[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fkdsGB-YzW8oy5VkquRGKrOUxP_ejFdqlvG2Xj5T_KNw":3,"$fZj2jrLx5qaSksqxJPYrkG_FHP-3PiB6h2TtTNBYW3i8":126,"$f_3AzVK40bOVKMXSrcekFWXZTneAVmapqYfde-Byr2Ik":131},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":37,"analysis":27,"fingerprints":27},"inhale-mcp-abilities","Inhale: MCP Abilities by Respira","0.4.5","Respira for WordPress","https:\u002F\u002Fprofiles.wordpress.org\u002Furbankidro\u002F","\u003Cp>Inhale: MCP Abilities is a small, focused utility that solves one problem: the default WordPress MCP server (provided by the official MCP Adapter plugin) does not expose any registered abilities by default. Site administrators have to write PHP filters to opt each ability into the public MCP surface.\u003C\u002Fp>\n\u003Cp>This is the workaround pattern documented in WordPress contributor blog posts and developer guides since the MCP Adapter shipped. Inhale: MCP Abilities replaces the PHP-filter workaround with a simple settings page.\u003C\u002Fp>\n\u003Cp>Once installed and activated, you’ll find a new page at Settings > Inhale: MCP Abilities where you can check off the abilities you want exposed to your default MCP server.\u003C\u002Fp>\n\u003Ch4>What the Inhale: MCP Abilities plugin does\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Lists every registered WordPress ability across all active plugins and themes\u003C\u002Fli>\n\u003Cli>Lets you select which abilities are exposed to the default MCP server with simple checkboxes\u003C\u002Fli>\n\u003Cli>Shows annotation metadata (read-only, destructive, idempotent) on each ability so you can make informed decisions\u003C\u002Fli>\n\u003Cli>Requires explicit confirmation when you inhale an ability marked as destructive\u003C\u002Fli>\n\u003Cli>Provides connection info for popular MCP clients (Claude Desktop, Cursor, Claude Code)\u003C\u002Fli>\n\u003Cli>Respects each ability’s own permission_callback. The Inhale: MCP Abilities plugin controls visibility, not authorization.\u003C\u002Fli>\n\u003Cli>Offers Respira for WordPress as the easiest connection path in the Connection section, and points WooCommerce stores at Respira ARC (free). Both are plain links: nothing loads from respira.press and nothing is sent unless you click.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>What the Inhale: MCP Abilities plugin doesn’t do\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Inhale: MCP Abilities does not run any MCP servers, transports, or authentication. Those are handled by the official MCP Adapter plugin, which the Inhale: MCP Abilities plugin extends.\u003C\u002Fli>\n\u003Cli>Inhale: MCP Abilities does not register any abilities of its own. It only toggles visibility of abilities other plugins have registered.\u003C\u002Fli>\n\u003Cli>Inhale: MCP Abilities does not phone home, collect telemetry, or make external network requests.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Requirements\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>WordPress 6.8 or later (Abilities API in core since 6.9; 6.8 requires the Abilities API plugin)\u003C\u002Fli>\n\u003Cli>PHP 7.4 or later\u003C\u002Fli>\n\u003Cli>The official WordPress MCP Adapter plugin installed and active\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Browse the abilities directory\u003C\u002Fh4>\n\u003Cp>Respira maintains a public, regularly-refreshed directory of WordPress plugins that register abilities through the Abilities API, including Respira’s own and the Respira WooCommerce add-on. Browse it at \u003Ca href=\"https:\u002F\u002Fwww.respira.press\u002Fabilities?utm_source=inhale&utm_medium=wp-org&utm_campaign=readme-abilities-directory\" rel=\"nofollow ugc\">respira.press\u002Fabilities\u003C\u002Fa> to see what each plugin exposes to AI agents before you decide which abilities to inhale.\u003C\u002Fp>\n\u003Ch4>About MCP\u003C\u002Fh4>\n\u003Cp>Model Context Protocol (MCP) is an open specification originally developed by Anthropic. Inhale: MCP Abilities is a third-party plugin and is not affiliated with, endorsed by, or sponsored by Anthropic. Respira is an independent company.\u003C\u002Fp>\n\u003Ch4>About Respira\u003C\u002Fh4>\n\u003Cp>The Inhale: MCP Abilities plugin is built and maintained by Respira, which ships AI infrastructure for WordPress. The main product is Respira for WordPress, a safety layer that registers 130+ abilities across 16 page builders (Elementor, Bricks, Divi, Beaver Builder, Oxygen, Breakdance and 10 more) with snapshot-before-write protection, render validation and one-click rollback. Inhale: MCP Abilities is a free utility offered to the WordPress community. Learn more at \u003Ca href=\"https:\u002F\u002Frespira.press\u002Finhale?utm_source=inhale&utm_medium=wp-org&utm_campaign=readme-description\" rel=\"nofollow ugc\">respira.press\u002Finhale\u003C\u002Fa>.\u003C\u002Fp>\n","A small settings page that lets WordPress site administrators choose which registered abilities are exposed to the default MCP server.",80,663,0,"2026-07-17T22:03:00.000Z","7.0.2","6.8","7.4",[19,20,21,22,23],"abilities","ai","ai-infrastructure","mcp","model-context-protocol","https:\u002F\u002Frespira.press\u002Finhale","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Finhale-mcp-abilities.0.4.5.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"urbankidro",2,30,94,"2026-08-25T01:10:01.115Z",[38,56,74,91,109],{"slug":20,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":47,"num_ratings":48,"last_updated":49,"tested_up_to":15,"requires_at_least":50,"requires_php":17,"tags":51,"homepage":54,"download_link":55,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"AI","1.2.0","WordPress.org","https:\u002F\u002Fprofiles.wordpress.org\u002Fwordpressdotorg\u002F","\u003Cp>The AI plugin brings AI-powered features directly into your WordPress admin and editing experience.\u003C\u002Fp>\n\u003Cp>Requires the WordPress Block Editor.  The Classic Editor plugin and other non-Block Editor editing experiences are not supported.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What’s Inside:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>This plugin is built on the \u003Ca href=\"https:\u002F\u002Fmake.wordpress.org\u002Fai\u002F2025\u002F07\u002F17\u002Fai-building-blocks\" rel=\"nofollow ugc\">AI Building Blocks for WordPress\u003C\u002Fa> initiative, combining the AI Client library and Abilities API into a unified experience. It serves as both a practical tool for content creators and a reference implementation for developers.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Current Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Abilities Explorer\u003C\u002Fstrong> – Browse and interact with registered AI abilities from a dedicated admin screen.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI Request Logging\u003C\u002Fstrong> – Logs AI requests for observability and debugging.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Alt Text Generation\u003C\u002Fstrong> – Generate descriptive alt text for images to improve accessibility.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Comment Moderation\u003C\u002Fstrong> – Automatically moderate comments based on toxicity detection and sentiment analysis.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Connector Approvals\u003C\u002Fstrong> – Require explicit administrator approval before plugins or themes can use AI connectors configured on this site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Content Classification\u003C\u002Fstrong> – Suggests relevant tags and categories to organize content.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Content Resizing\u003C\u002Fstrong> – Shorten, expand, or rephrase selected block content.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Content Summarization\u003C\u002Fstrong> – Summarizes long-form content into digestible overviews.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Dashboard Widgets\u003C\u002Fstrong> – AI Status and AI Capabilities widgets, plus framework for registering new ones.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Editorial Notes\u003C\u002Fstrong> – Reviews post content block-by-block and adds Notes with suggestions for Accessibility, Readability, Grammar, and SEO.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Editorial Updates\u003C\u002Fstrong> – Automatically apply editorial notes to content.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Excerpt Generation\u003C\u002Fstrong> – Automatically create concise summaries for your posts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Experiment Framework\u003C\u002Fstrong> – Opt-in system that lets you enable only the AI features you want to use.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Guidelines\u003C\u002Fstrong> – Allows abilities to respect site-wide editorial standards.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Image Generation and Editing\u003C\u002Fstrong> – Create and edit images from post content in the editor, also via the Media Library.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Key Encryption\u003C\u002Fstrong> – Encrypts AI provider API keys at rest using bundled libsodium encryption. Keys are transparently decrypted on read and re-encrypted on write. Disabling the experiment or deactivating the plugin restores plaintext keys.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Meta Description Generation\u003C\u002Fstrong> – Generates meta description suggestions and integrates those with various SEO plugins.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-Provider Support\u003C\u002Fstrong> – Works with AI Connector plugins for providers such as OpenAI, Google, and Anthropic.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Suggest Reply\u003C\u002Fstrong> – Adds a “Suggest Reply” action to the Comments screen and Activity widget, enabling moderators to quickly generate comment reply suggestions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Title Generation\u003C\u002Fstrong> – Generate title suggestions for your posts with a single click. Perfect for brainstorming headlines or finding the right tone for your content.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Type Ahead\u003C\u002Fstrong> – Contextual type-ahead assistance for suggestions while typing.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Provider Setup:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The AI plugin does not include provider credentials or provider implementations by itself. To use AI-powered features, install and activate at least one AI Connector plugin, then configure its credentials in \u003Ccode>Settings -> Connectors\u003C\u002Fcode>. Features may appear unavailable until a connector is installed, authenticated, and capable of the required operation.