{"id":359740,"date":"2026-09-08T09:28:47","date_gmt":"2026-09-08T09:28:47","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/siteself-connector\/"},"modified":"2026-10-01T16:20:41","modified_gmt":"2026-10-01T16:20:41","slug":"siteself-connector","status":"publish","type":"plugin","link":"https:\/\/oci.wordpress.org\/plugins\/siteself-connector\/","author":21039685,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.8.2","stable_tag":"0.8.2","tested":"7.1.2","requires":"5.6","requires_php":"7.4","requires_plugins":null,"header_name":"SiteSelf Connector","header_author":"Refact","header_description":"Connects this WordPress site to SiteSelf using authenticated, administrator-only REST API routes.","assets_banners_color":"","last_updated":"2026-10-01 16:20:41","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/siteself.com","header_author_uri":"https:\/\/refact.co","rating":0,"author_block_rating":0,"active_installs":0,"downloads":172,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.6.0":{"tag":"0.6.0","author":"refact","date":"2026-09-08 09:28:36","revision":3686296},"0.8.2":{"tag":"0.8.2","author":"refact","date":"2026-10-01 16:20:41","revision":3723469}},"upgrade_notice":[],"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.6.0","0.8.2"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[5590,2353,569,732],"plugin_category":[52],"plugin_contributors":[228522],"plugin_business_model":[],"class_list":["post-359740","plugin","type-plugin","status-publish","hentry","plugin_tags-agency","plugin_tags-ai","plugin_tags-automation","plugin_tags-maintenance","plugin_category-performance","plugin_contributors-refact","plugin_committers-refact"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/siteself-connector.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>SiteSelf is a service that works on your WordPress site for you \u2014 updating\ncontent, adjusting your design, keeping an eye on things \u2014 and reports back in\nchat. This plugin is the part that lives on your site, and it exists so your\nagent can work on your theme and plugin files rather than content alone.<\/p>\n\n<p><strong>What it can do<\/strong><\/p>\n\n<ul>\n<li>Read and write files inside your themes and plugins folders<\/li>\n<li>Tell your agent how the site is built: WordPress and PHP versions, active\ntheme, installed plugins, and which company hosts the site<\/li>\n<li>Measure the site: how big its database tables and folders are, how much disk\nis free, and what limits the server's PHP runs under<\/li>\n<li>Make a backup on your own server before your agent changes your live site,\ncovering the database tables and theme or plugin files the change touches<\/li>\n<li>Change a short, fixed list of settings: whether search engines may index the\nsite, and, when Yoast SEO is active, the separator in its page titles<\/li>\n<li>Send SiteSelf a copy of your database and your site's code when SiteSelf\nbuilds a staging site from yours<\/li>\n<li>Clear caches<\/li>\n<li>Keep a log of everything it did, readable under Tools \u2192 SiteSelf<\/li>\n<\/ul>\n\n<p><strong>What it will not do, by design<\/strong><\/p>\n\n<ul>\n<li>It never runs code that is sent to it. There is no remote code execution.<\/li>\n<li>It never gives your agent a setting that holds a credential. The settings it\nreads are a short, fixed list that describe how your site is built, and it\nrefuses anything whose name looks like a key, token or password. The settings\nit changes are a fixed list too, each written the way WordPress's own\nsettings screens write it; it never takes a setting's name, SQL or code from a\nrequest.<\/li>\n<li>The files it writes for your agent are inside your themes and plugins folders\nonly. Both folders are resolved before anything is written, so <code>..\/<\/code> cannot\nclimb out of them, and a file that turns out to be a shortcut to somewhere\nelse (a symlink) is refused rather than followed.<\/li>\n<li>Its backups stay on your server, in a private folder outside the part of the\nserver your site is served from, and are never sent anywhere. If your server\nhas no such folder, it takes no backup and says why.<\/li>\n<li>It cannot edit files that WordPress itself would not let you edit. Whether a\nrequest is allowed is WordPress's decision, using the same permissions as its\nbuilt-in editors \u2014 so <code>DISALLOW_FILE_MODS<\/code>, <code>DISALLOW_FILE_EDIT<\/code>, a managed\nhost that switches file changes off, and multisite's rule that only a network\nadministrator may touch shared plugin files all apply here too.