Open for Agents is the WordPress control layer for the machine-readable web. In plain language, it lets site owners review and control what AI agents can discover and use.
The plugin starts from a conservative position. Nothing is publicly published until an administrator enables it. Write actions remain off until they are individually reviewed and enabled, and execution remains unavailable unless a trusted approval verifier attests the visitor's exact approval.
What it provides
- A guided Setup, Review, and Publish & verify workflow in wp-admin, with advanced public URLs and diagnostics kept separate.
- Read-only standard tools for public WordPress content, navigation, search, and WooCommerce discovery.
- Scanning for WordPress core, Contact Form 7, WPForms Lite, WooCommerce, and selected custom REST or AJAX surfaces.
- Public discovery through well-known resources,
llms.txt, API Catalog, MCP Server Card, Agent Skills, and optional Agentic Resource Discovery output.
- An optional browser WebMCP runtime for reviewed same-origin page actions.
- A read-only MCP Streamable HTTP endpoint.
- Disabled-by-default transactional tools with explicit administrator opt-in, trusted visitor-approval attestation, replay protection, budgets, and audit history.
- AI crawler and Content Signal controls for WordPress-generated
robots.txt.
- JSON export, validation, readiness scoring, diagnostics, and scan history.
All capabilities included in this plugin are available without a paid upgrade or license key.
Safety model
Open for Agents does not turn every detected form or endpoint into a public tool. Administrators review proposed actions before publishing. Public exports exclude private, sensitive, dangerous, or unapproved actions. Transactional tools use separate controls and do not include checkout, payment, order placement, or account changes.
Optional integrations
Deep scan can accept rendered page reports from a compatible integration through the documented
open_for_agents_deep_scan_report WordPress filter. If no renderer is configured, the plugin falls back to its normal static scan and records a warning. Open for Agents does not send scan data to an Enoki Limited service.
The separately distributed Open for Agents Assistant is optional and is not included in this
WordPress.org package. It is packaged only for approved deployments, not general public download. Core works without it; the hosted gateway remains limited to the official demo and approved deployments.
Form integration status
- WooCommerce 10.5.1 and 10.9.4: tested discovery and coarse product availability, session-bound read-only cart inspection, certified visitor-approved reversible cart tools, and declared HPOS compatibility.
- Contact Form 7 6.1.5 and 6.1.6: tested detection, reviewed publication, and certified per-form execution for supported single-page text, email, URL, telephone, textarea, choice, and checkbox fields.
- WPForms Lite 1.9.9.2 and 1.10.2.1: tested detection, reviewed publication, and certified per-form execution for supported single-page text, textarea, email, URL, phone, number, choice, checkbox, name, and address fields.
For every executable provider, captcha, acceptance/consent, payment, upload, account, signature, calculation, and multi-page workflows remain blocked. Generic REST and AJAX mining is lower-confidence discovery for administrator review, not native provider support.
Detection never means automatic publication or execution. Administrators still review discovered actions, and every eligible form submission requires framework enablement, exact per-form opt-in, and a separately registered trusted approval verifier.
- Install and activate Open for Agents from the WordPress Plugins screen.
- Open Open for Agents > Setup in wp-admin.
- Enable Standard Tools for the built-in read-only starting set.
- Run a scan if you want to discover site-specific workflows.
- Review the proposed actions and adjust their visibility and execution policies.
- Review the Safe Public selection, then choose Publish Safe Public and verify. This one action runs the required checks, publishes the reviewed tools, and verifies their public delivery path.
Upgrading preserves existing settings, reviewed actions, scan history, and publication state.