WindCodex Ops connects Claude, ChatGPT, and other MCP-compatible AI platforms to your WordPress site through a fixed, tested list of actions – not open-ended code execution. If an action isn't on the list, the AI simply cannot do it, full stop.
This plugin covers everyday content management, entirely free: posts, pages, media, SEO, site structure, and site health.
Why Site Owners Choose WindCodex Ops
- No code execution, ever – the AI can only call the fixed list of tools this plugin ships with. There is no PHP execution, no arbitrary SQL, no shell access anywhere in the codebase.
- Safe on live, customer-facing sites – every tool is tested and scoped to a specific job (update a meta tag, insert a block, resize an image) rather than a general-purpose capability.
- Undo built in – write actions that support it keep an undo window (72 hours by default, extendable to 96 or 168 hours in Settings), so a mistaken edit is a rollback, not an incident. Undo covers posts, pages, categories, and tags. Undo history and the visible activity feed are independent settings, so you can hide the feed without losing the undo safety net.
- Works with any MCP-compatible AI platform – Claude, ChatGPT, and any other client that speaks the Model Context Protocol connects the same way, over standard OAuth.
- You control who can connect – only Administrators can connect an AI app by default, and each connection can only do what its approving user could do in the dashboard.
- No license key, no paywall – every tool group in this plugin is free and on by default.
Key Features
100+ tools across 5 groups, entirely free, no license key required, every group on by default:
- Content management – posts, pages, categories, tags, revisions, and Gutenberg content blocks (read, insert, remove, and update one in place by position).
- Media and assets – uploads, alt text, compression, format conversion, and usage lookup so the AI can tell you where an image is used before touching it.
- SEO and discoverability – meta tags, focus keyword, canonical URL, Open Graph, and readability tools that auto-detect Yoast SEO, Rank Math, All in One SEO, and SEOPress, so the same tools work correctly no matter which one is active.
- Site structure – menus, navigation blocks, classic widgets, redirects, sitemap status, and read-only permalink structure lookup.
- Site health and diagnostics – status checks, error logs, cron health, database/disk usage, and orphaned-data cleanup.
A flat 120 requests/minute rate limit applies. The undo window (72 hours by default, selectable 72, 96, or 168) applies to every write tool that supports undo: posts, pages, categories, and tags in this plugin.
Use Cases
- Let an AI assistant draft, edit, and publish blog posts and pages without giving it FTP or database access.
- Keep SEO metadata (titles, meta descriptions, Open Graph tags) consistent across every post, regardless of which SEO plugin the site runs.
- Batch-update image alt text and compress media for accessibility and page speed, from a chat interface.
- Clean up broken permalinks, stale redirects, and orphaned post meta without opening the database.
- Monitor site health – error logs, cron status, disk usage – and get a plain-language summary instead of digging through wp-admin screens.
- Insert or update a specific Gutenberg block on a page programmatically, without touching the rest of the content.
For Store Owners
The content, media, SEO, and structure tools below work on any post type, including WooCommerce products, so an AI assistant can help with all of this out of the box:
- Rewrite and standardize product page titles and meta descriptions ahead of a sale or new collection launch, without opening each product one by one.
- Compress and add missing alt text across a product image gallery in one pass – smaller images load faster on mobile, and alt text is what image search actually indexes.
- Set up a 301 redirect the moment a product is discontinued or its URL changes, so existing links and search rankings don't turn into 404s.
- Find every page and post referencing a specific image before swapping it out for a new banner or seasonal promo graphic.
- Add a limited-time menu item (e.g. a Black Friday or holiday collection link) to site navigation and remove it again afterward, without a developer touching the theme.
- Check sitemap status and crawl-facing site health before a big traffic push, so search engines can actually find the pages being promoted.
Risk Levels
Every tool group is tagged low or medium risk, shown as a badge in
Settings > WindCodex Ops > Tools – this is informational, not a gate. Every group is on by default; the risk label helps a site owner decide which groups to turn
off for their particular site.
How It Works
- Install and activate the plugin.
- Go to Settings > WindCodex Ops and review which tool groups are enabled.
