Most WordPress security issues don’t come from WordPress itself — but from how a site is set up and maintained.
In this guide, we’ll explain how secure WordPress is, where real risks come from, and what steps you can take to reduce your chances of being hacked.
Yes — WordPress is secure by design. Vulnerabilities in WordPress core are relatively rare and are usually patched quickly when discovered. Security issues occur within the WordPress ecosystem, not the core platform itself.
Most successful attacks exploit:
People think WordPress isn’t secure because it’s widely used, frequently targeted, and transparent about vulnerabilities — not because the core software is weak.
Here’s what contributes to this WordPress myth:

WordPress core software is secure and actively maintained. Security issues in the core platform are relatively rare and typically patched quickly.
WordPress core security is supported by:
Most large-scale WordPress security issues do not originate in core software, but in plugins, themes, or poor site management.
WordPress core provides a secure foundation. But in practice, many security risks come from how a site is hosted and managed.
WordPress.com reduces those risks by handling key security layers for you.
It includes:
To keep your WordPress site secure, you need to reduce avoidable risk — the kind that comes from outdated software, weak access controls, and hosting environments without built-in security protections.
Let’s explore the key steps you can follow.
Create a unique, complex password for each user account. Avoid easily-guessed formats like “password123” which are susceptible to brute force hacking attacks.
Use WordPress.com’s built-in password generator to create strong credentials, and change your password immediately if you receive a suspicious activity alert.

Turn on two-factor authentication to add a second verification step to your login.
With 2FA enabled, logging in requires your password plus a one-time code from an authenticator app or SMS.
Even if someone obtains your password, they won’t be able to access your account without that code.

WordPress.com includes built-in two-step authentication. On self-hosted WordPress sites, you can enable 2FA through a security plugin.
Control who has access to your site and review user roles regularly.
Give each user their own account with the appropriate role. Avoid shared logins, and limit Administrator access to trusted users only.
At least once a month, go to Users → All Users and check:

Remove unused accounts or downgrade permissions if full access isn’t required.
Then, check your site’s activity logs regularly to see who logged in, what changed, and when.
If you notice unfamiliar logins, new admin users, or unexpected plugin or settings changes, reset passwords immediately and investigate.

Update your WordPress core, themes, and plugins as soon as new versions are released.
It’s essential since outdated software is one of the most common causes of WordPress security issues.
Only install plugins and themes from reputable sources like the WordPress.com plugin directory, prioritize those that are actively maintained, and delete anything you’re not using — inactive plugins and themes can still create risk.

If you’re using WordPress.com, core updates are handled automatically, and the Business plan and higher include managed plugin updates.
Many core features also come built into WordPress.com, so you don’t need to install as many plugins, which lowers your overall security risk.
On self-hosted WordPress sites, you’re responsible for monitoring and applying updates yourself.
Make sure your site uses HTTPS to encrypt data between your website and your visitors.
An SSL certificate protects sensitive information like login credentials and form submissions. Without it, browsers may label your site as “Not secure,” which can damage trust and expose user data.
You can verify SSL is active by checking for https:// and a padlock icon in your browser’s address bar:

All sites hosted on WordPress.com include a free SSL certificate enabled by default. On self-hosted WordPress sites, SSL must be configured through your hosting provider.
Make sure your site is backed up regularly so you can restore it if something breaks or your site is compromised.
Backups allow you to roll back to a clean version after a failed update, malware infection, or accidental change.
Look for solutions that offer automated backups and simple restore options — e.g., the JetPack plugin.

On WordPress.com, sites are backed up at the platform level, and Business and Commerce plans include real-time backups with one-click restores via Jetpack VaultPress Backup.
For self-hosted WordPress sites, you’ll need to install a backup plugin to achieve the same level of protection.
Opt for a trusted WordPress hosting provider with robust security features to ensure a safe environment for your website.
When choosing a web hosting provider, look for:
On WordPress.com, these layers are built into the platform, with additional security features powered by Jetpack — including activity logging, malware scanning, and real-time backups on eligible plans.

New threats emerge all the time, so we recommend keeping up to date on WordPress and website security issues.
You don’t need to become a web security expert. But you can follow the latest WordPress security news and check for issues that may concern your site’s security.
We recommend these sources for reliable WordPress security news:
Out of the box, and at its core, WordPress is highly secure. Vulnerabilities typically come from outdated plugins and themes, insecure hosting, or poor security practices.
According to Patchstack, “vulnerability management and mitigation (coupled with 2FA & session management) remain the most important proactive security measures.”
The simplest way to stay on top of these security habits is to use a hosting provider that handles them for you.
WordPress.com includes built-in protections like automatic core updates, free SSL, firewalls, malware scanning, activity monitoring, and backups — reducing the number of security tools you need to manage yourself.
]]>But after hours, he’s been working on something else.
His son Jäger races motorcycles. He is the 2025 FIM MiniGP Canada Champion — six wins, nine podiums in a single season — and has represented Team Canada at the FIM MiniGP World Final twice.
None of it lived anywhere the public could find. Sponsors had nowhere to land. Fans who couldn’t make it to events had nothing to follow.
“I’ve always had this vision in my head of creating a website for Jäger to showcase what he’s doing.”

