[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5RmTPY25hrf2VbpBuR_x9EZRdMR4GQj8lUf2n1JslqE":3},{"slug":4,"display_name":5,"profile_url":6,"plugin_count":7,"total_installs":8,"avg_security_score":9,"avg_patch_time_days":10,"trust_score":11,"computed_at":12,"plugins":13},"bytecorestack","ByteCore Stack","https:\u002F\u002Fprofiles.wordpress.org\u002Fbytecorestack\u002F",2,20,100,30,94,"2026-08-24T09:51:26.137Z",[14,36],{"slug":15,"name":16,"version":17,"author":4,"author_profile":6,"description":18,"short_description":19,"active_installs":8,"downloaded":20,"rating":21,"num_ratings":21,"last_updated":22,"tested_up_to":23,"requires_at_least":24,"requires_php":25,"tags":26,"homepage":32,"download_link":33,"security_score":9,"vuln_count":21,"unpatched_count":21,"last_vuln_date":34,"fetched_at":35},"bcs-mcp-manager","AI Connector – MCP for Claude, ChatGPT, Gemini & More","1.0.0","\u003Cp>\u003Cstrong>AI Connector\u003C\u002Fstrong> turns your website into a working \u003Ca href=\"https:\u002F\u002Fmodelcontextprotocol.io\u002F\" rel=\"nofollow ugc\">Model Context Protocol (MCP)\u003C\u002Fa> endpoint — the open standard that lets AI assistants like \u003Cstrong>Claude\u003C\u002Fstrong>, \u003Cstrong>ChatGPT\u003C\u002Fstrong>, and \u003Cstrong>Gemini\u003C\u002Fstrong> connect directly to WordPress and take real action instead of just talking about it.\u003C\u002Fp>\n\u003Cp>Think of AI Connector as the missing bridge between AI and WordPress. Instead of copying an answer out of a chat window and pasting it into wp-admin by hand, your AI assistant becomes an AI agent working inside your site: it reads real data, writes real content, and makes real changes through a secure, permission-checked WordPress integration.\u003C\u002Fp>\n\u003Cp>As a WordPress AI plugin, AI Connector gives any MCP-compatible AI assistant structured, authenticated access to your site’s actual content and workflows — no scraping, no guessing, no manual data exports. Once connected, your AI agent can draft and publish posts, manage WooCommerce orders, fix SEO metadata, moderate comments, update Elementor pages, and call on \u003Cstrong>150+ WordPress AI tools\u003C\u002Fstrong>, each one checked against the connecting user’s real WordPress capabilities and recorded in an Activity Log you control.\u003C\u002Fp>\n\u003Cp>This is what WordPress automation looks like when it runs on an open protocol instead of a proprietary one: no vendor lock-in, no third-party cloud service relaying your data, and no static API key to manage by hand. Your AI assistant authenticates directly with your site over \u003Cstrong>OAuth 2.0 with PKCE\u003C\u002Fstrong> — the same authorization flow used by Google, Microsoft, and Slack — and every action it takes is capability-checked, logged, and fully reversible from \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Reset OAuth State\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>Whether you think of it as an AI integration, an AI workflow tool, or simply the fastest way to connect an AI assistant to WordPress, AI Connector is built to be the MCP server for WordPress you set up once and keep using.\u003C\u002Fp>\n\u003Ch4>Links\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fbytecorestack.com\u002Fplugins\u002Fai-connector\u002F\" rel=\"nofollow ugc\">Plugin homepage\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fbcs-mcp-manager\u002F\" rel=\"ugc\">Support forum\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmodelcontextprotocol.io\u002F\" rel=\"nofollow ugc\">Model Context Protocol specification\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why WordPress Sites Need an AI Automation Plugin\u003C\u002Fh4>\n\u003Cp>Without MCP, “AI help” for WordPress usually means: you open a chat window, describe what you want, copy the AI’s answer, switch back to wp-admin, and paste it in by hand. That works for a single blog post. It breaks down completely for anything involving real data — bulk SEO fixes, order refunds, comment moderation, or multi-step content workflows.\u003C\u002Fp>\n\u003Cp>MCP removes the copy-paste step entirely. Your AI assistant gets a structured, authenticated, capability-aware connection to your actual WordPress install, so it can query real data and make real changes — the same way it already works with your file system or terminal in tools like Claude Code, just pointed at your website instead. That’s the difference between an AI chatbot and genuine WordPress AI automation.\u003C\u002Fp>\n\u003Ch4>What Can an AI Agent Do With WordPress?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>“Draft and publish a blog post about [topic], generate a featured image, and tag it correctly.”\u003C\u002Fli>\n\u003Cli>“Show me yesterday’s WooCommerce orders over $100 and refund order #1042.”\u003C\u002Fli>\n\u003Cli>“Find every page with a missing or duplicate SEO title and fix it.”