[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjOjubc4TCSY7WERy8JR1lhiWM_Nr9WtIeIBiTurGcDA":3,"$ffMLAoDhNTRTwvt__wR9CEbObNEDHM8MhMV7vG0uz168":114,"$f_KQbV1dqZut8tzV-5rYCf-buBA--M2vA9cwCqCb3Cwk":119},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":35,"analysis":27,"fingerprints":27},"strifebridge-mcp","StrifeBridge MCP","2.3.1","strifero","https:\u002F\u002Fprofiles.wordpress.org\u002Fstrifero\u002F","\u003Cp>StrifeBridge MCP turns your WordPress site into an MCP (Model Context Protocol) endpoint that AI assistants like Claude can connect to directly. Instead of describing a change to an AI and then applying it yourself, you ask and it happens.\u003C\u002Fp>\n\u003Cp>Want to add a blog post? Ask Claude. Need to update a menu item? Ask Claude. Wondering which pages are missing SEO metadata? Ask Claude to check and fix them.\u003C\u002Fp>\n\u003Cp>StrifeBridge MCP exposes a structured, token-authenticated REST API and MCP server inside your WordPress install. AI assistants that support MCP (Claude.ai, Claude Desktop, Cursor, Windsurf, and any MCP-capable agent framework) can connect to it and perform tasks across your site through natural language.\u003C\u002Fp>\n\u003Ch4>What you can do\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Create, update, and delete posts, pages, and custom post types\u003C\u002Fli>\n\u003Cli>Upload files to the media library and manage attachments\u003C\u002Fli>\n\u003Cli>Read and write WordPress options, with a security blacklist for sensitive keys\u003C\u002Fli>\n\u003Cli>Manage navigation menus, taxonomy terms, and widgets\u003C\u002Fli>\n\u003Cli>List, activate, deactivate, and delete plugins\u003C\u002Fli>\n\u003Cli>List users and inspect their roles\u003C\u002Fli>\n\u003Cli>Get site info, flush rewrite rules\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How it works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Install and activate the plugin\u003C\u002Fli>\n\u003Cli>Go to Settings and copy your Connector URL (the bearer token is embedded in the path)\u003C\u002Fli>\n\u003Cli>Paste the URL into your AI assistant as a custom MCP connector\u003C\u002Fli>\n\u003Cli>Ask the assistant to do things on your site\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>No middleware, no third-party relay service. Every request goes from your AI assistant directly to your own WordPress site. You own the endpoint, you own the token, and you can revoke access at any time from Settings.\u003C\u002Fp>\n\u003Ch4>Compatible with\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Claude.ai (web and desktop) &mdash; primary integration\u003C\u002Fli>\n\u003Cli>Claude Desktop app\u003C\u002Fli>\n\u003Cli>Cursor\u003C\u002Fli>\n\u003Cli>Windsurf\u003C\u002Fli>\n\u003Cli>Any MCP-capable agent framework\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Security\u003C\u002Fh4>\n\u003Cp>StrifeBridge MCP was designed with security as a first-class concern:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Bearer token authentication on every request, validated with constant-time \u003Ccode>hash_equals()\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>WordPress secret keys, auth salts, and the plugin’s own token are blacklisted from the options API\u003C\u002Fli>\n\u003Cli>Emergency Lockdown button in Settings disables the entire API with one click\u003C\u002Fli>\n\u003Cli>Every tool group (posts, media, menus, etc.) can be individually toggled off from Settings\u003C\u002Fli>\n\u003Cli>The plugin includes no outbound network calls, no analytics, and no tracking\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Compatibility with self-hosted WordPress\u003C\u002Fh4>\n\u003Cp>StrifeBridge MCP works on any self-hosted WordPress installation running WordPress 5.6 or higher. WordPress.com and WordPress Multisite are not currently supported.\u003C\u002Fp>\n\u003Ch4>Extending StrifeBridge MCP\u003C\u002Fh4>\n\u003Cp>StrifeBridge MCP exposes extension hooks that let add-on plugins register additional MCP tools without modifying the core plugin. Developers can hook into \u003Ccode>sbmcp_register_rest_routes\u003C\u002Fcode>, \u003Ccode>sbmcp_mcp_tools\u003C\u002Fcode>, \u003Ccode>sbmcp_mcp_tool_call\u003C\u002Fcode>, \u003Ccode>sbmcp_tool_groups\u003C\u002Fcode>, and \u003Ccode>sbmcp_admin_after_settings\u003C\u002Fcode> to add routes, tools, admin UI, and tool groups. This is how separately distributed add-ons extend the plugin with features like file editing, database queries, and user management.\u003C\u002Fp>\n","Connect your WordPress site to Claude and other AI assistants through the Model Context Protocol. Manage posts, media, menus, and more in plain Englis &hellip;",30,391,0,"2026-07-10T08:45:00.000Z","7.0.2","5.6","7.4",[19,20,21,22,23],"ai","automation","claude","mcp","rest-api","https:\u002F\u002Fstrifetech.com\u002Fstrifebridge-mcp","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fstrifebridge-mcp.2.3.1.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":11,"trust_score":33,"computed_at":34},1,94,"2026-08-25T04:39:20.481Z",[36,54,69,87,100],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":44,"downloaded":45,"rating":26,"num_ratings":46,"last_updated":47,"tested_up_to":15,"requires_at_least":48,"requires_php":17,"tags":49,"homepage":52,"download_link":53,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"wpraiz-content-api-tool","WPRaiz Content API Tool","2.0.2","José Ícaro - WPRaiz","https:\u002F\u002Fprofiles.wordpress.org\u002Fzeicaro\u002F","\u003Cp>\u003Cstrong>WPRaiz Content API Tool\u003C\u002Fstrong> turns your WordPress site into a powerful content API. Create posts, manage categories, generate AI content, and connect AI agents — all via REST API or Model Context Protocol (MCP).\u003C\u002Fp>\n\u003Ch4>What You Can Do\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Create & Update Posts\u003C\u002Fstrong> — Full control over title, content, status, categories, tags, excerpt, featured images, and custom meta fields via REST API.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bulk Creation\u003C\u002Fstrong> — Create up to 50 posts in a single request (Pro).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI Content Generation\u003C\u002Fstrong> — Generate full articles from a topic using Claude or OpenAI with your own API keys (Pro).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI Rewrite\u003C\u002Fstrong> — Improve SEO, fix grammar, change tone, expand, or summarize existing posts (Pro).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto-SEO\u003C\u002Fstrong> — Automatically generate SEO titles and meta descriptions when not provided. Supports SEOPress, Yoast SEO, and Rank Math.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>MCP Server\u003C\u002Fstrong> — Connect AI agents (Claude Desktop, Cursor, Windsurf) directly to your site via Model Context Protocol.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Similar Post Search\u003C\u002Fstrong> — Find duplicate or related content using intelligent Levenshtein-based scoring.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Webhooks\u003C\u002Fstrong> — Get notified when posts are created or bulk operations complete, with HMAC signature verification.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>JWT Authentication\u003C\u002Fstrong> — Secure token-based auth with configurable rate limiting.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Free vs Pro\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Free\u003C\u002Fstrong> (this plugin):\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Create and update single posts via REST API\u003C\u002Fli>\n\u003Cli>Search similar posts\u003C\u002Fli>\n\u003Cli>List and manage categories\u003C\u002Fli>\n\u003Cli>JWT and Basic Auth (Application Passwords)\u003C\u002Fli>\n\u003Cli>SEO plugin auto-detection and meta writing\u003C\u002Fli>\n\u003Cli>Featured image upload from URL\u003C\u002Fli>\n\u003Cli>Rate limiting\u003C\u002Fli>\n\u003Cli>Legacy v1 endpoint compatibility\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Pro\u003C\u002Fstrong> ($49\u002Fyear at \u003Ca href=\"https:\u002F\u002Fwpraiz.com.br\u002Fpro\" rel=\"nofollow ugc\">wpraiz.com.br\u002Fpro\u003C\u002Fa>):\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Everything in Free, plus:\u003C\u002Fli>\n\u003Cli>Bulk post creation (up to 50 per batch)\u003C\u002Fli>\n\u003Cli>AI content generation (BYOK — Claude or OpenAI)\u003C\u002Fli>\n\u003Cli>AI post rewriting (5 modes)\u003C\u002Fli>\n\u003Cli>Auto-SEO via AI\u003C\u002Fli>\n\u003Cli>MCP Server (HTTP + STDIO transports)\u003C\u002Fli>\n\u003Cli>Webhook notifications with HMAC signing\u003C\u002Fli>\n\u003Cli>Priority support\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>MCP Server\u003C\u002Fh4>\n\u003Cp>The Model Context Protocol server lets AI agents interact with your WordPress site natively. Available via HTTP (REST API) or STDIO (WP-CLI).