{"id":337059,"date":"2026-07-30T20:09:47","date_gmt":"2026-07-30T20:09:47","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/alphabridge-mcp\/"},"modified":"2026-07-30T20:47:58","modified_gmt":"2026-07-30T20:47:58","slug":"alphabridge-mcp","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/alphabridge-mcp\/","author":23528922,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"4.2.0","stable_tag":"4.2.0","tested":"7.0.2","requires":"6.5","requires_php":"8.0","requires_plugins":null,"header_name":"AlphaBridge MCP","header_author":"AlphaBridge","header_description":"Connect Claude and other MCP clients directly and securely to WordPress. Native Streamable-HTTP MCP server \u2014 fast, stable, with tool-group switches.","assets_banners_color":"ffffff","last_updated":"2026-07-30 20:47:58","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/www.alphabridge-mcp.com","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":19,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"4.2.0":{"tag":"4.2.0","author":"cultureclub","date":"2026-07-30 20:47:58"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3629098,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3629098,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3629098,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3629098,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["4.2.0"],"block_files":[],"assets_screenshots":{"screenshot-1.jpg":{"filename":"screenshot-1.jpg","revision":3629098,"resolution":"1","location":"assets","locale":"","width":1424,"height":840},"screenshot-2.jpg":{"filename":"screenshot-2.jpg","revision":3629098,"resolution":"2","location":"assets","locale":"","width":1424,"height":840},"screenshot-3.jpg":{"filename":"screenshot-3.jpg","revision":3629098,"resolution":"3","location":"assets","locale":"","width":1424,"height":840}},"screenshots":{"1":"Set up the Claude.ai connector in two steps \u2014 copy the endpoint, then create a connection. Existing connections are listed and managed in the same place.","2":"The moment you create a connection, everything you need is shown once \u2014 the ready-made connector URL for Claude.ai, the Bearer token, and a copy-paste config for Cursor \/ Claude Code \u2014 with a reminder to save it, because the token is shown in full only once.","3":"Optional advanced settings for a connection: a label, a read-only or content-only access scope, the WordPress user it acts as, and an optional expiry.","4":"Enable or disable tools by functional group. Powerful (\"mighty\") tools are off by default, and one switch turns on a global read-only mode.","5":"Every tool call is written to the activity log with its status (allowed or denied)."}},"plugin_section":[],"plugin_tags":[2353,569,242115,23853,3972],"plugin_category":[59],"plugin_contributors":[273898],"plugin_business_model":[],"class_list":["post-337059","plugin","type-plugin","status-publish","hentry","plugin_tags-ai","plugin_tags-automation","plugin_tags-mcp","plugin_tags-rest-api","plugin_tags-tools","plugin_category-utilities-and-tools","plugin_contributors-cultureclub","plugin_committers-cultureclub"],"banners":{"banner":"https:\/\/ps.w.org\/alphabridge-mcp\/assets\/banner-772x250.png?rev=3629098","banner_2x":"https:\/\/ps.w.org\/alphabridge-mcp\/assets\/banner-1544x500.png?rev=3629098","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/alphabridge-mcp\/assets\/icon-128x128.png?rev=3629098","icon_2x":"https:\/\/ps.w.org\/alphabridge-mcp\/assets\/icon-256x256.png?rev=3629098","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/alphabridge-mcp\/assets\/screenshot-1.jpg?rev=3629098","caption":"Set up the Claude.ai connector in two steps \u2014 copy the endpoint, then create a connection. Existing connections are listed and managed in the same place."},{"src":"https:\/\/ps.w.org\/alphabridge-mcp\/assets\/screenshot-2.jpg?rev=3629098","caption":"The moment you create a connection, everything you need is shown once \u2014 the ready-made connector URL for Claude.ai, the Bearer token, and a copy-paste config for Cursor \/ Claude Code \u2014 with a reminder to save it, because the token is shown in full only once."},{"src":"https:\/\/ps.w.org\/alphabridge-mcp\/assets\/screenshot-3.jpg?rev=3629098","caption":"Optional advanced settings for a connection: a label, a read-only or content-only access scope, the WordPress user it acts as, and an optional expiry."