Help center
Open dashboard

Introducing the New Atarim WordPress Plugin: Everything You Need to Know

Install it, connect it, and control who collaborates, plus what Atarim's AI can do on your site.

Atarim team Updated 7 Oct 2026 · 30 min read
Integrations
The Atarim WordPress plugin connected, with its capabilities listed
Before you start

Relevant for

  • Agencies, developers and site owners who want feedback and AI collaboration to happen on the WordPress site itself — including staging sites that are not publicly reachable.

Required knowledge

  • Comfortable installing a WordPress plugin and reaching WordPress admin settings.

Tools & resources needed

  • WordPress 6.0 or later and PHP 7.4 or later for visual collaboration.
  • WordPress 6.9 or later and PHP 8.0 or later for the AI action layer, because it runs on the WordPress Abilities API. On older versions visual collaboration works normally and only the AI layer stays inactive.
  • An Atarim account and administrator access to the site.

The Atarim WordPress plugin brings visual collaboration onto the site itself, rather than onto a fetched copy of it. That is what makes it the right choice for staging environments and any site that is not publicly reachable — and it gives Atarim’s AI a defined set of actions it can carry out on the site directly, on WordPress 6.9 or later with PHP 8.0 or later.

The plugin is listed in WordPress as Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback, and the current release is version 5.1.6.

Check your PHP version first
The plugin requires PHP 7.4 or later and WordPress 6.0 or later. An outdated PHP version is the most common reason an install fails or the plugin activates but does nothing, and the resulting error rarely names the real cause. The AI “Do It” action layer additionally requires PHP 8.0 or later and WordPress 6.9 or later, as it is built on the WordPress Abilities API, which is part of WordPress core from version 6.9 onwards.

What the Plugin Enables

Installing the plugin changes where collaboration happens. Instead of reviewing a copy of the page, you and your team work on the site itself — which unlocks a set of things a shared link cannot do.

What you getWhy it matters
Works on staging and protected sitesBecause collaboration runs on the site, it reaches environments that are not publicly accessible.
Visual feedback on live pagesComments attach to the element they are about, so nobody has to describe where they mean.
AI review of any pageRun a review to identify gaps before a client sees the page rather than after.
Internal tasks hidden from clientsWork you do not want reviewed sits in the same project without appearing in the client’s view.
Private internal notesTeam-only discussion lives on the task, invisible to clients and silent on notifications.
Client-friendly feedbackMark review findings internal and clients see their own thread rather than your quality notes.
Clients need no WordPress accountGuest Mode or ?collab=true lets them ask questions in place.
Note
Internal tasks and private notes are visible to administrators and team members only. Clients and guests never see either, and private notes do not trigger notification email. Explore Internal Tasks

Install from the WordPress Plugin Repository

The fastest route if you have not downloaded the plugin from your Atarim dashboard.

Instructions:

  1. In your WordPress admin panel, go to Plugins → Add New.
  2. Search for Atarim.
  3. Select Install Now on the correct plugin. Look for Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback so you install the right one.
  4. Activate the plugin when the option appears.
The Plugins Add New screen in WordPress admin
Go to Plugins → Add Plugin in your WordPress admin panel
WordPress Add Plugins screen with atarim in the search field and the Atarim plugin listed first
Search for Atarim
WordPress Add Plugins results with an arrow on Install Now for the Atarim plugin
Select Install Now — check the name reads Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback
WordPress Add Plugins results with an arrow on the Activate button for the Atarim plugin
Activate the plugin when the option appears

Or Download It from Your Atarim Dashboard

Take this route when the site cannot reach the WordPress repository, or when you want a specific build.

Instructions:

  1. Log in to your Atarim workspace.
  2. Go to Projects if you are not already there.
  3. Select Add new and choose Manage a WordPress site.
  4. Select Download the plugin. It opens the plugin’s WordPress.org page, where you can download the latest version as a .zip file.
Projects screen with the Add new card at the top of the grid
Start from Projects in your Atarim workspace
Manage a WordPress site panel with the Download the plugin link
Download the Plugin

Installing the Downloaded File

Uploading a zip is the standard WordPress route, so nothing here is Atarim-specific until activation.