\u003C\u002Fli>\n\u003Cli>“Approve all pending comments from logged-in customers, spam the rest.”\u003C\u002Fli>\n\u003Cli>“Duplicate this Elementor page, swap the hero image, and update the headline.”\u003C\u002Fli>\n\u003Cli>“Create a new menu item for the spring sale and add it to the primary navigation.”\u003C\u002Fli>\n\u003Cli>“List my WooCommerce coupons expiring this month and extend them by two weeks.”\u003C\u002Fli>\n\u003Cli>“Pull this week’s Gravity Forms entries into a summary table.”\u003C\u002Fli>\n\u003Cli>“Restore the homepage to the revision from before my last edit.”\u003C\u002Fli>\n\u003Cli>“Clear the object cache and tell me how big my database is.”\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why Choose AI Connector for WordPress Automation?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>150+ tools, 20 categories\u003C\u002Fstrong> — one of the largest verified MCP tool sets available for WordPress, covering content, commerce, SEO, media, users, taxonomies, menus, plugins, cache, and more\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-client, not single-vendor\u003C\u002Fstrong> — works with AI assistants from Anthropic (Claude), OpenAI (ChatGPT), and Google (Gemini) out of the box, alongside Cursor, Windsurf, and any other client implementing the MCP 2025-11-25 specification\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real OAuth 2.0, not a shared API key\u003C\u002Fstrong> — full authorization code flow with PKCE (S256), Dynamic Client Registration (RFC 7591), and discovery endpoints (RFC 8414) — no static secret to leak or rotate by hand\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Conservative by design\u003C\u002Fstrong> — no MCP tool can ever create a new WordPress user, and role changes require the \u003Ccode>promote_users\u003C\u002Fcode> capability specifically, not just \u003Ccode>edit_users\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Local, redacted activity logging\u003C\u002Fstrong> — the Activity Log records every tool call (tool name, timestamp, client, status, and the call’s parameters\u002Fresult for audit and debugging) entirely in your own database; sensitive-looking values (passwords, tokens, secrets, keys) are automatically redacted before anything is written, and nothing is ever sent off your server\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero telemetry, ever\u003C\u002Fstrong> — no analytics, no tracking pixels, no “phone home” of any kind. The only outbound request the plugin can make is the one explicit image-download tool, and only when your AI client asks for it\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Grows with your stack\u003C\u002Fstrong> — WooCommerce, Advanced Custom Fields, Elementor, and Gravity Forms tools activate automatically the moment those plugins are detected, with zero extra configuration\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Open to extend\u003C\u002Fstrong> — register your own custom MCP tools from any plugin or theme with one function call\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Ideal For\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Agencies and freelancers\u003C\u002Fstrong> who want to run day-to-day WordPress maintenance through an AI assistant instead of clicking through wp-admin one task at a time\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce store owners\u003C\u002Fstrong> who want an AI agent that can check orders, adjust stock, and manage coupons on request\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO teams and content editors\u003C\u002Fstrong> running bulk metadata fixes, content audits, or multi-step publishing workflows\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developers\u003C\u002Fstrong> who want a real WordPress AI integration to build custom AI automation and AI workflow tools on top of\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Anyone already using Claude, ChatGPT, Cursor, or Windsurf\u003C\u002Fstrong> who wants those tools to actually reach into WordPress instead of just describing what to do next\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Supported AI Assistants & MCP Clients\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Claude.ai\u003C\u002Fstrong> — Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Integrations \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add integration \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Custom MCP\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Claude Desktop\u003C\u002Fstrong> — add the MCP URL to \u003Ccode>claude_desktop_config.json\u003C\u002Fcode> under \u003Ccode>mcpServers\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Claude Code\u003C\u002Fstrong> — connects over the same Streamable HTTP MCP