What it does
Clicking How to fix on a finding opens a drawer with four plain-language sections: What this is (the vulnerability class, affected versions, and what an attacker needs), Recommended fix (an update path that closes every open finding for that component, or mitigations if no fix has been released yet), Verify (re-run the scan and see the finding move to Resolved), and If you're stuck — Ask AI, or contact WPClientHub support with the finding pre-filled.
Ask AI sends the finding, the site's latest snapshot, and (when paired) live connector diagnostics to the same AI pipeline that powers Help Desk ticket diagnosis, under a purpose built specifically for security findings. It answers whether the finding is likely exploitable on this site, why, the risk of leaving it, concrete fix steps, mitigations, and a confidence score.
How to
- Open a finding's How to fix drawer.
- If the recommended fix and mitigations are enough, follow them — the drawer links straight to the Updates tab when an update is the fix.
- If you need more, click Ask AI — the cost in credits is shown before it runs.
- Read the assessment under "AI assessment", including its confidence and how many credits it used and how many remain this month.
- Click the drawer's re-run-scan action after applying a fix to confirm the finding moves to Resolved.
Limits & defaults
| Setting | Default |
|---|---|
| Ask AI cost | 1 AI credit per run (batch runs cost 1 credit per finding) |
| Rate limit | 3 Ask AI runs per finding per day |
| Low confidence | Below 0.5 confidence, the answer is shown as "needs a person" alongside a Contact support option, rather than a guess |
| Out of credits | The button is disabled with "Out of credits — top up or upgrade" instead of silently failing — see AI credits |