Instructions:

  1. Go to your WordPress dashboard.
  2. Navigate to Plugins → Add New Plugin.
  3. Select Upload Plugin, choose the .zip file, and select Install Now.
  4. Activate the plugin.
The Add New Plugin screen in WordPress admin
In WordPress, go to Plugins → Add New Plugin → Upload Plugin
Uploading the Atarim plugin zip file in WordPress
Select Upload Plugin, choose the .zip, then Install Now
Activating the uploaded Atarim plugin in WordPress
Activate the plugin

Connect the Plugin to Your Atarim Account

Until the plugin is connected, it is installed but inert — the connection is what pairs the site to your workspace.

Instructions:

  1. After activation, WordPress opens Settings → Collaborate. On a site that has never been connected, the Connect WordPress to Atarim screen covers the page.
  2. Select Connect site (or Connect with Atarim on the settings page). Atarim opens in a new tab.
  3. Sign in or create a free account.
  4. Check the site address and the workspace shown under Added to workspace on Connect this WordPress site to Atarim?, then select Connect site. To use a different workspace, switch workspace in Atarim before you connect.
  5. Back in WordPress, You’re connected appears, then the site’s homepage opens with Atarim loaded on it.
The Connect WordPress to Atarim screen showing the site address, with an arrow on Connect site
After activating the plugin, the Connect WordPress to Atarim screen appears with your site’s address already filled in. Select Connect site to link it to your Atarim account.
The connect confirmation, naming the site address and the workspace
The confirmation names the site address and the workspace the site joins. Nothing happens until you select Connect site.
The You're connected confirmation naming the linked site, with a Close window button
Confirmation screen reading “You’re connected”
A WordPress site homepage with the Atarim bottom bar and the Review sidebar open
Connected WordPress site with the Atarim overlay open
Note
If the redirect does not happen, refresh the settings page and select the button again.

Multisite networks

On a WordPress multisite network, connect each sub-site separately from its own Settings → Collaborate. Each sub-site keeps its own connection and settings. There is no network-wide screen.

The Settings Screen

Plugin settings live in WordPress admin under Settings → Collaborate. You can also select Settings under the plugin’s name on the Plugins screen. Only Administrators can open this page.

SettingWhat it does
Disconnect from DashboardDisconnects this site from your Atarim dashboard.
Project SettingsOpens project-level configuration without leaving WordPress.
How to collaborateLists the ways in: copy and share a quick link, add ?collab=true to any page address, or turn on Guest Mode in the Manage Access tab of the sharing window.
Explore Sharing OptionsOpens the Atarim sharing window: copy the collaboration link, invite clients or team members, and manage access, including Guest Mode.
Who can collaborateSelects which WordPress user roles see the collaboration interface when logged in. Only the selected roles see it unless Guest Mode is on.
1 click login from Atarim asThe WordPress user Atarim signs you in as when you open the site from Atarim. Atarim’s AI also acts on the site as this user. It starts as the Administrator who connected the site. Leave it on — Select a user — to switch one-click login off.
Enable “Do it” via Atarim AILets Atarim’s AI make changes on this site, from the Do It button and from connected assistants. On by default for new installs. Untick it and select Save & Apply to stop AI changes on the site.
Save & ApplyStores your changes. Nothing takes effect until you select it.
WordPress Plugins screen with an arrow on the Settings link under the Atarim plugin
Settings → Collaborate, in WordPress admin rather than the Atarim dashboard
Project settings and collaboration options opened from the WordPress plugin
Project Settings opens without leaving WordPress
Choose an Administrator for 1 click login from Atarim as
This user decides what the AI can do on the site as well as who you are signed in as. With an Editor, the AI cannot manage plugins, themes, users or settings. Learn More About User Roles And Permissions
Tip
Appending ?collab=true to a URL is the most useful sharing route day to day — it opens collaboration on one specific page without changing any settings or generating a new link. Explore URL Collaboration

Sharing from the Settings Screen

Explore Sharing Options opens the same sharing options you would use in Atarim — copy the collaboration link, invite clients, or add team members — without leaving WordPress.

