Beschreibung
miniOrange Secure MCP Server is a complete WordPress MCP server plugin that turns your WordPress site into a fully working Model Context Protocol (MCP) server. Once installed, you can connect Claude to WordPress, connect ChatGPT to WordPress, or link any MCP-compatible AI in just 2 minutes.
Ask AI to write blog posts, update WooCommerce products, manage Yoast SEO, moderate comments, handle contact form submissions, and much more, all through simple chat.
Unlike other WordPress MCP server plugins that give AI full admin access, we put you in complete control. Role-based AI permissions, Turn each tool on or off, self-hosted OAuth 2.1 login, and full activity logs are all included, with no restrictions.
Core WordPress MCP Server Features
The most complete WordPress MCP server on the WordPress marketplace:
- 300+ MCP Tools Included: Full coverage across content, commerce, users, forms, and SEO.
- Secure MCP Server with OAuth 2.1: Self-hosted authorization server where AI never sees your WordPress password.
- Role-Based AI Access (NHI Registry): Assign different MCP tools to each role so every AI client gets its own powers.
- Tool Controls: Turn any MCP tool on or off with one click.
- Works with Every AI: Connect Claude, ChatGPT, Cursor, Gemini, Windsurf, and any MCP-compatible AI.
- One-Click OAuth Connect: Paste your MCP server URL and approve access, with no API keys to copy.
- Full Activity Log: Every AI action recorded and reviewable.
- WordPress Abilities API Native: Built on WordPress 6.9’s official standard for a future-proof design.
- Unlimited Usage: No caps on MCP calls, connected AI clients, or users.
- Role-Based Access: Give each user or AI only the access their role allows.
- Agent Reputation Scoring: Rates each AI on past behavior to spot trusted or risky agents.
- Individual Credentials for Users: Every user connects with their own login, not a shared one.
- Dynamic OAuth & API Key Support: Connect using OAuth or an API key, whichever you prefer.
- Audit Log: See every AI action, including who did it and when.
- Policy Forming: Build your own rules for what AI is allowed to do.
- Abilities Restriction: Turn specific AI abilities on or off to limit what AI can touch.
- Human-in-the-Loop Approvals: Send risky actions to a real person to approve first.
- Data Rules + DLP: Hide emails, phone numbers, and secrets so AI never sees them.
- Prompt-Injection Detection: Catch hidden or harmful instructions before they reach the AI.
- Behavioral Anomaly Detection: Watches AI activity and flags anything unusual.
- Rate Limits & Quotas: Cap how many requests each AI can make to stop overuse.
- Multisite Policy: Apply the same AI rules across all your WordPress sites.
- Pre-Built Policy Templates: Ready-made rule sets so you can set up safe AI access fast.
Quick Links
Official Website | ChatGpt Setup Guide | Claude Setup Guide
What Is a WordPress MCP Server?
A WordPress MCP server is a plugin that lets AI tools like Claude by Anthropic and ChatGPT by OpenAI connect to your WordPress site through the Model Context Protocol (MCP), an open standard AI clients use to talk to external apps.
Think of MCP as USB-C for AI. One protocol. Every AI client. Every app. Install this WordPress MCP plugin, and your site instantly becomes an AI-ready backend at:
https://YOUR-SITE/wp-json/mosmcp/v1/mcp
Any AI that speaks MCP can now connect and manage your WordPress site through chat.
WordPress Core Content Tools: 92 MCP Abilities
Full AI control over your WordPress content: posts, pages, media, categories, tags, and revisions.
- Post Management (25 tools): Find, create, update, publish, schedule, categorize, tag, trash, restore, or delete posts for full editorial automation.
- Page Management (20 tools): Create drafts under parent pages, update content, publish, schedule, make private, manage review, trash, restore, or delete pages.
- Media Library Management (17 tools): List or filter files by type, get counts, find by title, update titles, alt text, captions, and descriptions, or delete files.
- Category Management (11 tools): List, create, rename, and update categories or slugs, find empty ones, and delete safely with reassignment to default.
