[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fv6dADsqnl9-jlFVqlhmakEgW961imqcRtCTAwVj-eBg":3},{"slug":4,"display_name":5,"profile_url":6,"plugin_count":7,"total_installs":8,"avg_security_score":9,"avg_patch_time_days":10,"trust_score":11,"computed_at":12,"plugins":13},"jboydston","Joe Boydston","https:\u002F\u002Fprofiles.wordpress.org\u002Fjboydston\u002F",2,0,100,30,94,"2026-08-25T05:56:01.374Z",[14,35],{"slug":15,"name":16,"version":17,"author":5,"author_profile":6,"description":18,"short_description":19,"active_installs":8,"downloaded":20,"rating":8,"num_ratings":8,"last_updated":21,"tested_up_to":22,"requires_at_least":23,"requires_php":24,"tags":25,"homepage":31,"download_link":32,"security_score":9,"vuln_count":8,"unpatched_count":8,"last_vuln_date":33,"fetched_at":34},"botcreds-agent-access","BotCreds Agent Access","2.3.2","\u003Cp>\u003Cstrong>BotCreds Agent Access\u003C\u002Fstrong> gives your AI agent, MCP client, or automation tool a secure, scoped credential to interact with your site — no code required.\u003C\u002Fp>\n\u003Cp>Whether you’re connecting Claude, ChatGPT, a custom MCP server, or an OpenClaw agent, BotCreds gives you a one-click setup wizard that generates a properly scoped WordPress Application Password and logs every action the agent takes.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Why BotCreds?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Most AI agent setups require digging into wp-config, creating users manually, or sharing admin credentials. BotCreds removes all of that. Install, click, copy, paste — your agent is connected in under a minute.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>One-click connection setup under Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> BotCreds\u003C\u002Fli>\n\u003Cli>Generates a secure, scoped Application Password for your AI agent or MCP client\u003C\u002Fli>\n\u003Cli>Works with any agent that supports the WordPress REST API: Claude, ChatGPT, OpenClaw, n8n, Zapier, custom MCP servers, and more\u003C\u002Fli>\n\u003Cli>User-level and site-level logging of agent actions — see exactly what your agent did and when\u003C\u002Fli>\n\u003Cli>Displays credentials in ready-to-paste format (table and JSON)\u003C\u002Fli>\n\u003Cli>Shows connection status, creation date, and last used date\u003C\u002Fli>\n\u003Cli>One-click revoke with confirmation\u003C\u002Fli>\n\u003Cli>Clean, modern admin UI using native WordPress styles\u003C\u002Fli>\n\u003Cli>Proper security: nonces, capability checks, password shown only once\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Compatibility:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Works with the Model Context Protocol (MCP)\u003C\u002Fli>\n\u003Cli>Compatible with all major AI agent frameworks\u003C\u002Fli>\n\u003Cli>No third-party services or accounts required — everything stays on your site\u003C\u002Fli>\n\u003C\u002Ful>\n","Scoped, per-agent application passwords for AI agents, MCP clients, and automation tools.",454,"2026-06-17T23:59:00.000Z","7.0.2","5.7","7.4",[26,27,28,29,30],"ai-agents","application-passwords","mcp","rest-api","security","https:\u002F\u002Fbotcreds.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbotcreds-agent-access.2.3.2.zip",null,"2026-07-22T17:31:50.256Z",{"slug":36,"name":37,"version":38,"author":5,"author_profile":6,"description":39,"short_description":40,"active_installs":8,"downloaded":41,"rating":8,"num_ratings":8,"last_updated":42,"tested_up_to":22,"requires_at_least":43,"requires_php":24,"tags":44,"homepage":49,"download_link":50,"security_score":9,"vuln_count":8,"unpatched_count":8,"last_vuln_date":33,"fetched_at":34},"botcreds-agent-artifacts","BotCreds Agent Artifacts","1.3.6","\u003Cp>\u003Cstrong>BotCreds Agent Artifacts\u003C\u002Fstrong> gives AI agents a permanent home for their outputs.\u003C\u002Fp>\n\u003Cp>Post a single HTML file to the REST API. The plugin parses it, extracts scripts and styles, saves them as static files, enqueues them properly via WordPress APIs, and serves the result at a clean public URL with strict security headers. No build tools. No infrastructure. One API call.