{"id":343896,"date":"2026-07-26T17:45:47","date_gmt":"2026-07-26T17:45:47","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/zen-mcp-bridge\/"},"modified":"2026-07-27T08:15:37","modified_gmt":"2026-07-27T08:15:37","slug":"zen-mcp-bridge","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/zen-mcp-bridge\/","author":23513961,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"3.2.3","stable_tag":"3.2.3","tested":"7.0.4","requires":"6.9","requires_php":"8.0","requires_plugins":null,"header_name":"Zen MCP Bridge","header_author":"Guram Zhgamadze","header_description":"Exposes your WordPress site to Claude.ai via the Model Context Protocol (MCP). Gives Claude read-only access to plugins, themes, post types, custom fields, database, source files, logs, hooks, and more \u2014 so it can write perfectly tailored plugins for your site.","assets_banners_color":"f4f8fc","last_updated":"2026-07-27 08:15:37","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/guramzhgamadze\/zen-mcp-bridge","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":130,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"3.2.2":{"tag":"3.2.2","author":"guramzhgamadze","date":"2026-07-26 17:45:11"},"3.2.3":{"tag":"3.2.3","author":"guramzhgamadze","date":"2026-07-27 08:15:37"}},"upgrade_notice":{"3.2.3":"<p>Bugfix release: stops the audit-log pruner writing a &quot;BIGINT UNSIGNED value is out of range&quot; database error to the log, and corrects the tool count shown on the Abilities API card. Recommended for all users; no action needed.<\/p>","3.2.2":"<p>The wp_db_query tool changed from raw SQL to a structured, injection-proof table reader (name a table + columns + filters instead of writing SQL). Joins\/aggregations are no longer available; everything else is unchanged.<\/p>","3.2.1":"<p>Review-compliance release: client_id derivation no longer uses a core auth key, the consent page uses an external stylesheet, and the Claude.ai\/Anthropic external service is now documented. No action needed.<\/p>","3.2.0":"<p>Adds opt-in write mode (off by default \u2014 nothing changes unless you enable it): draft-only post tools, allowlisted option updates, plugin toggling, cache clearing and term creation, gated behind a consent-screen write grant and fully audited.<\/p>","3.1.0":"<p>Security hardening: cache-safe revocation, token manager, audit log, per-tool switches, secret redaction. Existing OAuth sessions must re-authenticate once after updating; Bearer Token connections are unaffected.<\/p>","3.0.0":"<p>Renamed to Zen MCP Bridge. The MCP endpoint URL changed to <code>\u2026\/wp-json\/zen-mcp\/v1\/bridge<\/code> \u2014 update your Claude.ai connector and re-authenticate after upgrading. Your Bearer token and settings are migrated automatically.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3623673,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3623673,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3623673,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3623673,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["3.2.2","3.2.3"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3623673,"resolution":"1","location":"assets","locale":"","width":1445,"height":715},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3623673,"resolution":"2","location":"assets","locale":"","width":1438,"height":765},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3623673,"resolution":"3","location":"assets","locale":"","width":1436,"height":780},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3623673,"resolution":"4","location":"assets","locale":"","width":1416,"height":607},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3623673,"resolution":"5","location":"assets","locale":"","width":1420,"height":660}},"screenshots":{"1":"Connection settings \u2014 the MCP endpoint URL and Bearer token to paste into a Claude.ai custom connector, plus the OAuth token lifetime and the per-IP rate limit.","2":"Per-tool switches and write mode \u2014 every tool can be turned off individually (write tools are badged); write mode is off by default and has its own option allowlist.","3":"OAuth 2.1 (advanced) \u2014 authorization, token and discovery URLs, extra redirect URIs, and the WordPress Abilities API status card.","4":"Active OAuth tokens \u2014 issued tokens with client, user, issue\/expiry and last-used times, each revocable on the spot, plus the built-in health check.","5":"Health check, audit log and emergency revocation \u2014 every tool call is recorded with credential, tool, arguments, IP and outcome; all OAuth tokens can be invalidated instantly."