endpoint\u003C\u002Fli>\n\u003Cli>\u003Cstrong>ChatGPT\u003C\u002Fstrong> — Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Connectors \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add connector \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> MCP Server\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Gemini\u003C\u002Fstrong> — connect via Google AI Studio MCP integrations\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cursor (0.45+)\u003C\u002Fstrong> — Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> MCP \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add New Server \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> HTTP (Streamable HTTP transport)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Windsurf\u003C\u002Fstrong> — MCP settings panel, supports both Streamable HTTP and legacy SSE\u003C\u002Fli>\n\u003Cli>\u003Cstrong>VS Code, Cline, Continue, Zed, JetBrains\u003C\u002Fstrong> and any other editor or IDE with MCP client support\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Postman, Insomnia\u003C\u002Fstrong> and other API tools with MCP request support\u003C\u002Fli>\n\u003Cli>Any custom client or framework that implements the MCP 2025-11-25 specification\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WordPress AI Tools by Category (159 Tools, Verified)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Posts\u003C\u002Fstrong> — 14 tools (create, read, update, delete, duplicate, bulk trash, schedule, search, count, post types & statuses, post format, password protection)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pages\u003C\u002Fstrong> — 8 tools (CRUD, duplicate, page templates)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Media\u003C\u002Fstrong> — 11 tools (browse, upload from file or URL, update metadata, set featured image, regenerate thumbnails, attachment metadata, image sizes, count)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Taxonomies\u003C\u002Fstrong> — 11 tools (categories, tags, custom taxonomies, term meta, term assignment)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Comments\u003C\u002Fstrong> — 8 tools (CRUD, approve, spam, trash, pending queue)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Users\u003C\u002Fstrong> — 10 tools (list, view, update, delete, sessions, roles, password reset — no creation tool, by design)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Meta\u003C\u002Fstrong> — 6 tools (post meta and user meta read\u002Fwrite\u002Fdelete)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Menus\u003C\u002Fstrong> — 10 tools (menus, menu items, reordering, location assignment)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugins & Themes\u003C\u002Fstrong> — 7 tools (list, activate, deactivate, active theme, theme mods, custom CSS)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO\u003C\u002Fstrong> — 2 tools (read and update SEO meta fields)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Site \u002F Options\u003C\u002Fstrong> — 9 tools (site info, site health, server info, permalink structure, plugin settings, database size, debug log, send email)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Revisions\u003C\u002Fstrong> — 5 tools (history and restore)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cache\u003C\u002Fstrong> — 5 tools (flush, purge, optimize tables, transients)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blocks\u003C\u002Fstrong> — 2 tools (parse blocks, block patterns, reusable blocks)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Widgets\u003C\u002Fstrong> — 2 tools (registered sidebars, sidebar widgets)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developer Tools\u003C\u002Fstrong> — 5 tools (shortcode execution, cron jobs, rewrite rules, and more)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce\u003C\u002Fstrong> \u003Cem>(activates automatically)\u003C\u002Fem> — 33 tools (products, variations, attributes, coupons, orders, refunds, customers, shipping zones, tax rates, store stats, payment gateways)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Custom Fields\u003C\u002Fstrong> \u003Cem>(activates automatically)\u003C\u002Fem> — 3 tools (field groups, field values, field updates)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Elementor\u003C\u002Fstrong> \u003Cem>(activates automatically)\u003C\u002Fem> — 6 tools (clone page, bulk text replace, image swap, page outline, template import\u002Flisting)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Gravity Forms\u003C\u002Fstrong> \u003Cem>(activates automatically)\u003C\u002Fem> — 2 tools (list forms, read entries)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How to Connect Claude, ChatGPT, Gemini & More\u003C\u002Fh4>\n\u003Cp>Point your AI client to your MCP URL:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>https:\u002F\u002Fyoursite.com\u002Fwp-json\u002Fbcs-mcp\u002Fv1\u002Fmcp\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The client automatically discovers the OAuth server via \u003Ccode>\u002F.well-known\u002Foauth-protected-resource\u003C\u002Fcode>, registers itself using Dynamic Client Registration, and redirects to your site’s authorization page for one-time approval. All future requests use short-lived access tokens that refresh automatically — there is nothing to copy into a config file by hand for clients that support DCR.