{"id":309314,"date":"2026-05-30T16:12:19","date_gmt":"2026-05-30T16:12:19","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/siteagent\/"},"modified":"2026-09-23T12:50:40","modified_gmt":"2026-09-23T12:50:40","slug":"my-site-hand","status":"publish","type":"plugin","link":"https:\/\/es-ar.wordpress.org\/plugins\/my-site-hand\/","author":23493884,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.0","stable_tag":"1.2.0","tested":"7.1.2","requires":"6.2","requires_php":"8.1","requires_plugins":null,"header_name":"My Site Hand (AI)","header_author":"BuiltByTanin","header_description":"Turn your WordPress site into an AI agent-operable command layer using the Abilities API and Model Context Protocol (MCP). Let Claude Desktop, Cursor, VS Code, and other MCP-compatible AI clients discover, read, and safely operate your WordPress site through natural language.","assets_banners_color":"4c71d4","last_updated":"2026-09-23 12:50:40","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/my-site-hand","header_author_uri":"https:\/\/github.com\/taninrahman21","rating":5,"author_block_rating":0,"active_installs":0,"downloads":522,"num_ratings":2,"support_threads":1,"support_threads_resolved":1,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"builtbytanin","date":"2026-05-30 16:11:57","revision":3554876},"1.0.1":{"tag":"1.0.1","author":"builtbytanin","date":"2026-06-09 16:01:35","revision":3566279},"1.0.2":{"tag":"1.0.2","author":"builtbytanin","date":"2026-08-24 17:52:43","revision":3664066},"1.1.0":{"tag":"1.1.0","author":"builtbytanin","date":"2026-08-26 17:39:27","revision":3667552},"1.2.0":{"tag":"1.2.0","author":"builtbytanin","date":"2026-09-23 12:50:40","revision":3709357}},"upgrade_notice":{"1.2.0":"<p>Six new checks including security and accessibility, plus PDF, CSV and shareable report links. Existing scans, tokens and MCP connections are unchanged.<\/p>","1.1.0":"<p>Adds a one-click site scan with inline fixing \u2014 no setup, no API key. Your existing MCP connection, tokens and audit history are unchanged. If screens look unstyled after updating, refresh once.<\/p>","1.0.2":"<p>Security update. Token permissions are now enforced strictly. Your existing tokens are migrated automatically and will keep working. Please review your tokens after updating to narrow their scope.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":2},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3667552,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3667552,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3667627,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3667627,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.1","1.0.2","1.1.0","1.2.0"],"block_files":[],"assets_screenshots":{"screenshot-1.jpg":{"filename":"screenshot-1.jpg","revision":3683452,"resolution":"1","location":"assets","locale":"","width":1280,"height":960},"screenshot-10.jpg":{"filename":"screenshot-10.jpg","revision":3683452,"resolution":"10","location":"assets","locale":"","width":1280,"height":960},"screenshot-2.jpg":{"filename":"screenshot-2.jpg","revision":3683452,"resolution":"2","location":"assets","locale":"","width":1280,"height":960},"screenshot-3.jpg":{"filename":"screenshot-3.jpg","revision":3683452,"resolution":"3","location":"assets","locale":"","width":1280,"height":960},"screenshot-4.jpg":{"filename":"screenshot-4.jpg","revision":3683452,"resolution":"4","location":"assets","locale":"","width":1280,"height":960},"screenshot-5.jpg":{"filename":"screenshot-5.jpg","revision":3683452,"resolution":"5","location":"assets","locale":"","width":1280,"height":960},"screenshot-6.jpg":{"filename":"screenshot-6.jpg","revision":3683452,"resolution":"6","location":"assets","locale":"","width":1280,"height":960},"screenshot-7.jpg":{"filename":"screenshot-7.jpg","revision":3683452,"resolution":"7","location":"assets","locale":"","width":1280,"height":960},"screenshot-8.jpg":{"filename":"screenshot-8.jpg","revision":3683452,"resolution":"8","location":"assets","locale":"","width":1280,"height":960},"screenshot-9.jpg":{"filename":"screenshot-9.jpg","revision":3683452,"resolution":"9","location":"assets","locale":"","width":1280,"height":960}},"screenshots":{"1":"One click, no setup at all. Broken links, missing