}],"raw_content":"<!--section=description-->\n<p><strong>Your WordPress site, managed in conversation.<\/strong><\/p>\n\n<p>Tell Claude what you want done \u2014 \"draft a post from these notes, add last week's photos, fix the SEO titles and schedule everything for Friday\" \u2014 and it happens on your site. Not through screen-clicking or raw admin access, but through structured tools that respect WordPress permissions on every single call.<\/p>\n\n<p>AlphaBridge MCP turns your WordPress site into a native <strong>Model Context Protocol (MCP) server<\/strong>. AI clients such as Claude connect over one authenticated HTTPS endpoint and manage content, media, taxonomies, comments, widgets and site settings.<\/p>\n\n<p><strong>You stay in control<\/strong><\/p>\n\n<p>Handing an AI the keys to your site should feel safe \u2014 so control comes first:<\/p>\n\n<ul>\n<li>Every connection acts as a real WordPress user, and every tool checks the matching WordPress capability. What that user may not do, the AI cannot do.<\/li>\n<li>Scoped connections: hand out a read-only or content-only key with an optional expiry instead of full access. Rotate a connection's secret in one click.<\/li>\n<li>Tool groups you can switch off entirely \u2014 disabled tools vanish from the MCP surface. Plus a global read-only mode.<\/li>\n<li>An audit log records every tool call, and a fixed rate limit stops abusive request bursts.<\/li>\n<\/ul>\n\n<p><strong>Connected in two minutes<\/strong><\/p>\n\n<p>Paste your endpoint URL into Claude, click Connect, approve on your own site's login-protected consent screen \u2014 no token copying (standard OAuth 2.1 with PKCE; the login is your WordPress login, no account with us). For clients without a Connect button, create a token manually and paste one ready-made config.<\/p>\n\n<p><strong>Nothing extra to host<\/strong><\/p>\n\n<p>Unlike bridge-based solutions, AlphaBridge speaks MCP directly in PHP inside WordPress. No Node middleware, no external service, nothing else to run or pay for \u2014 it works on ordinary WordPress hosting, which makes it faster and more stable.<\/p>\n\n<p><strong>Free means free<\/strong><\/p>\n\n<p>Everything in this plugin is fully functional: no license keys, no registration, no plan-based, cumulative or time-based usage limits, no locked features.<\/p>\n\n<p><strong>What's inside<\/strong><\/p>\n\n<ul>\n<li>Native MCP endpoint (JSON-RPC 2.0 over HTTP POST; protocol versions 2024-11-05, 2025-03-26, 2025-06-18) \u2014 no external server required.<\/li>\n<li>39 structured tools across content, media, taxonomies, comments, widgets, site settings, site info, SEO reads and search.<\/li>\n<li>Bearer-token authentication mapped to a real WordPress user, with per-tool capability checks.<\/li>\n<li>Unlimited connections \u2014 create one deliberately limited key per client.<\/li>\n<\/ul>\n\n<p>Need more? A separate commercial add-on, AlphaBridge MCP Pro, adds tool groups for the database, users, plugin and theme files, WooCommerce, migration and one-step site deployment over SFTP. It is entirely optional \u2014 this free plugin is complete on its own and stays fully functional without it. Details are on the plugin website.<\/p>\n\n<p>AlphaBridge is our own product brand for this project. MCP (Model Context Protocol) is an open protocol standard; this plugin is an independent implementation and is not affiliated with or endorsed by the protocol's authors or by any other vendor.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin makes no automatic outbound requests and sends no telemetry. One tool can contact an external address, and only on your explicit instruction: when you call <code>wp_upload_media_from_url<\/code> with a URL, the plugin downloads that file from the address you provide (and up to a few safely re-validated redirects; SSRF-guarded, type- and size-checked). The plugin itself initiates no other outbound requests.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>alphabridge-mcp<\/code> folder to <code>\/wp-content\/plugins\/<\/code> (or install the ZIP via Plugins \u2192 Add New \u2192 Upload).<\/li>\n<li>Activate the plugin.<\/li>\n<li>In Claude (Settings \u2192 Connectors \u2192 Add custom connector) add the endpoint <code>https:\/\/your-site.tld\/wp-json\/alphabridge\/v1\/mcp<\/code> and click Connect \u2014 you approve on your own site's login-protected consent screen. Done.