Architecture and security

wp2ai is more than a plugin
It is an application

The logic does not run inside WordPress. Your sites are not slowed down. The engine updates without you touching anything.

How it works

WordPress

One-click connection. No key to copy, no technical setup.

wp2ai MCP Server

Receives AI requests, runs the 29 rules, orchestrates actions.

AI Assistant

ChatGPT, Claude, Gemini. Receives the editorial context of each site.

wp2ai App

Actions logged, per-site protection rules, validation before publishing.

The WordPress plugin is a lightweight connector. Everything else runs on wp2ai's servers.

Why it is different

WordPress MCP plugin: what connector plugins cannot do.

They expose your WordPress to your AI via MCP. That is useful. But the logic stops there.

Connector plugin alone
  • Connects one AI tool to one WordPress site
  • No memory between sessions
  • No multi-site view
  • No validation before publishing
  • No configurable rules per site
  • You re-explain context every session
  • Ignores the builder you use
wp2ai
  • Lightweight connector in WordPress + server-side engine
  • Persistent editorial memory per site
  • Centralised view across all your sites
  • 29 validation rules before every publication
  • Configurable protection rules per site
  • Your AI already knows each site's context
  • Compatible with Gutenberg, Elementor and Bricks
Rule engine

29 rules. Two levels of control.

Every action is evaluated against the relevant rules for your plan. Rules run on wp2ai servers — not inside WordPress. The result is injected directly into the AI response.

Solo — 12 rules
Safety (1)

Placeholder detection. Prevents publishing unfinished content.

Completeness (5)

Title, content, featured image, media presence, alt text

Structure (6)

Intro, conclusion, CTA, minimum structure, orphan sections, category set

Pro — 29 rules (Solo + 17 more)
SEO (11)

SEO title, meta description, slug, excerpt length, H1 in content, duplicates

Quality (6)

Minimum length, short sections, duplicate titles, broken links, orphan posts

Rules run on every write action — publish, edit, patch, update fields. The result is sent directly to the AI, which can correct and resubmit.

Validation flow

What happens before anything is applied.

Every action goes through the same pipeline. Nothing touches your site without passing this sequence.

01
AI sends the action

Your AI assistant sends an action request to wp2ai via MCP: publish, edit a block, update a field.

02
wp2ai analyses the action

wp2ai evaluates what the action will do: which blocks are affected, what changes, what the current state is.

03
Validation rules run

The relevant rules execute (12 on Solo, 29 on Pro) and produce a detailed analysis of the action.

04
You approve or reject

If validation mode is on, you see the full analysis and decide. You approve or reject in one click. Nothing is applied without your confirmation.

05
Action applied with revision

wp2ai creates a WordPress revision, applies the action, and logs it with timestamp. Rollback is available for 90 days.

Security first

Your sites stay under your control.
At all times.

wp2ai is designed so your AI can act. But never without validation, a trace of everything it did, and rules it cannot override.

01

No credentials in WordPress

The connection token is stored on wp2ai's servers, not in your WordPress database. If your site is compromised, no sensitive data is exposed.

02

Revocable in one click

Each site connection can be cut instantly from the wp2ai dashboard. No plugin to deactivate, no cleanup needed. Access stops immediately.

03

Every AI action is logged

Publications, edits, audits: every action is timestamped, attributed and stored. The complete history is accessible from wp2ai, at any time.

04

Analysis and validation before every action

Before every action, wp2ai analyzes what it will do and runs the validation rules. You see what changes and what blocks, then approve or reject.

FAQ

Technical questions about wp2ai.

What happens if my AI makes a mistake?

wp2ai creates a WordPress revision before every action. If the result is not what you expected, you can roll back in one click from the app. The rollback window is 90 days.

How does wp2ai connect to WordPress?

Through a lightweight plugin installed on your site. The connection token is stored on wp2ai servers, not in your WordPress database. Your site credentials are never exposed.

Does it work with any AI assistant?

Yes. wp2ai exposes a standard MCP server. Any AI assistant that supports the Model Context Protocol can connect to it — Claude, GPT-4, Gemini, and others.

Can I use wp2ai on multiple sites?

Solo plan supports 1 site. Pro supports up to 3. Agency supports up to 50. All sites are managed from a single AI conversation — no need to switch contexts.

Get started

Ready to connect your first site?

Two minutes to install the plugin. Your AI is up and running immediately.