{"id":300297,"date":"2026-05-08T12:14:09","date_gmt":"2026-05-08T12:14:09","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/mcp-manager\/"},"modified":"2026-09-24T04:01:59","modified_gmt":"2026-09-24T04:01:59","slug":"acrossai-mcp-manager","status":"publish","type":"plugin","link":"https:\/\/pcm.wordpress.org\/plugins\/acrossai-mcp-manager\/","author":15295430,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.3.7","stable_tag":"0.3.7","tested":"7.1.2","requires":"7.0","requires_php":"8.1","requires_plugins":null,"header_name":"AcrossAI MCP Manager","header_author":"raftaar1191","header_description":"Enable\/Disable MCP Adapter Integration for WordPress","assets_banners_color":"ccdbfb","last_updated":"2026-09-24 04:01:59","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/acrossai.co\/","header_author_uri":"https:\/\/profiles.wordpress.org\/raftaar1191\/","rating":5,"author_block_rating":0,"active_installs":10,"downloads":2617,"num_ratings":1,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.0.1":{"tag":"0.0.1","author":"raftaar1191","date":"2026-05-08 12:13:51","revision":3526498},"0.0.2":{"tag":"0.0.2","author":"raftaar1191","date":"2026-05-08 12:20:27","revision":3526506},"0.0.3":{"tag":"0.0.3","author":"raftaar1191","date":"2026-05-14 14:45:29","revision":3532152},"0.0.4":{"tag":"0.0.4","author":"raftaar1191","date":"2026-06-02 11:53:16","revision":3557976},"0.0.5":{"tag":"0.0.5","author":"raftaar1191","date":"2026-06-02 12:01:31","revision":3557991},"0.0.6":{"tag":"0.0.6","author":"raftaar1191","date":"2026-07-04 00:14:27","revision":3595613},"0.0.7":{"tag":"0.0.7","author":"raftaar1191","date":"2026-07-04 00:46:20","revision":3595622},"0.0.8":{"tag":"0.0.8","author":"raftaar1191","date":"2026-07-04 01:08:15","revision":3595628},"0.0.9":{"tag":"0.0.9","author":"raftaar1191","date":"2026-07-04 01:33:59","revision":3595640},"0.1.1":{"tag":"0.1.1","author":"raftaar1191","date":"2026-07-17 02:08:40","revision":3610897},"0.1.2":{"tag":"0.1.2","author":"raftaar1191","date":"2026-07-17 02:17:28","revision":3610902},"0.1.3":{"tag":"0.1.3","author":"raftaar1191","date":"2026-07-19 07:07:06","revision":3613298},"0.1.4":{"tag":"0.1.4","author":"raftaar1191","date":"2026-07-20 05:14:29","revision":3614210},"0.1.5":{"tag":"0.1.5","author":"raftaar1191","date":"2026-07-20 12:01:25","revision":3614699},"0.1.6":{"tag":"0.1.6","author":"raftaar1191","date":"2026-07-22 04:13:13","revision":3617920},"0.1.7":{"tag":"0.1.7","author":"raftaar1191","date":"2026-07-24 06:47:24","revision":3620868},"0.1.8":{"tag":"0.1.8","author":"raftaar1191","date":"2026-07-26 13:34:32","revision":3623493},"0.1.9":{"tag":"0.1.9","author":"raftaar1191","date":"2026-07-30 07:28:54","revision":3628087},"0.2.0":{"tag":"0.2.0","author":"raftaar1191","date":"2026-08-02 04:00:40","revision":3631473},"0.2.10":{"tag":"0.2.10","author":"raftaar1191","date":"2026-08-13 20:15:19","revision":3646132},"0.2.2":{"tag":"0.2.2","author":"raftaar1191","date":"2026-08-02 17:04:02","revision":3631961},"0.2.3":{"tag":"0.2.3","author":"raftaar1191","date":"2026-08-04 14:49:36","revision":3634312},"0.2.4":{"tag":"0.2.4","author":"raftaar1191","date":"2026-08-08 09:11:01","revision":3638552},"0.2.5":{"tag":"0.2.5","author":"raftaar1191","date":"2026-08-09 12:51:41","revision":3639368},"0.2.6":{"tag":"0.2.6","author":"raftaar1191","date":"2026-08-10 14:06:58","revision":3640698},"0.2.7":{"tag":"0.2.7","author":"raftaar1191","date":"2026-08-10 14:15:32","revision":3640712},"0.2.8":{"tag":"0.2.8","author":"raftaar1191","date":"2026-08-13 16:16:12","revision":3645803},"0.2.9":{"tag":"0.2.9","author":"raftaar1191","date":"2026-08-13 18:39:57","revision":3646020},"0.3.0":{"tag":"0.3.0","author":"raftaar1191","date":"2026-08-21 01:17:55","revision":3657993},"0.3.1":{"tag":"0.3.1","author":"raftaar1191","date":"2026-08-26 12:39:57","revision":3667013},"0.3.2":{"tag":"0.3.2","author":"raftaar1191","date":"2026-08-30 18:47:29","revision":3673028},"0.3.3":{"tag":"0.3.3","author":"raftaar1191","date":"2026-09-07 19:38:20","revision":3685479},"0.3.4":{"tag":"0.3.4","author":"raftaar1191","date":"2026-09-18 20:12:26","revision":3702733},"0.3.5":{"tag":"0.3.5","author":"raftaar1191","date":"2026-09-18 21:19:19","revision":3702769},"0.3.6":{"tag":"0.3.6","author":"raftaar1191","date":"2026-09-21 04:45:29","revision":3704846},"0.3.7":{"tag":"0.3.7","author":"raftaar1191","date":"2026-09-24 04:01:59","revision":3710450}},"upgrade_notice":{"0.3.7":"<p>Repairs sites whose database tables were missing columns \u2014 which could make a server advertise tools you never selected and silently refuse to remove them. It happens automatically on the next wp-admin page load. Reconnect your AI client afterwards to see the corrected tool list.<\/p>","0.3.6":"<p>Installing the AcrossAI Abilities Manager add-on now works immediately \u2014 no server-type change and no Reset needed. Adds a second, disabled-by-default AcrossAI server, and repairs servers that were created with no tools. Your own tool selections are left alone.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon.svg":{"filename":"icon.svg","revision":3595613,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3614699,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3614699,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.0.1","0.0.2","0.0.3","0.0.4","0.0.5","0.0.6","0.0.7","0.0.8","0.0.9","0.1.1","0.1.2","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9","0.2.0","0.2.10","0.2.2","0.2.3","0.2.4","0.2.5","0.2.6","0.2.7","0.2.8","0.2.9","0.3.0","0.3.1","0.3.2","0.3.3","0.3.4","0.3.5","0.3.6","0.3.7"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3614210,"resolution":"1","location":"assets","locale":"","width":3268,"height":1874},"screenshot-10.png":{"filename":"screenshot-10.png","revision":3710450,"resolution":"10","location":"assets","locale":"","width":3268,"height":1874},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3614210,"resolution":"2","location":"assets","locale":"","width":3268,"height":1874},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3614210,"resolution":"3","location":"assets","locale":"","width":3268,"height":1874},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3614210,"resolution":"4","location":"assets","locale":"","width":3268,"height":1874},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3614210,"resolution":"5","location":"assets","locale":"","width":3268,"height":1874},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3614210,"resolution":"6","location":"assets","locale":"","width":3268,"height":1874},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3614210,"resolution":"7","location":"assets","locale":"","width":3268,"height":1874},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3614210,"resolution":"8","location":"assets","locale":"","width":3268,"height":1874},"screenshot-9.png":{"filename":"screenshot-9.png","revision":3710450,"resolution":"9","location":"assets","locale":"","width":3268,"height":1874}},"screenshots":{"1":"The Overview tab \u2014 your server at a glance, including the live MCP endpoint URL to hand your AI client, with every supported client listed underneath.","2":"Terminal users connect with one command and approve it in the browser. Every approved, successful and failed attempt is recorded in the per-server CLI connection log.","3":"Pick your AI client, generate a WordPress Application Password in one click, and copy configuration JSON that already has the right file path and top-level key for that client.","4":"AI Connectors \u2014 paste one URL into Claude, ChatGPT, Grok, Gemini or Cursor and approve the consent screen on your own site. Requires the AcrossAI Pro add-on.","5":"WP-CLI STDIO transport \u2014 the client launches WP-CLI as a subprocess, so no credential ever crosses the network. Ideal for local development.","6":"The Tools tab \u2014 choose exactly which abilities this server advertises. Add three, or add hundreds.","7":"The Abilities tab \u2014 switch individual abilities on or off per server, with search, filters and bulk actions across the whole catalogue.","8":"Access Control \u2014 decide who may reach each server by user, role or capability. New servers are administrator-only until you change this.","9":"Run as many MCP servers as you need on one site, each with its own route, tools and rules, enabled or disabled independently.","10":"Global settings, including CLI connections and a deliberately non-destructive uninstall that keeps your data unless you opt out."}},"plugin_section":[],"plugin_tags":[148285,216196,229563,242115,260626],"plugin_category":[44,54],"plugin_contributors":[140910],"plugin_business_model":[],"class_list":["post-300297","plugin","type-plugin","status-publish","hentry","plugin_tags-ai-assistant","plugin_tags-chatgpt","plugin_tags-claude","plugin_tags-mcp","plugin_tags-mcp-server","plugin_category-discussion-and-community","plugin_category-security-and-spam-protection","plugin_contributors-raftaar1191","plugin_committers-raftaar1191"],"banners":{"banner":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/banner-772x250.png?rev=3614699","banner_2x":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/banner-1544x500.png?rev=3614699","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/icon.svg?rev=3595613","icon":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/icon.svg?rev=3595613","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-1.png?rev=3614210","caption":"The Overview tab \u2014 your server at a glance, including the live MCP endpoint URL to hand your AI client, with every supported client listed underneath."