Security advisorywp2shell Monday check: confirm 6.8.6, 6.9.5, 7.0.2. Patched is not clean.

Read the advisory

Why we built the AI Security Advisor

How WP Security Ninja’s AI Security Advisor turns real scan data into plain-language next steps on WordPress 7, without inventing another chatbot.

Topics Hardening & checklists

Lars Koudal

Lars Koudal

Updated Published

A lot of AI features exist because someone thought the product needed a chatbot in the corner. That was never the goal for WP Security Ninja.

Site owners already run security tests. They already collect warnings, vulnerabilities, and event noise. The hard part is deciding what matters first. The AI Security Advisor is built for that job: turn real Security Ninja findings into a structured, readable security audit inside wp-admin.

Built on WordPress 7 AI connectors

The advisor follows the WordPress 7 AI connector flow instead of inventing a separate API-key island inside the plugin.

  1. Configure a provider under Settings → Connectors in WordPress 7.
  2. Open Security Ninja → Security Advisor.
  3. Choose the connector, optionally preview context, then generate a report.

Current connector options recognized in the product include OpenAI, Google, and Anthropic. If WordPress AI support is not available, the plugin shows a WordPress 7 required screen instead of the full advisor UI.

Step-by-step setup: How to enable AI Security Advisor.

Generate your first report

What it actually does

The advisor gathers Security Ninja data already on the site (tests, feature state, vulnerability context, events, and related signals) and asks the configured model to return a structured report. On Pro, malware findings can inform the report too. The point is prioritization and plain-language next steps, not a free-form chat.

You get sections you can review, not a wall of raw findings. Follow-up questions after the first report (what to fix next, what can wait, what changed) keep the report useful as a working reference.

Docs for the workflow: How to get your first security report.

Generated security report

Transparency and privacy

Before you generate a report, you can preview the context that will be sent. That matters when the payload is security-related.

The generation flow is designed around a privacy-safe summary. Per our docs, domains, URLs, IPs, usernames, and emails are not included in that context. Reports are stored locally on your site so you can reopen them later. Details: What happens when you generate a report.

Free to use, with Pro adding depth

The core AI Security Advisor flow is available to Free and Pro users on supported WordPress 7 setups. Pro can expand what the model is allowed to recommend and deepen some improvement links. It is not a Pro-only checkbox that hides the whole feature.

What it is not

Clear boundaries help more than hype:

  • It does not replace malware scanning, a WAF / Cloud Firewall, or login protection.
  • It is manual and on-demand, not an always-on background AI.
  • It is not a streaming chatbot and does not claim zero residual risk.
  • It explains and prioritizes findings. Blocking traffic and cleaning malware remain separate capabilities (Pro for those active tools).

How to try it

  1. Use a WordPress 7 build with AI connector support.
  2. Configure a provider in Settings → Connectors.
  3. Install WP Security Ninja and run tests so there is data to work from.
  4. Open Security Ninja → Security Advisor.
  5. Preview context if you want, select the connector, generate the report.

More product detail: AI Security Advisor and WP 7 AI connectors.

Ask follow-up questions

Why this direction

AI is useful in a security plugin when it is tied to real site data and a clear outcome: a report you can act on. WordPress 7 is still early for many hosts, which is exactly when testing practical admin workflows matters.

If AI is going to live in wp-admin, I would rather it help you understand your own security status with less guesswork than pretend a chatbot is a strategy.

Found this useful? Share it.

Larger screenshot