AI Godmode

Free
Get it
Not published yet. This page is here while the first public release is prepared.

It Does Nothing On Its Own

AI Godmode has no MCP server of its own. It registers its sixty abilities with the WordPress Abilities API, and a separate MCP server plugin has to publish them to your AI as tools. Install it alone and nothing happens. Pair it with Easy MCP AI, which is what we test against, or one of the other servers listed on the Install tab.


From the project author, John P

You probably should not install this plugin.

Every other AI plugin for WordPress hands your assistant a pair of oven mitts. It can write a post. On a good day it can set the featured image. Then the site throws a 500 at three in the morning and your brilliant assistant tells you, very politely, what you should go and check for yourself.

That is not an assistant. That is a consultant with a clipboard.

I run a stack of sites with Claude as my partner, and I kept hitting the same wall. It could see the pretty half of WordPress and none of the machinery. No error log. No cron table. No database. No filesystem. Every actual problem ended with me doing the work while the smartest thing in the room watched me do it.

So I fixed that. Then I named it so nobody could install it by accident.

What This Plugin Does In A Nutshell

I took every function WordPress will let you call, dragged them all onto one slab, stitched them together, ran MCP through the whole assembly like lightning down a rod, and the thing sat up.

Your AI can now do anything you can do in wp-admin, plus the things you would normally need SSH and a database client for. Read the error log. Rewrite a file. Run a query. Install a plugin. Create a user. Fire a cron event. Execute PHP.

It is a monster. It is a useful monster, and like the original, the monster was never the problem. The problem was the guy who built it without thinking it through.

Which is why every ability ships switched off, why there is a master switch above those, and why everything it changes gets written to a log in your own Cloudflare account before it happens rather than after.

It is free, it is GPL, and it is not for everybody. That is the whole pitch.


From John P’s partner, Claude

60 abilities across eleven families. 23 of them only read. 37 can change something. Every one of them is off when you install the plugin, and the master switch above them is off too, so an ability runs only when both are on.

The switches are not the security boundary. Every ability checks a WordPress capability on every call, whatever the switches say, so a switched-on ability still refuses a caller who is not entitled to it. The switches decide what exists; WordPress decides who may use it.

What Is Covered

FamilyAbilitiesWhat it reaches
Options And Transients7The wp_options table and the transient cache. Secrets and salts are on a denylist these abilities refuse to touch.
Database5Direct SQL. Reads are capped and paged; writes are one statement at a time and audit logged.
Filesystem11Everything under the WordPress root. The root itself, wp-admin, wp-includes, the plugins folder and Godmode’s own folder are protected from moves and deletions.
Plugins6Install, update, activate, deactivate, delete. It refuses to deactivate or delete itself.
Themes5Install, switch, update, delete. It will not delete the active theme or its parent.
Users And Roles13Users, roles, capabilities and application passwords. It refuses to strip the last administrator’s manage_options.
Scheduled Events4The WP-Cron table: list it, fire a hook now, schedule one, remove one.
Diagnostics6The read-only view of the machine. This is the family that turns “it is broken” into “here is the line in the log.”
Arbitrary PHP1One ability, and the reason the plugin is named the way it is.
Reference1How the plugin works, in a form the assistant can read for itself instead of guessing.
Host Specific1Registers only when the matching host plugin is active.

The Details tab lists all 60 individually, with what each one does and whether it reads or writes.

The Off-Site Audit Log

Before a changing ability runs, the plugin writes what it is about to do to a Cloudflare Worker and R2 bucket in your own account, and writes the outcome after. Records are hash chained and the bucket carries an immutability lock, so a deleted or altered record leaves a hole you can see.

If that record cannot be written, the action is refused rather than run unlogged. A caller that genuinely has to proceed can pass acknowledge_unlogged, and that override is itself recorded as a gap marker. Reads are never blocked by it.

