🔥 Early bird prices end soon — save up to 51%
This plugin is going to revolutionise the way WordPress websites are made
Get Early Bird Price
Real Help — Real Fast

WordPress for Cowork
Support

Walkthroughs, fixes, and how-to guides — all in one place.

Browse the docs below, search the knowledge base, or ask the AI chat — it’s trained on these docs and answers most questions instantly.

Open an account first. An account at /my-account/ is what unlocks everything after purchase:
  • Download the plugin and your licence key any time
  • Plugin updates and release notes
  • Support tickets tied to your license
  • Member-only updates, coupons, and renewal offers

Getting Started

Prerequisites

Before you begin, make sure you have the following:

  • A Claude account — any plan, including Free (one website). Works in Claude on the web, the desktop app, the mobile apps and Cowork.
  • A WordPress site running on HTTPS
  • wordpress-for-cowork.zip and your licence key — both on your My Account page

Step 1: Install the plugin on your WordPress site

WordPress for Cowork is a normal WordPress plugin. You upload it in wp-admin like any other.

  1. Download wordpress-for-cowork.zip from your My Account page.
  2. In wp-admin, go to Plugins → Add New → Upload Plugin and choose the file.
  3. Click Install Now, then Activate.

Step 2: Paste your licence key

A Cowork menu appears in your wp-admin sidebar. Open it, paste your licence key (CW-XXXXXX-XXXXXX-XXXXXX) and save. The plugin validates it once, then sets itself up: it creates its own credentials and installs its endpoint. You should see Active and provisioned.

Step 3: Add your site to Claude

  1. Open the Cowork page in your WordPress admin. Click Cowork in the admin menu. The top of the page must say Active and provisioned. If it says anything else, fix that first — the page tells you what each message means.
  2. Copy your connection address from that page. It ends in /wp-json/coworkmcp/v1/mcp. Copy it rather than typing it — it has to match exactly.
  3. In Claude, open Customize → Connectors (Settings → Connectors on some versions), click +, then Add custom connector.
  4. Name it after your website and paste the address, then click Add. If you connect more than one site, the name is how Claude tells them apart — the Cowork page shows you exactly what to type.
  5. Connect, then sign in to your own website. Your site shows its normal WordPress login and then asks you to approve Claude. Press Allow. Your password is typed into your own site — Claude never sees it, and neither do we.

Then ask Claude: “What can you do on my website?” If it answers about your site by name, you are connected. There is no file to download, no restart and no new chat — the tools appear in the conversation you are already in.

You never hand over a password

You sign in to your own website once, on your site’s own login page, and press Allow. Your site then issues Claude its own access and checks it on every request. Your password is never given to Claude, and we never see it.

To disconnect, remove the connector in Claude (Customize → Connectors). Deleting the plugin from wp-admin also ends every connection to that site.

If it does not connect

Don’t guess, and don’t keep retrying. Go to Cowork → Run the check in your WordPress admin. It tests every step of the connection from your site’s side and tells you which one failed, including whether Claude ever reached your website at all.

  • No requests from Claude have reached your site — look at a firewall, a security plugin or Cloudflare. Claude connects from Anthropic’s servers, not from your computer, so anything that only allows your own IP address will block it. Anthropic publishes its outbound range as 160.79.104.0/21.
  • A step marked failed — that row names the step and the actual error. Send it to support and we will know exactly what happened.
  • Claude says the address could not be reached — copy it again from the Cowork page. A trailing slash, http instead of https, or www where your site has none will all do this.

If the Cowork page shows coworkmcp-endpoint.php missing, the licence has not been accepted — check the key and save again. Otherwise it is usually a security plugin or host firewall: see Plugin can’t connect? Check your security plugins first, further down this page.

Building & Design

How to build a page from a description

  1. Make sure your WordPress site is connected.
  2. Describe the page you want: “Build me a landing page for a photography service. It should have a hero section, a gallery grid, a pricing table, and a contact form.”
  3. Claude will generate the full HTML and CSS and create the page in WordPress.
  4. Review it live, then ask for any tweaks: “Make the hero text larger and center the pricing table.”

How to clone a site’s design using a URL

  1. Find a website whose style you’d like to match.
  2. Tell Claude: “Look at stripe.com and recreate that color palette and font style on my site.”
  3. Claude will fetch the site, extract its design tokens, and apply them to your WordPress theme.
  4. Review the result and refine: “Keep the font but use a darker background.”

How to update your site’s global theme

  1. Tell Claude what you want to change: “Update my site theme — dark background (#0d0d1a), white headings, purple accent (#7c3aed).”
  2. Claude will update your theme.json or inject global CSS as appropriate.
  3. Changes apply site-wide immediately. Ask Claude to revert if you don’t like the result.

Content & Publishing

How to write and publish a blog post

  1. Tell Claude the topic: “Write a 600-word blog post about why small businesses should use AI tools in 2025.”
  2. Claude will draft the post with a title, intro, body, and conclusion.
  3. Review and request edits: “Make the intro punchier and add a bulleted takeaways section at the end.”
  4. Say “Publish it” and Claude will push it live to your WordPress site.

