LolaCore – AI Admin Agent
You: Run the weekly cleanup. Lola: Last week you decided to keep post revisions for 30 days and leave the ones on your landing pages alone. Going by that, 1,240 revisions and 1.2K expired transients are safe to clear, about 34 MB. I’ll show you the exact list before anything runs. Proceed? You didn’t repeat your rules. You didn’t re-explain last week. Lola already knew, because she remembers your site across sessions while every other AI tool forgets the moment you close the tab. That is the difference between a chatbot and an agent that runs your site. Running WordPress once is easy; running it every day wears you down—separate screens, repeated clicks, context gone when you close the session. That grind has a name: admin fatigue, the real cost of running a site. It hits hardest in WooCommerce, where every order and stock update adds another screen. I ran a store for ten years; what burned me out was never the selling—it was the admin. LolaCore is where that stops. Lola is an AI agent inside your wp-admin. You tell her what you need; she does the admin work and shows you exactly what she will change before anything happens. No new dashboard. No external tool. She works where you already work. She is built natively on the WordPress 7.0 AI Client and the Abilities API. She reads your database, reasons about it, and executes real actions only with your explicit approval. Full picture: documentation. Persistent memory Memory is the foundation everything else stands on. Lola remembers facts across sessions: plugin conflicts, security findings, your preferences, decisions you have made—all stored locally in your WordPress database. Ask what you worked on last week and she searches that memory plus the action log before answering. Correct or archive individual facts from chat without a full wipe. Important findings stay sharp; old trivia fades; pinned facts stay longer. When you start a new conversation, you don’t re-explain your stack. You pick up the thread. How decay, boosting, and export/import work: persistent memory guide. 77 abilities. 10 domains. One chat. Site diagnostics (4 abilities). WordPress and PHP status, HTTPS, database size, security headers, SEO audit. Lola tells you what’s broken before your client does. Plugins (8). Search WordPress.org, install, activate, deactivate, update, roll back to an earlier release, or update all. “Update all plugins” is one sentence, not 14 update screens. Plugin Builder (9). Describe a custom plugin in chat. Lola reads your site, co-designs a short plan, generates files with safety checks and AI code review, then you test in Playground before it touches your live site. Block Builder (9). Same flow for custom Gutenberg blocks: Lola scaffolds block.json, editor scripts, and the PHP render callback; you preview in Playground, then install on approval. Content & metadata (7). Create pages, edit posts, change status, update slugs, read and write post meta. Works with Yoast, RankMath, and other post-meta plugins. Users (4). Create accounts, change roles, remove users with automatic content reassignment. Database & cache (3). Clean post revisions, expired transients, orphaned postmeta, and spam comments. The cleanup WordPress never does for you. Taxonomies & media (7). Categories, tags, comments, and media files. Themes & settings (13). Install, update, and delete themes with safety warnings, read and write site options, manage navigation menus, review cron jobs. WooCommerce (13). Detected automatically. Products, orders, customers, coupons, categories, sales reports. “How much revenue this week?”—from your store data, not a dashboard. Every ability in detail: ability reference. Store tools with examples: WooCommerce abilities. How Lola stays safe Your data never touches our servers. No telemetry, no analytics. Your conversations go from your hosting to your AI provider. That’s it. Nothing happens without your approval. Every write action shows a preview card with exactly what Lola is about to do. You confirm or cancel. Every action is logged with before/after snapshots. Admin-only. She has an opinion Lola has judgment. When a change would hurt your site, she tells you before you commit and offers a safer way to get what you want. If you still want to proceed, she does it your way and records the decision, so the next time it comes up the context is already there. Any model, your choice Lola works with whatever AI provider you configure in WordPress 7.0 (Settings → AI). Agentic models perform best: GPT-5.5, DeepSeek V4, Claude 4.6 Sonnet or Opus 4.7. Gemini, Grok, Ollama, and OpenRouter work through the native connector. You pay your provider directly—no token markup from LolaCore. Each message sends only the abilities your request needs, not the full catalog. Setup: connecting your AI provider. Work with your site from Claude If you already pay for Claude, that subscription can run your site. Open Lola → MCP Settings, find Connect from the web, and click Add to Claude. The dialog opens on claude.ai with everything filled in — sign in, approve the connection on your site, done. From that moment, “update the plugins on my site” or “how did the store do this week?” works from any Claude conversation, on desktop or mobile. No API key to generate, no provider account to configure. You approve the connection once, as an administrator, on your own site. Every connected app appears in a list on the same screen, with a Disconnect button that cuts its access on the spot. Three things the connection needs: HTTPS, a site reachable from the internet (not a local install), and pretty permalinks. If any of them is missing, the screen tells you exactly what to fix. If your host runs an aggressive firewall, allow Anthropic’s published address range 160.79.104.0/21 — the screen has a built-in connection check that tells you whether the site is answering correctly. Native to WordPress 7.0 LolaCore runs entirely on the native WordPress AI Client and Abilities API. No external HTTP libraries, no custom credential vaults. When WordPress updates its AI infrastructure, LolaCore updates with it. Spanish and Brazilian Portuguese Lola speaks your language. Set WordPress to es_ES or pt_BR and the full admin experience runs in native Spanish or Brazilian Portuguese: settings panel, chat widget, ability labels, onboarding, preview cards, errors, and status messages. More than 1,050 user-facing strings per locale — not a thin language pack. The intent router is localized for both languages. Ask in Spanish or Portuguese which pages are in draft, what needs attention today, or to list your skills — Lola routes to the