“Write a post about morning routines and save it as a draft.”
The finished post lands in your WordPress, with headings, a featured image, a category and filled-in SEO fields.
Available now
Write blog posts, build landing pages, upload images, sort categories, answer comments, change prices. You tell your AI assistant in plain sentences what should happen, and WPAgently carries it out in your WordPress site.
You do not write a line of code for this, but you do need your own access to Claude Code or Codex. WPAgently is the connection from there to your WordPress, not the AI itself.
Choose the plan that fits below. Polar processes the payment and provides your licence key and downloads after checkout.
“Write a post about morning routines and save it as a draft.”
Markdown is converted into native blocks server-side
Plugin=rankmath verified=OK [title:OK description:OK]
6 blocks, freeform: 0, words: 85
Post #105970 sits in your WordPress as a draft, verified and read back.
Abridged real run. The current catalog counts live further down in the catalog section.
Works with the AI access you already have
What you can do
Most of what you currently log in and click for, you now simply tell your assistant. Eight examples from a normal website day.
“Write a post about morning routines and save it as a draft.”
The finished post lands in your WordPress, with headings, a featured image, a category and filled-in SEO fields.
“Build me a sales page for my new group program.”
Twelve ready-made building blocks turn into a complete page. WPAgently picks up colors and fonts from your theme.
“Change the course price from 490 to 590 euros across all pages.”
You get a preview first, WPAgently changes at most 100 pages, and you can undo the whole thing.
“Upload this image, set it as the featured image and file the post under the right category.”
Media library, alt text, featured images, categories and tags are all part of the job, not just the text.
“Go through the new comments, delete the spam and answer the real questions.”
Approving, replying and deleting run through your assistant too. That is one more thing you no longer log in for.
“Rework the SEO titles of my last ten posts.”
WPAgently writes through the native paths of Rank Math, Yoast, AIOSEO, and SEOPress. Rank Math redirects can be read and managed safely. Without a supported plugin, the operation fails visibly.
“Put the new workbook in the shop as a product for 29 euros.”
WooCommerce products are part of the recommended content profile. Order data stays separate and needs its own approval.
“Move the old drafts from 2024 to the trash.”
Nothing gets deleted for good. The trash stays the way back, and restoring works the same way, on request.
Important posts can be marked as cornerstone content in Rank Math and Yoast. Bounded custom Rank Math schemas are read, created, updated, and deleted with conflict protection and exact ID confirmation. Yoast page and article types are read and changed through confirmed provider paths. Administrators can also manage bounded global SEO templates, archive rules, and identity data for Rank Math, Yoast, AIOSEO, and SEOPress with conflict protection. Where an individual provider path explicitly implements restoration, a change is read back. If it differs, WPAgently attempts to restore the previous state, verifies the result, and visibly reports a failed restore as well. An unsafe or ambiguous provider read-back instead reports recovery_required without an automatic follow-up mutation. AIOSEO post SEO is changed only on MySQL or MariaDB with a transactional InnoDB table. Other storage paths fail closed. WPAgently can manage simple local post redirects through SEOPress Free with complete cycle detection and a real HTTP read-back.
The recommended content profile exposes 312 verified actions to your assistant. It covers conflict-protected SEO data, safe builder and theme paths, structured content models, forms, WooCommerce, media, Site Context, and diagnostics. WPAgently includes 398 profile-gated Companion actions in total. The 26 deliberately separate Power actions bring both plugins to 424 typed Ability schemas.
The new paths stay deliberately narrow. Beaver Lite does not expose native user templates and rejects those paths fail closed, while the primitive global settings map is real. GenerateBlocks writes neither rich text nor arbitrary plain text. The commercial Meta Box Settings Pages runtime for values and further licensed or proprietary gaps are not externally certified.
Raw serialized block markup remains blocked. Every write action states its recovery behaviour. If a provider read-back is unsafe or ambiguous, the action reports recovery_required and deliberately makes no automatic follow-up mutation.
Menus, WordPress settings, plugins and themes deliberately stay locked in the recommended setup. Those actions are included in the plugin, but the content profile hides them and WordPress additionally denies them while your bot is an editor.
