{"id":361226,"date":"2026-09-02T22:44:17","date_gmt":"2026-09-02T22:44:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/webmcp-cockpit\/"},"modified":"2026-09-02T22:43:52","modified_gmt":"2026-09-02T22:43:52","slug":"ostheimer-webmcp-cockpit","status":"publish","type":"plugin","link":"https:\/\/mai.wordpress.org\/plugins\/ostheimer-webmcp-cockpit\/","author":414194,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.11","stable_tag":"1.0.11","tested":"7.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Ostheimer Cockpit for WebMCP","header_author":"Ostheimer","header_description":"Let browser-based AI agents write, edit and manage WordPress posts \u2014 with a human review step before anything is published.","assets_banners_color":"855b17","last_updated":"2026-09-02 22:43:52","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/ostheimer-webmcp-cockpit\/","header_author_uri":"https:\/\/ostheimer.at","rating":0,"author_block_rating":0,"active_installs":0,"downloads":37,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.11":{"tag":"1.0.11","author":"helpstring","date":"2026-09-02 22:43:52","revision":3678754}},"upgrade_notice":{"1.0.11":"<p>Aligns the plugin name and slug with WordPress.org requirements and hardens\npost-list permissions.<\/p>","1.0.10":"<p>Polishes the dashboard box buttons and spacing for a clearer, more compact layout.<\/p>","1.0.9":"<p>Adds the Cockpit tools and a live-status box directly to the WordPress dashboard.<\/p>","1.0.8":"<p>Adds a complete, filterable and administrator-controlled WebMCP audit log.<\/p>","1.0.1":"<p>Adds direct Base64 image uploads for agent-generated pictures and featured\nimage assignment by media ID.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3678754,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3678754,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3678754,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3678754,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.11"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3678754,"resolution":"1","location":"assets","locale":"","width":1440,"height":1116},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3678754,"resolution":"2","location":"assets","locale":"","width":1440,"height":800}},"screenshots":{"1":"The cockpit: agent tool status, the full tool list and a quick-start guide.","2":"The review queue: inspect agent drafts and approve them with one click."}},"plugin_section":[262246],"plugin_tags":[232494,569,242115,278930,258453],"plugin_category":[],"plugin_contributors":[88021],"plugin_business_model":[],"class_list":["post-361226","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-ai-agent","plugin_tags-automation","plugin_tags-mcp","plugin_tags-review-workflow","plugin_tags-webmcp","plugin_contributors-helpstring","plugin_committers-helpstring"],"banners":{"banner":"https:\/\/ps.w.org\/ostheimer-webmcp-cockpit\/assets\/banner-772x250.png?rev=3678754","banner_2x":"https:\/\/ps.w.org\/ostheimer-webmcp-cockpit\/assets\/banner-1544x500.png?rev=3678754","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/ostheimer-webmcp-cockpit\/assets\/icon-128x128.png?rev=3678754","icon_2x":"https:\/\/ps.w.org\/ostheimer-webmcp-cockpit\/assets\/icon-256x256.png?rev=3678754","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/ostheimer-webmcp-cockpit\/assets\/screenshot-1.png?rev=3678754","caption":"The cockpit: agent tool status, the full tool list and a quick-start guide."},{"src":"https:\/\/ps.w.org\/ostheimer-webmcp-cockpit\/assets\/screenshot-2.png?rev=3678754","caption":"The review queue: inspect agent drafts and approve them with one click."}],"raw_content":"<!--section=description-->\n<p><strong>Ostheimer Cockpit for WebMCP<\/strong> turns your WordPress site into a set of structured tools for\nAI agents that run through your browser. It implements the experimental\n<a href=\"https:\/\/webmachinelearning.github.io\/webmcp\/\">WebMCP Draft Community Group Report<\/a>,\nwhich is not a W3C Standard. Compatible browser agents can discover what your\nsite can do and act on it. The plugin requires no separate MCP server and no\nplugin API key.<\/p>\n\n<p>The agent drafts; the human approves.<\/p>\n\n<h4>How it works<\/h4>\n\n<ol>\n<li>Install and activate the plugin, then open the normal WordPress dashboard\nor the <strong>Cockpit for WebMCP<\/strong> page \u2014 both register the agent tools in your\nbrowser. A native dashboard box shows the live status and quick links.<\/li>\n<li>Enable experimental WebMCP support. Chrome 149+ offers an origin trial and\na local testing flag; the cockpit links to the current Chrome instructions.