{"id":293340,"date":"2026-04-24T15:59:09","date_gmt":"2026-04-24T15:59:09","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/webo-mcp\/"},"modified":"2026-09-26T12:21:17","modified_gmt":"2026-09-26T12:21:17","slug":"webo-mcp","status":"publish","type":"plugin","link":"https:\/\/tir.wordpress.org\/plugins\/webo-mcp\/","author":23464384,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"3.0.32","stable_tag":"3.0.32","tested":"7.1.2","requires":"6.4","requires_php":"8.0","requires_plugins":null,"header_name":"WEBO MCP","header_author":"Dinh WP","header_description":"MCP (Model Context Protocol) gateway for WordPress: JSON-RPC tools over the REST API for MCP clients.","assets_banners_color":"69877a","last_updated":"2026-09-26 12:21:17","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/webomcp.com","header_author_uri":"https:\/\/webomcp.com","rating":5,"author_block_rating":0,"active_installs":30,"downloads":3346,"num_ratings":3,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.0.28":{"tag":"2.0.28","author":"phuongwebo","date":"2026-04-25 08:06:45","revision":3515120},"2.0.29":{"tag":"2.0.29","author":"phuongwebo","date":"2026-04-28 18:29:53","revision":3517730},"2.0.34":{"tag":"2.0.34","author":"phuongwebo","date":"2026-05-04 20:29:27","revision":3522722},"2.0.35":{"tag":"2.0.35","author":"phuongwebo","date":"2026-05-04 20:53:17","revision":3522731},"2.0.40":{"tag":"2.0.40","author":"phuongwebo","date":"2026-05-05 22:31:15","revision":3523868},"2.0.45":{"tag":"2.0.45","author":"phuongwebo","date":"2026-05-08 14:51:09","revision":3526645},"2.1.0":{"tag":"2.1.0","author":"phuongwebo","date":"2026-05-08 16:12:27","revision":3526713},"2.1.10":{"tag":"2.1.10","author":"phuongwebo","date":"2026-07-14 05:12:59","revision":3606942},"2.1.11":{"tag":"2.1.11","author":"phuongwebo","date":"2026-05-12 11:41:34","revision":3529761},"2.1.12":{"tag":"2.1.12","author":"phuongwebo","date":"2026-05-12 13:25:56","revision":3529946},"2.1.13":{"tag":"2.1.13","author":"phuongwebo","date":"2026-05-12 16:54:17","revision":3530189},"2.1.14":{"tag":"2.1.14","author":"phuongwebo","date":"2026-05-13 20:58:26","revision":3531380},"2.1.17":{"tag":"2.1.17","author":"phuongwebo","date":"2026-05-19 16:00:43","revision":3537624},"2.1.19":{"tag":"2.1.19","author":"phuongwebo","date":"2026-05-24 16:15:10","revision":3546413},"2.1.3":{"tag":"2.1.3","author":"phuongwebo","date":"2026-05-08 17:55:21","revision":3526766},"2.1.4":{"tag":"2.1.4","author":"phuongwebo","date":"2026-07-14 05:12:59","revision":3606942},"2.1.9":{"tag":"2.1.9","author":"phuongwebo","date":"2026-07-14 05:12:59","revision":3606942},"2.2.0":{"tag":"2.2.0","author":"phuongwebo","date":"2026-05-27 14:39:20","revision":3550814},"2.2.1":{"tag":"2.2.1","author":"phuongwebo","date":"2026-05-27 20:52:37","revision":3551290},"2.3.0":{"tag":"2.3.0","author":"phuongwebo","date":"2026-05-28 15:27:37","revision":3552402},"2.3.1":{"tag":"2.3.1","author":"phuongwebo","date":"2026-05-29 09:38:59","revision":3553276},"2.3.2":{"tag":"2.3.2","author":"phuongwebo","date":"2026-05-29 17:09:44","revision":3553921},"2.3.3":{"tag":"2.3.3","author":"phuongwebo","date":"2026-05-29 17:39:37","revision":3553963},"2.3.4":{"tag":"2.3.4","author":"phuongwebo","date":"2026-05-29 17:56:19","revision":3553990},"2.3.5":{"tag":"2.3.5","author":"phuongwebo","date":"2026-05-29 18:00:40","revision":3553994},"2.3.6":{"tag":"2.3.6","author":"phuongwebo","date":"2026-05-29 18:16:18","revision":3554013},"2.3.7":{"tag":"2.3.7","author":"phuongwebo","date":"2026-05-29 18:23:27","revision":3554028},"2.4.0":{"tag":"2.4.0","author":"phuongwebo","date":"2026-05-29 18:31:00","revision":3554038},"2.4.1":{"tag":"2.4.1","author":"phuongwebo","date":"2026-05-29 18:33:27","revision":3554048},"2.4.2":{"tag":"2.4.2","author":"phuongwebo","date":"2026-05-29 20:26:04","revision":3554168},"2.4.4":{"tag":"2.4.4","author":"phuongwebo","date":"2026-05-29 22:30:30","revision":3554236},"2.4.5":{"tag":"2.4.5","author":"phuongwebo","date":"2026-06-02 14:58:01","revision":3558203},"2.4.6":{"tag":"2.4.6","author":"phuongwebo","date":"2026-06-04 12:46:25","revision":3560964},"2.4.7":{"tag":"2.4.7","author":"phuongwebo","date":"2026-06-07 05:29:16","revision":3563463},"2.4.8":{"tag":"2.4.8","author":"phuongwebo","date":"2026-06-08 14:24:22","revision":3564834},"2.5.5":{"tag":"2.5.5","author":"phuongwebo","date":"2026-06-18 17:47:14","revision":3577638},"2.5.6":{"tag":"2.5.6","author":"phuongwebo","date":"2026-06-20 04:05:48","revision":3579428},"2.5.7":{"tag":"2.5.7","author":"phuongwebo","date":"2026-06-21 08:31:34","revision":3580433},"2.5.8":{"tag":"2.5.8","author":"phuongwebo","date":"2026-06-22 07:04:32","revision":3581287},"2.5.9":{"tag":"2.5.9","author":"phuongwebo","date":"2026-07-04 02:04:57","revision":3595652},"2.6.10":{"tag":"2.6.10","author":"phuongwebo","date":"2026-07-14 14:27:57","revision":3607633},"2.6.11":{"tag":"2.6.11","author":"phuongwebo","date":"2026-07-14 14:46:56","revision":3607649},"2.6.12":{"tag":"2.6.12","author":"phuongwebo","date":"2026-07-14 16:18:48","revision":3607777},"2.6.13":{"tag":"2.6.13","author":"phuongwebo","date":"2026-07-14 17:08:49","revision":3607814},"2.6.14":{"tag":"2.6.14","author":"phuongwebo","date":"2026-07-14 