Title: PasteTheme
Author: chattanoogatshirt
Published: <strong>miz Here 1, 2026</strong>
Last modified: miz Here 1, 2026

---

Search plugins

![](https://ps.w.org/pastetheme/assets/banner-772x250.png?rev=3722619)

![](https://ps.w.org/pastetheme/assets/icon-256x256.png?rev=3722619)

# PasteTheme

 By [chattanoogatshirt](https://profiles.wordpress.org/chattanoogatshirt/)

[Download](https://downloads.wordpress.org/plugin/pastetheme.0.22.1.zip)

 * [Details](https://bre.wordpress.org/plugins/pastetheme/#description)
 * [Reviews](https://bre.wordpress.org/plugins/pastetheme/#reviews)
 *  [Installation](https://bre.wordpress.org/plugins/pastetheme/#installation)
 * [Development](https://bre.wordpress.org/plugins/pastetheme/#developers)

 [Support](https://wordpress.org/support/plugin/pastetheme/)

## Description

Give ChatGPT, Claude or Gemini the PasteTheme prompt and ask for a section — a hero,
a row of services, a contact form. Paste the code onto a PasteTheme drop zone (or
press Ctrl+V on an empty one). The plugin cleans it, gives it your site’s look through
its own section classes, and turns every heading, paragraph, image and button into
a field you can click and change. Everything else stays exactly as pasted: WordPress
itself refuses to move, remove or insert anything inside the section.

 * **Paste, then edit only your words.** Headings, text, list items, captions, images,
   buttons and videos become fields; layout, spacing and code are locked. A YouTube
   or Vimeo link pasted alone becomes a video section.
 * **A login for the client.** Add your client on WordPress’s own Users  Add User
   screen with the Site owner role (the card on Security & people says how, with
   a button to it): they can change every word and picture, cannot paste, move, 
   delete or restyle a section, and never see the settings.
 * **Re-paste to change the design.** The whole section is replaced; the old version
   stays in the page’s revisions.
 * **Clean by default.** Scripts, style elements, style attributes, stray iframes,
   inline event handlers, meta and base tags, external form actions and HTML comments
   are removed on paste, each with a short warning.
 * **Updates on their own.** One button on Settings ticks WordPress’s own auto-update
   setting for every installed plugin and theme and for WordPress itself.
 * **HTML, styled by the plugin.** A pasted section keeps its markup, stored in 
   the page the way a Custom HTML block is stored; the front end prints it through
   wp_kses with the plugin’s allow-list. Its look comes from the plugin’s own stylesheet
   through a fixed set of class names that the section prompt teaches your AI: a
   content box, two columns, cards in balanced rows, numbered steps, price plans,
   questions, forms, buttons, icons, videos at 16:9, a picture grid, a photo behind
   the words, figures, round portraits, small labels and three color tones, all 
   in your site’s colors, light and dark. The classes work with any theme, and a
   pasted section without the plugin’s section class gets it. A style element, a
   style attribute or a script inside a pasted section is dropped with a warning:
   the plugin stores and prints no CSS or script from a section and has no box for
   either.
 * **Setup first, then eight plain pages.** Setup walks a new site through seven
   steps: name your site, choose your pages, pick your look, get messages from your
   contact form, sell online, switch features on or off, go live. Each step has 
   one button to the screen its setting lives on. Pages & menu, Design, Forms, AI,
   Search & visits, Settings and Security & people hold the rest, grouped by what
   you came to do.
 * **Two switches for your AI.** “Let an AI connect” (off on a new site) and “Safe
   mode” (on for a new site: an AI changes words and pictures; a new section for
   a page that is on the site waits as a revision for you to approve; a new page,
   a page’s details or a ready-made site is refused with a note).
 * **Coming soon or Live.** One choice at the top of Setup: Coming soon shows visitors
   who are not logged in one plain page with your logo while you build; Live opens
   the site.
 * **Pick your pages.** Tick the pages you want (Home, About, Services, Contact,
   Questions, Prices, the privacy policy) and whether each goes in the menu; each
   arrives with a real starter section, and Home becomes the front page.
 * **Section edges.** Straight, a slight curve or a wave where one full-width section
   meets the next, for the whole site; the PasteTheme theme draws the shapes.
 * **Working contact forms.** Paste a form and it sends: a hidden trap field, a 
   fill-time check and a flood guard, always on, then emailed to you with the sender
   as reply-to. The Forms screen puts a ready-made contact form on any page in one
   click, says where messages go, lists every form, and keeps a list of the last
   fifty emails the site tried to send and whether each left (never the message 
   itself). An AI connected to the site changes a form’s fields in place through
   the edit-form ability.
 * **Clear caches in one click.** WordPress, PHP and every caching plugin or host
   cache the plugin recognizes, from the dashboard, the admin bar or an agent ability;
   also after updates.
 * **Faster images.** New JPEG and PNG uploads are saved as WebP as well, and oversized
   originals are shrunk to a sane maximum; nothing you upload is deleted.
 * **Shop-ready.** “Add a shop” in Setup’s Sell online step installs and switches
   on WooCommerce from wordpress.org and hands over to its own store setup; back
   on Setup the step shows your products, payments and whether the store is open.
   Pages with no shop on them skip WooCommerce’s classic stylesheets and its jQuery
   scripts.
 * **Search and sharing, per page.** Title, description and a hide-from-search switch,
   stored as plain post meta with documented names (hidden pages stay out of the
   sitemap too), and Open Graph and Twitter tags on every page: the page’s share
   image when one is set, else its featured image, else your logo, else the site
   icon.
 * **The font your AI asked for.** AI-written sections often name a Google font,
   and the link to Google is stripped on the way in. PasteTheme remembers the name
   and offers it on the Design page: one click downloads the font into your own 
   uploads folder and serves it from your site, so visitors never load anything 
   from Google.
 * **SVG logos.** Administrators who may publish raw HTML can upload SVG files. 
   Each is cleaned first (scripts, event handlers, links that point outside the 
   file), and a file that cannot be made safe is refused with a plain message.
 * **A checkup, in plain words.** A short list in Setup’s Go live step of the things
   that are easy to get wrong: a placeholder site email, automatic updates off, 
   two page caches fighting, mail leaving from the wrong domain, the site hidden
   from search engines, a host that sends CSS and JavaScript uncompressed. Each 
   line says the one thing to do.
 * **Hardened defaults.** Security headers, generic login errors, no user listing
   over REST, ?author= or oEmbed, no file editor, no pingback or version headers,
   login lockouts (five failed attempts from one address lock it out for fifteen
   minutes), XML-RPC off.
 * **Files that do not belong.** Switch it on (Security & people; it is off until
   you do) and once a day the site compares WordPress’s own files and every wordpress.
   org plugin’s files with the lists WordPress.org published for them, and looks
   for code where none belongs and for database dumps a browser could download. 
   You get an email the day something new appears. Two email alerts are on from 
   the start and ask no other server: a new administrator, and a new application
   password for someone who can edit the site.
 * **If you ever leave.** Your words and pictures are ordinary HTML in the page 
   and never depend on the plugin: switch it off and they stay where they are.
 * **Ready-made sections.** Twelve sections in the editor’s inserter (heroes, feature
   cards, about, services with prices, testimonials, call to action, FAQ, contact
   form, two prices, a picture grid, the team), each landing as a locked section
   with editable words on your own colors.
 * **Connect your AI with MCP.** MCP is how AI assistants such as Claude and ChatGPT
   connect to a website. The AI screen gives this site’s address and a “Make a key
   for my AI” button that opens WordPress’s own Authorize Application screen, where
   you approve the connection and WordPress makes the key. A key made this way changes
   the site’s content through PasteTheme’s own tools, never its administration, 
   and with Safe mode on it changes words and pictures only.
 * **Built for agents too.** Fifteen abilities on the WordPress Abilities API list,
   edit and replace sections and make and describe pages, the agent contract ships
   in the plugin folder as docs/AGENTS.md, and the same abilities are an MCP server
   at /wp-json/pastetheme/mcp, all on your own site’s REST API.

