A read-only look at your site and its plugins
Point an agent at a WordPress site for a plain inventory of the basics and the installed plugins, without handing it any power to change a thing.
Read morePlain guides, governance notes, and honest use cases for running an AI agent against your own WordPress site.
Point an agent at a WordPress site for a plain inventory of the basics and the installed plugins, without handing it any power to change a thing.
Read moreInstead of hunting post type by post type, ask an agent once and see everywhere a phrase, product name, old link, or claim appears across your whole site.
Read moreMost of the pitch is about what you can switch on. This post is about the floor under all of it: what an agent cannot do here, no matter what you enable.
Read moreA fix-only release: WPML sweeps now read every configured language, tool discovery matches permission, and a broken discovery route resolves again.
Read moreVersion 1.7.0 adds a one-click way to enable a section's ordinary writes, deliberately leaving deletes and high-risk abilities locked, plus a fuller audit log.
Read moreVersion 1.7.0 closes an OAuth revocation race, stops a payment gateway credential leak, and fixes four ACF writes that were destroying content.
Read moreIn 1.7.0 an agent asked to set an image's alt text hit a bare permission denied and had no way to know a different tool would have worked. Here is why, and what changed.
Read moreFive real risks of an AI agent on WordPress, deletion, data leakage, injected content, and credential exposure, mapped to the control that limits each one.
Read moreA hidden instruction in a comment can fool an AI agent on WordPress. What indirect prompt injection is, and how governance contains it when detection can't.
Read more