Title: SiteSelf Connector
Author: Refact
Published: <strong>8 setembre 2026</strong>
Last modified: 1 octobre 2026

---

Search plugins

![](https://s.w.org/plugins/geopattern-icon/siteself-connector.svg)

# SiteSelf Connector

 Per [Refact](https://profiles.wordpress.org/refact/)

[Download](https://downloads.wordpress.org/plugin/siteself-connector.0.8.2.zip)

 * [Details](https://oci.wordpress.org/plugins/siteself-connector/#description)
 * [Reviews](https://oci.wordpress.org/plugins/siteself-connector/#reviews)
 *  [Installation](https://oci.wordpress.org/plugins/siteself-connector/#installation)
 * [Development](https://oci.wordpress.org/plugins/siteself-connector/#developers)

 [Support](https://wordpress.org/support/plugin/siteself-connector/)

## Descripcion

SiteSelf is a service that works on your WordPress site for you — updating
 content,
adjusting your design, keeping an eye on things — and reports back in chat. This
plugin is the part that lives on your site, and it exists so your agent can work
on your theme and plugin files rather than content alone.

**What it can do**

 * Read and write files inside your themes and plugins folders
 * Tell your agent how the site is built: WordPress and PHP versions, active
    theme,
   installed plugins, and which company hosts the site
 * Measure the site: how big its database tables and folders are, how much disk
   
   is free, and what limits the server’s PHP runs under
 * Make a backup on your own server before your agent changes your live site,
    covering
   the database tables and theme or plugin files the change touches
 * Change a short, fixed list of settings: whether search engines may index the
   
   site, and, when Yoast SEO is active, the separator in its page titles
 * Send SiteSelf a copy of your database and your site’s code when SiteSelf
    builds
   a staging site from yours
 * Clear caches
 * Keep a log of everything it did, readable under Tools  SiteSelf

**What it will not do, by design**

 * It never runs code that is sent to it. There is no remote code execution.
 * It never gives your agent a setting that holds a credential. The settings it
   
   reads are a short, fixed list that describe how your site is built, and it refuses
   anything whose name looks like a key, token or password. The settings it changes
   are a fixed list too, each written the way WordPress’s own settings screens write
   it; it never takes a setting’s name, SQL or code from a request.
 * The files it writes for your agent are inside your themes and plugins folders
   
   only. Both folders are resolved before anything is written, so `../` cannot climb
   out of them, and a file that turns out to be a shortcut to somewhere else (a 
   symlink) is refused rather than followed.
 * Its backups stay on your server, in a private folder outside the part of the
   
   server your site is served from, and are never sent anywhere. If your server 
   has no such folder, it takes no backup and says why.
 * It cannot edit files that WordPress itself would not let you edit. Whether a
   
   request is allowed is WordPress’s decision, using the same permissions as its
   built-in editors — so `DISALLOW_FILE_MODS`, `DISALLOW_FILE_EDIT`, a managed host
   that switches file changes off, and multisite’s rule that only a network administrator
   may touch shared plugin files all apply here too.
 * Before replacing a file it keeps a copy of the previous version, and it
    refuses
   to save PHP that has a syntax error.

**Staging sites**

When SiteSelf builds a staging site from yours — a private working copy on
 SiteSelf’s
servers, where a change is made and checked before it is applied to your live site—
SiteSelf’s own systems, never your agent, ask this plugin for a copy of your database
tables and your site’s code: WordPress itself, your themes, your plugins, must-use
plugins and translations. Your uploads are not copied; the staging site shows your
live site’s images. The plugin never sends wp-config.php or a copy of it under another
name, and it leaves out any file whose name says it holds a credential (such as `.
env` or an SSH key), any key file that holds a private key, repositories, database
dumps and logs, and tells SiteSelf which it left out. The database copy holds every
one of your site’s tables — so it includes whatever other plugins store there — 
except the two rows where this plugin keeps its own keys. Each copy is requested
as a job that shows in the log under Tools  SiteSelf, and is sent in small pieces,
each checksummed; no file is written on your server to make it.