\u003C\u002Fp>\n\u003Ch4>How It Works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>POST raw HTML to \u003Ccode>\u002Fwp-json\u002Fwp\u002Fv2\u002Fartifacts\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>The plugin extracts \u003Ccode>\u003Cscript>\u003C\u002Fcode> and \u003Ccode>\u003Cstyle>\u003C\u002Fcode> blocks and saves them as static files in \u003Ccode>wp-content\u002Fuploads\u002Fartifacts\u002F{id}\u002F\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>JS and CSS are enqueued via \u003Ccode>wp_enqueue_script()\u003C\u002Fcode> \u002F \u003Ccode>wp_enqueue_style()\u003C\u002Fcode> — no inline scripts in rendered output\u003C\u002Fli>\n\u003Cli>The HTML body is sanitized with \u003Ccode>wp_kses()\u003C\u002Fcode> and an expanded allowed-tags list (canvas, SVG, inputs, video, audio, data-* attributes)\u003C\u002Fli>\n\u003Cli>The artifact is served at \u003Ccode>yourdomain.com\u002Fartifacts\u002F{slug}\u002F\u003C\u002Fcode> with a strict Content Security Policy\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>From the caller’s perspective: POST HTML, get URL. Everything else happens server-side.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Deployment\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Single REST API call — no SDK, no library, any HTTP client works\u003C\u002Fli>\n\u003Cli>Update artifacts in place — POST to \u003Ccode>\u002Fwp-json\u002Fwp\u002Fv2\u002Fartifacts\u002F{id}\u003C\u002Fcode> and the public URL stays the same\u003C\u002Fli>\n\u003Cli>Optional \u003Ccode>artifact_description\u003C\u002Fcode> field for internal documentation\u003C\u002Fli>\n\u003Cli>Head content preservation — \u003Ccode>\u003Cmeta>\u003C\u002Fcode> tags and other \u003Ccode>\u003Chead>\u003C\u002Fcode> elements from submitted HTML are preserved in output\u003C\u002Fli>\n\u003Cli>External script support — \u003Ccode>\u003Cscript src=\"...\">\u003C\u002Fcode> tags are registered as external dependencies and enqueued alongside local assets\u003C\u002Fli>\n\u003Cli>Asset cache busting — enqueued files are versioned with \u003Ccode>filemtime()\u003C\u002Fcode> so browsers fetch updates automatically\u003C\u002Fli>\n\u003Cli>Clean redeploys — old asset files are deleted before new ones are written\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Security\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Content Security Policy on every artifact page — blocks external script injection and cross-origin data exfiltration by default\u003C\u002Fli>\n\u003Cli>Trusted CDN list out of the box: \u003Ccode>cdn.jsdelivr.net\u003C\u002Fcode>, \u003Ccode>unpkg.com\u003C\u002Fcode>, \u003Ccode>cdnjs.cloudflare.com\u003C\u002Fcode>, \u003Ccode>esm.sh\u003C\u002Fcode>, \u003Ccode>cdn.skypack.dev\u003C\u002Fcode> — scripts and styles load from these without any configuration\u003C\u002Fli>\n\u003Cli>Per-artifact API allowlist — artifacts that call external APIs declare their origins via an HTML pragma comment (\u003Ccode>\u003C!-- artifact:fetch https:\u002F\u002Fapi.example.com -->\u003C\u002Fcode>) or a deploy-time meta field; the plugin adds them to \u003Ccode>connect-src\u003C\u002Fcode> automatically\u003C\u002Fli>\n\u003Cli>Additional security headers: \u003Ccode>X-Content-Type-Options\u003C\u002Fcode>, \u003Ccode>X-Frame-Options\u003C\u002Fcode>, \u003Ccode>Referrer-Policy\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Custom capability type — \u003Ccode>artifact\u003C\u002Fcode> capabilities are separate from standard post capabilities; only Administrators can create artifacts by default\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Developer Hooks\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>botcreds_agent_artifacts_csp\u003C\u002Fcode> — filter the full CSP header value for any artifact\u003C\u002Fli>\n\u003Cli>\u003Ccode>botcreds_agent_artifacts_allowed_html\u003C\u002Fcode> — filter the \u003Ccode>wp_kses\u003C\u002Fcode> allowed-tags array\u003C\u002Fli>\n\u003Cli>\u003Ccode>botcreds_agent_artifacts_grant_to_role()\u003C\u002Fcode> — helper to grant capabilities to additional roles\u003C\u002Fli>\n\u003Cli>Custom template — drop \u003Ccode>single-artifact.php\u003C\u002Fcode> in your active theme to replace the render template\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Use Cases\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>OpenClaw (AI personal assistant)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>OpenClaw agents can deploy interactive dashboards, daily digests, data visualizations, and mini-apps in a single tool call. Generate the HTML, POST it, get the URL — no manual steps, no context switching.\u003C\u002Fp>\n\u003Cp>For artifacts that fetch live data, add a pragma comment to the HTML and the CSP is updated automatically:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>\u003C!