Description
Acadium AI Site Editor (formerly Acadium Agent Publisher) lets an AI assistant such as Claude write, edit and publish content on your site through the WordPress Abilities API and the Model Context Protocol (MCP). The official MCP Adapter library is built in, so there is nothing else to install.
Your staff connect Claude with their own WordPress accounts. What Claude creates is credited to the person who connected it, and Claude can do only what that person’s WordPress role allows:
- Posts and pages: create, edit, publish, schedule, unpublish, move to the Trash and restore earlier versions. Editing someone else’s content keeps its original author.
- Exact edits: change a headline, sentence or link without resending the whole page, so the rest of the page stays untouched.
- Synced patterns: edit shared blocks such as a site header, footer or banner (Editors and Administrators).
- Navigation menus: add, rename, move and remove menu links, with one-step undo (Administrators).
- Categories and tags: create, rename, merge and delete (Editors and Administrators).
- Images: upload, use as featured images, and edit alt text, captions and titles.
- Redirects: add and remove redirects, for example when a page’s address changes (Administrators). Uses the Redirection plugin when it is active.
Claude can never permanently delete posts, pages or images, or change site settings, users, plugins or themes.
Under Settings > AI Site Editor you decide how far Claude may go on the whole site:
- Drafts only: Claude creates and edits drafts, and a person publishes them.
- Submit for review: Claude can also move drafts to “Pending review” for an editor.
- Publish: Claude can also publish or schedule posts, after the checks you set, and unpublish them again.
- Publish and edit live posts (default): Claude can also change live content, menus, categories and redirects.
Each person’s role still applies in every mode: a Contributor’s Claude can only write drafts and submit them for review.
Optional checks before Claude publishes: a featured image with alt text and a minimum width, allowed categories, and a daily limit. Every action Claude takes is listed under Recent activity on the settings page.
Connect Claude in a few clicks
Copy the connection URL from Settings > AI Site Editor and share it with your staff. Each person adds it in Claude (Claude Desktop, claude.ai or the Claude mobile apps) as a custom connector, logs in with their own WordPress account and clicks Allow. No Application Password and no software on their computer.
Connection checks on the same page test HTTPS, permalinks, the connection URL, the Authorization header and connector sign-in, and explain how to fix what fails. Sites that can’t use the connector (for example, WordPress in a subfolder) can use the Claude Desktop extension with an Application Password instead.
Safety
- Your role, nothing more. A connection can only do what the person’s own role allows for content, and never touches settings, users, plugins or themes.
- Nothing is lost silently. WordPress keeps revisions of posts, pages and patterns; menus are snapshotted before every change; a change that would strip markup the person’s role can’t save is refused instead.
- Page builders are respected. Claude is told when a page builder (Beaver Builder, Elementor, Divi, WPBakery) draws a page, and content edits that wouldn’t show are refused.
- Uploads are checked. The real file type must be JPEG, PNG, GIF or WebP, the size is limited, and URL uploads only fetch from public https addresses.
- Secure sign-in. OAuth 2.1 with PKCE; access tokens expire after an hour, refresh tokens are single-use and stored only as hashes, and tokens work only for the MCP and Abilities API routes. Administrators can disconnect any connection.
Publishing can trigger things that unpublishing cannot undo, such as subscriber emails or social media posts from other plugins. Choose a stricter mode if content should be reviewed before it goes live.
Abilities
Content:
agent-publisher/get-capabilities(read-only): what the site and the person’s role allowagent-publisher/find-posts,get-post(read-only): posts, pages and synced patternsagent-publisher/create-post,update-draft-post,update-published-postagent-publisher/submit-for-review,publish-post(now or scheduled),unpublish-postagent-publisher/trash-post,restore-revision
Site:
agent-publisher/list-menus,create-menu,update-menu,restore-menuagent-publisher/list-terms,create-term,update-term,delete-termagent-publisher/list-redirects,create-redirect,delete-redirect
Images:
agent-publisher/upload-media,find-media,update-mediaagent-publisher/request-upload,get-upload: a one-time link where the user uploads their own image
They are available through the core Abilities REST API (/wp-json/wp-abilities/v1/; read-only abilities use GET, the others POST) and, as one MCP tool each, at /wp-json/acadium-agent-publisher/mcp. Ability and endpoint names are unchanged from Acadium Agent Publisher, so existing connections keep working.
For developers
Filters:
agent_publisher_post_types: post types the content abilities work on (default:post,page,wp_block).agent_publisher_can_connect: who may connect Claude (default: anyone who can write posts).agent_publisher_post_meta: custom field keys agents may read and write (default: none).agent_publisher_upload_mimes: accepted image types (default: JPEG, PNG, GIF, WebP).agent_publisher_max_upload: maximum upload size in bytes (default: 10 MB).
Development happens on GitHub: https://github.com/Acadium/acadium-agent-publisher
Installation
- Install and activate Acadium AI Site Editor. If the site uses “Plain” permalinks, click the one-click “Post name” button the plugin shows.
- Under Settings > AI Site Editor, copy the connection URL and share it with your staff.
