Descrición
Mergúllate no Fediverso con ActivityPub espallando o teu blog por unha audiencia máis ampla! Atrae seguidoras, publica novidades e recibe comentarios na diversa base de usuarias das plataformas compatibles con ActivityPub
Cando o plugin ActivityPub está instalado, o teu blog WordPress funciona como un perfil federado máis, e os perfís de cada autora, tamén. Por exemplo, se a túa web é exemplo.com, entón o perfil do blog atoparase en @exemplo.com@exemplo.com, e os autores como María ou Xosé terán os seus perfís individuais en @maria@exemplo.com e @xose@exemplo.com, respectivamente.
Un exemplo: O meu nome de perfil en Mastodon é @pfefferle@mastodon.social. Ti buscas, atopas o meu perfil e premes “Seguir”. Desde agora, calquera entrada que eu publique aparecerá na portada do teu feed. Do mesmo xeito, podes buscar e seguir o perfil de María en @maria@exemplo.com.
En canto sigas o perfil de María @maria@exemplo.com, todas as entradas que ela publique en exemplo.com aparecerán na portada do teu feed. E se segues o perfil de todo o blog @exemplo.com@exemplo.com, recibirás as novidades que publiquen todas as autoras do blog.
Aviso: Se ninguén segue á autora ou ao perfil do blog, as túas entradas non se verán. Para verificar o funcionamento do plugin, o máis sinxelo é seguir o perfil do blog/autora. Se xa posúes un perfil en Mastodon ou noutra plataforma federada, comeza por seguir este novo perfil.
Testeouse que o plugin funciona coas seguintes plataformas federadas, pero pode haber outras que tamén funcionen:
Algunhas cousas a ter en conta:
- O perfil do blog só é compatible con sitios que teñan as regras de rescritura (rewrite rules) activadas. Se o teu sitio non ten as regras de rescritura, os perfís de autora si que poden funcionar.
- Moitos blogs dunha soa autora prefiren agochar ou redirixir as súas páxinas de arquivo de autora, normalmente usando un plugin SEO como Yoast ou Rank Math. Isto faise normalmente para evitar que se duplique o mesmo contido có da portada do teu blog. Se a túa páxina de autora está desactivada, os perfís de autora de ActivityPub non van funcionar. En vez diso, podes reactivar a túa páxina de autora e marcala como “noindex” nos axustes SEO. Así resolverás igualmente o problema do contido duplicado para os motores de busca e permitirá que os perfís de autora de ActivityPub funcionen.
- Unha vez que ActivityPub estea instalado, só as novas entradas creadas a partir dese momento estarán dispoñibles no fediverso. Do mesmo xeito, mesmo se xa levas un tempo usando ActivityPub, calquera que siga o teu sitio só verá as entradas que publiques desde entón; nunca verá na portada do seu feed as entradas que publicaras previamente. É un proceso moi similar ás subscricións ás newsletters: se te subscribes a unha newsletter, só recibirás correos electrónicos futuros, pero non os antigos, xa arquivados. Con ActivityPub, se alguén segue o teu sitio, só recibirá as novas entradas que publiques desde entón.
Cal é o proceso?
- Instala o plugin ActivityPub.
- Vai á páxina de axustes do plugin e configúraos ao teu gusto. Preme no botón Gardar cando esteas lista.
- Asegúrate de que o perfil de autora do blog está activo se estás usando perfís de autora.
- Vai a Mastodon ou a calquera outra plataforma federada, busca o teu perfil e ségueo. O teu novo perfil terá o formato
@o_teu_nome_de_usuaria@exemplo.comou@exemplo.com@exemplo.com, iso é o que tes que buscar. - No teu blog, publica unha nova entrada.
- Desde Mastodon, comproba se a nova entrada aparece na portada do teu feed.