},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-2.png?rev=3614210","caption":"Terminal users connect with one command and approve it in the browser. Every approved, successful and failed attempt is recorded in the per-server CLI connection log."},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-3.png?rev=3614210","caption":"Pick your AI client, generate a WordPress Application Password in one click, and copy configuration JSON that already has the right file path and top-level key for that client."},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-4.png?rev=3614210","caption":"AI Connectors \u2014 paste one URL into Claude, ChatGPT, Grok, Gemini or Cursor and approve the consent screen on your own site. Requires the AcrossAI Pro add-on."},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-5.png?rev=3614210","caption":"WP-CLI STDIO transport \u2014 the client launches WP-CLI as a subprocess, so no credential ever crosses the network. Ideal for local development."},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-6.png?rev=3614210","caption":"The Tools tab \u2014 choose exactly which abilities this server advertises. Add three, or add hundreds."},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-7.png?rev=3614210","caption":"The Abilities tab \u2014 switch individual abilities on or off per server, with search, filters and bulk actions across the whole catalogue."},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-8.png?rev=3614210","caption":"Access Control \u2014 decide who may reach each server by user, role or capability. New servers are administrator-only until you change this."},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-9.png?rev=3710450","caption":"Run as many MCP servers as you need on one site, each with its own route, tools and rules, enabled or disabled independently."},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-10.png?rev=3710450","caption":"Global settings, including CLI connections and a deliberately non-destructive uninstall that keeps your data unless you opt out."}],"raw_content":"<!--section=description-->\n<p><strong>AcrossAI MCP Manager turns your WordPress site into a Model Context Protocol (MCP) server.<\/strong> Claude, Cursor, VS Code, GitHub Copilot, Gemini CLI, Codex, Windsurf, Zed and more connect straight to your site and can read, write and act on it \u2014 using WordPress's own Application Passwords, with per-server access control you configure.<\/p>\n\n<p>The Model Context Protocol is the standard Anthropic introduced and the AI industry adopted: it lets an AI assistant discover and call tools on a service through one common interface. This plugin implements that server inside WordPress, so any MCP-capable AI becomes a WordPress co-pilot.<\/p>\n\n<p><strong>Setup takes about a minute<\/strong> via the <a href=\"https:\/\/acrossai.co\/mcp-manager-quick-setup\/\">Quick Setup wizard<\/a> \u2014 install, click through the guided flow, paste the ready-made JSON into your AI client, done.<\/p>\n\n<p><strong>Documentation:<\/strong> <a href=\"https:\/\/acrossai.co\/docs\/\">acrossai.co\/docs<\/a> \u00b7 <strong>Use cases:<\/strong> <a href=\"https:\/\/acrossai.co\/use-cases\/\">acrossai.co\/use-cases<\/a> \u00b7 <strong>Integrations:<\/strong> <a href=\"https:\/\/acrossai.co\/integrations\/\">acrossai.co\/integrations<\/a> \u00b7 <strong>Full changelog:<\/strong> <a href=\"https:\/\/acrossai.co\/changelog\/\">acrossai.co\/changelog<\/a><\/p>\n\n<p>Every section below links to the relevant page. Source and issues live at <a href=\"https:\/\/github.com\/acrossai-co\/acrossai-mcp-manager\">github.com\/acrossai-co\/acrossai-mcp-manager<\/a>.<\/p>\n\n<h4>Your Site Is the MCP Server \u2014 No Relay, No Third Party<\/h4>\n\n<p>This is the part worth reading twice, because it is the main thing that separates this plugin from the alternatives.<\/p>\n\n<p><strong>There is no middleman.<\/strong> The free plugin makes zero outbound HTTP requests of its own \u2014 no telemetry, no phone-home, no proxy, no hosted relay. Your MCP endpoint is a route on your own site, and your AI client talks to it directly. The <code>npx<\/code> bridge that some clients use runs on <em>your own computer<\/em>, not on anyone's server.<\/p>\n\n<p>That means <strong>your content never passes through a third party's infrastructure<\/strong>, there is no account to create with us to make it work, no service that has to stay online for your site to keep working, and nothing to migrate if you stop using the plugin. Your credentials are WordPress Application Passwords, issued by your own site and revocable from your own profile page.<\/p>\n\n<p>A plugin that relays your site through its vendor's servers has to disclose that. This one has nothing to disclose.<\/p>\n\n<h4>Connect Claude to WordPress<\/h4>\n\n<p>Works with <strong>Claude Desktop<\/strong>, <strong>Claude Code<\/strong> in the terminal, and Claude on the web. Open the server's connect tab, pick Claude, generate an Application Password with one click, copy the ready-made JSON into the config file path the screen shows you, and restart Claude. From then on, ask Claude to draft a post, fix a page, audit site health or reorganise a taxonomy, and it acts on your live site rather than describing what you should click.<\/p>\n\n<p>\u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-connect-a-client\/\">Connect an AI client<\/a><\/p>\n\n<h4>Connect ChatGPT and Grok to WordPress<\/h4>\n\n<p>ChatGPT and Grok connect through <strong>AI Connectors<\/strong>, the one-click flow in the separate <a href=\"https:\/\/acrossai.co\/pricing\/\">AcrossAI Pro<\/a> add-on <em>(Pro)<\/em>. Pro covers Claude, Gemini and Cursor the same way \u2014 paste one URL, approve the consent screen on your own site, done. No config file to edit.<\/p>\n\n<p>Worth knowing: Pro does not change the no-middleman model. The OAuth server runs <strong>on your own site<\/strong>, not on ours \u2014 there is still no third-party cloud between your AI and your WordPress.<\/p>\n\n<p>Everything else on this page \u2014 all 16 built-in clients, every server, every access rule \u2014 is free.<\/p>\n\n<p>\u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-ai-connectors\/\">AI Connectors<\/a><\/p>\n\n<h4>16 Built-In AI Clients, Configured For You<\/h4>\n\n<p>Pick your client and the plugin renders the exact config file path, the exact top-level key that client expects, and copy-paste-ready JSON:<\/p>\n\n<p><strong>Claude Desktop<\/strong> \u00b7 <strong>Claude Code<\/strong> \u00b7 <strong>VS Code<\/strong> \u00b7 <strong>GitHub Copilot<\/strong> \u00b7 <strong>Codex<\/strong> \u00b7 <strong>Cursor<\/strong> \u00b7 <strong>Gemini CLI<\/strong> \u00b7 <strong>Cline<\/strong> \u00b7 <strong>Roo Code<\/strong> \u00b7 <strong>Kilo Code<\/strong> \u00b7 <strong>Amazon Q Developer<\/strong> \u00b7 <strong>OpenCode<\/strong> \u00b7 <strong>Antigravity<\/strong> \u00b7 <strong>Windsurf<\/strong> \u00b7 <strong>Zed<\/strong> \u00b7 and a <strong>Custom Client<\/strong> template for anything else that speaks MCP.<\/p>\n\n<p>Every one uses the same transport underneath, so nothing is second-class. A new client can be registered from your own code through a filter \u2014 no fork required.<\/p>\n\n<h4>What Your AI Can Actually Do<\/h4>\n\n<p>On its own, this plugin is the server, the security and the plumbing. Install the <strong>free<\/strong> companion <a href=\"https:\/\/wordpress.org\/plugins\/acrossai-abilities-manager\/\">AcrossAI Abilities Manager<\/a> and your AI gains <strong>357 abilities across 14 toolsets on any WordPress site<\/strong>, rising to <strong>over 800 across 32 toolsets<\/strong> as it detects the plugins you already run.<\/p>\n\n<ul>\n<li><strong>Content<\/strong> \u2014 create and update posts, pages and any custom post type with their meta and revisions; moderate comments; manage the media library, categories and tags; run semantic search to find related content and propose, review and apply internal links.<\/li>\n<li><strong>Blocks<\/strong> \u2014 read and surgically edit a page's block tree without rewriting the page, build from patterns, generate sections and landing pages, audit copy and design.<\/li>\n<li><strong>Appearance<\/strong> \u2014 theme.json and global styles, site-editor templates and template parts, navigation menus, widget areas, fonts, and site title, logo and icon.<\/li>\n<li><strong>Users<\/strong> \u2014 create and edit users, reset passwords, create roles, grant or revoke individual capabilities.<\/li>\n<li><strong>Configuration<\/strong> \u2014 read and write any option including values nested inside serialised arrays, change permalinks, and walk the admin menu to find which screen a setting lives on.<\/li>\n<li><strong>Database<\/strong> \u2014 inspect schema and table sizes, audit index health and bloated autoloaded options, EXPLAIN a slow query, optimise tables, or run a serialisation-safe search-and-replace.<\/li>\n<li><strong>Files<\/strong> \u2014 browse, read, write and delete files inside an administrator-defined allowlist; take and extract zip backups; read and edit wp-config constants; read the debug log.<\/li>\n<li><strong>Cron<\/strong> \u2014 see every scheduled task, spot the overdue ones, run one on demand, and prove whether WP-Cron is firing at all.<\/li>\n<li><strong>Updates<\/strong> \u2014 search the WordPress.org directory, install and update plugins, themes and core, roll back, and verify files against official checksums.