RuleFence – AI Agent Control
by RuleFence 0 (0 reviews)

RuleFence – AI Agent Control

Govern Claude, ChatGPT, Cursor and any MCP agent: one decision per Ability, approval before risky work, and a signed audit trail.

RuleFence ranks #66,279 among WordPress.org plugins with 0+ active installations, is #2,394 of 4,566 in the Security category, and was last updated Sep 21, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1.2
v1.0.0 Current Version v1.0.0
Updated 2 days ago Last Update on 21 Sep, 2026
Refreshed 11 hours ago Last Refreshed on
#2,394 of 4,566 in Security Actively maintained
View on WordPress.org
Rank
#66,279
No change
Active Installs
0+
No change
KW Avg Position
151
No change
Downloads
45
+5 today
Support Resolved
0%
No change
Rating
0%
Review 0 out of 5
0 (0 reviews)

Next Milestone 10

Total Progress 10%
0+ 10+
20,726
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 9 more installs to reach 10+

Rank Changes

54,704 56,143 57,583 59,023 60,462 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
54,704 56,143 57,583 59,023 60,462 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Current #66,279
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 20 30 40 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
0 10 20 30 40 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

0.0
0 reviews
Overall 0%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about RuleFence – AI Agent Control

Use a dedicated least-privilege WordPress user for each security boundary you need to isolate. An agent is a separate RuleFence identity, but its Application Password still inherits the mapped WordPress user's native REST capabilities. Do not map an untrusted client to an administrator.
No, that is the default. Governance fails closed: an ability nobody granted is refused. Grant the specific ability in Abilities > Permissions.
Once, when the connection is created. It cannot be retrieved afterwards. If it is lost, revoke that connection and issue another.
Yes, and this is worth understanding before you judge it. WordPress 7.1 registers three Abilities of its own, all read-only: core/get-site-info and core/get-environment-info need an administrator, and core/get-user-info needs only a logged-in user. So on a site with no other Ability-aware plugins there is very little for an agent to do and very little to govern. Install WooCommerce and the list grows immediately, including writes with previews and captured before-states behind them. There is a wrinkle in the meantime. An Editor mapped to an agent can reach only one of the three, while still being free to write posts through the ordinary REST API, which the permission matrix does not cover. On a stock site the safest mapping and the useful one are not yet the same thing. That is WordPress's design rather than this plugin's, it improves as plugins register Abilities with sensible capabilities, and it is the reason the Readiness screen scores your mapping instead of assuming it.
It controls every Ability an agent invokes, which is what an AI client uses to work with your site. It does not sit in front of the ordinary WordPress REST API: a credential is a WordPress user, and that user's own capabilities decide what it can reach there. So map agents to a least-privilege user and keep it that way - the Readiness screen scores this, and the connection screen warns you if you point one at an administrator. The Activity trail records every Ability decision, and outside the Abilities API it records what a managed credential changed or was refused - so a change made through an ordinary REST route still appears, attributed to the agent that made it. Successful reads there are not kept one by one, because the trail is capped and a read-heavy client would crowd out the decisions.
Revoke its connection in Agents > Connections, or stop everything at once with Settings > Emergency mode. The record of what it already did stays intact and signed.
No. Agents, permissions, decisions and the audit trail are stored in your own database, and this plugin makes no outbound request of any kind - there is no webhook code in it to configure.
As many agents as you want, and everything on the governance side, are here: default-deny permissions, approvals, the signed audit trail, risk assessment, emergency mode, the readiness checks and runtime verification. The add-on sells automation and convenience - workflows, policies, undo, scheduling, export. No security control is ever sold; a control you have to buy is not a control. You do not need the add-on to use this plugin, and nothing here stops working without it.
No. It governs agents that connect to your site; it is not one, and it does not talk to any model. The AI client is whatever you connect - Claude, ChatGPT, a script of your own.
This plugin captures the before-state, so the evidence of what changed is kept whether or not you ever undo it. Performing the undo is in the paid add-on. Not everything is reversible either way, and the plugin does not claim otherwise - the Ability Explorer tells you which Abilities are covered before you grant one, so you know what a grant is worth before you make it.

Sign In / Register

You need to sign in or register to use this feature.