Aviso: Unha entrada nova pode tardar ata 15 minutos en aparecer no teu fío federado. As mensaxes envíanse a plataformas federadas empregando un cron retrasado. Isto evita problemas no proceso de publicación naqueles casos nos que as usuarias teñen moitas seguidoras. Por favor, non asumas que non funciona só porque non ves as entradas de inmediato. Dálle un tempo. Na maioría dos casos, aparecerá dentro duns minutos, e verás que todo funcionou como estaba previsto.
Capturas





Blocks
Este plugin proporciona 13 bloques.
- ActivityPub Dashboard Stats ActivityPub statistics dashboard widget
- ActivityPub Reply Intent Handler Handles reply intents for federated conversations in the block editor.
- Posts and Replies Display a tab bar to filter between posts only and posts with replies on author archives.
- Fediverse Reactions Display Fediverse likes and reposts for your posts.
- Fediverse Followers Display your followers from the Fediverse on your website.
- Fediverse Extra Fields Display extra fields from Fediverse user profiles.
- Federated Reply Reply to posts, notes, and other content on the Fediverse directly from the block editor.
- ActivityPub Stats Display your annual Fediverse stats as a shareable card.
- ActivityPub Command Palette Registers ActivityPub commands for the WordPress Command Palette.
- ActivityPub Post Format Suggestions Suggests optimal post formats for ActivityPub federation before publishing.
- Fediverse Following Display the accounts you follow in the Fediverse on your website.
- Follow me on the Fediverse Display your Fediverse profile so that visitors can follow you.
- ActivityPub Editor Integration Adds ActivityPub settings and controls to the WordPress block editor.
Instalación
Segue as instrucións habituais para instalar plugins en WordPress.
Instalación automática do plugin
Para engadir un plugin en WordPress empregando o instalador de plugins nativo:
- Vai a Plugins > Add New.
- Escribe “
activitypub” no campo Buscar plugins. - Atopa o plugin de WordPress que queres instalar.
- Preme en Detalles para ver máis información sobre as instrucións do plugin; podes gardalas ou imprimilas para axudarche a configurar o plugin.
- Preme Instalar agora para instalar o plugin en WordPress.
- Despois da instalación, indicarase nunha pantalla se rematou con éxito ou se houbo algún problema.
- Se foi todo ben, preme en Activar plugin para activalo, ou volve ao instalador de plugins para outras accións.
Instalación manual do plugin
Hai algúns casos nos que é axeitado instalar un plugin en WordPress manualmente.
- Se queres controlar a ubicación e o proceso de instalar un plugin en WordPress.
- Se o teu servidor non permite a instalación automática de plugins en WordPress.
- Se queres probar a última versión de desenvolvemento.
A instalación manual dun plugin en WordPress require certa familiaridade co FTP e ser consciente de que podes poñer en perigo o teu sitio se instalas algún plugin incompatible coa versión actual ou procedente dunha fonte que non é de confianza.
Fai unha copia de seguridade do teu sitio antes de continuar.
Para instalar un plugin de WordPress manualmente:
- Descarga o plugin de WordPress ao teu computador.
- Descargar desde o directorio de WordPress
- Descarga desde GitHub
- Se o descargaches como un arquivo .zip, extrae o cartafol do plugin.
- Co teu programa de FTP, sube o cartafol do plugin ao cartafol
wp-content/pluginsdo teu directorio de WordPress. - Vai á pantalla de plugins e atopa na lista o plugin que acabas de subir.
- Preme Activar para activalo.
Preguntas frecuentes
-
tl;dr
-
Este plugin conecta o teu blog de WordPress con populares plataformas sociais como Mastodon, facendo as túas entradas máis accesibles para unha audiencia maior. Cando o instales, as usuarias desas plataformas poderán seguir o teu blog, permitíndolles recibir novas entradas nos seus feeds.
-
Que é “ActivityPub para WordPress”
-
ActivityPub para WordPress engade as caracaterísticas do Fediverso a WordPress, pero non é un substituto para plataformas como Friendica ou Mastodon. Se queres aloxar unha rede social descentralizada, pensa en usar Mastodon ou Friendica.
