Changelog

What is new in AskYourStack

New tools, playbooks and safety improvements, newest first.

Improvement

The agent on your server is now askyourstack-agent

Agent 0.14.0 renamed itself in place on every server, with no action from you: the binary is /usr/local/bin/askyourstack-agent (or ~/.local/bin/askyourstack-agent for an agent that runs as your site's user), its folders are /etc/askyourstack and /var/lib/askyourstack, the service is askyourstack-agent, and a crontab watchdog was rewritten. Every old name stays as a link or an alias, so old instructions, running jobs and migration links keep working: sudowhizzy-agent lock still locks, systemctl disable --now sudowhizzy-agent still stops it. The release is reproducible from the public source like every one before it: github.com/shopwhizzy/askyourstack-agent.

Improvement

SudoWhizzy is now AskYourStack

Same product, same team, new name. "Sudo" said root, and the product never needed root to be useful: the agent runs as the Linux user who owns your sites, and you ask your stack, servers, sites, Search Console, Analytics, in plain words. So we are AskYourStack, at askyourstack.com, with the same account, servers, plan and prices. What changes for you: the dashboard and the sign-in address are https://askyourstack.com/mcp; the old address keeps working for a long while, so nothing breaks today. Connections made by signing in (Claude.ai, ChatGPT, Claude Code, Cursor) are tied to the old address and need reconnecting once with the new one. Private addresses, installed agents and Google, Bing, Cloudflare and site connections carry on as they are. Emails now come from info@askyourstack.com, the Telegram bot is @AskYourStack_Bot (press Start on it once), and the agent's source lives at github.com/shopwhizzy/askyourstack-agent. The agent itself keeps its current name on your servers until its next release renames it in place.

Security

Nothing changes on a server unless you opened changes on it

Every server now has a change window. It is closed by default, and while it is closed your AI can look, read logs, run reports and plan, but every tool that would change something is refused and your AI is told to ask you. You open changes on the Servers page, on the dashboard or from the link your AI gives you, for 1, 2, 4 or 8 hours; there is no way to leave them open for good. A countdown shows on the server card, the dashboard and the sidebar, and you can close them early at any time. Inside the window everything works as before, within the server's safety mode: in normal mode destructive actions still wait for your approval. An approval you press runs once even when changes are closed, because you pressed it; a job that is already running finishes; and AskYourStack's own daily checks, site checks and reports never need the window. Agencies can open or close changes on all servers at once. If your AI hits a closed window you also get the link by email (the approvals switch) and Telegram, at most once per server every 10 minutes. The idea is sudo's: access to change a server should be something you grant for a while, not something that is on forever.

Security

The agent is open source, releases can be checked, and a lock on the server itself

You install AskYourStack's agent as root, so you should be able to see what it is. Its source is now public at github.com/shopwhizzy/askyourstack-agent (Apache-2.0, Go, no third-party dependencies), and every release from 0.13.0 on is built reproducibly from a commit of that repository: the signed release manifest names the commit and the Go version, and verify.sh in the repository rebuilds it and compares the hash with the binary we serve and with the one on your server. The dashboard now also shows the install in three steps (download the script, read it, run it) for anyone who prefers that to one line. And the agent has a lock: askyourstack-agent lock, run on the server, makes it answer only its own read-only operations (facts, files, logs, reports, read-only database queries) and refuse everything else, shell commands included, whatever your AI asks and whatever mode the dashboard shows, until someone with a shell on that server unlocks it. The dashboard and your AI see the server as locked. The security page also reminds you that root is optional: installed as an ordinary, jailed Linux user, the agent manages only that user's own sites and files, a boundary the operating system enforces. It starts with how to check each claim, written so that a person, or an AI assistant you ask about us, can look instead of guessing.