17:49:51","revision":3607847},"2.6.15":{"tag":"2.6.15","author":"phuongwebo","date":"2026-07-14 20:09:28","revision":3607974},"2.6.16":{"tag":"2.6.16","author":"phuongwebo","date":"2026-07-17 07:44:25","revision":3611137},"2.6.3":{"tag":"2.6.3","author":"phuongwebo","date":"2026-07-05 08:47:38","revision":3596534},"2.6.4":{"tag":"2.6.4","author":"phuongwebo","date":"2026-07-05 08:59:00","revision":3596540},"2.6.8":{"tag":"2.6.8","author":"phuongwebo","date":"2026-07-14 05:12:59","revision":3606942},"2.6.9":{"tag":"2.6.9","author":"phuongwebo","date":"2026-07-14 14:02:59","revision":3607590},"3.0.0":{"tag":"3.0.0","author":"phuongwebo","date":"2026-07-23 18:13:33","revision":3620370},"3.0.18":{"tag":"3.0.18","author":"phuongwebo","date":"2026-08-20 09:36:40","revision":3656381},"3.0.2":{"tag":"3.0.2","author":"phuongwebo","date":"2026-08-13 02:06:33","revision":3644129},"3.0.22":{"tag":"3.0.22","author":"phuongwebo","date":"2026-09-05 01:29:36","revision":3681957},"3.0.3":{"tag":"3.0.3","author":"phuongwebo","date":"2026-08-14 18:39:59","revision":3647828},"3.0.32":{"tag":"3.0.32","author":"phuongwebo","date":"2026-09-26 12:21:17","revision":3714231},"3.0.5":{"tag":"3.0.5","author":"phuongwebo","date":"2026-08-15 21:35:35","revision":3649065},"3.0.6":{"tag":"3.0.6","author":"phuongwebo","date":"2026-08-15 21:53:50","revision":3649078},"3.0.7":{"tag":"3.0.7","author":"phuongwebo","date":"2026-08-17 17:46:29","revision":3651514}},"upgrade_notice":{"3.0.22":"<p>Security update. Upgrade immediately to prevent authenticated Author-level users from reading and republishing server-local files through the media upload tool.<\/p>","3.0.18":"<p>Multisite site admins can keep style and script tags in MCP content when Trusted raw HTML is enabled. Enable it under Settings \u2192 WEBO MCP \u2192 Security.<\/p>","2.3.2":"<p>Recommended for Claude Desktop and other MCP SDK clients: SSE keepalive, standard tools\/call content format, and safer AI editing via content checkpoint tools.<\/p>","2.3.1":"<p>Recommended compatibility update for installs using SCF or plugins that register abilities during activation.<\/p>","2.2.1":"<p>Recommended compatibility update for sites relying on bundled MCP schema classes or layered ability execution through MCP clients.<\/p>","2.1.23":"<p>Opt-in fix for multisite Elementor\/custom HTML workflows that need trusted administrators to preserve raw HTML tags. Disabled by default.<\/p>","2.1.17":"<p>Adds post password updates to <code>webo\/content-mutate<\/code> for protected content workflows.<\/p>","2.1.14":"<p>Recommended for multisite networks using child-site plugin activation through MCP; fixes WordPress capability checks after <code>switch_to_blog()<\/code>.<\/p>","2.1.13":"<p>Adds core plugin mutation plus child-site plugin activation\/deactivation via <code>site_id<\/code> or <code>blog_id<\/code> for multisite network admins.<\/p>","2.1.12":"<p>Adds MCP audit logging, optional tool allowlists, and an administrator health\/status tool. Existing MCP access remains unchanged unless allowlist enforcement is enabled in Settings.<\/p>","2.1.11":"<p>Recommended security hardening release: MCP tools now enforce object-level post\/media\/term capabilities and only list tools the current user can call.<\/p>","2.1.10":"<p>Registers the missing <strong><code>webo\/plugin-query<\/code><\/strong> tool (plugin inventory and updates via MCP). Recommended for automation that lists pending plugin updates.<\/p>","2.1.9":"<p>Internal refactor (standalone tool bootstrap file only). No MCP tool renaming; safe routine update.<\/p>","2.1.8":"<p>Critical for <code>webo.vn<\/code> \/ multi-BOM REST bodies: fixes BOM sanitizer regex so repeated UTF-8 BOM prefixes are actually removed.<\/p>","2.1.7":"<p>Recommended if MCP\/remote clients still hit <code>Unexpected token<\/code> \/ invalid JSON \u2014 BOM strip now defaults on for <strong>all<\/strong> REST API responses.<\/p>","2.1.6":"<p>Use this if MCP clients still fail JSON parse on <code>discover-abilities<\/code> \/ ability tools \u2014 BOM strip now covers <code>wp-abilities<\/code> REST routes.<\/p>","2.1.5":"<p>If MCP clients still parse-fail on BOM: this release starts the BOM-stripping buffer before <code>rest_api_init<\/code> for MCP-like URLs.<\/p>","2.1.4":"<p>Further hardening for leading-BOM MCP JSON failures: earlier buffer bootstrap on MCP-like REST URLs.<\/p>","2.1.3":"<p>Recommended if MCP clients show JSON parse errors (leading BOM) on <code>tools\/list<\/code> or <code>tools\/call<\/code> \u2014 response body is sanitized for MCP REST routes.<\/p>","2.1.2":"<p>Restores packaged agent <strong><code>skills\/<\/code><\/strong> in the upstream repo clone; upgrade if you rely on Cursor\/Codex skills from GitHub.<\/p>","2.1.1":"<p>Documentation-only refresh: use docs\/MCP_TOOL_MIGRATION.md when mapping old MCP tool names to dispatchers + <code>action<\/code>. No behavioral change vs 2.1.0 expected.<\/p>","2.0.40":"<p>Recommended update for MCP clients that batch process posts or rely on seo\/article-analysis; list-posts pagination and H1\/schema detection are more accurate.<\/p>","2.0.35":"<p>Adds theme discovery and theme switching tools for MCP clients. This release also carries the shortened WordPress.org short description into the new tagged version.