wprigel logo
  • Home
  • Products
    • krom-automation-icon

      Krom Automation

      Build visual workflows that respond to signups, orders, forms, and posts- automatically. Free plugin, no monthly fees.
    • commandify-logo-pink

      Commandify- Best Command Palette Plugin for WordPress

      Navigate, search, and manage everything on your site with a simple keyboard-first workflow.
    • pollify plugin logo

      Pollify- Ultimate Poll Creator Plugin for WordPress

      Build interactive polls, surveys & voting experiences in WordPress with the best Gutenberg-native poll plugin.
  • Docs
  • Blog
  • Contact Us
Pricing
  • Best WordPress Email Automation Plugins Compared (2026)

    The best WordPress email automation plugins in 2026 are Krom Automation, FluentCRM, MailPoet, Omnisend, and Brevo, but the right choice depends entirely on whether you need CRM depth, ecommerce triggers, or a full visual workflow engine. WordPress has no built-in email automation. Every automated email your site sends, from welcome sequences to abandoned cart reminders, requires a plugin or an external service connected to WordPress.

    Most comparison articles stop at the sticker price. They do not show you that a self-hosted plugin license at $129 per year still needs a separate SMTP provider to send reliably, which adds $20 to $50 per month at moderate volume.

    They also do not tell you what switching from one plugin to another actually costs in time and rebuilt workflows. This article covers both.

    We have organised this by the decision you are making, not by feature category. Work through the sections that match your situation and skip the ones that do not.

    Browse the full Krom Automation feature list if you want to see what a visual workflow engine built for WordPress looks like before reading the comparisons below.

    Quick Summary

    • Best for visual workflow automation: Krom Automation (free tier includes 16 triggers, 21 actions, and AI actions at no extra cost)
    • Best self-hosted CRM and email: FluentCRM (deep segmentation, contact management, sequence builder)
    • Best for newsletters and list management: MailPoet (sending infrastructure included, subscriber limits on free tier)
    • Best for WooCommerce stores: Omnisend or Krom Automation, depending on whether you need a dedicated ESP or a flexible workflow engine
    • Best for teams that already use a cloud ESP: Brevo or ActiveCampaign connected via a WordPress plugin
    • Lowest true total cost at under 500 subscribers: Krom Automation free tier plus a transactional SMTP service

    Does WordPress Have Built-In Email Automation?

    WordPress sends a small number of system emails natively: password resets, new user notifications, comment alerts. It does not have a sequence builder, a list manager, a drag-and-drop email editor, or any concept of a triggered marketing campaign. Everything beyond the basics requires a plugin.

    WordPress also does not send email reliably on its own. The default PHP mail function is routinely blocked or flagged as spam by receiving servers.

    Almost every site that sends more than a handful of emails per day needs a dedicated SMTP service or a cloud ESP regardless of which automation plugin they choose. That cost belongs in any honest comparison.

    The plugin license is not the real cost. The sending infrastructure underneath it is, and most comparison articles pretend it does not exist.

    The Six Plugins Worth Comparing

    Krom Automation

    Krom Automation is a visual workflow automation plugin for WordPress. It is not a dedicated email marketing tool, but email is one of its core action types, and it handles triggered email sequences, conditional branching, delays, and AI-generated content inside a drag-and-drop canvas. The free version includes 16 triggers, 21 actions, and a documented welcome email workflow you can deploy in under ten minutes.

    Where it differs from every dedicated email plugin is scope. Krom Automation treats email as one step inside a larger workflow.

    A new WooCommerce order can trigger an email to the customer, update a custom field, tag a contact in FluentCRM, post a Slack alert, and add a row to Google Sheets, all in one canvas. The FluentCRM integration means you do not have to choose between the two.

    AI actions are included in the free version with no paywall. You supply your own API key from OpenAI, Google Gemini, or Groq, and Krom Automation never marks up the tokens or charges per execution. The Pro version adds a block-based visual email builder and 60+ additional actions across 24 integrations.

    FluentCRM

    FluentCRM is a self-hosted CRM and email automation plugin. It stores contacts, segments them by tags and lists, and runs email sequences natively inside WordPress.

    The free version on WordPress.org covers basic contact management. The paid version starts at around $129 per year for one site and unlocks automation sequences, advanced segmentation, and integrations with WooCommerce, LearnDash, MemberPress, and LifterLMS.

    FluentCRM does not send email itself. It relies on your configured WordPress mail method, which in practice means you need a transactional SMTP service like Postmark, SendGrid, or Amazon SES running alongside it.

    At 5,000 emails per month, Postmark costs around $10; Amazon SES costs around $0.50. That gap matters when you are comparing FluentCRM at $129 per year against a cloud platform with sending included.

    MailPoet

    MailPoet is a newsletter and automation plugin with its own sending infrastructure included. The free plan covers up to 500 subscribers with unlimited sends using MailPoet’s own servers.

    Above 500 subscribers, pricing scales by list size: roughly $10 per month at 1,000 subscribers, $25 at 5,000, $60 at 15,000. That includes sending, so the total cost comparison against self-hosted options is closer than the license fees suggest.

    MailPoet’s automation is sequence-based rather than canvas-based. You can build welcome series, post notification emails, and WooCommerce abandoned cart flows, but conditional branching is limited compared to FluentCRM or Krom Automation. For newsletters and simple drip sequences it is fast to set up and requires no SMTP configuration.

    Omnisend

    Omnisend is a cloud-based ESP with a WordPress and WooCommerce plugin for data sync. The plugin itself is free; the sending and automation happen on Omnisend’s servers. The free plan allows 500 emails per month to up to 250 contacts.

    Paid plans start at around $16 per month for 500 contacts with 6,000 sends. Omnisend is genuinely strong on ecommerce automation: abandoned cart, browse abandonment, post-purchase sequences, and SMS alongside email.

    The constraint is data residency. Subscriber data, purchase history, and automation logs live on Omnisend’s servers.

    That is the right trade-off for teams that want zero infrastructure responsibility, but it is the wrong choice for sites with strict data sovereignty requirements. Omnisend also becomes expensive at high contact counts: 10,000 contacts runs around $115 per month.

    Brevo

    Brevo (formerly Sendinblue) is a cloud ESP with a WordPress plugin for form capture and contact sync. Pricing is based on sends per month rather than contact count, which is unusual and often cheaper for sites with large lists that send infrequently.

    The free plan includes 300 emails per day. Paid plans start at around $9 per month for 5,000 sends.

    Brevo’s automation builder is cloud-side. WordPress fires events through the plugin, and the automation logic runs in Brevo’s dashboard.

    That means richer email-side tooling but less native WordPress depth. Triggers are mostly form submissions and contact additions rather than WordPress-native events like post status changes or user role updates.

    ActiveCampaign

    ActiveCampaign is a full CRM and marketing automation platform. The WordPress plugin handles contact sync and form embedding. Automation, segmentation, and email sending all happen on ActiveCampaign’s servers.

    Plans start at around $15 per month for 1,000 contacts on the Starter tier. The platform is the most powerful option for complex CRM workflows, lead scoring, and multi-channel sequences, but it is also the most expensive at scale and the hardest to migrate away from.

    For teams already using ActiveCampaign, the Krom Automation ActiveCampaign integration lets you trigger ActiveCampaign contact updates, tag additions, and list changes directly from WordPress events, without duplicating your automation logic on both platforms.

    Comparison Table: Sending Method, Segmentation, Automation Depth, Pricing Model

    Plugin Sending method Segmentation Automation depth Pricing model
    Krom Automation Via configured SMTP or ESP integration Conditional branching on any trigger data Visual canvas, 16 triggers, 21 actions, AI included free Free forever; Pro from $119/year or $299 lifetime
    FluentCRM Via configured SMTP (not included) Tags, lists, custom fields, dynamic segments Sequence builder with conditions; no visual canvas Free tier; paid from ~$129/year
    MailPoet MailPoet servers included; SMTP optional Lists and segments by WooCommerce data Sequence-based; limited branching Free to 500 subscribers; then ~$10 to $60+/month by list size
    Omnisend Omnisend servers (cloud) Purchase history, tags, engagement Ecommerce-focused sequences with SMS support Free to 250 contacts/500 sends; paid from ~$16/month
    Brevo Brevo servers (cloud) Contact attributes and lists Cloud-side automations; limited WordPress-native triggers Free to 300/day; paid from ~$9/month by send volume
    ActiveCampaign ActiveCampaign servers (cloud) Full CRM with lead scoring Most powerful; complex multi-step journeys From ~$15/month; scales steeply by contact count

    True Total Cost: What the Sticker Price Does Not Show

    Self-hosted plugins look cheap until you add the sending layer. A FluentCRM license at $129 per year plus Amazon SES at roughly $6 per month for 10,000 emails totals around $201 in year one.

    MailPoet at $25 per month for 5,000 subscribers totals $300 for the year with no separate SMTP bill. The gap is smaller than it appears.

    A self-hosted plugin at $129 per year sounds like half the price of a cloud platform. Add the SMTP bill and the gap closes faster than most buyers expect.

    Scenario Plugin cost SMTP / ESP cost Year 1 total Year 2+ total
    Krom Automation free + Amazon SES (under 10k sends/month) $0 ~$6/month ~$72 ~$72
    Krom Automation Pro Basic + Amazon SES $119/year ~$6/month ~$191 ~$191
    FluentCRM paid + Postmark (5k sends/month) ~$129/year ~$10/month ~$249 ~$249
    MailPoet (5,000 subscribers, sending included) ~$25/month $0 ~$300 ~$300
    Omnisend (1,000 contacts, sending included) ~$16/month $0 ~$192 ~$192
    ActiveCampaign Starter (1,000 contacts) ~$15/month $0 ~$180 ~$180

    Krom Automation Pro becomes the cheapest self-hosted option at scale because the license fee is a flat annual cost regardless of how many emails you send. At 50,000 sends per month, Amazon SES costs around $5. No per-task or per-execution fees apply at any Krom Automation tier.

    What Switching Actually Costs

    Migration difficulty is the question no comparison article answers. Switching email automation plugins is not a two-hour job. Here is what actually transfers and what you have to rebuild by hand.

    • Subscriber lists: Export as CSV from the old plugin, import to the new one. Tags and custom fields may not map cleanly. Plan for 2 to 4 hours on a list of 5,000 contacts.
    • Automation sequences: Do not transfer at all between platforms. Every sequence must be rebuilt in the new tool. A complex abandoned cart flow with 5 steps and 3 branches can take a full day to recreate and test.
    • Email templates: Block-based templates are not portable between editors. Expect to rebuild or re-import HTML manually.
    • Historical engagement data: Open rates, click history, and suppression lists may be partially exportable as CSV but rarely import cleanly into a new platform. You may lose the suppression data and re-email people who previously unsubscribed, which carries legal risk under GDPR and CAN-SPAM.
    • WooCommerce order data links: If your current platform stores order-to-contact links (Omnisend, Klaviyo), those relationships do not export. The new platform starts with no purchase history per contact.

    The honest conclusion: switching email automation platforms costs between 8 and 40 hours depending on complexity, plus a period of degraded automation while you rebuild and test. Choose carefully the first time.

    Switching email platforms costs between 8 and 40 hours. The tool you pick today is probably the one you will be running two years from now.

    Which Plugin Is Right for Your Situation?

    Small blogs and content sites

    If you are sending a weekly newsletter to fewer than 500 subscribers and want simple post notification automation, MailPoet’s free plan covers you with no SMTP setup required. If you want more flexibility, including triggered sequences based on user registration or comment activity, Krom Automation’s free tier handles those with its 16 built-in triggers and zero sending fees when paired with a cheap transactional SMTP service.

    WooCommerce stores

    WooCommerce stores need abandoned cart recovery, post-purchase sequences, and order status triggers. Omnisend handles all three with sending included, and the ecommerce-specific segmentation is strong. Krom Automation’s free tier includes Order Created and Order Completed triggers, and the Pro version adds WooCommerce Subscriptions events through the WooCommerce Subscriptions integration.

    If you want automation that also connects your store to Slack, Google Sheets, or a CRM in the same workflow, Krom Automation is the more flexible choice. For a deeper look at WooCommerce-specific automation ideas, see our guide to the best WooCommerce automation plugins.

    Membership and LMS sites

    FluentCRM has the deepest native integrations for MemberPress, LearnDash, and LifterLMS, including membership status changes as automation triggers. Krom Automation covers the same ground through its MemberPress integration and LearnDash integration, with the additional advantage that you can connect those membership events to external tools like Mailchimp or ConvertKit in the same workflow through the Mailchimp integration and ConvertKit integration.

    Teams already using a cloud ESP

    If you are invested in ActiveCampaign, Mailchimp, or MailerLite and want to push WordPress events into those platforms without rebuilding your existing automations, Krom Automation works as the bridge layer. WordPress fires the trigger on canvas, Krom Automation processes it, and your cloud ESP receives the contact update or tag addition.

    That keeps your existing ESP workflows intact while giving you WordPress-native trigger logic. See the MailerLite integration documentation for a concrete example of how that sync works.

    Agencies managing multiple sites

    Krom Automation’s Enterprise plan at $369 per year covers unlimited sites with one license. FluentCRM’s agency pricing starts higher. Cloud ESPs charge per account or per contact count regardless of how many sites you manage.

    For agencies running 10 or more WordPress sites, the flat-license model saves significant money at scale. Our guide on the best WordPress automation tools for agencies covers multi-site considerations in more detail.

    FluentCRM vs MailPoet: The Direct Comparison

    These two appear together in most searches, so they deserve a direct answer. FluentCRM is a CRM first and an email tool second. MailPoet is an email tool first, with no contact management depth.

    If you need subscriber tags, custom fields, dynamic segments, and a contact timeline, FluentCRM wins. If you need a fast newsletter setup with reliable sending and no SMTP configuration, MailPoet wins.

    • Contact management: FluentCRM has it. MailPoet has basic lists only.
    • Sending included: MailPoet yes (up to subscriber limits). FluentCRM no, requires SMTP.
    • Automation canvas: Neither. Both use sequence-based editors.
    • WooCommerce depth: Both have it. FluentCRM has more segmentation options.
    • Free tier limit: MailPoet free stops at 500 subscribers. FluentCRM free has limited automation features rather than a contact cap.

    Do These Plugins Deliver Email Reliably?

    Self-hosted plugins (Krom Automation, FluentCRM) rely entirely on your SMTP configuration. Without a proper SMTP service, emails go through PHP mail, which major providers like Gmail and Outlook routinely reject or send to spam.

    An SMTP plugin like WP Mail SMTP connected to Postmark, SendGrid, or Amazon SES fixes this and takes around 30 minutes to configure. Cloud platforms (Omnisend, Brevo, ActiveCampaign) handle deliverability themselves, which is a real advantage for teams that do not want to manage it.

    For self-hosted setups, we recommend treating SMTP configuration as a prerequisite, not an optional add-on. A workflow that correctly triggers but delivers to spam is worse than no workflow at all, because it consumes your sending budget and you may never notice.

    Self-Hosted vs Cloud: The Data Question

    Self-hosted plugins keep subscriber data, automation logs, and contact history inside your own WordPress database. Cloud platforms store that data on their servers, under their terms of service, in data centers you may not control. For sites under GDPR, CCPA, or sector-specific regulations, the self-hosted model is frequently the right answer.

    For teams that want zero infrastructure responsibility and have no data residency requirements, cloud platforms are simpler. Our article on self-hosted vs SaaS automation and data privacy covers this trade-off in detail.

    Also from wpRigel

    Pollify is wpRigel’s Gutenberg-native poll, survey, and quiz plugin. Polls are built as real blocks inside the block editor, so there are no shortcodes to paste and no separate interface to learn. It pairs well with email automation if you want to embed engagement prompts in posts and feed responses into a workflow.

    Commandify is a keyboard-driven command palette for the WordPress admin. Press Cmd or Ctrl plus K to jump anywhere, search any post or order, and run admin actions without clicking through menus. It is the only WordPress command palette with real WooCommerce order, product, and customer commands built in, which makes it genuinely useful for store operators who live in the admin.

    Our Verdict

    If you want a self-hosted plugin that handles email as part of a broader automation strategy, including connections to external tools, AI-generated content, conditional branching, and a visual canvas, Krom Automation is the pick for 2026. The free version is genuinely capable, not a trial. The Pro version at $119 per year or $299 lifetime is the right upgrade once you need integrations beyond the free set.

    If you need a dedicated CRM with deep segmentation and no interest in a visual canvas, FluentCRM is the right self-hosted choice. If you want the simplest possible newsletter setup with sending included, MailPoet free gets you to 500 subscribers at no cost. If you are running a high-volume WooCommerce store and want ecommerce-specific automation with sending infrastructure included, Omnisend is worth its price at moderate contact counts.

    What we would not do: pay for a cloud platform at scale when a flat-license self-hosted plugin plus cheap transactional SMTP delivers the same emails for a fraction of the long-term cost. Download the free version of Krom Automation from the WordPress.org plugin directory and build your first workflow before spending anything. The free tier has no run caps, no expiry, and no features locked behind a trial counter.

    See all Krom Automation plans and pricing, including the 14-day money-back guarantee on every Pro tier.

    Frequently Asked Questions

    What is the best free WordPress email automation plugin for a small blog?

    MailPoet covers up to 500 subscribers with sending included at no cost. Krom Automation’s free tier has no subscriber cap and handles triggered emails based on 16 WordPress events, but requires a separate SMTP service to send reliably.

    For a simple weekly newsletter, MailPoet is easier to start. For event-triggered automation, Krom Automation is more flexible.

    Can I do email automation inside WordPress without paying for Mailchimp?

    Yes. FluentCRM, MailPoet, and Krom Automation all run entirely inside WordPress.

