{"id":326332,"date":"2026-07-06T18:02:40","date_gmt":"2026-07-06T18:02:40","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/bytecore-mcp-manager\/"},"modified":"2026-09-18T02:26:07","modified_gmt":"2026-09-18T02:26:07","slug":"bcs-mcp-manager","status":"publish","type":"plugin","link":"https:\/\/id.wordpress.org\/plugins\/bcs-mcp-manager\/","author":23505918,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.2","stable_tag":"1.2.2","tested":"7.1.1","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"ByteCoreStack - MCP Connector for AI Tools","header_author":"ByteCore Stack","header_description":"Free WordPress AI plugin and MCP server \u2014 connects Claude, ChatGPT, Gemini, Cursor, Windsurf, and any MCP-compatible AI client to WordPress. Includes 150+ WordPress AI tools, OAuth 2.0 with PKCE, activity logging, and an admin dashboard.","assets_banners_color":"080f36","last_updated":"2026-09-18 02:26:07","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/bytecorestack.com\/plugins\/ai-connector\/","header_author_uri":"https:\/\/bytecorestack.com","rating":0,"author_block_rating":0,"active_installs":40,"downloads":786,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"bytecorestack","date":"2026-07-06 18:02:29","revision":3598184},"1.1.0":{"tag":"1.1.0","author":"bytecorestack","date":"2026-07-27 17:26:14","revision":3624960},"1.2.0":{"tag":"1.2.0","author":"bytecorestack","date":"2026-08-06 17:32:44","revision":3636906},"1.2.1":{"tag":"1.2.1","author":"bytecorestack","date":"2026-08-18 13:23:22","revision":3652956},"1.2.2":{"tag":"1.2.2","author":"bytecorestack","date":"2026-09-18 02:26:07","revision":3701220}},"upgrade_notice":{"1.2.1":"<p>Fixes AI clients being blocked by Wordfence\/AIOS-style &quot;REST API requires login&quot; settings, improves firewall-block diagnostics, closes an uninstall cleanup gap, and widens credential redaction. Fully backward compatible, no reconnection needed.<\/p>","1.1.0":"<p>Adds 56 new tools (SEO, forms, LMS, EDD, page builders, backups, CRM, BuddyPress, Events Calendar, WooCommerce subscriptions\/bookings), a security fix, and bug fixes. Fully backward compatible, no reconnection needed. Renamed to &quot;ByteCoreStack - MCP Connector for AI Tools.&quot;<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3598182,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3598182,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3598182,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3598182,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.1.0","1.2.0","1.2.1","1.2.2"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3598182,"resolution":"1","location":"assets","locale":"","width":1280,"height":800},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3598182,"resolution":"2","location":"assets","locale":"","width":1280,"height":800},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3598182,"resolution":"3","location":"assets","locale":"","width":1280,"height":800},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3598182,"resolution":"4","location":"assets","locale":"","width":1280,"height":800},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3598182,"resolution":"5","location":"assets","locale":"","width":1280,"height":800},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3598182,"resolution":"6","location":"assets","locale":"","width":1280,"height":800},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3598182,"resolution":"7","location":"assets","locale":"","width":1280,"height":800}},"screenshots":{"1":"Admin dashboard \u2014 server status, today's stats, and recent activity feed.","2":"Tools browser \u2014 every tool, most-used tool in the last 28 days, and quick docs.","3":"Tool detail view \u2014 tool name, method, and a plain-English explanation.","4":"Settings page \u2014 enable the MCP server, copy your endpoint URL, and setup guides per AI client.","5":"Activity Log \u2014 filter by client, status, and date range, with color-coded tags and CSV export.","6":"WP Dashboard widget \u2014 a 7-day activity sparkline on your wp-admin home screen.","7":"Claude connector page \u2014 tools list and permission settings for the connection."