Title: ByteCoreStack &#8211; MCP Connector for AI Tools
Author: ByteCore Stack
Published: <strong>July 6, 2026</strong>
Last modified: August 18, 2026

---

Search plugins

![](https://ps.w.org/bcs-mcp-manager/assets/banner-772x250.png?rev=3598182)

![](https://ps.w.org/bcs-mcp-manager/assets/icon-256x256.png?rev=3598182)

# ByteCoreStack – MCP Connector for AI Tools

 By [ByteCore Stack](https://profiles.wordpress.org/bytecorestack/)

[Download](https://downloads.wordpress.org/plugin/bcs-mcp-manager.1.2.1.zip)

 * [Details](https://pcm.wordpress.org/plugins/bcs-mcp-manager/#description)
 * [Reviews](https://pcm.wordpress.org/plugins/bcs-mcp-manager/#reviews)
 *  [Installation](https://pcm.wordpress.org/plugins/bcs-mcp-manager/#installation)
 * [Development](https://pcm.wordpress.org/plugins/bcs-mcp-manager/#developers)

 [Support](https://wordpress.org/support/plugin/bcs-mcp-manager/)

## Description

ByteCoreStack – MCP Connector for AI Tools is a WordPress AI plugin that turns your
site into a Model Context Protocol (MCP) server, so AI assistants like Claude, ChatGPT,
and Gemini can connect directly and take real action instead of just describing 
what to do.

Once connected, your AI agent can draft and publish posts, manage WooCommerce orders
and subscriptions, fix SEO metadata, moderate comments, sync FluentCRM contacts,
trigger UpdraftPlus backups, and update Elementor or Bricks pages — calling on 316
+ WordPress AI tools across 26 categories, each checked against the connecting user’s
real WordPress capabilities and logged in an Activity Log you control.

Authentication runs over OAuth 2.0 with PKCE, the same flow used by Google, Microsoft,
and Slack — no shared API key, no third-party relay, and every action is capability-
checked, logged, and reversible from Settings  Reset OAuth State.

See the Other Notes tab below for the full category breakdown, supported AI clients,
security details, and setup instructions.

#### Links

 * [Plugin homepage](https://bytecorestack.com/plugins/ai-connector/)
 * [Support forum](https://wordpress.org/support/plugin/bcs-mcp-manager/)
 * [Model Context Protocol specification](https://modelcontextprotocol.io/)

#### What Can an AI Agent Do With WordPress?

 * “Draft and publish a blog post about [topic], generate a featured image, and 
   tag it correctly.”
 * “Show me yesterday’s WooCommerce orders over $100 and refund order #1042.”
 * “Find every page with a missing or duplicate SEO title and fix it.”
 * “Duplicate this Elementor page, swap the hero image, and update the headline.”
 * “List my WooCommerce coupons expiring this month and extend them by two weeks.”
 * “Trigger an UpdraftPlus backup before I start a big content migration.”

#### Why Choose ByteCoreStack – MCP Connector for AI Tools for WordPress Automation?

 * **316+ tools, 26 categories** — one of the largest verified MCP tool sets for
   WordPress
 * **Multi-client** — works with Claude, ChatGPT, Gemini, Cursor, Windsurf, and 
   any MCP 2025-11-25 client
 * **Real OAuth 2.0** — full authorization code flow with PKCE, Dynamic Client Registration,
   and discovery endpoints — no shared API key
 * **Conservative by design** — no tool can create a WordPress user; role changes
   require `promote_users`
 * **Local, redacted activity logging** — every tool call is logged in your own 
   database with sensitive values redacted
 * **Zero telemetry, ever** — no analytics or tracking of any kind
 * **Grows with your stack** — WooCommerce, ACF, Elementor, Bricks, Divi, Gravity
   Forms, WPForms, Ninja Forms, Contact Form 7, MemberPress, LearnDash, EDD, Redirection,
   UpdraftPlus, FluentCRM, BuddyPress, and The Events Calendar tools activate automatically
   when detected
 * **Open to extend** — register your own custom MCP tools with one function call

#### Ideal For

 * **Agencies and freelancers** who want to run day-to-day WordPress maintenance
   through an AI assistant instead of clicking through wp-admin one task at a time
 * **WooCommerce store owners** who want an AI agent that can check orders, adjust
   stock, manage coupons, and handle subscriptions on request
 * **SEO teams and content editors** running bulk metadata fixes, content audits,
   or multi-step publishing workflows
 * **Developers** who want a real WordPress AI integration to build custom AI automation
   and AI workflow tools on top of
 * **Anyone already using Claude, ChatGPT, Cursor, or Windsurf** who wants those
   tools to actually reach into WordPress instead of just describing what to do 
   next

#### Supported AI Assistants & MCP Clients

 * **Claude.ai** — Settings  Integrations  Add integration  Custom MCP
 * **Claude Desktop** — add the MCP URL to `claude_desktop_config.json` under `mcpServers`
 * **Claude Code** — connects over the same Streamable HTTP MCP endpoint
 * **ChatGPT** — Settings  Connectors  Add connector  MCP Server
 * **Gemini** — connect via Google AI Studio MCP integrations
 * **Cursor (0.45+)** — Settings  MCP  Add New Server  HTTP (Streamable HTTP transport)
 * **Windsurf** — MCP settings panel, supports both Streamable HTTP and legacy SSE
 * **VS Code, Cline, Continue, Zed, JetBrains** and any other editor or IDE with
   MCP client support
 * **Postman, Insomnia** and other API tools with MCP request support
 * Any custom client or framework that implements the MCP 2025-11-25 specification

#### WordPress AI Tools by Category (316 Tools, Verified)

316 is the plugin’s total across every supported integration below. Tools marked_(
activates automatically)_ only appear to a connected AI client once the matching
plugin is active on your site — see “My AI client shows fewer than 316+ tools — 
is that a bug?” in the FAQ above for how the count works.

