MCP Expose Abilities
Let AI assistants edit your WordPress site via MCP.
Tested up to: 7.0 Stable tag: 3.0.84 License: GPLv2 or later License URI: https://www.gnu.org/licenses/gpl-2.0.html
What It Does
This plugin exposes WordPress functionality through MCP (Model Context Protocol), enabling AI assistants to directly interact with your WordPress site. No more copy-pasting between chat and admin.
Example: "Fix the phone numbers in these 25 articles to be clickable tel: links." - Done in 30 seconds, all 25 articles.
The Real Workflow
In practice, the human should not have to memorize the whole ecosystem.
The normal pattern is:
- point Codex or another MCP-capable agent to this repository
- let the agent read the README and wiki
- let the agent work out the required stack and relevant add-ons
- give the agent a clear task with boundaries
The human's job is mostly to describe the goal. The agent's job is to figure out the mechanics.
Why This Feels Different
Most WordPress AI demos still leave you doing the boring part yourself.
This ecosystem is different because the agent can actually do the work inside WordPress:
- fix repetitive content issues across many pages
- update menus, media, plugins, comments, and options
- work with real builder and plugin ecosystems like Elementor, GeneratePress, Rank Math, and Wordfence
- handle the kind of site maintenance people usually postpone because it is repetitive and dull
That changes the experience from:
Here is what you should do in wp-admin
to:
Tell the agent what needs doing, and let it carry out the work
Before vs After
Before
- ask the AI what to do
- copy the answer into WordPress by hand
- click through wp-admin for the repetitive bits
- lose momentum because the task is boring
- postpone the cleanup, maintenance, or optimization work again
After
- tell the agent what needs doing
- let it inspect the site directly
- let it make the targeted change
- verify the result
- move on to the next useful improvement instead of getting stuck in admin drudgery
That difference is the whole point of this ecosystem.
Who It Is For
This is a good fit for:
- agencies managing many WordPress sites
- companies with repetitive content and operations work
- organizations that want AI to do real maintenance, not just generate text
- technical teams that are tired of copy-paste workflows between chat and wp-admin
It is especially useful when work gets postponed simply because the manual version is boring.
If you want the more specific buyer case, start here:
Documentation
For setup and troubleshooting beyond the quick start, use the wiki:
- Why Teams Use It
- Use Cases
- Who It Is For
- Who Benefits Most
- Alternatives
- Getting Started
- Install Order and Dependencies
- First Working MCP Connection
- Which Add-On Do I Need?
- Troubleshooting
- Examples
If you are using an AI agent, the simplest instruction is often just:
Read https://github.com/bjornfix/mcp-expose-abilities and figure out the stack before making changes.
Start Here
If you are new to the stack, use this order:
- Use WordPress 6.9 or later, which provides the WordPress Abilities API
- Install WordPress MCP Adapter
- Install MCP Expose Abilities (this plugin)
- Confirm you can list and execute core abilities
- Add only the vendor-specific plugins you actually need
If you skip step 4 and start installing add-ons immediately, troubleshooting gets harder than it needs to be.
What You Actually Need
For a minimal working setup, you only need:
- WordPress 6.9+
- PHP 8.0+
- WordPress Abilities API
- WordPress MCP Adapter
- MCP Expose Abilities (this plugin)
Everything else in the ecosystem is optional.
5-Minute Setup
- Confirm WordPress 6.9 or later provides the WordPress Abilities API
- Install and activate WordPress MCP Adapter from https://github.com/WordPress/mcp-adapter/
- Install and activate MCP Expose Abilities from https://downloads.devenia.com/mcp-expose-abilities.zip
- Confirm the MCP adapter route is reachable on your site
- Run a simple read-only ability first, such as listing posts or reading a page
First Success Check
Before adding Elementor, Cloudflare, Gmail, or anything else, confirm the core stack works.
Good first tests:
- list posts
- get a page by ID
- list menus
- list installed plugins
If those work, the stack is wired correctly. If they do not, fix the core stack before adding add-ons.