This is tamper evidence, not tamper proofing. It tells you afterwards that something happened and whether somebody tried to hide it. It does not stop anything. The plugin is a set of guards around a door you have deliberately unlocked, and run-php, once you switch it on, is a general purpose way around every one of them. That is what arbitrary code execution means, and pretending otherwise would be a lie told to sell a plugin.

What It Refuses To Do, Whatever You Switch On

  • Deactivate or delete itself.
  • Strip manage_options from the last administrator, or leave the site without one.
  • Move or delete the WordPress root, wp-admin, wp-includes, the plugins folder, or its own folder.
  • Read or write the secrets and salts on its denylist, including its own settings, through the option abilities.
  • Delete the active theme, or the parent of the active theme.
  • Make any outbound request except to the audit endpoint in your own Cloudflare account. There is no phone home, and there is no vendor in the loop.

AI Godmode is a personal project by John Pozadzides. Free, GPLv2 or later, and hosted here because it is not on the WordPress plugin repository.

All 60 abilities, by family. READ abilities cannot change anything on your site. WRITE abilities can, and every one of them is written to the off-site log before it runs. Both kinds ship switched off.

Options And Transients (7)

The wp_options table and the transient cache. Secrets and salts are on a denylist these abilities refuse to touch.

AbilityKindWhat it does
read-optionREADRead one option from wp_options by name. Secret and salt options are refused by the denylist. Read only.
write-optionWRITECreate or update one option in wp_options. Audit logged before execution. Refuses denylisted secret names. Returns the previous value for revert.
list-optionsREADList wp_options rows by name prefix or substring. Returns names, autoload flag and value length, never values. Denylisted names are marked.
delete-optionWRITEDelete one wp_options row by name. Returns the previous value so it can be restored with write-option. Denylisted names are refused.
transient-getREADRead one transient by key, with its expiry when stored in the options table. Denylisted keys are refused.
transient-setWRITECreate or replace one transient. expiration is seconds from now, 0 means no expiry. Denylisted keys are refused.
transient-deleteWRITEDelete one transient by key, or every expired transient when key is “*expired*”.

Database (5)

Direct SQL. Reads are capped and paged; writes are one statement at a time and audit logged.

AbilityKindWhat it does
db-list-tablesREADList every table in the WordPress database with engine, row estimate and size in bytes.
db-describe-tableREADColumns, types, keys and indexes of one table.
db-query-readREADRun one SELECT, SHOW, DESCRIBE or EXPLAIN statement. Rows are capped (default 100, max 1000). Password hashes and denylisted option or meta values are scrubbed.
db-query-writeWRITERun one non-SELECT statement (INSERT, UPDATE, DELETE, ALTER, CREATE, DROP, TRUNCATE, OPTIMIZE, REPAIR). Returns affected rows and insert id. Audit logged.
db-exportWRITEWrite a SQL dump of all tables, or the listed tables, to wp-content/uploads/godmode-exports (web access denied by .htaccess). Returns the relative path. Read it with fs-read or fetch it with fs-zip.

Filesystem (11)

Everything under the WordPress root. The root itself, wp-admin, wp-includes, the plugins folder and Godmode’s own folder are protected from moves and deletions.

AbilityKindWhat it does
fs-listREADList a directory under the WordPress root with type, size, permissions and modified time. Optional recursion with depth and entry caps.
fs-readREADRead a file under the WordPress root. Text is returned with secrets scrubbed (config passwords, salts, keys); binary as base64 when encoding is base64. Capped at 1 MB per call with offset for more.
fs-searchREADSearch file contents under a directory for a substring or regex. Returns matching lines (scrubbed) with file and line number. Skips files over 2 MB and binary-looking files.
fs-writeWRITECreate or replace a file under the WordPress root atomically (temp file then rename). An existing file is backed up into the web-denied uploads/godmode-backups directory unless backup is false. Content may be base64.
fs-mkdirWRITECreate a directory (and parents) under the WordPress root.
fs-copyWRITECopy a file or directory (recursively) to a new path under the WordPress root. Refuses to overwrite unless overwrite is true.
fs-moveWRITEMove or rename a file or directory under the WordPress root. Refuses protected directories (root, wp-admin, wp-includes, wp-content, plugins, AI Godmode itself) and refuses to overwrite unless overwrite is true.
fs-deleteWRITEDelete a file, or a directory when recursive is true. Refuses protected directories (root, wp-admin, wp-includes, wp-content, plugins, AI Godmode itself).
fs-chmodWRITESet permissions (octal string such as 0644 or 755) on a file or directory, optionally recursively.
fs-zipWRITECreate a zip archive of a file or directory under the WordPress root. The archive path must not exist.
fs-unzipWRITEExtract a zip archive under the WordPress root into a directory (created if missing). Entries that would escape the target are skipped and reported.