-
Isto é un publicador cruzado (“crossposter”) para Mastodon? Podo publicar na miña conta de Mastodon xa existente?
-
Non. Un publicador cruzado (“crossposter”) envía copias das túas entradas a algunha conta diferente que teñas nalgún servidor alleo. ActivityPub para WordPress fai o contrario: converte o teu propio sitio nunha conta do Fediverso de primeiro nivel (
@ti@exemplo.com); así, a xente pode seguir o teu sitio directamente e as respostas recíbense como comentarios en WordPress, sen necesidade dunha segunda conta.Este plugin non fai publicacións cruzadas (“crossposting”) entre contas existentes; é unha decisión intencional, non unha característica pendente. Se queres reproducir as entradas nunha conta de Mastodon xa establecida, tes que empregar outro plugin que si estea dedicado ás publicacións cruzadas.
-
Por que “ActivityPub”?
-
O nome ActivityPub vén das dúas ideas fundamentais que sosteñen o protocolo:
- Activity: Baséase no concepto de actividades, como “Crear”, “Favorecer”, “Seguir”, “Anunciar”, etc. Estas son mensaxes estruturadas (normalmente no formato ActivityStreams) que describen o que as usuarias fan na rede.
- Pub: Abreviatura de “publicar” ou “publicación”. Refírese ao feito de que este é un protocolo de publicación-subscrición (pub-sub) – unha usuaria pode “seguir” a outra e recibir as actividades que publique.
En conxunto, ActivityPub é un protocolo para publicar e subscribirse a actividades, integrándose coas redes sociais descentralizadas – diferentes servidores poden interactuar entre si e as usuarias poden seguirse mutuamente polo Fediverso adiante.
-
Como soluciono…
-
Temos unha seción de FAQ na documentación con listas dos problemas máis frecuentes — por exemplo, peticións de seguimento que quedan como “pendentes” ou comentarios no Fediverso que non aparecen — e unha sección de Guías neste enlace da documentación para configurar axustes concretos.
-
Constantes
-
O plugin emprega constantes de PHP para activar, desactivar e cambiar o comportamento por defecto. Por favor, úsaas con coidado e só se sabes o que estás a facer.
ACTIVITYPUB_REST_NAMESPACE– Cambia o espazo de nome (namespace) do punto de acceso REST. Por defecto:activitypub/1.0.ACTIVITYPUB_EXCERPT_LENGTH– Cambia a lonxitude do extracto. Por defecto:400.ACTIVITYPUB_MAX_IMAGE_ATTACHMENTS– Cambia o número de adxuntos que deben ser federados. Por defecto:4.ACTIVITYPUB_HASHTAGS_REGEXP– Cambia a expresión regular por defecto para detectar cancelos nun texto. Por defecto:(?:(?<=\s)|(?<=<p>)|(?<=<br>)|^)#([A-Za-z0-9_]+)(?:(?=\s|[[:punct:]]|$)).ACTIVITYPUB_USERNAME_REGEXP– Cambia a expresión regular por defecto para detectar @-replies nun texto. Por defecto:(?:([A-Za-z0-9\._-]+)@((?:[A-Za-z0-9_-]+\.)+[A-Za-z]+)).ACTIVITYPUB_URL_REGEXP– Cambia a expresión regular (regex) por defecto para detectar urls nun texto. Por defecto:(www.|http:|https:)+[^\s]+[\w\/].ACTIVITYPUB_CUSTOM_POST_CONTENT– Cambia o modelo de Actividades por defecto. Por defecto:<strong>[ap_title]</strong>\n\n[ap_content]\n\n[ap_hashtags]\n\n[ap_shortlink].ACTIVITYPUB_AUTHORIZED_FETCH– Activar AUTHORIZED_FETCH.ACTIVITYPUB_DISABLE_REWRITES– Desactiva a xeneración automática de regrasmod_rewrite. Por defecto:false.ACTIVITYPUB_DISABLE_INCOMING_INTERACTIONS– Bloquea as respostas/comentarios/gústames entrantes. Por defecto:false.ACTIVITYPUB_DISABLE_OUTGOING_INTERACTIONS– Desactiva as respostas/comentarios/gústames saíntes. Por defecto:false.ACTIVITYPUB_DISABLE_REMOTE_CACHE– Desactiva a caché de medios remotos (avatares, medios, emoticonas). Por defecto:false. Substitúe aACTIVITYPUB_DISABLE_SIDELOADINGdesde 7.9.1.ACTIVITYPUB_SHARED_INBOX_FEATURE– Activa a caixa de entrada compartida. Por defecto:false.ACTIVITYPUB_SEND_VARY_HEADER– Actívaa para enviar a cabeceiraVary: Accept. Por defecto:false.