- Tag Management (10 tools): List, create, rename, and update tags, find unused tags for cleanup, and delete safely without breaking posts.
- Revisions & History (9 tools): List, count, and retrieve revisions or autosaves, and restore any post to a specific revision or delete one.
WooCommerce MCP Integration: 45 AI Tools
The most complete WooCommerce MCP server available. Let AI run your entire online store.
- Product Management (16 tools): Create and update simple, variable, grouped, or external products, manage stock, SKUs, attributes, and variations, and bulk update.
- Order Management (11 tools): List, create, and update orders, change status, edit billing and shipping, add notes, and create full or partial refunds.
- Customer Management (7 tools): List, create, update, and delete customers, view purchase history, and segment by spend, order count, or activity.
- WooCommerce Reports (6 tools): Sales reports by date range, top-selling products, order and inventory reports, customer acquisition, and coupon usage.
Yoast SEO MCP Integration: 8 AI Tools
The only WordPress MCP server with dedicated Yoast SEO support.
- Read Yoast SEO Data (3 tools): Get focus keyword, SEO analysis, and the full meta fields bundle in one call.
- Update Yoast SEO Data (4 tools): Update meta description, focus keyword, Open Graph tags, and robots meta.
- Sitemap Management (1 tool): Add or remove specific posts and pages from the Yoast XML sitemap.
User Management, Roles & Comments: 60 MCP Tools
The most complete user and moderation toolkit of any WordPress MCP plugin.
- User Administration (22 tools): List, get, search, count, create, and update users, and manage custom user metadata.
- User Deletion & Validation (5 tools): Delete with content reassignment, check username and email availability, and get or update user locale.
- Native Credentials (3 tools): Reset passwords, invalidate sessions, and validate password reset tokens.
- Content Association (2 tools): List posts and comments authored by a specific user.
- Roles & Permissions (8 tools): List roles and capabilities, get editable roles, assign or remove roles, and view MCP policy assignments.
- Comment Moderation, Read (8 tools): List pending, approved, spam, or trashed comments, search, and get counts by status.
- Comment Moderation, Status Changes (6 tools): Approve, unapprove, spam, restore, trash, or permanently delete comments.
- Comment Content & Metadata (6 tools): Reply as admin, get and update metadata, and get counts by post, status, or user.
Contact Form 7, WPForms & Gravity Forms: 40 MCP Tools
The only WordPress MCP server with support for the top 3 form plugins.
- Contact Form 7 (12 tools): List forms, fields, and mail settings, list and export submissions via Flamingo, mark read/unread, trash, and delete for GDPR.
- WPForms (14 tools): List forms, fields, settings, and notifications, list, count, and export entries, mark read/unread, trash, restore, and delete.
- Gravity Forms (14 tools): List all or active forms, get fields and settings, list, count, and export entries, mark read/unread, trash, restore, and delete.
WordPress Site Administration: 35 MCP Tools
- Site Settings, Read (10 tools): Get title, tagline, URL, timezone, language, permalinks, posts-per-page, homepage, privacy policy page, and search visibility.
- Site Settings, Write (7 tools): Update title, tagline, timezone, and posts-per-page, and set homepage, posts page, and privacy policy page.
- Plugin Management (9 tools): List, activate, deactivate, delete, and update plugins with confirmation, and get details, version, and author.
- Theme Management (3 tools): List installed themes, get the active theme, and get theme details by slug.
- Updates & Site Health (6 tools): Check core, plugin, and theme updates, and get WordPress version, PHP/MySQL info, and Site Health status.
Security & Governance: Why This Is the Safest WordPress MCP Server
Letting AI touch your WordPress site is a big trust decision, so our secure MCP server plugin is built with 5 protection layers:
- Self-Hosted OAuth 2.1 Authorization Server: Your site is its own OAuth server, so AI never sees your password and only gets a scoped access token.
- NHI Registry, Role-Based AI Permissions: Each AI is a first-class identity, and two users connecting the same AI get different permissions based on their role.