    You own your subscriber data, there are no per-contact fees from an external platform, and automation logic runs on your server. You will still need an SMTP service for reliable delivery if you use a self-hosted plugin, which costs around $6 to $10 per month at moderate volume.

    Which plugin is best for WooCommerce abandoned cart emails?

    Omnisend and MailPoet both include WooCommerce abandoned cart recovery out of the box with sending infrastructure included. Krom Automation can trigger on Order Created events and use delays and conditions to build a cart recovery sequence, but native abandoned cart detection requires the Pro version. For stores where abandoned cart is the primary need, Omnisend or MailPoet is the faster setup.

    Do I need a separate SMTP plugin if I use FluentCRM or Krom Automation?

    Yes, for reliable delivery. Both plugins send through your WordPress mail method, which defaults to PHP mail. PHP mail is blocked or marked as spam by most major email providers.

    Installing WP Mail SMTP and connecting it to a transactional provider like Postmark or Amazon SES takes around 30 minutes and costs under $10 per month at typical small-site volumes. Cloud platforms like Omnisend and Brevo handle this for you.

    How many subscribers can I have before I need to upgrade to a paid email plugin?

    MailPoet’s free plan caps at 500 subscribers. Omnisend’s free plan covers 250 contacts with 500 sends per month. Brevo’s free plan allows 300 emails per day with no contact cap.

    Krom Automation has no subscriber cap at any tier because it is a workflow tool rather than a list manager. The trigger fires, the email sends. FluentCRM’s free version has feature limits rather than a contact cap.

    The wpRigel Team

    September 5, 2026
    User Guide
  • Best AI Plugins for WordPress in 2026

    The best AI plugins for WordPress in 2026 are Krom Automation for workflow AI, Rank Math for SEO AI, Tidio for chatbots, Bertha AI for content generation, and DALL-E integrations for image creation. Which one you need depends on the problem you are trying to solve, and most sites need more than one. This guide covers each category honestly, including what these plugins cost, what they actually do, and two things almost no other roundup mentions: how they affect your page speed, and what happens to your data when content leaves your site and reaches a third-party API.

    WordPress has no shortage of plugins claiming AI capability. The practical divide is between plugins that put a thin AI wrapper around an existing feature and plugins where AI is genuinely central to what the tool does.

    The wrapper plugins add marginal value. The genuinely AI-native ones change how you work.

    We have organised this list by the job to be done, not by a ranked list of winners, because a chatbot plugin is irrelevant if you need content generation. Work through the category that matches your immediate need, then read the trade-off sections before you install anything.

    Browse the full Krom Automation feature list if workflow automation and AI actions are your primary interest.

    How to Read This Guide

    Each section covers one job: content generation, SEO, chatbots, image tools, and automation. Within each section we name the leading plugin, state what it costs, and then give you the honest limitation that the plugin’s own marketing page skips. We close with two sections that all competing roundups ignore: performance impact and data privacy.

    • Content generation: writing drafts, outlines, and product descriptions inside the editor
    • SEO: AI-assisted meta titles, descriptions, schema, and readability scoring
    • Chatbots: conversational customer support and lead capture
    • Image tools: generating or enhancing images without leaving WordPress
    • Workflow automation: connecting site events to AI-powered actions automatically

    AI Content Generation: Writing Inside the Editor

    Bertha AI is the most widely used dedicated content generation plugin for WordPress. It installs as a block editor sidebar and generates text from a short prompt without leaving the post editor.

    The free version allows around 2,500 words per month, which covers roughly 1 to 2 short posts. The Pro plan starts at $18 per month for unlimited generation on one site.

    Jetpack AI Assistant is available to any site already running Jetpack. It generates text, rewrites existing blocks, and summarises long content.

    The first 20 AI requests are free; beyond that, the AI add-on costs $4.95 per month. If you are already paying for Jetpack, this is the most cost-efficient entry point for occasional AI writing.

    The honest limitation of both tools is the same: they generate plausible text, not accurate text. A plugin cannot verify facts, and a post about a product’s specifications or a health topic that is AI-generated without a human review pass is a liability, not a time saver.

    Google’s stance is that AI-generated content is acceptable when it is helpful and reviewed by a human. The word “reviewed” is doing real work in that sentence.

    AI content generation saves drafting time. It does not replace the subject-matter knowledge that makes a post worth reading.

    AI for SEO: Rank Math, Yoast, and AIOSEO

    All three major SEO plugins now include AI features. The differences between them matter less than most comparison posts suggest, because the underlying functionality is similar: AI-assisted meta title and description generation, content analysis, and schema suggestions.

    Rank Math includes an AI assistant in its Pro plan at $6.99 per month. It generates meta descriptions, suggests focus keywords, and rewrites titles. The free version has no AI features.

    Yoast SEO Premium includes AI-generated meta descriptions and title patterns at $99 per year for one site. The Premium tier also adds internal linking suggestions based on content analysis, which is the feature that most clearly justifies the upgrade from free.

    AIOSEO includes an AI title and description generator in its Plus plan at $199 per year. The AI feature set across all three is broadly comparable. The deciding factor is usually which plugin’s overall UX you prefer, not the AI features specifically.

    Plugin AI features included Entry price for AI Sites covered
    Rank Math Pro Meta generation, keyword suggestions $6.99/month Unlimited personal sites
    Yoast SEO Premium Meta generation, internal linking $99/year 1 site
    AIOSEO Plus Meta generation $199/year 3 sites

    One thing none of these plugins disclose prominently: the AI meta generation sends your post content to an external API, usually OpenAI. On a membership site, a medical blog, or any site handling sensitive user discussions, that is worth knowing before you enable the feature.

    AI Chatbots: Tidio, Crisp, and What the Free Tier Actually Gets You

    Tidio is the leading AI chatbot plugin for WordPress by install count. The free plan includes live chat and a basic rule-based bot.

    The AI-powered Lyro assistant, which handles natural language customer questions, starts at $29 per month on top of the base plan. Lyro is trained on your site’s content via a URL crawl, which means setup is fast but the knowledge base is only as good as what is published on your site.

    Crisp offers a free plan with two agent seats and a basic chatbot. The AI summarisation and handoff features require the Unlimited plan at $95 per month per workspace. That price point makes Crisp a reasonable choice for a support team, not for a solo operator.

    The honest answer to the question “can I add a free AI chatbot that actually works?” is: not really. Free tiers of every major chatbot plugin cap conversations, agents, or AI requests. A chatbot that stops answering at 50 conversations per month is a worse experience than no chatbot, because visitors learn the tool is unreliable.

    A chatbot that hits its monthly cap mid-conversation is not a customer support tool. It is a broken promise with a sales pitch attached.

    AI Image Tools: Generation Inside WordPress

    There is no purpose-built image generation plugin that has emerged as a clear standard. The most common approach in 2026 is using a plugin that calls the OpenAI Images API (DALL-E 3) or the Stability AI API directly from the media library or block editor.

    AI Image Generator by Tasty Plugins and Wen AI Image Generator both follow this model. You supply your own API key and pay OpenAI or Stability AI directly for each image generated.

    DALL-E 3 via the API costs $0.04 per standard image at 1024×1024. Generating 50 images per month costs $2, which is substantially less than a stock photography subscription for the same volume. The trade-off is consistency: AI image generation produces novel images, not the controlled, brand-aligned photography that a product brand needs for its hero sections.

    • Best for: blog post featured images, article illustrations, concept visualisations
    • Poor fit for: product photography, brand campaigns, anything requiring legal copyright certainty
    • Setup requirement: an OpenAI or Stability AI account and API key before any image generates
    • Cost ceiling: set a monthly spend cap in your API provider dashboard before enabling; there is no hard limit built into the WordPress plugins themselves

    AI Workflow Automation: Krom Automation

    Krom Automation is a visual workflow automation plugin that includes AI actions in the free version with no paywall. It is the only WordPress-native automation plugin where AI is a first-class action type rather than a paid add-on or a separate plugin to install.

    The free version includes 3 AI actions: AI Generate Text, AI Content Moderation, and AI Auto-Tag. These fire automatically as part of a workflow.

    A practical example: a workflow triggered by a new comment submission runs the comment through AI Content Moderation before it reaches the approved queue, with no manual review required for comments that pass. You set the rules once and the workflow runs every time.

    Krom Automation supports 7 AI models across three providers in the free version. You bring your own API key and pay your provider at standard rates. wpRigel does not charge per AI call and does not mark up tokens.

    • OpenAI: GPT-4o Mini, GPT-4o
    • Google Gemini: Gemini 2.0 Flash, Gemini 2.5 Flash Preview, Gemini 2.5 Pro Preview
    • Groq: Llama 3.3 70B, Llama 3.1 8B

    The workflow builder runs on a drag-and-drop canvas built on ReactFlow. Triggers, actions, and conditions connect visually.

    The free version includes 16 triggers, 21 actions, and 20 ready-made workflow templates. You can read the complete trigger and action reference in the free actions documentation and the free triggers reference.

    Execution runs in the background via Action Scheduler, so nothing runs during page loads. Every execution produces a full per-step audit trail. The workflow simulator lets you test a workflow in dry-run mode with zero side effects before enabling it on live traffic.

    The Pro version adds 80+ additional triggers, 60+ additional actions, and 24 integrations covering forms, email marketing, CRM, LMS, membership, messaging, and social media. Pro also adds AI workflow generation: you describe an automation in plain English and get a working workflow in seconds. Pricing starts at $119 per year for one site, or $299 as a one-time lifetime purchase.

    See how Krom Automation compares to other automation plugins

    Automation plugin AI actions in free Visual canvas builder Per-task billing Self-hosted data
    Krom Automation Yes, 3 actions free Yes No Yes
    Uncanny Automator No, paid add-on No, list-based No Yes
    Zapier (external) Yes, limited Yes Yes, per task No, SaaS
    Make (external) Yes, limited Yes Yes, per operation No, SaaS

    For sites already using popular form plugins, Krom Automation connects natively. The Gravity Forms integration and the WPForms integration both fire triggers on form submission, letting you chain AI actions immediately after a form is completed.

    Download Krom Automation free from the WordPress.org plugin directory

    The Performance Question Nobody Answers

    Adding AI plugins does affect page speed, but not in the way most people assume. The performance cost is rarely on the frontend. It is in the WordPress admin and in the background processes that these plugins run.

    Content generation plugins that call an external AI API on page load can add 500ms to 3 seconds to the admin editor load time, depending on network latency and the API’s response time. This never affects your site visitors, but it slows down the editing experience. Plugins that load their AI UI as a deferred sidebar rather than inline with the editor block avoid most of this cost.

    Chatbot plugins almost always load JavaScript on every frontend page, including pages with no chat trigger. A poorly configured chatbot script adds 40 to 150KB to every page load. Always check whether your chatbot plugin supports conditional loading, meaning it only loads the script on pages where the widget is actually displayed.

    Automation plugins like Krom Automation have near-zero frontend impact because they run in the background via Action Scheduler. There is no AI API call during page render. We covered this in more detail in our post on whether automation plugins slow down WordPress.

    The Data Privacy Question

    Every AI plugin that calls an external API sends some portion of your site’s content to a third-party server. For most sites this is a non-issue. For some it is a serious problem.

    When you use a chatbot trained on your site content, that content is crawled and stored on the chatbot vendor’s servers. When you use an AI writing plugin to generate a draft, your prompt and any existing text you include goes to OpenAI, Google, or whichever provider is behind the plugin. When an SEO plugin generates a meta description, the post content is transmitted in that request.

    • Low risk: public blog content, product descriptions, published pages
    • Medium risk: unpublished drafts, editorial notes, internal documentation
    • High risk: membership content behind a login, patient or client records, financial data, anything covered by GDPR, HIPAA, or similar regulation

    Self-hosted automation tools like Krom Automation keep workflow data, execution logs, and API credentials in your own database. The only data that leaves your server is the specific content you choose to pass into an AI action, and you control what that is. We wrote a detailed breakdown of this trade-off in our post on self-hosted versus SaaS automation and data privacy.

    Sending a published blog post to an AI API is a different decision from sending unpublished member content. Most plugin setup guides treat them the same.

    The Stacking Problem: What Happens When You Run Multiple AI Plugins

    Most roundups recommend installing one plugin per category. In practice, a site running a content generator, an SEO plugin with AI, a chatbot, and an automation tool is running four separate AI integrations. Each one calls a different API, stores credentials separately, and may conflict with the others over WordPress hooks.

    The most common friction points when stacking AI plugins:

    • Duplicate API key management: if you use OpenAI across multiple plugins, each plugin stores its own key with no shared credential system
    • Overlapping post-save hooks: some content and SEO plugins both fire on save_post and can trigger competing actions on the same event
    • Admin JavaScript conflicts: AI sidebar panels from different plugins sometimes conflict in the block editor, particularly in Firefox
    • Unexpected API costs: with multiple plugins calling external APIs on the same events, monthly token usage can grow faster than any single plugin’s usage would suggest

    The practical mitigation is to test each plugin individually on a staging site before combining them, and to monitor your API provider’s usage dashboard weekly during the first month. We also recommend reading our post on AI plugin credits versus bringing your own API key, which covers the cost structure difference in detail.

    Quick Summary

    Job to be done Plugin we recommend Free tier useful? Starting price
    Content generation Bertha AI or Jetpack AI Yes, limited $4.95/month (Jetpack)
    SEO with AI Rank Math Pro No AI in free $6.99/month
    AI chatbot Tidio with Lyro Yes, rule-based only $29/month for AI
    AI image generation DALL-E API plugin Yes, BYOK $0.04/image via API
    Workflow automation with AI Krom Automation Yes, fully featured Free, Pro from $119/year

    Also from wpRigel

    Pollify is wpRigel’s poll, survey, and quiz plugin. It is built as native Gutenberg blocks, so creating a poll works exactly like writing a paragraph in the block editor.

    There are no shortcodes to paste and no separate interface to learn. It is worth knowing about if you run a content or community site that collects reader feedback.

    Commandify is a command palette for the WordPress admin. Press Cmd or Ctrl plus K to jump to any screen, search any content, and run admin actions without clicking through menus. It is the only command palette plugin with real WooCommerce order, product, and customer commands built in, which makes it particularly useful for store operators managing high order volumes.

    Our Verdict

    Install the plugin that solves the most expensive problem you have right now, not the one with the longest feature list. If you are losing an hour a day to repetitive WordPress tasks that could fire automatically, start with Krom Automation.

    If your site’s organic traffic is flat because meta descriptions are missing or poorly written, start with an AI SEO plugin. If customer support is your bottleneck, evaluate Tidio with a clear-eyed read of what Lyro’s free tier actually covers before you commit.

    The sites that get the most value from AI plugins in 2026 are the ones that install one, use it for 30 days, measure the actual time or revenue impact, and then decide what to add next. The sites that get the least value are the ones that install six AI plugins in a week and spend more time managing plugin conflicts than they save in automation.

    See Krom Automation pricing and plan details

    FAQ

    Do AI plugins slow down my WordPress site’s frontend?

    Rarely, if the plugin is well-built. Content generation and SEO plugins only call AI APIs in the admin, so they have no frontend impact.

    Chatbot plugins are the exception: a poorly configured chatbot script loads on every page and adds 40 to 150KB to each page load. Always check whether your chatbot supports conditional loading so the script only fires on pages where the chat widget is active.

    Is it safe to use AI-generated content, or will Google penalise it?

    Google’s position is that helpful, human-reviewed content is acceptable regardless of how it was drafted. AI-generated content that is published without review, is factually inaccurate, or clearly written for search engines rather than people is the category that risks a quality penalty.

    The plugin is not the risk. Publishing unreviewed output is.

    Which AI plugins work with your own OpenAI API key?

    Krom Automation, most AI image generation plugins, and the majority of standalone AI writing tools support BYOK (bring your own key). The SEO plugins with AI (Rank Math, Yoast, AIOSEO) manage the API connection themselves, so you do not supply a key directly. Whether BYOK is better depends on your volume: at low usage, the plugin’s bundled access is simpler; at high usage, your own key is almost always cheaper.

    What is the best free AI plugin for WordPress that has no meaningful restrictions?

    Krom Automation’s free version includes 3 AI actions, 16 triggers, 21 other actions, and 20 workflow templates with no run caps and no trial period. For AI-powered content generation, no free plugin offers genuinely unlimited generation: Bertha AI’s free tier caps at roughly 2,500 words per month. For SEO, all three major plugins reserve their AI features for paid plans.

    Can I send a form submission through an AI action automatically?

    Yes. Krom Automation fires a trigger on form submission from Gravity Forms, WPForms, Fluent Forms, Contact Form 7, and Elementor Forms. You then chain an AI Generate Text or AI Content Moderation action to that trigger.

    The submission is processed and the result stored or emailed before any human reviews the queue. See the Contact Form 7 integration documentation or the Fluent Forms integration guide for setup steps.

    The wpRigel Team

    September 5, 2026
    User Guide
  • Best WordPress Automation Tools for Agencies in 2026

    The best WordPress automation tools for agencies in 2026 are Krom Automation for self-hosted WordPress-native workflows, Uncanny Automator for deep plugin-to-plugin connections, and OttoKit for teams who want a cloud dashboard across client sites. The right pick depends almost entirely on how you price client work, because the licensing model at 25 sites is where the real cost difference appears, and that difference can exceed $2,000 per year between options.

    Agencies face a problem that solo site owners do not. Every workflow you build for one client needs to be reused, exported, documented, and handed over without breaking.

    Every tool you recommend gets multiplied across a portfolio. A $99 per year plugin sounds reasonable until you are paying for it 25 times over.

    This article covers the five tools worth evaluating in 2026, with a cost table at 5, 10, and 25 sites, honest notes on what each one does not do, and a section most roundups skip: how to turn automation into a client deliverable rather than an invisible cost center.