Works with any block theme. It is designed for the free PasteTheme theme: with that
theme active, turning the plugin on makes a starter Home page. Everything described
here works with this plugin alone. PasteTheme Pro is a separate plugin from pastetheme.
com with features of its own, such as a form builder that keeps every message, redirects,
more section edges and more ready-made sections.

### External services

Agents and the MCP server are not an outside service: the abilities and /wp-json/
pastetheme/mcp are routes on your own site’s REST API, answered by your own WordPress.
The plugin runs no server of its own, relays nothing and stores no key for any remote
party. An AI client you choose to connect logs in with an application password made
for one of your users and gets only that user’s capabilities. A key made from the
AI screen is limited further, to the site’s content through the PasteTheme abilities:
its only writes through WordPress’s own routes are a picture upload and a named 
list of settings (the site’s name, tagline, logo and icon and PasteTheme’s display
switches), users, plugins, themes, keys, site health, XML-RPC and every other setting
answer 403 to it, and for its requests WordPress holds no plugin, theme, user, import
or export capability. No ability installs, activates or removes plugins or themes,
creates or logs in users, edits code or changes the security settings, and the security
settings are not on the REST settings endpoint.

The “Make a key for my AI” button is not an outside service either. It opens WordPress’s
own Authorize Application screen on your own site (wp-admin/authorize-application.
php); after you approve, WordPress makes the key and, with JavaScript on, sends 
it back to the AI screen after the # in the address, a part browsers never send 
to any server (without JavaScript it arrives in the query, and the AI screen drops
it unread). The plugin never makes, stores, logs or sends it.

This plugin contacts an outside service in three cases started by an administrator’s
click, a fourth only if you choose to add Google Analytics, a fifth only after an
administrator switches on the daily file check, and a sixth only after one switches
on a video switch. Nothing else here contacts an outside service, and the plugin
itself adds nothing from another site to your pages unless you add that Google Analytics
id or a video. Clear caches asks any caching plugin it finds to empty its cache,
and some, such as Cloudflare’s, contact their own service to do it.

