Hostinger Agent and Kodee: Safe WordPress AI Guide

A current guide to the unified Hostinger Agent experience, formerly Kodee and specialized AI Agents, covering WordPress actions, content, SEO, permissions, backups, privacy, verification, and safe operating controls.

Hostinger Agent and Kodee: Safe WordPress AI Guide

Hostinger's AI tools have changed quickly. Kodee began as an hPanel support assistant, while specialized business agents handled writing, SEO, marketing, legal drafts, customer communication, sales, and planning. Hostinger has now announced that these experiences are being merged into a unified product called Hostinger Agent.

The name change matters because the assistant can do more than generate text. Depending on the account, hosting plan, connected site, and active feature, it can answer support questions, guide troubleshooting, draft business material, navigate account tools, and perform selected actions on Hostinger services or WordPress.

That convenience also changes the risk. A weak blog draft is easy to correct. An incorrect action affecting users, plugins, domains, products, DNS, content, or site settings can create downtime, data loss, security exposure, or customer confusion.

This guide explains the current Hostinger Agent model, the earlier Kodee and AI Agents terminology, WordPress access, business-agent skills, permissions, safe prompting, approvals, backups, verification, privacy, incident handling, and suitable use cases.

Key Takeaways

  • Hostinger has merged Kodee and its specialized Agents experience into the unified Hostinger Agent interface.
  • Available features depend on plan, account, rollout, context, and connected services.
  • Separate advice, draft creation, and state-changing actions because they require different controls.
  • Use least-privilege accounts and separate revocable credentials for external WordPress connections.
  • Back up and create a rollback point before high-impact site changes.
  • Ask for a plan and preview before authorizing destructive, public, financial, security, user, plugin, theme, or domain changes.
  • Review AI-generated SEO, marketing, customer, legal, and business output with accountable specialists where needed.
  • Never put secrets, unrestricted customer exports, or unnecessary personal data into chat.
  • Verify outcomes in the authoritative system; a confident response is not proof that an action succeeded.
  • Keep an audit log of requests, approvals, changes, tests, and rollback decisions.

What Happened to Kodee and Hostinger AI Agents?

Hostinger's current new Agent experience announcement says Kodee and specialized Agent experiences have been merged into one Hostinger Agent.

The unified assistant is available through hPanel entry points such as Agent or Ask AI. Hostinger says previous conversations and data are migrated and that support-related requests and business-related tasks can have different credit treatment.

Existing documentation may still use several names:

  • Kodee: the earlier hPanel AI assistant and action-oriented hosting helper
  • Hostinger AI Agents: specialized business agents
  • WordPress AI Assistant: WordPress-integrated content and Agent experience
  • Hostinger Agent: the current unified interface

When following instructions, check the document's update date and the labels in the live account. Do not assume an old button or product boundary still exists.

What Can Hostinger Agent Do?

Capabilities should be classified by consequence.

1. Explain and guide

Examples:

  • Explain an error message
  • Locate a setting
  • Summarize a help article
  • Describe a backup process
  • Clarify hosting terminology
  • Suggest troubleshooting steps

These are read-only in principle, but advice can still be wrong or incomplete. Verify high-risk instructions.

2. Analyze and draft

Examples:

  • Outline a business plan
  • Draft a blog post
  • Suggest keywords
  • Create a campaign brief
  • Draft a customer response
  • Propose a privacy-policy outline
  • Review a page supplied by the user

Drafts need human approval. Legal, tax, financial, medical, employment, privacy, and regulatory material needs qualified review appropriate to the situation.

3. Navigate and prepare

Examples:

  • Open the relevant hPanel area
  • Prepare a proposed metadata update
  • Identify outdated plugins
  • Suggest a domain or WordPress action
  • Present a confirmation step

Navigation assistance is lower risk than execution but can expose account context. Confirm the intended website and environment.

4. Change account or site state

Examples may include:

  • Create or edit WordPress posts and pages
  • Manage media
  • Change categories or tags
  • Work with plugins or themes
  • Change site settings
  • Assist with hosting or domain tasks
  • Manage WooCommerce products where supported

This category requires approval, backups, target verification, and post-change testing.

