See all monitors →
Docs

WordPress Abilities API: Relvato's abilities, and a look at everyone else's

WordPress 6.9 added the Abilities API: a standard way for a plugin to describe what it can do, so AI assistants and other tools can find it and call it. Relvato uses it in both directions. The Relvato plugin registers four abilities of its own, so an assistant connected to your site can read your monitors, get a fix brief and run the monitors again. And the exposure scan reads every ability the other plugins on your site register, and tells you when one can be run by anyone or can delete data.

What the Abilities API is

An ability is a named action a plugin registers with WordPress, such as relvato/list-monitors. It comes with a description, a schema for its input and output, a permission callback that decides who may run it, and annotations that say whether it only reads, or can delete data.

WordPress lists abilities in its REST API, under /wp-abilities/v1, for signed-in users. The WordPress MCP Adapter goes one step further: it offers the abilities a plugin marks as public to AI assistants such as Claude, Cursor or ChatGPT. Setting it up is covered in how to connect Claude to WordPress.

The four abilities Relvato adds

With WordPress 6.9 or newer and the Relvato plugin 1.42.0 or newer, the plugin registers a Relvato category with the four abilities in the table below. They talk to Relvato over the plugin's signed connection, so they answer with exactly what your Relvato dashboard shows.

relvato/get-fix-brief returns the same brief Relvato's own AI and the Relvato MCP connector use: the failing steps, the errors, and what changed on the site and when. Give it a run or a monitor; with neither, it picks the latest monitor with an open issue.

Who can use them, and what they can't do

Only administrators. Every ability checks that the signed-in user can manage the site's settings, whether the request comes through the MCP Adapter or the REST API. None of them changes your site, deletes anything or changes a monitor's settings.

relvato/run-monitors is the one that does something: it starts runs. It goes through the same signed request as the Run button in the plugin's dashboard, so Relvato applies the same rules: your plan, your monthly runs, a limit on requests per minute, and a log entry with the WordPress user who asked. Accepting visual changes, ignoring findings and one-click fixes stay in the Relvato dashboard, with you looking.

An example: fix, then confirm

Say the checkout monitor failed after an update. Ask your assistant “Which Relvato monitors are failing on this site?” and it calls relvato/list-monitors. “Get the fix brief for the checkout monitor” returns what broke and what changed. Once the fix is made, “Run the checkout monitor again” calls relvato/run-monitors, and a minute or two later relvato/list-monitors shows whether it passes.

The last step is the point. An assistant can tell you a change went through; only a test from outside tells you the site still works for the people who use it.

Turning them off

In WordPress, open Relvato → Settings and uncheck “Let AI assistants on this site use Relvato”. The abilities are gone from the next request. The setting is on by default. On WordPress 6.8 or older nothing is registered, and the setting changes nothing.

Checking every other plugin's abilities

Any plugin can register abilities, and not every one gets its permission callback right. With the Relvato plugin 1.43.0 or newer, the exposure scan lists every ability on your site from the inside: which plugin or theme registered it, whether it says it is read-only or can delete data, whether the REST API and the MCP Adapter offer it, and whether a visitor who isn't signed in may run it.

That last question is answered the way WordPress answers it for a request from someone who isn't signed in: by asking the ability's own permission callback, as a logged-out visitor. Nothing is run. An ability anyone can run that isn't read-only is reported as serious, like an exposed file. An open read-only one, a destructive one AI assistants can use, and abilities that appeared since the last scan are warnings.

Seeing the list from your AI assistant

The Relvato MCP connector's site_overview includes the same list for each WordPress site: how many abilities there are, how many AI assistants or REST clients can reach, which ones anyone can run, which can delete data, and every ability grouped by the plugin that registered it. Ask “Which plugins on my site give AI assistants abilities, and is any of them open to everyone?”. The connector is described on the developers page.

The abilities the Relvato plugin registers

AbilityWhat it doesChanges anything?
relvato/get-site-statusThe site's health: monitors passing and failing, the pass rate, each monitor's latest result and the most recent runsNo, read-only
relvato/list-monitorsEvery monitor with its id, group, schedule and latest run; optionally only the ones with an issue, or one groupNo, read-only
relvato/get-fix-briefThe brief for fixing what a monitor found: for a run, a monitor, or the latest open issueNo, read-only
relvato/run-monitorsRuns all monitors, or one, to confirm a fix; counts toward your monthly runsStarts runs; changes no setting and deletes nothing

FAQ

Do I need the MCP Adapter?

For an AI assistant to use Relvato's abilities over MCP, yes: install it as described in how to connect Claude to WordPress. The abilities also work over the REST API with an Application Password. The exposure scan's review of other plugins' abilities needs neither, only the Relvato plugin 1.43.0 or newer.

Is asking whether anyone can run an ability safe?

Yes. The plugin only calls each ability's permission callback, as a visitor who isn't signed in: the same question WordPress asks when someone calls the ability without signing in. It never runs the ability.

My store runs WooCommerce. Are its abilities offered to AI assistants?

Only if WooCommerce's MCP feature is switched on. WooCommerce ships the MCP Adapter's code but starts it only with that feature, and Relvato counts an ability as offered to AI assistants only while the adapter is actually running.

What happens on WordPress 6.8 or older?

Nothing changes. The plugin registers no abilities, and the exposure scan skips the step because there is nothing to read.

Why is a new ability a warning?

Because it changes what an assistant, or anyone, can do on your site, usually after a plugin update. The warning names the plugin and its new abilities so you can decide whether you want them. It appears once, on the first scan that sees them.

Related reading
Docs

Know what AI can do on your site

Connect your WordPress site and the exposure scan lists every ability your plugins register, and flags the ones that shouldn't be open.