[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fJbl_IGMx4Tgg9M8rUMKhmi8F2NvuBrv7YyJJ_1Gib7c":3,"$fzVK0Uoujl4onXkSox793mGffmAMnpUUxieE-Ksl7Fq4":127,"$faozQ11pf4wjD7zx40wm7SUSa0pwAoEAz1i1X3VT6YOs":132},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":38,"analysis":27,"fingerprints":27},"invizo-mcp","Invizo MCP – Secure AI Connector for Claude, Codex, Cursor and WooCommerce","2.0.8","Invizo","https:\u002F\u002Fprofiles.wordpress.org\u002Finvizo\u002F","\u003Cp>Invizo MCP turns WordPress into a secure, self-hosted Model Context Protocol server. Connect Claude Code, Claude Desktop, Codex, Cursor, Antigravity, and other MCP-compatible AI clients directly to your WordPress admin workflows without an Invizo-hosted proxy.\u003C\u002Fp>\n\u003Cp>Your site hosts the MCP endpoint:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>https:\u002F\u002Fexample.com\u002Fwp-json\u002Fmcp\u002Finvizo\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Invizo MCP uses WordPress Application Passwords, administrator-only access, granular scopes, and the WordPress Abilities API. Administrators decide exactly what an AI client can discover and execute: read-only content, post creation, WooCommerce operations, media uploads, Elementor workflows, Rank Math metadata, LearnPress course actions, Events Calendar management, and more.\u003C\u002Fp>\n\u003Cp>No Invizo account, subscription, license key, telemetry, or Invizo cloud service is required.\u003C\u002Fp>\n\u003Ch4>Why choose Invizo MCP?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Self-hosted WordPress MCP server:\u003C\u002Fstrong> WordPress serves MCP JSON-RPC at \u003Ccode>\u002Fwp-json\u002Fmcp\u002Finvizo\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security-first access:\u003C\u002Fstrong> only authenticated administrators with WordPress Application Passwords can connect.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Granular permissions:\u003C\u002Fstrong> separate read, write, and delete scopes for WordPress content and integrations.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Compact AI tool surface:\u003C\u002Fstrong> exposes \u003Ccode>discover-abilities\u003C\u002Fcode>, \u003Ccode>get-ability-info\u003C\u002Fcode>, and \u003Ccode>execute-ability\u003C\u002Fcode> instead of flooding clients with dozens of top-level tools.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Official MCP packages:\u003C\u002Fstrong> bundles the GPL-compatible WordPress MCP Adapter and PHP MCP Schema packages.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Works with major clients:\u003C\u002Fstrong> copy-ready setup for Claude Code, Claude Desktop, Codex, Cursor, and Antigravity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce-ready:\u003C\u002Fstrong> read, create, edit, and delete store data when WooCommerce scopes are enabled.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Builder and SEO support:\u003C\u002Fstrong> Gutenberg, Elementor, and Rank Math SEO scopes for content and metadata workflows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>LMS and event workflows:\u003C\u002Fstrong> LearnPress and The Events Calendar integrations activate only when those plugins are installed.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No external Invizo service:\u003C\u002Fstrong> no dashboard handshake, no shared secret, no remote Invizo backend.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>What can AI clients do with Invizo MCP?\u003C\u002Fh4>\n\u003Cp>After an administrator enables the endpoint, creates an Application Password, and selects scopes, approved AI clients can manage WordPress through MCP.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress content management\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Read, create, update, delete, and search posts.\u003C\u002Fli>\n\u003Cli>Read, create, update, and delete pages.\u003C\u002Fli>\n\u003Cli>Upload, edit, read, and delete media.\u003C\u002Fli>\n\u003Cli>Manage categories, tags, and taxonomy terms.\u003C\u002Fli>\n\u003Cli>Read, create, edit, moderate, and delete comments.\u003C\u002Fli>\n\u003Cli>Read revisions and delete revisions.\u003C\u002Fli>\n\u003Cli>Read reusable blocks and patterns.\u003C\u002Fli>\n\u003Cli>Create and edit reusable blocks.\u003C\u002Fli>\n\u003Cli>Read and update block templates.\u003C\u002Fli>\n\u003Cli>Read and update global styles.\u003C\u002Fli>\n\u003Cli>Search site content.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Site administration\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Read, create, edit, and delete users.\u003C\u002Fli>\n\u003Cli>Read, create, edit, and delete menus.\u003C\u002Fli>\n\u003Cli>Read site settings and structure.\u003C\u002Fli>\n\u003Cli>Update safe site settings through allowlisted handlers.\u003C\u002Fli>\n\u003Cli>Read plugins and themes.\u003C\u002Fli>\n\u003Cli>Discover post types, taxonomies, and post statuses.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Custom content and metadata\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Read custom post types.\u003C\u002Fli>\n\u003Cli>Create and edit custom post type definitions.\u003C\u002Fli>\n\u003Cli>Delete MCP-managed custom post type definitions.\u003C\u002Fli>\n\u003Cli>Read post meta.\u003C\u002Fli>\n\u003Cli>Update post meta.\u003C\u002Fli>\n\u003Cli>Manage MCP-defined metadata fields without deleting existing WordPress content on uninstall.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Page builders and SEO\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Work with Gutenberg content and page-builder workflows.\u003C\u002Fli>\n\u003Cli>Work with Elementor page data when Elementor is active.\u003C\u002Fli>\n\u003Cli>Read and update Rank Math SEO metadata when Rank Math SEO is active.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>WooCommerce AI automation\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Read WooCommerce products, variations, orders, customers, coupons, and terms.\u003C\u002Fli>\n\u003Cli>Create and update WooCommerce products, variations, orders, customers, coupons, order notes, order statuses, and product terms.\u003C\u002Fli>\n\u003Cli>Delete WooCommerce data only when delete scopes are enabled.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>LearnPress LMS\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Read LearnPress courses, lessons, quizzes, questions, orders, terms, and enrollments.\u003C\u002Fli>\n\u003Cli>Create and edit LearnPress data when LearnPress is active.\u003C\u002Fli>\n\u003Cli>Delete LearnPress data only when delete scopes are enabled.\u003C\u002Fli>\n\u003Cli>Use LearnPress builder workflows when enabled.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>The Events Calendar\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Read Events Calendar events, venues, and organizers.\u003C\u002Fli>\n\u003Cli>Create and edit event data when The Events Calendar is active.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>MCP tools exposed to clients\u003C\u002Fh4>\n\u003Cp>Invizo MCP keeps the connected AI client clean and efficient. Instead of publishing every action as a separate top-level tool, it exposes three compact adapter tools:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>discover-abilities\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>get-ability-info\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>execute-ability\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>These tools let Claude, Codex, Cursor, Antigravity, and other clients discover available WordPress abilities, inspect schemas, and execute only the abilities allowed by the administrator-selected scopes.\u003C\u002Fp>\n\u003Ch4>Supported AI clients\u003C\u002Fh4>\n\u003Cp>The settings page generates copy-ready configuration for:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Claude Code\u003C\u002Fli>\n\u003Cli>Claude Desktop\u003C\u002Fli>\n\u003Cli>Codex\u003C\u002Fli>\n\u003Cli>Cursor\u003C\u002Fli>\n\u003Cli>Antigravity\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Clients that require local STDIO MCP can use the \u003Ccode>@automattic\u002Fmcp-wordpress-remote\u003C\u002Fcode> bridge through \u003Ccode>npx\u003C\u002Fcode>. Clients that support authenticated remote HTTP MCP can connect directly to the WordPress endpoint.\u003C\u002Fp>\n\u003Ch4>Built for administrators, developers, stores, agencies, and site managers\u003C\u002Fh4>\n\u003Cp>Invizo MCP is for WordPress administrators, WooCommerce store owners, agencies, developers, SEO teams, educators, and site maintainers who want trusted AI clients to work with WordPress through a documented, scoped protocol.\u003C\u002Fp>\n\u003Cp>Use read-only scopes for research and reporting. Add write scopes for content workflows. Enable delete scopes only for trusted clients and tested workflows.\u003C\u002Fp>\n\u003Ch4>Authentication\u003C\u002Fh4>\n\u003Cp>Invizo MCP uses WordPress Application Passwords and WordPress REST authentication.\u003C\u002Fp>\n\u003Cp>Only authenticated users with the \u003Ccode>manage_options\u003C\u002Fcode> capability can access the MCP transport or execute Invizo abilities. In a standard WordPress installation this means administrators only.\u003C\u002Fp>\n\u003Cp>Create a dedicated Application Password from \u003Cstrong>Settings > Invizo MCP\u003C\u002Fstrong> for every AI client or computer. Passwords can be revoked individually from the same screen.\u003C\u002Fp>\n\u003Cp>Application Passwords normally require HTTPS. Local HTTP sites can enable them by setting:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>define( 'WP_ENVIRONMENT_TYPE', 'local' );\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Security plugins can disable Application Passwords. Invizo reports this condition on its settings screen.\u003C\u002Fp>\n\u003Ch4>Scopes and safeguards\u003C\u002Fh4>\n\u003Cp>Administrators choose exactly which read, write, and delete scopes are enabled. Abilities outside enabled scopes are hidden from MCP discovery and rejected during execution.\u003C\u002Fp>\n\u003Cp>Optional integration scopes are unavailable unless their required plugin is active.\u003C\u002Fp>\n\u003Cp>Existing handler safeguards remain in place, including:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WordPress sanitization and validation.\u003C\u002Fli>\n\u003Cli>Plugin availability checks.\u003C\u002Fli>\n\u003Cli>Scope checks inside action handlers.\u003C\u002Fli>\n\u003Cli>Dry-run previews for supported risky operations.\u003C\u002Fli>\n\u003Cli>Explicit \u003Ccode>confirm: true\u003C\u002Fcode> requirements for supported destructive operations.\u003C\u002Fli>\n\u003Cli>Reserved metadata protection and safe site-setting allow lists.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Complete scope list\u003C\u002Fh4>\n\u003Cp>Invizo MCP includes scope controls for:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Read Posts\u003C\u002Fli>\n\u003Cli>Create\u002FEdit Posts\u003C\u002Fli>\n\u003Cli>Delete Posts\u003C\u002Fli>\n\u003Cli>Read Media\u003C\u002Fli>\n\u003Cli>Upload\u002FEdit Media\u003C\u002Fli>\n\u003Cli>Delete Media\u003C\u002Fli>\n\u003Cli>Read Pages\u003C\u002Fli>\n\u003Cli>Create\u002FEdit Pages\u003C\u002Fli>\n\u003Cli>Delete Pages\u003C\u002Fli>\n\u003Cli>Read Categories and Tags\u003C\u002Fli>\n\u003Cli>Create\u002FEdit Categories and Tags\u003C\u002Fli>\n\u003Cli>Delete Categories and Tags\u003C\u002Fli>\n\u003Cli>Read Comments\u003C\u002Fli>\n\u003Cli>Create\u002FEdit Comments\u003C\u002Fli>\n\u003Cli>Delete Comments\u003C\u002Fli>\n\u003Cli>Read Users\u003C\u002Fli>\n\u003Cli>Create\u002FEdit Users\u003C\u002Fli>\n\u003Cli>Delete Users\u003C\u002Fli>\n\u003Cli>Read Menus\u003C\u002Fli>\n\u003Cli>Create\u002FEdit Menus\u003C\u002Fli>\n\u003Cli>Delete Menus\u003C\u002Fli>\n\u003Cli>Read Custom Post Types\u003C\u002Fli>\n\u003Cli>Create\u002FEdit Custom Post Types\u003C\u002Fli>\n\u003Cli>Delete Custom Post Types\u003C\u002Fli>\n\u003Cli>Read Post Meta\u003C\u002Fli>\n\u003Cli>Update Post Meta\u003C\u002Fli>\n\u003Cli>Read Revisions\u003C\u002Fli>\n\u003Cli>Delete Revisions\u003C\u002Fli>\n\u003Cli>Read Reusable Blocks and Patterns\u003C\u002Fli>\n\u003Cli>Create\u002FEdit Reusable Blocks\u003C\u002Fli>\n\u003Cli>Delete Reusable Blocks\u003C\u002Fli>\n\u003Cli>Read Block Templates\u003C\u002Fli>\n\u003Cli>Update Block Templates\u003C\u002Fli>\n\u003Cli>Read Global Styles\u003C\u002Fli>\n\u003Cli>Update Global Styles\u003C\u002Fli>\n\u003Cli>Read Site Settings and Structure\u003C\u002Fli>\n\u003Cli>Update Safe Site Settings\u003C\u002Fli>\n\u003Cli>Read Plugins and Themes\u003C\u002Fli>\n\u003Cli>Search Site Content\u003C\u002Fli>\n\u003Cli>Gutenberg Page Builder\u003C\u002Fli>\n\u003Cli>Elementor Page Builder\u003C\u002Fli>\n\u003Cli>Rank Math SEO\u003C\u002Fli>\n\u003Cli>Read Events Calendar Data\u003C\u002Fli>\n\u003Cli>Create\u002FEdit Events Calendar Data\u003C\u002Fli>\n\u003Cli>Read WooCommerce Data\u003C\u002Fli>\n\u003Cli>Create\u002FEdit WooCommerce Data\u003C\u002Fli>\n\u003Cli>Delete WooCommerce Data\u003C\u002Fli>\n\u003Cli>Read LearnPress Data\u003C\u002Fli>\n\u003Cli>Create\u002FEdit LearnPress Data\u003C\u002Fli>\n\u003Cli>Delete LearnPress Data\u003C\u002Fli>\n\u003Cli>LearnPress Page Builder\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Data stored by the plugin\u003C\u002Fh4>\n\u003Cp>Invizo MCP stores:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Endpoint enabled\u002Fdisabled status and selected scopes in the \u003Ccode>invizo_mcp_settings\u003C\u002Fcode> option.\u003C\u002Fli>\n\u003Cli>MCP-managed custom post type definitions in the \u003Ccode>invizo_mcp_registered_cpts\u003C\u002Fcode> option.\u003C\u002Fli>\n\u003Cli>MCP-managed post meta definitions in the \u003Ccode>invizo_mcp_registered_meta_fields\u003C\u002Fcode> option.\u003C\u002Fli>\n\u003Cli>A plugin version option used for upgrades.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Application Passwords are created and stored by WordPress in user metadata. Invizo tags only the credentials it creates so they can be listed and revoked from the settings page.\u003C\u002Fp>\n\u003Cp>Invizo MCP does not collect analytics or send usage information to Invizo.\u003C\u002Fp>\n\u003Ch3>Client Configuration\u003C\u002Fh3>\n\u003Cp>The settings page generates current, copy-ready values using your site endpoint and WordPress username.\u003C\u002Fp>\n\u003Ch4>Claude Code\u003C\u002Fh4>\n\u003Cp>The primary setup uses \u003Ccode>@automattic\u002Fmcp-wordpress-remote\u003C\u002Fcode> through \u003Ccode>npx\u003C\u002Fcode>, with the endpoint, username, and Application Password stored as environment variables.\u003C\u002Fp>\n\u003Cp>A direct HTTP \u003Ccode>.mcp.json\u003C\u002Fcode> alternative is also shown for clients that support authenticated HTTP MCP servers.\u003C\u002Fp>\n\u003Ch4>Claude Desktop\u003C\u002Fh4>\n\u003Cp>Add the generated JSON to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>macOS: \u003Ccode>~\u002FLibrary\u002FApplication Support\u002FClaude\u002Fclaude_desktop_config.json\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Windows: \u003Ccode>%APPDATA%\\Claude\\claude_desktop_config.json\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Codex\u003C\u002Fh4>\n\u003Cp>Add the generated TOML to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Project: \u003Ccode>.codex\u002Fconfig.toml\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Global: \u003Ccode>~\u002F.codex\u002Fconfig.toml\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Both \u003Ccode>npx\u003C\u002Fcode> bridge and direct authenticated HTTP examples are provided.