}},"plugin_section":[262246],"plugin_tags":[2353,216196,229563,242115,260626],"plugin_category":[],"plugin_contributors":[266332],"plugin_business_model":[],"class_list":["post-326332","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-ai","plugin_tags-chatgpt","plugin_tags-claude","plugin_tags-mcp","plugin_tags-mcp-server","plugin_contributors-bytecorestack","plugin_committers-bytecorestack"],"banners":{"banner":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/banner-772x250.png?rev=3598182","banner_2x":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/banner-1544x500.png?rev=3598182","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/icon-128x128.png?rev=3598182","icon_2x":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/icon-256x256.png?rev=3598182","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/screenshot-1.png?rev=3598182","caption":"Admin dashboard \u2014 server status, today's stats, and recent activity feed."},{"src":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/screenshot-2.png?rev=3598182","caption":"Tools browser \u2014 every tool, most-used tool in the last 28 days, and quick docs."},{"src":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/screenshot-3.png?rev=3598182","caption":"Tool detail view \u2014 tool name, method, and a plain-English explanation."},{"src":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/screenshot-4.png?rev=3598182","caption":"Settings page \u2014 enable the MCP server, copy your endpoint URL, and setup guides per AI client."},{"src":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/screenshot-5.png?rev=3598182","caption":"Activity Log \u2014 filter by client, status, and date range, with color-coded tags and CSV export."},{"src":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/screenshot-6.png?rev=3598182","caption":"WP Dashboard widget \u2014 a 7-day activity sparkline on your wp-admin home screen."},{"src":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/screenshot-7.png?rev=3598182","caption":"Claude connector page \u2014 tools list and permission settings for the connection."}],"raw_content":"<!--section=description-->\n<p>ByteCoreStack - MCP Connector for AI Tools is a WordPress AI plugin that turns your site into a Model Context Protocol (MCP) server, so AI assistants like Claude, ChatGPT, and Gemini can connect directly and take real action instead of just describing what to do.<\/p>\n\n<p>Once connected, your AI agent can draft and publish posts, manage WooCommerce orders and subscriptions, fix SEO metadata, moderate comments, sync FluentCRM contacts, trigger UpdraftPlus backups, and update Elementor or Bricks pages \u2014 calling on 335+ WordPress AI tools across 26 categories, each checked against the connecting user's real WordPress capabilities and logged in an Activity Log you control.<\/p>\n\n<p>Authentication runs over OAuth 2.0 with PKCE, the same flow used by Google, Microsoft, and Slack \u2014 no shared API key, no third-party relay, and every action is capability-checked, logged, and reversible from Settings \u2192 Reset OAuth State.<\/p>\n\n<p>The admin screens themselves (Dashboard, Settings, Connection Test, Activity Log) have a clean, modern interface with a one-click light\/dark mode switch (light by default) \u2014 your preference is remembered per browser.<\/p>\n\n<p>See the FAQ below for supported AI clients, integrations, and setup instructions \u2014 or browse the full tool list live in this plugin's own Settings \u2192 Tools screen once installed.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>bcs-mcp-manager<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install directly from the WordPress.org plugin directory.<\/li>\n<li>Activate the plugin via <strong>Plugins \u2192 Installed Plugins<\/strong>.<\/li>\n<li><strong>Running Wordfence, All In One WP Security, or a similar security plugin?<\/strong> Check its firewall settings for a \"restrict\/disable the REST API for logged-out users\" toggle and turn it off (or allowlist this plugin's URLs) <em>before<\/em> connecting an AI client \u2014 see the dedicated FAQ entry below. This is the single most common reason a connection fails on the first try.<\/li>\n<li>Go to <strong>ByteCoreStack - MCP Connector for AI Tools \u2192 Settings<\/strong> and enable the MCP server.<\/li>\n<li>Copy the MCP URL shown on the <strong>Dashboard<\/strong> page.<\/li>\n<li>Paste the MCP URL into your AI client (Claude.ai, Claude Desktop, ChatGPT, Gemini, Cursor, or Windsurf) and complete the one-time OAuth authorization.<\/li>\n<li>Open the <strong>Activity Log<\/strong> to confirm tool calls are arriving, and use the <strong>WP Dashboard widget<\/strong> to keep an eye on activity going forward.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20it%20free%3F\"><h3>Is it free?<\/h3><\/dt>\n<dd><p>Yes, completely free \u2014 no premium tiers, license keys, usage caps, or feature paywalls. Every tool is included.