{"id":337059,"date":"2026-07-30T20:09:47","date_gmt":"2026-07-30T20:09:47","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/alphabridge-mcp\/"},"modified":"2026-09-27T08:01:18","modified_gmt":"2026-09-27T08:01:18","slug":"alphabridge-mcp","status":"publish","type":"plugin","link":"https:\/\/bcc.wordpress.org\/plugins\/alphabridge-mcp\/","author":23528922,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"4.3.5","stable_tag":"4.3.5","tested":"7.1.2","requires":"6.5","requires_php":"8.0","requires_plugins":null,"header_name":"AlphaBridge MCP","header_author":"AlphaBridge","header_description":"Connect Claude and other MCP clients directly and securely to WordPress. Native Streamable-HTTP MCP server \u2014 fast, stable, with tool-group switches.","assets_banners_color":"ffffff","last_updated":"2026-09-27 08:01:18","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/www.alphabridge-mcp.com","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":577,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"4.2.0":{"tag":"4.2.0","author":"cultureclub","date":"2026-07-30 20:47:58","revision":3629110},"4.2.2":{"tag":"4.2.2","author":"cultureclub","date":"2026-08-26 17:36:48","revision":3667544},"4.2.3":{"tag":"4.2.3","author":"cultureclub","date":"2026-08-28 22:08:38","revision":3670959},"4.3.0":{"tag":"4.3.0","author":"cultureclub","date":"2026-09-14 08:07:28","revision":3694747},"4.3.1":{"tag":"4.3.1","author":"cultureclub","date":"2026-09-15 12:51:12","revision":3697000},"4.3.2":{"tag":"4.3.2","author":"cultureclub","date":"2026-09-16 19:03:07","revision":3699154},"4.3.3":{"tag":"4.3.3","author":"cultureclub","date":"2026-09-22 14:03:08","revision":3707487},"4.3.4":{"tag":"4.3.4","author":"cultureclub","date":"2026-09-26 19:41:12","revision":3714670},"4.3.5":{"tag":"4.3.5","author":"cultureclub","date":"2026-09-27 08:01:18","revision":3715124}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3629098,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3629098,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3629098,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3629098,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{"blueprint.json":{"filename":"blueprint.json","revision":3715124,"resolution":false,"location":"assets","locale":"","contents":"{\"$schema\":\"https:\\\/\\\/playground.wordpress.net\\\/blueprint-schema.json\",\"landingPage\":\"\\\/wp-admin\\\/options-general.php?page=alphabridge-mcp\",\"preferredVersions\":{\"php\":\"8.3\",\"wp\":\"latest\"},\"phpExtensionBundles\":[\"kitchen-sink\"],\"steps\":[{\"step\":\"login\",\"username\":\"admin\",\"password\":\"password\"},{\"step\":\"installPlugin\",\"pluginData\":{\"resource\":\"wordpress.org\\\/plugins\",\"slug\":\"alphabridge-mcp\"},\"options\":{\"activate\":true}}]}"}},"all_blocks":[],"tagged_versions":["4.2.0","4.2.2","4.2.3","4.3.0","4.3.1","4.3.2","4.3.3","4.3.4","4.3.5"],"block_files":[],"assets_screenshots":{"screenshot-1.jpg":{"filename":"screenshot-1.jpg","revision":3714212,"resolution":"1","location":"assets","locale":"","width":2560,"height":1690},"screenshot-2.jpg":{"filename":"screenshot-2.jpg","revision":3714212,"resolution":"2","location":"assets","locale":"","width":2560,"height":1330},"screenshot-3.jpg":{"filename":"screenshot-3.jpg","revision":3714212,"resolution":"3","location":"assets","locale":"","width":2560,"height":1400},"screenshot-4.jpg":{"filename":"screenshot-4.jpg","revision":3714212,"resolution":"4","location":"assets","locale":"","width":2560,"height":1720},"screenshot-5.jpg":{"filename":"screenshot-5.jpg","revision":3714212,"resolution":"5","location":"assets","locale":"","width":2560,"height":720},"screenshot-6.jpg":{"filename":"screenshot-6.jpg","revision":3714212,"resolution":"6","location":"assets","locale":"","width":2560,"height":560}},"screenshots":{"1":"Set up the Claude connector in two steps: copy the endpoint URL, then connect from Claude \u2014 or create a token manually for Cursor, Claude Code and scripts. Existing connections are listed and managed in the same place.","2":"The moment you create a connection, the plugin shows what you need once \u2014 the Bearer token and a copy-paste config for Cursor \/ Claude Code, and the connector URL if connector-URL authentication is switched on \u2014 with a reminder to save it, because the token is shown in full only once.","3":"Optional advanced settings for a connection: a label, the WordPress user it acts as, full, content-only or read-only access, and an optional expiry in days.","4":"Enable or disable tools by functional group. Powerful (\"mighty\") tools are off by default, and one switch turns on a global read-only mode.","5":"Connect from Claude is on by default: Claude discovers the site, you approve on a login-protected consent screen, and the approved connection appears in the list, revocable any time. Switching it off removes the OAuth endpoints.","6":"Connector-URL authentication is off by default, because a token in a URL leaks more easily than one in a header; the setting explains the trade-off before you switch it on."