Real Skill packageSource verifiedClawHub registry

WordPress API Pro

Production-grade WordPress REST API integration for managing posts, pages, media, WooCommerce products, Elementor content, SEO meta, ACF, and JetEngine fields. Use when you need to retrieve, draft, create, or update WordPress content programmatically on sites where the user has provided explicit credentials. For any operation that writes to a live site, get explicit user approval for the target site, post/product IDs, and final action before executing. Prefer drafts first. Run batch operations in dry-run mode firs…

Identity and source

Publisher attributionBen Kalskyregistry owner unverified by skillvetai
Functional categoryWriting, Content & Translationautomatically inferred · 62% rule confidence
Package forminstruction with code24 recorded files
Canonical sourceClawHub registryclawhub:benkalsky:wordpress-api-pro
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codepasses structure
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 9/13/2026.claude/skills/wordpress-api-pro

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 9/13/2026.agents/skills/wordpress-api-pro

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 9/13/2026skills/wordpress-api-pro

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @benkalsky/wordpress-api-pro
clawhub inspect @benkalsky/wordpress-api-pro --version 3.9.5

Security evidence

SkillVetAI static result: no findings detected

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
24 / 24 inspected as text
Checked
9/13/2026, 4:48:02 AM
Scanner
0.1.3
Policy
1.0.3
6 inferred permission indicators
  • shell execution — automatically inferred
  • network access — automatically inferred
  • filesystem read — automatically inferred
  • filesystem write — automatically inferred
  • credential access — automatically inferred
  • external write action — automatically inferred
7 dependency and API indicators
  • pypi: requests >=2.32.3,<3
  • api: cdn.example.com
  • api: clawhub.ai
  • api: developer.wordpress.org
  • api: www.googleapis.com
  • api: your-site.example
  • api: yoursite.com
External clawhub result: clean

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
9/13/2026, 1:17:29 AM
Release binding
Matches this record
  • vt: clean
  • skillspector: suspicious
  • llm: clean

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:4bd08acdbca1055749b65c63afae373a16fa23ab5a4a1fb96fbb00337b508204
Show up to 24 recorded paths
  • config/sites.example.json
  • references/api-reference.md
  • references/gutenberg-blocks.md
  • requirements.txt
  • scripts/acf_fields.py
  • scripts/batch_update.py
  • scripts/create_post.py
  • scripts/describe_cpt.py
  • scripts/detect_plugins.py
  • scripts/elementor_content.py
  • scripts/get_post.py
  • scripts/jetengine_fields.py
  • scripts/list_posts.py
  • scripts/security.py
  • scripts/seed_content.py
  • scripts/seo_meta.py
  • scripts/site_audit.py
  • scripts/update_post.py
  • scripts/upload_media.py
  • scripts/woo_products.py
  • scripts/wp_cli.py
  • skill-card.md
  • SKILL.md
  • wp.sh

Source changelog

**Security update: Restricts http:// access to named hosts only; dependency instructions clarified for better patching.** - HTTP API access to non-local hosts now requires explicit host naming in WP_ALLOW_HTTP; blanket WP_ALLOW_HTTP=1 is no longer accepted. - Permission fields and setup docs updated to reflect this variable change, preventing accidental plaintext credential exposure. - Dependency instructions now prescribe a secure version range for requests, explaining the reasoning for patch flexibility vs. reproducibility. - Removed legacy skill-card.md file.