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Claude.ai:\u003C\u002Fstrong> Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Integrations \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add integration \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Custom MCP \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> paste the MCP URL.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Claude Desktop:\u003C\u002Fstrong> Add to \u003Ccode>claude_desktop_config.json\u003C\u002Fcode>:\u003Cbr \u002F>\n    {“mcpServers”:{“wordpress”:{“url”:”https:\u002F\u002Fyoursite.com\u002Fwp-json\u002Fbcs-mcp\u002Fv1\u002Fmcp”,”transport”:”http”}}}\u003C\u002Fp>\n\u003Cp>\u003Cstrong>ChatGPT:\u003C\u002Fstrong> Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Connectors \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add connector \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> MCP Server \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> paste the MCP URL.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Cursor (0.45+):\u003C\u002Fstrong> Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> MCP \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add New Server \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> select HTTP \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> paste the MCP URL. Cursor uses the \u003Ccode>Mcp-Session-Id\u003C\u002Fcode> header returned by the server on initialization to track sessions.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Windsurf:\u003C\u002Fstrong> Open the MCP settings panel, add a new server with the MCP URL. Recent Windsurf versions use Streamable HTTP; older versions fall back to the legacy SSE transport automatically.\u003C\u002Fp>\n\u003Ch4>AI Connector Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>150+ WordPress MCP tools\u003C\u002Fstrong> across 20 categories — see the full breakdown above\u003C\u002Fli>\n\u003Cli>\u003Cstrong>OAuth 2.0 with PKCE\u003C\u002Fstrong> — full authorization code flow with Dynamic Client Registration (RFC 7591), refresh tokens, and discovery endpoints (RFC 8414)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Streamable HTTP transport\u003C\u002Fstrong> (MCP 2025-11-25) — the primary transport used by all modern AI clients\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Legacy SSE transport\u003C\u002Fstrong> — automatic fallback for older client versions, with \u003Ccode>X-Accel-Buffering: no\u003C\u002Fcode> so nginx doesn’t buffer the stream\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Activity log\u003C\u002Fstrong> — every tool call recorded with AI client detection, color-coded client tags, search\u002Ffilter by client, status, and date range, bulk delete, and one-click CSV export — sensitive-looking parameter values (passwords, tokens, secrets) are redacted before being written\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Rate limiting\u003C\u002Fstrong> — 60 requests per minute per IP, enforced automatically on every MCP request\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP allowlist\u003C\u002Fstrong> — optionally restrict MCP access to specific IPs or CIDR ranges\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin dashboard\u003C\u002Fstrong> — live server status, MCP endpoint URL, OAuth client count, today’s success\u002Ffail counts, recent activity feed, and a searchable WordPress tools browser\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WP Dashboard widget\u003C\u002Fstrong> — 7-day activity sparkline with success\u002Ferror breakdown, right on your wp-admin home screen\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built-in setup guides\u003C\u002Fstrong> — copy-paste connection instructions for every supported client, generated with your site’s real MCP URL\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Translation-ready\u003C\u002Fstrong> — ships with a complete \u003Ccode>.pot\u003C\u002Fcode> file in \u003Ccode>\u002Flanguages\u003C\u002Fcode> so translators can localize the plugin into any language\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developer-friendly\u003C\u002Fstrong> — extend with \u003Ccode>bcs_mcp_register_tool()\u003C\u002Fcode> or the \u003Ccode>bcs_mcp_tools\u003C\u002Fcode> filter\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WooCommerce, Elementor, ACF & Gravity Forms Integration\u003C\u002Fh4>\n\u003Cp>Tools for these plugins are included in the box but only activate when the respective plugin is installed and active. No errors are thrown if a plugin is absent, and nothing extra needs configuring. The MCP tool list shown to a connected AI client only ever includes tools whose dependencies are actually satisfied on your site — so a site without WooCommerce simply never advertises WooCommerce tools to the AI.