\u003C\u002Fp>\n\u003Ch4>Cursor\u003C\u002Fh4>\n\u003Cp>Add the generated JSON to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Project: \u003Ccode>.cursor\u002Fmcp.json\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Global: \u003Ccode>~\u002F.cursor\u002Fmcp.json\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Antigravity\u003C\u002Fh4>\n\u003Cp>Add the generated JSON to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>macOS\u002FLinux: \u003Ccode>~\u002F.gemini\u002Fantigravity\u002Fmcp_config.json\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Windows: \u003Ccode>%USERPROFILE%\\.gemini\\antigravity\\mcp_config.json\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Local HTTPS\u003C\u002Fh4>\n\u003Cp>Trust your local certificate whenever possible. For local development only, bridge configurations may use \u003Ccode>NODE_TLS_REJECT_UNAUTHORIZED=0\u003C\u002Fcode> when the certificate cannot be trusted normally.\u003C\u002Fp>\n\u003Cp>Never commit Application Passwords to source control or paste them into prompts, tickets, screenshots, or chat messages.\u003C\u002Fp>\n\u003Ch3>Privacy and Security\u003C\u002Fh3>\n\u003Cp>The MCP endpoint is disabled by default on new installations. Enabling it does not expose abilities until scopes are selected.\u003C\u002Fp>\n\u003Cp>The endpoint requires:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Valid WordPress Application Password authentication.\u003C\u002Fli>\n\u003Cli>A WordPress user with the \u003Ccode>manage_options\u003C\u002Fcode> capability.\u003C\u002Fli>\n\u003Cli>An enabled Invizo scope for the requested ability.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Use one dedicated Application Password per client or device so individual connections can be revoked without changing the WordPress account password.\u003C\u002Fp>\n\u003Cp>When the plugin is uninstalled, Invizo-created Application Passwords are always revoked. Plugin settings and MCP-managed definitions are removed only when \u003Cstrong>Delete Invizo settings and MCP-managed CPT\u002Fmeta definitions when the plugin is uninstalled\u003C\u002Fstrong> is enabled. Existing posts and post meta values are never deleted by the uninstaller.\u003C\u002Fp>\n\u003Ch4>Reporting security issues\u003C\u002Fh4>\n\u003Cp>Please report security issues privately through the contact information on https:\u002F\u002Finvizo.io\u002F. Do not publish sensitive vulnerability details in a public support topic before a fix is available.\u003C\u002Fp>\n\u003Ch3>Upgrade from 1.x\u003C\u002Fh3>\n\u003Cp>Version 2.0 automatically removes the stored external MCP Server URL and shared secret.\u003C\u002Fp>\n\u003Cp>It preserves:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Enabled scopes.\u003C\u002Fli>\n\u003Cli>MCP-managed custom post type definitions.\u003C\u002Fli>\n\u003Cli>MCP-managed post meta definitions.\u003C\u002Fli>\n\u003Cli>WordPress content and integration data.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Sites that previously had a shared secret configured are migrated with the standalone endpoint enabled. Other installations remain disabled until an administrator explicitly enables the endpoint.\u003C\u002Fp>\n\u003Cp>The legacy signed endpoint \u003Ccode>\u002Fwp-json\u002Finvizo\u002Fv1\u002Fexecute\u003C\u002Fcode> and its HMAC headers have been removed.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>Invizo MCP does not contact an Invizo-hosted service.\u003C\u002Fp>\n\u003Cp>MCP clients may use the third-party npm package \u003Ccode>@automattic\u002Fmcp-wordpress-remote\u003C\u002Fcode> as a local bridge when configured by the administrator. The package is downloaded from the npm registry and runs on the computer hosting the AI client, not inside WordPress.\u003C\u002Fp>\n\u003Cp>When the bridge is used, it sends the configured WordPress endpoint, username, Application Password, and MCP request data directly to the administrator’s WordPress site. It does not send those credentials to Invizo.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Package: https:\u002F\u002Fwww.npmjs.com\u002Fpackage\u002F@automattic\u002Fmcp-wordpress-remote\u003C\u002Fli>\n\u003Cli>Source: https:\u002F\u002Fgithub.com\u002FAutomattic\u002Fmcp-wordpress-remote\u003C\u002Fli>\n\u003Cli>npm Terms of Use: https:\u002F\u002Fdocs.npmjs.com\u002Fpolicies\u002Fterms\u003C\u002Fli>\n\u003Cli>npm Privacy Notice: https:\u002F\u002Fdocs.npmjs.com\u002Fpolicies\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Media upload actions can fetch a public file URL explicitly supplied by an authenticated MCP caller through WordPress media sideloading. In that case, the remote file host receives a normal HTTP request from the WordPress site. The service and data destination depend entirely on the URL supplied by the administrator’s MCP client.\u003C\u002Fp>\n\u003Cp>No external request is made merely by installing or activating Invizo MCP.\u003C\u002Fp>\n\u003Ch3>Build and Source Files\u003C\u002Fh3>\n\u003Cp>The distributed plugin contains the human-readable PHP source used at runtime.\u003C\u002Fp>\n\u003Ch4>PHP dependencies\u003C\u002Fh4>\n\u003Cp>Composer dependencies are included under \u003Ccode>vendor\u002F\u003C\u002Fcode> because they are required for the standalone MCP endpoint:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>automattic\u002Fjetpack-autoloader\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>wordpress\u002Fmcp-adapter\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>wordpress\u002Fphp-mcp-schema\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>All bundled packages use the GPL-2.0-or-later license. Package source, Composer metadata, and individual license files are included. See \u003Ccode>third-party-notices.txt\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Ch4>Rebuilding dependencies\u003C\u002Fh4>\n\u003Cp>From the plugin directory:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>composer install --no-dev --optimize-autoloader\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Create the WordPress.org submission ZIP from the parent plugins directory while excluding Git metadata, operating-system files, logs, and Node dependencies.\u003C\u002Fp>\n","Secure WordPress MCP server for Claude, ChatGPT, Codex & Cursor. Manage posts, WooCommerce, SEO, media, users, builders, LMS & events.",0,321,100,1,"2026-07-19T06:00:00.000Z","7.0.2","6.9","7.4",[20,21,22,23,24],"ai-automation","claude","cursor","mcp","woocommerce","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Finvizo-mcp\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Finvizo-mcp.2.0.8.zip",null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":34,"avg_security_score":13,"avg_patch_time_days":35,"trust_score":36,"computed_at":37},"invizo",7,70,30,94,"2026-08-24T06:43:17.437Z",[39,58,75,91,107],{"slug":40,"name":41,"version":42,"author":43,"author_profile":44,"description":45,"short_description":46,"active_installs":47,"downloaded":48,"rating":13,"num_ratings":49,"last_updated":50,"tested_up_to":16,"requires_at_least":51,"requires_php":18,"tags":52,"homepage":56,"download_link":57,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":27,"fetched_at":28},"stifli-flex-mcp","StifLi Flex MCP – MCP Server with undo for ChatGPT, Claude & Gemini","3.4.0","Esteban","https:\u002F\u002Fprofiles.wordpress.org\u002Festebandezafra\u002F","\u003Cp>\u003Cstrong>StifLi Flex MCP\u003C\u002Fstrong> is the most secure MCP Server for WordPress with built-in Undo. Connect ChatGPT, Claude Desktop, Gemini, and other MCP clients safely, roll back changes when needed, and manage your site through natural conversation without losing control.\u003C\u002Fp>\n\u003Cp>Choose the layers your site needs without loading the rest:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>MCP Server (always active)\u003C\u002Fstrong> — Connect ChatGPT, Claude Desktop, or any MCP client directly to your site. Includes Multimedia and Logs & Roll Back.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI Copilot (optional addon)\u003C\u002Fstrong> — A floating assistant inside the Gutenberg and Classic editors that writes, rewrites, and optimizes your content in real time.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI Chat Agent (optional addon)\u003C\u002Fstrong> — A full conversational interface to manage posts, WooCommerce, settings, and more.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automations, SEO, and Plugin Integrations (optional addons)\u003C\u002Fstrong> — Enable only the workflows and integrations used on your site.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>On first activation, a setup screen lets you select the addons to load. The default is the MCP Server layer only. You can change the selection later from \u003Cstrong>StifLi Flex MCP \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> MCP Server \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add-ons\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🎬 Video: Claude to WordPress MCP Connector in 1 Minute\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FAcmvwRzoOSM?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>📚 Documentation\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fandromedanova.com\u002Fstifli-flex-mcp.html\" rel=\"nofollow ugc\">StifLi Flex MCP Documentation\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Released in December 2025, \u003Cstrong>StifLi Flex MCP\u003C\u002Fstrong> was the first MCP plugin for WordPress and remains the most complete WordPress MCP platform for ChatGPT, Claude Desktop, and other MCP clients.\u003Cbr \u002F>\nIt starts with 122+ built-in MCP tools, and with supported integrations such as All Sources Images, Stifli Backup Tools, AiPatch Security Scanner, Notification for Telegram, WPCode, Code Snippets, Woody Snippets, Advanced Custom Fields, Yoast SEO, Rank Math, WPForms, Gravity Forms, Forminator, The Events Calendar, and Elementor, it can exceed 200 total tools depending on the plugins you install.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>📡 MCP Server — Connect ChatGPT, Claude Desktop, and Other MCP Clients\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>StifLi Flex MCP includes a full standards-compliant MCP server for WordPress, so ChatGPT, Claude Desktop, LibreChat, and other MCP clients can connect directly to your site and use real WordPress tools through OAuth 2.1.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>ChatGPT\u003C\u002Fstrong> — Connect through Apps & Connectors with OAuth 2.1 authentication\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Claude Desktop\u003C\u002Fstrong> — Connect through Connectors with automatic OAuth flow\u003C\u002Fli>\n\u003Cli>\u003Cstrong>LibreChat and other MCP clients\u003C\u002Fstrong> — Use the same MCP endpoint and discovery flow\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero shared secrets\u003C\u002Fstrong> — No custom API keys or passwords for external MCP clients\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Standards-based\u003C\u002Fstrong> — Automatic discovery, registration, and authentication with OAuth 2.1, PKCE, RFC 9728, RFC 8414, and RFC 7591\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Just copy the SSE URL from the Settings page, paste it into ChatGPT, Claude Desktop, or another MCP client, and authorize.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>✍️ AI Copilot — Your Writing Assistant Inside the Editor\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The AI Copilot lives as a floating widget right inside the WordPress post and page editor. It understands the full context of what you’re editing — title, content, categories, tags, featured image, and even WooCommerce product fields — and helps you write better, faster.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Rewrite, expand, or optimize content\u003C\u002Fstrong> — Ask the Copilot to improve your text and it applies the changes directly into the editor\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One-click quick actions\u003C\u002Fstrong> — “⚡ Optimize content”, “🏷️ Generate tags”, “📝 Write excerpt”, “🖼️ Generate image” — one tap, instant results\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-time editing\u003C\u002Fstrong> — The Copilot sets titles, excerpts, tags, slugs, and categories directly in the editor. No copy-pasting\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Content block operations\u003C\u002Fstrong> — Insert, update, replace, or delete Gutenberg blocks through conversation\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Visual feedback\u003C\u002Fstrong> — Changed fields and blocks are highlighted with a green border so you always see what the AI modified\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Keep or Undo\u003C\u002Fstrong> — Every change shows a floating banner: keep it or undo with a single click. You stay in control\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Image generation\u003C\u002Fstrong> — Ask the Copilot to generate an image and it sets it as the featured image or inserts it as a block, automatically\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Works with Gutenberg and Classic Editor\u003C\u002Fstrong> — Full support for both editors\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Context-aware\u003C\u002Fstrong> — The Copilot reads your current post content, blocks, metadata, and editor state to give relevant suggestions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce-aware\u003C\u002Fstrong> — When editing a product, the Copilot sees prices, stock, SKU, attributes, and product type\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Choose OpenAI (GPT-5.4), Anthropic (Claude 4.6 Opus\u002FSonnet), or Google (Gemini 3.1 Pro\u002FFlash), and optionally use WordPress AI Client connectors like OpenRouter and Mistral when installed. No complex setup — just your API key or connector credentials.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>💡 What Can You Do With the Copilot?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Here are just a few examples of what you can ask while editing a post or page:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>✏️ “Rewrite the introduction to sound more professional and engaging”\u003C\u002Fli>\n\u003Cli>📊 “Add a comparison table below the second paragraph with pros and cons”\u003C\u002Fli>\n\u003Cli>🖼️ “Generate an image that illustrates the idea in paragraph four and insert it right above”\u003C\u002Fli>\n\u003Cli>📝 “Write a compelling meta description and set it as the excerpt”\u003C\u002Fli>\n\u003Cli>🛒 “Update the product short description to highlight free shipping and set the sale price to $19.99”\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The Copilot reads your full content, understands context, and applies changes directly in the editor — no copy-pasting, no switching tabs.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🤖 AI Chat Agent — Your WordPress AI Assistant\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The built-in AI Chat Agent gives you a powerful conversational interface to manage your entire WordPress site:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Talk to your site\u003C\u002Fstrong> — “Show me the last 5 orders”, “Create a blog post about SEO tips”, “What plugins are installed?”