\u003C\u002Fp>\n\u003Cp>Provider connector plugins include \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fai-provider-for-anthropic\" rel=\"ugc\">Anthropic\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fai-provider-for-google\" rel=\"ugc\">Google\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fai-provider-for-openai\" rel=\"ugc\">OpenAI\u003C\u002Fa>, and \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Ftags\u002Fconnector\u002F\" rel=\"ugc\">others\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Coming Soon:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>We’re actively developing new features to enhance your WordPress workflow:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>AI Playground\u003C\u002Fstrong> – Experiment with different AI models and providers.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Content Assistant\u003C\u002Fstrong> – AI-powered writing and editing in Gutenberg.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Site Agent\u003C\u002Fstrong> – Natural language WordPress administration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Workflow Automation\u003C\u002Fstrong> – AI-driven task automation.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This is an experimental plugin; functionality may change as we gather feedback from the community.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Roadmap:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>You can view the active plugin roadmap in a filtered view in the WordPress AI \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Forgs\u002FWordPress\u002Fprojects\u002F240\u002Fviews\u002F1\" rel=\"nofollow ugc\">GitHub Project Board\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>For Developers\u003C\u002Fh3>\n\u003Cp>The AI plugin is designed to be studied, extended, and built upon. Whether you’re a plugin developer, agency, or hosting provider, here’s what you can do:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Extend the Plugin:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Build Custom Experiments\u003C\u002Fstrong> – Use the \u003Ccode>Abstract_Feature\u003C\u002Fcode> base class to create your own AI-powered features.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pre-configure Providers\u003C\u002Fstrong> – Hosts and agencies can set up AI Connector plugins so users don’t need their own API keys.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Abilities Explorer\u003C\u002Fstrong> – Test and explore registered AI abilities (available when experiments are enabled).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Register Custom Abilities\u003C\u002Fstrong> – Hook into the Abilities API to add new AI capabilities.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Override Default Behavior\u003C\u002Fstrong> – Use filters to customize prompts, responses, and UI elements.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Comprehensive Hooks\u003C\u002Fstrong> – Filters and actions throughout the codebase for customization.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Developer Tools Coming Soon:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>AI Playground\u003C\u002Fstrong> – Experiment with different AI models and prompts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>MCP (Model Context Protocol)\u003C\u002Fstrong> – Integrate and test Model Context Protocol capabilities in WordPress workflows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Extended Providers\u003C\u002Fstrong> – Support for experimenting with additional or alternate AI providers.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Get Started:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Read the \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FWordPress\u002Fai\u002Fblob\u002Ftrunk\u002FCONTRIBUTING.md\" rel=\"nofollow ugc\">Contributing Guide\u003C\u002Fa> for development setup\u003C\u002Fli>\n\u003Cli>Join the conversation in \u003Ca href=\"https:\u002F\u002Fwordpress.slack.com\u002Farchives\u002FC08TJ8BPULS\" rel=\"nofollow ugc\">#core-ai on WordPress Slack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Browse the \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FWordPress\u002Fai\" rel=\"nofollow ugc\">GitHub repository\u003C\u002Fa> to see how experiments are built\u003C\u002Fli>\n\u003Cli>Participate in \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FWordPress\u002Fai\u002Fdiscussions\" rel=\"nofollow ugc\">discussions\u003C\u002Fa> on how best the plugin should iterate.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>We welcome contributions! Whether you want to build new experiments, improve existing features, or help with documentation, check out our \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FWordPress\u002Fai\" rel=\"nofollow ugc\">GitHub repository\u003C\u002Fa> to get involved.\u003C\u002Fp>\n","AI features, experiments and capabilities for WordPress.",30000,155675,92,7,"2026-07-14T20:17:00.000Z","7.0",[19,20,52,53,22],"artificial-intelligence","experiments","https:\u002F\u002Fgithub.com\u002FWordPress\u002Fai","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fai.1.2.0.zip",{"slug":57,"name":58,"version":59,"author":60,"author_profile":61,"description":62,"short_description":63,"active_installs":64,"downloaded":65,"rating":26,"num_ratings":66,"last_updated":67,"tested_up_to":15,"requires_at_least":68,"requires_php":17,"tags":69,"homepage":72,"download_link":73,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"wsp-mcp-ai-agents-connector","WSP MCP – AI Agents Connector","2.6.2","Bilal Naseer","https:\u002F\u002Fprofiles.wordpress.org\u002Fbilalnaseer\u002F","\u003Cp>WSP MCP – AI Agents Connector turns your WordPress site into a Model Context Protocol (MCP) server. AI clients can read and edit posts, pages, categories, tags, media, comments, users, and (when installed) Yoast SEO meta and Elementor page content — all under granular, per-ability admin control.\u003C\u002Fp>\n\u003Cp>The plugin ships its \u003Cstrong>own native MCP server\u003C\u002Fstrong>. You do not need the WordPress MCP Adapter or any companion plugin: activate, copy your connection details from \u003Cstrong>MCP > Connection\u003C\u002Fstrong>, and connect. WooCommerce tools (products, orders, refunds, coupons, customers, reports) are available when WooCommerce is active, Advanced Custom Fields tools (field groups, fields, values, post types, taxonomies, options pages) when ACF is active, Ultimate Addons for Elementor (UAE) tools (widgets, templates, layout building, and settings) when UAE is active, and Gravity Forms tools (forms, entries, notifications, and confirmations) when Gravity Forms is active.\u003C\u002Fp>\n\u003Cp>Built and maintained by the \u003Ca href=\"https:\u002F\u002Fwebsensepro.com\u002F\" rel=\"nofollow ugc\">WebSensePro\u003C\u002Fa> team. For documentation, setup guides, and connection help, visit the plugin home at \u003Ca href=\"https:\u002F\u002Ffreewordpressmcp.com\u002F\" rel=\"nofollow ugc\">freewordpressmcp.com\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Video tutorial\u003C\u002Fh4>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002F1hGSUAdRxiU?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch4>Key features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Built-in MCP server over a single REST endpoint (Streamable HTTP, JSON-RPC 2.0) — no external dependency.\u003C\u002Fli>\n\u003Cli>Per-ability on\u002Foff toggles in \u003Cstrong>MCP > Settings\u003C\u002Fstrong>; write abilities are off by default.\u003C\u002Fli>\n\u003Cli>Two authentication methods: WordPress Application Passwords (HTTP Basic) or a plugin-generated API key (\u003Ccode>Authorization: Bearer\u003C\u002Fcode> or \u003Ccode>X-WSP-MCP-API-Key\u003C\u002Fcode>).\u003C\u002Fli>\n\u003Cli>Capability checks on every tool — an AI client can only do what its authenticated user can do.\u003C\u002Fli>\n\u003Cli>Optional Yoast SEO and Elementor tools, shown only when those plugins are active.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Complete tools list\u003C\u002Fh4>\n\u003Cp>Every tool is individually toggleable in \u003Cstrong>MCP > Settings\u003C\u002Fstrong>, and all write tools are off by default.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Core WordPress\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Posts — read, create, update, delete\u003C\u002Fli>\n\u003Cli>Pages — read, create, update, delete\u003C\u002Fli>\n\u003Cli>Categories — list, create, update, delete\u003C\u002Fli>\n\u003Cli>Tags — list, create, update, delete\u003C\u002Fli>\n\u003Cli>Comments — read, approve, and delete\u003C\u002Fli>\n\u003Cli>Media — read the media library\u003C\u002Fli>\n\u003Cli>Users — read user data\u003C\u002Fli>\n\u003Cli>Site info — read general site details\u003C\u002Fli>\n\u003Cli>Plugins — list active plugins\u003C\u002Fli>\n\u003Cli>Search — search across site content\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Yoast SEO\u003C\u002Fstrong> (requires Yoast SEO)\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Read SEO title, meta description, and focus keyphrase\u003C\u002Fli>\n\u003Cli>Update SEO title, meta description, and focus keyphrase\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Elementor\u003C\u002Fstrong> (requires Elementor)\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Pages — list pages\u002Fposts built with Elementor\u003C\u002Fli>\n\u003Cli>Page structure — read the full element tree of a page\u003C\u002Fli>\n\u003Cli>Elements — get a single element’s settings, or find elements by widget type or content\u003C\u002Fli>\n\u003Cli>Templates — list saved templates from the library\u003C\u002Fli>\n\u003Cli>Editing — add widgets, add layout containers\u002Fsections, update element settings, and remove elements\u003C\u002Fli>\n\u003Cli>Code-bearing widget types (HTML, Shortcode, Code) are rejected and code-bearing settings (Custom CSS, Custom Attributes) are stripped; all text settings are sanitized with \u003Ccode>wp_kses_post()\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>WooCommerce\u003C\u002Fstrong> (requires WooCommerce — financial and PII tools require the \u003Ccode>manage_woocommerce\u003C\u002Fcode> capability)\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Products — list, get, create, update\u003C\u002Fli>\n\u003Cli>Product variations — create\u003C\u002Fli>\n\u003Cli>Orders — list, update status\u003C\u002Fli>\n\u003Cli>Refunds — process refunds\u003C\u002Fli>\n\u003Cli>Coupons — create, list\u003C\u002Fli>\n\u003Cli>Order notes — add order notes\u003C\u002Fli>\n\u003Cli>Customers — read customer data\u003C\u002Fli>\n\u003Cli>Sales