<\/p>","2.0.34":"<p>Recommended update if you manage homepage reading settings via MCP; adds safe support for <code>show_on_front<\/code> and <code>page_on_front<\/code> updates.<\/p>","2.0.33":"<p>Documentation-only refresh on WordPress.org listings; recommended if you rely on the plugin directory description for onboarding.<\/p>","2.0.32":"<p>Recommended update for WP 6.9+ sites using Abilities API and MCP adapter integration.<\/p>","2.0.31":"<p>Maintenance update.<\/p>","2.0.30":"<p>Maintenance update.<\/p>","2.0.29":"<p>Maintenance update for runtime stability and cleaner CLI output. If you use WEBO MCP Pro, review\/update the Pro package compatibility notice before deploying this version to production.<\/p>","2.0.28":"<p>WordPress.org compliance update: readme now documents Google Suggest external service usage with Terms\/Privacy links, and nav-menu API loading no longer relies on WPINC.<\/p>","2.0.27":"<p>MCP clients must send WordPress Application Password (HTTP Basic) or use a logged-in session. API key\/HMAC alone are no longer sufficient when calling the router.<\/p>","2.0.26":"<p>Adds seo\/article-analysis for post-level SEO diagnostics (optional outbound suggest API; set no_autocomplete to skip).<\/p>","2.0.7":"<p>Readme and GitHub README now link webomcp.com and the n8n-nodes-webo-mcp npm package.<\/p>","2.0.6":"<p>License declaration aligned between readme and main plugin file for WordPress.org review.<\/p>","2.0.5":"<p>Plugin header updates for Plugin Check and WordPress.org tooling (@wordpress-plugin, GPLv2 license slug).<\/p>","2.0.4":"<p>Plugin header formatting for WordPress.org Plugin Check (Description, Version, License).<\/p>","2.0.3":"<p>Plugin Check and packaging fixes; upload the release zip from scripts\/build-release.ps1 for WordPress.org.<\/p>","2.0.2":"<p>Packaging and readme updates for WordPress.org review. Always upload the zip from scripts\/build-release.ps1, not the raw git folder.<\/p>","2.0.0":"<p>Major rename: reinstall from folder webo-mcp (or deploy to new path), then activate WEBO MCP. Settings are preserved via migration.<\/p>","1.1.1":"<p>Recommended update to fix tools\/call validation for core tools with no input.<\/p>","1.0.2":"<p>Recommended update to support active plugin verification via MCP tool.<\/p>","1.0.1":"<p>Recommended update to refresh plugin metadata and improve tools\/list compatibility.<\/p>","1.0.0":"<p>Initial public release of WEBO MCP (formerly WEBO WordPress MCP).<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":3},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3514777,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3514777,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.0.28","2.0.29","2.0.34","2.0.35","2.0.40","2.0.45","2.1.0","2.1.10","2.1.11","2.1.12","2.1.13","2.1.14","2.1.17","2.1.19","2.1.3","2.1.4","2.1.9","2.2.0","2.2.1","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7","2.4.0","2.4.1","2.4.2","2.4.4","2.4.5","2.4.6","2.4.7","2.4.8","2.5.5","2.5.6","2.5.7","2.5.8","2.5.9","2.6.10","2.6.11","2.6.12","2.6.13","2.6.14","2.6.15","2.6.16","2.6.3","2.6.4","2.6.8","2.6.9","3.0.0","3.0.18","3.0.2","3.0.22","3.0.3","3.0.32","3.0.5","3.0.6","3.0.7"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"MCP endpoint working in a REST client (initialize)","2":"tools\/list response with public tools","3":"tools\/call response for a WordPress tool"}},"plugin_section":[],"plugin_tags":[232494,569,69473,242115,253991],"plugin_category":[],"plugin_contributors":[261006],"plugin_business_model":[],"class_list":["post-293340","plugin","type-plugin","status-publish","hentry","plugin_tags-ai-agent","plugin_tags-automation","plugin_tags-json-rpc","plugin_tags-mcp","plugin_tags-model-context-protocol","plugin_contributors-phuongwebo","plugin_committers-phuongwebo"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/webo-mcp\/assets\/icon-128x128.png?rev=3514777","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>WEBO MCP securely connects authenticated AI agents and MCP-compatible clients to WordPress through JSON-RPC tools over REST. It provides bounded access to content, media, users, settings, site health, and extensible WordPress abilities while preserving native capability checks.<\/p>\n\n<p>Use Application Passwords or an authenticated WordPress session, discover tools with <code>tools\/list<\/code>, and invoke exact tools through <code>tools\/call<\/code>. Optional API-key, HMAC, scoped connector-token, allowlist, and audit controls are available for administrators. Documentation and ecosystem details: https:\/\/webomcp.com<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>This plugin does not send telemetry. MCP traffic is initiated by clients you configure. An administrator may explicitly activate or deactivate a separately installed paid add-on license from the WEBO MCP settings page; that action contacts webomcp.com. Some tools may perform outbound HTTP requests only when a client invokes them (for example seo\/article-analysis may request keyword suggestions from a third-party suggest API unless you pass no_autocomplete). Separately installed paid add-ons manage their own update checks; Core does not download or install their packages.