\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-provider\u003C\u002Fstrong> — Built-in OpenAI (GPT-5.4, GPT-5.3), Anthropic (Claude 4.6 Opus\u002FSonnet, Claude 4.5 Haiku), Google (Gemini 3.1 Pro, Gemini 3 Flash) + optional WordPress AI Client connectors (OpenRouter, Mistral)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>122+ MCP tools at its disposal\u003C\u002Fstrong> — The AI agent can read posts, create content, manage WooCommerce products, check orders, inspect SEO data, update settings, and much more\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart suggestions\u003C\u002Fstrong> — After each response, get contextual follow-up suggestions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Conversation history\u003C\u002Fstrong> — Auto-saved across sessions with multi-tab support\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Safe by design\u003C\u002Fstrong> — Choose “Always Allow” or “Ask User” mode for tool execution confirmations\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced tuning\u003C\u002Fstrong> — Control temperature, max tokens, top_p, system prompts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>💡 What Can You Do With It?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Here are just a few examples of what you can ask your AI agent:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>📝 “Write a 500-word blog post about healthy eating and publish it as draft”\u003C\u002Fli>\n\u003Cli>🛒 “Show me today’s WooCommerce orders and their total revenue”\u003C\u002Fli>\n\u003Cli>🔍 “What are the top 10 most commented posts on my site?”\u003C\u002Fli>\n\u003Cli>📊 “List all products with stock below 5 units”\u003C\u002Fli>\n\u003Cli>🎨 “Generate a hero image for my latest blog post about technology”\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The AI agent understands context, chains multiple operations, and works with your site’s real data in real time.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🎨 AI Image & Video Generation\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Generate stunning images and videos directly from your AI agent or the dedicated Multimedia Settings page:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Image Generation\u003C\u002Fstrong> — “Generate a hero image for my blog post about AI” using OpenAI (GPT Image family + DALL·E 2\u002F3) or Google Gemini (Gemini Image + Imagen 4)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Image Search\u003C\u002Fstrong> — “Find a real stock image for my post” with \u003Ccode>wp_search_image\u003C\u002Fcode> (Unsplash, Pexels, Pixabay) including attribution metadata\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Video Generation\u003C\u002Fstrong> — “Create a 5-second product showcase video” using OpenAI Sora or Google Veo 2\u002F3\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>🧩 Code Snippet Management — Design and Develop Through Conversation\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Create, edit, activate, and manage code snippets on your WordPress site entirely through AI — no manual coding required. Compatible with the three most popular snippet plugins: \u003Cstrong>WPCode\u003C\u002Fstrong>, \u003Cstrong>Code Snippets\u003C\u002Fstrong>, and \u003Cstrong>Woody Code Snippets\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Add functionality instantly\u003C\u002Fstrong> — “Add a PHP snippet that redirects users after login based on their role”\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom CSS on demand\u003C\u002Fstrong> — “Create a CSS snippet that hides the sidebar on mobile devices”\u003C\u002Fli>\n\u003Cli>\u003Cstrong>JavaScript injection\u003C\u002Fstrong> — “Add a JS snippet that shows a sticky banner with a 10% discount code”\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full lifecycle management\u003C\u002Fstrong> — List, create, edit, activate, deactivate, and delete snippets from conversation\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Safe by design\u003C\u002Fstrong> — PHP code is sanitized automatically, removing stray \u003Ccode>\u003C?php\u003C\u002Fcode> tags and markdown artifacts from AI-generated output\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This opens up powerful possibilities: customize your theme’s appearance, add tracking scripts, inject schema markup for SEO, modify WooCommerce checkout behavior, add custom shortcodes — all through natural language. Ask your AI agent to build it, test it, and activate it, without ever touching a code editor.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🧠 WordPress Abilities Integration\u003C\u002Fstrong> (WordPress 6.9+)\u003C\u002Fp>\n\u003Cp>Automatically discover and import abilities registered by other plugins into your AI agent’s toolkit. If a plugin supports the WordPress Abilities API, StifLi Flex MCP can detect, import, and expose it as an AI tool — zero configuration needed.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>⏰ Automation Tasks — Let AI Work While You Sleep\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Schedule AI-powered tasks to run automatically on your WordPress site:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Scheduled Tasks\u003C\u002Fstrong> — Create daily, weekly, or monthly automated workflows\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Templates\u003C\u002Fstrong> — Quick-start with pre-built templates (Daily Sales Report, Trending Article, Weekly Summary)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart Scheduling\u003C\u002Fstrong> — Flexible presets from “Every hour” to “Monthly” with custom times and timezones\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Detected Tools Mode\u003C\u002Fstrong> — AI automatically identifies which tools are needed, saving tokens significantly\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Output Actions\u003C\u002Fstrong> — Send results via email, webhook, draft post, or custom hooks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Execution Logs\u003C\u002Fstrong> — Full history with token usage, duration, and detailed results\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>🎯 Event Automations — Trigger AI on WordPress Events\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Run AI workflows automatically when specific events happen\u003C\u002Fp>\n\u003Cp>\u003Cstrong>⏪ Roll Back — The Only MCP Server With Undo\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Mistakes happen. You asked ChatGPT to update your landing page and the result isn’t what you expected? No problem — \u003Cstrong>roll back the change with one click\u003C\u002Fstrong> and your site is restored instantly.\u003C\u002Fp>\n\u003Cp>StifLi Flex MCP is the \u003Cstrong>only MCP server for WordPress that tracks every change and lets you undo it\u003C\u002Fstrong>. Every modification made by any AI — whether from ChatGPT, Claude Desktop, the built-in Chat Agent, the Copilot, or automated tasks — is recorded with a full before\u002Fafter snapshot.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>One-click Undo\u003C\u002Fstrong> — Roll back any change from the Logs & Roll Back page in your admin panel\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Redo support\u003C\u002Fstrong> — Changed your mind? Re-apply a rolled-back change just as easily\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session rollback\u003C\u002Fstrong> — Undo an entire AI conversation’s changes at once, in the correct order\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full audit trail\u003C\u002Fstrong> — See exactly what was changed, when, by whom, and from which source\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Works across everything\u003C\u002Fstrong> — Posts, pages, products, orders, options, menus, media, code snippets, and more\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI-accessible\u003C\u002Fstrong> — Your AI agent can also query and rollback changes through dedicated tools\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>💡 Real-world examples:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>🛒 “ChatGPT updated all my product prices but used the wrong currency — roll it back!”\u003C\u002Fli>\n\u003Cli>📝 “Claude rewrote my About page and I prefer the original — undo!”\u003C\u002Fli>\n\u003Cli>⚙️ “An automation changed my site settings at 3 AM — I can see exactly what happened and revert it”\u003C\u002Fli>\n\u003Cli>🎨 “The AI-generated image doesn’t match my brand — remove it and restore the previous one”\u003C\u002Fli>\n\u003Cli>🔗 “I told the AI to delete a menu item by mistake — bring it back!”\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>🛡️ Security — OAuth 2.1 Built In\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>StifLi Flex MCP uses \u003Cstrong>OAuth 2.1 with PKCE\u003C\u002Fstrong> — the latest industry-standard security protocol — to authenticate external AI clients. No API keys to copy, no passwords to share. Just paste the URL, authorize once, and you’re connected.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>OAuth 2.1 with PKCE (S256)\u003C\u002Fstrong> — The most modern and secure authentication standard, used by Google, Microsoft, and GitHub\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Dynamic Client Registration (RFC 7591)\u003C\u002Fstrong> — AI clients register automatically, no manual setup needed\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto-discovery (RFC 9728 + RFC 8414)\u003C\u002Fstrong> — Clients find your server’s auth endpoints automatically\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Token auto-refresh\u003C\u002Fstrong> — Sessions stay active for up to 90 days without re-authorization\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Application Passwords fallback\u003C\u002Fstrong> — Still supported for advanced setups and legacy clients\u003C\u002Fli>\n\u003Cli>Per-tool capability checks linked to WordPress roles\u003C\u002Fli>\n\u003Cli>Profile-based tool restrictions (8 predefined profiles + custom)\u003C\u002Fli>\n\u003Cli>Tool execution confirmations in AI Chat Agent\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>📋 Tool Profiles\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WordPress Read Only — safe read-only access\u003C\u002Fli>\n\u003Cli>WordPress Full Management — complete CRUD operations\u003C\u002Fli>\n\u003Cli>WooCommerce Read Only — query store data\u003C\u002Fli>\n\u003Cli>WooCommerce Store Management — products, orders, coupons\u003C\u002Fli>\n\u003Cli>Complete E-commerce — all WooCommerce tools\u003C\u002Fli>\n\u003Cli>Complete Site — all 122+ tools enabled\u003C\u002Fli>\n\u003Cli>Safe Mode — non-sensitive reads only\u003C\u002Fli>\n\u003Cli>Development\u002FDebug — diagnostic tools\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>🌐 Supported AI Platforms\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>StifLi Flex MCP integrates with:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Built-in AI Chat Agent + WordPress AI Client connectors:\u003C\u002Fstrong>\u003Cbr \u002F>\n* OpenAI — GPT-5.4, GPT-5.3, GPT-5.4 Mini\u003Cbr \u002F>\n* Anthropic Claude — Opus, Sonnet, Haiku\u003Cbr \u002F>\n* Google Gemini — Pro, Flash, Flash-Lite\u003Cbr \u002F>\n* OpenRouter and Mistral — via WordPress AI Client connectors (when installed)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>MCP Server (External Clients via OAuth 2.1):\u003C\u002Fstrong>\u003Cbr \u002F>\n* Claude Desktop, ChatGPT, LibreChat, Cursor, Cline, Roo Code, Windsurf, Claude Code\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Cloud & Local Providers (via MCP clients):\u003C\u002Fstrong>\u003Cbr \u002F>\n* Groq, Azure OpenAI, AWS Bedrock\u003Cbr \u002F>\n* Ollama, LM Studio, self-hosted solutions\u003C\u002Fp>\n\u003Cp>\u003Cstrong>📐 MCP Spec Compliance\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>StifLi Flex MCP implements the \u003Ca href=\"https:\u002F\u002Fmodelcontextprotocol.io\u002Fspecification\u002F2025-11-25\u002F\" rel=\"nofollow ugc\">Model Context Protocol (MCP) 2025-11-25 specification\u003C\u002Fa> for lifecycle and tool operations over JSON-RPC 2.0, while keeping legacy SSE compatibility for older MCP clients.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to third-party AI services to power the AI Chat Agent, AI Copilot, image generation, and video generation features. \u003Cstrong>No data is transmitted until you explicitly configure an API key and initiate a request.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What data is sent:\u003C\u002Fstrong> Your WordPress content (post text, metadata, product details) as included in AI prompts, and MCP tool execution results when using the MCP server with external AI clients.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When data is sent:\u003C\u002Fstrong> Only when you have configured an API key for a provider AND actively send a message to the AI agent or Copilot, or when an external MCP client makes an authenticated request to the MCP server endpoint.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Supported services and their policies:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>OpenAI\u003C\u002Fstrong> — Used for GPT models (AI Chat Agent, AI Copilot), GPT Image \u002F DALL·E (image generation), and Sora (video generation)\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fopenai.com\u002Fpolicies\u002Fterms-of-use\" rel=\"nofollow ugc\">Terms of Use\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fopenai.com\u002Fpolicies\u002Fprivacy-policy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Anthropic Claude\u003C\u002Fstrong> — Used for Claude AI models (AI Chat Agent, AI Copilot)\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\u002Flegal\u002Fconsumer-terms\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\u002Flegal\u002Fprivacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Google Gemini\u003C\u002Fstrong> — Used for Gemini AI models (AI Chat Agent, AI Copilot), Gemini Image + Imagen 4 (image generation), and Veo 2\u002F3 (video generation)\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fai.google.dev\u002Fterms\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fprivacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Google Search Console\u003C\u002Fstrong> – Used only when you connect your Google account in the SEO settings, for read-only site\u002Fsearch performance data.\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fterms\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fprivacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>When using the MCP server with external AI clients (ChatGPT, Claude Desktop, LibreChat, etc.), API requests are made by the AI client’s backend servers to your WordPress MCP endpoint. The plugin itself does not send data to third parties in this scenario — the external MCP client initiates all communication.\u003C\u002Fp>\n","The most secure MCP Server for WordPress with Undo, plus AI Copilot & Chat Agent. ChatGPT, Claude, Gemini, OpenRouter & Mistral.",1000,24038,4,"2026-07-20T09:13:00.000Z","5.9",[53,21,54,23,55],"chatgpt","copilot","woocommerce-ai","https:\u002F\u002Fgithub.com\u002Festebanstifli\u002Fstifli-flex-mcp","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fstifli-flex-mcp.3.4.0.zip",{"slug":59,"name":60,"version":61,"author":62,"author_profile":63,"description":64,"short_description":65,"active_installs":66,"downloaded":67,"rating":13,"num_ratings":68,"last_updated":69,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":70,"homepage":73,"download_link":74,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":27,"fetched_at":28},"wsp-mcp-ai-agents-connector","WSP MCP – AI Agents Connector","2.6.2","Bilal Naseer","https:\u002F\u002Fprofiles.wordpress.org\u002Fbilalnaseer\u002F","\u003Cp>WSP MCP – AI Agents Connector turns your WordPress site into a Model Context Protocol (MCP) server. AI clients can read and edit posts, pages, categories, tags, media, comments, users, and (when installed) Yoast SEO meta and Elementor page content — all under granular, per-ability admin control.