<\/p><\/dd>\n<dt id=\"what%20is%20mcp%2C%20and%20what%20can%20an%20ai%20agent%20actually%20do%20with%20wordpress%3F\"><h3>What is MCP, and what can an AI agent actually do with WordPress?<\/h3><\/dt>\n<dd><p>MCP (Model Context Protocol) is an open standard, created by Anthropic, that lets AI assistants securely call structured tools instead of free-text copy-paste. This plugin implements a full MCP server inside WordPress with 335+ tools across 26 categories \u2014 posts, media, WooCommerce, SEO, forms, CRM, backups, and more \u2014 each gated by the connecting user's real WordPress capabilities: no MCP tool can create a user, and role changes require <code>promote_users<\/code>. Every call is logged and revocable instantly from Settings \u2192 Reset OAuth State. Browse all tools live in this plugin's own Settings \u2192 Tools screen.<\/p><\/dd>\n<dt id=\"which%20ai%20clients%20are%20supported%2C%20and%20how%20do%20i%20connect%3F\"><h3>Which AI clients are supported, and how do I connect?<\/h3><\/dt>\n<dd><p>Any MCP 2025-11-25 Streamable HTTP client \u2014 MCP is a protocol, not a vendor, so it doesn't matter which model or provider powers the client: Claude.ai, Claude Desktop, Claude Code, ChatGPT, Cursor (0.45+), Windsurf, Gemini, general MCP-capable editors (VS Code, Cline, Zed), API tools (Postman), and custom-built MCP clients or agent frameworks running on Groq, Azure OpenAI, AWS Bedrock, Ollama, LM Studio, or any other model provider all connect the same way. Paste your MCP URL (shown on this plugin's Dashboard) into the client's connector settings and complete the OAuth flow \u2014 most clients register and authorize automatically. Older clients use the legacy <code>\/sse<\/code> endpoint. Your site must be on HTTPS and publicly reachable.<\/p><\/dd>\n<dt id=\"which%20plugins%20does%20this%20integrate%20with%3F\"><h3>Which plugins does this integrate with?<\/h3><\/dt>\n<dd><p>WooCommerce (+ Subscriptions\/Bookings), Easy Digital Downloads, ACF, Elementor\/Bricks\/Divi, Gravity Forms\/WPForms\/Ninja Forms\/CF7, UpdraftPlus, FluentCRM, BuddyPress\/bbPress, The Events Calendar, 6 SEO plugins, WPML\/Polylang\/TranslatePress, GiveWP, AffiliateWP, LearnDash, MemberPress, and more. Each integration's tools activate automatically once the matching plugin is detected active \u2014 a connected AI client only ever sees tools whose dependencies are satisfied on your site.<\/p><\/dd>\n<dt id=\"is%20there%20rate%20limiting%2C%20and%20can%20i%20restrict%20which%20ips%20connect%3F\"><h3>Is there rate limiting, and can I restrict which IPs connect?<\/h3><\/dt>\n<dd><p>Yes to both. The <code>\/mcp<\/code> endpoint is limited to 60 requests\/minute per IP (HTTP 429 beyond that), with a separate 10\/minute limit on client self-registration. You can also add an IP allowlist (single IPs or CIDR ranges) in Settings to reject connections from anywhere outside it.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20collect%20telemetry%2C%20or%20contact%20any%20external%20service%3F\"><h3>Does this plugin collect telemetry, or contact any external service?<\/h3><\/dt>\n<dd><p>No external telemetry \u2014 the Activity Log stays local to your own database (redacted, for your own auditing), and nothing is ever sent to the plugin author's servers. It's primarily an <strong>inbound<\/strong> server, but two tool families make an outbound request only when explicitly invoked by an authenticated client: <code>wp_upload_media_from_url<\/code> (downloads one image from a client-supplied URL, blocked from private\/loopback IPs, 20 MB cap), and the plugin\/theme install-update tools, which use WordPress core's own installer classes to contact <code>api.wordpress.org<\/code>\/<code>downloads.wordpress.org<\/code> \u2014 the same servers wp-admin's \"Install Now\" uses, and only ever by slug, never an arbitrary URL.<\/p><\/dd>\n<dt id=\"what%20happens%20on%20uninstall%2C%20and%20does%20this%20work%20on%20multisite%3F\"><h3>What happens on uninstall, and does this work on multisite?<\/h3><\/dt>\n<dd><p>A clean uninstall removes every table, option, and transient this plugin created \u2014 no orphaned data. On multisite, each site gets its own settings, MCP URL, and Activity Log with no cross-site access; <code>wp_get_multisite_info<\/code> reports network status when enabled.<\/p><\/dd>\n<dt id=\"can%20i%20add%20my%20own%20custom%20tools%3F\"><h3>Can I add my own custom tools?<\/h3><\/dt>\n<dd><p>Yes \u2014 call <code>bcs_mcp_register_tool( 'my_tool', 'Description', $schema, $callback )<\/code> from your theme or a plugin, or use the <code>bcs_mcp_tools<\/code> filter to add\/modify\/remove tools before they're advertised to a connecting client.