<\/li>\n<li><strong>Diagnostics<\/strong> \u2014 Site Health, maintenance mode, recent fatal errors, un-pause what WordPress auto-disabled, and bisect a plugin conflict without ever writing <code>active_plugins<\/code>.<\/li>\n<li><strong>Cache<\/strong> \u2014 transients, object cache and rewrite rules.<\/li>\n<\/ul>\n\n<p><strong>Plugins you already run get dedicated toolsets<\/strong>, active only when that plugin is: WooCommerce, Elementor (and Pro), Rank Math, Yoast SEO, LiteSpeed Cache, Contact Form 7, WPCode, CookieYes, WP Mail SMTP, The Events Calendar, Event Tickets, Loco Translate, Classic Editor, Advanced Custom Fields, Akismet, WPForms, UpdraftPlus and All-in-One WP Migration.<\/p>\n\n<p>\u2192 <a href=\"https:\/\/acrossai.co\/integrations\/\">Browse every integration<\/a><\/p>\n\n<h4>Decide Exactly What Each AI Can Touch<\/h4>\n\n<p>Nobody should hand an AI assistant their whole site by default, so this plugin does not.<\/p>\n\n<ul>\n<li><strong>Tool curation<\/strong> \u2014 choose precisely which abilities a server advertises. A server can offer three tools or three hundred.<\/li>\n<li><strong>Per-ability exposure<\/strong> \u2014 switch individual abilities on or off per server, with search, filters and bulk actions, plus a server-level default for everything you have not decided individually.<\/li>\n<li><strong>Read-only servers are easy<\/strong> \u2014 roughly half the ability catalogue is annotated read-only and only about 13% is flagged destructive, so a \"look but don't touch\" server is a matter of filtering.<\/li>\n<li><strong>Permission override<\/strong> \u2014 an explicit, per-server opt-in that is off by default.<\/li>\n<\/ul>\n\n<p>\u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-tools-and-abilities\/\">Tools and abilities<\/a><\/p>\n\n<h4>Administrator-Only by Default<\/h4>\n\n<p>A brand-new MCP server requires <code>manage_options<\/code> until you say otherwise. Then gate it by <strong>user, role, capability, or your own policy provider<\/strong>. Every MCP request passes the gate \u2014 tool calls, resource reads and prompt requests alike \u2014 and denials are observable through hooks.<\/p>\n\n<p>The gate is deliberately <strong>fail-closed<\/strong>: if the access-control package is unavailable, a server falls back to administrator-only rather than opening up.<\/p>\n\n<p>\u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-access-control\/\">Access control<\/a><\/p>\n\n<h4>Run More Than One MCP Server<\/h4>\n\n<p>Create as many servers as you need, each with its own route, namespace, version, enable switch, tool set, ability exposure, access rules and connect message. One locked-down read-only server for a client's AI and one full-access server for yourself, on the same site, without interfering with each other.<\/p>\n\n<p>\u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-servers\/\">MCP servers<\/a><\/p>\n\n<h4>Three Ways to Connect<\/h4>\n\n<ul>\n<li><strong>MCP Client (npx bridge)<\/strong> \u2014 the default. Paste JSON into Claude Desktop, Cursor, VS Code and the rest. Uses <code>@automattic\/mcp-wordpress-remote<\/code> with an Application Password. \u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-connect-a-client\/\">Docs<\/a><\/li>\n<li><strong>CLI connections with browser approval<\/strong> \u2014 one command in the terminal, one click in the browser, zero password copying. Every approved, successful and failed attempt is recorded in a per-server audit log. Off by default. \u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-cli-connections\/\">Docs<\/a><\/li>\n<li><strong>WP-CLI (STDIO)<\/strong> \u2014 the client launches WP-CLI as a subprocess, so <strong>no credential crosses the network at all<\/strong>. Ideal for local development and CI. \u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-wp-cli-stdio\/\">Docs<\/a><\/li>\n<\/ul>\n\n<h4>AcrossAI Pro \u2014 the Optional Paid Add-On<\/h4>\n\n<p>Everything above this point is free. <a href=\"https:\/\/acrossai.co\/pricing\/\">AcrossAI Pro<\/a> is a separate plugin that adds the following, and nothing here is required to run an MCP server:<\/p>\n\n<ul>\n<li><strong>One-click AI connectors <em>(Pro)<\/em><\/strong> \u2014 <strong>ChatGPT<\/strong>, <strong>Claude<\/strong>, <strong>Grok<\/strong>, <strong>Gemini<\/strong> and <strong>Cursor<\/strong>. Paste one URL into the AI client, approve the consent screen on your own site, and you are connected. No config file, no Application Password to copy.<\/li>\n<li><strong>n8n connection \u2014 Beta <em>(Pro)<\/em><\/strong> \u2014 connect your site to n8n workflows using a generated bearer token or an Application Password, with a chosen lifetime and one-click revocation. Off by default, and labelled Beta in the plugin itself: n8n's own MCP OAuth credential is not yet OAuth 2.1 compliant, so this path is deliberately token-based rather than OAuth.<\/li>\n<li><strong>An OAuth 2.1 authorization server, on your own site <em>(Pro)<\/em><\/strong> \u2014 authorization and token endpoints, mandatory PKCE (S256), refresh-token rotation with reuse detection, dynamic client registration, and metadata discovery. The clients, tokens and authorization codes are rows in <strong>your<\/strong> database. This is what makes one-click connectors possible without a vendor relay.<\/li>\n<li><strong>Connections dashboard <em>(Pro)<\/em><\/strong> \u2014 see every AI client currently connected to each server, and revoke any one of them.<\/li>\n<li><strong>Membership-aware access control <em>(Pro)<\/em><\/strong> \u2014 gate an MCP server by membership or course enrolment instead of only by WordPress role, across <strong>10 platforms<\/strong>: BuddyBoss, MemberPress, LearnDash, LifterLMS, Paid Memberships Pro, Restrict Content Pro, WooCommerce Memberships, s2Member, Wishlist Member and Memberium.<\/li>\n<li><strong>276 more abilities <em>(Pro)<\/em><\/strong> \u2014 deep coverage for <strong>LearnDash<\/strong> (74), <strong>BuddyBoss<\/strong> (60), <strong>MailerPress<\/strong> (89 plus 28 for MailerPress Pro) and <strong>GeoDirectory<\/strong> (25), each active only when that plugin is.<\/li>\n<\/ul>\n\n<p>Pro keeps the same model as the free plugin: <strong>it runs on your own server, with no third-party cloud<\/strong>, and actions are never metered or credited. Plans start at a <strong>30-day free trial with no card required<\/strong>, and every plan carries a <strong>14-day money-back guarantee<\/strong>. Local and staging sites do not count against your site limit.<\/p>\n\n<p>\u2192 <a href=\"https:\/\/acrossai.co\/pricing\/\">Plans and pricing<\/a> \u00b7 <a href=\"https:\/\/acrossai.co\/docs\/mcp-ai-connectors\/\">AI Connectors docs<\/a><\/p>\n\n<h4>For Site Owners, Developers and Agencies<\/h4>\n\n<p><strong>Site owners<\/strong> write, edit and publish through conversation with the AI they already pay for, without learning a new admin screen and without their content touching a third party.<\/p>\n\n<p><strong>Developers<\/strong> get a real WordPress MCP server with a documented extension surface: register a client, a server tab, a connect method or a server type through filters, no fork required. WP-CLI STDIO keeps credentials off the network entirely on local boxes.<\/p>\n\n<p><strong>Agencies<\/strong> run a separate server per client site with its own access rules, hand each client an AI connection scoped to exactly what they should reach, and keep an audit log of terminal approvals.<\/p>\n\n<p>\u2192 <a href=\"https:\/\/acrossai.co\/use-cases\/\">Real-world use cases<\/a><\/p>\n\n<h4>Built on the WordPress Abilities API<\/h4>\n\n<p>WordPress 6.9 introduced the Abilities API so plugins can declare self-describing operations an AI can discover and run. This plugin exposes those abilities as MCP tools, which means <strong>any plugin that registers abilities becomes reachable by your AI with no custom integration<\/strong> \u2014 including your own.<\/p>\n\n<h4>Privacy and Data<\/h4>\n\n<p>The free plugin sends nothing anywhere. No analytics, no usage reporting, no external service.<\/p>\n\n<p>The only outbound connection is WordPress core's own plugin installer reaching WordPress.org, and only when <em>you<\/em> click to install a companion plugin from the setup wizard.<\/p>\n\n<p>Uninstalling is <strong>non-destructive by default<\/strong>: your servers, rules and logs survive unless you explicitly tick the delete-all-data option first.<\/p>\n\n<h4>Extend It<\/h4>\n\n<p>Clients, server tabs, connect methods and server types are all registered through filters \u2014 <code>acrossai_mcp_client_classes<\/code>, <code>acrossai_mcp_manager_server_tabs<\/code>, <code>acrossai_mcp_manager_connect_methods<\/code>, <code>acrossai_mcp_server_types<\/code> \u2014 plus action hooks on access-control denials and CLI approvals. Add your own from a plugin of your own.