// docs / plans, security and data //
The WordPress plugin: install, connect and Safe Updates
The MyKavo WordPress plugin brings a site's monitoring into wp-admin and adds Safe Updates: when WordPress updates a plugin, theme, translation or itself, or a plugin is activated or deactivated, MyKavo checks the site straight away and names the update on every change it finds. It is free on every plan; automatic checks need Pro or Agency. It adds nothing to the pages visitors load.
Last updated: September 20, 2026
Download the plugin
Download the zip from mykavo.app/wordpress-plugin. Once the plugin is listed in the WordPress.org directory you can also search for MyKavo under Plugins > Add New.
Upload and activate it
In WordPress go to Plugins > Add New > Upload Plugin, choose the zip, install it and activate it. You need to be an administrator.
Connect
Open MyKavo in the admin menu and press Connect to MyKavo. Sign in, or create a free account, choose which MyKavo website this site is, and approve. If the site is not in MyKavo yet, the approval screen offers to add it first.
Check Safe Updates is on
Open the Safe Updates tab. The switch is on by default. From now on every update is listed there with a verdict.
What Safe Updates checks
- Plugin, theme, WordPress and translation updates, whether you pressed Update or WordPress updated automatically.
- A plugin being activated or deactivated, and the active theme being switched.
- Several updates in one go (a bulk update, or the nightly automatic run) are reported once, as one check.
When the update finishes the plugin tells MyKavo what changed, with the old and new versions, and MyKavo runs a deploy check: every monitored page is compared with its approved baseline. The result appears in the Safe Updates tab as "Verified - nothing changed" or "3 changes found after this update", and every change found is labelled with the update it appeared after. The same verdict goes to your email and chat alerts if you use them.
Other things the plugin adds
- The MyKavo screen: status, uptime, response time and SSL, changes with before-and-after screenshots, one-click approve, fixed or ignore, scan history and monitored pages.
- A "Monitor with MyKavo" link under every published page and post, and an address box on the Pages tab.
- With WooCommerce active, a store guard that shows whether Shop, Cart, Checkout and My account are monitored and adds the missing ones.
- A warning on the Plugins screen for a plugin whose last update changed the site.
- A MyKavo test in Tools > Site Health and a MyKavo section in its Info tab.
- WP-CLI commands: wp mykavo status, changes, scan --wait, monitor, updates, safe-updates and disconnect.
Performance and privacy
The plugin adds nothing to the pages visitors load: no scripts, styles, database queries or remote requests, no autoloaded options and no cron jobs. It sends MyKavo only the site's address when connecting, the names and versions of what was updated or switched on or off, the addresses of pages you choose to monitor, and the actions you take on the MyKavo screen. Nothing about visitors is sent. The connection key stays on your server and works for that one website only.
Disconnecting
Disconnect from the MyKavo screen's menu, from Settings > WordPress sites in the MyKavo dashboard, or by deleting the website in MyKavo. Deleting the plugin removes everything it stored on the site. Monitoring in your MyKavo account is not affected.
Frequently asked questions
Does the plugin slow WordPress down?
No. Nothing runs on the pages visitors load. The plugin works inside wp-admin and right after an update, and scanning happens on MyKavo's servers.
Which WordPress and PHP versions are supported?
WordPress 6.2 or newer, tested up to 7.1, on PHP 7.4 or newer.