Integration
Connect WordPress for Managed Automation without sharing your normal password
The WordPress connection is the only integration that writes anything, so it is built with the most care. A companion plugin, separate machine credentials for provisioning and publishing, a restricted developer role, and short-lived signed sign-on — and never your own WordPress password.
View Managed AutomationSee how it works
- Companion plugin
- Separate machine credentials
- Custom developer role
- Single-use SSO
The only integration that writes
Search Console, Analytics, PageSpeed and CrUX are all read-only. WordPress is different: it is where content gets published and where implementation work happens. That difference justifies a considerably more careful design than a single API token in a settings field.
Three separations do most of the work. Machine activity is separated from human activity. Provisioning is separated from publishing. And the public author identity that appears on published articles is separated from both of the machine accounts that put it there.
Connection summary
| Item | Detail |
|---|---|
| Component installed | WindspeedSEO companion plugin |
| Your WordPress password | Never requested, stored or used |
| Machine credentials | Separate credentials for provisioning and for publishing |
| Human developer access | Short-lived, single-use signed sign-on; asymmetric signature verification preferred |
| Developer role | Custom SEO developer role; not the built-in Administrator role |
| Denied capabilities | WordPress user management; arbitrary plugin and theme code installation |
| Developer accounts | Individually mapped per person; no shared accounts |
| Publishing byline | Dedicated public author identity, separate from machine accounts |
| Revocation | Credentials revocable independently; connection removable at any time |
| Plans | Managed Automation only |
What happens through the connection
Provisioning
The companion plugin is installed and the provisioning credential establishes the SEO developer role and the connection configuration. This credential is separate from the one used for day-to-day publishing.
Publishing
Generated articles and featured images are published under the dedicated public author identity using the publishing credential. Author biographies use verified and approved facts only.
Developer implementation
Landing-page, technical and on-page work is assigned to a developer who opens your site through single-use signed sign-on into the restricted role. No standing session remains afterwards.
Verification
Deterministic validators confirm the change is live and correct. Anything not machine-checkable is flagged for manual QA. Only verified work is reported to you as complete.
See WordPress SEO automation for the capability view, how WindspeedSEO works for where this sits in the loop, or plans and pricing for what Managed Automation costs.
Frequently asked questions
How does the WordPress integration connect to my site?
Through a companion plugin installed on your WordPress site. The plugin establishes the connection, holds the verification logic for developer sign-on, and mediates the machine credentials used for provisioning and publishing.
It is required because publishing and implementation genuinely need to write to your site; every other WindspeedSEO integration is read-only.
Will I be asked for my WordPress password?
No. Not your password, and not an application password issued from your own account. The connection uses machine credentials created for the purpose, and human developers never receive a credential at all — they receive short-lived, single-use signed sign-on.
If any vendor asks you to paste your administrator password into their dashboard, that is worth refusing on principle.
Why are provisioning and publishing credentials separate?
Because they have different jobs and different risk profiles. Provisioning sets up roles and configuration; publishing creates and updates content. Separating them means either can be rotated or revoked without breaking the other, and a compromise of one does not automatically grant the capabilities of the other.
What can the SEO developer role do, and what can’t it?
It can perform the SEO implementation work it is assigned — editing content, on-page elements and the technical settings within its scope. It cannot manage WordPress users, and the plugin and theme code capabilities that would allow arbitrary code installation are denied, because those would let someone route around every other restriction.
It is a purpose-built role, not the built-in Administrator role renamed.
Do developers share a login to my site?
Never. Every human developer has an individually mapped WordPress user with the restricted SEO developer role, so every change on your site is attributable to a specific person. Shared accounts make attribution impossible and revocation unreliable.
How do I disconnect WordPress?
Remove the connection from your WindspeedSEO account, which revokes the machine credentials. Because developer access is short-lived and single-use rather than a standing session, there are no long-lived logins waiting to expire. The companion plugin can then be deactivated on your site.
Does the integration change my theme or install plugins?
No. The companion plugin is the only component installed, and the developer role explicitly denies the capabilities that would allow arbitrary plugin or theme code installation. Implementation work happens within content and configuration, not by installing software on your site.
Is the WordPress integration available on Insights?
No. Insights is read-only and advisory by design and never connects to your website. The WordPress integration exists on Managed Automation because that is the plan where WindspeedSEO publishes and implements.
Connect WordPress without handing over your password
Managed Automation includes the WordPress connection, publishing, developer implementation and QA verification at $299/month for one primary website.