right tools without English keywords. Other locales fall back to English. Lola’s lane A tool that does everything does nothing well. Lola is built narrow on purpose. She doesn’t edit theme files, core, or server config. Plugin Builder and Block Builder are the exceptions: she generates custom plugins and blocks that you own and iterate in chat. She doesn’t see your frontend. Lola lives inside wp-admin. In wp-admin, she works on one site at a time. Over MCP, your editor can hold the whole fleet. Why these boundaries exist: what Lola cannot do. Skills and playbooks: teach Lola how you work Skills are short behavioral guides in plain Markdown that shape how Lola approaches a task. LolaCore ships with 14 built in, and you can write your own or ask Lola to create one for you in chat. Skills guide. A playbook is a curated manual for one area of work: your brand guidelines, your FSE build conventions, an internal process. Upload a document (TXT, Markdown, DOCX, or HTML), Lola distills it into a draft, you review and activate it. From then on she consults it whenever that domain comes up. Playbooks guide. Free addons teach Lola your stack When you work with a specific tool every day, a free addon teaches Lola that domain—all sharing the same site memory: LolaCore for Elementor: manage your Elementor pages and templates from chat LolaCore for ACF: read and write Advanced Custom Fields in plain language LolaCore for SEO: audit and edit your SEO without opening another panel LolaCore for Forms: work with your forms and their entries from the chat LolaCore for Statistics: ask about your traffic and get the number, not a dashboard LolaCore for FSE: a block and template builder for block themes Browse them all: lolacore.com/add-ons. For agencies and consultants Run WordPress for clients and the admin work multiplies with every site. Free addons go deep on the stack you build with: 91 for Elementor, 26 for ACF, 22 for SEO, 18 for Statistics, 15 for Forms, 17 for FSE—189 abilities on top of Lola’s core. Each client site is a separate install with its own memory; contexts never bleed across clients. Preview cards and logs mean you always know what changed on a live site. LolaCore bundles a zero-config MCP server—each client site becomes a tool in Cursor, Claude Code, or any MCP client. Connect the fleet and one agent runs it: “update plugins on site A”, “how did site B sell this week”, “SEO audit on every site”. Your agent, your rules, Lola’s full toolset—abilities, memory, builders, skills, playbooks. Don’t know what to say? Start here. No commands, no syntax. Three prompts you can paste right now: “Give me a quick briefing on the site. Anything that needs attention today.” “Update all plugins except Elementor and [plugin name]. Show me the list first.” “How much have we sold this week? Compare it to last week.” There are 45 more in the prompt library: daily check-ins, maintenance routines, session combos. External Services LolaCore connects to the following external services. Each connection is documented with what triggers it, what data is sent, and links to the relevant terms and privacy policies. AI Providers (Chat Feature) When you use the chat widget, your messages are sent to whichever AI provider you have configured in WordPress’s built-in AI settings (Settings → AI). LolaCore does not operate its own servers and does not route data through any intermediary. Data sent to your provider: – Your chat messages – A summary of your site scan (WordPress version, active plugin list, PHP version) – Relevant memory facts (site observations stored in your local database) Data never sent: – Passwords, API keys, wp-config values, or database credentials – Personal user data (emails, addresses, payment info) When this happens: Only when you actively send a message in the chat widget. No background calls. Supported providers: – OpenAI – https://openai.com | Terms of Use | Privacy Policy – Anthropic – https://anthropic.com | Terms of Service | Privacy Policy – DeepSeek – https://deepseek.com | Terms of Use | Privacy Policy Claude Web Connection (Optional) When you connect your site to Claude from Lola → MCP Settings, the traffic direction is inbound: Anthropic’s servers call your site’s REST API on behalf of your signed-in Claude account. LolaCore does not send any data to Anthropic on its own — data leaves the site only when you actively ask Claude to work with it, and every connection first requires an administrator’s approval on the site’s consent screen. Anthropic (Claude) – https://anthropic.com | Terms of Service | Privacy Policy Wordfence Vulnerability API LolaCore can check your installed plugins against the public Wordfence vulnerability database to identify known security issues. Endpoint: https://www.wordfence.com/api/intelligence/v2/vulnerabilities/scanner Data sent: An HTTP GET request with no request body. LolaCore sends only a User-Agent header identifying itself (LolaCore WordPress Plugin). No plugin lists, site URLs, or user data are transmitted to Wordfence. Data received: A public JSON feed of known WordPress plugin vulnerabilities. LolaCore compares this list locally against your installed plugin slugs and versions to surface relevant findings. When this happens: Only when you explicitly request a vulnerability check through the chat (e.g., “check my plugins for vulnerabilities”). This call is never made automatically during plugin activation, scheduled scans, or background operations. Service links: – Wordfence – https://www.wordfence.com | Terms of Service | Privacy Policy WordPress.org Plugin API When you ask Lola to search for or install plugins, LolaCore queries the official WordPress.org Plugin API. Data sent: Plugin search keywords or slug identifiers. Data received: Plugin metadata, descriptions, and download URLs from the WordPress.org repository. When this happens: Only when you use plugin search or install features through the chat. Service: https://wordpress.org | API Documentation Google Fonts The admin settings page loads two font families (Plus Jakarta Sans and JetBrains Mono) from Google Fonts for the plugin’s admin interface. Data sent: Standard HTTP font file requests. Google receives the requesting IP address and browser User-Agent. When this happens: Each time an administrator opens the LolaCore settings page. Service: https://fonts.google.com | Terms of Service | Privacy Policy
Top keywords
- site32×1.50%
- lola28×1.32%
- lolacore22×1.03%
- wordpress20×0.94%
- ai15×0.70%
- data15×0.70%
- chat14×0.66%
- claude12×0.56%
- work11×0.52%
- api10×0.47%
- https10×0.47%
- update10×0.47%
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!