The plugin's Collaborate settings in WordPress with an arrow on Explore Sharing Options
Open sharing options to invite clients and collaborators
The Atarim sharing panel opened from WordPress, with options to add team members and copy a link
Add team members, invite clients, or copy a collaboration link from here

How WordPress Users Start Collaborating

A WordPress user whose role is allowed in the settings, and who has not connected yet, sees a small Atarim launcher icon on the page. Users marked as Webmaster skip this step, and the admin who connected the site is a Webmaster automatically.

  1. The user selects the launcher icon.
  2. The Dive Into Real-Time Collaboration window opens.
  3. They select Connect Your Account to proceed. They are connected to the project and can collaborate immediately, and are added to the project as a collaborator.
The Atarim collaboration launcher on a WordPress page
The launcher appears for roles selected under Who can collaborate
The consent modal asking a WordPress user to connect their account to Atarim
The consent modal — accepting joins them as a collaborator
Consent adds them as a collaborator, not a team member
Every WordPress user who gives consent joins as a collaborator by default. For someone to be a team member — with dashboard access, project visibility and role permissions — they must be invited to your Atarim account first. Use the same email address for a person in both WordPress and Atarim: matching accounts mean that once they give consent they are recognised as a team member with no extra steps, and it avoids a whole class of permission confusion later.

Collaborating with Your Team and AI on a Page

The Review tab of the collaboration sidebar has a Chat for internal team members, so a team can work through a page together and bring AI into the same conversation. From there you can discuss page-level changes, run internal AI reviews, check the page across desktop, tablet and mobile, and leave feedback on a single element or the whole page. AI works with the full page context — layout, spacing, copy, visuals and structure.

Chat comes from Atarim, not the plugin
It is an Atarim surface the plugin makes available on your site rather than a feature of the plugin itself. If Chat is not behaving as expected, it is not a plugin problem — check your Atarim account and connection first.
Mark AI review findings internal before you share the page
Internal tasks are hidden from clients and guests entirely, which is what stops a quality pass reading as a list of faults in front of the client. Explore Internal Tasks

Collaborating Inside WP Admin

Collaboration is not limited to front-end pages — it also works on WP Admin screens. That is useful for leaving internal reminders, flagging settings that should not be changed, and coordinating backend implementation work. Feedback left in WP Admin can be marked internal in the same way. Inside WP Admin, Atarim always opens in Browse mode, so switch to Comment to leave feedback.

WordPress admin Dashboard with the Atarim bottom bar, the Review sidebar and an element highlighted for a comment
Collaboration works on WP Admin screens too, not just front-end pages
Note
Like Chat, WP Admin collaboration comes from Atarim’s collaboration interface rather than the plugin’s own settings, so there is nothing to switch on for it in Settings → Collaborate.

What “Do It” Can Do on the Site

Two things are easy to confuse here, so it is worth separating them before the capability list.

Show Me

When an AI reply suggests a change to something on the page, it comes with a Show me button. Click it to see the change applied right on the page before anything is saved.

Show Me is only a preview. The change appears in your browser and nothing is saved to your site. If you reload the page, the preview is gone.

While the preview is showing, you’ll see three icons:

  • Eye hides or shows the preview, so you can compare it with the original.
  • Image takes a screenshot of the page with the preview and posts it in the task as a new comment. Everyone on the task can see it, which makes it handy for getting a client’s approval before publishing.
  • Refresh asks the AI for a new version of the change if you don’t like the first one.

When you’re happy with it, click Do It to apply the exact version you previewed to your WordPress site.

“Do It” makes the change for real. It works through the capabilities below, writing to the actual WordPress site — content, media, themes, settings and the rest. It is not visible to clients or guests.

When you select Do It yourself, the change is applied straight away. When the AI runs a Do It for you from a chat or a task, a change to a published, private or scheduled page waits in the Approval Queue (Beta) until someone approves it. On a draft it runs straight away.

Applying a change with Do It uses no credits. The AI reply or review that suggested the change is charged as usual. Explore Credits & Usage

If Do It is greyed out, hover over it or select it to see why. The message is one of these:

  • Log in to your WordPress to use Do It
  • Your WordPress account can’t edit this page
  • Do It is turned off in the Atarim plugin settings
  • Do It works on individual pages and posts, not on listing pages like the blog or archives
  • Update the Atarim plugin to use Do It
  • Do It isn’t available on this page

On a project without the plugin, Do It has an arrow instead. It lists WordPress and the platforms marked Coming soon. Choose WordPress to open Connect WordPress to use Do It, where Install Plugin opens the plugin’s install page on your site.