New tool

Keyword volumes, keyword ideas, live Google results and what a domain ranks for

Four tools for the questions Search Console cannot answer, because it only knows the queries you already get. keyword_volume gives Google's monthly search volume, the last 12 months, cost per click and competition for up to 200 keywords in one call, in any country and language. keyword_ideas takes a seed keyword and returns up to 100 suggestions with volume, keyword difficulty (0 to 100) and search intent, for a content plan or for choosing what a page should target. serp_check reads the live Google results for a keyword, desktop or mobile, in a country, with your site's positions marked and what else is on the page (AI overview and who it cites, featured snippet, people also ask, shopping, video). domain_keywords lists what any domain ranks for with position, volume, estimated visits and the ranking page, and the domains that compete with it: ask for a competitor's domain to find the keywords you are missing. The data comes from a metered provider and costs us per call, so each plan has a monthly allowance: 100 lookups on Starter and SEO Starter, 300 on Pro and SEO Pro, 1,000 on Agency and SEO Agency; a lookup is one call whatever its size, so your AI is told to batch keywords. The answer always says how many lookups are left.

New tool

Bing Webmaster Tools, next to Search Console

On the SEO & Analytics page you can now connect Bing Webmaster Tools, by signing in at Bing or by pasting the API key from your Bing account, and pick the sites your AI may read (the same number as your plan's Search Console properties). Seven tools come with it: bing_performance (Bing's daily clicks and impressions, the last 28 days against the 28 before, top queries and pages, the pages one query lands on), bing_crawl (what Bingbot crawled, what is in the index, errors, and the crawl issues per address), bing_keywords (Bing's own search counts for a keyword, its monthly history and related keywords, free, good for ranking keywords against each other), bing_backlinks (inbound links, which Search Console has no API for), bing_sitemaps and bing_submit (pages or a sitemap, with the quota left). Bing is a few percent of search in most countries, and with it come DuckDuckGo, Yahoo and Ecosia; your AI is told to treat its numbers as a second opinion. On every paid plan, the SEO plans included.

New tool

Connect Cloudflare: DNS, cache, firewall and traffic

On the Sites & Apps page you can now connect Cloudflare with an API token you make for your zones (the page lists the permissions to tick). Your AI gets seven tools: cf_zones, cf_dns (list, add, change and remove records: a migration points your domain at the new server, a new subdomain gets its record), cf_purge_cache, cf_firewall (block or challenge addresses, networks, countries or a path, rate limits on login and search, an allow rule for your own address, always leaving verified search engines out), cf_settings (under attack mode, security level, development mode and, in the fullest mode, SSL and HTTPS settings) and cf_analytics (requests, cached share, threats and bandwidth per day, top countries, requests per hour, and what the firewall blocked in the last 24 hours). Like a connected site, the connection has a mode you choose: by default your AI adds records and protects the zone but does not change records that were there before you connected; "Change anything" lets it, for a migration. Every change is kept 90 days and cf_undo puts it back. The bot-attack and migrate playbooks use the tools when Cloudflare is there. A token does not take a place on your plan; Starter and up.

Security

Connect by signing in, without the secret address

AI clients that support sign-in (Claude, ChatGPT, Claude Code, Cursor, VS Code; tried and proven in Claude, ChatGPT, Claude Code and Cursor) can now connect to https://askyourstack.com/mcp: you sign in to AskYourStack, see which app is asking and where it will send you back, and allow it. Each app gets its own access, which expires and renews by itself, and you can disconnect one app under Security without touching the others. You get an email whenever a new app is connected. The private MCP address keeps working for clients that need it. What an app can do is the same either way: your tools, inside each server's safety mode, and destructive actions still wait for your approval in the dashboard.

Improvement

New tools without reconnecting, and progress on long calls

AskYourStack now speaks the whole of MCP's streamable HTTP. A client that opens the server's stream is told the moment your plan changes, so it reloads the tool list by itself instead of you reconnecting it. And a client that asks for progress gets a note every 10 seconds while a long call runs (a health report, a crawl of the logs, a big page audit), so it does not give up on it. Clients that do neither keep working exactly as before. Also in this release: list_dumps and db_restore, redirects, convert_images, seo_fields on Magento 2 and Ghost sites (MCP server 0.16.0).

Security

Known vulnerabilities from public feeds, every day

Until now AskYourStack knew about vulnerable software from a hand-kept list. The daily check on Pro and Agency now reads what each site runs (WordPress plugins, themes and core version from their files; composer packages from composer.lock, so Magento and Laravel too; agent 0.12.3) and asks two public feeds: WPVulnerability for WordPress, which gathers Wordfence, Patchstack, WPScan and CVE entries, and OSV for composer packages. A critical or high finding opens an alert at once, with the version that fixes it; the rest go in the Monday report. health_report shows the same list to your AI, so "what should I update first?" has a real answer. Only names and versions leave your server, and nothing is changed.