 * **Posts** — 14 tools (create, read, update, delete, duplicate, bulk trash, schedule,
   search, count, post types & statuses, post format, password protection)
 * **Pages** — 8 tools (CRUD, duplicate, page templates)
 * **Media** — 11 tools (browse, upload from file or URL, update metadata, set featured
   image, regenerate thumbnails, attachment metadata, image sizes, count)
 * **Taxonomies** — 11 tools (categories, tags, custom taxonomies, term meta, term
   assignment)
 * **Comments** — 9 tools (CRUD, approve, spam, trash, bulk delete, pending queue)
 * **Users** — 11 tools (list, view, update, delete, sessions, roles, password reset,
   CSV export — no creation tool, by design)
 * **Menus** — 11 tools (menus, menu items, reordering, duplication, location assignment)
 * **Plugins & Themes** — 7 tools (list, activate, deactivate, active theme, theme
   mods, custom CSS)
 * **SEO, Redirects & Content Quality** — 12 tools (per-post and bulk SEO meta across
   6 SEO plugins, site-wide SEO settings, URL redirects _(requires Redirection)_,
   missing alt text, broken links, orphaned media, content gap audit)
 * **Site / Options** — 17 tools (site info, site health, full Site Health diagnostics,
   multisite status, permalink structure, plugin settings, database size, send email,
   cron jobs, rewrite rules, shortcode execution, plus post/user meta read/write/
   delete)
 * **Content Structure & Revisions** — 9 tools (post revision history and restore,
   permalink structure, reusable blocks, block parsing and patterns, registered 
   sidebars and widgets)
 * **Site Health & Diagnostics** — 17 tools (cache detection/flush/purge, transients,
   server info, database size/optimize, search & replace, debug and error log, plugin/
   core update status, PHP runtime info, SSL certificate status, outgoing mail configuration_(
   requires WP Mail SMTP)_)
 * **WooCommerce** _(activates automatically)_ — 43 tools (products, variations,
   attributes, coupons, orders, refunds, customers, shipping zones, tax rates, store
   stats, sales report, top sellers, low-stock alerts, customer lifetime value, 
   product performance, payment gateways, subscriptions, bookings)
 * **Easy Digital Downloads** _(activates automatically)_ — 5 tools (products, orders,
   single order detail, customers, store stats)
 * **Advanced Custom Fields** _(activates automatically)_ — 14 tools (field groups
   CRUD and duplication, full field group definitions, field values, field updates,
   options page read/write and discovery, repeater/flexible content row add/delete,
   Local JSON sync status)
 * **Page Builders** _(activates automatically)_ — 11 tools across Elementor, Bricks,
   and Divi (clone page, bulk text replace, image swap, page outline, template import/
   listing, global widgets, raw page data)
 * **Forms** _(activates automatically)_ — 15 tools across Gravity Forms, Contact
   Form 7, WPForms, Ninja Forms, Formidable Forms, Ultimate Member, and User Registration(
   list forms, read entries/submissions/fields, create/update Gravity Forms entries)
 * **Backup & Migration** _(activates automatically)_ — 5 tools across UpdraftPlus,
   Duplicator, and All-in-One WP Migration (list backups/packages, trigger a backup,
   check job status)
 * **Marketing & CRM** _(activates automatically)_ — 14 tools across FluentCRM, 
   Mailchimp for WP, AffiliateWP, GiveWP, and WP Simple Pay (contacts, campaigns,
   lists, subscribers, affiliates, referrals, creatives, donation forms/donations/
   donors, payment forms)
 * **Membership & LMS** _(activates automatically)_ — 12 tools across LearnDash,
   MemberPress, Restrict Content Pro, and WooCommerce Memberships (courses, course
   progress, enrollment, memberships, members, subscription history, grant a membership)
 * **Community & Forums** _(activates automatically)_ — 12 tools across BuddyPress
   and bbPress (members, extended profile fields, activity stream, groups, group
   members, friends, forums, topics, replies)
 * **The Events Calendar** _(activates automatically)_ — 9 tools (events CRUD, venues,
   organizers, event categories)
 * **WPML / Polylang / TranslatePress** _(activates automatically)_ — 10 tools (
   list active languages, get/set a post’s language, get a post’s or a term’s translations,
   create a linked translation, plus Polylang String Translations and a translatable
   post types/taxonomies list _(requires Polylang)_, and default/configured languages
   plus string translation search _(requires TranslatePress)_)
 * **Analytics** _(activates automatically)_ — 11 tools across Google Site Kit, 
   WP Statistics, and MonsterInsights (Google Analytics report, top pages, AdSense
   earnings and Search Console queries via Site Kit; visit summary, top pages, online
   users, referrers, and browser/platform/country breakdown via WP Statistics; connection
   status and settings via MonsterInsights)
 * **Developer & Import Tools** _(activates automatically)_ — 9 tools across WP 
   All Import, WP All Export, Custom Post Type UI, and Code Snippets (import/export
   definitions, full post type & taxonomy CRUD through CPT UI, and a snippet audit
   list)
 * **Security & Compliance** _(activates automatically)_ — 9 tools across Wordfence,
   Two Factor, CookieYes, Complianz, Akismet, Jetpack, and Sucuri Security (scan
   issues, firewall status, 2FA status per user, cookie consent status, spam stats,
   connection status)

#### ByteCoreStack – MCP Connector for AI Tools Key Features

 * **316+ WordPress MCP tools** across 26 categories — see the full breakdown above
 * **OAuth 2.0 with PKCE** — full authorization code flow with Dynamic Client Registration
   and discovery endpoints
 * **Streamable HTTP transport** (MCP 2025-11-25) with legacy SSE fallback for older
   clients
 * **Activity log** — every tool call recorded with client detection, filters, bulk
   delete, and CSV export; sensitive values redacted
 * **Rate limiting** — 60 requests/minute per IP on `/mcp`, enforced automatically
 * **IP allowlist** — optionally restrict MCP access to specific IPs or CIDR ranges
 * **Admin dashboard** — live server status, OAuth client count, today’s success/
   fail counts, and a searchable tools browser
 * **WP Dashboard widget** — 7-day activity sparkline right on your wp-admin home
   screen
 * **Translation-ready** — ships with a complete `.pot` file in `/languages`
 * **Developer-friendly** — extend with `bcs_mcp_register_tool()` or the `bcs_mcp_tools`
   filter

#### WooCommerce, Elementor, ACF & Forms Plugin Integration

Tools for these plugins are included in the box but only activate when the respective
plugin is installed and active. No errors are thrown if a plugin is absent, and 
nothing extra needs configuring. The MCP tool list shown to a connected AI client
only ever includes tools whose dependencies are actually satisfied on your site —
so a site without WooCommerce simply never advertises WooCommerce tools to the AI.
The same applies to WooCommerce Subscriptions, WooCommerce Bookings, UpdraftPlus,
FluentCRM, BuddyPress, and The Events Calendar.

#### Multisite Support

ByteCoreStack – MCP Connector for AI Tools works on WordPress multisite networks
the same way it works on a single site: each site in the network has its own settings,
its own MCP endpoint, and its own Activity Log. There is no cross-site tool access—
an AI client connected to one site can never reach another site’s data through this
plugin. The `wp_get_multisite_info` tool reports network status and lists network
sites for site owners who need it.

#### Extending ByteCoreStack – MCP Connector for AI Tools (Developer API)

Register custom tools from any plugin or theme:

    ```
    bcs_mcp_register_tool( 'my_tool', 'Description', $schema, $callback );
    ```

Or use the `bcs_mcp_tools` filter directly to add, modify, or remove tools before
they’re advertised to a connecting AI client.