report — read sales reporting\u003C\u002Fli>\n\u003Cli>Low-stock alerts — read low-stock products\u003C\u002Fli>\n\u003Cli>Reviews — moderate product reviews\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Advanced Custom Fields\u003C\u002Fstrong> (requires ACF — structural changes require \u003Ccode>manage_options\u003C\u002Fcode>; value tools enforce per-object capabilities)\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Field groups — list, get, create, update, delete, import\u003C\u002Fli>\n\u003Cli>Fields — list, get, create, update, delete, duplicate, sync\u003C\u002Fli>\n\u003Cli>Field values — get and set with dot-notation deep access, delete, get-all, bulk-update, and field object\u003C\u002Fli>\n\u003Cli>Custom post types — manage\u003C\u002Fli>\n\u003Cli>Taxonomies — manage\u003C\u002Fli>\n\u003Cli>Options pages — manage\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Gravity Forms\u003C\u002Fstrong> (requires Gravity Forms — reads require \u003Ccode>gravityforms_edit_forms\u003C\u002Fcode> or \u003Ccode>gravityforms_view_entries\u003C\u002Fcode>; writes require form\u002Fentry-specific Gravity Forms caps)\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Forms — list (ON by default), get (ON by default), create, update, delete, update form settings\u003C\u002Fli>\n\u003Cli>Entries — list, get, update (status, read\u002Fstarred flags, field values), delete (trash or permanent)\u003C\u002Fli>\n\u003Cli>Notifications — get, create, update, delete\u003C\u002Fli>\n\u003Cli>Confirmations — get, create, update, delete\u003C\u002Fli>\n\u003Cli>All 18 tools are off by default (except list-forms and get-form); only registered when Gravity Forms is active\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Ultimate Addons for Elementor\u003C\u002Fstrong> (requires UAE — structural and settings writes require \u003Ccode>edit_posts\u003C\u002Fcode>, \u003Ccode>publish_posts\u003C\u002Fcode>, or \u003Ccode>manage_options\u003C\u002Fcode>)\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Widgets — list, check usage, activate, deactivate, bulk toggle\u003C\u002Fli>\n\u003Cli>Templates — list, get, create, duplicate, update, trash, restore Header\u002FFooter\u002FBlocks templates\u003C\u002Fli>\n\u003Cli>Layout building — add sections, add columns, move elements, build layouts from JSON\u003C\u002Fli>\n\u003Cli>Settings — get\u002Fupdate UAE settings, theme info, extensions, and design-system tokens\u003C\u002Fli>\n\u003Cli>All 45 tools are off by default; string inputs are sanitized with \u003Ccode>wp_kses_post()\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Links\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Plugin home & docs: \u003Ca href=\"https:\u002F\u002Ffreewordpressmcp.com\u002F\" rel=\"nofollow ugc\">freewordpressmcp.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Built by: \u003Ca href=\"https:\u002F\u002Fwebsensepro.com\u002F\" rel=\"nofollow ugc\">WebSensePro\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","Expose your WordPress site to AI agents (Claude, Cursor, and other MCP clients) through a built-in MCP server — no companion plugin required.",200,654,3,"2026-07-21T10:20:00.000Z","6.9",[20,70,22,23,71],"claude","woocommerce","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwsp-mcp-ai-agents-connector.2.6.2.zip",{"slug":75,"name":76,"version":77,"author":78,"author_profile":79,"description":80,"short_description":81,"active_installs":11,"downloaded":82,"rating":26,"num_ratings":83,"last_updated":84,"tested_up_to":85,"requires_at_least":86,"requires_php":17,"tags":87,"homepage":89,"download_link":90,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"abilities-bridge","Abilities Bridge","1.3.2","El Proximus","https:\u002F\u002Fprofiles.wordpress.org\u002Fjoe12345campbell\u002F","\u003Cp>\u003Cstrong>Making Connections Possible\u003C\u002Fstrong> | Now with Claude Opus 4.8, in-chat image attachments and screenshots, GPT-5.5, and Custom Apps in ChatGPT\u003C\u002Fp>\n\u003Cp>Abilities Bridge connects AI to your WordPress site. Use the built-in admin chat, connect via MCP to Claude Desktop, or integrate with other MCP-compatible applications. Supports both Anthropic (Claude) and OpenAI models.\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Admin chat interface for direct AI interaction\u003C\u002Fli>\n\u003Cli>Image attachments in chat — upload images or capture a browser-approved screenshot (can be disabled in settings)\u003C\u002Fli>\n\u003Cli>MCP server for Claude Desktop, ChatGPT, and other MCP clients\u003C\u002Fli>\n\u003Cli>Persistent memory storage across conversations\u003C\u002Fli>\n\u003Cli>Abilities execution with 7-gate permission controls\u003C\u002Fli>\n\u003Cli>Integrated Connected Plugins — discover and approve AI abilities that other plugins register, with per-ability permission controls\u003C\u002Fli>\n\u003Cli>Claude and OpenAI model support\u003C\u002Fli>\n\u003Cli>OAuth 2.0 authentication for MCP connections\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Four Ways to Connect\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\u003Cstrong>Admin Chat\u003C\u002Fstrong> – Built-in interface using your Anthropic or OpenAI API key\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Claude Custom Connector\u003C\u002Fstrong> – Connect Claude Desktop using your Claude subscription (no API key needed)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>ChatGPT Developer Mode\u003C\u002Fstrong> – Connect ChatGPT using the built-in MCP endpoint with OAuth\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Local MCP Config\u003C\u002Fstrong> – Connect Claude Code and other apps using API key or Claude account\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Requirements\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>WordPress 6.2+, PHP 7.4+\u003C\u002Fli>\n\u003Cli>Anthropic API key, OpenAI API key, or Claude account (depending on connection method)\u003C\u002Fli>\n\u003Cli>HTTPS required for MCP OAuth 2.0 connections\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>This plugin connects to external API services.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>This plugin communicates with Anthropic’s Claude API (https:\u002F\u002Fapi.anthropic.com) and\u002For OpenAI’s API (https:\u002F\u002Fapi.openai.com) to provide AI functionality. Data is only sent when you actively use the chat interface or MCP tools. No background data collection or telemetry occurs.\u003C\u002Fp>\n\u003Ch4>Data Sent\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Chat messages and prompts\u003C\u002Fli>\n\u003Cli>Memory contents\u003C\u002Fli>\n\u003Cli>Abilities execution requests and results\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Legal & Privacy\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Anthropic Privacy Policy: https:\u002F\u002Fwww.anthropic.com\u002Flegal\u002Fprivacy\u003C\u002Fli>\n\u003Cli>Anthropic Terms: https:\u002F\u002Fwww.anthropic.com\u002Flegal\u002Fconsumer-terms\u003C\u002Fli>\n\u003Cli>OpenAI Privacy Policy: https:\u002F\u002Fopenai.com\u002Fpolicies\u002Fprivacy-policy\u003C\u002Fli>\n\u003Cli>OpenAI Terms: https:\u002F\u002Fopenai.com\u002Fpolicies\u002Fterms-of-use\u003C\u002Fli>\n\u003Cli>Abilities Bridge Privacy Policy: https:\u002F\u002Faisystemadmin.com\u002Fprivacy-policy\u003C\u002Fli>\n\u003Cli>Abilities Bridge Terms: https:\u002F\u002Faisystemadmin.com\u002Fterms-and-conditions\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>By using this plugin, you acknowledge that data will be transmitted to your selected AI provider for processing.\u003C\u002Fp>\n\u003Ch3>Privacy & Security\u003C\u002Fh3>\n\u003Ch4>Data Transmission\u003C\u002Fh4>\n\u003Cp>This plugin sends data to Anthropic’s API (https:\u002F\u002Fapi.anthropic.com) or OpenAI’s API (https:\u002F\u002Fapi.openai.com) when you interact with the AI. This includes chat messages, memory contents, and abilities execution requests. You control what data is sent – the AI only accesses data when you use it.\u003C\u002Fp>\n\u003Ch4>Security\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Permission controls with explicit consent for all write capabilities\u003C\u002Fli>\n\u003Cli>7-gate ability authorization system\u003C\u002Fli>\n\u003Cli>Isolated memory storage with size limits (50MB total)\u003C\u002Fli>\n\u003Cli>Full activity logging and audit trails\u003C\u002Fli>\n\u003Cli>OAuth tokens encrypted with AES-256-CBC\u003C\u002Fli>\n\u003Cli>MCP access requires authentication for every method, including discovery (initialize, tools\u002Flist, ping); unauthenticated requests receive an HTTP 401 OAuth challenge\u003C\u002Fli>\n\u003Cli>All admin actions protected with nonce verification and capability checks\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Data Retention\u003C\u002Fh4>\n\u003Cp>Conversations and logs are stored in your WordPress database until manually deleted. Refer to your provider’s privacy policy for their data retention practices.\u003C\u002Fp>\n\u003Ch4>No Telemetry\u003C\u002Fh4>\n\u003Cp>This plugin does NOT send usage statistics, telemetry, or analytics to the plugin developer.\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>For support, visit https:\u002F\u002Faisystemadmin.com\u003C\u002Fp>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This plugin is licensed under the GPL v2 or later.\u003C\u002Fp>\n","MCP server for WordPress. Connect Claude AI or OpenAI to execute WordPress Abilities with configurable permissions.",1475,1,"2026-06-04T05:53:00.000Z","6.9.5","6.2",[19,20,70,22,88],"openai","https:\u002F\u002Faisystemadmin.com\u002Fabilities-bridge\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fabilities-bridge.1.3.2.zip",{"slug":92,"name":93,"version":94,"author":95,"author_profile":96,"description":97,"short_description":98,"active_installs":34,"downloaded":99,"rating":13,"num_ratings":13,"last_updated":100,"tested_up_to":15,"requires_at_least":101,"requires_php":102,"tags":103,"homepage":107,"download_link":108,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"webo-mcp","WEBO MCP","2.6.16","phuongwebo","https:\u002F\u002Fprofiles.wordpress.org\u002Fphuongwebo\u002F","\u003Cp>\u003Cstrong>WEBO MCP\u003C\u002Fstrong> is a WordPress MCP server — a complete \u003Cstrong>Model Context Protocol\u003C\u002Fstrong> gateway for WordPress. It lets AI agents and MCP-compatible clients (Claude Desktop, Cursor, Windsurf, n8n, and more) call well-defined tools over REST using JSON-RPC, instead of scraping the admin or sharing broad credentials.\u003C\u002Fp>\n\u003Cp>Official WEBO MCP website, documentation, and ecosystem hub: https:\u002F\u002Fwebomcp.com\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Why use WEBO MCP as your WordPress MCP server?