-
Onde podo xestionar as miñas seguidoras?
-
Se activaches o perfil do blog, atoparás a lista das súas seguidoras nos axustes
/wp-admin/options-general.php?page=activitypub&tab=followers.As seguidoras dunha usuaria poden atoparse no menú “Usuarias” -> “Seguidoras” ou en
wp-admin/users.php?page=activitypub-followers-list.Por cuestións relativas á protección de datos, non é posible ver as seguidoras doutras usuarias.
Comentarios
Colaboradores e desenvolvedores
“ActivityPub” é un software de código aberto. As seguintes persoas colaboraron con este plugin.
Colaboradores“ActivityPub” foi traducido a 26 idiomas. Grazas aos desenvolvedores polas súas contribucións.
Traduce “ActivityPub” ao teu idioma.
Interesado no desenvolvemento?
Revisa o código, bota unha ollada aorepositorio SVN, ou subscríbete ao log de desenvolvemento por RSS.
Rexistro de cambios
9.3.1 – 02-09-2026
Security
- Links to remote profiles in the Followers and Following blocks are now limited to regular web addresses when paging through the list.
- Replies cached on posts in the blog profile’s reader feed are no longer readable by logged-out visitors through the WordPress REST API.
- Signatures on incoming requests are now checked against the address the request was actually sent to.
9.3.0 – 2026-09-02
Security
- Block markup in posts from remote accounts is now removed before the post is saved.
- Follow, reply and reaction links advertised by other Fediverse servers now have to be regular web addresses.
- Followers, cached remote profiles, and reader posts are no longer readable by logged-out visitors through the WordPress REST API, and the setting that hides your follower list is now honoured everywhere.
- Inline styles are now removed from posts and profiles that come from remote accounts.
- Posts from remote accounts are now shown in the Social Web reader exactly as the site stored them.
- Replies from remote accounts are now filtered before they are saved when an administrator imports them through search.
Added
- Add a notification setting to turn off emails about likes, reposts, and quotes without silencing real comments and replies.
- Add the Fediverse and ActivityPub logos to the block editor’s icon library on WordPress 7.1 and newer.
- Federate podcast episodes published with Jetpack, including their audio file and cover art.
Changed
- Enable RFC 9421 HTTP Message Signatures by default.
Fixed
- Apps connected through the ActivityPub API now use the standard ActivityPub API permission names. Fetching remote content through your site is treated as reading rather than posting, so an app needs read permission for it.
- Apps now see the real error when a post they open through your site is missing, instead of a generic failure.
- Comment author names are no longer altered on comments that did not come from the fediverse.
- Fixed a crash that could fill the error log when another server edited a reply to a post that is no longer shared to the Fediverse.
- Fixed an error that could break embeds of Fediverse posts whose author was sent in an unexpected format.
- Fixed an error that could occur when looking up a profile on another Fediverse server that sends back an unexpected response.
- Fixed backslashes disappearing from titles and content in posts from remote accounts.
- Fixed responses to ActivityPub addresses written with different capitalisation not being cached correctly.
- Fixed the Application actor not being found when its address was written with different capitalisation.
- Fixed the Mastodon importer creating duplicate posts when an archive was imported a second time.
