{"id":293340,"date":"2026-04-24T15:59:09","date_gmt":"2026-04-24T15:59:09","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/webo-mcp\/"},"modified":"2026-09-05T01:29:36","modified_gmt":"2026-09-05T01:29:36","slug":"webo-mcp","status":"publish","type":"plugin","link":"https:\/\/mai.wordpress.org\/plugins\/webo-mcp\/","author":23464384,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"3.0.22","stable_tag":"3.0.22","tested":"7.1.2","requires":"6.4","requires_php":"8.0","requires_plugins":null,"header_name":"WEBO MCP","header_author":"Dinh WP","header_description":"MCP (Model Context Protocol) gateway for WordPress: JSON-RPC tools over the REST API for MCP clients.","assets_banners_color":"69877a","last_updated":"2026-09-05 01:29:36","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/webomcp.com","header_author_uri":"https:\/\/webomcp.com","rating":5,"author_block_rating":0,"active_installs":30,"downloads":3097,"num_ratings":3,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.0.28":{"tag":"2.0.28","author":"phuongwebo","date":"2026-04-25 08:06:45","revision":3515120},"2.0.29":{"tag":"2.0.29","author":"phuongwebo","date":"2026-04-28 18:29:53","revision":3517730},"2.0.34":{"tag":"2.0.34","author":"phuongwebo","date":"2026-05-04 20:29:27","revision":3522722},"2.0.35":{"tag":"2.0.35","author":"phuongwebo","date":"2026-05-04 20:53:17","revision":3522731},"2.0.40":{"tag":"2.0.40","author":"phuongwebo","date":"2026-05-05 22:31:15","revision":3523868},"2.0.45":{"tag":"2.0.45","author":"phuongwebo","date":"2026-05-08 14:51:09","revision":3526645},"2.1.0":{"tag":"2.1.0","author":"phuongwebo","date":"2026-05-08 16:12:27","revision":3526713},"2.1.10":{"tag":"2.1.10","author":"phuongwebo","date":"2026-07-14 05:12:59","revision":3606942},"2.1.11":{"tag":"2.1.11","author":"phuongwebo","date":"2026-05-12 11:41:34","revision":3529761},"2.1.12":{"tag":"2.1.12","author":"phuongwebo","date":"2026-05-12 13:25:56","revision":3529946},"2.1.13":{"tag":"2.1.13","author":"phuongwebo","date":"2026-05-12 16:54:17","revision":3530189},"2.1.14":{"tag":"2.1.14","author":"phuongwebo","date":"2026-05-13 20:58:26","revision":3531380},"2.1.17":{"tag":"2.1.17","author":"phuongwebo","date":"2026-05-19 16:00:43","revision":3537624},"2.1.19":{"tag":"2.1.19","author":"phuongwebo","date":"2026-05-24 16:15:10","revision":3546413},"2.1.3":{"tag":"2.1.3","author":"phuongwebo","date":"2026-05-08 17:55:21","revision":3526766},"2.1.4":{"tag":"2.1.4","author":"phuongwebo","date":"2026-07-14 05:12:59","revision":3606942},"2.1.9":{"tag":"2.1.9","author":"phuongwebo","date":"2026-07-14 05:12:59","revision":3606942},"2.2.0":{"tag":"2.2.0","author":"phuongwebo","date":"2026-05-27 14:39:20","revision":3550814},"2.2.1":{"tag":"2.2.1","author":"phuongwebo","date":"2026-05-27 20:52:37","revision":3551290},"2.3.0":{"tag":"2.3.0","author":"phuongwebo","date":"2026-05-28 15:27:37","revision":3552402},"2.3.1":{"tag":"2.3.1","author":"phuongwebo","date":"2026-05-29 09:38:59","revision":3553276},"2.3.2":{"tag":"2.3.2","author":"phuongwebo","date":"2026-05-29 17:09:44","revision":3553921},"2.3.3":{"tag":"2.3.3","author":"phuongwebo","date":"2026-05-29 17:39:37","revision":3553963},"2.3.4":{"tag":"2.3.4","author":"phuongwebo","date":"2026-05-29 17:56:19","revision":3553990},"2.3.5":{"tag":"2.3.5","author":"phuongwebo","date":"2026-05-29 18:00:40","revision":3553994},"2.3.6":{"tag":"2.3.6","author":"phuongwebo","date":"2026-05-29 18:16:18","revision":3554013},"2.3.7":{"tag":"2.3.7","author":"phuongwebo","date":"2026-05-29 18:23:27","revision":3554028},"2.4.0":{"tag":"2.4.0","author":"phuongwebo","date":"2026-05-29 18:31:00","revision":3554038},"2.4.1":{"tag":"2.4.1","author":"phuongwebo","date":"2026-05-29 18:33:27","revision":3554048},"2.4.2":{"tag":"2.4.2","author":"phuongwebo","date":"2026-05-29 20:26:04","revision":3554168},"2.4.4":{"tag":"2.4.4","author":"phuongwebo","date":"2026-05-29 22:30:30","revision":3554236},"2.4.5":{"tag":"2.4.5","author":"phuongwebo","date":"2026-06-02 14:58:01","revision":3558203},"2.4.6":{"tag":"2.4.6","author":"phuongwebo","date":"2026-06-04 12:46:25","revision":3560964},"2.4.7":{"tag":"2.4.7","author":"phuongwebo","date":"2026-06-07 05:29:16","revision":3563463},"2.4.8":{"tag":"2.4.8","author":"phuongwebo","date":"2026-06-08 14:24:22","revision":3564834},"2.5.5":{"tag":"2.5.5","author":"phuongwebo","date":"2026-06-18 17:47:14","revision":3577638},"2.5.6":{"tag":"2.5.6","author":"phuongwebo","date":"2026-06-20 04:05:48","revision":3579428},"2.5.7":{"tag":"2.5.7","author":"phuongwebo","date":"2026-06-21 08:31:34","revision":3580433},"2.5.8":{"tag":"2.5.8","author":"phuongwebo","date":"2026-06-22 