}},"plugin_section":[],"plugin_tags":[2353,236834,229563,25308,242115],"plugin_category":[],"plugin_contributors":[271108],"plugin_business_model":[],"class_list":["post-343896","plugin","type-plugin","status-publish","hentry","plugin_tags-ai","plugin_tags-anthropic","plugin_tags-claude","plugin_tags-connector","plugin_tags-mcp","plugin_contributors-guramzhgamadze","plugin_committers-guramzhgamadze"],"banners":{"banner":"https:\/\/ps.w.org\/zen-mcp-bridge\/assets\/banner-772x250.png?rev=3623673","banner_2x":"https:\/\/ps.w.org\/zen-mcp-bridge\/assets\/banner-1544x500.png?rev=3623673","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/zen-mcp-bridge\/assets\/icon-128x128.png?rev=3623673","icon_2x":"https:\/\/ps.w.org\/zen-mcp-bridge\/assets\/icon-256x256.png?rev=3623673","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/zen-mcp-bridge\/assets\/screenshot-1.png?rev=3623673","caption":"Connection settings \u2014 the MCP endpoint URL and Bearer token to paste into a Claude.ai custom connector, plus the OAuth token lifetime and the per-IP rate limit."},{"src":"https:\/\/ps.w.org\/zen-mcp-bridge\/assets\/screenshot-2.png?rev=3623673","caption":"Per-tool switches and write mode \u2014 every tool can be turned off individually (write tools are badged); write mode is off by default and has its own option allowlist."},{"src":"https:\/\/ps.w.org\/zen-mcp-bridge\/assets\/screenshot-3.png?rev=3623673","caption":"OAuth 2.1 (advanced) \u2014 authorization, token and discovery URLs, extra redirect URIs, and the WordPress Abilities API status card."},{"src":"https:\/\/ps.w.org\/zen-mcp-bridge\/assets\/screenshot-4.png?rev=3623673","caption":"Active OAuth tokens \u2014 issued tokens with client, user, issue\/expiry and last-used times, each revocable on the spot, plus the built-in health check."},{"src":"https:\/\/ps.w.org\/zen-mcp-bridge\/assets\/screenshot-5.png?rev=3623673","caption":"Health check, audit log and emergency revocation \u2014 every tool call is recorded with credential, tool, arguments, IP and outcome; all OAuth tokens can be invalidated instantly."}],"raw_content":"<!--section=description-->\n<p>Zen MCP Bridge turns your WordPress site into an MCP server that Claude.ai can connect to. Once connected, Claude can inspect your site's architecture in real time \u2014 plugins, database schema, source code, ACF fields, REST routes, cron jobs and more \u2014 so it can write plugins, debug issues and answer questions tailored to your exact setup.<\/p>\n\n<p><strong>Read-only by default. Claude cannot write, delete or modify anything unless you explicitly enable the opt-in write mode \u2014 and even then it can only work with drafts, allowlisted options, plugin toggles, caches and terms, with every action audited.<\/strong><\/p>\n\n<h4>Features<\/h4>\n\n<ul>\n<li>Full OAuth 2.1 authorization server with PKCE (S256), dynamic client registration (RFC 7591) and auto-discovery (RFC 8414 + RFC 9728).<\/li>\n<li>Bearer Token auth as a simpler alternative to OAuth \u2014 never expires.<\/li>\n<li>Configurable OAuth token lifetime \u2014 1 hour, 24 hours, 7 days or 30 days, plus an emergency \"Revoke all tokens\" button.<\/li>\n<li>25 read-only MCP tools covering site info, plugins, themes, post types, taxonomies, options, posts, database schema, structured table reads, files, code search, logs, hooks, ACF fields, users, menus, cron, transients, widgets, REST routes, Action Scheduler, WooCommerce and Elementor.<\/li>\n<li>MCP resources (site snapshots at wordpress:\/\/ URIs) and canned prompts for site analysis, debugging and plugin writing.<\/li>\n<li>Opt-in <strong>write mode<\/strong> (off by default): six scoped write tools \u2014 create\/update DRAFT posts, update allowlisted options, toggle plugins, clear caches, create terms. OAuth sessions additionally need a write grant ticked on the consent screen; everything is audited. Deleting, publishing, user management and write SQL are never possible.