Hostinger's current support contact guide says the Agent can perform selected account actions after confirmation. Feature availability varies; treat the live confirmation screen as a control, not a formality.

The Specialized Business Skills

Hostinger's Agent features overview currently describes seven business areas and an additional trial experience.

AreaUseful tasksRequired review
Business AdvisorGoals, planning, competitors, pricing hypothesesValidate data, assumptions, and market evidence
Creative WriterArticles, landing pages, products, newslettersFact, originality, brand, accessibility, and editorial review
SEO ConsultantKeywords, metadata, structure, local SEOSearch intent, data source, technical implementation, no ranking promises
Marketing PlannerCampaigns, calendars, launches, promotionsBudget, audience, claims, tracking, consent
Legal AdvisorDraft policies, contracts, checklistsQualified legal review before reliance or publication
Customer CommsReplies, reminders, review responsesAccount facts, tone, privacy, escalation
Sales & OutreachProposals, scripts, prospect messagesLawful sourcing, consent, accuracy, sender approval

These are roles for organizing assistance, not licensed professionals or autonomous employees. The person or business remains responsible for the output and action.

Hostinger Agent Inside WordPress

Hostinger's current WordPress AI Assistant guide describes content generation and access to Hostinger Agent from WordPress on eligible hosting plans.

Typical workflows include:

  • Draft posts or pages
  • Adjust tone and length
  • Suggest keywords and descriptions
  • Edit generated content as a draft
  • Receive account or site reminders
  • Ask support questions
  • Perform supported WordPress actions from chat

Use “Edit as draft” rather than direct publication for substantive content. A draft stage allows editorial, legal, SEO, accessibility, fact, and link review.

Do not assume content is original or correct

Check:

  • Facts and dates
  • Product details
  • Prices
  • Citations
  • Copyright and licensing
  • Claims
  • Grammar
  • Brand voice
  • Search intent
  • Internal links
  • External links
  • Accessibility
  • Disclosure
  • Author expertise
  • Metadata
  • Structured data
  • Cannibalization

AI-generated volume is not a content strategy. Thin or repetitive pages can waste crawl resources and weaken user trust.

WordPress Access and MCP Connections

Hostinger documents an MCP connection for external AI tools to access a hosted WordPress site through the Hostinger AI Plugin and WordPress Application Passwords.

The current WordPress MCP guide lists potential access to posts, pages, media, users, plugins, themes, categories, tags, and settings.

That is broad authority.

Use separate application passwords

WordPress Application Passwords are separate, revocable credentials.

Use:

  • One credential per tool
  • A descriptive label
  • The lowest suitable WordPress role
  • A password manager
  • A revocation date
  • An access register

Never reuse the main WordPress password in a tool configuration. Revoke the application password when a device, contractor, or tool no longer needs it.

Limit the WordPress user

Do not connect every assistant as a full administrator by default.

Possible role design:

  • Author for creating and editing own drafts
  • Editor for managed publishing workflows
  • Shop Manager for appropriate WooCommerce work
  • A custom role with specifically required capabilities
  • Administrator only for short, controlled tasks that truly require it

WordPress capabilities can be complex. Test custom roles on staging before relying on them.

Protect local configuration

Hostinger says external-tool credentials are stored locally in the described MCP setup. Local storage is still sensitive.

Protect:

  • Device login
  • Disk encryption
  • Configuration-file permissions
  • Backups
  • Screen sharing
  • Shell history
  • Cloud synchronization
  • Source-control exclusions
  • Employee offboarding

Never commit application passwords or tokens to a repository.

Build a Risk Classification for Agent Actions

Use four levels.