#### Security & Permissions

 * All tool calls verify WordPress capabilities (`current_user_can`) before executing—
   an AI client can never do more than the authorizing user is allowed to do
 * No MCP tool can create new WordPress users — user accounts must be created through
   wp-admin, full stop
 * Role changes (`wp_assign_user_role`) require the `promote_users` capability, 
   not just `edit_users`
 * OAuth tokens are SHA-256 hashed before database storage — plain tokens are never
   stored
 * PKCE (S256) is required for all authorization flows; plain challenges are rejected
 * Every `/mcp` request is rate-limited to 60 requests per minute per IP address(
   tracked by `REMOTE_ADDR` only — spoofable headers like `X-Forwarded-For` are 
   never trusted for this check), returning HTTP 429 once exceeded
 * Dynamic Client Registration is separately rate-limited to 10 registrations per
   IP per minute, preventing abuse of the open registration endpoint
 * Sensitive meta keys (`user_pass`, `session_tokens`, and similar) are permanently
   blocked from read/write, with no setting to disable the block
 * The Activity Log stores tool name, timestamp, client, status, and the call’s 
   parameters/result for audit purposes, all locally in your own database — any 
   value that looks like a password, token, secret, or key is redacted before it’s
   written, and large content fields are truncated
 * Outbound image downloads validate URLs against a blocklist of private/loopback
   IP ranges (SSRF protection) and enforce a 20 MB size limit
 * All admin AJAX actions are protected by nonce verification and a `manage_options`
   capability check
 * Session termination (`DELETE /mcp`) requires a valid bearer token
 * CSV exports (`wp_export_users_csv`) neutralize spreadsheet formula-injection 
   characters and escape embedded quotes before writing rows
 * Dynamic database table names are passed through `$wpdb->prepare()`‘s `%i` identifier
   placeholder rather than interpolated directly into query strings
 * The MCP server ships **disabled by default** — nothing is exposed until you explicitly
   enable it in Settings

### External Services

This plugin operates primarily as an **inbound** API server — AI clients connect
to it, not the other way around. No data is sent to any external service automatically
or in the background.

#### Image download via wp_upload_media_from_url

The `wp_upload_media_from_url` MCP tool, when explicitly invoked by an authenticated
AI client (e.g. Claude), makes a single outgoing HTTP GET request to download an
image from the URL the AI client provides. This request:

 * Is only made when the tool is called by a connected, OAuth-authenticated MCP 
   client
 * Carries no personal data beyond the image URL itself
 * Is validated against a blocklist of private/loopback IP ranges before the request
   is made
 * Is subject to a 20 MB size limit

No data is sent to the plugin author’s servers at any time. This plugin does not
include analytics, telemetry, or tracking of any kind.

## Screenshots

[⌊Admin dashboard — server status, today's stats, and recent activity feed.⌉⌊Admin
dashboard — server status, today's stats, and recent activity feed.⌉[

Admin dashboard — server status, today’s stats, and recent activity feed.

[⌊Tools browser — every tool, most-used tool in the last 28 days, and quick docs.⌉⌊
Tools browser — every tool, most-used tool in the last 28 days, and quick docs.⌉[

Tools browser — every tool, most-used tool in the last 28 days, and quick docs.

[⌊Tool detail view — tool name, method, and a plain-English explanation.⌉⌊Tool detail
view — tool name, method, and a plain-English explanation.⌉[

Tool detail view — tool name, method, and a plain-English explanation.

[⌊Settings page — enable the MCP server, copy your endpoint URL, and setup guides
per AI client.⌉⌊Settings page — enable the MCP server, copy your endpoint URL, and
setup guides per AI client.⌉[

Settings page — enable the MCP server, copy your endpoint URL, and setup guides 
per AI client.

[⌊Activity Log — filter by client, status, and date range, with color-coded tags
and CSV export.⌉⌊Activity Log — filter by client, status, and date range, with color-
coded tags and CSV export.⌉[

Activity Log — filter by client, status, and date range, with color-coded tags and
CSV export.

[⌊WP Dashboard widget — a 7-day activity sparkline on your wp-admin home screen.⌉⌊
WP Dashboard widget — a 7-day activity sparkline on your wp-admin home screen.⌉[

WP Dashboard widget — a 7-day activity sparkline on your wp-admin home screen.

[⌊Claude connector page — tools list and permission settings for the connection.⌉⌊
Claude connector page — tools list and permission settings for the connection.⌉[

Claude connector page — tools list and permission settings for the connection.

## Installation

 1. Upload the `bcs-mcp-manager` folder to `/wp-content/plugins/`, or install directly
    from the WordPress.org plugin directory.
 2. Activate the plugin via **Plugins  Installed Plugins**.
 3. **Running Wordfence, All In One WP Security, or a similar security plugin?** Check
    its firewall settings for a “restrict/disable the REST API for logged-out users”
    toggle and turn it off (or allowlist this plugin’s URLs) _before_ connecting an
    AI client — see the dedicated FAQ entry below. This is the single most common reason
    a connection fails on the first try.
 4. Go to **ByteCoreStack – MCP Connector for AI Tools  Settings** and enable the MCP
    server.
 5. Copy the MCP URL shown on the **Dashboard** page.
 6. Paste the MCP URL into your AI client (Claude.ai, Claude Desktop, ChatGPT, Gemini,
    Cursor, or Windsurf) and complete the one-time OAuth authorization.
 7. Open the **Activity Log** to confirm tool calls are arriving, and use the **WP 
    Dashboard widget** to keep an eye on activity going forward.

## FAQ

### Is ByteCoreStack – MCP Connector for AI Tools free?

Yes, the plugin is completely free with no premium tiers, license keys, usage caps,
or feature paywalls — every tool listed in this readme is included.

### I have Wordfence, All In One WP Security, or another security plugin — do I need to change anything before connecting?

**Possibly, yes — check this before you report a connection failure as a bug.** 
Security plugins commonly ship a firewall setting that restricts or disables the
WordPress REST API for anyone who isn’t logged into wp-admin. This plugin’s MCP/
OAuth endpoints are _intentionally_ reachable without a WordPress login — they authenticate
the AI client themselves via OAuth 2.0 Bearer tokens, not a WordPress session — 
so that kind of blanket “REST API requires login” setting is the wrong gate for 
them.

As of version 1.2.1, this plugin automatically exempts its own routes from that 
specific kind of lockdown, so most users won’t need to do anything. But if a connection
still fails after updating:

 1. In your security plugin’s firewall settings, look for a “restrict/disable the REST
    API for logged-out users” (or similarly worded) toggle and turn it off, or add 
    an allowlist entry for this plugin’s URLs instead.
 2. Allowlist these paths specifically: `/.well-known/oauth-protected-resource`, `/.
    well-known/oauth-authorization-server`, `/authorize`, `/token`, `/register`, and`/
    wp-json/bcs-mcp/*`.
 3. Make sure the HTTP `DELETE` method isn’t blocked for `/wp-json/bcs-mcp/*` — some
    firewalls block it by default (used for MCP session cleanup).
 4. Run **ByteCoreStack – MCP Connector for AI Tools  Diagnostics  Test Connection**—
    it detects active security plugins and gives you a specific, current status for
    each check rather than a generic pass/fail.

