
內容簡介
ByteCoreStack – MCP Connector for AI Tools 是一款 WordPress 外掛,將您的網站轉變為 Model Context Protocol (MCP) 伺服器,讓 AI 助手如 Claude、ChatGPT 和 Gemini 能夠直接連接並執行實際操作,而不僅僅是描述步驟。
【主要功能】
• 直接連接多種 AI 助手
• 自動撰寫和發佈文章
• 管理 WooCommerce 訂單與訂閱
• 修正 SEO 元數據
• 同步 FluentCRM 聯絡人
• 觸發 UpdraftPlus 備份
外掛標籤
開發者團隊
② 後台搜尋「ByteCoreStack – MCP Connector for AI Tools」→ 直接安裝(推薦)
原文外掛簡介
ByteCoreStack – MCP Connector for AI Tools is a WordPress AI plugin that turns your site into a Model Context Protocol (MCP) server, so AI assistants like Claude, ChatGPT, and Gemini can connect directly and take real action instead of just describing what to do.
Once connected, your AI agent can draft and publish posts, manage WooCommerce orders and subscriptions, fix SEO metadata, moderate comments, sync FluentCRM contacts, trigger UpdraftPlus backups, and update Elementor or Bricks pages — calling on 316+ WordPress AI tools across 26 categories, each checked against the connecting user’s real WordPress capabilities and logged in an Activity Log you control.
Authentication runs over OAuth 2.0 with PKCE, the same flow used by Google, Microsoft, and Slack — no shared API key, no third-party relay, and every action is capability-checked, logged, and reversible from Settings → Reset OAuth State.
See the Other Notes tab below for the full category breakdown, supported AI clients, security details, and setup instructions.
Links
Plugin homepage
Support forum
Model Context Protocol specification
What Can an AI Agent Do With WordPress?
“Draft and publish a blog post about [topic], generate a featured image, and tag it correctly.”
“Show me yesterday’s WooCommerce orders over $100 and refund order #1042.”
“Find every page with a missing or duplicate SEO title and fix it.”
“Duplicate this Elementor page, swap the hero image, and update the headline.”
“List my WooCommerce coupons expiring this month and extend them by two weeks.”
“Trigger an UpdraftPlus backup before I start a big content migration.”
Why Choose ByteCoreStack – MCP Connector for AI Tools for WordPress Automation?
316+ tools, 26 categories — one of the largest verified MCP tool sets for WordPress
Multi-client — works with Claude, ChatGPT, Gemini, Cursor, Windsurf, and any MCP 2025-11-25 client
Real OAuth 2.0 — full authorization code flow with PKCE, Dynamic Client Registration, and discovery endpoints — no shared API key
Conservative by design — no tool can create a WordPress user; role changes require promote_users
Local, redacted activity logging — every tool call is logged in your own database with sensitive values redacted
Zero telemetry, ever — no analytics or tracking of any kind
Grows with your stack — WooCommerce, ACF, Elementor, Bricks, Divi, Gravity Forms, WPForms, Ninja Forms, Contact Form 7, MemberPress, LearnDash, EDD, Redirection, UpdraftPlus, FluentCRM, BuddyPress, and The Events Calendar tools activate automatically when detected
Open to extend — register your own custom MCP tools with one function call
Ideal For
Agencies and freelancers who want to run day-to-day WordPress maintenance through an AI assistant instead of clicking through wp-admin one task at a time
WooCommerce store owners who want an AI agent that can check orders, adjust stock, manage coupons, and handle subscriptions on request
SEO teams and content editors running bulk metadata fixes, content audits, or multi-step publishing workflows
Developers who want a real WordPress AI integration to build custom AI automation and AI workflow tools on top of
Anyone already using Claude, ChatGPT, Cursor, or Windsurf who wants those tools to actually reach into WordPress instead of just describing what to do next
Supported AI Assistants & MCP Clients
Claude.ai — Settings → Integrations → Add integration → Custom MCP
Claude Desktop — add the MCP URL to claude_desktop_config.json under mcpServers
Claude Code — connects over the same Streamable HTTP MCP endpoint
ChatGPT — Settings → Connectors → Add connector → MCP Server
Gemini — connect via Google AI Studio MCP integrations
Cursor (0.45+) — Settings → MCP → Add New Server → HTTP (Streamable HTTP transport)
Windsurf — MCP settings panel, supports both Streamable HTTP and legacy SSE
VS Code, Cline, Continue, Zed, JetBrains and any other editor or IDE with MCP client support
Postman, Insomnia and other API tools with MCP request support
Any custom client or framework that implements the MCP 2025-11-25 specification
WordPress AI Tools by Category (316 Tools, Verified)
316 is the plugin’s total across every supported integration below. Tools marked (activates automatically) only appear to a connected AI client once the matching plugin is active on your site — see “My AI client shows fewer than 316+ tools — is that a bug?” in the FAQ above for how the count works.
