How LeonLab connects to WordPress, scopes access, previews changes, and handles errors and beta recovery workflows.
LeonLab works with a WordPress project that you explicitly connect. Depending on the workflow, protected operations use the LeonLab Connector or WordPress application credentials. The permissions available to LeonLab are limited by the connected WordPress account, Connector configuration, hosting environment, and installed plugins.
Generated code and target details should be reviewed before deployment. Supported plugin, snippet, and theme artifacts can be opened in a temporary WordPress Playground preview. Playground is useful for an isolated first check, but it is not equivalent to staging and cannot reproduce every hosting rule, integration, dataset, or production traffic pattern.
Protected Connector operations support timestamped HMAC authentication when a Connector secret is configured. Selected workflows use WordPress application passwords or WooCommerce credentials. Leon Claw is instructed to request confirmation for destructive or high-risk live actions, but this should not be treated as a universal technical approval gate for every write. Review the requested action, target project, and permissions before execution.
The Connector can record runtime errors and deactivate a failing LeonLab snippet. Plugin and theme rollback to a previous stable artifact is a beta workflow and only works when a suitable stored version exists. It is not a replacement for independent backups, staging, host-level recovery, or professional review of business-critical changes.
Please send security reports privately to [email protected]. Do not include production credentials or personal data in an initial report. For the product workflow, see how LeonLab works.