{"id":301757,"date":"2026-07-07T07:11:11","date_gmt":"2026-07-07T07:11:11","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/sproutos\/"},"modified":"2026-08-27T05:15:31","modified_gmt":"2026-08-27T05:15:31","slug":"sproutos","status":"publish","type":"plugin","link":"https:\/\/es-ar.wordpress.org\/plugins\/sproutos\/","author":15954481,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.4.0","stable_tag":"1.4.0","tested":"7.1","requires":"6.9","requires_php":"8.0","requires_plugins":null,"header_name":"SproutOS \u2013 Create Creative Sites with AI","header_author":"Posimyth","header_description":"AI-powered WordPress workflow tools with admin controls, analytics, notifications, and safer advanced site management.","assets_banners_color":"2e195b","last_updated":"2026-08-27 05:15:31","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/sproutos.ai","header_author_uri":"https:\/\/posimyth.com","rating":0,"author_block_rating":0,"active_installs":10,"downloads":1019,"num_ratings":0,"support_threads":3,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.0.10":{"tag":"0.0.10","author":"sandip111","date":"2026-07-08 10:35:36","revision":3600146},"0.0.11":{"tag":"0.0.11","author":"sandip111","date":"2026-07-08 16:12:16","revision":3600549},"0.0.8":{"tag":"0.0.8","author":"posimyththemes","date":"2026-07-07 07:10:39","revision":3598577},"0.0.9":{"tag":"0.0.9","author":"sandip111","date":"2026-07-08 01:49:46","revision":3599682},"1.1.0":{"tag":"1.1.0","author":"sandip111","date":"2026-07-10 11:12:47","revision":3602658},"1.1.1":{"tag":"1.1.1","author":"sandip111","date":"2026-07-13 10:48:06","revision":3605886},"1.1.2":{"tag":"1.1.2","author":"sandip111","date":"2026-07-13 11:17:06","revision":3605927},"1.1.3":{"tag":"1.1.3","author":"sandip111","date":"2026-07-17 12:17:11","revision":3611454},"1.1.5":{"tag":"1.1.5","author":"sandip111","date":"2026-07-22 18:14:17","revision":3619058},"1.2.0":{"tag":"1.2.0","author":"sandip111","date":"2026-07-26 08:02:37","revision":3623090},"1.3.0":{"tag":"1.3.0","author":"sandip111","date":"2026-08-01 11:57:50","revision":3630914},"1.4.0":{"tag":"1.4.0","author":"sandip111","date":"2026-08-27 05:15:31","revision":3668100}},"upgrade_notice":{"1.4.0":"<p>The bundled MCP Adapter and its vendored libraries are removed; this build ships the self-contained REST control API only. There is no MCP endpoint in this version \u2014 point clients at \/wp-json\/sprout-os\/v1\/.<\/p>","1.3.0":"<p>SproutOS now focuses on Create Mode, with a lighter, simplified plugin.<\/p>","1.2.0":"<p>Major revamp: the abilities-based engine is replaced by a self-contained REST API setup. Memory, the sandbox environment, and bundled page-builder integrations are removed.<\/p>","1.1.1":"<p>UI improvements, dark mode for the dashboard, and minor bug fixes and performance improvements.<\/p>","0.0.11":"<p>Code cleanup and optimizations.<\/p>","0.0.10":"<p>Dashboard rebuilt in React (same design), inline application-password management, and an admin-bar indicator toggle.<\/p>","0.0.9":"<p>Dashboard design and layout improvement.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3598577,"resolution":"128x128","location":"assets","locale":"","width":257,"height":257},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3598577,"resolution":"256x256","location":"assets","locale":"","width":129,"height":129}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3605746,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3605746,"resolution":"772x250","location":"assets","locale":"","width":1544,"height":500}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.0.10","0.0.11","0.0.8","0.0.9","1.1.0","1.1.1","1.1.2","1.1.3","1.1.5","1.2.0","1.3.0","1.4.0"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"SproutOS dashboard: a WordPress control API plus Create Mode import.","2":"Connect: open WordPress's Application Passwords settings and copy the API base URL for your client.","3":"Activity: the request log view, with risk levels, alerts, and retention controls.","4":"Settings: notifications, webhooks, and GDPR privacy controls.","5":"Create Mode: build sites the agency way, Scope to Sitemap to Design to Export."