{"id":373785,"date":"2026-09-23T04:59:17","date_gmt":"2026-09-23T04:59:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/windcodex-ops-safe-ai-actions\/"},"modified":"2026-09-23T06:31:54","modified_gmt":"2026-09-23T06:31:54","slug":"windcodex-ops","status":"publish","type":"plugin","link":"https:\/\/fon.wordpress.org\/plugins\/windcodex-ops\/","author":23476832,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1.2","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"WindCodex Ops \u2013 Safe AI Actions","header_author":"WindCodex","header_description":"Gives Claude, ChatGPT, and other MCP-compatible AI platforms a safe, pre-approved set of actions for everyday WordPress content management \u2013 posts, pages, media, SEO, navigation, and site health \u2013 with undo protection, previews before risky changes, and full OAuth-based authentication. Never runs raw code or touches site files directly.","assets_banners_color":"b3bbce","last_updated":"2026-09-23 06:31:54","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/windcodex.com\/","header_author_uri":"https:\/\/windcodex.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":43,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"windcodex","date":"2026-09-23 06:31:54","revision":3708624}},"upgrade_notice":{"1.0.0":"<p>Initial release \u2013 no upgrade steps required.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3708508,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3708508,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3708624,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3708624,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3708508,"resolution":"1","location":"assets","locale":"","width":1117,"height":1489},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3708508,"resolution":"2","location":"assets","locale":"","width":1119,"height":851},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3708508,"resolution":"3","location":"assets","locale":"","width":1118,"height":2054},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3708508,"resolution":"4","location":"assets","locale":"","width":1116,"height":715}},"screenshots":{"1":"Settings &gt; WindCodex Ops \u2013 Connection tab, with the Connector URL, OAuth discovery links, and a list of connected AI platforms.","2":"Settings &gt; WindCodex Ops \u2013 Tools tab, showing every tool group with its risk badge and on\/off toggle.","3":"Settings &gt; WindCodex Ops \u2013 General tab, including the Data &amp; Privacy uninstall cleanup option.","4":"Settings &gt; WindCodex Ops \u2013 Activity tab, showing the log of AI actions with what ran, when, and whether it succeeded."}},"plugin_section":[],"plugin_tags":[232494,569,216196,229563,260626],"plugin_category":[],"plugin_contributors":[260242],"plugin_business_model":[],"class_list":["post-373785","plugin","type-plugin","status-publish","hentry","plugin_tags-ai-agent","plugin_tags-automation","plugin_tags-chatgpt","plugin_tags-claude","plugin_tags-mcp-server","plugin_contributors-windcodex","plugin_committers-windcodex"],"banners":{"banner":"https:\/\/ps.w.org\/windcodex-ops\/assets\/banner-772x250.png?rev=3708624","banner_2x":"https:\/\/ps.w.org\/windcodex-ops\/assets\/banner-1544x500.png?rev=3708624","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/windcodex-ops\/assets\/icon-128x128.png?rev=3708508","icon_2x":"https:\/\/ps.w.org\/windcodex-ops\/assets\/icon-256x256.png?rev=3708508","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/windcodex-ops\/assets\/screenshot-1.png?rev=3708508","caption":"Settings &gt; WindCodex Ops \u2013 Connection tab, with the Connector URL, OAuth discovery links, and a list of connected AI platforms."},{"src":"https:\/\/ps.w.org\/windcodex-ops\/assets\/screenshot-2.png?rev=3708508","caption":"Settings &gt; WindCodex Ops \u2013 Tools tab, showing every tool group with its risk badge and on\/off toggle."},{"src":"https:\/\/ps.w.org\/windcodex-ops\/assets\/screenshot-3.png?rev=3708508","caption":"Settings &gt; WindCodex Ops \u2013 General tab, including the Data &amp; Privacy uninstall cleanup option."