My Site Hand – AI Assistant, Site Health & MCP Server for WordPress
My Site Hand finds what is wrong with your WordPress site, and helps you fix it. Activate the plugin and it scans your site straight away. No token, no API key, no Node.js, no terminal. About thirty seconds later you get a health score out of 100 and a list of real problems on your own site — and you can repair most of them inline, right there in the report. 🔍 The Site Health Scan (no setup required) Twelve checks, run one at a time so nothing times out. Broken links — checks the links in your recent posts and pages, and reports only the ones that are genuinely gone. Anything ambiguous is left alone rather than reported as a false alarm. Missing alt text — images your visitors using screen readers cannot see, and search engines cannot read. Missing meta descriptions — published posts and pages with no SEO description, for Yoast SEO and RankMath. Oversized media — files big enough to slow your pages down, with the space you would get back. Orphaned files — uploads that nothing on your site appears to use. Plugin and core health — pending updates, an unsupported PHP version, missing HTTPS, errors visible to visitors, a stalled cron. Images missing dimensions — the cause of pages that jump around while they load, which Google measures as a Core Web Vital. Images missing lazy loading — pictures further down a post that something has opted out, so visitors download them before they are ever seen. Exposed WordPress files — readme.html, license.txt and a debug log left publicly readable. The first hands an attacker your exact version; the last can contain server paths and credentials. XML-RPC — reported as a notice, with the tradeoff stated plainly. It is a brute-force vector, but the WordPress mobile app and Jetpack need it, so this is only worth turning off if you use neither. Sites running Jetpack are skipped entirely. Thin content — published pages with very few words. Read with judgement: a contact page is supposed to be short, and pages built from a shortcode, gallery or embed are left out. Accessibility basics — links that announce nothing to a screen reader, “click here” links, more than one main heading, and headings that skip a level. Structural checks only; it does not claim to be a full audit. ⚡ Quick Fix A list of complaints is not much use on its own. Write alt text straight into the report, replace a dead link, or trash a file you no longer need — one row at a time, with the score climbing as you go. No AI and no API key required for any of it. Your score is kept over time, so you can watch the site improve, and you can have a short report emailed to you when something changes. 📤 Send the report to someone else A report is more useful when the person who needs to act on it can read it. PDF — opens a clean, printable page and your browser’s own print dialog. Choose “Save as PDF”. No bloated PDF library bundled into the plugin to do a job your browser already does well. CSV — every issue as a row: check, severity, issue, context, link and object ID. Opens correctly in Excel and Google Sheets, in any language. A shareable link — a public web page your client can open without a login, with an expiry you choose: 7, 30 or 90 days. There is no never-expires option. Shared reports are redacted on purpose. They show the score, each check by name, and how many issues it found. They never show file names, page addresses, server paths, post or media IDs, edit links, or your plugin, theme, PHP and WordPress versions — and the two security checks are left out entirely, because publishing those would be publishing a vulnerability report about your own server. The page tells you exactly what a recipient will and will not see before you create the link, every link can be revoked instantly, and the report is a snapshot: re-scanning your site never changes what you already sent. 🤖 And when you want an AI to do the work Everything above works on its own. Connecting an AI assistant is the optional upgrade. Built on the open standard Model Context Protocol (MCP) developed by Anthropic (the creators of Claude), this plugin securely exposes safely-gated capabilities (Abilities) to clients like Claude Desktop, Cursor, and VS Code, so they can work on your site using plain language. 