- Each person adds the site in Claude: Settings > Connectors > Add custom connector, paste the connection URL, click Connect, log in with their own WordPress account and click Allow.
- Optionally, choose what Claude may do under Settings > AI Site Editor (default: Publish and edit live posts) and set image guidance.
Your site must use HTTPS.
FAQ
-
What happened to Acadium Agent Publisher?
-
This is the same plugin with a new name. Version 2.0 adds pages, synced patterns, menus, categories and tags, image details and redirects. Your settings, connections and tool names are unchanged.
-
What can Claude change?
-
What the connected person’s WordPress role allows for content: Administrators can have Claude edit everything this plugin covers, Editors everything except menus and redirects, Authors their own posts and images, Contributors their own drafts. Claude can’t change settings, users, plugins or themes, or permanently delete posts, pages or images.
-
How do I undo a change?
-
Ask Claude. Posts, pages and synced patterns can be restored from their revisions, menus from the snapshot taken before each change, and trashed content from the Trash for 30 days.
-
Can Claude bypass these rules through the REST API?
-
No. The connection’s access tokens work only on this plugin’s MCP and Abilities routes, and its capabilities are capped to content rights.
-
Do I need the MCP Adapter plugin?
-
No. The official MCP Adapter (https://github.com/WordPress/mcp-adapter) library is built in. If the MCP Adapter plugin, or another plugin that includes it, is also active, WordPress loads the newest copy once.
-
Does this plugin connect to external services?
-
No. It does not contact any server on its own. The upload ability downloads an image only when Claude supplies an image URL, and only from public https addresses. Apps such as claude.ai call your site’s endpoints; your site does not call them.
-
Do scheduled posts need anything special?
-
They are published by WordPress’ scheduler (WP-Cron), like posts you schedule yourself. If your site disables WP-Cron, make sure a server cron job runs it.
-
How do I revoke access?
-
Disconnect it under Settings > AI Site Editor > Connected apps. Deactivating the plugin removes all abilities.
-
claude.ai cannot connect
-
Run the connection checks under Settings > AI Site Editor. Connector sign-in needs WordPress at the root of its domain, and a firewall or CDN must pass
/.well-known/and/agent-publisher-oauth/requests to WordPress and forward the Authorization header.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Acadium AI Site Editor” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Acadium AI Site Editor” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
2.0.0
- Renamed to Acadium AI Site Editor. Settings, connections, endpoints and tool names are unchanged.
- Pages: create and edit pages with parent, template and order. Editing existing content follows the connected person’s role (Editors and Administrators: everyone’s, keeping the original author; Authors: their own; Contributors: their own drafts). New find-posts tool.
- Synced patterns: find, read, edit and restore shared blocks such as headers, footers and banners.
- Exact edits: update tools take edits ([{find, replace}]) to change specific text without resending the content. A whole-content save that would strip markup the person’s role can’t save is refused instead.
- The person’s own “unfiltered HTML” right is kept, so Administrators and Editors can keep scripts, SVG and embeds.
- New tools: trash-post, restore-revision; navigation menus (list-menus, create-menu, update-menu, restore-menu); categories and tags (create-term, update-term, delete-term with merge); image details (update-media); redirects (list-redirects, create-redirect, delete-redirect, using the Redirection plugin when active).
- Page builders: Claude is told whether Beaver Builder, Elementor, Divi or WPBakery draws a page, and content edits that wouldn’t show are refused.
- Responsive image attributes (srcset, sizes, loading and similar) are kept in Claude’s content.
1.9.0
- Staff connect Claude with their own WordPress accounts: posts Claude writes are credited to and owned by the person who connected it. No AI Agent user or administrator approval needed; anyone who can write posts can connect (filter agent_publisher_can_connect to limit it). Administrators can still credit an AI Agent user instead.
- Through a connection, a person’s capabilities are capped to the AI Agent’s (own posts only, no settings, no unfiltered HTML) and never exceed their own role: a Contributor’s Claude writes drafts; publishing needs both the site mode and the person’s own publish right.
- Upload links: request-upload gives the user a one-time page (valid 30 minutes) to drop their own image into the Media Library at full size; get-upload returns it to Claude. Needs a role that can upload files.
- Claude is told to use free stock photo URLs for generic images instead of generating images and sending them as base64.
- New installs: connector sign-in (OAuth) is on and the mode is “Publish and edit live posts”. Sites with saved settings keep them.
- Settings page: “Recommended Claude settings” for the connector’s tool permissions. Activity log marks actions “(via Claude)”.
1.8.0
- Featured images under the minimum width are refused when publishing or replacing a live post’s image, by default (Settings > Agent Publisher > Images; untick to allow them with a warning).
- Built-in minimum of 1,200 px when the site sets none, and a recommended width (the largest size WordPress generates) in get-capabilities, so agents always have a target.
- Agents are told never to reduce an image’s resolution to fit it through base64, and a small image sent as base64 gets a warning pointing to the upload route (Media > Add New, then find-media).
1.7.0
- New find-media tool: Claude finds images in the Media Library by title or file name. For large images, upload them in WordPress and ask Claude to use them.
