{"id":326332,"date":"2026-07-06T18:02:40","date_gmt":"2026-07-06T18:02:40","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/bytecore-mcp-manager\/"},"modified":"2026-07-27T17:26:14","modified_gmt":"2026-07-27T17:26:14","slug":"bcs-mcp-manager","status":"publish","type":"plugin","link":"https:\/\/hr.wordpress.org\/plugins\/bcs-mcp-manager\/","author":23505918,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.0","stable_tag":"1.1.0","tested":"7.0.2","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"ByteCoreStack - MCP Connector for AI Tools","header_author":"ByteCore Stack","header_description":"Free WordPress AI plugin and MCP server \u2014 connects Claude, ChatGPT, Gemini, Cursor, Windsurf, and any MCP-compatible AI client to WordPress. Includes 150+ WordPress AI tools, OAuth 2.0 with PKCE, activity logging, and an admin dashboard.","assets_banners_color":"080f36","last_updated":"2026-07-27 17:26:14","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/bytecorestack.com\/plugins\/ai-connector\/","header_author_uri":"https:\/\/bytecorestack.com","rating":0,"author_block_rating":0,"active_installs":20,"downloads":184,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"bytecorestack","date":"2026-07-06 18:02:29"},"1.1.0":{"tag":"1.1.0","author":"bytecorestack","date":"2026-07-27 17:26:14"}},"upgrade_notice":{"1.1.0":"<p>Adds 56 new tools (SEO, forms, LMS, EDD, page builders, backups, CRM, BuddyPress, Events Calendar, WooCommerce subscriptions\/bookings), a security fix, and bug fixes. Fully backward compatible, no reconnection needed. Renamed to &quot;ByteCoreStack - MCP Connector for AI Tools.&quot;<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3598182,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3598182,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3598182,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3598182,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.1.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3598182,"resolution":"1","location":"assets","locale":"","width":1280,"height":800},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3598182,"resolution":"2","location":"assets","locale":"","width":1280,"height":800},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3598182,"resolution":"3","location":"assets","locale":"","width":1280,"height":800},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3598182,"resolution":"4","location":"assets","locale":"","width":1280,"height":800},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3598182,"resolution":"5","location":"assets","locale":"","width":1280,"height":800},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3598182,"resolution":"6","location":"assets","locale":"","width":1280,"height":800},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3598182,"resolution":"7","location":"assets","locale":"","width":1280,"height":800}},"screenshots":{"1":"Admin dashboard \u2014 server status, today's stats, and recent activity feed.","2":"Tools browser \u2014 every tool, most-used tool in the last 28 days, and quick docs.","3":"Tool detail view \u2014 tool name, method, and a plain-English explanation.","4":"Settings page \u2014 enable the MCP server, copy your endpoint URL, and setup guides per AI client.","5":"Activity Log \u2014 filter by client, status, and date range, with color-coded tags and CSV export.","6":"WP Dashboard widget \u2014 a 7-day activity sparkline on your wp-admin home screen.","7":"Claude connector page \u2014 tools list and permission settings for the connection."}},"plugin_section":[262246],"plugin_tags":[2353,216196,229563,242115,260626],"plugin_category":[],"plugin_contributors":[266332],"plugin_business_model":[],"class_list":["post-326332","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-ai","plugin_tags-chatgpt","plugin_tags-claude","plugin_tags-mcp","plugin_tags-mcp-server","plugin_contributors-bytecorestack","plugin_committers-bytecorestack"],"banners":{"banner":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/banner-772x250.png?rev=3598182","banner_2x":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/banner-1544x500.png?rev=3598182","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/icon-128x128.png?rev=3598182","icon_2x":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/icon-256x256.png?rev=3598182","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/screenshot-1.png?rev=3598182","caption":"Admin dashboard \u2014 server status, today's stats, and recent activity feed."},{"src":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/screenshot-2.png?rev=3598182","caption":"Tools browser \u2014 every tool, most-used tool in the last 28 days, and quick docs."},{"src":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/screenshot-3.png?rev=3598182","caption":"Tool detail view \u2014 tool name, method, and a plain-English explanation."},{"src":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/screenshot-4.png?rev=3598182","caption":"Settings page \u2014 enable the MCP server, copy your endpoint URL, and setup guides per AI client."},{"src":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/screenshot-5.png?rev=3598182","caption":"Activity Log \u2014 filter by client, status, and date range, with color-coded tags and CSV export."},{"src":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/screenshot-6.png?rev=3598182","caption":"WP Dashboard widget \u2014 a 7-day activity sparkline on your wp-admin home screen."},{"src":"https:\/\/ps.w.org\/bcs-mcp-manager\/assets\/screenshot-7.png?rev=3598182","caption":"Claude connector page \u2014 tools list and permission settings for the connection."}],"raw_content":"<!--section=description-->\n<p>ByteCoreStack - MCP Connector for AI Tools is a WordPress AI plugin that turns your site into a Model Context Protocol (MCP) server, so AI assistants like Claude, ChatGPT, and Gemini can connect directly and take real action instead of just describing what to do.<\/p>\n\n<p>Once connected, your AI agent can draft and publish posts, manage WooCommerce orders and subscriptions, fix SEO metadata, moderate comments, sync FluentCRM contacts, trigger UpdraftPlus backups, and update Elementor or Bricks pages \u2014 calling on 215+ WordPress AI tools across 30 categories, each checked against the connecting user's real WordPress capabilities and logged in an Activity Log you control.<\/p>\n\n<p>Authentication runs over OAuth 2.0 with PKCE, the same flow used by Google, Microsoft, and Slack \u2014 no shared API key, no third-party relay, and every action is capability-checked, logged, and reversible from Settings \u2192 Reset OAuth State.