\u003C\u002Fp>\n\u003Cp>The plugin ships its \u003Cstrong>own native MCP server\u003C\u002Fstrong>. You do not need the WordPress MCP Adapter or any companion plugin: activate, copy your connection details from \u003Cstrong>MCP > Connection\u003C\u002Fstrong>, and connect. WooCommerce tools (products, orders, refunds, coupons, customers, reports) are available when WooCommerce is active, Advanced Custom Fields tools (field groups, fields, values, post types, taxonomies, options pages) when ACF is active, Ultimate Addons for Elementor (UAE) tools (widgets, templates, layout building, and settings) when UAE is active, and Gravity Forms tools (forms, entries, notifications, and confirmations) when Gravity Forms is active.\u003C\u002Fp>\n\u003Cp>Built and maintained by the \u003Ca href=\"https:\u002F\u002Fwebsensepro.com\u002F\" rel=\"nofollow ugc\">WebSensePro\u003C\u002Fa> team. For documentation, setup guides, and connection help, visit the plugin home at \u003Ca href=\"https:\u002F\u002Ffreewordpressmcp.com\u002F\" rel=\"nofollow ugc\">freewordpressmcp.com\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Video tutorial\u003C\u002Fh4>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002F1hGSUAdRxiU?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch4>Key features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Built-in MCP server over a single REST endpoint (Streamable HTTP, JSON-RPC 2.0) — no external dependency.\u003C\u002Fli>\n\u003Cli>Per-ability on\u002Foff toggles in \u003Cstrong>MCP > Settings\u003C\u002Fstrong>; write abilities are off by default.\u003C\u002Fli>\n\u003Cli>Two authentication methods: WordPress Application Passwords (HTTP Basic) or a plugin-generated API key (\u003Ccode>Authorization: Bearer\u003C\u002Fcode> or \u003Ccode>X-WSP-MCP-API-Key\u003C\u002Fcode>).\u003C\u002Fli>\n\u003Cli>Capability checks on every tool — an AI client can only do what its authenticated user can do.\u003C\u002Fli>\n\u003Cli>Optional Yoast SEO and Elementor tools, shown only when those plugins are active.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Complete tools list\u003C\u002Fh4>\n\u003Cp>Every tool is individually toggleable in \u003Cstrong>MCP > Settings\u003C\u002Fstrong>, and all write tools are off by default.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Core WordPress\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Posts — read, create, update, delete\u003C\u002Fli>\n\u003Cli>Pages — read, create, update, delete\u003C\u002Fli>\n\u003Cli>Categories — list, create, update, delete\u003C\u002Fli>\n\u003Cli>Tags — list, create, update, delete\u003C\u002Fli>\n\u003Cli>Comments — read, approve, and delete\u003C\u002Fli>\n\u003Cli>Media — read the media library\u003C\u002Fli>\n\u003Cli>Users — read user data\u003C\u002Fli>\n\u003Cli>Site info — read general site details\u003C\u002Fli>\n\u003Cli>Plugins — list active plugins\u003C\u002Fli>\n\u003Cli>Search — search across site content\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Yoast SEO\u003C\u002Fstrong> (requires Yoast SEO)\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Read SEO title, meta description, and focus keyphrase\u003C\u002Fli>\n\u003Cli>Update SEO title, meta description, and focus keyphrase\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Elementor\u003C\u002Fstrong> (requires Elementor)\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Pages — list pages\u002Fposts built with Elementor\u003C\u002Fli>\n\u003Cli>Page structure — read the full element tree of a page\u003C\u002Fli>\n\u003Cli>Elements — get a single element’s settings, or find elements by widget type or content\u003C\u002Fli>\n\u003Cli>Templates — list saved templates from the library\u003C\u002Fli>\n\u003Cli>Editing — add widgets, add layout containers\u002Fsections, update element settings, and remove elements\u003C\u002Fli>\n\u003Cli>Code-bearing widget types (HTML, Shortcode, Code) are rejected and code-bearing settings (Custom CSS, Custom Attributes) are stripped; all text settings are sanitized with \u003Ccode>wp_kses_post()\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>WooCommerce\u003C\u002Fstrong> (requires WooCommerce — financial and PII tools require the \u003Ccode>manage_woocommerce\u003C\u002Fcode> capability)\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Products — list, get, create, update\u003C\u002Fli>\n\u003Cli>Product variations — create\u003C\u002Fli>\n\u003Cli>Orders — list, update status\u003C\u002Fli>\n\u003Cli>Refunds — process refunds\u003C\u002Fli>\n\u003Cli>Coupons — create, list\u003C\u002Fli>\n\u003Cli>Order notes — add order notes\u003C\u002Fli>\n\u003Cli>Customers — read customer data\u003C\u002Fli>\n\u003Cli>Sales report — read sales reporting\u003C\u002Fli>\n\u003Cli>Low-stock alerts — read low-stock products\u003C\u002Fli>\n\u003Cli>Reviews — moderate product reviews\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Advanced Custom Fields\u003C\u002Fstrong> (requires ACF — structural changes require \u003Ccode>manage_options\u003C\u002Fcode>; value tools enforce per-object capabilities)\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Field groups — list, get, create, update, delete, import\u003C\u002Fli>\n\u003Cli>Fields — list, get, create, update, delete, duplicate, sync\u003C\u002Fli>\n\u003Cli>Field values — get and set with dot-notation deep access, delete, get-all, bulk-update, and field object\u003C\u002Fli>\n\u003Cli>Custom post types — manage\u003C\u002Fli>\n\u003Cli>Taxonomies — manage\u003C\u002Fli>\n\u003Cli>Options pages — manage\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Gravity Forms\u003C\u002Fstrong> (requires Gravity Forms — reads require \u003Ccode>gravityforms_edit_forms\u003C\u002Fcode> or \u003Ccode>gravityforms_view_entries\u003C\u002Fcode>; writes require form\u002Fentry-specific Gravity Forms caps)\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Forms — list (ON by default), get (ON by default), create, update, delete, update form settings\u003C\u002Fli>\n\u003Cli>Entries — list, get, update (status, read\u002Fstarred flags, field values), delete (trash or permanent)\u003C\u002Fli>\n\u003Cli>Notifications — get, create, update, delete\u003C\u002Fli>\n\u003Cli>Confirmations — get, create, update, delete\u003C\u002Fli>\n\u003Cli>All 18 tools are off by default (except list-forms and get-form); only registered when Gravity Forms is active\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Ultimate Addons for Elementor\u003C\u002Fstrong> (requires UAE — structural and settings writes require \u003Ccode>edit_posts\u003C\u002Fcode>, \u003Ccode>publish_posts\u003C\u002Fcode>, or \u003Ccode>manage_options\u003C\u002Fcode>)\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Widgets — list, check usage, activate, deactivate, bulk toggle\u003C\u002Fli>\n\u003Cli>Templates — list, get, create, duplicate, update, trash, restore Header\u002FFooter\u002FBlocks templates\u003C\u002Fli>\n\u003Cli>Layout building — add sections, add columns, move elements, build layouts from JSON\u003C\u002Fli>\n\u003Cli>Settings — get\u002Fupdate UAE settings, theme info, extensions, and design-system tokens\u003C\u002Fli>\n\u003Cli>All 45 tools are off by default; string inputs are sanitized with \u003Ccode>wp_kses_post()\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Links\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Plugin home & docs: \u003Ca href=\"https:\u002F\u002Ffreewordpressmcp.com\u002F\" rel=\"nofollow ugc\">freewordpressmcp.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Built by: \u003Ca href=\"https:\u002F\u002Fwebsensepro.com\u002F\" rel=\"nofollow ugc\">WebSensePro\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","Expose your WordPress site to AI agents (Claude, Cursor, and other MCP clients) through a built-in MCP server — no companion plugin required.",200,654,3,"2026-07-21T10:20:00.000Z",[71,21,23,72,24],"ai","model-context-protocol","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwsp-mcp-ai-agents-connector.2.6.2.zip",{"slug":76,"name":77,"version":78,"author":79,"author_profile":80,"description":81,"short_description":82,"active_installs":83,"downloaded":84,"rating":11,"num_ratings":11,"last_updated":85,"tested_up_to":86,"requires_at_least":17,"requires_php":87,"tags":88,"homepage":89,"download_link":90,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":27,"fetched_at":28},"mcp-content-manager-lite","MCP Content Manager Lite","1.1.0","Jose Conti","https:\u002F\u002Fprofiles.wordpress.org\u002Fjconti\u002F","\u003Cp>\u003Cstrong>MCP Content Manager Lite\u003C\u002Fstrong> turns your WordPress site into a first-class Model Context Protocol (MCP) server so AI assistants like Claude, ChatGPT, GitHub Copilot, Cursor, Windsurf, Continue, JetBrains AI Assistant or Cowork can manage your content using natural language.\u003C\u002Fp>\n\u003Cp>It is \u003Cstrong>not\u003C\u002Fstrong> a wrapper around the REST API. The plugin \u003Cstrong>auto-discovers\u003C\u002Fstrong> every CPT, taxonomy, ACF group, custom field and registered meta on your site and exposes them as MCP abilities, so your AI client instantly understands the structure of your specific install — without configuration files, without code, without YAML.\u003C\u002Fp>\n\u003Ch4>Why MCP Content Manager Lite over other MCP plugins\u003C\u002Fh4>\n\u003Cp>Most WordPress MCP plugins ship 10–20 hardcoded tools that wrap a fixed list of REST endpoints. MCP Content Manager Lite ships \u003Cstrong>60+ abilities\u003C\u002Fstrong> out of the box, plus trust, onboarding and observability features that the rest of the ecosystem treats as paid extras:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Auto-discovery, not hardcoded tools.\u003C\u002Fstrong> Your AI client sees your real schema — CPTs from CPT UI, ACF, JetEngine, Pods, Toolset; taxonomies; statuses; shortcodes; permalink structure — generated at runtime. No YAML files to maintain.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>OAuth 2.1 with PKCE built in.\u003C\u002Fstrong> No application passwords. The plugin runs its own OAuth 2.1 server with Dynamic Client Registration so Claude, ChatGPT, Cursor and Copilot connect with one click.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Granular per-client allowlists.\u003C\u002Fstrong> Each OAuth client has its own \u003Ccode>allowed_abilities\u003C\u002Fcode> list, editable visually. Give Claude full access, give a webhook integration only \u003Ccode>read-post\u003C\u002Fcode> and \u003Ccode>list-recent-posts\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI image generation with Google Gemini.\u003C\u002Fstrong> Generate up to three images per call, save them to the Media Library, set as featured image. Imagen, multiple aspect ratios, 2K\u002F4K and image editing remain Premium.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Rate limiting per client_id\u003C\u002Fstrong>, \u003Cstrong>Activity Log\u003C\u002Fstrong> with 30-day retention, \u003Cstrong>MCP annotations\u003C\u002Fstrong> on every ability and a public \u003Cstrong>\u002Fhealth endpoint\u003C\u002Fstrong> for uptime monitoring.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Get Started wizard\u003C\u002Fstrong> + \u003Cstrong>Connect tab\u003C\u002Fstrong> with copy\u002Fpaste config for Claude Desktop, ChatGPT, Cursor, Windsurf, Continue and JetBrains AI.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Universal SEO read\u003C\u002Fstrong> across Yoast, Rank Math, AIOSEO, The SEO Framework, SureRank, SEOPress, Slim SEO and Squirrly. One ability, eight plugins.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Universal multilingual read\u003C\u002Fstrong> across Polylang, WPML and TranslatePress.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce read-only\u003C\u002Fstrong> when WooCommerce is active.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Spanish translation bundled.\u003C\u002Fstrong> Coexistence with Premium with no conflicts.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>No code. No configuration. Install, activate, run the wizard, paste the URL into your MCP client.\u003C\u002Fp>\n\u003Ch4>Everything Included in Lite (60+ abilities)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Auto-discovery and schema introspection.\u003C\u002Fstrong> \u003Ccode>list-post-types\u003C\u002Fcode>, \u003Ccode>list-taxonomies\u003C\u002Fcode>, \u003Ccode>list-post-statuses\u003C\u002Fcode>, \u003Ccode>list-shortcodes\u003C\u002Fcode>, \u003Ccode>get-permalink-structure\u003C\u002Fcode>, \u003Ccode>list-blocks-registered\u003C\u002Fcode>, \u003Ccode>list-block-patterns\u003C\u002Fcode>, \u003Ccode>list-fse-templates\u003C\u002Fcode>. ACF groups, JetEngine fields and registered meta detected automatically.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Universal content CRUD.\u003C\u002Fstrong> Create, read, update, search and delete posts, pages and any custom post type. Full Gutenberg block markup with a built-in block reference so the AI generates clean blocks. Search filters by status, author, date range, taxonomy, meta. Custom fields and ACF fields read\u002Fwrite. Featured image from URL or Media Library. Bulk-friendly endpoints for agentic workflows.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Site stats and content shortcuts.\u003C\u002Fstrong> \u003Ccode>get-site-stats\u003C\u002Fcode>, \u003Ccode>get-media-stats\u003C\u002Fcode>, \u003Ccode>list-recent-posts\u003C\u002Fcode>, \u003Ccode>list-pending-comments\u003C\u002Fcode>, \u003Ccode>list-scheduled-posts\u003C\u002Fcode>, \u003Ccode>list-trashed-posts\u003C\u002Fcode>, \u003Ccode>list-post-revisions\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Taxonomies.\u003C\u002Fstrong> List, create, update and delete terms in any taxonomy with full hierarchy support.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Comments.\u003C\u002Fstrong> List, read, create, reply, approve, mark as spam, send to trash and delete. Bulk moderation friendly.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Media library.\u003C\u002Fstrong> List attachments with mime\u002Fsize filtering, upload from local files or remote URL, set featured image, attach to posts.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Users (read-only).\u003C\u002Fstrong> Browse users by role with detailed profile view.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Menus, widgets and sidebars (read-only).\u003C\u002Fstrong> \u003Ccode>list-nav-menus\u003C\u002Fcode>, \u003Ccode>list-widgets\u003C\u002Fcode>, \u003Ccode>list-sidebars\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WooCommerce read-only (conditional).\u003C\u002Fstrong> When WooCommerce is active, four abilities appear: \u003Ccode>wc-get-store-info\u003C\u002Fcode>, \u003Ccode>wc-list-products\u003C\u002Fcode>, \u003Ccode>wc-list-recent-orders\u003C\u002Fcode> (with email\u002Fname redaction by default) and \u003Ccode>wc-list-coupons\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>SEO read (universal, 8 plugins).\u003C\u002Fstrong> \u003Ccode>seo-read-meta\u003C\u002Fcode> with adapters for Yoast, Rank Math, AIOSEO, The SEO Framework, SureRank, SEOPress, Slim SEO and Squirrly. Title, description, canonical, robots, OpenGraph and Twitter where the source plugin exposes them.