alt text, missing meta descriptions, oversized media, orphaned files, security and accessibility problems \u2014 scored out of 100.","2":"Fix it from the report. Write alt text, replace a dead link or trash a file you no longer need. No AI and no API key.","3":"Twelve checks, run one at a time so nothing times out. Results appear as they land, and you can cancel at any point.","4":"Every scan is kept, so you can watch the score climb. The optional email arrives only when something actually changed.","5":"Send the report on. Save it as a PDF, export it as a CSV, or create a public link with an expiry you choose. Before you create one you are told exactly what the recipient will and will not see.","6":"Set the schedule once and leave it. Choose how often the site scans itself and where the report goes \u2014 or switch it off entirely.","7":"The dashboard opens with your health score, then the MCP endpoint, live figures and the most recent calls.","8":"Connecting Claude Desktop, Cursor or VS Code is the optional upgrade \u2014 the scan and inline fixing need none of it.","9":"Every ability is its own switch, and every token is scoped to exactly what you allow. Tokens are SHA-256 hashed and shown once.","10":"Every call recorded with its payload, duration and the exact reason it failed. Inline repairs are logged here too. Exportable to CSV."}},"plugin_section":[],"plugin_tags":[1953,17214,17210,31034,151481],"plugin_category":[54],"plugin_contributors":[265081],"plugin_business_model":[],"class_list":["post-309314","plugin","type-plugin","status-publish","hentry","plugin_tags-accessibility","plugin_tags-alt-text","plugin_tags-broken-link-checker","plugin_tags-seo-audit","plugin_tags-site-health","plugin_category-security-and-spam-protection","plugin_contributors-builtbytanin","plugin_committers-builtbytanin"],"banners":{"banner":"https:\/\/ps.w.org\/my-site-hand\/assets\/banner-772x250.png?rev=3667627","banner_2x":"https:\/\/ps.w.org\/my-site-hand\/assets\/banner-1544x500.png?rev=3667627","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/my-site-hand\/assets\/icon-128x128.png?rev=3667552","icon_2x":"https:\/\/ps.w.org\/my-site-hand\/assets\/icon-256x256.png?rev=3667552","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/my-site-hand\/assets\/screenshot-1.jpg?rev=3683452","caption":"One click, no setup at all. Broken links, missing alt text, missing meta descriptions, oversized media, orphaned files, security and accessibility problems \u2014 scored out of 100."},{"src":"https:\/\/ps.w.org\/my-site-hand\/assets\/screenshot-2.jpg?rev=3683452","caption":"Fix it from the report. Write alt text, replace a dead link or trash a file you no longer need. No AI and no API key."},{"src":"https:\/\/ps.w.org\/my-site-hand\/assets\/screenshot-3.jpg?rev=3683452","caption":"Twelve checks, run one at a time so nothing times out. Results appear as they land, and you can cancel at any point."},{"src":"https:\/\/ps.w.org\/my-site-hand\/assets\/screenshot-4.jpg?rev=3683452","caption":"Every scan is kept, so you can watch the score climb. The optional email arrives only when something actually changed."},{"src":"https:\/\/ps.w.org\/my-site-hand\/assets\/screenshot-5.jpg?rev=3683452","caption":"Send the report on. Save it as a PDF, export it as a CSV, or create a public link with an expiry you choose. Before you create one you are told exactly what the recipient will and will not see."},{"src":"https:\/\/ps.w.org\/my-site-hand\/assets\/screenshot-6.jpg?rev=3683452","caption":"Set the schedule once and leave it. Choose how often the site scans itself and where the report goes \u2014 or switch it off entirely."},{"src":"https:\/\/ps.w.org\/my-site-hand\/assets\/screenshot-7.jpg?rev=3683452","caption":"The dashboard opens with your health score, then the MCP endpoint, live figures and the most recent calls."},{"src":"https:\/\/ps.w.org\/my-site-hand\/assets\/screenshot-8.jpg?rev=3683452","caption":"Connecting Claude Desktop, Cursor or VS Code is the optional upgrade \u2014 the scan and inline fixing need none of it."},{"src":"https:\/\/ps.w.org\/my-site-hand\/assets\/screenshot-9.jpg?rev=3683452","caption":"Every ability is its own switch, and every token is scoped to exactly what you allow. Tokens are SHA-256 hashed and shown once."