<\/p>\n\n<p>See the Other Notes tab below for the full category breakdown, supported AI clients, security details, and setup instructions.<\/p>\n\n<h4>Links<\/h4>\n\n<ul>\n<li><a href=\"https:\/\/bytecorestack.com\/plugins\/ai-connector\/\">Plugin homepage<\/a><\/li>\n<li><a href=\"https:\/\/wordpress.org\/support\/plugin\/bcs-mcp-manager\/\">Support forum<\/a><\/li>\n<li><a href=\"https:\/\/modelcontextprotocol.io\/\">Model Context Protocol specification<\/a><\/li>\n<\/ul>\n\n<h4>What Can an AI Agent Do With WordPress?<\/h4>\n\n<ul>\n<li>\"Draft and publish a blog post about [topic], generate a featured image, and tag it correctly.\"<\/li>\n<li>\"Show me yesterday's WooCommerce orders over $100 and refund order #1042.\"<\/li>\n<li>\"Find every page with a missing or duplicate SEO title and fix it.\"<\/li>\n<li>\"Duplicate this Elementor page, swap the hero image, and update the headline.\"<\/li>\n<li>\"List my WooCommerce coupons expiring this month and extend them by two weeks.\"<\/li>\n<li>\"Trigger an UpdraftPlus backup before I start a big content migration.\"<\/li>\n<\/ul>\n\n<h4>Why Choose ByteCoreStack - MCP Connector for AI Tools for WordPress Automation?<\/h4>\n\n<ul>\n<li><strong>215+ tools, 30 categories<\/strong> \u2014 one of the largest verified MCP tool sets for WordPress<\/li>\n<li><strong>Multi-client<\/strong> \u2014 works with Claude, ChatGPT, Gemini, Cursor, Windsurf, and any MCP 2025-11-25 client<\/li>\n<li><strong>Real OAuth 2.0<\/strong> \u2014 full authorization code flow with PKCE, Dynamic Client Registration, and discovery endpoints \u2014 no shared API key<\/li>\n<li><strong>Conservative by design<\/strong> \u2014 no tool can create a WordPress user; role changes require <code>promote_users<\/code><\/li>\n<li><strong>Local, redacted activity logging<\/strong> \u2014 every tool call is logged in your own database with sensitive values redacted<\/li>\n<li><strong>Zero telemetry, ever<\/strong> \u2014 no analytics or tracking of any kind<\/li>\n<li><strong>Grows with your stack<\/strong> \u2014 WooCommerce, ACF, Elementor, Bricks, Divi, Gravity Forms, WPForms, Ninja Forms, Contact Form 7, MemberPress, LearnDash, EDD, Redirection, UpdraftPlus, FluentCRM, BuddyPress, and The Events Calendar tools activate automatically when detected<\/li>\n<li><strong>Open to extend<\/strong> \u2014 register your own custom MCP tools with one function call<\/li>\n<\/ul>\n\n<h4>Ideal For<\/h4>\n\n<ul>\n<li><strong>Agencies and freelancers<\/strong> who want to run day-to-day WordPress maintenance through an AI assistant instead of clicking through wp-admin one task at a time<\/li>\n<li><strong>WooCommerce store owners<\/strong> who want an AI agent that can check orders, adjust stock, manage coupons, and handle subscriptions on request<\/li>\n<li><strong>SEO teams and content editors<\/strong> running bulk metadata fixes, content audits, or multi-step publishing workflows<\/li>\n<li><strong>Developers<\/strong> who want a real WordPress AI integration to build custom AI automation and AI workflow tools on top of<\/li>\n<li><strong>Anyone already using Claude, ChatGPT, Cursor, or Windsurf<\/strong> who wants those tools to actually reach into WordPress instead of just describing what to do next<\/li>\n<\/ul>\n\n<h4>Supported AI Assistants &amp; MCP Clients<\/h4>\n\n<ul>\n<li><strong>Claude.ai<\/strong> \u2014 Settings \u2192 Integrations \u2192 Add integration \u2192 Custom MCP<\/li>\n<li><strong>Claude Desktop<\/strong> \u2014 add the MCP URL to <code>claude_desktop_config.json<\/code> under <code>mcpServers<\/code><\/li>\n<li><strong>Claude Code<\/strong> \u2014 connects over the same Streamable HTTP MCP endpoint<\/li>\n<li><strong>ChatGPT<\/strong> \u2014 Settings \u2192 Connectors \u2192 Add connector \u2192 MCP Server<\/li>\n<li><strong>Gemini<\/strong> \u2014 connect via Google AI Studio MCP integrations<\/li>\n<li><strong>Cursor (0.45+)<\/strong> \u2014 Settings \u2192 MCP \u2192 Add New Server \u2192 HTTP (Streamable HTTP transport)<\/li>\n<li><strong>Windsurf<\/strong> \u2014 MCP settings panel, supports both Streamable HTTP and legacy SSE<\/li>\n<li><strong>VS Code, Cline, Continue, Zed, JetBrains<\/strong> and any other editor or IDE with MCP client support<\/li>\n<li><strong>Postman, Insomnia<\/strong> and other API tools with MCP request support<\/li>\n<li>Any custom client or framework that implements the MCP 2025-11-25 specification<\/li>\n<\/ul>\n\n<h4>WordPress AI Tools by Category (215 Tools, Verified)<\/h4>\n\n<p>215 is the plugin's total across every supported integration below. Tools marked <em>(activates automatically)<\/em> only appear to a connected AI client once the matching plugin is active on your site \u2014 see \"My AI client shows fewer than 215+ tools \u2014 is that a bug?\" in the FAQ above for how the count works.<\/p>\n\n<ul>\n<li><strong>Posts<\/strong> \u2014 14 tools (create, read, update, delete, duplicate, bulk trash, schedule, search, count, post types &amp; statuses, post format, password protection)<\/li>\n<li><strong>Pages<\/strong> \u2014 8 tools (CRUD, duplicate, page templates)<\/li>\n<li><strong>Media<\/strong> \u2014 11 tools (browse, upload from file or URL, update metadata, set featured image, regenerate thumbnails, attachment metadata, image sizes, count)<\/li>\n<li><strong>Taxonomies<\/strong> \u2014 11 tools (categories, tags, custom taxonomies, term meta, term assignment)<\/li>\n<li><strong>Comments<\/strong> \u2014 9 tools (CRUD, approve, spam, trash, bulk delete, pending queue)<\/li>\n<li><strong>Users<\/strong> \u2014 11 tools (list, view, update, delete, sessions, roles, password reset, CSV export \u2014 no creation tool, by design)<\/li>\n<li><strong>Meta<\/strong> \u2014 6 tools (post meta and user meta read\/write\/delete)<\/li>\n<li><strong>Menus<\/strong> \u2014 11 tools (menus, menu items, reordering, duplication, location assignment)<\/li>\n<li><strong>Plugins &amp; Themes<\/strong> \u2014 7 tools (list, activate, deactivate, active theme, theme mods, custom CSS)<\/li>\n<li><strong>SEO<\/strong> \u2014 4 tools (read\/update per-post SEO meta, bulk SEO audit across posts, site-wide title\/description settings \u2014 Yoast SEO, Rank Math, AIOSEO, SEOPress, Slim SEO, or The SEO Framework)<\/li>\n<li><strong>Site \/ Options<\/strong> \u2014 11 tools (site info, site health, full Site Health diagnostics, multisite status, server info, permalink structure, plugin settings, database size, debug log, send