}},"plugin_section":[],"plugin_tags":[2353,232494,1556,569,23853],"plugin_category":[],"plugin_contributors":[153210,191589,264640],"plugin_business_model":[],"class_list":["post-301757","plugin","type-plugin","status-publish","hentry","plugin_tags-ai","plugin_tags-ai-agent","plugin_tags-api","plugin_tags-automation","plugin_tags-rest-api","plugin_contributors-posimyththemes","plugin_contributors-sagarpatel124","plugin_contributors-sandip111","plugin_committers-posimyththemes","plugin_committers-sandip111","plugin_support_reps-divyangposimyth","plugin_support_reps-mohitahuja"],"banners":{"banner":"https:\/\/ps.w.org\/sproutos\/assets\/banner-772x250.png?rev=3605746","banner_2x":"https:\/\/ps.w.org\/sproutos\/assets\/banner-1544x500.png?rev=3605746","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/sproutos\/assets\/icon-128x128.png?rev=3598577","icon_2x":"https:\/\/ps.w.org\/sproutos\/assets\/icon-256x256.png?rev=3598577","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>SproutOS exposes your WordPress site to authenticated tools through a clean, versioned REST control API, with your guardrails in place.<\/p>\n\n<p>Connect a tool or your own backend using a standard WordPress Application Password, and it can inspect and manage the site programmatically: safely, and administrator-only.<\/p>\n\n<h4>A Self-Contained WordPress Control API<\/h4>\n\n<p>Most AI writes WordPress code in a vacuum. SproutOS gives AI direct, structured access to your live WordPress install through a purpose-built REST API at \/wp-json\/sprout-os\/v1\/.<\/p>\n\n<p>It is fully self-contained: no MCP Adapter and no WordPress Abilities API dependency. Every endpoint is written from scratch, administrator-gated, and covered by a safety layer. The API areas in this build are:<\/p>\n\n<ul>\n<li>Site: info, aggregated snapshot, server-readiness check, resolved wp-config flags (never secrets), and a live capability manifest<\/li>\n<li>Inspection: users, database summary, plugin settings, pending updates, installed themes, active-theme docs and templates, and a page-builder probe<\/li>\n<li>Media: list and upload (URL sideload or base64), with executable-upload blocking<\/li>\n<li>Content: post meta for any post or post type. Read, write and delete, with a sensitive-key blocklist<\/li>\n<li>Settings: read the plugin's settings, and update a whitelisted set of its own toggles<\/li>\n<li>Create Mode import: the endpoints the dashboard's import flow drives \u2014 fetch a design you built at sproutos.ai, install the plugins and theme it needs, import the pages, and apply the matching settings<\/li>\n<\/ul>\n\n<p>Call GET \/manifest at any time for a live, self-describing list of every REST endpoint your install exposes. The list is read straight from WordPress's own route registry, so it can never drift from what is actually registered.<\/p>\n\n<p>The control API itself is deliberately read-first: of its endpoints, only three accept writes \u2014 media upload, post-meta write\/delete, and the plugin's own settings. The Create Mode import endpoints are the exception. They exist to do one job, build out a site you designed at sproutos.ai, and to do it they install plugins and themes and write pages. Like every other route they run only for a logged-in administrator, but treat them as the powerful part of the surface.<\/p>\n\n<h4>Built For Control And Safety<\/h4>\n\n<p>Giving AI access to a live site should never be a leap of faith. SproutOS ships the guardrails first:<\/p>\n\n<ul>\n<li>Administrator-only access: every route checks manage_options, and unauthenticated calls are rejected with 401<\/li>\n<li>Authentication with WordPress Application Passwords over HTTPS<\/li>\n<li>Read-first control API: outside the Create Mode import flow, only three endpoints accept writes<\/li>\n<li>Secret redaction: settings and wp-config responses never leak values whose keys look like secrets, tokens, keys, salts or passwords<\/li>\n<li>Sensitive-key blocklist on post meta: credentials stored in custom fields can neither be read nor written through the API<\/li>\n<li>Executable-upload block: media uploads reject .php and similar executable types<\/li>\n<li>Privacy and GDPR controls: IP anonymization, configurable data retention, CSV export, and a live summary of exactly what is collected<\/li>\n<\/ul>\n\n<p>Our advice: start on a staging site, and move to production once you are happy with the flow. SproutOS is built to be used on live and client sites too.