Makes code changes recoverable, errors actionable and going live explicit, and adds the publishing and file tools agents were missing.
- PHP file writes, moves and deletes are syntax- and compile-checked, then the site is loaded with WordPress's edit-scrape check and a change that causes a fatal error is reverted.
- Tool errors include the real message and line. PHP execution rejects exit and die and reports wp_die(), indirect exits and fatal errors as tool errors.
- Edits to published, private or scheduled posts are saved as autosaves for review unless a status is passed. Scheduling requires a future date. Titles keep tag-like text and percent sequences.
- Content writes accept terms, featured images, slugs, publish dates and SEO meta. New tools list terms, import media with alt text, update media, and create, delete or move source files; must-use plugins are reachable and credential files are blocked by name.
- Each Application Password can be limited to some tool groups. The audit history records targets, the password used and denied calls. Diagnostics and a Test connection button explain connection failures.
- URL credentials are removed before dispatch, WP-CLI @aliases are rejected, and SITE_AGENT_ALLOW_EXECUTION=false blocks source editing, PHP and WP-CLI.
- Updates use WordPress's Update URI hook, cache failed checks, and keep validated metadata when the store is unreachable during an upgrade. Signed-package verification ships without an enforcing key.
Validation: 59 WordPress integration tests / 383 assertions on PHP 8.3 and 8.5 locally and on the CI matrix, 9 converter tests, PHP syntax and coding standards, runtime and translation freshness, an HTTP MCP smoke test on disposable WordPress including a real fatal-change rollback, and both release ZIPs.
The companion archive is separate from the installable WordPress ZIP. Site Agent does not implement OAuth.