Changelog

What is new in SudoWhizzy

New tools, playbooks and safety improvements, newest first.

New tool

Move a site to another server

Ask your AI to move a shop or site between two of your servers. transfer copies folders directly from one server to the other over SSH, with a temporary key that only allows reading that folder and expires within 24 hours; nothing passes through SudoWhizzy. db_dump dumps a site's database with its own credentials, so the password never reaches the chat. The new migrate playbook does a first copy while the site stays live, a short maintenance window for the final catch-up, tests before the DNS change and keeps the old server as the way back. Try the prompt in the Prompt Library.

Improvement

Fewer approvals, and approving on the spot

Approval is now only asked for what is hard to undo: deleting your own folders or files, dropping or emptying database data, database users, reboots, SSH, sudo and firewall changes, switching off security checks, wiping disks and uninstalling a shop. Routine work runs straight away and is logged: clearing caches and generated code, creating admin users, ordinary database updates, removing packages and rollbacks. When something does need you, a card pops up on every page of your dashboard to approve or deny it, and the browser tab shows how many are waiting.

Security

Two-step sign-in with an authenticator app

Turn it on under Security: scan a QR code with Google Authenticator, 1Password, Authy or any authenticator app, and signing in will ask for a 6-digit code after the email link or Google. Ten recovery codes cover a lost phone, and you get an email whenever it is turned on or off or a recovery code is used.

Improvement

A Free plan

Every account now starts on Free: one server, read-only, 50 tool calls a day, with the daily health check and alerts. Your AI can look, read logs and config files and explain what is wrong. Starter adds changes, approvals, snapshots and the Magento, WordPress and database tools; Pro adds the malware scan and site checks every 15 minutes. After a plan change, reconnect SudoWhizzy in your AI client so it loads the new tools; the dashboard reminds you until it has.

New tool

Health checks, alerts and a Monday report

SudoWhizzy now checks every server daily and its sites every 15 minutes. You get an email when a server stops checking in, a site stops answering, a disk is over 90% full, a certificate is about to expire, a service fails or Magento cron stops, and again when it is fixed. A Monday report sums up the week. Ask your AI for health_report any time, and choose your emails under Notifications.

New tool

Tools for existing Magento and WordPress sites

list_sites finds the shops and sites on a server. db_query runs SQL with the site's own credentials, so your database password never reaches the chat; reads run read-only and writes need your approval. magento and wp run bin/magento and wp-cli as the site's owner. malware_scan looks for backdoors, skimmers in the database, disguised PHP and suspicious cron entries.

New playbook

Site check-up and hacked-site cleanup

Two new playbooks guide your AI through a full review of an existing site, and through cleaning a compromised one: evidence first, then containment, cleaning, and changing every credential.

Improvement

Long jobs run in the background

Installs, compiles, imports and scans now run as background jobs that keep going after your AI's call returns. Your AI follows them with job_output, so long work no longer times out.

Security

Signed agent updates

The agent on your server now updates itself, only when idle, after checking a digital signature and checksum, and only after the new version proves it starts. The previous version is kept.

New playbook

Playbooks for fresh servers

Your AI can follow step-by-step guides for a fresh server, Magento (Mage-OS or Magento Open Source), WordPress, hardening and backups. Use them from the Prompt Library or just ask; your AI fetches the right one.

Security

Approvals, modes and snapshots

Every action is sorted by risk. Destructive ones wait for your approval in the dashboard, which only you can give. Each server can be read-only, normal or full trust, and snapshots with rollback let you undo changes.