- Per-Tool On/Off Control: Disable any of the 300+ MCP tools with one click, globally, regardless of role or AI.
- Real WordPress User Enforcement: Every MCP request runs as a genuine WordPress user account, so all core capability checks apply.
- Full Audit Trail: Every MCP tool call, OAuth grant, and ability change is logged and searchable.
Plus: PKCE (S256) anti-hijack protection, RFC 7591 Dynamic Client Registration for one-click AI setup, Streamable HTTP transport and JSON-RPC 2.0 for reliable connections, Bearer token support for automation, and a clean uninstall.
Compatible AI Clients
This WordPress MCP server works with every major MCP-compatible AI:
- Claude by Anthropic (Claude.ai, Claude Desktop, Claude Code): connect in one click via OAuth.
- ChatGPT by OpenAI: connect as a custom MCP server.
- Cursor: AI code editor with MCP support.
- Windsurf: AI-powered IDE.
- Gemini AI by Google (Gemini CLI, Google Antigravity).
- n8n: automation platform with MCP nodes.
- **Any MCP-compatible client
Example Chat Prompts
Once you connect Claude or ChatGPT to WordPress with this MCP plugin, just chat:
- „Write a 700-word blog post about summer travel tips and save it as a draft.“
- „Update my About page to make the intro shorter and friendlier.“
- „Increase prices on all products in ‚Winter Collection‘ by 15%.“
- „Which products sold the most this month?“
- „Update the Yoast meta description on my homepage, keep it under 155 characters.“
- „Approve every pending comment that isn’t spam.“
- „Export all Contact Form 7 submissions from the last 30 days as CSV.“
- „Check for plugin updates and show me what’s available.“
Who Should Use This WordPress MCP Server?
- Bloggers using AI to write and publish faster
- WooCommerce store owners automating products, orders, and reports
- SEO agencies delegating Yoast optimization to AI
- Content teams scaling production with AI assistance
- Developers building AI agent workflows on WordPress
- Digital agencies managing multiple client WordPress sites
- Enterprise sites needing secure, role-based AI governance
- Small businesses running lean with AI automation
Best WordPress MCP Server Comparison
miniOrange Secure MCP vs. Other WordPress MCP Servers
- 300+ MCP tools included — miniOrange: Yes | Others: Fewer
- Role-based AI permissions — miniOrange: Yes (NHI Registry) | Others: No
- Per-tool on/off toggle — miniOrange: Yes | Others: Rare
- Self-hosted OAuth 2.1 — miniOrange: Full support | Others: Partial
- WordPress Abilities API — miniOrange: Native | Others: Some
- WooCommerce MCP (45 tools) — miniOrange: Yes | Others: Limited
- Yoast SEO MCP (8 tools) — miniOrange: Yes | Others: Limited
- Contact Form 7, WPForms, Gravity Forms — miniOrange: All 3 (40 tools) | Others: Rare
- Node.js or external service needed — miniOrange: Never | Others: Sometimes
- Full audit log — miniOrange: Yes | Others: Sometimes
- Unlimited usage, no caps — miniOrange: Yes | Others: Some restrict
Installation
How to Install the WordPress MCP Server (2 Minutes)
- Log in to your WordPress admin dashboard.
- Go to Plugins → Add New.
- Search „Secure MCP Server“
- Click Install Now, then Activate.
- Done — the plugin is now active.
How to Connect Claude to WordPress
- Open Tools Secure MCP Server.
- Go to the „Connect to AI“ tab.
- Copy your MCP server URL:
https://YOUR-SITE/wp-json/mosmcp/v1/mcp - Open Claude Desktop > Settings > Connector> Add custom connector.
- Paste the URL.
- Sign in to WordPress.
- Approve MCP tool access.
- Start chatting with your site through Claude.
How to Connect ChatGPT to WordPress
- Open Tools Secure MCP Server.
- Go to the „Connect to AI“ tab.