Google Fonts: when you add a font on the Design page (or accept one a pasted section
asked for), the plugin asks fonts.googleapis.com which files that family needs, 
then downloads those files from fonts.gstatic.com into wp-content/uploads/pastetheme/
fonts on your own site. It sends the font’s name and, with the file downloads, your
site’s address in WordPress’s browser identifier; nothing about you or your visitors.
The Switch screen’s carry-over does the same for the old theme’s body and heading
fonts, read from that theme’s own settings. It happens only when an administrator
clicks, never on a page visit and never on its own. Google Fonts terms: https://
developers.google.com/fonts/terms · Google privacy policy: https://policies.google.
com/privacy

WordPress.org, to install a plugin: two buttons, Two-step login (the Two Factor 
plugin, on Security & people) and Add a shop (WooCommerce, in Setup’s Sell online
step), install and switch on another plugin from wordpress.org through WordPress’s
own installer. Ticking Shop in the pages picker on Pages & menu and pressing “Make
these pages” installs and switches on WooCommerce the same way; the tick says so.
Each runs only when an administrator clicks: WordPress asks api.wordpress.org for
the plugin by its name and downloads it from downloads.wordpress.org, sending what
every WordPress install request carries (your WordPress version, language and site
address). WordPress.org privacy policy: https://wordpress.org/about/privacy/

Google Analytics: if you paste a Google Analytics 4 Measurement ID on Settings  
Connections & keys, every page loads Google’s tag script from www.googletagmanager.
com for visitors who are not logged in; Google Analytics receives their visits (
the page, the page they came from, their browser and device details and their network
address) and sets its own cookies. Leave the field empty (the default) and nothing
is loaded. Google terms of service: https://policies.google.com/terms · Google privacy
policy: https://policies.google.com/privacy

YouTube and Vimeo: a video in a section plays from www.youtube-nocookie.com (https://
policies.google.com/privacy, https://www.youtube.com/t/terms) or player.vimeo.com(
https://vimeo.com/privacy, https://vimeo.com/terms), like any embedded video. Until
play is pressed the page shows a picture instead: as installed, YouTube’s own thumbnail,
which the visitor’s browser asks i.ytimg.com for with the video’s id; on phones 
and in Safari the player loads once the video is scrolled into view. Two switches
under Settings, Site features, both off until you choose them, make your server 
fetch each thumbnail once (from i.ytimg.com; for Vimeo from vimeo.com/api/oembed.
json, then i.vimeocdn.com; only the video’s address is sent) and keep it in uploads/
pastetheme/video; the second also makes phones wait for the press.
 WordPress.org,
for the daily file check: only after an administrator switches it on (Security &
people  Files that do not belong; off until then), once a day and whenever Check
now is pressed, the plugin asks api.wordpress.org for the published checksums of
your WordPress version and language (kept once fetched: a version’s list never changes)
and downloads.wordpress.org for the published checksums of each installed wordpress.
org plugin, by the plugin’s name and version (kept for a month). Which plugins come
from wordpress.org is read from WordPress’s own update check; the plugin does not
ask for that itself. Like every request WordPress makes, these carry your site’s
address in the browser identifier. The comparison happens on your own server, and
no file, setting or visitor information leaves it. Switching the check off, or deactivating
the plugin, stops it at once. WordPress.org privacy policy: https://wordpress.org/
about/privacy/

Setup’s site checks send nothing when Setup opens. The PHP line reads the answer
WordPress’s own Dashboard and Site Health check already saved (core’s api.wordpress.
org check, kept for a week); until WordPress has checked, the line says to open 
the Dashboard once. The email line looks up your domain’s SPF record (a DNS lookup
of your own domain) only when you press Look up the domain, and keeps the answer
for a week. The “Measure the front page” button fetches your own front page and 
two of its files once, from your own server. None of these sends anything about 
you or your visitors.

## Screenshots

[⌊A home page on the PasteTheme theme with this plugin: chattworks.com, a sample
local jobs board. Every section is a pasted section.⌉⌊A home page on the PasteTheme
theme with this plugin: chattworks.com, a sample local jobs board. Every section
is a pasted section.⌉[

A home page on the PasteTheme theme with this plugin: chattworks.com, a sample local
jobs board. Every section is a pasted section.

[⌊The editor. A pasted section is locked: its headings, text, pictures and buttons
are fields you click and change.⌉⌊The editor. A pasted section is locked: its headings,
text, pictures and buttons are fields you click and change.⌉[

The editor. A pasted section is locked: its headings, text, pictures and buttons
are fields you click and change.

[⌊Setup: Coming soon or Live at the top, then seven steps, each with one button 
to the screen its setting lives on.⌉⌊Setup: Coming soon or Live at the top, then
seven steps, each with one button to the screen its setting lives on.⌉[

Setup: Coming soon or Live at the top, then seven steps, each with one button to
the screen its setting lives on.

[⌊Pages & menu: every page, whether it is on the site and in the menu, and the pages
picker.⌉⌊Pages & menu: every page, whether it is on the site and in the menu, and
the pages picker.⌉[

Pages & menu: every page, whether it is on the site and in the menu, and the pages
picker.

