Inspect
Read the site context and the value you plan to change. Choose a supported action for that site and transport.
Supported edits separate inspection, preview and execution. Keep the target clear and check the result after applying the change.
Self-hosted · MIT licensed · Bring your own AI client
In guarded mode, the core value-edit tools require an approved packet. Where supported, the change digest binds the target, payload and prior state.
Read the site context and the value you plan to change. Choose a supported action for that site and transport.
See the previous and proposed value. Review the exact target and any applicable correction checks.
Approve the change packet, then apply the matching request. Pass the preview’s state check to catch edits made in the meantime.
Read the stored result back, then capture desktop and mobile screenshots with checks for expected text, overflow, headings, and broken images.
An authorized edit can still remove something you meant to preserve. Active correction rules add checks for supported sites and fields.
Turn a specific requirement into a check for a named site and field. Supported edits are checked against active rules before they write.
A rule for one page stays on that page. A client preference does not become a rule for every site you manage.
Choose the tool and verification needed for the job.
Supported option, metadata and content edits save prior values. Do not assume an arbitrary operation, plugin update or raw PHP call can be undone automatically.
Local packet approval does not require a different human by default. Restrict tool credentials and access according to your team’s needs.
WPGuard captures desktop and mobile screenshots and checks measurable failures such as missing text, overflow, headings, and broken images. Use focused interaction or accessibility tests when the task requires them.
Administrative tools and bypass configuration require care. Read the full limitations →
Treat every token as a credential for a trusted operator. None is safe to hand to an untrusted caller.
Reads options, metadata, files and private history, including secrets other plugins store in the database. It also includes magic login, which creates a WordPress login link.
Adds content and file writes, SQL, snippets and sandboxed PHP. The PHP wrapper catches errors. It does not limit what PHP can do.
Adds raw PHP, WP-CLI execution and correction rules. Code runs with the permissions of the account you configured for that site.
Anyone with the site's Application Password or legacy key can call the plugin directly. Those calls skip token scopes, packet approval, correction checks and the snapshot ledger. Restrict network access to that route.
Much of the protection comes from how you run the server.
The server defaults to 127.0.0.1. Do not expose the port publicly. Reach it locally, or through a tunnel, tailnet or TLS proxy you control.
WPGUARD_BYPASS_GUARD=1 skips packet approval. It is meant for development. Correction checks still run, but keep it off for real sites.
Tokens are static shared secrets. Rotate them on a schedule and after any suspected leak. Treat Application Passwords, plugin keys and SSH keys as credentials to the site.
It holds snapshots, imported history, correction examples and registry details. Captured values can include passwords. Restrict access and protect its backups.
If you turn on the cloud report or notify webhooks, packet metadata such as site, target, summary and status leaves the machine. Snapshot content does not. Point hooks only at endpoints you trust.
Scopes are tool-level, not per-client. To isolate clients, run separate instances with separate registries, state and credentials.
These are not solved. Plan for them.
Read tools return live content that an attacker could have written. WPGuard wraps it as untrusted and flags instruction-like text. Your AI client still has to treat it as data.
expected_etag catches many changes made after a preview. It is opt-in, and it is not a database transaction across every editor and tool.
Approver names are attestations. If you need a second person to approve, enforce that in your own workflow.
Do not open a public issue. Use GitHub Security Advisories on the repository. Include steps to reproduce, the affected version and the impact. Read SECURITY.md →
Connect one site. Inspect it. Preview one useful change.