<\/li>\n<li>WordPress Abilities API integration (WP 6.9+): tools are discoverable by the WordPress AI ecosystem, admin-only. Stands down automatically when the official AI Provider for Anthropic plugin is active.<\/li>\n<li>MCP specification 2025-11-25 compliant.<\/li>\n<li>Rate limiting, path-traversal guards, credential redaction and clickjacking protection.<\/li>\n<li>Apache + FastCGI compatible (Authorization header normalization built in).<\/li>\n<li>Zero dependencies \u2014 pure WordPress, no Composer required.<\/li>\n<\/ul>\n\n<h4>Available tools<\/h4>\n\n<p>Read: <code>wp_get_site_info<\/code>, <code>wp_get_plugins<\/code>, <code>wp_get_themes<\/code>, <code>wp_get_post_types<\/code>, <code>wp_get_taxonomies<\/code>, <code>wp_get_options<\/code>, <code>wp_query_posts<\/code>, <code>wp_get_post<\/code>, <code>wp_get_db_schema<\/code>, <code>wp_db_query<\/code>, <code>wp_list_files<\/code>, <code>wp_read_file<\/code>, <code>wp_search_code<\/code>, <code>wp_get_logs<\/code>, <code>wp_get_hooks<\/code>, <code>wp_get_acf_fields<\/code>, <code>wp_get_users<\/code>, <code>wp_get_menus<\/code>, <code>wp_get_cron_jobs<\/code>, <code>wp_get_transients<\/code>, <code>wp_get_scheduled_actions<\/code>, <code>wp_get_active_widgets<\/code>, <code>wp_get_rest_routes<\/code>, <code>wp_get_woocommerce<\/code>, <code>wp_get_elementor<\/code>.<\/p>\n\n<p>Write (only with write mode enabled): <code>wp_create_draft_post<\/code>, <code>wp_update_draft_post<\/code>, <code>wp_update_option<\/code>, <code>wp_toggle_plugin<\/code>, <code>wp_clear_cache<\/code>, <code>wp_create_term<\/code>.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin is a bridge to <strong>Claude.ai<\/strong>, the AI assistant operated by <strong>Anthropic<\/strong>. That is the entire purpose of the plugin: it turns your site into an MCP (Model Context Protocol) server that Claude.ai connects to so it can read your WordPress data and help you build and debug your site.<\/p>\n\n<p><strong>What the service is and what it is used for:<\/strong> Claude.ai (Anthropic) is a third\u2011party AI assistant. You connect it to this plugin's MCP endpoint from the Claude.ai app. Claude then reads your site through the plugin's tools to answer questions, write code and debug issues tailored to your setup.<\/p>\n\n<p><strong>What data is sent, and when:<\/strong> No data is sent anywhere until <em>you<\/em>, as an administrator, connect Claude.ai to this site and authenticate (with the Bearer token or by completing the OAuth login). After that, data is transmitted to Claude.ai only in direct response to a request Claude makes, and only the data returned by the specific read tool it calls \u2014 for example site\/plugin\/theme information, post content, database query results (with credentials redacted), or source files under <code>wp-content<\/code> (with sensitive files such as <code>.env<\/code>, <code>wp-config<\/code> copies, keys and database dumps blocked). Options and query results have secret\u2011shaped values redacted, user passwords are never returned, and \u2014 unless you explicitly turn on the optional write mode \u2014 nothing on your site is ever modified. During the OAuth login flow the browser is also redirected to Claude.ai callback URLs (<code>https:\/\/claude.ai\/api\/mcp\/auth_callback<\/code> and the <code>app.<\/code>\/<code>www.<\/code> variants) carrying a short\u2011lived authorization code. The plugin does not send any usage analytics or telemetry, and it does not contact Anthropic on its own \u2014 Claude.ai always initiates the connection.<\/p>\n\n<p><strong>Service terms and privacy policy:<\/strong> Anthropic Consumer Terms of Service \u2014 https:\/\/www.anthropic.com\/legal\/consumer-terms ; Anthropic Privacy Policy \u2014 https:\/\/www.anthropic.com\/legal\/privacy ; Anthropic Usage Policy \u2014 https:\/\/www.anthropic.com\/legal\/aup<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to <code>wp-content\/plugins\/zen-mcp-bridge<\/code>, or install it from your WordPress admin.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> screen.<\/li>\n<li>Go to <strong>Settings \u2192 MCP Bridge<\/strong> to find your endpoint URL and Bearer token.<\/li>\n<li>Flush rewrite rules once: <strong>Settings \u2192 Permalinks \u2192 Save Changes<\/strong>.