Modular Architecture
Version 3.0 introduced a modular architecture. The core plugin provides WordPress-native abilities, while vendor-specific features are available as separate add-on plugins:
| Plugin | Abilities | Description |
|---|---|---|
| MCP Expose Abilities (core) | 79 | WordPress core: content, menus, users, media, widgets, plugins, options, comments, taxonomy, system |
| MCP Abilities - Filesystem | 11 | File operations with security hardening |
| MCP Abilities - Elementor | 40 | Elementor page builder integration |
| MCP Abilities - GeneratePress | 26 | GeneratePress theme + GenerateBlocks |
| MCP Abilities - Cloudflare | 4 | Cloudflare cache management |
| MCP Abilities - Google Workspace | 16 | Gmail API via Workspace service account |
| MCP Abilities - Rank Math | 23 | Rank Math SEO metadata access |
| MCP Abilities - Wordfence | 11 | Wordfence security status + blocks |
| MCP Abilities - Brevo | 22 | Brevo contacts, lists, campaigns |
| MCP Abilities - Advanced Ads | 17 | Advanced Ads management |
| MCP Abilities - Toolset | 38 | Toolset post types, custom fields, taxonomies, relationships |
| MCP Abilities - SitePress | 10 | WPML translation mapping, language-switcher recovery, and QA checks |
| MCP Abilities - Formidable | 6 | Formidable Forms settings, usage tracing, styles, and CSS cache controls |
| MCP Abilities - Store Locator | 9 | Store Locator settings, templates, store records, categories, and transient cleanup |
Total ecosystem: 312 abilities
Install only what you need. Running GeneratePress? Install that add-on. Don't use Elementor? Skip it.
Requirements
- WordPress 6.9+
- PHP 8.0+
- WordPress Abilities API
- WordPress MCP Adapter
WordPress Compatibility
- Requires WordPress 6.9 or newer
- Tested up to WordPress 7.0
- Requires PHP 8.0 or newer
- Maintained against the WordPress 6.9 release line together with the supported add-on plugins
Installation
- Confirm WordPress 6.9 or later is active
- Install and activate WordPress MCP Adapter from https://github.com/WordPress/mcp-adapter/
- Download https://downloads.devenia.com/mcp-expose-abilities.zip
- Upload the ZIP through WordPress Admin > Plugins > Add New > Upload Plugin
- Activate the plugin
- Optionally install add-on plugins for vendor-specific features
Which Add-On Should I Install?
Install add-ons only when your site actually uses that product:
- Elementor site: install
mcp-abilities-elementor - GeneratePress / GenerateBlocks site: install
mcp-abilities-generatepress - Cloudflare-managed site: install
mcp-abilities-cloudflare - Gmail / Workspace automation: install
mcp-abilities-workspace - Rank Math site: install
mcp-abilities-rankmath - Wordfence site: install
mcp-abilities-wordfence - Brevo site: install
mcp-abilities-brevo - Toolset site: install
mcp-abilities-toolset - WPML site: install
mcp-abilities-sitepress - Formidable Forms site: install
mcp-abilities-formidable - Store Locator site: install
mcp-abilities-store-locator
Do not install every add-on by default. Most sites only need one or two.
Common Failure Pattern
The most common onboarding mistake is treating this like one plugin instead of a stack.
When something does not work, check in this order:
- Does WordPress 6.9 or later provide the Abilities API?
- Is MCP Adapter active?
- Is MCP Expose Abilities active?
- Does the core plugin work without any add-ons?
- Is the vendor plugin itself installed and active?
- Only then debug the specific add-on
Recent Changes
3.0.84
- Fixed plugin updates started outside wp-admin so WordPress core update hooks have the Screen API they require.
3.0.83
- Restored normal
plugins/install-directoryuse for confirmed installs from the official WordPress.org directory without requiring the global arbitrary-code opt-in. - Kept URL/base64 plugin uploads and plugin deletion behind the server-side code-write gate; plugin updates retain their existing signed-policy or global opt-in requirement.
3.0.82
- Hardened
media/upload-base64so the existing core Media Ability verifies the uploaded bytes, rejects unsupported SVG uploads, checks access to an optional parent post, and cleans up failed attachments.
