Honeycup Free connects a supported AI client directly to your WordPress site. You stay in control of the WordPress user and its permissions.
An Ability is a task that your AI client can discover. Honeycup Free provides 34 Abilities: 18 read WordPress state, 13 write within explicit boundaries, and 3 remain manual-only.
The 18 read Abilities can:
The 13 write Abilities can:
honeycup/refresh-hooks.Markdown is converted on the server into a bounded set of native WordPress core blocks. Raw HTML and shortcode execution are not supported. Honeycup Free does not replace page-builder layouts.
Read the object first, then pass the returned state hash as expected_hash. Post fields, taxonomy assignments, featured images, terms, media and site context expose their own hashes. A stale hash stops the write. Honeycup serializes its own changes and reads the saved state back after WordPress runs its native hooks.
These checks are optimistic. They do not make WordPress admin edits or other plugins participate in a single atomic transaction. Avoid simultaneous editing. A verification failure requires inspection of the current state; Honeycup does not automatically overwrite it to roll back.
Creation of a post, term or upload requires a unique idempotency_key. Repeating the same successful request with that key returns the current authorized object instead of creating a duplicate. Reusing the key for different input is rejected. If a creation was interrupted, inspect WordPress before trying again and do not simply send a new key. Receipts remain local until uninstall; they store identifiers and fingerprints, not copies of content. A crashed write can retain its resource lock for administrator recovery.
For honeycup/list-posts, Honeycup applies WordPress’s native status and privacy-policy-page capability rules before pagination, then checks every returned item again. total and returned_count count only the authorized items returned on the requested page. total_scope is always page. Honeycup Free intentionally does not report a cross-page total or perform a full enumeration, because either could reveal metadata about posts the connected WordPress user cannot edit. A user without edit_private_posts can list only that user’s own private posts.
For honeycup/list-media, Honeycup checks edit_post for every attachment, including individual capability restrictions. Its total and returned_count likewise count only authorized items on the requested page, with total_scope set to page. A page can contain fewer items after permission filtering.
The remaining 3 change Abilities are manual-only: SEO metadata changes, comment moderation and comment replies. They remain visible for planning but return HTTP 409 with honeycup_core_manual_only and manual_only: true before changing WordPress. Complete those steps in the WordPress dashboard.
Honeycup Free has no account requirement, license key, hosted relay, remote package loader, or timed feature restriction. The plugin itself makes no outbound network request.
Your chosen AI client and AI provider may process information that you ask the client to read. Their terms and privacy policy apply to that separate connection.
Honeycup stores its own local settings, cryptographic secrets, write locks, creation receipts and a bounded activity ledger under the honeycup_core_ option namespace. Posts, terms and media you create are normal WordPress data.