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"how%20do%20i%20connect%20with%20a%20bearer%20token%20%28simplest%29%3F\"><h3>How do I connect with a Bearer token (simplest)?<\/h3><\/dt>\n<dd><ol>\n<li>In Claude.ai: <strong>Profile \u2192 Settings \u2192 Connectors \u2192 Add custom connector<\/strong>.<\/li>\n<li>Paste your MCP endpoint URL (shown on <strong>Settings \u2192 MCP Bridge<\/strong>), for example <code>https:\/\/your-site.com\/wp-json\/zen-mcp\/v1\/bridge<\/code>.<\/li>\n<li>Set the auth type to <strong>Bearer Token<\/strong> (or <strong>API Key<\/strong>) and paste the token from the settings page.<\/li>\n<li>Save. Bearer tokens never expire.<\/li>\n<\/ol><\/dd>\n<dt id=\"how%20does%20the%20oauth%202.1%20login%20flow%20work%3F\"><h3>How does the OAuth 2.1 login flow work?<\/h3><\/dt>\n<dd><p>Claude.ai auto-discovers the OAuth server from the <code>\/.well-known\/<\/code> URLs and opens a login page on your site, where an administrator clicks <strong>Allow Access<\/strong>. If Claude.ai asks for details manually, use the Authorization URL and Token URL shown in the <strong>OAuth (advanced)<\/strong> section of the settings page, any Client ID except the literal text \"Bearer Token\", and the scope <code>claudeai<\/code>.<\/p><\/dd>\n<dt id=\"i%20get%20a%20404%20%2F%20rest_no_route%20error\"><h3>I get a 404 \/ rest_no_route error<\/h3><\/dt>\n<dd><p>Go to <strong>Settings \u2192 Permalinks<\/strong> and click <strong>Save Changes<\/strong> to flush rewrite rules, and confirm the plugin is active.<\/p><\/dd>\n<dt id=\"the%20authorization%20header%20is%20always%20empty%20%28apache%20%2B%20fastcgi%29\"><h3>The Authorization header is always empty (Apache + FastCGI)<\/h3><\/dt>\n<dd><p>This is handled automatically. If it persists, add this line to your <code>.htaccess<\/code>:\n    RewriteRule ^ - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]<\/p><\/dd>\n<dt id=\"how%20do%20i%20enable%20debug%20logging%3F\"><h3>How do I enable debug logging?<\/h3><\/dt>\n<dd><p>Define <code>WP_DEBUG<\/code>, <code>WP_DEBUG_LOG<\/code> (true) and <code>WP_DEBUG_DISPLAY<\/code> (false) in <code>wp-config.php<\/code>, then read <code>wp-content\/debug.log<\/code> or use the <code>wp_get_logs<\/code> tool.<\/p><\/dd>\n<dt id=\"is%20it%20safe%3F\"><h3>Is it safe?<\/h3><\/dt>\n<dd><p>By default, yes \u2014 everything is read-only: credentials are redacted, database reads are structured (no raw SQL \u2014 table and column names are whitelisted against the live schema and every value is parameterized), file access is contained within <code>wp-content<\/code>, and OAuth uses mandatory PKCE with single-use, expiring authorization codes. Write access exists only when an administrator switches on write mode, is limited to drafts, allowlisted options, plugin toggles, caches and terms, and every write is recorded in the audit log. Deleting content, publishing, managing users and write SQL are impossible regardless of settings.<\/p><\/dd>\n<dt id=\"how%20does%20write%20mode%20work%3F\"><h3>How does write mode work?<\/h3><\/dt>\n<dd><p>Enable it under <strong>Settings \u2192 MCP Bridge \u2192 Write mode<\/strong> (off by default). The static Bearer token then gains write access; OAuth sessions must additionally tick \"Allow write access\" on the consent screen (the <code>claudeai:write<\/code> scope). Six scoped tools become available; drafts can never be published, options must be on an allowlist you control (site identity, code-execution and secret options are refused even if listed), and the plugin can never toggle itself off. Each write tool can be disabled individually and every call is audited.<\/p><\/dd>\n<dt id=\"how%20does%20this%20relate%20to%20the%20%22ai%20provider%20for%20anthropic%22%20plugin%3F\"><h3>How does this relate to the \"AI Provider for Anthropic\" plugin?<\/h3><\/dt>\n<dd><p>They point in opposite directions and can coexist: that plugin lets WordPress call Claude's API; Zen MCP Bridge lets Claude.ai read this site. When AI Provider for Anthropic is active, Zen MCP Bridge automatically stops registering its tools as WordPress Abilities so the site's AI surface has a single owner \u2014 Claude.ai access via the MCP endpoint is unaffected. The <code>zenmcp_enable_abilities<\/code> filter overrides this.