Catalog
Companion includes 398 profile-gated actions. The recommended content profile exposes 312 of them. Power deliberately stays separate and contains 26 actions. Together, both plugins register 424 typed Ability schemas.
Compatibility
WPAgently writes through the native interfaces of the plugins you probably use anyway. Every card states the verified scope, nothing more.
WordPress
Native core blocks, posts, pages, media, Site Editor templates
WooCommerce
Products plus separately gated order data
Rank Math
SEO data, redirects and bounded schemas, with read-back
Yoast SEO
SEO data, cornerstone and page types through confirmed paths
AIOSEO
SEO data with transactional protection on MySQL or MariaDB
SEOPress
SEO data and simple local redirects
Elementor
Documents, widgets, Global Classes and the Live Editor through the public API
Beaver Builder
Layouts, safe modules and revisions through the model API
Kadence Blocks
Advanced Heading, Spacer and Progress Bar, schema-checked
GenerateBlocks
Query and pagination attributes, deliberately without a text path
Spectra
Block library, popups and bounded block attributes
ACF
Field values for posts, users, terms, comments and options
Meta Box
Field groups, field values, relationships and settings-page definitions
Pods
Content models, field values and bounded ACT records
CPT UI
Post type and taxonomy definitions, conflict-protected
ACPT
Meta groups and supported field values through native paths
The scope per plugin is deliberately bounded and documented per action. Whatever sits outside the verified paths stays read-only or fails visibly. For themes, WPAgently works with the active (child) theme and the Site Editor templates. All names and logos belong to their respective owners and appear here only to state compatibility.
How it works
You need no technical background, just your WordPress site and your own AI assistant.
Install the plugin
You download the WPAgently plugin and install it like any other plugin.
Connect your assistant
A small setup program connects your assistant to your site once. A built-in check then confirms the connection works.
Get going
From then on you say in plain sentences what your website needs. You review and approve.
Claude Code and Codex are the main path. ChatGPT and Claude.ai connect through guided browser OAuth. Fallback configurations also exist for Claude Desktop, Cursor, Windsurf, Visual Studio Code, Gemini CLI, OpenCode, Cline, Roo Code, Kilo Code, Zed, GitHub Copilot, Amazon Q and Antigravity. From WordPress 7.0 onwards you can alternatively chat directly in the backend, click a visible element in the script-isolated preview and approve every proposed change individually.
What you get
Every plan contains the full feature set. The plans differ only in the number of websites.
It installs like any other plugin and makes your website reachable for your assistant.
They tell your assistant from the start how to handle WordPress.
A step-by-step setup in plain language, plus every update during your subscription period.
Your texts and images do not travel through WPAgently servers.
You pay Anthropic or OpenAI directly, and your assistant runs under your own contract. WPAgently does not process your content on its own servers, and the plugin does not send your WordPress credentials to us.
Safety
Letting an AI touch your live site is only a good idea if something checks afterwards. That is exactly what the hardened write paths do, without you configuring the check yourself.
Your bot is an Editor, never an Administrator
It may work on content, but not on menus, settings, plugins or themes.
A preflight check aborts every pipeline as soon as the authenticated account carries the administrator role. Menus, settings, plugins and themes stay locked either way.
New content starts as a draft
Nothing goes live unasked. You read it over and approve it.
Publishing is a separate step and requires two explicit confirmations. Nothing goes live unasked.
Changed values are read back
WPAgently does not trust the success message, it goes and looks afterwards.
The hardened write paths do not trust the success message from WordPress. They read the changed values back out of your website afterwards.
A backup before deeper changes
Without a suitable backup the operation does not start at all.
Before the CLI reaches deeper, it requires a suitable backup. Without one the operation does not start.
The optional developer mode is not a safe mode
It is completely off by default, and anyone who switches it on takes on that risk deliberately.