Preview changes nothing, an action changes your site
A preview reverses because nothing ever happened. A completed action is a real change to your site, and putting it back is a different job. A content change can be undone from the comment it came from, which restores the element that changed. Where the original content was never captured, undo falls back to restoring that page’s earlier revision instead — which reverts everything else on the page along with it, including edits made after the change you are undoing. Treat the two with different levels of caution — preview freely, and think before you run an action on production.

The plugin exposes a defined set of capabilities on the site, grouped by area. Knowing what is in scope tells you what to expect — and what to be careful about.

The specialist asks for the area it needs rather than the site’s whole list, and runs many operations in a single request instead of one call each. On a site with several plugins active that is the difference between fetching hundreds of operations for every task and fetching the handful the job actually uses, which means less waiting for you and fewer credits spent reaching the same result.

AreaCovers
ContentPosts, pages and the content within them.
Gutenberg and blocksBlock editing and block navigation.
Patterns and templatesReusable patterns and site templates.
MediaThe media library.
Metadata and taxonomiesPost metadata, categories and tags.
Themes, theme files and global stylesTheme-level changes, including site-wide styling.
PluginsPlugin-level operations on the site. Updating a plugin, singly or in bulk, leaves it active.
UsersWordPress user accounts.
SettingsWordPress site settings.
CacheClearing caches after a change. After a Do It, that page is cleared in WP Rocket, W3 Total Cache and WP Super Cache. A CDN without a WordPress plugin is not cleared.
Core updatesWordPress core version updates, alongside the existing plugin and theme updates, so a full update round runs in one go.
BackupsTaking a backup before risky work starts, and restoring a snapshot if a change needs undoing, on sites running JetBackup. Whether a fresh backup is worth the wait is judged per change — a recent snapshot often already covers a small edit.
Image optimizationCompressing a single image, or running a bulk pass, through the optimizer already installed on the site. Optimole is the exception: it optimises automatically through its own CDN, so there is nothing to trigger and only its status can be read.
CodeRunning a PHP snippet when a fix needs code rather than a content change. Administrator only, refused on sites with file editing switched off, and every run is logged.
WP-CLILarge or long-running jobs no other capability covers — a bulk search and replace, a database export, regenerating the media library. Runs in the background where it needs to. Administrator accounts only, refused for anyone else, and every run is recorded in the site’s log.
Security scanChecking the plugins, themes and WordPress core installed on the site against published vulnerability advisories. Read-only.
Page buildersEditing pages built with a page builder. Which builders are covered, and how, is set out under Page Builders It Can Edit below.
Collaborate settings in WordPress with an arrow on the Enable "Do it" via Atarim AI checkbox
Enable Do It option
An AI suggestion in a task thread with an arrow on the Show me button beside Do It
Show Me previews the suggested change on your page. Nothing is saved until you click Do It
The same suggestion with the preview on, showing the eye, image and refresh icons beside Do It
Preview is on. Use the icons to hide it, screenshot it for your client, or ask for a new version
The Do It action carrying out a real change on the WordPress site
“Do It” writes the change
This reaches beyond post content
The capabilities include theme files, plugins, users and site settings. Take a backup before letting AI actions run on production, and try them on staging first — on a site running JetBackup, Atarim can take one itself before starting something risky. The plugin makes the change; it does not second-guess whether you wanted it.
Tip
Plugin installation is one of the actions in that list, and it installs whichever plugin it is asked to. If you have a standard plugin you use for caching, SEO or forms, record those preferences in The Stack so the choice is decided once rather than per site. Discover The Stack

Following changes in the Do It Queue

When you select Do It, the button changes to Queued and the change joins the Do It Queue at the bottom of the collaboration sidebar. Changes run one at a time, in the order you selected them, so you can keep working while they apply.

The queue showsWhat it means
Waiting…The change is lined up behind another one.
Applying changes…The change is being written to your site now.
Changes appliedDone. The task moves to Pending Review. Select Undo this change (the curved arrow) to put it back.
The reason, in redThe change could not be applied. Select Retry to run it again.

