| 开发者 | wpagentmanager |
|---|---|
| 更新时间 | 2026年9月24日 19:26 |
| PHP版本: | 8.0 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
rulefence folder to /wp-content/plugins/.docs/SETUP.md.
WordPress 7.1 or later is required, because governance relies on the native Abilities execution lifecycle that 7.1 introduced.
After setup
A new agent starts paused and is allowed nothing. That is deliberate: every ability is blocked until you grant it in Abilities > Permissions. Grant a read ability first, watch it in Activity, and only then grant a write.Open the Ability Explorer after activating. It lists every Ability your installed plugins register, grouped by the plugin that registered it, with what each one does, how risky it is, and whether it is publicly exposed. You do not have to grant anything, connect anything, or configure anything to read it - and reading it is the point of installing this before you need it.
Use a dedicated least-privilege WordPress user for each security boundary you need to isolate. An agent is a separate RuleFence identity, but its Application Password still inherits the mapped WordPress user's native REST capabilities. Do not map an untrusted client to an administrator.
No, that is the default. Governance fails closed: an ability nobody granted is refused. Grant the specific ability in Abilities > Permissions.
Once, when the connection is created. It cannot be retrieved afterwards. If it is lost, revoke that connection and issue another.
Yes, and the list is telling you something real. WordPress 7.1 registers three Abilities of its own, all read-only: core/get-site-info and core/get-environment-info need an administrator, and core/get-user-info needs only a logged-in user. Everything beyond that comes from plugins, so a short list means the plugins on that site have not registered any - and there is correspondingly little for an agent to do there. Install WooCommerce and the list grows immediately, including writes with previews and captured before-states behind them. There is a wrinkle in the meantime. An Editor mapped to an agent can reach only one of the three, while still being free to write posts through the ordinary REST API, which the permission matrix does not cover. On a stock site the safest mapping and the useful one are not yet the same thing. That is WordPress's design rather than this plugin's, it improves as plugins register Abilities with sensible capabilities, and it is the reason the Readiness screen scores your mapping instead of assuming it.
It controls every Ability an agent invokes, which is what an AI client uses to work with your site. It does not sit in front of the ordinary WordPress REST API: a credential is a WordPress user, and that user's own capabilities decide what it can reach there. So map agents to a least-privilege user and keep it that way - the Readiness screen scores this, and the connection screen warns you if you point one at an administrator. The Activity trail records every Ability decision, and outside the Abilities API it records what a managed credential changed or was refused - so a change made through an ordinary REST route still appears, attributed to the agent that made it. Successful reads there are not kept one by one, because the trail is capped and a read-heavy client would crowd out the decisions.
Yes, and that is what the audit trail is for rather than a side effect of it. Every decision is stored with its reason in a hash-chained record, so the trail can demonstrate it has not been altered after the fact - by anyone, including this plugin. If you have to answer "what did the AI change, when, and who allowed it", the answer is on one screen and it is evidence rather than a log file.
Revoke its connection in Agents > Connections, or stop everything at once with Settings > Emergency mode. The record of what it already did stays intact and signed.
No. Agents, permissions, decisions and the audit trail are stored in your own database, and this plugin makes no outbound request of any kind - there is no webhook code in it to configure.
As many agents as you want, and everything on the governance side, are here: default-deny permissions, approvals, the signed audit trail, risk assessment, emergency mode, the readiness checks and runtime verification. The add-on sells automation and convenience - workflows, policies, undo, scheduling, export. No security control is ever sold; a control you have to buy is not a control. You do not need the add-on to use this plugin, and nothing here stops working without it.
No. It governs agents that connect to your site; it is not one, and it does not talk to any model. The AI client is whatever you connect - Claude, ChatGPT, a script of your own.
This plugin captures the before-state, so the evidence of what changed is kept whether or not you ever undo it. Performing the undo is in the paid add-on. Not everything is reversible either way, and the plugin does not claim otherwise - the Ability Explorer tells you which Abilities are covered before you grant one, so you know what a grant is worth before you make it.