}},"plugin_section":[],"plugin_tags":[2353,216196,229563,242115,260626],"plugin_category":[59],"plugin_contributors":[273898],"plugin_business_model":[],"class_list":["post-337059","plugin","type-plugin","status-publish","hentry","plugin_tags-ai","plugin_tags-chatgpt","plugin_tags-claude","plugin_tags-mcp","plugin_tags-mcp-server","plugin_category-utilities-and-tools","plugin_contributors-cultureclub","plugin_committers-cultureclub"],"banners":{"banner":"https:\/\/ps.w.org\/alphabridge-mcp\/assets\/banner-772x250.png?rev=3629098","banner_2x":"https:\/\/ps.w.org\/alphabridge-mcp\/assets\/banner-1544x500.png?rev=3629098","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/alphabridge-mcp\/assets\/icon-128x128.png?rev=3629098","icon_2x":"https:\/\/ps.w.org\/alphabridge-mcp\/assets\/icon-256x256.png?rev=3629098","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/alphabridge-mcp\/assets\/screenshot-1.jpg?rev=3714212","caption":"Set up the Claude connector in two steps: copy the endpoint URL, then connect from Claude \u2014 or create a token manually for Cursor, Claude Code and scripts. Existing connections are listed and managed in the same place."},{"src":"https:\/\/ps.w.org\/alphabridge-mcp\/assets\/screenshot-2.jpg?rev=3714212","caption":"The moment you create a connection, the plugin shows what you need once \u2014 the Bearer token and a copy-paste config for Cursor \/ Claude Code, and the connector URL if connector-URL authentication is switched on \u2014 with a reminder to save it, because the token is shown in full only once."},{"src":"https:\/\/ps.w.org\/alphabridge-mcp\/assets\/screenshot-3.jpg?rev=3714212","caption":"Optional advanced settings for a connection: a label, the WordPress user it acts as, full, content-only or read-only access, and an optional expiry in days."},{"src":"https:\/\/ps.w.org\/alphabridge-mcp\/assets\/screenshot-4.jpg?rev=3714212","caption":"Enable or disable tools by functional group. Powerful (\"mighty\") tools are off by default, and one switch turns on a global read-only mode."},{"src":"https:\/\/ps.w.org\/alphabridge-mcp\/assets\/screenshot-5.jpg?rev=3714212","caption":"Connect from Claude is on by default: Claude discovers the site, you approve on a login-protected consent screen, and the approved connection appears in the list, revocable any time. Switching it off removes the OAuth endpoints."},{"src":"https:\/\/ps.w.org\/alphabridge-mcp\/assets\/screenshot-6.jpg?rev=3714212","caption":"Connector-URL authentication is off by default, because a token in a URL leaks more easily than one in a header; the setting explains the trade-off before you switch it on."}],"raw_content":"<!--section=description-->\n<p><strong>Connect Claude and ChatGPT to WordPress \u2014 with the rights you choose.<\/strong><\/p>\n\n<p>AlphaBridge MCP turns your WordPress site into a native <strong>MCP server<\/strong> (Model Context Protocol). An AI assistant such as Claude \u2014 on Claude.ai, in Claude Desktop, Claude Code or Cursor \u2014 connects over one authenticated HTTPS endpoint and manages content, media, taxonomies, comments, widgets and site settings through structured tools that check WordPress permissions on every single call. ChatGPT connects the same way, as an MCP app on the Plus, Pro, Business, Enterprise and Edu plans. Tell Claude what you want done \u2014 \"draft a post from these notes, add last week's photos, file it under the right categories and schedule it for Friday\" \u2014 and it happens on your site, not through screen-clicking or raw admin access.<\/p>\n\n<p><strong>You stay in control<\/strong><\/p>\n\n<p>Handing an AI the keys to your site should feel safe \u2014 so control comes first:<\/p>\n\n<ul>\n<li>Every connection acts as a real WordPress user, and every tool checks the matching WordPress capability. What that user may not do, the AI cannot do.<\/li>\n<li>Scoped connections: hand out a read-only or content-only key with an optional expiry instead of full access. Rotate a connection's secret in one click.