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Tools:\u003C\u002Fstrong> create_post, update_post, search_similar, get_categories, generate_content, rewrite_post, bulk_create\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Resources:\u003C\u002Fstrong> site-info, recent-posts, categories, content-stats, seo-config\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Prompts:\u003C\u002Fstrong> publish_seo_article, content_series, seo_audit, refresh_old_content, internal_linking\u003C\u002Fp>\n\u003Cp>Add to your \u003Ccode>claude_desktop_config.json\u003C\u002Fcode>:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>{\n    \"mcpServers\": {\n        \"wpraiz\": {\n            \"command\": \"wp\",\n            \"args\": [\"wpraiz-mcp\", \"serve\", \"--path=\u002Fpath\u002Fto\u002Fwordpress\", \"--user=1\"]\n        }\n    }\n}\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>REST API Endpoints\u003C\u002Fh4>\n\u003Cp>Base URL: \u003Ccode>https:\u002F\u002Fyoursite.com\u002Fwp-json\u002Fwpraiz\u002Fv2\u002F\u003C\u002Fcode>\u003C\u002Fp>\n\u003Cp>  Endpoint\u003Cbr \u002F>\n  Method\u003Cbr \u002F>\n  Auth\u003Cbr \u002F>\n  Tier\u003C\u002Fp>\n\u003Cp>  create-post\u003Cbr \u002F>\n  POST\u003Cbr \u002F>\n  JWT\u002FBasic\u003Cbr \u002F>\n  Free\u003C\u002Fp>\n\u003Cp>  update-post\u003Cbr \u002F>\n  POST\u003Cbr \u002F>\n  JWT\u002FBasic\u003Cbr \u002F>\n  Free\u003C\u002Fp>\n\u003Cp>  create-posts\u003Cbr \u002F>\n  POST\u003Cbr \u002F>\n  JWT\u002FBasic\u003Cbr \u002F>\n  Pro\u003C\u002Fp>\n\u003Cp>  generate-content\u003Cbr \u002F>\n  POST\u003Cbr \u002F>\n  JWT\u002FBasic\u003Cbr \u002F>\n  Pro\u003C\u002Fp>\n\u003Cp>  rewrite-post\u003Cbr \u002F>\n  POST\u003Cbr \u002F>\n  JWT\u002FBasic\u003Cbr \u002F>\n  Pro\u003C\u002Fp>\n\u003Cp>  search-similar\u003Cbr \u002F>\n  GET\u003Cbr \u002F>\n  Public\u003Cbr \u002F>\n  Free\u003C\u002Fp>\n\u003Cp>  categories\u003Cbr \u002F>\n  GET\u003Cbr \u002F>\n  Public\u003Cbr \u002F>\n  Free\u003C\u002Fp>\n\u003Cp>  check-status\u003Cbr \u002F>\n  GET\u003Cbr \u002F>\n  Public\u003Cbr \u002F>\n  Free\u003C\u002Fp>\n\u003Cp>  auth\u002Ftoken\u003Cbr \u002F>\n  POST\u003Cbr \u002F>\n  Credentials\u003Cbr \u002F>\n  Free\u003C\u002Fp>\n\u003Ch4>Authentication\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>JWT Token:\u003C\u002Fstrong>\u003Cbr \u002F>\n1. POST to \u003Ccode>auth\u002Ftoken\u003C\u002Fcode> with \u003Ccode>username\u003C\u002Fcode> and \u003Ccode>password\u003C\u002Fcode>\u003Cbr \u002F>\n2. Use the returned token as \u003Ccode>Authorization: Bearer \u003Ctoken>\u003C\u002Fcode>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Basic Auth:\u003C\u002Fstrong>\u003Cbr \u002F>\nUse WordPress Application Passwords with standard HTTP Basic authentication.\u003C\u002Fp>\n\u003Ch4>Requirements\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>WordPress 5.8+\u003C\u002Fli>\n\u003Cli>PHP 7.4+\u003C\u002Fli>\n\u003Cli>For AI features: Claude API key or OpenAI API key\u003C\u002Fli>\n\u003Cli>For MCP STDIO: WP-CLI installed\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>Visit \u003Ca href=\"https:\u002F\u002Fwpraiz.com.br\" rel=\"nofollow ugc\">wpraiz.com.br\u003C\u002Fa> or open an issue on \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fwpraiz\u002Fwpraiz-content-api-tool\" rel=\"nofollow ugc\">GitHub\u003C\u002Fa>.\u003C\u002Fp>\n","REST API + MCP Server for WordPress. Create, update, and manage posts programmatically. AI content generation with your own API keys (BYOK).",70,1856,3,"2026-03-17T09:02:00.000Z","5.0",[50,21,51,22,23],"ai-content","content-automation","https:\u002F\u002Fwpraiz.com.br","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwpraiz-content-api-tool.2.0.2.zip",{"slug":55,"name":56,"version":57,"author":58,"author_profile":59,"description":60,"short_description":61,"active_installs":11,"downloaded":62,"rating":13,"num_ratings":13,"last_updated":63,"tested_up_to":15,"requires_at_least":64,"requires_php":17,"tags":65,"homepage":67,"download_link":68,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"aicom","AICOM – AI Commander","3.9.0","dudaster","https:\u002F\u002Fprofiles.wordpress.org\u002Fdudaster\u002F","\u003Cp>\u003Cstrong>AICOM – AI Commander\u003C\u002Fstrong> connects your WordPress site to any AI agent via MCP (Model Context Protocol) or OpenAPI. Use your existing AI subscription — Claude Code, OpenAI Codex, ChatGPT Custom GPTs, Copilot Studio, Dify, n8n, OpenClaw, Celine, Goose, or any MCP-compatible client — to manage content, build pages, run audits, and automate repetitive tasks, all without leaving your AI interface.\u003C\u002Fp>\n\u003Cp>No more copy-pasting between your AI assistant and the WordPress dashboard. Describe what you want, and your agent does it — safely, with a full record of every action.\u003C\u002Fp>\n\u003Ch4>Content Management\u003C\u002Fh4>\n\u003Cp>Create, update, and publish posts, pages, and custom post types directly from your AI agent. Build and duplicate Elementor pages, manage menus, upload media, update taxonomies, and handle bulk SEO fields including \u003Cstrong>Yoast SEO meta, titles, and social previews\u003C\u002Fstrong> — all in a single conversation. What used to take hours of dashboard work can be delegated to your AI in minutes.\u003C\u002Fp>\n\u003Ch4>Safety You Control\u003C\u002Fh4>\n\u003Cp>AICOM puts you in charge at every level:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Scope-based API keys\u003C\u002Fstrong> — each key grants access only to the operations you explicitly allow. One key for read-only content review, another for full publishing access.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Soft Lock \u002F Hard Lock\u003C\u002Fstrong> — freeze all write operations (Soft) or block everything except public tools (Hard) with one click from the admin bar or Safety page.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Working Hours Schedule\u003C\u002Fstrong> — automatically apply Soft or Hard Lock outside your configured working hours and days. Agents can’t make changes at night or on weekends unless you explicitly override it.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Dry-run mode\u003C\u002Fstrong> — test any operation before it runs. See exactly what would change without touching live data.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Confirm flag\u003C\u002Fstrong> — destructive operations require an explicit \u003Ccode>\"confirm\": true\u003C\u002Fcode> parameter. Accidental deletions are prevented by design.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Backup & Restore\u003C\u002Fh4>\n\u003Cp>Before every significant change, your agent can snapshot the current state of a post or term. If something goes wrong, restore the exact previous version in one call. Backups are stored in the database, organised by session, and can be cleaned up automatically based on age or total size.\u003C\u002Fp>\n\u003Ch4>Full Audit Trail\u003C\u002Fh4>\n\u003Cp>Every request is logged: timestamp, remote IP, API key label, tool used, parameters, result, and response time. Logs are grouped into \u003Cstrong>named sessions\u003C\u002Fstrong> — when an agent opens a session, all its actions are recorded together so you can review, replay, or undo an entire workflow at once. The Audit Logs page includes a session activity chart and a direct Restore button for each session.\u003C\u002Fp>\n\u003Ch4>Accessibility Audits — New in v3.2.0\u003C\u002Fh4>\n\u003Cp>AICOM now includes a dedicated \u003Cstrong>Accessibility module\u003C\u002Fstrong> so your AI agent can audit and fix WCAG issues across your entire site — no external tools or services required:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Site report\u003C\u002Fstrong> — instantly see how many images are missing alt text across your entire media library, with a ranked preview of the top offenders and a percentage score.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Post audit\u003C\u002Fstrong> — scan any post or page for heading hierarchy errors (missing H1, skipped heading levels), images without alt text, and links with non-descriptive anchor text (“click here”, “read more”). Each issue is rated by severity and the post receives an overall accessibility score from 0 to 100.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Fix in place\u003C\u002Fstrong> — set alt text on any media library image in one call. Pass an empty string to correctly mark it as decorative (\u003Ccode>aria-hidden\u003C\u002Fcode>). Full dry-run support so you can preview changes before saving.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Screenshot before & after\u003C\u002Fstrong> — combine AICOM’s audit tools with your AI agent’s browser capabilities to capture a visual record of the page before and after remediation.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>A typical AI-driven accessibility workflow: run the site report, get the list of problem images, let the agent analyse each image visually and write descriptive alt text, apply the fixes — then run the audit again to confirm the score improved. All in one session, with a full audit trail.\u003C\u002Fp>\n\u003Ch4>Supported Modules\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>WordPress Core\u003C\u002Fstrong> — posts, pages, custom post types, terms, meta, options, menus, plugins\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Media\u003C\u002Fstrong> — upload, update, delete media; direct file system access\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Users & Roles\u003C\u002Fstrong> — create, update, manage users and role assignments\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Backup\u003C\u002Fstrong> — per-post and per-term snapshots, session-based restore\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Sessions\u003C\u002Fstrong> — named audit sessions with grouped action history\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Accessibility\u003C\u002Fstrong> — site-wide alt text audit, post-level WCAG check, alt text fixes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce\u003C\u002Fstrong> \u003Cem>(optional)\u003C\u002Fem> — products, categories, settings\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Elementor\u003C\u002Fstrong> \u003Cem>(optional)\u003C\u002Fem> — page creation from template, widget inspection, theme builder conditions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Polylang\u003C\u002Fstrong> \u003Cem>(optional)\u003C\u002Fem> — translations, language assignment, string management\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Yoast SEO\u003C\u002Fstrong> \u003Cem>(optional)\u003C\u002Fem> — read and write SEO titles, meta descriptions, Open Graph and Twitter card fields; bulk audit across all posts in one session\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clautron\u003C\u002Fstrong> \u003Cem>(optional)\u003C\u002Fem> — blueprint management, capability catalog, event analytics\u003C\u002Fli>\n\u003Cli>\u003Cstrong>ECS\u003C\u002Fstrong> \u003Cem>(optional)\u003C\u002Fem> — Ele Custom Skin color schemes, font schemes, custom looks\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Who is this for?