<\/p><\/dd>\n<dt id=\"my%20ai%20client%20can%27t%20connect%20%E2%80%94%20where%20do%20i%20start%3F\"><h3>My AI client can't connect \u2014 where do I start?<\/h3><\/dt>\n<dd><p>Run <strong>Diagnostics \u2192 Test Connection<\/strong> first \u2014 it checks HTTPS, permalinks, and OAuth discovery, and names the specific cause instead of a generic error. The most common causes: (1) a security plugin (Wordfence, All In One WP Security, etc.) restricting the REST API to logged-in users \u2014 this plugin's OAuth routes are intentionally anonymous and auto-exempt themselves from that as of 1.2.1, but you may still need to allowlist <code>\/.well-known\/*<\/code>, <code>\/authorize<\/code>, <code>\/token<\/code>, <code>\/register<\/code>, and <code>\/wp-json\/bcs-mcp\/*<\/code> (incl. <code>DELETE<\/code>) in your firewall; (2) a host\/CDN blocking any dot-prefixed path (<code>.well-known\/<\/code>) at the server level before WordPress sees it \u2014 no plugin setting fixes this, ask your host\/CDN to allow it through, or front the site with Cloudflare; (3) OAuth rewrite rules not yet flushed \u2014 visit Settings \u2192 Permalinks and click Save. \"No tools available\" on the very first connection that's fixed by disconnecting and reconnecting is a confirmed Claude Desktop client-side bug (Anthropic issue #60222), not a server issue.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.2<\/h4>\n\n<ul>\n<li>Added 19 new WordPress AI tools, bringing the total to 335+: plugin\/theme install-from-WordPress.org and update-to-latest (<code>wp_install_plugin<\/code>, <code>wp_update_plugin<\/code>, <code>wp_install_theme<\/code>, <code>wp_update_theme<\/code>), a WordPress core update tool (<code>wp_update_core<\/code>), WP-Cron event scheduling and deletion (<code>wp_schedule_cron_event<\/code>, <code>wp_delete_cron_event<\/code>), classic widget add\/remove (<code>wp_add_widget<\/code>, <code>wp_remove_widget<\/code>), a Redirection update tool (<code>redirection_update_redirect<\/code>), a Gravity Forms entry delete tool (<code>gf_delete_entry<\/code>), bbPress reply posting and moderation (<code>bbp_create_reply<\/code>, <code>bbp_moderate_reply<\/code>), an Easy Digital Downloads refund tool (<code>edd_refund_order<\/code>), an AffiliateWP affiliate approve\/reject tool (<code>affwp_set_affiliate_status<\/code>), GiveWP donation recording and refund tools (<code>givewp_create_donation<\/code>, <code>givewp_refund_donation<\/code>), a Code Snippets activate\/deactivate tool (<code>code_snippets_set_active<\/code>), and a two-factor reset tool (<code>wp_reset_2fa<\/code>)<\/li>\n<li>Plugin and theme installs are restricted to the WordPress.org directory by slug \u2014 no tool accepts an arbitrary download URL<\/li>\n<li>Security: <code>wp_add_widget<\/code> runs string values in <code>settings<\/code> through <code>wp_kses_post<\/code> before saving. Writing directly to the widget option bypasses the widget's own <code>WP_Widget::update()<\/code>, which is what normally sanitizes saved content, so this closes a path for unescaped markup to reach the public-facing site via a widget's front-end render.<\/li>\n<li>Documentation: added an External Services disclosure for <code>wp_install_plugin<\/code>, <code>wp_update_plugin<\/code>, <code>wp_install_theme<\/code>, <code>wp_update_theme<\/code>, and <code>wp_update_core<\/code>, which contact the official WordPress.org API using WordPress core's own installer\/updater classes \u2014 the same servers and code path as wp-admin's \"Install Now\"\/\"Update Now\" \u2014 and documented that these tools accept a plugin\/theme slug only, never an arbitrary download URL, per the WordPress.org Plugin Directory guideline on not installing code from third-party servers<\/li>\n<li>Redesigned the plugin's admin UI: added a one-click light\/dark theme switcher (light by default, remembered per browser) next to Settings on every screen, refreshed the color palette and typography, gave buttons and icon controls a consistent rounded style, and reworked the Tools browser's category list into an animated, easier-to-scan accordion \u2014 all scoped to this plugin's own admin pages, with no effect on the rest of wp-admin<\/li>\n<li>New optional safeguard: a \"Require confirmation for destructive actions\" toggle in Settings (off by default). When enabled, the ~28 delete-type tools (posts, pages, media, terms, comments, users, menus, cron events, widgets, transients, and the WooCommerce\/ACF\/Gravity Forms\/Events