    Browse the full Krom Automation feature list if you want to start with what we build ourselves. The comparison below is written to be fair to every option.

    The Five Tools Worth Evaluating

    Krom Automation is a visual workflow builder that runs entirely inside WordPress. Triggers and actions connect on a drag-and-drop canvas powered by ReactFlow.

    The free version includes 16 triggers, 21 actions, and 20 ready-made templates. The Pro version adds 80+ additional triggers, 60+ additional actions, and 24 integrations, including FluentCRM, Mailchimp, LearnDash, MemberPress, Slack, Google Sheets, and social media publishing.

    Uncanny Automator is the most established plugin-to-plugin connector in the WordPress ecosystem. It has a large library of recipe templates and strong coverage of LMS platforms like LearnDash and TutorLMS. It uses a recipe metaphor rather than a visual canvas.

    OttoKit (formerly SureTriggers) operates as a cloud platform with a WordPress plugin that connects to the dashboard. It supports multi-site team workspaces, which is its main agency selling point. Workflows run on OttoKit’s servers rather than on the client’s hosting.

    AutomatorWP is the budget-first option. It uses an add-on model where each integration is a separate purchase. The base plugin is inexpensive, but the cost climbs quickly once you add the integrations a real agency workflow requires.

    Zapier and Make are external SaaS platforms, not WordPress plugins. They sit outside WordPress entirely and connect to it via webhooks or API. They are worth including because some agencies already run them for non-WordPress clients and want a single platform.

    Cost at 5, 10, and 25 Sites: The Table That Actually Matters

    Per-site licensing is the number most roundups omit. A tool that costs $199 per year for 5 sites sounds reasonable.

    At 25 sites on a per-license model, the same tool can cost over $900 per year. Self-hosted plugins with unlimited site licenses change that math entirely.

    Tool5 Sites / Year10 Sites / Year25 Sites / YearLicensing model
    Krom Automation Pro (Enterprise)$369$369$369Unlimited sites, one licence
    Krom Automation Pro (Standard)$199$398 (2x Standard)$995 (5x Standard)5 activations per licence
    Uncanny Automator (Agency)IncludedIncludedIncludedUnlimited sites on agency plan
    OttoKit ProScales by tasks/monthScales by tasks/monthScales by tasks/monthCloud, task-based billing
    Zapier (Team)Scales by tasks/monthScales by tasks/monthScales by tasks/monthCloud, task-based billing

    The most important row is Krom Automation Enterprise at $369 per year for unlimited sites. At 25 sites that is $14.76 per site per year.

    The lifetime Enterprise licence at $799 brings that to $31.96 total across every site you ever activate it on, with no recurring fee. For agencies with stable portfolios, the lifetime option removes the annual renewal conversation entirely.

    Per-task billing sounds affordable at one site. Across 25 active client workflows, it is a subscription that grows every time you do good work for a client.

    Workflow Reuse: What Transfers and What You Must Rebuild

    The ability to build a workflow once and deploy it across client sites is the single biggest time saving for any agency. Not every tool handles this the same way, and the gaps are not obvious until you are mid-onboarding for client number seven.

    • Krom Automation exports any workflow as a portable JSON file. Import it on a second site and the triggers and actions are pre-configured. You still need to map credentials and connection-specific settings per site, but the logic transfers in under 2 minutes. The workflow settings documentation covers import and export in detail.
    • Uncanny Automator does not have a native recipe export feature for moving workflows between sites. Reuse means rebuilding from a saved screenshot or a notes document.
    • OttoKit stores workflows in the cloud, so copying a workflow to a new client connection is faster than a plugin-to-plugin transfer. The tradeoff is that the workflow logic and all execution data live on OttoKit’s servers, not on the client’s hosting.
    • AutomatorWP has no native export. Each site is a fresh build.
    • Zapier and Make allow scenario duplication inside the same account, but sharing across separate client accounts requires manual recreation or Zapier’s paid transfer tools.

    For agencies running 10 or more client sites, JSON import and export is not a nice-to-have. Rebuilding a 12-step onboarding workflow by hand takes 45 to 90 minutes per site. Importing a JSON file and adjusting credentials takes 10.

    What Each Tool Handles Best

    Krom Automation: Best for agencies building client-facing workflows

    Krom Automation’s visual canvas makes it the easiest tool to hand over to a client without a training session. A client can look at the canvas, follow the flow from trigger to action, and understand what is happening without reading documentation. That matters when the client wants to edit a delay or swap an email template six months after you built the workflow.

    The visual workflow builder uses ReactFlow with auto layout, so even complex branching workflows stay readable. Conditional branching gives you Yes and No paths from any condition node, and the branching documentation shows how to chain conditions for multi-step logic without the workflow becoming unreadable.

    AI actions are included in the free version, with no paywall and no per-call fee added by wpRigel. You connect your own OpenAI, Google Gemini, or Groq API key and pay those providers at standard rates. For agencies building content pipelines, that means AI text generation, content moderation, and auto-tagging are available on every client site without a separate licence cost per site.

    Uncanny Automator: Best for LMS and community platforms

    If your agency builds LearnDash or TutorLMS sites, Uncanny Automator has deeper recipe coverage than any other plugin. Course completion triggers, quiz result conditions, and group enrollment actions are mature and well documented. The agency plan covers unlimited sites, which makes the licensing model competitive for large portfolios.

    The weakness is the list-based recipe editor. For agencies handing off to non-technical clients, a list of configured steps is harder to interpret than a visual canvas. Clients who want to adjust a workflow after handover typically need to call you back.

    OttoKit: Best for agencies that want a single cross-site dashboard

    OttoKit’s team workspace lets multiple agency staff access client workflows from one interface without logging into each WordPress admin separately. If your team manages 30 or more sites and needs shared visibility into what is running and what has failed, that is a real operational advantage.

    The cost model is the limitation. OttoKit charges by task executions per month.

    A client site running 500 order completion workflows, 200 user registration sequences, and 300 scheduled nudges per month adds up quickly. Agencies that build high-volume automation for e-commerce clients can find the monthly cost scaling faster than the client retainer.

    AutomatorWP: Best for budget-constrained single sites

    AutomatorWP’s base plugin is inexpensive, but each integration is a separate purchase. An agency workflow touching WooCommerce, FluentCRM, and Mailchimp requires three add-ons.

    At 10 sites, those add-on costs multiply. AutomatorWP makes sense for a single client site with a narrow use case, not for agencies building reusable workflows across a varied portfolio.

    Zapier and Make: Best for non-WordPress workflows

    Zapier and Make are the right choice when the automation connects two external services and WordPress is not involved in either the trigger or the action. For agencies with mixed portfolios, a Krom Automation licence for WordPress-native work and a Zapier account for external service connectors is a reasonable combination rather than a competition between them. Krom Automation’s incoming webhook receiver lets external services trigger WordPress workflows, and the webhook documentation covers the security layers including HMAC-SHA256 signature verification.

    Zapier is not a WordPress automation tool. It is an external automation tool that can touch WordPress. That distinction changes how you scope client work and how you bill for it.

    Integrations That Matter for Agency Stacks

    Most agency sites use some combination of a form plugin, a CRM, an email marketing tool, and either WooCommerce or an LMS. The integration depth across those four categories determines whether a tool is genuinely useful or requires workarounds on every client site.

    Krom Automation Pro covers the common agency stack directly. Form integrations include Gravity Forms, WPForms, Fluent Forms, Contact Form 7, and Elementor Forms.

    CRM and email integrations cover FluentCRM, Mailchimp, ActiveCampaign, MailerLite, and ConvertKit. Messaging covers Slack, Discord, Twilio, and Telegram.

    That coverage means a single Krom Automation Enterprise licence handles the integration layer across an entire agency portfolio without add-on purchases per site. The 24 Pro integrations span forms, CRM, email marketing, LMS, membership, messaging, social media, data storage, and productivity tools.

    Client Onboarding Automation: The Workflow Agencies Rarely Build

    Most automation roundups focus on what happens after a site is live. The workflow that saves agencies the most time is the one that runs when a new client site is set up: user account creation, role assignment, welcome email delivery, and CRM contact creation, all triggered by a single event.

    A practical agency onboarding sequence in Krom Automation looks like this:

    1. Trigger: User Registered (filtered to the client-admin role)
    2. Action: Update User Meta to record the onboarding date and assigned account manager
    3. Action: Send Email with the branded welcome sequence using the visual email builder
    4. Action: Create a FluentCRM contact tagged as “New Client” for the account manager’s pipeline
    5. Action: Post a Slack message to the agency’s internal #new-clients channel with the client name and site URL
    6. Delay: 3 days
    7. Action: Send a follow-up email checking whether the client has logged in

    That sequence runs automatically on every new client site where you activate and import the workflow JSON. The welcome email automation guide walks through the first steps, and the delays and scheduling documentation covers how to configure the 3-day gap without relying on WP-Cron alone.

    Turning Automation Into a Retainer Line Item

    The gap none of the competing roundups address is how agencies charge for automation work. Building a 10-step onboarding sequence and handing it over as part of a project is one model. Building it, monitoring it, improving it, and reporting on it monthly is a retainer.

    Krom Automation’s analytics dashboard gives you the numbers to justify that retainer. The reports page shows total executions, success rate per workflow, failed execution count, and an execution trend chart.

    It exports to CSV. That is a client-ready report, not just an internal log.

    • Total executions per month shows how much manual work the automation replaced.
    • Estimated time saved translates executions into hours, which translates into dollars.
    • Failed execution count with automatic retry logging shows that the system is monitored, not just installed.
    • Per-workflow success rate lets you identify which automations need attention before a client notices.

    A client paying $200 per month for an automation retainer wants evidence that $200 is worth it. A CSV showing 1,400 automated executions last month, 98.6% success rate, and an estimated 47 hours of manual work replaced is that evidence. No other plugin in this list generates that report out of the box.

    Automation that has no reporting is an invisible service. Invisible services get cut at the first budget review.

    What Each Tool Does Not Do: The Honest List

    Every tool in this comparison has genuine limitations. Marketing pages do not mention them. This section does.

    ToolWhat it does not doWho that affects
    Krom AutomationDelays depend on Action Scheduler, which relies on WordPress Cron. Low-traffic sites need a real server cron configured or delays fire late.Agencies hosting clients on very low-traffic shared hosting
    Krom AutomationAI actions require the client to supply their own API key. Not suitable if the client refuses to create an AI provider account.Clients with strict data policies or AI hesitancy
    Uncanny AutomatorNo visual canvas. Workflow logic is a list of configured steps. Non-technical clients cannot interpret or edit it without guidance.Agencies with high client self-service expectations
    OttoKitAll workflow data and execution logs live on OttoKit’s servers. Clients in regulated industries may not accept that.Legal, financial, healthcare, and education clients
    AutomatorWPNo export or import. Every site is a fresh build. Integration costs multiply across a portfolio.Any agency managing more than 5 sites
    Zapier / MakeNo WordPress-native triggers without webhook setup. Every WordPress event requires a plugin bridge to reach the platform.Agencies wanting triggers from WP core events like post status changes

    For agencies with clients in regulated industries, the self-hosted nature of Krom Automation is a practical advantage. Execution logs, workflow data, API credentials, and merge tag outputs all stay in the client’s own database. We have written about the data privacy question in more detail in our self-hosted versus SaaS automation guide.

    The Agency Recommendation, by Portfolio Type

    The right tool depends on what your portfolio actually looks like, not what a generic roundup recommends. Use this to find your fit:

    • Mixed portfolio of 10 to 50 WordPress sites: Krom Automation Enterprise at $369 per year. One licence, unlimited activations, full feature set, visual canvas for client handover, JSON export for workflow reuse.
    • Mostly LearnDash or LMS-heavy clients: Uncanny Automator Agency plan for the recipe depth, supplemented by Krom Automation for sites where visual handover matters.
    • Large team needing shared cross-site visibility: OttoKit for the team dashboard, with a separate Krom Automation licence for clients who need self-hosted data storage.
    • Mostly external service automation with WordPress on the edge: Zapier or Make for the external flows, Krom Automation for the WordPress-native triggers that Zapier cannot reach natively.
    • Single client, tight budget, simple use case: Krom Automation free version. 16 triggers, 21 actions, and 20 templates cover most single-site needs without a Pro licence.

    If you are starting a new agency or expanding an existing one and need a benchmark, the agency automation workflows playbook covers the workflows worth building on every client site before you build anything custom.

    Also from wpRigel

    Pollify is wpRigel’s poll, survey, and quiz plugin. It is built as native Gutenberg blocks, so adding a poll to a client post works exactly like adding a paragraph.

    No shortcodes, no separate interface, no embed step. Useful for agencies building engagement-focused content sites or lead capture pages.

    Commandify is a command palette for the WordPress admin. Press Cmd or Ctrl plus K from anywhere in the dashboard to search, navigate, and run admin actions without clicking through menus.

    It is the only command palette with genuine WooCommerce depth, including order management, product updates, and customer lookup from a single keystroke. For agencies who spend hours per week in client dashboards, it is a meaningful time saver.

    Our Verdict

    For most agencies, Krom Automation Enterprise at $369 per year is the correct answer. The unlimited site licence means the cost is fixed regardless of how many clients you add. The visual canvas makes handover work.

    The JSON export makes workflow reuse real. The analytics dashboard makes the service billable.

    Uncanny Automator is the right second choice for LMS-heavy portfolios. OttoKit earns its place for large teams who need shared cross-site visibility and are comfortable with cloud-stored workflow data.

    Neither of those is a reason to avoid Krom Automation. They serve different parts of the same problem.

    The tools to avoid for agency use are AutomatorWP at scale, where the per-integration cost multiplies, and any tool without workflow export, where every new client site is a rebuild.

    The free version of Krom Automation is a legitimate starting point. Download it from the WordPress.org plugin directory, build your first workflow on a test site, and export the JSON. If it transfers cleanly to a second site in under 10 minutes, you have your answer.

    See the full Krom Automation pricing and plan details to compare the Standard and Enterprise options before deciding.

    Frequently Asked Questions

    Can I manage automations across all client sites from one place?

    Not with a self-hosted plugin like Krom Automation or Uncanny Automator. Each site has its own installation and its own workflow dashboard. OttoKit is the tool designed for cross-site visibility from a single cloud dashboard, at the cost of storing workflow data externally.

    Is Krom Automation white-label ready?

    Krom Automation does not currently include a built-in white-label mode for rebranding the plugin interface under a client’s name. Agencies can install it on client sites under the wpRigel branding or restrict client access to specific workflow areas using WordPress user roles.

    How does per-task billing work and when does it become expensive?

    Cloud platforms like OttoKit and Zapier charge based on how many individual actions or tasks run per month across all your workflows. A single 5-step workflow that fires 200 times per month counts as 1,000 tasks.

    Agencies with high-volume e-commerce clients can exhaust task allowances quickly. Self-hosted plugins like Krom Automation run unlimited executions at no additional cost.

    What happens to client workflows if we stop paying for the licence?

    With Krom Automation, existing workflows continue to run after a licence expires because the core execution engine is part of the free plugin. You lose access to Pro triggers, actions, and integrations, but workflows built on free features keep firing. With cloud platforms like Zapier or OttoKit, workflows stop running immediately if the account lapses.

    Which automation tool works best with WooCommerce, FluentCRM, and Elementor together?

    Krom Automation Pro covers all three directly: WooCommerce order triggers and actions, a FluentCRM integration for contact and tag management, and an Elementor Forms integration that fires workflows on form submission. That combination covers the most common agency stack without requiring separate add-ons or bridges.

    The wpRigel Team

    September 4, 2026
    User Guide
  • Best WooCommerce Automation Plugins in 2026

    The best WooCommerce automation plugins in 2026 are Krom Automation, AutomateWoo, Uncanny Automator, and FluentCRM. Each solves a different problem, and picking the wrong one means paying for capability you will never use or missing the one trigger your store actually needs. This guide compares all four honestly, including the limitations none of their own marketing pages will tell you.

    A mid-size WooCommerce store generates dozens of actionable events every day: orders placed, payments failed, subscriptions renewed, carts abandoned. Handling those manually costs between 10 and 20 hours a month for a store processing 200 or more orders. That time adds up to a meaningful salary cost before you factor in the errors that come from doing repetitive work by hand.

    The plugins below were evaluated on four dimensions competitors rarely discuss openly: failure handling, AI support, performance impact, and data privacy. Those four factors separate a tool you can trust at scale from one that works fine until it does not.

    Browse the full Krom Automation feature list if you want to see how it handles each of those dimensions before reading the full comparison.

    Quick Summary

    • Best for visual, self-hosted automation: Krom Automation. Free tier covers 16 triggers and 21 actions. Pro starts at $119/year for 1 site.
    • Best for WooCommerce-specific follow-up sequences: AutomateWoo. Deep native WooCommerce hooks, but no visual canvas and no free tier.
    • Best for connecting many WordPress plugins together: Uncanny Automator. 190+ integrations, but logic lives in a list editor rather than a canvas.
    • Best for email marketing CRM combined: FluentCRM. Strong contact management, but automation depth outside email is limited.
    • Best for stores worried about data leaving the server: Krom Automation. All execution logs, workflow data and API keys stay in your own database.