\u003C\u002Fp>\n\u003Ch4>Multisite Support\u003C\u002Fh4>\n\u003Cp>AI Connector works on WordPress multisite networks the same way it works on a single site: each site in the network has its own settings, its own MCP endpoint, and its own Activity Log. There is no cross-site tool access — an AI client connected to one site can never reach another site’s data through this plugin.\u003C\u002Fp>\n\u003Ch4>Extending AI Connector (Developer API)\u003C\u002Fh4>\n\u003Cp>Register custom tools from any plugin or theme:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>bcs_mcp_register_tool( 'my_tool', 'Description', $schema, $callback );\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Or use the \u003Ccode>bcs_mcp_tools\u003C\u002Fcode> filter directly to add, modify, or remove tools before they’re advertised to a connecting AI client.\u003C\u002Fp>\n\u003Ch4>Security & Permissions\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>All tool calls verify WordPress capabilities (\u003Ccode>current_user_can\u003C\u002Fcode>) before executing — an AI client can never do more than the authorizing user is allowed to do\u003C\u002Fli>\n\u003Cli>No MCP tool can create new WordPress users — user accounts must be created through wp-admin, full stop\u003C\u002Fli>\n\u003Cli>Role changes (\u003Ccode>wp_assign_user_role\u003C\u002Fcode>) require the \u003Ccode>promote_users\u003C\u002Fcode> capability, not just \u003Ccode>edit_users\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>OAuth tokens are SHA-256 hashed before database storage — plain tokens are never stored\u003C\u002Fli>\n\u003Cli>PKCE (S256) is required for all authorization flows; plain challenges are rejected\u003C\u002Fli>\n\u003Cli>Dynamic Client Registration is rate-limited to 10 registrations per IP per minute\u003C\u002Fli>\n\u003Cli>Sensitive meta keys (\u003Ccode>user_pass\u003C\u002Fcode>, \u003Ccode>session_tokens\u003C\u002Fcode>, and similar) are permanently blocked from read\u002Fwrite, with no setting to disable the block\u003C\u002Fli>\n\u003Cli>The Activity Log stores tool name, timestamp, client, status, and the call’s parameters\u002Fresult for audit purposes, all locally in your own database — any value that looks like a password, token, secret, or key is redacted before it’s written, and large content fields are truncated\u003C\u002Fli>\n\u003Cli>Outbound image downloads validate URLs against a blocklist of private\u002Floopback IP ranges (SSRF protection) and enforce a 20 MB size limit\u003C\u002Fli>\n\u003Cli>All admin AJAX actions are protected by nonce verification and a \u003Ccode>manage_options\u003C\u002Fcode> capability check\u003C\u002Fli>\n\u003Cli>Session termination (\u003Ccode>DELETE \u002Fmcp\u003C\u002Fcode>) requires a valid bearer token\u003C\u002Fli>\n\u003Cli>The MCP server ships \u003Cstrong>disabled by default\u003C\u002Fstrong> — nothing is exposed until you explicitly enable it in Settings\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin operates primarily as an \u003Cstrong>inbound\u003C\u002Fstrong> API server — AI clients connect to it, not the other way around. No data is sent to any external service automatically or in the background.\u003C\u002Fp>\n\u003Ch4>Image download via wp_upload_media_from_url\u003C\u002Fh4>\n\u003Cp>The \u003Ccode>wp_upload_media_from_url\u003C\u002Fcode> MCP tool, when explicitly invoked by an authenticated AI client (e.g. Claude), makes a single outgoing HTTP GET request to download an image from the URL the AI client provides. This request:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Is only made when the tool is called by a connected, OAuth-authenticated MCP client\u003C\u002Fli>\n\u003Cli>Carries no personal data beyond the image URL itself\u003C\u002Fli>\n\u003Cli>Is validated against a blocklist of private\u002Floopback IP ranges before the request is made\u003C\u002Fli>\n\u003Cli>Is subject to a 20 MB size limit\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>No data is sent to the plugin author’s servers at any time. This plugin does not include analytics, telemetry, or tracking of any kind.\u003C\u002Fp>\n","Connect Claude, ChatGPT, Gemini, Cursor, and other AI assistants to your WordPress site using the Model Context Protocol (MCP). 