The WordPress of AI

Issue #594

WP Edge Newsletter Issue #594 featured image
Sent On August 17, 2026

Recent Issues

Man, with everything happening, it is harder and harder to NOT have an issue of this newsletter which talks about AI. And I promise, this is NOT an AI newsletter! 😇 But, here’s the thing… AI is touching everything. Not only how solopreneurs run their business, but WordPress itself.

Last week, Claude made a move which directly affects anybody using it to “write” blog posts, emails, sales pages, etc. If you make content with Claude, you should know this. And, Claude won’t be the only one.

And… I love WordPress because of digital sovereignty. You own and control your own platform. But, what about AI? Well, I’m making moves internally… and setting up a tool I consider to be “the WordPress of AI”. You may find it interesting.

OK, let’s dance…


AI Content Just Got A Lot Easier To Catch

So Anthropic (the company behind Claude, which… yeah, I use constantly, more on that in a second) just announced something that broke a small corner of the internet last week.

Every bit of text Claude generates now, invisible watermark. Baked in. Can’t see it, can’t feel it, but it’s there… a statistical fingerprint in the word choices that lets anyone with the right key prove “yep, AI wrote this.” Images get it too, as signed metadata.

Why now? The EU AI Act. There’s a transparency rule that kicked in August 2nd requiring AI companies to mark generated content in a machine-readable way. So this isn’t Anthropic waking up one day feeling philosophical. They’re following EU law, but being super proactive about it and rolling it out world wide. Whether we like it or not.

Right now, it is all about Claude. But, they’re not alone. OpenAI (aka ChatGPT) has committed to do it, too, but just hasn’t launched it yet. Google has been doing it for awhile, even watermarking images you make with Gemini. Grok (for now) is the one big holdout. They’ve refused to sign the voluntary version of this EU law. Grok is still subject to it, though, so it’ll be interesting to see what happens there. Point is… I think this watermarking thing is going to be quite normal.

But the reaction wasn’t “oh, a compliance update, and it’s industry-wide.” People are mad. Like, canceling-their-subscription mad. Lot of social media chatter and arguing about it. I’m seeing 4 different points here…

First… the “don’t catch me” crowd. Some people are annoyed because this makes it a lot easier to catch someone who quietly had AI write their essay, their email, their whatever, and passed it off as fully theirs. Honestly? I think that’s a fine outcome. If a student is having Claude write their paper start to finish, getting caught is kind of the point of a watermark. I’m not losing sleep over that one. 🤷‍♂️

And here’s the funny part… it’s already not that hard to beat, if you’re determined. Within days of the announcement, a whole corner of X was picking the thing apart. Turns out there are two flavors of watermark. A cheap one that hides weird invisible characters and spacing in the text (trivial to strip once you know to look for it), and a much tougher one baked into the actual word choices at a statistical level. Anthropic’s own writeup admits the second kind survives light edits but a genuine rewrite… changing enough words and sentence structure… breaks the pattern. Which, if you think about it, means the watermark mostly catches the lazy copy-paste crowd, not anyone actually motivated to hide it.

Second… the content marketing angle, and this one actually matters to you. If AI text becomes reliably detectable, that opens a door. Platforms, readers, maybe even search engines could start treating “AI-touched” as a strike against the content, whether or not it’s actually any good. We don’t know yet whether Google will use this as a ranking signal. Probably not directly… but “probably not” isn’t the same as “definitely not,” and it’s worth watching. The bigger, more immediate risk is just human perception… people already have a bias that AI-touched content is worth less, and now that bias has a tool to act on.

Third… the sovereignty complaint. A chunk of the backlash isn’t really about being caught at all. It’s that Anthropic made this decision for users without asking. You didn’t get a vote. Your output changed underneath you because a regulator in Brussels said so. I get why that stings, even if I think the alternative (nobody discloses anything, ever) is worse for everybody long-term.

Fourth… is using AI even “creation” the same way unassisted writing is?

Here’s the thing. If I sit down, work out what I actually think about a topic, organize my own thoughts, and then use Claude to help me structure and articulate them… did AI “create” that? Or did I create it, and just used a tool to get it out of my head faster?

Think of a carpenter with a power drill. Nobody drags him for not using a hand screwdriver. Nobody watermarks the cabinet to say “assembled with electric tools, buyer beware.” The drill is a tool. The ideas, the design, the decisions… those are his.

A lot of the anger at Anthropic, if you dig past the surface, is really this question wearing a different coat: is AI just a tool now? Or is it something else, something that taints whatever it touches, no matter how much human thinking went into the final product?

Anyway, regardless of your own personal thoughts about whether this is right or wrong… it is happening. And if you’re using AI to help you create blog posts, emails, etc… you should be aware of this. More details will be forthcoming. The market will react and it will all settle out and be normal.


The Inside Scoop

So, here’s a little operational change to Concierge. Nothing changes for my clients, but it does mean better security for you.

