BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
WAC POST icon
Actively maintained Tested with WP 7.1

WAC POST

The WAC POST plugin registers secure endpoints to create and manage posts from the WeAreContent platform with full SEO integration.

Active installs<10New
Downloads · 30d235▲ 5.6× vs prev. 30d
Rating—0 reviews
Health score64/100Good
All-time downloads452Since Apr 2026
Support resolved—No recent threads
RequiresWP 5.0PHP 7.4+
Downloads · 7d26▼ -75% week over week
Our verdict

Solid choice

WAC POST is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 1 week ago, and scores 64/100 on our health check.

  • Actively developed — last update 1 week ago
  • Tested with the latest WordPress (7.1)
  • Small user base (<10 active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

71523Jul 5Aug 18Oct 2
Yesterday5
Daily average (1y)3
Peak day31Sep 22, 2026
Last 12 months466

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where WAC POST stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
posts >100 10,000 Best posts plugins →
rankmath #95 301 Best rankmath plugins →
rest-api >100 7,513 Best rest-api plugins →
seo >100 8,327 Best seo plugins →
Yoast >100 2,339 Best Yoast plugins →

About WAC POST

From the official readme · v4.2.2

Description

The WAC POST plugin provides a robust integration between the WeAreContent platform and WordPress sites. It registers two specialized REST API endpoints designed for secure, high-performance content delivery.

These endpoints are strictly protected by a three-layer security model:
1. IP Whitelisting: Access is only granted to authorized IP addresses (local and remote dynamic lists).
2. Application Key: Every request must include a valid X-WACPO-App-Key header, compared using a timing-safe check.
3. Author Capability Check: The configured Default Content Author must have permission to publish posts, verified server-side on every request.

No WordPress username, password, or native Application Password is required to authorize the connection. Content received through the API is attributed to the Administrator or Editor selected in Default Content Author.

Security design note (v4.2.0)

Earlier versions additionally required a native WordPress Application Password tied to a specific user account. That requirement has been intentionally removed: it did not add meaningful security on top of the Application Key, but it forced every site owner to create a WordPress user and generate an application password by hand, which was the leading cause of failed/abandoned setups. The security boundary has not weakened — it moved from “a WordPress user session plus a key” to “two independent, site-owner-controlled secrets that must both match” (Application Key + IP address), plus a real server-side capability check against the configured Default Content Author (fails closed if that user cannot publish posts). Author attribution, which used to be inferred implicitly from the WordPress user session, is now an explicit, admin-only setting that can only ever resolve to a real local user, never to caller-supplied data.

Available Endpoints:
* POST /wp-json/wac/v2/create-and-seo-post: Create new posts including featured images, secondary media, and full SEO metadata.
* POST /wp-json/wac/v2/postsys: Update SEO metadata and keywords for existing posts.
* GET /wp-json/wac/v2/ping: Lightweight, read-only connectivity check to verify the Application Key and see the configured default author, without creating any content.

External Services

This plugin relies on external services provided by WeAreContent to ensure secure integration and media processing. By using this plugin, you acknowledge and agree to the terms of these third-party services:

  1. WeAreContent Auth-IP List:

    • Service: A remote security list hosted at app.wearecontent.com.
    • Purpose: Provides a dynamic list of authorized MD5 IP hashes to secure REST API endpoints via IP Whitelisting.
    • Data processed: The plugin only fetches security hashes from the server; no user or website data is transmitted to WeAreContent during this process.
    • Terms of Service: https://www.wearecontent.com/terminos-y-condiciones
    • Privacy Policy: https://www.wearecontent.com/tratamiento-de-datos
  2. WeAreContent Media Server:

    • Service: A dedicated media hosting platform (files.wearecontent.com).
    • Purpose: Allows the plugin to download and sideload featured images and extra media assets directly into the WordPress library.
    • Data processed: The plugin performs a secure download of media files to the local server; no personal user data is sent to the external host.
    • Terms of Service: https://www.wearecontent.com/terminos-y-condiciones
    • Privacy Policy: https://www.wearecontent.com/tratamiento-de-datos

Features

  • Secure REST Endpoints: Dedicated points for content creation and metadata updates.
  • IP Security & Proxy Support: Advanced detection of real client IPs behind Cloudflare, Nginx, or other proxies.
  • Custom Authentication: Secure header-based validation via a unique Application Key.
  • SEO Integration: Automatic mapping of metadata for both Yoast SEO and RankMath SEO.
  • Automated Media Management: Downloads and attaches featured images and in-content media from authorized hosts.
  • Smart Taxonomy Handling: Automatically creates categories and tags if they do not exist on the site.
  • Privacy Ready: Includes suggested text for the site’s privacy policy regarding technical data processing.
  • Translation Ready: Fully internationalized with support for multiple locales.