**Two important exceptions this plugin cannot fix on its own — but will now tell
you about automatically (as of 1.2.1) via a dismissible notice on the Plugins screen
and this plugin’s own screens:**

 * Some hosting environments (particularly nginx-based hosts and some CDNs) block
   access to any dot-prefixed path — like `.well-known/`, `.env`, or `.git` — at
   the web server level, before the request ever reaches WordPress or PHP. If Diagnostics
   or the admin notice reports that the discovery endpoint’s response “never reached
   WordPress,” that’s this case: no WordPress or security-plugin setting can fix
   it, because it’s not being blocked by WordPress or the plugin — it’s blocked 
   by the server/CDN infrastructure itself. You’ll need to ask your hosting provider(
   or your CDN, e.g. Cloudflare, Sucuri) to explicitly allow `/.well-known/*` through,
   since OAuth (RFC 8414) requires that path to be reachable.
 * **SiteGround specifically** is the most commonly reported case of this. SiteGround’s
   nginx reserves the entire `/.well-known/` prefix for their own SSL certificate(
   ACME) validation and returns a 404 for anything else under it — fleet-wide, and
   per multiple independent reports SiteGround support has declined to adjust this
   per-site, so a support ticket may not resolve it. You can confirm you’re on SiteGround
   by checking the response headers at `https://yoursite.com/.well-known/oauth-authorization-
   server` for `X-CDN-C: static` (SiteGround’s free CDN tier signature). If that’s
   your situation, the two working paths are:
    1. **Put Cloudflare (free tier works) in front of your site**, and add a Cloudflare
       Worker or Page Rule that intercepts `/.well-known/oauth-authorization-server`
       and `/.well-known/oauth-protected-resource` specifically and serves/proxies 
       them before the request ever reaches SiteGround’s nginx. This is the workaround
       other SiteGround-hosted sites in this situation have used successfully.
    2. Ask SiteGround support anyway to allowlist those two specific paths for your
       domain — low odds based on other reports, but it costs nothing to ask.
 * Some hosts redirect `POST /register` to `/register/` with an HTTP 301 (a generic
   trailing-slash canonicalization rule). OAuth clients don’t follow redirects on
   POST requests, so registration silently dies before it ever reaches this plugin—
   even when `.well-known/` discovery works perfectly fine. This is also a web-server
   config issue, not a WordPress setting; ask your host to exempt `/register`, `/
   token`, and `/authorize` from trailing-slash redirects.

### My host blocks /.well-known/ and won’t fix it (e.g. SiteGround) — can I manually add an OAuth Client ID in my AI client to work around it?

**Maybe, and it’s worth trying, but understand what it does and doesn’t fix before
you spend time on it.** This plugin has no admin screen for pre-creating a Client
ID/Secret — the only way to get one is to call this plugin’s own `/register` endpoint
directly (the same endpoint your AI client would normally call automatically):

    ```
    curl -X POST https://yoursite.com/register -H "Content-Type: application/json" -d '{"client_name": "Claude", "redirect_uris": ["https://claude.ai/api/mcp/auth_callback"], "token_endpoint_auth_method": "client_secret_post", "grant_types": ["authorization_code", "refresh_token"]}'
    ```

The JSON response contains `client_id` and `client_secret` — paste both into your
AI client’s connector settings.

**The catch:** supplying a Client ID only skips the _registration_ step. Your AI
client still needs to know where `/authorize` and `/token` live, and it normally
learns that by reading `/.well-known/oauth-authorization-server` — the exact document
that’s blocked in this scenario. A Client ID alone doesn’t tell it where to send
the user for consent or where to exchange the authorization code. Before generating
one, check whether your AI client’s connector settings _also_ have fields to manually
specify the authorization and token endpoint URLs (`https://yoursite.com/authorize`
and `https://yoursite.com/token`) alongside the Client ID/Secret. If those fields
don’t exist, this workaround won’t fully solve a blocked `.well-known/` path — you’ll
need the Cloudflare-in-front-of-your-host fix described in the previous FAQ entry
instead.

### Will updating to version 1.1.0 break my existing AI connection or settings?

No. Version 1.1.0 is a fully backward-compatible update: your existing OAuth connection,
access tokens, Settings, and Activity Log history all carry over automatically —
nothing is reset, revoked, or reconfigured. The plugin was renamed from “AI Connector–
MCP for Claude, ChatGPT, Gemini & More” to “ByteCoreStack – MCP Connector for AI
Tools,” but the plugin slug, database tables, and MCP URL are unchanged, so Claude,
ChatGPT, Gemini, Cursor, and Windsurf all keep working without needing to reconnect.
New tools simply appear the next time your AI client refreshes its tool list.

### What is MCP (Model Context Protocol)?

MCP is an open standard, originally created by Anthropic, that lets AI assistants
like Claude and ChatGPT securely connect to external tools and data sources using
a structured, authenticated protocol instead of free-text copy-paste. This plugin
implements a full MCP server inside WordPress so any MCP-compatible AI client can
read and manage your site’s content directly.

### What’s the best MCP server for WordPress?

There are a few MCP servers for WordPress, and the right one depends on what you
need. ByteCoreStack – MCP Connector for AI Tools’s focus is breadth of verified 
tools (316+ across 26 categories), real OAuth 2.0 with PKCE instead of a shared 
API key, and zero telemetry — every action is capability-checked and recorded in
your own database rather than sent anywhere else. If you’re comparing options, look
closely at tool coverage, how authentication actually works, and what happens to
your data; ByteCoreStack – MCP Connector for AI Tools is built to hold up well on
all three.

### Which AI clients are supported?

Any client that implements the MCP 2025-11-25 Streamable HTTP transport. Tested 
and confirmed working with Claude.ai, Claude Desktop, Claude Code, ChatGPT, Cursor(
0.45+), and Windsurf. Gemini uses the same standard protocol and is expected to 
work via Google AI Studio’s MCP integrations. Editors and IDEs with general-purpose
MCP client support — VS Code, Continue, Cline, Zed, JetBrains — and API tools like
Postman also connect successfully. Older client versions that use the legacy SSE
transport are supported via the `/sse` endpoint.

### Can an AI agent manage my entire WordPress site?

It can call any of the 316+ MCP tools this plugin exposes — content, WooCommerce,
SEO, media, comments, users, backups, CRM, and more — but always scoped to what 
the authorizing WordPress user is allowed to do. No MCP tool creates new WordPress
users, and role changes require the `promote_users` capability specifically. Think
of it as an AI assistant with exactly the permissions of whoever connected it, not
an unsupervised admin.