},{"src":"https:\/\/ps.w.org\/my-site-hand\/assets\/screenshot-10.jpg?rev=3683452","caption":"Every call recorded with its payload, duration and the exact reason it failed. Inline repairs are logged here too. Exportable to CSV."}],"raw_content":"<!--section=description-->\n<p><strong>Scan your WordPress site for broken links, missing image alt text, missing SEO meta descriptions and accessibility problems \u2014 and fix them without leaving the report.<\/strong><\/p>\n\n<p>Activate the plugin and it starts scanning straight away. No token, no API key, no Node.js, no terminal. About thirty seconds later you get a health score out of 100 and a list of real problems on your own site.<\/p>\n\n<h3>What it finds<\/h3>\n\n<p>Twelve checks, run one at a time so nothing times out.<\/p>\n\n<p><strong>Broken link checker<\/strong> \u2014 checks the links in your recent posts and pages and reports only the ones that are genuinely gone. Only a 404 or 410 counts. Anything ambiguous is retried a different way and left alone rather than reported as a false alarm.<\/p>\n\n<p><strong>Missing alt text<\/strong> \u2014 images your visitors using screen readers cannot see, and search engines cannot read.<\/p>\n\n<p><strong>Missing meta descriptions<\/strong> \u2014 published posts and pages with no SEO description, for Yoast SEO and RankMath.<\/p>\n\n<p><strong>Accessibility basics<\/strong> \u2014 links that announce nothing to a screen reader, \"click here\" links, more than one main heading, and headings that skip a level. Structural checks only; it does not claim to be a full WCAG audit.<\/p>\n\n<p><strong>Images missing dimensions<\/strong> \u2014 the cause of pages that jump around while they load, which Google measures as a Core Web Vital.<\/p>\n\n<p><strong>Images missing lazy loading<\/strong> \u2014 pictures further down a post that something has opted out, so visitors download them before they are ever seen.<\/p>\n\n<p><strong>Oversized media<\/strong> \u2014 files big enough to slow your pages down, with the space you would get back.<\/p>\n\n<p><strong>Orphaned files<\/strong> \u2014 uploads that nothing on your site appears to use.<\/p>\n\n<p><strong>Thin content<\/strong> \u2014 published pages with very few words. Read with judgement: a contact page is supposed to be short, and pages built from a shortcode, gallery or embed are left out.<\/p>\n\n<p><strong>Plugin and core health<\/strong> \u2014 pending updates, an unsupported PHP version, missing HTTPS, errors visible to visitors, a stalled cron.<\/p>\n\n<p><strong>Exposed WordPress files<\/strong> \u2014 readme.html, license.txt and a debug log left publicly readable. The first hands an attacker your exact version; the last can contain server paths and credentials.<\/p>\n\n<p><strong>XML-RPC<\/strong> \u2014 reported as a notice, with the tradeoff stated plainly. It is a brute-force vector, but the WordPress mobile app and Jetpack need it, so this is only worth turning off if you use neither. Sites running Jetpack are skipped entirely.<\/p>\n\n<h3>Fix it from the report<\/h3>\n\n<p>A list of complaints is not much use on its own. Write alt text straight into the report, replace a dead link, or trash a file you no longer need \u2014 one row at a time, with the score climbing as you go.<\/p>\n\n<p><strong>No AI and no API key required for any of it.<\/strong><\/p>\n\n<p>Your score is kept over time, so you can watch the site improve, and you can have a short report emailed to you when something changes.<\/p>\n\n<h3>Send the report to a client<\/h3>\n\n<p>A report is more useful when the person who needs to act on it can read it.<\/p>\n\n<ul>\n<li><strong>PDF<\/strong> \u2014 opens a clean, printable page and your browser's own print dialog. Choose \"Save as PDF\". No bloated PDF library bundled into the plugin to do a job your browser already does well.<\/li>\n<li><strong>CSV<\/strong> \u2014 every issue as a row: check, severity, issue, context, link and object ID. Opens correctly in Excel and Google Sheets, in any language.<\/li>\n<li><strong>A shareable link<\/strong> \u2014 a public web page your client can open without a login, with an expiry you choose: 7, 30 or 90 days. There is no never-expires option.