07:04:32","revision":3581287},"2.5.9":{"tag":"2.5.9","author":"phuongwebo","date":"2026-07-04 02:04:57","revision":3595652},"2.6.10":{"tag":"2.6.10","author":"phuongwebo","date":"2026-07-14 14:27:57","revision":3607633},"2.6.11":{"tag":"2.6.11","author":"phuongwebo","date":"2026-07-14 14:46:56","revision":3607649},"2.6.12":{"tag":"2.6.12","author":"phuongwebo","date":"2026-07-14 16:18:48","revision":3607777},"2.6.13":{"tag":"2.6.13","author":"phuongwebo","date":"2026-07-14 17:08:49","revision":3607814},"2.6.14":{"tag":"2.6.14","author":"phuongwebo","date":"2026-07-14 17:49:51","revision":3607847},"2.6.15":{"tag":"2.6.15","author":"phuongwebo","date":"2026-07-14 20:09:28","revision":3607974},"2.6.16":{"tag":"2.6.16","author":"phuongwebo","date":"2026-07-17 07:44:25","revision":3611137},"2.6.3":{"tag":"2.6.3","author":"phuongwebo","date":"2026-07-05 08:47:38","revision":3596534},"2.6.4":{"tag":"2.6.4","author":"phuongwebo","date":"2026-07-05 08:59:00","revision":3596540},"2.6.8":{"tag":"2.6.8","author":"phuongwebo","date":"2026-07-14 05:12:59","revision":3606942},"2.6.9":{"tag":"2.6.9","author":"phuongwebo","date":"2026-07-14 14:02:59","revision":3607590},"3.0.0":{"tag":"3.0.0","author":"phuongwebo","date":"2026-07-23 18:13:33","revision":3620370},"3.0.18":{"tag":"3.0.18","author":"phuongwebo","date":"2026-08-20 09:36:40","revision":3656381},"3.0.2":{"tag":"3.0.2","author":"phuongwebo","date":"2026-08-13 02:06:33","revision":3644129},"3.0.22":{"tag":"3.0.22","author":"phuongwebo","date":"2026-09-05 01:29:36","revision":3681957},"3.0.3":{"tag":"3.0.3","author":"phuongwebo","date":"2026-08-14 18:39:59","revision":3647828},"3.0.5":{"tag":"3.0.5","author":"phuongwebo","date":"2026-08-15 21:35:35","revision":3649065},"3.0.6":{"tag":"3.0.6","author":"phuongwebo","date":"2026-08-15 21:53:50","revision":3649078},"3.0.7":{"tag":"3.0.7","author":"phuongwebo","date":"2026-08-17 17:46:29","revision":3651514}},"upgrade_notice":{"3.0.22":"<p>Security update. Upgrade immediately to prevent authenticated Author-level users from reading and republishing server-local files through the media upload tool.<\/p>","3.0.18":"<p>Multisite site admins can keep style and script tags in MCP content when Trusted raw HTML is enabled. Enable it under Settings \u2192 WEBO MCP \u2192 Security.<\/p>","2.3.2":"<p>Recommended for Claude Desktop and other MCP SDK clients: SSE keepalive, standard tools\/call content format, and safer AI editing via content checkpoint tools.<\/p>","2.3.1":"<p>Recommended compatibility update for installs using SCF or plugins that register abilities during activation.<\/p>","2.2.1":"<p>Recommended compatibility update for sites relying on bundled MCP schema classes or layered ability execution through MCP clients.<\/p>","2.1.23":"<p>Opt-in fix for multisite Elementor\/custom HTML workflows that need trusted administrators to preserve raw HTML tags. Disabled by default.<\/p>","2.1.17":"<p>Adds post password updates to <code>webo\/content-mutate<\/code> for protected content workflows.<\/p>","2.1.14":"<p>Recommended for multisite networks using child-site plugin activation through MCP; fixes WordPress capability checks after <code>switch_to_blog()<\/code>.<\/p>","2.1.13":"<p>Adds core plugin mutation plus child-site plugin activation\/deactivation via <code>site_id<\/code> or <code>blog_id<\/code> for multisite network admins.<\/p>","2.1.12":"<p>Adds MCP audit logging, optional tool allowlists, and an administrator health\/status tool. Existing MCP access remains unchanged unless allowlist enforcement is enabled in Settings.<\/p>","2.1.11":"<p>Recommended security hardening release: MCP tools now enforce object-level post\/media\/term capabilities and only list tools the current user can call.<\/p>","2.1.10":"<p>Registers the missing <strong><code>webo\/plugin-query<\/code><\/strong> tool (plugin inventory and updates via MCP). Recommended for automation that lists pending plugin updates.<\/p>","2.1.9":"<p>Internal refactor (standalone tool bootstrap file only). No MCP tool renaming; safe routine update.<\/p>","2.1.8":"<p>Critical for <code>webo.vn<\/code> \/ multi-BOM REST bodies: fixes BOM sanitizer regex so repeated UTF-8 BOM prefixes are actually removed.<\/p>","2.1.7":"<p>Recommended if MCP\/remote clients still hit <code>Unexpected token<\/code> \/ invalid JSON \u2014 BOM strip now defaults on for <strong>all<\/strong> REST API responses.<\/p>","2.1.6":"<p>Use this if MCP clients still fail JSON parse on <code>discover-abilities<\/code> \/ ability tools \u2014 BOM strip now covers <code>wp-abilities<\/code> REST routes.