<\/p>\n\n<h4>Full Feature List<\/h4>\n\n<ul>\n<li>Self-hosted MCP server \u2014 your site is the endpoint, and the plugin makes zero outbound requests<\/li>\n<li>Multiple MCP servers per site, each independently routed, versioned and enabled<\/li>\n<li>16 built-in AI-client guides with copy-paste JSON and the exact config path per client<\/li>\n<li>Three transports: npx bridge, CLI browser-approval, and WP-CLI STDIO<\/li>\n<li>WordPress Application Passwords \u2014 generated in one click, revocable from your profile<\/li>\n<li>Per-server tool curation and per-ability exposure, with search, filters and bulk actions<\/li>\n<li>Per-server access control by user, role, capability or custom provider \u2014 administrator-only until you change it<\/li>\n<li>Per-server custom connect message for the AI client<\/li>\n<li>CLI connection audit log covering approved, successful and failed attempts<\/li>\n<li>Guided Quick Connect wizard, plus a full manual path<\/li>\n<li>Optional request logging through the free MCP Tracker plugin<\/li>\n<li>Tunable ability-discovery page size with a live token-cost estimate<\/li>\n<li>Non-destructive uninstall by default<\/li>\n<li>Filter-based extension surface for clients, tabs, connect methods and server types<\/li>\n<li>Works with the free AcrossAI Abilities Manager add-on for 357+ abilities across 14 toolsets<\/li>\n<\/ul>\n\n<p>Optionally, with <a href=\"https:\/\/acrossai.co\/pricing\/\">AcrossAI Pro<\/a>: one-click connectors for five AI vendors, an OAuth 2.1 server on your own site, a connections dashboard, membership-aware access control across 10 platforms, 276 more abilities, and an n8n connection in Beta. See the section above for detail.<\/p>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li>WordPress 7.0 or higher<\/li>\n<li>PHP 8.1 or higher<\/li>\n<li>WordPress Application Passwords (built into WordPress since 5.6; requires HTTPS)<\/li>\n<\/ul>\n\n<h3>Support<\/h3>\n\n<ul>\n<li><strong>Documentation<\/strong> \u2014 <a href=\"https:\/\/acrossai.co\/docs\/\">acrossai.co\/docs<\/a><\/li>\n<li><strong>MCP Manager docs<\/strong> \u2014 <a href=\"https:\/\/acrossai.co\/doc-category\/mcp-manager\/\">acrossai.co\/doc-category\/mcp-manager<\/a><\/li>\n<li><strong>Use cases<\/strong> \u2014 <a href=\"https:\/\/acrossai.co\/use-cases\/\">acrossai.co\/use-cases<\/a><\/li>\n<li><strong>Integrations<\/strong> \u2014 <a href=\"https:\/\/acrossai.co\/integrations\/\">acrossai.co\/integrations<\/a><\/li>\n<li><strong>Full changelog<\/strong> \u2014 <a href=\"https:\/\/acrossai.co\/changelog\/\">acrossai.co\/changelog<\/a><\/li>\n<li><strong>Troubleshooting &amp; FAQ<\/strong> \u2014 <a href=\"https:\/\/acrossai.co\/docs\/mcp-faq-troubleshooting\/\">acrossai.co\/docs\/mcp-faq-troubleshooting<\/a><\/li>\n<li><strong>Source code + issue tracker<\/strong> \u2014 <a href=\"https:\/\/github.com\/acrossai-co\/acrossai-mcp-manager\">github.com\/acrossai-co\/acrossai-mcp-manager<\/a><\/li>\n<\/ul>\n\n<h3>Support &amp; Contribution<\/h3>\n\n<p>For issues, feature requests, or contributions, visit the plugin repository.<\/p>\n\n<p>Questions? Check the FAQ section or look for documentation in the plugin settings page.<\/p>\n\n<h3>Development<\/h3>\n\n<p>This plugin follows WordPress coding standards and best practices:\n- PHP 7.4+ compatible\n- Full object-oriented architecture\n- Secure nonce verification\n- Proper capability checks\n- Sanitized input validation\n- Escaped output<\/p>\n\n<h3>License<\/h3>\n\n<p>This plugin is licensed under the GPL-2.0-or-later license. See LICENSE file for details.<\/p>\n\n<h3>Credits<\/h3>\n\n<p>MCP Manager is built with:\n- WordPress native APIs\n- Automattic's MCP WordPress Remote package\n- WordPress Application Passwords system<\/p>\n\n<p>Developed with \u2764\ufe0f for the WordPress community.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Go to <strong>Plugins \u2192 Add New<\/strong>, search for \"AcrossAI MCP Manager\", then click <strong>Install Now<\/strong> and <strong>Activate<\/strong>.<\/li>\n<li>The Quick Connect wizard opens automatically. Follow it, or close it and configure by hand.<\/li>\n<li>Manual path: open <strong>AcrossAI \u2192 MCP<\/strong>, open a server, choose how you want to connect, generate an Application Password, and copy the JSON into your AI client.<\/li>\n<li>Restart your AI client. It now sees your site.<\/li>\n<\/ol>\n\n<p>Global options \u2014 CLI connections, ability-discovery page size and uninstall behaviour \u2014 live under <strong>AcrossAI \u2192 Settings \u2192 MCP<\/strong>.<\/p>\n\n<p>To install manually, upload the plugin folder to <code>\/wp-content\/plugins\/<\/code> and activate it from the Plugins screen.<\/p>\n\n<!--section=faq-->\n<p>Full FAQ + troubleshooting lives at <a href=\"https:\/\/acrossai.co\/docs\/mcp-faq-troubleshooting\/\">acrossai.co\/docs\/mcp-faq-troubleshooting<\/a>. Quick answers below.<\/p>\n<dl>\n<dt id=\"is%20this%20plugin%20free%3F\"><h3>Is this plugin free?<\/h3><\/dt>\n<dd><p>Yes, entirely \u2014 and so is the <a href=\"https:\/\/wordpress.org\/plugins\/acrossai-abilities-manager\/\">AcrossAI Abilities Manager<\/a> add-on that supplies the abilities. Both are on WordPress.org under GPL.<\/p>\n\n<p>The only paid piece is <a href=\"https:\/\/acrossai.co\/pricing\/\">AcrossAI Pro<\/a>, which adds one-click connectors for ChatGPT, Claude, Grok, Gemini and Cursor, an n8n connection, an OAuth 2.1 server that runs on your own site, a connections dashboard, membership-aware access control across 10 platforms, and extra plugin toolsets. It starts with a 30-day free trial and no card. Everything else described on this page works without paying anyone.<\/p><\/dd>\n<dt id=\"does%20my%20content%20go%20to%20a%20third%20party%3F\"><h3>Does my content go to a third party?<\/h3><\/dt>\n<dd><p>No. The plugin makes no outbound HTTP requests of its own \u2014 no telemetry, no relay, no proxy. Your MCP endpoint is a route on your own site and your AI client talks to it directly; the <code>npx<\/code> bridge runs on your own machine. The only external call is WordPress core's plugin installer, and only when you click to install a companion plugin.<\/p><\/dd>\n<dt id=\"do%20i%20need%20an%20ai%20subscription%3F\"><h3>Do I need an AI subscription?<\/h3><\/dt>\n<dd><p>You need an AI client that speaks MCP, and you bring your own. This plugin never charges for AI usage and never runs inference \u2014 it exposes your WordPress site as a set of tools your AI can call.<\/p><\/dd>\n<dt id=\"which%20ai%20clients%20are%20supported%3F\"><h3>Which AI clients are supported?<\/h3><\/dt>\n<dd><p>Sixteen built-in clients ship with the free plugin \u2014 every one gets a ready-to-paste JSON snippet and its own tab:<\/p>\n\n<ul>\n<li>Claude Desktop<\/li>\n<li>Claude Code<\/li>\n<li>VS Code<\/li>\n<li>GitHub Copilot<\/li>\n<li>Codex<\/li>\n<li>Cursor<\/li>\n<li>Gemini CLI<\/li>\n<li>Windsurf<\/li>\n<li>Zed<\/li>\n<li>Cline<\/li>\n<li>Roo Code<\/li>\n<li>Kilo Code<\/li>\n<li>Amazon Q Developer<\/li>\n<li>OpenCode<\/li>\n<li>Antigravity<\/li>\n<li>Custom Client (template for any other MCP-compatible tool)<\/li>\n<\/ul>\n\n<p><strong>ChatGPT and Grok<\/strong> connect through the paid <strong>AcrossAI Pro<\/strong> add-on's one-click connectors <em>(Pro)<\/em>, which also cover Claude, Gemini and Cursor and run their OAuth on your own site rather than through anyone's cloud. Adding a brand-new client is a filter callback. See <a href=\"https:\/\/acrossai.co\/docs\/mcp-connect-a-client\/\">Connecting an AI client<\/a>.<\/p><\/dd>\n<dt id=\"can%20the%20ai%20break%20my%20site%3F\"><h3>Can the AI break my site?<\/h3><\/dt>\n<dd><p>It can only do what you allow. New servers are administrator-only until you add an access rule; you choose which abilities each server exposes at all; and every ability still runs WordPress's own capability check for the connecting user, so reaching it through MCP grants nothing extra.<\/p>\n\n<p>With the Abilities Manager add-on, roughly half the catalogue is annotated read-only and only about 13% is flagged destructive. Higher-risk operations require an explicit confirmation flag, search-and-replace is a dry run unless you say otherwise, file access is confined to an administrator-defined path allowlist, and secrets such as database credentials and auth salts are stripped out of file and log reads.<\/p><\/dd>\n<dt id=\"what%20can%20the%20ai%20actually%20do%20once%20connected%3F\"><h3>What can the AI actually do once connected?<\/h3><\/dt>\n<dd><p>With the free Abilities Manager add-on: 357 abilities across 14 toolsets on any site \u2014 content, blocks, appearance, users, configuration, database, files, cron, cache, updates and diagnostics \u2014 rising to over 800 across 32 toolsets as it detects plugins such as WooCommerce, Elementor, Rank Math, Yoast SEO, ACF and LiteSpeed Cache. Without the add-on, the plugin still serves whatever abilities WordPress and your other plugins have registered.<\/p><\/dd>\n<dt id=\"do%20i%20have%20to%20install%20the%20abilities%20manager%20add-on%3F\"><h3>Do I have to install the Abilities Manager add-on?<\/h3><\/dt>\n<dd><p>No. This plugin is a complete MCP server on its own and will expose any abilities registered by WordPress or other plugins. The add-on is what gives your AI a large, curated catalogue to work with, and the setup wizard offers to install it for you.<\/p><\/dd>\n<dt id=\"can%20i%20give%20one%20ai%20access%20to%20everything%20and%20another%20almost%20nothing%3F\"><h3>Can I give one AI access to everything and another almost nothing?<\/h3><\/dt>\n<dd><p>Yes \u2014 that is what multiple servers are for. Create a server per audience, curate its tools, set its ability exposure, and gate it by user, role or capability. They do not interfere with each other.<\/p><\/dd>\n<dt id=\"are%20my%20credentials%20secure%3F\"><h3>Are my credentials secure?<\/h3><\/dt>\n<dd><p>They are WordPress's native Application Passwords \u2014 generated by WordPress, tied to your user, shown once, never stored in this plugin's own tables, and revocable from your profile page. The CLI flow never puts a password in the terminal: you approve in a logged-in browser tab and the credential is issued to that approved session. Application Passwords require HTTPS. Full detail: <a href=\"https:\/\/acrossai.co\/docs\/mcp-application-passwords\/\">Application passwords &amp; security<\/a>.