<\/li>\n<li>Tool groups you can switch off entirely \u2014 disabled tools vanish from the MCP surface. Plus a global read-only mode.<\/li>\n<li>An audit log records every tool call, and a fixed rate limit stops abusive request bursts.<\/li>\n<\/ul>\n\n<p><strong>Connected in two minutes<\/strong><\/p>\n\n<p>Paste your endpoint URL into Claude, click Connect, approve on your own site's login-protected consent screen \u2014 no token copying (standard OAuth 2.1 with PKCE; the login is your WordPress login, no account with us). For clients without a Connect button, create a token manually and paste one ready-made config. ChatGPT connects the same way: add the endpoint as an MCP app (Plugins \u2192 Add \u2192 Create MCP app, authentication OAuth) and approve on your site \u2014 checked on 26 September 2026 with ChatGPT Pro, directly and through the hub.<\/p>\n\n<p><strong>Several sites, one connection \u2014 AlphaBridge Connect<\/strong><\/p>\n\n<p>If you look after more than one WordPress site, you can add one connector in Claude or ChatGPT instead of one per site: the hosted hub at connect.alphabridge-mcp.com links your sites to a single connection in the client you use. Each site keeps its own rights and its own audit log, and you approve every site on that site's own login screen. The hub is optional and free, and this plugin never contacts it on its own \u2014 the hub connects to your site for authorization, connection setup and management, and to forward the tool calls you make through it. It stores the site's access key encrypted and passes content through without storing it; the details are in its privacy notice (https:\/\/connect.alphabridge-mcp.com\/legal\/privacy) and its data processing agreement (https:\/\/connect.alphabridge-mcp.com\/legal\/dpa).<\/p>\n\n<p><strong>Nothing extra to host<\/strong><\/p>\n\n<p>Unlike bridge-based solutions, AlphaBridge speaks MCP directly in PHP inside WordPress. With a direct connection there is no Node middleware, no external service and nothing else to run or pay for \u2014 it works on ordinary WordPress hosting, which makes it faster and more stable. The hub above is the one optional exception, and you choose whether to use it.<\/p>\n\n<p><strong>Free means free<\/strong><\/p>\n\n<p>Everything in this plugin is fully functional: no license keys, no registration, no plan-based, cumulative or time-based usage limits, no locked features.<\/p>\n\n<p><strong>What's inside<\/strong><\/p>\n\n<ul>\n<li>Native MCP endpoint (JSON-RPC 2.0 over HTTP POST; protocol versions 2024-11-05, 2025-03-26, 2025-06-18) \u2014 no external server required.<\/li>\n<li>39 structured tools across content, media, taxonomies, comments, widgets, site settings, site info, SEO reads and search.<\/li>\n<li>Bearer-token authentication mapped to a real WordPress user, with per-tool capability checks.<\/li>\n<li>Unlimited connections \u2014 create one deliberately limited key per client.<\/li>\n<\/ul>\n\n<p><strong>How it compares<\/strong><\/p>\n\n<p>A dated comparison with other WordPress MCP plugins, every cell checked against the vendors' own pages: https:\/\/alphabridge-mcp.com\/compare.html<\/p>\n\n<p>Need more? A separate commercial add-on, AlphaBridge MCP Pro, adds tool groups for the database, users, plugin and theme files, WooCommerce and migration, plus an undo for changes made through it (undo points expire after 24 hours). The Agency plan adds Site Deploy: files, themes and whole builds published onto your own hosting over SFTP; ZIP deploys can run atomically, with rollback when the swap fails. Both are entirely optional \u2014 this free plugin is complete on its own and stays fully functional without them. Details are on the plugin website.<\/p>\n\n<p>AlphaBridge is our own product brand for this project. MCP (Model Context Protocol) is an open protocol standard; this plugin is an independent implementation and is not affiliated with or endorsed by the protocol's authors or by any other vendor.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin makes no automatic outbound requests and sends no telemetry. One tool can contact an external address, and only on your explicit instruction: when you call <code>wp_upload_media_from_url<\/code> with a URL, the plugin downloads that file from the address you provide (and up to a few safely re-validated redirects; SSRF-guarded, type- and size-checked). The plugin itself initiates no other outbound requests.