<\/p>","2.1.5":"<p>If MCP clients still parse-fail on BOM: this release starts the BOM-stripping buffer before <code>rest_api_init<\/code> for MCP-like URLs.<\/p>","2.1.4":"<p>Further hardening for leading-BOM MCP JSON failures: earlier buffer bootstrap on MCP-like REST URLs.<\/p>","2.1.3":"<p>Recommended if MCP clients show JSON parse errors (leading BOM) on <code>tools\/list<\/code> or <code>tools\/call<\/code> \u2014 response body is sanitized for MCP REST routes.<\/p>","2.1.2":"<p>Restores packaged agent <strong><code>skills\/<\/code><\/strong> in the upstream repo clone; upgrade if you rely on Cursor\/Codex skills from GitHub.<\/p>","2.1.1":"<p>Documentation-only refresh: use docs\/MCP_TOOL_MIGRATION.md when mapping old MCP tool names to dispatchers + <code>action<\/code>. No behavioral change vs 2.1.0 expected.<\/p>","2.0.40":"<p>Recommended update for MCP clients that batch process posts or rely on seo\/article-analysis; list-posts pagination and H1\/schema detection are more accurate.<\/p>","2.0.35":"<p>Adds theme discovery and theme switching tools for MCP clients. This release also carries the shortened WordPress.org short description into the new tagged version.<\/p>","2.0.34":"<p>Recommended update if you manage homepage reading settings via MCP; adds safe support for <code>show_on_front<\/code> and <code>page_on_front<\/code> updates.<\/p>","2.0.33":"<p>Documentation-only refresh on WordPress.org listings; recommended if you rely on the plugin directory description for onboarding.<\/p>","2.0.32":"<p>Recommended update for WP 6.9+ sites using Abilities API and MCP adapter integration.<\/p>","2.0.31":"<p>Maintenance update.<\/p>","2.0.30":"<p>Maintenance update.<\/p>","2.0.29":"<p>Maintenance update for runtime stability and cleaner CLI output. If you use WEBO MCP Pro, review\/update the Pro package compatibility notice before deploying this version to production.<\/p>","2.0.28":"<p>WordPress.org compliance update: readme now documents Google Suggest external service usage with Terms\/Privacy links, and nav-menu API loading no longer relies on WPINC.<\/p>","2.0.27":"<p>MCP clients must send WordPress Application Password (HTTP Basic) or use a logged-in session. API key\/HMAC alone are no longer sufficient when calling the router.<\/p>","2.0.26":"<p>Adds seo\/article-analysis for post-level SEO diagnostics (optional outbound suggest API; set no_autocomplete to skip).<\/p>","2.0.7":"<p>Readme and GitHub README now link webomcp.com and the n8n-nodes-webo-mcp npm package.<\/p>","2.0.6":"<p>License declaration aligned between readme and main plugin file for WordPress.org review.<\/p>","2.0.5":"<p>Plugin header updates for Plugin Check and WordPress.org tooling (@wordpress-plugin, GPLv2 license slug).<\/p>","2.0.4":"<p>Plugin header formatting for WordPress.org Plugin Check (Description, Version, License).<\/p>","2.0.3":"<p>Plugin Check and packaging fixes; upload the release zip from scripts\/build-release.ps1 for WordPress.org.<\/p>","2.0.2":"<p>Packaging and readme updates for WordPress.org review. Always upload the zip from scripts\/build-release.ps1, not the raw git folder.<\/p>","2.0.0":"<p>Major rename: reinstall from folder webo-mcp (or deploy to new path), then activate WEBO MCP. Settings are preserved via migration.<\/p>","1.1.1":"<p>Recommended update to fix tools\/call validation for core tools with no input.<\/p>","1.0.2":"<p>Recommended update to support active plugin verification via MCP tool.<\/p>","1.0.1":"<p>Recommended update to refresh plugin metadata and improve tools\/list compatibility.<\/p>","1.0.0":"<p>Initial public release of WEBO MCP (formerly WEBO WordPress MCP).<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":3},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3514777,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3514777,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.0.28","2.0.29","2.0.34","2.0.35","2.0.40","2.0.45","2.1.0","2.1.10","2.1.11","2.1.12","2.1.13","2.1.14","2.1.17","2.1.19","2.1.3","2.1.4","2.1.9","2.2.0","2.2.1","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7","2.4.0","2.4.1","2.4.2","2.4.4","2.4.5","2.4.6","2.4.7","2.4.8","2.5.5","2.5.6","2.5.7","2.5.8","2.5.9","2.6.10","2.6.11","2.6.12","2.6.13","2.6.14","2.6.15","2.6.16","2.6.3","2.6.4","2.6.8","2.6.9","3.0.0","3.0.18","3.0.2","3.0.22","3.0.3","3.0.5","3.0.6","3.0.7"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"MCP endpoint working in a REST client (initialize)","2":"tools\/list response with public tools","3":"tools\/call response for a WordPress tool"}},"plugin_section":[],"plugin_tags":[232494,569,69473,242115,253991],"plugin_category":[],"plugin_contributors":[261006],"plugin_business_model":[],"class_list":["post-293340","plugin","type-plugin","status-publish","hentry","plugin_tags-ai-agent","plugin_tags-automation","plugin_tags-json-rpc","plugin_tags-mcp","plugin_tags-model-context-protocol","plugin_contributors-phuongwebo","plugin_committers-phuongwebo"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/webo-mcp\/assets\/icon-128x128.png?rev=3514777","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>WEBO MCP securely connects authenticated AI agents and MCP-compatible clients to WordPress through JSON-RPC tools over REST. It provides bounded access to content, media, users, settings, site health, and extensible WordPress abilities while preserving native capability checks.