org/plugins/borges-bibliography-builder/).
 *  [ترجمة إلى لغتك](https://translate.wordpress.org/projects/wp-plugins/borges-bibliography-builder)
 * Tags
 * [academic](https://ar.wordpress.org/plugins/tags/academic/)[bibliography](https://ar.wordpress.org/plugins/tags/bibliography/)
   [bibtex](https://ar.wordpress.org/plugins/tags/bibtex/)[citation](https://ar.wordpress.org/plugins/tags/citation/)
   [doi](https://ar.wordpress.org/plugins/tags/doi/)
 *  [عرض متقدم](https://ar.wordpress.org/plugins/borges-bibliography-builder/advanced/)

## التقييم

لم يتم تقديم أي مراجعات بعد.

[Your review](https://wordpress.org/support/plugin/borges-bibliography-builder/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/borges-bibliography-builder/reviews/)

## المساهمون

 *   [ Dan Knauss ](https://profiles.wordpress.org/dpknauss/)

## الدعم

لديك شيء لتقوله؟ بحاجة الى مساعدة؟

 [عرض منتدى الدعم](https://wordpress.org/support/plugin/borges-bibliography-builder/)

## تبرع

هل ترغب في تقديم دعم متقدم لهذه الإضافة؟

 [ تبرع لهذه الإضافة ](https://github.com/sponsors/dknauss)