🚀 What an AI assistant can do for you: Write & Edit Content – Ask Claude to draft, edit, format, or publish posts and pages directly on your site. AI-Driven SEO Audits – Let your AI scan Yoast or RankMath metadata, optimize it for targeted keywords, and update titles/descriptions instantly. WooCommerce Store Management – Ask your AI to list low-stock items, draft product listings, check recent orders, or summarize sales analytics. Site Health & Diagnostics – Let the AI inspect PHP error logs, check loopback status, or look up site details to debug issues. Zero-Config Automated Setup – No manual editing of hidden JSON config files. Copy a single command from your WordPress dashboard, paste it into your terminal, and Claude connects automatically! Total Safety & Security – All tokens are SHA-256 hashed. You can toggle specific abilities (like writing or deleting) on/off with simple switches, and monitor everything the AI does in real-time with the built-in Audit Log. 📦 Included Modules: Content — posts, pages and custom post types (9 abilities) SEO — analysis and meta management, for Yoast SEO and RankMath (6) Diagnostics — site health, error logs, cron and database details (7) Media — the media library, including alt text (6) Users — accounts and roles (5) WooCommerce — products, orders and coupons (12, registers only when WooCommerce is active) That is 33 abilities on a standard install, or 45 with WooCommerce. Every one of them is an individual switch, and a token can only call what you allow. 🔒 Security API tokens are SHA-256 hashed — the raw token is shown once and never stored. Every token is scoped to specific abilities. A token can only do what you explicitly allow. Optional IP allowlist restricts a token to specific addresses or CIDR ranges. Tokens are sent via the Authorization header, never in the URL. Every action is written to a searchable audit log with configurable retention. ⚠️ Important Requirements (Honest & Transparent): The Site Health scan and Quick Fix need none of the following. They apply only if you choose to connect an AI assistant: Node.js: The automated desktop bridge (mcp-remote) requires Node.js installed on your local computer to run. SSL/HTTPS: For security, your site must run on HTTPS so your API tokens remain encrypted in transit. Administrator Access: You must be an administrator to generate API tokens and toggle module permissions. External Services Link Checker (SEO Module) When the check-broken-links ability is called via the MCP API, this plugin sends HTTP HEAD requests to URLs found in your post content to verify they are reachable. No personal user data is transmitted — only a standard HTTP request is made to each URL being checked. This is triggered only when explicitly called by an authorized API token holder. Link Checker (Site Health scan) The Broken Links check in the Site Health scan sends HTTP HEAD requests (and, where a server refuses HEAD, a single ranged GET) to the links found in your 50 most recent published posts and pages, to see whether they still resolve. The request identifies this plugin and your site URL in its user agent. No personal user data is transmitted. Results are cached for 12 hours. This runs when you start a scan from the admin, and during the scheduled scan if you leave that enabled — on sites with more than 500 published posts the link check is skipped on the schedule. Turning scheduled reports off in My Site Hand → Settings stops the scheduled scan entirely. Requests this plugin makes to your own site The Exposed WordPress Files and XML-RPC checks ask your own site, over HTTP, whether /readme.html, /license.txt, /wp-config-sample.php, /wp-content/debug.log and /xmlrpc.php answer to an anonymous visitor. These are loopback requests to your own domain, not to any third party, and no data is sent in them. Results are cached for 12 hours. If your host blocks loopback requests, both checks report that they could not run rather than reporting your files as safe. Shared report links Creating a share link stores a redacted snapshot of your scan in your own database and serves it from your own site at a tokenized URL. Nothing is uploaded anywhere. The page is sent with X-Robots-Tag: noindex, nofollow, every link expires, and you can revoke one at any time. No data is sent to any third-party analytics or tracking service by this plugin.