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Token-optimized unified tools:\u003C\u002Fstrong> every domain exposes two abilities — \u003Ccode>*-query\u003C\u002Fcode> (all reads) and \u003Ccode>*-mutate\u003C\u002Fcode> (all writes) — with a single \u003Ccode>action\u003C\u002Fcode> discriminator. \u003Ccode>tools\u002Flist\u003C\u002Fcode> payload is up to 70% smaller than per-operation APIs, which means less of the model’s context window is consumed by tool schemas, lower cost per session, and fewer hallucinated tool names.\u003C\u002Fli>\n\u003Cli>Primary router endpoint: \u003Ccode>POST \u002Fwp-json\u002Fmcp\u002Fv1\u002Frouter\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Standard MCP-style flow: \u003Ccode>initialize\u003C\u002Fcode> \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Ccode>tools\u002Flist\u003C\u002Fcode> \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Ccode>tools\u002Fcall\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Session lifecycle for clients (pass \u003Ccode>session_id\u003C\u002Fcode> or \u003Ccode>Mcp-Session-Id\u003C\u002Fcode> after \u003Ccode>initialize\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>Built-in tool registry for common WordPress operations (posts, media, terms, menus, options, and more)\u003C\u002Fli>\n\u003Cli>Bundled Abilities API + MCP Adapter integration, with automatic bridging from registered abilities to MCP tools (configurable)\u003C\u002Fli>\n\u003Cli>WordPress 7.0\u002FCore-aware bridge mode that uses Core Abilities\u002FAPI surfaces when available and falls back only when needed\u003C\u002Fli>\n\u003Cli>Public tool policy controls (category filters and optional allowlists) plus optional internal tool exposure for private environments\u003C\u002Fli>\n\u003Cli>Bounded MCP audit log, optional per-user\u002Frole\u002Fclient tool allowlists, and a read-only administrator health\u002Fstatus tool\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Security model (high level)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>MCP access requires a real WordPress user context: Application Password over HTTP Basic, or an existing logged-in session.\u003C\u002Fli>\n\u003Cli>Optional site-wide or per-user API key and HMAC can be enabled in Settings as an additional gate (they do not replace WordPress authentication). Generate\u002Frotate from Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Security; by default they are skipped for Application Password and Bearer clients unless you enable “Require for App Password \u002F Bearer”. Do not put the normal WEBO API key in URLs. For clients that cannot send headers, create a short-lived scoped \u003Ccode>mcp_token\u003C\u002Fcode> URL connector token in Settings -> WEBO MCP.\u003C\u002Fli>\n\u003Cli>Default access expectations for the router and \u003Ccode>GET \u002Fwp-json\u002Fwebo-mcp\u002Fv1\u002Ftools\u003C\u002Fcode>: users who are super admins, can \u003Ccode>manage_options\u003C\u002Fcode>, or can \u003Ccode>edit_posts\u003C\u002Fcode>, consistent with typical site operator and editor workflows (filterable).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Client guidance\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Always discover tools before calling them: run \u003Ccode>tools\u002Flist\u003C\u002Fcode>, pick an exact tool name from the response, validate required arguments, then call \u003Ccode>tools\u002Fcall\u003C\u002Fcode>. This reduces mistakes and keeps automation predictable in production.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Further documentation and optional integrations\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Official website, documentation, and ecosystem notes: https:\u002F\u002Fwebomcp.com\u003C\u002Fli>\n\u003Cli>Optional n8n community node (separate package): https:\u002F\u002Fwww.npmjs.com\u002Fpackage\u002Fn8n-nodes-webo-mcp\u003C\u002Fli>\n\u003Cli>Release notes and migration map: see docs\u002FRELEASE_NOTES_2.1.0.md and docs\u002FMIGRATION_GUIDE_2.1.0.md in the GitHub repository\u003C\u002Fli>\n\u003Cli>Cross-addon dispatcher map (granular legacy names removed from discovery): docs\u002FMCP_TOOL_MIGRATION.md\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Compatibility note: any MCP-capable client can be used; which large language model runs inside the client is outside this plugin.\u003C\u002Fp>\n\u003Cp>Standalone core tools included:\u003Cbr \u002F>\n– Site info\u003Cbr \u002F>\n– Content (posts\u002Fpages): \u003Ccode>webo\u002Fcontent-query\u003C\u002Fcode> (list, get, find-by-url, search-replace, list-revisions, get-revision; with author\u002Fdate\u002Ftaxonomy filters) and \u003Ccode>webo\u002Fcontent-mutate\u003C\u002Fcode> (create, update, delete, bulk-update-status, restore-revision, change-author)\u003Cbr \u002F>\n– Users: \u003Ccode>webo\u002Flist-users\u003C\u002Fcode> and \u003Ccode>webo\u002Fuser-mutate\u003C\u002Fcode> (add-to-blog, set-role)\u003Cbr \u002F>\n– Media: \u003Ccode>webo\u002Fmedia-query\u003C\u002Fcode> (list with search\u002FMIME\u002Fpost_id filters, get) and \u003Ccode>webo\u002Fmedia-mutate\u003C\u002Fcode> (upload, update, delete)\u003Cbr \u002F>\n– Comments: \u003Ccode>webo\u002Fcomment-query\u003C\u002Fcode> (list, get) and \u003Ccode>webo\u002Fcomment-mutate\u003C\u002Fcode> (create, update, delete)\u003Cbr \u002F>\n– Taxonomy\u002FTerms: \u003Ccode>webo\u002Ftaxonomy-query\u003C\u002Fcode> (discover, list, get) and \u003Ccode>webo\u002Ftaxonomy-mutate\u003C\u002Fcode> (create, update, delete)\u003Cbr \u002F>\n– Nav menus: list menus, list menu items (menu_order, db_id), add menu link from post (explicit post_id + menu_order required)\u003Cbr \u002F>\n– Plugins: \u003Ccode>webo\u002Fplugin-query\u003C\u002Fcode> (installed, active, updates, …) and \u003Ccode>webo\u002Fplugin-mutate\u003C\u002Fcode> (install, activate, deactivate; supports child-site \u003Ccode>site_id\u003C\u002Fcode> \u002F \u003Ccode>blog_id\u003C\u002Fcode> activation for network admins)\u003Cbr \u002F>\n– Health: \u003Ccode>webo\u002Fhealth-status\u003C\u002Fcode> (REST\u002Frouter status, Application Password support, permalinks, cron, object cache, plugin update summary, WordPress\u002FPHP versions, and redacted MCP config)\u003Cbr \u002F>\n– Client health: \u003Ccode>webo\u002Fclient-health-report\u003C\u002Fcode> (score 0–100, grade A–D, Markdown scoreboard for agency clients; hybrid foundation for Pro collectors later)\u003Cbr \u002F>\n– 404 logs: \u003Ccode>webo\u002Fget-404-logs\u003C\u002Fcode> (read-only Rank Math \u002F Redirection 404 monitor: url, hits, accessed, referrer)\u003Cbr \u002F>\n– Abilities bridge: \u003Ccode>webo\u002Fability-query\u003C\u002Fcode> and \u003Ccode>webo\u002Fability-execute\u003C\u002Fcode> in default layered mode. Only abilities with \u003Ccode>meta.mcp.public === true\u003C\u002Fcode> are visible and executable through WEBO MCP.\u003Cbr \u002F>\n– Themes: \u003Ccode>webo\u002Ftheme-query\u003C\u002Fcode> (installed themes) and \u003Ccode>webo\u002Ftheme-mutate\u003C\u002Fcode> (install from WordPress.org by slug, switch installed theme)\u003Cbr \u002F>\n– Theme context: \u003Ccode>webo\u002Ftheme-context\u003C\u002Fcode> (active theme info, block editor settings, style presets, registered blocks)\u003Cbr \u002F>\n– Block patterns: \u003Ccode>webo\u002Fblock-patterns\u003C\u002Fcode> (list\u002Fget patterns, list\u002Fget synced patterns)\u003Cbr \u002F>\n– Site stats: \u003Ccode>webo\u002Fsite-stats\u003C\u002Fcode> (overview, post counts, comment counts, user counts, media stats, activity summary)\u003Cbr \u002F>\n– Activity log: \u003Ccode>webo\u002Factivity-log\u003C\u002Fcode> (list events, summary, clear)\u003Cbr \u002F>\n– User profile: \u003Ccode>webo\u002Fuser-profile\u003C\u002Fcode> (get own profile, update display name \u002F bio \u002F preferences)\u003Cbr \u002F>\n– Site settings: \u003Ccode>webo\u002Fsite-settings\u003C\u002Fcode> (get and update the 20 most common WordPress options via MCP)\u003Cbr \u002F>\n– Content search: \u003Ccode>webo\u002Fcontent-search\u003C\u002Fcode> (full-text cross-post-type search with grouped results)\u003Cbr \u002F>\n– Menus: \u003Ccode>webo\u002Fmenu-query\u003C\u002Fcode>, \u003Ccode>webo\u002Fmenu-mutate\u003C\u002Fcode> (navigation menu items; not post\u002FCPT list order)\u003Cbr \u002F>\n– Post\u002FCPT order (optional): \u003Ccode>webo\u002Freorder-query\u003C\u002Fcode>, \u003Ccode>webo\u002Freorder-mutate\u003C\u002Fcode> when \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fmrphuong-webo\u002Fwebo-reorder\" rel=\"nofollow ugc\">Webo Reorder\u003C\u002Fa> is active — see docs\u002Fabilities\u002Freorder.md\u003Cbr \u002F>\n– Options: get\u002Fupdate (safe allowlist only), set site icon\u002Ffavicon from media\u003Cbr \u002F>\n– SEO (WordPress post): seo\u002Farticle-analysis — requires post_id; merges Rank Math meta when available (same data path as webo-rank-math\u002Fget-post-seo-meta); optional related-keyword suggestions via outbound request unless no_autocomplete is true\u003C\u002Fp>\n\u003Cp>Excluded by default in standalone-safe mode:\u003Cbr \u002F>\n– Bulk\u002Fmass execution tools\u003Cbr \u002F>\n– Plugin\u002Ftheme write-management abilities\u003Cbr \u002F>\n– Multisite-specific abilities\u003C\u002Fp>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>This plugin does not phone home or send telemetry. MCP traffic is initiated by clients you configure. Some tools may perform outbound HTTP requests only when a client invokes them (for example seo\u002Farticle-analysis may request keyword suggestions from a third-party suggest API unless you pass no_autocomplete).\u003C\u002Fp>\n\u003Cp>The plugin stores the following options in the WordPress database when configured:\u003Cbr \u002F>\n– \u003Ccode>webo_mcp_api_key\u003C\u002Fcode>: API key used to authenticate MCP requests.\u003Cbr \u002F>\n– \u003Ccode>webo_mcp_hmac_secret\u003C\u002Fcode>: HMAC secret used to sign and validate MCP requests.\u003Cbr \u002F>\n– \u003Ccode>webo_mcp_require_secondary_credentials\u003C\u002Fcode>: when enabled, also require API key\u002FHMAC for Application Password and Bearer clients (off by default so standard connectors are not blocked).\u003Cbr \u002F>\n– \u003Ccode>webo_mcp_url_connector_tokens\u003C\u002Fcode>: hashed, expirable, revocable URL connector tokens for clients that cannot send headers. Raw tokens are shown once and are not stored.\u003Cbr \u002F>\n– \u003Ccode>webo_mcp_tool_allowlist_enabled\u003C\u002Fcode> and \u003Ccode>webo_mcp_tool_allowlist_rules\u003C\u002Fcode>: optional administrator-configured MCP tool allowlist policy.