Posts — 14 tools (create, read, update, delete, duplicate, bulk trash, schedule, search, count, post types & statuses, post format, password protection)
Pages — 8 tools (CRUD, duplicate, page templates)
Media — 11 tools (browse, upload from file or URL, update metadata, set featured image, regenerate thumbnails, attachment metadata, image sizes, count)
Taxonomies — 11 tools (categories, tags, custom taxonomies, term meta, term assignment)
Comments — 9 tools (CRUD, approve, spam, trash, bulk delete, pending queue)
Users — 11 tools (list, view, update, delete, sessions, roles, password reset, CSV export — no creation tool, by design)
Menus — 11 tools (menus, menu items, reordering, duplication, location assignment)
Plugins & Themes — 7 tools (list, activate, deactivate, active theme, theme mods, custom CSS)
SEO, Redirects & Content Quality — 12 tools (per-post and bulk SEO meta across 6 SEO plugins, site-wide SEO settings, URL redirects (requires Redirection), missing alt text, broken links, orphaned media, content gap audit)
Site / Options — 17 tools (site info, site health, full Site Health diagnostics, multisite status, permalink structure, plugin settings, database size, send email, cron jobs, rewrite rules, shortcode execution, plus post/user meta read/write/delete)
Content Structure & Revisions — 9 tools (post revision history and restore, permalink structure, reusable blocks, block parsing and patterns, registered sidebars and widgets)
Site Health & Diagnostics — 17 tools (cache detection/flush/purge, transients, server info, database size/optimize, search & replace, debug and error log, plugin/core update status, PHP runtime info, SSL certificate status, outgoing mail configuration (requires WP Mail SMTP))
WooCommerce (activates automatically) — 43 tools (products, variations, attributes, coupons, orders, refunds, customers, shipping zones, tax rates, store stats, sales report, top sellers, low-stock alerts, customer lifetime value, product performance, payment gateways, subscriptions, bookings)
Easy Digital Downloads (activates automatically) — 5 tools (products, orders, single order detail, customers, store stats)
Advanced Custom Fields (activates automatically) — 14 tools (field groups CRUD and duplication, full field group definitions, field values, field updates, options page read/write and discovery, repeater/flexible content row add/delete, Local JSON sync status)
Page Builders (activates automatically) — 11 tools across Elementor, Bricks, and Divi (clone page, bulk text replace, image swap, page outline, template import/listing, global widgets, raw page data)
Forms (activates automatically) — 15 tools across Gravity Forms, Contact Form 7, WPForms, Ninja Forms, Formidable Forms, Ultimate Member, and User Registration (list forms, read entries/submissions/fields, create/update Gravity Forms entries)
Backup & Migration (activates automatically) — 5 tools across UpdraftPlus, Duplicator, and All-in-One WP Migration (list backups/packages, trigger a backup, check job status)
Marketing & CRM (activates automatically) — 14 tools across FluentCRM, Mailchimp for WP, AffiliateWP, GiveWP, and WP Simple Pay (contacts, campaigns, lists, subscribers, affiliates, referrals, creatives, donation forms/donations/donors, payment forms)
Membership & LMS (activates automatically) — 12 tools across LearnDash, MemberPress, Restrict Content Pro, and WooCommerce Memberships (courses, course progress, enrollment, memberships, members, subscription history, grant a membership)
Community & Forums (activates automatically) — 12 tools across BuddyPress and bbPress (members, extended profile fields, activity stream, groups, group members, friends, forums, topics, replies)
The Events Calendar (activates automatically) — 9 tools (events CRUD, venues, organizers, event categories)
WPML / Polylang / TranslatePress (activates automatically) — 10 tools (list active languages, get/set a post’s language, get a post’s or a term’s translations, create a linked translation, plus Polylang String Translations and a translatable post types/taxonomies list (requires Polylang), and default/configured languages plus string translation search (requires TranslatePress))
Analytics (activates automatically) — 11 tools across Google Site Kit, WP Statistics, and MonsterInsights (Google Analytics report, top pages, AdSense earnings and Search Console queries via Site Kit; visit summary, top pages, online users, referrers, and browser/platform/country breakdown via WP Statistics; connection status and settings via MonsterInsights)
Developer & Import Tools (activates automatically) — 9 tools across WP All Import, WP All Export, Custom Post Type UI, and Code Snippets (import/export definitions, full post type & taxonomy CRUD through CPT UI, and a snippet audit list)
Security & Compliance (activates automatically) — 9 tools across Wordfence, Two Factor, CookieYes, Complianz, Akismet, Jetpack, and Sucuri Security (scan issues, firewall status, 2FA status per user, cookie consent status, spam stats, connection status)
ByteCoreStack – MCP Connector for AI Tools Key Features