3.0.81
- Added
users/revoke-current-application-passwordfor revoking only the Application Password that authenticated the current request. - Requires exact
revoke_current_application_passwordconfirmation, accepts no credential selector, and verifies deletion before reporting success.
3.0.80
- Added
users/create-restricted-application-passwordfor creating one WordPress Application Password when the caller can manage users, edit the exact target user, and that user has no generic WordPress Core write authority. - Requires explicit
create_restricted_application_passwordconfirmation and returns the secret only as a libsodium sealed box for the supplied recipient key.
3.0.79
- Routes create, update, patch, and revision restore through one vendor-neutral Content Write Gate.
- Keeps only vendor-neutral Core layout markers in the public plugin and unions Adapter markers.
3.0.78
- Validates proposed published source pages through the canonical registered source-design Interface before
content/create-pageorcontent/update-pagemutates WordPress. - Keeps
content_write_mode: "full_rebuild"as explicit replacement intent without letting it bypass page design validation. - Lets site adapters register additional protected design markers for ordinary guarded writes without adding site policy to this public plugin.
- Runs optional site-owned content-write preflight through a neutral filter before mutation.
- Validates requested page templates before content mutation so a rejected template cannot leave a partial update behind.
3.0.77
- Added explicit
content_write_mode: "full_rebuild"support tocontent/update-postandcontent/update-pagefor intentional complete design replacements. The default guarded mode still blocks accidental design-markup loss.
3.0.75
- Added
comments/update-author-urlfor narrowly updating or clearing one comment author URL with per-comment permission checks and write verification.
3.0.50
- Security:
plugins/updatecan run through MCP only with explicit confirmation and either the global code-write opt-in or approval from a registered update-policy adapter; generic plugin code writes remain disabled by default.
3.0.49
- Security:
options/updatenow blocks theme bootstrap optionstemplateandstylesheet.
3.0.48
- Security: plugin code write abilities are disabled by default unless server-side configuration explicitly enables
MCP_EXPOSE_ENABLE_PLUGIN_CODE_WRITES. - Security: WordPress.org plugin install, plugin update, and plugin delete now require explicit per-ability confirmation when plugin code writes are enabled.
3.0.47
- Security: MCP transport and generic execute-ability entrypoints now default to
manage_optionsvia adapter capability filters. - Security: high-risk
plugins/upload,plugins/upload-base64, andoptions/updatecalls now require explicit per-ability confirmation.
3.0.46
- Improved generic post meta writes to use one post meta write policy interface with a filterable protected-key registry.
- Added a local ability contract harness for verifying protected Elementor meta writes are rejected before side effects.
3.0.45
- Security: generic content/meta abilities now block protected Elementor meta keys and require dedicated
elementor/*abilities for Elementor document writes. - Changed plugin ZIP uploads to use WordPress core
Plugin_Upgraderinstead of direct plugin-directory unzip/copy operations.
3.0.44
- Fixed
plugins/updateso plugins that were active before a WordPress-native update are reactivated if WordPress leaves them inactive after the upgrader run. - Added
active_before,active_after, andreactivatedfields to theplugins/updateresponse.
3.0.43
- Fixed:
plugins/uploadno longer defines a temporaryget_current_screen()stub, avoiding a fatal redeclare when WordPress loads admin screen helpers during REST/MCP plugin installs.
3.0.42
- Added efficient
plugins/listfiltering with asearchparameter and null-safe no-argument input handling.
3.0.41
- Fixed broad content update and patch abilities so they block accidental removal of existing GenerateBlocks/design markup unless explicitly overridden.
3.0.40
- Added
content/update-discussion-statusfor opening or closing comments and pings on posts/pages.
3.0.39
- Added
media/upload-base64for uploading local or generated media files into the WordPress media library through MCP.
3.0.38
- Added
datesupport tocontent/update-postfor updating local post publish dates. - Added post meta support via
content/create-post,content/update-post,meta/update-post-meta, andmeta/delete-post-meta. - Security: post meta writes now check per-key
edit_post_meta/delete_post_metacapabilities before modifying metadata.