<\/p>\n\n<p>Use Application Passwords or an authenticated WordPress session, discover tools with <code>tools\/list<\/code>, and invoke exact tools through <code>tools\/call<\/code>. Optional API-key, HMAC, scoped connector-token, allowlist, and audit controls are available for administrators. Documentation and ecosystem details: https:\/\/webomcp.com<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>This plugin does not phone home or send telemetry. MCP traffic is initiated by clients you configure. Some tools may perform outbound HTTP requests only when a client invokes them (for example seo\/article-analysis may request keyword suggestions from a third-party suggest API unless you pass no_autocomplete).<\/p>\n\n<p>The plugin stores the following options in the WordPress database when configured:\n- <code>webo_mcp_api_key<\/code>: API key used to authenticate MCP requests.\n- <code>webo_mcp_hmac_secret<\/code>: HMAC secret used to sign and validate MCP requests.\n- <code>webo_mcp_require_secondary_credentials<\/code>: when enabled, also require API key\/HMAC for Application Password and Bearer clients (off by default so standard connectors are not blocked).\n- <code>webo_mcp_url_connector_tokens<\/code>: hashed, expirable, revocable URL connector tokens for clients that cannot send headers. Raw tokens are shown once and are not stored.\n- <code>webo_mcp_tool_allowlist_enabled<\/code> and <code>webo_mcp_tool_allowlist_rules<\/code>: optional administrator-configured MCP tool allowlist policy.\n- <code>webo_mcp_audit_log_enabled<\/code>, <code>webo_mcp_audit_log_max_entries<\/code>, and <code>webo_mcp_audit_log<\/code>: bounded MCP tool-call audit log settings and compact audit events. Audit entries include user\/tool\/action\/status data, anonymized IPs, and hashed session IDs; they do not store request payloads, API keys, HMAC secrets, or Application Passwords.\n- <code>webo_mcp_installed_at<\/code> and <code>webo_mcp_review_notice<\/code>: local timestamps\/state for an optional WordPress.org review request notice (not sent off-site; dismissible).<\/p>\n\n<p>These options are removed when the plugin is uninstalled via the WordPress Plugins screen.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin can connect to Google Suggest (Autocomplete) when a client calls the <code>seo\/article-analysis<\/code> tool and does not set <code>no_autocomplete<\/code> to true. This external request is used to return related keyword suggestions for SEO analysis.<\/p>\n\n<p>Service provider: Google LLC (Google Suggest \/ Autocomplete API endpoint).<\/p>\n\n<p>Data sent and when:\n- Sent only when <code>seo\/article-analysis<\/code> is called with autocomplete enabled.\n- Sends the analysis query text to <code>https:\/\/suggestqueries.google.com\/complete\/search<\/code> as the <code>q<\/code> parameter.\n- Sends standard HTTP request metadata such as IP address and User-Agent as part of the web request.<\/p>\n\n<p>Terms of Service: https:\/\/policies.google.com\/terms\nPrivacy Policy: https:\/\/policies.google.com\/privacy<\/p>\n\n<h3>Developer Hooks<\/h3>\n\n<p>The plugin exposes the following actions and filters for developers:<\/p>\n\n<h3>Actions<\/h3>\n\n<ul>\n<li><code>webo_mcp_register_tools<\/code>\nFired during plugin bootstrap after standalone tools are registered. Use this to register custom MCP tools from other plugins.<\/li>\n<\/ul>\n\n<h3>Filters<\/h3>\n\n<ul>\n<li><p><code>webo_mcp_current_user_can_use_mcp<\/code> (bool $allowed, int $user_id)\nGate for all MCP REST access. Default: super admin OR <code>manage_options<\/code> OR <code>edit_posts<\/code>. Override to tighten (e.g. super-admin only) in hardened installs.<\/p><\/li>\n<li><p><code>webo_mcp_secondary_credentials_exempt<\/code> (bool $exempt, WP_REST_Request $request)\nWhen true, skip optional API key \/ HMAC after WordPress auth. Default true for Application Password (Basic) and Bearer sessions unless Settings \u2192 Security \u2192 \u201cRequire for App Password \/ Bearer\u201d is enabled. Return false to always enforce <code>X-WEBO-*<\/code> headers.