**How access works**

The plugin adds no new way into your site. Every request must come from a
 signed-
in WordPress user with the right permissions, using WordPress’s own application 
passwords — which you create, and can revoke at any time under Users  Profile  Application
Passwords. Deactivating this plugin disconnects the site from SiteSelf and removes
the application password it created.

### External services

This plugin connects your site to **SiteSelf**, a service run by Refact at
 https://
siteself.com. The plugin is the site-side half of that service and is not useful
without it.

The plugin sends two kinds of request to SiteSelf at api.siteself.com, over
 HTTPS,
and only when an administrator acts. It sends nothing on a schedule.

 * **When you select Connect this site or Get a new key**, it sends SiteSelf a
    
   new application password for your WordPress account (with Connect this site only),
   your username, this site’s addresses, the public half of its identity key, whether
   it uses Elementor, Divi or Beaver Builder, whether WooCommerce is active, whether
   your host marks it as a staging site, and the plugin’s version. SiteSelf answers
   with a one-time key.
 * **When you select Disconnect or deactivate the plugin**, it sends this site’s
   
   id and addresses, why (disconnect or deactivate) and the plugin’s version, so
   SiteSelf ends the connection on its side. No credential is sent.

Both are signed with this site’s identity key, whose private half never leaves
 
your server. Otherwise the plugin answers requests that SiteSelf makes to your site,
and only when they carry a signed-in WordPress user with administrator permissions—
the application password, which you can revoke.

**What leaves your site when SiteSelf asks.** A status request returns a
 description
of how this site is built:

 * your site’s name, home address, admin address and language
 * your WordPress and PHP version numbers
 * every plugin installed, with its version and whether it is active
 * your active theme, its version, and whether it is a child theme
 * which company hosts the site, any must-use plugins that identify them, and
    whether
   the host reports this as a staging copy
 * the server software string and the file path WordPress is installed at
 * how many published posts and pages you have
 * whether this site permits file changes
 * a public key this plugin creates for the site, so that moving to a new
    domain
   does not look like a different site. The matching private key never leaves your
   server — not to SiteSelf, not in any request.

A measurement request returns the size of each of your database tables and
 how 
many rows it has, the size of your WordPress, theme, plugin, content and uploads
folders, the free space on your server’s disk, your PHP version and limits, whether
scheduled tasks run, which drop-in files replace parts of WordPress (such as an 
object cache), and where a backup would be kept. It returns sizes and counts, never
what is in a table or a file.

Other requests return the contents of a file inside your themes or plugins
 folders,
a folder listing, one of a short fixed list of WordPress settings that describe 
how the site is built, or the current value of a setting the plugin can change. 
Anything whose name looks like a key, token, secret or password is refused.

The one exception is the staging site described above: when SiteSelf builds
 one,
it receives your database tables — which hold your content and whatever personal
data of your users your site stores, such as accounts and orders — and your site’s
code, excluding uploads, `wp-config.php` and the files listed there. Apart from 
that copy, this plugin sends no content, visitor data, analytics or personal data
of your users. Backups the plugin makes stay on your server.

Service terms: https://siteself.com/terms
 Privacy policy: https://siteself.com/
privacy

## Installacion

This plugin does nothing on its own. It is the site-side half of a service, so
 
there is a short setup after you activate it.

 1. Install and activate the plugin. It opens **Tools  SiteSelf**.
 2. Select **Connect this site**. The plugin creates an application password for
     your
    account and sends it to SiteSelf, which answers with a key.
 3. Copy the key and paste it at https://siteself.com/setup/key.

There are no settings to configure. **Tools  SiteSelf** shows what your agent
 has
done, the previous versions of any file it replaced, and a button that disconnects
the site.

To stop it at any time: select Disconnect under Tools  SiteSelf, or deactivate
 
the plugin. Either tells SiteSelf and removes the application password the plugin
created.

## FAQ

### Can I see what the agent has done?

Yes. Tools  SiteSelf lists every action with a timestamp.

### How do I stop it?

Select Disconnect under Tools  SiteSelf, or deactivate the plugin. Either
 tells
SiteSelf, removes the application password the plugin created, and takes effect 
immediately.