See… if you pay much attention to the WordPress space, you might have noticed a big pickup in security releases. More frequent WordPress patches, followed by a wave of emails saying WordPress auto-updated itself. And more security notices and incremental plugin releases as developers fix security holes. Of course, this is being driven by AI. AI is being used to find and detect security issues. All of this is a good thing, actually.

But, it does mean more frequent updates. In fact, I think it was WordPress 7.0.3 that was released on a Friday, and some other people who manage client sites were lamenting, “why would they possibly release a core update right before the weekend?” 😜 Well, because it fixed security issues. And the same AI tools the good guys use to find and patch security issues… are being used by the bad guys to find and exploit them.

So, weekly updates for sites for all Concierge clients has been my norm for awhile. That’s already more than most companies… since may do it once per month and think it is fine. That might have worked before, but not anymore.

So, I’m now checking on things TWICE per week. Across the board. Every client site I manage as part of Concierge. I’m also paying closer attention to plugin changelogs, security advisories, emails from plugin developers, etc. And my goal is to make such updates to client sites in a timely manner and, usually, before the client even notices. In fact, about a week ago, a vulnerability was surfaced in the Stripe plugin for WooCommerce. Instant update was recommended. One of my clients got the same email I did and forwarded it to me to see if it was a problem. Yes, it was… but… I had already updated the entire Concierge fleet. No issues. 😎

So, that’s the change. I’m watching closely. Moving faster when it matters.

Keep in mind, if your site is running unlicensed plugins, I can’t be as fast about that. That requires a very manual process… and sometimes I don’t even have access to it. So, just a general reminder… it is worth it to maintain active licenses to the plugins you’re running on your site. Especially these days, those updates are coming at us fast and furious.

WordPress News & Updates

WordPress shipped 7.0.4, patching a nearly decade-old bug that let a plain image file execute code. If a site runs Imagick with Ghostscript, an Author-level account (more common than you’d think, if you’ve got any contributors) could disguise a file as an image and get real code to run. No public exploit yet, but it’s a same-day update, not a someday one.

A security researcher is calling something in WPForms Lite a “backdoor,” and WPForms isn’t thrilled about the word choice. Version 2.0.0 (5 million+ installs) quietly hands a one-hour login token to WPForms’ own servers during setup, letting their system install plugins on your site without asking first. One writer actually tested it before forming an opinion, worth a read either way. Personally, I’m already not a big fan of Awesome Motive plugins, as auto-installs and other aggressive tactics are par for the course.

A whole family of BdThemes plugins got hit by a genuinely clever supply-chain attack. Attackers poisoned the JSON feed that powers admin dashboard promo banners across seven plugins (Element Pack, Ultimate Post Kit, and others), quietly planting rogue admin accounts and a webshell using your own logged-in session. The plugins got pulled from the repo while it gets sorted out.

Turns out 2,385 plugins are quietly rigging what you see on the “Add New Plugin” screen. A scan of 63,619 WordPress.org plugins found vendors using hooks to bury competitors and promote themselves in search results, right inside your own dashboard. The full breakdown names names, and it’s a little eye-opening.

FluentSnippets just crossed 50,000 active installs, and the founder finally told the origin story. WordPress.org rejected his original plugin outright, so he bought a dead, ~1,000-install plugin called Easy Code Manager off its original developer and rebuilt it from the inside… which is why the URL still says “easy-code-manager” today. Worth a read if you’ve ever wondered about that.

WordPress finally shipped an official browser extension. Chrome and Safari, lets you hide the admin bar with one click on the sites you choose (bringing it back takes two), plus some handy shortcuts for developers and content folks. Available now if you want to try it.

FluentCart now lives natively inside the Divi 5 builder. Eighteen modules, no more pasting shortcodes into a text box and hoping it renders right. Pro users also got one-click saved payment methods for repeat customers. The release notes are here if you’re running a store on Divi.

Fluent Forms shipped an MCP server, so you can now point Claude or Cursor straight at your form data. Ask it things like “which form got the most submissions last month” and it’ll actually go look. Off by default, a couple minutes to turn on. Setup details here.

A cooling failure at one Phoenix data center took down a surprising chunk of the internet’s plumbing at once. Namecheap hosting, DNS, and email all went dark for about 30 hours, and Hosting.com… which absorbed Rocket.net last year… got hit too, since they share the same facility. Namecheap’s own writeup is worth reading, if only as a reminder that “the cloud” is still just a building somewhere.

223 vulnerabilities across 176 plugins, in one week. That’s this week’s Wordfence count, and it ties right back into everything we’ve talked about the last couple issues. Keep those updates running.


I’m Building My WordPress of AI

That whole watermark saga from the first article? It’s really just one specific example of a bigger pattern I keep bumping into: the tools we build our businesses on can change under us, and we don’t get a vote.