    Comparison Table: What Actually Matters for WooCommerce Stores

    Factor Krom Automation AutomateWoo Uncanny Automator FluentCRM
    Free tier Yes, full featured, no run caps No Yes, limited integrations Yes, contact cap applies
    Visual canvas builder Yes, drag-and-drop ReactFlow No, list-based rules No, list-based rules No, linear sequences
    AI actions built in Yes, free, bring your own key No No No
    Execution logging per step Yes, full audit trail, free Yes, queue log Limited Limited
    Failure alerts and retry Email alert plus configurable retry Queue retry only No built-in alerting No built-in alerting
    Data stays on your server Yes, fully self-hosted Yes Yes, except external integrations Yes
    WooCommerce Subscriptions support Yes, Pro Yes, native Yes, via integration Partial
    Conditional branching Yes, Yes/No paths, free Yes, rule filters Yes, Pro only Yes, sequence conditions
    Background execution Yes, Action Scheduler Yes, Action Scheduler Yes, Action Scheduler Yes, Action Scheduler
    Pro pricing, 1 site $119/year or $299 lifetime $99/year (WooCommerce.com) $149/year $129/year

    The Hidden Cost No One Puts in a Comparison Table

    Every plugin in this list has a list price. What the list price omits is the cost of a workflow that fires silently and fails. An order status change that never triggered, a subscription renewal that skipped the welcome sequence, a low-stock alert that never sent: those failures cost real money, and most plugins offer no visibility into them unless you already know to look.

    Krom Automation stores a full per-step audit trail for every execution, free of charge. If a workflow fails at step three, you see exactly which step, why, and when.

    Email alerts fire on failure and a configurable retry backoff attempts recovery automatically. That is the kind of infrastructure most tools reserve for enterprise tiers.

    A workflow that fails silently is worse than no automation at all. You stop doing the task manually because you think the plugin is handling it, and it is not.

    Krom Automation: Best WooCommerce Automation Plugin for Visual Workflows

    Krom Automation is a visual workflow automation plugin built natively for WordPress. You connect triggers to actions on a drag-and-drop canvas. The free version includes 16 triggers, 21 actions, and 20 ready-made workflow templates, with no run caps and no features locked behind a paywall.

    For WooCommerce stores, the free tier covers Order Created and Order Completed triggers, plus actions to create coupons and update order status. That covers the most common post-purchase sequences without spending anything. Pro adds 80+ additional triggers and 60+ additional actions, including deeper WooCommerce Subscriptions support for renewal, expiry and payment events.

    What Krom Automation does best

    • Visual canvas: workflows are easier to audit, hand off to a developer, and debug when you can see the full flow at a glance rather than reading a list of rules.
    • AI actions, free: generate email copy, moderate comments, or auto-tag posts using GPT-4o, Gemini, or Llama, with your own API key and no markup on tokens.
    • Failure handling: email alerts on failure plus automatic retry with configurable backoff, included in every tier.
    • Data privacy: all execution logs, workflow data, and API credentials live in your own 9 custom database tables. Nothing leaves your server by default.
    • Dry-run simulator: test any workflow with zero side effects before it goes live, which matters when a mistake would send emails to your entire customer list.

    Honest limitations

    Krom Automation is WordPress-native. If you need to automate a workflow between two external services with no WordPress involvement, it is the wrong tool.

    Delay scheduling also depends on WordPress Cron, which fires unreliably on very low traffic sites unless you configure a real server cron. AI actions require you to supply your own API key from OpenAI, Google or Groq.

    The Pro version is newer than AutomateWoo’s integration catalogue, so a handful of niche WooCommerce extensions may not yet have dedicated Pro triggers. The full triggers reference and the public roadmap show what is available now and what is coming.

    Pricing: Free forever. Pro at $119/year for 1 site, $199/year for 5 sites, $369/year for unlimited sites.

    Lifetime licences available from $299. See the full pricing breakdown.

    AutomateWoo: Best for WooCommerce-Specific Follow-Up Sequences

    AutomateWoo is owned by Automattic and sold through WooCommerce.com. It is purpose-built for WooCommerce follow-up marketing: abandoned cart recovery, post-purchase emails, subscription renewal reminders, win-back sequences. Its trigger library is deep in WooCommerce-specific events that a general automation plugin may not cover out of the box.

    What AutomateWoo does best

    • Abandoned cart recovery with timing controls and coupon generation baked in.
    • WooCommerce Subscriptions native hooks, including renewal, payment retry and cancellation.
    • Review request sequences with delay rules tied to order fulfillment status.
    • A mature integration with WooCommerce’s own ecosystem, maintained by the same company.

    Honest limitations

    AutomateWoo has no visual canvas. Workflows are built as rule lists, which becomes harder to audit as sequences grow. There is no free tier: the plugin costs $99/year for a single site.

    There are no AI actions. Failure alerting is limited to a queue log you must actively check rather than a push notification. For stores that need automation beyond WooCommerce, such as connecting form submissions to a CRM or posting to Slack when an order flags, AutomateWoo reaches its limits quickly.

    AutomateWoo earns its place on WooCommerce-heavy stores, but it solves one problem well rather than many problems adequately.

    Uncanny Automator: Best for Connecting Many WordPress Plugins

    Uncanny Automator markets itself on breadth: 190+ WordPress plugins and external services connected through a single interface. If your store runs WooCommerce alongside LearnDash, MemberPress, Gravity Forms and a handful of other plugins, and you need events from all of them to talk to each other, Uncanny Automator covers that surface area better than any single-purpose tool.

    What Uncanny Automator does best

    • Cross-plugin trigger coverage, connecting WooCommerce purchases to LearnDash course enrollment, MemberPress membership grants, and more in a single workflow.
    • External service integrations including Google Sheets, Mailchimp, ActiveCampaign and Slack without requiring a separate connector plugin.
    • A free tier that covers single-trigger, single-action recipes for straightforward use cases.

    Honest limitations

    Uncanny Automator uses a list-based recipe editor, not a visual canvas. Conditional branching is a Pro-only feature, so free users cannot add Yes/No logic. Failure alerting is not built in.

    At $149/year for Pro, it is the most expensive option in this comparison for a single site. The breadth of integrations is the selling point, but if you only need WooCommerce automation without cross-plugin complexity, you are paying for surface area you will not use.

    FluentCRM: Best for Email Marketing CRM Combined

    FluentCRM is a self-hosted CRM and email marketing plugin with automation sequences. It stores contacts, segments them by WooCommerce purchase history, and sends email campaigns or drip sequences triggered by store events. If your primary automation goal is email marketing tied to purchase data, FluentCRM does that job well at a reasonable price.

    What FluentCRM does best

    • Contact management with WooCommerce purchase history synced natively, no external CRM subscription required.
    • Email sequences triggered by order status, product purchase, or subscription events.
    • A free tier with a contact cap that covers small stores without any upfront cost.
    • The Krom Automation FluentCRM integration lets you use FluentCRM as a contact store while Krom handles the workflow logic, combining the strengths of both.

    Honest limitations

    FluentCRM is primarily an email tool. Automation outside email, such as updating order meta, posting to Slack, or calling an external API, is limited. There is no visual canvas and no AI action support.

    Failure alerting is not a built-in feature. For stores that want a CRM, FluentCRM is a strong pick. For stores that want general workflow automation, it is the wrong layer of the stack.

    Which Plugin Suits Which Store

    Situation Best fit Why
    Small store, no budget, needs order automations now Krom Automation free 16 triggers, 21 actions, no run caps, no trial expiry
    Mid-size store, abandoned cart and review requests are the priority AutomateWoo Purpose-built for WooCommerce follow-up, mature abandoned cart logic
    Store also running LearnDash, MemberPress and Gravity Forms Uncanny Automator Pro Cross-plugin trigger coverage is its core strength
    Store that wants a self-hosted CRM plus email sequences FluentCRM Contact management and purchase history sync in one plugin
    Agency managing multiple WooCommerce stores Krom Automation Enterprise Unlimited sites at $369/year, workflow import/export as JSON for deployment
    Store that needs AI-generated email copy in workflows Krom Automation AI Generate Text action included free, supports GPT-4o, Gemini 2.5, Llama
    Store worried about automation data leaving the server Krom Automation or FluentCRM Both are fully self-hosted with no phone-home data sharing

    Does Running Automation Plugins Slow Down WooCommerce?

    All four plugins in this comparison use Action Scheduler for background execution. That means workflows do not run during a page load or checkout request.

    A customer completing an order does not wait for your post-purchase email sequence to fire. The execution happens in the background after the request is finished.

    The performance risk is different: it is database table growth over time. A store running 500 orders a month through a five-step workflow generates 2,500 execution log rows per month. After 12 months that is 30,000 rows.

    Most plugins handle this, but only Krom Automation gives you a reports page with date range filtering and CSV export so you can audit what is actually running. We have written a longer breakdown on whether automation plugins slow down WordPress if you want the full technical picture.

    The AI Question: Why Most Plugins Ignore It

    None of AutomateWoo, Uncanny Automator or FluentCRM include AI actions as a native feature. Krom Automation includes three: AI Generate Text, AI Content Moderation, and AI Auto-Tag. All three are available in the free version, and you pay your AI provider directly at their standard rates.

    The practical value for WooCommerce stores is not theoretical. A post-purchase workflow can generate a personalised thank-you email using order data injected via merge tags, with copy written by GPT-4o or Gemini 2.5 Flash at the point of execution.

    That is not something you set up once and forget: the AI writes fresh copy for each order based on the actual products purchased. We have covered the broader question of what AI WordPress automation actually does for stores that want to evaluate it carefully before committing.

    Paying a plugin vendor a markup on AI tokens is a business model, not a feature. If you supply your own API key, that markup disappears entirely.

    What the Marketing Pages Do Not Tell You

    Every plugin in this comparison has a features page that lists what it does. Here is what those pages omit.

    • WordPress Cron dependency: delayed actions on all four plugins depend on WP-Cron firing reliably. On very low traffic sites or shared hosting, cron fires late. A one-hour delay could become four hours. The fix is a real server cron, but you have to know to configure it.
    • Execution volume limits: none of these plugins impose per-execution billing, which is their shared advantage over SaaS tools like Zapier. However, very high volume stores should audit database growth every quarter regardless of which plugin they use.
    • Migration cost: switching between any of these tools means rebuilding workflows by hand. Krom Automation supports workflow import and export as portable JSON, which helps when moving between sites but does not help when migrating from a different plugin’s format.
    • Team handoff: a workflow built as a list of rules is harder to hand to a new team member than one built on a visual canvas. That is a real cost for stores with staff turnover or agency relationships.
    • API credentials storage: if your workflow calls an external API, where do those credentials sit? Krom Automation stores them in your own database. SaaS-adjacent tools may store them on a third-party server. This matters for stores with PCI or GDPR obligations. Our breakdown of self-hosted versus SaaS automation data privacy covers this in detail.

    Connecting WooCommerce to External Services

    All four plugins can send data to external services. The approach differs.

    Uncanny Automator has the widest pre-built connector library. Krom Automation Pro includes 24 integrations covering email marketing platforms like Mailchimp, ActiveCampaign, and MailerLite, plus messaging services including Slack, Discord, Twilio and Telegram, plus Google Sheets and Google Calendar.

    For services without a dedicated integration, Krom Automation’s HTTP Request action supports GET, POST, PUT, PATCH and DELETE with JSON response parsing. That covers most REST APIs without waiting for a dedicated connector. The incoming webhook receiver in Pro adds a secret URL per workflow so external services can trigger WordPress workflows directly, with HMAC-SHA256 signature verification and 9 security layers.

    Also from wpRigel

    Pollify is wpRigel’s Gutenberg-native poll, survey and quiz plugin. Polls are built directly inside the block editor as real blocks, so there are no shortcodes to paste and no separate admin screen to configure. It suits WooCommerce stores that want to collect post-purchase feedback or run product preference surveys without leaving the editor.

    Commandify is a command palette for the WordPress admin. Press Cmd or Ctrl plus K to jump anywhere, search anything, and run admin actions without clicking through menus.

    It is the only WordPress command palette with real WooCommerce depth: search orders by customer email, change order status, update product prices and stock levels, and manage customers, all from the keyboard. For store managers processing high order volumes, it cuts the daily admin routine measurably.

    Our Verdict

    If you are starting from scratch or evaluating options for a store under 500 orders a month, start with Krom Automation’s free version. You get 16 triggers, 21 actions, AI actions, conditional branching, a visual canvas, failure alerts, and execution logging with no time limit and no run cap. That is a more complete free tier than AutomateWoo’s paid entry point for most standard WooCommerce workflows.

    Upgrade to Krom Automation Pro if you need WooCommerce Subscriptions triggers, an incoming webhook receiver, the visual email builder, or any of the 24 third-party integrations. At $119/year for a single site or $299 as a one-time lifetime purchase, it is competitive against AutomateWoo and Uncanny Automator on price while adding capabilities neither of them offer.

    Choose AutomateWoo if abandoned cart recovery and WooCommerce-specific follow-up sequences are your entire brief, and you do not need anything outside that scope. Choose Uncanny Automator if your store runs alongside LearnDash, MemberPress, or a complex plugin stack where cross-plugin triggers are the central requirement. Choose FluentCRM if you want a self-hosted CRM and email marketing tool rather than a general workflow builder.

    The free Krom Automation plugin is available now in the WordPress.org plugin directory. Download it from WordPress.org and run your first WooCommerce workflow today without touching your budget.

    Compare all Krom Automation plans and pricing if you are ready to look at Pro.

    Frequently Asked Questions

    Can I automate abandoned cart emails in WooCommerce without paying for a plugin?

    Krom Automation’s free tier does not currently include an abandoned cart trigger in the free version. That trigger is available in Pro.

    AutomateWoo covers it but has no free tier. For genuinely free abandoned cart recovery, WooCommerce’s built-in email settings cover a basic version without any additional plugin.

    Do WooCommerce automation plugins slow down checkout?

    All four plugins in this comparison use Action Scheduler, which runs workflows in the background after the page request completes. Checkout speed is not directly affected.

    The real performance consideration is database table growth over time, which should be monitored on high-volume stores. Our full breakdown covers what actually happens at scale.

    What is the difference between AutomateWoo and Krom Automation?

    AutomateWoo is purpose-built for WooCommerce follow-up marketing with a rule-list editor and no visual canvas. Krom Automation is a general WordPress automation platform with a drag-and-drop canvas, AI actions, failure alerting, and a free tier. AutomateWoo goes deeper on WooCommerce-specific events; Krom Automation covers a wider range of site events and connects to more external services.

    Which plugin works best with Mailchimp or ActiveCampaign?

    Krom Automation Pro has dedicated integrations for both Mailchimp and ActiveCampaign, triggered by WooCommerce order events. Uncanny Automator also connects to both. FluentCRM connects to ActiveCampaign but positions itself as a replacement rather than a companion.

    Can WooCommerce automation handle low-stock alerts automatically?

    WooCommerce core sends a basic low-stock email to the admin. For custom logic, such as posting a Slack alert when a specific product drops below 5 units or creating a draft reorder post, you need an automation plugin.

    Krom Automation’s HTTP Request action or Slack integration in Pro can handle this. See how Slack alerts work for WooCommerce events.

    Is it safe to store API keys inside a WordPress automation plugin?

    Safety depends on where the credentials are stored. Krom Automation stores all API keys in your own WordPress database, encrypted, with no third-party server involved.

    SaaS tools route credentials through their own infrastructure. For stores with GDPR or PCI obligations, self-hosted credential storage is the lower-risk option.

    The wpRigel Team

    September 4, 2026
    User Guide
  • Do Automation Plugins Slow Down WordPress? The Honest Answer

    Automation plugins do not slow down WordPress page loads if they are built correctly, and a well-built one like Krom Automation runs every workflow in a background queue so visitors never wait for your automations to finish. The honest answer is more nuanced than a yes or no: a badly built automation plugin absolutely can hurt performance, while a well-architected one adds no measurable overhead to front-end speed at all. The difference comes down to one question: does the plugin run its work during the page request, or after it?

    Most performance advice online treats all plugins as interchangeable. A plugin that adds a CSS animation and a plugin that processes 500 order completions per day are not the same thing, and they do not create the same performance footprint. Automation plugins belong in their own category because their work is continuous and event-driven, not tied to a single page load.

    This article explains exactly how automation plugin execution works, what “background processing” means in practice, what genuinely does cause slowdowns, and how to diagnose a performance problem if you have one. We will be direct about the cases where an automation plugin is the culprit.

    Browse the full feature list for Krom Automation to see how background execution is built in from the start.

    How Automation Plugins Actually Execute Work

    The critical distinction is between synchronous execution and asynchronous background execution. Synchronous means the code runs during the HTTP request that a visitor or admin triggered.

    The server cannot send the response until that code finishes. Every millisecond the automation logic takes is a millisecond added to the page load time.

    Asynchronous background execution means the trigger fires, the job gets added to a queue, and the response goes back to the browser immediately. The queue processes separately, usually via a scheduled background process, with no connection to the page load that triggered it.

    Here is what that looks like in practice for a WooCommerce store:

    • A customer places an order. WooCommerce marks it complete and returns the confirmation page to the browser in under 500ms.
    • In the background, the automation queue picks up the “Order Completed” trigger and starts processing: tagging the customer in Mailchimp, updating a Google Sheet row, sending a Slack notification to your team.
    • Those three actions might take 2 to 4 seconds combined because each involves an external API call. The customer never waits for any of it.

    Krom Automation uses Action Scheduler for background execution, which is the same library WooCommerce itself uses for its own background tasks. No workflow logic runs during a page load.

    The trigger captures the event data, serialises it, and hands it to the queue. Page delivery is already done before the first action starts.

    The question is never whether an automation plugin runs code. Every plugin runs code. The question is when that code runs, and whether visitors are waiting for it.

    What Actually Causes Performance Problems

    Badly built automation plugins create performance problems in three specific ways. Understanding each one helps you audit what you have installed.

    1. Running heavy logic on every page load

    Some plugins register hooks that fire on every front-end request, even when there is nothing to do. If a plugin checks 12 conditions and queries 3 database tables every time any page loads, that overhead adds up fast. On a site serving 10,000 pages per day, a 50ms overhead per request costs 8 minutes of cumulative delay every single day, paid by your visitors.