Calendar\/CPT UI equivalents) return a preview of what would happen instead of executing on their first call, and only run once the connecting AI client resubmits the identical call with an added <code>\"confirm\": true<\/code> argument<\/li>\n<\/ul>\n\n<h4>1.2.1<\/h4>\n\n<ul>\n<li>Fixed: uninstalling the plugin left the <code>bcs_mcp_review_notice<\/code> option behind instead of removing it along with the plugin's other options, contradicting this readme's \"clean uninstall, no orphaned data\" claim<\/li>\n<li>Hardened: the sensitive-value redaction list (used by the Activity Log and by generic postmeta\/usermeta read tools) now also matches meta keys containing the bare substring <code>pass<\/code> \u2014 e.g. a third-party plugin storing a credential under a key like <code>smtp_pass<\/code> or <code>ftp_pass<\/code> is now redacted; previously only keys containing the full word <code>password<\/code> or <code>passwd<\/code> were caught<\/li>\n<li>Fixed: security plugins that ship a \"restrict the REST API to logged-in users\" toggle (Wordfence, All In One WP Security, and similar) could block AI clients entirely, since this plugin's MCP\/OAuth routes are intentionally anonymous at the WordPress-login level and authenticate the caller themselves via OAuth Bearer token. This plugin's own routes are now automatically exempted from that kind of blanket lockdown set by another plugin.<\/li>\n<li>Diagnostics: the \"OAuth discovery endpoint reachable\" check now gives a specific, actionable message based on the actual HTTP status returned (401\/403\/406 now correctly points at a firewall\/security-plugin block instead of the generic \"rewrite rules\" message) instead of one generic failure message for every cause<\/li>\n<li>Diagnostics: added a new check that detects active security plugins (Wordfence, All In One WP Security, iThemes\/Solid Security, Sucuri Security, WP Cerber) and lists exactly which URLs and HTTP methods to allowlist in their firewall if a client still can't connect<\/li>\n<li>Diagnostics: the discovery-endpoint check now also detects when a 404 response never actually reached WordPress at all (identified by the response missing any PHP\/WordPress fingerprint). Previously this was misreported as \"rewrite rules not flushed,\" which sent people to the wrong settings screen; it now correctly says this needs a firewall\/allowlist fix, and explicitly names any active security plugin that could be the cause (its own protection layer, e.g. Wordfence's \"Extended Protection\" mode, can run before WordPress loads exactly like a host or CDN block would) rather than only pointing at the host\/CDN<\/li>\n<li>Added a dedicated FAQ entry with step-by-step guidance for Wordfence\/AIOS\/firewall-blocked connections and for the server\/CDN-level <code>.well-known<\/code> blocking case<\/li>\n<li>New: a proactive admin notice (shown on the Plugins screen and this plugin's own screens, not just when you manually run Diagnostics) that detects OAuth discovery\/registration problems automatically \u2014 a host or CDN blocking <code>\/.well-known\/*<\/code> before PHP runs, Sucuri\/CloudProxy specifically, a response that's HTML instead of JSON (another plugin or theme intercepting the request), Plain permalinks, or a host redirecting <code>POST \/register<\/code> to <code>\/register\/<\/code> with a 301 (which OAuth clients don't follow, silently breaking registration even when discovery works). Each case gets its own specific fix, and the notice is dismissible and re-checkable per admin<\/li>\n<li>Fixed: clicking \"Test Connection\" on the Diagnostics page didn't clear the separate cache the admin notice above uses, so the notice could keep reporting an already-fixed problem for up to its own refresh interval. Both now refresh together<\/li>\n<li>Fixed: a rejected connection attempt (an invalid\/expired token, an IP-allowlist block, or a rate limit) never appeared in the Activity Log at all \u2014 only successful tool calls were recorded, so a failing connection looked like total silence with nothing to debug from. These rejections are now logged with a specific reason (e.g. \"token was explicitly revoked\" vs. \"token expired at ... UTC\" vs. \"no matching access token found \u2014 never issued, or issued by a different site\/environment\") instead of the generic \"invalid or expired\" message alone. The routine unauthenticated request every OAuth client sends first (before it has a token) is deliberately not logged, since logging that would flood the log with noise rather than signal<\/li>\n<li>Documentation: identified SiteGround specifically (via its <code>X-CDN-C: static<\/code> free-CDN response header) as the most common cause of the \"host\/CDN blocking <code>.well-known\/<\/code>\" case \u2014 SiteGround's nginx reserves that entire path prefix for its own SSL certificate validation, fleet-wide, and per multiple reports won't adjust it per-site even on request. Added FAQ guidance covering how to identify it, the Cloudflare-edge-proxy workaround other SiteGround-hosted sites have used, and the tradeoffs of working around it by manually supplying an OAuth Client ID\/Secret in your AI client instead of relying on automatic discovery<\/li>\n<li>Documentation: added an FAQ entry explaining \"This connector has no tools available\" on a first-time connection that resolves after disconnect\/reconnect \u2014 confirmed via Anthropic's own issue tracker to be a Claude Desktop client-side bug (zero traffic reaches the server during the failure), not something a server-side fix can address<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Added 96+ new WordPress AI tools, bringing the total to 316+ across all supported integrations<\/li>\n<li>New integrations: MonsterInsights, Sucuri Security, and TranslatePress, plus WP Mail SMTP configuration status<\/li>\n<li>Fixed: admin screens were loading DM Sans \/ DM Mono from Google's font CDN on every page view even though local copies were already bundled; now fully self-hosted with no external requests<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<p>This release adds 56 new WordPress MCP tools (215+ total, up from 150+), six more SEO plugin integrations, two new community\/events integrations, a dedicated connection diagnostics page, and a redesigned admin dashboard \u2014 plus security hardening and bug fixes. <strong>Fully backward compatible:<\/strong> existing OAuth connections, access tokens, Activity Log history, and settings are preserved automatically on update \u2014 no re-authorization, reconfiguration, or action of any kind is required from existing users. Full details below.<\/p>\n\n<p><strong>New: SEO tools now support 6 plugins (was 2)<\/strong>\n* SEO meta tools (per-post title\/description\/focus keyword\/noindex, bulk SEO audit, site-wide title separator and homepage settings) now auto-detect and support Yoast SEO, Rank Math, All in One SEO (AIOSEO), SEOPress, Slim SEO, and The SEO Framework\n* AIOSEO is read and written directly through its own database table (not postmeta), matching how AIOSEO v4+ actually stores data<\/p>\n\n<p><strong>New: Community &amp; Events integrations<\/strong>\n* BuddyPress \u2014 list members, read extended profile (xProfile) fields, read and post to the activity stream, list and create groups, list group members, list friend connections\n* The Events Calendar \u2014 full event CRUD (create, read, update, delete), plus venues, organizers, and event categories<\/p>\n\n<p><strong>New: Forms, LMS &amp; e-commerce integrations<\/strong>\n* Contact Form 7 \u2014 list forms, read form fields and mail settings\n* WPForms \u2014 list forms, read entries (requires WPForms Pro or entry storage enabled)\n* Ninja Forms \u2014 list forms, read submissions\n* MemberPress \u2014 list memberships and members, get a member's subscriptions and transaction history\n* LearnDash \u2014 list courses, get a user's course progress, enroll\/unenroll a user\n* Easy Digital Downloads \u2014 products, orders, single order detail, customers, store stats\n* WooCommerce Subscriptions &amp; Bookings \u2014 list subscriptions, cancel a subscription, list bookings (added to the existing WooCommerce category)<\/p>\n\n<p><strong>New: Page builder &amp; site management integrations<\/strong>\n* Bricks Builder \u2014 read a page's element tree, clone a page with its Bricks content\n* Divi Builder \u2014 read a page's shortcode content, clone a page with its Divi content\n* Redirection \u2014 list, create, and delete URL redirects\n* UpdraftPlus (Backup &amp; Migration) \u2014 list backup sets, trigger a new backup, check job status\n* FluentCRM (Email \/ CRM) \u2014 list contacts, create or update a contact by email, list email campaigns<\/p>\n\n<p><strong>New: Core WordPress tools<\/strong>\n* Cache status detection \u2014 reports which page-caching and object-caching plugins are active\n* Users CSV export\n* Full Site Health diagnostics \u2014 runs the same tests shown under Tools \u2192 Site Health and summarizes critical\/recommended\/passed counts\n* <code>wp_bulk_delete_comments<\/code> \u2014 delete or trash multiple comments by ID in one