AI Can Now Edit Your WordPress Website. What That Means for Small Businesses

The failure nobody reported

In July 2026 Automattic, the company behind WordPress.com, ran a webinar for agencies showing what AI assistants can now do on WordPress sites. One example from their hosting side stuck with me. An online shop reported every payment as successful, customers’ cards were charged, but the orders were never written to the system. Nobody had reported it. It only came to light when an AI assistant went through several client sites on a Friday evening.

That was a vendor demo, not an independent test. The point behind it still holds for any small business website on the Costa Blanca: the expensive failures are the quiet ones. A contact form that hasn’t sent an email in three weeks. A booking plugin that stalls after an update. A hacked site quietly serving spam links. You see none of it. Things just go a bit quiet.

This article covers what changed in WordPress in 2026, why it is mostly a question of access and upkeep, and six things you can check yourself without any technical background.

What changed: AI no longer just reads, it acts

Until recently, AI was a reader of your website. ChatGPT, Perplexity and Google read your pages and summarised them. That is what most writing on AI visibility has been about, including my own piece on how AI reads your website to name your business.

Now there is a second role: AI as an editor. Three steps made that possible.

  • WordPress 6.9 (December 2025) added the Abilities API to core. Put simply, it is a directory of what a WordPress site can do, written so that software can understand it too.
  • The official MCP adapter connects that directory to AI assistants. MCP (Model Context Protocol) is an open standard that lets tools such as Claude or ChatGPT work with other systems. Think of it as a standard plug socket.
  • WordPress.com switched on write access in March 2026. An AI assistant there can now create posts and pages, reply to comments, reorganise categories and fill in missing image descriptions across the media library, all from instructions in plain language.

What they got right

To be fair, WordPress.com built this carefully. It is limited to paid plans and has to be switched on deliberately, site by site and function by function. Before every change the assistant describes what it is about to do and asks for confirmation. New posts are saved as drafts, deleted items go to the bin first, and every action is recorded in the activity log.

Most importantly, the assistant respects user roles. An editor account can edit posts but cannot change settings. A contributor account can write drafts but cannot publish anything.

Automattic also argues that AI models are especially good at WordPress because hardly any platform on the internet is so well documented. That sounds plausible, but it is the vendor’s claim, not a measured fact.

The real question: who holds the keys?

This is where it starts to matter for you. An AI assistant has exactly the permissions of the account it is connected to. If it is connected to an administrator account, it can in principle do anything an administrator can: install plugins, create users, change settings.

Most business websites on the Costa Blanca do not run on WordPress.com. They sit with a host such as IONOS, Raiola or all-inkl, with a purchased theme and a handful of plugins. There, an AI connection usually runs through a plugin and an access key that someone creates in a user profile. The WordPress.com safeguards do not come along automatically. What is allowed depends on whoever sets it up.

That makes an old question more pressing, and plenty of owners already struggle to answer it: who actually has access to my site? A typical picture around here: the site was built in 2019 by a friend who has since moved back home, and their administrator account still exists. An agency was given a login for an SEO project, and it was never removed. Nobody is quite sure of the owner’s own password any more.

If someone offers to “connect AI to your website”, ask which account it will use and what that account is allowed to do. That goes double for offers that arrive by email. How to tell a dubious AI offer from a sound one is covered in AI-visibility offer by email for 99 euros: legit or not?

Launch was never the hard part

The best line in the Automattic webinar was almost a throwaway: launching a website was never the hard part. The hard part is everything after.

The numbers behind that come from Patchstack, a security company that tracks vulnerabilities in the WordPress ecosystem. According to its State of WordPress Security in 2026 report:

  • 11,334 new vulnerabilities were found in the WordPress ecosystem in 2025, 42% more than the year before.
  • 91% of them were in plugins, 9% in themes. WordPress core itself had just six, all of low importance.
  • For 46%, the developer had no fix available at the time the vulnerability was made public.
  • For the most heavily targeted flaws, the median time from disclosure to the first attacks was just five hours.

What that means for you: WordPress itself is not the problem. The problem is the site nobody looks after. Every plugin that has been running untouched for years is a door, and every forgotten account is a key to it. AI assistants don’t change that. They make it more urgent, because a key can now be used by software as well as by people.

If you are reassessing your website anyway, website subscription or buy? looks at the question of who is actually responsible for upkeep once the site is live.

Six questions to settle this week

You don’t need technical knowledge for this, only your login to the WordPress dashboard.

  1. Who has an account? Under “Users” you can see all of them. Any account you can’t match to someone who still works with you today should be removed or downgraded.
  2. Are there access keys for software? Every user profile has a section called “Application Passwords”. It lists which programs may log in without a normal password. On WordPress.com, AI connections are listed in the MCP settings of your account.
  3. How many plugins are running, and what for? Under “Plugins” you will find the list. Deactivated plugins nobody needs any more are better deleted entirely. A plugin flagged as not updated in years deserves a conversation.
  4. Who installs updates, and when did it last happen? If the answer is “I think it happens automatically”, have a look under “Dashboard” and “Updates”.
  5. Would anyone notice if the contact form stopped sending? Send yourself a test enquiry once a month. It takes two minutes and catches the most common silent failure I come across on business websites.
  6. Is there a backup that has actually been restored at least once? A backup nobody has ever tested is a hope. Ask your host or whoever looks after the site when a restore was last tried.

If you are unsure about two or more of these, there is no need to panic. It is a reason to sit down and go through the site calmly with someone.

How I use AI myself

I work with AI tools every day, on websites too. They are quick at checking, sorting and routine work. What goes onto a client’s site and who gets which access is my decision, and it stays that way.

That is also how I read what is happening with WordPress. An AI assistant that checks several sites for errors overnight and writes a report in the morning can be genuinely useful for a small business. An assistant with administrator rights that nobody remembers setting up is the opposite.

If you are not sure who has access to your site right now, or when anyone last checked for updates, get in touch. I’ll look at your situation and tell you where I would start, even if the answer is that your site is in good shape.

Sources: Automattic, “Where WordPress fits in the age of AI” (23 July 2026, vendor statements); Patchstack, “State of WordPress Security in 2026”; WordPress.org, Make WordPress AI.

Share this article

Frequently asked questions

Can an AI change my WordPress website without me knowing?

Not on its own. An AI assistant needs a connection to your site, and someone has to set that up: on WordPress.com through a setting in your account, on self-hosted sites usually through a plugin and an access key. So the real question is who is allowed to create those connections, and whether you know which ones already exist.

What is MCP in WordPress?

MCP (Model Context Protocol) is an open standard that lets AI assistants such as Claude or ChatGPT work with other software. WordPress has had an official MCP adapter since 2025, and since March 2026 WordPress.com also allows write access: posts, pages, comments, categories, tags and media.

What permissions does an AI agent have on my WordPress site?

The permissions of the user account it is connected to. If the agent runs on an administrator account, it can in principle do anything an administrator can. If it runs on an editor account, it is limited to content. Anyone connecting AI should create a separate account for it with as few permissions as possible.

Is WordPress still a good choice for a small business website in 2026?

Yes, as long as someone looks after it. According to Patchstack, WordPress core itself had only six reported vulnerabilities in 2025, all minor. Almost all of the risk sits in plugins and themes. A WordPress site with a few up-to-date plugins and clear access is solid. One that nobody has touched in years is not.

Would you notice if your contact form had stopped sending enquiries weeks ago? Get a free website check →