<\/p>\n\n<p>The plugin stores the following options in the WordPress database when configured:\n- <code>webo_mcp_api_key<\/code>: API key used to authenticate MCP requests.\n- <code>webo_mcp_hmac_secret<\/code>: HMAC secret used to sign and validate MCP requests.\n- <code>webo_mcp_require_secondary_credentials<\/code>: when enabled, also require API key\/HMAC for Application Password and Bearer clients (off by default so standard connectors are not blocked).\n- <code>webo_mcp_url_connector_tokens<\/code>: hashed, expirable, revocable URL connector tokens for clients that cannot send headers. Raw tokens are shown once and are not stored.\n- <code>webo_mcp_tool_allowlist_enabled<\/code> and <code>webo_mcp_tool_allowlist_rules<\/code>: optional administrator-configured MCP tool allowlist policy.\n- <code>webo_mcp_audit_log_enabled<\/code>, <code>webo_mcp_audit_log_max_entries<\/code>, and <code>webo_mcp_audit_log<\/code>: bounded MCP tool-call audit log settings and compact audit events. Audit entries include user\/tool\/action\/status data, anonymized IPs, and hashed session IDs; they do not store request payloads, API keys, HMAC secrets, or Application Passwords.\n- <code>webo_mcp_installed_at<\/code> and <code>webo_mcp_review_notice<\/code>: local timestamps\/state for an optional WordPress.org review request notice (not sent off-site; dismissible).<\/p>\n\n<p>These Core options are removed when the plugin is uninstalled via the WordPress Plugins screen. If an administrator enters a paid add-on license, the license key and status are stored locally in that add-on's <code>webo_mcp_*_license_key<\/code> and <code>webo_mcp_*_license_status<\/code> options. Those shared add-on options are not deleted when Core is uninstalled, so separately installed add-ons retain their license state.<\/p>\n\n<h3>External services<\/h3>\n\n<p>When an administrator explicitly activates or deactivates a paid add-on license in WEBO MCP settings, Core sends an HTTPS POST to webomcp.com (WEBO MCP \/ \u0110inh WP) for Easy Digital Downloads license validation. The request includes the entered license key, add-on product ID, WordPress site URL, requested activation\/deactivation action, and a user-agent containing the Core version and site URL. Standard request metadata such as the server IP address is also sent. This is not triggered merely by activating Core. Separately installed paid add-ons may contact the same service for their own update checks and downloads; see their documentation. Service information: https:\/\/webomcp.com<\/p>\n\n<p>This plugin can connect to Google Suggest (Autocomplete) when a client calls the <code>seo\/article-analysis<\/code> tool and does not set <code>no_autocomplete<\/code> to true. This external request is used to return related keyword suggestions for SEO analysis.<\/p>\n\n<p>Service provider: Google LLC (Google Suggest \/ Autocomplete API endpoint).<\/p>\n\n<p>Data sent and when:\n- Sent only when <code>seo\/article-analysis<\/code> is called with autocomplete enabled.\n- Sends the analysis query text to <code>https:\/\/suggestqueries.google.com\/complete\/search<\/code> as the <code>q<\/code> parameter.\n- Sends standard HTTP request metadata such as IP address and User-Agent as part of the web request.<\/p>\n\n<p>Terms of Service: https:\/\/policies.google.com\/terms\nPrivacy Policy: https:\/\/policies.google.com\/privacy<\/p>\n\n<h3>Developer Hooks<\/h3>\n\n<p>The plugin exposes the following actions and filters for developers:<\/p>\n\n<h3>Actions<\/h3>\n\n<ul>\n<li><code>webo_mcp_register_tools<\/code>\nFired during plugin bootstrap after standalone tools are registered. Use this to register custom MCP tools from other plugins.<\/li>\n<\/ul>\n\n<h3>Filters<\/h3>\n\n<ul>\n<li><p><code>webo_mcp_current_user_can_use_mcp<\/code> (bool $allowed, int $user_id)\nGate for all MCP REST access. Default: super admin OR <code>manage_options<\/code> OR <code>edit_posts<\/code>. Override to tighten (e.g. super-admin only) in hardened installs.<\/p><\/li>\n<li><p><code>webo_mcp_secondary_credentials_exempt<\/code> (bool $exempt, WP_REST_Request $request)\nWhen true, skip optional API key \/ HMAC after WordPress auth. Default true for Application Password (Basic) and Bearer sessions unless Settings \u2192 Security \u2192 \u201cRequire for App Password \/ Bearer\u201d is enabled. Return false to always enforce <code>X-WEBO-*<\/code> headers.<\/p><\/li>\n<li><p><code>webo_mcp_allow_internal_tools<\/code> (bool $allow_internal, WP_REST_Request $request)\nControls whether internal tools are included in tools\/list responses. Defaults to false for public environments.<\/p><\/li>\n<li><p><code>webo_mcp_public_categories<\/code> (array $categories, WP_REST_Request $request, array $tool)\nFilters which tool categories are exposed as public. Defaults to array( 'wordpress' ).<\/p><\/li>\n<li><p><code>webo_mcp_rate_limit_per_hour<\/code> (int $limit, string $client, array|null $profile)\nAdjust effective hourly limit (fallback for both buckets).<\/p><\/li>\n<li><p><code>webo_mcp_rate_limit_read_per_hour<\/code> \/ <code>webo_mcp_rate_limit_mutate_per_hour<\/code> (int $limit, string $client, array|null $profile)\nPer-bucket limits after admin\/profile resolution.