<\/li>\n<li>Tell your browser's AI agent what to do, for example:\n<em>\"Write a draft post about pumpkin recipes and submit it for review.\"<\/em><\/li>\n<li>The agent drafts the content and submits it with the status\n<strong>Zur Pr\u00fcfung<\/strong> (pending review) \u2014 it never publishes on its own.<\/li>\n<li>You review the draft in the review queue and approve it with one click.<\/li>\n<\/ol>\n\n<p>Tool registration and WordPress requests run in your browser tab and your own\nWordPress installation. The plugin itself does not send content to the plugin\ndeveloper or another third-party service. Your chosen browser, AI agent, or\nextension may process prompts, page content, tool inputs, or tool results on\nexternal systems under its provider\u2019s terms and privacy policy.<\/p>\n\n<h4>Agent tools included<\/h4>\n\n<ul>\n<li><code>create_post<\/code> \/ <code>update_post<\/code> \u2014 common core post fields: title, content,\nexcerpt, slug, author, scheduling date (planned posts), comment and ping\nstatus, password protection, sticky, post format, page attributes\n(parent, template, order).<\/li>\n<li>Featured images in one step \u2014 the agent passes an image URL or uploads\nself-generated images as Base64 (PNG, JPEG, WebP, GIF), the plugin puts\nthem into the media library and sets the featured image.<\/li>\n<li>Taxonomies by name \u2014 <code>categories_names<\/code> \/ <code>tags_names<\/code> resolve names to\nterms; missing tags are created automatically.<\/li>\n<li>SEO fields are written to <strong>Yoast SEO<\/strong> or <strong>Rank Math<\/strong> automatically when\nactive, so agents can set meta titles and descriptions where your SEO\nplugin actually reads them.<\/li>\n<li><code>list_posts<\/code>, <code>get_post<\/code>, <code>get_post_markdown<\/code> \u2014 search and read content in\nagent-friendly formats.<\/li>\n<li><code>list_terms<\/code>, <code>get_site_info<\/code>, <code>get_activity<\/code> \u2014 context and audit trail.<\/li>\n<li><code>upload_media<\/code>, <code>upload_media_base64<\/code> \u2014 media library uploads.<\/li>\n<li>Developers can register their own agent tools with the\n  webmcp_cockpit_tools filter \u2014 anything a PHP callback can do becomes an\nagent tool.<\/li>\n<\/ul>\n\n<h4>Safe by design<\/h4>\n\n<ul>\n<li>Agent content lands in a dedicated review status, invisible to visitors.<\/li>\n<li>Publishing is only possible from the review queue, and only for users with\nthe publish capability.<\/li>\n<li>Successful and failed agent tool calls plus workflow actions are written to\na controllable activity log with timestamp and user. Read entries contain\nmetadata only, never post content, search terms, tool inputs or tool results.<\/li>\n<li>Session-bound authentication with a dedicated workflow nonce; per-user rate\nlimiting on write operations.<\/li>\n<li>Works with caching plugins (Autoptimize, WP Rocket, LiteSpeed Cache,\nW3 Total Cache, SG Optimizer) and with the Classic Editor and Gutenberg.<\/li>\n<\/ul>\n\n<h4>For developers<\/h4>\n\n<p>The cockpit is extensible: register custom tools via\n    apply_filters( 'webmcp_cockpit_tools', $tools ) with a name, description,\nJSON schema and PHP callback. Custom tools appear alongside the built-in ones\nin the browser agent's tool list.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>ostheimer-webmcp-cockpit<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install\nit through the WordPress plugin directory.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> screen.<\/li>\n<li>Open the normal WordPress dashboard or <strong>Cockpit for WebMCP<\/strong> in your admin\nmenu. The dashboard box shows the live registration status and quick links.<\/li>\n<li>Keep that dashboard or cockpit tab open and talk to your browser's AI\nagent.<\/li>\n<\/ol>\n\n<p>Requirements: WordPress 6.0+, PHP 7.4+, and a browser or extension that\nimplements the experimental WebMCP API (<code>document.modelContext<\/code>). Chrome 149+\noffers WebMCP through an origin trial or the\n    chrome:\/\/flags\/#enable-webmcp-testing flag for local testing. WebMCP is in\nearly preview and its API may change.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"can%20the%20ai%20agent%20publish%20posts%20on%20its%20own%3F\"><h3>Can the AI agent publish posts on its own?<\/h3><\/dt>\n<dd><p>No. By design the agent can only create or update drafts and content in the\ndedicated review status. Published or scheduled content cannot be changed or\nmoved by an agent. Publishing is a separate, capability-protected action that\na human performs in the review queue.<\/p><\/dd>\n<dt id=\"which%20ai%20agents%20work%20with%20this%3F\"><h3>Which AI agents work with this?