<\/li>\n<li>For clients without a Connect button (Cursor, Claude Code, scripts): open <strong>Settings \u2192 AlphaBridge MCP<\/strong>, create a connection manually and copy its token.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20it%20secure%3F\"><h3>Is it secure?<\/h3><\/dt>\n<dd><p>Every request needs a token bound to a WordPress user; each tool enforces the matching WordPress capability, including object-level checks for the specific post, attachment or taxonomy (non-public taxonomies additionally require that taxonomy's own capability). Powerful tools are off by default and only run once the admin enables their group. All calls are logged. Arbitrary option or transient values cannot be read through this plugin at all \u2014 only a fixed list of common site settings is exposed. Post, term and user meta is layered-protected: protected (\"_\"-prefixed) keys, keys flagged by is_protected_meta(), and keys matching common credential patterns (api_key, token, secret, oauth, \u2026) are refused \u2014 and every generic post, term and user meta read or write additionally passes WordPress's own per-key meta capability (edit_post_meta \/ edit_term_meta \/ edit_user_meta), which honours auth_callback rules that other plugins register via register_meta() (the media and SEO tools read only their own fixed keys). A key you may not edit is not exposed over MCP either. Tokens are accepted via the Authorization or X-Api-Key header \u2014 header authentication is the default. An admin can optionally enable a connector URL that carries the token in its path (served with Referrer-Policy: no-referrer and Cache-Control: no-store); this is off by default, because a token in a URL leaks more easily. Query-string tokens are never accepted. If you turn the connector URL on, treat it like a password: it contains the token \u2014 rotate the connection if the URL is shared, logged or pasted anywhere.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20shared%20hosting%3F\"><h3>Does it work on shared hosting?<\/h3><\/dt>\n<dd><p>Yes. It is pure PHP and uses the WordPress REST API. PHP 8.0+ and HTTPS are recommended.<\/p><\/dd>\n<dt id=\"is%20the%20free%20plugin%20limited%3F\"><h3>Is the free plugin limited?<\/h3><\/dt>\n<dd><p>No. Every feature in this plugin works without payment, registration or license keys, and there are no plan-based, cumulative or time-based usage limits. A uniform security throttle (120 requests\/minute, identical for every user) protects your server from abusive request bursts.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20send%20data%20anywhere%3F\"><h3>Does the plugin send data anywhere?<\/h3><\/dt>\n<dd><p>No. It contacts no external service on its own. The only outbound request happens when you explicitly ask a tool to fetch a file from a URL you provide (see External services).<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>4.2.0<\/h4>\n\n<ul>\n<li>New: Connect from Claude. The site now speaks the OAuth flow MCP clients expect: add the endpoint URL in Claude (web, desktop or mobile) and click Connect \u2014 Claude discovers the site, you approve on a login-protected consent screen (choosing full, content-only or read-only access), and the approved connection appears in the connections list like any other, revocable at any time. Technically: RFC 9728\/8414 discovery metadata under \/.well-known\/, dynamic client registration (RFC 7591), authorization-code grant with PKCE (S256 required) and resource indication (RFC 8707); 401 responses point clients at the metadata via WWW-Authenticate. Issued tokens are ordinary hashed connection tokens \u2014 nothing new is stored in readable form. No account with us, no external service: the login is your own WordPress login. Can be switched off under \u201cConnect from Claude (OAuth, advanced)\u201d; manual tokens keep working unchanged.<\/li>\n<\/ul>\n\n<h4>4.1.6<\/h4>\n\n<ul>\n<li>The connector URL is now only offered once connector-URL authentication is actually enabled \u2014 if it is off, a one-click \u201cEnable and show the connector URL\u201d button (with the same security note as the setting itself) appears in its place. A copied connector URL therefore always authenticates; previously the URL was shown with only a small note and would be rejected until the setting was switched on. The Bearer token and the Cursor \/ Claude Code config are unaffected and always work.