\u003Cbr \u002F>\n– \u003Ccode>webo_mcp_audit_log_enabled\u003C\u002Fcode>, \u003Ccode>webo_mcp_audit_log_max_entries\u003C\u002Fcode>, and \u003Ccode>webo_mcp_audit_log\u003C\u002Fcode>: bounded MCP tool-call audit log settings and compact audit events. Audit entries include user\u002Ftool\u002Faction\u002Fstatus data, anonymized IPs, and hashed session IDs; they do not store request payloads, API keys, HMAC secrets, or Application Passwords.\u003Cbr \u002F>\n– \u003Ccode>webo_mcp_installed_at\u003C\u002Fcode> and \u003Ccode>webo_mcp_review_notice\u003C\u002Fcode>: local timestamps\u002Fstate for an optional WordPress.org review request notice (not sent off-site; dismissible).\u003C\u002Fp>\n\u003Cp>These options are removed when the plugin is uninstalled via the WordPress Plugins screen.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin can connect to Google Suggest (Autocomplete) when a client calls the \u003Ccode>seo\u002Farticle-analysis\u003C\u002Fcode> tool and does not set \u003Ccode>no_autocomplete\u003C\u002Fcode> to true. This external request is used to return related keyword suggestions for SEO analysis.\u003C\u002Fp>\n\u003Cp>Service provider: Google LLC (Google Suggest \u002F Autocomplete API endpoint).\u003C\u002Fp>\n\u003Cp>Data sent and when:\u003Cbr \u002F>\n– Sent only when \u003Ccode>seo\u002Farticle-analysis\u003C\u002Fcode> is called with autocomplete enabled.\u003Cbr \u002F>\n– Sends the analysis query text to \u003Ccode>https:\u002F\u002Fsuggestqueries.google.com\u002Fcomplete\u002Fsearch\u003C\u002Fcode> as the \u003Ccode>q\u003C\u002Fcode> parameter.\u003Cbr \u002F>\n– Sends standard HTTP request metadata such as IP address and User-Agent as part of the web request.\u003C\u002Fp>\n\u003Cp>Terms of Service: https:\u002F\u002Fpolicies.google.com\u002Fterms\u003Cbr \u002F>\nPrivacy Policy: https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fp>\n\u003Ch3>Developer Hooks\u003C\u002Fh3>\n\u003Cp>The plugin exposes the following actions and filters for developers:\u003C\u002Fp>\n\u003Ch3>Actions\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Ccode>webo_mcp_register_tools\u003C\u002Fcode>\u003Cbr \u002F>\nFired during plugin bootstrap after standalone tools are registered. Use this to register custom MCP tools from other plugins.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Filters\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Ccode>webo_mcp_current_user_can_use_mcp\u003C\u002Fcode> (bool $allowed, int $user_id)\u003Cbr \u002F>\nGate for all MCP REST access. Default: super admin OR \u003Ccode>manage_options\u003C\u002Fcode> OR \u003Ccode>edit_posts\u003C\u002Fcode>. Override to tighten (e.g. super-admin only) in hardened installs.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ccode>webo_mcp_secondary_credentials_exempt\u003C\u002Fcode> (bool $exempt, WP_REST_Request $request)\u003Cbr \u002F>\nWhen true, skip optional API key \u002F HMAC after WordPress auth. Default true for Application Password (Basic) and Bearer sessions unless Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Security \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> “Require for App Password \u002F Bearer” is enabled. Return false to always enforce \u003Ccode>X-WEBO-*\u003C\u002Fcode> headers.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ccode>webo_mcp_allow_internal_tools\u003C\u002Fcode> (bool $allow_internal, WP_REST_Request $request)\u003Cbr \u002F>\nControls whether internal tools are included in tools\u002Flist responses. Defaults to false for public environments.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ccode>webo_mcp_public_categories\u003C\u002Fcode> (array $categories, WP_REST_Request $request, array $tool)\u003Cbr \u002F>\nFilters which tool categories are exposed as public. Defaults to array( ‘wordpress’ ).\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ccode>webo_mcp_rate_limit_per_hour\u003C\u002Fcode> (int $limit, string $client, array|null $profile)\u003Cbr \u002F>\nAdjust effective hourly limit (fallback for both buckets).\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ccode>webo_mcp_rate_limit_read_per_hour\u003C\u002Fcode> \u002F \u003Ccode>webo_mcp_rate_limit_mutate_per_hour\u003C\u002Fcode> (int $limit, string $client, array|null $profile)\u003Cbr \u002F>\nPer-bucket limits after admin\u002Fprofile resolution.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ccode>webo_mcp_tool_is_mutating\u003C\u002Fcode> (bool $is_mutating, string $tool_name, array|null $tool_definition, array $arguments)\u003Cbr \u002F>\nOverride mutating classification for rate limits and read-only profiles.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ccode>webo_mcp_tool_arguments_allow_extra\u003C\u002Fcode> (bool $allow, string $tool_name, array $schema, array $arguments)\u003Cbr \u002F>\nWhen true, unknown tool argument keys are passed through (default false).\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ccode>webo_mcp_disallow_url_token_query\u003C\u002Fcode> (bool $disallowed)\u003Cbr \u002F>\nBlock URL connector tokens in query strings (admin setting is the default source).\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ccode>webo_mcp_rest_bom_guard_json_api_requests\u003C\u002Fcode> (bool $activate, string $uri_raw)\u003Cbr \u002F>\nOpt-in BOM sanitizer for all \u003Ccode>\u002Fwp-json\u002F\u003C\u002Fcode> responses (default false; MCP routes only).\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ccode>webo_mcp_bridge_deny_patterns\u003C\u002Fcode> (array $patterns)\u003Cbr \u002F>\nControls which abilities are excluded when auto-bridging abilities into MCP tools (e.g. bulk, themes\u002F, multisite\u002F).\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ccode>webo_mcp_auto_bridge_abilities\u003C\u002Fcode> (bool $enabled)\u003Cbr \u002F>\nEnables or disables automatic bridging of registered abilities into MCP tools. Defaults to true; bridge mode still controls whether the bridge is off, layered, or full.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ccode>webo_mcp_bridge_mode\u003C\u002Fcode> (string $mode)\u003Cbr \u002F>\nControls Abilities bridge mode after the \u003Ccode>WEBO_MCP_BRIDGE_MODE\u003C\u002Fcode> constant and before the stored option. Values: \u003Ccode>off\u003C\u002Fcode>, \u003Ccode>layered\u003C\u002Fcode>, \u003Ccode>full\u003C\u002Fcode>. Default: \u003Ccode>layered\u003C\u002Fcode>.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ccode>webo_mcp_enable_adapter\u003C\u002Fcode> (bool $enabled)\u003Cbr \u002F>\nEnables or disables the bundled WordPress MCP Adapter runtime. Defaults to true.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ccode>webo_mcp_validate_media_fetch_url\u003C\u002Fcode> (true|\\WP_Error $ok, string $url, array $parsed)\u003Cbr \u002F>\nReject unsafe URLs for webo\u002Fmedia-mutate upload action (return WP_Error to block).\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ccode>webo_mcp_tool_allowlist_allowed\u003C\u002Fcode> (bool $allowed, string $tool_name, WP_REST_Request $request, array $params, array $allowed_tools)\u003Cbr \u002F>\nFilters the optional per-user\u002Frole\u002Fclient allowlist decision.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Credits\u003C\u002Fh3>\n\u003Cp>Special thanks to the authors and open source projects that contributed to this plugin:\u003Cbr \u002F>\n– WordPress (https:\u002F\u002Fwordpress.org)\u003Cbr \u002F>\n– Abilities API (https:\u002F\u002Fgithub.com\u002FWordPress\u002Fabilities-api)\u003Cbr \u002F>\n  Reference: https:\u002F\u002Fmake.wordpress.org\u002Fai\u002F2025\u002F07\u002F17\u002Fabilities-api\u002F\u003Cbr \u002F>\n– MCP Adapter (https:\u002F\u002Fgithub.com\u002FWordPress\u002Fmcp-adapter)\u003Cbr \u002F>\n  Reference: https:\u002F\u002Fmake.wordpress.org\u002Fai\u002F2025\u002F07\u002F17\u002Fmcp-adapter\u002F\u003Cbr \u002F>\n– Composer (https:\u002F\u002Fgetcomposer.org)\u003Cbr \u002F>\n– Other PHP and JS libraries from the community\u003C\u002Fp>\n\u003Cp>If you use this plugin, please give credit to the authors of these libraries.\u003C\u002Fp>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This plugin is licensed under the GPLv2 or later.\u003Cbr \u002F>\nSee https:\u002F\u002Fwww.gnu.org\u002Flicenses\u002Fgpl-2.0.html for details.\u003C\u002Fp>\n","WordPress MCP server for AI agents and automation, with JSON-RPC tools over REST for Claude, Cursor, n8n, and MCP clients.",1845,"2026-07-17T07:44:00.000Z","6.4","8.0",[104,105,106,22,23],"ai-agent","automation","json-rpc","https:\u002F\u002Fwebomcp.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwebo-mcp.2.6.16.zip",{"slug":110,"name":111,"version":112,"author":113,"author_profile":114,"description":115,"short_description":116,"active_installs":117,"downloaded":118,"rating":13,"num_ratings":13,"last_updated":119,"tested_up_to":50,"requires_at_least":16,"requires_php":17,"tags":120,"homepage":123,"download_link":124,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":125},"ai-workflow-automation-ai-agent-hub","AI Workflow Automation – AI Agent Hub","1.5.0","Azizul Hasan","https:\u002F\u002Fprofiles.wordpress.org\u002Fhasanazizul\u002F","\u003Cp>AI Agent Hub is the most complete AI integration plugin for WordPress. It provides \u003Cstrong>80+ abilities\u003C\u002Fstrong> across 10 modules, a built-in \u003Cstrong>MCP (Model Context Protocol)\u003C\u002Fstrong> server for AI agent connectivity, \u003Cstrong>AI experiments\u003C\u002Fstrong> directly in the Gutenberg block editor, \u003Cstrong>role-based access control\u003C\u002Fstrong>, \u003Cstrong>JWT authentication\u003C\u002Fstrong>, a \u003Cstrong>workflow builder\u003C\u002Fstrong>, and full \u003Cstrong>WooCommerce\u003C\u002Fstrong> support.\u003C\u002Fp>\n\u003Ch4>Highlights\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>80+ registered abilities\u003C\u002Fstrong> covering posts, pages, media, users, custom post types, REST API discovery, site diagnostics, WordPress settings, WooCommerce, and AI-powered content analysis.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>11 independently toggleable modules\u003C\u002Fstrong> – enable only what you need.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Error Debugger\u003C\u002Fstrong> – Monitor PHP errors in real time, receive email alerts with a one-click fix command, and fix errors directly from your AI assistant via MCP (Pro).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI Experiments in the Block Editor\u003C\u002Fstrong> – Generate excerpts, feature images, and more directly from the post editor with multi-provider AI support.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built-in MCP server\u003C\u002Fstrong> – expose abilities as tools, resources, and prompts to AI agents over JSON-RPC 2.0.