Skip to content
RankX AI
RankX AI Docs
Integrations

WordPress

Connect WordPress to RankX AI in one click or with an Application Password, add the optional RankX AI plugin, and see what RankX AI writes and how it checks.

RankX AI connects to WordPress in one click: you type your site's address, approve RankX AI on WordPress's own approval screen, and come back connected, with nothing to copy or paste. Once connected, RankX AI can read your content, propose changes, and apply them with every write verified by reading the object back. No edit is applied without a dry run first, and no article is published without being approved first.

The connection uses the site's own REST API and a WordPress Application Password. With one-click approval, WordPress issues that password itself when you approve, and RankX AI never asks for your WordPress login. Entering an Application Password by hand is always available beside it.

Before you connect

You need three things:

  • A WordPress site reachable over HTTPS with the REST API enabled. It is enabled by default; some security plugins disable it.
  • An account on that site with the capabilities you want RankX AI to have. RankX AI acts as that user and can never do more than that user could.
  • Application Passwords available. They ship with WordPress and are on by default, but some hardening plugins switch them off. Both ways of connecting rely on them.

Connecting in one click

Enter your site's address

In RankX AI, open the Website's settings and its Integrations section, choose to connect WordPress, type the address and press Check. RankX AI asks the site what it supports, so the next screen shows what is true for that site rather than a menu of options.

Approve RankX AI on WordPress's own screen

When the site supports one-click approval, press Approve in WordPress. Your own wp-admin opens (sign in if WordPress asks), and WordPress asks whether to approve the connection. Approve it on the account you want RankX AI to act as.

Come back connected

WordPress returns you to RankX AI with the connection made, and RankX AI checks what the site supports (see below). The approval appears in your WordPress profile under Application Passwords, named RankX AI, which is also where you remove it.

WordPress offers one-click approval on sites served over HTTPS, and a host or security plugin can switch it off. Where it is not offered, RankX AI says so on the same screen and the manual route below works instead. The manual route also suits an agency that holds a credential for a client's site without a wp-admin session there.

Connecting with an Application Password instead

Open your WordPress profile

In wp-admin, go to Users, then your own profile. Application Passwords are per user, not per site, so create it on the account you want RankX AI to act as.

Scroll to Application Passwords

Give it a name you will recognise later, such as RankX AI. The name is only a label for you; revoking it later is how you disconnect.

Copy the generated password immediately

WordPress shows it once, in groups separated by spaces. Copy the whole thing including the spaces. If you lose it, revoke that entry and create another; there is no way to see it again.

Paste it into RankX AI

In RankX AI, open the Website's settings and its Integrations section, choose to connect WordPress, and choose Enter an Application Password instead. You need three fields: the site URL, the WordPress username (not the email address), and the Application Password.

What RankX AI checks as soon as you connect

However you connect, RankX AI immediately probes what your site actually supports: which content types exist and are editable, which taxonomies exist, whether SEO fields are writable, whether WooCommerce is present, whether a page builder is in use, and whether the RankX AI plugin is installed.

This probe is the reason nothing later has to guess. A WordPress site only exposes what its plugins and the connected account allow, so nothing about it can be assumed.

What RankX AI can do once connected

AreaWhat it does
ContentList, read and create posts, pages and custom types. Update title, body, excerpt, slug, categories, tags and featured image
Targeted editsChange specific text inside an existing page without rewriting the rest of it
BlocksAdd, place or remove whole blocks, with a free outline action that lists every block first
SEO metadataSet the SEO title and meta description, where your plugin exposes them or on any site with the RankX AI plugin
MediaList images, upload new ones, and set alt text, caption and title
TaxonomiesList and create categories, tags and custom terms
BulkApply one change across an explicit list of ids, dry run first
Structured dataRead every schema a page carries, and add, replace or remove one through your SEO plugin, dry run first
RedirectsRead your redirects and 404 log, and redirect a genuinely missing address through the Redirection plugin, Rank Math or the RankX AI plugin, dry run first
SEO coverageCheck which SEO features the site actually prints, as a visitor sees them, whatever SEO plugin it runs
Publishing articlesSend an approved Content Studio article to the site as a draft, scheduled, or live, with every field verified
Site settingsRead settings, menus, users, comments, widgets, templates, plugins and themes. Change a small set of site settings and moderate comments
RevisionsList a page's WordPress revisions, which is what an edit can be rolled back to

Every one of those is also an MCP tool, and in practice that is how most of it gets used: you ask an assistant, it dry runs (or, for an article, you approve it), you look, it applies.

The four rules, and why each exists

1. Every write is verified by reading the object back. RankX AI writes, then re-reads the object and compares. A write it cannot confirm is reported as unverified, never as success. This exists because plugins that return HTTP 200 while persisting nothing are common, and a status code proves nothing on this platform.

The read-back deliberately bypasses your page cache, without which a successful write reports as failed on most managed hosts.

2. Every write can be refused before it is attempted. RankX AI checks whether a page's body can be rewritten at all before offering to rewrite it, and reports that on every listing row rather than only on failure.

3. Nothing you send is discarded. A body the converter cannot map to native blocks is preserved verbatim in a raw HTML block and reported.

4. Every edit defaults to a dry run. The dry run runs the identical conversion pipeline as the real write, so the warnings it produces are the warnings the write will produce. Applying is a second, explicit call. Publishing a Content Studio article has no dry run: it needs the article approved first instead.