### Does it work without the SiteSelf service?

No. This plugin is the site-side half of a service at https://siteself.com.

### Where are backups kept?

On your own server, never anywhere else: in WP Engine’s private folder on WP
 Engine,
and otherwise in a `siteself-backups` folder in your hosting account’s home folder
or beside the WordPress folder, when that is outside what your site serves. To choose
another, define `SITESELF_BACKUP_DIR` in `wp-config.php`. A backup is hidden until
it is complete and has been read back. The newest five are kept; older ones, and
any left unfinished for two days, are removed, each with a line in the log, and 
nothing else there is touched. Removing the plugin leaves them in place.

If your site keeps its themes or plugins outside WordPress’s own `wp-content`
 folder,
the plugin backs up the database only: a backup of those files could not be put 
back where they are.

### Can it edit files if my host has locked them down?

No, and that is deliberate. It asks WordPress the same question WordPress asks
 
before showing you its own file editors. If your host or your `wp-config.php` has
switched file changes off, this plugin is refused too, and your agent will tell 
you which setting stopped it.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“SiteSelf Connector” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ Refact ](https://profiles.wordpress.org/refact/)

[Translate “SiteSelf Connector” into your language.](https://translate.wordpress.org/projects/wp-plugins/siteself-connector)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/siteself-connector/),
check out the [SVN repository](https://plugins.svn.wordpress.org/siteself-connector/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/siteself-connector/)
by [RSS](https://plugins.trac.wordpress.org/log/siteself-connector/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 0.8.2

 * Sites connected to SiteSelf before 0.7.0 now show as connected.
 * Disconnecting also sends this site’s addresses, so a staging copy of your
    site
   is not taken for the live one.
 * Read-only files are left unchanged, and `.phtml` and `.inc` files are checked
   
   for PHP errors too.
 * Other small fixes.

#### 0.8.1

 * A file is saved in one step, so it is never left half-written.
 * If a PHP change causes a fatal error on your home page, the previous version
   
   is put back.
 * Credential files, such as `.env` files and private keys, are not read.

#### 0.8.0

 * When SiteSelf builds a staging site from yours — a private working copy
    where
   a change is tried before it reaches your live site — the plugin sends it your
   database and your site’s code in small, checksummed pieces, when SiteSelf’s own
   systems ask; never your uploads, `wp-config.php` or a file that holds a credential.
   See « Staging sites » above.
 * Your agent can make a backup on your own server before it changes your live
    
   site, covering the database tables and theme or plugin files the change touches.
   Backups stay on your server, in a private folder, and are never sent anywhere;
   the newest five are kept.
 * Your agent can change two settings through the plugin: whether search
    engines
   may index your site, and the separator Yoast SEO puts in page titles. Each change
   reads the setting first, is written the way WordPress’s own screens write it,
   and is read back. Every change and every refusal is in the log under Tools  SiteSelf.
 * The plugin can measure your site — the sizes of your database tables and
    folders,
   free disk space and your server’s PHP limits — so SiteSelf knows what a copy 
   or a backup takes before it starts one.

#### 0.7.2

 * No change for your site. The status the plugin reports to SiteSelf no longer
   
   includes a setting that always read « no », whatever your server has. It was 
   about how that one request ran, not about your server, and it was misread.

#### 0.7.1

 * No change for your site. Tools  SiteSelf now takes the SiteSelf address it
    names,
   and the link where you paste your key, from the one address this copy of the 
   plugin connects to, rather than writing them out separately. A copy that SiteSelf’s
   team points at its test service now sends its key there too.