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Content teams\u003C\u002Fstrong> using Claude, ChatGPT, or any AI assistant who want it to publish and update WordPress content directly\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Agencies\u003C\u002Fstrong> managing multiple client sites and wanting AI-assisted workflows with a full paper trail\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developers\u003C\u002Fstrong> building AI-powered WordPress tools or automation pipelines\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Accessibility specialists\u003C\u002Fstrong> who want to audit and remediate WCAG issues at scale with AI assistance\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Claude Code users\u003C\u002Fstrong> — point AICOM as an MCP server from your terminal and control WordPress alongside your code\u003C\u002Fli>\n\u003Cli>\u003Cstrong>OpenAI Codex users\u003C\u002Fstrong> — connect Codex to your site via AICOM’s MCP endpoint and let it manage content as part of your dev workflow\u003C\u002Fli>\n\u003Cli>\u003Cstrong>ChatGPT, Copilot Studio, Dify, n8n users\u003C\u002Fstrong> — import the OpenAPI schema URL into any OpenAPI-compatible client; all tools are discovered automatically with Bearer auth\u003C\u002Fli>\n\u003Cli>\u003Cstrong>OpenClaw \u002F Celine \u002F Goose users\u003C\u002Fstrong> — native MCP connector, works out of the box\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How it works\u003C\u002Fh4>\n\u003Cp>AICOM exposes a secure HTTP endpoint on your WordPress site. Your AI agent sends structured MCP requests, AICOM authenticates the request, checks scopes and lock state, executes the operation, logs it, and returns a structured response.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>AI Agent \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> AICOM Endpoint \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> WordPress\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>API Key Scopes\u003C\u002Fh4>\n\u003Cp>Each API key is granted specific scopes — you control exactly what each AI agent can and cannot do:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>read.wp, `write.wp.posts`, `manage.taxonomies`, `manage.meta`, `manage.wordpress.settings`, `manage.media`, `manage.files`, `manage.users`, `manage.plugins`, `manage.backups`, `manage.a11y`, `manage.woocommerce.products`, `manage.woocommerce.settings`, `manage.elementor`, `manage.polylang`, `manage.yoast`, `manage.clautron`\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>Endpoint\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>REST API:\u003C\u002Fstrong>\u003Cbr \u002F>\n    POST \u002Fwp-json\u002Faicom\u002Fv1\u002Fmcp\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Fallback\u003C\u002Fstrong> (no mod_rewrite required):\u003Cbr \u002F>\n    POST \u002F?aicom=1\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Health check:\u003C\u002Fstrong>\u003Cbr \u002F>\n    GET \u002F?aicom=1\u003C\u002Fp>\n\u003Ch4>Authentication\u003C\u002Fh4>\n\u003Cpre>\u003Ccode>Authorization: Bearer aicom_XXXXXXXX_\u003Csecret>\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>or:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>X-API-Key: aicom_XXXXXXXX_\u003Csecret>\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>MCP Request Example\u003C\u002Fh4>\n\u003Cpre>\u003Ccode>{\"jsonrpc\":\"2.0\",\"method\":\"tools\u002Fcall\",\"params\":{\"name\":\"wp.posts.list\",\"arguments\":{\"post_type\":\"post\",\"posts_per_page\":10}},\"id\":1}\n\u003C\u002Fcode>\u003C\u002Fpre>\n","Use your AI subscription to manage WordPress: create Elementor pages, update content, automate tasks, and stay fully in control.",1620,"2026-07-01T12:23:00.000Z","6.0",[19,66,20,22,23],"ai-agent","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Faicom\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faicom.3.9.0.zip",{"slug":70,"name":71,"version":72,"author":73,"author_profile":74,"description":75,"short_description":76,"active_installs":77,"downloaded":78,"rating":13,"num_ratings":13,"last_updated":79,"tested_up_to":15,"requires_at_least":80,"requires_php":17,"tags":81,"homepage":85,"download_link":86,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"bcs-mcp-manager","AI Connector – MCP for Claude, ChatGPT, Gemini & More","1.0.0","bytecorestack","https:\u002F\u002Fprofiles.wordpress.org\u002Fbytecorestack\u002F","\u003Cp>\u003Cstrong>AI Connector\u003C\u002Fstrong> turns your website into a working \u003Ca href=\"https:\u002F\u002Fmodelcontextprotocol.io\u002F\" rel=\"nofollow ugc\">Model Context Protocol (MCP)\u003C\u002Fa> endpoint — the open standard that lets AI assistants like \u003Cstrong>Claude\u003C\u002Fstrong>, \u003Cstrong>ChatGPT\u003C\u002Fstrong>, and \u003Cstrong>Gemini\u003C\u002Fstrong> connect directly to WordPress and take real action instead of just talking about it.\u003C\u002Fp>\n\u003Cp>Think of AI Connector as the missing bridge between AI and WordPress. Instead of copying an answer out of a chat window and pasting it into wp-admin by hand, your AI assistant becomes an AI agent working inside your site: it reads real data, writes real content, and makes real changes through a secure, permission-checked WordPress integration.\u003C\u002Fp>\n\u003Cp>As a WordPress AI plugin, AI Connector gives any MCP-compatible AI assistant structured, authenticated access to your site’s actual content and workflows — no scraping, no guessing, no manual data exports. Once connected, your AI agent can draft and publish posts, manage WooCommerce orders, fix SEO metadata, moderate comments, update Elementor pages, and call on \u003Cstrong>150+ WordPress AI tools\u003C\u002Fstrong>, each one checked against the connecting user’s real WordPress capabilities and recorded in an Activity Log you control.\u003C\u002Fp>\n\u003Cp>This is what WordPress automation looks like when it runs on an open protocol instead of a proprietary one: no vendor lock-in, no third-party cloud service relaying your data, and no static API key to manage by hand. Your AI assistant authenticates directly with your site over \u003Cstrong>OAuth 2.0 with PKCE\u003C\u002Fstrong> — the same authorization flow used by Google, Microsoft, and Slack — and every action it takes is capability-checked, logged, and fully reversible from \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Reset OAuth State\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>Whether you think of it as an AI integration, an AI workflow tool, or simply the fastest way to connect an AI assistant to WordPress, AI Connector is built to be the MCP server for WordPress you set up once and keep using.\u003C\u002Fp>\n\u003Ch4>Links\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fbytecorestack.com\u002Fplugins\u002Fai-connector\u002F\" rel=\"nofollow ugc\">Plugin homepage\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fbcs-mcp-manager\u002F\" rel=\"ugc\">Support forum\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmodelcontextprotocol.io\u002F\" rel=\"nofollow ugc\">Model Context Protocol specification\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why WordPress Sites Need an AI Automation Plugin\u003C\u002Fh4>\n\u003Cp>Without MCP, “AI help” for WordPress usually means: you open a chat window, describe what you want, copy the AI’s answer, switch back to wp-admin, and paste it in by hand. That works for a single blog post. It breaks down completely for anything involving real data — bulk SEO fixes, order refunds, comment moderation, or multi-step content workflows.\u003C\u002Fp>\n\u003Cp>MCP removes the copy-paste step entirely. Your AI assistant gets a structured, authenticated, capability-aware connection to your actual WordPress install, so it can query real data and make real changes — the same way it already works with your file system or terminal in tools like Claude Code, just pointed at your website instead. That’s the difference between an AI chatbot and genuine WordPress AI automation.\u003C\u002Fp>\n\u003Ch4>What Can an AI Agent Do With WordPress?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>“Draft and publish a blog post about [topic], generate a featured image, and tag it correctly.”\u003C\u002Fli>\n\u003Cli>“Show me yesterday’s WooCommerce orders over $100 and refund order #1042.”\u003C\u002Fli>\n\u003Cli>“Find every page with a missing or duplicate SEO title and fix it.”\u003C\u002Fli>\n\u003Cli>“Approve all pending comments from logged-in customers, spam the rest.”\u003C\u002Fli>\n\u003Cli>“Duplicate this Elementor page, swap the hero image, and update the headline.”\u003C\u002Fli>\n\u003Cli>“Create a new menu item for the spring sale and add it to the primary navigation.”