How to add images to your content

  1. Once your post or page content is ready, ask: “Add a relevant featured image to this post.”
  2. Claude can source an image via URL or upload one you provide.
  3. To add an image inline: “Insert an image of a laptop after the second paragraph.”

How to update SEO metadata

  1. Tell Claude which page or post to update: “Update the SEO title and meta description for my About page.”
  2. Provide the text or let Claude generate it: “Write an SEO-optimized meta description for my homepage.”
  3. Claude will update the metadata via your SEO plugin (Yoast, Rank Math, or All-in-One SEO).

WooCommerce

How to manage products with Claude

  1. Tell Claude what you need: “Update the description for my ‘Leather Wallet’ product.”
  2. Claude will fetch the current product data and show you what it plans to change before making edits.
  3. You can batch updates too: “Update the price of every product in the ‘Summer Sale’ category to 20% off.”

How to check and update inventory

  1. Ask Claude: “Show me all products with stock under 10 units.”
  2. Review the list and say: “Set the stock for SKU WH-001 to 50.”
  3. Claude updates inventory in real time.

Site Management

How to back up your site

Automatic daily backups run on their own at ~3 AM site time — no setup needed after install. You can also trigger a backup any time by asking Claude.

Tell Claude: “Back up my site.” The plugin runs wp_backup server-side and saves a full JSON snapshot covering 12 content types: posts, pages, media, categories, tags, comments, menus, users, site settings, WooCommerce products, WooCommerce orders, and SEO metadata. The snapshot is .htaccess-protected on your server — not stored in a third-party cloud.

To list and restore: “Show me my recent backups” then “Restore from backup <ID>.” Claude calls wp_list_backups and wp_restore with the snapshot you choose.

Retention: the 5 most recent snapshots are kept automatically — older ones auto-prune. If you need long-term archival, run a backup before any major change so the latest stays in the rotation.

Pre-flight prompt: on the first destructive action in a Cowork session, the plugin asks if you want a backup first. Say yes once and you’re covered for the rest of the session.

How to manage users and roles

  1. Ask Claude: “Add a new editor user with the email [email protected].”
  2. Claude will create the user and send a welcome email.
  3. To change a role: “Change John’s role from Subscriber to Author.”

How to fix a broken layout

  1. Describe the problem in plain English: “The hero section on my homepage is overlapping the navigation on mobile.”
  2. Claude will inspect the page CSS and identify the likely cause.
  3. It will propose a fix and ask before applying it.

Troubleshooting

My plugin isn’t showing any tools

  • In Claude, open Customize → Connectors and check your site is listed and connected. If it shows as disconnected, click it and sign in again.
  • If you have several sites connected, make sure this one is switched on in the + menu of the conversation.

Claude says it can’t connect to my site

  • Go to Cowork → Run the check in wp-admin. It tests each step of the connection from your site’s side and names the one that failed.
  • Copy the connection address again from the Cowork page. A trailing slash, http instead of https, or www where your site has none will all fail.
  • Claude connects from Anthropic’s servers, not from your computer. A firewall or security plugin that only allows your own IP address blocks it — allow 160.79.104.0/21.
  • Make sure your site is on HTTPS.

Do I need an Application Password?

  • No. You never create one. The plugin creates its own credentials, and you connect Claude by signing in to your own site and pressing Allow.

A change was made that I want to undo

  • Tell Claude: “Undo the last change you made.”
  • For page edits, WordPress revision history also lets you roll back — go to Pages → Edit → Revisions in wp-admin.

Plugin can’t connect? Check your security plugins first.

The most common reason WordPress for Cowork fails to connect is a security plugin or firewall on your WordPress site blocking the requests Claude makes to your site. Claude connects from Anthropic’s servers, not from your computer. If your plugin says “Authentication failed” or “Could not connect to your site”, the fix is almost always one of these:

Wordfence Security

Wordfence’s Login Security module blocks Application Passwords by default in some configurations. Two ways to fix:

  • In wp-admin, go to Wordfence → Login Security → Settings. Find the option labelled “Disable XML-RPC authentication” and turn it off (Application Passwords use the WordPress REST API, but Wordfence’s blocker often catches them too).
  • If you’d rather keep that locked down: Wordfence → Tools → Allowlisted IPs, and add Anthropic’s published outbound range 160.79.104.0/21 — that is where Claude’s requests come from, not your own computer.

iThemes Security / Solid Security

Go to Security → Settings → Configure → WordPress Tweaks. Find “REST API” and ensure it’s set to “Default Access” (not “Restricted Access”). If you have “Disable XML-RPC” enabled, that one is fine — Application Passwords don’t use XML-RPC.

Sucuri Security

Sucuri’s WAF can rate-limit or block REST API traffic. In the Sucuri dashboard, allowlist Anthropic’s outbound range 160.79.104.0/21 (where Claude’s requests come from) under Firewall → Settings → Whitelist URL or IP. If you’re using Sucuri’s free plugin only (no WAF), no action needed.

WP Cerber

WP Cerber blocks REST API access by default. Go to WP Cerber → Hardening and disable “Block access to WordPress REST API except for any of the following”, OR add an exception for the routes /wp/v2/*.

