TERMS OF SERVICE · UPDATED 2026-09-17

Terms of service

The terms that govern the wpreef hosted connector: subscriptions, plan changes, what the WordPress credential means, and what we do not warrant.

These terms govern your use of the wpreef hosted connector and any subscription you buy here. The short version: you connect your own WordPress sites with your own credentials, we run the connector that ChatGPT and Claude talk to, and what the credential can do is what an assistant can do.

Who runs this

The hosted connector is operated by WISE IT LLC ("we"). The wpreef npm package is MIT licensed and the wpreef-bridge companion plugin is GPL-2.0-or-later; both are open source and neither is sold. By using the connector or buying a subscription you agree to these terms.

The service

wpreef is a remote MCP server. It talks to your self-hosted WordPress over the WordPress REST API using an application password you create and can revoke. Nothing is installed on your site unless you choose to install the companion plugin.

What we provide is the connector, the OAuth sign-in in front of it, the site registry and the audit log. What we do not provide is WordPress hosting, WordPress support, or the assistant — ChatGPT and Claude are OpenAI's and Anthropic's products and their terms apply to your use of them.

Your account

Sign-in is handled by Clerk. You are responsible for what happens under your account and for the WordPress credentials you register. Register only sites you are authorised to administer.

Plans and payment

Subscriptions are sold through Polar (polar.sh), our merchant of record. Polar processes the payment, issues the receipt, and handles sales tax and VAT. Your card details go to Polar, never to us. Polar's own terms apply to the payment transaction.

Prices are shown in USD before checkout. Plans differ only by how many sites you may register: Starter up to 3, Pro up to 10. The Free tier allows one site and includes ten actions on that site, once; that allowance does not renew.

Move between Starter and Pro at any time. The difference is prorated by Polar. A change of plan takes effect on the site cap immediately.

Cancellation

Cancel at any time from Billing. The subscription runs to the end of the period you have paid for, and is not renewed.

When your site cap drops — a cancellation, a downgrade or a refund — sites beyond the new cap are paused, not deleted. The newest ones pause first, and you can choose which sites stay inside the cap instead. A paused site keeps its settings and its stored credential and is excluded from the list an assistant may act on. Subscribing again un-pauses it.

Refunds

14 days, and the plan is revoked automatically when the refund lands. The full policy is on the refunds page, which is part of these terms.

Your WordPress credential is the real boundary

This is the security section from the project README, unchanged, and it is a term of this agreement as much as a technical note:

wpreef does not sandbox the model. It hands the model a WordPress credential and shapes how easily each capability is reached. The two real boundaries are the closed site list in your config and the WordPress role of the application password. Everything else is blast-radius shaping: read-only mode, opt-in toolsets, policy flags enforced on the canonical request, client approval prompts driven by tool annotations, and revision handles for recovery. confirm and allow_lossy flags are accident guards, not security controls.

Site content is returned inside a nonced <untrusted> boundary. No sanitiser prevents prompt injection; the guard, read-only mode and the credential's role are what limit the damage.

You choose the WordPress account the application password belongs to, and therefore what an assistant may do. An administrator credential can change anything an administrator can change.

No warranty about changes to your WordPress

Assistants act on instructions in natural language and are not deterministic. We do not warrant that a change an assistant makes to your site is the change you intended, and we are not responsible for the content it writes, the design it applies, or anything it deletes.

Keep backups. Every write returns a restore handle and undo runs through WordPress's own revisions, but revisions do not cover everything WordPress stores, and recovery is not prevention.

The service is provided as-is. We do not warrant that it fits a particular purpose or works with every WordPress installation, host or plugin. Our total liability for any claim is capped at what you paid us in the 12 months before the claim. Nothing here limits liability that cannot lawfully be limited.

Acceptable use

The connector exists to be used, by people and by their agents. What is not allowed:

  • registering a site you are not authorised to administer,
  • using the connector to publish spam, malware or unlawful content on any site,
  • load patterns intended to degrade the service for others,
  • attempting to reach another account's sites, credentials or audit history.

We may rate-limit or suspend an account that does any of this.

Intellectual property

The npm package and the companion plugin are open source under their own licences and those licences govern them. The hosted service, its site and its content are ours. Everything in your WordPress site remains yours; we claim no rights over it and do not use it to train anything.

Changes to these terms

We may update these terms; the date at the top is the version you are reading. Changes apply from posting and never retroactively change a period you have already paid for.

Governing law

These terms are governed by the law of WISE IT LLC's place of registration. If a dispute cannot be settled by talking to us first — please try that, it usually works — it belongs to the courts of that jurisdiction.