\u003C\u002Fli>\n\u003Cli>“List my WooCommerce coupons expiring this month and extend them by two weeks.”\u003C\u002Fli>\n\u003Cli>“Pull this week’s Gravity Forms entries into a summary table.”\u003C\u002Fli>\n\u003Cli>“Restore the homepage to the revision from before my last edit.”\u003C\u002Fli>\n\u003Cli>“Clear the object cache and tell me how big my database is.”\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why Choose AI Connector for WordPress Automation?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>150+ tools, 20 categories\u003C\u002Fstrong> — one of the largest verified MCP tool sets available for WordPress, covering content, commerce, SEO, media, users, taxonomies, menus, plugins, cache, and more\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-client, not single-vendor\u003C\u002Fstrong> — works with AI assistants from Anthropic (Claude), OpenAI (ChatGPT), and Google (Gemini) out of the box, alongside Cursor, Windsurf, and any other client implementing the MCP 2025-11-25 specification\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real OAuth 2.0, not a shared API key\u003C\u002Fstrong> — full authorization code flow with PKCE (S256), Dynamic Client Registration (RFC 7591), and discovery endpoints (RFC 8414) — no static secret to leak or rotate by hand\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Conservative by design\u003C\u002Fstrong> — no MCP tool can ever create a new WordPress user, and role changes require the \u003Ccode>promote_users\u003C\u002Fcode> capability specifically, not just \u003Ccode>edit_users\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Local, redacted activity logging\u003C\u002Fstrong> — the Activity Log records every tool call (tool name, timestamp, client, status, and the call’s parameters\u002Fresult for audit and debugging) entirely in your own database; sensitive-looking values (passwords, tokens, secrets, keys) are automatically redacted before anything is written, and nothing is ever sent off your server\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero telemetry, ever\u003C\u002Fstrong> — no analytics, no tracking pixels, no “phone home” of any kind. The only outbound request the plugin can make is the one explicit image-download tool, and only when your AI client asks for it\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Grows with your stack\u003C\u002Fstrong> — WooCommerce, Advanced Custom Fields, Elementor, and Gravity Forms tools activate automatically the moment those plugins are detected, with zero extra configuration\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Open to extend\u003C\u002Fstrong> — register your own custom MCP tools from any plugin or theme with one function call\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Ideal For\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Agencies and freelancers\u003C\u002Fstrong> who want to run day-to-day WordPress maintenance through an AI assistant instead of clicking through wp-admin one task at a time\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce store owners\u003C\u002Fstrong> who want an AI agent that can check orders, adjust stock, and manage coupons on request\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO teams and content editors\u003C\u002Fstrong> running bulk metadata fixes, content audits, or multi-step publishing workflows\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developers\u003C\u002Fstrong> who want a real WordPress AI integration to build custom AI automation and AI workflow tools on top of\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Anyone already using Claude, ChatGPT, Cursor, or Windsurf\u003C\u002Fstrong> who wants those tools to actually reach into WordPress instead of just describing what to do next\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Supported AI Assistants & MCP Clients\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Claude.ai\u003C\u002Fstrong> — Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Integrations \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add integration \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Custom MCP\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Claude Desktop\u003C\u002Fstrong> — add the MCP URL to \u003Ccode>claude_desktop_config.json\u003C\u002Fcode> under \u003Ccode>mcpServers\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Claude Code\u003C\u002Fstrong> — connects over the same Streamable HTTP MCP endpoint\u003C\u002Fli>\n\u003Cli>\u003Cstrong>ChatGPT\u003C\u002Fstrong> — Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Connectors \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add connector \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> MCP Server\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Gemini\u003C\u002Fstrong> — connect via Google AI Studio MCP integrations\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cursor (0.45+)\u003C\u002Fstrong> — Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> MCP \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add New Server \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> HTTP (Streamable HTTP transport)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Windsurf\u003C\u002Fstrong> — MCP settings panel, supports both Streamable HTTP and legacy SSE\u003C\u002Fli>\n\u003Cli>\u003Cstrong>VS Code, Cline, Continue, Zed, JetBrains\u003C\u002Fstrong> and any other editor or IDE with MCP client support\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Postman, Insomnia\u003C\u002Fstrong> and other API tools with MCP request support\u003C\u002Fli>\n\u003Cli>Any custom client or framework that implements the MCP 2025-11-25 specification\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WordPress AI Tools by Category (159 Tools, Verified)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Posts\u003C\u002Fstrong> — 14 tools (create, read, update, delete, duplicate, bulk trash, schedule, search, count, post types & statuses, post format, password protection)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pages\u003C\u002Fstrong> — 8 tools (CRUD, duplicate, page templates)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Media\u003C\u002Fstrong> — 11 tools (browse, upload from file or URL, update metadata, set featured image, regenerate thumbnails, attachment metadata, image sizes, count)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Taxonomies\u003C\u002Fstrong> — 11 tools (categories, tags, custom taxonomies, term meta, term assignment)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Comments\u003C\u002Fstrong> — 8 tools (CRUD, approve, spam, trash, pending queue)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Users\u003C\u002Fstrong> — 10 tools (list, view, update, delete, sessions, roles, password reset — no creation tool, by design)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Meta\u003C\u002Fstrong> — 6 tools (post meta and user meta read\u002Fwrite\u002Fdelete)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Menus\u003C\u002Fstrong> — 10 tools (menus, menu items, reordering, location assignment)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugins & Themes\u003C\u002Fstrong> — 7 tools (list, activate, deactivate, active theme, theme mods, custom CSS)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO\u003C\u002Fstrong> — 2 tools (read and update SEO meta fields)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Site \u002F Options\u003C\u002Fstrong> — 9 tools (site info, site health, server info, permalink structure, plugin settings, database size, debug log, send email)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Revisions\u003C\u002Fstrong> — 5 tools (history and restore)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cache\u003C\u002Fstrong> — 5 tools (flush, purge, optimize tables, transients)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blocks\u003C\u002Fstrong> — 2 tools (parse blocks, block patterns, reusable blocks)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Widgets\u003C\u002Fstrong> — 2 tools (registered sidebars, sidebar widgets)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developer Tools\u003C\u002Fstrong> — 5 tools (shortcode execution, cron jobs, rewrite rules, and more)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce\u003C\u002Fstrong> \u003Cem>(activates automatically)\u003C\u002Fem> — 33 tools (products, variations, attributes, coupons, orders, refunds, customers, shipping zones, tax rates, store stats, payment gateways)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Custom Fields\u003C\u002Fstrong> \u003Cem>(activates automatically)\u003C\u002Fem> — 3 tools (field groups, field values, field updates)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Elementor\u003C\u002Fstrong> \u003Cem>(activates automatically)\u003C\u002Fem> — 6 tools (clone page, bulk text replace, image swap, page outline, template import\u002Flisting)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Gravity Forms\u003C\u002Fstrong> \u003Cem>(activates automatically)\u003C\u002Fem> — 2 tools (list forms, read entries)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How to Connect Claude, ChatGPT, Gemini & More\u003C\u002Fh4>\n\u003Cp>Point your AI client to your MCP URL:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>https:\u002F\u002Fyoursite.com\u002Fwp-json\u002Fbcs-mcp\u002Fv1\u002Fmcp\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The client automatically discovers the OAuth server via \u003Ccode>\u002F.well-known\u002Foauth-protected-resource\u003C\u002Fcode>, registers itself using Dynamic Client Registration, and redirects to your site’s authorization page for one-time approval. All future requests use short-lived access tokens that refresh automatically — there is nothing to copy into a config file by hand for clients that support DCR.