<\/p>\n\n<h4>Set Up In Three Steps<\/h4>\n\n<ol>\n<li>Install and activate SproutOS.<\/li>\n<li>Open SproutOS in the admin, use the button to open WordPress's Application Passwords settings, and create a password there.<\/li>\n<li>Copy the API base URL and point your authenticated tool or backend at the API.<\/li>\n<\/ol>\n\n<h4>Create Sites With AI (Create Mode)<\/h4>\n\n<p>SproutOS also builds new WordPress sites from a prompt, the agency way. In Create Mode at https:\/\/sproutos.ai you turn a client brief into a Scope, a Sitemap, and an on-brand Design, then export production-ready WordPress to Elementor, Gutenberg, or Figma. Use this plugin to import those sites into WordPress.<\/p>\n\n<h4>Who It Is For<\/h4>\n\n<p>WordPress agencies, freelancers, and developers who want authenticated tools to inspect and update selected parts of their sites safely.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>The control API runs on your own site using a WordPress Application Password over HTTPS. Create Mode connects to the SproutOS service at https:\/\/sproutos.ai; site details and the content you choose to act on are sent there to perform the requested work. Terms: https:\/\/sproutos.ai\/privacy-policy?tab=terms . Privacy: https:\/\/sproutos.ai\/privacy-policy?tab=privacy .<\/p>\n\n<h3>Development<\/h3>\n\n<p>SproutOS is open source (GPLv2 or later) and nothing in it is obfuscated. The complete, human-readable source for the compiled dashboards is maintained publicly at https:\/\/github.com\/posimyth\/sproutos\/tree\/sproutos-source<\/p>\n\n<p>For the full compiled-file-to-source map and build steps, see the <code>Source-Readme.txt<\/code> file in the plugin root.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install SproutOS from Plugins &gt; Add New, or upload the plugin to \/wp-content\/plugins\/sproutos.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Open SproutOS in your WordPress admin, use the button to open WordPress's Application Passwords settings, and create a password there.<\/li>\n<li>Point your authenticated tool or backend at \/wp-json\/sprout-os\/v1\/ using the Application Password over HTTPS.<\/li>\n<\/ol>\n\n<p>Requirements: WordPress 6.9+ and PHP 8.0+.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20does%20this%20plugin%20do%3F\"><h3>What does this plugin do?<\/h3><\/dt>\n<dd><p>It turns your WordPress site into a controllable REST API. An authenticated tool or backend uses a WordPress Application Password and can then inspect the site, upload media, and manage post meta programmatically, administrator-only, with a safety layer around every write.<\/p><\/dd>\n<dt id=\"can%20a%20client%20connect%20directly%20over%20mcp%3F\"><h3>Can a client connect directly over MCP?<\/h3><\/dt>\n<dd><p>Not with this build. SproutOS ships the REST control API only; there is no MCP (JSON-RPC) endpoint in this version. Any tool that can send an authenticated HTTP request works today.<\/p><\/dd>\n<dt id=\"which%20tools%20work%20with%20sproutos%3F\"><h3>Which tools work with SproutOS?<\/h3><\/dt>\n<dd><p>Any tool or backend that can send an authenticated HTTP request.<\/p><\/dd>\n<dt id=\"how%20do%20i%20connect%20it%3F\"><h3>How do I connect it?<\/h3><\/dt>\n<dd><p>Create a WordPress Application Password in Users &gt; Profile. The SproutOS admin page includes a button that takes you directly to WordPress's Application Passwords section. Use that password over HTTPS against \/wp-json\/sprout-os\/v1\/. Call GET \/manifest for the live list of every endpoint the install exposes.<\/p><\/dd>\n<dt id=\"is%20it%20safe%20to%20use%20on%20a%20live%20wordpress%20site%3F\"><h3>Is it safe to use on a live WordPress site?<\/h3><\/dt>\n<dd><p>It is built for it. Every route \u2014 control API and Create Mode alike \u2014 is administrator-only. The control API is read-first, with just three write endpoints; settings and wp-config responses redact anything that looks like a secret, post meta holding credentials is blocklisted, and executable uploads are blocked. The import endpoints that install plugins and write pages run from the dashboard, on your click. We still recommend you start on staging until you trust the flow.<\/p><\/dd>\n<dt id=\"can%20i%20connect%20multiple%20wordpress%20sites%3F\"><h3>Can I connect multiple WordPress sites?