Control your WordPress connection.
Avius lets an agent act inside WordPress. Understand the scope of that access before connecting a site.
The tools can make real changes.
PHP execution and file operations can affect more than the page you are looking at. Database changes, settings, and code execution may take effect immediately.
Use development and staging environments. Keep a restorable backup and inspect the result before carrying changes into production. Avius is not a substitute for a deployment or backup process.
A connection must be authenticated.
Avius uses WordPress-side authentication and permission checks. Depending on the client, connection setup may use OAuth or a WordPress Application Password.
Keep credentials out of chat messages, shared screenshots, source control, and support tickets. If access is no longer needed, revoke it through the relevant WordPress controls and remove the client connection.
Understand where information goes.
Your agent connects to the WordPress endpoint. The core connection does not require an Avius hosted proxy.
The AI client and model provider may process content returned by your site. Their privacy and retention settings still apply. Licensing, payment, and support are separate data flows and should be evaluated separately.
A sandbox is not a complete rollback.
Recovery for a generated PHP file does not restore a deleted record, reverse a direct database change, or repair every configuration edit. Treat each tool according to what it can affect.
Ask for small, understandable changes. Keep a record of the intended outcome and verify the actual site afterward.
Report sensitive issues privately.
If you believe you have found a security issue, describe the affected version and the conditions needed to reproduce it. Do not post credentials or a working exploit against a live customer site in a public thread.
Contact Avius support