- Image guidance under Settings > Agent Publisher > Images: minimum width, the aspect ratios your theme crops featured images to, and guidance for agents. get-capabilities reports it along with accepted types, the size limit and the sizes WordPress generates. Images that don’t fit get warnings in the result; “Strict” refuses to publish with them.
- update-draft-post and update-published-post accept featured_image, so a live post’s featured image can be replaced in one step. Post results include the featured image and the sizes WordPress generated from it.
- get-post reads the agent’s own published and scheduled posts.
- Base64 uploads accept line breaks, data: prefixes, URL-safe characters and missing padding; errors show what’s wrong and where. An optional sha256 refuses corrupted uploads. upload-media returns the file’s size and sha256.
1.6.1
- Fix: connector requests failed with a server error (HTTP 500, “Couldn’t connect to the server” in Claude) on sites where another plugin checks the logged-in user early, such as Limit Login Attempts Reloaded. Introduced in 1.5.0.
1.6.0
- Claude Desktop extension (MCP Bundle) for sites that can’t use the connector: download it from Settings > Agent Publisher, create an Application Password there, and open the file. Claude Desktop installs it with its own Node.js; no Node.js install, npx path or JSON editing. The password is stored securely by Claude Desktop.
- The Application Password panel now shows the connection URL, username and password with Copy buttons, for the extension’s install dialog. The claude_desktop_config.json block is still available for manual setups.
- The extension pins the WordPress MCP bridge to a tested version instead of fetching the latest from npm at every start.
1.5.0
- New “Connect Claude” setup on the settings page: create the AI Agent user, turn on connector sign-in and copy the connection URL in a few clicks. An Application Password and a ready-made Claude Desktop configuration are available for sites that can’t use the connector.
- New connection checks: HTTPS, permalinks, whether the connection URL answers, whether the Authorization header reaches WordPress (with a one-click .htaccess fix on Apache) and whether connector sign-in can be discovered.
- Security: publishing, unpublishing and editing live posts through the abilities is now limited to AI Agent users; other users need their own WordPress capabilities (for example, Contributors can no longer publish through the abilities in Publish mode).
- Security: OAuth access tokens work only on the MCP and Abilities REST routes, checked on the route actually dispatched; never in wp-admin, admin-ajax, cron or XML-RPC.
- Security: invalid authorization requests show an error page instead of redirecting; the consent screen shows the app’s address and flags apps outside claude.ai as unverified; administrators who also hold the AI Agent role can’t be chosen as a connection’s user.
- Security: reusing a rotated refresh token revokes the connection; clients can only revoke their own tokens; token and revocation rate limits are per client (new filter agent_publisher_client_ip for sites behind a proxy).
- Image downloads stop at the size limit instead of fetching the whole file first.
- MCP errors are written to the PHP error log only when WP_DEBUG is on.
1.4.0
- New
create-postreplacescreate-draft-post. In one call it creates the post with categories, tags and a featured image (featured_imageuploads it), and can submit it for review or publish or schedule it when the site mode allows. An agent now needs one approval for a finished post instead of up to three. - If a pre-publish check fails,
create-postcreates nothing (including the uploaded image), so the agent can fix its input and try again. - Tool descriptions and server instructions no longer tell agents to ask again in chat for something the user already requested.
1.3.1
- Fix: when no custom fields are enabled, the create, update and update-published tools no longer send an invalid schema. MCP clients such as Claude Desktop skipped those tools, so agents could not create posts.
1.3.0
- The MCP Adapter is now built in; the separate MCP Adapter plugin is no longer needed.
- New MCP endpoint
/wp-json/acadium-agent-publisher/mcplists each ability as its own tool. The MCP Adapter default endpoint keeps working, including with OAuth. - A notice with a one-click fix when the site uses “Plain” permalinks, which AI clients cannot connect through.
- Setup status on the settings page now shows permalinks and the connection URL.
1.2.0
- OAuth 2.1 for MCP clients, so claude.ai (web, desktop and mobile apps) can connect as a custom connector without an Application Password. Includes discovery metadata (RFC 9728, RFC 8414), dynamic client registration (RFC 7591), authorization code with PKCE, rotating refresh tokens and revocation (RFC 7009).
- Administrator consent screen: each connection acts as a chosen AI Agent user.
- Connected apps list with Disconnect on the settings page.
- OAuth is off by default (“Allow OAuth connections”).
1.1.0
- Publishing modes under Settings > Agent Publisher: drafts only (default), submit for review, publish, publish and edit live posts.
- New abilities: get-capabilities, submit-for-review, publish-post (now or scheduled), unpublish-post, update-published-post.
- Pre-publish checks: featured image with alt text, allowed categories, daily limit.
- Recent agent activity on the settings page.
- The AI Agent role (previously “AI Agent (drafts only)”) never has publishing capabilities; publishing goes only through the plugin’s abilities.
- Write abilities now all use POST in the core Abilities REST API (update-draft-post previously required DELETE).
1.0.0
- First release: list terms, get post, create draft post, update draft post and upload media abilities, plus the AI Agent (drafts only) role.