call\n* <code>wp_duplicate_menu<\/code> \u2014 duplicate a nav menu including all of its items\n* <code>wp_get_multisite_info<\/code> \u2014 check multisite status and list network sites<\/p>\n\n<p><strong>New: Admin dashboard &amp; setup experience<\/strong>\n* Dedicated \"Connection Test\" page (between Settings and Activity Log) \u2014 checks HTTPS, permalinks, and live MCP\/OAuth-discovery endpoint reachability, and reports the specific reason a connection would fail instead of a generic error\n* \"Setup Health\" checklist on the Dashboard \u2014 at-a-glance status for server enabled, HTTPS, pretty permalinks, and whether an AI client is connected, with a \"Fix now \u2192\" shortcut\n* In-admin review prompt (shown only on this plugin's own screens, only after real successful tool calls) with \"Remind me later\" and \"No thanks\" options \u2014 never shown on first activation<\/p>\n\n<p><strong>Improved: Dashboard &amp; Settings UI<\/strong>\n* The \"Enable MCP Server\" toggle is now a full-width, color-coded banner at the top of Settings instead of a small switch buried inside a card\n* Removed the \"Quick Connect\" card from the Dashboard (it duplicated the per-client setup steps already on Settings); the \"WordPress Tools\" browser now spans the full page width\n* Dashboard pairs \"Setup Health\" on the left with the stat cards on the right (3 per row, 2 rows), matched to equal height\n* Setup Health checklist rows show a check\/warning icon and a \"Ready\" \/ \"Needs attention\" status tag, and are noticeably more compact\n* \"Recent Activity\" and \"Most Used Tools\" are now always shown side by side (2\/3 + 1\/3 columns) instead of \"Most Used Tools\" being hidden entirely until there's data \u2014 it now shows an empty state like Recent Activity does\n* Activity Log pagination now truncates to \"1 2 3 \u2026 8 9 10\" style instead of listing every page number when there are many pages\n* Fixed excess vertical spacing between the tool name and its usage bar in \"Most Used Tools\" (Dashboard and Settings)<\/p>\n\n<p><strong>Improved: Connection Test &amp; Activity Log<\/strong>\n* Redesigned the \"Connected AI Clients\" list on Connection Test: branded per-client color and avatar, total calls, calls today, and a session-expiry countdown, plus a \"View activity\" button that jumps straight to the Activity Log pre-filtered to that client\n* Activity Log table no longer scrolls inside its own box \u2014 it now scrolls with the page like the rest of the admin screen\n* Activity Log gained a \"Show \u2304 per page\" control (10 \/ 20 \/ 50 \/ 100, default 20); pagination now sits to the right of it instead of centered alone\n* \"Last tested\" timestamp on Connection Test now displays in the site's configured local timezone (Settings \u2192 General \u2192 Timezone) instead of the server's UTC time\n* Removed the redundant per-client \"connected X ago\" breakdown from the Dashboard's Setup Health card \u2014 the full detail now lives on the Connection Test page\n* Removed the \"No test run yet\" placeholder that could stay visible after a test had actually completed<\/p>\n\n<p><strong>Fixed<\/strong>\n* <code>tools\/list<\/code> now actually filters out addon-gated tools whose required plugin isn't active, instead of advertising all 215+ tools regardless of what's installed \u2014 a connected AI client only ever sees tools that will work on the site\n* Removed the \"REST endpoint reachable\" check from Connection Test \u2014 a self-request through some caching\/security-plugin setups could return HTTP 200 with a body that didn't parse as expected, producing a false failure on connections that were actually working fine. The remaining 4 checks (server enabled, HTTPS, permalinks, OAuth discovery) cover the same ground without the false positive\n* The \"Enable MCP Server\" toggle's label text was never actually rendered bold, and the switch itself blended into the banner background \u2014 both now have proper contrast\n* Activity Log's built-in connection-test entries were being mislabeled after the plugin rename\n* A missing <code>translators:<\/code> comment on the OAuth authorization screen was breaking automatic <code>.pot<\/code> generation\n* <code>wc_create_variation<\/code> \/ <code>wc_update_variation<\/code> \u2014 attribute values passed as <code>{name, option}<\/code> could silently save as an empty string instead of the intended value; the variation's postmeta key was being double-prefixed, and a brand-new attribute or term was never registered on the parent product as usable for variations. Both are now