Pinch to Post - WordPress REST API, WooCommerce & Content Automation owner avatar

Pinch to Post - WordPress REST API, WooCommerce & Content Automation

Alert level: High

WordPress automation for Clawdbot. Manage posts, pages, WooCommerce products, orders, inventory, comments, SEO (Yoast/RankMath), media via REST API or WP-CLI. Multi-site support, bulk operations, content health checks, markdown to Gutenberg, social cross-posting. 50+ features—just ask.

Locality:Hybrid
Data access:Sensitive
Actions:Write
Installs 4Downloads 872Stars 1Updated 205h ago

Why this rating

Deterministic checks triggered by the tool capabilities and evidence.

  • Locality: Hybrid

    Calls WordPress REST API endpoints on a user-provided WordPress site (and may use WP-CLI locally).

  • Data access: Sensitive

    Can access private site content and e-commerce data (orders/inventory) and requires credentials like `WP_APP_PASSWORD` and WooCommerce keys.

  • Action surface: Write

    Can publish and bulk-manage posts/pages, moderate comments (approve/spam), and update WooCommerce products/orders.

Best practices

Follow these steps to reduce risk when using this skill.

  • Use an application password with the least-privileged WordPress role needed (avoid full admin when possible) and rotate credentials if exposed.
  • Back up the site and use drafts/dry-runs before bulk publish/delete or inventory/order operations.
  • Keep all API tokens in env vars or secret files (never in git) and enable audit logs/2FA on connected accounts.

Evidence links

Public sources backing the indicator assignments.

Always be careful when navigating away from the website.

Max-risk rule

If any capability reaches a higher level, the entire indicator level bumps up to keep ratings deterministic and easy to scan.