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Multilingual read (universal, 3 plugins).\u003C\u002Fstrong> \u003Ccode>i18n-list-languages\u003C\u002Fcode>, \u003Ccode>i18n-list-translations-for-post\u003C\u002Fcode>, \u003Ccode>i18n-get-post-in-language\u003C\u002Fcode>, \u003Ccode>i18n-list-string-translations\u003C\u002Fcode>. Adapters for Polylang, WPML and TranslatePress.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress options (read-only, security whitelist).\u003C\u002Fstrong> Site title, URL, admin email, timezone, date\u002Ftime format, language, posts per page, permalink structure, reading and writing settings.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Theme customizations (read-only).\u003C\u002Fstrong> Custom logo, site icon, colors, header text, background.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>System diagnostics.\u003C\u002Fstrong> Complete environment report (WordPress, PHP, database, theme, active plugins, server, memory, SSL, REST base, security indicators), \u003Ccode>list-cron-events\u003C\u002Fcode>, \u003Ccode>list-user-roles\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Plugin management.\u003C\u002Fstrong> List every installed plugin and activate or deactivate them.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Recovery and debug.\u003C\u002Fstrong> \u003Ccode>site-health\u003C\u002Fcode> summary, \u003Ccode>clear-recovery\u003C\u002Fcode> for recovery-mode flags, debug logging toggle without editing wp-config.php.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>AI image generation (Gemini).\u003C\u002Fstrong> When a Google Gemini API key is configured in Settings: \u003Ccode>generate-image\u003C\u002Fcode> (1–3 images per prompt, saved to Media Library, optional post attachment) and \u003Ccode>set-featured-from-prompt\u003C\u002Fcode> (generate and assign as featured image in one call). Imagen, multiple aspect ratios, 2K\u002F4K and image editing remain Premium.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>OAuth 2.1 server.\u003C\u002Fstrong> Authorization Code flow with PKCE, Dynamic Client Registration (RFC 7591), per-client \u003Ccode>allowed_abilities\u003C\u002Fcode> allowlist with a visual editor, token revocation, refresh tokens, scope management.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Trust, observability and rate limiting.\u003C\u002Fstrong> Activity Log (30-day retention, daily cron purge, paginated admin viewer). Hourly and daily rate limits per \u003Ccode>client_id\u003C\u002Fcode> (filterable). MCP annotations on every ability. Public \u003Ccode>\u002Fwp-json\u002Fmcpcomal\u002Fv1\u002Fhealth\u003C\u002Fcode> endpoint for uptime monitoring.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Onboarding and connection.\u003C\u002Fstrong> Get Started wizard (environment check, OAuth client creation, AI client picker, live connection test). Connect tab with copy\u002Fpaste config exporter for Claude Desktop, ChatGPT, Cursor, Windsurf, Continue, JetBrains AI and a curl debug snippet. Prompts gallery (30+ curated prompts). “Detected on this site” badges in Status. Navigable Premium catalog inside the Go Premium tab. Spanish translation bundled.\u003C\u002Fp>\n\u003Ch4>Example Requests You Can Make\u003C\u002Fh4>\n\u003Cp>Just talk to your AI assistant naturally:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>“Create a draft blog post titled ‘Summer Travel Guide’ with an introduction and three headings.”\u003C\u002Fli>\n\u003Cli>“Show me all draft posts from the last month and publish the ones tagged ‘ready’.”\u003C\u002Fli>\n\u003Cli>“Find posts in the ‘Tutorials’ category without a featured image.”\u003C\u002Fli>\n\u003Cli>“Create a new category called ‘Case Studies’ under ‘Resources’.”\u003C\u002Fli>\n\u003Cli>“Approve all pending comments from the last 24 hours.”\u003C\u002Fli>\n\u003Cli>“Upload this image from a URL and set it as the featured image for post 42.”\u003C\u002Fli>\n\u003Cli>“Generate a hero image of a sunset over the ocean and set it as the featured image of post 123.” (Gemini)\u003C\u002Fli>\n\u003Cli>“What languages does this site have configured in Polylang? Fetch the Spanish version of the ‘About’ page.”\u003C\u002Fli>\n\u003Cli>“Read the SEO meta of the homepage and list the meta description of every post in the ‘Services’ category.”\u003C\u002Fli>\n\u003Cli>“Show me the last 20 paid WooCommerce orders and which coupons are active.”\u003C\u002Fli>\n\u003Cli>“Show me a complete system diagnostics report and which plugins are currently active.”\u003C\u002Fli>\n\u003Cli>“What content types does this site have? Show me the custom fields registered for the ‘product’ post type.”\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Compatible MCP Clients\u003C\u002Fh4>\n\u003Cp>The plugin works with any MCP client that supports remote servers and OAuth 2.1. Confirmed clients:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Claude Desktop, Claude Code, Cowork\u003C\u002Fstrong> (Anthropic) — full native OAuth 2.1.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>ChatGPT\u003C\u002Fstrong> (OpenAI) — full native OAuth 2.1 with Dynamic Client Registration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>GitHub Copilot in VS Code\u003C\u002Fstrong> — native OAuth (VS Code 1.101+).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cursor AI\u003C\u002Fstrong> — OAuth (some servers may need the mcp-remote bridge).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Windsurf\u003C\u002Fstrong> (Codeium) — OAuth for remote MCP servers.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Continue\u003C\u002Fstrong> — full native OAuth 2.1 in VS Code and IntelliJ.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Augment Code\u003C\u002Fstrong> — native OAuth with one-click approval.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>JetBrains AI Assistant\u003C\u002Fstrong> — MCP support in JetBrains IDEs (2025.2+).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Any application that implements the Model Context Protocol with remote server support should work. There are 500+ MCP clients today and the protocol is the same everywhere.\u003C\u002Fp>\n\u003Ch4>Who Is This For?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Content creators\u003C\u002Fstrong> who want to draft, schedule and update posts using natural language.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Site administrators\u003C\u002Fstrong> who want quick diagnostics, log inspection and bulk content oversight.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Agencies\u003C\u002Fstrong> managing dozens of WordPress sites from a single AI assistant.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce store owners\u003C\u002Fstrong> who want to inspect their catalog, orders and coupons via chat.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multilingual site owners\u003C\u002Fstrong> running Polylang, WPML or TranslatePress.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developers\u003C\u002Fstrong> building agentic workflows on top of WordPress.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Requirements\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>WordPress 6.9 or later (AI Mode requires WordPress 7.0+ — see FAQ).\u003C\u002Fli>\n\u003Cli>PHP 8.3 or later.\u003C\u002Fli>\n\u003Cli>The \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FWordPress\u002Fmcp-adapter\" rel=\"nofollow ugc\">WordPress MCP Adapter\u003C\u002Fa> plugin (the Lite plugin can also load the bundled adapter automatically if no other source provides it).\u003C\u002Fli>\n\u003Cli>An MCP-compatible client.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Need More? Get Premium\u003C\u002Fh4>\n\u003Cp>The \u003Cstrong>\u003Ca href=\"https:\u002F\u002Fplugins.joseconti.com\u002Fen\u002Fproduct\u002Fmcp-content-manager-for-wordpress\u002F\" rel=\"nofollow ugc\">Premium version\u003C\u002Fa>\u003C\u002Fstrong> turns your WordPress site into a full agentic workstation: \u003Cstrong>575 abilities across 17 categories\u003C\u002Fstrong>, with everything Lite has, plus:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>WooCommerce write (8 modules):\u003C\u002Fstrong> products with variations and attributes, orders edit, refunds, customers CRUD, sales analytics, shipping zones, webhooks, store settings and subscriptions across 5 platforms (WooCommerce Subscriptions, Yith, Sumo, ASWC, WBTE).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO suite:\u003C\u002Fstrong> universal write across the same 8 plugins as Lite + a content auditor with scoring and bulk fixes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security and recovery:\u003C\u002Fstrong> 23 hardening measures with audit scoring, hacked-site cleanup (core integrity, malware scan, DB injection detection, rogue admin detection, salt regeneration), maintenance mode and Time Machine backups with one-click rollback.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Performance:\u003C\u002Fstrong> adapter for 7 cache plugins (WP Rocket, W3TC, WP Super Cache, LiteSpeed, SG Optimizer, Hummingbird, FlyingPress) and a profiler with 0–100 scoring and 20 built-in optimizations.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WP-CLI bridge\u003C\u002Fstrong> with per-command permissions, default 16-command blocklist and timeout\u002Fshell-metachar protection.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin and theme installation\u003C\u002Fstrong> from WordPress.org or ZIP URL, with a 14-phase site-creation guide.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Users, roles and multisite:\u003C\u002Fstrong> users CRUD, roles and capabilities CRUD with escalation prevention, network-wide site CRUD and cross-site ability execution.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full Site Editing write:\u003C\u002Fstrong> navigation, theme.json global styles, fonts, templates and widgets.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom fields write\u003C\u002Fstrong> across ACF, Meta Box, Pods and JetEngine (full repeater and flexible content support).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multilingual write\u003C\u002Fstrong> with site-wide AI translation queueing across Polylang, WPML and TranslatePress.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI image generation extended:\u003C\u002Fstrong> Google Gemini and Imagen with 10 aspect ratios, 1K\u002F2K\u002F4K, PNG\u002FJPEG and image editing.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File manager, htaccess manager and wp-config\u003C\u002Fstrong> safe write.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Action logger with diff\u003C\u002Fstrong> and \u003Cstrong>HMAC-signed confirmations\u003C\u002Fstrong> on 30+ destructive abilities — nothing destructive runs without explicit cryptographic consent.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced diagnostics:\u003C\u002Fstrong> hook inspector, REST route discovery, shortcode registry, Action Scheduler, SSL\u002FDNS analysis and a coding-guidelines validator.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fplugins.joseconti.com\u002Fen\u002Fproduct\u002Fmcp-content-manager-for-wordpress\u002F\" rel=\"nofollow ugc\">Get MCP Content Manager Premium\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to the following external services:\u003C\u002Fp>\n\u003Ch4>WordPress.org API\u003C\u002Fh4>\n\u003Cp>The system diagnostics feature tests whether your server can make outgoing HTTP requests (both GET and POST) by connecting to the WordPress.org core version check API. This is used only when the user explicitly requests a system diagnostics report. The data sent is the WordPress version number. No personal data is transmitted.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Service: \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002F\" rel=\"ugc\">WordPress.org\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fabout\u002Fterms-of-service\u002F\" rel=\"ugc\">Terms of Use\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\" rel=\"ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>OAuth 2.1 Authentication\u003C\u002Fh4>\n\u003Cp>This plugin implements an OAuth 2.1 server so that MCP clients (Claude, ChatGPT, Copilot, Cursor, etc.) can authenticate with your site. The OAuth flow happens entirely between the MCP client application and your own WordPress site. No data is sent to any third-party service by the plugin during authentication. The MCP client connects directly to your site’s REST API endpoints.\u003C\u002Fp>\n\u003Ch4>Google Gemini (optional, only when image generation is configured)\u003C\u002Fh4>\n\u003Cp>If — and only if — you configure a Google Gemini API key in \u003Cstrong>Settings > MCP Content Manager Lite > Settings\u003C\u002Fstrong>, the \u003Ccode>generate-image\u003C\u002Fcode> and \u003Ccode>set-featured-from-prompt\u003C\u002Fcode> abilities call Google’s Gemini API at \u003Ccode>generativelanguage.googleapis.com\u003C\u002Fcode>. The data sent is: the prompt provided by the AI client, the model id you have configured (default \u003Ccode>gemini-2.0-flash-exp\u003C\u002Fcode>) and the API key. The response (a base64-encoded image) is saved to the Media Library and the prompt is stored as attachment meta. No data is sent to Google when the API key is empty or the abilities are not invoked.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Service: \u003Ca href=\"https:\u002F\u002Fai.google.dev\u002F\" rel=\"nofollow ugc\">Google AI \u002F Gemini\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fai.google.dev\u002Fgemini-api\u002Fterms\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fprivacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","Manage WordPress from Claude, ChatGPT, Copilot or any MCP client. 60+ abilities, OAuth 2.1, allowlists, activity log, multilingual and SEO read.",90,965,"2026-04-29T19:58:00.000Z","6.9.5","8.3",[71,53,21,23,24],"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fmcp-content-manager-lite\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmcp-content-manager-lite.1.1.0.zip",{"slug":92,"name":93,"version":94,"author":95,"author_profile":96,"description":97,"short_description":98,"active_installs":99,"downloaded":100,"rating":11,"num_ratings":11,"last_updated":101,"tested_up_to":16,"requires_at_least":102,"requires_php":18,"tags":103,"homepage":105,"download_link":106,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":27,"fetched_at":28},"bcs-mcp-manager","AI Connector – MCP for Claude, ChatGPT, Gemini & More","1.0.0","bytecorestack","https:\u002F\u002Fprofiles.wordpress.org\u002Fbytecorestack\u002F","\u003Cp>\u003Cstrong>AI Connector\u003C\u002Fstrong> turns your website into a working \u003Ca href=\"https:\u002F\u002Fmodelcontextprotocol.io\u002F\" rel=\"nofollow ugc\">Model Context Protocol (MCP)\u003C\u002Fa> endpoint — the open standard that lets AI assistants like \u003Cstrong>Claude\u003C\u002Fstrong>, \u003Cstrong>ChatGPT\u003C\u002Fstrong>, and \u003Cstrong>Gemini\u003C\u002Fstrong> connect directly to WordPress and take real action instead of just talking about it.\u003C\u002Fp>\n\u003Cp>Think of AI Connector as the missing bridge between AI and WordPress. Instead of copying an answer out of a chat window and pasting it into wp-admin by hand, your AI assistant becomes an AI agent working inside your site: it reads real data, writes real content, and makes real changes through a secure, permission-checked WordPress integration.