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Claude.ai:\u003C\u002Fstrong> Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Integrations \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add integration \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Custom MCP \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> paste the MCP URL.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Claude Desktop:\u003C\u002Fstrong> Add to \u003Ccode>claude_desktop_config.json\u003C\u002Fcode>:\u003Cbr \u002F>\n    {“mcpServers”:{“wordpress”:{“url”:”https:\u002F\u002Fyoursite.com\u002Fwp-json\u002Fbcs-mcp\u002Fv1\u002Fmcp”,”transport”:”http”}}}\u003C\u002Fp>\n\u003Cp>\u003Cstrong>ChatGPT:\u003C\u002Fstrong> Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Connectors \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add connector \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> MCP Server \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> paste the MCP URL.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Cursor (0.45+):\u003C\u002Fstrong> Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> MCP \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add New Server \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> select HTTP \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> paste the MCP URL. Cursor uses the \u003Ccode>Mcp-Session-Id\u003C\u002Fcode> header returned by the server on initialization to track sessions.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Windsurf:\u003C\u002Fstrong> Open the MCP settings panel, add a new server with the MCP URL. Recent Windsurf versions use Streamable HTTP; older versions fall back to the legacy SSE transport automatically.\u003C\u002Fp>\n\u003Ch4>AI Connector Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>150+ WordPress MCP tools\u003C\u002Fstrong> across 20 categories — see the full breakdown above\u003C\u002Fli>\n\u003Cli>\u003Cstrong>OAuth 2.0 with PKCE\u003C\u002Fstrong> — full authorization code flow with Dynamic Client Registration (RFC 7591), refresh tokens, and discovery endpoints (RFC 8414)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Streamable HTTP transport\u003C\u002Fstrong> (MCP 2025-11-25) — the primary transport used by all modern AI clients\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Legacy SSE transport\u003C\u002Fstrong> — automatic fallback for older client versions, with \u003Ccode>X-Accel-Buffering: no\u003C\u002Fcode> so nginx doesn’t buffer the stream\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Activity log\u003C\u002Fstrong> — every tool call recorded with AI client detection, color-coded client tags, search\u002Ffilter by client, status, and date range, bulk delete, and one-click CSV export — sensitive-looking parameter values (passwords, tokens, secrets) are redacted before being written\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Rate limiting\u003C\u002Fstrong> — 60 requests per minute per IP, enforced automatically on every MCP request\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP allowlist\u003C\u002Fstrong> — optionally restrict MCP access to specific IPs or CIDR ranges\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin dashboard\u003C\u002Fstrong> — live server status, MCP endpoint URL, OAuth client count, today’s success\u002Ffail counts, recent activity feed, and a searchable WordPress tools browser\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WP Dashboard widget\u003C\u002Fstrong> — 7-day activity sparkline with success\u002Ferror breakdown, right on your wp-admin home screen\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built-in setup guides\u003C\u002Fstrong> — copy-paste connection instructions for every supported client, generated with your site’s real MCP URL\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Translation-ready\u003C\u002Fstrong> — ships with a complete \u003Ccode>.pot\u003C\u002Fcode> file in \u003Ccode>\u002Flanguages\u003C\u002Fcode> so translators can localize the plugin into any language\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developer-friendly\u003C\u002Fstrong> — extend with \u003Ccode>bcs_mcp_register_tool()\u003C\u002Fcode> or the \u003Ccode>bcs_mcp_tools\u003C\u002Fcode> filter\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WooCommerce, Elementor, ACF & Gravity Forms Integration\u003C\u002Fh4>\n\u003Cp>Tools for these plugins are included in the box but only activate when the respective plugin is installed and active. No errors are thrown if a plugin is absent, and nothing extra needs configuring. The MCP tool list shown to a connected AI client only ever includes tools whose dependencies are actually satisfied on your site — so a site without WooCommerce simply never advertises WooCommerce tools to the AI.\u003C\u002Fp>\n\u003Ch4>Multisite Support\u003C\u002Fh4>\n\u003Cp>AI Connector works on WordPress multisite networks the same way it works on a single site: each site in the network has its own settings, its own MCP endpoint, and its own Activity Log. There is no cross-site tool access — an AI client connected to one site can never reach another site’s data through this plugin.\u003C\u002Fp>\n\u003Ch4>Extending AI Connector (Developer API)\u003C\u002Fh4>\n\u003Cp>Register custom tools from any plugin or theme:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>bcs_mcp_register_tool( 'my_tool', 'Description', $schema, $callback );\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Or use the \u003Ccode>bcs_mcp_tools\u003C\u002Fcode> filter directly to add, modify, or remove tools before they’re advertised to a connecting AI client.\u003C\u002Fp>\n\u003Ch4>Security & Permissions\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>All tool calls verify WordPress capabilities (\u003Ccode>current_user_can\u003C\u002Fcode>) before executing — an AI client can never do more than the authorizing user is allowed to do\u003C\u002Fli>\n\u003Cli>No MCP tool can create new WordPress users — user accounts must be created through wp-admin, full stop\u003C\u002Fli>\n\u003Cli>Role changes (\u003Ccode>wp_assign_user_role\u003C\u002Fcode>) require the \u003Ccode>promote_users\u003C\u002Fcode> capability, not just \u003Ccode>edit_users\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>OAuth tokens are SHA-256 hashed before database storage — plain tokens are never stored\u003C\u002Fli>\n\u003Cli>PKCE (S256) is required for all authorization flows; plain challenges are rejected\u003C\u002Fli>\n\u003Cli>Dynamic Client Registration is rate-limited to 10 registrations per IP per minute\u003C\u002Fli>\n\u003Cli>Sensitive meta keys (\u003Ccode>user_pass\u003C\u002Fcode>, \u003Ccode>session_tokens\u003C\u002Fcode>, and similar) are permanently blocked from read\u002Fwrite, with no setting to disable the block\u003C\u002Fli>\n\u003Cli>The Activity Log stores tool name, timestamp, client, status, and the call’s parameters\u002Fresult for audit purposes, all locally in your own database — any value that looks like a password, token, secret, or key is redacted before it’s written, and large content fields are truncated\u003C\u002Fli>\n\u003Cli>Outbound image downloads validate URLs against a blocklist of private\u002Floopback IP ranges (SSRF protection) and enforce a 20 MB size limit\u003C\u002Fli>\n\u003Cli>All admin AJAX actions are protected by nonce verification and a \u003Ccode>manage_options\u003C\u002Fcode> capability check\u003C\u002Fli>\n\u003Cli>Session termination (\u003Ccode>DELETE \u002Fmcp\u003C\u002Fcode>) requires a valid bearer token\u003C\u002Fli>\n\u003Cli>The MCP server ships \u003Cstrong>disabled by default\u003C\u002Fstrong> — nothing is exposed until you explicitly enable it in Settings\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin operates primarily as an \u003Cstrong>inbound\u003C\u002Fstrong> API server — AI clients connect to it, not the other way around. No data is sent to any external service automatically or in the background.\u003C\u002Fp>\n\u003Ch4>Image download via wp_upload_media_from_url\u003C\u002Fh4>\n\u003Cp>The \u003Ccode>wp_upload_media_from_url\u003C\u002Fcode> MCP tool, when explicitly invoked by an authenticated AI client (e.g. Claude), makes a single outgoing HTTP GET request to download an image from the URL the AI client provides. This request:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Is only made when the tool is called by a connected, OAuth-authenticated MCP client\u003C\u002Fli>\n\u003Cli>Carries no personal data beyond the image URL itself\u003C\u002Fli>\n\u003Cli>Is validated against a blocklist of private\u002Floopback IP ranges before the request is made\u003C\u002Fli>\n\u003Cli>Is subject to a 20 MB size limit\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>No data is sent to the plugin author’s servers at any time. This plugin does not include analytics, telemetry, or tracking of any kind.\u003C\u002Fp>\n","Connect Claude, ChatGPT, Gemini, Cursor, and other AI assistants to your WordPress site using the Model Context Protocol (MCP). 