<\/p><\/li>\n<li><p><code>webo_mcp_allow_internal_tools<\/code> (bool $allow_internal, WP_REST_Request $request)\nControls whether internal tools are included in tools\/list responses. Defaults to false for public environments.<\/p><\/li>\n<li><p><code>webo_mcp_public_categories<\/code> (array $categories, WP_REST_Request $request, array $tool)\nFilters which tool categories are exposed as public. Defaults to array( 'wordpress' ).<\/p><\/li>\n<li><p><code>webo_mcp_rate_limit_per_hour<\/code> (int $limit, string $client, array|null $profile)\nAdjust effective hourly limit (fallback for both buckets).<\/p><\/li>\n<li><p><code>webo_mcp_rate_limit_read_per_hour<\/code> \/ <code>webo_mcp_rate_limit_mutate_per_hour<\/code> (int $limit, string $client, array|null $profile)\nPer-bucket limits after admin\/profile resolution.<\/p><\/li>\n<li><p><code>webo_mcp_tool_is_mutating<\/code> (bool $is_mutating, string $tool_name, array|null $tool_definition, array $arguments)\nOverride mutating classification for rate limits and read-only profiles.<\/p><\/li>\n<li><p><code>webo_mcp_tool_arguments_allow_extra<\/code> (bool $allow, string $tool_name, array $schema, array $arguments)\nWhen true, unknown tool argument keys are passed through (default false).<\/p><\/li>\n<li><p><code>webo_mcp_disallow_url_token_query<\/code> (bool $disallowed)\nBlock URL connector tokens in query strings (admin setting is the default source).<\/p><\/li>\n<li><p><code>webo_mcp_rest_bom_guard_json_api_requests<\/code> (bool $activate, string $uri_raw)\nOpt-in BOM sanitizer for all <code>\/wp-json\/<\/code> responses (default false; MCP routes only).<\/p><\/li>\n<li><p><code>webo_mcp_bridge_deny_patterns<\/code> (array $patterns)\nControls which abilities are excluded when auto-bridging abilities into MCP tools (e.g. bulk, themes\/, multisite\/).<\/p><\/li>\n<li><p><code>webo_mcp_auto_bridge_abilities<\/code> (bool $enabled)\nEnables or disables automatic bridging of registered abilities into MCP tools. Defaults to true; bridge mode still controls whether the bridge is off, layered, or full.<\/p><\/li>\n<li><p><code>webo_mcp_bridge_mode<\/code> (string $mode)\nControls Abilities bridge mode after the <code>WEBO_MCP_BRIDGE_MODE<\/code> constant and before the stored option. Values: <code>off<\/code>, <code>layered<\/code>, <code>full<\/code>. Default: <code>layered<\/code>.<\/p><\/li>\n<li><p><code>webo_mcp_enable_adapter<\/code> (bool $enabled)\nEnables or disables the bundled WordPress MCP Adapter runtime. Defaults to true.<\/p><\/li>\n<li><p><code>webo_mcp_validate_media_fetch_url<\/code> (true|\\WP_Error $ok, string $url, array $parsed)\nReject unsafe URLs for webo\/media-mutate upload action (return WP_Error to block).<\/p><\/li>\n<li><p><code>webo_mcp_tool_allowlist_allowed<\/code> (bool $allowed, string $tool_name, WP_REST_Request $request, array $params, array $allowed_tools)\nFilters the optional per-user\/role\/client allowlist decision.<\/p><\/li>\n<\/ul>\n\n<h4>Quick start<\/h4>\n\n<ol>\n<li>Upload the plugin folder to \/wp-content\/plugins\/webo-mcp<\/li>\n<li>Run composer install inside the plugin folder<\/li>\n<li>Activate the plugin in WordPress Admin<\/li>\n<li>Send JSON-RPC requests to POST \/wp-json\/mcp\/v1\/router<\/li>\n<\/ol>\n\n<p>For release packaging, use scripts\/build-release.ps1 to create a clean zip with .distignore exclusions.<\/p>\n\n<h3>Credits<\/h3>\n\n<p>Special thanks to the authors and open source projects that contributed to this plugin:\n- WordPress (https:\/\/wordpress.org)\n- Abilities API (https:\/\/github.com\/WordPress\/abilities-api)\n  Reference: https:\/\/make.wordpress.org\/ai\/2025\/07\/17\/abilities-api\/\n- MCP Adapter (https:\/\/github.com\/WordPress\/mcp-adapter)\n  Reference: https:\/\/make.wordpress.org\/ai\/2025\/07\/17\/mcp-adapter\/\n- Composer (https:\/\/getcomposer.org)\n- Other PHP and JS libraries from the community<\/p>\n\n<p>If you use this plugin, please give credit to the authors of these libraries.<\/p>\n\n<h3>License<\/h3>\n\n<p>This plugin is licensed under the GPLv2 or later.\nSee https:\/\/www.gnu.org\/licenses\/gpl-2.0.html for details.<\/p>\n\n<!--section=installation-->\n<p><strong>WEBO MCP<\/strong> is a WordPress MCP server \u2014 a complete <strong>Model Context Protocol<\/strong> gateway for WordPress. It lets AI agents and MCP-compatible clients (Claude Desktop, Cursor, Windsurf, n8n, and more) call well-defined tools over REST using JSON-RPC, instead of scraping the admin or sharing broad credentials.