Level 1: Read-only

Examples:

  • Explain settings
  • Summarize public information
  • Analyze a supplied report
  • List existing pages

Controls:

  • Verify sensitive facts
  • Avoid unnecessary data
  • Keep records when relevant

Level 2: Draft-only

Examples:

  • Create a blog draft
  • Propose metadata
  • Draft a customer reply
  • Suggest plugin changes

Controls:

  • Save as draft
  • Named reviewer
  • Source and claim checks
  • No automatic publication or sending

Level 3: Reversible change

Examples:

  • Update draft content
  • Change non-critical settings
  • Upload approved media
  • Create a staging page

Controls:

  • Backup or version
  • Exact target
  • Preview
  • Approval
  • Regression test
  • Rollback step

Level 4: High-impact change

Examples:

  • DNS or domain action
  • Plugin or theme update
  • User or role change
  • Production database work
  • Public bulk publication
  • WooCommerce price or stock change
  • Site deletion or migration
  • Security setting
  • Payment or billing change

Controls:

  • Administrator authorization
  • Maintenance window
  • Recoverable backup
  • Staging or rehearsal
  • Dependency check
  • Monitoring
  • Written rollback trigger
  • Human execution when tool behavior is not sufficiently predictable

An AI assistant should not be given standing approval for all Level 4 actions.

Use a Plan–Preview–Approve–Execute–Verify Workflow

1. Plan

Ask the Agent to state:

  • Exact site and environment
  • Current problem
  • Proposed action
  • Files, records, settings, or users affected
  • Dependencies
  • Risks
  • Backup requirement
  • Rollback
  • Verification

2. Preview

Request the draft, diff, record list, or intended values before mutation.

Examples:

  • Show the proposed title and description.
  • List the five plugins and target versions.
  • Show the product SKUs and prices that would change.
  • Describe the DNS records without changing them.
  • Draft the reply without sending it.

3. Approve

Approval must identify the target and scope.

Weak: Do it.

Better: On staging.example.com only, update the draft page titled “Returns Policy” with the approved text. Do not publish it or alter navigation.

4. Execute

Perform one bounded change. Avoid mixing content, plugins, users, DNS, and payment settings into one conversation.

5. Verify

Check the authoritative system:

  • WordPress admin
  • Public page
  • DNS lookup
  • Payment provider
  • Analytics
  • Database or export
  • Email delivery
  • Cache status
  • Error logs

Capture evidence and test related functionality.

Safe Prompt Templates

WordPress content draft

Create a draft only for the article “[title]” on [site]. Use the approved outline below. Do not publish, change its URL, alter other posts, add unsupported statistics, or generate legal claims. After creating it, return the draft URL and a list of sources and assertions requiring review.

Plugin update assessment

Do not update anything. On [staging site], list outdated plugins, current and target versions, changelogs, compatibility concerns, known dependencies, database migrations, backup requirements, and individual rollback steps. Rank by security urgency and business risk.

WooCommerce product update

Prepare a preview only. For SKUs [list], show current price, proposed price, stock, tax state, sale schedule, and variation impact. Do not change products until the merchandising owner approves the exact table.

Troubleshooting

Investigate [error] on [environment] using read-only checks first. State evidence for the likely cause, safe tests, and recovery options. Do not disable plugins, change DNS, edit the database, clear customer carts, or publish changes without separate approval.

Customer response

Draft but do not send a response to the attached customer message. Use only facts in the order record, do not expose internal notes, acknowledge the issue, and propose the approved remedy. Flag anything requiring a refund or manager decision.

Backups and Staging

Before changing production:

  • Back up database and files.
  • Confirm the backup timestamp.
  • Verify restoration access.
  • Use Hostinger staging or another safe environment when available.
  • Keep production and staging credentials separate.
  • Sanitize customer data in non-production.
  • Test the change and rollback.
  • Schedule a maintenance window when needed.

A backup is only useful if it is complete, accessible, and restorable.

Do not ask an Agent to “optimize everything” on production. Theme, plugin, cache, database, image, and JavaScript changes can interact.

For a structured performance workflow, see our WordPress Core Web Vitals optimization guide.

Safe Plugin and Theme Management

Updates can contain security fixes, but bulk unattended updates can break the site.