<\/li>\n<li>Before replacing a file it keeps a copy of the previous version, and it\nrefuses to save PHP that has a syntax error.<\/li>\n<\/ul>\n\n<p><strong>Staging sites<\/strong><\/p>\n\n<p>When SiteSelf builds a staging site from yours \u2014 a private working copy on\nSiteSelf's servers, where a change is made and checked before it is applied to\nyour live site \u2014 SiteSelf's own systems, never your agent, ask this plugin for\na copy of your database tables and your site's code: WordPress itself, your\nthemes, your plugins, must-use plugins and translations. Your uploads are not\ncopied; the staging site shows your live site's images. The plugin never sends\n    wp-config.php or a copy of it under another name, and it leaves out any file\nwhose name says it holds a credential (such as <code>.env<\/code> or an SSH key), any key\nfile that holds a private key, repositories, database dumps and logs, and tells\nSiteSelf which it left out. The database copy holds every one of your site's\ntables \u2014 so it includes whatever other plugins store there \u2014 except the two\nrows where this plugin keeps its own keys. Each copy is requested as a job that\nshows in the log under Tools \u2192 SiteSelf, and is sent in small pieces, each\nchecksummed; no file is written on your server to make it.<\/p>\n\n<p><strong>How access works<\/strong><\/p>\n\n<p>The plugin adds no new way into your site. Every request must come from a\nsigned-in WordPress user with the right permissions, using WordPress's own\napplication passwords \u2014 which you create, and can revoke at any time under\nUsers \u2192 Profile \u2192 Application Passwords. Deactivating this plugin disconnects\nthe site from SiteSelf and removes the application password it created.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects your site to <strong>SiteSelf<\/strong>, a service run by Refact at\nhttps:\/\/siteself.com. The plugin is the site-side half of that service and is\nnot useful without it.<\/p>\n\n<p>The plugin sends two kinds of request to SiteSelf at api.siteself.com, over\nHTTPS, and only when an administrator acts. It sends nothing on a schedule.<\/p>\n\n<ul>\n<li><strong>When you select Connect this site or Get a new key<\/strong>, it sends SiteSelf a\nnew application password for your WordPress account (with Connect this site\nonly), your username, this site's addresses, the public half of its identity\nkey, whether it uses Elementor, Divi or Beaver Builder, whether WooCommerce\nis active, whether your host marks it as a staging site, and the plugin's\nversion. SiteSelf answers with a one-time key.<\/li>\n<li><strong>When you select Disconnect or deactivate the plugin<\/strong>, it sends this site's\nid and addresses, why (disconnect or deactivate) and the plugin's version, so\nSiteSelf ends the connection on its side. No credential is sent.<\/li>\n<\/ul>\n\n<p>Both are signed with this site's identity key, whose private half never leaves\nyour server. Otherwise the plugin answers requests that SiteSelf makes to your\nsite, and only when they carry a signed-in WordPress user with administrator\npermissions \u2014 the application password, which you can revoke.<\/p>\n\n<p><strong>What leaves your site when SiteSelf asks.<\/strong> A status request returns a\ndescription of how this site is built:<\/p>\n\n<ul>\n<li>your site's name, home address, admin address and language<\/li>\n<li>your WordPress and PHP version numbers<\/li>\n<li>every plugin installed, with its version and whether it is active<\/li>\n<li>your active theme, its version, and whether it is a child theme<\/li>\n<li>which company hosts the site, any must-use plugins that identify them, and\nwhether the host reports this as a staging copy<\/li>\n<li>the server software string and the file path WordPress is installed at<\/li>\n<li>how many published posts and pages you have<\/li>\n<li>whether this site permits file changes<\/li>\n<li>a public key this plugin creates for the site, so that moving to a new\ndomain does not look like a different site. The matching private key never\nleaves your server \u2014 not to SiteSelf, not in any request.