New tool

WebP copies of your images, in one job

convert_images makes a WebP (or AVIF) copy next to every JPEG and PNG in a site's upload folders, with the encoder your server has (ImageMagick, cwebp, avifenc or vips), running as the site's owner so the files belong to the site. Originals are never changed, a copy that is not smaller is dropped, tiny files are skipped, and a second run only does new uploads. A dry run counts first. The performance playbook has the nginx and Apache lines that serve the copy to browsers that accept it, and the check with curl. Starter and up; agent 0.12.2.

New tool

A redirect manager fed by your 404s

The new redirects tool finds the pages that are gone and costing you visitors: the paths that answered 404 to Googlebot and the other crawlers in your server's logs over the last week, and, when Search Console is connected, the pages that had clicks in the last 90 days and are gone now. Each comes with a suggested target from your sitemap, marked high or low confidence. Your AI then writes the redirects where your site keeps them (Magento's url_rewrite table, or the Redirection or Rank Math plugin on WordPress) after a preview, and a batch id removes them again for 90 days. A site with no redirect store gets the exact nginx and Apache lines instead. Starter and up.

New tool

Bulk SEO fields for Magento 2

seo_fields, which wrote SEO titles, meta descriptions and alt texts on WordPress, now does the same on Magento 2: products and categories (meta title and meta description at the default store scope), CMS pages, and the alt text of product images. As before: list what is there or missing, a preview of old against new, small batches, and a batch id that puts the old values back for 90 days. Writes are single statements with the value quoted by AskYourStack, never SQL composed by the AI, and the tool tells the AI to flush the full page cache afterwards.

Improvement

Ghost sites are recognised

The agent (0.12.1) now finds Ghost installs, as ghost-cli makes them or in the official Docker image: version, database (MySQL; SQLite is noted), address, uploads for the malware scan and its own log for the logs tool. site_console runs ghost-cli as the site's owner (ls, doctor, log, update, restart; uninstall needs your approval). A ghost playbook and a check-up prompt come with it.

Improvement

Site checks catch error pages, and a text you require

The 5-minute site check on Pro and Agency used to accept any page that answered: a WordPress "Error establishing a database connection", a Magento error page, a stuck maintenance notice or the web server's default page all counted as up. They now count as down, with the reason in the alert. And under Site checks on each server card you can give each site a text that must be on its page (a shop's "Add to cart", a line from the footer): an empty or wrong page is then caught too. The Prompt Library on the SEO plans now shows only the prompts that work without a server, with two new ones: an audit of the pages that bring the most clicks, and titles and descriptions to rewrite with the new text.

New tool

Restore a database dump, with a way back

Two new tools. list_dumps shows the dumps kept on a server: the ones made with db_dump, the copies of tables AskYourStack took before an approved destructive statement, and the copies taken before a restore. db_restore loads one of them, or any .sql or .sql.gz file on the server, into the site's database with the site's own credentials. It is a risky action, so in normal mode it asks for your approval first, and the approval page says in plain words what is replaced and what is lost. Before loading, the agent dumps the database as it is now, so a restore that made things worse is undone with the same tool. The restore playbook now uses it for a whole database and keeps the scratch-database way for a single table or a few rows. Agent 0.12.0, updated by itself.

Improvement

Alerts on Telegram

On the Notifications page, press Connect Telegram, open our bot @AskYourStack_Bot and press Start: problems and fixes on your servers and sites, and the SEO alerts, then arrive as Telegram messages the moment they happen, whether the alert email is on or off. It works in a private chat or in a group you add the bot to. Send /stop to the bot, or press Disconnect on the page, to end it.

Improvement

SEO plans by site, with no server

Three plans for people who want the SEO tools and nothing on a server: SEO Starter (€12 a month, 1 site, the last 30 days), SEO Pro (€32, 5 sites, 90 days) and SEO Agency (€92, 25 sites, all 16 months Google keeps, up to 3 Google accounts). The first 10 SEO subscribers pay founding prices, €10, €28 and €86, kept while they stay subscribed; quarterly 15% off. A site is one Search Console property and its GA4 property. You get every Google and page tool (Search Console, Analytics, page audits, links, robots.txt, sitemaps, schema, Core Web Vitals, SEO history with alerts, IndexNow) and the dashboard becomes the three Google steps: connect, pick properties, add to your AI. Servers, connected sites, commands and the malware scan stay with the server plans, and switching between the two keeps your Google connection and picks. The plans are on the pricing page, below the server plans.