[⌊Design: the name and logo, colors, fonts, the header and footer, and the section
edges.⌉⌊Design: the name and logo, colors, fonts, the header and footer, and the
section edges.⌉[

Design: the name and logo, colors, fonts, the header and footer, and the section
edges.

[⌊Forms: a ready-made contact form, where messages go, every form on the site, and
whether each email left.⌉⌊Forms: a ready-made contact form, where messages go, every
form on the site, and whether each email left.⌉[

Forms: a ready-made contact form, where messages go, every form on the site, and
whether each email left.

[⌊AI: connect your AI over MCP, the two switches, and the prompts to give it.⌉⌊AI:
connect your AI over MCP, the two switches, and the prompts to give it.⌉[

AI: connect your AI over MCP, the two switches, and the prompts to give it.

[⌊Security & people: what is always on, login lockouts, two-step login, a login 
for your client and the daily file check.⌉⌊Security & people: what is always on,
login lockouts, two-step login, a login for your client and the daily file check
.⌉[

Security & people: what is always on, login lockouts, two-step login, a login for
your client and the daily file check.

[⌊The same home page on a phone.⌉⌊The same home page on a phone.⌉[

The same home page on a phone.

## Blocks

This plugin provides 2 blocks.

 *   Section (paste drop zone) Paste AI-generated section code here. PasteTheme 
   locks the structure and opens only the text and images for editing.
 *   Editable field One editable text, image, button or video inside a pasted section.
   Created by the paste pipeline — not inserted by hand.

## Installation

 1. Install and activate the plugin.
 2. Add a “Section” block to any page and paste your code, or press Ctrl+V on the empty
    drop zone.
 3. Open PasteTheme  Setup and follow the steps. Optional: activate the PasteTheme 
    theme first for the design shell, the starter sections and the section edges.

## FAQ

### Do I need to know how to code?

No. Describe what you want to an AI, copy what it gives you, and paste. You never
edit the code.

### Which AI should I use?

Any that writes HTML. Give it the section prompt from PasteTheme  AI and ask for
one section at a time: it writes the words in the HTML and uses PasteTheme’s class
names for the look.

### Why WordPress 7.1?

The section mechanic is built on the way 7.1’s Custom HTML block holds editable 
blocks inside it.

### What changes when I activate it?

Nothing is hidden from visitors: a new site starts live, and Coming soon is a choice
at the top of Setup. What does change: on a brand-new site comments are switched
off, the way a business site has them, while a site that already has content of 
its own keeps them as they were (Settings  Comments switches either way); the private
visit counter starts counting (Search & visits  Visits; it stores the page’s address
and the referring site’s name, never who visited, sets no cookie and skips browsers
that ask not to be tracked); a back-to-top button, a floating header, dark mode 
that follows the visitor’s device and your logo on the login page are on (Settings
Site features); XML-RPC is off and login lockouts are on (Settings  Advanced, Security&
people). On a brand-new site “Let an AI connect” starts off, and while it is off
no application password logs in, for any app (PasteTheme  AI switches it on). With
the PasteTheme theme active, a starter Home page is made and set as the front page,
unless the site already has one. On a brand-new install the section edges start 
on the slight curve with every other section shaded; a site that was here before
stays straight (Design  Section edges). In the admin, for administrators: a Setup
link on the plugin’s row on the Plugins screen, a small PasteTheme Setup box on 
the Dashboard while Setup has steps left (Hide this hides it for good), a Site owner
role in the role list (a login that can change words and pictures only), and Clear
caches in the admin bar. While Setup has steps left, an administrator who logs in
lands on Setup instead of the Dashboard. WordPress’s Dashboard leaves out its Events
and News, Quick Draft and Welcome boxes for every login, and while comments are 
off the Comments menu, its screen and the Dashboard’s comments box are hidden. After
a plugin, theme or WordPress update, or a theme switch, caches are cleared the way
Clear caches does it. The plugin checks nothing against WordPress.org until an administrator
switches on the daily file check (Security & people  Files that do not belong). 
Once it is on, the site checks its own files against WordPress.org’s published lists
once a day, with a count on the PasteTheme menu while anything needs a look and 
an email to the site’s address the same day something new appears; switching it 
off stops it, and deactivating the plugin stops it and switches it off. From the
start, the site’s address gets an email when a login is given the Administrator 
role or an application password is added for someone who can edit the site; these
two alerts go to the site’s own address, contact no other server, and one switch
on the same card turns them off. Developers: the new-site defaults are the PASTETHEME_NEW_SITE_COMING_SOON
and PASTETHEME_NEW_SITE_EDGE constants, each behind a filter (pastetheme_new_site_coming_soon,
pastetheme_section_edge_default).

