Track Debug – MCP Server and AI Site Control

Deskripsi

Track Debug connects your WordPress site to AI assistants using the open Model Context Protocol (MCP). It publishes a small, safe set of site “abilities” as MCP tools and gives you a self-contained admin dashboard to manage the connection — no third-party account and no data leaving your site except to the AI client you choose to connect.

Under the hood the plugin registers its features with the WordPress Abilities API and exposes them through a bundled MCP server at:

/wp-json/track-debug/mcp

Connections authenticate with a standard WordPress application password, so you are not creating or storing any new credential system. You can create, list, and revoke those passwords from the dashboard at any time.

What you can do

Once connected, an MCP-compatible AI client (for example, Claude Desktop or Codex) can call these tools:

Read (informational, non-destructive)

  • Get site info — site name, URL, WordPress and PHP versions, active theme, and whether debugging is enabled.
  • List content — list posts or pages with id, title, status and link, filtered by a search term and status.
  • Read debug log — return the most recent lines of wp-content/debug.log so you can diagnose errors from your AI client (administrators only).

Write (content)

  • Create page — create a new page (defaults to draft).
  • Create post — create a new post (defaults to draft).
  • Update post or page — update the title, content, or status of an existing item.

Every tool declares a JSON schema for its input and output, so the AI client knows exactly how to call it, and every tool runs a WordPress capability check before it does anything.

The dashboard

The plugin adds a Track Debug screen to wp-admin with:

  • Application Passwords — create a key in one click, see the keys you already have, and revoke any you no longer use. WordPress shows an application password only once, so the dashboard makes that moment clear.
  • Connection — a ready-to-paste configuration for your AI client, or a plain-language prompt that sets it up for you. Switch between clients (such as Claude or Codex) and between the raw config and the prompt.
  • Overview — your MCP endpoint URL, site URL, active key count, and WordPress/PHP versions at a glance.
  • Light and dark mode, and a layout that works on phones as well as the desktop.

How connecting works

AI clients talk to your site over HTTP using MCP. Because most desktop AI clients launch MCP servers as local commands, the dashboard’s generated configuration uses a small, open-source client-side proxy (@automattic/mcp-wordpress-remote) that runs on your own computer and forwards requests to your site’s endpoint using your application password. Your WordPress site does not call out to any external service on its own.

Security model

  • Every ability checks a WordPress capability before running. Reading the debug log and any site-management action require an administrator.
  • Access is authenticated with an application password that you create and can revoke at any time.
  • The free plugin intentionally does not include high-risk operations such as running arbitrary PHP or deleting data.

Higher-risk, advanced abilities — running PHP, and managing plugins, themes, users, options, and the database — are available only in the separate Track Debug Pro add-on, where they are gated behind an administrator capability and a “Power Mode” switch that is off by default and logs every call.

Open source

This plugin is free software licensed under the GPL. It bundles the WordPress MCP Adapter library (GPL-2.0-or-later) to expose the Abilities API over MCP. If the official MCP Adapter plugin is active on your site, Track Debug uses that copy instead of its bundled one.

Instalasi

  1. Upload the plugin folder to wp-content/plugins/track-debug, or install it from your site’s Plugins screen.
  2. Activate Track Debug through the Plugins menu in WordPress.
  3. Open the Track Debug menu in your admin sidebar.
  4. Click Connect MCP Server, then create an application password.
  5. On the last step, choose your AI client and copy either the configuration or the prompt.
  6. Paste it into your AI client (for example, Claude Desktop or Codex) and connect.

After setup, the dashboard becomes your home screen for managing keys, re-copying the connection details, and viewing your endpoint.

Requirements

  • WordPress with the Abilities API available and REST API enabled.
  • Application passwords enabled (they require HTTPS, or the wp_is_application_passwords_available filter).
  • An MCP-compatible AI client on your computer.

Tanya Jawab

What is MCP?

The Model Context Protocol is an open standard that lets AI assistants talk to external tools and data sources in a consistent way. Track Debug makes your WordPress site one of those sources.

Do I need an account or API key from a third party?

No. Track Debug does not require any third-party account. It uses a WordPress application password that you generate on your own site.

How do clients authenticate?

With a standard WordPress application password created from the dashboard. The connection proxy sends it with each request. You can revoke the password at any time from the Application Passwords tab.

Where is the MCP endpoint?

At /wp-json/track-debug/mcp on your site. The exact URL is shown on the dashboard’s Overview tab.

Does the plugin send my data anywhere?

The plugin itself does not phone home or send your data to any external service. Data is only ever returned to the AI client that you explicitly connect using your own application password. Because that client can read the information the tools expose (such as content lists and the debug log), only connect clients you trust and revoke passwords you no longer use.

Can the AI run arbitrary PHP or delete my content?

Not with the free plugin. It is limited to reading site info/content/logs and creating or updating posts and pages. Running PHP and destructive management actions are part of the separate Track Debug Pro add-on and are gated behind an administrator capability and an off-by-default Power Mode.

Application passwords are disabled on my site. What do I do?

Application passwords require HTTPS by default. Serve your site over HTTPS, or enable them with the wp_is_application_passwords_available filter. The dashboard will tell you when they are unavailable.

Why does connecting use a local proxy command?

Most desktop AI clients start MCP servers as local commands rather than connecting to a URL directly. The generated config uses an open-source proxy that runs on your machine and forwards authenticated requests to your site’s endpoint.

Does it work with the official MCP Adapter plugin?

Yes. If the official WordPress MCP Adapter plugin is active, Track Debug uses it. Otherwise it uses its own bundled copy of the library.

Ulasan

Belum ada ulasan untuk plugin ini.

Kontributor & Pengembang

“Track Debug – MCP Server and AI Site Control” adalah perangkat lunak open source. Berikut ini mereka yang sudah berkontribusi pada plugin ini.

Kontributor

Log Perubahan

3.0.2

  • Runs cleanly alongside other plugins that ship their own MCP server.
  • Lighter load and general stability improvements.

3.0.0

  • New sidebar dashboard with Application Passwords, Connection, Power Mode, and Overview tabs.
  • Streamlined first run: a single welcome screen that opens straight into the dashboard.
  • Stable, fixed-height dashboard layout and various UI refinements.

2.0.0

  • Added an MCP server endpoint backed by the WordPress Abilities API, exposing three read tools and three write tools.
  • Added a React admin dashboard for application passwords, connection setup, and an environment overview.
  • Added light and dark mode and a mobile-friendly layout.