- Fixed titles, summaries, captions and display names from remote accounts being stored with stray markup.
- Imported Mastodon media descriptions now have unsafe HTML removed before they are saved.
- Imported Mastodon replies now have unsafe HTML removed before they are saved as comments.
- Improve how blocked accounts are matched.
- Improve permission checks for third-party apps connected through the ActivityPub API.
- Improve validation of incoming activities from other servers.
- Screen readers now announce errors in the follow, reply and reaction dialogs.
- Text inside hidden page elements, like invisible dialog pop-ups, no longer shows up in posts shared to the Fediverse.
- The blog profile can be found again from other Fediverse servers on sites that also run Polylang.
9.2.2 – 2026-08-11
Fixed
- Fixed avatars and emoji occasionally failing to cache, and the file warnings that came with it.
- Fixed deletions from Mastodon and other servers not removing the corresponding comment on your site.
- Fixed some styles not loading on the Fediverse admin screens and in the Followers and Following blocks.
- Fixed the editor warning about unsaved changes right after saving a post with an older date.
9.2.1 – 2026-08-03
Fixed
- Fixed duplicate entries and failed undo actions for activities received from other WordPress sites.
- Fixed posts and profiles not being found on Mastodon and other Fediverse software, which happened when a request asked for ActivityPub data but also accepted HTML as a low-priority fallback.
- Fixed remote profiles and followers not being found when their address contains unusual characters.
- Improved checks on boosted content so it is only accepted from the server that published it.
- Improve escaping of embedded link URLs in federated content.
- Improve permission checks for admin-only actions.
- Improve validation of incoming federated activities so the signing key and referenced objects are bound to the sender.
9.2.0 – 2026-07-31
Changed
- ActivityPub responses are now served only to clients that ask for ActivityPub data and nothing else, which keeps that data out of page caches meant for regular web pages.
- Only users enabled for ActivityPub can obtain and use OAuth access tokens.
Removed
- Remove support for the WP REST Cache plugin.
Fixed
- Hide the heading on the Followers and Following blocks when its text is cleared, matching the Reactions block.
- Under Authorized Fetch, ActivityPub responses are no longer stored by page caches such as LiteSpeed or Surge.
9.1.0 – 2026-07-22
Security
- Ensure apps you connect can only act within the access you granted them, and not make wider changes to your site.
- Ensure remote profiles and content are served from the address they claim before storing them.
- Fix a security issue where a remote actor’s profile link could run scripts in the admin area.
- Ignore an incoming follow request whose actor resolves to a different account than the one that sent it.
Added
- Add a filter that allows federating with servers on private or internal networks.
- Add an actor autocomplete endpoint so Fediverse apps can offer typeahead search when mentioning people.
- Federate the episode summary for Podlove Podcast Publisher episodes.
Changed
- Improve reliability of the Social Web admin screen loading.
- Improve the internal handling of the Application actor used for server-to-server requests.
Fixed
- Ensure a follow can only be declined by the account you followed.
- Fixed using the correct cache representation in Surge config
- Fix follow requests from some fediverse services staying pending after they are accepted.
- Fix likes from some accounts being recorded as multiple duplicate comments.
- Fix posts being removed from the Fediverse when edited while scheduled for a future publish date.
- Fix repeated deliveries of a like or repost creating new comments after the original was marked as spam or moved to the trash.
- Fix Starter Kit imports failing on Fediverse servers that require signed requests.
- Fix the scheduled refresh of remote profiles so it actually re-fetches from the remote server. Previously, stale avatars and bios for commenters never updated until they sent a new activity to your site.
- Fix URLs with multiple query parameters (such as avatars, images, profile links, and podcast media) being corrupted in content sent to the Fediverse.
- Prevent caching non-actor objects (such as notes) as remote profiles.
- Refresh cached remote profiles in place during scheduled updates to avoid creating duplicate copies.
- Show the Fediverse Preview for scheduled posts instead of the regular post preview.
- Stop storing responses from remote servers in the database when they were requested uncached.