<\/h3><\/dt>\n<dd><p>This plugin connects one site.<\/p><\/dd>\n<dt id=\"how%20do%20i%20use%20create%20mode%3F\"><h3>How do I use Create Mode?<\/h3><\/dt>\n<dd><p>Sign in at https:\/\/sproutos.ai, turn a client brief into a Scope, Sitemap, and Design, and export production-ready WordPress to Elementor, Gutenberg, or Figma. Use this plugin to import those sites into WordPress.<\/p><\/dd>\n<dt id=\"do%20i%20need%20to%20know%20how%20to%20code%3F\"><h3>Do I need to know how to code?<\/h3><\/dt>\n<dd><p>No. Basic setup only requires creating a WordPress Application Password and using the REST API details shown in SproutOS. Coding knowledge helps for advanced API use, but it is not required.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20uninstall%20the%20plugin%3F\"><h3>What happens if I uninstall the plugin?<\/h3><\/dt>\n<dd><p>The API is removed and authenticated tools can no longer reach the site through SproutOS. Your WordPress content is untouched.<\/p><\/dd>\n<dt id=\"does%20it%20slow%20down%20my%20site%3F\"><h3>Does it slow down my site?<\/h3><\/dt>\n<dd><p>No. Endpoints run only when an authenticated tool or backend calls them. There is no load on your visitors.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>New : API-based MCP architecture.<\/li>\n<li>Fix : Minor bug fixes and performance improvements.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Improvement : SproutOS now focuses on Create Mode. Design your WordPress site with AI at <a href=\"http:\/\/sproutos.ai\/\">sproutos.ai<\/a> and import it into WordPress as Elementor or Gutenberg pages.<\/li>\n<li>Improvement : Simplified and cleaned up the plugin for a lighter, faster setup.<\/li>\n<li>Fix : Minor bug fixes and performance improvements.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>New : API-based WordPress control architecture.<\/li>\n<li>Update : Major platform revamp from the abilities-based engine to a self-contained REST API setup.<\/li>\n<li>Removed : Memory functionality.<\/li>\n<li>Removed : Sandbox environment.<\/li>\n<li>Removed : Integrations for Elementor, Bricks, ACF, Pods, Divi, Breakdance, Beaver Builder, Oxygen, ASE, and other page builder features.<\/li>\n<li>Improvement : Simplified and cleaned up the core architecture.<\/li>\n<li>Fix : Minor bug fixes and performance improvements.<\/li>\n<\/ul>\n\n<h4>1.1.5<\/h4>\n\n<ul>\n<li>Fix : Minor bug fixes and performance improvements.<\/li>\n<\/ul>\n\n<h4>1.1.3<\/h4>\n\n<ul>\n<li>Fix : Minor bug fixes and performance improvements.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Improvement : UI improvements across the dashboard.<\/li>\n<li>New : Dark mode option for the dashboard.<\/li>\n<li>Fix : Minor bug fixes and performance improvements.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>New : Create Mode Included<\/li>\n<li>Improvement : Code cleanup and optimizations and removed unused code<\/li>\n<\/ul>\n\n<h4>0.0.11<\/h4>\n\n<ul>\n<li>Improvement : Code cleanup and optimizations - removed unused server-rendered code and dead assets.<\/li>\n<\/ul>\n\n<h4>0.0.10<\/h4>\n\n<ul>\n<li>Improvement : Rebuilt the admin dashboard as a React app (same design, no feature changes).<\/li>\n<li>New : Setting to show or hide the \"AI ACTIVE\" indicator in the WordPress admin bar.<\/li>\n<\/ul>\n\n<h4>0.0.9<\/h4>\n\n<ul>\n<li>Improvement : Dashboard design and layout improvement.<\/li>\n<\/ul>\n\n<h4>0.0.8<\/h4>\n\n<ul>\n<li>Update : Removed theme file read and list abilities.<\/li>\n<li>Improvement : Reduced the filesystem surface further.<\/li>\n<\/ul>","raw_excerpt":"WordPress REST control API for authenticated tools. Inspect the site, upload media, and manage post meta over REST, admin-only.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/301757","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=301757"}],"author":[{"embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/posimyththemes"}],"wp:attachment":[{"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=301757"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=301757"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=301757"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=301757"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=301757"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=301757"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}