<\/li>\n<\/ul>\n\n<p>Shared reports are <strong>redacted on purpose<\/strong>. They show the score, each check by name, and how many issues it found. They never show file names, page addresses, server paths, post or media IDs, edit links, or your plugin, theme, PHP and WordPress versions \u2014 and the two security checks are left out entirely, because publishing those would be publishing a vulnerability report about your own server. The page tells you exactly what a recipient will and will not see before you create the link, every link can be revoked instantly, and the report is a snapshot: re-scanning your site never changes what you already sent.<\/p>\n\n<h3>Optional: let an AI assistant do the work<\/h3>\n\n<p>Everything above works on its own. Connecting an AI assistant is an upgrade, not a requirement.<\/p>\n\n<p>Built on the open standard <strong>Model Context Protocol (MCP)<\/strong> developed by Anthropic, this plugin exposes safely-gated capabilities to clients like <strong>Claude Desktop<\/strong>, <strong>Cursor<\/strong>, <strong>VS Code<\/strong> and <strong>Windsurf<\/strong>, so they can work on your site in plain language.<\/p>\n\n<ul>\n<li><strong>Write and edit content<\/strong> \u2014 draft, edit, format or publish posts and pages.<\/li>\n<li><strong>SEO audits<\/strong> \u2014 scan Yoast or RankMath metadata, optimise it for a keyword, update titles and descriptions.<\/li>\n<li><strong>WooCommerce<\/strong> \u2014 list low-stock items, draft products, check recent orders, summarise sales.<\/li>\n<li><strong>Diagnostics<\/strong> \u2014 inspect PHP error logs, check loopback status, look up site details.<\/li>\n<li><strong>Zero-config setup<\/strong> \u2014 no hand-editing hidden JSON files. Copy one command from your dashboard, paste it into your terminal, and it connects.<\/li>\n<\/ul>\n\n<p><strong>Included modules:<\/strong> Content (9 abilities), SEO (6), Diagnostics (7), Media (6), Users (5), WooCommerce (12, registers only when WooCommerce is active). That is 33 abilities on a standard install, or 45 with WooCommerce. Every one is an individual switch, and a token can only call what you allow.<\/p>\n\n<h3>Security<\/h3>\n\n<ul>\n<li>API tokens are SHA-256 hashed \u2014 the raw token is shown once and never stored.<\/li>\n<li>Every token is scoped to specific abilities. A token can only do what you explicitly allow.<\/li>\n<li>Optional IP allowlist restricts a token to specific addresses or CIDR ranges.<\/li>\n<li>Tokens are sent via the Authorization header, never in the URL.<\/li>\n<li>Every action is written to a searchable audit log with configurable retention.<\/li>\n<\/ul>\n\n<h3>What you need<\/h3>\n\n<p>The site scan and inline fixing need none of the following. These apply only if you choose to connect an AI assistant:<\/p>\n\n<ul>\n<li><strong>Node.js<\/strong> \u2014 the desktop bridge (<code>mcp-remote<\/code>) runs on your own computer.<\/li>\n<li><strong>HTTPS<\/strong> \u2014 so your API tokens stay encrypted in transit.<\/li>\n<li><strong>Administrator access<\/strong> \u2014 to generate tokens and toggle module permissions.<\/li>\n<\/ul>\n\n<h3>Help translate this plugin<\/h3>\n\n<p>My Site Hand is available in English and Bengali. If you speak another language, you can help \u2014 no coding needed:<\/p>\n\n<p>https:\/\/translate.wordpress.org\/projects\/wp-plugins\/my-site-hand\/<\/p>\n\n<p>New to translating? Start here: https:\/\/make.wordpress.org\/polyglots\/handbook\/translating\/first-steps\/<\/p>\n\n<h3>External Services<\/h3>\n\n<h4>Link Checker (SEO Module)<\/h4>\n\n<p>When the check-broken-links ability is called via the MCP API, this plugin sends HTTP HEAD requests to URLs found in your post content to verify they are reachable. No personal user data is transmitted \u2014 only a standard HTTP request is made to each URL being checked. This is triggered only when explicitly called by an authorized API token holder.