DXTechAI Claw Agent
WP DXTechAI Claw Agent is an AI Agent plugin for WordPress, powered by a ReAct (Reason + Act) loop. The Agent doesn’t just answer questions — it executes actions directly on your WordPress site. Key Features 🤖 Command Palette — Open with Ctrl+I, Ctrl+G or Ctrl+Shift+K, modern glassmorphism chat interface 🧠 ReAct Loop — Agent reasons, selects tools, executes, observes results, and continues ✅ Confirm Before Executing — Data-changing actions require user confirmation 🔗 Chain Actions — Automatically performs sequential actions (e.g., create category then create multiple products) 🔌 Multi LLM Provider — Supports OpenAI (GPT-4o), Google Gemini (2.5 Flash/Pro), Anthropic Claude (Sonnet 4), Cloudflare Workers AI (Free) 🛒 WooCommerce Ready — Auto-detects WooCommerce and activates product, order, and customer management tools 💾 Session Persistence — Saves session state to resume after action confirmation 🔍 Web Research — Built-in web search via DuckDuckGo (free) or Google Custom Search 📱 Telegram Bot — Control your WordPress site via Telegram with inline keyboard confirmations 12 Built-in Tools WordPress Core (9 tools): Content Manager (wp_content_manager) — Create/update posts with categories, tags, and HTML content System Inspector (wp_system_inspector) — View site info, active plugins, categories, tags, post types Web Research (web_research_tool) — Search the web via DuckDuckGo (free) or Google Custom Search Taxonomy Manager (wp_taxonomy_manager) — Create/update/delete categories & tags Media Manager (wp_media_manager) — Upload images from URL, set featured images, list/delete media Page Manager (wp_page_manager) — Create/update/delete/list pages, supports templates & sub-pages User Inspector (wp_user_inspector) — List users, view details, count by role Analytics Reader (wp_analytics_reader) — Post stats by status, comment stats, content summary Report & Analytics (wp_report) — Dashboard overview, order reports, product reports, content reports WooCommerce (3 tools — auto-activated when WooCommerce is active): Product Manager (woo_product_manager) — Full product CRUD (name, price, SKU, stock, images), manage product categories Order Inspector (woo_order_inspector) — List/view orders, update status, revenue statistics Customer Inspector (woo_customer_inspector) — List/search customers, customer stats, top customers Architecture ReAct Loop Engine (Kernel) — Reason→Act→Observe loop with configurable max iterations Dynamic Confirmation — Mixed read/write tools only require confirmation for write actions Context Provider — Auto-injects site snapshot (categories, post types, user) into LLM context Auto-Discovery — Automatically discovers and registers tools from the Actions/ directory REST API — Two endpoints: /agent/chat and /agent/confirm with session management Telegram Controller — Webhook-based bot with inline keyboard confirmations and session per chat Usage Examples WordPress: * “Create a Technology category” * “Write a blog post about AI trends 2025, save as draft” * “Search the web for WordPress performance tips and write a summary post” * “Show me site post statistics” * “Create an About Us page with company introduction content” * “Upload an image from URL and set it as featured image for the post” WooCommerce: * “Create 3 T-shirt products priced at 250,000” * “Create a Fashion product category, then add 5 products to it” * “Show me this month’s revenue” * “Update order #123 status to completed” * “Find customers with ‘gmail’ in their email” * “Show me the top 5 customers by total spending” Reports & Analytics: * “Show me dashboard overview” * “Thống kê đơn hàng tháng này” * “Sản phẩm bán chạy nhất” * “Báo cáo bài viết và trang” Configuration LLM Provider Choose one of four providers: Google Gemini (AI Studio) — Free tier available at aistudio.google.com Models: Gemini 2.5 Flash (Free), Gemini 2.5 Flash Lite (Free), Gemini 2.5 Pro Preview, Gemini 2.0 Flash Lite OpenAI — API key required from platform.openai.com Models: GPT-4o, GPT-4o Mini, GPT-4 Turbo Anthropic — API key required from console.anthropic.com Models: Claude Sonnet 4, Claude 3.5 Haiku Cloudflare Workers AI — API token required from dash.cloudflare.com Models: Qwen 2.5 72B (Best Vietnamese), Gemma 3 12B, DeepSeek R1 32B Web Search Default: DuckDuckGo (free, no API key required) Optional: Google Custom Search (requires API key + Search Engine ID) Agent Settings Max Iterations — Maximum ReAct loop iterations (1–20, default: 10) Telegram Integration Control the AI agent directly from Telegram: Create a bot via @BotFather on Telegram Copy the Bot Token to DXTechAI Claw Agent → Telegram → Bot Token Add your Telegram Chat ID to Allowed Chat IDs (send a message to your bot, then use the Telegram Bot API getUpdates method to find your chat ID) Click Register Webhook to connect