### How do I connect Claude.ai to my WordPress site?

Go to Claude.ai  Settings  Integrations  Add integration  Custom MCP. Paste your
MCP URL (`https://yoursite.com/wp-json/bcs-mcp/v1/mcp`) and follow the OAuth authorization
flow. Claude handles client registration and token management automatically.

### How do I connect ChatGPT?

In ChatGPT: Settings  Connectors  Add connector  MCP Server. Paste your MCP URL 
and complete the OAuth flow. Your site must be publicly accessible (not localhost)
and on HTTPS.

### How do I connect Claude Desktop?

Add the following to your `claude_desktop_config.json` file under `mcpServers`:

    ```
    "wordpress": { "url": "https://yoursite.com/wp-json/bcs-mcp/v1/mcp", "transport": "http" }
    ```

Restart Claude Desktop and authorize via the OAuth consent page that opens in your
browser.

### How do I connect Cursor?

In Cursor: Settings  MCP  Add New Server  select type HTTP  paste your MCP URL. 
Cursor uses the Streamable HTTP transport and sessions tracked via the `Mcp-Session-
Id` header. Ensure your WordPress site is on HTTPS.

### How do I connect Windsurf?

Open Windsurf’s MCP settings and add a new server with your MCP URL. Recent Windsurf
versions use Streamable HTTP; older versions connect via the legacy SSE endpoint
at `/sse`. Both are supported automatically.

### Does this work with WooCommerce?

Yes. 36 tools covering products, variations, attributes, coupons, orders, refunds,
customers, shipping zones, tax rates, payment gateways, store statistics, subscriptions,
and bookings activate automatically once WooCommerce (and WooCommerce Subscriptions/
Bookings, where relevant) is detected — no extra configuration required.

### Does this work with Elementor, ACF, or Gravity Forms?

Yes, all three are supported. Tools for each only become active when the respective
plugin is installed and active, and the AI client only ever sees the tools whose
dependencies are actually satisfied on your site.

### Does this work with backup and CRM plugins?

Yes. UpdraftPlus tools let an AI client list backups, trigger a new backup, and 
check job status. FluentCRM tools let it list contacts, create or update a contact,
and list email campaigns. Both integrations activate automatically when the respective
plugin is detected — no extra setup required.

### Does this work with BuddyPress or The Events Calendar?

Yes. BuddyPress tools cover members, extended profile fields, the activity stream,
groups, group members, and friend connections. The Events Calendar tools cover full
event CRUD plus venues, organizers, and event categories. Both activate automatically
when the respective plugin is detected — no extra configuration required.

### Which SEO plugins are supported?

Yoast SEO, Rank Math, All in One SEO, SEOPress, Slim SEO, and The SEO Framework.
The plugin detects whichever one is active and reads/writes its native storage directly—
per-post title, meta description, focus keyword, and noindex status, plus site-wide
title separator and homepage title/description.

### My AI client shows fewer than 316+ tools — is that a bug?

No, that’s expected. 316+ is the plugin’s _total_ tool count across every supported
integration. The list your AI client actually sees is filtered down to only the 
tools that will work on your specific site — so anything gated behind a plugin you
don’t have active (WooCommerce, ACF, Elementor, a supported SEO plugin, BuddyPress,
The Events Calendar, and so on) simply isn’t advertised. A fresh WordPress install
with none of those companion plugins active will see roughly 124 core tools; each
supported plugin you activate adds its tools to the list automatically. To see the
full 316+, install and activate every supported integration.

### Can I add my own custom tools?

Yes. Use `bcs_mcp_register_tool()` or the `bcs_mcp_tools` filter from any plugin
or your theme’s `functions.php`. See the Other Notes tab for a code example.

### Can AI delete or change things without my permission?

Every tool call is checked against real WordPress capabilities before it runs — 
an AI client can never do more than the authorizing user is allowed to do. Destructive
actions are logged in the Activity Log, and you can revoke access instantly from
Settings  Reset OAuth State.

### Can AI create new WordPress users or admin accounts?

No, and there is no setting to turn this on. No MCP tool in this plugin can create
a WordPress user under any circumstance — new accounts must always be created through
wp-admin by a human. Role changes are still possible through `wp_assign_user_role`,
but only for a token authorized by a user with the `promote_users` capability.

### Can I restrict which IPs can connect?

Yes. Add an IP allowlist (single IPs or CIDR ranges) in Settings, and the MCP endpoint
will reject any request from outside that list.

### Is there rate limiting to prevent abuse?

Yes. Every request to the `/mcp` endpoint is limited to 60 requests per minute per
IP address, enforced automatically with no configuration needed — requests over 
that limit get an HTTP 429 response instead of reaching your database. Dynamic Client
Registration (the endpoint AI clients use to register themselves) has its own separate
limit of 10 registrations per IP per minute.

### Can I use this for WordPress AI automation and workflows?

Yes. Because ByteCoreStack – MCP Connector for AI Tools exposes real WordPress actions
as MCP tools instead of just answering questions, your AI assistant can chain several
steps together in one request — draft a post, generate a featured image, assign 
categories, and publish, for example. Each step still runs through the same permission
checks and Activity Log as if you’d done it by hand in wp-admin.

### Does this plugin collect any user data or telemetry?

No external telemetry of any kind. The Activity Log does record each tool call’s
parameters and result locally, in your own WordPress database, so you can audit 
and debug what your AI client has done — values that look like passwords, tokens,
or secrets are redacted before they’re written, and large content fields are truncated.
None of this data is ever sent anywhere outside your own server, and the plugin 
includes zero analytics or tracking code.

### Will this slow down my WordPress site?

No. The MCP server only runs when an AI client actively makes a request to the `/
mcp` endpoint — there is no background polling, no front-end script, and no impact
on normal page load times for your visitors.

### Does this work on WordPress multisite?

Yes, per-site. Each site on the network gets its own settings, its own MCP URL, 
and its own Activity Log. There is no shared or cross-site tool access. The `wp_get_multisite_info`
tool lets a connected AI client check network status and list network sites when
multisite is enabled.

### What happens if I uninstall the plugin?

A clean uninstall removes every database table the plugin created (logs, OAuth tokens,
OAuth clients, authorization codes), every plugin option, and every transient it
set. No orphaned data is left behind in your database.

### I restored my site from a backup and my AI client can’t reconnect. What do I do?

Database restores can leave your AI client holding OAuth credentials that no longer
match what’s stored on the (restored) site. Go to **ByteCoreStack – MCP Connector
for AI Tools  Settings  Reset OAuth State** to clear all stored tokens and client
registrations, then remove and re-add the connector in your AI client to trigger
a fresh authorization flow.