Page builders: three tiers

Page builders store content in different places, and where a builder stores it decides what is possible. RankX AI classifies every page into one of three tiers and tells you which:

The page isWhere its content livesWhat RankX AI can do
Plain GutenbergThe page body, core blocksReplace the whole body, or patch specific text
A block-based builderThe page body, in the builder's own block namespaceTargeted text patches, and adding or removing a block, each asked for explicitly
A meta-based builderPost meta rather than the page bodyProtected. Edit the body in the builder itself; every body write from a tool is refused, so the layout stays intact

Elementor, Divi and WPBakery are the common meta-based case. A page built with one of them is listed as not writable and refuses a body write, with no override from MCP. That guarantee protects the page: the alternative is a page that keeps every word and silently loses its layout.

An unrecognised builder namespace is classified as meta-based rather than plain, deliberately. Refusing by shape rather than by name keeps the guard working for a builder RankX AI has never seen.

Editing a block-based builder page, by a text patch or by adding or removing a block, has to be asked for explicitly on the change. It is never automatic, because WordPress re-validates a block when the editor next opens it, and a patch that upsets that check can be rebuilt from the block's stored attributes afterwards. Meta-based builder pages are refused whatever you ask for, and there is no override.

SEO metadata: it depends on your plugin, and the answer is actionable

With the RankX AI plugin installed, RankX AI writes your SEO title and meta description whatever SEO plugin you run. Without it, writability depends on how your SEO plugin stores those fields and whether it exposes them over the REST API, and RankX AI checks that for you per content type.

PluginWritable over the REST API?
YoastUsually, and it varies per content type. Yoast registers three keys itself, and measured on a real site they were on posts and not on pages, so writability is resolved per type and never from the site-level flag, which reported writable for that same site
Rank MathNot by default, because its fields are not exposed to the API. Exposing them makes them fully writable
SEOPressSame as Rank Math
All in One SEONot without the RankX AI plugin. It stores metadata in its own database tables rather than in post meta, so a REST write returns success and persists nothing. Without the plugin, RankX AI refuses rather than appearing to succeed
Any of them, with the RankX AI pluginYes. The optional RankX AI plugin writes the SEO title and meta description through Yoast, Rank Math, SEOPress, All in One SEO or The SEO Framework, or on a site with no SEO plugin, with no snippet to add, and RankX AI still reads every value back

If your plugin's fields are not exposed, RankX AI does not simply report a flat "cannot write". It tells you which of the possible reasons applies, and where the fix is a small registration snippet it gives you that snippet with your site's actual field names in it, in the form that will parse wherever you paste it.

The remedy travels with the refusal, on the tool that hit the wall, rather than sitting on a different screen, so whoever meets the refusal also gets the fix.

Two things the snippet deliberately leaves out, and both are safety rather than oversight. It does not expose the robots field, because that field can be stored as an array and declaring the wrong type can stop a post opening in the editor at all. And it does not expose the focus keyword, because making a field readable over the API makes it publicly readable, and for an agency that would publish every page's target keyword to anyone who asks.

The optional RankX AI plugin

The RankX AI plugin is a free companion plugin for WordPress that runs beside whatever SEO plugin you use and extends what the RankX AI connection can do. It is optional: every feature on this page works without it, and a site without it keeps exactly the behaviour described above. Installed, it adds:

  • SEO title and meta description through every major SEO plugin. Yoast, Rank Math, SEOPress, All in One SEO and The SEO Framework, or a site with no SEO plugin at all, with no registration snippet to add.
  • Redirects with Rank Math, or with no redirect plugin. The RankX AI plugin adds redirects to Rank Math's own Redirections list, or keeps them itself and answers only for addresses that would otherwise show "page not found". With the Redirection plugin installed, no RankX AI plugin is needed for redirects.
  • llms.txt, agents.md and ai.txt served from your site's own root, published from RankX AI in one click. A file or plugin that already serves one of those addresses keeps it, and RankX AI tells you which.
  • A markdown copy of each page for AI assistants, off until you switch it on, held out of search results, and never made for a page marked noindex.
  • A count of which AI crawlers fetch which pages, which the site's administrator switches on in the plugin's own screen. RankX AI shows the counts on AI Readiness beside which assistants cite your pages. The counts cover the visits that reach WordPress, so treat them as a floor: a page cache or firewall that answers a crawler first serves visits WordPress never sees.
  • Site checks and View as AI in the plugin's own RankX AI menu in wp-admin, including what an assistant is given for each post and page.

How to get it. The plugin is a free download inside RankX AI: on a connected WordPress site that does not have it, the Website's WordPress connection settings offer Download the plugin. In your WordPress admin, go to Plugins, then Add New Plugin, then Upload Plugin, choose the file, then Install Now and Activate. Back in RankX AI, press Test to confirm RankX AI can see it. New versions then appear on your Plugins screen with the usual update link.

After a successful write

A verified write means RankX AI confirmed the change in the database, through the REST API. That is the signal that catches a plugin returning 200 while persisting nothing, and it is the right one.

It does not mean your visitors see the change yet. A page cache in front of your site can serve the old version for as long as its own rules say, and RankX AI appends a note saying exactly that to every successful content or SEO write rather than letting you discover it on the live URL.

Disconnecting

Revoke RankX AI's entry under Application Passwords in your WordPress profile. One-click approval names that entry RankX AI; on the manual route it carries the name you gave it. That is the whole disconnection: RankX AI holds no other credential for your site, and every subsequent call fails cleanly.

Removing the connection inside RankX AI is worth doing too, so the Website stops offering publishing actions that can no longer work.

Where to go next

Last updated