<\/h3><\/dt>\n<dd><p>Any compatible browser agent or extension that uses the experimental WebMCP\nAPI (<code>document.modelContext<\/code>). The Model Context Tool Inspector can list and\nmanually call tools for testing. Its natural-language prompts may be processed\nby an external AI provider, so review the extension\u2019s current terms before\nusing private content.<\/p><\/dd>\n<dt id=\"does%20it%20send%20my%20content%20to%20external%20services%3F\"><h3>Does it send my content to external services?<\/h3><\/dt>\n<dd><p>The plugin itself does not send your content to the plugin developer or another\nthird-party service. Tool calls reach your own WordPress REST API using your\nlogged-in session. However, the browser, AI agent, or extension you choose may\nsend prompts, page content, tool inputs, or tool results to its provider.\nReview that provider\u2019s terms and privacy policy before using private content.<\/p><\/dd>\n<dt id=\"do%20i%20need%20an%20mcp%20server%20or%20api%20keys%3F\"><h3>Do I need an MCP server or API keys?<\/h3><\/dt>\n<dd><p>No separate MCP server or plugin API key is required. The tools live on the\nWordPress admin page and the browser mediates between the agent and that page.\nThe browser agent itself may still require its own account or configuration.<\/p><\/dd>\n<dt id=\"which%20browsers%20are%20supported%3F\"><h3>Which browsers are supported?<\/h3><\/dt>\n<dd><p>Chrome 149+ exposes experimental WebMCP through an origin trial or the\n    chrome:\/\/flags\/#enable-webmcp-testing flag for local testing. Other browsers\nor extensions can work if they implement the current draft. WebMCP is an early\npreview, not a W3C Standard, and support may change. WordPress continues to\nwork normally when WebMCP is unavailable.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20yoast%20seo%20%2F%20rank%20math%3F\"><h3>Does it work with Yoast SEO \/ Rank Math?<\/h3><\/dt>\n<dd><p>Yes. SEO title, meta description and canonical URL written by the agent go\ndirectly into the active SEO plugin's fields. Without an SEO plugin, portable\ncustom fields are used.<\/p><\/dd>\n<dt id=\"what%20is%20the%20upload%20size%20limit%20for%20agent%20images%3F\"><h3>What is the upload size limit for agent images?<\/h3><\/dt>\n<dd><p>Base64 image uploads accept PNG, JPEG, WebP and GIF up to\n    min( wp_max_upload_size(), 10 MB ) of decoded data. The JSON request body is\nroughly 1.37\u00d7 the image size, so your host's <code>post_max_size<\/code> must be at least\nthat; the error message names the exact limit when it is exceeded.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20woocommerce%20or%20custom%20post%20types%3F\"><h3>Does it work with WooCommerce or custom post types?<\/h3><\/dt>\n<dd><p>Posts and pages are supported out of the box. Additional post types and\ncapabilities can be added with the <code>webmcp_cockpit_tools<\/code> filter \u2014 for\nexample WooCommerce product tools.<\/p><\/dd>\n<dt id=\"who%20can%20use%20the%20agent%20tools%3F\"><h3>Who can use the agent tools?<\/h3><\/dt>\n<dd><p>Only logged-in users with the <code>edit_posts<\/code> capability (authors, editors,\nadministrators). Media uploads additionally require <code>upload_files<\/code>,\npublishing requires the publish capability. Guests and subscribers get\nnothing.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.11<\/h4>\n\n<ul>\n<li>Renames the plugin to <strong>Ostheimer Cockpit for WebMCP<\/strong> and aligns the plugin\nfolder, main file and text domain with <code>ostheimer-webmcp-cockpit<\/code>.<\/li>\n<li>Limits post-list results to posts the current user is allowed to edit, with\nregression coverage for separate author accounts.<\/li>\n<li>Moves the plugin pages below WordPress <strong>Tools<\/strong> and removes the obsolete\nmanual translation loader and bundled runtime translation files.<\/li>\n<li>Makes Plugin Check warnings fail the release check.<\/li>\n<\/ul>\n\n<h4>1.0.10<\/h4>\n\n<ul>\n<li>Refines the WordPress dashboard box with a clearer action hierarchy, compact\nnative buttons and consistent spacing in narrow dashboard columns.<\/li>\n<li>Keeps the copy action beside the prompt label and gives the review queue\nprimary emphasis above the two secondary links.<\/li>\n<\/ul>\n\n<h4>1.0.9<\/h4>\n\n<ul>\n<li>Registers all WebMCP tools on the normal WordPress start dashboard (<code>\/wp-admin\/<\/code>)\nin addition to the dedicated Cockpit page.<\/li>\n<li>Adds a native, draggable dashboard box with live tool status, a copyable\nexample prompt, review count, and links to the Cockpit and activity log.<\/li>\n<li>Adds server-side regression coverage for the dashboard widget and asset host.