WordPress plugin profile

Secure MCP Server for Claude, ChatGPT, Gemini and other AI providers

The #1 secure WordPress MCP server for connecting Claude, ChatGPT, & AI agents (MCP Clients) with 300+ tools for WooCommerce, Elementor, audit log …

Version1.4.9
Active installs1K+
Rating5.0 / 5
Tested toWP 7.1

About this plugin

miniOrange Secure MCP Server is a complete WordPress MCP server plugin that turns your WordPress site into a fully working Model Context Protocol (MCP) server. Once installed, you can connect Claude to WordPress, connect ChatGPT to WordPress, or link any MCP-compatible AI in just 2 minutes. Ask AI to write blog posts, edit Elementor and Kadence page layouts, manage custom post types and their custom fields, upload media, update WooCommerce products, manage Yoast SEO, moderate comments, handle contact form submissions, and much more, all through simple chat. Unlike other WordPress MCP server plugins that give AI full admin access, we put you in complete control. Role-based AI permissions, Turn each tool on or off, self-hosted OAuth 2.1 login, and full activity logs are all included, with no restrictions. Video: Connect Chagpt to WordPress Using Secure MCP Server Core WordPress MCP Server Features The most complete WordPress MCP server on the WordPress marketplace: 300+ MCP Tools Included: Full coverage across content, commerce, users, forms, and SEO. Secure MCP Server with OAuth 2.1: Self-hosted authorization server where AI never sees your WordPress password. Role-Based AI Access (NHI Registry): Assign different MCP tools to each role so every AI client gets its own powers. Tool Controls: Turn any MCP tool on or off with one click. Works with Every AI: Connect Claude, ChatGPT, Cursor, Gemini, Windsurf, and any MCP-compatible AI. One-Click OAuth Connect: Paste your MCP server URL and approve access, with no API keys to copy. Full Activity Log: Every AI action recorded and reviewable. WordPress Abilities API Native: Built on WordPress 6.9’s official standard for a future-proof design. Unlimited Usage: No caps on MCP calls, connected AI clients, or users. Role-Based Access: Give each user or AI only the access their role allows. Agent Reputation Scoring: Rates each AI on past behavior to spot trusted or risky agents. Individual Credentials for Users: Every user connects with their own login, not a shared one. Dynamic OAuth & API Key Support: Connect using OAuth or an API key, whichever you prefer. Audit Log: See every AI action, including who did it and when. Policy Forming: Build your own rules for what AI is allowed to do. Abilities Restriction: Turn specific AI abilities on or off to limit what AI can touch. Human-in-the-Loop Approvals: Send risky actions to a real person to approve first. Data Rules + DLP: Hide emails, phone numbers, and secrets so AI never sees them. Prompt-Injection Detection: Catch hidden or harmful instructions before they reach the AI. Behavioral Anomaly Detection: Watches AI activity and flags anything unusual. Rate Limits & Quotas: Cap how many requests each AI can make to stop overuse. Multisite Policy: Apply the same AI rules across all your WordPress sites. Pre-Built Policy Templates: Ready-made rule sets so you can set up safe AI access fast. Quick Links Official Website | ChatGpt Setup Guide | Claude Setup Guide What Is a WordPress MCP Server? A WordPress MCP server is a plugin that lets AI tools like Claude by Anthropic and ChatGPT by OpenAI connect to your WordPress site through the Model Context Protocol (MCP), an open standard AI clients use to talk to external apps. Think of MCP as USB-C for AI. One protocol. Every AI client. Every app. Install this WordPress MCP plugin, and your site instantly becomes an AI-ready backend at: https://YOUR-SITE/wp-json/mosmcp/v1/mcp Any AI that speaks MCP can now connect and manage your WordPress site through chat. WordPress Core Content Tools: 105 MCP Abilities Full AI control over your WordPress content: posts, pages, media, categories, tags, and revisions. Post Management (31 tools): Find, create, update, publish, schedule, categorize, tag, trash, restore, or delete posts for full editorial automation. Edit the URL slug, set the featured image, choose the page template, and duplicate an existing post to reuse it as a template. Page Management (25 tools): Create drafts under parent pages, update any page you can edit, publish, schedule, make private, manage review, trash, restore, or delete pages. Edit slugs, set featured images, choose page templates, and duplicate a page with its layout and settings intact. Media Library Management (19 tools): Upload files straight into the library from a public URL or from supplied file contents, list or filter by type, get counts, find by title, update titles, alt text, captions, and descriptions, or delete files. Category Management (11 tools): List, create, rename, and update categories or slugs, find empty ones, and delete safely with reassignment to default. Tag Management (10 tools): List, create, rename, and update tags, find unused tags for cleanup, and delete safely without breaking posts. Revisions & History (9 tools): List, count, and