<\/li>\n<\/ul>\n\n<p>A measurement request returns the size of each of your database tables and\nhow many rows it has, the size of your WordPress, theme, plugin, content and\nuploads folders, the free space on your server's disk, your PHP version and\nlimits, whether scheduled tasks run, which drop-in files replace parts of\nWordPress (such as an object cache), and where a backup would be kept. It\nreturns sizes and counts, never what is in a table or a file.<\/p>\n\n<p>Other requests return the contents of a file inside your themes or plugins\nfolders, a folder listing, one of a short fixed list of WordPress settings\nthat describe how the site is built, or the current value of a setting the\nplugin can change. Anything whose name looks like a key, token, secret or\npassword is refused.<\/p>\n\n<p>The one exception is the staging site described above: when SiteSelf builds\none, it receives your database tables \u2014 which hold your content and whatever\npersonal data of your users your site stores, such as accounts and orders \u2014\nand your site's code, excluding uploads, <code>wp-config.php<\/code> and the files listed\nthere. Apart from that copy, this plugin sends no content, visitor data,\nanalytics or personal data of your users. Backups the plugin makes stay on your\nserver.<\/p>\n\n<p>Service terms: https:\/\/siteself.com\/terms\nPrivacy policy: https:\/\/siteself.com\/privacy<\/p>\n\n<!--section=installation-->\n<p>This plugin does nothing on its own. It is the site-side half of a service, so\nthere is a short setup after you activate it.<\/p>\n\n<ol>\n<li>Install and activate the plugin. It opens <strong>Tools \u2192 SiteSelf<\/strong>.<\/li>\n<li>Select <strong>Connect this site<\/strong>. The plugin creates an application password for\nyour account and sends it to SiteSelf, which answers with a key.<\/li>\n<li>Copy the key and paste it at https:\/\/siteself.com\/setup\/key.<\/li>\n<\/ol>\n\n<p>There are no settings to configure. <strong>Tools \u2192 SiteSelf<\/strong> shows what your agent\nhas done, the previous versions of any file it replaced, and a button that\ndisconnects the site.<\/p>\n\n<p>To stop it at any time: select Disconnect under Tools \u2192 SiteSelf, or deactivate\nthe plugin. Either tells SiteSelf and removes the application password the\nplugin created.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"can%20i%20see%20what%20the%20agent%20has%20done%3F\"><h3>Can I see what the agent has done?<\/h3><\/dt>\n<dd><p>Yes. Tools \u2192 SiteSelf lists every action with a timestamp.<\/p><\/dd>\n<dt id=\"how%20do%20i%20stop%20it%3F\"><h3>How do I stop it?<\/h3><\/dt>\n<dd><p>Select Disconnect under Tools \u2192 SiteSelf, or deactivate the plugin. Either\ntells SiteSelf, removes the application password the plugin created, and\ntakes effect immediately.<\/p><\/dd>\n<dt id=\"does%20it%20work%20without%20the%20siteself%20service%3F\"><h3>Does it work without the SiteSelf service?<\/h3><\/dt>\n<dd><p>No. This plugin is the site-side half of a service at https:\/\/siteself.com.<\/p><\/dd>\n<dt id=\"where%20are%20backups%20kept%3F\"><h3>Where are backups kept?<\/h3><\/dt>\n<dd><p>On your own server, never anywhere else: in WP Engine's private folder on WP\nEngine, and otherwise in a <code>siteself-backups<\/code> folder in your hosting account's\nhome folder or beside the WordPress folder, when that is outside what your site\nserves. To choose another, define <code>SITESELF_BACKUP_DIR<\/code> in <code>wp-config.php<\/code>. A\nbackup is hidden until it is complete and has been read back. The newest five\nare kept; older ones, and any left unfinished for two days, are removed, each\nwith a line in the log, and nothing else there is touched. Removing the plugin\nleaves them in place.<\/p>\n\n<p>If your site keeps its themes or plugins outside WordPress's own <code>wp-content<\/code>\nfolder, the plugin backs up the database only: a backup of those files could\nnot be put back where they are.<\/p><\/dd>\n<dt id=\"can%20it%20edit%20files%20if%20my%20host%20has%20locked%20them%20down%3F\"><h3>Can it edit files if my host has locked them down?<\/h3><\/dt>\n<dd><p>No, and that is deliberate. It asks WordPress the same question WordPress asks\nbefore showing you its own file editors. If your host or your <code>wp-config.php<\/code>\nhas switched file changes off, this plugin is refused too, and your agent will\ntell you which setting stopped it.