Giving AI access to your site, safely.
Letting an AI assistant change a live website is a real responsibility. This page explains exactly how WPMate limits what can happen, who can approve it and how to undo it.
Connecting a site
- No passwords. You connect a site by pasting a one-time code into the Mate Connector plugin. The code is valid for 30 minutes and works once. Neither WPMate nor your AI ever sees your WordPress password.
- A secret per site. Pairing creates a random secret shared only by your site and WPMate. Disconnecting the site, or deleting the plugin, removes it.
- Acts as you. The plugin acts as the administrator who connected the site. If that person loses admin access, requests stop working until someone reconnects.
Every request is signed
Each request from WPMate to your site carries an HMAC-SHA256 signature over a timestamp, a random single-use nonce and the request body. The plugin rejects requests that are unsigned, signed with the wrong secret, older than five minutes or replayed. Sites must use HTTPS.
A fixed set of actions
The plugin doesn't expose raw database access, file access or arbitrary code execution. It implements 26 specific actions, documented in the tools reference, using WordPress's own functions:
- Post and page content is filtered to the HTML WordPress allows in posts; scripts, iframes and event handlers are removed.
- Custom CSS that could run scripts (for example
javascript:URLs or non-HTTPS imports) is refused. - Plugins and themes can only be installed from WordPress.org.
Approvals and rollback
Publishing, trashing, installing, updating, switching or deleting plugins and themes, rolling back snapshots and changing search visibility or the homepage are never done straight away. The AI receives “approval required”, and the change waits in your WPMate dashboard until you approve it there. An AI assistant can't approve its own request.
To undo changes: content edits keep WordPress revisions, CSS changes keep snapshots, and plugins and themes are copied before updates and deletions. These are not a full site backup, so keep your own backups too.
Your WPMate account
- AI assistants connect with OAuth 2.1 and PKCE and get short-lived access tokens. You can disconnect every AI assistant at once from your dashboard.
- Passwords and tokens are stored hashed. Sign-in, sign-up and password-reset attempts are rate limited, and password resets use single-use links that expire after an hour.
- Every action is listed in your activity log, with the site, the tool and the result.
Data we keep
WPMate stores your account, your connected sites, approvals and an activity log of actions. Content passes through WPMate to your AI assistant when it reads your site; once returned to the assistant, it's handled under that provider's terms. Activity, approvals and sign-in records are kept for up to 12 months. The full details are in the privacy policy.
Open source plugin
The Mate Connector plugin is GPLv2 and its source is public on GitHub, so you or your developer can review exactly what runs on your site.
Report a vulnerability
If you find a security issue in WPMate or the Mate Connector plugin, please email support@wpmate.ai with “Security” in the subject. Please give us a reasonable time to fix it before disclosing it publicly.