### I see “Couldn’t register with sign-in service” in Claude

Claude shows this when it can’t reach `/register` or the `/.well-known/oauth-authorization-
server` discovery endpoint it depends on. There are two distinct causes with different
fixes:

 1. **OAuth rewrite rules haven’t been flushed.** Log in to wp-admin — the plugin auto-
    flushes on the first admin page load after each update. If the error persists, 
    go to **Settings  Permalinks** and click **Save Changes**.
 2. **Your web server or CDN is blocking `/.well-known/\*` before it ever reaches WordPress.**
    This is a different problem than #1, and no WordPress or plugin setting can fix
    it. Many nginx-based hosts ship a blanket rule blocking any dot-prefixed path (
    meant to block `.env`/`.git`/`.htaccess` exposure) that also catches `.well-known/`,
    which OAuth (RFC 8414) requires to be reachable. You can tell the two apart: visit`
    https://yoursite.com/.well-known/oauth-authorization-server` directly in a browser—
    if you get your site’s normal 404 page, it’s #1; if you get a bare, unstyled 404
    with no site branding at all (or the connection just times out), it’s #2. For #
    2, run **Diagnostics  Test Connection** — as of 1.2.1 it detects this specific 
    case and tells you plainly. The fix has to happen at the server/CDN level: ask 
    your host or CDN provider (e.g. Cloudflare) to explicitly allow `/.well-known/*`
    through their firewall/dotfile-blocking rule.

### Cursor says it can’t establish a session

Ensure your WordPress site is on HTTPS and publicly accessible. Cursor requires 
the `Mcp-Session-Id` header in the server’s `initialize` response — this plugin 
sends it correctly. If you’re behind a caching plugin or CDN, make sure `/wp-json/
bcs-mcp/*` is excluded from caching.

### My site uses nginx. Will SSE work?

Yes. The plugin sends `X-Accel-Buffering: no` on SSE responses to prevent nginx 
from buffering the stream. No additional nginx configuration is required.

### My site is on HTTP (not HTTPS). Will this work?

OAuth 2.0 requires HTTPS for security, and most AI clients will refuse to connect
to non-HTTPS endpoints. A valid SSL certificate is strongly recommended. For local
development with localhost, HTTP is allowed by the OAuth redirect URI validator.

### How do I disconnect an AI client?

Go to **ByteCoreStack – MCP Connector for AI Tools  Settings**  Reset OAuth State.
This revokes all tokens and clears all registered clients. Any connected AI client
will need to re-authorize.

### I see “This connector has no tools available” the first time I connect, but disconnecting and reconnecting fixes it. Is this a bug in the plugin?

No — this is a **confirmed Claude Desktop client bug**, not a server-side issue.
Anthropic’s own GitHub tracker documents it (issue #60222 and related reports #5826,#
22299, #23736, #14807, #38343): the first `tools/list` call after connecting a Streamable
HTTP + OAuth connector can fail or return empty in Claude Desktop specifically, 
and the affected server’s own logs show **zero incoming traffic** during the failure—
proving the request never left the client. The same connection works without issue
through Claude Code CLI and Claude.ai web the whole time. Anthropic closed the issue
as “not planned,” so there’s no fix timeline, and nothing on the server side can
prevent it since it happens before any request reaches this plugin.

The workaround is exactly what fixes it for you: disconnect and reconnect the connector,
which re-runs `initialize`/`tools/list` and typically restores the tool list. If
a tool call ever seems to hang or silently no-op right after reconnecting, try it
once more — the same report notes the very first call can occasionally still fail
once before settling.

### My connection broke after a plugin or theme update. Where do I start troubleshooting?

Update to the latest version of ByteCoreStack – MCP Connector for AI Tools first—
most connection issues are fixed in the next release. If the problem persists: (
1) temporarily deactivate other plugins to rule out a conflict, (2) check that your
caching plugin or CDN excludes `/wp-json/bcs-mcp/*`, (3) reset OAuth state from 
Settings and reconnect, (4) check the Activity Log for the specific error status
on the failing tool call.

### I have Wordfence, All In One WP Security, or another security plugin — my AI client can’t connect. What do I do?

See “I have Wordfence, All In One WP Security, or another security plugin — do I
need to change anything before connecting?” near the top of this FAQ for the full
walkthrough (what this plugin already handles automatically, what to allowlist manually,
and the separate server/CDN-level `.well-known` blocking case that no plugin setting
can fix).

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“ByteCoreStack – MCP Connector for AI Tools” is open source software. The following
people have contributed to this plugin.

Contributors

 *   [ ByteCore Stack ](https://profiles.wordpress.org/bytecorestack/)

[Translate “ByteCoreStack – MCP Connector for AI Tools” into your language.](https://translate.wordpress.org/projects/wp-plugins/bcs-mcp-manager)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/), 
check out the [SVN repository](https://plugins.svn.wordpress.org/bcs-mcp-manager/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/bcs-mcp-manager/)
by [RSS](https://plugins.trac.wordpress.org/log/bcs-mcp-manager/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.2.1