New tool

Connect a WhizzyCommerce shop

WhizzyCommerce shops are hosted, so there is no server to connect. On the Sites & Apps page, press Connect WhizzyCommerce, sign in there, pick the shop and press Allow. Your AI then works through the shop's own connector with two new tools: whizzy_tools lists what your shop lets it do (you decide that per group under Agents in your WhizzyCommerce dashboard: catalogue, prices, orders, customers, content, design, settings, reports) and whizzy_call does it. Reads answer straight away: sales, orders waiting, stock running out, promotions, products, pages. A change is never made from the chat: your AI gets a preview and a link, you open the link in your WhizzyCommerce dashboard and confirm or decline, and your AI can then check what you decided. Several changes can come as one plan with one confirmation. AskYourStack stores nothing the shop answers; the activity log keeps the capability's name only. A new playbook (whizzycommerce) and a prompt in the Prompt Library show your AI how to work this way, including titles and descriptions for search. A shop takes one of your plan's places, like a server or a WordPress site. Reconnect AskYourStack in your AI client, or start a new chat, to load the new tools.

New playbook

Your SEO of the last 90 days as one dashboard

Ask your AI: "Review example.com latest 90 days SEO performance and return an insightful dashboard." A new playbook sets only the basics: real figures, the exact period, the answer first, a trend with Google's updates marked, recommended actions in priority order, and one page set in the Inter typeface. What to analyse is left to your AI: brand against non-brand, countries, pages that compete with each other, whether the lost visits ever bought, tracking that distorts the numbers, speed, whatever the data of your site shows. It only reads; nothing on your site changes. The prompt is in the Prompt Library under SEO.

New tool

No server? Connect a WordPress site anyway, or use the SEO tools on their own

AskYourStack used to start with "connect a server". Many sites live on managed hosting where there is no server to install anything on, so there are now two ways in without one. Sites: on the new Sites page, enter your WordPress address and approve AskYourStack in your own WordPress admin. WordPress makes a password only for this (your own is never asked for), and your AI can then read your posts, pages, media, categories and your other content types such as products, write new posts and pages as drafts, edit drafts and upload images. You get a preview link and publish yourself. Each site has a mode you choose: read only, drafts only (the default: nothing your visitors see changes) or publish too. Nothing is ever deleted for good, and what a change replaced is kept 90 days, so any change can be undone. It works on any host, with no plugin to install. SEO alone: Search Console, Analytics, Core Web Vitals, page audits and history with alerts never needed a server; the dashboard now says so and step 2 is done once Google or a site is connected. A connected site takes one of your plan's places, like a server (Starter 1, Pro 5, Agency 25); on Free your AI can read a connected site but not change it.

New tool

Seven more kinds of site, WooCommerce as a shop, and sites in Docker

Until now AskYourStack knew Magento 2 and WordPress by name; everything else was "a folder with PHP in it". The agent (0.11.0, it updates itself) now recognises PrestaShop, Shopware 6, Drupal, Joomla, OpenCart, Laravel applications and OpenMage (Magento 1) as well, wherever your hosting panel keeps them, and reads each one's version and database settings from its own configuration. For all of them your AI gets what Magento and WordPress had: database queries that keep the password off the chat, database dumps, the site's own log by name, the malware scan with the right upload folders, the whole-site crawl, and a playbook written for that software. The new site_console tool runs each site's own command line as the site's owner (bin/console for Shopware and PrestaShop, artisan for Laravel, drush for Drupal, Joomla's cli): listing and status commands run straight away, while uninstalling, wiping or resetting a database, new secret keys and commands that run arbitrary code wait for your approval. WooCommerce is now seen as a shop: the daily check tells you when its background tasks pile up (the reason order emails and renewals arrive late), and there is a playbook for orders, WP-Cron and what a cache must never store. Shopware gets an alert when its scheduled tasks stop. And sites that run in Docker containers (docker compose, Coolify, Dokploy) are found when their files are mounted from the server: commands run inside the container and the database is reached through the container network. Six new playbooks and six new prompts come with it.

