WordPress AI Access Watch: Plugin Assistants, Credentials and Permission Changes
This watch tracks verifiable changes to WordPress plugin assistants, credentials, registered abilities, permission checks, consent and revocation behavior. The review date is 2026-08-30, and every entry separates declared, observed, reproduced, unverified or corrected evidence.
What this watch records
- Plugin, version and release date.
- Change declared by the publisher.
- Credential type, owning WordPress user and lifecycle when documented.
- New or changed route, Ability, MCP tool or permission callback.
- Consent, activation, revocation and cleanup behavior.
- Primary source and a reproducible observation when available.
Evidence status
| Status | Meaning |
|---|---|
DECLARED | The publisher or official source states the change; no independent execution is claimed. |
OBSERVED | The behavior was seen in a controlled environment, but the complete causal path is not yet reproduced. |
REPRODUCED | The behavior was repeated with recorded versions, steps, expected result and sanitized evidence. |
UNVERIFIED | A relevant claim exists, but the available evidence is insufficient or contradictory. |
CORRECTED | A later version or official correction addresses the previously recorded behavior. |
Observation method
Every entry must separate declaration from observation. Record exact artifacts, versions, environment, identity, action, expected refusal and rollback. Do not retain live credentials, personal data or customer domains in public evidence.
Frequently asked questions
Is this watch a vulnerability database?
No. It records documented access-related changes and their evidence status. A security classification requires a separate responsible verification and disclosure process.
Related guides
- Why Rank Math Shows a WAP AI Assistant Notice
- What Is WAP AI Assistant in WordPress?
- How to Audit Every AI Credential on a WordPress Site
- Checklist Before Enabling an AI Assistant Inside a WordPress Plugin
- Why a WordPress Application Password Keeps Reappearing or Rotating
Research context
Place each dated entry in the WordPress AI research lab so declarations, observations and reproductions remain distinguishable over time.
Sources and verification
This page was checked against the following primary sources. Last source review: .
- WAP Client for WordPress Plugins · group.one / One.com
- Rank Math Free Changelog · Rank Math
- Rank Math SEO Plugin · WordPress.org
- Application Passwords · WordPress Developer Resources
- Model Context Protocol: Tools · Model Context Protocol