<\/li>\n<\/ul>\n\n<h4>4.1.5<\/h4>\n\n<ul>\n<li>When you create a connection, the settings screen now shows everything ready for copy-paste: the full connector URL with the token embedded (for Claude.ai), the Bearer token, and a ready-made config snippet for Cursor \/ Claude Code \u2014 plus a clear reminder to save it, because the token is shown in full only once.<\/li>\n<\/ul>\n\n<h4>4.1.4<\/h4>\n\n<ul>\n<li>Simpler, clearer connector setup: the settings screen now shows one \u201cClaude.ai Connector\u201d box with a two-step flow \u2014 copy the endpoint, then click one \u201cCreate connection\u201d button (label, access scope, user and expiry moved into optional advanced settings). The token appears right below the button, and existing connections are listed in the same box. Removes the previous duplicate create buttons.<\/li>\n<\/ul>\n\n<h4>4.1.3<\/h4>\n\n<ul>\n<li>Uninstall no longer removes this plugin's data while the separately distributed AlphaBridge MCP Pro plugin is still installed \u2014 Pro shares this core data (connections, tool state, settings, log), so removing the free plugin alone keeps Pro fully configured. Uninstalling last (or alone) cleans up as before.<\/li>\n<\/ul>\n\n<h4>4.1.2<\/h4>\n\n<ul>\n<li>Added an informational box about the separately distributed AlphaBridge MCP Pro plugin to the plugin's own settings page. Nothing in this free plugin changed \u2014 it remains complete and fully functional on its own.<\/li>\n<\/ul>\n\n<h4>4.1.1<\/h4>\n\n<ul>\n<li>Hardened connection handling: the token is shown once at creation and only its hash is stored; scope values are validated fail-closed; header authentication is the default and connector-URL authentication is an explicit opt-in.<\/li>\n<li>User-meta reads limited to a fixed list of standard profile fields.<\/li>\n<li>Improved capability checks and packaging consistency.<\/li>\n<\/ul>\n\n<h4>4.1.0<\/h4>\n\n<ul>\n<li>Added connection scopes, an optional expiry and one-click rotation.<\/li>\n<li>Improved transport and object-level security.<\/li>\n<\/ul>\n\n<h4>4.0.0<\/h4>\n\n<ul>\n<li>Rebuilt the directory package as a fully standalone free plugin.<\/li>\n<li>Connections are unlimited and every bundled tool is available without restriction.<\/li>\n<li>Removed the raw option\/transient readers; site settings are available through wp_get_site_settings.<\/li>\n<li>Update status is read from WordPress's cache and performs no remote request.<\/li>\n<li>Broadened object-level and per-key capability checks across posts, meta, terms, taxonomies, media and search.<\/li>\n<li>Simplified the settings screen and the distribution package.<\/li>\n<\/ul>\n\n<h4>3.0.0<\/h4>\n\n<ul>\n<li>MCP tool annotations (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) for every tool.<\/li>\n<li>MCP protocol negotiation: the server echoes the client's requested protocol version when supported (2024-11-05, 2025-03-26, 2025-06-18).<\/li>\n<li>New global read-only mode: one switch blocks every writing tool; read, list and search tools keep working.<\/li>\n<li>Better error messages: argument validation reports all missing or invalid fields at once.<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Restructured for the WordPress.org directory: this plugin contains the core free toolset.<\/li>\n<li>Settings-screen JavaScript is enqueued from assets\/admin.js (2.0.2).<\/li>\n<\/ul>\n\n<h4>1.x<\/h4>\n\n<ul>\n<li>Initial development line: MCP endpoint, token auth, tool groups, security hardening (SSRF guards, path traversal guards, capability checks, rate limiting, audit log), 26 bundled translations.<\/li>\n<\/ul>","raw_excerpt":"Talk to your WordPress site. Claude and other AI assistants manage content, media and settings over one secure, native MCP endpoint.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/337059","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=337059"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/cultureclub"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=337059"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=337059"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=337059"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=337059"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=337059"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=337059"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}