150+ tools, OAuth 2.",140,0,"2026-07-06T18:02:00.000Z","7.0.2","6.2","7.4",[27,28,29,30,31],"ai-connector","ai-automation","chatgpt","claude","mcp","https:\u002F\u002Fbytecorestack.com\u002Fplugins\u002Fai-connector\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbcs-mcp-manager.1.0.0.zip",null,"2026-07-22T17:31:50.256Z",{"slug":37,"name":38,"version":39,"author":4,"author_profile":6,"description":40,"short_description":41,"active_installs":21,"downloaded":42,"rating":21,"num_ratings":21,"last_updated":43,"tested_up_to":23,"requires_at_least":44,"requires_php":45,"tags":46,"homepage":52,"download_link":53,"security_score":9,"vuln_count":21,"unpatched_count":21,"last_vuln_date":34,"fetched_at":35},"bcs-smtp-manager","SMTP Manager – Email Logs, Monitoring & Alerts","1.1.0","\u003Cp>\u003Cstrong>Is your WordPress site silently failing to send emails?\u003C\u002Fstrong> Order confirmations, password resets, contact form notifications, shipping updates — when they don’t land in the inbox, you’re usually the last person to find out, often from an angry customer. SMTP Manager – Email Logs, Monitoring & Alerts is the WordPress SMTP plugin that fixes email deliverability at the source, logs every single send, and alerts your team the instant delivery breaks again — on Slack, Microsoft Teams, Google Chat, or Discord, completely free.\u003C\u002Fp>\n\u003Cp>Most WordPress SMTP plugins stop the moment your email starts sending again. This one keeps going: continuous SMTP health monitoring, a fully searchable email log with CSV export, scheduled delivery reports, and real-time failure alerts that many competing SMTP plugins lock behind a paid upgrade.\u003C\u002Fp>\n\u003Ch4>Why your WordPress emails are failing\u003C\u002Fh4>\n\u003Cp>By default, WordPress sends email through your server’s PHP \u003Ccode>mail()\u003C\u002Fcode> function. PHP mail has no authentication — no SPF, no DKIM, nothing that proves to Gmail, Outlook, or Yahoo that the message is legitimate. Most inbox providers either bin it as spam or drop it outright. That’s why “WordPress not sending email” is one of the most common WordPress problems there is, and why every serious site needs proper SMTP — authenticated, encrypted mail delivery through a real mail server or transactional email provider.\u003C\u002Fp>\n\u003Ch4>How SMTP Manager fixes it\u003C\u002Fh4>\n\u003Cp>The plugin reconfigures \u003Ccode>wp_mail()\u003C\u002Fcode> to send through the authenticated SMTP server you configure — your hosting provider, Gmail, Microsoft 365, or any transactional email service (SendGrid, Mailgun, Amazon SES, Brevo, Zoho, SMTP.com, and others all work over standard SMTP). Every email is logged with its delivery status, and an automated health check keeps testing your connection in the background — so instead of finding out about a broken mail server from an angry customer, you find out from a Slack message.\u003C\u002Fp>\n\u003Ch4>✅ Core features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Universal SMTP connection\u003C\u002Fstrong> — host, port, and encryption (SSL \u002F TLS \u002F none) for any standard SMTP provider, with auto-TLS upgrade support\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built-in quick-reference for popular providers\u003C\u002Fstrong> — Gmail \u002F Google Workspace, Microsoft 365 \u002F Outlook, Yahoo Mail, SendGrid, Amazon SES, and Mailgun host\u002Fport\u002Fencryption settings, right inside the settings page\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full email log\u003C\u002Fstrong> — date, subject, sender, recipient, delivery status, and the actual error message for every email \u003Ccode>wp_mail()\u003C\u002Fcode> sends\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AJAX-driven search and filtering\u003C\u002Fstrong> — live search-as-you-type plus date-range presets (today through all time), no page reloads\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CSV export\u003C\u002Fstrong> of the filtered log for record-keeping or support tickets\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One-click “Send Test Email”\u003C\u002Fstrong> to verify your configuration instantly, with failure-type classification (authentication failure, SMTP rejection, or plugin\u002Fsystem error) so you know exactly what’s wrong\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scheduled HTML delivery reports\u003C\u002Fstrong> — daily, weekly, or monthly summary emails with a visual chart of sent\u002Ffailed\u002Funconfirmed volume\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic log retention\u003C\u002Fstrong> — keep the last 30 days or the last 1,000 records, pruned automatically\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress Dashboard widget\u003C\u002Fstrong> — SMTP health and 30-day send volume at a glance, without opening the plugin’s settings page\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Encrypted password storage\u003C\u002Fstrong> — your