I run a football club's WordPress website by talking to it
ClaudiaClaudia·1 October 2026·5 min read

I run a football club's WordPress website by talking to it

I look after the website for a local non-league football club. Match programmes, fixtures, squad photos, the "next up" panel on the homepage. The kind of job that eats a Sunday evening every week and nobody thanks you for.

Now I open Claude, type "sync the men's fixtures" or "build the programme for Saturday", and it does it. It shows me what it is about to change first, I say yes, and it goes.

The interesting part is not the asking. It is the connection underneath it, because that is where people get themselves in trouble.

None of this is about football

The club is just my example. Everything here works the same on any WordPress site: a shop, a charity, a one-page business site. If it runs WordPress, it already has what you need.

Start here, because everything else depends on it

The obvious way to let an AI change your website is to hand over your admin username and password. There is a far better way, and it is already built into WordPress.

Not this
Your admin login
  • Can publish, delete, install plugins, add users
  • No way to tell what made which change
  • Turning it off means locking yourself out too
  • One password, shared with everything
Do this
An Application Password
  • Created per tool and named, so you know what it is for
  • Revoked on its own without touching your login
  • Connect three tools, get three passwords
  • Found in WP Admin under your own profile

If you take one thing from this article

Make an Application Password and use that. WP Admin, Users, your profile, scroll down to Application Passwords. Name it something like "Match Bot". You see the password once, so copy it somewhere safe.

The four parts of a safe setup

None of this is clever. All of it is the difference between a useful tool and handing over your website.

A named Application Password

One per tool, revocable on its own. Never the login you use yourself.

Credentials out of the project

They live in one local settings file that is excluded from version control, with an example file alongside it holding no real values.

Keys in the configuration, not the theme

Anything the site itself needs is defined once in the main configuration file. The theme refers to it by name and carries no secret.

Everything through the official API

No database access, no FTP. WordPress rules still apply, so the tool can only do what that user is allowed to do.

The third one is the part most people get wrong. A theme file gets edited, copied, backed up and sometimes shared. Put a key inside it and the key goes everywhere it goes.

Order matters here

Set the key in the configuration file before you deploy the theme that uses it. Do it the other way round and every one of those calls fails and parts of the site go blank. It is not a fun ten minutes.

Why the API point matters more than it sounds

Going through WordPress's own API means your existing permissions keep working. Connect as an editor rather than an administrator and the tool simply cannot install a plugin, however nicely anyone asks it to.

Direct database access throws all of that away. So does FTP. The front door exists for a reason.

You might wonder how anything knows where to send a request in the first place. It is the same on every WordPress site, and it is published. Every site answers at /wp-json/, and asking for that address returns a list of everything that site allows and what each one expects. So nothing is guessed. The tool asks your site what it can do, and your site tells it.

It shows you first

Claude previews what it is going to do before it does it. A list of what will change, then it waits for you.

This sounds minor and it is the whole difference between useful and terrifying. I have caught real mistakes at that step, including a change about to hit the wrong fixture because two opponents had similar names.

A note on which Claude

I use Claude Code, which runs in a folder on my machine, because that is where I work anyway. It is not the only way.

Claude Desktop can connect to a WordPress site too, through its connectors, and there are ready-made WordPress ones including one from Automattic, who make WordPress.com. I have not set it up that way, so I am not going to pretend to walk you through it.

What I can tell you is that it changes nothing about the advice above. Those connectors authenticate with Application Passwords as well. Whichever route you take, the same password is doing the work, and it should still be a named one you can revoke on its own.

Two things nobody warns you about

Is it worth it

For a volunteer-run club, easily. The weekly job that used to eat an evening is now a sentence.

The setup is about an hour, most of which is reading your own settings screens. If you run a club, a charity or a small business on WordPress, that is the shape of it.

Not sure what you need yet? Start here.

No email requiredNo sales call neededGet a ballpark estimate in minutes
I run a football club's WordPress website by talking to it | All Trouser Digital