Keep WordPress Safe When Using Application Passwords and AI Tools

Have you started using AI tools to update or manage your WordPress site? I’ve spoken to lots of PublishPress customers who are using AI tools to create posts, generate images, audit existing content, and much more.

Most AI tools use Application Passwords.

These passwords are super easy to set up.

But here’s the catch: they get full administrator access. That means they can delete posts, plugins, themes, and users. Your entire site is in their hands.

That felt like a problem worth solving.

In the newest release of PublishPress Capabilities, we’re treating Application Passwords like users — so you can actually lock them down.

  • Want your AI tool to edit posts, but nothing else? Done.
  • Want it to create new posts, but not touch existing ones? Easy.
  • Just managing Tags and Categories? No problem.

You stay in control of your site. Your AI tool only gets access to what it actually need.

Application Password control

What are Application Passwords?

Application Passwords are special passwords you create for a specific integration. This is safer than sharing your main WordPress login password. Here’s the official WordPress guide.

Application Passwords are used for a more than just AI. But nearly all AI tools use Application Passwords.

If you’re connecting your AI tools to WordPress, you might use one of these tools:

Almost all of them will allow you to connect using an Application Passwords. You create your own Application Password by going to Users > Profile in your WordPress site.

User Profile admin menu screen

Scroll down to the “Application Passwords” area. Each password has its own name, so you can see what it is being used for. Enter a name and click “Add Application Password”.

"Application Passwords" area

You’ll get a password that looks like this: 8p75 tz2p sWas w9au 0iz3 Sfy7. You can enter that into your AI tool and connect it with your WordPress site.

New application password

How to Control Access for Application Passwords

This feature is available in the PublishPress Capabilities plugin.

Go to Capabilities > Settings > Capabilities and enable “Application password capabilities”.

Application Password capability option

Now you can go to the Capabilities > Capabilities and control what your AI tools can do. In the main dropdown, select your Application Password.

Capabilities password

This screenshot below shows a common use-case. You can allow your AI tool to edit Posts, not Pages or any other post type.

Edit post type with AI tool

This next screenshot shows a common safety example. You can go to the “Plugins” tab and block your AI tool from making any changes to plugins.

block your AI tool from making any changes to plugins
PublishPress Capabilities icon
  • Steve is the founder of PublishPress. He's been working with open source software for over 20 years. Originally from the UK, he now lives in Sarasota in the USA. This profile is generated by the PublishPress Authors plugin.

Leave a Reply

Your email address will not be published. Required fields are marked *