},{"src":"https:\/\/ps.w.org\/windcodex-ops\/assets\/screenshot-4.png?rev=3708508","caption":"Settings &gt; WindCodex Ops \u2013 Activity tab, showing the log of AI actions with what ran, when, and whether it succeeded."}],"raw_content":"<!--section=description-->\n<p><strong>WindCodex Ops<\/strong> connects Claude, ChatGPT, and other MCP-compatible AI platforms to your WordPress site through a fixed, tested list of actions \u2013 not open-ended code execution. If an action isn't on the list, the AI simply cannot do it, full stop.<\/p>\n\n<p>This plugin covers everyday content management, entirely free: posts, pages, media, SEO, site structure, and site health.<\/p>\n\n<h4>Why Site Owners Choose WindCodex Ops<\/h4>\n\n<ul>\n<li><strong>No code execution, ever<\/strong> \u2013 the AI can only call the fixed list of tools this plugin ships with. There is no PHP execution, no arbitrary SQL, no shell access anywhere in the codebase.<\/li>\n<li><strong>Safe on live, customer-facing sites<\/strong> \u2013 every tool is tested and scoped to a specific job (update a meta tag, insert a block, resize an image) rather than a general-purpose capability.<\/li>\n<li><strong>Undo built in<\/strong> \u2013 write actions that support it keep an undo window (72 hours by default, extendable to 96 or 168 hours in Settings), so a mistaken edit is a rollback, not an incident. Undo covers posts, pages, categories, and tags. Undo history and the visible activity feed are independent settings, so you can hide the feed without losing the undo safety net.<\/li>\n<li><strong>Works with any MCP-compatible AI platform<\/strong> \u2013 Claude, ChatGPT, and any other client that speaks the Model Context Protocol connects the same way, over standard OAuth.<\/li>\n<li><strong>No license key, no paywall<\/strong> \u2013 every tool group in this plugin is free and on by default.<\/li>\n<\/ul>\n\n<h4>Key Features<\/h4>\n\n<p>100+ tools across 5 groups, entirely free, no license key required, every group on by default:<\/p>\n\n<ul>\n<li><strong>Content management<\/strong> \u2013 posts, pages, categories, tags, revisions, and Gutenberg content blocks (read, insert, remove, and update one in place by position).<\/li>\n<li><strong>Media and assets<\/strong> \u2013 uploads, alt text, compression, format conversion, and usage lookup so the AI can tell you where an image is used before touching it.<\/li>\n<li><strong>SEO and discoverability<\/strong> \u2013 meta tags, focus keyword, canonical URL, Open Graph, and readability tools that auto-detect Yoast SEO, Rank Math, All in One SEO, and SEOPress, so the same tools work correctly no matter which one is active.<\/li>\n<li><strong>Site structure<\/strong> \u2013 menus, navigation blocks, classic widgets, redirects, sitemap status, and read-only permalink structure lookup.<\/li>\n<li><strong>Site health and diagnostics<\/strong> \u2013 status checks, error logs, cron health, database\/disk usage, and orphaned-data cleanup.<\/li>\n<\/ul>\n\n<p>A flat 120 requests\/minute rate limit applies. The undo window (72 hours by default, selectable 72, 96, or 168) applies to every write tool that supports undo: posts, pages, categories, and tags in this plugin.<\/p>\n\n<h4>Use Cases<\/h4>\n\n<ul>\n<li>Let an AI assistant draft, edit, and publish blog posts and pages without giving it FTP or database access.<\/li>\n<li>Keep SEO metadata (titles, meta descriptions, Open Graph tags) consistent across every post, regardless of which SEO plugin the site runs.<\/li>\n<li>Batch-update image alt text and compress media for accessibility and page speed, from a chat interface.<\/li>\n<li>Clean up broken permalinks, stale redirects, and orphaned post meta without opening the database.<\/li>\n<li>Monitor site health \u2013 error logs, cron status, disk usage \u2013 and get a plain-language summary instead of digging through wp-admin screens.<\/li>\n<li>Insert or update a specific Gutenberg block on a page programmatically, without touching the rest of the content.<\/li>\n<\/ul>\n\n<h4>For Store Owners<\/h4>\n\n<p>The content, media, SEO, and structure tools below work on any post type, including WooCommerce products, so an AI assistant can help with all of this out of the box:<\/p>\n\n<ul>\n<li>Rewrite and standardize product page titles and meta descriptions ahead of a sale or new collection launch, without opening each product one by one.