Plugins (6)

Install, update, activate, deactivate, delete. It refuses to deactivate or delete itself.

AbilityKindWhat it does
plugin-listREADList installed plugins with version, active state and available update.
plugin-installWRITEInstall a plugin from a wordpress.org slug or an https zip URL, optionally activating it. Refuses if the folder already exists.
plugin-activateWRITEActivate an installed plugin by folder, slug or folder/file.php. A fatal error on load is caught and reported and the plugin stays inactive.
plugin-deactivateWRITEDeactivate an active plugin. Refuses AI Godmode itself.
plugin-updateWRITEUpdate one plugin to the latest version wordpress.org (or its own updater) offers.
plugin-deleteWRITEDelete an inactive plugin (deactivate first). Refuses AI Godmode itself.

Themes (5)

Install, switch, update, delete. It will not delete the active theme or its parent.

AbilityKindWhat it does
theme-listREADList installed themes with version, active state, parent and available update.
theme-installWRITEInstall a theme from a wordpress.org slug or an https zip URL. Does not switch to it.
theme-switchWRITEMake an installed theme the active theme. Returns the previous theme so it can be switched back.
theme-updateWRITEUpdate one theme to the latest version offered.
theme-deleteWRITEDelete an installed theme that is not active and not the parent of the active theme.

Users And Roles (13)

Users, roles, capabilities and application passwords. It refuses to strip the last administrator’s manage_options.

AbilityKindWhat it does
user-listREADList users with roles, filtered by role or search, paged.
user-getREADFull profile of one user by id, login or email, including capabilities and public meta keys.
user-createWRITECreate a user. If password is omitted a strong one is generated and returned once. Default role is subscriber.
user-updateWRITEChange email, display name, url, password, or replace the role set of one user. Refuses to strip the administrator role from the last administrator.
user-deleteWRITEDelete a user, reassigning their content to another user id (or deleting it when reassign is omitted). Refuses the current user and the last administrator.
role-listREADEvery role with its capability list and user count.
role-createWRITECreate a role with a capability list, optionally cloning another role first.
role-deleteWRITERemove a role. Refuses built-in roles and roles that still have users.
role-add-capWRITEGrant capabilities to a role, or to one user when user is given.
role-remove-capWRITERevoke capabilities from a role, or from one user when user is given. Refuses to strip manage_options from the administrator role.
app-password-listREADApplication passwords of one user: name, uuid, created, last used. Never the secret.
app-password-createWRITECreate an application password for a user. The password is returned exactly once, in this response, and is never stored in clear text anywhere.
app-password-deleteWRITERevoke one application password by uuid, or all of a user’s when uuid is “*”.

Scheduled Events (4)

The WP-Cron table: list it, fire a hook now, schedule one, remove one.

AbilityKindWhat it does
cron-listREADEvery scheduled WP-Cron event with hook, next run, recurrence and args, plus the available schedules and whether cron is disabled.
cron-runWRITEFire one scheduled hook immediately in this request (with its args) and reschedule recurring events as WP-Cron would. Output and errors from the hook are captured.
cron-scheduleWRITESchedule a hook: once at a unix timestamp (or in delay seconds), or recurring on a named schedule (hourly, twicedaily, daily, weekly, or any registered one).
cron-unscheduleWRITERemove every scheduled occurrence of a hook (optionally only those with matching args).