your site to Telegram Send messages to your bot — the AI agent will respond! Telegram Features: * Send natural language messages to control WordPress * Inline keyboard buttons for action confirmations (Approve/Reject) * Session persistence per chat — multi-turn conversations * Automatic Markdown fallback if formatting fails * Secure with secret token verification and chat ID whitelist Commands: * /start — Show help message * /reset — Clear current session Discord Integration Control the AI agent directly from Discord via slash commands (/agent) and interaction buttons: Create an Application in the Discord Developer Portal Copy the Bot Token, Application ID, and Public Key to the DXTechAI Claw Agent settings Set your Interactions Endpoint URL in Discord to: https://your-domain/wp-json/dxtechai-claw-agent/v1/discord/interactions Use the Sync Commands button in the plugin settings to register the /agent slash command Use /agent in your Discord server to command the agent Discord Features: * Control WordPress natively using the Discord slash command interface * Rich Embeds for agent responses and confirmation prompts * Action buttons directly in the chat to Approve or Reject changes safely * Secure validation of every request using Ed25519 signatures External Services This plugin connects to third-party AI and search services to provide its core functionality. No data is sent to any external service until the user explicitly configures an API key and initiates a request. OpenAI API When OpenAI is selected as the AI provider, user prompts and WordPress site context are sent to the OpenAI API for processing. * Service URL: https://api.openai.com * Terms of Use: https://openai.com/terms * Privacy Policy: https://openai.com/privacy Google Gemini (AI Studio) When Gemini is selected as the AI provider, user prompts and WordPress site context are sent to the Google Generative AI API. * Service URL: https://generativelanguage.googleapis.com * Terms of Use: https://ai.google.dev/terms * Privacy Policy: https://policies.google.com/privacy Anthropic (Claude) When Anthropic is selected as the AI provider, user prompts and WordPress site context are sent to the Anthropic API. * Service URL: https://api.anthropic.com * Terms of Use: https://www.anthropic.com/terms * Privacy Policy: https://www.anthropic.com/privacy Cloudflare Workers AI When Cloudflare is selected as the AI provider, user prompts and WordPress site context are sent to the Cloudflare API. * Service URL: https://api.cloudflare.com * Terms of Use: https://www.cloudflare.com/website-terms/ * Privacy Policy: https://www.cloudflare.com/privacypolicy/ DuckDuckGo Search The web research tool uses DuckDuckGo’s HTML search as the default search provider. Search queries are sent when the AI agent decides to perform web research. * Service URL: https://html.duckduckgo.com * Terms of Use: https://duckduckgo.com/terms * Privacy Policy: https://duckduckgo.com/privacy Google Custom Search When configured, the web research tool can use Google Custom Search API instead of DuckDuckGo. Search queries are sent to the Google API. * Service URL: https://www.googleapis.com/customsearch * Terms of Use: https://developers.google.com/terms * Privacy Policy: https://policies.google.com/privacy Pexels API When Pexels API key is configured, the agent may search and download free stock photos from Pexels for blog post thumbnails. Search queries (based on your post titles or keywords) are sent to the Pexels API. * Service URL: https://api.pexels.com * Terms of Use: https://www.pexels.com/terms-of-service/ * Privacy Policy: https://www.pexels.com/privacy-policy/ Unsplash API When Unsplash API key is configured, the agent may search and download free stock photos from Unsplash for blog post thumbnails. Search queries (based on your post titles or keywords) are sent to the Unsplash API. * Service URL: https://api.unsplash.com * Terms of Use: https://unsplash.com/terms * Privacy Policy: https://unsplash.com/privacy Telegram Bot API When Telegram integration is enabled, the plugin sends messages to the Telegram Bot API to deliver responses and inline keyboards to the configured bot. * Service URL: https://api.telegram.org * Terms of Use: https://telegram.org/tos * Privacy Policy: https://telegram.org/privacy Discord Bot API When Discord integration is enabled, the plugin communicates with the Discord API to sync slash commands and send callback responses. * Service URL: https://discord.com/api * Terms of Use: https://discord.com/terms * Privacy Policy: https://discord.com/privacy
Top keywords
- api32×2.26%
- https31×2.19%
- com30×2.12%
- search21×1.49%
- agent20×1.42%
- ai18×1.27%
- privacy18×1.27%
- telegram17×1.20%
- terms17×1.20%
- google15×1.06%
- discord14×0.99%
- bot13×0.92%
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!