BACK TO DIRECTORY

ByteCoreStack – MCP Connector for AI Tools

by ByteCore Stack

0.0
(0 ratings)

ByteCoreStack – MCP Connector for AI Tools is a WordPress AI plugin that turns your site into a Model Context Protocol (MCP) server, so AI assistants like Claude, ChatGPT, and Gemini can connect directly and take real action instead of just describing what to do.

Once connected, your AI agent can draft and publish posts, manage WooCommerce orders and subscriptions, fix SEO metadata, moderate comments, sync FluentCRM contacts, trigger UpdraftPlus backups, and update Elementor or Bricks pages — calling on 316+ WordPress AI tools across 26 categories, each checked against the connecting user’s real WordPress capabilities and logged in an Activity Log you control.

Authentication runs over OAuth 2.0 with PKCE, the same flow used by Google, Microsoft, and Slack — no shared API key, no third-party relay, and every action is capability-checked, logged, and reversible from Settings Reset OAuth State.

See the Other Notes tab below for the full category breakdown, supported AI clients, security details, and setup instructions.

Links

What Can an AI Agent Do With WordPress?

  • “Draft and publish a blog post about [topic], generate a featured image, and tag it correctly.”
  • “Show me yesterday’s WooCommerce orders over $100 and refund order #1042.”
  • “Find every page with a missing or duplicate SEO title and fix it.”
  • “Duplicate this Elementor page, swap the hero image, and update the headline.”
  • “List my WooCommerce coupons expiring this month and extend them by two weeks.”
  • “Trigger an UpdraftPlus backup before I start a big content migration.”

Why Choose ByteCoreStack – MCP Connector for AI Tools for WordPress Automation?

  • 316+ tools, 26 categories — one of the largest verified MCP tool sets for WordPress
  • Multi-client — works with Claude, ChatGPT, Gemini, Cursor, Windsurf, and any MCP 2025-11-25 client
  • Real OAuth 2.0 — full authorization code flow with PKCE, Dynamic Client Registration, and discovery endpoints — no shared API key
  • Conservative by design — no tool can create a WordPress user; role changes require promote_users
  • Local, redacted activity logging — every tool call is logged in your own database with sensitive values redacted
  • Zero telemetry, ever — no analytics or tracking of any kind
  • Grows with your stack — WooCommerce, ACF, Elementor, Bricks, Divi, Gravity Forms, WPForms, Ninja Forms, Contact Form 7, MemberPress, LearnDash, EDD, Redirection, UpdraftPlus, FluentCRM, BuddyPress, and The Events Calendar tools activate automatically when detected
  • Open to extend — register your own custom MCP tools with one function call

Ideal For

  • Agencies and freelancers who want to run day-to-day WordPress maintenance through an AI assistant instead of clicking through wp-admin one task at a time
  • WooCommerce store owners who want an AI agent that can check orders, adjust stock, manage coupons, and handle subscriptions on request
  • SEO teams and content editors running bulk metadata fixes, content audits, or multi-step publishing workflows
  • Developers who want a real WordPress AI integration to build custom AI automation and AI workflow tools on top of
  • Anyone already using Claude, ChatGPT, Cursor, or Windsurf who wants those tools to actually reach into WordPress instead of just describing what to do next

Supported AI Assistants & MCP Clients

  • Claude.ai — Settings Integrations Add integration Custom MCP
  • Claude Desktop — add the MCP URL to claude_desktop_config.json under mcpServers
  • Claude Code — connects over the same Streamable HTTP MCP endpoint
  • ChatGPT — Settings Connectors Add connector MCP Server
  • Gemini — connect via Google AI Studio MCP integrations
  • Cursor (0.45+) — Settings MCP Add New Server HTTP (Streamable HTTP transport)
  • Windsurf — MCP settings panel, supports both Streamable HTTP and legacy SSE
  • VS Code, Cline, Continue, Zed, JetBrains and any other editor or IDE with MCP client support
  • Postman, Insomnia and other API tools with MCP request support
  • Any custom client or framework that implements the MCP 2025-11-25 specification

WordPress AI Tools by Category (316 Tools, Verified)

316 is the plugin’s total across every supported integration below. Tools marked (activates automatically) only appear to a connected AI client once the matching plugin is active on your site — see “My AI client shows fewer than 316+ tools — is that a bug?” in the FAQ above for how the count works.