    2. Blocking on external API calls

    An automation that calls the Mailchimp API, the HubSpot API, or Slack during the page request is the worst pattern. External API calls can take anywhere from 200ms to over 3 seconds depending on the service, your server location, and network conditions. If that call happens synchronously, the user stares at a blank screen while your server waits for a response from a third-party service you do not control.

    3. Unoptimised database queries

    Automation plugins that store execution logs, workflow state, and trigger history need database tables to do it properly. A plugin that instead runs complex queries against the default wp_options or wp_postmeta tables will generate table locks and slow queries at scale. Krom Automation uses 9 custom database tables with proper indexing so execution logs stay completely separate from the tables WordPress uses for every page render.

    Performance failure patterns, summarised

    Failure pattern What causes it Visible symptom
    Synchronous execution Workflow logic runs during the page request Page load spikes when events fire
    Blocking API calls External service called before page response is sent Intermittent slow loads tied to third-party uptime
    wp_options bloat Execution data stored in autoloaded options Every page load queries a growing options table
    Missing background queue No job queue; triggers process inline Admin and checkout pages slow under load
    Front-end hook overload Conditions checked on every request, even idle pages Baseline page time inflated across the board

    Does Plugin Count Matter?

    Plugin count is the wrong metric. What matters is the code each plugin loads on each request and what that code does. A site with 40 focused, well-coded plugins will outperform a site with 15 plugins where 3 of them are bloated all-in-one tools loading their entire feature set on every page.

    For automation plugins specifically, the question is not how many workflows you have built. It is whether those workflows run in the background. How Krom Automation works explains the trigger-action model in detail, but the short version is that every execution is queued and processed asynchronously regardless of how many workflows are active.

    Fifty active workflows running in a proper background queue put less pressure on your server than one workflow running synchronously during checkout.

    The All-in-One Plugin Problem

    One category that genuinely does carry higher performance risk is the “swiss army knife” automation platform that ships with 200 integrations, a form builder, a CRM, a landing page tool, and a loyalty program in a single plugin. These tools load code for every feature on every page, including the integrations you never activated.

    The performance cost is not always visible in a basic page speed test. It shows up as:

    • Elevated Time to First Byte (TTFB) across the entire site, not just on triggered pages
    • WordPress admin slowdowns because the plugin initialises its full stack on every admin request
    • Database query count per page climbing even when no automations are actively running
    • Autoloaded options growing past 1MB, which WordPress loads on every single request

    A focused automation plugin that does one job well will almost always have a smaller performance footprint than a platform trying to replace five other plugins at once.

    Do Inactive Plugins Slow Down WordPress?

    No. An inactive plugin’s files sit on disk but none of its code executes. WordPress checks whether a plugin is active before loading it.

    Inactive plugins do not run hooks, do not query databases, and do not load on any page. Leaving them installed has no performance cost, though it is still good practice to remove unused plugins for security reasons rather than performance ones.

    For automation plugins specifically, this means you can safely install and test a plugin without it affecting front-end performance. The performance question only applies once the plugin is active and workflows are running.

    How to Diagnose Whether an Automation Plugin Is Slowing Your Site

    If you suspect a plugin is causing slowdowns, work through these steps in order. Skipping ahead to step 4 wastes time if step 1 is the actual cause.

    1. Check TTFB baseline: Measure page load time before and after deactivating the suspected plugin using a tool like GTmetrix or WebPageTest. A meaningful TTFB increase with the plugin active points to synchronous execution overhead.
    2. Install Query Monitor: This free plugin shows every database query on a given page, which plugin generated it, and how long it took. An automation plugin adding 20+ queries to the front page is a problem.
    3. Check autoloaded options size: Run SELECT length(option_value) as option_value_length, option_name FROM wp_options WHERE autoload='yes' ORDER BY option_value_length DESC LIMIT 20; in your database client. If any single option from an automation plugin exceeds 100KB, it is being stored in the wrong place.
    4. Check the Action Scheduler queue: A healthy background queue processes jobs within a few minutes. If your queue shows thousands of pending jobs that are not clearing, your server cron may not be firing. This is a reliability issue more than a speed issue, but it can cause memory spikes when the queue finally catches up.
    5. Deactivate, measure, reactivate: If the above steps are inconclusive, deactivate the suspected plugin and measure load time for 24 hours. A measurable improvement confirms the source.

    WordPress Cron and Automation Reliability

    Background execution depends on WP-Cron firing regularly. By default, WP-Cron runs when a visitor loads a page.

    On low-traffic sites, hours can pass between page loads, which means queued automation jobs wait to execute. This is a reliability issue, not a performance issue, but it is worth understanding.

    The fix is to disable WP-Cron in wp-config.php and add a real server cron job that hits wp-cron.php every minute. This costs nothing extra and makes background execution genuinely reliable. We cover this in more detail in our article on why WordPress Cron is unreliable and what that breaks.

    The other point worth making honestly: a site processing very high automation volume, say 10,000 workflow executions per hour, will generate real server load regardless of how well the plugin is architected. That load happens in the background, not during page requests, but it is still CPU and database work. For sites at that scale, what breaks when your WordPress automation volume grows covers the specifics.

    What Good Architecture Actually Looks Like

    A well-built automation plugin leaves the smallest possible footprint on page requests. Here is what that looks like in practice:

    • Triggers capture event data and write a single row to a dedicated queue table. That write takes under 5ms.
    • All action execution happens in background processes, completely decoupled from page delivery.
    • External API calls, including connections to Mailchimp, Slack, Google Sheets, and similar services, run inside those background processes with no blocking.
    • Execution logs, workflow state, and analytics data go into dedicated indexed tables, not into wp_options or wp_postmeta.
    • Front-end JavaScript and CSS assets are loaded only on pages where they are needed, not site-wide.

    You can verify whether a plugin follows these patterns using Query Monitor on your front end and by checking whether the plugin creates its own database tables on activation. Plugins that store everything in wp_postmeta are the ones that grow into performance problems over time.

    The execution log that shows you a workflow failed 20 percent of last month’s runs is worth far more than the marginal overhead of keeping it. The insight is not the same as the cost.

    How Krom Automation Handles Performance

    Krom Automation was built with background execution as a non-negotiable. Every workflow, whether it is a simple welcome email or a multi-step sequence involving Mailchimp subscriber tagging, Google Sheets row creation, and a Slack notification, executes entirely in the background via Action Scheduler.

    The 9 custom database tables mean execution logs, analytics, workflow state, and the queue itself are fully isolated from core WordPress tables. The analytics dashboard, which shows total executions, success rate per workflow, and a 30-day trend chart, queries those dedicated tables and never touches wp_posts or wp_options during the calculation.

    The workflow simulator lets you test a workflow end to end before activating it, with zero side effects and zero background jobs created, so you can verify logic without adding load to your queue.

    For sites building out integrations with forms, the same background execution applies whether you are using Gravity Forms, WPForms, or Contact Form 7. The form submission fires the trigger synchronously in under 5ms, and everything else runs in the queue.

    The free version is available on the WordPress.org plugin directory with no trial period and no feature limits on the core automation engine. Download Krom Automation free and test it on a staging site to see the query footprint yourself.

    The Honest Limitations

    We said we would be honest, so here are the real constraints:

    • Server cron dependency: Delays and scheduled actions depend on WP-Cron firing. Shared hosting sites with very low traffic may see delays of 30 to 60 minutes between trigger fire and action execution unless a real server cron is configured.
    • High-volume background load: Background execution does not mean zero server load. A site running tens of thousands of executions per day will see meaningful background CPU and database use. That is expected and separate from page load performance, but it is not invisible.
    • Memory on catch-up: If a cron job misses several cycles and then runs, Action Scheduler may process a large batch at once. On servers with less than 256MB PHP memory limit, this can cause occasional timeouts. The fix is to configure a real server cron, not to disable background processing.

    These are solvable operational concerns, not architectural flaws. Our guide on what to expect as automation volume grows covers mitigation steps for each.

    Also from wpRigel

    Pollify is wpRigel’s Gutenberg native poll, survey and quiz plugin. Polls are built as real blocks directly inside the block editor, so there are no shortcodes to paste and no separate interface to learn. It fits naturally into any post or page without the overhead of a separate plugin loading a different builder.

    Commandify is a command palette for the WordPress admin. Press Cmd or Ctrl plus K from anywhere in the admin or on the front end to jump to any page, search any content type, or run admin actions without clicking through menus. It is the only command palette plugin with real WooCommerce order, product and customer commands built in.

    Our Verdict

    Automation plugins do not slow down WordPress page loads when they use proper background execution. The fear is understandable but misplaced for any plugin built on a background job queue. Where the fear is fully justified is for older or poorly architected plugins that run workflow logic synchronously, block on external API calls during page requests, or dump gigabytes of execution data into wp_options.

    If you are evaluating an automation plugin, ask one question before anything else: does it use a background queue, and can you verify that with Query Monitor? If the answer is yes and the plugin uses dedicated database tables, add it with confidence. If the plugin’s documentation does not mention background execution at all, treat that as a red flag.

    Sites that are already automated and noticing slowdowns should work through the diagnostic steps above before blaming the automation plugin. The cause is more often an unrelated plugin loading scripts site-wide, or a poorly configured server cron causing queue catch-up spikes.

    Ready to see what background-first automation looks like in practice? Compare Krom Automation plans or start with the free version and measure the footprint yourself.

    Frequently Asked Questions

    Will adding more workflows to an automation plugin slow down my site?

    Not if the plugin uses background execution. More workflows mean more background jobs, which run after page delivery. The front-end load for a site with 5 workflows and a site with 50 workflows is effectively identical because neither set runs during page requests.

    Do automation plugins that connect to external APIs slow down my site?

    Only if they make those API calls synchronously during the page request. A properly built plugin queues the API call and runs it in the background. The Mailchimp call, the Slack notification, and the Google Sheets write all happen after the visitor’s browser has already received the page.

    How do I know if my automation plugin is running code during page loads?

    Install Query Monitor and look at the Queries panel on your front end with the plugin active. If the plugin’s database calls appear there on ordinary page loads, it is running synchronously. Also check whether page load time drops noticeably when you deactivate the plugin on a staging copy of your site.

    Are all-in-one automation platforms worse for performance than focused plugins?

    Generally yes, because they load code for every feature regardless of what you use. A plugin with 200 integrations will initialise a larger code surface on every request than a focused plugin. The gap shows up in TTFB and admin page speed rather than in dramatic front-end failures.

    Does WordPress Cron affect page speed?

    Not page speed directly, but an unreliable WP-Cron affects when background jobs actually run. If cron fires infrequently, jobs queue up and then process in a large batch, which creates a temporary spike in server load. Configuring a real server cron job to run every minute eliminates the problem.

    The wpRigel Team

    September 4, 2026
    User Guide
  • Is It Safe to Automate WordPress? Security and Permissions

    WordPress automation security comes down to four things: where credentials are stored, whether every API endpoint enforces capability checks, how incoming webhooks are verified, and whether your automation tool itself could become an attack vector. Get those four right and automation makes your site more secure, not less, because consistent automated responses are harder to bypass than human ones that vary by day and by how much coffee someone had.

    The concern is reasonable. You are granting a tool permission to create users, publish posts, fire HTTP requests, and modify order data. If that tool is poorly built, you have just handed an attacker a pre-configured skeleton key.

    But the question is not whether to automate. It is whether the automation tool earns the access it is given.

    This guide covers the specific mechanisms that make automation safe or unsafe, what questions to ask before you install anything, and how Krom Automation handles each one. Where a risk is real, we say so. Where a concern is overstated, we say that too.

    Browse the full Krom Automation feature list to see exactly what the plugin can and cannot do before you read further.

    The Four Security Questions Every Automation Tool Must Answer

    Before you connect any automation plugin to a production WordPress site, it should be able to answer these questions clearly. Vague answers are a red flag.

    • Where are API keys and credentials stored? They should live in your own database, encrypted, never in a third-party cloud you do not control.
    • Do REST API endpoints enforce WordPress capability checks? Every endpoint that reads or writes data should verify the current user has permission before it acts.
    • How are incoming webhooks verified? A webhook with no signature check accepts data from anyone who knows the URL.
    • What does an execution audit trail look like? If a workflow misfires, you need a per-step log, not just a pass or fail result.

    These are not advanced concerns reserved for enterprise sites. A single misconfigured automation on a WooCommerce store with 500 orders a month is a real exposure. The good news is that a well-built plugin solves all four at the architecture level, so you do not have to solve them yourself.

    Credential Storage: Where Your API Keys Actually Live

    The most important security question for any automation tool is the simplest: where do your credentials go when you save them? A SaaS automation platform stores them on its own servers. That means your OpenAI key, your Mailchimp API token, your Google Sheets OAuth credential, and your WooCommerce application password all live in a third party’s database. When that vendor is breached, your keys are exposed.

    Krom Automation is self-hosted. Every credential, every API key, every execution log, and every workflow definition lives in your WordPress database on your own server.

    Nothing leaves your infrastructure except the outbound requests your workflows intentionally make. If you want to understand the full privacy argument, the blog post on self-hosted versus SaaS automation and data privacy covers it in depth.

    A SaaS automation platform is not just a tool you use. It is a third party that holds your credentials, your workflow logic, and your execution history. A vendor breach is your breach.

    Self-hosting is not a silver bullet. Your server still needs to be hardened, your WordPress installation still needs to be kept current, and your database still needs access controls. But it removes an entire category of supply chain risk that SaaS platforms cannot eliminate regardless of how good their security team is.

    REST API Security: Capability Checks Are Not Optional

    WordPress automation plugins that expose a REST API must enforce capability checks on every endpoint. This is a WordPress core requirement, but not every plugin follows it correctly. The pattern is straightforward: before any endpoint reads data, creates a user, or changes an order status, it calls current_user_can() with the appropriate capability and returns a 403 if the check fails.

    Where this goes wrong in practice:

    • Endpoints that check authentication but not authorization, so any logged-in subscriber can trigger administrative actions.
    • Webhook receivers that accept any inbound POST request without verifying who sent it.
    • Trigger endpoints that return event data without confirming the requester has permission to see that data.
    • Bulk action endpoints that apply a single capability check for the first item and skip it for the rest.

    Krom Automation operates under the krom-automation/v1 REST namespace. Every endpoint enforces WordPress capability checks before acting. Workflows run in the background via Action Scheduler, which means they execute server-side under a controlled context, not in response to a raw unauthenticated request.

    Incoming Webhooks: Signature Verification Is the Whole Game

    An incoming webhook receiver is a URL that listens for data from an external service. Without signature verification, anyone who discovers that URL can POST arbitrary data to it and trigger your workflows.

    This is not a theoretical risk. Webhook URLs get discovered through server logs, referrer headers, and simple enumeration.

    Krom Automation’s Pro incoming webhook receiver uses HMAC-SHA256 signature verification with a unique secret URL per workflow. The sending service signs its payload with a shared secret.

    Your site recalculates the signature on receipt and rejects the request if it does not match. An attacker who knows the URL but not the secret cannot forge a valid request.

    The Pro webhook receiver includes 9 security layers beyond signature verification. For the full technical setup, the incoming webhook receiver documentation covers each layer and the configuration steps. For sites receiving webhooks from services like Stripe, Shopify, or any external API, this is the correct architecture.

    A webhook URL without signature verification is an open door. The question is not whether someone will find it. It is how long before they do.

    The Supply Chain Risk Nobody Talks About

    Every guide covering WordPress automation security focuses on the WordPress side: update your plugins, use strong passwords, enable two-factor authentication. That advice is correct and necessary. But it misses a risk that matters more as automation becomes central to how a site operates: the automation tool itself is part of your attack surface.

    When you connect a SaaS automation platform to WordPress, you are trusting that platform’s entire software supply chain. That includes their npm dependencies, their cloud infrastructure providers, their subprocessors, and every engineer who has commit access to their codebase. A single compromised dependency in their pipeline can result in your workflows being modified, your credentials being exfiltrated, or your site being used as a relay for malicious requests.

    Three practices reduce this risk, regardless of which automation tool you use:

    • Least-privilege API tokens: When an automation workflow needs to write to Google Sheets, create a token scoped only to that sheet, not your entire Google account. When it needs to send email via Mailchimp, use a key scoped to that list, not the full account. Scope every token to the minimum it needs. The Mailchimp integration documentation shows how to configure this correctly.
    • Audit logging at the workflow level: Krom Automation stores a per-step execution audit trail in your own database. If a workflow fires unexpectedly or produces unexpected output, you have a timestamped record of exactly what happened at every step.
    • Rotate credentials on a schedule: API keys that never rotate are a permanent exposure. Set a calendar reminder every 90 days and regenerate any key connected to your automation workflows.

    A self-hosted automation tool removes most of this exposure because there is no vendor infrastructure to compromise. Your automation logic and credentials live on your server, under your control, with no third-party cloud in the middle.

    What a Workflow Can and Cannot Do

    A common concern is that enabling automation means giving a plugin unlimited power over your site. That is not how WordPress capability checks work when they are implemented correctly. Here is what Krom Automation workflows can and cannot do, based on the actions available in the free version.

    Action What it does WordPress capability required
    Create Post Publishes a new post with specified content and status edit_posts
    Create User Registers a new user with a specified role create_users
    Change User Role Promotes or demotes a user’s role edit_users
    HTTP Request Sends data to an external endpoint via GET, POST, PUT, PATCH, or DELETE Controlled by workflow permissions
    Update Order Status Changes a WooCommerce order status edit_shop_orders
    AI Generate Text Calls an AI provider API with user-supplied key and returns generated text User’s own API key required

    The key point in that table is the capability column. Workflows do not bypass WordPress’s permission system. They operate within it.