<\/p>\n\n<p>Official WEBO MCP website, documentation, and ecosystem hub: https:\/\/webomcp.com<\/p>\n\n<p><strong>Why use WEBO MCP as your WordPress MCP server?<\/strong><\/p>\n\n<ul>\n<li><strong>Token-optimized unified tools:<\/strong> every domain exposes two abilities \u2014 <code>*-query<\/code> (all reads) and <code>*-mutate<\/code> (all writes) \u2014 with a single <code>action<\/code> discriminator. <code>tools\/list<\/code> payload is up to 70% smaller than per-operation APIs, which means less of the model's context window is consumed by tool schemas, lower cost per session, and fewer hallucinated tool names.<\/li>\n<li>Primary router endpoint: <code>POST \/wp-json\/mcp\/v1\/router<\/code><\/li>\n<li>Standard MCP-style flow: <code>initialize<\/code> \u2192 <code>tools\/list<\/code> \u2192 <code>tools\/call<\/code><\/li>\n<li>Session lifecycle for clients (pass <code>session_id<\/code> or <code>Mcp-Session-Id<\/code> after <code>initialize<\/code>)<\/li>\n<li>Built-in tool registry for common WordPress operations (posts, media, terms, menus, options, and more)<\/li>\n<li>Bundled Abilities API + MCP Adapter integration, with automatic bridging from registered abilities to MCP tools (configurable)<\/li>\n<li>WordPress 7.0\/Core-aware bridge mode that uses Core Abilities\/API surfaces when available and falls back only when needed<\/li>\n<li>Public tool policy controls (category filters and optional allowlists) plus optional internal tool exposure for private environments<\/li>\n<li>Bounded MCP audit log, optional per-user\/role\/client tool allowlists, and a read-only administrator health\/status tool<\/li>\n<\/ul>\n\n<p><strong>Security model (high level)<\/strong><\/p>\n\n<ul>\n<li>MCP access requires a real WordPress user context: Application Password over HTTP Basic, or an existing logged-in session.<\/li>\n<li>Optional site-wide or per-user API key and HMAC can be enabled in Settings as an additional gate (they do not replace WordPress authentication). Generate\/rotate from Settings \u2192 Security; by default they are skipped for Application Password and Bearer clients unless you enable \u201cRequire for App Password \/ Bearer\u201d. Do not put the normal WEBO API key in URLs. For clients that cannot send headers, create a short-lived scoped <code>mcp_token<\/code> URL connector token in Settings -&gt; WEBO MCP.<\/li>\n<li>Default access expectations for the router and <code>GET \/wp-json\/webo-mcp\/v1\/tools<\/code>: users who are super admins, can <code>manage_options<\/code>, or can <code>edit_posts<\/code>, consistent with typical site operator and editor workflows (filterable).<\/li>\n<\/ul>\n\n<p><strong>Client guidance<\/strong><\/p>\n\n<p>Always discover tools before calling them: run <code>tools\/list<\/code>, pick an exact tool name from the response, validate required arguments, then call <code>tools\/call<\/code>. This reduces mistakes and keeps automation predictable in production.<\/p>\n\n<p><strong>Further documentation and optional integrations<\/strong><\/p>\n\n<ul>\n<li>Official website, documentation, and ecosystem notes: https:\/\/webomcp.com<\/li>\n<li>Optional n8n community node (separate package): https:\/\/www.npmjs.com\/package\/n8n-nodes-webo-mcp<\/li>\n<li>Release notes and migration map: see docs\/RELEASE_NOTES_2.1.0.md and docs\/MIGRATION_GUIDE_2.1.0.md in the GitHub repository<\/li>\n<li>Cross-addon dispatcher map (granular legacy names removed from discovery): docs\/MCP_TOOL_MIGRATION.md<\/li>\n<\/ul>\n\n<p>Compatibility note: any MCP-capable client can be used; which large language model runs inside the client is outside this plugin.<\/p>\n\n<p>Standalone core tools included:\n- Site info\n- Content (posts\/pages): <code>webo\/content-query<\/code> (list, get, find-by-url, search-replace, list-revisions, get-revision; with author\/date\/taxonomy filters) and <code>webo\/content-mutate<\/code> (create, update, delete, bulk-update-status, restore-revision, change-author)\n- Users: <code>webo\/list-users<\/code> and <code>webo\/user-mutate<\/code> (add-to-blog, set-role)\n- Media: <code>webo\/media-query<\/code> (list with search\/MIME\/post_id filters, get) and <code>webo\/media-mutate<\/code> (upload, update, delete)\n- Comments: <code>webo\/comment-query<\/code> (list, get) and <code>webo\/comment-mutate<\/code> (create, update, delete)\n- Taxonomy\/Terms: <code>webo\/taxonomy-query<\/code> (discover, list, get) and <code>webo\/taxonomy-mutate<\/code> (create, update, delete)\n- Nav menus: list menus, list menu items (menu_order, db_id), add menu link from post (explicit post_id + menu_order required)\n- Plugins: <code>webo\/plugin-query<\/code> (installed, active, updates, \u2026) and <code>webo\/plugin-mutate<\/code> (install, activate, deactivate; supports child-site <code>site_id<\/code> \/ <code>blog_id<\/code> activation for network admins)\n- Health: <code>webo\/health-status<\/code> (REST\/router status, Application Password support, permalinks, cron, object cache, plugin update summary, WordPress\/PHP versions, and redacted MCP config)\n- Client health: <code>webo\/client-health-report<\/code> (score 0\u2013100, grade A\u2013D, Markdown scoreboard for agency clients; hybrid foundation for Pro collectors later)\n- 404 logs: <code>webo\/get-404-logs<\/code> (read-only Rank Math \/ Redirection 404 monitor: url, hits, accessed, referrer)\n- Abilities bridge: <code>webo\/ability-query<\/code> and <code>webo\/ability-execute<\/code> in default layered mode. Only abilities with <code>meta.mcp.public === true<\/code> are visible and executable through WEBO MCP.\n- Themes: <code>webo\/theme-query<\/code> (installed themes) and <code>webo\/theme-mutate<\/code> (install from WordPress.org by slug, switch installed theme)\n- Theme context: <code>webo\/theme-context<\/code> (active theme info, block editor settings, style presets, registered blocks)\n- Block patterns: <code>webo\/block-patterns<\/code> (list\/get patterns, list\/get synced patterns)\n- Site stats: <code>webo\/site-stats<\/code> (overview, post counts, comment counts, user counts, media stats, activity summary)\n- Activity log: <code>webo\/activity-log<\/code> (list events, summary, clear)\n- User profile: <code>webo\/user-profile<\/code> (get own profile, update display name \/ bio \/ preferences)\n- Site settings: <code>webo\/site-settings<\/code> (get and update the 20 most common WordPress options via MCP)\n- Content search: <code>webo\/content-search<\/code> (full-text cross-post-type search with grouped results)\n- Menus: <code>webo\/menu-query<\/code>, <code>webo\/menu-mutate<\/code> (navigation menu items; not post\/CPT list order)\n- Post\/CPT order (optional): <code>webo\/reorder-query<\/code>, <code>webo\/reorder-mutate<\/code> when <a href=\"https:\/\/github.com\/mrphuong-webo\/webo-reorder\">Webo Reorder<\/a> is active \u2014 see docs\/abilities\/reorder.md\n- Options: get\/update (safe allowlist only), set site icon\/favicon from media\n- SEO (WordPress post): seo\/article-analysis \u2014 requires post_id; merges Rank Math meta when available (same data path as webo-rank-math\/get-post-seo-meta); optional related-keyword suggestions via outbound request unless no_autocomplete is true<\/p>\n\n<p>Excluded by default in standalone-safe mode:\n- Bulk\/mass execution tools\n- Plugin\/theme write-management abilities\n- Multisite-specific abilities<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"which%20endpoint%20should%20mcp%20clients%20use%3F\"><h3>Which endpoint should MCP clients use?<\/h3><\/dt>\n<dd><p>POST \/wp-json\/mcp\/v1\/router<\/p><\/dd>\n<dt id=\"where%20is%20the%20official%20website%20and%20the%20n8n%20package%3F\"><h3>Where is the official website and the n8n package?<\/h3><\/dt>\n<dd><p>The project hub is https:\/\/webomcp.com. For n8n, install the community node from npm: https:\/\/www.npmjs.com\/package\/n8n-nodes-webo-mcp<\/p><\/dd>\n<dt id=\"is%20webomcp.com%20the%20official%20webo%20mcp%20website%3F\"><h3>Is webomcp.com the official WEBO MCP website?<\/h3><\/dt>\n<dd><p>Yes. The official WEBO MCP website, documentation hub, and ecosystem landing page is https:\/\/webomcp.com.<\/p><\/dd>\n<dt id=\"can%20this%20run%20wordpress%20abilities%20by%20itself%3F\"><h3>Can this run WordPress abilities by itself?<\/h3><\/dt>\n<dd><p>Yes. On WordPress versions where Core provides the Abilities API, WEBO MCP uses Core and does not load a duplicate bundled Abilities API. On older WordPress versions it falls back to the bundled Composer package. The default bridge mode is <code>layered<\/code>, which exposes compact <code>webo\/ability-query<\/code> and <code>webo\/ability-execute<\/code> tools instead of one tool per ability. You can set bridge mode to <code>off<\/code>, <code>layered<\/code>, or <code>full<\/code> with <code>WEBO_MCP_BRIDGE_MODE<\/code>, the <code>webo_mcp_bridge_mode<\/code> filter, or the <code>webo_mcp_bridge_mode<\/code> option.<\/p><\/dd>\n<dt id=\"which%20abilities%20are%20exposed%20through%20webo%20mcp%3F\"><h3>Which abilities are exposed through WEBO MCP?<\/h3><\/dt>\n<dd><p>Only abilities that explicitly set <code>meta.mcp.public<\/code> to true are exposed. Execution also checks the ability permission callback, WEBO allowlist\/policy, and scope\/risk metadata such as <code>meta.webo_mcp.scope<\/code> and <code>meta.webo_mcp.risk<\/code>.