Diagnostics (6)

The read-only view of the machine. This is the family that turns “it is broken” into “here is the line in the log.”

AbilityKindWhat it does
get-environmentREADReport WordPress, PHP, database, server and plugin runtime facts for this site. Read only.
site-healthREADRun WordPress Site Health direct tests (php version, https, loopback, updates, and so on) and return each result with its label and status.
php-infoREADPHP version, SAPI, loaded extensions, and key ini values (memory_limit, max_execution_time, upload sizes, and so on).
constantsREADValues of common WordPress constants (ABSPATH shown relative, WP_DEBUG, memory limits, multisite, and so on). Database and secret constants are redacted.
hooks-inspectREADList the callbacks attached to one action or filter, in priority order, with a readable name for each.
error-log-tailREADReturn the last N lines of the active PHP or WordPress debug log (wp-content/debug.log or the ini error_log). Lines are scrubbed of secrets.

Arbitrary PHP (1)

One ability, and the reason the plugin is named the way it is.

AbilityKindWhat it does
run-phpWRITEExecute PHP code as an administrator inside WordPress. The code runs in a function scope; return a value to get it back as “returned”, echo to get “output”. Errors are caught and reported. This is total control of the site: audit logged, and refused when the log is unavailable unless acknowledge_unlogged is set. Do not paste code you have not read.

Reference (1)

How the plugin works, in a form the assistant can read for itself instead of guessing.

AbilityKindWhat it does
get-referenceREADHow AI Godmode works: the switch model, the audit log and acknowledge_unlogged, the secrets denylist, filesystem path rules, and the list of abilities by family. Read this first when unsure how a family behaves.

Host Specific (1)

Registers only when the matching host plugin is active.

AbilityKindWhat it does
siteground-purge-cacheWRITEFlush the SiteGround Speed Optimizer dynamic and file caches. Only present when Speed Optimizer is active.

Ability names are prefixed godmode/ on the Abilities API. Your MCP client may show them with its own prefix instead.

First, The Part People Trip Over

AI Godmode does not talk to your AI by itself. It registers its abilities on the WordPress Abilities API, which has been in core since 6.9, and a separate MCP server publishes those abilities as tools your assistant can call. If there is no MCP server on the site, installing this plugin will appear to do nothing at all.

Our recommendation is Easy MCP AI, free on the WordPress plugin repository. Every AI Godmode release is tested against it, and the steps below assume it. It is not the only choice: any MCP server that reads the Abilities API will publish Godmode’s abilities, and the ability names are the same whichever one you use.

Other Servers That Read The Abilities API

We have proven AI Godmode with Easy MCP AI only. The three below read the same Abilities API and should work; we have not tested them with this plugin ourselves yet, so treat them as options, not recommendations.

  • The official WordPress MCP Adapter, installed from its GitHub releases page. The WordPress project’s own reference implementation. It publishes the abilities a plugin marks public and serves them at /wp-json/mcp/mcp-adapter-default-server; remote AI clients reach it through Automattic’s mcp-wordpress-remote proxy with an application password.
  • Agent Abilities for MCP, free on the WordPress plugin repository. Built on the official MCP Adapter, with a screen where abilities from other active plugins can be switched on one at a time. Connects by OAuth or an application password.
  • mcp-wp-abilities, a small Node program that runs on your own computer, with nothing installed on the site. It discovers the site’s abilities through WordPress core’s own REST routes using an application password and publishes them to a local client such as Claude Desktop, so the credential never leaves your machine. One release so far (1.0.1, December 2025).

Not on the list: plugins such as Enable Abilities for MCP that register abilities of their own but still need one of the servers above to reach your AI.

Requirements

  • WordPress 6.9 or newer.
  • PHP 8.0 or newer.
  • A Cloudflare account for the off-site audit log. The free tier is enough and it does not ask for a card.
  • An AI client that speaks MCP. This was built and tested against Claude.