Installation

  1. Upload the plugin folder to the /wp-content/plugins/ directory, or install the plugin through the WordPress plugins screen directly.
  2. Activate the plugin through the ‘Plugins’ screen in WordPress.
  3. Go to Settings > WAC Post and click “Generate Secure Key” to create your Application Key.
  4. Select the Default Content Author that content received from WeAreContent should be attributed to.
  5. Copy the Application Key into the WeAreContent platform. No WordPress username or password is needed.

Frequently asked questions

How is endpoint security guaranteed?

Access is restricted by three layers: a custom Application Key (X-WACPO-App-Key, compared with a timing-safe function), IP address validation (via local and remote whitelists), and a server-side check that the configured Default Content Author has permission to publish posts.

Do I need to create a WordPress user or Application Password for WeAreContent?

No. Starting with version 4.2.0, the plugin no longer relies on WordPress user logins or native Application Passwords. You only need to copy the Application Key generated on the plugin’s settings page and choose a Default Content Author.

Which SEO plugins are supported?

The plugin automatically detects and maps SEO titles, descriptions, and focus keywords for Yoast SEO and RankMath SEO.

Is it safe for the plugin to download external images?

Yes. The plugin uses a whitelist of allowed hosts (e.g., files.wearecontent.com), validates MIME types, and checks file sizes before processing and adding them to the library.

Does the plugin handle data privacy?

Yes. It includes a privacy policy content generator to inform users about technical data processing and authorized external connections.

What happens if a post category does not exist?

The plugin will automatically create the category or tag using the name or slug provided in the REST request.

Changelog

4.2.2

  • Fixed: SEO metadata sent to create-and-seo-post (titleSeo, metaDesc, focusKw) was silently discarded since 4.1.3. It is now mapped again to Yoast SEO (_yoast_wpseo_title, _yoast_wpseo_metadesc, _yoast_wpseo_focuskw) and/or Rank Math (rank_math_title, rank_math_description, rank_math_focus_keyword), depending on which plugin is active. If neither is active the post is still created and the SEO fields are skipped.
  • Fixed: categories and tags were silently discarded since 4.1.3. They are resolved again by slug or name (array or comma-separated string), creating missing terms.
  • Fixed: duplicate-slug detection never worked (the slug was being passed as the post status to post_exists()), and the requested slug is now verified after the post is created.
  • Fixed: status is restricted again to publish, draft, pending or private (defaults to draft).
  • Changed: the maximum size for images received through the API is now 1 MB for both the featured image and extra images (previously 300 KB and 200 KB, which silently discarded most images). It can be adjusted with the wacpo_max_image_bytes filter.
  • Improved: the create-and-seo-post response now also returns slug, seo_meta, categories, tags and warnings (e.g. images skipped for exceeding the size limit), so the caller can confirm what was stored instead of images being dropped silently.

4.2.1

  • Fixed: content sent via content was being stripped of all HTML (paragraphs, headings, bold) before it could be sanitized with wp_kses_post(), because the request-wide sanitization pass ran sanitize_text_field() on every field indiscriminately, including content. The content field is now excluded from that generic pass and sanitized with wp_kses_post() instead, so paragraph and heading formatting is preserved as intended.
  • Improved: IP addresses pasted into “Authorized IP Hash(es)” are now automatically converted to their hash before being saved, so a site’s real IP is never stored in plain text by mistake. Values that are already a hash are left untouched.

4.2.0

Authentication redesign (deliberate, not a regression — see “Security design note” above and inline docblocks in class-wacpo-security.php for the full rationale):
* Removed dependency on WordPress user login and native Application Passwords for API authentication; this was a significant source of setup friction and support requests for site owners.
* Added a “Default Content Author” setting, editable only by users with manage_options, to explicitly attribute posts created via the API — this value is always a real local user ID (falling back to the site’s first Administrator), never derived from request input.
* Added a server-side capability check against the configured Default Content Author (fails closed with a 403 error if that user cannot publish posts), in addition to the Application Key + IP whitelist.

