Novamira HQ in beta: all your WordPress sites, one connection for your AI. Get it free →

Disabling Novamira

A common question: if I disable Novamira for security reasons, do the changes my AI made stop working? The answer depends on where the AI wrote things.

AI-generated code in the Novamira sandbox

If the AI wrote code into Novamira’s sandbox (wp-content/novamira-sandbox/), you can keep the plugin active in production with the AI abilities switched off.

The sandbox will keep loading that code, but no AI agent can reach WordPress anymore. This is the recommended pattern: build with AI on staging, deploy to production with abilities off.

AI abilities are tied to the site URL

AI abilities are bound to the specific site URL, not to the installation itself. So if you develop on staging and push to production, the abilities automatically stay off on the production URL until you explicitly turn them on there.

Migrations don’t carry AI access with them. This is a deliberate safety net: cloning a site never leaks AI connectivity to a new environment.

Direct writes to WordPress

If the AI wrote things directly into WordPress (posts, pages, database rows, theme files, installed plugins, options), those persist regardless of Novamira’s state. Disabling the plugin does not roll back any of those changes.

This is standard WordPress behavior: Novamira is a conduit for changes, not a layer that owns them. Once data is in the database or files are on disk, they belong to WordPress.

Before you deactivate: the review page

Available from Novamira 1.11.3, refined in 1.11.4. When you deactivate Novamira, a review page first shows what is at stake and lets you decide:

  • Sandbox files powering the site. If code in the sandbox may be running real site functionality, Novamira warns you and gives you a copyable prompt to paste into your connected AI client, so it moves that code into a normal plugin or the theme before the sandbox stops loading.
  • Stored data. The page lists your Novamira Pro memories, the skills you added, and your Novamira Chat sessions, and lets you choose, per type, whether to preserve them or permanently delete them when the plugin is removed.
  • Credentials on uninstall. You can choose whether uninstalling should remove OAuth data and revoke Novamira Application Passwords across all users.

What to disable, and when

  • Turning off AI abilities (Novamira > Configuration) keeps the plugin active but closes the MCP server. Sandbox code keeps loading. Safe for production.
  • Deactivating the plugin entirely stops the sandbox from loading too. Any code the AI wrote there will no longer run.
  • Uninstalling removes the plugin files. Your stored data (Pro memories, added skills, Chat sessions) and credentials (OAuth data, Application Passwords) follow the choices you made on the review page above. The sandbox directory (wp-content/novamira-sandbox/) is left on disk and must be deleted manually if you want it gone. Database content and changes made directly to WordPress also remain.