3.0.37
- Docs: removed the stray
Claudemention from the README workflow wording.
3.0.36
- Fixed
plugins/search-directoryso WordPress.org search results are populated correctly when the API returns array-shaped plugin rows. - Fixed
plugins/list-updatesso it accepts no-argument execution through the MCP proxy like the older null-safe list abilities.
3.0.35
- Added
plugins/search-directoryto search the official WordPress.org plugin directory from MCP. - Added
plugins/install-directoryto install WordPress.org plugins by slug. - Added
plugins/list-updatesandplugins/updatefor WordPress-native plugin update discovery and execution. - Added
plugins/switchto toggle between installed plugins with rollback if the target activation fails.
3.0.34
- Docs: added a clearer GitHub onboarding path with
Start Here, setup order, first-success checks, and add-on selection guidance. - Docs: added explicit WordPress and PHP compatibility notes.
- Docs: corrected ecosystem add-on and ability counts, including the Formidable add-on and the current Elementor and Rank Math totals.
- Docs: replaced the stale hardcoded Abilities API ZIP URL with the generic latest-release link.
- Docs: fixed the GitHub release badge so it follows the actual latest release.
3.0.33
- Validates local plugin ZIP signatures before unzip so corrupted
plugins/uploadorplugins/upload-base64payloads fail with a direct ZIP-validation error. - Intended to pair with the MCP proxy HTTP transport fix that raises the default JSON body limit for large base64 plugin uploads.
Core Plugin Abilities (79)
Content Management (27)
| Ability | Description |
|---|---|
content/list-posts |
List posts with filtering by status, category, author, search |
content/get-post |
Get single post by ID or slug |
content/get-next-post |
Find the next existing post after an ID, even when IDs have gaps |
content/create-post |
Create new post, including featured_image_id |
content/update-post |
Update an existing post, including guarded or explicit full-rebuild content replacement and featured_image_id |
content/delete-post |
Delete post (trash or permanent) |
content/restore-post |
Restore a post, page, or custom post type from trash |
content/patch-post |
Find/replace in post content |
content/list-pages |
List pages with filtering |
content/get-page |
Get single page by ID or slug |
content/create-page |
Create new page, including featured_image_id |
content/update-page |
Update an existing page, including guarded or explicit full-rebuild content replacement and featured_image_id |
content/update-discussion-status |
Open or close comments and pings for posts/pages |
content/delete-page |
Delete page |
content/patch-page |
Find/replace in page content |
content/list-categories |
List all categories |
content/create-category |
Create new category |
content/update-category |
Update existing category |
content/list-tags |
List all tags |
content/create-tag |
Create new tag |
content/list-media |
List media items |
content/list-users |
List users |
content/search |
Search across posts, pages, media |
content/list-revisions |
List revisions for a post/page |
content/get-revision |
Get specific revision details |
content/restore-revision |
Restore one exact post or page revision |
content/update-tag |
Update an existing tag name, slug, or description |
Menu Management (8)
| Ability | Description |
|---|---|
menus/list |
List all menus and theme locations |
menus/get-items |
Get items from a menu |
menus/create |
Create new menu |
menus/add-item |
Add item to menu |
menus/update-item |
Update menu item |
menus/upsert-item |
Create or update an item by object identity or custom URL |
menus/delete-item |
Delete menu item |
menus/assign-location |
Assign menu to theme location |
User Management (7)
| Ability | Description |
|---|---|
users/list |
List users with roles |
users/get |
Get user by ID, login, or email |
users/create |
Create new user |
users/update |
Update user |
users/delete |
Delete user (can reassign content) |
users/create-restricted-application-password |
Create one sealed Application Password after explicit confirmation for an exact editable user without generic WordPress Core write authority |