\u003C\u002Fp>\n\u003Cp>As a WordPress AI plugin, AI Connector gives any MCP-compatible AI assistant structured, authenticated access to your site’s actual content and workflows — no scraping, no guessing, no manual data exports. Once connected, your AI agent can draft and publish posts, manage WooCommerce orders, fix SEO metadata, moderate comments, update Elementor pages, and call on \u003Cstrong>150+ WordPress AI tools\u003C\u002Fstrong>, each one checked against the connecting user’s real WordPress capabilities and recorded in an Activity Log you control.\u003C\u002Fp>\n\u003Cp>This is what WordPress automation looks like when it runs on an open protocol instead of a proprietary one: no vendor lock-in, no third-party cloud service relaying your data, and no static API key to manage by hand. Your AI assistant authenticates directly with your site over \u003Cstrong>OAuth 2.0 with PKCE\u003C\u002Fstrong> — the same authorization flow used by Google, Microsoft, and Slack — and every action it takes is capability-checked, logged, and fully reversible from \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Reset OAuth State\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>Whether you think of it as an AI integration, an AI workflow tool, or simply the fastest way to connect an AI assistant to WordPress, AI Connector is built to be the MCP server for WordPress you set up once and keep using.\u003C\u002Fp>\n\u003Ch4>Links\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fbytecorestack.com\u002Fplugins\u002Fai-connector\u002F\" rel=\"nofollow ugc\">Plugin homepage\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fbcs-mcp-manager\u002F\" rel=\"ugc\">Support forum\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmodelcontextprotocol.io\u002F\" rel=\"nofollow ugc\">Model Context Protocol specification\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why WordPress Sites Need an AI Automation Plugin\u003C\u002Fh4>\n\u003Cp>Without MCP, “AI help” for WordPress usually means: you open a chat window, describe what you want, copy the AI’s answer, switch back to wp-admin, and paste it in by hand. That works for a single blog post. It breaks down completely for anything involving real data — bulk SEO fixes, order refunds, comment moderation, or multi-step content workflows.\u003C\u002Fp>\n\u003Cp>MCP removes the copy-paste step entirely. Your AI assistant gets a structured, authenticated, capability-aware connection to your actual WordPress install, so it can query real data and make real changes — the same way it already works with your file system or terminal in tools like Claude Code, just pointed at your website instead. That’s the difference between an AI chatbot and genuine WordPress AI automation.\u003C\u002Fp>\n\u003Ch4>What Can an AI Agent Do With WordPress?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>“Draft and publish a blog post about [topic], generate a featured image, and tag it correctly.”\u003C\u002Fli>\n\u003Cli>“Show me yesterday’s WooCommerce orders over $100 and refund order #1042.”\u003C\u002Fli>\n\u003Cli>“Find every page with a missing or duplicate SEO title and fix it.”\u003C\u002Fli>\n\u003Cli>“Approve all pending comments from logged-in customers, spam the rest.”\u003C\u002Fli>\n\u003Cli>“Duplicate this Elementor page, swap the hero image, and update the headline.”\u003C\u002Fli>\n\u003Cli>“Create a new menu item for the spring sale and add it to the primary navigation.”\u003C\u002Fli>\n\u003Cli>“List my WooCommerce coupons expiring this month and extend them by two weeks.”\u003C\u002Fli>\n\u003Cli>“Pull this week’s Gravity Forms entries into a summary table.”\u003C\u002Fli>\n\u003Cli>“Restore the homepage to the revision from before my last edit.”\u003C\u002Fli>\n\u003Cli>“Clear the object cache and tell me how big my database is.”\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why Choose AI Connector for WordPress Automation?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>150+ tools, 20 categories\u003C\u002Fstrong> — one of the largest verified MCP tool sets available for WordPress, covering content, commerce, SEO, media, users, taxonomies, menus, plugins, cache, and more\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-client, not single-vendor\u003C\u002Fstrong> — works with AI assistants from Anthropic (Claude), OpenAI (ChatGPT), and Google (Gemini) out of the box, alongside Cursor, Windsurf, and any other client implementing the MCP 2025-11-25 specification\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real OAuth 2.0, not a shared API key\u003C\u002Fstrong> — full authorization code flow with PKCE (S256), Dynamic Client Registration (RFC 7591), and discovery endpoints (RFC 8414) — no static secret to leak or rotate by hand\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Conservative by design\u003C\u002Fstrong> — no MCP tool can ever create a new WordPress user, and role changes require the \u003Ccode>promote_users\u003C\u002Fcode> capability specifically, not just \u003Ccode>edit_users\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Local, redacted activity logging\u003C\u002Fstrong> — the Activity Log records every tool call (tool name, timestamp, client, status, and the call’s parameters\u002Fresult for audit and debugging) entirely in your own database; sensitive-looking values (passwords, tokens, secrets, keys) are automatically redacted before anything is written, and nothing is ever sent off your server\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero telemetry, ever\u003C\u002Fstrong> — no analytics, no tracking pixels, no “phone home” of any kind. The only outbound request the plugin can make is the one explicit image-download tool, and only when your AI client asks for it\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Grows with your stack\u003C\u002Fstrong> — WooCommerce, Advanced Custom Fields, Elementor, and Gravity Forms tools activate automatically the moment those plugins are detected, with zero extra configuration\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Open to extend\u003C\u002Fstrong> — register your own custom MCP tools from any plugin or theme with one function call\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Ideal For\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Agencies and freelancers\u003C\u002Fstrong> who want to run day-to-day WordPress maintenance through an AI assistant instead of clicking through wp-admin one task at a time\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce store owners\u003C\u002Fstrong> who want an AI agent that can check orders, adjust stock, and manage coupons on request\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO teams and content editors\u003C\u002Fstrong> running bulk metadata fixes, content audits, or multi-step publishing workflows\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developers\u003C\u002Fstrong> who want a real WordPress AI integration to build custom AI automation and AI workflow tools on top of\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Anyone already using Claude, ChatGPT, Cursor, or Windsurf\u003C\u002Fstrong> who wants those tools to actually reach into WordPress instead of just describing what to do next\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Supported AI Assistants & MCP Clients\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Claude.ai\u003C\u002Fstrong> — Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Integrations \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add integration \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Custom MCP\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Claude Desktop\u003C\u002Fstrong> — add the MCP URL to \u003Ccode>claude_desktop_config.json\u003C\u002Fcode> under \u003Ccode>mcpServers\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Claude Code\u003C\u002Fstrong> — connects over the same Streamable HTTP MCP endpoint\u003C\u002Fli>\n\u003Cli>\u003Cstrong>ChatGPT\u003C\u002Fstrong> — Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Connectors \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add connector \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> MCP Server\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Gemini\u003C\u002Fstrong> — connect via Google AI Studio MCP integrations\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cursor (0.45+)\u003C\u002Fstrong> — Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> MCP \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add New Server \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> HTTP (Streamable HTTP transport)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Windsurf\u003C\u002Fstrong> — MCP settings panel, supports both Streamable HTTP and legacy SSE\u003C\u002Fli>\n\u003Cli>\u003Cstrong>VS Code, Cline, Continue, Zed, JetBrains\u003C\u002Fstrong> and any other editor or IDE with MCP client support\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Postman, Insomnia\u003C\u002Fstrong> and other API tools with MCP request support\u003C\u002Fli>\n\u003Cli>Any custom client or framework that implements the MCP 2025-11-25 specification\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WordPress AI Tools by Category (159 Tools, Verified)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Posts\u003C\u002Fstrong> — 14 tools (create, read, update, delete, duplicate, bulk trash, schedule, search, count, post types & statuses, post format, password protection)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pages\u003C\u002Fstrong> — 8 tools (CRUD, duplicate, page templates)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Media\u003C\u002Fstrong> — 11 tools (browse, upload from file or URL, update metadata, set featured image, regenerate thumbnails, attachment metadata, image sizes, count)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Taxonomies\u003C\u002Fstrong> — 11 tools (categories, tags, custom taxonomies, term meta, term assignment)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Comments\u003C\u002Fstrong> — 8 tools (CRUD, approve, spam, trash, pending queue)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Users\u003C\u002Fstrong> — 10 tools (list, view, update, delete, sessions, roles, password reset — no creation tool, by design)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Meta\u003C\u002Fstrong> — 6 tools (post meta and user meta read\u002Fwrite\u002Fdelete)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Menus\u003C\u002Fstrong> — 10 tools (menus, menu items, reordering, location assignment)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugins & Themes\u003C\u002Fstrong> — 7 tools (list, activate, deactivate, active theme, theme mods, custom CSS)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO\u003C\u002Fstrong> — 2 tools (read and update SEO meta fields)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Site \u002F Options\u003C\u002Fstrong> — 9 tools (site info, site health, server info, permalink structure, plugin settings, database size, debug log, send email)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Revisions\u003C\u002Fstrong> — 5 tools (history and restore)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cache\u003C\u002Fstrong> — 5 tools (flush, purge, optimize tables, transients)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blocks\u003C\u002Fstrong> — 2 tools (parse blocks, block patterns, reusable blocks)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Widgets\u003C\u002Fstrong> — 2 tools (registered sidebars, sidebar widgets)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developer Tools\u003C\u002Fstrong> — 5 tools (shortcode execution, cron jobs, rewrite rules, and more)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce\u003C\u002Fstrong> \u003Cem>(activates automatically)\u003C\u002Fem> — 33 tools (products, variations, attributes, coupons, orders, refunds, customers, shipping zones, tax rates, store stats, payment gateways)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Custom Fields\u003C\u002Fstrong> \u003Cem>(activates automatically)\u003C\u002Fem> — 3 tools (field groups, field values, field updates)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Elementor\u003C\u002Fstrong> \u003Cem>(activates automatically)\u003C\u002Fem> — 6 tools (clone page, bulk text replace, image swap, page outline, template import\u002Flisting)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Gravity Forms\u003C\u002Fstrong> \u003Cem>(activates automatically)\u003C\u002Fem> — 2 tools (list forms, read entries)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How to Connect Claude, ChatGPT, Gemini & More\u003C\u002Fh4>\n\u003Cp>Point your AI client to your MCP URL:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>https:\u002F\u002Fyoursite.com\u002Fwp-json\u002Fbcs-mcp\u002Fv1\u002Fmcp\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The client automatically discovers the OAuth server via \u003Ccode>\u002F.well-known\u002Foauth-protected-resource\u003C\u002Fcode>, registers itself using Dynamic Client Registration, and redirects to your site’s authorization page for one-time approval. All future requests use short-lived access tokens that refresh automatically — there is nothing to copy into a config file by hand for clients that support DCR.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Claude.ai:\u003C\u002Fstrong> Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Integrations \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add integration \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Custom MCP \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> paste the MCP URL.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Claude Desktop:\u003C\u002Fstrong> Add to \u003Ccode>claude_desktop_config.json\u003C\u002Fcode>:\u003Cbr \u002F>\n    {“mcpServers”:{“wordpress”:{“url”:”https:\u002F\u002Fyoursite.com\u002Fwp-json\u002Fbcs-mcp\u002Fv1\u002Fmcp”,”transport”:”http”}}}\u003C\u002Fp>\n\u003Cp>\u003Cstrong>ChatGPT:\u003C\u002Fstrong> Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Connectors \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add connector \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> MCP Server \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> paste the MCP URL.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Cursor (0.45+):\u003C\u002Fstrong> Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> MCP \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add New Server \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> select HTTP \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> paste the MCP URL. Cursor uses the \u003Ccode>Mcp-Session-Id\u003C\u002Fcode> header returned by the server on initialization to track sessions.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Windsurf:\u003C\u002Fstrong> Open the MCP settings panel, add a new server with the MCP URL. Recent Windsurf versions use Streamable HTTP; older versions fall back to the legacy SSE transport automatically.