New tool

A crawl of your whole site, SEO history with alerts, and IndexNow

Three additions for search. A whole-site crawl (Pro and Agency): ask your AI to "crawl my site and tell me what to fix first" and the new site_audit tool walks every page from your own server, up to 5,000, the way a search engine would. Because it fetches from the server itself, no CDN or firewall blocks it and it costs you nothing. It keeps what every page answered and names the issues: links to missing pages, server errors, redirect chains, repeated titles and descriptions, the same text on several addresses, thin and slow pages, and sitemap entries that redirect, fail or are marked noindex. Your AI reads it by issue, fixes what you choose, and the next crawl shows each count against the last one. History and alerts (every paid plan): switch it on under SEO & Analytics and AskYourStack stores one line a day per property (clicks, impressions, position, Analytics sessions and revenue, Core Web Vitals) for as long as it stays on, longer than Google keeps it. It emails you when clicks fall hard against the week before or when one of your ten best pages leaves Google's index, and puts smaller warnings (a softer fall, a Core Web Vital turned poor) in the Monday report, which now has a line per site. On Pro and Agency the daily server check also tells you when Googlebot is being served errors. IndexNow (every paid plan): after publishing, changing or removing pages, your AI can tell Bing, Yandex and the other IndexNow search engines right away. The agent updates itself to 0.10.0.

Security

Fewer approvals, and each one easier to judge

Three changes to how your AI asks before doing something risky. A plan: for a job with several risky steps, your AI now lists them and asks once; you see every step, approve them together, and each runs once when your AI reaches it, exactly as shown. Plain words: every approval page now says what the action does, what could go wrong and how to undo it, next to the exact command, and your AI can add its own sentence about why it needs it (marked as its words). A safety copy: before an approved statement that deletes or empties database tables, AskYourStack saves those tables on the server, and before an approved removal of whole folders it takes a snapshot, when the command names them plainly; the answer says where the copy is. And when you are watching a big job, an approval page lets you stop the questions on that server for 30 or 60 minutes; they come back by themselves, and everything is still logged.

New tool

Bulk SEO titles, descriptions and alt texts, with undo

Ask your AI to "write the missing meta descriptions for my products" and it can now do exactly that on a WordPress site. The new seo_fields tool lists pages with their SEO title and description (or only the ones missing one) and images without an alt text, takes the new texts in small batches, shows you old against new before anything is written, and keeps what it replaced for 90 days so a whole batch can be undone with one call. It works with Yoast SEO, Rank Math, SEOPress and The SEO Framework. On every paid plan.

New tool

Logs your AI can actually read

When something is wrong, the answer is usually in a log, buried under the same line repeated ten thousand times. The new logs tool takes a log by name (web server errors, PHP, Magento, WordPress, database, system, mail, logins, or any file) and a time window, and returns the different errors, how often each happened, when it started, a sample with the top of its stack trace, and the latest lines. It finds each site's own log files wherever your hosting panel keeps them. On every plan, Free included.

New playbook

Eight more jobs your AI knows how to do properly

New step-by-step playbooks: find why a site is slow (measured, with numbers, before any fix), apply updates safely (system, WordPress plugins one at a time, Magento security patches), bring back a site that is down, add another domain to a server with its own user and SSL, make a private staging copy with email and payments switched off, restore from a backup or snapshot without a second accident, upgrade Magento with a rehearsal first, and make the site's email arrive (SPF, DKIM, DMARC and a proper mail service). The Prompt Library has a prompt for each.

New tool

Watching the things you assumed were watched

The daily check of every server now also looks at what tends to fail quietly. Backups: it finds your backup files, learns how often they run, and tells you at once when they stop (and mentions it in the Monday report when a server has none). Memory: it tells you when the system had to kill the database or PHP because the server ran out. It notes when PHP ran out of workers or the database hit its connection limit, the usual reasons behind "the site was slow this morning". Certificates of sites that no longer exist stop raising alarms. On Pro and Agency it also looks every day for software with a known vulnerability (missing Magento security patches, vulnerable modules, WordPress plugins and themes), checks from outside when each site's domain expires and whether its email has SPF and DMARC records, and checks that your sites answer every 5 minutes instead of 15. And problems and fixes can now go to Slack, Discord or any webhook as well as email: paste the address on the Notifications page.