  • Posts — 14 tools (create, read, update, delete, duplicate, bulk trash, schedule, search, count, post types & statuses, post format, password protection)
  • Pages — 8 tools (CRUD, duplicate, page templates)
  • Media — 11 tools (browse, upload from file or URL, update metadata, set featured image, regenerate thumbnails, attachment metadata, image sizes, count)
  • Taxonomies — 11 tools (categories, tags, custom taxonomies, term meta, term assignment)
  • Comments — 9 tools (CRUD, approve, spam, trash, bulk delete, pending queue)
  • Users — 11 tools (list, view, update, delete, sessions, roles, password reset, CSV export — no creation tool, by design)
  • Menus — 11 tools (menus, menu items, reordering, duplication, location assignment)
  • Plugins & Themes — 7 tools (list, activate, deactivate, active theme, theme mods, custom CSS)
  • SEO, Redirects & Content Quality — 12 tools (per-post and bulk SEO meta across 6 SEO plugins, site-wide SEO settings, URL redirects (requires Redirection), missing alt text, broken links, orphaned media, content gap audit)
  • Site / Options — 17 tools (site info, site health, full Site Health diagnostics, multisite status, permalink structure, plugin settings, database size, send email, cron jobs, rewrite rules, shortcode execution, plus post/user meta read/write/delete)
  • Content Structure & Revisions — 9 tools (post revision history and restore, permalink structure, reusable blocks, block parsing and patterns, registered sidebars and widgets)
  • Site Health & Diagnostics — 17 tools (cache detection/flush/purge, transients, server info, database size/optimize, search & replace, debug and error log, plugin/core update status, PHP runtime info, SSL certificate status, outgoing mail configuration (requires WP Mail SMTP))
  • WooCommerce (activates automatically) — 43 tools (products, variations, attributes, coupons, orders, refunds, customers, shipping zones, tax rates, store stats, sales report, top sellers, low-stock alerts, customer lifetime value, product performance, payment gateways, subscriptions, bookings)
  • Easy Digital Downloads (activates automatically) — 5 tools (products, orders, single order detail, customers, store stats)
  • Advanced Custom Fields (activates automatically) — 14 tools (field groups CRUD and duplication, full field group definitions, field values, field updates, options page read/write and discovery, repeater/flexible content row add/delete, Local JSON sync status)
  • Page Builders (activates automatically) — 11 tools across Elementor, Bricks, and Divi (clone page, bulk text replace, image swap, page outline, template import/listing, global widgets, raw page data)
  • Forms (activates automatically) — 15 tools across Gravity Forms, Contact Form 7, WPForms, Ninja Forms, Formidable Forms, Ultimate Member, and User Registration (list forms, read entries/submissions/fields, create/update Gravity Forms entries)
  • Backup & Migration (activates automatically) — 5 tools across UpdraftPlus, Duplicator, and All-in-One WP Migration (list backups/packages, trigger a backup, check job status)
  • Marketing & CRM (activates automatically) — 14 tools across FluentCRM, Mailchimp for WP, AffiliateWP, GiveWP, and WP Simple Pay (contacts, campaigns, lists, subscribers, affiliates, referrals, creatives, donation forms/donations/donors, payment forms)
  • Membership & LMS (activates automatically) — 12 tools across LearnDash, MemberPress, Restrict Content Pro, and WooCommerce Memberships (courses, course progress, enrollment, memberships, members, subscription history, grant a membership)
  • Community & Forums (activates automatically) — 12 tools across BuddyPress and bbPress (members, extended profile fields, activity stream, groups, group members, friends, forums, topics, replies)
  • The Events Calendar (activates automatically) — 9 tools (events CRUD, venues, organizers, event categories)
  • WPML / Polylang / TranslatePress (activates automatically) — 10 tools (list active languages, get/set a post’s language, get a post’s or a term’s translations, create a linked translation, plus Polylang String Translations and a translatable post types/taxonomies list (requires Polylang), and default/configured languages plus string translation search (requires TranslatePress))
  • Analytics (activates automatically) — 11 tools across Google Site Kit, WP Statistics, and MonsterInsights (Google Analytics report, top pages, AdSense earnings and Search Console queries via Site Kit; visit summary, top pages, online users, referrers, and browser/platform/country breakdown via WP Statistics; connection status and settings via MonsterInsights)
  • Developer & Import Tools (activates automatically) — 9 tools across WP All Import, WP All Export, Custom Post Type UI, and Code Snippets (import/export definitions, full post type & taxonomy CRUD through CPT UI, and a snippet audit list)
  • Security & Compliance (activates automatically) — 9 tools across Wordfence, Two Factor, CookieYes, Complianz, Akismet, Jetpack, and Sucuri Security (scan issues, firewall status, 2FA status per user, cookie consent status, spam stats, connection status)

ByteCoreStack – MCP Connector for AI Tools Key Features

  • 316+ WordPress MCP tools across 26 categories — see the full breakdown above
  • OAuth 2.0 with PKCE — full authorization code flow with Dynamic Client Registration and discovery endpoints
  • Streamable HTTP transport (MCP 2025-11-25) with legacy SSE fallback for older clients
  • Activity log — every tool call recorded with client detection, filters, bulk delete, and CSV export; sensitive values redacted
  • Rate limiting — 60 requests/minute per IP on /mcp, enforced automatically
  • IP allowlist — optionally restrict MCP access to specific IPs or CIDR ranges
  • Admin dashboard — live server status, OAuth client count, today’s success/fail counts, and a searchable tools browser
  • WP Dashboard widget — 7-day activity sparkline right on your wp-admin home screen
  • Translation-ready — ships with a complete .pot file in /languages
  • Developer-friendly — extend with bcs_mcp_register_tool() or the bcs_mcp_tools filter

WooCommerce, Elementor, ACF & Forms Plugin Integration

Tools for these plugins are included in the box but only activate when the respective plugin is installed and active. No errors are thrown if a plugin is absent, and nothing extra needs configuring. The MCP tool list shown to a connected AI client only ever includes tools whose dependencies are actually satisfied on your site — so a site without WooCommerce simply never advertises WooCommerce tools to the AI. The same applies to WooCommerce Subscriptions, WooCommerce Bookings, UpdraftPlus, FluentCRM, BuddyPress, and The Events Calendar.