Before updating:

1. Check current WordPress, PHP, theme, and plugin versions.

2. Review the changelog.

3. Confirm compatibility.

4. Identify add-ons and dependencies.

5. Check licenses.

6. Back up.

7. Test on staging.

8. Run critical journeys.

9. Deploy in a controlled window.

10. Monitor logs and customer reports.

Critical journeys include:

  • Login
  • Forms
  • Search
  • Navigation
  • Product variations
  • Cart and checkout
  • Payment
  • Order email
  • Membership access
  • Scheduled jobs
  • Caching
  • Analytics
  • Consent

Do not allow an Agent to replace a plugin based only on a generic feature comparison. Data formats, shortcodes, blocks, APIs, and licenses can make replacement destructive.

Safe WooCommerce Operations

AI-assisted commerce changes need inventory and financial controls.

High-risk fields include:

  • Regular and sale price
  • Currency
  • Tax status
  • Stock
  • Backorders
  • SKU
  • Variation relationships
  • Weight and dimensions
  • Shipping class
  • Coupons
  • Order status
  • Refunds
  • Customer roles
  • Payment settings

Use SKU-based preview tables, a second-person approval, a small batch, and reconciliation.

After a change:

  • Check storefront price.
  • Select each variation.
  • Add to cart.
  • Check tax and shipping.
  • Place an authorized test order.
  • Verify inventory deduction.
  • Confirm analytics.
  • Reconcile changed products.

Never send a refund, cancel an order, or change a customer's access based only on a chat summary without checking the actual order and policy.

Content and SEO Quality Controls

The SEO Consultant and Creative Writer can help organize research and drafts, but they cannot guarantee rankings.

Keyword work

Require:

  • Market and language
  • Audience
  • Search intent
  • Source and date
  • Existing ranking pages
  • Cannibalization check
  • Business relevance
  • Evidence of demand
  • Cluster and internal-link role

Article acceptance

  • Original value
  • Accurate facts
  • Primary sources
  • Clear authorship
  • Search intent satisfied
  • Useful examples
  • No invented experience
  • Logical headings
  • Accessible tables and media
  • Relevant internal links
  • Unique metadata
  • Visible FAQ matching any FAQ schema
  • Disclosure for affiliate or commercial relationships
  • Editorial approval

Publishing controls

Generate as draft, assign a reviewer, preview the rendered page, validate links and schema, then publish manually or through a separately approved workflow.

For marketplace content standards, see our Wish merchant guide and Bonanza cross-listing guide.

Hostinger's own Agent overview says legal output is a draft and should be reviewed before publication.

A privacy policy or contract must match:

  • Legal entity
  • Actual data collection
  • Vendors
  • Countries
  • Retention
  • User rights
  • Cookies
  • Payments
  • Marketing
  • Children
  • Product terms
  • Governing law

Do not publish a generic generated policy that describes controls the business does not have.

Business advice

Request assumptions and sensitivity analysis. Validate market size, competitor price, costs, and legal constraints with independent sources.

Marketing

Review claims, audience, budget, consent, attribution, trademarks, endorsements, and promotion terms. Do not automatically send outreach to scraped lists.

Customer communication

Use order-specific facts, protect internal notes, avoid unnecessary personal data, and escalate threats, safety issues, legal demands, chargebacks, or vulnerable customers to a human.

Privacy and Data Handling

Hostinger Agent can accept files and may retain memory or chat history according to active settings and policies. Use data minimization.

Do not upload unless required:

  • Passwords
  • Secret keys
  • Full database dumps
  • Payment card data
  • Government identity
  • Medical records
  • Unredacted customer exports
  • Private employee files
  • Confidential contracts unrelated to the task
  • Authentication cookies
  • Backup archives

Prefer:

  • Redacted screenshots
  • Minimal error excerpts
  • Synthetic sample records
  • Aggregated metrics
  • Time-limited credentials through approved systems
  • Links to public documentation
  • Secure support channels for sensitive incidents

Review current privacy terms, retention, memory settings, subprocessors, and organizational requirements.