<\/p><\/dd>\n<dt id=\"can%20i%20connect%20multiple%20ai%20clients%20to%20the%20same%20site%3F\"><h3>Can I connect multiple AI clients to the same site?<\/h3><\/dt>\n<dd><p>Yes \u2014 generate a separate password (or CLI approval) per client. You can also run multiple MCP servers on the same site with different tool and ability sets and per-server access rules. See <a href=\"https:\/\/acrossai.co\/docs\/mcp-servers\/\">MCP servers<\/a>.<\/p><\/dd>\n<dt id=\"what%20is%20mcp%3F\"><h3>What is MCP?<\/h3><\/dt>\n<dd><p>The Model Context Protocol \u2014 an open standard introduced by Anthropic and adopted across the AI industry \u2014 lets an AI assistant discover and call tools on a service through one common interface. An MCP server exposes those tools; this plugin makes WordPress one.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20multisite%3F\"><h3>Does it work on multisite?<\/h3><\/dt>\n<dd><p>It works per site: each site in a network keeps its own servers, rules and credentials. There is no network-admin screen, so activate it per site rather than network-wide.<\/p><\/dd>\n<dt id=\"can%20i%20add%20my%20own%20ai%20client%20or%20connection%20method%3F\"><h3>Can I add my own AI client or connection method?<\/h3><\/dt>\n<dd><p>Yes. Clients, server tabs, connect methods and server types are all registered through filters, so you can add your own from a plugin without forking this one.<\/p><\/dd>\n<dt id=\"how%20do%20i%20revoke%20an%20ai%20client%27s%20access%3F\"><h3>How do I revoke an AI client's access?<\/h3><\/dt>\n<dd><p>Delete its Application Password from your WordPress profile page, or disable the MCP server from the servers list. Either takes effect immediately.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<p>The complete, formatted release history \u2014 including releases older than the ones shown here \u2014 lives at <a href=\"https:\/\/acrossai.co\/changelog\/\">acrossai.co\/changelog<\/a>. WordPress.org truncates this section, so the site is the fuller record.<\/p>\n\n<h4>0.3.7<\/h4>\n\n<ul>\n<li><strong>Fixed \u2014 a server could offer tools you never chose, and refuse to let you remove them.<\/strong> On some sites the plugin's database tables were missing columns the plugin expected, and had been for a long time. Nothing reported it: the missing settings simply read as \"on\", so a server could advertise three extra tools, and unchecking them said \"saved\" while changing nothing \u2014 the setting was being written to a column that did not exist. Affected sites now repair themselves on the next wp-admin page load. You do not need to do anything, and your own tool selections are left exactly as you set them.<\/li>\n<li><strong>Please note \u2014 reconnect your AI client afterwards.<\/strong> An AI client is handed its list of tools once, at the moment it connects, and there is no way to hand it a new one. So a repaired site serves the right tools immediately, but a client that was already connected keeps showing the old list until you disconnect and reconnect it. If the count still looks wrong after the repair, that is why.<\/li>\n<li><strong>Please note \u2014 the repair runs when someone opens wp-admin.<\/strong> It happens on the first admin page load after updating, with no reactivation needed. A site nobody ever signs into is not repaired, because nothing runs there to do it.<\/li>\n<li><strong>Fixed \u2014 a failed database change no longer records itself as done.<\/strong> Certain changes that could not be applied were nevertheless marked complete, which meant they were never retried and the site stayed wrong indefinitely. They now retry on the next admin page load.<\/li>\n<li><strong>Changed \u2014 the WordPress.org listing now describes what the plugin actually does.<\/strong> The description, feature list and FAQ were rewritten against the code, three claims that the plugin did not support were removed, and every screenshot is now captioned. No change to the plugin itself.<\/li>\n<\/ul>\n\n<h4>0.3.6<\/h4>\n\n<ul>\n<li><strong>Fixed \u2014 installing the AcrossAI Abilities Manager add-on now just works.<\/strong> Before this release, installing the add-on after this plugin changed nothing you could see: your server still offered the same few tools and nothing told you the larger set had arrived. Getting it took four undocumented steps \u2014 open <strong>Tools<\/strong>, change <strong>Server type<\/strong> to AcrossAI, confirm, then press <strong>Reset to Type Defaults<\/strong>. The cause was that the AcrossAI type shipped with an empty tool list, because this plugin did not know what belonged on it until the add-on turned up and said so. It knows now, so the list is written down in advance and the tools start working the moment the add-on is activated. No type change, no Reset, nothing to read.<\/li>\n<li><strong>New \u2014 the plugin creates a second server, **AcrossAI<\/strong>, alongside the default one.** It arrives <strong>disabled<\/strong>, listed after <strong>Default MCP Server<\/strong>, at <code>\/acrossai\/mcp<\/code>, and carries the AcrossAI toolsets from the start. Nothing is served until you enable it, and enabling it is your decision. If you do not want it, disable or delete it. (0.3.4 briefly added a similar server and 0.3.5 withdrew it \u2014 the row was never the problem, the tools it carried were. It returns with the right ones.)<\/li>\n<li><strong>Fixed \u2014 a fresh install created that server with no tools at all.<\/strong> Found by installing on a genuinely new site rather than by resetting an existing one. The plugin created its servers <em>before<\/em> creating the table their tool selections live in, so every selection was written into a table that did not exist yet \u2014 and the write reported success. Activation looked fine and the server arrived empty. Sites already affected are repaired automatically on the next wp-admin page load; a server you have curated yourself is left alone.<\/li>\n<li><strong>Changed \u2014 a server can be enabled before its add-on is installed, and says what it is waiting for.<\/strong> Previously such a server could not be switched on at all, which broke the <strong>Quick Connect<\/strong> wizard for exactly the person who had not installed the add-on yet. Now enabling records your intent, the admin shows which plugin is still missing, and installing that plugin makes the server live with no further clicks. Quick Connect will still not hand over a client configuration until then, and says why \u2014 a configuration pasted into Claude or Cursor too early connects and looks broken, and because AI clients cache their tool list when they connect, it would keep looking broken afterwards. A server whose type is <strong>unrecognised<\/strong> still cannot be enabled: no install fixes that one.<\/li>\n<li><strong>Fixed \u2014 the Tools tab now shows the tools your server is configured with.<\/strong> It was showing what the server is <em>serving right now<\/em>, so a server carrying fifteen tools could read \"Added as tools (1)\". Related fixes in the same screen: <strong>Reset to Type Defaults<\/strong>, <strong>Enable All<\/strong> and even adding a single tool could quietly delete the rest of your selection; the picker offered tools belonging to a different server type; and changing <strong>Server type<\/strong> appeared to work but reverted on the next page load.<\/li>\n<li><strong>New \u2014 you can write your own connect message.<\/strong> Every server sends a short briefing to an AI client when it connects, explaining what kind of server it is and which tool to call first. The <strong>Overview<\/strong> tab now offers <strong>System default<\/strong> (recommended, and kept up to date by the plugin) or <strong>Custom<\/strong>, prefilled with the message your server sends today so you can edit rather than start from nothing. Already-connected clients keep the message they received; new connections get yours.<\/li>\n<li><strong>Changed \u2014 every existing server gains **Server guide<\/strong>.** A one-time addition to servers created before it existed, so they get the tool that explains what the site actually contains. Your own tool selections are untouched.<\/li>\n<li><strong>Changed \u2014 a quieter admin.<\/strong> Warnings about a missing add-on now appear only once a server is actually enabled, rather than on a server that is switched off and serving nobody. Tools waiting on a plugin read as ordinary rows instead of a column of apologies. The Overview tab no longer repeats the client list and credential notes that belong on the Connect tab.<\/li>\n<li><strong>Removed \u2014 the **Backups<\/strong> toolset.** It was the one toolset named after a category rather than a plugin, covering UpdraftPlus and All-in-One WP Migration together, while every other integration is named for the plugin it serves. It is being rebuilt as one toolset per backup plugin. The backup abilities themselves are unchanged and stay in the add-on.<\/li>\n<li><strong>Internal \u2014 this plugin now owns the Toolset layer<\/strong> (the dispatchers behind <code>toolset\/content<\/code>, <code>toolset\/users<\/code> and the rest) instead of the add-on. <strong>Nothing changes for you:<\/strong> on a site running both plugins the add-on's copies still win and this plugin's stand down, verified by comparing the two side by side. The abilities themselves have not moved and stay in the add-on.<\/li>\n<li><strong>No database change.<\/strong> Schema stays at <code>1.1.7<\/code>; no table is added, altered or removed. The new server is an ordinary row, written on the first wp-admin page load after updating.