SMTP password is encrypted at rest, not stored as plaintext\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Dark-mode admin UI\u003C\u002Fstrong> built for clarity, not just decoration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🔔 Real-time failure alerts — completely free\u003C\u002Fh4>\n\u003Cp>This is the feature most SMTP plugins put behind a premium plan. Here, it’s free:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Automated SMTP health checks\u003C\u002Fstrong> via WordPress Cron — a real connection + EHLO + STARTTLS + AUTH test on the interval you choose, with no test email sent on success\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Five alert channels\u003C\u002Fstrong>: Slack, Microsoft Teams, Google Chat, Discord, and a Custom Webhook option that POSTs a structured JSON payload (\u003Ccode>event\u003C\u002Fcode>, \u003Ccode>site_name\u003C\u002Fcode>, \u003Ccode>error_msg\u003C\u002Fcode>, \u003Ccode>consecutive_failures\u003C\u002Fcode>, and more) for Zapier, Make, n8n, or your own endpoint\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Configurable failure threshold\u003C\u002Fstrong> — alert after 1 failure or wait for N consecutive failures, your choice\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Notification cap\u003C\u002Fstrong> so a prolonged outage doesn’t spam your channel forever\u003C\u002Fli>\n\u003Cli>\u003Cstrong>External provider status check\u003C\u002Fstrong> — when an alert fires, the plugin checks whether the failure looks like an outage on your provider’s end before notifying you\u003C\u002Fli>\n\u003Cli>All webhook URLs are validated against the provider’s real domain and sent over \u003Ccode>wp_safe_remote_post()\u003C\u002Fcode>, so a misconfigured webhook can’t be used to reach internal network addresses\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🔌 Works with everything that uses wp_mail()\u003C\u002Fh4>\n\u003Cp>WooCommerce, Contact Form 7, WPForms, Gravity Forms, Elementor Forms, user registration\u002Fpassword reset emails, and literally any other plugin or theme that sends mail through WordPress’s standard \u003Ccode>wp_mail()\u003C\u002Fcode> function — because that’s exactly what this plugin hooks into. Nothing to reconfigure on the form\u002Fstore plugin side.\u003C\u002Fp>\n\u003Ch4>🌐 Supported SMTP providers\u003C\u002Fh4>\n\u003Cp>Anything that speaks standard SMTP with host\u002Fport\u002Fusername\u002Fpassword authentication works, because the plugin talks SMTP directly rather than locking you into a specific provider’s proprietary API:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmyaccount.google.com\u002Fapppasswords\" rel=\"nofollow ugc\">Gmail \u002F Google Workspace\u003C\u002Fa> (App Passwords, or \u003Ca href=\"https:\u002F\u002Fsupport.google.com\u002Fa\u002Fanswer\u002F2956491\" rel=\"nofollow ugc\">Workspace SMTP relay\u003C\u002Fa> for higher volume)\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fexchange\u002Fmail-flow-best-practices\u002Fhow-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365\" rel=\"nofollow ugc\">Microsoft 365 \u002F Outlook\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocs.sendgrid.com\u002Ffor-developers\u002Fsending-email\u002Fgetting-started-smtp\" rel=\"nofollow ugc\">SendGrid\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocumentation.mailgun.com\u002Fdocs\u002Fmailgun\u002Fuser-manual\u002Fsending-messages\u002F\" rel=\"nofollow ugc\">Mailgun\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocs.aws.amazon.com\u002Fses\u002Flatest\u002Fdg\u002Fsend-email-smtp.html\" rel=\"nofollow ugc\">Amazon SES\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fhelp.brevo.com\u002Fhc\u002Fen-us\u002Farticles\u002F209462765\" rel=\"nofollow ugc\">Brevo\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.zoho.com\u002Fmail\u002Fhelp\u002F\" rel=\"nofollow ugc\">Zoho Mail\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Yahoo Mail, SMTP.com, or your own hosting provider’s mail server\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🆚 How this is different\u003C\u002Fh4>\n\u003Cp>Most SMTP plugins solve half the problem: they get your email sending again, and stop there. If the connection breaks again next month — expired app password, host changed something, provider outage — you won’t know until someone tells you. Many plugins in this category also reserve email alerting (Slack, Teams, Discord notifications) for their paid tier. SMTP Manager – Email Logs, Monitoring & Alerts treats failure alerting as core functionality, not an upsell, because a delivery plugin that can’t tell you when delivery breaks isn’t finished doing its job.