316+ WordPress MCP tools across 26 categories — see the full breakdown above
OAuth 2.0 with PKCE — full authorization code flow with Dynamic Client Registration and discovery endpoints
Streamable HTTP transport (MCP 2025-11-25) with legacy SSE fallback for older clients
Activity log — every tool call recorded with client detection, filters, bulk delete, and CSV export; sensitive values redacted
Rate limiting — 60 requests/minute per IP on /mcp, enforced automatically
IP allowlist — optionally restrict MCP access to specific IPs or CIDR ranges
Admin dashboard — live server status, OAuth client count, today’s success/fail counts, and a searchable tools browser
WP Dashboard widget — 7-day activity sparkline right on your wp-admin home screen
Translation-ready — ships with a complete .pot file in /languages
Developer-friendly — extend with bcs_mcp_register_tool() or the bcs_mcp_tools filter
WooCommerce, Elementor, ACF & Forms Plugin Integration
Tools for these plugins are included in the box but only activate when the respective plugin is installed and active. No errors are thrown if a plugin is absent, and nothing extra needs configuring. The MCP tool list shown to a connected AI client only ever includes tools whose dependencies are actually satisfied on your site — so a site without WooCommerce simply never advertises WooCommerce tools to the AI. The same applies to WooCommerce Subscriptions, WooCommerce Bookings, UpdraftPlus, FluentCRM, BuddyPress, and The Events Calendar.
Multisite Support
ByteCoreStack – MCP Connector for AI Tools works on WordPress multisite networks the same way it works on a single site: each site in the network has its own settings, its own MCP endpoint, and its own Activity Log. There is no cross-site tool access — an AI client connected to one site can never reach another site’s data through this plugin. The wp_get_multisite_info tool reports network status and lists network sites for site owners who need it.
Extending ByteCoreStack – MCP Connector for AI Tools (Developer API)
Register custom tools from any plugin or theme:
bcs_mcp_register_tool( 'my_tool', 'Description', $schema, $callback );
Or use the bcs_mcp_tools filter directly to add, modify, or remove tools before they’re advertised to a connecting AI client.
Security & Permissions
All tool calls verify WordPress capabilities (current_user_can) before executing — an AI client can never do more than the authorizing user is allowed to do
No MCP tool can create new WordPress users — user accounts must be created through wp-admin, full stop
Role changes (wp_assign_user_role) require the promote_users capability, not just edit_users
OAuth tokens are SHA-256 hashed before database storage — plain tokens are never stored
PKCE (S256) is required for all authorization flows; plain challenges are rejected
Every /mcp request is rate-limited to 60 requests per minute per IP address (tracked by REMOTE_ADDR only — spoofable headers like X-Forwarded-For are never trusted for this check), returning HTTP 429 once exceeded
Dynamic Client Registration is separately rate-limited to 10 registrations per IP per minute, preventing abuse of the open registration endpoint
Sensitive meta keys (user_pass, session_tokens, and similar) are permanently blocked from read/write, with no setting to disable the block
The Activity Log stores tool name, timestamp, client, status, and the call’s parameters/result for audit purposes, all locally in your own database — any value that looks like a password, token, secret, or key is redacted before it’s written, and large content fields are truncated
Outbound image downloads validate URLs against a blocklist of private/loopback IP ranges (SSRF protection) and enforce a 20 MB size limit
All admin AJAX actions are protected by nonce verification and a manage_options capability check
Session termination (DELETE /mcp) requires a valid bearer token
CSV exports (wp_export_users_csv) neutralize spreadsheet formula-injection characters and escape embedded quotes before writing rows
Dynamic database table names are passed through $wpdb->prepare()‘s %i identifier placeholder rather than interpolated directly into query strings
The MCP server ships disabled by default — nothing is exposed until you explicitly enable it in Settings
External Services
This plugin operates primarily as an inbound API server — AI clients connect to it, not the other way around. No data is sent to any external service automatically or in the background.
Image download via wp_upload_media_from_url
The wp_upload_media_from_url MCP tool, when explicitly invoked by an authenticated AI client (e.g. Claude), makes a single outgoing HTTP GET request to download an image from the URL the AI client provides. This request:
Is only made when the tool is called by a connected, OAuth-authenticated MCP client
Carries no personal data beyond the image URL itself
Is validated against a blocklist of private/loopback IP ranges before the request is made
Is subject to a 20 MB size limit
No data is sent to the plugin author’s servers at any time. This plugin does not include analytics, telemetry, or tracking of any kind.