Limit Login Attempts Reloaded / WPS Hide Login

Both of these are usually fine — Claude signs in through your normal login page once, when you approve it; after that its requests never touch the login form, so login-attempt limiters don’t see them. WPS Hide Login does NOT affect REST API endpoints, only wp-login.php.

Two-factor authentication (2FA) plugins

2FA plugins (Wordfence Login Security, Two Factor, Google Authenticator, etc.) protect the wp-admin login form — and that is exactly where you approve Claude, so your 2FA applies to the approval too. After that, Claude uses the access your site issued it and never touches the login form again. No changes needed to your 2FA setup.

Hosting-provider firewall (Hostinger, SiteGround, Kinsta, WP Engine, Pressable)

Some managed hosts have a host-level firewall that strips the Authorization header from incoming requests, which silently breaks the credentials Claude sends with every request. If you’ve ruled out plugin-level blocking and the connection still fails, contact your host’s support and ask: “Does your firewall pass the HTTP Authorization header through to WordPress for REST API requests?” If they say no, ask them to enable it for your site (most will).

Quick test: Run the check

Go to wp-admin → Cowork → Run the check. It tests every step of the connection from your site’s side over real HTTP and shows the actual status code of each. If it says no requests from Claude have reached your site, the block is in front of WordPress (a firewall, security plugin or Cloudflare); if a step fails, that row names the error — send it to support.

Catch problems early: monitor your site’s uptime

The faster you find out your site is down, the fresher the backup you can restore from. WordPress for Cowork keeps the 5 most recent snapshots from the backups Claude takes, including the one it offers before any big change — older ones auto-prune. Once a snapshot rolls off, it’s gone. So the sooner you find out something’s wrong, the more recent your restore point will be.

An external uptime monitor closes that gap. Pick one and set it up before launch, not after.

Recommended: UptimeRobot (free)

UptimeRobot pings any URL every 5 minutes from real internet locations and alerts you when it stops responding. The free tier covers 50 monitors, which is way more than any single site needs.

  1. Sign up at dashboard.uptimerobot.com/sign-up with your real email.
  2. Click Add Monitor → choose Keyword type.
  3. URL: https://your-site.com/ (replace with your actual site)
  4. Keyword: any short string that always appears on your site (e.g. your site name). UptimeRobot alerts when the page either fails to load or loads but the keyword is missing — catches both crashes and “white screen of death” cases.
  5. Interval: 5 minutes (free tier minimum).
  6. Alert contacts: add your email — and ideally a second channel (SMS, Telegram, Slack, or webhook) so an email outage doesn’t keep you in the dark about the site outage.
  7. Save.

When the alert fires

UptimeRobot tells you the site went down. Don’t restore yet. Open Cowork and tell Claude:

"My site is showing as down. Investigate before doing anything destructive."

Claude will check the most likely causes first, in order:

  • Hosting status — is the host itself reporting an outage? UptimeRobot can’t tell the difference between your site dying and your hosting provider dying.
  • DNS and SSL — has the cert expired, or is DNS resolving correctly?
  • Recent changes — was a plugin or theme activated/updated in the last hour? That’s the most common cause of a sudden white screen.
  • Error logs — PHP error log entries with timestamps near the outage.
  • Database connection — can WordPress reach its database?
  • Security plugin lockout — Wordfence or Cloudflare WAF blocking your IP, or rate-limiting legitimate traffic?

Most outages are one of these and have a small, surgical fix — deactivate one plugin, whitelist an IP, restart the host’s PHP-FPM, etc. No backup restore needed.

Restore as a last resort. If the investigation shows actual data corruption, a malicious file injection, or a botched edit, then ask Claude:

"List my recent backups, then restore from the most recent one before the incident."

A restore wipes any changes made since that snapshot, so save it for cases where there’s no targeted fix.

Other monitors that work fine

If you already use one, no need to switch: BetterStack, Pingdom, HetrixTools, updown.io, or your hosting provider’s built-in monitor. Any URL pinger with email or webhook alerts works.

Earn 25% on every referral — Affiliate program

Refer customers to WordPress for Cowork and earn 25% commission on every sale that comes through your link. Whether you write about WordPress tools, run a YouTube channel, or just have a few clients you’d like to send our way — sign up and start earning.

  • Sign up or log in: /affiliate-area/
  • Grab your unique referral link from your affiliate dashboard.
  • Get paid 25% on every Solo, Agency, or Enterprise license sold through your link.

Questions about commissions, payouts, or terms? Use the chat bubble in the corner and we’ll get back to you.

Knowledge base & tickets

Browse the Knowledge Base for step-by-step articles on installation, licensing, backups, security plugins, and more — the same articles the AI chat draws from.

If your question isn’t covered (or the AI chat couldn’t resolve it), submit a ticket. Include your license key and a clear description — replies go back to you via your account dashboard and email.

Still need help?

Use the chat bubble in the bottom-right corner — it’s a real support channel, not a generic FAQ bot. Include your license key and a clear description of the issue, and we’ll get back to you within 24 hours on business days.