email)<\/li>\n<li><strong>Revisions<\/strong> \u2014 5 tools (history and restore)<\/li>\n<li><strong>Cache<\/strong> \u2014 6 tools (cache status detection, flush, purge, optimize tables, transients)<\/li>\n<li><strong>Blocks<\/strong> \u2014 2 tools (parse blocks, block patterns, reusable blocks)<\/li>\n<li><strong>Widgets<\/strong> \u2014 2 tools (registered sidebars, sidebar widgets)<\/li>\n<li><strong>Developer Tools<\/strong> \u2014 5 tools (shortcode execution, cron jobs, rewrite rules, and more)<\/li>\n<li><strong>WooCommerce<\/strong> <em>(activates automatically)<\/em> \u2014 36 tools (products, variations, attributes, coupons, orders, refunds, customers, shipping zones, tax rates, store stats, payment gateways, subscriptions, bookings)<\/li>\n<li><strong>Advanced Custom Fields<\/strong> <em>(activates automatically)<\/em> \u2014 3 tools (field groups, field values, field updates)<\/li>\n<li><strong>Elementor<\/strong> <em>(activates automatically)<\/em> \u2014 6 tools (clone page, bulk text replace, image swap, page outline, template import\/listing)<\/li>\n<li><strong>Forms<\/strong> <em>(activates automatically)<\/em> \u2014 8 tools across Gravity Forms, Contact Form 7, WPForms, and Ninja Forms (list forms, read entries\/submissions)<\/li>\n<li><strong>Backup &amp; Migration<\/strong> <em>(activates automatically, requires UpdraftPlus)<\/em> \u2014 3 tools (list backups, trigger a backup, check job status)<\/li>\n<li><strong>Email \/ CRM<\/strong> <em>(activates automatically, requires FluentCRM)<\/em> \u2014 3 tools (list contacts, create\/update a contact, list campaigns)<\/li>\n<li><strong>MemberPress<\/strong> <em>(activates automatically)<\/em> \u2014 3 tools (list memberships, list members, get member subscriptions\/transactions)<\/li>\n<li><strong>LearnDash<\/strong> <em>(activates automatically)<\/em> \u2014 3 tools (list courses, get course progress, enroll\/unenroll a user)<\/li>\n<li><strong>Easy Digital Downloads<\/strong> <em>(activates automatically)<\/em> \u2014 5 tools (products, orders, single order detail, customers, store stats)<\/li>\n<li><strong>Bricks Builder<\/strong> <em>(activates automatically)<\/em> \u2014 2 tools (get page element tree, clone page with Bricks content)<\/li>\n<li><strong>Divi Builder<\/strong> <em>(activates automatically)<\/em> \u2014 2 tools (get page shortcode content, clone page with Divi content)<\/li>\n<li><strong>Redirection<\/strong> <em>(activates automatically)<\/em> \u2014 3 tools (list, create, delete URL redirects)<\/li>\n<li><strong>BuddyPress<\/strong> <em>(activates automatically)<\/em> \u2014 8 tools (members, extended profile fields, activity stream, groups, group members, friends)<\/li>\n<li><strong>The Events Calendar<\/strong> <em>(activates automatically)<\/em> \u2014 9 tools (events CRUD, venues, organizers, event categories)<\/li>\n<\/ul>\n\n<h4>ByteCoreStack - MCP Connector for AI Tools Key Features<\/h4>\n\n<ul>\n<li><strong>215+ WordPress MCP tools<\/strong> across 30 categories \u2014 see the full breakdown above<\/li>\n<li><strong>OAuth 2.0 with PKCE<\/strong> \u2014 full authorization code flow with Dynamic Client Registration and discovery endpoints<\/li>\n<li><strong>Streamable HTTP transport<\/strong> (MCP 2025-11-25) with legacy SSE fallback for older clients<\/li>\n<li><strong>Activity log<\/strong> \u2014 every tool call recorded with client detection, filters, bulk delete, and CSV export; sensitive values redacted<\/li>\n<li><strong>Rate limiting<\/strong> \u2014 60 requests\/minute per IP on <code>\/mcp<\/code>, enforced automatically<\/li>\n<li><strong>IP allowlist<\/strong> \u2014 optionally restrict MCP access to specific IPs or CIDR ranges<\/li>\n<li><strong>Admin dashboard<\/strong> \u2014 live server status, OAuth client count, today's success\/fail counts, and a searchable tools browser<\/li>\n<li><strong>WP Dashboard widget<\/strong> \u2014 7-day activity sparkline right on your wp-admin home screen<\/li>\n<li><strong>Translation-ready<\/strong> \u2014 ships with a complete <code>.pot<\/code> file in <code>\/languages<\/code><\/li>\n<li><strong>Developer-friendly<\/strong> \u2014 extend with <code>bcs_mcp_register_tool()<\/code> or the <code>bcs_mcp_tools<\/code> filter<\/li>\n<\/ul>\n\n<h4>WooCommerce, Elementor, ACF &amp; Forms Plugin Integration<\/h4>\n\n<p>Tools for these plugins are included in the box but only activate when the respective plugin is installed and active. No errors are thrown if a plugin is absent, and nothing extra needs configuring. The MCP tool list shown to a connected AI client only ever includes tools whose dependencies are actually satisfied on your site \u2014 so a site without WooCommerce simply never advertises WooCommerce tools to the AI. The same applies to WooCommerce Subscriptions, WooCommerce Bookings, UpdraftPlus, FluentCRM, BuddyPress, and The Events Calendar.<\/p>\n\n<h4>Multisite Support<\/h4>\n\n<p>ByteCoreStack - MCP Connector for AI Tools works on WordPress multisite networks the same way it works on a single site: each site in the network has its own settings, its own MCP endpoint, and its own Activity Log. There is no cross-site tool access \u2014 an AI client connected to one site can never reach another site's data through this plugin. The <code>wp_get_multisite_info<\/code> tool reports network status and lists network sites for site owners who need it.<\/p>\n\n<h4>Extending ByteCoreStack - MCP Connector for AI Tools (Developer API)<\/h4>\n\n<p>Register custom tools from any plugin or theme:<\/p>\n\n<pre><code>bcs_mcp_register_tool( 'my_tool', 'Description', $schema, $callback );\n<\/code><\/pre>\n\n<p>Or use the <code>bcs_mcp_tools<\/code> filter directly to add, modify, or remove tools before they're advertised to a connecting AI client.