MountDev AI MCP Connector Security & Risk Analysis

wordpress.org/plugins/mountdev-ai-mcp-connector

Transform your WordPress site into an AI-powered Model Context Protocol (MCP) server. Exposes WordPress functionality for AI agents.

0 active installs v1.1.1 PHP 7.4+ WP 5.8+ Updated Apr 14, 2026
aichatgptclaudemcpwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MountDev AI MCP Connector Safe to Use in 2026?

Generally Safe

Score 100/100

MountDev AI MCP Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The mountdev-ai-mcp-connector plugin version 1.1.1 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices by using prepared statements for all SQL queries and properly escaping all output. The presence of numerous nonce and capability checks further indicates an awareness of WordPress security best practices. The plugin also has no recorded vulnerability history, suggesting a relatively clean past.

However, a significant concern arises from the static analysis of its attack surface. The plugin exposes 6 out of 19 total entry points (AJAX handlers and REST API routes) without proper authorization checks. While taint analysis did not reveal any critical or high-severity vulnerabilities, the presence of 4 flows with unsanitized paths, even if not currently exploitable as critical, warrants attention as they represent potential vectors for future issues if not handled carefully. The external HTTP requests also introduce a minor risk if the target endpoints are compromised or misconfigured.

Overall, while the plugin's core database and output handling are secure, the unprotected entry points represent a tangible risk. The lack of past vulnerabilities is encouraging, but the identified unsanitized paths and unprotected entry points suggest that while the plugin might be in a decent state now, there are areas that require immediate attention to maintain a strong security posture and prevent potential future exploits.

Key Concerns

  • REST API routes without permission callbacks
  • AJAX handlers without auth checks
  • Flows with unsanitized paths
  • External HTTP requests
Vulnerabilities
None known

MountDev AI MCP Connector Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

MountDev AI MCP Connector Release Timeline

v1.1.1Current
v1.1.0
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

MountDev AI MCP Connector Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
11 prepared
Unescaped Output
2
935 escaped
Nonce Checks
14
Capability Checks
13
File Operations
6
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared11 total queries

Output Escaping

100% escaped937 total outputs
Data Flows · Security
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
handle_profile_form (includes/admin/class-admin.php:99)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

MountDev AI MCP Connector Attack Surface

Entry Points19
Unprotected6

AJAX Handlers 13

authwp_ajax_mountdev_ai_mcp_connector_get_disclaimer_tsincludes/admin/class-disclaimer-handler.php:30
authwp_ajax_mountdev_ai_mcp_connector_set_disclaimer_tsincludes/admin/class-disclaimer-handler.php:31
authwp_ajax_mountdev_ai_mcp_connector_generate_oauth_credentialsincludes/admin/class-oauth-credentials-handler.php:26
authwp_ajax_mountdev_ai_mcp_connector_revoke_oauth_credentialsincludes/admin/class-oauth-credentials-handler.php:27
authwp_ajax_mountdev_ai_mcp_connector_get_profileincludes/admin/class-profile-ajax-handler.php:26
authwp_ajax_mountdev_ai_mcp_connector_create_profileincludes/admin/class-profile-ajax-handler.php:27
authwp_ajax_mountdev_ai_mcp_connector_update_profileincludes/admin/class-profile-ajax-handler.php:28
authwp_ajax_mountdev_ai_mcp_connector_delete_profileincludes/admin/class-profile-ajax-handler.php:29
authwp_ajax_mountdev_ai_mcp_connector_activate_profileincludes/admin/class-profile-ajax-handler.php:30
authwp_ajax_mountdev_ai_mcp_connector_export_profileincludes/admin/class-profile-ajax-handler.php:31
authwp_ajax_mountdev_ai_mcp_connector_import_profileincludes/admin/class-profile-ajax-handler.php:32
authwp_ajax_mountdev_ai_mcp_connector_test_connectionincludes/admin/class-test-connection-handler.php:28
authwp_ajax_mountdev_ai_mcp_connector_download_installerincludes/class-installer-handler.php:26

REST API Routes 6

GET/wp-json/mountdev-ai-mcp-connector/v1/.well-known/oauth-authorization-serverincludes/class-oauth-controller.php:94
GET/wp-json/.well-known/oauth-authorization-serverincludes/class-oauth-controller.php:107
GET/wp-json/mountdev-ai-mcp-connector/v1/oauth/authorizeincludes/class-oauth-controller.php:120
GET/wp-json/mountdev-ai-mcp-connector/v1/oauth/tokenincludes/class-oauth-controller.php:134
GET/wp-json/mountdev-ai-mcp-connector/v1/oauth/revokeincludes/class-oauth-controller.php:148
GET/wp-json/mountdev-ai-mcp-connector/v1/oauth/registerincludes/class-oauth-controller.php:162
WordPress Hooks 7
filterdetermine_current_userincludes/class-authenticator.php:37
filterrest_authentication_errorsincludes/class-authenticator.php:38
actionrest_api_initincludes/class-oauth-controller.php:26
actiontemplate_redirectincludes/class-oauth-controller.php:27
actionrest_api_initmountdev-ai-mcp-connector.php:75
actionadmin_menumountdev-ai-mcp-connector.php:76
actionadmin_enqueue_scriptsmountdev-ai-mcp-connector.php:77
Maintenance & Trust

MountDev AI MCP Connector Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 14, 2026
PHP min version7.4
Downloads259

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

MountDev AI MCP Connector Developer Profile

Cascadia Web Services

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MountDev AI MCP Connector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mountdev-ai-mcp-connector/assets/css/admin.css/wp-content/plugins/mountdev-ai-mcp-connector/assets/js/admin.js/wp-content/plugins/mountdev-ai-mcp-connector/assets/js/client-setup.js/wp-content/plugins/mountdev-ai-mcp-connector/assets/js/oauth-credentials.js
Script Paths
/wp-content/plugins/mountdev-ai-mcp-connector/assets/js/admin.js/wp-content/plugins/mountdev-ai-mcp-connector/assets/js/client-setup.js/wp-content/plugins/mountdev-ai-mcp-connector/assets/js/oauth-credentials.js
Version Parameters
mountdev-ai-mcp-connector/assets/css/admin.css?ver=mountdev-ai-mcp-connector/assets/js/admin.js?ver=mountdev-ai-mcp-connector/assets/js/client-setup.js?ver=mountdev-ai-mcp-connector/assets/js/oauth-credentials.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-mountdev-ai-mcp-connector-nonce
JS Globals
mountdevAiMcpConnectorAdminmountdevAiMcpConnectorClientSetupmountdevAiMcpConnectorOAuth
REST Endpoints
/mountdev-ai-mcp-connector/v1/messages/mountdev-ai-mcp-connector/v1/bridge
FAQ

Frequently Asked Questions about MountDev AI MCP Connector