<\/li>\n<\/ul>\n\n<h4>1.0.8<\/h4>\n\n<ul>\n<li>Adds a complete metadata-only audit trail for successful and failed WebMCP\ntool calls, including read tools such as <code>list_posts<\/code> and <code>get_post<\/code>.<\/li>\n<li>Adds administrator filters for read\/write and tool\/workflow events, bulk\nselection, and nonce-protected deletion of selected, filtered or all log\nentries. Agents cannot delete the audit log.<\/li>\n<li>Adds an automatic database migration for the activity type and tool-name\ncolumns when updating the plugin in place.<\/li>\n<\/ul>\n\n<h4>1.0.7<\/h4>\n\n<ul>\n<li>Enforces the human review boundary: browser agents cannot update, publish or\nunpublish published or scheduled content; only the review queue can publish.<\/li>\n<li>Completes the <code>create_post<\/code> and <code>update_post<\/code> schemas for author, scheduling,\npassword, sticky, post format, page attributes and canonical URL fields.<\/li>\n<li>Keeps agent-facing source output in English and clarifies that the activity\nlog records agent write actions.<\/li>\n<\/ul>\n\n<h4>1.0.6<\/h4>\n\n<ul>\n<li>Tool errors now return a machine-readable signal (<code>isError: true<\/code> plus a\nstable <code>code<\/code>, following the MCP CallToolResult convention) instead of\nrelying on localized text prefixes. The readable, translatable message\nstays unchanged.<\/li>\n<li>Clarifies that WebMCP is experimental and distinguishes the plugin\u2019s own\ndata handling from external processing by a chosen browser or AI agent.<\/li>\n<\/ul>\n\n<h4>1.0.5<\/h4>\n\n<ul>\n<li>Sharper agent-facing tool descriptions: http(s)-only URLs for\n  upload_media, formats\/size limit\/filename handling for\n  upload_media_base64, precedence and failure behaviour for\n  featured_image_url\/<code>featured_media_id<\/code>, and the warning behaviour of\n  create_post when a featured image fails.<\/li>\n<li>Regression suite (<code>tests\/<\/code>) and documentation for server-side edge cases.<\/li>\n<\/ul>\n\n<h4>1.0.4<\/h4>\n\n<ul>\n<li>i18n: the plugin source is now fully English and translation-ready.\nA German (de_DE) translation ships with the plugin.<\/li>\n<\/ul>\n\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Fix: a failed featured-image import from <code>featured_image_url<\/code> (e.g. a URL\nthat returns no image) no longer reports success and no longer touches an\nexisting featured image; imported attachments are verified as real images\nfrom the downloaded bytes, failed imports are cleaned up.<\/li>\n<li>Fix: error messages now name the originally submitted value for invalid\nmedia IDs (e.g. <code>-5<\/code>) and distinguish URL format errors from network\/DNS\nerrors.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Fix: invalid <code>featured_media_id<\/code> values now return a clear error instead of\na silent success; attachments are validated for existence and image type.<\/li>\n<li>Fix: rejected media uploads (wrong type, broken Base64, size limit) are now\nrecorded in the activity log as <code>media_rejected<\/code> entries.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>New: <code>upload_media_base64<\/code> tool \u2014 agents can upload self-generated images\n(PNG, JPEG, WebP, GIF) directly into the media library without a public URL.\nReal MIME type is verified from the decoded bytes; size capped at 10 MB.<\/li>\n<li>New: <code>featured_media_id<\/code> parameter for <code>create_post<\/code>\/<code>update_post<\/code> \u2014 assign\na featured image from an existing media ID (takes precedence over\n  featured_image_url).<\/li>\n<li>Tool errors now return readable messages to the agent.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release: 10 agent tools for creating, updating and reviewing posts,\nfull post field coverage, featured images from URL, taxonomy assignment by\nname, SEO plugin integration (Yoast SEO, Rank Math), review workflow with\nhuman approval, activity log, rate limiting and a PHP API for custom tools.<\/li>\n<\/ul>","raw_excerpt":"Let browser-based AI agents write, edit and manage WordPress posts \u2014 with a human review step before anything is published.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/361226","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=361226"}],"author":[{"embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/helpstring"}],"wp:attachment":[{"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=361226"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=361226"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=361226"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=361226"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=361226"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=361226"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}