If you really want to go under the hood (or have someone who does that for you), you can unlock the separate developer mode. It is completely off by default. Before deeper write operations, the CLI requires a suitable backup. Remote database backups contain a versioned restore schema. Tables, views, and triggers that cannot be restored completely are rejected before export. Plugin and theme ZIPs can be inspected within strict bounds, but WPAgently does not install, update, overwrite, or activate them. Actual installation remains a deliberate administrator action in WordPress. Where an individual bounded file or database operation explicitly supports crash recovery, it can be rolled back automatically after a detected crash. This promise explicitly does not apply to arbitrary PHP code.
And yes, something can still go wrong with a verification layer. The difference is that you see it in writing straight away instead of discovering it weeks later. WPAgently does not promise absolute safety, and checks make errors visible without preventing every possible effect.
Comparisons
There are several ways to connect an AI agent to WordPress. The right one depends on how much control over the path of your data you need.
| Dimension | WPAgently | WPVibe | AI Engine |
|---|---|---|---|
| Connection path | Direct to your website's MCP endpoint | Through the vendor's hosted MCP server | MCP server as a feature inside the plugin on your website |
| Your own AI access | Yes, Claude Code or Codex | Yes, the AI subscription you already have | Yes, your own agent operates the website |
| Agent permissions | Editor role, an admin account aborts the run | The permissions of the connected account, up to administrator depending on the account | No role restriction described in the public documentation |
| Draft and approval | Draft by default, publishing requires two explicit switches | Draft by default, dry run with approval before critical bulk actions | Not described in the public documentation |
| Pricing logic | Annual price by number of websites, no call metering | Free entry, paid tiers by tool calls per day | Free version includes the MCP server, the Pro licence extends the framework |
Abridged side-by-side, last checked 14 August 2026 against the vendors' public materials. “Not described” means we cannot substantiate it there, not that it is missing. Novamira covers a broader developer surface, and Angie is a different product model with its own AI. All details, prices and sources live in the four full comparisons.
Who is behind it
I am Finn Hillebrandt, an SEO coach and blogger since 2011. Since mid-2025, I have built real apps, scripts and websites with Claude Code, although I am not a developer. WPAgently is built with Claude Code as well and gives Claude Code and Codex a bounded, verified way to work in WordPress.
I develop and operate it largely on my own in Germany. If you have a question, write to info@blogmojo.de. The person who built it answers.
Pricing
Free runs locally on unlimited websites and does not count calls. The three paid plans contain the full feature set and differ only by number of websites.
Free
$0
forever
Unlimited websites
For a complete, safe content workflow without a licence key.
No account or credit card required
Solo
$99
per year
1 website
For your own website, for example your coaching, course or blog site.
Immediate access through Polar
Pro
$199
per year
5 websites
For several of your own projects or a small team.
Immediate access through Polar
Agency
$399
per year
25 websites
For agencies and service providers with client websites.
Immediate access through Polar
WPAgently is now available. Polar processes payment and taxes as merchant of record. Your licence key and downloads are available in the Polar customer portal after purchase.
What it catches
An agent can write to WordPress without anything arriving. WordPress still reports success. These five cases are the reason WPAgently exists.
The Gutenberg markup was invalid, WordPress silently falls back to the old editor and still reports the save as a success.
Your assistant never writes block markup, it writes Markdown. The server turns that into native blocks and verifies before saving that zero core/freeform blocks were produced.
Title and description go out through the standard interface, but the SEO plugin expects its own fields and ignores both.
WPAgently writes through the native paths of Rank Math, Yoast, AIOSEO and SEOPress and reads the values back afterwards. Without a supported plugin the operation fails visibly instead of writing into the void.
Some side effects only run when you save inside the WordPress backend, for example the sitemap cache and permalink rules.
After writing, WPAgently runs exactly those follow-ups and reports which ones fired.
The retry after a dropped connection simply creates the post again, because nothing checks whether the first attempt got through.
Every write carries an idempotency key. A repeated run recognizes the existing post instead of creating a second one.
Uploading an image by URL is convenient, but that URL can also point at your own server or into a private network.
WPAgently fetches media only from public addresses and checks the resolved IP for it (including DNS rebinding and redirect protection). Everything else is rejected.
FAQ
Yes. You bring your own Claude Code or Codex assistant and pay Anthropic or OpenAI directly. WPAgently connects that assistant to your website, it is not the AI itself.