    A workflow that creates users needs the same capability a human admin would need to create users manually. If that capability is not present, the action fails and logs the failure.

    For a full reference of every available trigger and action, the free actions reference and the free triggers reference list every option with its configuration fields.

    The “Run Once” Safeguard and Why It Matters

    One underappreciated security feature in automation is duplicate execution prevention. A poorly built automation that fires twice on the same event can create duplicate users, send duplicate emails, or apply a coupon twice to the same order. In a WooCommerce context, duplicate execution on an order completed trigger can mean a customer receives two refunds or two fulfillment requests reach your warehouse.

    Krom Automation includes a run-once-per-entity enforcement setting at the workflow level. Enable it and the workflow will not execute more than once for the same triggering entity, regardless of how many times the trigger fires.

    This is a configuration choice, not a default, because some workflows genuinely need to run multiple times per entity. But for anything touching financial transactions or user account state, it should be on.

    The workflow settings documentation covers run-once configuration alongside pausing, notes, and import and export options.

    Testing Before Production: The Simulator

    Running an untested workflow on a live site is the automation equivalent of deploying untested code to production. The workflow may behave differently than expected, trigger unintended side effects, or expose logic errors that only appear with real data. Testing is not optional for any workflow that touches user accounts, orders, or external services.

    Krom Automation includes a built-in workflow simulator for dry run testing with zero side effects. You supply sample data, the simulator runs the workflow logic, and you see exactly what would have happened at every step, including which conditions would pass or fail and what each action would have sent. No emails are sent.

    No users are created. No API calls leave your server.

    For workflows that use conditional branching, the conditions and branching documentation explains how to test each path separately. For time-sensitive workflows, the delays and scheduling documentation covers how delays interact with the simulator. The workflow simulator documentation walks through the full dry run process.

    Execution Logging: Your Audit Trail When Something Goes Wrong

    Security is not just prevention. It is also detection and response. When a workflow fires unexpectedly, produces wrong output, or fails partway through, you need to know exactly what happened and when.

    A pass or fail result at the workflow level is not enough. You need a per-step record.

    Krom Automation stores a full execution log with a per-step audit trail for every workflow run. Each log entry includes:

    • The trigger that fired and the data it carried
    • The result of every condition check, including which path was taken
    • The input and output of every action
    • Timestamps at each step, so you can reconstruct the sequence
    • Failure details with the error message, plus the automatic retry schedule

    That level of logging matters because a workflow failing 20 percent of the time looks identical to a working one from the outside. The analytics dashboard shows overall success rate and a failure count, but the per-step log is what tells you whether an HTTP Request action is receiving a 401 from your external API or whether an AI action is timing out because the model is overloaded. Most competing plugins put this level of logging behind a paid tier.

    AI Actions and API Key Security

    Krom Automation includes AI actions in the free version: AI Generate Text, AI Content Moderation, and AI Auto-Tag. Every AI action requires you to supply your own API key from your chosen provider. OpenAI, Google Gemini, and Groq are all supported.

    wpRigel never charges per AI call and never marks up tokens. The API key is stored in your WordPress database and your requests go directly from your server to the AI provider. No request routes through wpRigel’s infrastructure.

    This model has a direct security implication: your AI API key is only as secure as your WordPress installation. If someone gains admin access to your site, they can read the stored key. That is the same risk as storing any other credential in WordPress, and the mitigation is the same: keep WordPress updated, use strong admin passwords, enable two-factor authentication, and restrict admin access by IP where your hosting environment allows it.

    The blog post on AI plugin credits versus your own API key covers the full tradeoff between shared credit pools and direct API key models, including the cost and control implications.

    Comparing Automation Security Models

    This table answers the decision most site owners are actually making: whether to use a self-hosted automation plugin or a SaaS platform connected to WordPress via REST API. The comparison is based on architecture, not marketing claims.

    Security dimension Self-hosted plugin (Krom Automation) SaaS platform (Zapier, Make, n8n Cloud)
    Where credentials are stored Your own database Vendor’s cloud infrastructure
    Execution logs Your own database, full per-step detail Vendor’s servers, retention varies by plan
    Vendor breach exposure None. No vendor holds your data Full exposure of stored credentials and workflow logic
    Webhook verification HMAC-SHA256 with unique secret per workflow (Pro) Varies by vendor and plan tier
    Capability enforcement WordPress capability checks on every endpoint Depends on the WordPress plugin connecting the two
    Data residency Your server, your jurisdiction Vendor’s data centers, may cross borders
    Supply chain risk Limited to your WordPress installation Vendor’s entire software and infrastructure stack

    SaaS platforms are not inherently insecure. They invest heavily in infrastructure security and often have security teams larger than any plugin vendor. The question is whether you are comfortable with a third party holding your credentials and execution history.

    For sites in regulated industries or handling sensitive customer data, that question has a clear answer. The blog post on self-hosted automation and data privacy goes further if you need to make a compliance argument internally.

    Self-hosted automation does not mean more work. It means the attack surface stays within infrastructure you already own, patch, and monitor.

    Practical Security Checklist Before Your First Workflow Goes Live

    Work through these in order. The first three items eliminate the largest categories of risk. Skipping ahead to webhook verification while running an outdated WordPress installation gets the priority backwards.

    1. WordPress core and all plugins current. Automation workflows call WordPress functions. An unpatched vulnerability in a dependency is exploitable regardless of how well the automation plugin itself is written.
    2. Admin accounts using unique, strong passwords with two-factor authentication. Automation credentials stored in the database are only as protected as admin account access.
    3. Application-specific passwords for any external service connection. Never use your primary account password for an API connection. Generate a scoped token and revoke it immediately if a workflow is retired.
    4. Run-once enforcement enabled on any workflow that touches financial transactions or user account state. Duplicate execution on an order workflow is not a nuisance. It is a real financial exposure.
    5. Simulator tested before production activation. Any workflow that sends email, creates accounts, or calls an external API should be dry-run tested with sample data before it goes live.
    6. Failure notifications configured. Krom Automation sends email alerts on workflow failure. Make sure these go to an address someone actually reads. A failing workflow that nobody notices can mean lost orders, unprocessed registrations, or missed alerts for days.
    7. Execution logs reviewed weekly for the first month. The first 30 days of a new automation reveal edge cases that testing does not. Reviewing logs takes 5 minutes and catches problems before they compound.

    If you are unsure which workflows to build first, the guide on what to automate first on a WordPress site puts the highest-value, lowest-risk automations at the top of the list.

    Also from wpRigel

    Pollify is wpRigel’s Gutenberg native poll, survey, and quiz plugin. Polls are built as real blocks directly inside the block editor, so there are no shortcodes to paste and no separate interface to configure. It is the right tool if you want to add audience engagement to your content without bolting on a separate platform.

    Commandify is a command palette for the WordPress admin. Press Cmd or Ctrl plus K to jump anywhere in the admin, search content and users, and run admin actions without navigating through menus. It is particularly useful for WooCommerce stores because it is the only command palette plugin with real order, product, and customer commands built in.

    Our Verdict

    WordPress automation is safe when the tool is built correctly and you follow basic credential hygiene. The risks are real but specific: credentials stored off-site, endpoints that skip capability checks, webhooks with no signature verification, and duplicate execution on sensitive workflows. Each of those has a defined solution, not a workaround.

    Krom Automation addresses all four at the architecture level. Credentials and logs stay on your server. Every REST endpoint enforces WordPress capability checks.

    The Pro incoming webhook receiver uses HMAC-SHA256 signature verification. Run-once enforcement prevents duplicate execution. The workflow simulator lets you test before anything touches production.

    Sites that should move forward: WooCommerce stores handling 50 or more orders a month, membership sites with active user registration, and any site where a manual process runs more than 3 times a week. The automation pays for itself in time within the first month and reduces the human-error risk that comes with repetitive manual work.

    Sites that should go slowly: those running outdated WordPress core or plugins, those on shared hosting with no real server cron configured (which affects delay reliability, as covered in the WordPress cron reliability post), and those that have not yet audited which admin accounts exist and who has access to them. Fix the foundation before you build on it.

    The free version is a permanent free tier with no run caps, no feature locks, and no trial period. Download Krom Automation from the WordPress.org plugin directory and build your first workflow with the simulator before anything goes live. When you are ready to add Pro features including the webhook receiver and 60 or more additional actions, see the full pricing details to pick the plan that fits your site count.

    Frequently Asked Questions

    Does enabling automation mean giving a plugin admin access to my entire site?

    No. A well-built automation plugin operates within WordPress’s existing capability system.

    Each action requires the same capability a human user would need to perform the same task manually. Krom Automation enforces WordPress capability checks on every REST endpoint, so no action bypasses the permission model.

    What happens if a workflow fires on the wrong data and sends emails to the wrong people?

    Use the built-in simulator to test every workflow with sample data before activating it on production. The simulator runs the full workflow logic and shows you exactly what each action would send, with no real emails dispatched. Enable run-once enforcement and review the execution log after the first few live runs to catch any edge cases the simulator did not surface.

    Is it safe to store AI API keys inside a WordPress plugin?

    The key is stored in your WordPress database, so its security depends on your WordPress installation’s security. Use strong admin passwords, enable two-factor authentication on all admin accounts, and keep WordPress and all plugins updated. The advantage of the self-hosted model is that the key never leaves your infrastructure unless a workflow explicitly calls the AI provider API.

    Can a third-party automation service like Zapier read my WordPress database?

    Not directly. SaaS platforms connect via the WordPress REST API or a dedicated plugin and can only access what that connection exposes.

    The risk is not database access but credential exposure: if the SaaS vendor is breached, any API tokens or application passwords you stored with them are compromised. A self-hosted plugin eliminates this because there is no third-party vendor holding your credentials.

    What is the safest way to automate user registration on a WordPress site?

    Combine the User Registered trigger with a conditional branch that checks a field value or source before proceeding. Use Krom Automation’s AI Content Moderation action to flag suspicious input in registration fields.

    Enable run-once enforcement so a single registration event cannot trigger the same follow-up workflow twice. For sites using form plugins, the Gravity Forms integration and the WPForms integration each support form-specific triggers that give you finer control over which submissions enter your automation.

    The wpRigel Team

    September 3, 2026
    User Guide
  • What to Automate First on a WordPress Site (In Order)

    The first thing to automate on a WordPress site is the task that happens most often, takes the most manual time, and causes the most damage when something goes wrong. For most sites, that is the new user welcome sequence, not backups, not social sharing, not updates. This guide ranks the most common WordPress automation candidates in a defensible order so you build the right thing first, not just the easiest thing.

    Every competing guide on this topic presents a flat list of 10 or 15 ideas and calls it a day. None of them answer the actual question: given limited time, which automation do you build first?

    The answer depends on a simple framework: frequency times manual time times error risk. Multiply those three factors together and the ranking writes itself.

    We built Krom Automation specifically for this kind of WordPress-native workflow work. The free version includes 16 triggers and 21 actions, covers every automation in this guide, and requires no code. Everything below can be built on a visual drag-and-drop canvas without touching a line of PHP.

    Browse the full feature list to see what each automation step looks like in practice.

    The Framework: How to Rank What to Build First

    Before the list, the logic. Score every candidate automation on three dimensions:

    • Frequency: How many times per month does this task happen? A task that fires 200 times a month outranks one that fires twice.
    • Manual time: How long does the manual version take, in minutes? Even a 3-minute task adds up fast at 200 repetitions.
    • Error risk: What breaks if a human forgets or rushes? A missed welcome email costs a subscriber. A forgotten order status update costs a customer relationship.

    Multiply those three together and you get a rough priority score. The automations at the top of this list score highest on all three. The ones near the bottom are either infrequent, fast to do manually, or low stakes when they slip.

    The easiest automation to set up is rarely the one worth building first. Build for frequency and error risk, not for convenience.

    Priority 1: New User Welcome Emails

    This fires every time someone registers, subscribes, or completes a purchase. On an active site that might be 50 to 500 times a month.

    The manual version, copying a name and sending a personal email, takes 3 to 5 minutes per person. At 100 registrations a month, that is 300 to 500 minutes of repetitive work.

    The error risk is also high. A late or missing welcome email reduces the chance that a new user ever logs back in.

    Studies across SaaS products consistently show that first-session engagement drops sharply when onboarding contact is delayed beyond 15 minutes. An automated welcome workflow fires in seconds.

    Building this in Krom Automation takes about 10 minutes. The first workflow walkthrough in the documentation uses exactly this scenario: a User Registered trigger connected to a Send Email action, with merge tags pulling in the user’s first name and login URL dynamically. Read the merge tags documentation to see how dynamic variables work across every action field.

    Priority 2: Form Submission Follow-Up

    Contact forms, lead capture forms, and quote request forms all share the same problem: someone fills them out and waits. The average manual response time for a business website contact form is over 40 hours. The person who filled it out is gone in 40 minutes.

    An automated acknowledgement email buys time and sets expectations. A follow-up sequence, delayed by 24 hours, keeps the conversation alive without anyone monitoring an inbox. This workflow fires every time a form submits, which on a busy site might be 20 to 200 times a month.

    Krom Automation connects natively to every major form plugin. See the integration documentation for Contact Form 7, Gravity Forms, WPForms, Fluent Forms, and Elementor Forms for setup steps and example workflows for each.

    Priority 3: Email List Sync on Registration or Purchase

    When someone registers on your site, joins a membership, or completes an order, they should be in your email marketing tool within seconds. The manual version is an export from WordPress, an import into Mailchimp or ActiveCampaign, and a hope that nothing slipped through. Most site owners do this weekly at best, which means new subscribers wait up to 7 days before receiving their first campaign.

    This automation scores extremely high on error risk. A subscriber who misses the first week of onboarding emails churns at a higher rate than one who received them. The frequency matches your registration rate, which for a growing site means it fires daily.

    Krom Automation Pro connects directly to Mailchimp, ActiveCampaign, FluentCRM, MailerLite, and ConvertKit, among others. The trigger is User Registered or Order Completed. The action is a single subscribe call with the user’s email and any tags you want applied.

    Priority 4: WooCommerce Order Status Notifications

    WooCommerce sends a default order confirmation, but it stops there. When an order ships, when a refund processes, when a backorder clears, those updates require manual intervention unless you automate them. On a store processing 50 orders a week, manually updating customers on status changes takes 30 to 60 minutes a day.

    The error risk here is reputational. A customer who places an order and hears nothing for 5 days files a dispute.

    An automated shipping notification with a tracking number cuts that support ticket load dramatically. For a deeper look at the time this recovers, see how the WooCommerce daily admin routine can be cut in half.

    The free version of Krom Automation includes Order Created and Order Completed triggers, plus an Update Order Status action. Pro adds the full WooCommerce Subscriptions workflow set, documented in the WooCommerce Subscriptions integration guide.

    A customer who places an order and hears nothing for five days does not wait. They open a dispute. Automated status updates are not a nice-to-have.

    Priority 5: Comment Spam and Moderation

    On a site with active comments, moderation is daily work. Reviewing, approving, flagging, and deleting comments manually takes 10 to 30 minutes a day on a moderately active blog. Multiply that by 365 and you are looking at 60 to 180 hours a year spent on comments alone.

    Automation here looks like: when a comment is submitted, run it through an AI content moderation check, then approve it automatically if it passes or flag it for review if it does not. The free Krom Automation AI Content Moderation action handles exactly this. The comment moderation automation guide walks through the full workflow configuration.

    Priority 6: Post-Publish Social Sharing

    Every time a post publishes, someone on your team either manually shares it to LinkedIn, Twitter/X, and Facebook, or it does not get shared at all. Manual sharing takes 5 to 15 minutes per post across three platforms. Miss it once and that content never gets its initial distribution push.

    This automation scores lower than the ones above because the frequency is lower (most sites publish 2 to 8 posts per month) and the damage from missing it is recoverable. But the time-per-execution is high enough that automating it still returns several hours a month for a content-heavy site.

    The social media integration documentation covers how to connect your accounts and build a Post Published trigger that fires on any post type or specific category.

    Priority 7: Internal Alerts for Site Events

    Your team does not know what it cannot see. When a high-value order arrives, when a membership payment fails, when a new affiliate registers, someone should know within minutes, not when they happen to check the dashboard the next morning. The manual version is checking the admin panel several times a day, which is itself a form of repetitive work that automation eliminates.

    A Slack or Discord alert workflow costs almost nothing to build and saves 15 to 30 minutes of dashboard-checking per day per team member. The messaging integration documentation covers Slack, Discord, Twilio, and Telegram. For the WooCommerce-specific version, this guide on Slack alerts for orders shows the exact workflow structure.

    What the Ranking Looks Like as a Table

    Here is how the seven automations score against each other. The priority number reflects frequency times manual time times error risk, not an arbitrary list order.

    Automation Fires per month (typical) Manual time per occurrence Cost of missing it Build priority
    Welcome email on registration 50 to 500 3 to 5 minutes Lower re-engagement rate 1
    Form submission follow-up 20 to 200 5 to 10 minutes Lost lead within hours 2
    Email list sync on registration Matches registration rate Weekly batch: 20 to 40 minutes 7-day gap in onboarding 3
    WooCommerce order notifications Matches order volume 2 to 4 minutes per order Disputes and chargebacks 4
    Comment moderation Daily on active blogs 10 to 30 minutes per day Spam published, time lost 5
    Post-publish social sharing 2 to 8 posts 5 to 15 minutes per post Missed distribution window 6
    Internal team alerts Varies widely 15 to 30 min/day of checking Delayed response to events 7

    How Site Type Changes the Order

    The ranking above is a reasonable default, but three site types have different enough workflows that the order shifts.