users/revoke-current-application-password |
Revoke only the Application Password authenticating the current request after explicit confirmation and deletion readback |
Media Library (5)
| Ability | Description |
|---|---|
media/upload |
Upload media from URL |
media/upload-base64 |
Upload media from base64-encoded bytes |
media/get |
Get media item details and sizes |
media/update |
Update title, alt, caption |
media/delete |
Delete media item |
Post Meta (3)
| Ability | Description |
|---|---|
meta/get-post-meta |
Read one exact post meta key |
meta/update-post-meta |
Update one permitted post meta key |
meta/delete-post-meta |
Delete one permitted post meta key |
Widget Management (3)
| Ability | Description |
|---|---|
widgets/list-sidebars |
List all widget areas |
widgets/get-sidebar |
Get widgets in a sidebar |
widgets/list-available |
List available widget types |
Plugin Management (11)
| Ability | Description |
|---|---|
plugins/upload |
Upload plugin from URL |
plugins/upload-base64 |
Upload plugin from local file (base64 or zip path) |
plugins/search-directory |
Search the official WordPress.org plugin directory |
plugins/install-directory |
Install plugin from the official WordPress.org plugin directory by slug |
plugins/list |
List installed plugins |
plugins/list-updates |
List available plugin updates |
plugins/update |
Update an installed plugin |
plugins/activate |
Activate installed plugin |
plugins/deactivate |
Deactivate active plugin |
plugins/switch |
Activate one plugin and deactivate one or more others |
plugins/delete |
Delete inactive plugin |
Comments (7)
| Ability | Description |
|---|---|
comments/list |
List comments with filtering |
comments/get |
Get single comment details |
comments/update-author-url |
Update or clear one comment author URL |
comments/create |
Create top-level comment |
comments/reply |
Reply to existing comment |
comments/update-status |
Update comment status (approve, spam, trash) |
comments/delete |
Delete comment |
Options (3)
| Ability | Description |
|---|---|
options/get |
Get option value |
options/update |
Update option (protected options blocked) |
options/list |
List all options |
System (4)
| Ability | Description |
|---|---|
system/get-transient |
Get transient value |
system/ability-timings |
Read recent slow or failed ability timings |
system/debug-log |
Read debug.log file |
system/toggle-debug |
Toggle WP_DEBUG, WP_DEBUG_LOG, WP_DEBUG_DISPLAY |
Taxonomy Utilities (1)
| Ability | Description |
|---|---|
taxonomy/associate-with-post-type |
Associate a taxonomy with a post type and persist the mapping |
Add-on Plugin Abilities
Filesystem (mcp-abilities-filesystem) - 11 abilities
| Ability | Description |
|---|---|
filesystem/get-changelog |
Get plugin/theme changelog |
filesystem/read-file |
Read file contents (security hardened) |
filesystem/write-file |
Write file (PHP code blocked) |
filesystem/append-file |
Append to file |
filesystem/list-directory |
List directory contents |
filesystem/delete-file |
Delete file (creates backup) |
filesystem/delete-directory |
Delete directory (optional recursive) |
filesystem/file-info |
Get file metadata |
filesystem/create-directory |
Create directory |
filesystem/copy-file |
Copy file |
filesystem/move-file |
Move/rename file |
Elementor (mcp-abilities-elementor) - 40 abilities
See the add-on readme for the full list. Common abilities:
| Ability | Description |
|---|---|
elementor/get-data |
Get Elementor JSON for a page |
elementor/update-data |
Replace Elementor JSON |
elementor/patch-data |
Find/replace in Elementor JSON |
elementor/update-element |
Update specific element by ID |
elementor/list-templates |
List saved templates |
elementor/clear-cache |
Clear CSS cache |
GeneratePress (mcp-abilities-generatepress) - 26 abilities
See the add-on readme for the full list. Common abilities:
| Ability | Description |
|---|---|
generatepress/get-settings |
Get theme settings |
generatepress/update-settings |
Update theme settings |
generatepress/get-typography |
Get typography rules and font manager |
generatepress/list-elements |
List GeneratePress Elements |
generatepress/list-modules |
List module statuses |
