What we fixed: media reads reached past the uploader
In 1.4.3 an author-level user could read the entire WordPress media library, not just their own uploads. Here is the bug, the fix, and what else shipped.
Read morePlain guides, governance notes, and honest use cases for running an AI agent against your own WordPress site.
In 1.4.3 an author-level user could read the entire WordPress media library, not just their own uploads. Here is the bug, the fix, and what else shipped.
Read moreIn 1.4.2 we fixed a bug where asking for a draft post published it live, two related permission gaps, and two WooCommerce order and product update bugs.
Read moreVersion 1.4.0 adds a one-screen Quick Connect wizard that gets an agent connected fast, without loosening the off by default governance underneath.
Read moreCopy-paste prompts for a freshly connected WordPress MCP server: safe reads, a careful draft write, and what a refusal looks like when an agent overreaches.
Read moreHow an AI agent reads a WPML site correctly over MCP. Content reads now take a language, report what they returned, and counts match the list scope.
Read moreLet an AI agent manage customers and orders on a membership, subscription, or LMS WooCommerce store, safely and audited, now that custom roles are visible.
Read moreLet an AI agent write your titles, meta descriptions, noindex flags, and social images across Yoast, Rank Math, and AIOSEO, under full governance.
Read moreHow contract tests against real vendor code and write verification keep an AI agent's WordPress tools honest and trustworthy.
Read moreIn 1.3.0 we turned OAuth off by default and fixed real security gaps in our own plugin, patched in the open. Here is what changed.
Read more