Anthropic didn’t ask permission before changing how Claude behaves. Neither does any platform, ever, really, when you get down to it. That’s the deal you make when your whole operation depends on somebody else’s infrastructure.

Whether it is a proprietary website builder, a video platform, a social media algorithm you rely on for traffic… when you build core functionality of your business on somebody else’s platform, you’re a dependent. And you don’t control the rules… they do.

The same exact thing applies to our usage of AI. In fact, these companies KNOW that, too… and it is why prices are kinda cheap. Those monthly subscription plans are cheaper than the actual token cost of the AI you’re using. Those plans are, in essence, subsidized. They’re doing that to get you HOOKED. To increase their market share and the pain of disconnect.

So, funny timing… last week I took shipment of a little computer called a DGX Spark. Built specifically for running AI locally, in-office.

Not gonna lie… this little thing is freakin’ expensive. I paid about $4600 for it. And if you’ve looked much into local AI, you know full well how the prices of hardware have shot through the roof because of the sheer amount of demand.

Anyway, remember last month (in issue #590) when I built a local AI on a spare mini PC and told you plainly it sucked? 😜 I even said the DGX Spark looked interesting but too finicky, and that I’d probably end up going the Mac route instead. Well… I changed my mind. Ask me again in a month, I said. Here we are. 😇 I bought a Spark.

But this article isn’t really about the hardware. It’s about something I’m doing alongside it that matters more.

I’m quietly moving my day-to-day AI driver off of Claude Desktop and over to a tool called Hermes… specifically the Hermes agent and Hermes desktop app. And no, I’m not going to get technical about setting that up. That’s not the point today.

The point is… with Claude Desktop, I’m locked into Claude’s models. Same deal if you’re living in ChatGPT… locked into OpenAI. With Hermes, the model becomes a dropdown. I can point it at a model running locally, right here in my office on that little DGX Spark. Or I can point it at any number of cloud-based models. My choice. Any time.

Now, the AI tooling that I am building… my workflows and my intellectual property of how I use AI… is now all moving into an environment I fully own and control. It is like… the WordPress of AI. 😇 And just like WordPress where I can choose to host it anywhere I want and move it around as my mind changes… now Hermes allows me to plug any AI model I want into my infrastructure.

If Claude’s model pisses me off, I just switch to another one. I can plug and play models from different companies with just a dropdown. Or… even use my self-hosted AI sitting right over in the corner of my office.

This is digital sovereignty. Something I’ve been banging the drum about for YEARS now.

It’s why I like WordPress so much. You own the platform. Even a licensed plugin is just code, running on your own hosting, that you control. Let the license lapse and the plugin still runs, because it’s your site. Nobody can reach in and turn it off.

AI, as most of us use it today, is the opposite of that. We’re all building fairly sophisticated systems on tools that only work because one specific corporation lets them work. And that corporation can change the deal any time it wants… just like the watermark thing, just like every social platform and website builder before it. They can also change the pricing, too… which is something quite likely to happen as time goes on, IMO.

The DGX Spark can’t run everything. I can’t run models on that thing that compare with the big guns. So, I will still use models from Anthropic, OpenAI, DeepSeek, etc. I can use the right model for the right job… and I use my own local model (currently using Qwen 3.8) as my default.

There’s a genuine privacy win in this too, and not just for me personally. Some of what I do for Concierge clients involves sensitive stuff… site data, credentials, business details. I’ve had a couple of clients ask me about this. Since I make no secret of the fact that I use AI as a tool for Concierge. Was sensitive data from clients being sent up to Anthropic?

I have a real answer to that one now. Trust me, I was always taking that issue seriously, but now I have an option that means literally NOTHING would be sent to Anthropic.

If you’re integrating AI more and more into what you do, I encourage you to look at digital sovereignty and how it applies to AI, too. It doesn’t mean you run out and buy a $5K computer, but it could mean you at least set up the software infrastructure in a way where you’re not so baked into one corporation’s AI that… you could never leave.


Curious what I do?


Be On A First-Name Basis With Your “Web Guy”


  • WP Speed Fix. Get the performance scores and core web vitals for your website fixed. Let me deal with the nerdy stuff. And let’s make your site purr like a kitten.
  • Technical Service: Going cross-eyed with WordPress plugins, theme changes, membership site setup, automations? Having difficulty making it all work? I can handle it. Ala carte work, as needed. No contracts.
  • Book A Call Anytime!. You can book either a strategy call (to talk strategy and planning) or an implementation session (where we’ll work on your site together).
  • ONEPass – All Access Pass To Every Course In The Library. For one small one-time purchase, you can unlock every course in the Blog Marketing Academy library. For life.
  • Get Some Anytime Credits. Use credits on your account to book development work or calls. Credits don’t expire, so services are flexible and “pay as you go”.

The WP Edge is the official weekly newsletter of the Blog Marketing Academy.
Sent every Monday.