<\/p>\n\n<h4>Security &amp; Permissions<\/h4>\n\n<ul>\n<li>All tool calls verify WordPress capabilities (<code>current_user_can<\/code>) before executing \u2014 an AI client can never do more than the authorizing user is allowed to do<\/li>\n<li>No MCP tool can create new WordPress users \u2014 user accounts must be created through wp-admin, full stop<\/li>\n<li>Role changes (<code>wp_assign_user_role<\/code>) require the <code>promote_users<\/code> capability, not just <code>edit_users<\/code><\/li>\n<li>OAuth tokens are SHA-256 hashed before database storage \u2014 plain tokens are never stored<\/li>\n<li>PKCE (S256) is required for all authorization flows; plain challenges are rejected<\/li>\n<li>Every <code>\/mcp<\/code> request is rate-limited to 60 requests per minute per IP address (tracked by <code>REMOTE_ADDR<\/code> only \u2014 spoofable headers like <code>X-Forwarded-For<\/code> are never trusted for this check), returning HTTP 429 once exceeded<\/li>\n<li>Dynamic Client Registration is separately rate-limited to 10 registrations per IP per minute, preventing abuse of the open registration endpoint<\/li>\n<li>Sensitive meta keys (<code>user_pass<\/code>, <code>session_tokens<\/code>, and similar) are permanently blocked from read\/write, with no setting to disable the block<\/li>\n<li>The Activity Log stores tool name, timestamp, client, status, and the call's parameters\/result for audit purposes, all locally in your own database \u2014 any value that looks like a password, token, secret, or key is redacted before it's written, and large content fields are truncated<\/li>\n<li>Outbound image downloads validate URLs against a blocklist of private\/loopback IP ranges (SSRF protection) and enforce a 20 MB size limit<\/li>\n<li>All admin AJAX actions are protected by nonce verification and a <code>manage_options<\/code> capability check<\/li>\n<li>Session termination (<code>DELETE \/mcp<\/code>) requires a valid bearer token<\/li>\n<li>CSV exports (<code>wp_export_users_csv<\/code>) neutralize spreadsheet formula-injection characters and escape embedded quotes before writing rows<\/li>\n<li>Dynamic database table names are passed through <code>$wpdb-&gt;prepare()<\/code>'s <code>%i<\/code> identifier placeholder rather than interpolated directly into query strings<\/li>\n<li>The MCP server ships <strong>disabled by default<\/strong> \u2014 nothing is exposed until you explicitly enable it in Settings<\/li>\n<\/ul>\n\n<h3>External Services<\/h3>\n\n<p>This plugin operates primarily as an <strong>inbound<\/strong> API server \u2014 AI clients connect to it, not the other way around. No data is sent to any external service automatically or in the background.<\/p>\n\n<h4>Image download via wp_upload_media_from_url<\/h4>\n\n<p>The <code>wp_upload_media_from_url<\/code> MCP tool, when explicitly invoked by an authenticated AI client (e.g. Claude), makes a single outgoing HTTP GET request to download an image from the URL the AI client provides. This request:<\/p>\n\n<ul>\n<li>Is only made when the tool is called by a connected, OAuth-authenticated MCP client<\/li>\n<li>Carries no personal data beyond the image URL itself<\/li>\n<li>Is validated against a blocklist of private\/loopback IP ranges before the request is made<\/li>\n<li>Is subject to a 20 MB size limit<\/li>\n<\/ul>\n\n<p>No data is sent to the plugin author's servers at any time. This plugin does not include analytics, telemetry, or tracking of any kind.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>bcs-mcp-manager<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install directly from the WordPress.org plugin directory.<\/li>\n<li>Activate the plugin via <strong>Plugins \u2192 Installed Plugins<\/strong>.<\/li>\n<li>Go to <strong>ByteCoreStack - MCP Connector for AI Tools \u2192 Settings<\/strong> and enable the MCP server.<\/li>\n<li>Copy the MCP URL shown on the <strong>Dashboard<\/strong> page.<\/li>\n<li>Paste the MCP URL into your AI client (Claude.ai, Claude Desktop, ChatGPT, Gemini, Cursor, or Windsurf) and complete the one-time OAuth authorization.<\/li>\n<li>Open the <strong>Activity Log<\/strong> to confirm tool calls are arriving, and use the <strong>WP Dashboard widget<\/strong> to keep an eye on activity going forward.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20bytecorestack%20-%20mcp%20connector%20for%20ai%20tools%20free%3F\"><h3>Is ByteCoreStack - MCP Connector for AI Tools free?<\/h3><\/dt>\n<dd><p>Yes, the plugin is completely free with no premium tiers, license keys, usage caps, or feature paywalls \u2014 every tool listed in this readme is included.<\/p><\/dd>\n<dt id=\"will%20updating%20to%20version%201.1.0%20break%20my%20existing%20ai%20connection%20or%20settings%3F\"><h3>Will updating to version 1.1.0 break my existing AI connection or settings?<\/h3><\/dt>\n<dd><p>No. Version 1.1.0 is a fully backward-compatible update: your existing OAuth connection, access tokens, Settings, and Activity Log history all carry over automatically \u2014 nothing is reset, revoked, or reconfigured. The plugin was renamed from \"AI Connector \u2013 MCP for Claude, ChatGPT, Gemini &amp; More\" to \"ByteCoreStack - MCP Connector for AI Tools,\" but the plugin slug, database tables, and MCP URL are unchanged, so Claude, ChatGPT, Gemini, Cursor, and Windsurf all keep working without needing to reconnect. New tools simply appear the next time your AI client refreshes its tool list.<\/p><\/dd>\n<dt id=\"what%20is%20mcp%20%28model%20context%20protocol%29%3F\"><h3>What is MCP (Model Context Protocol)?<\/h3><\/dt>\n<dd><p>MCP is an open standard, originally created by Anthropic, that lets AI assistants like Claude and ChatGPT securely connect to external tools and data sources using a structured, authenticated protocol instead of free-text copy-paste. This plugin implements a full MCP server inside WordPress so any MCP-compatible AI client can read and manage your site's content directly.<\/p><\/dd>\n<dt id=\"what%27s%20the%20best%20mcp%20server%20for%20wordpress%3F\"><h3>What's the best MCP server for WordPress?<\/h3><\/dt>\n<dd><p>There are a few MCP servers for WordPress, and the right one depends on what you need. ByteCoreStack - MCP Connector for AI Tools's focus is breadth of verified tools (215+ across 30 categories), real OAuth 2.0 with PKCE instead of a shared API key, and zero telemetry \u2014 every action is capability-checked and recorded in your own database rather than sent anywhere else. If you're comparing options, look closely at tool coverage, how authentication actually works, and what happens to your data; ByteCoreStack - MCP Connector for AI Tools is built to hold up well on all three.<\/p><\/dd>\n<dt id=\"which%20ai%20clients%20are%20supported%3F\"><h3>Which AI clients are supported?<\/h3><\/dt>\n<dd><p>Any client that implements the MCP 2025-11-25 Streamable HTTP transport. Tested and confirmed working with Claude.ai, Claude Desktop, Claude Code, ChatGPT, Cursor (0.45+), and Windsurf. Gemini uses the same standard protocol and is expected to work via Google AI Studio's MCP integrations. Editors and IDEs with general-purpose MCP client support \u2014 VS Code, Continue, Cline, Zed, JetBrains \u2014 and API tools like Postman also connect successfully. Older client versions that use the legacy SSE transport are supported via the <code>\/sse<\/code> endpoint.