Jason isn’t a web professional. But his employer had recently relaunched their business website on WordPress — and working through that process gave him a feel for the platform.
“I really found that WordPress’s format was really user-friendly. It was intimidating at first, but not stopping me from doing it.”
He signed up, picked a template, and started building on his own.
The setup was fast — no complicated hosting decisions to figure out, no technical configuration, just straight into building.
Then the WordPress.com team reached out about our Website Design Service. Jason said yes.
Jason shared his vision, and the WordPress.com design experts took it from there — helping him build the site and get it live.

Jason also got support from WordPress.com’s Happiness Onboarding team, who helped him think through the launch strategy.
“Nick Severson has been really helpful in walking me through the strategy for launching my website. I can’t say enough about that experience.”
For someone who doesn’t build websites for a living, that mattered.
Today, jagerstockillracing.com covers Jäger’s full championship history, a sponsor section, a merch store, race news, and a newsletter.

The big launch is still coming — podcast, social push, the works. The website is where it all points to.

Jason and Jäger’s story started on the track. Now there’s a website that shows the world what they’ve built.
WordPress.com’s Website Design Service pairs you with an expert who guides you through the whole build. You get a professional, fully managed website — no coding, no setup headaches, no doing it alone.
Just a site that’s live in days, with fast and secure hosting included.
Ready to launch yours?
]]>The challenge? Figuring out which SEO plugins actually move the needle versus which ones just clutter your dashboard.
We looked at WordPress.com usage data and user ratings, then I tested the top contenders myself. Here are the 12 SEO plugins worth installing, what each one does best, and which ones to skip:

Yoast SEO Premium is a reliable, safety-first plugin that prevents small SEO mistakes from compounding as your site grows. It provides real-time optimization feedback directly in your editor.
You can use this SEO plugin to optimize site pages for target keywords, generate SEO titles and meta descriptions, fix internal linking issues, manage redirects, and meet readability and technical SEO standards.
I found it most useful when maintaining or updating existing content on a website with limited content.
For example, when I tested it on an older site, it flagged broken links and surfaced inconsistent meta descriptions I had missed during regular publishing.


Pros:
Cons:

All-in-One SEO handles site-wide SEO setup with minimal input, then lets you step in and fine-tune details as your site grows.
During page-level edits, the optimization panel works like a checklist, grouping tasks into sections for schema markup, social previews, internal linking, metadata, and more.

It also includes AI tools that generate SEO titles, meta descriptions, FAQs, and key points — helping you structure content in a way that’s easier for both search engines and AI systems to understand.
The operational visibility stood out the most to me.
Built-in 404 monitoring and redirect management helped me catch and fix broken URLs immediately, without relying on Search Console or extra plugins.
Pros:
Cons:

The SEO Framework is a lightweight, automation-first SEO plugin that handles core SEO tasks quietly in the background without constant prompts, ads, or upsells.
When I first tested it on an inherited site, it automatically filled in titles and meta descriptions and generated an XML sitemap immediately, without any setup.

The one trade-off is that it doesn’t guide you step by step or score keywords. So, if you rely on prescriptive SEO prompts, know that this plugin is minimal by design.
The SEO Framework works best on performance-sensitive sites where speed and minimal overhead matter more than in-editor guidance.

Pros:
Cons:

Rank Math combines on-page SEO tools, schema markup, redirects, and basic technical SEO features into a single plugin — with many capabilities available on the free plan.
At the page level, Rank Math is highly directive. Each page includes a checklist and score that flag issues with title structure, focus keyword usage, and indexing before publishing.

Once schema templates are set up, you can reuse them across content types instead of configuring structured data page by page.

For the most part, visibility makes Rank Math powerful for scaling sites and teams, but it’s best for users who want active SEO guidance rather than hands-off SEO.
Pros:
Cons:

Google Site Kit pulls key data from Google tools like Search Console, Analytics, and PageSpeed Insights into your WordPress dashboard. You can monitor search performance and Core Web Vitals in one place.
When I installed it, I got a clear, high-level view of how my site was performing in Google, within minutes.
I could quickly see trends in search traffic and analyze technical aspects like the Core Web Vitals without jumping between dashboards.

