Welcome to WP Defense Lab — your weekly brief on the WordPress news that impacts your business.
This week: Cloudflare is building wallets that let AI agents pay for content, APIs, and data access, and the publishers who can actually collect that money are the ones who already control their infrastructure.
In WP Radar: product pages are being rebuilt for AI search, a plugin supply-chain attack exposes a new security blind spot, Claude adds invisible watermarks, and new research reveals how ChatGPT decides which sites to cite.
🎥 Did you know we have a YouTube channel focused on WordPress security?
We share step-by-step tutorials on how to secure your site and protect your content.
👉 Explore the full channel:
youtube/@wpdefenselab
AI Agents Are Getting Wallets. Most Publishers Aren't Ready to Bill Them.
Cloudflare's new payment rails let AI agents pay for API and content access, but only sites with the right infrastructure will collect.
Cloudflare announced two products during Agents Week: Cloudflare Wallets, designed to let AI agents hold stablecoins and pay for what they use, and Cloudflare.pay, an identity system that gives agents their own payment handles.
Reservations for Handle are open, but Cloudflare says the actual wallet and payment capabilities are still to come.
Charging AI bots for access is not new. Cloudflare launched Pay-per-crawl in private beta in July 2025, letting site owners allow, charge, or block individual crawlers.
What ships next is the other half of that transaction: a way for the caller to actually pay.
The Wallet Structure
Wallets come in two tiers. Account Wallets belong to humans and hold the funds, while Virtual Wallets permit AI agents to spend from that balance within predefined limits.
Cloudflare gives a simple example: a company could give each employee a $100 weekly AI budget, with their agents using that allowance through API keys.
Funds are held in stablecoins rather than on a credit card, with onramps and offramps planned for supported regions.
Charging Extends Past Crawlers
The selling side is the Monetization Gateway.
It charges for any asset Cloudflare protects, including webpages, datasets, APIs, or MCP tools, with payment clearing at Cloudflare's edge before a request reaches the origin server.
That is a wider scope than pay-per-crawl, which only covered content requests.
Payments settle through a protocol called x402, built on the HTTP 402 Payment Required status code.
x402 now sits under the Linux Foundation body whose members include Visa, Mastercard, American Express, Google, Shopify, and Stripe, which signals this is being built as durable payment infrastructure rather than a one-off Cloudflare feature.
Identity Stays Optional, Attribution Doesn't
An agent that declares itself gets a readable name, something like research.example.cloudflare.pay, built on top of Cloudflare's existing Web Bot Auth keypair system. Declaring is entirely the agent's choice.
Cloudflare leaves it up to businesses to decide whether to prioritize transactions with known agents.
Undeclared agents are treated much like VPN traffic: not automatically untrustworthy, but expected to provide more proof of who they are.
Why This Matters for Publishers
Cloudflare's data shows bots accounted for 60.6% of requests to HTML content in the week ending August 10, compared with 39.4% from humans.
The web is already serving more automated requests than human ones. The business infrastructure just hasn't caught up.
Cloudflare points to a basic problem: systems like free trials and signup credits were built around the assumption that one account represents one person.
That breaks when a single user can deploy dozens of agents, each arriving without a persistent identity or payment history.
The new system isn't live yet. There's a waitlist, no published pricing, and no AI company has been named as a paying counterparty.
But the architecture introduces something WordPress publishers haven't really had before.
Today, the choice for an AI bot is largely binary: let it access your content or block it.
Cloudflare is building toward a third option: let it in, but make it pay.
That turns AI traffic from a crawling problem into a potential customer class. And if agents increasingly account for the requests hitting your WordPress site, the question changes from how do you keep them out, to what would you make worth paying for?

WP RADAR
This week in WP Radar: a plugin supply-chain attack bypasses WordPress code review, and Stanley rewrites its product pages for AI shoppers.
AI Search Is Changing What Your Product Pages Need to Say. Stanley 1913 discovered that product pages built to look great for humans weren't giving AI enough information to recommend them. It’s now adding FAQs, use cases, care guides, clearer product copy, and structured data. This is a practical blueprint for WordPress stores that want to show up when shoppers ask AI what to buy.
Poisoned Plugin Data Made Fake WP Admins. Attackers compromised BdThemes Elementor addons without touching the plugin code on WordPress. Instead, they poisoned a remote JSON feed that created rogue admins and installed a web shell, exposing a supply-chain blind spot that traditional plugin review can miss.
Claude Is Putting Invisible Watermarks in AI-Written Text. WordPress publishers using Claude to draft content may soon be carrying AI provenance directly into their CMS. Anthropic is embedding machine-readable watermarks into text from newer Claude models that can survive copy-and-paste and some editing.
No Licensing Deal? ChatGPT Cites You Anyway. Resoneo analyzed more than 1,200 ChatGPT answers and found OpenAI's in-house search index treats sites without licensing deals much like major publishing partners. For WordPress publishers, the more actionable finding is that ChatGPT often works from your title plus roughly 200 characters of page content, making a clean H1 and the copy immediately below it unusually valuable real estate.

5+ million WordPress sites run WPForms Lite.
A new setup wizard has sparked a debate over how much access plugin onboarding should have to your site.
During setup, WPForms Lite can create a temporary admin-level token that lasts for one hour and allows its hosted service to perform actions such as installing additional plugins.
Critics argue site owners aren't clearly told how much access they're granting, while WPForms supporters say it's standard onboarding that an administrator must initiate.
Either way, 5 million sites are running a workflow most owners have probably never thought to audit.
That’s all for this week!
Michael - Operator @WP Folio - now WP Defense Lab. Same Plugins. Different Name.