 * Fixed: uninstalling the plugin left the `bcs_mcp_review_notice` option behind
   instead of removing it along with the plugin’s other options, contradicting this
   readme’s “clean uninstall, no orphaned data” claim
 * Hardened: the sensitive-value redaction list (used by the Activity Log and by
   generic postmeta/usermeta read tools) now also matches meta keys containing the
   bare substring `pass` — e.g. a third-party plugin storing a credential under 
   a key like `smtp_pass` or `ftp_pass` is now redacted; previously only keys containing
   the full word `password` or `passwd` were caught
 * Fixed: security plugins that ship a “restrict the REST API to logged-in users”
   toggle (Wordfence, All In One WP Security, and similar) could block AI clients
   entirely, since this plugin’s MCP/OAuth routes are intentionally anonymous at
   the WordPress-login level and authenticate the caller themselves via OAuth Bearer
   token. This plugin’s own routes are now automatically exempted from that kind
   of blanket lockdown set by another plugin.
 * Diagnostics: the “OAuth discovery endpoint reachable” check now gives a specific,
   actionable message based on the actual HTTP status returned (401/403/406 now 
   correctly points at a firewall/security-plugin block instead of the generic “
   rewrite rules” message) instead of one generic failure message for every cause
 * Diagnostics: added a new check that detects active security plugins (Wordfence,
   All In One WP Security, iThemes/Solid Security, Sucuri Security, WP Cerber) and
   lists exactly which URLs and HTTP methods to allowlist in their firewall if a
   client still can’t connect
 * Diagnostics: the discovery-endpoint check now also detects when a 404 response
   never actually reached WordPress at all (identified by the response missing any
   PHP/WordPress fingerprint). Previously this was misreported as “rewrite rules
   not flushed,” which sent people to the wrong settings screen; it now correctly
   says this needs a firewall/allowlist fix, and explicitly names any active security
   plugin that could be the cause (its own protection layer, e.g. Wordfence’s “Extended
   Protection” mode, can run before WordPress loads exactly like a host or CDN block
   would) rather than only pointing at the host/CDN
 * Added a dedicated FAQ entry with step-by-step guidance for Wordfence/AIOS/firewall-
   blocked connections and for the server/CDN-level `.well-known` blocking case
 * New: a proactive admin notice (shown on the Plugins screen and this plugin’s 
   own screens, not just when you manually run Diagnostics) that detects OAuth discovery/
   registration problems automatically — a host or CDN blocking `/.well-known/*`
   before PHP runs, Sucuri/CloudProxy specifically, a response that’s HTML instead
   of JSON (another plugin or theme intercepting the request), Plain permalinks,
   or a host redirecting `POST /register` to `/register/` with a 301 (which OAuth
   clients don’t follow, silently breaking registration even when discovery works).
   Each case gets its own specific fix, and the notice is dismissible and re-checkable
   per admin
 * Fixed: clicking “Test Connection” on the Diagnostics page didn’t clear the separate
   cache the admin notice above uses, so the notice could keep reporting an already-
   fixed problem for up to its own refresh interval. Both now refresh together
 * Fixed: a rejected connection attempt (an invalid/expired token, an IP-allowlist
   block, or a rate limit) never appeared in the Activity Log at all — only successful
   tool calls were recorded, so a failing connection looked like total silence with
   nothing to debug from. These rejections are now logged with a specific reason(
   e.g. “token was explicitly revoked” vs. “token expired at … UTC” vs. “no matching
   access token found — never issued, or issued by a different site/environment”)
   instead of the generic “invalid or expired” message alone. The routine unauthenticated
   request every OAuth client sends first (before it has a token) is deliberately
   not logged, since logging that would flood the log with noise rather than signal
 * Documentation: identified SiteGround specifically (via its `X-CDN-C: static` 
   free-CDN response header) as the most common cause of the “host/CDN blocking `.
   well-known/`” case — SiteGround’s nginx reserves that entire path prefix for 
   its own SSL certificate validation, fleet-wide, and per multiple reports won’t
   adjust it per-site even on request. Added FAQ guidance covering how to identify
   it, the Cloudflare-edge-proxy workaround other SiteGround-hosted sites have used,
   and the tradeoffs of working around it by manually supplying an OAuth Client 
   ID/Secret in your AI client instead of relying on automatic discovery
 * Documentation: added an FAQ entry explaining “This connector has no tools available”
   on a first-time connection that resolves after disconnect/reconnect — confirmed
   via Anthropic’s own issue tracker to be a Claude Desktop client-side bug (zero
   traffic reaches the server during the failure), not something a server-side fix
   can address

#### 1.2.0

 * Added 96+ new WordPress AI tools, bringing the total to 316+ across all supported
   integrations
 * New integrations: MonsterInsights, Sucuri Security, and TranslatePress, plus 
   WP Mail SMTP configuration status
 * Fixed: admin screens were loading DM Sans / DM Mono from Google’s font CDN on
   every page view even though local copies were already bundled; now fully self-
   hosted with no external requests

#### 1.1.0

This release adds 56 new WordPress MCP tools (215+ total, up from 150+), six more
SEO plugin integrations, two new community/events integrations, a dedicated connection
diagnostics page, and a redesigned admin dashboard — plus security hardening and
bug fixes. **Fully backward compatible:** existing OAuth connections, access tokens,
Activity Log history, and settings are preserved automatically on update — no re-
authorization, reconfiguration, or action of any kind is required from existing 
users. Full details below.

**New: SEO tools now support 6 plugins (was 2)**
 * SEO meta tools (per-post title/
description/focus keyword/noindex, bulk SEO audit, site-wide title separator and
homepage settings) now auto-detect and support Yoast SEO, Rank Math, All in One 
SEO (AIOSEO), SEOPress, Slim SEO, and The SEO Framework * AIOSEO is read and written
directly through its own database table (not postmeta), matching how AIOSEO v4+ 
actually stores data

**New: Community & Events integrations**
 * BuddyPress — list members, read extended
profile (xProfile) fields, read and post to the activity stream, list and create
groups, list group members, list friend connections * The Events Calendar — full
event CRUD (create, read, update, delete), plus venues, organizers, and event categories

**New: Forms, LMS & e-commerce integrations**
 * Contact Form 7 — list forms, read
form fields and mail settings * WPForms — list forms, read entries (requires WPForms
Pro or entry storage enabled) * Ninja Forms — list forms, read submissions * MemberPress—
list memberships and members, get a member’s subscriptions and transaction history*
LearnDash — list courses, get a user’s course progress, enroll/unenroll a user *
Easy Digital Downloads — products, orders, single order detail, customers, store
stats * WooCommerce Subscriptions & Bookings — list subscriptions, cancel a subscription,
list bookings (added to the existing WooCommerce category)

**New: Page builder & site management integrations**
 * Bricks Builder — read a 
page’s element tree, clone a page with its Bricks content * Divi Builder — read 
a page’s shortcode content, clone a page with its Divi content * Redirection — list,
create, and delete URL redirects * UpdraftPlus (Backup & Migration) — list backup
sets, trigger a new backup, check job status * FluentCRM (Email / CRM) — list contacts,
create or update a contact by email, list email campaigns

**New: Core WordPress tools**
 * Cache status detection — reports which page-caching
and object-caching plugins are active * Users CSV export * Full Site Health diagnostics—
runs the same tests shown under Tools  Site Health and summarizes critical/recommended/
passed counts * `wp_bulk_delete_comments` — delete or trash multiple comments by
ID in one call * `wp_duplicate_menu` — duplicate a nav menu including all of its
items * `wp_get_multisite_info` — check multisite status and list network sites

**New: Admin dashboard & setup experience**
 * Dedicated “Connection Test” page (
between Settings and Activity Log) — checks HTTPS, permalinks, and live MCP/OAuth-
discovery endpoint reachability, and reports the specific reason a connection would
fail instead of a generic error * “Setup Health” checklist on the Dashboard — at-
a-glance status for server enabled, HTTPS, pretty permalinks, and whether an AI 
client is connected, with a “Fix now ” shortcut * In-admin review prompt (shown 
only on this plugin’s own screens, only after real successful tool calls) with “
Remind me later” and “No thanks” options — never shown on first activation