Verify Every Action

An Agent message saying “done” is not proof.

Content

  • Draft exists
  • Correct status
  • Correct author
  • Correct URL
  • No unexpected edits
  • Links work
  • Mobile layout works

WordPress change

  • Site loads
  • Admin works
  • Logs are clean
  • Cache purged appropriately
  • Critical journeys pass
  • No new accessibility defect

Domain or DNS

  • Exact records
  • Email records preserved
  • HTTPS active
  • Correct host resolves
  • Redirects work
  • Rollback available

WooCommerce

  • Price and stock correct
  • Variation works
  • Checkout completes
  • Emails arrive
  • Inventory reconciles
  • Analytics records one order

Business content

  • Sources checked
  • Claims supported
  • Numbers reconciled
  • Named owner approves

Keep screenshots, exports, or logs for material changes.

Incident Response

If an Agent action creates a problem:

1. Stop further automated changes.

2. Record the time, target, prompt, approval, and response.

3. Preserve logs and evidence.

4. Assess customer, security, payment, and data impact.

5. Activate maintenance or containment when needed.

6. Revoke credentials if exposure is possible.

7. Restore the last verified state.

8. Test critical journeys.

9. Notify required stakeholders.

10. Document root cause and control improvements.

Do not continue prompting “fix it” repeatedly when the system state is uncertain. More changes can destroy evidence and make rollback harder.

Escalate to Hostinger support or a qualified WordPress developer with precise evidence.

Measure Whether the Agent Creates Value

Track more than time saved.

Efficiency

  • Draft time
  • Resolution time
  • Repetitive steps removed
  • Credit usage
  • Human review time

Quality

  • Fact correction rate
  • Publishing defects
  • Reopened incidents
  • Rollbacks
  • Accessibility defects
  • Customer complaints
  • SEO changes requiring rework

Risk

  • Unauthorized actions
  • Permission exceptions
  • Secret exposure
  • Failed changes
  • Backup and rollback success
  • Data incidents

Business outcomes

  • Qualified leads
  • Content engagement
  • Support resolution
  • Conversion
  • Revenue contribution
  • Retention

An AI workflow that is fast but produces high review and rollback costs may not be efficient.

30-Day Adoption Plan

Week 1: Read-only and drafts

  • Configure account security.
  • Review memory and privacy settings.
  • Classify tasks.
  • Use support questions and draft-only workflows.
  • Create prompt templates.
  • Establish an audit log.

Week 2: Staging changes

  • Create fresh backups.
  • Test one reversible WordPress action on staging.
  • Validate permission boundaries.
  • Test rollback.
  • Measure review time and defects.

Week 3: Limited production use

  • Approve a low-risk bounded action.
  • Verify the exact outcome.
  • Monitor errors.
  • Review audit evidence.
  • Revoke unnecessary credentials.

Week 4: Governance review

  • Assess value, defects, and credit cost.
  • Decide allowed and prohibited actions.
  • Assign approvers.
  • Document incident response.
  • Expand only proven workflows.

Hostinger Agent Governance Checklist

Account and permissions

  • [ ] Multi-factor authentication enabled
  • [ ] Named account owners
  • [ ] Separate application password per external tool
  • [ ] Lowest suitable WordPress role
  • [ ] Credential inventory and revocation process
  • [ ] Contractor and employee offboarding
  • [ ] Local configuration protected

Change control

  • [ ] Risk level assigned
  • [ ] Exact target confirmed
  • [ ] Read-only diagnosis first
  • [ ] Preview or plan reviewed
  • [ ] Backup verified
  • [ ] Staging used when appropriate
  • [ ] Named approval
  • [ ] One bounded change
  • [ ] Post-change tests
  • [ ] Rollback evidence

Content and communication

  • [ ] Draft status
  • [ ] Sources and claims checked
  • [ ] Brand and legal review
  • [ ] Privacy respected
  • [ ] No unauthorized sending
  • [ ] Affiliate or commercial disclosure
  • [ ] Accessibility reviewed
  • [ ] Final human approval

Operations

  • [ ] Audit log retained
  • [ ] Credits and total cost tracked
  • [ ] Incidents measured
  • [ ] Permissions reviewed quarterly
  • [ ] Obsolete access revoked
  • [ ] Product changes reconciled
  • [ ] Support escalation documented

For professional implementation and governance, review our WordPress maintenance service and business automation services.