Until a change is applied, Remove from queue (the ×) takes it off the list. Removing a change that is already applying does not stop it.

The queue belongs to the page you are on. Reloading or leaving the page clears it, and changes still waiting will not run, so stay on the page until they show Changes applied.

Asking for a change in a chat

Besides selecting Do It on a suggestion, you can describe a change in your own words and have a specialist make it on the connected site.

Instructions:

  1. Open the task for the page in the Inbox, type your request and select Send to Claro, or @-mention a specialist. Or ask in workspace chat (Beta), where typing / offers Work on a WordPress site and Give a site instruction.
  2. Say what to change and where, for example “Change the phone number in the footer to 555-0142.”
  3. Read the reply to see what was changed.
  4. In workspace chat, when the work includes editing a file such as a theme file, an edit card follows it: Queued, Editing, then Completed, Failed or Cancelled. To stop an edit that hasn’t finished, select Cancel edit on its card.
  5. If the change needs approval, it waits until someone approves it. See What Waits for Your Approval.

On a site without the Atarim plugin, the specialist gives you advice and assets but cannot change the site.

Page Builders It Can Edit

The plugin writes through the builder your page was actually built with, rather than editing the HTML underneath it. Which builder is in use is worked out per page.

BuilderWhat Atarim can do
GutenbergFull block editing. The default when no other builder is detected on the page.
ElementorEdit individual elements in place.
Beaver BuilderEdit individual modules in place with the Do It button.
SiteOriginEdit individual widgets in place with the Do It button.
Bricks, Divi, Breakdance, Mosaic, Etch, WPBakeryElement-level editing through each builder’s own structure when you ask the AI in a chat or task. The Do It button does not support these builders yet.
Visual Composer, BrizyNot edited. Atarim recognises these and declines rather than writing.
Why two builders are declined rather than supported
Visual Composer and Brizy compile their layout down into the page’s stored content, so that copy is a build output rather than the source. An edit written there looks like it worked, then disappears the next time somebody opens the builder and saves, because the builder regenerates it. Declining is deliberate: a refusal you can see beats a change that quietly vanishes a week later.

On a page built with a builder the button does not support, Do It looks the same as anywhere else. It does not check the builder before you select it, so if the change cannot be applied, the reason shows in the Do It Queue.

Elementor edits are checked before they are saved. A value that Elementor’s own rules would reject, such as a heading tag outside h1 to h6, is refused up front and reported with the element and setting that failed, rather than saving quietly and then aborting the whole page the next time somebody presses Publish.

Plugins the AI can work with

When one of these plugins is active on the site, the AI gets matching actions automatically. There is nothing to set up.

PluginWhat the AI can do
WooCommerceProducts, variations, upsells and cross-sells, sale prices, attributes, coupons and store email templates. Orders and sales figures are read-only, and it never changes an order or a payment.
Forms: WPForms, Gravity Forms, Fluent Forms, Formidable Forms, Forminator, Ninja Forms, Contact Form 7Read forms and entries, find forms that have stopped receiving submissions, export entries and change notification settings. Most can also create and edit forms.
Custom fields: ACF, Meta Box, JetEngine, Pods, ACPT, ASERead and edit field groups and fields.
SEO: Yoast SEO, Rank Math, All in One SEORead and edit SEO titles and descriptions. Rank Math and All in One SEO also cover schema.

Some actions need the plugin’s paid edition. Redirects need Yoast SEO Premium or AIOSEO Pro, and form entries need WPForms Pro rather than WPForms Lite. Contact Form 7 keeps no entries of its own, so those come from the Flamingo plugin. Deleting any of these things waits for your approval.

Undoing a Change

A content change the AI applies can be put back. How that works depends on what was edited.

  • For Gutenberg and classic content, the edit is saved as a WordPress revision, and undo restores the revision saved just before the change.
  • For Elementor, Beaver Builder and SiteOrigin, Atarim saves the page’s state before each change and keeps the last 10, so undo puts it back.

The control sits on the comment the change came from, so undo is next to the request rather than in a separate history screen.

Note
Undo covers one change at a time. Putting back something wider, such as a page after several edits or a whole site, is the job of WordPress’s own revision history or a backup.