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.8.2<\/h4>\n\n<ul>\n<li>Sites connected to SiteSelf before 0.7.0 now show as connected.<\/li>\n<li>Disconnecting also sends this site's addresses, so a staging copy of your\nsite is not taken for the live one.<\/li>\n<li>Read-only files are left unchanged, and <code>.phtml<\/code> and <code>.inc<\/code> files are checked\nfor PHP errors too.<\/li>\n<li>Other small fixes.<\/li>\n<\/ul>\n\n<h4>0.8.1<\/h4>\n\n<ul>\n<li>A file is saved in one step, so it is never left half-written.<\/li>\n<li>If a PHP change causes a fatal error on your home page, the previous version\nis put back.<\/li>\n<li>Credential files, such as <code>.env<\/code> files and private keys, are not read.<\/li>\n<\/ul>\n\n<h4>0.8.0<\/h4>\n\n<ul>\n<li>When SiteSelf builds a staging site from yours \u2014 a private working copy\nwhere a change is tried before it reaches your live site \u2014 the plugin sends\nit your database and your site's code in small, checksummed pieces, when\nSiteSelf's own systems ask; never your uploads, <code>wp-config.php<\/code> or a file\nthat holds a credential. See \"Staging sites\" above.<\/li>\n<li>Your agent can make a backup on your own server before it changes your live\nsite, covering the database tables and theme or plugin files the change\ntouches. Backups stay on your server, in a private folder, and are never\nsent anywhere; the newest five are kept.<\/li>\n<li>Your agent can change two settings through the plugin: whether search\nengines may index your site, and the separator Yoast SEO puts in page titles.\nEach change reads the setting first, is written the way WordPress's own\nscreens write it, and is read back. Every change and every refusal is in the\nlog under Tools \u2192 SiteSelf.<\/li>\n<li>The plugin can measure your site \u2014 the sizes of your database tables and\nfolders, free disk space and your server's PHP limits \u2014 so SiteSelf knows\nwhat a copy or a backup takes before it starts one.<\/li>\n<\/ul>\n\n<h4>0.7.2<\/h4>\n\n<ul>\n<li>No change for your site. The status the plugin reports to SiteSelf no longer\nincludes a setting that always read \"no\", whatever your server has. It was\nabout how that one request ran, not about your server, and it was misread.<\/li>\n<\/ul>\n\n<h4>0.7.1<\/h4>\n\n<ul>\n<li>No change for your site. Tools \u2192 SiteSelf now takes the SiteSelf address it\nnames, and the link where you paste your key, from the one address this copy\nof the plugin connects to, rather than writing them out separately. A copy\nthat SiteSelf's team points at its test service now sends its key there too.<\/li>\n<\/ul>\n\n<h4>0.7.0<\/h4>\n\n<ul>\n<li>Connecting your site is now one button. Press <strong>Connect this site<\/strong> and the\nplugin creates an application password for SiteSelf, sends it to SiteSelf\nwith your site's address, and shows you a connect key. Paste that key at\nsiteself.com and your site is connected. You no longer type your site's\naddress anywhere.<\/li>\n<li>Getting a new key does not create a new application password.<\/li>\n<li>Activating the plugin opens its screen, Tools \u2192 SiteSelf, once. Bulk\nactivation is left alone.<\/li>\n<li>The screen is shorter: three steps to connect, with what Connect sends one\nclick away.<\/li>\n<li>Disconnect and Deactivate are separate. A connected site shows Disconnect,\nwhich asks you to confirm and keeps the plugin active so you can connect\nagain. A site that is not connected shows Deactivate.<\/li>\n<li>Disconnecting keeps this site's SiteSelf identity, so connecting again is\nrecognised as the same site.<\/li>\n<li>A connected site says so at the top of Tools \u2192 SiteSelf, in green.<\/li>\n<li>Disconnect and deactivation now tell SiteSelf, so the site shows as\ndisconnected there too, and remove the application password the plugin\ncreated. Updating the plugin does not disconnect it.<\/li>\n<li>A connect key now works for a year, until it is pasted or replaced by Get a\nnew key.<\/li>\n<\/ul>\n\n<h4>0.6.1<\/h4>\n\n<ul>\n<li>No change to the plugin. A link in the repository's own README pointed at a\nfile that moved, and the version moves with any change inside the plugin\nfolder.