Description
MCPServe creates local MCP server profiles for compatible AI clients. Each profile has its own URL, selected WordPress Editor or Author, allowed content types and tools, and revocable credentials. The plugin performs no AI inference. Your chosen client provides the conversation and reasoning.
Included tools
- List and read permitted posts and pages.
- Create drafts, edit permitted posts and pages, publish drafts or pending content, and move content to Trash. Content changes require a current version hash and explicit confirmation. WordPress capabilities and profile permissions still apply.
- Audit and update on-page SEO titles and descriptions. Yoast SEO and Rank Math metadata are supported, or you can enable the plugin’s local title/description output when no supported SEO plugin is active.
- List image attachments, categories, and tags; resolve same-site content URLs.
- Pause profiles, revoke connections, review recent activity, and set global write and content-exclusion controls.
Every included tool works without payment, a license key, or a trial clock. The configurable expiration of a server profile or credential is a security setting; an administrator can renew or replace it without payment. Builder-managed content is protected from body replacement because this plugin does not edit builder layouts. Theme, plugin, file, user, and critical-setting administration is outside the scope of this connector.
Security and client requirements
A site administrator creates the profile, but the remote connection must be assigned to an Editor or Author without administrator capabilities. This is rechecked on every MCP request and token refresh. The assigned user explicitly signs in and consents to the requested scopes. Tools check the user’s WordPress permissions at the point of use. OAuth uses authorization code with S256 PKCE; advanced clients can use an expiring server-bound Bearer key. Revoke access in the plugin dashboard.
Use an HTTPS site with pretty permalinks and an AI client that supports remote MCP with OAuth or Bearer authentication. The connector implements stateless Streamable HTTP JSON responses. GET event streams, JSON-RPC batches, resources, and prompts are not implemented. Custom connector availability may depend on the client’s plan. No AI subscription or API key is provided.
Privacy and external connections
This plugin makes no licensing, telemetry, or model API calls. Local assets are bundled with it. The administrator must enable it, create a profile, and approve exact OAuth callback hostnames. Authorized clients may receive permitted site identity, content (including private or draft content accessible to the assigned user), URLs, SEO metadata, image URLs, and taxonomy data. They may transmit those responses to their AI provider. Review your chosen provider’s terms and privacy policy before connecting. For optional clients: https://openai.com/policies/terms-of-use/ , https://openai.com/policies/privacy-policy/ , https://www.anthropic.com/legal/consumer-terms , and https://www.anthropic.com/legal/privacy .
Profiles, assigned user IDs, client identifiers, callback URLs, hashed keys, temporary tokens, and tool activity are stored locally in WordPress. Activity entries include tool name, timestamp, connection/user identifiers and success status, without article bodies, prompts, or raw credentials. Uninstall removes connector settings and operational records while preserving WordPress content and SEO fields.
Screenshots






Installation
- Install and activate on an HTTPS WordPress site.
- Open MCPServe in the administrator menu and create a profile for a dedicated non-administrator Editor or Author.
- Choose tools and content types, enable the global write switch if needed, and copy the generated URL into your compatible AI client.
- Sign in as the assigned user and review the OAuth consent screen.
- For content changes, ask the client to read the current content/version hash first and confirm the change.
If OAuth discovery returns 404, configure the web server to route /.well-known/oauth-authorization-server to WordPress. Subdirectory sites also need host-root discovery routing. Keep Bearer keys secret.
FAQ
-
What does the separate Pro plugin add?
-
MCPServe Pro provides a seven-day trial of additional site and design tools, including supported Elementor, WPBakery, theme, code, and deeper SEO/GEO operations. A one-time purchase retains Pro after the trial. The free connector remains fully functional without payment. See https://mcpserve.dev/ for current details. The editions are separate plugins; deactivate this edition before installing Pro, then create a new server profile and reconnect your AI client. Profiles and credentials are not imported.
-
Can this plugin edit published content?
-
Yes, for permitted posts/pages when the assigned user can edit the post, global and profile writes are enabled, and the current version hash plus confirmation is supplied. Builder-managed body content must be edited in its builder.
-
Can this plugin publish or delete posts?
-
It can publish permitted draft or pending content when the user has the WordPress publishing capability. It can move content to WordPress Trash when the user has the WordPress delete capability. It does not permanently delete content.
-
Can an administrator connect through MCP?
-
No. Remote tokens are restricted to eligible non-administrator content editors; the administrator configures profiles in the WordPress dashboard.
-
Does this connect to every AI client?
-
No universal compatibility is claimed. The client must support the implemented MCP transport and authentication.
-
Can I activate this beside an earlier MCPServe connector?
-
Use one connector edition at a time. Deactivate the earlier connector before activating this one. This edition creates independent profiles; reconnect the AI client to its new URL.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“MCPServe” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “MCPServe” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.0.7
- Sanitize and unslash admin and OAuth request inputs consistently; clarify nonce handling for read-only navigation and validated form fields.
- Document the atomic edit-lock database operations and uninstall cleanup for Plugin Check.
1.0.6
- Add a closeable, contextual Pro information panel on the MCPServe admin page with a clear summary of the separate Pro plugin. The panel reappears on a new page load; it does not display across the WordPress dashboard.
1.0.5
- Align plugin ownership and directory metadata with the MCPServe WordPress.org account and mcpserve.dev domain.
- Keep the directory edition independent from previously installed connector editions.
1.0.4
- Make ordinary content editing, publishing, and trash tools available without a license or trial; keep WordPress capability checks, version hashes, and explicit confirmation.
- Use WordPress-managed translations and enqueued assets; remove bundled translation files and edition upsell.
- Clarify that remote access is limited to non-administrator content users.