generateblocks/get-global-styles |
Get global styles |
generateblocks/update-global-styles |
Update global styles |
generateblocks/clear-cache |
Clear CSS cache |
Cloudflare (mcp-abilities-cloudflare) - 4 abilities
| Ability | Description |
|---|---|
cloudflare/clear-cache |
Clear Cloudflare cache (entire site or specific URLs) |
cloudflare/get-zone |
Get resolved Cloudflare zone context |
cloudflare/get-development-mode |
Read development mode status |
cloudflare/set-development-mode |
Enable/disable development mode |
Google Workspace (mcp-abilities-workspace) - 16 abilities
| Ability | Description |
|---|---|
gmail/configure |
Set up Gmail API service account credentials |
gmail/status |
Check API connection status and configuration |
gmail/list-labels |
List labels |
gmail/get-label |
Get label by ID |
gmail/create-label |
Create label |
gmail/update-label |
Update label |
gmail/delete-label |
Delete label |
gmail/list |
List inbox messages with filtering |
gmail/list-threads |
List threads |
gmail/get |
Get full email content by ID |
gmail/get-thread |
Get thread details |
gmail/get-attachment |
Fetch attachment as base64 |
gmail/send |
Send email with HTML, attachments, CC, BCC |
gmail/modify |
Modify labels (archive, mark read/unread, etc.) |
gmail/reply |
Reply to an existing email thread |
email/send |
Send email via WordPress wp_mail (non-Gmail fallback) |
Usage with MCP Clients
1. Create Application Password
WordPress Admin → Users → Your Profile → Application Passwords
2. Add MCP Server
Configure your MCP client to connect to:
https://yoursite.com/wp-json/mcp/mcp-adapter-default-server
Use HTTP transport with a Basic Auth header generated from your WordPress username and application password.
3. Start Using
Your MCP client can now edit your WordPress site through conversation.
Examples
Create a new page
{
"ability_name": "content/create-page",
"parameters": {
"title": "About Us",
"content": "<!-- wp:paragraph --><p>Hello world!</p><!-- /wp:paragraph -->",
"status": "publish"
}
}
Add menu item
{
"ability_name": "menus/add-item",
"parameters": {
"menu_id": 5,
"title": "Contact",
"url": "/contact/"
}
}
Upload media from URL
{
"ability_name": "media/upload",
"parameters": {
"url": "https://example.com/image.jpg",
"title": "Hero Image",
"alt_text": "Beautiful sunset"
}
}
Batch find/replace
{
"ability_name": "content/patch-post",
"parameters": {
"id": 123,
"find": "+44 203 3181 832",
"replace": "<a href=\"tel:+442033181832\">+44 203 3181 832</a>"
}
}
Security
- Authentication required - Uses WordPress application passwords
- Permission checks - Every ability verifies user capabilities
- Your server - AI connects to your site, you control access
- Protected options - Critical settings blocked from modification
- Filesystem hardening - PHP code detection, path traversal protection (in add-on)
Architecture
Three-plugin stack plus optional add-ons:
- Abilities API - Framework for registering abilities (WordPress core team)
- MCP Adapter - MCP protocol layer (WordPress core team)
- MCP Expose Abilities (this plugin) - Core WordPress abilities
- Add-on plugins (optional) - Vendor-specific abilities
Changelog
3.0.84
- Fixed plugin updates started outside wp-admin so WordPress core update hooks have the Screen API they require.
3.0.83
- Restored confirmed plugin installation by slug from the official WordPress.org directory without enabling arbitrary plugin uploads.
- URL/base64 plugin uploads and plugin deletion remain disabled unless the site owner enables them in server configuration.
3.0.82
- Hardened
media/upload-base64so the existing core Media Ability verifies the uploaded bytes, rejects unsupported SVG uploads, checks access to an optional parent post, and cleans up failed attachments.
3.0.81
- Added
users/revoke-current-application-passwordwith Core authentication-hook binding, no caller-selected credential identity, explicit confirmation, and deletion readback before success.
3.0.80
- Added
users/create-restricted-application-passwordwithedit_usersplus exact-targetedit_userauthorization, denial for generic-write targets, explicit confirmation, and a sealed credential response containing WordPress' UUID and stored verifier.