All in all, Site Kit works best as a monitoring and context dashboard to identify where problems exist.
From there, you can dig deeper into Search Console or use dedicated SEO and performance plugins to address them.
Pros:
Cons:

Jetpack Boost improves Core Web Vitals using a small set of safe, automated performance optimizations, including Critical CSS, deferred JavaScript, and improved image loading.
When I tested it on a lightly optimized site, it immediately highlighted issues related to Critical CSS, deferred JavaScript, and oversized images.
Instead of tweaking dozens of technical settings, the SEO plugin focuses on a narrow set of optimizations designed specifically to safely improve Google’s performance metrics.

It’s a good fit for site owners who want quick, measurable improvements in Core Web Vitals with minimal effort.
Tip: The full Jetpack plugin also covers security, backups, analytics, and more. It’s included for WordPress.com users, with features like real-time backups and SEO support available on Business plans and higher.
Pros:
Cons:

SureRank keeps SEO basics in one place: titles and meta descriptions, social previews, sitemaps, and default schema.
When I tested it, the first audit surfaced a short list of fixes I could act on immediately. Then, the editor kept flagging common issues as I worked, like missing alt text, oversized images, or titles that ran too long.

It adds default schema (like BreadcrumbList and Article) and keeps your SEO titles/descriptions consistent with your social share previews.

Altogether, SureRank works best for small blogs, portfolios, and simple business sites that need essential SEO with minimal setup.
Pros:
Cons:

Xagio is an SEO system built for planning and managing SEO at the site level, not just optimizing individual pages.
When I tested it, this SEO plugin analyzed existing pages first and grouped them by the keywords they were already ranking for. It then surfaced where pages were competing with each other or missing clear search intent.

Instead of fixing posts individually, you work from a central planner where titles, descriptions, and headings can be updated across multiple pages at once.
This makes site-wide cleanup and restructuring far faster than editing pages manually.
Pros:
Cons:

Schema & Structured Data for WP & AMP is built for sites that need more control over structured data than most SEO plugins offer.
Instead of applying one generic schema type site-wide, it lets you assign schema by content type — so products, articles, FAQs, and How-To pages stay correctly marked up.
Once configured, those rules apply automatically across your site, keeping markup consistent and reducing manual work.
I especially like that you can add schema directly from the block editor using dedicated schema blocks, which is especially useful for FAQ, How-To, and review content.

Pros:
Cons:

The Smush plugin focuses on image optimization, automatically compressing images as you upload them to help pages load faster.
New uploads are optimized immediately, and oversized images are clearly highlighted as you browse the site, which makes performance issues easy to spot and fix.

For best results, I found that enabling both resizing and metadata removal had more impact than compression alone.
All in all, I found Smush works best on smaller or newer sites where ongoing uploads matter more than bulk cleanup.
Pros:
Cons:

Better Robots.txt lets you control how search engines and bots crawl your site directly from the WordPress dashboard — no file editing required.
It generates and serves a robots.txt file automatically, making it easy to update crawl rules, block unwanted bots, or add sitemap references without touching server settings.

Keep in mind that robots.txt controls crawling, not indexing. It works best for managing bot access and crawl behavior rather than hiding pages from search results entirely.
Tip: The plugin can also generate an llms.txt file. While not essential for SEO, it’s a useful addition if you want to prepare for how AI search engines like ChatGPT may discover content over time.
Pros:
Cons:

Redirection manages URL redirects and tracks 404 errors directly inside WordPress, without requiring server access or file edits.
As soon as it’s activated, it starts logging 404 errors and lets you create, edit, and test redirects from the WordPress admin.
What stands out is visibility: You can see which redirects are active, where users are hitting dead URLs, and whether rules are actually matching real traffic.

Overall, I found Redirection most useful during migrations or cleanups — when you’re handling lots of URL changes and need reliable 404 tracking in one place.
Pros:
Cons:
If you want a simple starting point for SEO plugins, focus on the essentials:
On WordPress.com, you already benefit from fast managed hosting, built-in security, SSL, sitemaps, and various Jetpack features.
These plugins don’t replace that foundation — they extend it where you need more control, insight, or flexibility.
]]>When I first learned to build WordPress sites, I had to stitch them together from different tools and vendors. Think of connecting your domain registrar to a hosting provider, installing backup, security, and performance plugins — that sort of thing.
When I switched to WordPress.com, the experience became entirely different. Here are 14 ways it makes site ownership easier.
On WordPress.com, getting a domain, hosting, security, backups, and performance are already configured.
Your site runs on WordPress-first infrastructure, built to handle updates, plugins, traffic spikes, and security without you having to tune the stack yourself.