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>External Abilities\u003C\u002Fstrong> – automatically discovers and integrates abilities from WordPress core and third-party plugins via the Abilities API.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>JWT authentication\u003C\u002Fstrong> – secure MCP and REST API access with token-based auth.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Workflow builder\u003C\u002Fstrong> – combine abilities into reusable workflows from the admin dashboard or the post editor meta box.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-provider AI\u003C\u002Fstrong> – connect OpenAI, Google Gemini, or Anthropic Claude via the WordPress AI Client.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Role-based access control\u003C\u002Fstrong> – assign abilities per WordPress role so each MCP connection only exposes what that user is allowed to use.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Backward compatible\u003C\u002Fstrong> – bundles the WordPress Abilities API and MCP Adapter as vendor dependencies, so it works on WordPress 6.8+ (not just 6.9+ where these APIs ship in core).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>AI Agent Hub Pro\u003C\u002Fh4>\n\u003Cp>Unlock the full power of AI Agent Hub with \u003Ca href=\"https:\u002F\u002Fatlasaidev.com\u002Fai-agent-hub-pro\u002F\" rel=\"nofollow ugc\">AI Agent Hub Pro\u003C\u002Fa>:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Unlimited Workflows\u003C\u002Fstrong> – Create unlimited MCP workflows (free: 3 max).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>T\u002FR\u002FP Access Modes\u003C\u002Fstrong> – Granular per-ability Tool\u002FResource\u002FPrompt toggles for fine-grained MCP control.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced AI Experiments\u003C\u002Fstrong> – Templates library, batch generation mode, explain AI reasoning, generation history, and keyboard shortcuts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Workflow Prompt Builders\u003C\u002Fstrong> – 6 pre-built prompt builder workflows (SEO Audit, Content Brief, Site Overview, and more).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>External Abilities\u003C\u002Fstrong> – Discover and expose third-party plugin abilities via the Abilities API.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Per-Ability RBAC\u003C\u002Fstrong> – Assign individual abilities (not just modules) to each WordPress role.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>MCP Fix Command\u003C\u002Fstrong> – Error emails include a ready-to-paste MCP command that lets your AI assistant read, analyse, and fix the error with one paste — automatic backup included.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Webhook Notifications\u003C\u002Fstrong> – Send error alerts to Slack, Discord, or a custom webhook.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Backups Manager\u003C\u002Fstrong> – All AI-applied fixes are backed up automatically; restore any backup with one click.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Priority Support\u003C\u002Fstrong> – Direct support from the development team.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fatlasaidev.com\u002Fai-agent-hub-pro\u002F\" rel=\"nofollow ugc\">Upgrade to Pro\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>Modules\u003C\u002Fh4>\n\u003Cp>Each module can be independently enabled or disabled from the \u003Cstrong>AI Agent Hub\u003C\u002Fstrong> dashboard.\u003C\u002Fp>\n\u003Ch3>1. AI Content Steward (8 abilities)\u003C\u002Fh3>\n\u003Cp>AI-powered content analysis, generation, and improvement for posts and pages.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>awfah-content\u002Fanalyze-post\u003C\u002Fcode> – Summarize a post with readability and improvement suggestions.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-content\u002Fgenerate-feature-image\u003C\u002Fcode> – Generate an AI feature image and set it as the post’s featured image.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-content\u002Fgenerate-excerpt\u003C\u002Fcode> – Create a concise, SEO-friendly excerpt.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-content\u002Ffocus-keywords\u003C\u002Fcode> – Extract relevant focus keywords for SEO targeting.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-content\u002Flsi-keywords\u003C\u002Fcode> – Generate related LSI keyword ideas.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-content\u002Fsuggest-titles\u003C\u002Fcode> – Generate alternative title ideas.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-content\u002Fsummarize\u003C\u002Fcode> – Generate a content summary for a post.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-content\u002Fgenerate-alt-text\u003C\u002Fcode> – Generate accessible alt text for images using vision AI.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>2. Posts Manager (13 abilities)\u003C\u002Fh3>\n\u003Cp>Full CRUD for WordPress posts, categories, and tags.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>awfah-posts\u002Fwp-posts-search\u003C\u002Fcode> – Search and filter posts with pagination.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-posts\u002Fwp-get-post\u003C\u002Fcode> – Get a post by ID.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-posts\u002Fwp-add-post\u003C\u002Fcode> – Create a new post.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-posts\u002Fwp-update-post\u003C\u002Fcode> – Update an existing post.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-posts\u002Fwp-delete-post\u003C\u002Fcode> – Delete a post.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-posts\u002Fwp-list-categories\u003C\u002Fcode> – List all post categories.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-posts\u002Fwp-add-category\u003C\u002Fcode> – Add a new category.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-posts\u002Fwp-update-category\u003C\u002Fcode> – Update a category.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-posts\u002Fwp-delete-category\u003C\u002Fcode> – Delete a category.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-posts\u002Fwp-list-tags\u003C\u002Fcode> – List all post tags.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-posts\u002Fwp-add-tag\u003C\u002Fcode> – Add a new tag.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-posts\u002Fwp-update-tag\u003C\u002Fcode> – Update a tag.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-posts\u002Fwp-delete-tag\u003C\u002Fcode> – Delete a tag.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>3. Pages Manager (5 abilities)\u003C\u002Fh3>\n\u003Cp>CRUD operations for WordPress pages.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>awfah-pages\u002Fwp-pages-search\u003C\u002Fcode> – Search and filter pages with pagination.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-pages\u002Fwp-get-page\u003C\u002Fcode> – Get a page by ID.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-pages\u002Fwp-add-page\u003C\u002Fcode> – Create a new page.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-pages\u002Fwp-update-page\u003C\u002Fcode> – Update an existing page.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-pages\u002Fwp-delete-page\u003C\u002Fcode> – Delete a page.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>4. Media Manager (7 abilities)\u003C\u002Fh3>\n\u003Cp>Upload, update, and manage media files.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>awfah-media\u002Fwp-media-search\u003C\u002Fcode> – Search and filter media with pagination.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-media\u002Fwp-get-media\u003C\u002Fcode> – Get a media item by ID.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-media\u002Fwp-upload-media\u003C\u002Fcode> – Upload a new media file (base64 or URL).\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-media\u002Fwp-update-media\u003C\u002Fcode> – Update media metadata (title, alt text, caption).\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-media\u002Fwp-delete-media\u003C\u002Fcode> – Delete a media item.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-media\u002Fwp-get-media-sizes\u003C\u002Fcode> – Get all available image sizes for a media item.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-media\u002Fwp-get-media-file\u003C\u002Fcode> – Get the actual file content of a media item.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>5. Users Manager (7 abilities)\u003C\u002Fh3>\n\u003Cp>Search, create, and manage WordPress users.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>awfah-users\u002Fwp-users-search\u003C\u002Fcode> – Search and filter users.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-users\u002Fwp-get-user\u003C\u002Fcode> – Get a user by ID.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-users\u002Fwp-create-user\u003C\u002Fcode> – Create a new user.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-users\u002Fwp-update-user\u003C\u002Fcode> – Update a user.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-users\u002Fwp-delete-user\u003C\u002Fcode> – Delete a user.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-users\u002Fwp-get-current-user\u003C\u002Fcode> – Get the currently authenticated user.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-users\u002Fwp-list-roles\u003C\u002Fcode> – List all available user roles.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>6. Custom Post Types Manager (6 abilities)\u003C\u002Fh3>\n\u003Cp>CRUD operations for any registered custom post type.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>awfah-cpt\u002Fwp-list-post-types\u003C\u002Fcode> – List all registered post types.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-cpt\u002Fwp-cpt-search\u003C\u002Fcode> – Search items of a specific post type.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-cpt\u002Fwp-cpt-get\u003C\u002Fcode> – Get a single CPT item by ID.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-cpt\u002Fwp-cpt-add\u003C\u002Fcode> – Create a new CPT item.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-cpt\u002Fwp-cpt-update\u003C\u002Fcode> – Update a CPT item.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-cpt\u002Fwp-cpt-delete\u003C\u002Fcode> – Delete a CPT item.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>7. REST API Tools (3 abilities)\u003C\u002Fh3>\n\u003Cp>Discover and execute any WordPress REST API endpoint dynamically.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>awfah-rest-api\u002Flist-api-functions\u003C\u002Fcode> – List all available REST API endpoints that support CRUD.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-rest-api\u002Fget-function-details\u003C\u002Fcode> – Get detailed metadata for a specific endpoint and method.