150+ tools, OAuth 2.",20,140,"2026-07-06T18:02:00.000Z","6.2",[82,83,84,21,22],"ai-connector","ai-automation","chatgpt","https:\u002F\u002Fbytecorestack.com\u002Fplugins\u002Fai-connector\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbcs-mcp-manager.1.0.0.zip",{"slug":88,"name":89,"version":90,"author":91,"author_profile":92,"description":93,"short_description":94,"active_installs":13,"downloaded":95,"rating":13,"num_ratings":13,"last_updated":96,"tested_up_to":15,"requires_at_least":80,"requires_php":17,"tags":97,"homepage":98,"download_link":99,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"axtolab-ai-connector","Axtolab AI Connector","1.0.3","axtolab","https:\u002F\u002Fprofiles.wordpress.org\u002Faxtolab\u002F","\u003Cp>Axtolab AI Connector for WordPress connects your WordPress site to AI agents like Claude, ChatGPT, and any MCP-compatible tool. AI agents can safely create drafts, edit content, manage media, work with taxonomies, and integrate with Yoast SEO — all through a secure gateway with per-connection tool access, sensitive-action consent, and \u003Cstrong>Roll Back \u002F Undo\u003C\u002Fstrong> on every write.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>How it works:\u003C\u002Fstrong> The plugin adds a REST API gateway to your WordPress site. A lightweight MCP server runs on your local machine and translates AI tool calls into WordPress REST requests. The plugin enforces per-connection permissions and allow \u002F ask first \u002F block consent for sensitive actions, validates requests, captures every write into a Roll Back \u002F Undo changelog, and logs actions.\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Roll Back \u002F Undo on every write\u003C\u002Fstrong> — every AI-driven change captures a before\u002Fafter snapshot. Revert any tool call with one click from the Logs & Roll Back admin page.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Sensitive-action consent\u003C\u002Fstrong> — choose whether publishing, trash\u002Fdelete\u002Frestore, WooCommerce price\u002Fcoupon updates, and AI image actions run automatically, ask first, or are blocked for each connection.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Content Management\u003C\u002Fstrong> — Create, edit, and manage posts, pages, and custom post types. Clone existing content as drafts. View and restore revisions. Generate shareable preview links.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Media Library\u003C\u002Fstrong> — Upload images from URL, local file, or drag-and-drop portal. Search and browse existing media. Set featured images. Insert, replace, and remove inline images.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce Tools\u003C\u002Fstrong> — When WooCommerce is active, list products and orders, update product prices, bulk-adjust prices, and create guarded coupons with Roll Back capture.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Stock Photos\u003C\u002Fstrong> — Search and import free stock photos from Unsplash and Pexels with automatic attribution.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Yoast SEO\u003C\u002Fstrong> — Read SEO and readability scores. Update focus keyphrase, SEO title, and meta description. Preview rendered meta tags.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Authors & Taxonomies\u003C\u002Fstrong> — Assign authors from an allowlist. Create and assign categories, tags, and custom taxonomy terms.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Per-connection privilege model\u003C\u002Fstrong> — every MCP connection authenticates as a WordPress user via Application Password. The connection’s capability set determines which AI tools can be called; the user’s WP role determines which objects they can act on. Both layers must allow an action for it to succeed. The plugin never creates WordPress users — admins create the Application Password under their own (or a dedicated) WordPress profile and paste it into the connection wizard. Sensitive-action behavior controls can require approval or block actions after the tool permission check passes. Allowlist-driven content type and taxonomy controls. Rate limiting on authentication endpoints.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Two authentication methods\u003C\u002Fstrong> — Application Passwords (for Desktop AI clients) and OAuth 2.1 with PKCE (for Web AI clients like ChatGPT and Claude Web).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Upload Portal\u003C\u002Fstrong> — Drag-and-drop media uploads with time-limited tokens. No WordPress login required for the upload session.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Available MCP Tools\u003C\u002Fh4>\n\u003Cp>The connector exposes a categorized tool surface to MCP-compatible AI clients. All tools are documented and discoverable via the standard MCP \u003Ccode>tools\u002Flist\u003C\u002Fcode> JSON-RPC method.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Search & Discovery\u003C\u002Fstrong> — \u003Ccode>wp_find_content\u003C\u002Fcode> (filter + search), \u003Ccode>wp_list_content_types\u003C\u002Fcode>, \u003Ccode>wp_get_content\u003C\u002Fcode>, \u003Ccode>wp_site_info\u003C\u002Fcode>, \u003Ccode>wp_getting_started\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Content Authoring\u003C\u002Fstrong> — \u003Ccode>wp_create_draft\u003C\u002Fcode>, \u003Ccode>wp_update_content\u003C\u002Fcode>, \u003Ccode>wp_publish_content\u003C\u002Fcode>, \u003Ccode>wp_clone_content\u003C\u002Fcode>, \u003Ccode>wp_get_preview_link\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Trash & Revisions\u003C\u002Fstrong> — \u003Ccode>wp_trash_content\u003C\u002Fcode>, \u003Ccode>wp_restore_content\u003C\u002Fcode>, \u003Ccode>wp_list_revisions\u003C\u002Fcode>, \u003Ccode>wp_restore_revision\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Media\u003C\u002Fstrong> — \u003Ccode>wp_search_media\u003C\u002Fcode>, \u003Ccode>wp_get_media\u003C\u002Fcode>, \u003Ccode>wp_update_media\u003C\u002Fcode>, \u003Ccode>wp_set_featured_image\u003C\u002Fcode>, \u003Ccode>wp_upload_media_from_url\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Inline Images (Gutenberg-aware)\u003C\u002Fstrong> — \u003Ccode>wp_insert_inline_image\u003C\u002Fcode>, \u003Ccode>wp_replace_inline_image\u003C\u002Fcode>, \u003Ccode>wp_remove_inline_image\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Authors & Taxonomy\u003C\u002Fstrong> — \u003Ccode>wp_list_authors\u003C\u002Fcode>, \u003Ccode>wp_assign_author\u003C\u002Fcode>, \u003Ccode>wp_list_terms\u003C\u002Fcode>, \u003Ccode>wp_create_term\u003C\u002Fcode>, \u003Ccode>wp_assign_terms\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Yoast SEO\u003C\u002Fstrong> — \u003Ccode>wp_get_yoast_analysis\u003C\u002Fcode>, \u003Ccode>wp_update_yoast_metadata\u003C\u002Fcode>, \u003Ccode>wp_get_yoast_head_preview\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce\u003C\u002Fstrong> — \u003Ccode>wp_woo_list_products\u003C\u002Fcode>, \u003Ccode>wp_woo_get_product\u003C\u002Fcode>, \u003Ccode>wp_woo_update_product_price\u003C\u002Fcode>, \u003Ccode>wp_woo_bulk_update_prices\u003C\u002Fcode>, \u003Ccode>wp_woo_list_orders\u003C\u002Fcode>, \u003Ccode>wp_woo_get_order\u003C\u002Fcode>, \u003Ccode>wp_woo_create_coupon\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Stock Photos\u003C\u002Fstrong> — \u003Ccode>wp_search_stock_photos\u003C\u002Fcode>, \u003Ccode>wp_import_stock_photo\u003C\u002Fcode> (Unsplash + Pexels with auto-attribution)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Image Providers\u003C\u002Fstrong> — \u003Ccode>wp_generate_image\u003C\u002Fcode>, \u003Ccode>wp_list_image_providers\u003C\u002Fcode>, \u003Ccode>wp_confirm_image\u003C\u002Fcode> with site-owner supplied provider API keys\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Upload Portal\u003C\u002Fstrong> — \u003Ccode>wp_create_upload_session\u003C\u002Fcode>, \u003Ccode>wp_get_upload_session\u003C\u002Fcode> (drag-and-drop with time-limited tokens)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Connection Introspection\u003C\u002Fstrong> — \u003Ccode>wp_get_my_capabilities\u003C\u002Fcode> returns the calling connection’s capability groups, named preset (if any), and the resolved tool list — letting AI agents plan work without trial-and-error.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Post Type support\u003C\u002Fstrong> — Default allowlist accepts \u003Ccode>post\u003C\u002Fcode>, \u003Ccode>page\u003C\u002Fcode>, \u003Ccode>featured_item\u003C\u002Fcode>. To accept ANY registered public post type (e.g. WooCommerce \u003Ccode>product\u003C\u002Fcode>, EDD \u003Ccode>download\u003C\u002Fcode>, custom CPTs), set the allowlist to \u003Ccode>[\"*\"]\u003C\u002Fcode> in MCP Gateway settings. \u003Ccode>wp_list_content_types\u003C\u002Fcode> then expands the wildcard to the live list of public types on the site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Audit Log\u003C\u002Fstrong> — every tool call is recorded with timestamp, source, and redacted parameters\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Rate Limiting\u003C\u002Fstrong> — per-IP token bucket on every authenticated endpoint\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>What’s Included\u003C\u002Fh4>\n\u003Cp>Axtolab AI Connector is \u003Cstrong>fully featured with no limits\u003C\u002Fstrong>. No publish limits, no connection caps, no feature gates.