Image Optimization

Rather than adding another optimizer, Atarim drives whichever one is already installed on the site.

OptimizerWhat Atarim can do with it
ShortPixelOptimize one image, run a bulk pass, check how far it has got.
EWWWOptimize one image, run a bulk pass, check how far it has got.
SmushOptimize one image, run a bulk pass, check how far it has got.
reSmush.itOptimize one image, run a bulk pass, check how far it has got.
OptimoleReport its status only. Optimization happens on Optimole’s side rather than through Atarim.
Tip
If a site has no optimizer yet, the Images row in The Stack is where you say which one you want, and installing it is one approval away.

How the Connection Is Secured

An Administrator makes the connection from the site’s WordPress admin, and it belongs to the site rather than to anyone’s WordPress login, so people can change their WordPress passwords without affecting it.

Note
Connecting Claude, Codex or another assistant to Atarim is a separate setup. Explore Atarim MCP

What Waits for Your Approval

The set of actions is different on every site — only the ones your active plugins support are registered, so a plain WordPress site offers a fraction of what a site running WooCommerce and a page builder does. Whatever the set, each action declares at the point it is registered whether it is destructive, and Atarim reads that declaration back from your site before it runs anything.

What the AI asks to doWhat happens
Read somethingRuns. Listing posts, checking which plugins are active, reading a page’s blocks, pulling a report — none of it changes the site.
Create or update something not marked destructiveRuns. Drafting a post, uploading a media file, setting a custom field.
Edit a page in the block editor or a page builderHeld if the page is published, private or scheduled. On a draft it runs straight away.
Activate a theme, update WordPress core, change a user’s roleRuns. These are registered as non-destructive, so they are not held. Worth knowing before you hand core or theme work over.
Anything the plugin marks destructiveHeld. The request goes to the project’s Approval Queue (Beta) naming the exact action and the values it would run with. Nothing reaches your site until you approve it. A request nobody decides on within 14 days is declined automatically, and nothing runs.
Install or activate a pluginHeld in the same queue, as an install request.
Run a WP-CLI commandHeld. It is declared destructive whatever the command itself does, so even a read-only listing waits for approval rather than being judged on the command you can see.

Destructive covers more than deletion. Removing content, terms, menus, media, users or a theme; merging terms; replacing or restoring a theme file; updating, deactivating or deleting a plugin; restoring a revision or a backup; changing global styles, a site template, a navigation menu or a widget area; deleting form entries or a form; removing a product, coupon or product attribute; and deleting a custom field group are all declared destructive, and all of them wait for you. Edits in the block editor or a page builder are judged by the page instead: they wait for you on a published, private or scheduled page, and run straight away on a draft.

Project dashboard panel Your Approval Is Needed, listing pending plugin install requests
A request waiting in the Approval Queue, showing exactly what would run
An install request expanded under Your Approval Is Needed, with Decline and Approve buttons
The Approval Queue with pending request, naming the action and its values

Not everything that changes a site is marked that way, and the exceptions are worth knowing before you hand one over. Activating a theme, updating or reinstalling WordPress core, installing a theme, editing a user or changing their role are all registered as non-destructive, so they run without waiting for you. Running a backup is treated the same way, on the grounds that it adds a snapshot rather than replacing anything — restoring one is held.

Some settings cannot be written the blunt way
Separately from the approval gate, the generic option writer refuses eighteen WordPress options outright, plus the role-to-capability map: your site and home URLs, the administrator email, the active plugin and theme records, the permalink structure, the default role given to new users, whether registration is open, and the mail server credentials. That does not put those values out of reach — the site URL, home URL, administrator email and permalink structure each have their own dedicated, validated ability that can change them. What is blocked is writing them raw through the general-purpose option tool, and each refusal names the ability to use instead. Raw PHP execution and WP-CLI are handled differently again — an unattended workflow run is refused both outright, while on a turn you typed they are available and wait for your approval like any other destructive action.
Note
Two things are worth knowing. If Atarim cannot reach your site to read how an action is declared, the action is refused outright with a site-unreachable message rather than queued for your approval — approving it could not help, because the problem is the connection. Inside a batch it works the other way: an individual operation whose annotation cannot be read is treated as destructive.