New tool

Your AI remembers your servers between chats

Every new chat used to start from zero: your AI had to look around the server again and you had to explain again what was special about it. Now it keeps short notes about each server (how it is set up, what must not be touched, what you decided) and, when a task is done, writes two or three plain lines about what it did. The next chat gets both at the start, together with what needs attention. You read all of it at the top of the Activity page and can delete any note. It never stores passwords or keys there: such a note is refused. Reconnect AskYourStack in your AI client (or start a new chat) so it loads the new tools.

Security

The malware scan knows 124 more things to look for

The scan now runs a maintained set of rules on top of its own checks. On the site: signatures of known card skimmers and backdoors in files and in stored content (CMS blocks, pages, settings), Magento security patches that are missing (SessionReaper, CosmicSting and later ones), modules, WordPress plugins and themes with vulnerabilities that were exploited at scale, copies of wp-config.php or env.php, a .git folder or .env file the web server hands out, forgotten database tools and installers. On the server: crypto miners, programs posing as system services, hidden programs in temp folders, rootkit preloads, a botnet's SSH key, cron jobs that bring malware back. Each finding says what to do about it. The rules are updated without touching your server. Pro and Agency.

Improvement

Sites are found wherever your hosting panel keeps them

Until now AskYourStack looked for Magento and WordPress in a few usual folders, so on Plesk, CloudPanel, RunCloud or DirectAdmin servers it could list no sites at all, and the database, wp-cli, bin/magento and malware scan tools had nothing to work on. The agent (0.9.3, it updates itself) now reads your web server's own configuration, nginx server blocks and Apache virtual hosts, and knows those panels' layouts, so it finds every site, with its domains and access logs. Your AI can name a site by its domain instead of its folder, and the crawl report and bot attack watch read the logs panels keep next to each site. Agents that run as a limited user list only that user's own sites.

New tool

Your AI now starts by knowing what needs attention

A new overview tool gives your AI the whole picture in one call at the start of a chat: your plan, every server with its sites, the open problems and warnings AskYourStack's monitoring has found (a site not answering, a full disk, failed services, certificates about to expire, a possible bot attack), approvals waiting for you, and your connected Search Console and Analytics properties. Ask "what needs my attention?" and it answers from what AskYourStack already watches, most urgent first, without checking each server one by one. It is on every plan, Free included. Reconnect AskYourStack in your AI client (or start a new chat) so it loads the new tool.

Improvement

A one-prompt performance dashboard

A new entry in the Prompt Library asks your AI to review a site and draw you a dashboard. It pulls the real numbers through AskYourStack, Search Console (clicks, impressions, CTR and position against the period before, with your winning and losing pages and queries), Google Analytics if it is connected (visits, engagement, conversions and visits from AI assistants), Core Web Vitals for your main page types, what Googlebot fetches from your logs and the 404s and errors it hits, and the server's own health, then draws it as one dashboard your AI client shows as an HTML page: headline numbers with their change, trends, top and losing pages and queries, speed by page type, and a short ranked list of what to do next. Richest on Pro and Agency with Search Console connected.

Improvement

Up to 3 Google accounts on Agency

Agencies whose clients keep Search Console and Analytics in their own Google accounts can now connect up to 3 Google accounts on the SEO & Analytics page. The property lists show every account's sites and GA4 properties together (with the account each comes from), and your AI reads each one through the account that can see it.

New tool

On-page and technical SEO tools (Pro and Agency)

Six new tools that work on any public site, yours or a competitor's. page_audit checks up to 10 pages at once: status and redirect chains, headers (X-Robots-Tag, caching, CDN), title and description lengths, robots, canonical, hreflang, headings, Open Graph, image alt text, links and content length, with a list of issues per page, and checks that http/https and www all reach one address. page_links lists every link with its anchor text and nofollow, and finds broken and redirected links. page_content gives the main text of a page without menus and footers. robots_check tests URLs against robots.txt the way Google does, for Googlebot, Bing and AI crawlers. sitemap_check audits every sitemap and spot-checks its URLs. gsc_cannibalization finds searches where two of your pages compete in Google. Pages are fetched the way a normal browser would, so sites behind Cloudflare answer too.