    Site type Start here instead Why the order changes
    WooCommerce store Order status notifications Order volume is high and customer expectation is immediate. A missed status update costs more than a missed welcome email.
    Membership site Welcome email plus email list sync, simultaneously Member onboarding in the first 48 hours determines whether they ever log in again. Both automations fire on the same trigger.
    LMS or course site Enrollment confirmation and completion follow-up Learner drop-off peaks in the first week. An automated nudge sequence on day 3 and day 7 recovers completions that would otherwise be lost.
    Solo blog, no commerce Post-publish social sharing No users registering and no orders means social sharing jumps to the top. It is the only high-frequency manual task.
    Lead generation site Form submission follow-up Every form submission is a potential sale. Response time is the single biggest factor in lead conversion.

    What Is Not Worth Automating First (and Why)

    Several tasks appear on every WordPress automation list but score poorly on the frequency-time-risk framework.

    • Auto-updates for plugins and themes: Frequency is low (a few times per month), manual time is under 5 minutes per update, and the risk is reversed because automatic updates on a production site can break things. Automate this last, or not at all without a staging environment and a rollback plan.
    • Automated backups: Worth doing, but the right tool for this is a dedicated backup plugin (Updraft, BlogVault, WP Time Capsule), not a workflow automation plugin. It is infrastructure, not a workflow.
    • Scheduled reports: Useful but the frequency is low and the manual version takes 10 minutes a week. Not a priority until the higher-impact workflows are running.
    • Content scheduling: WordPress already does this natively. Automating something the platform handles is not a gain.

    Auto-updates appear on every automation list because they are easy to talk about. They are not where your time is going. Build for what actually costs you hours.

    How to Build These Without Code

    Every automation in this guide is buildable in Krom Automation’s free version. The process is the same for all of them: pick a trigger from the 16 available, add one or more actions from the 21 available, configure your conditions and delays, and test with the built-in workflow simulator before activating.

    The simulator runs a dry run with zero side effects, so you can confirm that merge tags resolve correctly and that the right email body is constructed before a real user ever triggers it. Read how Krom Automation works for the full explanation of triggers, actions, and the canvas.

    If you want to add conditional logic, for example sending a different welcome email to users who register via a specific form versus via WooCommerce checkout, the conditions and branching documentation explains how Yes and No paths work on the canvas. For automations that should fire 24 hours or 7 days after the trigger, delays and scheduling covers every unit from minutes to weeks.

    The free plugin is available directly from the WordPress.org plugin directory with no trial period, no run caps, and no features paywalled. Pro starts at $119 per year for 1 site and adds 80+ additional triggers, 60+ additional actions, and 24 integrations.

    Also from wpRigel

    Pollify is a Gutenberg-native poll, survey, and quiz plugin. Everything is built as real blocks inside the editor, so there are no shortcodes to paste and no separate interface to learn. It is the right tool if you want to collect structured feedback or run audience polls without leaving the block editor.

    Commandify is a command palette for the WordPress admin. Press Cmd or Ctrl plus K to search everything, jump anywhere in the admin, and run actions on orders, products, and customers without clicking through menus. It is the only WordPress command palette with full WooCommerce order, product, and customer commands built in.

    Frequently Asked Questions

    Should I automate backups or welcome emails first on WordPress?

    Welcome emails first. Backups are important infrastructure, but the right tool for them is a dedicated backup plugin, not a workflow automation plugin. Welcome emails fire daily on an active site and the manual version is slow and error-prone.

    Can I automate WordPress without any coding?

    Yes. Krom Automation’s free version uses a visual drag-and-drop canvas.

    You pick a trigger, add actions, configure the fields, and test with the simulator. No PHP, no JavaScript, and no custom code at any step.

    Is Zapier or a WordPress plugin better for automating my site?

    A WordPress-native plugin is better when the trigger and the action both involve your WordPress site. Zapier adds cost per task, stores your data on external servers, and adds a round-trip latency for every execution. If you are connecting two external services with no WordPress involvement, Zapier makes sense.

    For everything in this guide, a self-hosted plugin wins. We covered the data angle in depth in our self-hosted versus SaaS automation comparison.

    What free plugins can automate repetitive WordPress tasks?

    Krom Automation’s free version covers welcome emails, form follow-ups, post publishing triggers, comment moderation, WooCommerce order events, and more, across 16 triggers and 21 actions with no run caps and no paywalled features.

    How do I automate WordPress plugin and theme updates safely?

    Enable auto-updates only on a site with automated staging and a rollback mechanism. Without those two things, an auto-update that breaks a page builder or WooCommerce extension takes down a live store with no easy path back. For most sites, manual updates reviewed in a staging environment are lower risk than full automation.

    What breaks first when automation volume grows on WordPress?

    WordPress Cron. On low-traffic sites, WP-Cron only fires when someone visits a page, which means delayed workflows wait until a visitor triggers the cron queue.

    The fix is a real server cron job running every minute. We covered this problem and its solutions in detail in the guide on WordPress Cron reliability.

    The right order for WordPress automation is not the order that feels easiest. It is the order that returns the most time, at the lowest error rate, on the tasks that happen most often. Start with welcome emails.

    Build form follow-up next. Add email list sync, order notifications, comment moderation, social sharing, and team alerts in that sequence. Everything in the list above is buildable for free, today, without writing a line of code.

    See Krom Automation pricing and choose a plan, or download the free version from WordPress.org and start with the welcome email workflow.

    The wpRigel Team

    September 3, 2026
    User Guide
  • Self-Hosted vs SaaS Automation: The Data Privacy Question

    Self-hosted automation data privacy comes down to one question: who can see what your workflows are doing? When you run automation on your own server, execution logs, API credentials, user data, and trigger payloads stay in your database.

    No third party holds them. But that guarantee only holds as long as you run the stack correctly, patch it consistently, and treat outbound integrations as the external data flows they are.

    Most guides stop at “self-host it and your data is safe.” That is half the story. The other half is that owning the stack means owning every vulnerability in it. This article covers both halves, with specific attention to where WordPress-native automation sits in that picture and what Krom Automation does, and does not do, with your data.

    If you are evaluating workflow automation for a site handling personal data, regulated information, or simply data you would rather not hand to a third party, this is the comparison that matters.

    Browse the full Krom Automation feature list to see how the architecture decisions described below translate into specific capabilities.

    Where Your Data Actually Lives: Self-Hosted vs SaaS

    The core difference between a SaaS automation platform and a self-hosted one is custody. When you use Zapier or Make, every trigger payload, every action parameter, and every execution log passes through their infrastructure. That is not a design flaw.

    It is how those services work, and their security teams are large and competent. But it does mean your data leaves your server on every workflow run.

    With a self-hosted tool, or a WordPress-native plugin like Krom Automation, the execution happens inside your own environment. A user registers on your site, the trigger fires, the workflow runs, the log is written to your database. Nothing leaves unless an action explicitly sends it somewhere.

    The question is not whether self-hosting is more private by default. It is whether you are prepared to keep it that way.

    That distinction matters for GDPR and CCPA compliance. If you are a data controller, you need to know which processors touch personal data.

    A SaaS automation platform that processes trigger payloads containing email addresses, order totals, or health information is a data processor, and you need a data processing agreement with them. A self-hosted workflow that never sends that data anywhere is not creating that relationship.

    What “Staying on Your Server” Actually Means for Krom Automation

    Krom Automation stores everything in your WordPress database across 9 custom tables: workflow definitions, execution logs, per-step audit trails, analytics data, and any merge tag values resolved during a run. None of that syncs to wpRigel servers. There is no telemetry call home, no usage reporting, and no remote logging.

    Background execution runs through Action Scheduler, which means workflows fire during WordPress’s own cron cycle rather than during a page load. The entire execution stays on-server. You can read exactly how triggers, actions, and workflows connect in the documentation.

    Execution logs are written locally and kept locally. The workflow settings documentation covers import and export as portable JSON, which is useful for audits: you can extract a full workflow definition without any external service being involved.

    The Three Things That Do Leave Your Server

    Being honest about this matters. There are three situations where data moves outside your server when using Krom Automation:

    • Action-driven outbound calls. If a workflow sends an email, posts to Slack, writes a row to Google Sheets, or calls an external API via the HTTP Request action, that data leaves your server. That is the point of the action. The privacy question shifts from “does the plugin send data?” to “which services receive it, and do you have agreements with them?”
    • Third-party integrations. Connecting to Mailchimp, ActiveCampaign, or FluentCRM means subscriber data flows to those platforms. Self-hosting the automation layer does not change the data flow created by the action itself. It just means the automation layer is not an additional recipient.
    • AI actions, when you use them. The AI Generate Text, AI Content Moderation, and AI Auto-Tag actions send prompts to whichever provider you have configured: OpenAI, Google Gemini, or Groq. This is a deliberate opt-in. You supply your own API key. wpRigel never receives those prompts, never marks up the token cost, and you pay your AI provider directly. You can read more about the trade-offs of using your own key versus plugin-managed credits in our breakdown of AI plugin credits versus your own API key.

    The practical implication: a Krom Automation workflow that only uses internal actions (Create Post, Update User Meta, Change User Role, Add Comment) generates zero outbound data. A workflow that ends with a Mailchimp subscription call generates exactly as much outbound data as subscribing someone to Mailchimp, nothing more.

    The Gap Every Other Guide Skips: What Happens After Deployment

    Almost every self-hosting guide ends at setup. “Your data is on your server, therefore it is private.” That framing is incomplete in a way that matters.

    Owning the stack means owning every vulnerability in it. That is not an argument against self-hosting. It is an argument for taking the maintenance seriously.

    Here is what the post-deployment burden actually looks like for a self-hosted automation stack:

    • Dependency patching. WordPress core, PHP, MySQL, and every plugin in the stack need updates. A known vulnerability in an unpatched dependency can expose execution logs containing personal data. The question is not whether your data is on your server. It is whether your server is hardened against the vulnerabilities that became public last month.
    • Secret rotation. API keys stored in workflow configurations are only as safe as the database they live in. If a key is long-lived and the database is compromised, the attacker has access to whatever that key controls. Rotating keys on a schedule and scoping them to minimum permissions is maintenance work that does not happen automatically.
    • Log retention policy. Execution logs that contain personal data are themselves personal data under GDPR. A self-hosted tool that keeps every execution log forever is not more compliant just because the logs are on your server. You need a retention and deletion policy, and it needs to be enforced.
    • Server access controls. Who has SSH access to the machine? Who can read the WordPress database? Self-hosting creates a single point of control that is either a security advantage (only you) or a liability (only you, and you got phished).

    For WordPress sites, the picture is somewhat simpler than running a full Docker stack because the security surface is familiar. WordPress hosting providers handle server patching, database backups, and SSL. The automation plugin operates inside that environment rather than adding a new infrastructure layer on top of it.

    Self-Hosted vs SaaS: The Real Privacy Trade-Off

    Question Self-Hosted (e.g. Krom Automation) SaaS (e.g. Zapier, Make)
    Who holds execution logs? You, in your database The SaaS vendor, on their infrastructure
    Who holds API credentials? Your database, encrypted at rest if your host does so The SaaS vendor’s credential store
    Is the vendor a GDPR data processor? No, for the automation layer itself Yes, you need a DPA with them
    Data residency control Full, your server is wherever you choose Depends on vendor region settings
    Who is responsible for security patching? You (or your host) The SaaS vendor
    Outbound data from integrations Only what your actions explicitly send Same, but the automation layer is also a recipient
    Breach exposure if the vendor is hacked Not applicable, no vendor holds your data Yes, your workflow data is in the vendor’s breach
    Breach exposure if your server is hacked Yes, all local data including logs and keys Partial, local WordPress data only

    The table above makes the trade-off concrete. Self-hosting removes the vendor as a data processor and eliminates the risk of a vendor-side breach affecting your workflow data. It adds the responsibility of securing and maintaining your own environment.

    Neither option is unconditionally safer. They are different risk profiles.

    Can You Actually Verify a Tool Is Not Phoning Home?

    This is one of the most common practical questions, and it has a real answer. The most reliable method is network monitoring at the server level: a tool like Wireshark on a local test environment, or outbound firewall logging on a VPS, will show every connection the application makes. If you see connections to an analytics endpoint you did not configure, you have your answer.

    For WordPress plugins specifically, the plugin code is readable. Krom Automation is available on the WordPress.org plugin directory and the source is open for inspection.

    Searching the codebase for wp_remote_post, wp_remote_get, and curl_exec will surface every outbound HTTP call the plugin makes. You can do this before installing.

    A second practical check is your browser’s network tab during workflow execution. Some tools send telemetry from the admin interface rather than the server. Watching the network requests during a workflow run in the visual builder reveals any calls to external analytics services.

    GDPR Compliance: What Self-Hosting Changes and What It Does Not

    Self-hosting the automation layer helps with GDPR in specific, limited ways. It removes the automation platform from your list of data processors, which simplifies your Record of Processing Activities.

    It gives you full control over data residency, which matters if you are serving EU users and need to keep personal data in EU infrastructure. It means your execution logs, which can contain personal data from trigger payloads, never leave your jurisdiction.

    What it does not change:

    • Your obligations as the data controller. You are still responsible for what the workflows do with personal data.
    • The processor relationships created by actions. If a workflow subscribes someone to Mailchimp, Mailchimp is still a processor and you still need a DPA.
    • Retention obligations. Execution logs with personal data are subject to the same deletion requirements as any other personal data store.
    • Security obligations. Article 32 of GDPR requires “appropriate technical and organisational measures.” Self-hosting does not satisfy that by default. A poorly secured self-hosted stack is less compliant than a well-managed SaaS platform.

    Self-hosting does not make you GDPR compliant. It removes one processor from the chain. What you do with that control is still your responsibility.

    For sites running MemberPress, LearnDash, or WooCommerce with personal member or student data, the automation layer touches that data on every workflow run. Keeping that processing on-server is a meaningful data minimisation measure. It is one part of a compliance picture, not the whole picture.

    How the Webhook Architecture Affects Your Data Perimeter

    Webhooks are where self-hosted automation most commonly creates unintended data flows. An incoming webhook sends data from an external service to your server. An outgoing webhook sends data from your server to an external service.

    Both are legitimate and useful. Both move data.

    Krom Automation Pro includes an incoming webhook receiver with HMAC-SHA256 signature verification across 9 security layers. That matters because an unsecured webhook endpoint is effectively a public API for anyone who discovers the URL. Signature verification ensures only the authorised source can trigger the workflow.

    The outgoing equivalent is the HTTP Request action, which supports GET, POST, PUT, PATCH, and DELETE with JSON response parsing. Any time you use it, you are making a deliberate data transfer decision. The right practice is to map exactly which fields you are sending in each request and confirm that the receiving service has an appropriate data processing agreement in place.

    For form integrations like Gravity Forms, WPForms, or Contact Form 7, the trigger fires from a form submission that is already on your server. The data was submitted to your site. The question is where the workflow sends it next.

    Who Should Self-Host Automation, and Who Should Not

    Situation Self-Hosted Is the Right Call SaaS May Be the Better Fit
    Data residency requirements Yes, you control the server location Only if the vendor offers region locking
    Regulated personal data (health, finance) Yes, fewer processors in the chain Possible, but DPA and audit requirements are heavier
    WordPress-native triggers and actions Yes, native plugins fire on WordPress events directly Requires webhooks to bridge the gap
    Team has no capacity to maintain a server Not ideal without managed hosting Yes, vendor handles patching
    Automation between two external SaaS tools Not well suited, no WordPress event involved Yes, this is what SaaS automation is built for
    Cost at scale (high execution volume) Yes, no per-task fees SaaS pricing scales with volume, costs grow fast

    The honest answer for most WordPress sites is that self-hosted automation is the right default, and a managed WordPress hosting environment handles most of the security maintenance burden that makes pure self-hosting complicated. The risk profile of a WordPress plugin running on WP Engine or Kinsta is materially different from running a Docker stack on an unmanaged VPS.

    The Cost and Operational Picture

    SaaS automation platforms charge per task or per execution. At low volumes this is affordable.

    At the scale a growing WordPress site actually generates, say 50,000 workflow executions per month across user registrations, order completions, and form submissions, SaaS costs become significant. Zapier’s mid-tier plans start around $49 to $69 per month for 2,000 tasks, and 50,000 executions would require a substantially higher tier.

    Krom Automation Pro costs $119 per year for a single site on the Basic plan, $199 per year for 5 sites, or $369 per year for unlimited sites. There are no per-execution fees at any tier.

    A site running 200,000 workflow executions per year pays the same as one running 2,000. That pricing model is a direct consequence of the self-hosted architecture: because nothing runs on wpRigel’s infrastructure, there is no cost that scales with volume.

    The operational cost is the time spent on maintenance. For a WordPress site on managed hosting, that is largely absorbed by the host. Estimate 1 to 2 hours per month for plugin updates, log reviews, and key rotation if you are running a compliance-sensitive site.

    That is the honest number. It is not zero, and it is not 10 hours.

    Testing Workflows Without Side Effects

    One underappreciated privacy-adjacent feature is the workflow simulator. Before a workflow runs live, you can dry-run it to see exactly what it would do without executing any actions or touching any real data. That matters for privacy because it lets you audit what data each step would access and where it would send it before any real user data is involved.

    The workflow simulator documentation covers how dry runs work and what the output tells you. Pair that with the conditions and branching documentation to understand how to build workflows that only access the minimum data needed for each path.

    Also from wpRigel

    Pollify is wpRigel’s Gutenberg-native poll, survey, and quiz plugin. Polls are built as real blocks inside the WordPress editor, with no shortcodes to paste and no separate admin interface to learn. If you collect opinion data or run NPS surveys, Pollify keeps that response data inside your WordPress database by the same logic: the plugin runs on your site, not on a third-party platform.

