Limit an AI agent to Editor, not Admin
An AI agent takes on whatever WordPress user connects it. Here is why Editor beats Administrator as that account, and how to scope the connection on purpose.
Read morePlain guides, governance notes, and honest use cases for running an AI agent against your own WordPress site.
An AI agent takes on whatever WordPress user connects it. Here is why Editor beats Administrator as that account, and how to scope the connection on purpose.
Read moreHow to list, audit, and retire WooCommerce coupons with an AI agent: reads first, approval before any write, and every coupon write locked behind a second gate.
Read moreThe WordPress MCP Adapter is the official building block for AI agents. Agent Abilities for MCP adds a governed catalog, admin UI, and audit log on top of it.
Read moreThree 1.6.2 fixes make the plugin's audit log worth trusting: it records the true cause of a block, covers every path that changes state, and stays readable.
Read moreManaging a store and editing a user are different powers. Here is why customer data belongs behind the capability that actually governs editing user accounts.
Read moreIn 1.6.2 we corrected a claim about the audit log. It keeps identifier-only values by design, never free-text content, and here is why that line matters.
Read moreVersion 1.6.2 corrects a claim about our own audit log, tightens who can edit customer data, and closes gaps in what the plugin records and sanitizes.
Read moreTwo controls decide what an AI agent is even offered on your WordPress site, before any per-call permission check runs: the high-risk lock and read-only mode.
Read moreA user-reported OAuth bug and six related fixes bring error responses, discovery, and tool status codes in line with what MCP and OAuth clients expect.
Read more