Multisite Support

ByteCoreStack – MCP Connector for AI Tools works on WordPress multisite networks the same way it works on a single site: each site in the network has its own settings, its own MCP endpoint, and its own Activity Log. There is no cross-site tool access — an AI client connected to one site can never reach another site’s data through this plugin. The wp_get_multisite_info tool reports network status and lists network sites for site owners who need it.

Extending ByteCoreStack – MCP Connector for AI Tools (Developer API)

Register custom tools from any plugin or theme:

bcs_mcp_register_tool( 'my_tool', 'Description', $schema, $callback );

Or use the bcs_mcp_tools filter directly to add, modify, or remove tools before they’re advertised to a connecting AI client.

Security & Permissions

  • All tool calls verify WordPress capabilities (current_user_can) before executing — an AI client can never do more than the authorizing user is allowed to do
  • No MCP tool can create new WordPress users — user accounts must be created through wp-admin, full stop
  • Role changes (wp_assign_user_role) require the promote_users capability, not just edit_users
  • OAuth tokens are SHA-256 hashed before database storage — plain tokens are never stored
  • PKCE (S256) is required for all authorization flows; plain challenges are rejected
  • Every /mcp request is rate-limited to 60 requests per minute per IP address (tracked by REMOTE_ADDR only — spoofable headers like X-Forwarded-For are never trusted for this check), returning HTTP 429 once exceeded
  • Dynamic Client Registration is separately rate-limited to 10 registrations per IP per minute, preventing abuse of the open registration endpoint
  • Sensitive meta keys (user_pass, session_tokens, and similar) are permanently blocked from read/write, with no setting to disable the block
  • The Activity Log stores tool name, timestamp, client, status, and the call’s parameters/result for audit purposes, all locally in your own database — any value that looks like a password, token, secret, or key is redacted before it’s written, and large content fields are truncated
  • Outbound image downloads validate URLs against a blocklist of private/loopback IP ranges (SSRF protection) and enforce a 20 MB size limit
  • All admin AJAX actions are protected by nonce verification and a manage_options capability check
  • Session termination (DELETE /mcp) requires a valid bearer token
  • CSV exports (wp_export_users_csv) neutralize spreadsheet formula-injection characters and escape embedded quotes before writing rows
  • Dynamic database table names are passed through $wpdb->prepare()‘s %i identifier placeholder rather than interpolated directly into query strings
  • The MCP server ships disabled by default — nothing is exposed until you explicitly enable it in Settings

External Services

This plugin operates primarily as an inbound API server — AI clients connect to it, not the other way around. No data is sent to any external service automatically or in the background.

Image download via wp_upload_media_from_url

The wp_upload_media_from_url MCP tool, when explicitly invoked by an authenticated AI client (e.g. Claude), makes a single outgoing HTTP GET request to download an image from the URL the AI client provides. This request:

  • Is only made when the tool is called by a connected, OAuth-authenticated MCP client
  • Carries no personal data beyond the image URL itself
  • Is validated against a blocklist of private/loopback IP ranges before the request is made
  • Is subject to a 20 MB size limit

No data is sent to the plugin author’s servers at any time. This plugin does not include analytics, telemetry, or tracking of any kind.

Screenshots

Admin dashboard — server status, today's stats, and recent activity feed.

Admin dashboard — server status, today's stats, and recent activity feed.

Tools browser — every tool, most-used tool in the last 28 days, and quick docs.

Tools browser — every tool, most-used tool in the last 28 days, and quick docs.

Tool detail view — tool name, method, and a plain-English explanation.

Tool detail view — tool name, method, and a plain-English explanation.

Settings page — enable the MCP server, copy your endpoint URL, and setup guides per AI client.

Settings page — enable the MCP server, copy your endpoint URL, and setup guides per AI client.

Activity Log — filter by client, status, and date range, with color-coded tags and CSV export.

Activity Log — filter by client, status, and date range, with color-coded tags and CSV export.

WP Dashboard widget — a 7-day activity sparkline on your wp-admin home screen.

WP Dashboard widget — a 7-day activity sparkline on your wp-admin home screen.

Claude connector page — tools list and permission settings for the connection.

Claude connector page — tools list and permission settings for the connection.

Plugin Details

Active Installs
40
Total Downloads
625
Version
1.2.1
Requires WP
6.2
Requires PHP
7.4
Tested Up To
7.0.4
Added
2026-07-06
Last Updated
2026-08-18 1:23pm GMT

Ratings

5
0
4
0
3
0
2
0
1
0