
MountDev AI MCP Connector Security & Risk Analysis
wordpress.org/plugins/mountdev-ai-mcp-connectorTransform your WordPress site into an AI-powered Model Context Protocol (MCP) server. Exposes WordPress functionality for AI agents.
Is MountDev AI MCP Connector Safe to Use in 2026?
Generally Safe
Score 100/100MountDev AI MCP Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mountdev-ai-mcp-connector plugin version 1.1.1 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices by using prepared statements for all SQL queries and properly escaping all output. The presence of numerous nonce and capability checks further indicates an awareness of WordPress security best practices. The plugin also has no recorded vulnerability history, suggesting a relatively clean past.
However, a significant concern arises from the static analysis of its attack surface. The plugin exposes 6 out of 19 total entry points (AJAX handlers and REST API routes) without proper authorization checks. While taint analysis did not reveal any critical or high-severity vulnerabilities, the presence of 4 flows with unsanitized paths, even if not currently exploitable as critical, warrants attention as they represent potential vectors for future issues if not handled carefully. The external HTTP requests also introduce a minor risk if the target endpoints are compromised or misconfigured.
Overall, while the plugin's core database and output handling are secure, the unprotected entry points represent a tangible risk. The lack of past vulnerabilities is encouraging, but the identified unsanitized paths and unprotected entry points suggest that while the plugin might be in a decent state now, there are areas that require immediate attention to maintain a strong security posture and prevent potential future exploits.
Key Concerns
- REST API routes without permission callbacks
- AJAX handlers without auth checks
- Flows with unsanitized paths
- External HTTP requests
MountDev AI MCP Connector Security Vulnerabilities
MountDev AI MCP Connector Release Timeline
MountDev AI MCP Connector Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
MountDev AI MCP Connector Attack Surface
AJAX Handlers 13
REST API Routes 6
WordPress Hooks 7
Maintenance & Trust
MountDev AI MCP Connector Maintenance & Trust
Maintenance Signals
Community Trust
MountDev AI MCP Connector Alternatives
StifLi Flex MCP – AI Copilot, Chat Agent and MCP Server
stifli-flex-mcp
AI Copilot for the WordPress editor, AI Chat Agent for full site management & MCP server for external AI clients. OpenAI, Claude & Gemini.
Royal MCP
royal-mcp
The security-first MCP server for WordPress. Connect Claude, ChatGPT, and Gemini with API key auth, rate limiting, and activity logging.
Albert – The AI Butler
albert-ai-butler
At your service — Albert connects AI assistants to your WordPress site so they can manage content, handle tasks, and keep things running smoothly.
Notification for Telegram
notification-for-telegram
Sends notifications to Telegram users or groups, when some events occur in WordPress.
AI Share & Summarize
ai-share-summarize
Share on social media and generate summaries with citations from leading AIs (Claude, ChatGPT, Gemini, Grok, Perplexity, DeepSeek, Copilot, Qwen)
MountDev AI MCP Connector Developer Profile
1 plugin · 0 total installs
How We Detect MountDev AI MCP Connector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mountdev-ai-mcp-connector/assets/css/admin.css/wp-content/plugins/mountdev-ai-mcp-connector/assets/js/admin.js/wp-content/plugins/mountdev-ai-mcp-connector/assets/js/client-setup.js/wp-content/plugins/mountdev-ai-mcp-connector/assets/js/oauth-credentials.js/wp-content/plugins/mountdev-ai-mcp-connector/assets/js/admin.js/wp-content/plugins/mountdev-ai-mcp-connector/assets/js/client-setup.js/wp-content/plugins/mountdev-ai-mcp-connector/assets/js/oauth-credentials.jsmountdev-ai-mcp-connector/assets/css/admin.css?ver=mountdev-ai-mcp-connector/assets/js/admin.js?ver=mountdev-ai-mcp-connector/assets/js/client-setup.js?ver=mountdev-ai-mcp-connector/assets/js/oauth-credentials.js?ver=HTML / DOM Fingerprints
data-mountdev-ai-mcp-connector-noncemountdevAiMcpConnectorAdminmountdevAiMcpConnectorClientSetupmountdevAiMcpConnectorOAuth/mountdev-ai-mcp-connector/v1/messages/mountdev-ai-mcp-connector/v1/bridge