-- artifact:fetch https:\u002F\u002Fapi.openweathermap.org -->\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>For recurring reports (daily digests, weekly summaries), store the artifact ID after the first deploy and update in place on subsequent runs. The URL never changes.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Claude Code (terminal-based coding agent)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Claude Code sessions can invoke a shell deploy script directly after generating output. Add a \u003Ccode>scripts\u002Fdeploy-artifact.sh\u003C\u002Fcode> to your project and reference it in your \u003Ccode>CLAUDE.md\u003C\u002Fcode> — Claude will use it to ship outputs without leaving the terminal. No manual copy-paste, no browser switching.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Codex (OpenAI coding agent)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Same pattern as Claude Code. Add deployment instructions to your \u003Ccode>AGENTS.md\u003C\u002Fcode> and Codex can write HTML, call the deploy script, and report the live URL — all in one agent run.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>GitHub Actions (versioned project)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>For projects that build a static HTML output — dashboards, reports, documentation, changelogs — a GitHub Actions workflow can deploy to an artifact on every push to \u003Ccode>main\u003C\u002Fcode>. The artifact ID is stored as a repository variable so the public URL stays stable across all future deploys. Push \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> build \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> deploy \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> done.\u003C\u002Fp>\n\u003Ch4>Example: Deploy via REST API\u003C\u002Fh4>\n\u003Cpre>\u003Ccode>curl -X POST \"https:\u002F\u002Fyour-site.com\u002Fwp-json\u002Fwp\u002Fv2\u002Fartifacts\" \\\n  -u \"username:application-password\" \\\n  -H \"Content-Type: application\u002Fjson\" \\\n  -d '{\n    \"title\": \"My App\",\n    \"status\": \"publish\",\n    \"meta\": {\n      \"artifact_html\": \"\u003C!DOCTYPE html>\u003Chtml>\u003Cbody>\u003Ch1>Hello.\u003C\u002Fh1>\u003C\u002Fbody>\u003C\u002Fhtml>\",\n      \"artifact_description\": \"Built by my AI agent\"\n    }\n  }'\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The response \u003Ccode>link\u003C\u002Fcode> field is the public URL of the deployed artifact.\u003C\u002Fp>\n\u003Ch4>Example: Artifact with Live Data\u003C\u002Fh4>\n\u003Cp>Include the fetch pragma in your HTML — no configuration needed:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>\u003C!-- artifact:fetch https:\u002F\u002Fapi.openweathermap.org -->\n\u003C!DOCTYPE html>\n\u003Chtml>\n\u003Cbody>\n  \u003Cdiv id=\"weather\">\u003C\u002Fdiv>\n  \u003Cscript>\n    fetch('https:\u002F\u002Fapi.openweathermap.org\u002Fdata\u002F2.5\u002Fweather?q=Denver&appid=YOUR_KEY')\n      .then(r => r.json())\n      .then(d => document.getElementById('weather').textContent = d.weather[0].description);\n  \u003C\u002Fscript>\n\u003C\u002Fbody>\n\u003C\u002Fhtml>\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>Example: GitHub Actions Deployment\u003C\u002Fh4>\n\u003Cpre>\u003Ccode>name: Deploy Artifact\non:\n  push:\n    branches: [main]\njobs:\n  deploy:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions\u002Fcheckout@v4\n      - run: npm ci && npm run build\n      - name: Deploy to Artifact\n        env:\n          WP_SITE: ${{ secrets.ARTIFACT_WP_SITE }}\n          WP_USER: ${{ secrets.ARTIFACT_WP_USER }}\n          WP_PASS: ${{ secrets.ARTIFACT_WP_PASS }}\n          ARTIFACT_ID: ${{ vars.ARTIFACT_ID }}\n        run: |\n          PAYLOAD=$(jq -n --arg title \"My Dashboard\" --rawfile html dist\u002Findex.html \\\n            '{title: $title, status: \"publish\", meta: {artifact_html: $html}}')\n          ENDPOINT=\"$WP_SITE\u002Fwp-json\u002Fwp\u002Fv2\u002Fartifacts\"\n          [ -n \"$ARTIFACT_ID\" ] && ENDPOINT=\"$ENDPOINT\u002F$ARTIFACT_ID\"\n          curl -sf -X POST \"$ENDPOINT\" -u \"$WP_USER:$WP_PASS\" \\\n            -H \"Content-Type: application\u002Fjson\" -d \"$PAYLOAD\" | jq -r '.link'\n\u003C\u002Fcode>\u003C\u002Fpre>\n","Deploy self-contained HTML\u002FCSS\u002FJS apps to WordPress via REST API. One call from any AI agent or CI pipeline — plugin handles the rest.",101,"2026-06-19T02:09:00.000Z","6.0",[45,46,47,48,29],"agents","ai","api","artifacts","https:\u002F\u002Fbotcreds.com\u002Fagent-artifacts","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbotcreds-agent-artifacts.1.3.6.zip"]