<\/p><\/li>\n<li><p><code>webo_mcp_tool_is_mutating<\/code> (bool $is_mutating, string $tool_name, array|null $tool_definition, array $arguments)\nOverride mutating classification for rate limits and read-only profiles.<\/p><\/li>\n<li><p><code>webo_mcp_tool_arguments_allow_extra<\/code> (bool $allow, string $tool_name, array $schema, array $arguments)\nWhen true, unknown tool argument keys are passed through (default false).<\/p><\/li>\n<li><p><code>webo_mcp_disallow_url_token_query<\/code> (bool $disallowed)\nBlock URL connector tokens in query strings (admin setting is the default source).<\/p><\/li>\n<li><p><code>webo_mcp_rest_bom_guard_json_api_requests<\/code> (bool $activate, string $uri_raw)\nOpt-in BOM sanitizer for all <code>\/wp-json\/<\/code> responses (default false; MCP routes only).<\/p><\/li>\n<li><p><code>webo_mcp_bridge_deny_patterns<\/code> (array $patterns)\nControls which abilities are excluded when auto-bridging abilities into MCP tools (e.g. bulk, themes\/, multisite\/).<\/p><\/li>\n<li><p><code>webo_mcp_auto_bridge_abilities<\/code> (bool $enabled)\nEnables or disables automatic bridging of registered abilities into MCP tools. Defaults to true; bridge mode still controls whether the bridge is off, layered, or full.<\/p><\/li>\n<li><p><code>webo_mcp_bridge_mode<\/code> (string $mode)\nControls Abilities bridge mode after the <code>WEBO_MCP_BRIDGE_MODE<\/code> constant and before the stored option. Values: <code>off<\/code>, <code>layered<\/code>, <code>full<\/code>. Default: <code>layered<\/code>.<\/p><\/li>\n<li><p><code>webo_mcp_enable_adapter<\/code> (bool $enabled)\nEnables or disables the bundled WordPress MCP Adapter runtime. Defaults to true.<\/p><\/li>\n<li><p><code>webo_mcp_validate_media_fetch_url<\/code> (true|\\WP_Error $ok, string $url, array $parsed)\nReject unsafe URLs for webo\/media-mutate upload action (return WP_Error to block).<\/p><\/li>\n<li><p><code>webo_mcp_tool_allowlist_allowed<\/code> (bool $allowed, string $tool_name, WP_REST_Request $request, array $params, array $allowed_tools)\nFilters the optional per-user\/role\/client allowlist decision.<\/p><\/li>\n<\/ul>\n\n<h4>Quick start<\/h4>\n\n<ol>\n<li>Upload the plugin folder to \/wp-content\/plugins\/webo-mcp<\/li>\n<li>Run composer install inside the plugin folder<\/li>\n<li>Activate the plugin in WordPress Admin<\/li>\n<li>Send JSON-RPC requests to POST \/wp-json\/mcp\/v1\/router<\/li>\n<\/ol>\n\n<p>For release packaging, use scripts\/build-release.ps1 to create a clean zip with .distignore exclusions.<\/p>\n\n<h3>Credits<\/h3>\n\n<p>Special thanks to the authors and open source projects that contributed to this plugin:\n- WordPress (https:\/\/wordpress.org)\n- Abilities API (https:\/\/github.com\/WordPress\/abilities-api)\n  Reference: https:\/\/make.wordpress.org\/ai\/2025\/07\/17\/abilities-api\/\n- MCP Adapter (https:\/\/github.com\/WordPress\/mcp-adapter)\n  Reference: https:\/\/make.wordpress.org\/ai\/2025\/07\/17\/mcp-adapter\/\n- Composer (https:\/\/getcomposer.org)\n- Other PHP and JS libraries from the community<\/p>\n\n<p>If you use this plugin, please give credit to the authors of these libraries.<\/p>\n\n<h3>License<\/h3>\n\n<p>This plugin is licensed under the GPLv2 or later.\nSee https:\/\/www.gnu.org\/licenses\/gpl-2.0.html for details.<\/p>\n\n<!--section=installation-->\n<p><strong>WEBO MCP<\/strong> is a WordPress MCP server \u2014 a complete <strong>Model Context Protocol<\/strong> gateway for WordPress. It lets AI agents and MCP-compatible clients (Claude Desktop, Cursor, Windsurf, n8n, and more) call well-defined tools over REST using JSON-RPC, instead of scraping the admin or sharing broad credentials.<\/p>\n\n<p>Official WEBO MCP website, documentation, and ecosystem hub: https:\/\/webomcp.com<\/p>\n\n<p><strong>Why use WEBO MCP as your WordPress MCP server?<\/strong><\/p>\n\n<ul>\n<li><strong>Token-optimized unified tools:<\/strong> every domain exposes two abilities \u2014 <code>*-query<\/code> (all reads) and <code>*-mutate<\/code> (all writes) \u2014 with a single <code>action<\/code> discriminator. <code>tools\/list<\/code> payload is up to 70% smaller than per-operation APIs, which means less of the model's context window is consumed by tool schemas, lower cost per session, and fewer hallucinated tool names.<\/li>\n<li>Primary router endpoint: <code>POST \/wp-json\/mcp\/v1\/router<\/code><\/li>\n<li>Standard MCP-style flow: <code>initialize<\/code> \u2192 <code>tools\/list<\/code> \u2192 <code>tools\/call<\/code><\/li>\n<li>Session lifecycle for clients (pass <code>session_id<\/code> or <code>Mcp-Session-Id<\/code> after <code>initialize<\/code>)<\/li>\n<li>Built-in tool registry for common WordPress operations (posts, media, terms, menus, options, and more)<\/li>\n<li>Bundled Abilities API + MCP Adapter integration, with automatic bridging from registered abilities to MCP tools (configurable)<\/li>\n<li>WordPress 7.0\/Core-aware bridge mode that uses Core Abilities\/API surfaces when available and falls back only when needed<\/li>\n<li>Public tool policy controls (category filters and optional allowlists) plus optional internal tool exposure for private environments<\/li>\n<li>Bounded MCP audit log, optional per-user\/role\/client tool allowlists, and a read-only administrator health\/status tool<\/li>\n<\/ul>\n\n<p><strong>Security model (high level)<\/strong><\/p>\n\n<ul>\n<li>MCP access requires a real WordPress user context: Application Password over HTTP Basic, or an existing logged-in session.