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-rest-api\u002Frun-api-function\u003C\u002Fcode> – Execute any REST API endpoint with provided parameters.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>8. Site Info & Diagnostics (4 abilities)\u003C\u002Fh3>\n\u003Cp>View site info, plugins, themes, and users at a glance.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>awfah-site\u002Fget-site-info\u003C\u002Fcode> – Detailed info about the WordPress site (name, URL, version, plugins, themes, users).\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-site\u002Fget-plugin-info\u003C\u002Fcode> – Info about active plugins.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-site\u002Fget-theme-info\u003C\u002Fcode> – Info about the active theme.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-site\u002Fget-user-info\u003C\u002Fcode> – Info about the current authenticated user.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>9. Settings Manager (3 abilities)\u003C\u002Fh3>\n\u003Cp>View and update WordPress site settings.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>awfah-settings\u002Fwp-get-settings\u003C\u002Fcode> – Get WordPress general site settings.\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-settings\u002Fwp-update-settings\u003C\u002Fcode> – Update general settings (title, tagline, timezone, etc.).\u003C\u002Fli>\n\u003Cli>\u003Ccode>awfah-settings\u002Fget-site-settings\u003C\u002Fcode> – Get all settings including reading, discussion, media, permalinks, and privacy.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>10. AI Store Manager – WooCommerce (24 abilities)\u003C\u002Fh3>\n\u003Cp>Full WooCommerce management through AI. Requires WooCommerce to be active.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Products: search, get, add, update, delete.\u003C\u002Fli>\n\u003Cli>Product categories: list, add, update, delete.\u003C\u002Fli>\n\u003Cli>Product tags: list, add, update, delete.\u003C\u002Fli>\n\u003Cli>Product brands: list, add, update, delete.\u003C\u002Fli>\n\u003Cli>Orders: search.\u003C\u002Fli>\n\u003Cli>Reports: coupons totals, customers totals, orders totals, products totals, reviews totals, sales.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>11. Error Debugger\u003C\u002Fh3>\n\u003Cp>Monitor PHP errors in real time and fix them faster. Works out of the box — no configuration required to start tracking errors.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Free features:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Real-time PHP error tracking grouped by file and message.\u003Cbr \u002F>\n* Email notifications for errors in plugins and themes — configurable recipient, severity levels, and rate limit.\u003Cbr \u002F>\n* \u003Cstrong>Fix Command\u003C\u002Fstrong> in every email — a pre-filled text snippet you can paste into any AI assistant to get fix instructions.\u003Cbr \u002F>\n* Admin dashboard widget showing the last 5 errors and a 24-hour error count.\u003Cbr \u002F>\n* Debug log scanner catches errors that occur before the plugin loads (e.g. fatal parse errors during activation).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Pro features (requires AI Agent Hub Pro):\u003C\u002Fstrong>\u003Cbr \u002F>\n* MCP Fix Command — paste directly into Claude Desktop, Cursor, or any connected MCP client. The AI reads the file, suggests a fix, creates a backup, and applies it.\u003Cbr \u002F>\n* Webhook notifications — send error alerts to Slack, Discord, or a custom URL.\u003Cbr \u002F>\n* Backups Manager — all AI-applied fixes are backed up; restore any backup with one click.\u003Cbr \u002F>\n* Extended error sources — monitor WordPress Core, MU-Plugins, and Drop-ins in addition to plugins and themes.\u003C\u002Fp>\n\u003Ch3>Coming Soon\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>AI Support Desk\u003C\u002Fstrong> – Summarize comment threads, suggest reply drafts, categorize support requests.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI Automation Recipes \u002F Workflows\u003C\u002Fstrong> – Rule-based AI automations triggered by WordPress events.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>AI Experiments in the Block Editor\u003C\u002Fh4>\n\u003Cp>AI Agent Hub adds AI-powered experiment panels directly into the WordPress block editor:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Excerpt Generation\u003C\u002Fstrong> – Generate SEO-friendly excerpts from post content with one click. Appears in the post sidebar excerpt panel.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Image Generation\u003C\u002Fstrong> – Generate AI feature images from post content. Integrated into the Featured Image panel.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>With \u003Ca href=\"https:\u002F\u002Fatlasaidev.com\u002Fai-agent-hub-pro\u002F\" rel=\"nofollow ugc\">AI Agent Hub Pro\u003C\u002Fa>, experiments gain advanced features: prompt templates library, batch generation mode, “Explain This Generation” reasoning, generation history, and keyboard shortcuts.\u003C\u002Fp>\n\u003Ch4>Error Debugger\u003C\u002Fh4>\n\u003Cp>The \u003Cstrong>Error Debugger\u003C\u002Fstrong> module monitors PHP errors on your WordPress site and helps you fix them faster.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>How it works:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Enable the \u003Cstrong>Error Debugger\u003C\u002Fstrong> module from the AI Agent Hub dashboard.\u003C\u002Fli>\n\u003Cli>Optionally enable \u003Cstrong>Email Notifications\u003C\u002Fstrong> and configure the recipient address, severity levels, and rate limit.\u003C\u002Fli>\n\u003Cli>When a PHP error occurs in a plugin or theme, an email is sent with full error details and a \u003Cstrong>How to Fix\u003C\u002Fstrong> block.\u003C\u002Fli>\n\u003Cli>Copy the fix command from the email and paste it into your AI assistant to get step-by-step fix instructions.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>Free fix flow:\u003C\u002Fstrong>\u003Cbr \u002F>\nCopy the pre-filled text from the email \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> paste into ChatGPT, Claude, Gemini, or any AI chat \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> the AI explains the error and how to fix it.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Pro fix flow (MCP):\u003C\u002Fstrong>\u003Cbr \u002F>\nCopy the MCP command block from the email \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> paste into Claude Desktop, Cursor, or any MCP client connected to your site \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> the AI reads the file, suggests a fix, creates a backup, and applies it automatically.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Admin dashboard widget:\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen the Error Debugger module is active, a \u003Cstrong>“AI Agent Hub — Recent Errors”\u003C\u002Fstrong> widget appears on the WordPress admin dashboard showing the last 5 errors and a 24-hour error count. You can disable the widget from the Error Debugger settings without disabling the module.\u003C\u002Fp>\n\u003Ch4>Connecting AI Agents via MCP\u003C\u002Fh4>\n\u003Cp>AI Agent Hub includes a built-in \u003Cstrong>MCP (Model Context Protocol)\u003C\u002Fstrong> server that lets external AI agents interact with your WordPress site. The MCP endpoint is:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>https:\u002F\u002Fyour-site.com\u002Fwp-json\u002Fawfah_mcp\u002Fmcp\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Any MCP-compatible AI client can connect and use all enabled abilities as tools, resources, and prompts.\u003C\u002Fp>\n\u003Ch4>AI Agent Hub Dashboard\u003C\u002Fh4>\n\u003Cp>The plugin adds a top-level \u003Cstrong>“AI Agent Hub”\u003C\u002Fstrong> menu in WordPress admin with:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>Connected AI Agents\u003C\u002Fstrong> – shows which AI providers are available (Auto, OpenAI, Gemini, Claude) and their status.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Modules & Features\u003C\u002Fstrong> – 10 module cards with independent on\u002Foff toggles.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Workflow Builder\u003C\u002Fstrong> – search abilities, drag them into a workflow, preview the prompt, and save.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Access Control\u003C\u002Fstrong> – assign abilities and workflows per WordPress role.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Documentation\u003C\u002Fstrong> – built-in getting started guide with Pro features overview.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Contact Support\u003C\u002Fstrong> – direct link to support.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Post Editor Meta Box\u003C\u002Fh4>\n\u003Cp>On every post and page edit screen, the \u003Cstrong>AI Content Steward\u003C\u002Fstrong> meta box provides:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Provider selection (Auto, OpenAI, Gemini, Claude).\u003C\u002Fli>\n\u003Cli>Ability checkboxes to select which analyses to run.\u003C\u002Fli>\n\u003Cli>Editable prompt preview that updates as you select abilities.\u003C\u002Fli>\n\u003Cli>One-click workflow execution.\u003C\u002Fli>\n\u003Cli>Save workflows for reuse.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Connecting AI Agents\u003C\u002Fh3>\n\u003Ch4>Claude Desktop\u003C\u002Fh4>\n\u003Cp>Claude Desktop supports MCP servers natively. To connect it to your WordPress site:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Step 1: Generate a JWT token\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Send a POST request to your site to get a JWT token:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>curl -X POST \"https:\u002F\u002Fyour-site.com\u002Fwp-json\u002Fjwt-auth\u002Fv1\u002Ftoken\" -H \"Content-Type: application\u002Fjson\" -d \"{\\\"username\\\":\\\"your-username\\\",\\\"password\\\":\\\"your-password\\\",\\\"expires_in\\\":2592000}\"\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>This returns a token valid for 30 days (2592000 seconds). Copy the \u003Ccode>token\u003C\u002Fcode> value from the response.