<\/li>\n<\/ul>\n\n<h4>0.3.5<\/h4>\n\n<ul>\n<li><strong>Changed \u2014 a new server now arrives with its type's tools already selected.<\/strong> Creating a server, from either the classic form or the Quick Connect wizard, used to hand it the same three <code>mcp-adapter\/*<\/code> protocol tools whatever type you picked, because that is what the database columns default to. A type's tool set was only ever written when you pressed <strong>Reset to Type Defaults<\/strong>. A new MCP Adapter server now includes <strong>Server guide<\/strong> from the start, and a new AcrossAI server starts with the AcrossAI toolsets rather than the wrong three. Existing servers are untouched \u2014 where a type has tools a server does not, the Tools tab still offers them with a one-click <strong>Apply<\/strong>, and your own selection is never overwritten.<\/li>\n<li><strong>Changed \u2014 the plugin no longer creates a second MCP server.<\/strong> 0.3.4 added an AcrossAI-branded server at <code>acrossai\/mcp<\/code> on every site. It is not created any more: a second MCP endpoint appearing unasked is a decision that belongs to you, and the <strong>AcrossAI<\/strong> server <em>type<\/em> already covers it \u2014 create a server and choose that type when you want one. If your site already has that server it is left exactly as it is, still working, and it is now deletable like any other server rather than locked as plugin-managed. Servers list in the order they were created.<\/li>\n<li><strong>Changed \u2014 the Server type control is hidden when there is only one type to choose.<\/strong> With no add-on installed there is nothing to pick, so the create form and the Tools tab no longer show a dropdown whose only other option is unavailable. It returns the moment a second type is installed.<\/li>\n<li><strong>Internal \u2014 the full changelog moved to <code>changelog.txt<\/code>, shipped with the plugin.<\/strong> WordPress.org truncates a readme's changelog at 5,000 words and had begun cutting this one, so the readme now carries the recent releases and that file holds the complete history.<\/li>\n<li><strong>No database change.<\/strong> Schema stays at <code>1.1.7<\/code>; nothing is added, altered or removed on update.<\/li>\n<\/ul>\n\n<h4>0.3.4<\/h4>\n\n<ul>\n<li><strong>New + changed \u2014 the Tools tab now lists tools, and the Abilities tab lists abilities (F087).<\/strong> Two admin screens were each showing the wrong set. The per-server <strong>Tools<\/strong> tab offered all ~370 registered abilities in its left pool, even though abilities have not been advertised individually in <code>tools\/list<\/code> since 0.2.x \u2014 they reach AI clients <em>through<\/em> a handful of tool-level entries: the three <code>mcp-adapter\/*<\/code> protocol tools, and the <code>toolset\/*<\/code> dispatchers the AcrossAI Abilities Manager plugin registers (each one a router that takes <code>action=discover|info|execute<\/code> and forwards to a whole group of abilities). Meanwhile those same dispatchers cluttered the <strong>Abilities<\/strong> tab as ordinary rows with their own Exposed toggle, where a toggle on them either does nothing or breaks the protocol. Both screens now read from one declared list of tool-level abilities: the Abilities tab hides them, the Tools tab shows nothing else. The left pool is relabelled <strong>Available tools<\/strong> to match. Any plugin can declare its own through the new filter <code>apply_filters( 'acrossai_mcp_manager_tool_abilities', string[] $slugs )<\/code>, which is seeded with the three protocol tools; removing one of those puts it back on the Abilities tab. <strong>Behaviour change worth reading:<\/strong> on a site where no plugin hooks the filter, the Tools pool holds exactly the three protocol tools, so individual abilities can no longer be added as tools from that screen \u2014 use the existing <code>acrossai_mcp_manager_server_tools<\/code> filter to put one on a server in PHP. <strong>Nothing you already picked is lost:<\/strong> abilities already added to a server keep rendering in the \"Added as tools\" pane with their real labels, stay removable, and survive every save; they simply can't be re-added from the left pool once removed. The list is presentational \u2014 it changes neither per-server exposure, nor tool curation, nor call-time permission enforcement; every tool call is gated exactly as before. Contract and worked examples in <code>docs\/extending-abilities-tab.md<\/code>.<\/li>\n<li><strong>Changed \u2014 the plugin now keeps its own servers' details in step, and will undo edits to them.<\/strong> Before this release the plugin-managed server rows were written once and never revisited, so an edit to one stuck. They are now reconciled on each admin page load: <strong>name, description, route, route namespace and version are plugin-owned and get restored if they differ.<\/strong> If you renamed <strong>Default MCP Server<\/strong> or changed its description or route, that change is reverted on update \u2014 recreate it as your own server instead, where nothing will overwrite it. What stays yours: whether the server is <strong>enabled<\/strong>, its <strong>server type<\/strong>, and every <strong>tool and ability selection<\/strong> on it.<\/li>\n<li><strong>New \u2014 Server types, and Reset finally restores the right tools (F090).<\/strong> Every MCP server now records what type of server it is. This fixes a real defect: the Tools tab's <strong>Reset<\/strong> button restored the same three <code>mcp-adapter\/*<\/code> protocol tools on every server regardless of what that server was for, so on a server meant to serve the AcrossAI toolsets \"reset to defaults\" produced the <em>wrong<\/em> defaults and silently discarded the operator's selection. Reset now restores the server's own type's tool set. Two types ship: <strong>MCP Adapter<\/strong> (the three protocol tools) and <strong>AcrossAI<\/strong> (toolsets supplied by the AcrossAI Abilities Manager add-on). Every server that existed before this release is recorded as <strong>MCP Adapter<\/strong> and what it advertises is unchanged \u2014 byte for byte. New filter <code>apply_filters( 'acrossai_mcp_server_types', array $types )<\/code> lets any plugin contribute a type or replace a shipped one; contract and worked example in <code>docs\/extending-server-types.md<\/code>.<\/li>\n<li><strong>New \u2014 the AcrossAI type requires its add-on, and says so instead of failing quietly.<\/strong> A server whose type declares a requirement that is unmet cannot be <strong>enabled<\/strong>, and the refusal names the missing plugin rather than silently doing nothing. Enforcement is server-side on every route that can switch a server on \u2014 the single toggle, the bulk action, and the Quick Connect wizard \u2014 not in the interface alone. Two ways out are always offered: install the add-on, or change the server's type. <strong>Disabling is never blocked<\/strong>, so a server stranded by a deactivated add-on can always be switched off, and a running server is <strong>never auto-disabled<\/strong> \u2014 that would break a live AI client session instead of explaining itself.<\/li>\n<li><strong>New \u2014 a connected AI client is told what is wrong.<\/strong> If the add-on is deactivated underneath a server that was already enabled, the server keeps answering and advertises a single entry whose description names the plugin that must be installed. Its address does not 404 and the connection is not dropped. Curated tool selections are untouched throughout and return intact when the add-on is reactivated. One caveat worth knowing: a client holding a tool list from <em>before<\/em> the deactivation and calling one of those tools receives the MCP Adapter's own generic \"tool not found\" \u2014 that lookup happens inside the adapter before any plugin filter runs. Clients that re-list after an error, which is what most agents do, see the explanation.<\/li>\n<li><strong>New \u2014 bulk tool controls on the Tools tab, matching the Abilities tab.<\/strong> <strong>Enable All<\/strong>, <strong>Disable All<\/strong> and <strong>Reset to Type Defaults<\/strong>. Each is a one-time write to the server's tool selection, not a standing rule: \"Enable All\" adds every tool available to this server right now, and a tool-level ability registered <em>later<\/em> by a plugin you install in future is offered in the picker rather than added automatically. That is a deliberate choice \u2014 what a server serves is decided in exactly one place, the selection you can see on the tab, so what the screen shows and what an AI client receives cannot disagree. The confirmation dialog says a bulk action replaces the current selection, because it does.<\/li>\n<li><strong>Tools tab \u2014 says when a change has not reached connected AI clients yet.<\/strong> An MCP client caches the server's tool list at the moment it connects, and the protocol gives a WordPress server no way to reach one that is already connected: the MCP Adapter advertises <code>tools.listChanged: false<\/code> and its server-to-client channel is unimplemented. Measured against a real client, the notification is ignored even with both corrected. So after a change that alters what the server serves, the Tools tab now states plainly that already-connected clients keep the list they loaded and will see the change on their next session \u2014 rather than leaving you with a count that is not yet true for anyone connected. New connections get the change immediately. This is the companion to the AcrossAI Abilities Manager\u2019s <code>toolset\/integrations<\/code>, which keeps new capability reachable through a tool a connected client already holds: together, a stale list neither blocks anything nor goes unmentioned.