- Copy your MCP server URL:
https://YOUR-SITE/wp-json/mosmcp/v1/mcp - Open Claude Desktop > Settings > Plugins>Browse Plugins> Add New Plugin.
- Paste the URL.
- Sign in to WordPress.
- Approve MCP tool access.
- Start chatting with your site through Chagpt.
Requirements
- WordPress 6.9 or newer (Abilities API required)
- PHP 7.4 or higher (PHP 8.0+ recommended)
- HTTPS enabled (for OAuth login)
FAQ
-
What is the NHI Registry?
-
The NHI (Non-Human Identity) Registry is where you create and manage named, role-based ability policies for AI clients. Each NHI maps WordPress roles to the abilities those roles may invoke. When an AI client makes an MCP request, the effective set of allowed abilities is the union — across every enabled NHI — of the abilities granted to the connecting user’s role(s). So two users connecting the same client to the same site can see different tools, based on their roles. You can create as many NHIs as you need and toggle them on or off independently.
-
Can I disable an NHI without deleting it?
-
Yes. Every NHI has an enable/disable toggle in the NHI Registry screen. A disabled NHI has no effect on MCP requests but its name and ability list are preserved, so you can re-enable it at any time without reconfiguring it.
-
Does this WordPress MCP server work with WooCommerce?
-
Yes — full WooCommerce MCP support with 45 tools covering products, variations, orders, customers, coupons, and reports. Perfect for AI-powered store management.
-
Does it work with Yoast SEO?
-
Yes. 8 dedicated Yoast SEO MCP tools for meta descriptions, focus keywords, Open Graph tags, robots meta, and sitemap inclusion. Deepest Yoast integration of any WordPress MCP server.
-
Does it work with Contact Form 7, WPForms, and Gravity Forms?
-
Yes — all three form plugins supported with 40 MCP tools total. Read entries, export CSV, moderate submissions, delete for GDPR compliance.
-
Is it safe to connect AI to my WordPress site?
-
With this MCP plugin, absolutely. AI never sees your WordPress password (OAuth 2.1 with PKCE). Every action is capability-checked at the WordPress core level. Role-based permissions limit what each AI can do. All actions are logged. You can revoke access anytime.
-
Can I disable specific MCP tools?
-
Yes. Every MCP tool has a global on/off toggle. Turn off dangerous actions like „delete permanently“ while keeping safe ones enabled. One-click safety.
-
How do I revoke AI access?
-
Open the NHI Registry and click Revoke. The AI immediately loses access. You can also disable specific NHIs (preserving their config) or turn off individual tools instantly.
-
Can multiple AI connect at once?
-
Yes. Connect Claude, ChatGPT, Cursor, and Gemini simultaneously, each with different permissions. Track their activity separately in the audit log.
-
Why does the „Source“ column show a namespace instead of a plugin name?
-
The Abilities API does not record which plugin registered a given ability. The namespace prefix (the part before the slash in the ability name) is the most reliable indicator of where an ability comes from.
Rezensionen
Zu diesem Plugin liegen noch keine Rezensionen vor.
Mitwirkende und Entwickler
„Secure MCP Connector for Claude, ChatGPT, Gemini and other AI providers“ ist Open-Source-Software. Folgende Menschen haben an diesem Plugin mitgewirkt:
MitwirkendeInteressiert an der Entwicklung?
Durchstöbere den Code, sieh dir das SVN-Repository an oder abonniere das Entwicklungsprotokoll per RSS.
Änderungsprotokoll
1.4.0
- New — bundled abilities library: 260+ ready-to-use, security-reviewed WordPress abilities exposed as MCP tools out of the box. Core content (posts, pages, categories, tags, media, revisions), users & roles, and comments are always available; ability sets for WooCommerce, Advanced Custom Fields, Yoast SEO, Contact Form 7 (with Flamingo), WPForms, and Gravity Forms activate automatically when those plugins are present.
- Every bundled ability is capability-gated, carries explicit MCP tool annotations (read-only / destructive / idempotent / open-world), declares full input/output JSON schemas, and is reachable only through the governed MCP endpoint — never the public REST API.