    Commandify is a command palette for the WordPress admin. Press Cmd or Ctrl plus K from anywhere in the admin to search, navigate, and run admin actions without clicking through menus. It is the only WordPress command palette with real WooCommerce order, product, and customer commands built in.

    What We Would Do

    If you run a WordPress site that handles personal data and you are currently routing workflow executions through a SaaS platform, switching to a self-hosted option removes a data processor from your chain without adding meaningful operational complexity, provided you are already on managed WordPress hosting. That is the straightforward case.

    If you are on an unmanaged VPS with no patching cadence and no one responsible for updates, a well-run SaaS platform with a signed DPA may genuinely be the more secure option. The privacy benefit of self-hosting is real. It is also conditional on maintaining the environment correctly.

    For WordPress-native automation specifically, we recommend downloading Krom Automation free from the WordPress.org plugin directory and building your first workflow. The free version includes 16 triggers, 21 actions, and a full execution log. You can verify exactly where data goes before you connect a single external service.

    Krom Automation Pro adds 80+ additional triggers, 60+ additional actions, and 24 integrations. See the full pricing breakdown to compare the annual and lifetime options across 1, 5, and unlimited sites. Every plan carries a 14-day money-back guarantee.

    Frequently Asked Questions

    Does a self-hosted automation plugin send telemetry back to the developer?

    It depends entirely on the plugin. The only reliable way to verify is to inspect the source code for outbound HTTP calls or monitor network traffic during execution.

    Krom Automation does not send telemetry to wpRigel. The source code is available on WordPress.org for inspection before installation.

    If my server gets hacked, am I more exposed than with a SaaS tool?

    In one sense, yes: a server compromise exposes execution logs, API credentials, and workflow definitions that a SaaS tool would hold separately. In another sense, a SaaS vendor breach exposes the same data across all their customers simultaneously. Self-hosting concentrates the risk in your environment rather than sharing it with a third party’s security posture.

    Do AI actions in self-hosted automation break the privacy model?

    AI actions are an explicit opt-in exception. When you use Krom Automation’s AI Generate Text, AI Content Moderation, or AI Auto-Tag actions, the prompt is sent to the AI provider you configure: OpenAI, Google Gemini, or Groq.

    wpRigel never receives those prompts. You should treat the AI provider as a data processor and check their data processing terms before sending personal data in a prompt.

    Does self-hosting solve data residency requirements on its own?

    Self-hosting gives you full control over where the automation layer runs. If your server is in the EU and your actions do not send data outside the EU, you can satisfy EU data residency requirements for the automation layer. Actions that call US-based services, such as Mailchimp or Slack, still create cross-border transfers that need to be addressed separately.

    Is self-hosted automation realistic for a site without a developer on staff?

    For a WordPress plugin like Krom Automation, yes. The installation is identical to any other plugin, and managed WordPress hosting handles server security.

    The maintenance burden is closer to 1 to 2 hours per month for updates and log review. A full Docker-based self-hosted stack on an unmanaged server requires more technical capability and is a different situation.

    The wpRigel Team

    September 3, 2026
    User Guide
  • AI Plugin Credits vs Your Own API Key: Which Wins?

    If you are deciding between AI plugin credits vs your own API key, the short answer is this: use your own key. Bundled credits add a margin on top of what AI providers actually charge, and they cap your usage.

    Your own key pays OpenAI, Google or Groq at their published rates, with no markup and no monthly ceiling. The difference is not trivial, and this article shows exactly what it costs and what else changes when you make that choice.

    This is not a theoretical comparison. It affects how much you pay per workflow run, which models you can access, and where your data actually goes. Those three things matter regardless of whether you are a solo blogger or running a business site with thousands of automations per month.

    Krom Automation builds AI actions into its free tier with a bring-your-own-key model from day one. No credits to buy, no markup on tokens, and no paywall between you and the AI actions. Browse the full feature list to see what that includes in practice.

    Quick Summary

    • Bundled credits are convenient to start but mark up tokens, cap usage, and limit model choice.
    • Your own API key pays provider rates directly, no markup, no cap, no middleman.
    • Cost difference is real: a plugin selling 1,000 AI credits at $10 may be charging 3x to 10x what the underlying API call costs.
    • Data and privacy differ significantly between the two models, and that gap is almost never discussed.
    • Your ChatGPT Plus or Claude Pro subscription does not cover API usage. Those are separate billing systems.
    • BYOK (bring your own key) is not just for developers. Modern plugins make setup a five-minute task.

    What Bundled Credits Actually Are

    When a plugin sells you AI credits, it is buying API access from a provider at wholesale rates, then reselling that access to you at a higher price. The plugin vendor becomes a middleman between you and OpenAI, Google Gemini or whichever model powers the feature. That margin covers their infrastructure, support, and profit.

    The markup varies, but it is almost never disclosed. A credit pack priced at $10 for 1,000 credits might represent API calls that cost the vendor $1.50 to $3.00 at provider rates. You are paying 3x to 7x the actual cost for the convenience of not setting up a key yourself.

    Buying bundled AI credits is like paying a currency exchange booth at the airport. The rate exists, it is just not the real rate.

    Credits also expire or cap out. If you hit your monthly allowance mid-workflow, your automations stop until you top up. That is a meaningful operational risk for any site where AI actions are part of a live customer-facing process.

    What Your Own API Key Actually Does

    When you supply your own API key, the plugin sends requests directly to the AI provider using your credentials. You are billed by the provider at their published per-token rates. There is no middleman, no markup, and no monthly credit ceiling.

    As a concrete example: GPT-4o Mini via OpenAI’s API costs roughly $0.15 per million input tokens and $0.60 per million output tokens as of 2026. A typical WordPress automation prompt, generating a product description or moderating a comment, uses somewhere between 200 and 800 tokens.

    That puts the cost of a single AI action well under $0.001. Running 10,000 of those in a month costs under $10 at provider rates, before any markup.

    Your spend scales with actual usage. Low-traffic months cost almost nothing.

    High-volume months cost proportionally more. There are no overages because you are paying per token, not per credit block.

    Does Your ChatGPT Plus Subscription Cover This?

    No, and this is one of the most common misunderstandings. ChatGPT Plus is a consumer product subscription. It gives you access to the ChatGPT web interface and app at a fixed monthly fee. It does not give you API access.

    API access is a completely separate billing system. You create an API key in your OpenAI developer account, add a payment method, and you are billed per token based on your usage. The same separation applies to Anthropic (Claude), Google Gemini, and every other major provider.

    • ChatGPT Plus ($20/month): consumer chat interface, no API access included
    • OpenAI API: separate account, pay per token, no subscription required
    • Claude Pro: consumer interface, no API access included
    • Anthropic API: separate account, pay per token
    • Google Gemini Advanced: consumer interface, no plugin API access included
    • Google AI Studio / Gemini API: separate account, pay per token

    If a plugin tells you to “connect your ChatGPT subscription,” read the documentation carefully. It almost certainly means your API key, not your Plus login.

    The Models You Can Actually Access

    Bundled credit systems often run on a single model, usually whichever is cheapest for the vendor to operate at scale. You get no choice. When a better model releases, you wait for the vendor to update their system, then potentially pay more credits per call.

    With your own key, you choose the model per workflow or per action. Krom Automation supports seven models across three providers in the free version.

    Provider Models Available Best for
    OpenAI GPT-4o Mini, GPT-4o General text generation, content moderation
    Google Gemini Gemini 2.0 Flash, Gemini 2.5 Flash Preview, Gemini 2.5 Pro Preview Long context tasks, document processing
    Groq Llama 3.3 70B, Llama 3.1 8B Speed-sensitive workflows, high-volume tagging

    Choosing the right model for each task is not academic. Groq’s Llama 3.1 8B is dramatically faster and cheaper than GPT-4o for a simple tagging job.

    GPT-4o handles nuanced content moderation better than a smaller model. With your own key, you match the model to the task instead of accepting whatever the vendor chose.

    Letting a vendor pick your AI model is like letting a restaurant pick your meal. They will pick whatever keeps their costs down.

    The Cost Comparison Over Time

    The setup cost of BYOK is real but one-time. Creating an API account, adding a payment method, and pasting a key into a plugin settings page takes about 5 minutes. After that, the ongoing economics strongly favour your own key.

    Scenario Bundled Credits (estimated) Own API Key (estimated) Monthly difference
    500 AI actions/month (small blog) $5 to $15 $0.50 to $2 Save $4 to $13/month
    5,000 AI actions/month (active store) $40 to $80 $3 to $8 Save $35 to $70/month
    50,000 AI actions/month (agency or SaaS) $300 to $600+ $20 to $60 Save $250 to $550/month

    These are estimates using published token costs and typical credit pack pricing from 2026. Your actual figures will vary by model, prompt length and vendor. The direction does not change: at every usage tier, your own key costs less, often by a factor of 5 to 10.

    What Happens to Your Data: The Question Nobody Asks

    This is the gap in almost every comparison article about AI plugin credits vs your own API key, so we are covering it directly. The data routing is fundamentally different between the two models, and it matters for business sites.

    With bundled credits: your prompt, your content, and any data you pass into the AI action travel to the plugin vendor’s server first. The vendor proxies the request to the AI provider.

    That means the vendor can see every prompt you send, log it, and is responsible for securing it. You are trusting the plugin vendor’s infrastructure, their logging policy, and their data handling practices, none of which are typically disclosed in plugin marketing pages.

    With your own API key: the request goes from your WordPress server directly to the AI provider. The plugin vendor never sees the prompt content.

    Your API key credentials are stored in your own database, not on the vendor’s servers. You are only trusting the AI provider’s handling, which is covered by their published API terms and privacy policies.

    • What the vendor can see with bundled credits: every prompt, every response, usage patterns, content being processed
    • What the vendor can see with your own key: that you made an API call, not what it contained
    • Where your key is stored with bundled credits: the vendor holds the API key, not you
    • Where your key is stored with BYOK: your own WordPress database, encrypted

    For sites handling customer data, personally identifiable information, or proprietary content, the BYOK model is meaningfully more private. The AI provider’s data handling is a known quantity governed by published terms. The vendor’s logging behaviour usually is not.

    Is It Safe to Paste Your API Key into a Plugin?

    The honest answer is: it depends on the plugin. Entering your API key into any third-party tool creates risk if that tool is poorly secured. A few things to check before you paste a key anywhere.

    • Is the plugin well maintained? Check the WordPress.org listing for recent updates, active install count, and support response rate.
    • Does the plugin store your key encrypted? Reputable plugins encrypt API keys at rest in the database rather than storing them as plain text.
    • Does the plugin use your key server-side only? Your key should never appear in frontend page source or browser requests. If it does, any visitor to your site can steal it.
    • Can you set usage limits on the key? OpenAI, Google and Groq all allow you to set monthly spend caps and restrict keys to specific API endpoints. Use those controls.
    • Can you rotate or revoke the key instantly? Generate a dedicated key for your WordPress plugin and nothing else. That way you can revoke it without affecting other systems.

    Krom Automation stores keys server-side only and never exposes them to the browser. The AI actions reference covers exactly how that works. If you want to understand what the plugin does before connecting anything, the introduction to how Krom Automation works is the right place to start.

    When Bundled Credits Are the Right Choice

    We should be honest about this. Bundled credits do have a use case.

    If you are testing an AI feature for the first time and you do not want to create a separate API account just to try something, credits lower the barrier to getting started. The friction of creating an API account, finding the key management section, setting a spend cap, and pasting the key is real, even if it only takes five minutes.

    • Testing AI features before committing to a tool
    • Very low-volume use where the markup is trivially small in absolute dollars
    • Situations where you want a single invoice from one vendor covering everything
    • Platforms where the bundled model is genuinely well-matched to the task

    For any site running more than a few hundred AI actions per month, the economics of credits deteriorate fast. At 5,000 actions per month, the markup can cost more than many premium plugin subscriptions. That is the point where switching to your own key saves real money.

    How Krom Automation Handles AI Actions

    Krom Automation includes three AI actions in the free version: AI Generate Text, AI Content Moderation, and AI Auto-Tag. All three are available without any credit purchase and without unlocking a paid tier.

    You connect your own API key from OpenAI, Google Gemini or Groq in the plugin settings. From that point on, every AI action in every workflow uses your key and bills your account directly. Krom Automation never charges per AI call, never adds a markup, and never holds a pool of credits that can run out mid-month.

    Those AI actions slot into any workflow on the drag-and-drop canvas alongside the conditional branching and delay scheduling tools. So you can, for example, run a content moderation check on every new comment, branch on the result, and either approve or flag the comment for review, all without writing a line of code.

    If you want to understand the practical applications of AI inside WordPress automation more broadly, our article on what AI WordPress automation actually does and does not do covers that territory honestly.

    An AI action that costs $0.0008 to run should not cost $0.05 because a vendor decided to sit in the middle.

    What You Pay Krom Automation vs What You Pay for AI

    This is a question worth answering directly: if you bring your own key, do you still pay for the plugin?

    Yes, the plugin itself has a free tier and a Pro tier. The AI actions are included in the free tier at no charge. What you pay the AI provider is completely separate from what you pay (or do not pay) for the plugin.

    What you are paying for Who you pay What it covers
    The automation plugin (free tier) Nobody 16 triggers, 21 actions, 3 AI actions, visual builder
    The automation plugin (Pro) wpRigel, from $119/year for 1 site 80+ additional triggers, 60+ additional actions, 24 integrations
    AI API usage OpenAI / Google / Groq directly The actual AI calls your workflows make

    The two costs do not interact. A free plugin user with their own OpenAI key pays only for the tokens they use.

    A Pro user pays for the plugin licence plus their tokens. Neither pays Krom Automation for AI credits, because there are none to buy.

    You can download Krom Automation free from the WordPress.org plugin directory and connect your own API key without spending anything on the plugin itself. See how to install Krom Automation for the full setup walkthrough.

    Practical Setup: Getting Your Own API Key in Five Minutes

    The friction argument against BYOK is mostly overstated. Here is what the process actually looks like for OpenAI, which is the most common starting point.

    1. Go to platform.openai.com and create an account (separate from ChatGPT.com)
    2. Add a payment method and set a monthly spend limit, $5 or $10 is more than enough for most WordPress sites to start
    3. Navigate to the API keys section and click “Create new secret key”
    4. Copy the key and paste it into the Krom Automation settings page
    5. Run a test workflow using the workflow simulator to confirm it is working before enabling live execution

    The Google Gemini API and Groq API follow the same pattern with their respective developer consoles. The process is identical in structure. Once the key is in place, you forget it exists and your workflows run at provider rates automatically.

    Also from wpRigel

    Pollify is our Gutenberg-native poll, survey and quiz plugin. Polls are built as real blocks inside the block editor, so there are no shortcodes to paste and no separate interface to learn. It fits into the writing flow rather than interrupting it.

    Commandify is a command palette for the WordPress admin. Press Cmd or Ctrl plus K to jump anywhere, search everything, and run admin actions without clicking through menus. It is the only WordPress command palette with genuine WooCommerce depth, covering orders, products and customers as first-class commands.

    FAQ

    Is using my own API key actually cheaper than plugin credits?

    In almost every case, yes. At typical usage volumes, provider rates are 3x to 10x cheaper than what credit-based plugins charge per call. The gap widens at higher volumes because the markup is per-token, so it compounds.

    What if I run out of API credits with my own key?

    You set a monthly spend cap in your API provider account, for example $10 or $20. Once you hit that cap the provider stops accepting requests until the next billing cycle.

    This is controllable and predictable. With bundled credits you run out of a fixed allowance and must purchase more manually.

    Does BYOK mean my WordPress site has to handle the API calls directly?

    Yes. Your WordPress server makes the API request to the AI provider.

    That requires your server to be able to make outbound HTTP requests, which is standard on any modern hosting environment. The AI actions in the free version use this approach, and the HTTP Request action supports GET, POST, PUT, PATCH and DELETE.

    Can I switch models mid-workflow or use different models for different actions?

    With your own key, yes. You choose the model at the action level.

    A single workflow can use GPT-4o Mini for a fast tagging task and GPT-4o for a detailed content moderation check. Credit systems typically lock you to one model across everything.

    What should I do if my API key is compromised?

    Revoke it immediately in your provider’s developer dashboard. Generate a new key, paste it into the plugin settings, and check your usage logs for unexpected spend. This is why keeping your plugin API key separate from any other key you use is important: one compromised key does not cascade to other systems.

    The Verdict

    For any site running AI-powered automation beyond a handful of test calls, your own API key wins on cost, model choice, and data privacy. The setup takes under five minutes.

    The savings start immediately and compound with volume. The privacy benefit is structural: your prompts never touch the plugin vendor’s servers.

    Bundled credits are a reasonable starting point if you want zero friction for a quick test. They are not a good long-term choice for anything running at meaningful volume, and they are never the right choice if you care about who can see the content your automations are processing.

    See Krom Automation pricing, including the free tier that includes all three AI actions with your own key and no credits required.

    The wpRigel Team

    September 2, 2026
    User Guide
Previous Page
1 2 3 4 5 … 15
Next Page
wprigel logo

wpRigel builds innovative WordPress plugins for developers, marketers and agencies. Be with us, get more users for your business and increase conversion using our powerful tools.

  • x.com icon
  • linkedin icon

Products

  • Pollify
  • Commandify
  • Krom Automation (Now Live 🎉)

Company

  • Affiliate Program
  • About Us
  • Contact Us
  • Privacy Policy

Resources

  • Docs
  • Blog
  • Support Area
  • Refund policy

Comparisons

  • Commandify vs CommandUI
  • Pollify vs CrowdSignal
  • Krom Automation vs others

Changelogs

  • Commandify Changelog
  • Pollify Changelog
  • Krom Automation Pro Changelog

wpRigel 2026. All Rights Reserved

  • Terms of use
  • Privacy Policy
  • Cookie Policy