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Step 2: Configure Claude Desktop\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Open the Claude Desktop config file:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Windows:\u003C\u002Fstrong> \u003Ccode>%APPDATA%\\Claude\\claude_desktop_config.json\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>macOS:\u003C\u002Fstrong> \u003Ccode>~\u002FLibrary\u002FApplication Support\u002FClaude\u002Fclaude_desktop_config.json\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Add this MCP server entry:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>{\n  \"mcpServers\": {\n    \"wordpress\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"@anthropic-ai\u002Fmcp-wordpress-remote@latest\",\n        \"--url\",\n        \"https:\u002F\u002Fyour-site.com\u002Fwp-json\u002Fawfah_mcp\u002Fmcp\"\n      ],\n      \"env\": {\n        \"JWT_TOKEN\": \"paste-your-jwt-token-here\"\n      }\n    }\n  }\n}\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>\u003Cstrong>Step 3: Restart Claude Desktop\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>After saving the config, restart Claude Desktop. All enabled abilities will appear as tools. You can then ask Claude to manage posts, pages, media, users, settings, and WooCommerce from natural language.\u003C\u002Fp>\n\u003Ch4>Claude Code (CLI)\u003C\u002Fh4>\n\u003Cp>Claude Code can also connect to MCP servers. Add the server using:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>claude mcp add wordpress -- npx -y @anthropic-ai\u002Fmcp-wordpress-remote@latest --url https:\u002F\u002Fyour-site.com\u002Fwp-json\u002Fawfah_mcp\u002Fmcp\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Then set the JWT token as an environment variable before running Claude Code:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>export JWT_TOKEN=\"paste-your-jwt-token-here\"\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>Cursor \u002F Windsurf \u002F Other MCP Clients\u003C\u002Fh4>\n\u003Cp>Any editor or AI tool that supports MCP can connect. The setup is similar:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Generate a JWT token (see above).\u003C\u002Fli>\n\u003Cli>Point the MCP client to: \u003Ccode>https:\u002F\u002Fyour-site.com\u002Fwp-json\u002Fawfah_mcp\u002Fmcp\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Use the \u003Ccode>@anthropic-ai\u002Fmcp-wordpress-remote\u003C\u002Fcode> transport package, or configure your client’s native MCP settings with the URL and JWT token.\u003C\u002Fli>\n\u003Cli>The authentication header format is: \u003Ccode>Authorization: Bearer \u003Cyour-jwt-token>\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Postman \u002F API Testing\u003C\u002Fh4>\n\u003Cp>You can test the MCP endpoint directly using Postman or any HTTP client. The MCP protocol uses JSON-RPC 2.0 over HTTP.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Step 1: Initialize a session\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Send a POST request to \u003Ccode>https:\u002F\u002Fyour-site.com\u002Fwp-json\u002Fawfah_mcp\u002Fmcp\u003C\u002Fcode> with:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Header: \u003Ccode>Authorization: Bearer \u003Cyour-jwt-token>\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Header: \u003Ccode>Content-Type: application\u002Fjson\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Body:\u003Cbr \u002F>\n{\u003Cbr \u002F>\n  “jsonrpc”: “2.0”,\u003Cbr \u002F>\n  “id”: 1,\u003Cbr \u002F>\n  “method”: “initialize”,\u003Cbr \u002F>\n  “params”: {\u003Cbr \u002F>\n    “protocolVersion”: “2024-11-05”,\u003Cbr \u002F>\n    “capabilities”: {},\u003Cbr \u002F>\n    “clientInfo”: { “name”: “postman”, “version”: “1.0” }\u003Cbr \u002F>\n  }\u003Cbr \u002F>\n}\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Copy the \u003Ccode>Mcp-Session-Id\u003C\u002Fcode> header from the response.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Step 2: Send initialized notification\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Send a POST with the session ID header:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Header: \u003Ccode>Mcp-Session-Id: \u003Csession-id-from-step-1>\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Body:\u003Cbr \u002F>\n{\u003Cbr \u002F>\n  “jsonrpc”: “2.0”,\u003Cbr \u002F>\n  “method”: “notifications\u002Finitialized”\u003Cbr \u002F>\n}\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Step 3: Call a tool\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Now you can call any ability as a tool:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>{\n  \"jsonrpc\": \"2.0\",\n  \"id\": 2,\n  \"method\": \"tools\u002Fcall\",\n  \"params\": {\n    \"name\": \"awfah-site-get-site-info\",\n    \"arguments\": {}\n  }\n}\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Note: In MCP tool names, the \u003Ccode>\u002F\u003C\u002Fcode> in ability IDs is replaced with \u003Ccode>-\u003C\u002Fcode>. So \u003Ccode>awfah-site\u002Fget-site-info\u003C\u002Fcode> becomes \u003Ccode>awfah-site-get-site-info\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Ch4>JWT Token Management\u003C\u002Fh4>\n\u003Cp>AI Agent Hub provides three JWT endpoints:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Generate token:\u003C\u002Fstrong> \u003Ccode>POST \u002Fwp-json\u002Fjwt-auth\u002Fv1\u002Ftoken\u003C\u002Fcode> – Pass \u003Ccode>username\u003C\u002Fcode>, \u003Ccode>password\u003C\u002Fcode>, and optional \u003Ccode>expires_in\u003C\u002Fcode> (seconds, min 3600, max 2592000).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>List tokens:\u003C\u002Fstrong> \u003Ccode>GET \u002Fwp-json\u002Fjwt-auth\u002Fv1\u002Ftokens\u003C\u002Fcode> – List all active tokens (requires authentication).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Revoke token:\u003C\u002Fstrong> \u003Ccode>POST \u002Fwp-json\u002Fjwt-auth\u002Fv1\u002Frevoke\u003C\u002Fcode> – Revoke a specific token (requires authentication).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Tokens are signed with HS256 using a per-site secret key stored in the \u003Ccode>awfah_jwt_secret_key\u003C\u002Fcode> option. Each token includes the user ID, issued-at time, expiration, and a unique JTI.\u003C\u002Fp>\n\u003Ch4>Role-Based MCP Access\u003C\u002Fh4>\n\u003Cp>AI Agent Hub provides \u003Cstrong>role-based access control\u003C\u002Fstrong> for MCP connections. This means different WordPress users see different abilities depending on their role.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>How it works:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>An administrator configures which abilities each WordPress role can access via the \u003Cstrong>Access Control\u003C\u002Fstrong> tab in the AI Agent Hub dashboard.\u003C\u002Fli>\n\u003Cli>When an AI client connects via MCP, it authenticates as a specific WordPress user (using JWT or Application Password).\u003C\u002Fli>\n\u003Cli>The plugin checks that user’s role and only exposes the abilities assigned to that role.\u003C\u002Fli>\n\u003Cli>The AI client can only see and execute the allowed abilities — everything else is hidden.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>Example scenarios:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Administrator\u003C\u002Fstrong> — Full access to all 80+ abilities including post CRUD, site settings, user management, media, WooCommerce, and content analysis.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Editor\u003C\u002Fstrong> — Content-focused abilities only (e.g. analyze posts, generate excerpts, suggest titles, focus keywords). No access to site settings, user management, or destructive operations.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Author \u002F Contributor\u003C\u002Fstrong> — Can be fully  &hellip;\u003C\u002Fli>\n\u003C\u002Ful>\n","AI-powered WordPress hub: 80+ abilities, MCP server, block editor AI experiments, RBAC, JWT auth, and workflows.",10,774,"2026-04-13T17:59:00.000Z",[121,20,105,22,122],"abilities-api","workflow","https:\u002F\u002Fatlasaidev.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fai-workflow-automation-ai-agent-hub.1.5.0.zip","2026-04-16T10:56:18.058Z",{"error":127,"url":128,"statusCode":129,"statusMessage":130,"message":130},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Finhale-mcp-abilities\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":132,"versions":133},6,[134,140,147,154,161,168],{"version":6,"download_url":25,"svn_tag_url":135,"released_at":27,"has_diff":136,"diff_files_changed":137,"diff_lines":27,"trac_diff_url":138,"vulnerabilities":139,"is_current":127},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Finhale-mcp-abilities\u002Ftags\u002F0.4.5\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Finhale-mcp-abilities%2Ftags%2F0.4.4&new_path=%2Finhale-mcp-abilities%2Ftags%2F0.4.5",[],{"version":141,"download_url":142,"svn_tag_url":143,"released_at":27,"has_diff":136,"diff_files_changed":144,"diff_lines":27,"trac_diff_url":145,"vulnerabilities":146,"is_current":136},"0.4.4","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Finhale-mcp-abilities.0.4.4.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Finhale-mcp-abilities\u002Ftags\u002F0.4.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Finhale-mcp-abilities%2Ftags%2F0.4.3&new_path=%2Finhale-mcp-abilities%2Ftags%2F0.4.4",[],{"version":148,"download_url":149,"svn_tag_url":150,"released_at":27,"has_diff":136,"diff_files_changed":151,"diff_lines":27,"trac_diff_url":152,"vulnerabilities":153,"is_current":136},"0.4.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Finhale-mcp-abilities.0.4.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Finhale-mcp-abilities\u002Ftags\u002F0.4.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Finhale-mcp-abilities%2Ftags%2F0.4.2&new_path=%2Finhale-mcp-abilities%2Ftags%2F0.4.3",[],{"version":155,"download_url":156,"svn_tag_url":157,"released_at":27,"has_diff":136,"diff_files_changed":158,"diff_lines":27,"trac_diff_url":159,"vulnerabilities":160,"is_current":136},"0.4.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Finhale-mcp-abilities.0.4.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Finhale-mcp-abilities\u002Ftags\u002F0.4.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Finhale-mcp-abilities%2Ftags%2F0.4.1&new_path=%2Finhale-mcp-abilities%2Ftags%2F0.4.2",[],{"version":162,"download_url":163,"svn_tag_url":164,"released_at":27,"has_diff":136,"diff_files_changed":165,"diff_lines":27,"trac_diff_url":166,"vulnerabilities":167,"is_current":136},"0.4.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Finhale-mcp-abilities.0.4.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Finhale-mcp-abilities\u002Ftags\u002F0.4.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Finhale-mcp-abilities%2Ftags%2F0.4.0&new_path=%2Finhale-mcp-abilities%2Ftags%2F0.4.1",[],{"version":169,"download_url":170,"svn_tag_url":171,"released_at":27,"has_diff":136,"diff_files_changed":172,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":173,"is_current":136},"0.4.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Finhale-mcp-abilities.0.4.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Finhale-mcp-abilities\u002Ftags\u002F0.4.0\u002F",[],[]]