- Security hardening in the bundled abilities: reserved user-meta keys (capabilities, role level, session tokens) can never be read or written through an ability; role grants are limited to roles whose capabilities the caller already holds; and CSV entry exports are neutralized against spreadsheet formula injection.
- Fixed the role & ability editor incorrectly flagging object-level abilities (those gated by per-object capabilities such as editing or deleting a specific post or page) as capability conflicts for every role, including Administrator. These capabilities are resolved per request against the target object, so they are no longer shown as conflicts; the runtime permission check is unchanged and was always correct.
- Added a „Test Connection“ check that confirms an AI client will actually be able to reach and sign in to your site, run from both your server and an outside vantage so it catches firewall, CDN, and reverse-proxy issues a same-server check would miss. Available on the Connect to AI page and beside Register Agent on the AI Agents screen.
- Added a Troubleshooting guide, always available from the toolbar, that explains the common reasons an AI client can’t connect and gives copy-paste Apache/Nginx fixes for each. When a connection test finds an issue, the most likely cause is highlighted automatically.
- Reliability on CDN/cached hosts: the OAuth and MCP endpoints (discovery, registration, the MCP transport, and the authentication challenge) now send „Cache-Control: no-store“, so an edge cache or CDN — such as Pantheon’s Varnish, Cloudflare, WP Engine, or Kinsta — can no longer cache and misdeliver these per-request responses, which could otherwise intermittently break AI-client connections.
1.3.1
- Minor fixes and reliability improvements.
1.3.0
- Execution activity log: a full audit trail of every tool call, filterable by agent, status, or time range, with per-event detail including latency and error context.
- Dashboard redesign: four focused metrics — Active Agents, Total Executions, Success Rate, and Average Latency — for an at-a-glance view of MCP server health.
- Activity timeline on the agent overview: the last 5 executions appear inline on each NHI’s overview tab.
- Denied and unknown-tool calls are now correctly attributed to the responsible NHI, so the audit log is never missing an agent name.
1.2.3
- Clearer role & ability editor: a single Select all / Clear all control (instead of separate All and None buttons), role names shown in each NHI’s summary, and a smoother role & ability layout.
- Refined the admin/member view switcher to a clearer segmented control.
- Fixed the support form’s country picker so it no longer shifts the page or scrolls unexpectedly when opened.
- General UI polish across the NHI Registry and connection screens.
1.2.2
- NHI Registry is now role-based: grant abilities to each WordPress role, with live capability-conflict detection. A request receives the abilities its user’s role(s) are granted across all enabled NHIs.
- Added a „My AI Access“ member view so any logged-in user can see the tools available to their role, with an admin/member view switcher for administrators.
- Rebuilt NHI create/edit as full-screen pages (guided create wizard ending in a connection step); removed the cramped modal editor.
- Existing NHIs are migrated automatically and keep working; review each one to scope its abilities per role.
- Support and deactivation-feedback emails now include the customer’s email address in the subject line.
- Added a Settings link to the plugin’s row on the Plugins page.
1.2.1
- Added a floating Contact Support button, available throughout the admin app.
- Added a Setup Guide link in the toolbar for quick access to the connection guide.
- Redesigned the deactivation feedback prompt with a clearer, on-brand layout, guided reason selection, and the option to get help instead of deactivating.
1.2.0
- Added NHI Registry: a new admin screen to view and manage all non-human identity (AI client) registrations, including OAuth client details and token status.
- Added per-ability toggle to enable or disable individual abilities from being exposed as MCP tools.
- Revamped the plugin UI.
1.1.1
- Added in-plugin support form and deactivation feedback modal.
1.1.0
- Added a remote MCP server endpoint that exposes registered abilities as MCP tools.
- Added a self-hosted OAuth 2.1 authorization server with Dynamic Client Registration, PKCE, and discovery metadata so ChatGPT and Claude can connect.
1.0.0
- Initial release: read-only viewer for abilities registered through the WordPress Abilities API.