<\/li>\n<li><strong>Changed \u2014 new servers are created as **MCP Adapter<\/strong>, and they arrive with that type's tools already selected.** Creating a server from either the classic form or the Quick Connect wizard now starts it on the MCP Adapter type; pick AcrossAI from the <strong>Server type<\/strong> dropdown when you want it. Servers list in the order they were created, with nothing pinned above anything else. Which type new servers start on is one declaration, <code>ServerTypes::seed()<\/code>'s <code>is_default<\/code> key, resolved everywhere through the existing <code>ServerTypes::default_slug()<\/code>.<\/li>\n<li><strong>Database \u2014 schema 1.1.7.<\/strong> Adds <code>server_type varchar(32) NOT NULL DEFAULT 'mcp-adapter'<\/code> to <code>{prefix}acrossai_mcp_servers<\/code>, applied automatically on the first wp-admin page load after updating. The column default is what backfills existing rows, so every pre-existing server keeps its current behaviour. Schema <code>1.1.7<\/code> also drops a <code>tools_default_policy<\/code> column, which <strong>you will not have<\/strong> if you are updating from 0.3.3 \u2014 it existed only between two development migrations and was never released. The coarse expose\/hide tool rule it backed was never honoured at call time, so a server could advertise a tool it then refused; the drop is there to clean up development installs. <code>abilities_default_policy<\/code> on the Abilities tab is a different setting and is unaffected.<\/li>\n<\/ul>\n\n<h4>0.3.3<\/h4>\n\n<ul>\n<li><strong>New \u2014 Per-server default ability policy (F082, #95).<\/strong> Each MCP server now carries a tri-state default policy: <strong>Use each ability's own default<\/strong> (the pre-F082 behaviour every existing server migrates to), <strong>Expose every ability by default<\/strong>, or <strong>Hide every ability by default<\/strong>. Clicking <strong>Enable All<\/strong> or <strong>Disable All<\/strong> on the per-server Abilities tab now flips this server-level policy \u2014 so abilities that a later plugin update or mu-plugin registers inherit the operator's intent automatically, without any admin action. Per-ability overrides still win over the default. Backwards-compatible: existing servers land on <strong>Use each ability's own default<\/strong> and every ability's effective exposure is byte-for-byte unchanged. New REST route <code>POST \/acrossai-mcp-manager\/v1\/servers\/{id}\/abilities\/policy<\/code> (permission_callback: <code>manage_options<\/code>). New action hook <code>acrossai_mcp_server_policy_changed( $server_id, $old_policy, $new_policy, $affected_slugs, $user_id )<\/code> fires on non-no-op transitions with a per-slug <code>[was, now]<\/code> diff map \u2014 policy-transition audit events carry the affected ability slugs and their exposure states, so choose audit-log integrations you trust. Row-only F030 permission-callback bypass semantics preserved verbatim via the SEC-001 rename <code>ExposureResolver::resolve()<\/code> \u2192 <code>resolve_row_only()<\/code>; the three-tier resolver used everywhere else is the new <code>resolve_effective()<\/code> sibling.<\/li>\n<li><strong>Cleanup \u2014 orphaned pre-F040 OAuth tables retired (F083).<\/strong> Older builds of this plugin created <code>wp_acrossai_mcp_oauth_clients<\/code>, <code>wp_acrossai_mcp_oauth_tokens<\/code>, <code>wp_acrossai_mcp_oauth_auth_codes<\/code>, and <code>wp_acrossai_mcp_connector_approved_users<\/code>. Feature 040 moved the OAuth subsystem to the paid companion, which creates its own fresh tables under the <code>acrossai_pro_mcp_*<\/code> namespace and only cleans up those names (it never reads, migrates, or drops the old ones) \u2014 leaving the old tables abandoned in place with no owner. This release cleans them up two ways. (1) Automatic: on the first wp-admin page load after updating, a one-shot routine drops each orphaned table <strong>only if it exists and is empty<\/strong> and deletes its stale <code>*_db_version<\/code> option; non-empty tables are never auto-dropped (their rows were never migrated anywhere) \u2014 instead the <code>acrossai_mcp_legacy_oauth_cleanup_skipped<\/code> action fires with a per-table row-count map so operators can decide. Re-trigger after emptying by deleting the <code>acrossai_mcp_legacy_oauth_cleanup_done<\/code> option. (2) Safety net: the four old-name tables are also restored to <code>uninstall.php<\/code>'s opt-in drop list (<code>DROP TABLE IF EXISTS<\/code>; cannot touch the companion's differently-named live tables). Operators who prefer manual cleanup can run, after confirming the tables are empty:\n    DROP TABLE IF EXISTS wp_acrossai_mcp_oauth_clients, wp_acrossai_mcp_oauth_tokens, wp_acrossai_mcp_oauth_auth_codes, wp_acrossai_mcp_connector_approved_users;\n    DELETE FROM wp_options WHERE option_name IN ('acrossai_mcp_oauth_clients_db_version', 'acrossai_mcp_oauth_tokens_db_version', 'acrossai_mcp_oauth_auth_codes_db_version', 'acrossai_mcp_connector_approved_users_db_version');\n(Adjust the <code>wp_<\/code> prefix to your site's table prefix. Do NOT touch <code>wp_acrossai_pro_mcp_*<\/code> tables \u2014 those belong to the active AcrossAI Pro plugin.)<\/li>\n<li><strong>UI \u2014 the five connection tabs merged into one (F084, #109).<\/strong> <strong>npm<\/strong>, <strong>MCP Clients<\/strong>, <strong>Connectors\/Integrations<\/strong>, <strong>n8n<\/strong> and <strong>WP-CLI<\/strong> all answered the same question \u2014 <em>how do I connect an AI client to this server?<\/em> \u2014 while sitting as five separate tabs in an eleven-tab strip. They are now one tab, labelled <strong>How would you like to connect?<\/strong>, with the five choices as a second-level row inside it: Connectors\/Integrations\/Plugins, MCP Client via config file, npm, n8n, WP-CLI. The top-level strip drops from 11 tabs to 8. <strong>Every existing link keeps working:<\/strong> the five old addresses (<code>?tab=npm<\/code>, <code>?tab=clients<\/code>, <code>?tab=ai-connectors<\/code>, <code>?tab=n8n<\/code>, <code>?tab=wp-cli<\/code>) resolve to the new tab with the right choice selected, and any deeper selection they carry (<code>&amp;client=<\/code>, <code>&amp;panel=<\/code>) is preserved \u2014 resolved in place, never via a redirect, so anything keyed to the requested address keeps working. On a local install the tab opens on <strong>MCP Client via config file<\/strong> rather than the first choice, since copying a client config is almost always the next step there and those configs carry a local-only TLS setting worth seeing early. The servers-list <strong>Connectors<\/strong> and <strong>MCP Clients<\/strong> row shortcuts point at the new addresses; the other three shortcuts are untouched. All three navigation rows now use one consistent WordPress tab styling, graded by size so the hierarchy reads at a glance. <strong>Requires AcrossAI Pro 0.9.10+<\/strong> if that add-on is active \u2014 the Connectors and n8n choices are supplied by it, and the two plugins must be updated together; an older Pro leaves those two as leftover top-level tabs until it is updated. Third-party plugins can contribute their own connection method through the new <code>acrossai_mcp_manager_connect_methods<\/code> filter (same entry shape as the existing tab filter, documented in <code>docs\/extending-per-server-tabs.md<\/code>).<\/li>\n<li><strong>Internal: <code>ACROSSAI_MCP_MANAGER_VERSION<\/code> constant + <code>Stable tag<\/code> bumped to <code>0.3.3<\/code> matching the plugin header.<\/strong> <code>Tested up to: 7.1<\/code> and <code>Requires at least: 7.0<\/code> unchanged from 0.3.2.<\/li>\n<\/ul>\n\n<h4>0.3.2<\/h4>\n\n<ul>\n<li><strong>UI + backend \u2014 F069 Quick Setup wizard renamed to \"Quick Connect via AcrossAI\" everywhere (F080, #97).<\/strong> Every admin surface (plugins.php row action, MCP Servers list page-title button + per-row pill, Settings-page sub-nav tab, admin-bar chip) now reads <strong>Quick Connect via AcrossAI<\/strong>. The AcrossAI parent-menu submenu and the wizard header itself use the shorter <strong>Quick Connect<\/strong> \u2014 those two surfaces already sit next to the AcrossAI logo \/ brand context, so the tail is redundant there (#100). Machine identifiers renamed to <code>quick-connect<\/code> in the same pass: URL query param (<code>?quick-connect=1<\/code>), REST routes (<code>\/quick-connect\/state|step|complete<\/code>), PHP namespace <code>AcrossAI_MCP_Manager\\Admin\\Partials\\QuickConnect<\/code>, class <code>QuickConnectController<\/code>, source directories <code>src\/js\/quick-connect\/<\/code> + <code>src\/scss\/quick-connect.scss<\/code>, asset directory <code>assets\/quick-connect\/<\/code>, JS bootstrap global <code>window.acrossaiMcpQuickConnect<\/code>, CSS classes <code>.acrossai-mcp-quick-connect-*<\/code>, transient key prefix <code>acrossai_mcp_manager_quick_connect_state_<\/code>. <strong>Breaking change \u2014 no backwards-compat shim:<\/strong> any operator bookmark against <code>?quick-setup=1<\/code> will 404; any external code calling the old REST route will 404; any in-flight wizard scratchpad transient at deploy time is orphaned (harmless \u2014 30 min TTL). Wizard state, entry-point behaviour, licensing gates, and all downstream integrations otherwise unchanged. Historical <code>README.txt<\/code> changelog entries for 0.3.0 \/ 0.3.1 that mention \"Quick Setup Wizard\" are intentionally left as-is \u2014 they describe what shipped under that name at merge time.