retrieve revisions or autosaves, and restore any post to a specific revision or delete one. WooCommerce MCP Integration: 45 AI Tools The most complete WooCommerce MCP server available. Let AI run your entire online store. Product Management (16 tools): Create and update simple, variable, grouped, or external products, manage stock, SKUs, attributes, and variations, and bulk update. Order Management (11 tools): List, create, and update orders, change status, edit billing and shipping, add notes, and create full or partial refunds. Customer Management (7 tools): List, create, update, and delete customers, view purchase history, and segment by spend, order count, or activity. WooCommerce Reports (6 tools): Sales reports by date range, top-selling products, order and inventory reports, customer acquisition, and coupon usage. Yoast SEO MCP Integration: 15 AI Tools The only WordPress MCP server with dedicated Yoast SEO support. Every field an AI client can write, it can also read back. Read Yoast SEO Data (3 tools): Get focus keyword, SEO analysis, and the full meta fields bundle in one call — including the SEO title with its template variables already resolved, so you see what search engines will see. Titles & Indexing (5 tools): Update the SEO title, breadcrumb title, canonical URL, robots meta, and the advanced robots directives (no-image-index, no-archive, no-snippet). Content & Social (5 tools): Update the meta description, focus keyphrase, Open Graph tags, X/Twitter card, and cornerstone content flag. Structured Data (1 tool): Set the schema page type and article type used for rich results. Sitemap Management (1 tool): Add or remove specific posts and pages from the Yoast XML sitemap. Every Yoast tool works on posts, pages, and any custom post type, so a single call pattern covers your whole site. User Management, Roles & Comments: 60 MCP Tools The most complete user and moderation toolkit of any WordPress MCP plugin. User Administration (22 tools): List, get, search, count, create, and update users, and manage custom user metadata. User Deletion & Validation (5 tools): Delete with content reassignment, check username and email availability, and get or update user locale. Native Credentials (3 tools): Reset passwords, invalidate sessions, and validate password reset tokens. Content Association (2 tools): List posts and comments authored by a specific user. Roles & Permissions (8 tools): List roles and capabilities, get editable roles, assign or remove roles, and view MCP policy assignments. Comment Moderation, Read (8 tools): List pending, approved, spam, or trashed comments, search, and get counts by status. Comment Moderation, Status Changes (6 tools): Approve, unapprove, spam, restore, trash, or permanently delete comments. Comment Content & Metadata (6 tools): Reply as admin, get and update metadata, and get counts by post, status, or user. Contact Form 7, WPForms & Gravity Forms: 40 MCP Tools The only WordPress MCP server with support for the top 3 form plugins. Contact Form 7 (12 tools): List forms, fields, and mail settings, list and export submissions via Flamingo, mark read/unread, trash, and delete for GDPR. WPForms (14 tools): List forms, fields, settings, and notifications, list, count, and export entries, mark read/unread, trash, restore, and delete. Gravity Forms (14 tools): List all or active forms, get fields and settings, list, count, and export entries, mark read/unread, trash, restore, and delete. Elementor Page Builder: 10 MCP Tools Elementor keeps its layout in its own data, not in the WordPress editor, which is why asking AI to “update the page content” normally changes nothing a visitor sees. These tools work on the real Elementor layout, so a design you built in Elementor survives the edit. Read Elementor Layouts (3 tools): List the elements on a page with their text, images, and links, filter by widget type or by the text they contain, and read any widget’s full settings schema before writing to it. Reading a layout also reports which text widget holds the article body, so AI editing an article never confuses the caption for the prose. Edit Content Without Touching Design (1 tool): Change the text, image, or link of a single element. It can only reach content settings, so colours, fonts, and spacing cannot be altered by accident. Edit Styling Deliberately (1 tool): Set text and background colour, font size, weight and family, line height, letter spacing, letter casing, alignment, padding, and margin — with separate values for tablet and mobile. Restricted to that list on purpose, so the rest of your design is untouchable. Restructure Layouts (4 tools): Duplicate, move, or delete an element, or replace a whole layout when you are building from scratch. Check Before You Trust It (1 tool): Render the page, or a single element, to the markup a visitor would receive — so a change can be verified rather than assumed. Duplicate and Rewrite (workflow): Build one article in Elementor, then have AI duplicate it and replace the copy’s text, featured image, categories, and SEO. The copy keeps the original’s fonts, colours, spacing, and layout exactly. Every