#### 0.7.0

 * Connecting your site is now one button. Press **Connect this site** and the
    
   plugin creates an application password for SiteSelf, sends it to SiteSelf with
   your site’s address, and shows you a connect key. Paste that key at siteself.
   com and your site is connected. You no longer type your site’s address anywhere.
 * Getting a new key does not create a new application password.
 * Activating the plugin opens its screen, Tools  SiteSelf, once. Bulk
    activation
   is left alone.
 * The screen is shorter: three steps to connect, with what Connect sends one
    click
   away.
 * Disconnect and Deactivate are separate. A connected site shows Disconnect,
    which
   asks you to confirm and keeps the plugin active so you can connect again. A site
   that is not connected shows Deactivate.
 * Disconnecting keeps this site’s SiteSelf identity, so connecting again is
    recognised
   as the same site.
 * A connected site says so at the top of Tools  SiteSelf, in green.
 * Disconnect and deactivation now tell SiteSelf, so the site shows as
    disconnected
   there too, and remove the application password the plugin created. Updating the
   plugin does not disconnect it.
 * A connect key now works for a year, until it is pasted or replaced by Get a
    
   new key.

#### 0.6.1

 * No change to the plugin. A link in the repository’s own README pointed at a
    
   file that moved, and the version moves with any change inside the plugin folder.

#### 0.6.0

 * Closed a hole in the file rails. A file that was a shortcut to somewhere else
   (
   a symlink) could be written through, which meant a write inside your themes folder
   could change a file outside it. Those are now refused. If you have deliberately
   symlinked a theme or plugin file, your agent will now say it cannot write to 
   it rather than quietly changing the file at the other end.
 * File editing now uses exactly the permissions WordPress uses for its own
    editors.**
   On a multisite network this is a real change**: only a network administrator 
   can edit theme and plugin files now, because those folders are shared by every
   site on the network. A single-site administrator is unaffected. Sites whose host
   switches file changes off through a filter rather than a constant are now correctly
   refused as well.
 * Tools  SiteSelf and your SiteSelf dashboard now report whether writes are
    actually
   permitted, rather than only whether the two `wp-config.php` constants are set.
   The two can disagree, and it was the second one that was being shown.

#### 0.5.0

 * Updates now come from WordPress.org, like every other plugin on your site.
    Earlier
   versions fetched their own updates from siteself.com because this plugin was 
   not in the directory yet. Nothing changes on your Plugins screen — the update
   button is in the same place and works the same way.
 * This is the last update that arrives from siteself.com. After it, your site
    
   checks WordPress.org.

#### 0.4.0

 * Your site can now tell SiteSelf who it is, so moving to a new domain no longer
   
   looks like a different site. The plugin creates a key the first time SiteSelf
   asks about your site, and keeps it here. The private half never leaves your server—
   not to SiteSelf, not in any request.
 * Nothing else changes, and there is nothing to set up. If you move your site,
   
   restore a backup, or your host makes a staging copy, SiteSelf can tell which 
   one is which instead of guessing from the address.
 * Removing the plugin leaves the key in place, so reinstalling brings your site
   
   back as the same site. Disconnect, under Tools  SiteSelf, is what removes it.

#### 0.3.0

 * Updates now arrive on your own Plugins screen. Earlier versions had no way to
   
   tell WordPress where newer copies live, so updating meant deleting the plugin
   and uploading a zip by hand. It is now an ordinary one-click update, and can 
   be turned on for automatic updates like any other plugin.

#### 0.2.0

 * Renamed from « Refact Agent Connector » to « SiteSelf Connector », including 
   the
    plugin folder and the REST namespace. WordPress treats a renamed plugin 
   as a different one, so this version had to be installed by hand alongside removing
   the old one — the change in 0.3.0 exists so that never happens again.

#### 0.1.0

 * First release: status, file read/write with backups, allowlisted settings
    reads,
   cache flush, and the activity log.

## Mèta

 *  Version **0.8.2**
 *  Last updated **3 jorns ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.6 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/siteself-connector/)
 * Tags
 * [agency](https://oci.wordpress.org/plugins/tags/agency/)[AI](https://oci.wordpress.org/plugins/tags/ai/)
   [automation](https://oci.wordpress.org/plugins/tags/automation/)[maintenance](https://oci.wordpress.org/plugins/tags/maintenance/)
 *  [Advanced View](https://oci.wordpress.org/plugins/siteself-connector/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/siteself-connector/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/siteself-connector/reviews/)

## Contributors

 *   [ Refact ](https://profiles.wordpress.org/refact/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/siteself-connector/)