Here’s what you get:
In short, instead of spending time setting up your site’s infrastructure, you can get online — and stay online — while focusing on growing your business.
On WordPress.com, AI helps you launch quickly — while still creating a real WordPress site you control.
Some AI website builders generate sites inside proprietary platforms, which can make it harder to customize, add advanced features, or move your site elsewhere later.
That’s different on WordPress.com.
The AI website builder creates your site using native WordPress functionality, including proven themes, patterns, and the Block Editor. Instead of generating loose code, it assembles your site from building blocks that are designed to work well together.
Because of that, you’re building directly on WordPress from day one. You can redesign, add features, or scale your site over time without rebuilding it from scratch.

And it doesn’t stop after launch. With the WordPress AI Assistant, the AI truly understands your site’s content and layout. You can use it to add smart improvements and optimize your site for better results.

On WordPress.com, success doesn’t create extra work or extra fees. When your site starts getting attention, you don’t need to scramble to keep it online or worry about sudden costs.
No matter if you have 10 visitors or 100,000, all WordPress.com plans come with:

That means you’ll never be forced to upgrade for performance reasons. While you can upgrade to a Business or Commerce plan for advanced features, your site will remain safe and stable on any plan.
WordPress.com connects your site to the AI tools you already use.
You can build themes and plugins with AI, connect Claude to analyze your real site data, or use the built-in WordPress AI Assistant directly inside your dashboard.
These integrations are officially supported and permission-based, so you control what AI can access.
Instead of copying content into a generic chatbot, AI works with your actual WordPress environment — your posts, pages, traffic data, and structure.

All this helps you focus on the actions, pages, content, and opportunities that actually drive business results.
That said, you don’t have to figure everything out alone.
With WordPress.com’s website design services, real WordPress experts build your site with you — refining your vision, making sure it looks professional, and helping you launch with confidence.
Take Jason, a WordPress.com user who wanted a website to support his son’s motorcycle racing journey. He worked directly with the WordPress.com team to refine the design and structure, so it felt credible and ready to launch.

But the help didn’t stop at launch. The team continued guiding him through SEO setup, plugin choices, and planning his rollout strategy.
That’s the difference. You’re not just buying a template. You’re getting real people who help you build it right — and stay available as your site evolves.
Every WordPress.com site is automatically backed up behind the scenes. You don’t need to install a plugin or set up a backup schedule — it’s handled for you.
On Business and Commerce plans, you can also restore your site yourself with one click — even if you can’t access your WordPress dashboard.

Like all other features, backups and restores happen on the platform level. This means you don’t need to log in to your site or server. Trust me, the last thing you want to do in this situation is struggle to get your website back.
WordPress.com keeps your site up to date automatically — without you managing core updates, plugins, themes, or server software.
On most setups, it’s your responsibility to update WordPress core, plugins, themes, and even PHP. On WordPress.com, that maintenance is handled for you and coordinated to reduce compatibility issues and update-related errors.
How so?
First of all, core website updates are applied automatically, as are new versions of plugins and themes. Server maintenance is also taken care of for you.

Because the platform and infrastructure are built to work together, updates are tested and coordinated before they reach your site. That reduces the chance of something breaking after an update.
And if you want more control, you still have it. For example, on Business and Commerce plans, you can change your PHP version from the site settings — no server access required.

On WordPress.com, security and performance are built in — so plugins serve to add features rather than fix fundamentals.
On many setups, you install plugins just to handle backups, security, or caching. Here, that infrastructure is already managed for you. For example, all WordPress.com sites come with Jetpack, which offers SEO tools, analytics, newsletter functionality, additional editor blocks, and more.
That means you can focus on adding capabilities instead — ecommerce, memberships, translations, forums, and more.

With access to over 50,000 plugins, you can shape your site around your goals, not around technical gaps.
With WordPress Studio, you can test changes on your own computer in the same environment your live site uses — then sync them when you’re ready.
This is more relevant to developers than beginners, but it’s useful to understand. Local development gives you a safe space to experiment, redesign pages, or test features without visitors seeing half-finished work.
The tricky part with local development is usually deployment. If your local setup doesn’t match your live environment, things can break when you push changes.
WordPress Studio solves that by mirroring your WordPress.com environment, making it much easier to move changes from local to live without surprises. It also comes with reusable site blueprints, shareable preview sites, and selective push and pull.

Tip: Other WordPress.com developer features include free staging sites, SFTP/SSH, WP-CLI, Git commands, and GitHub deployments.
Website performance and security are usually ongoing projects. But, as we’ve already settled, on WordPress.com this happens at the platform level, so you don’t have to worry about it at all.
Keeping a site fast and protected means adjusting cache plugins, configuring security tools, and monitoring logs over time. Here, that work happens behind the scenes.
Features that keep your site resilient include:
And if you ever need a hand, WordPress.com’s Happiness Engineers are available 24/7 to help.