3.0.79
- Routed create, update, patch, and revision restore through one vendor-neutral Content Write Gate.
- Kept only vendor-neutral Core layout markers in the public plugin and unioned Adapter markers.
3.0.78
- Added published source-page design preflight to
content/create-pageandcontent/update-pagethrough the canonical registered validation Interface. - Kept deliberate full rebuilds available while rejecting invalid replacement trees before mutation.
- Added neutral site adapters for guarded design markers and content-write preflight; the public plugin contains no site-specific design, metadata, translation, or workflow policy.
- Moved manifest-gated plugin-update decisions behind a neutral policy filter.
- Validates a requested page template before changing page content, so an invalid template cannot leave a partial update behind.
3.0.77
- Added
content_write_mode: "full_rebuild"tocontent/update-postandcontent/update-pageso callers can intentionally replace a complete design while ordinary guarded writes still block accidental design-markup loss.
3.0.76
- Fixed
content/patch-postandcontent/patch-pageso stale invalid assigned-template metadata is cleared immediately before content writes, preventing successful patches from returning anInvalid page templateerror.
3.0.75
- Added
comments/update-author-urlfor narrowly updating or clearing one comment author URL with per-comment permission checks and write verification.
3.0.73
- Fixed
content/patch-postto pass correctly slashed Gutenberg content into WordPress, so approved design-neutral source patches keep the same content hash through the downstream publish gate.
3.0.72
- Deepened design-neutral source patch approval so MCP preflight and the downstream source publish gate filter share one approval path.
3.0.71
- Fixed design-neutral
content/patch-postwrites so registered site policy can carry hash-bound approval through downstream save guards.
3.0.70
- Added
content/patch-postsupport for an explicitly justified design-neutral patch on source content when the registered site policy confirms it does not worsen source-design validation.
3.0.69
- Fixed
content/update-postandcontent/update-pageso featured-image-only or taxonomy-only updates do not callwp_update_post()and trigger unrelated publish/design hooks.
3.0.68
- Added dry-run support for MCP post create, update, and patch writes.
- Fixed registered source-content policy preflight so status-only publishes of invalid drafts are blocked.
3.0.67
- Added optional site-policy preflight for MCP post create/update/patch writes.
3.0.66
- Added
content/update-tagfor correcting tag names, slugs, and descriptions through MCP without direct REST or database access.
3.0.65
- Fixed
content/update-postandcontent/update-pageso generic post/page updates protect translated sibling content and critical Elementor/featured image meta from WPML/Polylang-style sync hooks. - Added
translation_guarddetails to content update responses so callers can verify which translated siblings were protected and restored.
3.0.64
- Fixed
meta/update-post-metaandmeta/delete-post-metaso updates to_yoast_wpseo_*fields trigger a post refresh for SEO indexable rebuilds.
3.0.63
- Added
meta/get-post-metafor narrow, read-only inspection of explicit post meta keys with per-post capability checks.
3.0.62
- Fixed
content/restore-postandcontent/update-pageso stale invalid assigned page-template metadata is cleared before WordPress status/content writes, allowing legacy trashed pages from old themes to be restored safely.
3.0.61
- Fixed
content/list-pagesso the documentedsearchparameter is accepted and passed through to the WordPress page query.
3.0.60
- Added:
content/list-postsnow supportsstatus:trashfor explicit trash inspection. - Added:
content/restore-postrestores posts, pages, and custom post types from trash with per-post edit permission checks.
3.0.59
- Changed: plugin-code-write guards now pass structured ability name and input to a dedicated filter, allowing trusted upload gates without request-body parsing or stack inspection.
- Fixed: plugin uploads with
overwrite:truenow recover from empty stale target directories left by failed installs.
3.0.58
- Added:
content/restore-revisionability for restoring posts, pages, and custom post types through WordPress revisions without transporting block content through JSON.
3.0.57
- Added: MCP HTTP shutdown timing fallback records long-running or fatal MCP REST requests even when adapter-level observability does not fire.
