The AI Agent in a 4-Million-Site Plugin Was Quietly Making Admin Keys. Here’s the Lesson.
I have Claude reading my email drafts, writing code on client sites, and building automations that touch client data I’d genuinely rather not lose sleep over. I say yes to AI access more than almost anyone I know. So when I tell you to slow down before you click “allow” on the next AI feature your software vendor ships, know that I’m the last person who gets to act holier-than-thou about it.
Which is exactly why the Rank Math story stopped me cold last week.
What actually happened
Rank Math is one of the biggest SEO plugins in WordPress, north of 4 million active installs. In late August, they shipped a feature called Support Agent: an AI assistant that could read your site to help answer support questions. Handy idea. Except when an admin opened the Help & Support screen, the plugin quietly generated a WordPress Application Password tied to that admin’s account and sent it to the parent company’s servers, according to reporting from Search Engine Journal. That credential inherited whatever permissions the admin had, which for most site owners means full admin. Not a login to some sandbox. The whole damn dashboard.
The consent screen existed. It just didn’t stop anything from happening before you clicked it.
Rank Math didn’t dig in and defend it. They paused the Support Agent, shipped a version that removes it entirely, and said the feature comes back once the permission flow is rebuilt so users are asked in plain language before any credential gets created. Search Engine Journal covered the walk-back too. That’s the right response. Genuinely. Nobody here is accusing anybody of malice. This reads like a team that moved fast on a good idea and skipped the part where they made sure people knew what they were agreeing to.
The bigger ripple: WordPress co-founder Matt Mullenweg reportedly called for mandatory security audits on any plugin that takes admin-level access to a site, using this exact controversy as the case study, per The Repository. When the guy who built the platform says “we need to check these,” that’s worth an owner’s attention even if you’ve never heard of Rank Math.
This isn’t an anti-AI post
I want to be clear about that, because it’d be easy to read this and think “see, AI is dangerous, avoid it.” I don’t believe that, and I write about using AI daily. This is about one specific, fixable thing: the difference between AI that drafts something for you to review, and AI that has the keys to the building.
A chatbot that writes your product descriptions can be wrong. Annoying, sure. Not catastrophic. An agent that can log into your site as an admin is a different category of risk entirely, and most owners have no idea which category the tools in their stack fall into.
A framework that isn’t complicated
Before you turn on any AI feature in a tool you already use — your SEO plugin, your CRM, your form builder, whatever — ask five questions:
What can it actually touch? Read access to analytics is not the same as write access to your user database. Find out specifically.
Does it draft, or does it act? A tool that suggests a fix and waits for you to click “apply” is fundamentally safer than one that just does the thing on its own.
**Did you say yes to this, specifically?** A general terms-of-service checkbox from onboarding six months ago doesn’t count. If a feature needs new access, it should ask you again, clearly, when it needs it.
Can you turn it off? If there’s no visible toggle, no clear list of what it created (application passwords, API keys, whatever), that’s a red flag on its own.
Who’s checking the vendor’s work? Independent audits, a security disclosure history, a track record of owning mistakes in public. Rank Math gets partial credit here for the fast reversal. Not every vendor will.
That’s it. It’s not a checklist you need a developer to run. You just have to actually run it, instead of clicking through the setup wizard because you want the shiny new feature working before lunch.
The honest part
I don’t have a clean line for where AI access should stop. Nobody does yet, not me, not Rank Math, not the platform itself. We’re all figuring this out in public, and some of the figuring-out is going to look messy from the outside, the way this did.
The mistake isn’t installing an AI feature. It’s not knowing your SEO plugin can log in as you. If you can’t answer “what does this thing have access to right now” for the tools already running on your site, that’s the actual gap — and it’s worth ten minutes to go find out.
If you want a second set of eyes on what your current stack can actually touch, that’s a conversation worth having before it becomes a headline. We do exactly that kind of AI consulting work, alongside the broader question of how many plugins is too many for your site to responsibly carry. And if you’re a developer wondering how this changes plugin development itself, I dug into that more directly in building a WordPress plugin in the age of AI.