\u003C\u002Fp>\n\u003Ch4>Documentation & support\u003C\u002Fh4>\n\u003Cp>Full plugin details: \u003Ca href=\"https:\u002F\u002Fbytecorestack.com\u002Fplugins\u002Fsmtp-manager\u002F\" rel=\"nofollow ugc\">bytecorestack.com\u002Fplugins\u002Fsmtp-manager\u003C\u002Fa>. For SMTP protocol background, see the \u003Ca href=\"https:\u002F\u002Fdeveloper.wordpress.org\u002Freference\u002Ffunctions\u002Fwp_mail\u002F\" rel=\"nofollow ugc\">WordPress wp_mail() developer reference\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin may contact the following external services. All connections are either user-initiated or require explicit configuration by the site administrator.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>1. Your SMTP server (user-configured)\u003C\u002Fstrong>\u003Cbr \u002F>\nThe plugin routes all WordPress emails through the SMTP server credentials you enter in Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> SMTP Manager. The hostname, port, username, and password are provided entirely by you. No data is sent to any ByteCore Stack server.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>2. Slack Incoming Webhooks (optional)\u003C\u002Fstrong>\u003Cbr \u002F>\nIf you enable Slack alerts, the plugin will POST a JSON failure notification to the Slack Incoming Webhook URL you provide when consecutive SMTP failures are detected. This URL is specific to your Slack workspace and is created by you.\u003Cbr \u002F>\n* Service: Slack Technologies, LLC\u003Cbr \u002F>\n* Privacy policy: https:\u002F\u002Fslack.com\u002Fprivacy-policy\u003Cbr \u002F>\n* Terms of service: https:\u002F\u002Fslack.com\u002Fterms-of-service\u003C\u002Fp>\n\u003Cp>\u003Cstrong>3. Microsoft Teams Incoming Webhooks (optional)\u003C\u002Fstrong>\u003Cbr \u002F>\nIf you enable Teams alerts, the plugin will POST a JSON failure notification to the Teams Incoming Webhook URL you provide when consecutive SMTP failures are detected. This URL is specific to your Teams channel and is created by you.\u003Cbr \u002F>\n* Service: Microsoft Corporation\u003Cbr \u002F>\n* Privacy policy: https:\u002F\u002Fprivacy.microsoft.com\u002Fen-us\u002Fprivacystatement\u003Cbr \u002F>\n* Terms of service: https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fservicesagreement\u003C\u002Fp>\n\u003Cp>\u003Cstrong>4. Google Chat Incoming Webhooks (optional)\u003C\u002Fstrong>\u003Cbr \u002F>\nIf you enable Google Chat alerts, the plugin will POST a JSON failure notification to the Google Chat Incoming Webhook URL you provide when consecutive SMTP failures are detected. This URL is specific to your Chat space and is created by you.\u003Cbr \u002F>\n* Service: Google LLC\u003Cbr \u002F>\n* Privacy policy: https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003Cbr \u002F>\n* Terms of service: https:\u002F\u002Fpolicies.google.com\u002Fterms\u003C\u002Fp>\n\u003Cp>\u003Cstrong>5. Discord Incoming Webhooks (optional)\u003C\u002Fstrong>\u003Cbr \u002F>\nIf you enable Discord alerts, the plugin will POST a JSON failure notification to the Discord Incoming Webhook URL you provide when consecutive SMTP failures are detected. This URL is specific to your Discord channel and is created by you.\u003Cbr \u002F>\n* Service: Discord Inc.\u003Cbr \u002F>\n* Privacy policy: https:\u002F\u002Fdiscord.com\u002Fprivacy\u003Cbr \u002F>\n* Terms of service: https:\u002F\u002Fdiscord.com\u002Fterms\u003C\u002Fp>\n\u003Cp>\u003Cstrong>6. Custom Webhook (optional)\u003C\u002Fstrong>\u003Cbr \u002F>\nIf you enable the Custom Webhook channel, the plugin will POST a structured JSON failure notification to the URL you provide when consecutive SMTP failures are detected. This URL is entirely user-supplied — point it at Zapier, Make, n8n, or your own server. No data is sent unless you configure this channel.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>7. Google Fonts API\u003C\u002Fstrong>\u003Cbr \u002F>\nThe admin settings page loads two typefaces (DM Sans and DM Mono) from the Google Fonts API to render the admin UI. This request is made only by the administrator’s browser when visiting the plugin settings page. No personal data from site visitors is ever transmitted.\u003Cbr \u002F>\n* Service: Google LLC\u003Cbr \u002F>\n* Privacy policy: https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003Cbr \u002F>\n* Terms of service: https:\u002F\u002Fpolicies.google.com\u002Fterms\u003Cbr \u002F>\n* Font API endpoint: https:\u002F\u002Ffonts.googleapis.com\u002F\u003C\u002Fp>\n\u003Cp>No data is collected, transmitted to, or processed by ByteCore Stack servers.\u003C\u002Fp>\n","The WordPress SMTP plugin for reliable email delivery — full email log, health monitoring, and instant Slack, Teams, Discord & Google Chat alerts.",157,"2026-06-20T13:51:00.000Z","5.3","7.2",[47,48,49,50,51],"deliverability","email","email-log","smtp","smtp-alerts","https:\u002F\u002Fbytecorestack.com\u002Fplugins\u002Fsmtp-manager\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbcs-smtp-manager.1.1.0.zip"]