**Improved: Dashboard & Settings UI**
 * The “Enable MCP Server” toggle is now a
full-width, color-coded banner at the top of Settings instead of a small switch 
buried inside a card * Removed the “Quick Connect” card from the Dashboard (it duplicated
the per-client setup steps already on Settings); the “WordPress Tools” browser now
spans the full page width * Dashboard pairs “Setup Health” on the left with the 
stat cards on the right (3 per row, 2 rows), matched to equal height * Setup Health
checklist rows show a check/warning icon and a “Ready” / “Needs attention” status
tag, and are noticeably more compact * “Recent Activity” and “Most Used Tools” are
now always shown side by side (2/3 + 1/3 columns) instead of “Most Used Tools” being
hidden entirely until there’s data — it now shows an empty state like Recent Activity
does * Activity Log pagination now truncates to “1 2 3 … 8 9 10” style instead of
listing every page number when there are many pages * Fixed excess vertical spacing
between the tool name and its usage bar in “Most Used Tools” (Dashboard and Settings)

**Improved: Connection Test & Activity Log**
 * Redesigned the “Connected AI Clients”
list on Connection Test: branded per-client color and avatar, total calls, calls
today, and a session-expiry countdown, plus a “View activity” button that jumps 
straight to the Activity Log pre-filtered to that client * Activity Log table no
longer scrolls inside its own box — it now scrolls with the page like the rest of
the admin screen * Activity Log gained a “Show ⌄ per page” control (10 / 20 / 50/
100, default 20); pagination now sits to the right of it instead of centered alone*“
Last tested” timestamp on Connection Test now displays in the site’s configured 
local timezone (Settings  General  Timezone) instead of the server’s UTC time * 
Removed the redundant per-client “connected X ago” breakdown from the Dashboard’s
Setup Health card — the full detail now lives on the Connection Test page * Removed
the “No test run yet” placeholder that could stay visible after a test had actually
completed

**Fixed**
 * `tools/list` now actually filters out addon-gated tools whose required
plugin isn’t active, instead of advertising all 215+ tools regardless of what’s 
installed — a connected AI client only ever sees tools that will work on the site*
Removed the “REST endpoint reachable” check from Connection Test — a self-request
through some caching/security-plugin setups could return HTTP 200 with a body that
didn’t parse as expected, producing a false failure on connections that were actually
working fine. The remaining 4 checks (server enabled, HTTPS, permalinks, OAuth discovery)
cover the same ground without the false positive * The “Enable MCP Server” toggle’s
label text was never actually rendered bold, and the switch itself blended into 
the banner background — both now have proper contrast * Activity Log’s built-in 
connection-test entries were being mislabeled after the plugin rename * A missing`
translators:` comment on the OAuth authorization screen was breaking automatic `.
pot` generation * `wc_create_variation` / `wc_update_variation` — attribute values
passed as `{name, option}` could silently save as an empty string instead of the
intended value; the variation’s postmeta key was being double-prefixed, and a brand-
new attribute or term was never registered on the parent product as usable for variations.
Both are now handled automatically * `wp_get_site_health_tests` could hang the whole
request (“connector’s server isn’t responding”) if a network-dependent Site Health
test wasn’t already excluded, or if a single test threw a fatal error; hardened 
with a wider skip list for network-calling tests, a 3-second HTTP timeout clamp 
for the duration of the run, and per-test error isolation so one broken test can’t
take down the whole diagnostic * A tool call that hit an uncaught PHP fatal error(
as opposed to a caught `Exception`) was left stuck at `status = pending` in the 
Activity Log forever instead of being recorded as `error`

**Security**
 * `wp_export_users_csv` now neutralizes spreadsheet formula-injection
characters (`=`, `+`, `-`, `@`) and escapes embedded quotes in exported fields *
Dynamic database table names in the WPForms, MemberPress, and Redirection queries
now use `$wpdb->prepare()`‘s `%i` identifier placeholder instead of raw string interpolation

**Changed**
 * Plugin renamed to “ByteCoreStack – MCP Connector for AI Tools” (previously“
AI Connector – MCP for Claude, ChatGPT, Gemini & More”) * Readme tags updated for
search discoverability (`mcp, ai, claude, chatgpt, mcp-server`) * All new integrations
activate automatically when their corresponding plugin is detected, matching the
existing WooCommerce/ACF/Elementor/Gravity Forms behavior — no configuration required*
215+ WordPress MCP tools across 30 categories (215 verified at release)

#### 1.0.0

 * Initial release
 * 150+ WordPress MCP tools across 20 categories (159 verified at release)
 * OAuth 2.0 with PKCE (authorization code flow, Dynamic Client Registration, refresh
   tokens)
 * Discovery endpoints: `/.well-known/oauth-protected-resource` and `/.well-known/
   oauth-authorization-server`
 * Streamable HTTP transport (MCP 2025-11-25) as primary transport
 * Legacy SSE transport (`/sse` + `/messages`) for older client versions — compatible
   with all clients, not restricted by User-Agent
 * `Mcp-Session-Id` response header on `initialize` for session tracking (required
   by Cursor)
 * `X-Accel-Buffering: no` on SSE responses for nginx compatibility
 * Auth validation on session termination (DELETE /mcp)
 * Activity logging with client detection (Claude, ChatGPT, Gemini, Cursor, Windsurf,
   and others), storing each call’s parameters/result locally for audit purposes
   with sensitive-looking values redacted automatically
 * IP allowlist support
 * Admin dashboard with today’s success/fail stat cards, settings page, and activity
   log with CSV export
 * WP Dashboard widget (7-day activity bar chart)
 * WooCommerce (33 tools), ACF (3 tools), Elementor (6 tools), and Gravity Forms(
   2 tools) integrations — activate automatically when those plugins are present
 * Developer API: `bcs_mcp_register_tool()` helper and `bcs_mcp_tools` filter for
   custom tools
 * No tool creates new WordPress users; `wp_update_user` no longer accepts a `role`
   parameter — use `wp_assign_user_role` (requires `promote_users`) for role changes
 * Clean uninstall: removes all plugin tables, options, and transients with no orphaned
   data
 * Translation-ready: full `.pot` file included in `/languages` for translators

## Meta

 *  Version **1.2.1**
 *  Last updated **2 weeks ago**
 *  Active installations **30+**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.0.4**
 *  PHP version ** 7.4 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/bcs-mcp-manager/)
 * Tags
 * [AI](https://pcm.wordpress.org/plugins/tags/ai/)[ChatGPT](https://pcm.wordpress.org/plugins/tags/chatgpt/)
   [Claude](https://pcm.wordpress.org/plugins/tags/claude/)[mcp](https://pcm.wordpress.org/plugins/tags/mcp/)
   [mcp-server](https://pcm.wordpress.org/plugins/tags/mcp-server/)
 *  [Advanced View](https://pcm.wordpress.org/plugins/bcs-mcp-manager/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/bcs-mcp-manager/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/bcs-mcp-manager/reviews/)

## Contributors

 *   [ ByteCore Stack ](https://profiles.wordpress.org/bytecorestack/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/bcs-mcp-manager/)