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>alphabridge-mcp<\/code> folder to <code>\/wp-content\/plugins\/<\/code> (or install the ZIP via Plugins \u2192 Add New \u2192 Upload).<\/li>\n<li>Activate the plugin.<\/li>\n<li>In Claude (Settings \u2192 Connectors \u2192 Add custom connector) add the endpoint <code>https:\/\/your-site.tld\/wp-json\/alphabridge\/v1\/mcp<\/code> and click Connect \u2014 you approve on your own site's login-protected consent screen. Done. In ChatGPT: Plugins \u2192 Add \u2192 Create MCP app with the same URL and OAuth.<\/li>\n<li>For clients without a Connect button (Cursor, Claude Code, scripts): open <strong>Settings \u2192 AlphaBridge MCP<\/strong>, create a connection manually and copy its token.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20it%20secure%3F\"><h3>Is it secure?<\/h3><\/dt>\n<dd><p>Every request needs a token bound to a WordPress user; each tool enforces the matching WordPress capability, including object-level checks for the specific post, attachment or taxonomy (non-public taxonomies additionally require that taxonomy's own capability). Powerful tools are off by default and only run once the admin enables their group. All calls are logged. Arbitrary option or transient values cannot be read through this plugin at all \u2014 only a fixed list of common site settings is exposed. Post, term and user meta is layered-protected: protected (\"_\"-prefixed) keys, keys flagged by is_protected_meta(), and two kinds of credential-shaped key are refused: keys whose whole name is a credential word, singular or plural (token, secret, password, passphrase, passcode, pwd, otp, credential), and keys containing one of a fixed list of compound credential patterns (api_key, access_token, client_secret, license_key, oauth, _token, _secret, _password, passwd, \u2026). Case and surrounding whitespace are ignored. The list is matched literally, which makes this guard deliberately conservative rather than exhaustive: token_count, password_hint, credential_type, api_version, counters such as maxTokens and camelCase spellings such as accessToken all pass it, and the layers around it do the real work \u2014 and every generic post, term and user meta read or write additionally passes WordPress's own per-key meta capability (edit_post_meta \/ edit_term_meta \/ edit_user_meta), which honours auth_callback rules that other plugins register via register_meta() (the media and SEO tools read only their own fixed keys). A key you may not edit is not exposed over MCP either. Tokens are accepted via the Authorization or X-Api-Key header \u2014 header authentication is the default. An admin can optionally enable a connector URL that carries the token in its path (served with Referrer-Policy: no-referrer and Cache-Control: no-store); this is off by default, because a token in a URL leaks more easily. Query-string tokens are never accepted. If you turn the connector URL on, treat it like a password: it contains the token \u2014 rotate the connection if the URL is shared, logged or pasted anywhere.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20shared%20hosting%3F\"><h3>Does it work on shared hosting?<\/h3><\/dt>\n<dd><p>Yes. It is pure PHP and uses the WordPress REST API. PHP 8.0+ and HTTPS are recommended.<\/p><\/dd>\n<dt id=\"is%20the%20free%20plugin%20limited%3F\"><h3>Is the free plugin limited?<\/h3><\/dt>\n<dd><p>No. Every feature in this plugin works without payment, registration or license keys, and there are no plan-based, cumulative or time-based usage limits. A uniform security throttle (120 requests\/minute, identical for every user) protects your server from abusive request bursts.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20send%20data%20anywhere%3F\"><h3>Does the plugin send data anywhere?<\/h3><\/dt>\n<dd><p>No. It contacts no external service on its own. The only outbound request happens when you explicitly ask a tool to fetch a file from a URL you provide (see External services).<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>4.3.5<\/h4>\n\n<ul>\n<li>A request for a review on WordPress.org, on the plugin's own settings page only. It appears once a site has been using the plugin for at least 14 days and has made at least 50 successful tool calls, links to the review form (whatever your verdict), and stays on that page until \u00abDon't ask again\u00bb ends it for good \u2014 also across updates, and no tool call that is still counting can undo it. The counter stops once 50 successful calls are stored, so counting is a small, bounded cost rather than a write per call; nothing is sent anywhere.