Skip to content

Connect WordPress

Give RankGrep permission to apply fixes to a WordPress site with an Application Password, never your real password.

Updated 17 Sept 20262 min read

On this page
  1. Before you start
  2. 1. Create an Application Password
  3. 2. Connect in RankGrep
  4. What is stored
  5. Revoking access
  6. Common problems

A WordPress connection is what lets RankGrep apply a fix instead of only describing it. It takes about two minutes.

Before you start

  • The site must be served over HTTPS. RankGrep refuses to send credentials over plain HTTP.
  • The WordPress REST API must be reachable at /wp-json/. Most sites have it; some security plugins switch it off.
  • Install the RankGrep Connector plugin first if you want exact SEO titles, meta descriptions, and heading repairs. The connection works without it, but fewer fixes can be applied automatically.

1. Create an Application Password

In WordPress, go to Users → Profile, scroll to Application Passwords, type RankGrep as the name and click Add New Application Password. Copy the password WordPress shows. It is displayed once.

Use an account with the Editor or Administrator role. RankGrep needs to edit published pages and media; it does not need to manage plugins or users.

2. Connect in RankGrep

Open Connections for the website, choose WordPress, enter the WordPress username and the Application Password, and connect. RankGrep verifies the credentials against your site, records the account's role and capabilities, and detects the connector plugin or a supported SEO plugin.

What is stored

The Application Password is encrypted at rest and is never shown again, logged, or sent to any AI provider. Your real WordPress password is never asked for.

Revoking access

Delete the Application Password in WordPress under Users → Profile → Application Passwords. Every RankGrep write stops immediately. You can also disconnect from the Connections page in RankGrep, which deletes the stored credential.

Common problems

"Could not verify the connection." Check that the REST API answers at https://your-site.com/wp-json/wp/v2/users/me when signed in. Security plugins such as Wordfence or iThemes can block Application Passwords; look for a setting named REST API or Application Passwords and allow them.

"The account cannot edit published content." The WordPress user is a Contributor or Author. Use an Editor or Administrator account.

Meta descriptions come as guidance only. Neither the connector nor a supported SEO plugin is installed, so there is no field to write. Install the connector.