Workflow

From plugin install to verified repair without handing over hosting credentials.

WPFixAgent uses an outbound WordPress connector. Your site pairs with a one-time token, sends health signals, polls for approved commands, and reports results back to the dashboard.

Outbound

Connector

Signed

Commands

5 stages

Repair run

Audited

Outcome

wpfixagent.com/how-it-works

The connector lifecycle

BaselineSigned inventory and health data establish the site's current state and connector capabilities.
DetectionHealth rules, incidents, vulnerabilities, and update findings become prioritized site-specific issues.
DiagnosisThe dashboard explains evidence, risk, available playbook, backup requirement, and whether the issue is safe to auto-fix.
ProtectionA required local restore point is created and validated before the repair can change site behavior.
RepairThe API queues a signed, allowlisted command; the connector validates it, executes it, and reports the result.

Setup and connection

Start in WordPress. Operate from the site dashboard.

The connector establishes a least-privilege outbound channel. Each stage produces a visible state you can confirm before moving on.

Setup 1

Install the connector

Upload the WPFixAgent Connector ZIP to WordPress and activate it from the plugin screen.

Setup 2

Generate a token

Create a short-lived pairing token from the SaaS dashboard for the selected organization.

Setup 3

Pair the website

Paste the token into WordPress. The connector registers the site, encrypts its site-specific secret locally, and begins signed outbound communication.

Setup 4

Confirm the baseline

Wait for the first heartbeat, then review software inventory, REST health, cron state, disk signals, and connector capabilities.

Setup 5

Open the website dashboard

Use the site's own Overview, Issues, Plugins, Backups, Repairs, Emergency, Tests, Alerts, and Activity pages for daily work.

Setup 6

Operate safely

Queue scans, restore points, supported fixes, and safe auto-fix. WordPress polls outbound and reports every command result.

Setup 7

Configure emergency polling

Add the displayed hosting cron command when the rescue bridge must continue polling even if normal WordPress requests cannot load.

Setup 8

Update or reinstall when needed

Apply a normal plugin, theme, core, or database update with an automatic snapshot, or reinstall a plugin or theme from its official source when a file was tampered with directly and no update is showing.

Request and result path

No public remote-control endpoint is exposed.

01

Dashboard

An authorized user reviews the site and queues a registered action.

02

WPFixAgent API

The API scopes the command to the organization and connected website.

03

WordPress connector

The plugin polls outbound, validates the signature and action, then reports the result.

04

Repair history

Verification, failure, rollback, and audit evidence return to the website workspace.

The connector lifecycle

1

Step 1

Baseline

Signed inventory and health data establish the site's current state and connector capabilities.

2

Step 2

Detection

Health rules, incidents, vulnerabilities, and update findings become prioritized site-specific issues.

3

Step 3

Diagnosis

The dashboard explains evidence, risk, available playbook, backup requirement, and whether the issue is safe to auto-fix.

4

Step 4

Protection

A required local restore point is created and validated before the repair can change site behavior.

5

Step 5

Repair

The API queues a signed, allowlisted command; the connector validates it, executes it, and reports the result.

6

Step 6

Verification and recovery

A fresh health scan and optional independent test confirm success. Failed checks preserve evidence and can trigger rollback when supported.

Why this workflow is safer

No arbitrary remote PHP execution endpoint

No generic shell access requirement

Commands are explicitly registered

Every queued command has a status and result

FAQ

Common questions

Does WordPress need inbound firewall access?

No. The connector is designed to poll the API outbound.

Can I pause monitoring?

Yes. The connector includes local settings for monitoring and repair permissions.

What happens if a repair fails?

The failed stage and connector message remain in repair history. Backup-aware runs can enter rollback automatically when a valid restore point and rollback playbook exist.

How quickly do commands run?

Commands run when the connector polls. WP-Cron polling depends on site traffic unless a real server cron is configured.

Does the dashboard assume success?

No. A command result advances the run, but completion depends on follow-up verification rather than the command merely returning.

Free 14-day trial · no card required

Give every WordPress site a safer path from incident to verified recovery.

Install the connector, pair with a one-time token, and start monitoring in minutes -- upgrade whenever you're ready.

Start Free Trial