9.0.2 – 2026-06-29
Fixed
- Improve handling of content received from other servers.
9.0.1 – 2026-06-15
Added
- Add FAQ guides that help solve follow requests stuck on “pending” and comments from the Fediverse not showing up.
Fixed
- Notify followers about your new preference when the Starter Kit policy setting changes, so other servers no longer act on an outdated one.
- Publish the Starter Kit consent policy only on your own blog and author profiles, no longer on system or third-party profiles.
- Starter Kit consent now also works for the blog profile, not just for individual authors.
9.0.0 – 2026-06-10
Security
- Enforce the signing-key host check on incoming federated activities regardless of how the key identifier is formatted.
- Fix the real-time activity stream so it only returns the requesting user’s own activities.
- Harden the Site Health connectivity check so it cannot be used to reach unsafe network addresses.
- Only share comment replies in the Fediverse when the post they belong to is itself federated, so replies on private or non-federated posts stay private.
- Prevent a remote server from discovering which of your followers belong to a third-party server it does not control.
- Prevent logged-in users from viewing another user’s private outbox activities.
- Prevent remote servers from modifying or deleting federated profiles, posts, and interactions they do not own.
- Rate-limit the remote-follow lookup to prevent it from being abused to trigger outbound requests.
- Stop the OAuth token introspection endpoint from revealing another user’s token details to logged-in users.
- Stop the quote-authorization stamp from exposing a post’s other metadata.
Added
- Add a Distribution Mode setting to control how quickly posts are delivered to followers.
- Add an opt-in setting to consent to inclusion in Starter Kits (also called Starter Packs or Featured Collections). Off by default. Find it under Settings, ActivityPub, Activities.
- C2S clients can now request canonical SWICG ActivityPub API scope names such as
activitypub:read:allandactivitypub:write:all, and the OAuth discovery metadata advertises them. - C2S token responses now include
activitypub_actor_idso clients following the SWICG ActivityPub API Basic Profile can discover the authenticated actor. - Generate a blurred color preview (blurhash) for images so other fediverse apps can show a placeholder while your photos load.
- Quote notification emails now include a link to the post that quoted you, so you can review and respond more quickly.
- Warn in the editor before making a post that’s already shared on the Fediverse a draft, private, or password-protected, since followers’ copies will be removed.
Changed
- Add the
blurhashterm to the outbound JSON-LD@contextso attachments that include ablurhashproperty are strictly correct JSON-LD, matching Mastodon’s own context shape. - Federated posts moved to draft, pending, private, trash, or password-protected now send a Delete to followers (previously sent a placeholder “editing” Update or were silent).
- OAuth rate-limit responses now include a
Retry-Afterheader so clients know how long to wait before retrying. - Updated a build dependency to a clean release now that a fixed version is available.
Removed
- Removed functions, methods, and the Follower class that were deprecated in versions 7.0 through 7.4.
Fixed
- Fix a fatal error when receiving a new follower while the Stream plugin is active.
- Fix a follow request being marked as accepted when the confirmation came from a different account than the one being followed.
- Fix the Fediverse settings appearing twice and visibility changes not saving in the block editor when the Classic Editor plugin is also active.
- Fix the introduction video failing to load on the Getting Started help screen.
- Follower synchronization with Mastodon no longer fails, signed requests with query strings now verify correctly.
- Harden the Blurhash encoder: skip decompression-bomb images before decoding, flatten transparency onto white so transparent logos no longer produce near-black placeholders, and defer the cron encode until attachment metadata is saved.
- Images and videos placed in a Media & Text block are now included when a post is shared to the Fediverse.
- Requests from other platforms to feature your posts are now handled correctly instead of being ignored.
- RSS and Atom feeds now show a simple
@usernamemention in place of the reply block’s full embed card, which only renders properly when the plugin’s frontend CSS is loaded. - Stop a deprecation notice from appearing in the error log when the NodeInfo plugin is also active.
Consulta o rexistro de cambios completo en GitHub.