<\/li>\n<li>Compress and add missing alt text across a product image gallery in one pass \u2013 smaller images load faster on mobile, and alt text is what image search actually indexes.<\/li>\n<li>Set up a 301 redirect the moment a product is discontinued or its URL changes, so existing links and search rankings don't turn into 404s.<\/li>\n<li>Find every page and post referencing a specific image before swapping it out for a new banner or seasonal promo graphic.<\/li>\n<li>Add a limited-time menu item (e.g. a Black Friday or holiday collection link) to site navigation and remove it again afterward, without a developer touching the theme.<\/li>\n<li>Check sitemap status and crawl-facing site health before a big traffic push, so search engines can actually find the pages being promoted.<\/li>\n<\/ul>\n\n<h4>Risk Levels<\/h4>\n\n<p>Every tool group is tagged low or medium risk, shown as a badge in <strong>Settings &gt; WindCodex Ops &gt; Tools<\/strong> \u2013 this is informational, not a gate. Every group is on by default; the risk label helps a site owner decide which groups to turn <em>off<\/em> for their particular site.<\/p>\n\n<h4>How It Works<\/h4>\n\n<ol>\n<li>Install and activate the plugin.<\/li>\n<li>Go to <strong>Settings &gt; WindCodex Ops<\/strong> and review which tool groups are enabled.<\/li>\n<li>Copy the Connector URL from the Connection tab and add it to Claude, ChatGPT, or any other MCP-compatible AI platform as a custom connector.<\/li>\n<li>Authenticate once via OAuth \u2013 most platforms register themselves automatically from the discovery URLs on the Connection tab.<\/li>\n<li>The AI can now use any enabled tool group against your site. Revoke any connected app at any time from the Connection tab.<\/li>\n<\/ol>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li>WordPress 6.0 or higher<\/li>\n<li>PHP 7.4 or higher<\/li>\n<li>An MCP-compatible AI platform (Claude, ChatGPT, or similar) to connect to<\/li>\n<li>No WindCodex account, API key, or license required to use this plugin itself \u2013 see <strong>External services<\/strong> below for what it connects to and why<\/li>\n<\/ul>\n\n<h4>Privacy<\/h4>\n\n<p>This plugin has no code-execution capability of any kind \u2013 that's not present anywhere in the codebase. It does not collect data for WindCodex or sell any data. All tool calls run locally against your own site's database through WordPress's normal APIs. The plugin does send data externally in two specific, limited cases \u2013 see <strong>External services<\/strong> below for exactly what's sent, when, and to whom: (1) whatever a specific tool returns, sent only to the AI platform you've explicitly connected via OAuth and only when that platform calls that tool, and (2) a plugin slug (no site or user data) sent to the WordPress.org API only when the plugin-staleness tool is used. By default, deleting the plugin leaves all data in place; opt into full cleanup via <strong>Settings &gt; WindCodex Ops &gt; General &gt; Data &amp; Privacy<\/strong>.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to the following external services:<\/p>\n\n<p><strong>The AI platform you connect (e.g. Claude, ChatGPT, or any other MCP-compatible client)<\/strong><\/p>\n\n<p>The entire purpose of this plugin is to let an AI platform you choose to connect \u2013 over the OAuth connector you set up yourself in <strong>Settings &gt; WindCodex Ops &gt; Connection<\/strong> \u2013 call a fixed list of tools against your site. When that platform calls an enabled tool, this plugin sends back only what that specific tool returns (for example: post\/page content and metadata, media URLs, SEO fields, or site-diagnostic data such as WordPress\/PHP versions or database size), and only in direct response to that tool call. Nothing is sent proactively, on a schedule, or to any platform you haven't explicitly connected and authorized via OAuth. Because you choose which platform to connect, its terms and privacy policy are the platform's own \u2013 for example, Anthropic's (https:\/\/www.anthropic.com\/legal\/consumer-terms and https:\/\/www.anthropic.com\/legal\/privacy) or OpenAI's (https:\/\/openai.com\/policies\/terms-of-use and https:\/\/openai.com\/policies\/privacy-policy).