<\/li>\n<li>Times on the settings screen follow the site's timezone. \u00abLast used\u00bb in the connections list measured against the site's local clock instead of real time and was off by the site's UTC offset: on a site in Central European summer time, a connection used a minute ago read \u00ab2 hours ago\u00bb. The log showed the UTC clock without saying so. Both now read like every other time in WordPress.<\/li>\n<li>A connection made by approving an app on this site is labelled with the app's name and \u00abOAuth\u00bb, for example \u00abChatGPT \u00b7 OAuth\u00bb, instead of \u00ab\u2026 \u00b7 Claude Connect\u00bb, which put Claude's name on every app that connects this way. A connection through AlphaBridge Connect keeps that name alone. Existing connections keep the label they were given.<\/li>\n<li>The connections list marks an older connection when the same app has connected again for the same user. ChatGPT's \u00abreconnect\u00bb, for one, leaves the earlier connection working. Nothing is removed automatically, because a second connection of the same app can be wanted; compare \u00abLast used\u00bb and delete the one no longer in use. Only connections made from this version on can be matched.<\/li>\n<li>Post, media, revision and comment dates in the tools' answers are in the site's time with the UTC offset written out, for example \u00ab2026-06-16T09:00:00+02:00\u00bb. They used to be the UTC time without saying so: a post published at 09:00 in Zurich read as 07:00. A draft whose date is not fixed yet shows its local date instead of \u00ab0000-00-00 00:00:00\u00bb; no date at all is null. A date whose offset has seconds, like Zurich before 1894, or that would leave the years 1 to 9999 in site time, is given in UTC (\u00ab\u2026Z\u00bb). wp_create_post takes this form as well as site time as before. A date it cannot use is refused with the reason: no such day, a time the clocks skip, a year out of range, or a time where they go back that WordPress would read, and schedule, as the other of the two.<\/li>\n<li>Uninstalling the plugin now also removes the list of apps that registered with the site to connect through OAuth \u2014 their names, return addresses and when they registered and last connected; that list stayed in the database until now. On a network, uninstalling now cleans every site: it stopped after the first 100, and the sites beyond kept their connections and settings.<\/li>\n<\/ul>\n\n<h4>4.3.4<\/h4>\n\n<ul>\n<li>The capabilities screen says what to do after saving: a client that is already connected may cache the tool list it loaded, and this endpoint offers no server-initiated stream, so it cannot push <code>notifications\/tools\/list_changed<\/code>; if a change is not visible in such a client, refresh its tool list or reconnect it. The message after saving and a note under the Save button say so. Found by the acceptance test of 25 September 2026, where a newly enabled tool stayed invisible to a connected client until it reconnected.<\/li>\n<li>Widget ids are trimmed and matched to the end of the string. An id such as <code>text-2<\/code> followed by a newline was split into its base and number (the pattern ended in <code>$<\/code>, which also matches before a trailing newline) but never found in the sidebar map, so a delete removed the settings row and left the sidebar entry behind. Found while re-reading the widget tools after the September 2026 security review.<\/li>\n<li><code>wp_upload_media_from_url<\/code> now says what it does. The site itself downloads the file from a public http(s) URL through WordPress' safe-URL check (private and internal hosts refused unless WordPress itself allows them, such as the site's own host; checked on every redirect), with at most 3 redirects, 20 seconds per request and 20 MB by default; the URL or the content type must say JPEG, PNG, GIF, WebP or PDF, and WordPress then checks the file as for any upload. Behaviour unchanged; the description is what Claude reads before choosing a tool, and the automatic check in Anthropic's connector portal asked for a description that names the source.<\/li>\n<\/ul>\n\n<h4>4.3.3<\/h4>\n\n<ul>\n<li><strong>Security: a connection for another user can only be created by someone who may edit that user.