New tool

Google Analytics 4 for your AI (Pro and Agency)

Connect Google Analytics on the SEO & Analytics page (read-only; if Search Console is already connected, press Add Google Analytics once) and tick your GA4 properties: 10 on Pro with the last 90 days, 25 on Agency with all history. Six new tools: ga4_overview (sessions, users, engagement, conversions and revenue against the period before, by channel, with organic search's share), ga4_landing_pages (engagement, bounce and conversions per landing page), ga4_ai_traffic (visits from ChatGPT, Perplexity, Gemini, Claude, Copilot and others, and where they land), ga4_report (any GA4 report: new vs returning, site search terms, devices, countries, e-commerce), ga4_realtime and ga4_properties with a health check of your tracking. Your AI can now follow a page from its Google ranking to its visits and sales, and fix what it finds on the server.

New tool

Core Web Vitals, schema checks, Google updates and a performance overview

Four more SEO tools for your AI on every paid plan. core_web_vitals: Google's real-user speed figures for a page or the whole site (LCP, INP, CLS, FCP, TTFB, passing or failing), and on request a Lighthouse test that shows what slows the page and which element is the LCP. validate_schema: checks a page's structured data twice, once against schema.org (with "did you mean" for typos) and once against what Google needs for rich results such as product stars, prices and breadcrumbs; it can also check markup before you publish it or from a staging site on your server. google_updates: every Google core, spam and Discover update with its dates, so your AI can tell a Google update from a problem on your site. gsc_performance_overview: how your site is doing in one call, with the period against the one before, the daily trend and the biggest winning and losing queries and pages. Start a new chat so your AI loads them.

New tool

Google Search Console, built in

Connect Google Search Console on the new Search Console page (read-only, one click if you sign in with Google), tick the properties your AI may read (Starter: 3 properties and the last 30 days; Pro: 10 and 90 days; Agency: 25 and all 16 months Google keeps) and it comes in the same AskYourStack connection: nothing new to add to your AI. Four new tools: gsc_search_analytics (clicks, impressions, CTR and position by query, page, country, device or date, with filters and a comparison of two periods), gsc_inspect_url (Google's own view of up to 20 URLs: indexed or not and why, last crawl, canonical), gsc_sitemaps and gsc_properties. The seo-technical playbook now puts Search Console next to what your server logs show, so your AI can see a problem in Google and fix its cause on the server. Step 3 of the setup also explains each AI client step by step, now including Claude Desktop, VS Code, Windsurf and Codex. Start a new chat (or reconnect in Claude Code) so your AI loads the new tools.

Improvement

Approvals now run after you approve them

Before, a risky action only ran if your AI asked for it a second time after you approved. If the AI moved on, your approval did nothing. Now, once you approve (on the approvals page or from the email), AskYourStack runs the action itself a couple of minutes later if the AI has not, and emails you the result. If the AI is still with you and you tell it you approved, it runs straight away as before. It still runs once, exactly as shown, only after you approve, and never if you deny or do nothing. Your AI is also told more firmly to stop and show you the approval link instead of carrying on.

New tool

Run the agent without root, for shared hosting

The install line now works two ways. As root (or with sudo) it manages the whole server, as before. Run it as an ordinary Linux user, with no root, and it manages just that user's own sites and files: made for shared hosting and for agencies with one jailed account per client. It does everything to the shop (Magento and WP CLI, database, files, snapshots of the shop folder, SEO) but not system work (packages, services, SSL, other users), and says so clearly when asked. You can run both on one machine, a root agent and one or more user agents; each counts as a server on your plan. The dashboard shows which user each agent runs as.

New tool

SEO: what Googlebot really crawls, audits and drafts

crawl_report reads your web server's logs and shows what Googlebot, Bingbot, AI crawlers and SEO tools actually fetched: errors and redirects they got, how much goes to filtered layered-navigation URLs, crawl rate per hour, and which "Googlebots" are fake. The seo-technical playbook combines it with Search Console, SE Ranking or a report you attach, checks robots, sitemaps, redirects, canonicals and speed from the server, and fixes what you choose. The publish-content playbook turns your SEO data (a Semrush weekly PDF works) into a content plan and writes articles and pages in your site's voice, saved as WordPress drafts or disabled Magento pages for you to review. Three new prompts in the Prompt Library.