<\/p>\n\n<p><strong>WordPress.org Plugin API (api.wordpress.org)<\/strong><\/p>\n\n<p>The \"Check Plugin Staleness\" tool (<code>wp_check_plugin_staleness<\/code>), when called by your connected AI, looks up each active plugin's last-updated date from <code>https:\/\/api.wordpress.org\/plugins\/info\/1.0\/{slug}.json<\/code> to flag plugins that look abandoned. Only the plugin's slug (its folder\/file name) is sent \u2013 no site data, user data, or content. This call only happens when that specific tool is invoked. See the WordPress.org API's terms (https:\/\/wordpress.org\/about\/privacy\/) for how WordPress.org handles requests to its services.<\/p>\n\n<!--section=installation-->\n<h4>From your WordPress dashboard<\/h4>\n\n<ol>\n<li>Go to <strong>Plugins &gt; Add New<\/strong>.<\/li>\n<li>Search for <strong>WindCodex Ops<\/strong>.<\/li>\n<li>Click <strong>Install Now<\/strong>, then <strong>Activate<\/strong>.<\/li>\n<\/ol>\n\n<h4>Manual installation<\/h4>\n\n<ol>\n<li>Download the plugin ZIP file.<\/li>\n<li>Upload the <code>windcodex-ops<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate through the <strong>Plugins<\/strong> screen in WordPress.<\/li>\n<\/ol>\n\n<h4>After activation<\/h4>\n\n<ol>\n<li>Go to <strong>Settings &gt; WindCodex Ops<\/strong>.<\/li>\n<li>Review which tool groups are on \u2013 everything is enabled by default; turn off anything you'd rather a connected AI not touch.<\/li>\n<li>Copy the Connector URL from the Connection tab and add it to your AI platform as a custom connector.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20phone%20home%20or%20require%20an%20account%3F\"><h3>Does this plugin phone home or require an account?<\/h3><\/dt>\n<dd><p>No license key or WindCodex account is required. The plugin does talk to external services in two specific cases \u2013 see <strong>External services<\/strong> above \u2013 but only to the AI platform you explicitly connect over the OAuth connector you set up yourself, and to the WordPress.org API when the plugin-staleness tool is used.<\/p><\/dd>\n<dt id=\"can%20the%20ai%20run%20arbitrary%20code%20or%20sql%20through%20this%20plugin%3F\"><h3>Can the AI run arbitrary code or SQL through this plugin?<\/h3><\/dt>\n<dd><p>No. WindCodex Ops has no code-execution capability of any kind \u2013 not client-side, not server-side. The AI can only call the fixed, pre-approved list of tools this plugin exposes.<\/p><\/dd>\n<dt id=\"how%20does%20authentication%20work%3F\"><h3>How does authentication work?<\/h3><\/dt>\n<dd><p>OAuth only. Most platforms register themselves automatically via the discovery URLs shown on the Connection tab. If auto-registration fails, paste the Client ID\/Secret from that same tab into the platform's Advanced\/OAuth settings instead. The Connection tab lists every app that's ever connected, who it's currently acting as, and lets you revoke any one of them individually.<\/p><\/dd>\n<dt id=\"which%20ai%20platforms%20can%20connect%20to%20windcodex%20ops%3F\"><h3>Which AI platforms can connect to WindCodex Ops?<\/h3><\/dt>\n<dd><p>Any platform that supports the Model Context Protocol (MCP) as a client, including Claude and ChatGPT. Connection uses standard OAuth, so most platforms auto-register themselves from the discovery URLs on the Connection tab.<\/p><\/dd>\n<dt id=\"can%20i%20undo%20a%20change%20the%20ai%20made%3F\"><h3>Can I undo a change the AI made?<\/h3><\/dt>\n<dd><p>Yes, for any write tool that supports it: post\/page edits and deletes, and category\/tag edits and deletes. WindCodex Ops keeps an undo window (72 hours by default, extendable to 96 or 168 hours under <strong>Settings &gt; WindCodex Ops &gt; General &gt; Preferences<\/strong>) so a mistaken edit can be rolled back instead of manually fixed. Note: WordPress has no trash for categories or tags, so undoing a deleted term recreates it from its saved name\/slug\/description rather than restoring it in place \u2013 posts that had it aren't automatically reassigned. \"Show activity feed\" and \"Keep undo history\" are separate toggles in <strong>Settings &gt; WindCodex Ops &gt; General &gt; Preferences<\/strong> \u2013 turning off the feed doesn't affect undo.