write is checked after saving and rolled back if it did not persist, and an optional page lock refuses the edit if someone changed the page since AI last read it. Works on posts, pages, and custom post types. Custom Post Types & Custom Fields: 19 MCP Tools Works with any custom post type registered on your site, whatever created it — CPT UI, JetEngine, ACF, Toolset, or your own code. Nothing needs configuring first. Discover What Exists (3 tools): List the custom post types on the site with their taxonomies, supported features, and whether the connected account may edit them; describe one type in detail; and list its items. Read & Edit Items (4 tools): Read an item with all of its custom fields, update the title, content, excerpt, and slug, create new items, and set the parent for hierarchical types. Custom Fields (2 tools): Read and write custom field values, including repeatable fields. A field managed by another plugin is reported as read-only instead of being corrupted, and a read tells you exactly why a field cannot be written — so AI never plans an edit that will be refused. Taxonomies & Featured Image (3 tools): Assign or remove terms in any taxonomy attached to the type, and set the featured image. Publishing & Lifecycle (5 tools): Change status, trash, restore, duplicate an item as a template, and permanently delete. Page Templates (2 tools): Read and set the template a single item uses. Yoast SEO and Elementor tools work on custom post types too, so an events listing or a services directory can be managed end to end. Kadence Blocks & Kadence Theme: 17 MCP Tools The first WordPress MCP server that can safely edit a page builder. AI reads and rewrites the actual Kadence block tree, so your layout, styling, and responsive settings survive the edit. Read Kadence Pages (4 tools): Read a page’s full nested block structure by ID or title, get one block’s complete settings, search blocks by type or by the text they contain, and list the Kadence block types registered on your site. Edit Kadence Blocks (4 tools): Update text in 16 separate fields across 9 block types (headings, buttons, info boxes, testimonials, icon lists, image captions, accordion titles), update styling and responsive attributes across all 59 Kadence block types, and duplicate or delete any block. Build Kadence Layouts (7 tools): Insert rows, columns, headings, images, and buttons, create a new draft page pre-built with a row and columns, or build a nested row-and-column layout in a single request. Kadence Theme Layout (2 tools): Read and set Kadence’s per-page layout options. Every edit rewrites only the block you target and leaves the rest of the page byte-for-byte identical, and responsive desktop, tablet, and mobile values can be set directly. Kadence tools appear once you grant them to a role in the AI Agent Registry. WordPress Site Administration: 35 MCP Tools Site Settings, Read (10 tools): Get title, tagline, URL, timezone, language, permalinks, posts-per-page, homepage, privacy policy page, and search visibility. Site Settings, Write (7 tools): Update title, tagline, timezone, and posts-per-page, and set homepage, posts page, and privacy policy page. Plugin Management (9 tools): List, activate, deactivate, delete, and update plugins with confirmation, and get details, version, and author. Theme Management (3 tools): List installed themes, get the active theme, and get theme details by slug. Updates & Site Health (6 tools): Check core, plugin, and theme updates, and get WordPress version, PHP/MySQL info, and Site Health status. Security & Governance: Why This Is the Safest WordPress MCP Server Letting AI touch your WordPress site is a big trust decision, so our secure MCP server plugin is built with 5 protection layers: Self-Hosted OAuth 2.1 Authorization Server: Your site is its own OAuth server, so AI never sees your password and only gets a scoped access token. NHI Registry, Role-Based AI Permissions: Each AI is a first-class identity, and two users connecting the same AI get different permissions based on their role. Per-Tool On/Off Control: Disable any of the 300+ MCP tools with one click, globally, regardless of role or AI. Real WordPress User Enforcement: Every MCP request runs as a genuine WordPress user account, so all core capability checks apply. Full Audit Trail: Every MCP tool call, OAuth grant, and ability change is logged and searchable. Plus: PKCE (S256) anti-hijack protection, RFC 7591 Dynamic Client Registration for one-click AI setup, Streamable HTTP transport and JSON-RPC 2.0 for reliable connections, Bearer token support for automation, and a clean uninstall. Compatible AI Clients This WordPress MCP server works with every major MCP-compatible AI: Claude by Anthropic (Claude.ai, Claude Desktop, Claude Code): connect in one click via OAuth. ChatGPT by OpenAI: connect as a custom MCP server. Cursor: AI code editor with MCP support. Windsurf: AI-powered IDE. Gemini AI by Google (Gemini CLI, Google Antigravity). n8n: automation platform with MCP nodes. Any MCP-compatible client Example Chat Prompts Once you connect Claude or ChatGPT to WordPress with this MCP plugin, just chat: …