<\/p><\/dd>\n<dt id=\"can%20an%20ai%20agent%20manage%20my%20entire%20wordpress%20site%3F\"><h3>Can an AI agent manage my entire WordPress site?<\/h3><\/dt>\n<dd><p>It can call any of the 215+ MCP tools this plugin exposes \u2014 content, WooCommerce, SEO, media, comments, users, backups, CRM, and more \u2014 but always scoped to what the authorizing WordPress user is allowed to do. No MCP tool creates new WordPress users, and role changes require the <code>promote_users<\/code> capability specifically. Think of it as an AI assistant with exactly the permissions of whoever connected it, not an unsupervised admin.<\/p><\/dd>\n<dt id=\"how%20do%20i%20connect%20claude.ai%20to%20my%20wordpress%20site%3F\"><h3>How do I connect Claude.ai to my WordPress site?<\/h3><\/dt>\n<dd><p>Go to Claude.ai \u2192 Settings \u2192 Integrations \u2192 Add integration \u2192 Custom MCP. Paste your MCP URL (<code>https:\/\/yoursite.com\/wp-json\/bcs-mcp\/v1\/mcp<\/code>) and follow the OAuth authorization flow. Claude handles client registration and token management automatically.<\/p><\/dd>\n<dt id=\"how%20do%20i%20connect%20chatgpt%3F\"><h3>How do I connect ChatGPT?<\/h3><\/dt>\n<dd><p>In ChatGPT: Settings \u2192 Connectors \u2192 Add connector \u2192 MCP Server. Paste your MCP URL and complete the OAuth flow. Your site must be publicly accessible (not localhost) and on HTTPS.<\/p><\/dd>\n<dt id=\"how%20do%20i%20connect%20claude%20desktop%3F\"><h3>How do I connect Claude Desktop?<\/h3><\/dt>\n<dd><p>Add the following to your <code>claude_desktop_config.json<\/code> file under <code>mcpServers<\/code>:<\/p>\n\n<pre><code>\"wordpress\": { \"url\": \"https:\/\/yoursite.com\/wp-json\/bcs-mcp\/v1\/mcp\", \"transport\": \"http\" }\n<\/code><\/pre>\n\n<p>Restart Claude Desktop and authorize via the OAuth consent page that opens in your browser.<\/p><\/dd>\n<dt id=\"how%20do%20i%20connect%20cursor%3F\"><h3>How do I connect Cursor?<\/h3><\/dt>\n<dd><p>In Cursor: Settings \u2192 MCP \u2192 Add New Server \u2192 select type HTTP \u2192 paste your MCP URL. Cursor uses the Streamable HTTP transport and sessions tracked via the <code>Mcp-Session-Id<\/code> header. Ensure your WordPress site is on HTTPS.<\/p><\/dd>\n<dt id=\"how%20do%20i%20connect%20windsurf%3F\"><h3>How do I connect Windsurf?<\/h3><\/dt>\n<dd><p>Open Windsurf's MCP settings and add a new server with your MCP URL. Recent Windsurf versions use Streamable HTTP; older versions connect via the legacy SSE endpoint at <code>\/sse<\/code>. Both are supported automatically.<\/p><\/dd>\n<dt id=\"does%20this%20work%20with%20woocommerce%3F\"><h3>Does this work with WooCommerce?<\/h3><\/dt>\n<dd><p>Yes. 36 tools covering products, variations, attributes, coupons, orders, refunds, customers, shipping zones, tax rates, payment gateways, store statistics, subscriptions, and bookings activate automatically once WooCommerce (and WooCommerce Subscriptions \/ Bookings, where relevant) is detected \u2014 no extra configuration required.<\/p><\/dd>\n<dt id=\"does%20this%20work%20with%20elementor%2C%20acf%2C%20or%20gravity%20forms%3F\"><h3>Does this work with Elementor, ACF, or Gravity Forms?<\/h3><\/dt>\n<dd><p>Yes, all three are supported. Tools for each only become active when the respective plugin is installed and active, and the AI client only ever sees the tools whose dependencies are actually satisfied on your site.<\/p><\/dd>\n<dt id=\"does%20this%20work%20with%20backup%20and%20crm%20plugins%3F\"><h3>Does this work with backup and CRM plugins?<\/h3><\/dt>\n<dd><p>Yes. UpdraftPlus tools let an AI client list backups, trigger a new backup, and check job status. FluentCRM tools let it list contacts, create or update a contact, and list email campaigns. Both integrations activate automatically when the respective plugin is detected \u2014 no extra setup required.<\/p><\/dd>\n<dt id=\"does%20this%20work%20with%20buddypress%20or%20the%20events%20calendar%3F\"><h3>Does this work with BuddyPress or The Events Calendar?<\/h3><\/dt>\n<dd><p>Yes. BuddyPress tools cover members, extended profile fields, the activity stream, groups, group members, and friend connections. The Events Calendar tools cover full event CRUD plus venues, organizers, and event categories. Both activate automatically when the respective plugin is detected \u2014 no extra configuration required.<\/p><\/dd>\n<dt id=\"which%20seo%20plugins%20are%20supported%3F\"><h3>Which SEO plugins are supported?<\/h3><\/dt>\n<dd><p>Yoast SEO, Rank Math, All in One SEO, SEOPress, Slim SEO, and The SEO Framework. The plugin detects whichever one is active and reads\/writes its native storage directly \u2014 per-post title, meta description, focus keyword, and noindex status, plus site-wide title separator and homepage title\/description.<\/p><\/dd>\n<dt id=\"my%20ai%20client%20shows%20fewer%20than%20215%2B%20tools%20%E2%80%94%20is%20that%20a%20bug%3F\"><h3>My AI client shows fewer than 215+ tools \u2014 is that a bug?<\/h3><\/dt>\n<dd><p>No, that's expected. 215+ is the plugin's <em>total<\/em> tool count across every supported integration. The list your AI client actually sees is filtered down to only the tools that will work on your specific site \u2014 so anything gated behind a plugin you don't have active (WooCommerce, ACF, Elementor, a supported SEO plugin, BuddyPress, The Events Calendar, and so on) simply isn't advertised. A fresh WordPress install with none of those companion plugins active will see roughly 124 core tools; each supported plugin you activate adds its tools to the list automatically. To see the full 215+, install and activate every supported integration.<\/p><\/dd>\n<dt id=\"can%20i%20add%20my%20own%20custom%20tools%3F\"><h3>Can I add my own custom tools?<\/h3><\/dt>\n<dd><p>Yes. Use <code>bcs_mcp_register_tool()<\/code> or the <code>bcs_mcp_tools<\/code> filter from any plugin or your theme's <code>functions.php<\/code>. See the Other Notes tab for a code example.<\/p><\/dd>\n<dt id=\"can%20ai%20delete%20or%20change%20things%20without%20my%20permission%3F\"><h3>Can AI delete or change things without my permission?<\/h3><\/dt>\n<dd><p>Every tool call is checked against real WordPress capabilities before it runs \u2014 an AI client can never do more than the authorizing user is allowed to do. Destructive actions are logged in the Activity Log, and you can revoke access instantly from Settings \u2192 Reset OAuth State.<\/p><\/dd>\n<dt id=\"can%20ai%20create%20new%20wordpress%20users%20or%20admin%20accounts%3F\"><h3>Can AI create new WordPress users or admin accounts?