<\/li>\n<li>Optional site-wide or per-user API key and HMAC can be enabled in Settings as an additional gate (they do not replace WordPress authentication). Generate\/rotate from Settings \u2192 Security; by default they are skipped for Application Password and Bearer clients unless you enable \u201cRequire for App Password \/ Bearer\u201d. Do not put the normal WEBO API key in URLs. For clients that cannot send headers, create a short-lived scoped <code>mcp_token<\/code> URL connector token in Settings -&gt; WEBO MCP.<\/li>\n<li>Default access expectations for the router and <code>GET \/wp-json\/webo-mcp\/v1\/tools<\/code>: users who are super admins, can <code>manage_options<\/code>, or can <code>edit_posts<\/code>, consistent with typical site operator and editor workflows (filterable).<\/li>\n<\/ul>\n\n<p><strong>Client guidance<\/strong><\/p>\n\n<p>Always discover tools before calling them: run <code>tools\/list<\/code>, pick an exact tool name from the response, validate required arguments, then call <code>tools\/call<\/code>. This reduces mistakes and keeps automation predictable in production.<\/p>\n\n<p><strong>Further documentation and optional integrations<\/strong><\/p>\n\n<ul>\n<li>Official website, documentation, and ecosystem notes: https:\/\/webomcp.com<\/li>\n<li>Optional n8n community node (separate package): https:\/\/www.npmjs.com\/package\/n8n-nodes-webo-mcp<\/li>\n<li>Release notes: see the changelog below. Documentation and migration guidance: https:\/\/webomcp.com<\/li>\n<li>Cross-addon dispatcher map (granular legacy names removed from discovery): docs\/MCP_TOOL_MIGRATION.md<\/li>\n<\/ul>\n\n<p>Compatibility note: any MCP-capable client can be used; which large language model runs inside the client is outside this plugin.<\/p>\n\n<p>Standalone core tools included:\n- Site info\n- Content (posts\/pages): <code>webo\/content-query<\/code> (list, get, find-by-url, search-replace, list-revisions, get-revision; with author\/date\/taxonomy filters) and <code>webo\/content-mutate<\/code> (create, update, delete, bulk-update-status, restore-revision, change-author)\n- Users: <code>webo\/list-users<\/code> and <code>webo\/user-mutate<\/code> (add-to-blog, set-role)\n- Media: <code>webo\/media-query<\/code> (list with search\/MIME\/post_id filters, get) and <code>webo\/media-mutate<\/code> (upload, update, delete)\n- Comments: <code>webo\/comment-query<\/code> (list, get) and <code>webo\/comment-mutate<\/code> (create, update, delete)\n- Taxonomy\/Terms: <code>webo\/taxonomy-query<\/code> (discover, list, get) and <code>webo\/taxonomy-mutate<\/code> (create, update, delete)\n- Nav menus: list menus, list menu items (menu_order, db_id), add menu link from post (explicit post_id + menu_order required)\n- Plugins: <code>webo\/plugin-query<\/code> (installed, active, updates, \u2026) and <code>webo\/plugin-mutate<\/code> (install, activate, deactivate; supports child-site <code>site_id<\/code> \/ <code>blog_id<\/code> activation for network admins)\n- Health: <code>webo\/health-status<\/code> (REST\/router status, Application Password support, permalinks, cron, object cache, plugin update summary, WordPress\/PHP versions, and redacted MCP config)\n- Client health: <code>webo\/client-health-report<\/code> (score 0\u2013100, grade A\u2013D, Markdown scoreboard for agency clients; hybrid foundation for Pro collectors later)\n- 404 logs: <code>webo\/get-404-logs<\/code> (read-only Rank Math \/ Redirection 404 monitor: url, hits, accessed, referrer)\n- Abilities bridge: <code>webo\/ability-query<\/code> and <code>webo\/ability-execute<\/code> in default layered mode. Only abilities with <code>meta.mcp.public === true<\/code> are visible and executable through WEBO MCP.\n- Themes: <code>webo\/theme-query<\/code> (installed themes) and <code>webo\/theme-mutate<\/code> (install from WordPress.org by slug, switch installed theme)\n- Theme context: <code>webo\/theme-context<\/code> (active theme info, block editor settings, style presets, registered blocks)\n- Block patterns: <code>webo\/block-patterns<\/code> (list\/get patterns, list\/get synced patterns)\n- Site stats: <code>webo\/site-stats<\/code> (overview, post counts, comment counts, user counts, media stats, activity summary)\n- Activity log: <code>webo\/activity-log<\/code> (list events, summary, clear)\n- User profile: <code>webo\/user-profile<\/code> (get own profile, update display name \/ bio \/ preferences)\n- Site settings: <code>webo\/site-settings<\/code> (get and update the 20 most common WordPress options via MCP)\n- Content search: <code>webo\/content-search<\/code> (full-text cross-post-type search with grouped results)\n- Menus: <code>webo\/menu-query<\/code>, <code>webo\/menu-mutate<\/code> (navigation menu items; not post\/CPT list order)\n- Post\/CPT order (optional): <code>webo\/reorder-query<\/code>, <code>webo\/reorder-mutate<\/code> when <a href=\"https:\/\/github.com\/mrphuong-webo\/webo-reorder\">Webo Reorder<\/a> is active \u2014 see docs\/abilities\/reorder.md\n- Options: get\/update (safe allowlist only), set site icon\/favicon from media\n- SEO (WordPress post): seo\/article-analysis \u2014 requires post_id; merges Rank Math meta when available (same data path as webo-rank-math\/get-post-seo-meta); optional related-keyword suggestions via outbound request unless no_autocomplete is true<\/p>\n\n<p>Excluded by default in standalone-safe mode:\n- Bulk\/mass execution tools\n- Plugin\/theme write-management abilities\n- Multisite-specific abilities<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"which%20endpoint%20should%20mcp%20clients%20use%3F\"><h3>Which endpoint should MCP clients use?<\/h3><\/dt>\n<dd><p>POST \/wp-json\/mcp\/v1\/router<\/p><\/dd>\n<dt id=\"where%20is%20the%20official%20website%20and%20the%20n8n%20package%3F\"><h3>Where is the official website and the n8n package?<\/h3><\/dt>\n<dd><p>The project hub is https:\/\/webomcp.com. For n8n, install the community node from npm: https:\/\/www.npmjs.com\/package\/n8n-nodes-webo-mcp<\/p><\/dd>\n<dt id=\"is%20webomcp.com%20the%20official%20webo%20mcp%20website%3F\"><h3>Is webomcp.com the official WEBO MCP website?<\/h3><\/dt>\n<dd><p>Yes. The official WEBO MCP website, documentation hub, and ecosystem landing page is https:\/\/webomcp.com.<\/p><\/dd>\n<dt id=\"can%20this%20run%20wordpress%20abilities%20by%20itself%3F\"><h3>Can this run WordPress abilities by itself?<\/h3><\/dt>\n<dd><p>Yes. On WordPress versions where Core provides the Abilities API, WEBO MCP uses Core and does not load a duplicate bundled Abilities API. On older WordPress versions it falls back to the bundled Composer package. The default bridge mode is <code>layered<\/code>, which exposes compact <code>webo\/ability-query<\/code> and <code>webo\/ability-execute<\/code> tools instead of one tool per ability. You can set bridge mode to <code>off<\/code>, <code>layered<\/code>, or <code>full<\/code> with <code>WEBO_MCP_BRIDGE_MODE<\/code>, the <code>webo_mcp_bridge_mode<\/code> filter, or the <code>webo_mcp_bridge_mode<\/code> option.<\/p><\/dd>\n<dt id=\"which%20abilities%20are%20exposed%20through%20webo%20mcp%3F\"><h3>Which abilities are exposed through WEBO MCP?<\/h3><\/dt>\n<dd><p>Only abilities that explicitly set <code>meta.mcp.public<\/code> to true are exposed. Execution also checks the ability permission callback, WEBO allowlist\/policy, and scope\/risk metadata such as <code>meta.webo_mcp.scope<\/code> and <code>meta.webo_mcp.risk<\/code>.<\/p><\/dd>\n<dt id=\"how%20do%20i%20migrate%20from%20legacy%20one-operation%20tool%20names%3F\"><h3>How do I migrate from legacy one-operation tool names?<\/h3><\/dt>\n<dd><p>Use <code>tools\/list<\/code> to discover the dispatcher tool names on your site, then pass the correct <code>action<\/code> (or query\/mutate discriminant) for each operation. Use docs\/MIGRATION_GUIDE_2.1.0.md for the 2.1.0 rollout narrative and docs\/MCP_TOOL_MIGRATION.md for a consolidated addon-by-addon map (Rank Math, Rocket, WooCommerce groups, etc.).<\/p><\/dd>\n<dt id=\"can%20i%20expose%20internal%20tools%3F\"><h3>Can I expose internal tools?<\/h3><\/dt>\n<dd><p>Yes, via filter webo_mcp_allow_internal_tools in private environments.<\/p><\/dd>\n<dt id=\"can%20i%20limit%20public%20tools%20by%20category%3F\"><h3>Can I limit public tools by category?<\/h3><\/dt>\n<dd><p>Yes, via filter webo_mcp_public_categories.<\/p><\/dd>\n<dt id=\"can%20i%20keep%20only%20wordpress.org-safe%20features%3F\"><h3>Can I keep only WordPress.org-safe features?<\/h3><\/dt>\n<dd><p>Yes. Default bridge rules exclude patterns for bulk, themes, and multisite abilities.<\/p><\/dd>\n<dt id=\"is%20this%20plugin%20suitable%20for%20production%3F\"><h3>Is this plugin suitable for production?<\/h3><\/dt>\n<dd><p>Yes, when used with proper authentication, TLS, and a limited tool exposure policy.<\/p><\/dd>\n<dt id=\"how%20do%20i%20authenticate%20mcp%20clients%3F\"><h3>How do I authenticate MCP clients?<\/h3><\/dt>\n<dd><p>Use a WordPress <strong>Application Password<\/strong> (Users \u2192 Profile \u2192 Application Passwords) and send it with HTTP Basic Auth (username = WordPress username, password = the application password). Optional <strong>API Key<\/strong> (<code>X-WEBO-API-KEY<\/code>) and <strong>HMAC<\/strong> (<code>X-WEBO-TIMESTAMP<\/code> + <code>X-WEBO-SIGNATURE<\/code>) are managed under Settings \u2192 WEBO MCP \u2192 Security (generate\/rotate; secrets are shown once). By default those optional headers are <strong>not<\/strong> required for Application Password or Bearer clients; enable \u201cRequire for App Password \/ Bearer\u201d if your client can send <code>X-WEBO-*<\/code> headers. HMAC signature: <code>sha256=<\/code> + HMAC-SHA256( <code>timestamp + \".\" + raw_body<\/code>, secret ), skew \u2264 300s. If a client cannot send headers, create a short-lived scoped URL connector token and pass it as <code>?mcp_token=...<\/code>; it is shown once, stored only as a hash, limited to an explicit tool scope, expirable, and revocable.