Launch offer: 3-day trial for $1, then $39/mo. Cancel anytime.

Connect WordPress to LazySEO

LazySEO publishes to WordPress through the WordPress REST API, signing in with your username and an application password. Application passwords are built into WordPress (since version 5.6), so you do not need a plugin.

Last reviewed October 1, 2026.

Before you start

  • A WordPress site that loads over https://. WordPress only offers application passwords on sites served over HTTPS.
  • A WordPress user that can publish posts and upload images: the Author, Editor or Administrator role. Contributor and Subscriber accounts cannot publish, and the connection test tells you so. Pick Editor (or Administrator) if you want LazySEO to create new tags; an Author can only use tags that already exist. A dedicated user (for example "LazySEO", role Editor) makes it easy to see and revoke what LazySEO posts.
  • The WordPress REST API, which is on by default. Any permalink setting works, including Plain: LazySEO then uses the ?rest_route= form of the API address.

Step by step

  1. 1Create an application password in WordPress

    • Log in to your WordPress admin as the user LazySEO should publish as.
    • Go to Users → Profile (or Users → All Users and edit that user).
    • Scroll down to Application Passwords.
    • In New Application Password Name, type LazySEO and click Add New Application Password.
    • Copy the password WordPress shows (24 characters in groups of four, like abcd efgh ijkl mnop qrst uvwx). WordPress shows it only once. The spaces are fine to keep.
  2. 2Open the integration form in LazySEO

    • Open your project in LazySEO.
    • In the left sidebar, under Settings, click Integrations.
    • Click Add Integration.
    • In the window that says "Choose the type of integration you want to add.", click WordPress.
  3. 3Save the integration

    Fill in the fields as described in the table below, leave Enabled switched on (disabled integrations are skipped during publish) and click Add integration.

Fill in the LazySEO form

Labels below match the WordPress form in LazySEO. Fields marked required must be filled in before you can save.

Namerequired

Any name that helps you recognise this connection. Only shown inside LazySEO.

Example: Company blog (WordPress)

Site URLrequired

The address of your WordPress site, including https:// (or http://). Paste it the way you see it in the browser: LazySEO follows redirects (http to https, with or without www) and removes a /wp-admin or /wp-json ending if you include one. The form reminds you to remove those endings, but you can still save. A trailing slash is fine. If WordPress is installed in a subfolder, include the subfolder.

Example: https://www.example.com (or https://www.example.com/blog)

Usernamerequired

The WordPress username (the login name) of the user who owns the application password. Not the display name.

Example: lazyseo

Application Passwordrequired

The application password you just created. Not the password you log in with.

Example: abcd efgh ijkl mnop qrst uvwx

Enabled

Leave on. When it is off, LazySEO skips this integration when publishing.

Test the connection

  • Right after you save, the window shows Test the connection: click Run quick test. You can test again at any time from the integration card with Test.
  • Quick test ("Check endpoint is reachable") is read-only: LazySEO finds your site's REST API, signs in with the username and application password, and checks that the user can write and publish posts (the edit_posts and publish_posts capabilities). A Contributor or Subscriber account fails with a reason that says so. Nothing is created.
  • On the card's Test menu, Full test ("Send a test blog post (draft)") sends a real test article titled "[TEST] LazySEO Test Article" with the slug lazyseo-test-article. In WordPress it is created as a Draft post, so it is not visible to visitors. Delete it from Posts once you have checked it.
  • If a test fails, LazySEO shows the reason it got from your platform (for example a rejected key or a missing permission). Check it against the troubleshooting section below, click Edit on the card to fix the field, and test again.