### How do I connect my AI assistant?

Open PasteTheme  AI and switch on “Let an AI connect”. Copy the site’s address, 
press “Make a key for my AI” and approve on the WordPress screen it opens, then 
give your assistant the two. WordPress makes the key and, with JavaScript on, sends
you back to the AI screen with it after the # in the address, where it is shown 
once (without JavaScript the AI screen cannot show it and says so); the plugin never
makes, stores or sends it. Claude Code works with any site, even one on your own
computer, in one line the AI screen writes for you. Claude, ChatGPT and other apps
that run in the cloud need the site on the public internet, and ChatGPT makes changes
only from a Business, Enterprise or Edu workspace.

The key logs in as you and changes the site’s content through PasteTheme’s own tools:
words, pictures, sections, new pages, page search settings, forms and putting pages
live. Site-wide looks, templates, menus (beyond the links its own website and ready-
made-site tools add), posts, comments, deleting, users, plugins and themes answer
403 to it, and with Safe mode on it changes words and pictures only. Revoke it whenever
you like: the key list on the same screen opens WordPress’s own list of keys on 
that login’s profile.

### Where do contact form messages go?

To the address on PasteTheme  Forms (“Messages go to”); left empty, to the site’s
own admin address. The Email card on the same Forms screen shows whether each email
left.

### How do I change a form?

Its heading, sentences and Send button change with a click, like the rest of the
page. For the fields, ask your AI (it changes them in place) or paste the section
again. A label wrapped around its box, the way many AI-written forms are built, 
is part of the form itself, so it changes the same way as a field.

### Does it work on multisite?

Not in this version. On a sub-site WordPress filters pasted markup and quietly damages
it; the plugin refuses with a clear message instead.

One more limit on any site: an account without the unfiltered_html capability (an
Editor on a multisite network) cannot paste or replace a section, and WordPress 
filters the page’s markup when such an account saves it, exactly as it does for 
a Custom HTML block. Give that person an administrator account to paste sections,
or a Site owner login (Users  Add User) if they only change words and pictures.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“PasteTheme” is open source software. The following people have contributed to this
plugin.

Contributors

 *   [ chattanoogatshirt ](https://profiles.wordpress.org/chattanoogatshirt/)

[Translate “PasteTheme” into your language.](https://translate.wordpress.org/projects/wp-plugins/pastetheme)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/pastetheme/), check
out the [SVN repository](https://plugins.svn.wordpress.org/pastetheme/), or subscribe
to the [development log](https://plugins.trac.wordpress.org/log/pastetheme/) by 
[RSS](https://plugins.trac.wordpress.org/log/pastetheme/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 0.22.1

 * New: a “Footer contact line” on Design, Header & footer. What you type there (
   your email address, phone number and hours) fills the “Get in touch” paragraph
   of the footer that “Make these pages” wrote, for as long as that paragraph is
   still PasteTheme’s own. An AI can set it too (`pastetheme_footer_contact`).
 * Site checks: on a site reached through Cloudflare, a new line says whether wrong
   passwords are counted per visitor, and names the switch that does it (Settings,
   Advanced, “Behind a proxy or load balancer”).
 * Faster first paint: the section stylesheet is small, so WordPress now prints 
   it into the page instead of asking for one more file.
 * Fixed: in a pasted section a row of buttons straight after a row of cards, steps
   or pictures sat against them. It now keeps a gap.
 * The ready-made Contact section no longer mentions adding a photo (its form has
   no file field).

#### 0.22.0

 * New: videos. Paste a YouTube or Vimeo link on its own into a section’s paste 
   box (or have your AI pass it) and it becomes a section with that video. A video
   in any pasted section is now a field: click it in the editor and paste another
   link, or change its name, in the sidebar. Watch pages, youtu.be links, Shorts(
   shown upright), live streams, playlists, start times and vimeo.com links are 
   all read.
 * A video now reaches the visitor as a picture with a play button, and the player
   loads when it is pressed, so the page stays light. On phones and in Safari, which
   do not let that press start a video with sound, the player loads once the visitor
   scrolls to it and one press plays. Two new switches under Settings, Site features,
   both off until you choose them: “Keep video pictures on this site” (your site
   fetches each video’s thumbnail once and serves it itself: sharper, and a Vimeo
   video gets one) and “Load videos only after a click” (nothing is asked of YouTube
   or Vimeo before the press, on any device).
 * The player is asked for YouTube’s cookieless address, to play inside the page
   on a phone, and to suggest videos from the same channel only; it is told which
   page it is on, which YouTube now requires.
 * For agents: list-sections reports video fields with their title, edit-field takes
   a YouTube or Vimeo address for one (alt sets its name), and convert and replace-
   section accept a bare video link.
 * Everything in 0.21.2 below, which was not published here.

#### 0.21.2

 * “Make these pages” points the starter Home page’s two buttons at the Contact 
   page. Before, they led nowhere until you gave each a link.
 * The footer “Make these pages” writes now follows the site: a new site name or
   tagline shows there, a page that leaves the site leaves its Pages list, and a
   link you add to the menu joins it. A line or a list you changed yourself is left
   alone.
 * The edit-field ability takes href for a button field, so a connected AI can say
   where a button goes, and list-sections says where each button goes now.
 * A page a connected AI adds with add-page joins the menu when set-page-live puts
   it on the site, as the tool always said it would.
 * A row of buttons inside a centred section is centred too.
 * A card on a shaded section takes the page color, and a small label (pt-badge)
   is a tint of the text, so both show on any ground.
 * Taking WordPress’s Sample Page off the site in the pages picker no longer makes
   the Switch screen appear on a new site.