<\/p><\/dd>\n<dt id=\"does%20webo%20mcp%20reorder%20posts%20and%20pages%3F\"><h3>Does WEBO MCP reorder posts and pages?<\/h3><\/dt>\n<dd><p>Use <strong><code>webo\/reorder-query<\/code><\/strong> and <strong><code>webo\/reorder-mutate<\/code><\/strong> when the separate <strong>Webo Reorder<\/strong> plugin is installed and active. Those tools control post <code>menu_order<\/code> and taxonomy-specific order \u2014 not navigation menus. For Appearance \u2192 Menus, use <strong><code>webo\/menu-query<\/code><\/strong> and <strong><code>webo\/menu-mutate<\/code><\/strong>. See <code>docs\/abilities\/reorder.md<\/code> in the plugin repository.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>3.0.32<\/h4>\n\n<ul>\n<li>Keep strict capability confirmation inside the mutation guard while forwarding <code>force<\/code> only when the callback schema accepts it.<\/li>\n<li>Move paid-addon update delivery into the separately distributed addons; Core no longer injects third-party packages into WordPress updates.<\/li>\n<li>Disclose opt-in addon license requests to webomcp.com.<\/li>\n<\/ul>\n\n<h4>3.0.31<\/h4>\n\n<ul>\n<li>Normalize schema-injected execution controls before hashing SEO runtime dry-run plans, keeping approved hashes stable through execution.<\/li>\n<li>Cover the Hub path where tool validation supplies default <code>force=false<\/code> and <code>remove=false<\/code> arguments.<\/li>\n<\/ul>\n\n<h4>3.0.30<\/h4>\n\n<ul>\n<li>Keep approved SEO plan hashes stable across plan and execute stages by excluding orchestration-only fields from business-argument normalization.<\/li>\n<li>Preserve content preconditions, fencing, idempotency, checkpoints, and verified readback while fixing false plan-hash mismatch rejections.<\/li>\n<\/ul>\n\n<h4>3.0.29<\/h4>\n\n<ul>\n<li>Add a default-off, Hub-orchestrated seo-runtime\/v1 execute path for title, content, and excerpt updates.<\/li>\n<li>Create and verify a content checkpoint before writing, then persist a site-local idempotency\/fencing receipt for replay-safe reconciliation.<\/li>\n<li>Return verified fingerprint, revision, and checkpoint evidence after readback; direct execution and unapproved plan hashes remain blocked.<\/li>\n<\/ul>\n\n<h4>3.0.28<\/h4>\n\n<ul>\n<li>Add preview-only seo-runtime\/v1 support to the exact webo\/content-mutate update provider, including stable resource identity, revision, and fingerprint readback.<\/li>\n<li>Keep explicit v1 dry-runs on the zero-write path and fail closed on v1 execute until durable idempotency and fencing persistence is available.<\/li>\n<\/ul>\n\n<h4>3.0.27<\/h4>\n\n<ul>\n<li>Reject opt-in legacy builder text\/style payloads before plain-text sanitization can strip inline style markers.<\/li>\n<\/ul>\n\n<h4>3.0.26<\/h4>\n\n<ul>\n<li>Add a unified License &amp; Updates center for installed commercial addons inside WEBO MCP settings.<\/li>\n<li>Connect the 13-product marketplace catalog to canonical EDD product IDs and existing addon license options.<\/li>\n<li>Deliver licensed addon releases through the normal WordPress updater while rejecting update packages unless EDD confirms a valid license.<\/li>\n<li>Keep license keys out of request URLs and rendered markup, with cached version checks to reduce storefront load.<\/li>\n<\/ul>\n\n<h4>3.0.25<\/h4>\n\n<ul>\n<li>Fixed addon Configure and nested menu links so settings screens retain their original WordPress screen hooks.<\/li>\n<\/ul>\n\n<h4>3.0.24<\/h4>\n\n<ul>\n<li>Added an integrated Add-ons marketplace inside WEBO MCP Settings.<\/li>\n<li>Shows active, installed, and available add-on states with direct configuration and purchase actions.<\/li>\n<li>Keeps commercial capabilities inside their add-ons while Core provides only catalog and navigation UI.<\/li>\n<\/ul>\n\n<h4>3.0.22<\/h4>\n\n<ul>\n<li>Security: block server-local paths in <code>webo-media\/upload-file<\/code>; accept only connector-rewritten file objects, validated remote URLs, or caller-provided file data.<\/li>\n<li>Preserve ChatGPT sandbox file rewriting without allowing Author-level users to read files from WordPress, uploads, or temporary directories.<\/li>\n<li>Fix the WordPress 7.1 Ability API identifier used for the legacy plugin mutation alias.<\/li>\n<li>Resolve all remaining WordPress Plugin Check findings for the resubmission package.<\/li>\n<\/ul>\n\n<p>Historical release notes are maintained in CHANGELOG.md in the public source repository.<\/p>","raw_excerpt":"WordPress MCP server for AI agents and automation, with JSON-RPC tools over REST for Claude, Cursor, n8n, and MCP clients.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/293340","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=293340"}],"author":[{"embeddable":true,"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/phuongwebo"}],"wp:attachment":[{"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=293340"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=293340"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=293340"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=293340"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=293340"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=293340"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}