- Copy the Connector URL from the Connection tab and add it to Claude, ChatGPT, or any other MCP-compatible AI platform as a custom connector.
- Authenticate once via OAuth while logged in as an Administrator – most platforms register themselves automatically from the discovery URLs on the Connection tab.
- The AI can now use any enabled tool group against your site. Revoke any connected app at any time from the Connection tab.
Requirements
- WordPress 6.0 or higher
- PHP 7.4 or higher
- An MCP-compatible AI platform (Claude, ChatGPT, or similar) to connect to
- No WindCodex account, API key, or license required to use this plugin itself – see External services below for what it connects to and why
Privacy
This plugin has no code-execution capability of any kind – that's not present anywhere in the codebase. It does not collect data for WindCodex or sell any data. All tool calls run locally against your own site's database through WordPress's normal APIs. The plugin does send data externally in two specific, limited cases – see
External services below for exactly what's sent, when, and to whom: (1) whatever a specific tool returns, sent only to the AI platform you've explicitly connected via OAuth and only when that platform calls that tool, and (2) a plugin slug (no site or user data) sent to the
WordPress.org API only when the plugin-staleness tool is used. By default, deleting the plugin leaves all data in place; opt into full cleanup via
Settings > WindCodex Ops > General > Data & Privacy.
From your WordPress dashboard
- Go to Plugins > Add New.
- Search for WindCodex Ops.
- Click Install Now, then Activate.
Manual installation
- Download the plugin ZIP file.
- Upload the
windcodex-ops folder to /wp-content/plugins/.
- Activate through the Plugins screen in WordPress.
After activation
- Go to Settings > WindCodex Ops.
- Review which tool groups are on – everything is enabled by default; turn off anything you'd rather a connected AI not touch.
- Copy the Connector URL from the Connection tab and add it to your AI platform as a custom connector.
1.1.1
- New: "Require preview before high-risk actions" now works. Actions that can't be undone – permanently deleting media, recompressing an image, deleting a category or tag, removing a menu item, navigation item or widget – first return a preview and only run when the AI calls again with confirm=true.
- New: "Email me on high-risk actions" now emails the site admin address whenever a high-risk action runs (including confirmed bulk changes), limited to 10 emails an hour.
- New: "Weekly activity summary" now emails a weekly digest of tool calls, changes and high-risk actions. Weeks with no activity are skipped.
- Tweak: clearer descriptions for these settings and for "Show activity feed".
- New: Help menu in the WindCodex Ops settings header, with quick links to the documentation, the support forum, and leaving a review.
- New: "Settings" and "Docs" links on the Plugins screen.
1.1.0
- New: "Who can connect" setting under Settings > WindCodex Ops > General – Administrators only by default, or Editors and above. Only those users can approve an AI connection on the consent screen.
- Security: a connection now stops working as soon as the user who approved it loses that role or is deleted, and every tool call requires it.
- Removed: the "Acting user" setting. Every connection runs as the person who approved it – there is no shared or fallback account.
- Removed: the custom delete confirmation on the Plugins screen (WordPress's standard one is shown instead), the relabelling of this plugin's row on the Enable Abilities for MCP settings screen, and the script that moved other plugins' notices on the WindCodex Ops settings page. Notices now appear above the settings header.
1.0.0
Initial release of WindCodex Ops as its own standalone, entirely free plugin covering content, media, SEO, site structure, and site health.
- Split the old "Log all AI activity" toggle into two independent settings: "Show activity feed" (the visible Activity tab, purely cosmetic) and "Keep undo history" (the undo safety net). Turning off the feed no longer disables undo.
- Moved the "Undo window" setting next to "Keep undo history" in Preferences so the two related controls sit together.
- Extended the undo/restore system to categories and tags (
wp_update_category, wp_delete_category, wp_update_tag, wp_delete_tag). Note: a deleted term is recreated from its saved fields rather than restored in place, since WordPress has no trash for taxonomy terms.
- The Plugins screen's delete confirmation now correctly skips itself when WindCodex Ops Pro is active, since deleting this plugin in that case never touches any data (Pro owns the shared settings and tables).