Frequently Asked Questions

Is Kodee still available?

Hostinger announced that Kodee and the specialized Agents experiences have been merged into Hostinger Agent. Older articles and interfaces may still mention Kodee during the transition.

What is Hostinger Agent?

It is Hostinger's unified AI assistant for support, hosting and website guidance, selected account or WordPress actions, and specialized business tasks such as writing, SEO, planning, customer communication, and outreach.

Can Hostinger Agent manage WordPress?

On eligible plans and configurations, Hostinger documents WordPress actions and an AI Plugin. Available permissions can include posts, pages, media, users, plugins, themes, categories, tags, and settings. Verify the live capability and use least privilege.

Can the Agent fix every WordPress error?

No. It can explain and assist with supported problems, but errors involving custom code, complex plugins, corrupted data, security incidents, hosting limits, or third parties can require manual diagnosis and specialist support.

Should Hostinger Agent automatically publish blog posts?

Use draft-first publishing. Generated content requires factual, editorial, brand, legal, accessibility, SEO, and link review.

Treat it as a draft. Hostinger itself says legal drafts should be reviewed. Use a qualified legal professional for documents or advice the business will rely on.

Can an external AI tool connect to Hostinger WordPress?

Hostinger documents connections through its WordPress AI Plugin, MCP, and WordPress Application Passwords for supported tools and plans. Use a separate revocable credential and the lowest suitable role.

Does Hostinger Agent guarantee better SEO or faster performance?

No. It can assist with analysis and changes, but results depend on implementation, competition, content, hosting, code, media, third parties, and real-user conditions. Measure before and after.

What should never be fully automated?

Avoid standing autonomous authority over deletion, production databases, DNS, domains, payments, refunds, user roles, security controls, bulk product changes, legal publication, or public customer messaging without strong safeguards and approval.

How do I know an Agent action succeeded?

Verify it in the authoritative system and run the relevant journey. Keep evidence such as a screenshot, export, log, test result, or DNS lookup.

Final Recommendation

Use Hostinger Agent as a capable assistant operating inside a governed process. It can reduce navigation, drafting, research, and repetitive work, and it may execute supported actions after confirmation.

The correct control depends on consequence. Let it explain freely, draft under review, make reversible changes with a backup, and approach high-impact actions with explicit authorization and specialist oversight.

The goal is not to automate every task. It is to automate well-defined work while preserving human accountability, recoverability, privacy, and proof that the result is correct.

Related posts

Business Website Development Guide for Small Companies
Web Development9 min read

Business Website Development Guide for Small Companies

A practical guide for small companies planning a business website that needs to look credible, load quickly, explain services clearly and convert visitors into real inquiries.

Read article →

Canonical Tags: A Practical Guide for Business and E-Commerce Sites
SEO & Marketing14 min read

Canonical Tags: A Practical Guide for Business and E-Commerce Sites

A practical canonical tags guide for business and e-commerce websites covering duplicate URLs, rel canonical, redirects, sitemaps, hreflang, product variants and audit workflows.

Read article →

E-Commerce Analytics Setup: GA4 Events and Revenue Validation
E-commerce19 min read

E-Commerce Analytics Setup: GA4 Events and Revenue Validation

A practical GA4 e-commerce analytics setup guide for tracking product discovery, checkout, purchases, refunds and revenue accuracy without duplicate data.

Read article →

Author

Anushka Dahanayake

Anushka Dahanayake is the founder of ANUSHKA DAHANAYAKE (PVT) LTD, building SEO-driven content, digital services, and revenue platforms for businesses in Sri Lanka and worldwide.