<\/h3><\/dt>\n<dd><p>No, and there is no setting to turn this on. No MCP tool in this plugin can create a WordPress user under any circumstance \u2014 new accounts must always be created through wp-admin by a human. Role changes are still possible through <code>wp_assign_user_role<\/code>, but only for a token authorized by a user with the <code>promote_users<\/code> capability.<\/p><\/dd>\n<dt id=\"can%20i%20restrict%20which%20ips%20can%20connect%3F\"><h3>Can I restrict which IPs can connect?<\/h3><\/dt>\n<dd><p>Yes. Add an IP allowlist (single IPs or CIDR ranges) in Settings, and the MCP endpoint will reject any request from outside that list.<\/p><\/dd>\n<dt id=\"is%20there%20rate%20limiting%20to%20prevent%20abuse%3F\"><h3>Is there rate limiting to prevent abuse?<\/h3><\/dt>\n<dd><p>Yes. Every request to the <code>\/mcp<\/code> endpoint is limited to 60 requests per minute per IP address, enforced automatically with no configuration needed \u2014 requests over that limit get an HTTP 429 response instead of reaching your database. Dynamic Client Registration (the endpoint AI clients use to register themselves) has its own separate limit of 10 registrations per IP per minute.<\/p><\/dd>\n<dt id=\"can%20i%20use%20this%20for%20wordpress%20ai%20automation%20and%20workflows%3F\"><h3>Can I use this for WordPress AI automation and workflows?<\/h3><\/dt>\n<dd><p>Yes. Because ByteCoreStack - MCP Connector for AI Tools exposes real WordPress actions as MCP tools instead of just answering questions, your AI assistant can chain several steps together in one request \u2014 draft a post, generate a featured image, assign categories, and publish, for example. Each step still runs through the same permission checks and Activity Log as if you'd done it by hand in wp-admin.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20collect%20any%20user%20data%20or%20telemetry%3F\"><h3>Does this plugin collect any user data or telemetry?<\/h3><\/dt>\n<dd><p>No external telemetry of any kind. The Activity Log does record each tool call's parameters and result locally, in your own WordPress database, so you can audit and debug what your AI client has done \u2014 values that look like passwords, tokens, or secrets are redacted before they're written, and large content fields are truncated. None of this data is ever sent anywhere outside your own server, and the plugin includes zero analytics or tracking code.<\/p><\/dd>\n<dt id=\"will%20this%20slow%20down%20my%20wordpress%20site%3F\"><h3>Will this slow down my WordPress site?<\/h3><\/dt>\n<dd><p>No. The MCP server only runs when an AI client actively makes a request to the <code>\/mcp<\/code> endpoint \u2014 there is no background polling, no front-end script, and no impact on normal page load times for your visitors.<\/p><\/dd>\n<dt id=\"does%20this%20work%20on%20wordpress%20multisite%3F\"><h3>Does this work on WordPress multisite?<\/h3><\/dt>\n<dd><p>Yes, per-site. Each site on the network gets its own settings, its own MCP URL, and its own Activity Log. There is no shared or cross-site tool access. The <code>wp_get_multisite_info<\/code> tool lets a connected AI client check network status and list network sites when multisite is enabled.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20uninstall%20the%20plugin%3F\"><h3>What happens if I uninstall the plugin?<\/h3><\/dt>\n<dd><p>A clean uninstall removes every database table the plugin created (logs, OAuth tokens, OAuth clients, authorization codes), every plugin option, and every transient it set. No orphaned data is left behind in your database.<\/p><\/dd>\n<dt id=\"i%20restored%20my%20site%20from%20a%20backup%20and%20my%20ai%20client%20can%27t%20reconnect.%20what%20do%20i%20do%3F\"><h3>I restored my site from a backup and my AI client can't reconnect. What do I do?<\/h3><\/dt>\n<dd><p>Database restores can leave your AI client holding OAuth credentials that no longer match what's stored on the (restored) site. Go to <strong>ByteCoreStack - MCP Connector for AI Tools \u2192 Settings \u2192 Reset OAuth State<\/strong> to clear all stored tokens and client registrations, then remove and re-add the connector in your AI client to trigger a fresh authorization flow.<\/p><\/dd>\n<dt id=\"i%20see%20%22couldn%27t%20register%20with%20sign-in%20service%22%20in%20claude\"><h3>I see \"Couldn't register with sign-in service\" in Claude<\/h3><\/dt>\n<dd><p>This usually means the OAuth rewrite rules haven't been flushed. Log in to wp-admin \u2014 the plugin auto-flushes on the first admin page load after each update. If the error persists, go to <strong>Settings \u2192 Permalinks<\/strong> and click <strong>Save Changes<\/strong>.<\/p><\/dd>\n<dt id=\"cursor%20says%20it%20can%27t%20establish%20a%20session\"><h3>Cursor says it can't establish a session<\/h3><\/dt>\n<dd><p>Ensure your WordPress site is on HTTPS and publicly accessible. Cursor requires the <code>Mcp-Session-Id<\/code> header in the server's <code>initialize<\/code> response \u2014 this plugin sends it correctly. If you're behind a caching plugin or CDN, make sure <code>\/wp-json\/bcs-mcp\/*<\/code> is excluded from caching.<\/p><\/dd>\n<dt id=\"my%20site%20uses%20nginx.%20will%20sse%20work%3F\"><h3>My site uses nginx. Will SSE work?<\/h3><\/dt>\n<dd><p>Yes. The plugin sends <code>X-Accel-Buffering: no<\/code> on SSE responses to prevent nginx from buffering the stream. No additional nginx configuration is required.<\/p><\/dd>\n<dt id=\"my%20site%20is%20on%20http%20%28not%20https%29.%20will%20this%20work%3F\"><h3>My site is on HTTP (not HTTPS). Will this work?<\/h3><\/dt>\n<dd><p>OAuth 2.0 requires HTTPS for security, and most AI clients will refuse to connect to non-HTTPS endpoints. A valid SSL certificate is strongly recommended. For local development with localhost, HTTP is allowed by the OAuth redirect URI validator.<\/p><\/dd>\n<dt id=\"how%20do%20i%20disconnect%20an%20ai%20client%3F\"><h3>How do I disconnect an AI client?<\/h3><\/dt>\n<dd><p>Go to <strong>ByteCoreStack - MCP Connector for AI Tools \u2192 Settings<\/strong> \u2192 Reset OAuth State. This revokes all tokens and clears all registered clients. Any connected AI client will need to re-authorize.<\/p><\/dd>\n<dt id=\"my%20connection%20broke%20after%20a%20plugin%20or%20theme%20update.%20where%20do%20i%20start%20troubleshooting%3F\"><h3>My connection broke after a plugin or theme update. Where do I start troubleshooting?