Rank Math has temporarily paused its new Support Agent after Sybre Waaijer (founder of The SEO Framework plugin) raised concerns about how the feature created and sent WordPress Application Passwords. The Support Agent was introduced in Rank Math SEO 1.0.277, and version 1.0.277.2 has now removed it while Rank Math rebuilds the access-request flow.
Rank Math Support Agent raised application password concerns
Waaijer identified the file vendor/groupone/wap-client/includes/class-app-password-manager.php and said it creates a WordPress Application Password for the administrator when the “Help & Support” panel is opened on a site connected to a free Rank Math account. He said the credential is then sent to group.one’s servers without the administrator being asked to approve it.
He also said the “Terms & Conditions” checkbox shown in the panel does not prevent the credential from being created or sent, with the transfer beginning before the checkbox appears.
Gaurav Tiwari tested it out and said, “ WTF. This is correct. Their Terms of Service doesn’t say anything about this. I didn’t even send a message.”
Waaijer also highlighted that the Application Password carries the administrator’s permissions and has no capability scopes. Based on that, he said the credential could be used to install and activate plugins, change settings, create administrator accounts, and edit or delete content.
The Application Password appears in the user’s profile as “WAP – Rank Math Support Agent,” according to Waaijer. He said closing the Help & Support panel does not revoke it, the password does not expire, and there is no option to turn off the Support Agent credential. He recommended that users who opened Help & Support while connected revoke Application Passwords beginning with “WAP –”.
Rank Math removed Support Agent and addressed concerns
Rank Math said the Support Agent was introduced in version 1.0.277 as part of its plans for “Agentic SEO.” The company said the agent needed access to site settings to answer support questions and that opening the Help & Support panel created a WordPress Application Password to provide that access.
In version 1.0.277.2, Rank Math removed the Support Agent, saying no new credentials would be created. The company said the credentials generated by the earlier version were encrypted, were not stored or persisted on its side, and were used only while an agent session was running.
Rank Math also said the Support Agent was read-only and could not make changes to a WordPress website and that the agent operated with the current user’s role and did not elevate beyond it.
They also acknowledged that the plugin had not clearly explained that credentials were being generated for AI agents, saying, “That feedback is fair, and we take responsibility for making this clearer.”
Rank Math said it plans to bring the Support Agent back after updating the access-request process, with users being asked to approve the required access before any credentials are created or access is provided.
Waaijer on Rank Math’s explanation
Waaijer responded to Rank Math’s explanation and said encryption did not prevent group.one’s servers from accessing the credentials, and that saying they were not stored by Rank Math did not change the fact that the Application Password remained in the WordPress account and did not expire. He agreed that the agent did not elevate a user’s permissions, but said an administrator’s Application Password would still provide administrator-level access.
He also disputed the read-only description, saying the Application Password itself could be used through the WordPress REST API, XML-RPC, and Rank Math’s API. While agreeing that users should be clearly told when an AI agent is being given access, he said Rank Math had not addressed his concern that the password was created and sent before the terms and conditions were accepted.
Mullenweg proposes security audits
Mullenweg also posted on Slack about the security requirements for plugins with administrative and update capabilities. He called for such plugins to undergo an infrastructure security audit, saying, “We need to only allow these admin and management plugins that go through an infrastructure security audit.”
He said he was confident in Automattic’s plugins but claimed that “AwesomeMotive, RankMath, etc have been recently hacked.” Mullenweg also described administrative and update capabilities from those plugins as “more a back door than a service” and warned that failing to apply the same standards could mean “we’re just creating botnets on expensive well-connected accounts all over the internet.”
Three months ago, Awesome Motive’s portfolio suffered security breaches affecting five products: Uncanny Automator, OptinMonster, TrustPulse, PushEngage, and MonsterInsights. Also, Rank Math did not suffer a breach, contrary to Mullenweg’s claim.
Waaijer had raised a similar concern about WPForms Lite last month, saying its servers could act on behalf of administrators during the plugin’s setup process. After Waaijer highlighted the issue, Awesome Motive later updated the plugin and added a notice saying, “You will be transferred to a WPForms.com site to complete the setup wizard.”