<\/strong> The token form accepted any user id: an administrator could issue a full-access connection in the name of any account \u2014 on a multisite network also in the name of a network administrator, whose rights a site administrator does not have \u2014 and rotating an existing entry had the same gap. Creating and rotating now require WordPress' own <code>edit_user<\/code> right for the account the connection acts as; on multisite a network administrator's connection can only be issued by a network administrator. Existing entries are left as they are: if connections for other users exist, look through the list. Found by an external code review in September 2026.<\/li>\n<li><strong>Security: password-protected posts no longer hand out their text to every token whose user may edit posts at all.<\/strong> <code>wp_get_post<\/code> and <code>wp_duplicate_post<\/code> checked <code>read_post<\/code>, which for a published post means \"may read the site\" and does not look at the post password; a revision of such a post carries the text but never the password, so it had the same gap. Both tools now require the right to edit the post when a password is set, and a revision \u2014 its text as well as its excerpt in any listing \u2014 is available only to someone who may edit its parent, the rule the WordPress REST API applies in its edit context. <code>wp_list_revisions<\/code> follows the same rule, <code>wp_list_posts<\/code> lists revisions only for one post at a time and only for someone who may edit it, and <code>wp_search<\/code> does not search revisions at all \u2014 a bare count of matches would already tell of the text. Same review.<\/li>\n<li><strong>Hardening: the pending-consent record of a Claude connection is signed.<\/strong> The record that carries user, scope and PKCE challenge from the consent page to the token endpoint lives in WordPress' transient store, which every plugin and any generic \"set transient\" tool can write to. It now carries a signature over its fields and its storage key, made with the site's auth salt; the token endpoint refuses a record without a valid signature, one older than a code's two minutes, or one naming an unknown scope. Consent records written before the update are refused too; they live for two minutes, so at most a connection started during the update has to be started again. Same review.<\/li>\n<\/ul>\n\n<h4>4.3.2<\/h4>\n\n<ul>\n<li><strong>Change: the rate limit on client registration is thirty per sender and hour instead of ten, and the hour now starts over on its own.<\/strong> The public registration endpoint (RFC 7591) counts requests per sender address. Until now every request that passed the limit gave the counter a fresh hour, so the count only started over after an hour without such a request: ten registrations, each less than an hour after the one before, reached the limit even when spread over an afternoon, and further registrations from that address were refused until an hour after the tenth. The count now starts over one hour after the first request it counted. A registration grants no access by itself, and <code>MAX_CLIENTS<\/code> with eviction keeps the client store from filling up.<\/li>\n<\/ul>\n\n<h4>4.3.1<\/h4>\n\n<ul>\n<li><strong>Fix: four tools told MCP clients they only add data, while they overwrite it.<\/strong> <code>wp_update_post<\/code>, <code>wp_update_media<\/code>, <code>wp_update_term<\/code> and <code>wp_moderate_comment<\/code> reported <code>destructiveHint: false<\/code>, which the Model Context Protocol defines as \"performs only additive updates\". Clients use that hint to decide whether to ask you before a call, so an overwrite could run without a prompt. All four now report <code>destructiveHint: true<\/code>. The hint no longer comes from the \"off by default\" flag, which answers a different question: anything that writes counts as destructive unless it only ever adds (create, upload, duplicate, reply).<\/li>\n<\/ul>\n\n<h4>4.3.0<\/h4>\n\n<ul>\n<li><strong>Breaking (Pro): the WooCommerce tools are renamed.<\/strong> <code>wc_list_orders<\/code> becomes <code>wp_wc_list_orders<\/code>, and so on for all nine. Same reason as below, and the same one-time move of any per-tool on\/off override you had set.<\/li>\n<li><strong>Breaking: the two SEO tools are renamed.