Besides, WordPress is one of the most rigorously tested and actively maintained software projects in the world, with thousands of contributors and a dedicated security team.
On WordPress.com, that foundation is reinforced with managed infrastructure that keeps your site protected as you grow.
On WordPress.com, you can redesign, extend, and turn your site into something bigger without changing platforms or rebuilding from scratch.
Your website might start as a simple blog or portfolio. Later, you might add a shop, memberships, bookings, or a newsletter. On many setups, that means migrating systems, upgrading servers, or reworking your entire stack.
Here, you build on the same foundation.
You can refresh your design using native blocks, patterns, and themes — and use tools like newsletters. You can also add ecommerce, payments, or other features through plugins.

And you can do it all without touching hosting, security, or performance settings behind the scenes.
With WordPress.com, your content and data remain yours forever — and you can export them if you ever decide to move.
Some proprietary website builders make it difficult to take your site elsewhere, limiting how easily you can export your content, structure, or integrations. While self-hosting WordPress gives you full ownership, it also means full responsibility for managing everything.
WordPress.com runs on the open-source WordPress software, which means your content isn’t trapped in a proprietary system. If your needs change, you can export and migrate your site without rebuilding it from scratch.

On WordPress.com, most routine upkeep happens automatically, so you’re not constantly managing your site behind the scenes.
It’s great that WordPress and its components receive regular updates. But keeping WordPress core, themes, plugins, and infrastructure up to date can turn into an ongoing cycle of small tasks and checks.
Here, those updates — along with performance and security management — are handled for you.
That means less time maintaining your website and more time using it to move your work or business forward.

WordPress core is updated automatically on all plans; themes are maintained for you.
On Business and Commerce plans, plugins can be updated automatically as well. Server-level components like PHP are managed by WordPress.com behind the scenes.
Finally, WordPress.com also helps you seamlessly migrate your website, whether you do it yourself or with expert help.
Moving hosting providers comes with a long list of to-dos. You have to move all parts of your site, fix compatibility issues with the new environment, and cross your fingers that the website won’t go down during the switch.
To avoid this, on WordPress.com Business and Commerce, migration and launch happen as separate steps:

Your visitors won’t even notice the change. Better yet, you can choose the “do it for me” option and the WordPress.com team will handle the migration for you, and then guide you through the final steps.
The difference of hosting your site on WordPress.com versus elsewhere doesn’t come down to a single feature — it changes your entire experience of website ownership.
From the beginning, your site lives in an optimized, centrally managed environment that it never has to leave, no matter how much you grow.
This reduces the technical work necessary to keep it running smoothly, allowing you to focus on what really matters and moves the needle. At the same time, you retain full ownership and control over your site.
Ready to make this a reality for yourself?
]]>Since then, thousands of you have built blocks, shared feedback, and pushed the tool in directions we didn’t expect.
That enthusiasm kept us going. Here’s what’s new.
You can now upload reference images when describing your block. A Figma mockup. A screenshot of a design you like. A napkin sketch.
Upload it alongside your prompt and let Telex see what you’re imagining.
This helps most with complex layouts — or when you’re chasing a specific aesthetic. Instead of writing a detailed description of how every element should be arranged, just show it.
A picture is worth a thousand prompt words, or so they say.
One of our most requested features — editing blocks outside of Telex — is here.
Download your block, open it in VS Code, Cursor, or whatever you prefer (we’re not starting that debate), and make your changes. Then upload the zip back to Telex to keep refining with AI.

This round-trip workflow bridges AI generation and traditional development. It’s early days — we’ll keep improving it.
Version history now works better. When you restore a previous version, Telex creates a new version instead of overwriting your current work.
This means you can explore past iterations, compare approaches, and recover that thing you deleted three prompts ago.

Your past mistakes are now just research. Or as we call it: iterative development.
Telex is now available in 7 languages for you to create blocks and experiment.

We also fixed an issue where Japanese, Chinese, emoji, and other multi-byte characters weren’t streaming correctly.
We’ve also shipped a bunch of smaller fixes:
Telex is a living experiment. Your feedback shapes where it goes.
Spin up a block. Try the image upload. Tell us what’s working and what isn’t — in the comments or through the in-app feedback form.
]]>But something was missing.
“I really enjoyed thinking about very deep questions,” she says. “But I kind of missed the human element. I would get frustrated — why should a normal, everyday person care about this?”
That question led her toward science writing. And eventually, to a portfolio she built in an hour using our AI website builder.
To pursue her science writing dream, Lily built up slowly. Volunteer projects. Small bylines. Then, in late 2023, she applied to the AAAS Mass Media Fellowship — mostly as practice.
She got in.
Ten weeks at a public radio station in North Carolina, reporting on science. That was the moment it became real.
“This might actually be something I could do.”