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Everything included free:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Create, edit, publish, and schedule content with AI agents\u003C\u002Fli>\n\u003Cli>Unlimited connections — connect Claude, ChatGPT, and any MCP agent\u003C\u002Fli>\n\u003Cli>Upload and manage media (URL, local file, drag-and-drop portal)\u003C\u002Fli>\n\u003Cli>Search and import stock photos (Unsplash, Pexels)\u003C\u002Fli>\n\u003Cli>Generate images through supported providers when you configure your own provider API key\u003C\u002Fli>\n\u003Cli>WooCommerce read\u002Fwrite tools for products, orders, prices, and coupons when WooCommerce is active\u003C\u002Fli>\n\u003Cli>Yoast SEO integration\u003C\u002Fli>\n\u003Cli>Both authentication methods (App Passwords, OAuth 2.1)\u003C\u002Fli>\n\u003Cli>All taxonomy and author management\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The free core is feature-complete and useful on its own. Separate plugins may extend it, but no built-in feature in this WordPress.org package requires a license key.\u003C\u002Fp>\n\u003Ch4>Getting Started\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Install and activate the plugin\u003C\u002Fli>\n\u003Cli>Go to AI Connector > Connections in wp-admin\u003C\u002Fli>\n\u003Cli>Click “+ Add new connection” and follow the wizard — it walks you through creating an Application Password on your WordPress profile (or on a dedicated WP user if you prefer the production-grade setup), pasting it into the connection, and choosing what that connection can do\u003C\u002Fli>\n\u003Cli>Click the “Download Extension (.mcpb)” button on the setup page to grab the Claude Desktop bundle from GitHub Releases, then drag it into Claude Desktop’s Extensions panel — or connect a compatible client through MCP-over-HTTP\u003C\u002Fli>\n\u003Cli>Start using your AI agent with WordPress\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to the following external services only when the corresponding feature is configured or used. Provider API keys are supplied by the site owner. The plugin does not send telemetry or analytics to Axtolab.\u003C\u002Fp>\n\u003Ch4>Claude (Anthropic) — OAuth Callback\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service:\u003C\u002Fstrong> Anthropic’s Claude products at https:\u002F\u002Fclaude.ai and https:\u002F\u002Fclaude.com\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Type:\u003C\u002Fstrong> OAuth 2.1 authorization-code callback redirect (no inbound network call from Anthropic during this step)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Endpoints (registered redirect URIs):\u003C\u002Fstrong>\n\u003Cul>\n\u003Cli>\u003Ccode>https:\u002F\u002Fclaude.ai\u002Fapi\u002Fmcp\u002Fauth_callback\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>https:\u002F\u002Fclaude.com\u002Fapi\u002Fmcp\u002Fauth_callback\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When used:\u003C\u002Fstrong> When a logged-in WordPress administrator authorizes a Claude AI client to connect to their WordPress site via the plugin’s OAuth 2.1 flow. The plugin’s \u003Ccode>\u002Foauth\u002Fauthorize\u003C\u002Fcode> endpoint redirects the administrator’s browser to one of these URLs after consent.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent in redirect:\u003C\u002Fstrong> A one-time, short-lived OAuth authorization code plus the original \u003Ccode>state\u003C\u002Fcode> parameter. No personal data, no site content, no credentials.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\u002Flegal\u002Fconsumer-terms\" rel=\"nofollow ugc\">Anthropic Consumer Terms\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\u002Flegal\u002Fprivacy\" rel=\"nofollow ugc\">Anthropic Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>ChatGPT (OpenAI) — OAuth Callback\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service:\u003C\u002Fstrong> OpenAI’s ChatGPT custom-connector platform and OpenAI apps platform\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Type:\u003C\u002Fstrong> OAuth 2.1 authorization-code callback redirect (no inbound network call from OpenAI during this step)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Endpoints (registered redirect URIs):\u003C\u002Fstrong>\n\u003Cul>\n\u003Cli>\u003Ccode>https:\u002F\u002Fchatgpt.com\u002Fconnector_platform_oauth_redirect\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>https:\u002F\u002Fplatform.openai.com\u002Fapps-manage\u002Foauth\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When used:\u003C\u002Fstrong> When a logged-in WordPress administrator authorizes ChatGPT (or an OpenAI Apps Platform client) to connect to their WordPress site via the plugin’s OAuth 2.1 flow. The plugin’s \u003Ccode>\u002Foauth\u002Fauthorize\u003C\u002Fcode> endpoint redirects the administrator’s browser to one of these URLs after consent.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent in redirect:\u003C\u002Fstrong> A one-time, short-lived OAuth authorization code plus the original \u003Ccode>state\u003C\u002Fcode> parameter. No personal data, no site content, no credentials.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fopenai.com\u002Fpolicies\u002Fterms-of-use\" rel=\"nofollow ugc\">OpenAI Terms of Use\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fopenai.com\u002Fpolicies\u002Fprivacy-policy\" rel=\"nofollow ugc\">OpenAI Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>GitHub Releases (Claude Desktop installer bundle download)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service:\u003C\u002Fstrong> GitHub Releases — the Axtolab AI Connector for WordPress (Free) public repository\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Type:\u003C\u002Fstrong> Static binary file download (HTTP GET, no inbound request from GitHub to the WordPress site)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Endpoint:\u003C\u002Fstrong> API host \u003Ccode>github.com\u003C\u002Fcode>, path \u003Ccode>\u002FAxtolab\u002Faxtolab-ai-connector-for-wordpress-free\u002Freleases\u002Flatest\u002Fdownload\u002Faxtolab-ai-connector.mcpb\u003C\u002Fcode> (HTTPS).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When used:\u003C\u002Fstrong> When a logged-in WordPress administrator clicks the “Download Extension (.mcpb)” button on the AI Connector setup page. The administrator’s browser is redirected to GitHub Releases to fetch the file. The plugin itself does not initiate an outbound request to GitHub; the user’s browser does, when they click the link. Filterable via \u003Ccode>axtolab_ai_connector_mcpb_download_url\u003C\u002Fcode> if a site owner wants to self-host the bundle.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> Standard HTTP browser request headers only. No WordPress site data, content, credentials, or telemetry is sent.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fdocs.github.com\u002Fen\u002Fsite-policy\u002Fgithub-terms\u002Fgithub-terms-of-service\" rel=\"nofollow ugc\">GitHub Terms of Service\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fdocs.github.com\u002Fen\u002Fsite-policy\u002Fprivacy-policies\u002Fgithub-general-privacy-statement\" rel=\"nofollow ugc\">GitHub Privacy Statement\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Local MCP clients (Claude Desktop, Cursor, Claude Code, VS Code)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service:\u003C\u002Fstrong> A local AI client running on the site administrator’s own computer.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When used:\u003C\u002Fstrong> When the site administrator installs the \u003Ccode>.mcpb\u003C\u002Fcode> bundle (downloaded from GitHub Releases via the AI Connector setup page) into a local AI client such as Claude Desktop. That client then connects inbound to the site’s REST API using credentials issued during setup. The plugin does not initiate any outbound network call to these clients.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> Only what the AI client requests through tool calls the administrator has approved. The plugin does not send unsolicited data.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Unsplash (Stock Photo Search)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Funsplash.com\u002F\" rel=\"nofollow ugc\">Unsplash\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Endpoint:\u003C\u002Fstrong> API host \u003Ccode>api.unsplash.com\u003C\u002Fcode>, path \u003Ccode>\u002Fsearch\u002Fphotos\u003C\u002Fcode> (HTTPS).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When used:\u003C\u002Fstrong> When an AI agent searches for stock photos via the stock photo tool\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> Search query, orientation preference\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Funsplash.com\u002Fterms\" rel=\"nofollow ugc\">Unsplash Terms\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Funsplash.com\u002Fprivacy\" rel=\"nofollow ugc\">Unsplash Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Pexels (Stock Photo Search)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwww.pexels.com\u002F\" rel=\"nofollow ugc\">Pexels\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Endpoint:\u003C\u002Fstrong> API host \u003Ccode>api.pexels.com\u003C\u002Fcode>, path \u003Ccode>\u002Fv1\u002Fsearch\u003C\u002Fcode> (HTTPS).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When used:\u003C\u002Fstrong> When an AI agent searches for stock photos via the stock photo tool\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> Search query, orientation preference\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwww.pexels.com\u002Fterms-of-service\u002F\" rel=\"nofollow ugc\">Pexels Terms of Service\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwww.pexels.com\u002Fprivacy-policy\u002F\" rel=\"nofollow ugc\">Pexels Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Google Imagen (AI Image Generation)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fcloud.google.com\u002Fvertex-ai\u002Fgenerative-ai\u002Fdocs\u002Fimage\u002Foverview\" rel=\"nofollow ugc\">Google Cloud AI\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Endpoint:\u003C\u002Fstrong> API host \u003Ccode>generativelanguage.googleapis.com\u003C\u002Fcode>, path \u003Ccode>\u002Fv1beta\u002Fmodels\u002Fimagen-3.0-generate-002:predict\u003C\u002Fcode> (HTTPS).