#### 0.21.1

 * Switch, step 4: the list of plugins and the old theme is a table again and its
   rows can be ticked. In 0.21.0 the boxes could not be ticked, and on a phone the
   screen scrolled sideways.

#### 0.21.0

 * A style attribute in a pasted section is left out with a short warning, like 
   a style element, so the plugin stores and prints no CSS from a section. A section
   saved before this version keeps its style attributes in the page, but the plugin
   no longer prints them; paste it again with the section prompt.
 * A pasted section element without the plugin’s section class gets it, so it takes
   your site’s look.
 * The section classes now cover icons, videos at 16:9, picture grids, a photo behind
   the words, figures, round portraits and small labels, and the content box, balanced
   rows, numbered steps and light and dark pictures work with any theme.
 * Two new library sections: a picture grid and the team.
 * A YouTube or Vimeo embed keeps its data attributes.
 * The Google font a pasted section asks for is read only from its font link.
 * Authors and Contributors keep the whole block editor in their own posts: only
   a Site owner login has a page’s blocks locked.
 * A key logs in only through the standard Authorization header or the copy the 
   server makes of it, never through a header of another name.
 * The AI key is made on WordPress’s own Authorize Application screen, which “Make
   a key for my AI” opens; you approve there and come back to the AI screen with
   the key (with JavaScript on; without it, the AI screen drops the key unread and
   says to make another). Revoke opens WordPress’s own list of keys on that login’s
   profile. The plugin no longer makes, changes or deletes keys itself.
 * The client login is added on WordPress’s own Users  Add User screen with the 
   Site owner role; the card on Security & people says how and has a button there.
   The plugin no longer makes logins itself, and its line on Users  Add New User
   is gone. Safe mode’s note no longer mentions logins.
 * The daily file check waits for you: it is off until an administrator switches
   it on under Security & people  Files that do not belong, and nothing is asked
   of WordPress.org before then. Which plugins come from wordpress.org is read from
   WordPress’s own update check. The two email alerts are unchanged.
 * Setup’s site checks contact no other server when Setup opens: the PHP line reads
   what WordPress’s Dashboard already checked, and the email-domain line is looked
   up when you press Look up the domain.
 * The Switch no longer reads, shows or copies CSS or code from the old theme or
   from other plugins. Carry-over takes the accent color and the body and heading
   fonts from the old theme’s own settings. A plain page whose markup carries styling
   of its own (a style element, a stylesheet link or a style attribute) is no longer
   converted: it stays as it is, gets a page pack like a builder page, and the Switch
   log names it. The footer box’s log also says when style attributes were left 
   out.

#### 0.20.0

 * A style element in a pasted section is dropped with a short warning, the way 
   a script always was.
 * Sections get their look from the plugin’s own stylesheet through a fixed set 
   of class names: a content box, two columns, cards, price plans, priced lists,
   questions, ticks, facts, forms, buttons and three color tones, in your site’s
   colors, light and dark. The section prompt on the AI screen teaches them to your
   AI.
 * The ten library sections, the starter pages and the ready-made sites use those
   classes instead of style elements of their own. They look the same.
 * A section saved before this version keeps its style element in the page, but 
   the plugin no longer prints it. Paste the section again with the prompt to give
   it the classes.
 * The AI key reaches content only: words, pictures, sections, new pages, page search
   settings, forms, putting pages live, visits, caches and a named list of settings,
   all through the plugin’s abilities. Its writes to WordPress’s own routes are 
   refused except a picture upload (photos only), WordPress gives it no plugin, 
   theme, user, import or export capability, it no longer switches Coming soon or
   reads comments and the other settings, and it does not log in over XML-RPC. A
   ready-made site installed by the AI no longer replaces an existing home page.
 * Two new abilities: add-page makes a draft page, and set-page-details sets a page’s
   title, address, excerpt, featured image, search title, search description and
   hide-from-search switch.
 * WordPress’s Additional CSS is no longer printed a second time by the plugin; 
   WordPress prints it as it always does.
 * The If you ever leave card on Settings is gone: there is nothing left for it 
   to move.
 * The Switch no longer copies the old theme’s CSS into Additional CSS. Its footer
   box drops style elements as well as scripts, and the page-wide style and script
   blocks of the pages it turns into sections are not carried.
 * An SVG animation in a section that changes a link’s address or an event handler
   is refused, and a data: address is kept only as a picture’s source.

