WordPress (self-hosted)
Connect a self-hosted WordPress site with an Application Password. Once connected, Rankealo can publish new articles and update existing ones directly on your site — no copy and paste.
Self-hosted vs. WordPress.com
This guide covers self-hosted WordPress (your own wordpress.org install), which uses an Application Password. If your site is hosted on WordPress.com, use the WordPress.com guide instead — it connects with an OAuth access token.What you'll need#
- Admin access to your WordPress dashboard.
- A user with the Author, Editor or Administrator role — it needs the
publish_postsandupload_filescapabilities. Contributor and Subscriber roles cannot publish or upload images, and Test Connection will tell you so. - Your site served over HTTPS — Application Passwords are disabled on non-secure sites.
- WordPress 5.6 or newer (Application Passwords are built in since 5.6).
- The WordPress REST API reachable (it is on by default; some security plugins block it).
Step 1 — Create an Application Password#
An Application Password is a secure, revocable key that lets Rankealo publish and update posts without your main account password.
- 1Log in to your WordPress admin dashboard.
- 2Go to Users → Profile.
- 3Scroll down to the Application Passwords section.
- 4Enter a name (for example, Rankealo SEO) and click Add New Application Password.
- 5Copy the generated password immediately — WordPress only shows it once.
Copy it now
The Application Password is displayed a single time. If you lose it, revoke it and generate a new one from the same screen. You can revoke Rankealo's access here at any time.Reference: WordPress Application Passwords guide.
Step 2 — Connect in Rankealo#
In Rankealo, open Integrations, choose WordPress (Self-Hosted), and fill in these fields:
| Field | Required | Where to find it |
|---|---|---|
| WordPress Site URL | Required | Your site's base URL, e.g. https://yoursite.com. Must be HTTPS. |
| Username | Required | The WordPress username the Application Password belongs to. |
| Application Password | Required | The password from Step 1 (format xxxx xxxx xxxx xxxx xxxx xxxx). Paste it including the spaces. |
Click Test Connection. Rankealo verifies the credentials against your site's REST API — you must see a successful test before Save Integration becomes available. Once saved, the integration is ready for publishing.
Updating credentials later
Secrets are write-only. When you reopen a saved integration, the password field shows “leave blank to keep existing”— only re-enter it if you're rotating the key.What gets synced#
When Rankealo publishes to WordPress, each article carries:
- TitleThe post title.
- ContentFull article body as HTML.
- Meta descriptionUsed as the post excerpt.
- SlugA stable slug derived from the title, set when the post is first created.
- Featured imageUploaded to your media library (with alt text) and set as the featured image.
- SEO title, description and focus keywordSent to Yoast SEO, Rank Math and AIOSEO fields — see "SEO plugin fields" below.
Tags and categories are not synced; assign them in WordPress after publishing.
SEO plugin fields (Yoast, Rank Math, AIOSEO)#
WordPress only accepts SEO plugin fields over the REST API when the plugin exposes them. After each publish or update Rankealo reads the post back; if the fields were not saved, the article is marked as partially published with the warning “SEO meta not saved”. The post itself is live.
- Yoast SEO: Yoast does not register its meta keys for REST. Add a small snippet (for example in a code-snippets plugin) that calls
register_post_metawithshow_in_rest => truefor_yoast_wpseo_title,_yoast_wpseo_metadescand_yoast_wpseo_focuskwonpost(andpageif you publish pages). - Rank Math: Rank Math exposes its fields through its own REST endpoint (
/wp-json/rankmath/v1/updateMeta) rather thanmeta, so the read-back may warn even on a working setup. Set the Rank Math fields inside WordPress if you need them. - AIOSEO: register
_aioseo_titleand_aioseo_descriptionfor REST the same way as Yoast, or edit them in the AIOSEO panel.
Updates & re-publishing#
Rankealo tracks the WordPress post it created for each article. When an article is edited — or automatically re-optimized by Improvements — Rankealo updates the same post in place rather than creating a duplicate. You keep one canonical URL and its history.
Deleting an article in Rankealo permanently deletes the WordPress post (it bypasses the WordPress trash). If the post was already removed in WordPress, the delete is treated as done.
Troubleshooting#
Test connection fails with an authentication error+
Application Passwords section is missing in my profile+
https://and that Application Passwords aren't disabled by a plugin or host policy.Connection works but publishing is blocked+
/wp-json/route. Allow REST API access for your user, or whitelist Rankealo's requests.Featured image did not appear+
Still stuck? Contact support