Some jobs are too large or too slow for an ordinary page action — replacing a domain across a large database, exporting the database, regenerating a whole media library. For those, Atarim can run a command through WordPress’s own command line on your server. You will not write these yourself: what reaches you is the finished command in the Approval Queue, exactly as it will run, and its output afterwards. Read it the way you would read a command before pasting it into a terminal on a client’s site, because it changes files and database content directly. It is available on administrator accounts only, and every run is recorded in the site’s log.

Security Scan

A connected site can be scanned for known vulnerabilities in the plugins, themes and WordPress core it currently has installed. Where a component matches a published advisory, the scan reports the version sitting on the site alongside the version that fixes the problem — so the question becomes whether to update, rather than whether there is anything to update at all. You can ask for a scan in chat, or from a connected assistant.

Reading is safe: the scan never installs, updates, activates or changes anything, and acting on a finding is an ordinary update that goes through the approval gate like any other. Two results are worth reading properly rather than at a glance. If the site’s installed inventory could not be read, nothing was assessed. And a component reported as untracked was never checked against the advisory data in the first place. Neither of those is a clean bill of health.

Running a scan

Instructions:

  1. In workspace chat (Beta), ask for a scan and say which project, for example “Scan the Bloom Bakery site for known vulnerabilities.” In a project’s own chat, “Scan this site” is enough.
  2. Read the reply. In a project’s own chat, a scan that runs in the background also shows a scan card, which reads Scanning while it checks what is installed.
  3. Read the result. On a scan card, Clean means nothing installed matched an advisory. A count such as 2 vulnerable lists each affected item with its severity and either Update to the fixed version or Abandoned, no fix available. Inventory unavailable means nothing was checked, as described above.
  4. To act on a finding, ask for the update. It waits for your approval like any other plugin update.
  5. After updating, ask for another scan to confirm, or select Scan again on the scan card.

Backups and Restores

These capabilities only appear on sites running JetBackup for WordPress. Without it there is nothing here — there is no generic backup layer behind them.

What you can ask forWhat happens
Take a backupQueues a run of one of your existing JetBackup jobs and reports progress. Nothing is overwritten, so it runs without approval.
Arm a restore pointPrepares a point to roll back to before risky work starts. It is not cover the moment you ask for it: readiness is tracked until the point actually reads as ready, so a point that has only just been requested is not yet protection. A snapshot taken in the last 24 hours is reused rather than run again.
Restore a snapshot by nameA snapshot can be identified by its name rather than its id, so a restore can be asked for in the words you would use yourself.
List and inspect backupsRead-only — which snapshots exist, when they ran, and their logs.
Restore a snapshotWaits for approval. Once approved, Atarim prepares the restore and gives you a recovery link. Nothing is overwritten until someone opens that link. Only people who can edit the workspace can get it, and it lapses after 24 hours.
Manage jobs, schedules and destinationsWhere backups run, when, and where they are stored. Deleting any of these is held for approval.
A restore point is only cover if the restore can reach it
Arming a point on a site that the restore step cannot get back to is not protection — it is a record that something was attempted. Before treating a restore point as your safety net, check that the route back is intact, not just that the point exists. JetBackup also holds only one restore point per site, so arming a new one replaces the one already there.

A restore is by snapshot, never by upload — you cannot hand it a backup file. Files and the database are handled separately, and each can be restored in full, limited to named folders or tables, or skipped altogether; the default is a full restore of both. Only account backups can be restored, and only WordPress administrators can reach any of this.

Opening the recovery link overwrites the site
A restore is the most consequential thing the plugin can do. Opening the recovery link is the step that overwrites the live site, so open it only when you are ready.

Example Use Cases

SituationHow the plugin helps
A staging site behind a passwordCollaborate on the site directly, where a shared public link cannot reach.
A quality pass before a client reviewRun an AI review, then mark the findings internal so the client sees only their own feedback.
A client who keeps emailing questionsGive them guest access so questions land on the page they are about.
Onboarding a new client to a projectShare the collaboration link from the settings screen without leaving WordPress.
A developer joining mid-projectAdd their WordPress role to Who can collaborate so they see the interface when logged in.
Frequent trips into the dashboardOpen Project Settings from inside WordPress instead.
Repeated logins when collaboratingChoose a user under 1 click login from Atarim as so opening the site from Atarim signs you straight in.