But to get paid work, she needed a portfolio. A place to show her clips. Proof she could do the job.
She kept putting it off.
I had been dreading making the website — not because it would be so hard, but I just didn’t know exactly how to do it.
Then a deadline hit. An internship application. Four hours to finish everything — resume, cover letter, portfolio.
She opened WordPress.com, found the AI website builder, and started typing. About an hour later, her online portfolio was live.
It lowered the barrier for me to get started and get everything together.

She didn’t get that first job. But the website stuck around.
A few weeks later, another interview. They wanted writing samples. She sent the website immediately.
As a result, Lily got:
They asked for writing samples. I sent them my website. I got the contract.

Lily had been putting off her portfolio for too long. A deadline forced her hand — and the AI website builder got her there in an hour.
WordPress.com’s managed hosting also means she’s not dealing with updates or maintenance. She focuses on her career. The platform handles the rest.
Her story started in the lab. But her website is where the next chapter begins.
Yours can too.
]]>If you’ve used our AI website builder, you already know how easy it is to create a full site by having a conversation. Now, that same intelligence stays with you inside the editor and Media Library.
Unlike standalone AI tools, the WordPress AI Assistant works inside your site. It understands your content and layout and can take action where you’re already building — no copy-pasting, no prompt engineering, and no code to figure out what to do with.
Sites on WordPress.com’s Business or Commerce plans can now opt into the WordPress AI Assistant at no extra cost.
The new AI assistant will show up in a few places within your WordPress experience once enabled on each of your sites:

Get help with site-wide structure and design decisions, as well as content editing and refinement without leaving the editor. You can adjust layouts, styles, and patterns on your posts and pages just by talking — and see changes take shape as you work.
You can ask it to:

Create and edit images directly in your Media Library. The AI assistant helps you generate new visuals or make targeted edits to existing images, so your media stays consistent with your site’s look and brand. You can specify aspect ratios and image styles to have even more control over the final look.
This feature uses the latest Nano Banana models, bringing you added value without needing other subscriptions.
In your Media Library, click the “Generate Image” button. You can ask the assistant things like:

The block notes feature introduced in WordPress 6.9 lets you collaborate with teammates directly in the editor. The WordPress AI Assistant extends that same workflow with AI: ask questions in block notes and get answers with your content as context, including relevant links and info from external sources:
The WordPress AI Assistant works right inside WordPress, so you get help exactly where you’re building, writing, and editing.
You can opt-in in just a few clicks:

Alternatively, if you purchase a site built with our AI website builder, the AI assistant will be enabled automatically, regardless of which plan you choose.
Note that the AI assistant works best with block themes. If you’re using a classic theme, the AI assistant won’t appear in the editor. However, you can still generate and edit AI images in the Media Library.
Most tools stop after generating a site. Others give you a single chat box isolated from your workflow or one-off code you need to know what to do with.
The WordPress AI Assistant works inside your actual site, helping adjust blocks, shape layouts, write content, and guide decisions.
This is WordPress, now with intelligence built in — ready to help you create, design, and grow faster than ever. And just one of the many ways WordPress.com users will be empowered by AI this year.
]]>The good news? Your WordPress site can show up in both traditional Google results and AI-generated answers with a few practical tweaks.
In fact, most of what AI systems need already exists in WordPress — if you structure and use it properly.
This guide shows you how to optimize your WordPress site for AI search with nine simple steps.
Start each section with the main point, then add supporting details when creating content for your website.
AI systems extract information by scanning for direct answers and clear patterns. When you lead with the answer and use structured formatting, AI can quickly identify, extract, and cite your content.
Here’s an example of this answer-first approach: a question-based heading followed by a paragraph that starts with the most relevant details, then adds more context later.


Group related content into clear topic areas to demonstrate authority, and explicitly name the people, brands, tools, and concepts you’re discussing.
Entities are the specific elements AI systems look for to understand meaning and context, such as “Monday.com” as a product, “remote teams” as a concept, or “integrations” as a feature category.
When you organize website content around these entities and use consistent terminology, AI can map relationships between topics and understand your expertise.

Source: Ninja Promo


Add schema markup (structured data) — code that labels what type of content you’re publishing — to tell search engines and AI systems exactly what your pages are about.
For example, you can mark a page as a recipe, product review, or local business listing.

Schema isn’t a magic bullet (few things in SEO/GEO are), but it can help AI better understand your WordPress site and pages.
For example, a recent Semrush study found a correlation between schema use and AI citations, likely because schema adds context and credibility that AI systems can analyze.