#### 0.19.0

 * Files that do not belong (since 0.21.0 it runs only after an administrator switches
   it on): once a day the site compares WordPress’s own files (and any theme WordPress
   ships, while the shipped version is installed) with the files WordPress published
   for your version and language, and every wordpress.org plugin, in use or not,
   with its published files; it looks for code in the uploads folder or loose in
   wp-content, for a settings file that makes PHP run a hidden file first, for code
   that reaches into WordPress’s folders by a back way, for a .maintenance file 
   an update left behind, for files the known backdoor kit of September 2026 left,
   and for database dumps a browser could download. On a big site the plugin comparison
   and the uploads folder carry on where the last run stopped; an earlier finding
   the check could not get back to stays listed. A count on the menu, a line in 
   Site checks, the list with what to do on Security & people (Check now, Block 
   web access to these folders, and This one is fine on a file you know), and an
   email the same day something new appears.
 * Alerts: an email the moment a login is given the Administrator role through WordPress(
   a new user, a role change, a profile edit, or a plugin using WordPress’s user
   functions) or an application password is added for someone who can edit the site,
   saying who did it; at most ten an hour of each. On by default; a switch on the
   same card.
 * Login lockouts are kept in one setting of their own, so clearing caches no longer
   lifts them.
 * A password-protected page no longer shows the start of its text as its search
   and sharing description.
 * Login lockouts behind a proxy read the address the proxy added (the last X-Forwarded-
   For entry), so a forged header no longer slips past them.
 * Site checks says when WordPress was installed here and that its installer has
   been closed since, and names any plugin that is installed but switched off.
 * The shop page (WooCommerce) and the blog’s posts page now carry their own page’s
   search title, description, share picture and share address, the way every other
   page does; before, a listing had none.
 * The oEmbed answer (what another site gets when it embeds one of your pages) no
   longer names the page’s author or links to an author address; it names the site.
   A login-guessing run read usernames that way.

#### 0.18.6

 * Switch, step 3: the pages WordPress draws itself (Shop, Cart, Checkout, My account)
   no longer offer “Copy the page pack” and “See the old page”; there is nothing
   on them to copy.
 * Nothing else changes on a site. The readme’s Description is shorter (the directory
   shows the whole of it now) and one Save-button line carries its escaping note
   for Plugin Check.

#### 0.18.5

 * A form’s hidden fields, and any check a plugin adds to the form, now sit right
   above the Send button instead of after it, so a visitor meets a challenge before
   pressing Send.

#### 0.18.4

 * Replacing a section that holds a form (a new design pasted over the old one, 
   by hand or by an AI) keeps the form’s settings: its thank-you words, and what
   another plugin set on it. Before, a re-paste reset them.

#### 0.18.3

 * The settings a key from the AI screen may change are a named list now (the site’s
   name, tagline, logo and icon; the PasteTheme switches, colors, image, section-
   edge and dark-mode settings) instead of “every PasteTheme setting but a few”:
   a setting added later stays with a person signed in to the dashboard until it
   is named. The visits counter switch joins the mail and analytics settings on 
   the person-only side.
 * A refusal from an ability’s own permission check (a Site owner login asked to
   paste a section, an account without unfiltered_html) reaches the AI with its 
   reason, on the MCP route too, instead of a bare “does not have necessary permission”.
 * Settings > Connections & keys: “Remove the saved password” is a switch row like
   every other setting.
 * A card with fewer than three rows keeps its Save button in place instead of pinning
   it to the bottom of the window.

#### 0.18.2

 * A key made with “Make a key for my AI” now reaches the site’s content only: the
   PasteTheme abilities and MCP route, pages, posts, media, menus, patterns, templates,
   the PasteTheme settings, and the site’s name, tagline, logo and icon. Other users,
   plugins, themes, the mail and analytics settings, the other WordPress settings,
   site health and key management answer 403 to it, whoever made it (it may read
   its own login). With Safe mode on, its page, menu, design and settings writes
   are refused too; pictures still upload. A key made on a user’s profile is WordPress’s
   own and is not changed. (0.20.0 narrowed this to content through the abilities.)
 * Putting a page live through the set-page-live ability checks the page’s own publish
   capability (publish_pages) by name.

#### 0.18.1

 * The ten library sections, the four starter pages and the ready-made sites now
   say what goes in each place (“Your headline: what you do, in one line”, “A customer’s
   words, in their own voice”) instead of sample words about a made-up business.
   Nothing reads as if it came with WordPress, and nothing can go live by mistake
   as someone else’s copy. The layouts and the editable fields are the same.

#### 0.18.0

 * One shape for every setting: a row with its name on the left, the control on 
   the right and one sentence under it; on/off is a switch; each card has one Save
   that stays in view while you scroll. Every card on every screen is drawn this
   way now. Nothing changed in what is saved.
 * Connections & keys, a new card on Settings: every login and key the site uses
   in one place (the Google Analytics id and the mailbox login for now; other plugins
   add theirs). The screens that use one say so and link there.
 * AI screen: two switches. “Let an AI connect” is off on a brand-new site, and 
   while it is off no key works. “Safe mode” is on for a brand-new site: an AI changes
   words and pictures; a new section for a page that is on the site is saved as 
   a revision for you to approve; a new page or a ready-made site is refused with
   a note. A site that was here before keeps working as it did (both switches unset).
 * After login an administrator lands on PasteTheme’s Setup screen, and WordPress’s
   Dashboard no longer shows “WordPress Events and News”, “Quick Draft” or the Welcome
   panel.

