AI Webmaster is designed to help WordPress website owners build, expand and manage websites with AI-assisted workflows while keeping the site owner or administrator in control.
This page explains important security and privacy principles related to AI Webmaster, including API keys, external AI services, administrator control, AI-generated content, data handling and responsible use.
AI Webmaster is a free WordPress plugin. AIWOS Cloud is a separate future platform for autonomous website operation.
AI Webmaster should be used as an assistant, not as a replacement for responsible website administration.
The website owner or administrator remains responsible for configuring the plugin, managing API keys, reviewing AI-generated content, deciding what data may be sent to external services, maintaining WordPress security, managing user accounts and permissions, backing up the website, reviewing changes before publication and complying with applicable laws and policies.
Administrator Control
AI Webmaster is intended to operate under the control, configuration or supervision of the WordPress site owner or administrator.
AI-assisted workflows may help with generating page drafts, improving existing content, creating documentation, suggesting internal links, identifying missing content, supporting page structure and generating task reports.
AI Webmaster should not be described as a fully autonomous background operating system. Full Autopilot, scheduled tasks, continuous monitoring, daily and weekly reports, Approval Center, rollback and multi-site operations belong to the future AIWOS Cloud platform.
Learn more:
API Keys
Some AI-powered features may require an API key from an external AI service provider, such as the OpenAI API. An API key is a private access credential and should be treated like a password.
You should never publish API keys on public pages, share them in screenshots, send them through unsecured messages, include them in public support requests, store them in visible page content or expose them in logs or debug output.
If you believe an API key has been exposed, revoke or rotate it immediately through the external service provider.
Learn more:
User-Owned API Keys
AI Webmaster is designed around the principle that the site owner controls the external AI connection. The website owner or administrator is responsible for creating the API key, entering it into plugin settings, managing billing and usage, monitoring quotas, reviewing provider terms and rotating keys when needed.
External AI Services
AI Webmaster may send selected prompts, instructions, task context or website content to an external AI provider when AI-powered features are configured and used. The exact data sent depends on the feature, prompt, selected content, plugin configuration, provider and website owner’s decisions.
No external AI service should be described as active unless it is configured, triggered or authorized by the site owner or administrator.
For details, see:
What Data May Be Sent to AI Services
When AI features are used, requests may include prompts written by the administrator, task instructions, selected page or post content, headings or excerpts, task context, website structure information, internal link context, and generated or revised content.
What Not to Send to AI Services
Do not send sensitive, confidential, regulated or legally protected information to AI services unless you have confirmed that it is appropriate and lawful to do so. Avoid sending passwords, private API keys, administrator credentials, database credentials, customer personal data, payment data, confidential business data, health information, legal case details, financial account information, authentication tokens or security keys.
AI-Generated Content Review
AI-generated content should always be reviewed before publication or use. It may contain inaccuracies, outdated information, unsupported claims, incomplete explanations, unsuitable wording, incorrect links, legal or compliance risks, factual errors or duplicated language.
No Hidden Administrator Accounts
AI Webmaster should not be presented as creating hidden administrator accounts, secret access mechanisms or backdoors.
AI Webmaster may use an AI Webmaster Operator identity to clearly mark and manage AI-assisted actions inside WordPress.
AI Webmaster Operator is an AI working identity used to clearly mark and manage AI-assisted actions inside WordPress.
Learn more: AI Webmaster Operator
WordPress Roles and Permissions
AI Webmaster should respect the WordPress permission model. Only authorized WordPress users should be able to configure sensitive plugin settings, run powerful AI tasks or manage API keys.
Website Backups
Before running larger AI-assisted content or structure changes, create a backup. Backups help recover from mistakes, plugin conflicts, content issues or unintended changes.
Internal Links and Automated Changes
AI Webmaster may help with internal links, orphan pages, missing page destinations or content structure. However, automated link repair should be reviewed.
For example, a “Security & Privacy” link should normally point to a dedicated Security & Privacy page, not automatically to the Privacy Policy unless the context is specifically about privacy.
Privacy Policy and Legal Pages
AI Webmaster may help draft or improve legal and trust-related pages, including Privacy Policy, Terms of Use, External Services, Security & Privacy, API Key documentation and Support policy. These pages require human review.
Related pages:
AIWOS Cloud Separation
AI Webmaster and AIWOS Cloud have different roles. AI Webmaster is a free WordPress plugin for AI-assisted website building, content development and administrator-supervised workflows. AIWOS Cloud is a separate future platform for autonomous website operation and is not a paid unlock of AI Webmaster.
Safe Support Requests
When contacting support, include enough technical information to understand the issue, but do not send sensitive access details. Technical support: support@aiwebmaster.cloud. General contact: contact@aiwebmaster.cloud.
Security Best Practices
- Keep WordPress, themes and plugins updated.
- Use strong passwords.
- Limit administrator access.
- Use HTTPS.
- Maintain regular backups.
- Secure API keys.
- Review AI-generated content.
- Review automated link changes.
- Avoid sending sensitive data to AI services.
- Monitor API usage and costs.
Frequently Asked Questions
Does AI Webmaster share my data automatically?
AI Webmaster should only send data to external AI services when AI-powered features are configured, triggered or authorized by the site owner or administrator.
Does AI Webmaster require an API key?
Some AI-powered features may require an external AI API key. See API Keys for details.
Are API keys safe to share with support?
No. Do not share private API keys with support, public forms, screenshots or email messages.
Can AI Webmaster replace human review?
No. Human review remains necessary.
Is AI Webmaster a security plugin?
No. AI Webmaster is not a dedicated WordPress security plugin, firewall, malware scanner or compliance system.
Does AI Webmaster create hidden admin accounts?
No. AI Webmaster Operator is an AI working identity for transparency, not a hidden admin account or backdoor.