Add FAQ sections with clear question-and-answer pairs that AI systems can easily extract and quote.
FAQs work well for AI search because they mirror how people ask questions conversationally. They also let you control how your answers are framed and presented.
For example, you can use FAQs to communicate your brand positioning in a structured way, such as in this article about picking a cloud GPU provider:


Add author information, credentials, and original thoughts to your website content so readers and AI tools know who wrote it and why they’re credible.
When you clearly show practical experience and expertise — what Google calls E-E-A-T (Experience, Expertise, Authoritativeness, and Trustworthiness) — both search engines and AI tools are more likely to trust and cite your content.
For example, DigitalOcean published original research testing AI detector accuracy on its company blog. It became one of the company’s top traffic drivers and eventually earned a citation from Cornell University.


For example, iFixit — an e-commerce and how-to site — extensively highlights the expertise of its writers:

This helps users trust the site when getting tips on fixing their electronics and sends positive signals to AI search engines.
Create clear, comprehensive About and Contact pages so visitors and AI systems can verify that you’re legitimate.
AI doesn’t just evaluate individual posts — it looks at your entire WordPress site to determine if you’re a trustworthy source.
Websites with transparent information about who runs them, how to reach them, and what they stand for earn more trust from both readers and search engines.
Here’s another great example of the About Us page from iFixit:


Pro tip: Your WordPress site’s trustworthiness also stems from external signals. To prove to AI search engines and Google that you’re credible, you need mentions and backlinks from outside sources, such as guest posts, media coverage, content creators, partners, and community platforms like Reddit.
If you run a local business, add location details, business hours, and customer reviews to show you’re a real, legitimate company.
Local business information strengthens trust for both physical storefronts and service-based businesses.
When AI search tools see consistent contact details, genuine reviews, and clear location data, they’re more confident mentioning your brand.
For example, here’s how Cha Cha Matcha showcases its address and other details on its website:



Remove technical barriers so search engines and AI tools can find and index your content.
For example, if your site blocks crawlers, loads slowly, or isn’t indexed, even great content stays invisible.
Reliable WordPress hosting solves most of these issues automatically by maintaining site speed, enforcing HTTPS, and ensuring reliable uptime.
Tip: For the best foundation, invest in a WordPress host that prioritizes performance and security. Managed WordPress hosting on WordPress.com includes caching, automated software updates, security, and performance optimization.
Tip: AI search relies on standard indexing, so avoid blocking AI bots unless the content is proprietary, paywalled, or sensitive. You can use the Block AI Crawlers plugin or Better Robots TXT plugin if needed.
Add images, diagrams, and screenshots that help readers understand your content, not just decorative stock photos.
Clear, explanatory visuals make complex topics easier to grasp. AI systems are also moving toward multimodal search, meaning they’ll increasingly interpret visual content directly.
For example, this article on how to use Google Colab for non-developers includes step-by-step screenshots that walk readers through the entire process:



An llms.txt file is an experimental way to tell AI tools which pages on your site matter most, such as your best guides, category hubs, and About page.
This isn’t a requirement, and AI systems aren’t obligated to follow it. Think of it like the early days of robots.txt — a suggestion, not a control mechanism.
Here’s how to do it in WordPress:
We explored the core steps to make your WordPress site visible in AI search: clear structure, credible authorship, organized content, and strong technical foundations.
Start with steps 1–5, then expand as you grow. The sooner you adapt to AI-driven search, the stronger your long-term visibility will be.
You don’t need a new strategy — just a more intentional approach. When your expertise is clear and your site is technically sound, AI systems can better understand and surface your content.
WordPress.com further supports this with secure managed hosting and publishing tools built for performance and reliability.
]]>Today, we’re releasing new Skills and a Claude Cowork plugin designed for vibe coders and anyone who wants to create WordPress themes, generate sites, and experiment with AI-assisted development. You’ll find that you don’t need to be technical at all.
These tools are in rapid development and changing constantly, but we wanted to get them into your hands now.
We believe this is where site building is headed.