<\/h3><\/dt>\n<dd><p>Update to the latest version of ByteCoreStack - MCP Connector for AI Tools first \u2014 most connection issues are fixed in the next release. If the problem persists: (1) temporarily deactivate other plugins to rule out a conflict, (2) check that your caching plugin or CDN excludes <code>\/wp-json\/bcs-mcp\/*<\/code>, (3) reset OAuth state from Settings and reconnect, (4) check the Activity Log for the specific error status on the failing tool call.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.0<\/h4>\n\n<p>This release adds 56 new WordPress MCP tools (215+ total, up from 150+), six more SEO plugin integrations, two new community\/events integrations, a dedicated connection diagnostics page, and a redesigned admin dashboard \u2014 plus security hardening and bug fixes. <strong>Fully backward compatible:<\/strong> existing OAuth connections, access tokens, Activity Log history, and settings are preserved automatically on update \u2014 no re-authorization, reconfiguration, or action of any kind is required from existing users. Full details below.<\/p>\n\n<p><strong>New: SEO tools now support 6 plugins (was 2)<\/strong>\n* SEO meta tools (per-post title\/description\/focus keyword\/noindex, bulk SEO audit, site-wide title separator and homepage settings) now auto-detect and support Yoast SEO, Rank Math, All in One SEO (AIOSEO), SEOPress, Slim SEO, and The SEO Framework\n* AIOSEO is read and written directly through its own database table (not postmeta), matching how AIOSEO v4+ actually stores data<\/p>\n\n<p><strong>New: Community &amp; Events integrations<\/strong>\n* BuddyPress \u2014 list members, read extended profile (xProfile) fields, read and post to the activity stream, list and create groups, list group members, list friend connections\n* The Events Calendar \u2014 full event CRUD (create, read, update, delete), plus venues, organizers, and event categories<\/p>\n\n<p><strong>New: Forms, LMS &amp; e-commerce integrations<\/strong>\n* Contact Form 7 \u2014 list forms, read form fields and mail settings\n* WPForms \u2014 list forms, read entries (requires WPForms Pro or entry storage enabled)\n* Ninja Forms \u2014 list forms, read submissions\n* MemberPress \u2014 list memberships and members, get a member's subscriptions and transaction history\n* LearnDash \u2014 list courses, get a user's course progress, enroll\/unenroll a user\n* Easy Digital Downloads \u2014 products, orders, single order detail, customers, store stats\n* WooCommerce Subscriptions &amp; Bookings \u2014 list subscriptions, cancel a subscription, list bookings (added to the existing WooCommerce category)<\/p>\n\n<p><strong>New: Page builder &amp; site management integrations<\/strong>\n* Bricks Builder \u2014 read a page's element tree, clone a page with its Bricks content\n* Divi Builder \u2014 read a page's shortcode content, clone a page with its Divi content\n* Redirection \u2014 list, create, and delete URL redirects\n* UpdraftPlus (Backup &amp; Migration) \u2014 list backup sets, trigger a new backup, check job status\n* FluentCRM (Email \/ CRM) \u2014 list contacts, create or update a contact by email, list email campaigns<\/p>\n\n<p><strong>New: Core WordPress tools<\/strong>\n* Cache status detection \u2014 reports which page-caching and object-caching plugins are active\n* Users CSV export\n* Full Site Health diagnostics \u2014 runs the same tests shown under Tools \u2192 Site Health and summarizes critical\/recommended\/passed counts\n* <code>wp_bulk_delete_comments<\/code> \u2014 delete or trash multiple comments by ID in one call\n* <code>wp_duplicate_menu<\/code> \u2014 duplicate a nav menu including all of its items\n* <code>wp_get_multisite_info<\/code> \u2014 check multisite status and list network sites<\/p>\n\n<p><strong>New: Admin dashboard &amp; setup experience<\/strong>\n* Dedicated \"Connection Test\" page (between Settings and Activity Log) \u2014 checks HTTPS, permalinks, and live MCP\/OAuth-discovery endpoint reachability, and reports the specific reason a connection would fail instead of a generic error\n* \"Setup Health\" checklist on the Dashboard \u2014 at-a-glance status for server enabled, HTTPS, pretty permalinks, and whether an AI client is connected, with a \"Fix now \u2192\" shortcut\n* In-admin review prompt (shown only on this plugin's own screens, only after real successful tool calls) with \"Remind me later\" and \"No thanks\" options \u2014 never shown on first activation<\/p>\n\n<p><strong>Improved: Dashboard &amp; Settings UI<\/strong>\n* The \"Enable MCP Server\" toggle is now a full-width, color-coded banner at the top of Settings instead of a small switch buried inside a card\n* Removed the \"Quick Connect\" card from the Dashboard (it duplicated the per-client setup steps already on Settings); the \"WordPress Tools\" browser now spans the full page width\n* Dashboard pairs \"Setup Health\" on the left with the stat cards on the right (3 per row, 2 rows), matched to equal height\n* Setup Health checklist rows show a check\/warning icon and a \"Ready\" \/ \"Needs attention\" status tag, and are noticeably more compact\n* \"Recent Activity\" and \"Most Used Tools\" are now always shown side by side (2\/3 + 1\/3 columns) instead of \"Most Used Tools\" being hidden entirely until there's data \u2014 it now shows an empty state like Recent Activity does\n* Activity Log pagination now truncates to \"1 2 3 \u2026 8 9 10\" style instead of listing every page number when there are many pages\n* Fixed excess vertical spacing between the tool name and its usage bar in \"Most Used Tools\" (Dashboard and Settings)<\/p>\n\n<p><strong>Improved: Connection Test &amp; Activity Log<\/strong>\n* Redesigned the \"Connected AI Clients\" list on Connection Test: branded per-client color and avatar, total calls, calls today, and a session-expiry countdown, plus a \"View activity\" button that jumps straight to the Activity Log pre-filtered to that client\n* Activity Log table no longer scrolls inside its own box \u2014 it now scrolls with the page like the rest of the admin screen\n* Activity Log gained a \"Show \u2304 per page\" control (10 \/ 20 \/ 50 \/ 100, default 20); pagination now sits to the right of it instead of centered alone\n* \"Last tested\" timestamp on Connection Test now displays in the site's configured local timezone (Settings \u2192 General \u2192 Timezone) instead of the server's UTC time\n* Removed the redundant per-client \"connected X ago\" breakdown from the Dashboard's Setup Health card \u2014 the full detail now lives on the Connection Test page\n* Removed the \"No test run yet\" placeholder that could stay visible after a test had