\u003C\u002Fp>\n\u003Ch4>AI Connector Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>150+ WordPress MCP tools\u003C\u002Fstrong> across 20 categories — see the full breakdown above\u003C\u002Fli>\n\u003Cli>\u003Cstrong>OAuth 2.0 with PKCE\u003C\u002Fstrong> — full authorization code flow with Dynamic Client Registration (RFC 7591), refresh tokens, and discovery endpoints (RFC 8414)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Streamable HTTP transport\u003C\u002Fstrong> (MCP 2025-11-25) — the primary transport used by all modern AI clients\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Legacy SSE transport\u003C\u002Fstrong> — automatic fallback for older client versions, with \u003Ccode>X-Accel-Buffering: no\u003C\u002Fcode> so nginx doesn’t buffer the stream\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Activity log\u003C\u002Fstrong> — every tool call recorded with AI client detection, color-coded client tags, search\u002Ffilter by client, status, and date range, bulk delete, and one-click CSV export — sensitive-looking parameter values (passwords, tokens, secrets) are redacted before being written\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Rate limiting\u003C\u002Fstrong> — 60 requests per minute per IP, enforced automatically on every MCP request\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP allowlist\u003C\u002Fstrong> — optionally restrict MCP access to specific IPs or CIDR ranges\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin dashboard\u003C\u002Fstrong> — live server status, MCP endpoint URL, OAuth client count, today’s success\u002Ffail counts, recent activity feed, and a searchable WordPress tools browser\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WP Dashboard widget\u003C\u002Fstrong> — 7-day activity sparkline with success\u002Ferror breakdown, right on your wp-admin home screen\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built-in setup guides\u003C\u002Fstrong> — copy-paste connection instructions for every supported client, generated with your site’s real MCP URL\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Translation-ready\u003C\u002Fstrong> — ships with a complete \u003Ccode>.pot\u003C\u002Fcode> file in \u003Ccode>\u002Flanguages\u003C\u002Fcode> so translators can localize the plugin into any language\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developer-friendly\u003C\u002Fstrong> — extend with \u003Ccode>bcs_mcp_register_tool()\u003C\u002Fcode> or the \u003Ccode>bcs_mcp_tools\u003C\u002Fcode> filter\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WooCommerce, Elementor, ACF & Gravity Forms Integration\u003C\u002Fh4>\n\u003Cp>Tools for these plugins are included in the box but only activate when the respective plugin is installed and active. No errors are thrown if a plugin is absent, and nothing extra needs configuring. The MCP tool list shown to a connected AI client only ever includes tools whose dependencies are actually satisfied on your site — so a site without WooCommerce simply never advertises WooCommerce tools to the AI.\u003C\u002Fp>\n\u003Ch4>Multisite Support\u003C\u002Fh4>\n\u003Cp>AI Connector works on WordPress multisite networks the same way it works on a single site: each site in the network has its own settings, its own MCP endpoint, and its own Activity Log. There is no cross-site tool access — an AI client connected to one site can never reach another site’s data through this plugin.\u003C\u002Fp>\n\u003Ch4>Extending AI Connector (Developer API)\u003C\u002Fh4>\n\u003Cp>Register custom tools from any plugin or theme:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>bcs_mcp_register_tool( 'my_tool', 'Description', $schema, $callback );\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Or use the \u003Ccode>bcs_mcp_tools\u003C\u002Fcode> filter directly to add, modify, or remove tools before they’re advertised to a connecting AI client.\u003C\u002Fp>\n\u003Ch4>Security & Permissions\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>All tool calls verify WordPress capabilities (\u003Ccode>current_user_can\u003C\u002Fcode>) before executing — an AI client can never do more than the authorizing user is allowed to do\u003C\u002Fli>\n\u003Cli>No MCP tool can create new WordPress users — user accounts must be created through wp-admin, full stop\u003C\u002Fli>\n\u003Cli>Role changes (\u003Ccode>wp_assign_user_role\u003C\u002Fcode>) require the \u003Ccode>promote_users\u003C\u002Fcode> capability, not just \u003Ccode>edit_users\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>OAuth tokens are SHA-256 hashed before database storage — plain tokens are never stored\u003C\u002Fli>\n\u003Cli>PKCE (S256) is required for all authorization flows; plain challenges are rejected\u003C\u002Fli>\n\u003Cli>Dynamic Client Registration is rate-limited to 10 registrations per IP per minute\u003C\u002Fli>\n\u003Cli>Sensitive meta keys (\u003Ccode>user_pass\u003C\u002Fcode>, \u003Ccode>session_tokens\u003C\u002Fcode>, and similar) are permanently blocked from read\u002Fwrite, with no setting to disable the block\u003C\u002Fli>\n\u003Cli>The Activity Log stores tool name, timestamp, client, status, and the call’s parameters\u002Fresult for audit purposes, all locally in your own database — any value that looks like a password, token, secret, or key is redacted before it’s written, and large content fields are truncated\u003C\u002Fli>\n\u003Cli>Outbound image downloads validate URLs against a blocklist of private\u002Floopback IP ranges (SSRF protection) and enforce a 20 MB size limit\u003C\u002Fli>\n\u003Cli>All admin AJAX actions are protected by nonce verification and a \u003Ccode>manage_options\u003C\u002Fcode> capability check\u003C\u002Fli>\n\u003Cli>Session termination (\u003Ccode>DELETE \u002Fmcp\u003C\u002Fcode>) requires a valid bearer token\u003C\u002Fli>\n\u003Cli>The MCP server ships \u003Cstrong>disabled by default\u003C\u002Fstrong> — nothing is exposed until you explicitly enable it in Settings\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin operates primarily as an \u003Cstrong>inbound\u003C\u002Fstrong> API server — AI clients connect to it, not the other way around. No data is sent to any external service automatically or in the background.\u003C\u002Fp>\n\u003Ch4>Image download via wp_upload_media_from_url\u003C\u002Fh4>\n\u003Cp>The \u003Ccode>wp_upload_media_from_url\u003C\u002Fcode> MCP tool, when explicitly invoked by an authenticated AI client (e.g. Claude), makes a single outgoing HTTP GET request to download an image from the URL the AI client provides. This request:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Is only made when the tool is called by a connected, OAuth-authenticated MCP client\u003C\u002Fli>\n\u003Cli>Carries no personal data beyond the image URL itself\u003C\u002Fli>\n\u003Cli>Is validated against a blocklist of private\u002Floopback IP ranges before the request is made\u003C\u002Fli>\n\u003Cli>Is subject to a 20 MB size limit\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>No data is sent to the plugin author’s servers at any time. This plugin does not include analytics, telemetry, or tracking of any kind.\u003C\u002Fp>\n","Connect Claude, ChatGPT, Gemini, Cursor, and other AI assistants to your WordPress site using the Model Context Protocol (MCP). 150+ tools, OAuth 2.",20,140,"2026-07-06T18:02:00.000Z","6.2",[104,20,53,21,23],"ai-connector","https:\u002F\u002Fbytecorestack.com\u002Fplugins\u002Fai-connector\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbcs-mcp-manager.1.0.0.zip",{"slug":108,"name":109,"version":110,"author":111,"author_profile":112,"description":113,"short_description":114,"active_installs":115,"downloaded":116,"rating":13,"num_ratings":117,"last_updated":118,"tested_up_to":16,"requires_at_least":119,"requires_php":18,"tags":120,"homepage":122,"download_link":123,"security_score":124,"vuln_count":125,"unpatched_count":11,"last_vuln_date":126,"fetched_at":28},"royal-mcp","Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini","1.4.36","Royal Plugins","https:\u002F\u002Fprofiles.wordpress.org\u002Froyalpluginsteam\u002F","\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002Fpf-mdRnXezM?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002F6P7TU1Tva3k?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Cp>Royal MCP is a security-first Model Context Protocol (MCP) server for WordPress. It gives AI platforms like Claude, ChatGPT, and Google Gemini structured access to your WordPress content — with authentication, rate limiting, and audit logging that most MCP implementations skip entirely.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>First-time setup walkthrough (with videos):\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Froyalplugins.com\u002Fsupport\u002Froyal-mcp\u002Fconnecting-to-claude\u002F\" rel=\"nofollow ugc\">royalplugins.com\u002Fsupport\u002Froyal-mcp\u002Fconnecting-to-claude\u002F\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>According to \u003Ca href=\"https:\u002F\u002Fmcpplaygroundonline.com\u002Fblog\u002Fmcp-server-security-complete-guide-2026\" rel=\"nofollow ugc\">recent security research\u003C\u002Fa>, 41% of public MCP servers have no authentication and respond to tool calls without any credentials. Royal MCP takes the opposite approach: every MCP session requires an API key, every request is rate-limited, and every interaction is logged.\u003C\u002Fp>\n\u003Ch4>Why Security Matters for MCP\u003C\u002Fh4>\n\u003Cp>MCP gives AI agents the ability to read, create, update, and delete your WordPress content. Without proper authentication, anyone who discovers your MCP endpoint can:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Read all your posts, pages, and media\u003C\u002Fli>\n\u003Cli>Create or delete content\u003C\u002Fli>\n\u003Cli>Access user data and plugin information\u003C\u002Fli>\n\u003Cli>Overwhelm your server with rapid-fire requests\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Royal MCP prevents all of this with API key authentication on session initialization, timing-safe key comparison, per-IP rate limiting (60 requests\u002Fminute), and a full activity log of every MCP interaction.\u003C\u002Fp>\n\u003Ch4>Free, Self-Hosted, Fully Featured\u003C\u002Fh4>\n\u003Cp>Royal MCP is fully featured in its free, GPL-licensed release. There is no Pro version &mdash; all tools ship in the wp.org plugin, and updates go through the standard WordPress plugin updater.\u003C\u002Fp>\n\u003Cp>Your credentials stay on your server. Royal MCP runs entirely inside WordPress: API keys, OAuth tokens, and session state all live in your own database. Royal MCP makes no outbound connections to Royal Plugins&rsquo; own servers &mdash; no license check, no telemetry, no traffic beacon. If you prefer to keep AI inference local too, Ollama and LM Studio are first-class platforms alongside Claude, ChatGPT, and Gemini.\u003C\u002Fp>\n\u003Ch4>69 Core Tools + 60 Integration Tools\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>WordPress Core (69 tools):\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Posts – create, read, update, delete, search, count (any registered public post type, featured images supported)\u003C\u002Fli>\n\u003Cli>Pages – full CRUD with parent page support\u003C\u002Fli>\n\u003Cli>Post Types – discover all registered public post types on the site\u003C\u002Fli>\n\u003Cli>Post Revisions – list revision history and roll a post back to any prior version\u003C\u002Fli>\n\u003Cli>Media – browse, upload from URL or base64, update alt text\u002Fcaption\u002Ftitle\u002Fdescription, set as featured image, delete\u003C\u002Fli>\n\u003Cli>Comments – create, read, delete; full moderation suite (list pending, approve, mark spam, trash)\u003C\u002Fli>\n\u003Cli>Users – display names and roles (emails and usernames are not exposed)\u003C\u002Fli>\n\u003Cli>Categories & Tags & Custom Taxonomies – create, update (rename\u002Fre-slug\u002Fedit\u002Fmove), delete, assign, count, discover all registered taxonomies\u003C\u002Fli>\n\u003Cli>Term Meta – read, update, delete (most useful for term-level SEO meta – titles, descriptions, focus keywords stored against categories and tags)\u003C\u002Fli>\n\u003Cli>Menus – list menus, list menu items, create \u002F update \u002F delete \u002F reorder menu items\u003C\u002Fli>\n\u003Cli>Post Meta – read, update, delete custom fields (works with ACF, MetaBox, JetEngine, Pods, CPT UI)\u003C\u002Fli>\n\u003Cli>SEO Meta – read and write Yoast SEO or Rank Math title\u002Fdescription\u002Ffocus keyword\u002Frobots\u002FOG fields (auto-detects active SEO plugin)\u003C\u002Fli>\n\u003Cli>Site Info – site name, description, WordPress version, timezone\u003C\u002Fli>\n\u003Cli>Plugins & Themes – list installed plugins and themes with active status\u003C\u002Fli>\n\u003Cli>Theme Appearance – get active theme, read\u002Fwrite theme mods (gated by admin toggle + allowlist), read\u002Fwrite Custom CSS\u003C\u002Fli>\n\u003Cli>Search – full-text content search across post types\u003C\u002Fli>\n\u003Cli>Permalink Structure – read and update permalink settings (gated by admin toggle)\u003C\u002Fli>\n\u003Cli>Options – read allowlisted core options, read full plugin settings by slug (sensitive keys redacted), and write to allowlisted options when an admin enables it\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Plugin Integrations (Conditional)\u003C\u002Fh4>\n\u003Cp>Royal MCP automatically detects compatible plugins and adds specialized MCP tools. No configuration needed — if the plugin is active, the tools appear.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WooCommerce Integration (26 tools):\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen WooCommerce is active, AI agents can manage your store end-to-end:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Browse and search products by category, status, or type\u003C\u002Fli>\n\u003Cli>Create and update simple and variable products with prices, SKUs, stock levels\u003C\u002Fli>\n\u003Cli>Manage variable products — list, get, create, update, delete, and batch-update product variations\u003C\u002Fli>\n\u003Cli>Manage global attributes (\u003Ccode>pa_*\u003C\u002Fcode> taxonomies) — list registered attributes, list attribute terms, register new attributes, assign attributes to a product as variation axes\u003C\u002Fli>\n\u003Cli>Manage coupons — list, search by code, get, create, update, delete (trash or permanent), and bulk-purge trash; supports all standard WC coupon fields (discount type, expiry, usage limits, product\u002Fcategory restrictions, email allowlists)\u003C\u002Fli>\n\u003Cli>View orders, order details, and update order status\u003C\u002Fli>\n\u003Cli>List customers with order count and total spent\u003C\u002Fli>\n\u003Cli>Get store statistics — revenue, order count, average order value by period\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Elementor Integration (7 tools):\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen Elementor (free or Pro) is active, AI agents can clone and customize existing Elementor pages without trying to generate page-builder JSON from scratch:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Clone an existing Elementor page with a new title and fresh element IDs (so the duplicate opens in the editor without ID collisions)\u003C\u002Fli>\n\u003Cli>Bulk-replace text across heading, text-editor, button, image-box, icon-box, icon-list, testimonial, tabs, accordion, toggle, star-rating, call-to-action, and flip-box widgets\u003C\u002Fli>\n\u003Cli>Swap image URLs across image, image-box, background_image, and gallery widget settings\u003C\u002Fli>\n\u003Cli>Get a compact outline of any page (section\u002Fcontainer hierarchy, widget types, text snippets) so Claude can reason over a full page in a few KB instead of the raw JSON\u003C\u002Fli>\n\u003Cli>List saved templates from the Elementor template library and import templates from JSON\u003C\u002Fli>\n\u003Cli>Atomic widgets (Elementor 4.0+ Editor V4 elements) pass through opaque — we never decode atomic schemas because Elementor itself may shift them. Widget-level creation from scratch is intentionally out of scope; the design commitment is to work from an existing-known-good source.