Local state
Site registry, saved values, packets and imported corrections live in the configured state directory. Protect that directory and its backups.
Core connects to WordPress from your own installation. Cloud is optional and uses a separate pairing and reporting connection.
Self-hosted · MIT licensed · Bring your own AI client
Import records you are authorized to use into your own state directory. A private requirement can improve your installation without becoming public product content.
Site registry, saved values, packets and imported corrections live in the configured state directory. Protect that directory and its backups.
Attach requirements to the correct site and field. Review a rule’s scope before activating it for future supported changes.
Inspect configured webhook and Cloud reporting payloads before enabling them. Targets, summaries and metadata can still contain sensitive information.
Information returned by a tool is available to the connected AI client. Choose client settings and access appropriate for your sites.
The server, the WordPress transport, and an optional Cloud pairing use separate credentials. Treat each one according to the access it grants.
Configure recon, mutate, or admin tokens in the server environment. The server fails closed when no token exists. Put the token in your AI client environment and send it through the Authorization header; do not commit it with client configuration.
SSH sites use the key or agent available to the WPGuard process. Mount keys read-only and limit the remote account to the registered WordPress path. WPGuard does not turn an unrestricted shell account into a restricted one.
Each companion site refers to an environment variable containing that site's shared key. Use a different key for each site, serve the plugin only over HTTPS, and rotate a key if it enters logs, screenshots, or chat.
Packets, prior-value snapshots, the site registry, and correction records survive in the configured state directory. Back it up as sensitive operational data. The open-source container declares /state as its persistent volume.
Connect a WPGuard instance to share packet records and approval decisions with your team. Contact us to activate Cloud.
The local server performs WordPress operations. Cloud pairing uses its own instance credential.
Enterprise plans are tailored around identity, deployment, retention, and support requirements.
Connect one site. Inspect it. Preview one useful change.