<\/p><\/dd>\n<dt id=\"will%20this%20work%20with%20any%20seo%20plugin%3F\"><h3>Will this work with any SEO plugin?<\/h3><\/dt>\n<dd><p>Yes. The SEO tools auto-detect Yoast SEO, Rank Math, All in One SEO, and SEOPress, and read\/write the correct plugin-specific meta fields automatically \u2013 no manual configuration needed.<\/p><\/dd>\n<dt id=\"can%20i%20turn%20off%20specific%20tool%20groups%3F\"><h3>Can I turn off specific tool groups?<\/h3><\/dt>\n<dd><p>Yes. Every one of the 5 tool groups can be switched off independently in <strong>Settings &gt; WindCodex Ops &gt; Tools<\/strong>, regardless of its risk level. Everything is on by default.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20affect%20site%20performance%3F\"><h3>Does this plugin affect site performance?<\/h3><\/dt>\n<dd><p>No. Tools only run when an AI platform actively calls them through the connector; there is no background processing or scheduled task running on every page load.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20my%20data%20if%20i%20uninstall%20the%20plugin%3F\"><h3>What happens to my data if I uninstall the plugin?<\/h3><\/dt>\n<dd><p>By default, all plugin data (settings, connected apps) is left in place in case you reinstall later. If you want everything removed, opt into full cleanup under <strong>Settings &gt; WindCodex Ops &gt; General &gt; Data &amp; Privacy<\/strong> before uninstalling.<\/p><\/dd>\n<dt id=\"is%20my%20data%20sent%20to%20windcodex%20or%20any%20third-party%20server%3F\"><h3>Is my data sent to WindCodex or any third-party server?<\/h3><\/dt>\n<dd><p>Nothing is ever sent to WindCodex, and this plugin does not collect or sell any data. Data is sent externally only as described in <strong>External services<\/strong> above: to the AI platform you've explicitly connected via OAuth (only what an enabled tool returns, only when that platform calls it), and a plugin slug to the WordPress.org API when the plugin-staleness tool is used. Every public, unauthenticated endpoint (OAuth token exchange, dynamic client registration) is rate-limited per IP.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<p>Initial release of WindCodex Ops as its own standalone, entirely free plugin covering content, media, SEO, site structure, and site health.<\/p>\n\n<ul>\n<li>Split the old \"Log all AI activity\" toggle into two independent settings: \"Show activity feed\" (the visible Activity tab, purely cosmetic) and \"Keep undo history\" (the undo safety net). Turning off the feed no longer disables undo.<\/li>\n<li>Moved the \"Undo window\" setting next to \"Keep undo history\" in Preferences so the two related controls sit together.<\/li>\n<li>Extended the undo\/restore system to categories and tags (<code>wp_update_category<\/code>, <code>wp_delete_category<\/code>, <code>wp_update_tag<\/code>, <code>wp_delete_tag<\/code>). Note: a deleted term is recreated from its saved fields rather than restored in place, since WordPress has no trash for taxonomy terms.<\/li>\n<li>The Plugins screen's delete confirmation now correctly skips itself when WindCodex Ops Pro is active, since deleting this plugin in that case never touches any data (Pro owns the shared settings and tables).<\/li>\n<\/ul>","raw_excerpt":"Connect Claude, ChatGPT, and MCP AI platforms to WordPress with safe, pre-approved content, media, SEO, and site health tools. No code execution.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/373785","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=373785"}],"author":[{"embeddable":true,"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/windcodex"}],"wp:attachment":[{"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=373785"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=373785"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=373785"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=373785"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=373785"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=373785"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}