This new Claude Cowork plugin turns a conversation with Claude into a fully built WordPress site. Describe what you want, and it creates a complete block theme and deploys it to a local site running in WordPress Studio.
For example:
/create-site A website for my fitness coaching business. I help busy professionals get strong without living at the gym. I want to book discovery calls and share workout tips.
Claude kicks off by asking you about your site and then provides multiple design options. Iterate until you are happy, and then a few minutes later, you have a full WordPress block theme.
WordPress Studio provides you with a preview link you can send to anyone, and it also allows you to easily sync your completed site with WordPress.com.
There are two parts to set up: WordPress Studio (which runs your site locally) and the Cowork plugin (which generates the theme). The whole process takes about 10 minutes.
First, download and install WordPress Studio (macOS only for now). Open Studio, go to Settings → Preferences, and click “Enable the studio command in the terminal.”
Then open your terminal and run:
studio --version
This confirms it’s working.
Next, connect Studio to Claude Desktop so Claude can create and manage your local WordPress sites.
In Claude Desktop, go to Settings → Developer → Edit Config, and add the following to your configuration file:
{"mcpServers": {"wordpress-studio-mcp-server": {"command": "node","args": ["/ABSOLUTE/PATH/TO/wordpress-studio-mcp-server/dist/index.js"]}}}
From here, replace /ABSOLUTE/PATH/TO/ with the actual path where you cloned the wordpress-agent-skills repo on your computer. For example:
/Users/yourname/projects/wordpress-agent-skills/studio-mcp/dist/index.js
Quit Claude Desktop and reopen it.
Finally, install the Cowork plugin. In Cowork, open the plugins menu at the bottom of the left sidebar, select Add to marketplace from GitHub, and paste:
https://github.com/Automattic/wordpress-agent-skills
Install the Create WP Site plugin.
That’s it.
Run the /create-site command in Cowork (or select it from the plugins menu) and describe the site you want to build.
*Note: This is a developer preview. Things will break, and results will vary. That’s expected — we’re sharing it early because we want your feedback. If you run into issues, file them on GitHub.
Alongside the plugin, we’re sharing the Skills that make it work. Skills are reusable instruction sets that teach AI assistants how to perform specific tasks — think of them as the next evolution of prompts.
We have skills for:
The best part is you can use these Skills just about anywhere, including ChatGPT, Codex, or your favorite vibe coding tool.
These Skills are in active development and changing weekly. But they’re already producing themes worth shipping, and we expect results to only improve.
We’re in a significant period of change. There’s uncertainty. But there’s also opportunity, especially for site builders willing to experiment.
Try the new tools. Break them. Tell us what’s missing. Help us make them better.
We have the hosting solutions to make it easy to take your AI-created sites and share them with the world.
And watch this space. Claude Cowork is just the start; we want to help you build WordPress sites with your AI agent of choice.
This guide shows you how to set up Claude Code and WordPress Studio to create working plugins with text prompts.
Claude Code is Anthropic’s AI coding assistant. WordPress Studio is a free local WordPress environment. Together, they let you go from idea to a working plugin in minutes — no deep coding knowledge required.
This walkthrough covers the complete setup and shows you how to build your first plugin.
Head to Claude Code and sign up for an account — you can choose any paid plan available.
Run the native installer from the setup page and follow the on-screen instructions to complete the installation.
The installation runs for a minute or two. When it finishes, Claude Code is ready to use.

Download WordPress Studio — it’s completely free and works on both Mac and Windows.
Install it, then create a new site. Give it any name you want — e.g., “My WordPress Website” works fine.

Because Studio runs locally on your computer, everything you build stays safely contained on your machine — so you can experiment with AI-generated plugins without risking a live website.
Using the Open in… options on the Overview tab in Studio, click Terminal. This will open a terminal window at your project file’s location.

Then, type claude. If it’s your first time, you’ll be prompted to log in to your Claude account and confirm that you trust the files in this folder.
Click Enter/Return on your keyboard to trust the folder, and you’ll see the welcome message.

In the Claude terminal, describe what you want. Give it some context about where you are and what you need. For example:
“We are in the root of the WordPress site folder. I want a simple plugin that prints out ‘Hello [Your Name]’ in the admin of the site.”

From here, Claude will ask some follow-up questions, create a plugin folder, and generate the complete plugin file with proper WordPress structure.

Go back to WordPress Studio and open your WordPress admin. Navigate to Plugins, find your new plugin, and activate it.

If the plugin works correctly, your custom message will appear at the top of the admin area — in our case, “Hello Nick” shows up as an admin notice.
If you haven’t changed your name, you may see it say “Hello admin.” Simply go to your Users list and change the name of your default user.

This is the simplest plugin possible, but it shows how fast you can build with Claude and WordPress.
From here, you can add more features.
Go back to the Terminal in your editor and ask Claude to add new functionality — settings pages, custom blocks, whatever you need.
As with any AI tool, experimenting with prompting will help you achieve better results:
Telex is another unique tool that helps you generate WordPress blocks with AI — and it’s completely free to use.
Just describe what WordPress block you want, and Telex builds it with a live preview in WordPress Playground.

Test it, refine it with follow-up prompts, then download it as a plugin and install it on your WordPress site.

You now have an AI-powered setup for building plugins for your WordPress site.
Start simple, then tackle more complex projects as you get comfortable.
And if you build something fun, share it in the comments — we’d love to see what you make.
]]>