<\/p><\/dd>\n<dt id=\"how%20do%20i%20migrate%20from%20legacy%20one-operation%20tool%20names%3F\"><h3>How do I migrate from legacy one-operation tool names?<\/h3><\/dt>\n<dd><p>Use <code>tools\/list<\/code> to discover the dispatcher tool names on your site, then pass the correct <code>action<\/code> (or query\/mutate discriminant) for each operation. Use docs\/MIGRATION_GUIDE_2.1.0.md for the 2.1.0 rollout narrative and docs\/MCP_TOOL_MIGRATION.md for a consolidated addon-by-addon map (Rank Math, Rocket, WooCommerce groups, etc.).<\/p><\/dd>\n<dt id=\"can%20i%20expose%20internal%20tools%3F\"><h3>Can I expose internal tools?<\/h3><\/dt>\n<dd><p>Yes, via filter webo_mcp_allow_internal_tools in private environments.<\/p><\/dd>\n<dt id=\"can%20i%20limit%20public%20tools%20by%20category%3F\"><h3>Can I limit public tools by category?<\/h3><\/dt>\n<dd><p>Yes, via filter webo_mcp_public_categories.<\/p><\/dd>\n<dt id=\"can%20i%20keep%20only%20wordpress.org-safe%20features%3F\"><h3>Can I keep only WordPress.org-safe features?<\/h3><\/dt>\n<dd><p>Yes. Default bridge rules exclude patterns for bulk, themes, and multisite abilities.<\/p><\/dd>\n<dt id=\"is%20this%20plugin%20suitable%20for%20production%3F\"><h3>Is this plugin suitable for production?<\/h3><\/dt>\n<dd><p>Yes, when used with proper authentication, TLS, and a limited tool exposure policy.<\/p><\/dd>\n<dt id=\"how%20do%20i%20authenticate%20mcp%20clients%3F\"><h3>How do I authenticate MCP clients?<\/h3><\/dt>\n<dd><p>Use a WordPress <strong>Application Password<\/strong> (Users \u2192 Profile \u2192 Application Passwords) and send it with HTTP Basic Auth (username = WordPress username, password = the application password). Optional <strong>API Key<\/strong> (<code>X-WEBO-API-KEY<\/code>) and <strong>HMAC<\/strong> (<code>X-WEBO-TIMESTAMP<\/code> + <code>X-WEBO-SIGNATURE<\/code>) are managed under Settings \u2192 WEBO MCP \u2192 Security (generate\/rotate; secrets are shown once). By default those optional headers are <strong>not<\/strong> required for Application Password or Bearer clients; enable \u201cRequire for App Password \/ Bearer\u201d if your client can send <code>X-WEBO-*<\/code> headers. HMAC signature: <code>sha256=<\/code> + HMAC-SHA256( <code>timestamp + \".\" + raw_body<\/code>, secret ), skew \u2264 300s. If a client cannot send headers, create a short-lived scoped URL connector token and pass it as <code>?mcp_token=...<\/code>; it is shown once, stored only as a hash, limited to an explicit tool scope, expirable, and revocable.<\/p><\/dd>\n<dt id=\"does%20webo%20mcp%20reorder%20posts%20and%20pages%3F\"><h3>Does WEBO MCP reorder posts and pages?<\/h3><\/dt>\n<dd><p>Use <strong><code>webo\/reorder-query<\/code><\/strong> and <strong><code>webo\/reorder-mutate<\/code><\/strong> when the separate <strong>Webo Reorder<\/strong> plugin is installed and active. Those tools control post <code>menu_order<\/code> and taxonomy-specific order \u2014 not navigation menus. For Appearance \u2192 Menus, use <strong><code>webo\/menu-query<\/code><\/strong> and <strong><code>webo\/menu-mutate<\/code><\/strong>. See <code>docs\/abilities\/reorder.md<\/code> in the plugin repository.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>3.0.22<\/h4>\n\n<ul>\n<li>Security: block server-local paths in <code>webo-media\/upload-file<\/code>; accept only connector-rewritten file objects, validated remote URLs, or caller-provided file data.<\/li>\n<li>Preserve ChatGPT sandbox file rewriting without allowing Author-level users to read files from WordPress, uploads, or temporary directories.<\/li>\n<li>Fix the WordPress 7.1 Ability API identifier used for the legacy plugin mutation alias.<\/li>\n<li>Resolve all remaining WordPress Plugin Check findings for the resubmission package.<\/li>\n<\/ul>\n\n<p>Historical release notes are maintained in CHANGELOG.md in the public source repository.<\/p>","raw_excerpt":"WordPress MCP server for AI agents and automation, with JSON-RPC tools over REST for Claude, Cursor, n8n, and MCP clients.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/293340","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=293340"}],"author":[{"embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/phuongwebo"}],"wp:attachment":[{"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=293340"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=293340"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=293340"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=293340"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=293340"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=293340"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}