Top keywords
- site22×1.50%
- link10×0.68%
- own10×0.68%
- ai9×0.62%
- only9×0.62%
- pages9×0.62%
- report9×0.62%
- scan9×0.62%
- health8×0.55%
- links8×0.55%
- api7×0.48%
- token7×0.48%
AI Agent by SiteGround
The AI Agent by SiteGround plugin enables an AI agent for your WordPress and WooCommerce instances, and activates SiteGround AI connector for WordPress. Why get this plugin? Brings an AI agent directly into your WordPress workflow to assist you in streamlining site management. Regardless of your WordPress level of expertise, you can simply describe what you want in a chat and the AI agent will do it for you. Lets you manage WordPress and WooCommerce through an AI chat – the faster, simpler, smarter way. The AI Agent is trained on WordPress and is able to execute real, consequential tasks securely. It offers a centralized chat to do all tasks – no screen hopping across the admin. Saves you time and reduces manual work. It also enables SiteGround AI connector for WordPress, which means you can use native AI functionalities through AI Studio. SiteGround customers get free monthly tokens. 🗝️ Key Capabilities The AI Agent for WordPress has a wide range of capabilities, covering a large scope of WordPress and WooCommerce tasks: Content Management Easily generate, edit, publish, and organize content on one site or across your entire portfolio. Create or edit posts and pages: Create, update, and delete posts and pages. Draft the actual content with AI-generated text and images. Publish or unpublish content: Control when your posts and pages go live, or save them as drafts until they’re ready. Add categories and tags: Apply, update, or remove categories and tags to keep your content organized. Builds navigation menus, organizes page structure and hierarchy. It handles successfully complete taxonomy restructures – merging categories, creating new hierarchies, and reassigning posts to different tags. Moderate comments: Approve, edit, or delete comments to keep discussions clean and relevant. Media Library Control: Upload, retrieve, or delete images and files with a single prompt. Optimise for search engines: audits for missing SEO meta data, generates meta for new WordPress posts and pages – SEO titles, meta descriptions, keywords, alt text and captions. Point it at a media library with 200+ product images, and it adds the needed metadata for each one, maintaining consistent keyword usage throughout. That’s 800+ individual fields – a week and a half of mind-numbing work, finished in an afternoon. Translate content: Translate posts, pages, or even your entire WooCommerce product catalogue into any language. Perform bulk content changes across sites: Update text, URLs, or meta data across dozens of pages on multiple sites. WooCommerce Management Let the AI Agent for WordPress handle key WooCommerce tasks for your store. Create and update products: Add new listings or edit product details like price, description, labels and stock. Manage inventory: Adjust stock levels and availability across your catalog. Handle orders: View, update, cancel, or delete orders. Retrieve customer orders and details instantly for faster order processing and support. Track store performance: Ask the agent for sales reports, top-performing products, coupon usage, and trends for any date range. Translate your product catalogue: Expand into new markets by translating your full WooCommerce catalogue, with HTML formatting and technical specifications preserved. Plugins & Themes Maintain your WordPress installation effortlessly and keep your entire site portfolio up to date at once. Install or remove plugins: Add new or clean up unused plugins in seconds. Manage themes quickly: Install, update, or delete themes with a single prompt. Audit plugins and themes: Ask for a list of all installed plugins or themes with their version numbers and update status, so you can spot outdated or unnecessary extensions. Update plugins and themes across all sites: Push updates to your entire portfolio with one command, with no separate wp-admin logins. Site Settings Control your WordPress configuration through chat commands and standardize it across every connected site. Update core settings: Change site title, tagline, language, timezone, and permalink structure in one step. Standardize settings across sites: Apply the same configuration to all your connected WordPress installations instantly. User Management Simplify user control and community moderation. Add and manage users: Create new accounts, reset passwords, update user details, or adjust roles and permissions. Manage users across sites: Add a new editor to all connected sites, review Admin access everywhere, or remove a user’s access across your entire portfolio. 🛡️ Power Mode for High-Impact Actions To protect your website from accidental or harmful changes, the AI Agent for WordPress includes a built-in safety layer called Power Mode. Power Mode is disabled by default to ensure that high-impact actions are never executed without your explicit confirmation. When you request a potentially irreversible operation, the Agent will pause and alert you before proceeding. Actions that require Power Mode ON include: Deletions: posts, pages, categories, tags, users, media files, plugins, themes, products, orders. Bulk operations: mass-editing post titles, updating URLs across multiple pages, mass-deleting drafts. Create, edit, and delete users Updating global site settings Creating, updating, or deleting WooCommerce products and orders By combining AI automation with built-in safeguards, SiteGround ensures you get speed and convenience without compromising safety. 