What gets published

WhatHow LazySEO handles it
TitleThe article title becomes the post title.
ContentThe full article body as HTML. LazySEO converts the article's Markdown to HTML (headings, lists, links, tables, code), sends articles you edited in the LazySEO editor as the HTML you saved, and drops a first heading that only repeats the title, because WordPress shows the title itself.
SlugThe article slug is used as the post slug (the end of the URL).
StatusPublished immediately (WordPress status "publish"). The Full test creates a draft instead.
ExcerptThe meta description is saved as the WordPress post excerpt. LazySEO does not write to SEO plugin fields such as Yoast or Rank Math.
TagsThe article topics become WordPress tags. LazySEO uses the existing tag when there is one, and creates missing tags if the user can manage tags (Editor or Administrator). With an Author account, missing tags are skipped and the post is still published; Sync History lists the skipped tags in the publish's response.
Featured imageThe article banner is uploaded to your Media Library and set as the featured image. If that upload fails, the post is still published without a featured image, and Sync History shows why. The image is uploaded again each time the article is republished.
CategoryLazySEO does not choose a category, so WordPress uses your default category.
Post URLLazySEO saves the link WordPress returns as the article's published URL.
UpdatesIf the same article is published again to the same integration, LazySEO updates the existing post instead of creating a second one. If the post was deleted in WordPress in the meantime, LazySEO publishes it again as a new post.
UnpublishingUnpublishing an article inside LazySEO does not remove it from your site. Delete or unpublish the post in your platform if you need it gone.

Troubleshooting

There is no "Application Passwords" section on the profile page.

Your site is probably not served over HTTPS, or a security plugin has turned application passwords off. Enable HTTPS (most hosts offer free SSL) or check your security plugin settings (for example Wordfence: "Disable WordPress application passwords").

Test fails, or publishing fails with HTTP 401 (for example rest_not_logged_in, incorrect_password or application_passwords_disabled).

Check the Username and that Application Password is the application password, not your login password. application_passwords_disabled means a security plugin has turned application passwords off. If the details are right and you see rest_not_logged_in, your host or a security plugin may be stripping the Authorization header. Ask your host to pass the Authorization header through to PHP, and allow REST API access in your security plugin.

The test says the user "can't write posts" or "can only submit posts for review".

The WordPress user is a Subscriber or a Contributor. Give it the Author, Editor or Administrator role (Users → All Users → edit the user → Role), or use an application password from a user that has one of those roles.

Publishing fails with HTTP 403 (for example rest_cannot_create or rest_cannot_publish).

The WordPress user is not allowed to publish posts or upload files. Give it the Author, Editor or Administrator role.

The test says "No WordPress REST API found" (it checked /wp-json and ?rest_route=/).

Check that Site URL is the address of your WordPress site (with the subfolder, if WordPress is installed in one). If it is, a security plugin or firewall is blocking the REST API: allow access to it in the plugin settings.

Publishing fails with HTTP 404 rest_no_route.

The posts endpoint is missing, usually because a plugin has disabled the REST API or the posts route. Re-enable it in that plugin.

The error says "WordPress redirected the request".

Your site sent LazySEO to another address. Set Site URL to the address the redirect points to (the one shown in the error).

The error shows an HTML page from Cloudflare, a firewall or "Access denied".

A firewall is blocking server-to-server requests. Allow requests to the REST API on your site (/wp-json/, or ?rest_route= with Plain permalinks), for example with a WAF rule or an allowlist in your security plugin.

The post was published but has no featured image.

The image upload to your Media Library failed (upload permission, file size limit or a security plugin). The reason is shown in the publish's response under Sync History. The rest of the post was published normally; you can add the image by hand.

Some topics are missing from the post's tags.

The WordPress user is an Author, so it can only use tags that already exist. Create those tags in Posts → Tags, or give the user the Editor role so LazySEO can create them.

The Media Library has several copies of the same banner image.

Each publish uploads the banner again, including when an article is republished to update it. You can delete the older copies that no post uses.

Frequently asked questions

Do I need to install a WordPress plugin for LazySEO?

No. LazySEO uses the REST API and application passwords that are built into WordPress 5.6 and later.

Does it work with Plain permalinks?

Yes. When the /wp-json/ address is not available, LazySEO uses the ?rest_route= form of the REST API, which works with every permalink setting.

What happens if I delete a LazySEO post in WordPress and publish the article again?

LazySEO notices that the post no longer exists and creates it again as a new post.

Does it work with WooCommerce stores?

Yes. WooCommerce runs on WordPress, so articles are published as normal WordPress blog posts on the same site.

Can I revoke LazySEO's access later?

Yes. In WordPress go to Users → Profile → Application Passwords and click Revoke next to the LazySEO password. LazySEO can no longer publish until you add a new one.

Still stuck?

Email support@lazyseo.io with the error message from LazySEO and we'll help you connect.