<\/li>\n<\/ul>\n\n<h4>0.6.0<\/h4>\n\n<ul>\n<li>Closed a hole in the file rails. A file that was a shortcut to somewhere else\n(a symlink) could be written through, which meant a write inside your themes\nfolder could change a file outside it. Those are now refused. If you have\ndeliberately symlinked a theme or plugin file, your agent will now say it\ncannot write to it rather than quietly changing the file at the other end.<\/li>\n<li>File editing now uses exactly the permissions WordPress uses for its own\neditors. <strong>On a multisite network this is a real change<\/strong>: only a network\nadministrator can edit theme and plugin files now, because those folders are\nshared by every site on the network. A single-site administrator is\nunaffected. Sites whose host switches file changes off through a filter\nrather than a constant are now correctly refused as well.<\/li>\n<li>Tools \u2192 SiteSelf and your SiteSelf dashboard now report whether writes are\nactually permitted, rather than only whether the two <code>wp-config.php<\/code>\nconstants are set. The two can disagree, and it was the second one that was\nbeing shown.<\/li>\n<\/ul>\n\n<h4>0.5.0<\/h4>\n\n<ul>\n<li>Updates now come from WordPress.org, like every other plugin on your site.\nEarlier versions fetched their own updates from siteself.com because this\nplugin was not in the directory yet. Nothing changes on your Plugins screen \u2014\nthe update button is in the same place and works the same way.<\/li>\n<li>This is the last update that arrives from siteself.com. After it, your site\nchecks WordPress.org.<\/li>\n<\/ul>\n\n<h4>0.4.0<\/h4>\n\n<ul>\n<li>Your site can now tell SiteSelf who it is, so moving to a new domain no longer\nlooks like a different site. The plugin creates a key the first time SiteSelf\nasks about your site, and keeps it here. The private half never leaves your\nserver \u2014 not to SiteSelf, not in any request.<\/li>\n<li>Nothing else changes, and there is nothing to set up. If you move your site,\nrestore a backup, or your host makes a staging copy, SiteSelf can tell which\none is which instead of guessing from the address.<\/li>\n<li>Removing the plugin leaves the key in place, so reinstalling brings your site\nback as the same site. Disconnect, under Tools \u2192 SiteSelf, is what removes it.<\/li>\n<\/ul>\n\n<h4>0.3.0<\/h4>\n\n<ul>\n<li>Updates now arrive on your own Plugins screen. Earlier versions had no way to\ntell WordPress where newer copies live, so updating meant deleting the plugin\nand uploading a zip by hand. It is now an ordinary one-click update, and can\nbe turned on for automatic updates like any other plugin.<\/li>\n<\/ul>\n\n<h4>0.2.0<\/h4>\n\n<ul>\n<li>Renamed from \"Refact Agent Connector\" to \"SiteSelf Connector\", including the\nplugin folder and the REST namespace. WordPress treats a renamed plugin as a\ndifferent one, so this version had to be installed by hand alongside removing\nthe old one \u2014 the change in 0.3.0 exists so that never happens again.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>First release: status, file read\/write with backups, allowlisted settings\nreads, cache flush, and the activity log.<\/li>\n<\/ul>","raw_excerpt":"Lets your SiteSelf agent work on this site&#039;s theme and plugin files, with a log you can read and a one-click disconnect.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/oci.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/359740","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oci.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/oci.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/oci.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=359740"}],"author":[{"embeddable":true,"href":"https:\/\/oci.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/refact"}],"wp:attachment":[{"href":"https:\/\/oci.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=359740"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/oci.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=359740"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/oci.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=359740"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/oci.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=359740"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/oci.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=359740"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/oci.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=359740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}