<\/p>\n\n<h4>Link Checker (Site Health scan)<\/h4>\n\n<p>The Broken Links check in the Site Health scan sends HTTP HEAD requests (and, where a server refuses HEAD, a single ranged GET) to the links found in your 50 most recent published posts and pages, to see whether they still resolve. The request identifies this plugin and your site URL in its user agent. No personal user data is transmitted. Results are cached for 12 hours. This runs when you start a scan from the admin, and during the scheduled scan if you leave that enabled \u2014 on sites with more than 500 published posts the link check is skipped on the schedule. Turning scheduled reports off in <strong>My Site Hand \u2192 Settings<\/strong> stops the scheduled scan entirely.<\/p>\n\n<h4>Requests this plugin makes to your own site<\/h4>\n\n<p>The Exposed WordPress Files and XML-RPC checks ask your own site, over HTTP, whether \/readme.html, \/license.txt, \/wp-config-sample.php, \/wp-content\/debug.log and \/xmlrpc.php answer to an anonymous visitor. These are loopback requests to your own domain, not to any third party, and no data is sent in them. Results are cached for 12 hours. If your host blocks loopback requests, both checks report that they could not run rather than reporting your files as safe.<\/p>\n\n<h4>Shared report links<\/h4>\n\n<p>Creating a share link stores a redacted snapshot of your scan in your own database and serves it from your own site at a tokenized URL. Nothing is uploaded anywhere. The page is sent with X-Robots-Tag: noindex, nofollow, every link expires, and you can revoke one at any time.<\/p>\n\n<p>No data is sent to any third-party analytics or tracking service by this plugin.<\/p>\n\n<!--section=installation-->\n<p>Search for <strong>My Site Hand<\/strong> in your WordPress dashboard, install, and activate it. You land on Site Health and the first scan starts by itself. That is the whole setup.<\/p>\n\n<p>Connecting an AI assistant is optional, and fully guided:<\/p>\n\n<ol>\n<li><strong>Generate a token<\/strong> \u2014 go to <strong>My Site Hand &gt; API Tokens<\/strong> and click <strong>Create Token<\/strong>. Give it a label, e.g. \"Claude Desktop\".<\/li>\n<li><strong>Open the How to Use page<\/strong> in your dashboard.<\/li>\n<li><strong>Run two commands<\/strong> \u2014 one installs the <code>mcp-remote<\/code> bridge on your computer, the second (auto-generated, with your token) connects it.<\/li>\n<li><strong>Restart<\/strong> your AI client and start talking to your site.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20this%20a%20broken%20link%20checker%3F\"><h3>Is this a broken link checker?<\/h3><\/dt>\n<dd><p>Yes, among other things. It checks the links in your 50 most recent published posts and pages and reports the ones that are genuinely gone. Unlike a dedicated link crawler it does not run continuously in the background, so it will not slow your site down \u2014 it runs when you start it, or on a schedule you choose.<\/p><\/dd>\n<dt id=\"will%20it%20report%20links%20that%20are%20not%20really%20broken%3F\"><h3>Will it report links that are not really broken?<\/h3><\/dt>\n<dd><p>It tries hard not to. Only 404 and 410 count as gone. Anything ambiguous \u2014 a 403, a 405, a server error \u2014 is retried a different way, and if it is still unclear the link is not reported at all. A single false alarm would make you distrust the whole report.<\/p><\/dd>\n<dt id=\"can%20it%20find%20images%20with%20no%20alt%20text%3F\"><h3>Can it find images with no alt text?<\/h3><\/dt>\n<dd><p>Yes, and you can write the alt text straight into the report without opening the media library or the post editor. The score updates as you go.<\/p><\/dd>\n<dt id=\"does%20it%20check%20accessibility%3F\"><h3>Does it check accessibility?<\/h3><\/dt>\n<dd><p>It checks four structural problems: links that announce nothing to a screen reader, \"click here\" link text, more than one H1 on a page, and heading levels that skip. It is a useful first pass, not a full WCAG audit, and it does not claim to be one.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20yoast%20seo%20and%20rankmath%3F\"><h3>Does it work with Yoast SEO and RankMath?<\/h3><\/dt>\n<dd><p>Yes. The missing meta description check reads whichever of the two is active.<\/p><\/dd>\n<dt id=\"do%20i%20need%20an%20ai%20assistant%2C%20an%20api%20key%20or%20a%20token%20to%20use%20this%3F\"><h3>Do I need an AI assistant, an API key or a token to use this?<\/h3><\/dt>\n<dd><p>No. The scan and inline fixing work on their own, with nothing to install and nothing to configure. Connecting Claude, Cursor or VS Code is an optional upgrade.