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When used:\u003C\u002Fstrong> When an AI agent generates images using the Google Imagen provider and the site owner has configured a Google API key\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> Text prompt, aspect ratio, safety filter level\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fcloud.google.com\u002Fterms\" rel=\"nofollow ugc\">Google Cloud Terms\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fprivacy\" rel=\"nofollow ugc\">Google Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>OpenAI (AI Image Generation)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fopenai.com\u002F\" rel=\"nofollow ugc\">OpenAI\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Endpoint:\u003C\u002Fstrong> API host \u003Ccode>api.openai.com\u003C\u002Fcode>, path \u003Ccode>\u002Fv1\u002Fimages\u002Fgenerations\u003C\u002Fcode> (HTTPS).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When used:\u003C\u002Fstrong> When an AI agent generates images using the OpenAI provider and the site owner has configured an OpenAI API key\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> Text prompt, image size, quality setting\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fopenai.com\u002Fpolicies\u002Fterms-of-use\" rel=\"nofollow ugc\">OpenAI Terms of Use\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fopenai.com\u002Fpolicies\u002Fprivacy-policy\" rel=\"nofollow ugc\">OpenAI Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>All API keys are stored encrypted using AES-256-CBC with WordPress security salts and are only decrypted at the time of the API call.\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>WordPress.org plugin support forum\u003C\u002Fstrong> — https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Faxtolab-ai-connector\u002F (please use this for general questions; replies are public so the next merchant searching for the same answer can find it).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email support\u003C\u002Fstrong> — support@axtolab.com (for license, account, or anything sensitive).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Documentation\u003C\u002Fstrong> — https:\u002F\u002Faxtolab.com\u002Fdocs\u002Fai-connector-free\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bug reports\u003C\u002Fstrong> — use the WordPress.org support forum for public issues or email support for sensitive reports.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The same support entry points are also surfaced inside wp-admin: a “Need help?” footer on every Axtolab settings page, and “Settings · Support” \u002F “Email support · WordPress.org forum · Docs” rows on the Plugins admin row for this plugin.\u003C\u002Fp>\n","Let AI agents read, draft, edit, and publish WordPress with per-connection permissions, consent gates, and Roll Back.",267,"2026-06-18T21:44:00.000Z",[19,20,84,21,22],"","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faxtolab-ai-connector.1.0.3.zip",{"slug":101,"name":102,"version":103,"author":104,"author_profile":105,"description":106,"short_description":107,"active_installs":13,"downloaded":26,"rating":13,"num_ratings":13,"last_updated":108,"tested_up_to":109,"requires_at_least":64,"requires_php":110,"tags":111,"homepage":98,"download_link":113,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"born-creative-mcp-server","Born Creative MCP Server","0.0.6","jonathansblog","https:\u002F\u002Fprofiles.wordpress.org\u002Fjonathansblog\u002F","\u003Cp>Born Creative MCP Server transforms your WordPress site into a fully authenticated remote MCP (Model Context Protocol) endpoint. It allows AI assistants — such as Claude.ai — to securely connect to your site and create, update, schedule, and manage posts, pages, media, and taxonomy, all via a standards-compliant OAuth 2.1 and JSON-RPC 2.0 interface.\u003C\u002Fp>\n\u003Cp>Unlike local stdio-based MCP servers, this plugin exposes a remote HTTP transport, meaning your AI tools can connect to your live WordPress site without needing direct server access.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>How it works\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The plugin registers a set of REST API endpoints that implement the MCP streamable HTTP transport. Clients authenticate using OAuth 2.1 with PKCE (Proof Key for Code Exchange), receive a bearer access token, and then use that token to call any of the 18 built-in MCP tools.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>MCP Tools included\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Posts\u003C\u002Fstrong> — list, get, create, update, delete, search\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pages\u003C\u002Fstrong> — list, get, create, update, delete\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Media\u003C\u002Fstrong> — list, get, upload from URL, upload base64-encoded, delete\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Categories\u003C\u002Fstrong> — list, create, update\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Tags\u003C\u002Fstrong> — list, create\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Yoast SEO\u003C\u002Fstrong> \u003Cem>(optional)\u003C\u002Fem> — get and update Yoast SEO metadata (requires Yoast SEO plugin)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>OAuth 2.1 Authentication\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Dynamic client registration (RFC 7591)\u003C\u002Fli>\n\u003Cli>Authorization code flow with PKCE\u003C\u002Fli>\n\u003Cli>Access token and refresh token lifecycle management\u003C\u002Fli>\n\u003Cli>Token rotation and revocation\u003C\u002Fli>\n\u003Cli>Tokens are SHA-256 hashed — plaintext tokens are never stored\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Advanced content features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Schedule posts by setting a future publish date\u003C\u002Fli>\n\u003Cli>Set featured images\u003C\u002Fli>\n\u003Cli>Add custom post meta\u003C\u002Fli>\n\u003Cli>Sideload media from external URLs\u003C\u002Fli>\n\u003Cli>Full category and tag assignment\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Yoast SEO integration\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>If the Yoast SEO plugin is active, two additional MCP tools are automatically registered: \u003Ccode>yoast_get_seo\u003C\u002Fcode> and \u003Ccode>yoast_update_seo\u003C\u002Fcode>, allowing AI assistants to read and write SEO titles, descriptions, and focus keywords.\u003C\u002Fp>\n","A remote MCP server over HTTP with OAuth 2.1, letting AI assistants like Claude securely create, update, and schedule WordPress content.","2026-06-16T19:50:00.000Z","6.9.5","8.1",[19,21,22,112,23],"oauth","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fborn-creative-mcp-server.zip",{"error":115,"url":116,"statusCode":117,"statusMessage":118,"message":118},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fstrifebridge-mcp\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":120,"versions":121},5,[122,128,135,142,149],{"version":6,"download_url":25,"svn_tag_url":123,"released_at":27,"has_diff":124,"diff_files_changed":125,"diff_lines":27,"trac_diff_url":126,"vulnerabilities":127,"is_current":115},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fstrifebridge-mcp\u002Ftags\u002F2.3.1\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fstrifebridge-mcp%2Ftags%2F2.3.0&new_path=%2Fstrifebridge-mcp%2Ftags%2F2.3.1",[],{"version":129,"download_url":130,"svn_tag_url":131,"released_at":27,"has_diff":124,"diff_files_changed":132,"diff_lines":27,"trac_diff_url":133,"vulnerabilities":134,"is_current":124},"2.3.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fstrifebridge-mcp.2.3.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fstrifebridge-mcp\u002Ftags\u002F2.3.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fstrifebridge-mcp%2Ftags%2F2.2.0&new_path=%2Fstrifebridge-mcp%2Ftags%2F2.3.0",[],{"version":136,"download_url":137,"svn_tag_url":138,"released_at":27,"has_diff":124,"diff_files_changed":139,"diff_lines":27,"trac_diff_url":140,"vulnerabilities":141,"is_current":124},"2.2.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fstrifebridge-mcp.2.2.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fstrifebridge-mcp\u002Ftags\u002F2.2.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fstrifebridge-mcp%2Ftags%2F2.1.0&new_path=%2Fstrifebridge-mcp%2Ftags%2F2.2.0",[],{"version":143,"download_url":144,"svn_tag_url":145,"released_at":27,"has_diff":124,"diff_files_changed":146,"diff_lines":27,"trac_diff_url":147,"vulnerabilities":148,"is_current":124},"2.1.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fstrifebridge-mcp.2.1.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fstrifebridge-mcp\u002Ftags\u002F2.1.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fstrifebridge-mcp%2Ftags%2F2.0.0&new_path=%2Fstrifebridge-mcp%2Ftags%2F2.1.0",[],{"version":150,"download_url":151,"svn_tag_url":152,"released_at":27,"has_diff":124,"diff_files_changed":153,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":154,"is_current":124},"2.0.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fstrifebridge-mcp.2.0.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fstrifebridge-mcp\u002Ftags\u002F2.0.0\u002F",[],[]]