<\/li>\n<li><strong>UI \u2014 Quick Connect wizard Step 10 now embeds the AcrossAI Pro per-connector walkthrough panels when the paid add-on is active (F081 + F082, #98 \/ #101 \/ #102).<\/strong> When acrossai-pro 0.9.4+ is installed, Step 10 renders the same rich per-vendor walkthrough (Claude \/ ChatGPT \/ Cursor \/ Gemini \/ Grok) that the per-server <strong>AI Connectors<\/strong> admin tab shows \u2014 three sub-boxes per client with numbered instructions, an inline <code>&lt;pre&gt;<\/code> command block for CLI paths, and a \"Still stuck? Full walkthroughs...\" docs footnote. F082 exposes the walkthrough HTML through its own discovery lane (<code>acrossai_mcp_manager_discovery_ai_connector_instructions<\/code>, mirroring the existing <code>..._ai_connectors<\/code> producer\/consumer pattern) rather than piggybacking on the connector DTO; the pro plugin emits the HTML with a <code>__ACROSSAI_MCP_URL__<\/code> sentinel that Step 10 substitutes with the currently-selected server's URL client-side just before rendering (HTML-escaped). Single source of truth: <code>*ConnectorProfile::get_mcp_url_setup_html()<\/code> on the pro side, consumed unchanged by both this wizard AND the pro plugin's own tab \u2014 if a vendor changes their onboarding flow, one edit updates both surfaces. The rich walkthrough renders BELOW the wizard's Back \/ Finish footer so the primary CTA stays visible without scrolling past the guide (#102 \u2014 new <code>useBelowFooter()<\/code> hook on <code>hooks\/useAdvanceGuard.js<\/code>, opt-in per step, zero effect on the other twelve). When acrossai-pro is missing or on a pre-F082 version, Step 10 falls back to today's rendering (MCP URL + Copy + \"Dynamic Client Registration only\" notice) \u2014 zero visual regression. Rendered via <code>dangerouslySetInnerHTML<\/code> trusting the paid plugin's <code>wp_kses_post<\/code> guarantee at the filter write boundary. Ports ~20 CSS rules from <code>acrossai-pro\/includes\/Connectors\/AbstractConnectorProfile::print_setup_styles()<\/code> into <code>src\/scss\/quick-connect.scss<\/code> with a source-of-truth comment banner \u2014 identical class names on both surfaces per D50 (cross-surface visual parity via shared markup contract, F077).<\/li>\n<li><strong>Compatibility \u2014 Tested up to WordPress 7.1.<\/strong> Minimum required version (<code>Requires at least: 7.0<\/code>) unchanged.<\/li>\n<li><strong>Internal: <code>ACROSSAI_MCP_MANAGER_VERSION<\/code> constant + <code>Stable tag<\/code> bumped to <code>0.3.2<\/code> matching the plugin header.<\/strong><\/li>\n<\/ul>\n\n<h4>0.3.1<\/h4>\n\n<ul>\n<li><strong>Docs \u2014 WordPress.org listing refresh: tags, short description, \"under a minute\" positioning, and supported-client roster updated.<\/strong> <code>Tags:<\/code> header replaced (<code>mcp, ai, claude, chatgpt, cursor<\/code> \u2192 <code>ai assistant, chatgpt, claude, mcp, mcp-server<\/code>). Short description reframed to lead with the \"Connect ChatGPT \/ Claude \/ Grok to WordPress in under a minute\" hook and cite the 16-client roster. Description opening paragraph gains a second lede sentence linking the <a href=\"https:\/\/acrossai.co\/mcp-manager-quick-setup\/\">Quick Setup wizard docs<\/a> and stating the under-a-minute end-to-end setup claim; the same link + claim also lead the \"How It Works\" section above the six-step manual flow (kept as an alternative for operators who prefer to do it by hand). Key Features connection-guides bullet and \"Which AI clients are supported?\" FAQ answer now enumerate all 16 built-in clients (Claude Desktop, Claude Code, VS Code, GitHub Copilot, Codex, Cursor, Gemini CLI, Windsurf, Zed, Cline, Roo Code, Kilo Code, Amazon Q Developer, OpenCode, Antigravity, Custom Client). Paid AcrossAI Pro OAuth Connectors (ChatGPT \/ Claude \/ Grok \/ Gemini \/ Cursor) are called out as a separate optional add-on. No behavioural change; readme-only refresh.<\/li>\n<li><strong>Fix \u2014 VS Code + GitHub Copilot user-level MCP config path corrected (F078).<\/strong> Previously shipped <code>~\/.vscode\/mcp.json<\/code> (Cursor's convention, not VS Code's). Now ships the documented macOS user-level path <code>~\/Library\/Application Support\/Code\/User\/mcp.json<\/code> for both clients. Instructions also mention the <code>Cmd\/Ctrl + Shift + P \u2192 \"MCP: Open User Configuration\"<\/code> menu entry. GitHub Copilot restart phrasing now correctly explains that Copilot Chat needs to be in Agent mode and VS Code auto-starts the server. Fix cites <a href=\"https:\/\/code.visualstudio.com\/docs\/agents\/reference\/mcp-configuration\">VS Code MCP docs<\/a> and <a href=\"https:\/\/code.visualstudio.com\/docs\/copilot\/customization\/mcp-servers\">Copilot MCP docs<\/a> \u2014 see <code>specs\/078-client-config-upstream-fixes\/research.md<\/code>. The audit that surfaced this fix (4 parallel research agents across all 16 clients) also verified 7 other clients had drift; those fixes are deferred to a follow-up PR pending review.<\/li>\n<li><strong>Fix \u2014 Local dev sites now auto-inject <code>NODE_TLS_REJECT_UNAUTHORIZED: \"0\"<\/code> into the copied MCP client JSON and surface an Automattic troubleshooting link (F075).<\/strong> When the environment looks local (<code>wp_get_environment_type()<\/code> returns <code>local<\/code> or <code>development<\/code>, or the host is <code>localhost<\/code> \/ <code>127.0.0.1<\/code> \/ <code>::1<\/code>, or ends with <code>.local<\/code> \/ <code>.test<\/code> \/ <code>.localhost<\/code>) \u2014 regardless of whether the site is served over HTTPS or plain HTTP \u2014 every generated client snippet (all 16 clients: Claude Desktop, Claude Code, Cursor, VS Code, GitHub Copilot, Codex, Gemini, Windsurf, Zed, Cline, Roo Code, Kilo Code, Amazon Q, OpenCode, Antigravity, Custom) now carries the flag in its <code>env<\/code> block, and a static warning notice above the JSON on both surfaces (per-server <strong>MCP Clients<\/strong> tab and Quick Setup wizard <strong>Step 11<\/strong>) explains what was added and why, with a link to Automattic's mcp-wordpress-remote troubleshooting doc. Fixes the \"MCP client connects but the tool list stays empty\" symptom on Local by Flywheel \/ MAMP \/ DDEV \/ wp-env style installs \u2014 the flag is the real fix when the local site uses HTTPS with a self-signed certificate, and a harmless no-op on plain HTTP (Node's HTTP client never runs TLS validation) \u2014 but the warning + doc link is useful in both cases. Live sites are unaffected: on a real production install (<code>wp_get_environment_type() = production<\/code>, non-local hostname), the injection does not occur and no notice renders. Ops teams that self-host on custom suffixes (<code>.docker<\/code>, <code>.internal<\/code>, <code>.dev<\/code>) can extend the host-suffix list via the new <code>acrossai_mcp_local_hostname_suffixes<\/code> filter. Internal refactor: all 16 clients' <code>env<\/code> arrays are now built via a shared <code>AbstractMCPClient::build_env()<\/code> helper \u2014 the previous 16-way duplication of the standard env-key list is retired in the same pass.<\/li>\n<li><strong>UI \u2014 Client picker emojis removed on both admin surfaces (F076).<\/strong> The per-server MCP Clients tab pill sub-nav and Quick Setup wizard Step 11 client-picker buttons now render each client's name only \u2014 no leading emoji glyph. The <code>get_icon()<\/code> methods on all 16 client classes stay defined (so companion plugins reading the ConnectionMethodRegistry DTO's <code>icon<\/code> field still see the value); only the two visible pickers stop rendering it.<\/li>\n<li><strong>UI \u2014 Per-server MCP Clients tab now uses the same numbered STEP 1..5 walkthrough as the Quick Setup wizard's Step 11 (F077).<\/strong> The admin tab's client-detail area is reorganized under STEP 1 (Generate the password) \u2192 STEP 2 (Open the config file) \u2192 STEP 3 (Locate the top-level key) \u2192 STEP 4 (Copy this config and paste it under the top-level key \u2014 includes the local-dev warning + JSON + Copy button) \u2192 STEP 5 (Restart the MCP client \u2014 client-specific action). Same content as before; consistent visual scaffolding between the two surfaces.<\/li>\n<li><strong>Internal: <code>ACROSSAI_MCP_MANAGER_VERSION<\/code> constant + <code>Stable tag<\/code> bumped to <code>0.3.1<\/code> matching the plugin header.<\/strong><\/li>\n<\/ul>\n\n<h4>Earlier versions<\/h4>\n\n<ul>\n<li>Entries for 0.3.0 and everything before it live in <code>changelog.txt<\/code>, shipped inside the plugin, and in the release history on GitHub: https:\/\/github.com\/acrossaico\/acrossai-mcp-manager\/releases<\/li>\n<\/ul>","raw_excerpt":"Self-hosted WordPress MCP server. Connect Claude, Cursor, VS Code, Copilot and 12 more AI clients. No relay, no middleman, no lock-in.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/300297","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=300297"}],"author":[{"embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/raftaar1191"}],"wp:attachment":[{"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=300297"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=300297"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=300297"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=300297"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=300297"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=300297"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}