<\/p><\/dd>\n<dt id=\"does%20the%20scan%20slow%20my%20site%20down%3F\"><h3>Does the scan slow my site down?<\/h3><\/dt>\n<dd><p>No. It runs only when you start it, or on the schedule you choose, and it works in small batches so no single request runs long enough to time out. Scheduled scans skip the link check on sites with more than 500 published posts.<\/p><\/dd>\n<dt id=\"what%20does%20a%20shared%20report%20link%20show%20the%20person%20i%20send%20it%20to%3F\"><h3>What does a shared report link show the person I send it to?<\/h3><\/dt>\n<dd><p>The score, the name of each check, and how many issues each one found. Nothing else. No file names, no page addresses, no server paths, no post or media IDs, no edit links, and no plugin, theme, PHP or WordPress version numbers. The two security checks are excluded from public reports entirely. Every link expires \u2014 7, 30 or 90 days, your choice \u2014 and you can revoke one at any time.<\/p><\/dd>\n<dt id=\"does%20the%20%22download%20pdf%22%20button%20make%20a%20pdf%20on%20my%20server%3F\"><h3>Does the \"Download PDF\" button make a PDF on my server?<\/h3><\/dt>\n<dd><p>No, and deliberately so. It opens a clean printable page and your browser's own print dialog, where you choose \"Save as PDF\". Bundling a PDF library would multiply the size of the plugin to do something every browser already does well.<\/p><\/dd>\n<dt id=\"should%20i%20turn%20xml-rpc%20off%20because%20the%20scan%20mentions%20it%3F\"><h3>Should I turn XML-RPC off because the scan mentions it?<\/h3><\/dt>\n<dd><p>Only if you do not use the WordPress mobile app, Jetpack, or a desktop publishing tool \u2014 all of which need it. That is why it is reported as a notice rather than a warning, and why sites running Jetpack are skipped entirely. Disabling it on a site that needs it breaks that site, which is worse than leaving it alone.<\/p><\/dd>\n<dt id=\"do%20i%20need%20node.js%3F\"><h3>Do I need Node.js?<\/h3><\/dt>\n<dd><p>Not for the scan or inline fixing. Node.js is only needed if you choose to connect an AI assistant, because the desktop bridge (<code>mcp-remote<\/code>) runs on your own computer.<\/p><\/dd>\n<dt id=\"is%20this%20plugin%20secure%3F\"><h3>Is this plugin secure?<\/h3><\/dt>\n<dd><p>API tokens are SHA-256 hashed and shown once. You choose exactly which abilities each token may call, and you can revoke access instantly. The built-in audit log records what ran, who ran it, and when.<\/p><\/dd>\n<dt id=\"what%20ai%20applications%20are%20supported%3F\"><h3>What AI applications are supported?<\/h3><\/dt>\n<dd><p>Any client that supports the Model Context Protocol (MCP): <strong>Claude Desktop<\/strong>, <strong>Cursor<\/strong>, <strong>VS Code<\/strong> via an MCP extension, and <strong>Windsurf<\/strong>.<\/p><\/dd>\n<dt id=\"does%20this%20send%20my%20data%20to%20third-party%20servers%3F\"><h3>Does this send my data to third-party servers?<\/h3><\/dt>\n<dd><p>No. MCP communication happens directly between your local AI client and your WordPress site. The plugin does not track, collect or store your data on external servers. The only outbound requests are the link checks described under External Services.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.0 - 6 September 2026<\/h4>\n\n<ul>\n<li><strong>New: six more checks<\/strong> \u2014 image dimensions, lazy loading, exposed WordPress files, XML-RPC, thin content, and accessibility basics. Twelve checks in total.<\/li>\n<li><strong>New: PDF and CSV export.<\/strong> Send a client the report without giving them a login.<\/li>\n<li><strong>New: shareable report links<\/strong> with an expiry you choose. Public reports show scores and counts only \u2014 never paths, IDs, versions or plugin names.<\/li>\n<li><strong>New:<\/strong> Bengali translation, and the plugin is now fully ready for community translation.<\/li>\n<li><strong>Improved:<\/strong> Score weighting was retuned for twelve checks, so an ordinary site still lands in a usable range rather than being marked critical for having twice as much measured.<\/li>\n<\/ul>\n\n<h4>1.1.0 - 26 August 2026<\/h4>\n\n<ul>\n<li><strong>New: Site Health Scan<\/strong> \u2014 one click, no setup. Find broken links, missing alt text, missing meta descriptions, oversized media, orphaned files, and plugin or core health problems.