actually completed<\/p>\n\n<p><strong>Fixed<\/strong>\n* <code>tools\/list<\/code> now actually filters out addon-gated tools whose required plugin isn't active, instead of advertising all 215+ tools regardless of what's installed \u2014 a connected AI client only ever sees tools that will work on the site\n* Removed the \"REST endpoint reachable\" check from Connection Test \u2014 a self-request through some caching\/security-plugin setups could return HTTP 200 with a body that didn't parse as expected, producing a false failure on connections that were actually working fine. The remaining 4 checks (server enabled, HTTPS, permalinks, OAuth discovery) cover the same ground without the false positive\n* The \"Enable MCP Server\" toggle's label text was never actually rendered bold, and the switch itself blended into the banner background \u2014 both now have proper contrast\n* Activity Log's built-in connection-test entries were being mislabeled after the plugin rename\n* A missing <code>translators:<\/code> comment on the OAuth authorization screen was breaking automatic <code>.pot<\/code> generation\n* <code>wc_create_variation<\/code> \/ <code>wc_update_variation<\/code> \u2014 attribute values passed as <code>{name, option}<\/code> could silently save as an empty string instead of the intended value; the variation's postmeta key was being double-prefixed, and a brand-new attribute or term was never registered on the parent product as usable for variations. Both are now handled automatically\n* <code>wp_get_site_health_tests<\/code> could hang the whole request (\"connector's server isn't responding\") if a network-dependent Site Health test wasn't already excluded, or if a single test threw a fatal error; hardened with a wider skip list for network-calling tests, a 3-second HTTP timeout clamp for the duration of the run, and per-test error isolation so one broken test can't take down the whole diagnostic\n* A tool call that hit an uncaught PHP fatal error (as opposed to a caught <code>Exception<\/code>) was left stuck at <code>status = pending<\/code> in the Activity Log forever instead of being recorded as <code>error<\/code><\/p>\n\n<p><strong>Security<\/strong>\n* <code>wp_export_users_csv<\/code> now neutralizes spreadsheet formula-injection characters (<code>=<\/code>, <code>+<\/code>, <code>-<\/code>, <code>@<\/code>) and escapes embedded quotes in exported fields\n* Dynamic database table names in the WPForms, MemberPress, and Redirection queries now use <code>$wpdb-&gt;prepare()<\/code>'s <code>%i<\/code> identifier placeholder instead of raw string interpolation<\/p>\n\n<p><strong>Changed<\/strong>\n* Plugin renamed to \"ByteCoreStack - MCP Connector for AI Tools\" (previously \"AI Connector \u2013 MCP for Claude, ChatGPT, Gemini &amp; More\")\n* Readme tags updated for search discoverability (<code>mcp, ai, claude, chatgpt, mcp-server<\/code>)\n* All new integrations activate automatically when their corresponding plugin is detected, matching the existing WooCommerce\/ACF\/Elementor\/Gravity Forms behavior \u2014 no configuration required\n* 215+ WordPress MCP tools across 30 categories (215 verified at release)<\/p>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<li>150+ WordPress MCP tools across 20 categories (159 verified at release)<\/li>\n<li>OAuth 2.0 with PKCE (authorization code flow, Dynamic Client Registration, refresh tokens)<\/li>\n<li>Discovery endpoints: <code>\/.well-known\/oauth-protected-resource<\/code> and <code>\/.well-known\/oauth-authorization-server<\/code><\/li>\n<li>Streamable HTTP transport (MCP 2025-11-25) as primary transport<\/li>\n<li>Legacy SSE transport (<code>\/sse<\/code> + <code>\/messages<\/code>) for older client versions \u2014 compatible with all clients, not restricted by User-Agent<\/li>\n<li><code>Mcp-Session-Id<\/code> response header on <code>initialize<\/code> for session tracking (required by Cursor)<\/li>\n<li><code>X-Accel-Buffering: no<\/code> on SSE responses for nginx compatibility<\/li>\n<li>Auth validation on session termination (DELETE \/mcp)<\/li>\n<li>Activity logging with client detection (Claude, ChatGPT, Gemini, Cursor, Windsurf, and others), storing each call's parameters\/result locally for audit purposes with sensitive-looking values redacted automatically<\/li>\n<li>IP allowlist support<\/li>\n<li>Admin dashboard with today's success\/fail stat cards, settings page, and activity log with CSV export<\/li>\n<li>WP Dashboard widget (7-day activity bar chart)<\/li>\n<li>WooCommerce (33 tools), ACF (3 tools), Elementor (6 tools), and Gravity Forms (2 tools) integrations \u2014 activate automatically when those plugins are present<\/li>\n<li>Developer API: <code>bcs_mcp_register_tool()<\/code> helper and <code>bcs_mcp_tools<\/code> filter for custom tools<\/li>\n<li>No tool creates new WordPress users; <code>wp_update_user<\/code> no longer accepts a <code>role<\/code> parameter \u2014 use <code>wp_assign_user_role<\/code> (requires <code>promote_users<\/code>) for role changes<\/li>\n<li>Clean uninstall: removes all plugin tables, options, and transients with no orphaned data<\/li>\n<li>Translation-ready: full <code>.pot<\/code> file included in <code>\/languages<\/code> for translators<\/li>\n<\/ul>","raw_excerpt":"Connect Claude, ChatGPT &amp; Gemini to WordPress via MCP \u2014 AI automation with 215+ tools, OAuth 2.0, WooCommerce &amp; SEO support.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/hr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/326332","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/hr.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/hr.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=326332"}],"author":[{"embeddable":true,"href":"https:\/\/hr.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/bytecorestack"}],"wp:attachment":[{"href":"https:\/\/hr.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=326332"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/hr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=326332"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/hr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=326332"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/hr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=326332"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/hr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=326332"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/hr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=326332"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}