diff --git a/README.md b/README.md
index cac902e1..4f9d4ccd 100644
--- a/README.md
+++ b/README.md
@@ -17,7 +17,7 @@
-
+
---
@@ -239,6 +239,12 @@ These plug straight into **Aura's Fleet MCP Gateway**: read tools run on demand,
## Changelog
+### 2.20.0
+
+- **A rule can target custom CSS.** New rule target type `custom_css` (Digitizers/Aura#576): id = a post id, or id-less / `*` = every page, element and kit custom CSS. `block` / `warn` over-block — a `custom_css:` rule matches a touch on that id or `custom_css:*`, an id-less rule matches any, and `unknown:*` matches every live CSS block/warn. `allow` is strict: it needs a touch with `precise: true` and `css_only: true`, and it fails closed for the whole call if anything else in it is unaccounted CSS. Clearing (`null` / whitespace) is not CSS. (#135)
+- **Elementor's own door declares CSS.** Every write ability is classified: `update-page-settings` and `manage-elements` are precise (CSS read from named arguments; any other field makes the call mixed; a CSS-named key other than `custom_css` in an open `settings` is CSS of unknown shape), `build-composition` and `manage-component` are conservative, global-class and tag-default CSS stay `design_system`. A write whose live input schema grew a CSS-capable path the classification does not handle declares conservatively. (#135)
+- **Older elementor-mcp forks are widened.** An `elementor-mcp/…` write from a fork that cannot declare CSS (below 1.37.0, or without `Elementor_MCP_Rules::css_touches()`) also counts as `custom_css` on its page (or `*` for site-wide) for block/warn — never for allow. `/status` reports `css_rules: { fork: precise | widened | absent }`. (#135)
+
### 2.19.3
- **A sandbox root that is a link is reported as one, even when its target is gone.** `third_party.emcp_sandbox` probed `is_dir()` before `is_link()`; `is_dir()` follows a link, so a `wp-content/emcp-sandbox` link to a missing target read as `present: false, store: null`, and a healthy link was resolved before the no-follow rule applied. The link test now comes first in both places: presence counts the link itself, and `store` answers `sandbox_is_link` without resolving anything. (#133)
diff --git a/digitizer-site-worker/digitizer-site-worker.php b/digitizer-site-worker/digitizer-site-worker.php
index f3f6c82f..1b34fa96 100644
--- a/digitizer-site-worker/digitizer-site-worker.php
+++ b/digitizer-site-worker/digitizer-site-worker.php
@@ -3,7 +3,7 @@
* Plugin Name: SiteAgent for Aura
* Plugin URI: https://my-aura.app/siteagent
* Description: Remote site management agent for Aura dashboard. Enables secure updates, health monitoring, and maintenance operations via REST API.
- * Version: 2.19.3
+ * Version: 2.20.0
* Requires at least: 6.2
* Requires PHP: 7.4
* Author: Digitizer
@@ -18,7 +18,7 @@
exit;
}
-define( 'AURA_WORKER_VERSION', '2.19.3' );
+define( 'AURA_WORKER_VERSION', '2.20.0' );
define( 'AURA_WORKER_FILE', __FILE__ );
define( 'AURA_WORKER_DIR', plugin_dir_path( __FILE__ ) );
diff --git a/digitizer-site-worker/readme.txt b/digitizer-site-worker/readme.txt
index 3bfa8e7b..11c6a1f2 100644
--- a/digitizer-site-worker/readme.txt
+++ b/digitizer-site-worker/readme.txt
@@ -4,7 +4,7 @@ Tags: ai, automation, maintenance, updates, wordpress management
Requires at least: 6.2
Tested up to: 7.1
Requires PHP: 7.4
-Stable tag: 2.19.3
+Stable tag: 2.20.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html
@@ -253,6 +253,9 @@ Yes. SiteAgent is open source under the GPLv2 or later license. The source code
== Changelog ==
+= 2.20.0 =
+* Rules can now target custom CSS: a rule of type `custom_css` blocks, warns about or allows writes that change a page's, an element's or the site kit's custom CSS, on one page or everywhere. Blocking is cautious: a write that might carry CSS counts. Allowing is strict: only a write the plugin can prove does nothing but set CSS is let through. No new settings; a ruleset without such rules behaves exactly as before.
+
= 2.19.3 =
* A third-party sandbox directory that is a link to a missing or unreachable location is now reported as a link, not as "no sandbox here". The audit checks for a link before it looks at what the link points to. Read-only; nothing changes on the site.