No. You should know your way around your WordPress and be willing to set up an assistant like Claude Code once, with instructions. I have been building almost everything with Claude Code for over a year without being a programmer.
A WordPress site on a current version (6.9 or newer) and your own access to Claude Code or Codex. That is all.
Your assistant uses a constrained role in the Companion core, new content starts as a draft, hardened write paths read changed values back after saving, and the CLI workflow requires a suitable backup before deeper changes. WPAgently still does not promise absolute safety. Verification can surface failures, but it cannot prevent every possible effect.
In normal use WPAgently writes natively to Gutenberg and targeted schema-bound attributes of server-registered dynamic Spectra blocks. It also has two version-bound Spectra 2.20.1 paths for three responsive alignments and up to three classic hex colors on one `uagb/advanced-heading`, plus forty-six deliberately narrow provider attributes: five GenerateBlocks attributes covering four Query and pagination attributes including two canonical wrapper tags plus one canonical plain-text wrapper tag, thirty Kadence Advanced Heading attributes including responsive pixel sizes, line heights, letter spacing, four bounded pixel margins, and classic icon and hover-icon colors plus icon side and vertical icon alignment for an existing provider icon, four responsive Kadence Spacer attributes, and seven bounded values, widths, and colors on a simple line Progress Bar, each checked against the live server schema. Other GenerateBlocks and Kadence attributes remain read-only. Practically verified Elementor actions administer documents, widgets, controls, subtrees, and global design tokens through its public API, with the write action for global tokens limited to the Design profile. The approval-gated Live Editor can open the real Elementor editor and execute only those existing verified Elementor actions after individual confirmation and a fresh conflict-hash check. Practically verified Beaver Builder actions administer layouts, safe modules, bounded nested column groups, local nodes, and revisions through its model API. Conflict protection, revisions, complete read-back, frontend verification, and verified rollback apply only where the respective builder action explicitly provides them. If a provider read-back is uncertain, the action reports recovery_required instead and deliberately makes no automatic follow-up mutation. Raw HTML and shortcode modules, unfiltered legacy widgets, and global or linked Beaver nodes remain blocked. Static Spectra blocks registered only in JavaScript remain read-only through these write paths, except for its three responsive alignments and classic heading, description, and optional existing separator colors on Spectra 2.20.1. Breakdance, Oxygen, Bricks, and WPBakery are detected, but WPAgently does not blindly rewrite their proprietary data. Bricks, Breakdance, and Oxygen are not yet practically certified with licensed test artifacts.
Claude Code and Codex are the main path. ChatGPT and Claude.ai connect through guided browser OAuth, and fallback configurations exist for Claude Desktop, Cursor, Windsurf, Visual Studio Code, Zed and others. From WordPress 7.0 onwards you can alternatively chat directly in the backend, with your own AI provider through the native WordPress AI Client.
Companion is the plugin for everyday content work and is always installed. Power is a separate plugin for the developer and staging mode, with file, database and PHP access behind several dedicated switches, completely off by default. Companion loads no Power code, and a panic switch can deactivate Power at any time.
No. Your assistant talks directly to your website's MCP endpoint, with no WPAgently server in between. Your texts and images are not processed on third-party servers, and the plugin does not send your WordPress credentials to us.
Every plan is an annual subscription through Polar as merchant of record. You activate the licence key in Companion, the number of websites depends on the plan, and you can cancel online in the Polar customer portal.
For posts and pages the theme does not matter, WPAgently writes native blocks there. Landing-page blocks pick up colors and fonts from your theme. Direct theme files are written only into the active (child) theme and only as .html, .json or .css, with protection against path tricks.
Free costs $0 forever and includes 34 core abilities without call limits on unlimited websites. The annual subscriptions unlock all 398 Companion abilities, Power, backup, restore, CLI, and Skills. Solo (1 website) costs $99 per year, Pro (5 websites) $199 per year and Agency (25 websites) $399 per year.
Yes. Choose the plan that fits in the pricing section. After purchase, Polar provides your licence key and all four downloads in the customer portal.