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>3.2.3<\/h4>\n\n<ul>\n<li><strong>Fixed a database error written to the log on every site with fewer than 5,000 audit entries.<\/strong> Audit-log retention pruning computed its cutoff as <code>MAX(id) - 5000<\/code> inside the query; because <code>id<\/code> is <code>BIGINT UNSIGNED<\/code>, that underflowed and raised \"BIGINT UNSIGNED value is out of range\". The cutoff is now calculated in PHP and the delete is skipped entirely until the table actually exceeds the retention limit. No audit data was ever lost \u2014 the failing statement deleted nothing.<\/li>\n<li>The Abilities API status card now reports the tools it actually registers. It previously counted the full 31-tool registry and described them all as read-only, ignoring per-tool switches and counting the six write tools even when write mode was off.<\/li>\n<\/ul>\n\n<h4>3.2.2<\/h4>\n\n<ul>\n<li><strong><code>wp_db_query<\/code> no longer accepts raw SQL.<\/strong> It is now a structured, injection-proof table reader: you name a table, columns, WHERE conditions, ordering and a limit, and the plugin builds the query \u2014 table\/column names are validated against the live schema and every value is bound through <code>$wpdb-&gt;prepare()<\/code>. Credential columns stay blocked and secret values redacted. Joins and aggregate expressions are no longer supported (use <code>wp_query_posts<\/code> or the dedicated inspector tools).<\/li>\n<\/ul>\n\n<h4>3.2.1<\/h4>\n\n<ul>\n<li>Dynamic client registration now derives <code>client_id<\/code> from a dedicated plugin secret instead of the WordPress <code>AUTH_KEY<\/code>, keeping core authentication secrets scoped to authentication.<\/li>\n<li>The OAuth consent page loads its styles from an external stylesheet (no inline <code>&lt;style&gt;<\/code>).<\/li>\n<li>Documented the Claude.ai \/ Anthropic external service in the readme.<\/li>\n<li>Added <code>X-Content-Type-Options: nosniff<\/code> to all plugin responses (MCP endpoint, OAuth token\/discovery endpoints, consent page) \u2014 hardening surfaced by an OWASP ZAP scan.<\/li>\n<\/ul>\n\n<h4>3.2.0<\/h4>\n\n<ul>\n<li><strong>Opt-in write mode (off by default)<\/strong> with six scoped write tools: <code>wp_create_draft_post<\/code> \/ <code>wp_update_draft_post<\/code> (status locked to draft\/pending \u2014 publishing always needs a human), <code>wp_update_option<\/code> (admin-managed allowlist with hard denies for site identity, code-execution and secret options), <code>wp_toggle_plugin<\/code> (cannot touch Zen MCP Bridge itself), <code>wp_clear_cache<\/code> and <code>wp_create_term<\/code>.<\/li>\n<li><strong>Consent-screen write grant<\/strong>: OAuth sessions receive write access only when \"Allow write access\" is explicitly ticked during authorization (<code>claudeai:write<\/code> scope); the static Bearer token has write access only while write mode is on.<\/li>\n<li><strong>MCP tool annotations<\/strong>: all tools now declare <code>readOnlyHint<\/code> (and write tools <code>destructiveHint: false<\/code>) per the 2025-11-25 specification.<\/li>\n<li>Write tools are hidden from <code>tools\/list<\/code> for credentials without write access, individually toggleable, registered as Abilities only in write mode, and fully audited.<\/li>\n<\/ul>\n\n<h4>3.1.0<\/h4>\n\n<ul>\n<li><strong>Cache-safe token revocation<\/strong>: \"Revoke all\" now bumps a token-generation counter instead of deleting options-table rows, so it works instantly under Redis\/Memcached object caches too. <strong>Existing OAuth sessions must re-authenticate once after this update.<\/strong><\/li>\n<li><strong>Token manager<\/strong>: active OAuth tokens are listed in the admin (client, user, issued, expires, last used) with per-token revocation.<\/li>\n<li><strong>Secret-exfiltration hardening<\/strong>: <code>wp_db_query<\/code> now rejects queries referencing the plugin's own credentials and redacts secret-bearing values (API keys, session tokens, consumer secrets) from results; <code>wp_get_options<\/code> applies the same secret-name heuristic; sensitive files (.env, wp-config copies, SQL dumps, keys\/certificates) cannot be read or searched, and credential-like lines are masked in code-search results.