<\/strong> <code>seo_detect<\/code> becomes <code>wp_seo_detect<\/code> and <code>seo_get<\/code> becomes <code>wp_seo_get<\/code>. Every other tool already carried the <code>wp_<\/code> prefix; these two did not. The prefix is what keeps a WordPress tool from colliding with a same-named tool from another CMS when a client reaches several sites at once \u2014 without it, two different tools merge into one and one of the two sites gets a description that does not fit it. If you have saved instructions or automations that call the tools by name, change those two names. Nothing else about what they do has changed. If you had switched one of them off in the settings, it stays off \u2014 the stored override moves to the new name during the update.<\/li>\n<li>New: a revocation endpoint (RFC 7009) at <code>\/wp-json\/alphabridge\/v1\/oauth\/revoke<\/code>. A client that holds a connection token can now hand it back and end the connection itself, instead of the connection lingering until somebody deletes it in the settings. The endpoint is announced in the discovery document, so clients find it without being told the path. It answers the same way whether or not the token existed, which is what the standard requires: the answer must not reveal whether a token is valid.<\/li>\n<li>New: the <code>initialize<\/code> response now carries a short self-description under <code>_meta<\/code> \u2014 which CMS answered, its version, the plugin version, the licensed edition and the scope of the token that was used. A hub or client that speaks to several sites can tell them apart without guessing from version strings. Nothing about your content is included.<\/li>\n<li>Change: a connection created through AlphaBridge Connect is now labelled with that name alone in the connections list, instead of \"AlphaBridge Connect \u00b7 Claude Connect\".<\/li>\n<\/ul>\n\n<h4>4.2.3<\/h4>\n\n<ul>\n<li>Fix: a backslash in a title, name, description, comment or custom field was silently dropped when writing. WordPress expects the data it is given to be escaped and removes one level of escaping itself, so passing it through unchanged turned \"C:\\Docs\" into \"C:Docs\" \u2014 with no error anywhere. Every write path now escapes what it hands over: posts and pages, media titles and alt text, terms, post meta and comments. Values without a backslash are unaffected, and nothing already stored changes.<\/li>\n<\/ul>\n\n<h4>4.2.2<\/h4>\n\n<ul>\n<li>Hardening: the meta-key credential guard now refuses keys whose whole name is a bare credential word \u2014 token, secret, password, passphrase, passcode, pwd, otp, credential, and their plurals. Previously only compound patterns such as api_token or client_secret were caught, so a key named exactly \"token\" could be read or written by a user who already held the key's own edit capability. The compound list itself is unchanged apart from license_key, so everything 4.2.0 refused stays refused and no ordinary key changes behaviour. If one of your fields is named exactly like one of those words, its value stays untouched in the database but is no longer readable or writable over MCP.<\/li>\n<li>Docs: the security answer in the FAQ now describes the rule exactly \u2014 which names are refused as a whole, that the compound list is matched literally, and where the guard deliberately stops \u2014 instead of implying that any key containing \"token\" or \"secret\" is refused.<\/li>\n<\/ul>\n\n<h4>4.2.0<\/h4>\n\n<ul>\n<li>New: Connect from Claude. The site now speaks the OAuth flow MCP clients expect: add the endpoint URL in Claude (web, desktop or mobile) and click Connect \u2014 Claude discovers the site, you approve on a login-protected consent screen (choosing full, content-only or read-only access), and the approved connection appears in the connections list like any other, revocable at any time. Technically: RFC 9728\/8414 discovery metadata under \/.well-known\/, dynamic client registration (RFC 7591), authorization-code grant with PKCE (S256 required) and resource indication (RFC 8707); 401 responses point clients at the metadata via WWW-Authenticate. Issued tokens are ordinary hashed connection tokens \u2014 nothing new is stored in readable form. No account with us, no external service: the login is your own WordPress login. Can be switched off under \u201cConnect from Claude (OAuth, advanced)\u201d; manual tokens keep working unchanged.<\/li>\n<\/ul>\n\n<h4>4.1.6<\/h4>\n\n<ul>\n<li>The connector URL is now only offered once connector-URL authentication is actually enabled \u2014 if it is off, a one-click \u201cEnable and show the connector URL\u201d button (with the same security note as the setting itself) appears in its place. A copied connector URL therefore always authenticates; previously the URL was shown with only a small note and would be rejected until the setting was switched on. The Bearer token and the Cursor \/ Claude Code config are unaffected and always work.