Select one or more tags, then press “Search Plugins”

Find Plugin with any / all of the selected criteria
Search Plugin

RuleFence – AI Agent Control Wordpress Plugin - Rating, Reviews, Demo & Download

RuleFence – AI Agent Control Wordpress Plugin - Rating, Reviews, Demo & Download
No ratings yet
Free
Follow for free plugins, new theme releases and theme news

Plugin Description

Give an AI agent a WordPress login and it can do anything that login can do. The role is the only limit, and roles come in whole jobs: a Shop Manager can refund an order as easily as fix a typo in a product description.

RuleFence draws the line inside the job. Every agent gets its own identity and its own credential, so you can see which agent did something and not just which user. Every registered Ability gets a decision – allow it, hold it for a person, or refuse it outright – and a request that turns out riskier than the Ability looked can be escalated on the spot rather than waved through. One switch stops every agent on the site at once. All of it – the decisions, the requests, the refusals – lands in a signed record that cannot be edited afterwards, not even by this plugin.

In practice that reads like: this agent may look up orders and add notes to them, must ask a person before it changes an order’s status, and may never delete a product.

It connects to the clients people are actually using – Claude Desktop, Claude Code, Cursor, ChatGPT, anything else that speaks the Model Context Protocol, or plain REST. Setting up a connection ends with a configuration block you paste into the client, with the credential already in it.

It governs the WordPress Abilities API, so it covers whatever your plugins register – core, WooCommerce, your own – rather than a fixed list. That also sets the scale: a site whose plugins register a lot of Abilities has a lot for this to govern, and a site with none has little. WordPress 7.1 itself registers three, all read-only.

Abilities are what it governs, and that is worth being exact about. An agent’s credential is a WordPress user, so anything that user could already do through the ordinary REST API, it still can – the permission matrix is not in that path. What limits it there is the WordPress user you map the agent to, which is why this plugin asks for a least-privilege one, warns you when an agent is mapped to an administrator, and scores it in Readiness. WordPress capabilities are the ceiling; the matrix is how you carve out what an agent may do underneath it.

The rule everything else follows

An Ability nobody granted is refused. A new agent starts paused and is allowed nothing, and stays that way until you say otherwise, one Ability at a time. Nothing you install can widen that by accident, because nothing widens it except you.

What it does

  • Identity. Each agent is a managed identity with its own credential, mapped to a least-privilege WordPress user. You can see which agent did what, not just which user.
  • Permissions. A matrix of every registered Ability against every agent: allow, require approval, or block.
  • Approvals. A risky request stops and waits for a person. The approval is bound to the exact input it was granted for, so it cannot be reused for a different request.
  • Risk. A contextual engine reads the request itself – how many records, how large a change, how sensitive – and can make a decision stricter than the matrix, never weaker.
  • Previews. See what a write would do before it happens.
  • Activity and audit. Every decision is recorded with its reason, allowed or blocked, in a hash-chained trail that can prove it has not been edited.
  • Emergency controls. Stop every agent on the site immediately, or drop everything to read-only, in one click.
  • Readiness. A scored check of what still weakens the site, with the evidence behind each score.
  • Runtime verification. The governance controls are re-tested on the installed site rather than assumed.

Using it with Claude, ChatGPT, Cursor and other MCP clients

RuleFence is not the MCP server and does not pretend to be one. WordPress 7.1 registers Abilities, the official MCP Adapter publishes them over the Model Context Protocol, and an MCP client – Claude Desktop, Claude Code, Cursor, ChatGPT, Windsurf, whatever you use – calls them. RuleFence is the layer that decides which of those calls are allowed, which wait for you, and which are refused, and records all of it.

That means it governs whichever of those clients you connect, including more than one at a time, each with its own identity and its own credential that you can revoke on its own.

Setting up a connection ends with the endpoint, a username, an Application Password and a configuration block you paste straight into the client. A site with no MCP Adapter is still covered: the same credential works against the REST endpoint.

What this plugin is, and what a separate add-on adds

Everything above is this plugin. There is no licence key, no edition, and nothing in it that a payment unlocks – what you install is what you get, working, for as many agents as you care to run.

A separate paid add-on, RuleFence Pro, is available from rulefence.com and adds conditional policies and ready-made policy sets, a simulator that tries a draft policy against calls already recorded, a record of which rules actually fire, multi-step workflows with human checkpoints, undo and rollback, scheduling, email alerts and webhooks, approval routing, risk threshold and rate ceiling tuning, audit export, custom retention, saved activity views, reusable agent and permission profiles, and configuration transfer between sites. A further tier governs a multisite network: shared policies, one approval queue, a fleet inventory, and named site groups. It is a second plugin you install alongside this one; nothing about it is present here.

That is worth being plain about, because the two arrangements look similar from outside and are not. This plugin does not ship the paid features in a disabled state. The screens have no buttons that exist to tell you what something would cost, and no control is switched off waiting for a key.

What is never sold, in this plugin or that one: default-deny, human approvals, the signed audit chain, audit logging, secret redaction, emergency mode, WordPress capability checks, failing closed when audit integrity is unavailable, and session expiry. A security control that only works if you pay is not a security control.

External services

This plugin contacts nothing, ever. There is no analytics call, no version ping, no licence check and no webhook. Your agents, permissions, decisions and audit trail live in your own database and are never sent anywhere.

The two features that could make an outbound request – webhook notifications, and validating a licence key – both belong to the paid add-on. Neither is here, so there is no code in this plugin that could make a request even if something asked it to.

Agents reach your site from outside it, over the REST API, using an Application Password you issue and can revoke. That is inbound, and it is what the plugin exists to govern.

Screenshots

No screenshots provided


Reviews & Comments