What can stop the AI working on your site

The AI reaches your site through the plugin, from Atarim’s servers rather than your browser. Three things on the site’s side can stop it:

  • File editing is switched off in your site’s configuration. The AI cannot run code or create or change theme files. If all file changes are switched off, it also cannot install or update plugins and themes, or update WordPress core.
  • A security plugin or firewall blocks Atarim. If Atarim’s requests to the site are blocked, the AI cannot reach it. Explore Whitelisting Atarim
  • The AI’s WordPress account lacks the rights. The AI acts as the account chosen under 1 click login from Atarim as, so it can only do what that account can. Explore Autologin

Known Limitations

  • PHP 7.4 and WordPress 6.0 are minimums. The AI actions need PHP 8.0 and WordPress 6.9.
  • Plugin settings are separate from Atarim settings. The role picker and 1 click login from Atarim as live in WordPress admin.
  • Settings need Save & Apply. Nothing takes effect until you select it.
  • Consent creates collaborators, not team members. Team membership requires an Atarim invitation.
  • AI actions reach beyond content — including themes, plugins, users and settings.

FAQs

What is the plugin called in WordPress?

Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO and Client Feedback. The current release is version 5.1.6.

What are the minimum requirements?

WordPress 6.0 or later and PHP 7.4 or later. The AI “Do It” action layer additionally requires WordPress 6.9 or later and PHP 8.0 or later — the WordPress Abilities API, available in core from 6.9.

Can I collaborate on staging or protected sites?

Yes. Because the plugin runs on the site itself, it works where a publicly reachable link would not.

Can clients leave feedback without a WordPress account?

Yes, with Guest Mode enabled, or by adding ?collab=true to the page URL.

Can clients trigger AI actions?

No. “Do It” is not visible to clients and guests.

Will tasks created in WordPress appear in the Atarim dashboard?

Yes. The plugin is a way into the same project, so tasks created on the site show up in that project’s views in your dashboard.

Does the plugin replace the Atarim dashboard?

No. It brings collaboration onto the site and puts some project settings within reach, but the dashboard remains where projects, boards and workspace settings live.

Common issues

  • The plugin will not install or activate — check the site runs PHP 7.4 or later and WordPress 6.0 or later.
  • The AI actions are missing although the plugin works — the site is below WordPress 6.9 or PHP 8.0, or Enable "Do it" via Atarim AI is unticked in Settings → Collaborate. Everything else keeps working.
  • No collaboration interface after activation — confirm the site is connected, and that your WordPress role is selected under Who can collaborate.
  • A colleague cannot see the launcher — their role is not selected in the settings, or Guest Mode is off and they are not logged in.
  • Settings changes had no effect — select Save & Apply. The screen does not autosave.
  • Someone joined as a collaborator instead of a team member — invite them to your Atarim account first, using the same email address as their WordPress account.
  • 1 click login signs in but nothing works — the chosen account lacks the permissions it needs. Choose an Administrator under 1 click login from Atarim as.
  • An AI action changed more than expected — restore from backup and run future actions on staging first.
  • The site is behind a firewall and will not connect — whitelist Atarim at the host or WAF level. See the whitelisting guide.

Conclusion

Installation is straightforward: install from the repository or upload the file from your dashboard, connect, then set who can collaborate. The settings worth deliberate thought are the role picker and 1 click login from Atarim as, because both decide who can act on the site.

The plugin also gives Atarim’s AI a defined set of actions it can perform — reaching content, media, themes, plugins, users and settings — on WordPress 6.9 or later with PHP 8.0 or later. Set it up the way you would set up anything with that reach: backup first, staging before production.

Tips & best practices

  • Confirm PHP 7.4 or later before installing, and PHP 8.0 or later if you want the AI actions.
  • Use matching email addresses in WordPress and Atarim so consent recognises team members.
  • Keep Who can collaborate limited to roles that should have it.
  • Pick an Administrator for 1 click login from Atarim as, because the AI acts as that user too.
  • Use ?collab=true to open collaboration on one page without changing settings.
  • Back up before letting AI actions run on production, and try them on staging.
  • Remember to select Save & Apply.

Related articles