3.0.56
- Added: MCP Adapter transport requests are now recorded in
system/ability-timingswhen they fail or exceed the timing threshold, including method/tool context for discovery andtools/listdiagnostics.
3.0.55
- Fixed:
content/patch-pageandcontent/patch-postnow use a short per-post write lock so concurrent patch calls against the same item cannot overwrite each other with stale content.
3.0.54
- Added:
system/ability-timingsexposes a bounded read-only log of slow or failed ability calls. - Improved: ability callbacks now record timing data only when calls fail or exceed the default 1000 ms threshold.
3.0.53
- Added:
menus/upsert-itemcreates or updates menu items idempotently by page/post/category identity or custom URL. - Improved: menu add/update now use one normalized nav menu item module with write readback, object/type preservation, title persistence, and contract-test coverage.
3.0.52
- Fixed: menu item title updates now also persist the underlying nav menu item post title, so frontend labels do not fall back to stale object labels.
3.0.51
- Fixed:
menus/add-itemnow validates page/post/category object IDs before creating non-custom menu items. - Fixed:
menus/update-itemnow preserves existing menu item fields when only changing title, URL, parent, position, target, or classes.
3.0.50
- Security:
plugins/updatecan run through MCP only with explicit confirmation and either the global code-write opt-in or a registered update-policy approval; generic plugin code writes remain disabled by default.
3.0.49
- Security:
options/updatenow blocks theme bootstrap optionstemplateandstylesheet.
3.0.48
- Security: plugin code write abilities are disabled by default unless server-side configuration explicitly enables
MCP_EXPOSE_ENABLE_PLUGIN_CODE_WRITES. - Security: WordPress.org plugin install, plugin update, and plugin delete now require explicit per-ability confirmation when plugin code writes are enabled.
3.0.47
- Security: MCP transport and generic execute-ability entrypoints now default to
manage_optionsvia adapter capability filters. - Security: high-risk
plugins/upload,plugins/upload-base64, andoptions/updatecalls now require explicit per-ability confirmation.
3.0.46
- Improved: generic post meta writes now use a single post meta write policy interface with a filterable protected-key registry.
- Added: local ability contract harness for verifying protected Elementor meta writes are rejected before side effects.
3.0.45
- Security: generic content/meta abilities now block protected Elementor meta keys and require dedicated
elementor/*abilities for Elementor document writes. - Changed: plugin ZIP uploads now use WordPress core
Plugin_Upgraderinstead of direct plugin-directory unzip/copy operations.
3.0.44
- Fixed:
plugins/updatenow preserves active plugin state across WordPress-native plugin updates and reports the before/after activation state.
3.0.42
- Added:
plugins/listnow supports asearchparameter for filtering installed plugins by file, slug, name, author, or description. - Fixed:
plugins/listnow accepts no-argument execution through the MCP proxy like the other null-safe list abilities.
3.0.41
- Fixed: broad content update and patch abilities now block accidental removal of existing GenerateBlocks/design markup unless explicitly overridden.
3.0.40
- Added:
content/update-discussion-statusfor opening or closing comments and pings on posts/pages.
3.0.39
- Added:
media/upload-base64for uploading local/generated media files into the WordPress media library through MCP
3.0.38
- Added:
content/update-postnow supports updating the local post date with thedateparameter - Added: post meta support via
content/create-post,content/update-post,meta/update-post-meta, andmeta/delete-post-meta - Security: post meta writes now check per-key
edit_post_meta/delete_post_metacapabilities before modifying metadata
3.0.37
- Docs: removed the stray
Claudemention from the GitHub README workflow wording
3.0.36
- Fixed:
plugins/search-directorynow handles WordPress.org directory rows correctly when plugin data is returned as arrays instead of objects - Fixed:
plugins/list-updatesnow accepts no-argument execution through the MCP proxy like the other null-safe list abilities
3.0.35
- Added:
plugins/search-directoryto search the official WordPress.org plugin directory from MCP - Added:
plugins/install-directoryto install plugins from the official WordPress.org directory by slug - Added:
plugins/list-updatesandplugins/update
No comments yet
Be the first to share your take.