🌐 Manage Multiple Sites in Bulk Connect any number of WordPress sites to SiteGround AI Studio and manage them all from a single AI-powered workspace. Turn repetitive wp-admin logins into one set of instructions that instantly runs across your connected sites. Push plugin and theme updates across your entire portfolio with one command. Add or remove users across all sites at once, onboard a new team member or revoke access when someone leaves. Perform bulk content changes such as updating text or URLs across dozens of pages on multiple sites. Standardize WordPress settings like site title or timezone across all connected sites instantly. ✨ AI Connector The plugin also enables SiteGround AI as an AI connector for your WordPress. SiteGround AI is a multi-model AI service that intelligently routes each task to the best-suited LLM, optimizing for output quality and cost efficiency. It powers WordPress AI features, including text, image, and code generation, translation, research, analysis, and more. It orchestrates several models – Gemini, Nano Banana, ChatGPT, GPT-Image, Claude – and automatically selects the best one for each job. Install the AI Agent by SiteGround plugin, create a free account for SiteGround AI Studio service, and the connector activates automatically. No API key is needed to activate. In the plugin you have separate settings to activate and deactivate the SiteGround AI Connector separately from the AI agent. If you deactivate the Connector it will stop powering up AI features in the WP admin, enabled by the AI plugin. Disconnecting the SiteGround AI Connector will not affect the work of the AI agent – it will remain active until you disable this plugin entirely. Learn More. 🚀 Getting Started To start using the AI Agent for WordPress, you need to sign up for SiteGround AI Studio and activate the AI Agent by SiteGround plugin. The plugin works with any WordPress site, regardless of where it is hosted. If your WordPress site is hosted on SiteGround servers, you can enable the connection in a click. What is AI Studio by SiteGround? SiteGround AI Studio is the connector that powers the AI Agent by SiteGround plugin with AI capabilities. By signing up for AI Studio you not only enable the AI Agent for WordPress, but also get a unified platform to chat with multiple LLMs: Claude, ChatGPT, Gemini, Imagen, Nano Banana, and gives you access to 14+ agents that perform different business and marketing tasks. How to get started? Sign up for SiteGround AI Studio Log into your WordPress admin and activate AI Agent by SiteGround plugin. Paste the connection key from your AI Studio account to link your site. Once connected, chat with the agent from the SiteGround’s AI Studio interface or directly inside your WordPress Admin via a built-in chat pop-up. External services This plugin connects to SiteGround’s AI Studio API (api.studio.siteground.ai) to provide AI-powered WordPress site management features. The plugin transmits data to the following endpoints: AI Chat Service – Purpose: Process user requests and generate AI-powered content, site management commands, and responses – Endpoint: https://api.studio.siteground.ai/api/v1/* (various chat and generation endpoints) – Data sent: User prompts/queries, site context (WordPress version, active plugins, theme info), content being edited – When: Every time you interact with the AI assistant chat interface or use AI generation features Authentication & Key Management – Purpose: Securely authenticate the plugin and manage API access credentials – Endpoint: https://api.studio.siteground.ai/[service]/v1/sign/token – Data sent: Site URL, authentication tokens, plugin version – When: During initial plugin setup, when connecting/reconnecting the service, and during automatic token refresh Key Refresh Service – Purpose: Periodically refresh authentication keys to maintain secure access – Endpoint: https://api.studio.siteground.ai/dynamic-keys/v1/key-refresh – Data sent: Current authentication credentials, site URL – When: Automatically when authentication keys need renewal Usage Analytics – Purpose: Track feature usage and display usage statistics in the plugin dashboard – Endpoint: https://api.studio.siteground.ai/api/v1/usage (analytics endpoints) – Data sent: Usage metrics requests – When: When viewing the plugin dashboard or usage statistics Access Control – Purpose: Retrieve and verify user permissions for plugin features – Endpoint: https://api.studio.siteground.ai/api/v1/acl/wp-acl – Data sent: User/site identification data – When: During feature access verification and permission checks Connection Management – Purpose: Establish and terminate plugin connections to the AI Studio service – Endpoint: https://api.studio.siteground.ai/api/v1/wp/wp-disconnect – Data sent: Site URL, connection credentials – When: When connecting or disconnecting the plugin from AI Studio service Service provider: SiteGround SiteGround Terms of Service SiteGround AI Studio Terms SiteGround Privacy Policy SiteGround Plugins Privacy Notice