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Advanced Custom Fields Integration (4 tools):\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen ACF (free or Pro) is active, AI agents can read and write ACF fields with the field-type-aware formatting the ACF UI uses — instead of the raw serialized values WordPress meta returns:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Read a single ACF field, formatted per its Return Format setting (hydrated post objects, parsed repeater rows, image arrays, etc.)\u003C\u002Fli>\n\u003Cli>Read every ACF field on a post in one call, with name\u002Flabel\u002Ftype\u002Fvalue bundled — the most efficient way for an AI to discover what fields exist and read them all\u003C\u002Fli>\n\u003Cli>Update an ACF field with type-aware value handling (scalar for text\u002Fnumber, array for repeaters and flex content, post ID for relationships, attachment ID for images)\u003C\u002Fli>\n\u003Cli>Enumerate ACF field groups on the site, optionally filtered by post type — for AI-driven discovery of available custom fields before reading\u002Fwriting\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>GuardPress Integration (7 tools):\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen GuardPress is active, AI agents can monitor your site security:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Get current security score and grade with factor breakdown\u003C\u002Fli>\n\u003Cli>View security statistics — failed logins, blocked IPs, alerts\u003C\u002Fli>\n\u003Cli>Run vulnerability scans and review results\u003C\u002Fli>\n\u003Cli>List blocked IP addresses and failed login attempts\u003C\u002Fli>\n\u003Cli>Browse the security audit log filtered by severity\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>SiteVault Integration (6 tools):\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen SiteVault is active, AI agents can manage your backups:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>List available backups filtered by status or type\u003C\u002Fli>\n\u003Cli>Trigger new backups (full, database, files, plugins, themes)\u003C\u002Fli>\n\u003Cli>Check backup progress in real time\u003C\u002Fli>\n\u003Cli>View backup statistics — total size, last backup, counts\u003C\u002Fli>\n\u003Cli>List and review backup schedules\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>ForgeCache Integration (3 tools):\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen ForgeCache is active, AI agents can manage your page cache:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Clear the entire cache, or purge a specific URL\u003C\u002Fli>\n\u003Cli>View cache statistics — hit rate, file count, total size\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Royal Ledger Integration (4 tools):\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen Royal Ledger is active, AI agents can review your software costs and license data:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>List recurring software costs and renewal dates\u003C\u002Fli>\n\u003Cli>Get cost summaries grouped by month, vendor, or category\u003C\u002Fli>\n\u003Cli>List stored license keys (key VALUES are never exposed — only masked previews; decryption requires logging into wp-admin)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Royal Links Integration (3 tools):\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen Royal Links is active, AI agents can manage your branded short links:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>List existing links with click counts and target URLs\u003C\u002Fli>\n\u003Cli>Create new branded short links\u003C\u002Fli>\n\u003Cli>Get click statistics for any link\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Royal MCP and the WordPress Core Abilities API\u003C\u002Fh4>\n\u003Cp>WordPress 6.9 shipped the Abilities API in November 2025 — a primitive that lets plugins register typed capabilities AI agents can call. Core ships three default abilities (site info, user info, environment info) and the \u003Ccode>wordpress\u002Fmcp-adapter\u003C\u002Fcode> package bridges abilities to the MCP protocol.\u003C\u002Fp>\n\u003Cp>Royal MCP is a complete, production-ready MCP server that predates the official adapter. It runs the full Streamable HTTP transport, enforces API key authentication on every request, ships OAuth 2.0 for Claude Desktop’s native connector flow, rate-limits per-IP, redacts sensitive data, and logs every interaction. Out of the box it includes 67 tools for WordPress core operations plus 60 integration tools that auto-load when WooCommerce, GuardPress, SiteVault, ForgeCache, Royal Ledger, Royal Links, Elementor, or Advanced Custom Fields (ACF) is active.\u003C\u002Fp>\n\u003Ch4>Supported AI Platforms\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Claude (Anthropic)\u003C\u002Fstrong> – Full MCP support via Claude Desktop, Claude Code, and VS Code\u003C\u002Fli>\n\u003Cli>\u003Cstrong>OpenAI \u002F ChatGPT\u003C\u002Fstrong> – GPT-5.5, GPT-5, GPT-5 Mini, o3\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google Gemini\u003C\u002Fstrong> – Gemini 3.5 Flash, 3.1 Flash-Lite\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Groq\u003C\u002Fstrong> – Llama 3.3, Llama 3.1, GPT-OSS\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Azure OpenAI\u003C\u002Fstrong> – Azure-hosted OpenAI deployments\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AWS Bedrock\u003C\u002Fstrong> – Claude, Llama, Titan models\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Ollama \u002F LM Studio\u003C\u002Fstrong> – Local self-hosted models (no external data transmission)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom MCP Servers\u003C\u002Fstrong> – Connect to any MCP-compatible endpoint\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Compatible Clients & Frameworks\u003C\u002Fh4>\n\u003Cp>\u003C!-- compliance: technical-context -->\u003Cbr \u002F>\nRoyal MCP works with any MCP-compliant client, IDE, or AI agent framework — no per-tool configuration required. Each entry below describes the specific integration path Royal MCP provides for that target, so customers can answer “will this work with the tool I already use?”:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Desktop AI apps\u003C\u002Fstrong> – Claude Desktop (native MCP connector via OAuth 2.0), ChatGPT Desktop, Gemini Advanced.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI code IDEs\u003C\u002Fstrong> – Claude Code, VS Code (with MCP extension), Cursor, Windsurf, Continue, Cline, Zed, JetBrains AI Assistant.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>API testing tools\u003C\u002Fstrong> – Postman, Bruno, Insomnia (use the API key in the \u003Ccode>X-Royal-MCP-API-Key\u003C\u002Fcode> header).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom field plugins\u003C\u002Fstrong> – Advanced Custom Fields (ACF) has dedicated \u003Ccode>acf_*\u003C\u002Fcode> tools that return values formatted per each field’s Return Format setting (the same way the ACF UI shows them). MetaBox, JetEngine, Pods, CPT UI, and Custom Field Suite are supported through the \u003Ccode>wp_get_post_meta\u003C\u002Fcode> \u002F \u003Ccode>wp_update_post_meta\u003C\u002Fcode> tools, so AI agents can populate custom fields just like a human editor.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Page builders\u003C\u002Fstrong> – Elementor has dedicated tools for clone-and-customize workflows (clone a page, find\u002Freplace text, swap images, get an outline, import templates) – see the Tools list. Widget-level creation from scratch is intentionally out of scope. Divi, Beaver Builder, Bricks, Gutenberg, Spectra, and Stackable store standard post content that is readable and writable by AI; page-builder-specific JSON storage is opaque unless covered by a dedicated tool.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multilingual\u003C\u002Fstrong> – WPML, Polylang, TranslatePress, qTranslate. Translated posts appear as separate posts and can be read or written via the standard post tools.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI agent frameworks\u003C\u002Fstrong> – LangChain, AutoGen, CrewAI, LlamaIndex, Haystack – any MCP-compatible framework can call Royal MCP’s tools.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI app platforms\u003C\u002Fstrong> – Anthropic Console, OpenAI Playground, Google AI Studio, Vertex AI, Azure AI Studio, Amazon Bedrock Console.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>MCP Spec Compliance\u003C\u002Fh4>\n\u003Cp>Royal MCP implements the \u003Ca href=\"https:\u002F\u002Fmodelcontextprotocol.io\u002Fspecification\u002F2025-11-25\u002Fbasic\u002Ftransports#streamable-http\" rel=\"nofollow ugc\">MCP 2025-11-25 Streamable HTTP transport specification\u003C\u002Fa>:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Single \u003Ccode>\u002Fmcp\u003C\u002Fcode> endpoint for all JSON-RPC communication\u003C\u002Fli>\n\u003Cli>POST for client messages, GET for server-sent events, DELETE for session termination\u003C\u002Fli>\n\u003Cli>Cryptographically secure session IDs with transient-based storage\u003C\u002Fli>\n\u003Cli>Origin header validation to prevent DNS rebinding attacks\u003C\u002Fli>\n\u003Cli>Proper CORS handling for browser-based MCP clients\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to third-party AI services to enable AI platforms to interact with your WordPress content. \u003Cstrong>No data is transmitted until you explicitly configure and enable a platform connection.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What data is sent:\u003C\u002Fstrong> Your WordPress content (posts, pages, media metadata) as requested by the connected AI platform through authenticated MCP tool calls.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When data is sent:\u003C\u002Fstrong> Only when you have configured a platform with API credentials AND enabled that platform connection AND the AI platform makes an authenticated request.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Supported services and their policies:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Anthropic Claude\u003C\u002Fstrong> — Used for Claude AI integration\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\u002Flegal\u002Fconsumer-terms\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\u002Flegal\u002Fprivacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>OpenAI\u003C\u002Fstrong> — Used for ChatGPT\u002FGPT-4 integration\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fopenai.com\u002Fpolicies\u002Fterms-of-use\" rel=\"nofollow ugc\">Terms of Use\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fopenai.com\u002Fpolicies\u002Fprivacy-policy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Google Gemini\u003C\u002Fstrong> — Used for Gemini AI integration\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fai.google.dev\u002Fterms\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fprivacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Groq\u003C\u002Fstrong> — Used for Groq LPU inference\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fgroq.com\u002Fterms-of-use\u002F\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fgroq.com\u002Fprivacy-policy\u002F\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Microsoft Azure OpenAI\u003C\u002Fstrong> — Used for Azure-hosted OpenAI models\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fazure.microsoft.com\u002Fen-us\u002Fsupport\u002Flegal\u002F\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fprivacy.microsoft.com\u002Fen-us\u002Fprivacystatement\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>AWS Bedrock\u003C\u002Fstrong> — Used for AWS-hosted AI models\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Faws.amazon.com\u002Fservice-terms\u002F\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Faws.amazon.com\u002Fprivacy\u002F\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Ollama \u002F LM Studio\u003C\u002Fstrong> — Local self-hosted models (no external data transmission)\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Custom MCP Servers\u003C\u002Fstrong> — User-configured servers (data sent to user-specified endpoints only)\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n","Security-first MCP server. Connect Claude, ChatGPT & Gemini to WordPress with API key auth, rate limiting, audit logs, and Elementor tools.",8000,56924,5,"2026-07-21T06:23:00.000Z","5.8",[71,53,21,121,23],"elementor","https:\u002F\u002Froyalplugins.com\u002Fsupport\u002Froyal-mcp\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Froyal-mcp.1.4.36.zip",98,2,"2026-06-18 00:00:00",{"error":128,"url":129,"statusCode":130,"statusMessage":131,"message":131},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Finvizo-mcp\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":133,"versions":134},6,[135,141,148,155,162,169],{"version":6,"download_url":26,"svn_tag_url":136,"released_at":27,"has_diff":137,"diff_files_changed":138,"diff_lines":27,"trac_diff_url":139,"vulnerabilities":140,"is_current":128},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Finvizo-mcp\u002Ftags\u002F2.0.8\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Finvizo-mcp%2Ftags%2F2.0.7&new_path=%2Finvizo-mcp%2Ftags%2F2.0.8",[],{"version":142,"download_url":143,"svn_tag_url":144,"released_at":27,"has_diff":137,"diff_files_changed":145,"diff_lines":27,"trac_diff_url":146,"vulnerabilities":147,"is_current":137},"2.0.7","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Finvizo-mcp.2.0.7.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Finvizo-mcp\u002Ftags\u002F2.0.7\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Finvizo-mcp%2Ftags%2F2.0.6&new_path=%2Finvizo-mcp%2Ftags%2F2.0.7",[],{"version":149,"download_url":150,"svn_tag_url":151,"released_at":27,"has_diff":137,"diff_files_changed":152,"diff_lines":27,"trac_diff_url":153,"vulnerabilities":154,"is_current":137},"2.0.6","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Finvizo-mcp.2.0.6.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Finvizo-mcp\u002Ftags\u002F2.0.6\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Finvizo-mcp%2Ftags%2F2.0.5&new_path=%2Finvizo-mcp%2Ftags%2F2.0.6",[],{"version":156,"download_url":157,"svn_tag_url":158,"released_at":27,"has_diff":137,"diff_files_changed":159,"diff_lines":27,"trac_diff_url":160,"vulnerabilities":161,"is_current":137},"2.0.5","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Finvizo-mcp.2.0.5.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Finvizo-mcp\u002Ftags\u002F2.0.5\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Finvizo-mcp%2Ftags%2F2.0.4&new_path=%2Finvizo-mcp%2Ftags%2F2.0.5",[],{"version":163,"download_url":164,"svn_tag_url":165,"released_at":27,"has_diff":137,"diff_files_changed":166,"diff_lines":27,"trac_diff_url":167,"vulnerabilities":168,"is_current":137},"2.0.4","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Finvizo-mcp.2.0.4.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Finvizo-mcp\u002Ftags\u002F2.0.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Finvizo-mcp%2Ftags%2F2.0.3&new_path=%2Finvizo-mcp%2Ftags%2F2.0.4",[],{"version":170,"download_url":171,"svn_tag_url":172,"released_at":27,"has_diff":137,"diff_files_changed":173,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":174,"is_current":137},"2.0.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Finvizo-mcp.2.0.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Finvizo-mcp\u002Ftags\u002F2.0.3\u002F",[],[]]