<\/li>\n<li><strong>New: Quick Fix<\/strong> \u2014 repair issues inline from the report. No AI or API key required.<\/li>\n<li><strong>New:<\/strong> Score history and trend so you can watch your site improve.<\/li>\n<li><strong>New:<\/strong> Optional weekly email report. It stays quiet when there is nothing new to say.<\/li>\n<li><strong>New:<\/strong> Plugin checks now appear in WordPress's own Tools \u2192 Site Health.<\/li>\n<li><strong>Improved:<\/strong> Activation now takes you straight to a scan of your site instead of setup instructions. The MCP connection steps are still there, collapsed on the Dashboard as an optional upgrade.<\/li>\n<li><strong>New:<\/strong> Redesigned admin interface. The left sidebar is replaced by a brand row and a tab bar, and every page now has a numbered index so you can jump straight to the section you came for.<\/li>\n<li><strong>Improved:<\/strong> A single accent colour, flat surfaces, and a monospaced type scale make status, counts, and destructive actions easier to read at a glance.<\/li>\n<li><strong>Improved:<\/strong> The dashboard now surfaces what needs your attention \u2014 missing HTTPS, tokens expiring within 30 days, or a stopped endpoint.<\/li>\n<li><strong>Fixed:<\/strong> The \"Trust proxy headers\" and \"Allow token in URL query string\" settings did not save. Both now work.<\/li>\n<li><strong>Fixed:<\/strong> The settings page could submit itself and blank stored options if you pressed Enter in a text field. Settings save individually as you change them, so the form has been removed.<\/li>\n<\/ul>\n\n<h4>1.0.2 - 24 August 2026<\/h4>\n\n<ul>\n<li><strong>Security:<\/strong> Tokens created without an explicit ability selection no longer default to full access. Existing tokens are migrated automatically and continue to work unchanged.<\/li>\n<li><strong>Security:<\/strong> API tokens are no longer accepted via URL query string by default. Use the Authorization header instead. An opt-in setting remains available for clients that cannot send headers.<\/li>\n<li><strong>New:<\/strong> Optional per-token IP allowlist with CIDR range support.<\/li>\n<li><strong>New:<\/strong> Trusted proxy setting for sites behind Cloudflare or a reverse proxy.<\/li>\n<li><strong>Improved:<\/strong> Token creation now clearly distinguishes full access from limited access.<\/li>\n<li><strong>Fixed:<\/strong> Database schema version was not being stored after an upgrade, causing unnecessary schema checks on every page load.<\/li>\n<\/ul>\n\n<h4>1.0.1 - 9 June 2026<\/h4>\n\n<ul>\n<li>Added a \"Suggest a Feature\" page so users can submit feature requests directly to the developer's email.<\/li>\n<li>Improved email deliverability with dynamic \"From\" headers and real-time failure log captures.<\/li>\n<li>Styled and aligned the admin menu icon in the sidebar with a white background and centered flex alignment.<\/li>\n<li>Added automatic redirection to the dashboard immediately upon plugin activation for faster onboarding.<\/li>\n<li>Added a \"How to Use\" shortcut link directly on the Plugins page.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Official initial release.<\/li>\n<li>Automated zero-config setup for Claude Desktop.<\/li>\n<li>Support for Content, SEO (Yoast, RankMath), WooCommerce, and Diagnostics.<\/li>\n<li>Secure token management and real-time audit logs.<\/li>\n<\/ul>","raw_excerpt":"Find broken links, missing alt text and missing meta descriptions in 30 seconds, then fix them inline. No setup, no API key.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/309314","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=309314"}],"author":[{"embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/builtbytanin"}],"wp:attachment":[{"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=309314"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=309314"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=309314"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=309314"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=309314"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=309314"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}