handled automatically\n* <code>wp_get_site_health_tests<\/code> could hang the whole request (\"connector's server isn't responding\") if a network-dependent Site Health test wasn't already excluded, or if a single test threw a fatal error; hardened with a wider skip list for network-calling tests, a 3-second HTTP timeout clamp for the duration of the run, and per-test error isolation so one broken test can't take down the whole diagnostic\n* A tool call that hit an uncaught PHP fatal error (as opposed to a caught <code>Exception<\/code>) was left stuck at <code>status = pending<\/code> in the Activity Log forever instead of being recorded as <code>error<\/code><\/p>\n\n<p><strong>Security<\/strong>\n* <code>wp_export_users_csv<\/code> now neutralizes spreadsheet formula-injection characters (<code>=<\/code>, <code>+<\/code>, <code>-<\/code>, <code>@<\/code>) and escapes embedded quotes in exported fields\n* Dynamic database table names in the WPForms, MemberPress, and Redirection queries now use <code>$wpdb-&gt;prepare()<\/code>'s <code>%i<\/code> identifier placeholder instead of raw string interpolation<\/p>\n\n<p><strong>Changed<\/strong>\n* Plugin renamed to \"ByteCoreStack - MCP Connector for AI Tools\" (previously \"AI Connector \u2013 MCP for Claude, ChatGPT, Gemini &amp; More\")\n* Readme tags updated for search discoverability (<code>mcp, ai, claude, chatgpt, mcp-server<\/code>)\n* All new integrations activate automatically when their corresponding plugin is detected, matching the existing WooCommerce\/ACF\/Elementor\/Gravity Forms behavior \u2014 no configuration required\n* 215+ WordPress MCP tools across 30 categories (215 verified at release)<\/p>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<li>150+ WordPress MCP tools across 20 categories (159 verified at release)<\/li>\n<li>OAuth 2.0 with PKCE (authorization code flow, Dynamic Client Registration, refresh tokens)<\/li>\n<li>Discovery endpoints: <code>\/.well-known\/oauth-protected-resource<\/code> and <code>\/.well-known\/oauth-authorization-server<\/code><\/li>\n<li>Streamable HTTP transport (MCP 2025-11-25) as primary transport<\/li>\n<li>Legacy SSE transport (<code>\/sse<\/code> + <code>\/messages<\/code>) for older client versions \u2014 compatible with all clients, not restricted by User-Agent<\/li>\n<li><code>Mcp-Session-Id<\/code> response header on <code>initialize<\/code> for session tracking (required by Cursor)<\/li>\n<li><code>X-Accel-Buffering: no<\/code> on SSE responses for nginx compatibility<\/li>\n<li>Auth validation on session termination (DELETE \/mcp)<\/li>\n<li>Activity logging with client detection (Claude, ChatGPT, Gemini, Cursor, Windsurf, and others), storing each call's parameters\/result locally for audit purposes with sensitive-looking values redacted automatically<\/li>\n<li>IP allowlist support<\/li>\n<li>Admin dashboard with today's success\/fail stat cards, settings page, and activity log with CSV export<\/li>\n<li>WP Dashboard widget (7-day activity bar chart)<\/li>\n<li>WooCommerce (33 tools), ACF (3 tools), Elementor (6 tools), and Gravity Forms (2 tools) integrations \u2014 activate automatically when those plugins are present<\/li>\n<li>Developer API: <code>bcs_mcp_register_tool()<\/code> helper and <code>bcs_mcp_tools<\/code> filter for custom tools<\/li>\n<li>No tool creates new WordPress users; <code>wp_update_user<\/code> no longer accepts a <code>role<\/code> parameter \u2014 use <code>wp_assign_user_role<\/code> (requires <code>promote_users<\/code>) for role changes<\/li>\n<li>Clean uninstall: removes all plugin tables, options, and transients with no orphaned data<\/li>\n<li>Translation-ready: full <code>.pot<\/code> file included in <code>\/languages<\/code> for translators<\/li>\n<\/ul>","raw_excerpt":"Connect Claude, ChatGPT &amp; Gemini to WordPress via MCP \u2014 AI automation with 335+ tools, OAuth 2.0, WooCommerce &amp; SEO support.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/326332","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=326332"}],"author":[{"embeddable":true,"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/bytecorestack"}],"wp:attachment":[{"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=326332"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=326332"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=326332"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=326332"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=326332"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=326332"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}