Setup

  1. Install and activate Easy MCP AI and connect it to your AI client, following its own setup under Easy MCP AI › API Token & OAuth.
  2. Install AI Godmode through Plugins › Add New › Upload Plugin and activate it. Nothing is armed and nothing is switched on.
  3. Go to Settings › AI Godmode and set up the off-site log first, on the Off-site Log tab. You paste a Cloudflare API token with three permissions, the plugin builds the Worker and the bucket for you, and it shows you a viewer key exactly once. Put that key in your password manager when it appears, because the site never stores it.
  4. Switch on only the abilities you actually need. Leave the rest off. You can come back for more later.
  5. Arm the master switch. Nothing runs until you do.
  6. Go to Easy MCP AI › Abilities and enable the Godmode abilities there as well. Write tools are off until you tick them. This is the step people miss.
  7. Reconnect your AI client so it picks up the new tool list.

Download

AI Godmode 0.6.3 is the current release: download ai-godmode-0.6.3.zip. Install it through Plugins › Add New › Upload Plugin, or unzip the ai-godmode folder into wp-content/plugins. sha256 d440431bd790da5ca48d38da20b95a34de560d7224ce2d5e765900ddcaf43fe0. GPLv2 or later.

0.6.2 and 0.6.3 are a security release, and every earlier version should be replaced. They came out of an independent audit: an armed assistant could switch on more of its own abilities, some file reads could return configuration secrets unscrubbed, a file copy could put wp-config.php where the web server would serve it, and a masked setting written back could overwrite the real secret. All of it is fixed, and each fix has a test that fails on the older versions.

If Something Looks Wrong

The plugin tells you when it is in trouble in two places that are hard to ignore: a banner you can dismiss for twelve hours, and a red mark on the Settings menu that stays until the problem is actually fixed. A WRITE ability showing WARNING means that ability is being refused right now because the off-site log has stopped recording. A clean screen means the log is working.

You are about to give a machine the keys to your website. Read this bit.

A well directed AI with this plugin installed will fix in four minutes what used to cost you a Saturday. It will find the fatal in the error log, trace it to the snippet, patch the file, clear the cache and tell you what it did, while you are still looking for your coffee.

A badly directed one will drop a table in about the same four minutes. It will do it cheerfully. It will then report success, because from where it is standing the statement ran fine.

Both of those are the same plugin. The difference is entirely in what you switched on, what you asked for, and whether you were paying attention. There is no setting that supplies judgement.

Before You Switch Anything On

  • Get real backups. Off the server, automatic, and restored at least once so you know the restore works. A backup you have never restored is a rumour. This is not optional, and it is the thing that turns a catastrophe into a bad afternoon.
  • Get a security audit. Not because this plugin opens a hole, but because it raises the value of every hole you already have. An attacker who gets an administrator account inherits everything you have switched on here.
  • Fix your passwords. Long, unique, in a password manager, two factor on every administrator account, and application passwords revoked when they are done. The whole security model of this plugin rests on the assumption that only the right people hold administrator credentials.
  • Start with the reads. Switch on the diagnostics family and nothing else for a week. It is the most useful family anyway, and it cannot change a thing.
  • Leave run-php until last, if you turn it on at all. Everything else in this plugin is a specific action with specific guards. That one is a blank sheet of paper.

What This Plugin Will Not Save You From

  • A correct instruction you did not mean. The plugin cannot tell the difference between the delete you wanted and the delete you regret.
  • An assistant that is confidently wrong. The audit log records that it happened, not that it was a good idea.
  • Anyone who already has your administrator password.
  • Yourself, at two in the morning, when you decide to arm everything and see what happens.

The off-site log is there for one scenario: something with administrator access does something catastrophic and the local record cannot be trusted, because whatever did the damage could edit it. Most of the time it is an insurance policy sitting in a drawer. The day you need it, nothing else will do.

If that all sounds like a lot of responsibility for a free plugin, good. That is the correct reaction, and it is why the plugin is called what it is called.