Agentic Admin
Agentic Admin

Agentic Admin

0/5 (0 ratings) — active installs Updated Oct 3, 2026
The Agentic Admin chat tab in wp-admin, mid-conversation. The model has just answered a question about installed plugins by calling the <code>plugin-list</code> tool locally — full ReAct trace (user question, thought process, tool call, answer) visible.

The Agentic Admin chat tab in wp-admin, mid-conversation. The model has just answered a question about installed plugins by calling the <code>plugin-list</code> tool locally — full ReAct trace (user question, thought process, tool call, answer) visible.

Agentic Admin transforms your WordPress admin panel into an intelligent command center. Instead of navigating through multiple screens to diagnose issues, you simply describe your problem in plain English.

Features

  • 100% Local AI: Uses WebLLM to run Qwen 3 1.7B (default) or Qwen 2.5 7B directly in your browser via WebGPU
  • Privacy-First: AI inference runs in your browser – your prompts and content are never sent to an AI service. A few abilities look up public data (CVE databases, WordPress.org checksums, web search); all are listed under External services
  • Zero Server Costs: No GPU infrastructure needed – computation happens on the client
  • WordPress Abilities API: Natively integrates with WordPress’s official Abilities API
  • Natural Language Interface: Describe problems in plain English, get intelligent solutions

Requirements

  • WordPress 6.9+ (includes the Abilities API)
  • PHP 8.2+
  • Modern browser with WebGPU support (Chrome 113+, Edge 113+)

External services

This plugin runs AI locally in your browser by default, and your prompts and chat content are never sent to an AI service unless you explicitly enable the external LLM provider below.

Separately from AI inference, some abilities query public data sources to do their job: a security scan checks your plugin versions against CVE databases, a checksum verification compares your files against WordPress.org, and a web search sends your query to a search engine. Every external request the plugin makes is listed here:

Model source for the local engine (site-owner configured) — Only when an administrator sets a model source and loads a model.
The local engine runs a language model in the administrator’s browser. The model is not part of the plugin: model files are over 1 GB. The plugin contains no model download address. An administrator enters where models are downloaded from under Settings Model source, and until then the local engine is off. Nothing is downloaded until an administrator then selects a model and clicks Load Model. The browser fetches the files directly from the configured source (the WordPress server makes no requests for them), and no prompts, admin data, or telemetry are sent. Files are cached in the browser after the first download.

To use the models published by the MLC-AI project, enter these addresses. No account or API key is needed:

  • Model weights URL: https://huggingface.co/mlc-ai/
  • Model library URL: https://raw.githubusercontent.com/mlc-ai/binary-mlc-llm-libs/main/web-llm-models/

You can also host the same files yourself and enter your own https addresses. Use the same layout: each model’s weights in <weights URL>/<model ID>/resolve/main/, and the compiled model libraries in <library URL>/<WebLLM version>/ (the plugin adds the version it needs, currently v0_2_80).
Hugging Face terms: https://huggingface.co/terms-of-service — Privacy: https://huggingface.co/privacy
GitHub terms: https://docs.github.com/en/site-policy/github-terms/github-terms-of-service — Privacy: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement

External LLM provider (user-configured) — Only when you switch the engine from “Local” to “Remote” in settings.
When enabled, chat messages, tool descriptions, and tool results are sent through this plugin’s REST proxy (/wp-json/agentic-admin/v1/llm-proxy/) to the OpenAI-compatible endpoint URL you configure (e.g. Ollama, LM Studio, vLLM, OpenAI, Groq, Together). You choose the endpoint; the plugin does not preselect or default to any third-party provider. No data is sent until you save an endpoint and start a chat in Remote mode.

DuckDuckGo HTML search — Only when the optional web-search ability is invoked by the assistant.
The user’s search query is sent to https://html.duckduckgo.com/html/ over GET. No WordPress user data is sent.
DuckDuckGo terms: https://duckduckgo.com/terms — Privacy: https://duckduckgo.com/privacy

NVD CVE database (NIST) — Whenever the security-scan ability is invoked.
security-scan includes a plugin vulnerability check, so the names and versions of your active plugins are sent to https://services.nvd.nist.gov/rest/json/cves/2.0 to look up known CVEs. No user data, post content, or credentials are sent.
NVD terms: https://nvd.nist.gov/developers/terms-of-use — Privacy: https://www.nist.gov/privacy-policy

MITRE CVE API — Only when the security-scan vulnerability check finds a CVE identifier and follows up on it.
The CVE ID (e.g. CVE-2024-12345) is sent to https://cveawg.mitre.org/api/cve/ for details. No WordPress user data is sent.
MITRE terms: https://www.cve.org/Legal/TermsOfUse — Privacy: https://www.cve.org/Legal/PrivacyPolicy

WordPress.org plugin checksums — Only when the optional verify-plugin-checksums ability is invoked.
Installed plugin slugs and versions are sent to https://downloads.wordpress.org/plugin-checksums/ and https://plugins.svn.wordpress.org/ to verify file integrity against the official WordPress.org distribution.
WordPress.org policies: https://wordpress.org/about/privacy/

WordPress.org core source (SVN) — Only when the optional verify-core-checksums ability finds a modified core file and diffs are requested.
The original copy of that one file is fetched from https://core.svn.wordpress.org/tags/{version}/ so the plugin can show you a diff against your local version. Only the WordPress version number and the core file path are sent, both of which are public information; no site data is transmitted. The checksum list itself comes from WordPress core’s own get_core_checksums() function.
WordPress.org policies: https://wordpress.org/about/privacy/

Source code and build process

Agentic Admin is fully open source under GPL-2.0-or-later. The complete, human-readable source — including the JavaScript/React sources behind the compiled assets in build-extensions/ — is maintained in a public repository:

https://github.com/pluginslab/wp-agentic-admin

The files under build-extensions/ are generated from the sources in src/ with @wordpress/scripts (webpack). They contain only JavaScript and CSS: the bundles (index.js, sw.js, and code-split chunks) and the stylesheets. No WebAssembly, binaries, or other compiled artifacts are distributed with the plugin. To regenerate them from a checkout:

  1. npm install
  2. npm run build

There is no build step for the PHP. The WebLLM engine is bundled into the plugin from its npm package. The AI model weights and their compiled model libraries are loaded at runtime from the provider documented under External services above; these are large provider-hosted model files (over 1 GB), not part of the plugin code.