WP BaseStation

What's in the 100 tools

Every capability is listed here — 51 free tools, 49 Pro, nothing behind a contact-us. Five groups: build, audit, protect, the WordPress side of a site, and the agency tools for moving work between sites. Everything here works on any theme; every builder-specific claim is re-measured against Divi 5.12.

Build

Real pages from prompts, on Divi 5 or the block editor — the same block markup the editor writes.

  • The authoring rules for your builder, served from your own install, so Claude works to the builder you actually have — not to whatever Divi documentation it was trained on
  • Pages, sections and modules, created and edited in place
  • A render probe that reads the CSS Divi actually emitted for every block, so “saved” can never pass for “styled”
  • Loop Builder and dynamic content — a loop pointed at any query, module fields bound to real post data, and display conditions on any section
  • Your design system read from the pages you already built — shadows, radii, borders, spacing, type and palette, proposed as a scale you can adopt in one click
  • Global colours, variables and gradients as design tokens
  • Module presets, so pages restyle when the brand changes
  • Theme Builder headers, footers and templates
  • Pattern library — save a section once, reuse it anywhere
  • WooCommerce shop, cart and product layouts
  • Media uploads with alt text prompted on every upload

Building pages →
Design system & patterns →
Beyond pages →

Audit

Seven engines, and every one states what it cannot see.

  • Site QA — the client-can-edit-it guarantee, checked on every page
  • Accessibility — headings, alt text, link text, contrast, the Divi-specific defects generic checkers miss — and, from the rendered page, the theme itself: language, skip link, landmarks, zoom, form labels, button names
  • Performance — image weight, module counts, nesting depth, resolved against your media library
  • SEO — how your pages are built to rank; it cannot see rankings or volume, and says so
  • Legal — expected documents, whether they're published, and what your site actually loads
  • Design Guardian — a fixed list of dated patterns, plus heading sizes checked against your own type scale
  • Site Health — new in 2.1: the install itself. Versions against their support windows, pending updates, abandoned plugins, security posture, database bloat, mail deliverability, WordPress core's own Site Health tests — on any theme, any builder, with one-click hardening fixes

How the audits work →
Automatic fixes →
On a schedule →

Protect

Built for other people's sites, so it refuses writes it can't verify.

  • Snapshots before every design-system write, with restore
  • One step back before every page write — a WordPress revision, or a saved copy of the previous content where revisions are switched off
  • Site history — what changed, and whether it was Claude or you
  • A 2,437-check self-test you can run on your own install, measured against Divi 5.12
  • Owner safety switches: draft-only, read-only, confirm-overwrite, protected design system
  • Licence keys activated in wp-admin, with seats you can move when a site retires

Snapshots & switches →
Diagnostics →

For agencies

The tools for a book of client sites.

  • Site memory — record a convention once (palette rules, tone, always do X here) and it is injected into every future session, so you never re-explain your rules
  • Site-to-site page transfer, with the design tokens a page depends on
  • Rescue audit — Divi 4 shortcodes, orphaned plugins, classic-editor sediment, with an ordered fix plan
  • Client-ready reports that lead with what changed
  • Scheduled audits — a site that drifts tells you before a client does
  • Style guide generator from the site's own design system
  • Legal page drafts from what the site actually loads

Rescuing an older site →

Site — new in 2.0

Every job used to end with “ask the owner to do it in wp-admin” three times. These nine tools end that — they work on any WordPress site, whatever the theme or builder.

  • Site setup — title, tagline, front page and posts page, read and written (a draft is refused as the front page)
  • Menus — read every menu and location; build or extend one, with every item validated before anything is created
  • Forms — finds Gravity Forms, Contact Form 7, WPForms, Ninja, Fluent and Formidable forms, with the shortcode to place each
  • Media search across the library, so an existing image is reused instead of re-uploaded
  • Broken-link check — internal and external, live status codes, cached so a rerun is cheap
  • Search & replace across pages — dry-run by default, structure-verified after the write, refuses needles that could corrupt Divi markup
  • SEO title and meta description per page — into Yoast, Rank Math or SEOPress if present, otherwise printed by Autopilot itself
  • Structured data — JSON-LD per page, with fabricated ratings and reviews refused

What changed in 2.1.0 →

Site Health — new in 2.1

The seventh audit reads the install, not the pages — so it works on any theme with any builder, and it is the first thing to run on a site you did not build.

  • WordPress, PHP and database versions against their support windows; pending core, plugin and theme updates (a same-branch security release is a failure, not a warning)
  • Inactive plugins, and plugins with no wordpress.org release in two years
  • Security posture — guessable admin logins, open registration, XML-RPC, user enumeration, missing login protection or backups, default salts, security headers, version disclosure, mixed content, a browsable uploads folder
  • Database bloat — autoloaded options past WordPress's own line, revision and transient backlogs, orphaned meta
  • Content hygiene — sample content still published, soft 404s, robots.txt, empty menu locations, comments open with no spam protection
  • Mail — SPF, DMARC and MX for your domain, and whether mail leaves through PHP mail()
  • WordPress core's own Site Health tests, folded in
  • Every network probe is cached, time-boxed and reported as unchecked by name when it cannot run — a short list is never read as a clean one
  • Seven hardening switches, each reversible and undoable: XML-RPC off, hidden versions, no user enumeration, security headers, HSTS, file editors off, sitemap in robots.txt — applied from the finding with one call

What changed in 2.1.0 →

Audit the whole site free. Fix one page.

Free gives you 51 of the 100 tools: every auditor, run read-only across your whole site, the site reads (setup, menus, forms, media, broken links), and fixes on one page — the first one you point it at. No card, no time limit. Pro unlocks the other 49 — writes on every page, the design system, Theme Builder, presets, patterns, menus and search & replace.