New playbook

Bot attacks: an alert and a playbook

On Pro and Agency, AskYourStack now reads the request rate of your web server every 5 minutes and emails you when it jumps to 5 times its usual level, with what the bots go after (search, layered navigation, login, sign-up, the API) and whether it looks like a botnet or a few addresses. Ask your AI to use the bot-attack playbook: it reads the logs first, never blocks real Google or Bing, rate-limits only the costly pages, bans the addresses that keep going, makes Magento cheaper to hit (CAPTCHA, search limits, filtered URLs) and tells you when a CDN in front is the real answer. Every change comes with how to undo it.

New tool

Move a site to another server

Ask your AI to move a shop or site between two of your servers. transfer copies folders directly from one server to the other over SSH, with a temporary key that only allows reading that folder and expires within 24 hours; nothing passes through AskYourStack. db_dump dumps a site's database with its own credentials, so the password never reaches the chat. The new migrate playbook does a first copy while the site stays live, a short maintenance window for the final catch-up, tests before the DNS change and keeps the old server as the way back. Try the prompt in the Prompt Library.

Improvement

Fewer approvals, and approving on the spot

Approval is now only asked for what is hard to undo: deleting your own folders or files, dropping or emptying database data, database users, reboots, SSH, sudo and firewall changes, switching off security checks, wiping disks and uninstalling a shop. Routine work runs straight away and is logged: clearing caches and generated code, creating admin users, ordinary database updates, removing packages and rollbacks. When something does need you, a card pops up on every page of your dashboard to approve or deny it, and the browser tab shows how many are waiting.

Security

Two-step sign-in with an authenticator app

Turn it on under Security: scan a QR code with Google Authenticator, 1Password, Authy or any authenticator app, and signing in will ask for a 6-digit code after the email link or Google. Ten recovery codes cover a lost phone, and you get an email whenever it is turned on or off or a recovery code is used.

Improvement

A Free plan

Every account now starts on Free: one server, read-only, 50 tool calls a day, with the daily health check and alerts. Your AI can look, read logs and config files and explain what is wrong. Starter adds changes, approvals, snapshots and the Magento, WordPress and database tools; Pro adds the malware scan and site checks every 15 minutes. After a plan change, reconnect AskYourStack in your AI client so it loads the new tools; the dashboard reminds you until it has.

New tool

Health checks, alerts and a Monday report

AskYourStack now checks every server daily and its sites every 15 minutes. You get an email when a server stops checking in, a site stops answering, a disk is over 90% full, a certificate is about to expire, a service fails or Magento cron stops, and again when it is fixed. A Monday report sums up the week. Ask your AI for health_report any time, and choose your emails under Notifications.

New tool

Tools for existing Magento and WordPress sites

list_sites finds the shops and sites on a server. db_query runs SQL with the site's own credentials, so your database password never reaches the chat; reads run read-only and writes need your approval. magento and wp run bin/magento and wp-cli as the site's owner. malware_scan looks for backdoors, skimmers in the database, disguised PHP and suspicious cron entries.

New playbook

Site check-up and hacked-site cleanup

Two new playbooks guide your AI through a full review of an existing site, and through cleaning a compromised one: evidence first, then containment, cleaning, and changing every credential.

Improvement

Long jobs run in the background

Installs, compiles, imports and scans now run as background jobs that keep going after your AI's call returns. Your AI follows them with job_output, so long work no longer times out.

Security

Signed agent updates

The agent on your server now updates itself, only when idle, after checking a digital signature and checksum, and only after the new version proves it starts. The previous version is kept.

New playbook

Playbooks for fresh servers

Your AI can follow step-by-step guides for a fresh server, Magento (Mage-OS or Magento Open Source), WordPress, hardening and backups. Use them from the Prompt Library or just ask; your AI fetches the right one.

Security

Approvals, modes and snapshots

Every action is sorted by risk. Destructive ones wait for your approval in the dashboard, which only you can give. Each server can be read-only, normal or full trust, and snapshots with rollback let you undo changes.