<\/li>\n<li><strong>Audit log<\/strong>: every tool call is recorded (credential, tool, arguments, IP, outcome) with an admin viewer, filtering and automatic retention.<\/li>\n<li><strong>Per-tool switches<\/strong>: any of the 25 tools can be disabled entirely from the settings page \u2014 hidden from tools\/list, rejected by tools\/call, and excluded from Abilities.<\/li>\n<li><strong>Configurable rate limit<\/strong> (10\u20131000 tool calls per minute per IP) and an in-admin <strong>health check<\/strong> that runs the same initialize\/tools\/discovery checks a Claude.ai connection performs.<\/li>\n<li>Developer: PHPUnit test suite with GitHub Actions CI, phpcs.xml ruleset.<\/li>\n<\/ul>\n\n<h4>3.0.0<\/h4>\n\n<ul>\n<li>Renamed from \"WordPress MCP Bridge\" to <strong>Zen MCP Bridge<\/strong> (new slug, <code>zenmcp_<\/code> code prefix, text domain and REST namespace <code>zen-mcp\/v1<\/code>). Existing installs keep their Bearer token, redirect URIs and token lifetime via a one-time migration on activation. <strong>The MCP endpoint URL changed \u2014 reconnect Claude.ai to <code>\u2026\/wp-json\/zen-mcp\/v1\/bridge<\/code>.<\/strong><\/li>\n<li>Rebuilt the admin settings page to the Zen family theme: card layout, external stylesheet\/script (no inline styles or handlers), and setup\/troubleshooting docs moved into a Help tab. Settings consolidated into a single option.<\/li>\n<li>Six new read-only tools: <code>wp_search_code<\/code>, <code>wp_get_post<\/code>, <code>wp_get_transients<\/code> (auth\/secret values redacted), <code>wp_get_scheduled_actions<\/code>, <code>wp_get_woocommerce<\/code> (no customer data or credentials) and <code>wp_get_elementor<\/code> \u2014 25 tools total.<\/li>\n<li>MCP <code>resources<\/code> (site snapshots at <code>wordpress:\/\/<\/code> URIs) and <code>prompts<\/code> (site analysis, error debugging, plugin writing) capabilities.<\/li>\n<li>WordPress Abilities API bridge (WP 6.9+): tools registered as admin-only abilities; stands down automatically when AI Provider for Anthropic is active.<\/li>\n<li>Added <code>uninstall.php<\/code> (removes options and transients on delete) and internationalization.<\/li>\n<\/ul>\n\n<h4>2.8.0<\/h4>\n\n<ul>\n<li>Configurable OAuth token lifetime (1 hour \/ 24 hours \/ 7 days \/ 30 days) and an emergency \"Revoke all tokens\" button.<\/li>\n<li>MCP specification 2025-11-25 support: latest protocol version, <code>client_id_metadata_document_supported<\/code>, <code>scope<\/code> in <code>WWW-Authenticate<\/code>, and <code>description<\/code> in <code>serverInfo<\/code>.<\/li>\n<li>Hardened a SQL-injection vector in the DB-schema tool and corrected the OAuth consent nonce sanitizer (2.7.0).<\/li>\n<\/ul>\n\n<h4>2.6.0<\/h4>\n\n<ul>\n<li>Fixed an OAuth consent 403 (two-nonce form) and blocked the plugin's own Bearer token from the options tool. Crash-hardened the cron tool and added transient cleanup on deactivation.<\/li>\n<\/ul>\n\n<h4>2.5.0<\/h4>\n\n<ul>\n<li>Added dynamic client registration (RFC 7591), corrected the required PHP version, and closed path-containment and OAuth parameter-handling gaps.<\/li>\n<\/ul>\n\n<h4>2.2.0 \u2013 2.4.0<\/h4>\n\n<ul>\n<li>Implemented the full OAuth 2.1 PKCE authorization server with discovery endpoints, plus CORS, clickjacking, path-traversal and Apache\/FastCGI fixes.<\/li>\n<\/ul>\n\n<h4>2.1.0<\/h4>\n\n<ul>\n<li>Initial hardened release: GET\/OPTIONS handling, CORS headers and the read-only tool suite.<\/li>\n<\/ul>","raw_excerpt":"Connect your WordPress site to Claude.ai via the Model Context Protocol (MCP), giving Claude read-only access to your site&#039;s internals.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/343896","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=343896"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/guramzhgamadze"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=343896"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=343896"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=343896"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=343896"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=343896"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=343896"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}