4.1.4

  • Hardened the Application Key comparison to use hash_equals(), preventing timing attacks (previously used a direct string comparison).
  • Added a GET /wp-json/wac/v2/ping endpoint so the Application Key and WordPress permissions can be verified without creating any content.

4.1.3

  • Added management menu in the admin dashboard.
  • Implemented full internationalization (i18n) support.
  • Optimized security logic and code standards for WordPress.org compliance.

4.1.2

  • Added support for detecting real client IP behind proxies/CDN (Cloudflare, Nginx, etc.).
  • Added support for RankMath SEO integration.
  • Improved logging for IP detection debugging.

Full changelog on WordPress.org →

Screenshots

WAC POST settings page: Application Key, Default Content Author, IP whitelist, and allowed image hosts.
WAC POST settings page: Application Key, Default Content Author, IP whitelist, and…

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best WAC POST alternatives

All posts plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 GenerateBlocks GenerateBlocks A small collection of lightweight WordPress blocks that can accomplish nearly anything. by Tom 200K+ ★★★★★★★★★★ 4.9 (122) 2 months ago 80
2 Post Duplicator Post Duplicator Creates functionality to duplicate any and all post types, including taxonomies & custom… by metaphorcreations 200K+ ★★★★★★★★★★ 4.8 (80) 1 month ago 84
3 WP Popular Posts WP Popular Posts A highly customizable, easy-to-use popular posts plugin! by Hector Cabrera 100K+ ★★★★★★★★★★ 4.5 (249) 6 days ago 94
4 Public Post Preview Public Post Preview Allow anonymous users to preview a draft of a post before it is published. by Dominik Schilling 100K+ ★★★★★★★★★★ 4.5 (80) 4 months ago 79
5 YARPP – Yet Another Related Posts Plugin YARPP – Yet Another Related Posts Plugin The best WordPress plugin for displaying related posts. Simple and flexible, with a… by YARPP 100K+ ★★★★★★★★★★ 4.8 (1.2K) 2 years ago 40
6 WP Meta and Date Remover WP Meta and Date Remover Remove meta author and date information from posts and pages. Hide from Humans and Search… by prasadkirpekar 90K+ ★★★★★★★★★★ 4.2 (71) 4 months ago 77
7 Display Posts – Easy lists, grids, navigation, and more Display Posts – Easy lists, grids, navigation, and more Add a listing of content on your website using a simple shortcode. Filter the results by… by Bill Erickson 80K+ ★★★★★★★★★★ 4.8 (164) 2 years ago 51
8 List category posts List category posts Very customizable plugin to list posts by category (or tag, author and more) in a post… by Fernando Briano 80K+ ★★★★★★★★★★ 4.7 (254) 3 months ago 71
9 WP Telegram (Auto Post and Notifications) WP Telegram (Auto Post and Notifications) Integrate your WordPress site perfectly with Telegram with full control. by WP Socio 30K+ ★★★★★★★★★★ 5 (426) 8 months ago 52
10 WP Admin UI Customize WP Admin UI Customize Customize the management screen UI. by gqevu6bsiz 30K+ ★★★★★★★★★★ 4.6 (59) 2 years ago 49

FAQ

WAC POST: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 3, 2026

Is WAC POST free?

Yes. WAC POST is free to download and use from the official WordPress.org plugin directory.

Is WAC POST safe to use in 2026?

WAC POST is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 1 week ago, and scores 64/100 on our health check.

How many websites use WAC POST?

WAC POST is active on <10 WordPress websites and has been downloaded 452 times since it launched in April 2026. It was downloaded 235 times in the last 30 days.

Does WAC POST work with WordPress 7.1?

Yes. The developer has tested WAC POST up to WordPress 7.1.2, the latest release. It requires WordPress 5.0 or newer.

What PHP version does WAC POST need?

WAC POST requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was WAC POST last updated?

The latest version, 4.2.2, was released on September 24, 2026 (1 week ago).

Who makes WAC POST?

WAC POST is developed and maintained by desarrollowac.

What are the best alternatives to WAC POST?

The most popular alternatives to WAC POST are GenerateBlocks (200K+ installs), Post Duplicator (200K+ installs) and WP Popular Posts (100K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.