<\/li>\n<\/ul>\n\n<h4>4.1.5<\/h4>\n\n<ul>\n<li>When you create a connection, the settings screen now shows everything ready for copy-paste: the full connector URL with the token embedded (for Claude.ai), the Bearer token, and a ready-made config snippet for Cursor \/ Claude Code \u2014 plus a clear reminder to save it, because the token is shown in full only once.<\/li>\n<\/ul>\n\n<h4>4.1.4<\/h4>\n\n<ul>\n<li>Simpler, clearer connector setup: the settings screen now shows one \u201cClaude.ai Connector\u201d box with a two-step flow \u2014 copy the endpoint, then click one \u201cCreate connection\u201d button (label, access scope, user and expiry moved into optional advanced settings). The token appears right below the button, and existing connections are listed in the same box. Removes the previous duplicate create buttons.<\/li>\n<\/ul>\n\n<h4>4.1.3<\/h4>\n\n<ul>\n<li>Uninstall no longer removes this plugin's data while the separately distributed AlphaBridge MCP Pro plugin is still installed \u2014 Pro shares this core data (connections, tool state, settings, log), so removing the free plugin alone keeps Pro fully configured. Uninstalling last (or alone) cleans up as before.<\/li>\n<\/ul>\n\n<h4>4.1.2<\/h4>\n\n<ul>\n<li>Added an informational box about the separately distributed AlphaBridge MCP Pro plugin to the plugin's own settings page. Nothing in this free plugin changed \u2014 it remains complete and fully functional on its own.<\/li>\n<\/ul>\n\n<h4>4.1.1<\/h4>\n\n<ul>\n<li>Hardened connection handling: the token is shown once at creation and only its hash is stored; scope values are validated fail-closed; header authentication is the default and connector-URL authentication is an explicit opt-in.<\/li>\n<li>User-meta reads limited to a fixed list of standard profile fields.<\/li>\n<li>Improved capability checks and packaging consistency.<\/li>\n<\/ul>\n\n<h4>4.1.0<\/h4>\n\n<ul>\n<li>Added connection scopes, an optional expiry and one-click rotation.<\/li>\n<li>Improved transport and object-level security.<\/li>\n<\/ul>\n\n<h4>4.0.0<\/h4>\n\n<ul>\n<li>Rebuilt the directory package as a fully standalone free plugin.<\/li>\n<li>Connections are unlimited and every bundled tool is available without restriction.<\/li>\n<li>Removed the raw option\/transient readers; site settings are available through wp_get_site_settings.<\/li>\n<li>Update status is read from WordPress's cache and performs no remote request.<\/li>\n<li>Broadened object-level and per-key capability checks across posts, meta, terms, taxonomies, media and search.<\/li>\n<li>Simplified the settings screen and the distribution package.<\/li>\n<\/ul>\n\n<h4>3.0.0<\/h4>\n\n<ul>\n<li>MCP tool annotations (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) for every tool.<\/li>\n<li>MCP protocol negotiation: the server echoes the client's requested protocol version when supported (2024-11-05, 2025-03-26, 2025-06-18).<\/li>\n<li>New global read-only mode: one switch blocks every writing tool; read, list and search tools keep working.<\/li>\n<li>Better error messages: argument validation reports all missing or invalid fields at once.<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Restructured for the WordPress.org directory: this plugin contains the core free toolset.<\/li>\n<li>Settings-screen JavaScript is enqueued from assets\/admin.js (2.0.2).<\/li>\n<\/ul>\n\n<h4>1.x<\/h4>\n\n<ul>\n<li>Initial development line: MCP endpoint, token auth, tool groups, security hardening (SSRF guards, path traversal guards, capability checks, rate limiting, audit log), 26 bundled translations.<\/li>\n<\/ul>","raw_excerpt":"Connect Claude and ChatGPT to your WordPress site through a native MCP server: rights per connection, audit log, optional hub for all sites.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/337059","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=337059"}],"author":[{"embeddable":true,"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/cultureclub"}],"wp:attachment":[{"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=337059"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=337059"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=337059"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=337059"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=337059"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=337059"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}