Rankealo

WordPress (self-hosted)

Connect a self-hosted WordPress site with an Application Password. Once connected, Rankealo can publish new articles and update existing ones directly on your site — no copy and paste.

Self-hosted vs. WordPress.com

This guide covers self-hosted WordPress (your own wordpress.org install), which uses an Application Password. If your site is hosted on WordPress.com, use the WordPress.com guide instead — it connects with an OAuth access token.

What you'll need#

  • Admin access to your WordPress dashboard.
  • A user with the Author, Editor or Administrator role — it needs the publish_posts and upload_files capabilities. Contributor and Subscriber roles cannot publish or upload images, and Test Connection will tell you so.
  • Your site served over HTTPS — Application Passwords are disabled on non-secure sites.
  • WordPress 5.6 or newer (Application Passwords are built in since 5.6).
  • The WordPress REST API reachable (it is on by default; some security plugins block it).

Step 1 — Create an Application Password#

An Application Password is a secure, revocable key that lets Rankealo publish and update posts without your main account password.

  1. 1
    Log in to your WordPress admin dashboard.
  2. 2
    Go to Users → Profile.
  3. 3
    Scroll down to the Application Passwords section.
  4. 4
    Enter a name (for example, Rankealo SEO) and click Add New Application Password.
  5. 5
    Copy the generated password immediately — WordPress only shows it once.

Copy it now

The Application Password is displayed a single time. If you lose it, revoke it and generate a new one from the same screen. You can revoke Rankealo's access here at any time.

Reference: WordPress Application Passwords guide.

Step 2 — Connect in Rankealo#

In Rankealo, open Integrations, choose WordPress (Self-Hosted), and fill in these fields:

FieldRequiredWhere to find it
WordPress Site URLRequiredYour site's base URL, e.g. https://yoursite.com. Must be HTTPS.
UsernameRequiredThe WordPress username the Application Password belongs to.
Application PasswordRequiredThe password from Step 1 (format xxxx xxxx xxxx xxxx xxxx xxxx). Paste it including the spaces.

Click Test Connection. Rankealo verifies the credentials against your site's REST API — you must see a successful test before Save Integration becomes available. Once saved, the integration is ready for publishing.

Updating credentials later

Secrets are write-only. When you reopen a saved integration, the password field shows “leave blank to keep existing”— only re-enter it if you're rotating the key.

What gets synced#

When Rankealo publishes to WordPress, each article carries:

  • TitleThe post title.
  • ContentFull article body as HTML.
  • Meta descriptionUsed as the post excerpt.
  • SlugA stable slug derived from the title, set when the post is first created.
  • Featured imageUploaded to your media library (with alt text) and set as the featured image.
  • SEO title, description and focus keywordSent to Yoast SEO, Rank Math and AIOSEO fields — see "SEO plugin fields" below.

Tags and categories are not synced; assign them in WordPress after publishing.

SEO plugin fields (Yoast, Rank Math, AIOSEO)#

WordPress only accepts SEO plugin fields over the REST API when the plugin exposes them. After each publish or update Rankealo reads the post back; if the fields were not saved, the article is marked as partially published with the warning “SEO meta not saved”. The post itself is live.

  • Yoast SEO: Yoast does not register its meta keys for REST. Add a small snippet (for example in a code-snippets plugin) that calls register_post_meta with show_in_rest => true for _yoast_wpseo_title, _yoast_wpseo_metadesc and _yoast_wpseo_focuskw on post (and page if you publish pages).
  • Rank Math: Rank Math exposes its fields through its own REST endpoint (/wp-json/rankmath/v1/updateMeta) rather than meta, so the read-back may warn even on a working setup. Set the Rank Math fields inside WordPress if you need them.
  • AIOSEO: register _aioseo_title and _aioseo_description for REST the same way as Yoast, or edit them in the AIOSEO panel.

Updates & re-publishing#

Rankealo tracks the WordPress post it created for each article. When an article is edited — or automatically re-optimized by Improvements — Rankealo updates the same post in place rather than creating a duplicate. You keep one canonical URL and its history.

Deleting an article in Rankealo permanently deletes the WordPress post (it bypasses the WordPress trash). If the post was already removed in WordPress, the delete is treated as done.

Troubleshooting#

Test connection fails with an authentication error+
Double-check the username matches the account that owns the Application Password, and that you pasted the password with its spaces. Regenerate the password if unsure.
Application Passwords section is missing in my profile+
It only appears on HTTPS sites running WordPress 5.6+. Confirm your site loads over https://and that Application Passwords aren't disabled by a plugin or host policy.
Connection works but publishing is blocked+
A security plugin (Wordfence, iThemes, etc.) or a firewall may be blocking the REST API or the /wp-json/route. Allow REST API access for your user, or whitelist Rankealo's requests.
Featured image did not appear+
Ensure your user role can upload media. Images are pushed to the media library before being attached to the post.

Still stuck? Contact support

Reading is step one. Measuring your AI visibility is step two.

Rankealo tracks how often your brand is mentioned and cited across the major AI engines, then helps you publish the pages that close the gaps.