#### 0.17.2

 * One home for every setting. Setup’s steps no longer repeat the forms that live
   on Design, Pages & menu, Forms, Settings and Security & people: each step keeps
   its status line and has one button to the screen where the setting is. Extras
   is four buttons.
 * The pages picker and the ready-made sites are on Pages & menu, under the page
   and menu list.
 * Email (sender, SMTP, the test and the recent emails) is on Forms, next to the
   forms that send it; the “Did it send?” card is gone because the Email card says
   the same thing.
 * The AI screen opens with what your AI can do and the two things it needs; the
   rest is folded.
 * Caches: “Last cleared … ago” no longer names who cleared it.

#### 0.17.1

 * Forms: the handler reads only the fields the form itself declares (their names
   are signed into the form when the page is drawn); anything else posted is ignored.
   A page cached before this update shows “could not be sent” until its cache is
   cleared, which the plugin does itself after its own update.
 * SVG uploads: only for administrators who may publish raw HTML, a file with markup
   inside a style or title element is refused, and an animation may not target any
   namespaced href.
 * “Make these pages” no longer closes comments on posts that already exist; closing
   them all stays a tick of its own on Settings, Comments.
 * A site that already has content of its own keeps its comments on when the plugin
   is first activated; a brand-new site still starts with comments off.
 * Fixed: with comments off, a block theme still showed a post’s earlier comments.
   They are hidden there too now, as on a classic theme; nothing is deleted.

#### 0.17.0

 * The PasteTheme menu is regrouped by what people come to do: Setup, Pages & menu,
   Design, Forms, AI, Search & visits, Settings and Security & people, plus the 
   Switch while another theme left something to move. Setup takes Home’s address,
   so every old link lands on it.
 * Setup: seven steps, each with one sentence, a status line and where it lives 
   afterwards, and Coming soon or Live at the top, which reads and sets WooCommerce’s
   own Coming soon too, so there is one answer. A new site starts live.
 * The pages picker: Home, About, Services, Contact, Questions and Prices, each 
   with a real starter section, the privacy policy and the shop, each with its own“
   In the menu” tick. WordPress’s automatic every-page menu is replaced by the pages
   you ticked.
 * Section edges on Setup and Design: straight, a slight curve or a wave, with a
   live preview in the site’s own colors, light and dark, drawn by the PasteTheme
   theme.
 * Forms and AI are screens of their own. Forms holds your contact form, every form
   on the site, spam protection and whether the last email left. AI holds connecting
   your AI over MCP, the prompts for your AI, every key on the site with when it
   was last used, and the switch that keeps AI training crawlers out.
 * The Form panel left the section sidebar. Pasted forms still send, and the edit-
   form ability still adds, removes, reorders and renames a form’s fields in place.
 * A page ticked for the menu joins it when it is published, not while it is a draft,
   and a page moved to the trash takes its menu link with it and gets it back in
   the same place when it is published again.
 * The agent contract moved to docs/AGENTS.md, and the section and agent prompts
   describe only this plugin.
 * Settings  Privacy gets suggested policy text: what the forms, the visit counter,
   the login lockout and the email log keep, and the Google Analytics case.
 * Deleting the plugin removes the Site owner role; a login with that role keeps
   its account, and reinstalling the plugin gives the role back.
 * Pictures and video players below a page’s first section load when they are scrolled
   to; a picture from the media library gets WordPress’s wp-image class, so a phone
   downloads a smaller copy; a block theme’s pages with no shop content leave out
   WooCommerce’s classic stylesheets and its jQuery scripts.
 * No ?author= address names a login any more.

#### 0.13.0 to 0.16.0

 * Earlier releases: the admin grouped by task, the section library, the MCP server,
   the image, email, font and shop settings, the rule that stops uploaded files 
   running as PHP (written only when an administrator presses its button), the Switch’s
   cleanup list (nothing ticked until you tick it), and the answers to the first
   wordpress.org review rounds (every style and script on WordPress’s queue, sections
   printed through wp_kses with an allow-list, no script attribute and no CSS box,
   and the security settings off the REST settings endpoint).

## Meta

 *  Version **0.22.1**
 *  Last updated **6 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 7.1 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 8.0 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/pastetheme/)
 * Tags
 * [AI](https://bre.wordpress.org/plugins/tags/ai/)[blocks](https://bre.wordpress.org/plugins/tags/blocks/)
   [paste](https://bre.wordpress.org/plugins/tags/paste/)[sections](https://bre.wordpress.org/plugins/tags/sections/)
   [site setup](https://bre.wordpress.org/plugins/tags/site-setup/)
 *  [Advanced View](https://bre.wordpress.org/plugins/pastetheme/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/pastetheme/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/pastetheme/reviews/)

## Contributors

 *   [ chattanoogatshirt ](https://profiles.wordpress.org/chattanoogatshirt/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/pastetheme/)

## Donate

Would you like to support the advancement of this plugin?

 [ Donate to this plugin ](https://pastetheme.com/support/)