Title: ByteCoreStack &#8211; MCP Connector for AI Tools
Author: ByteCore Stack
Published: <strong>July 6, 2026</strong>
Last modified: September 24, 2026

---

Search plugins

![](https://ps.w.org/bcs-mcp-manager/assets/banner-772x250.png?rev=3598182)

![](https://ps.w.org/bcs-mcp-manager/assets/icon-256x256.png?rev=3598182)

# ByteCoreStack – MCP Connector for AI Tools

 By [ByteCore Stack](https://profiles.wordpress.org/bytecorestack/)

[Download](https://downloads.wordpress.org/plugin/bcs-mcp-manager.1.2.4.zip)

 * [Details](https://twd.wordpress.org/plugins/bcs-mcp-manager/#description)
 * [Reviews](https://twd.wordpress.org/plugins/bcs-mcp-manager/#reviews)
 *  [Installation](https://twd.wordpress.org/plugins/bcs-mcp-manager/#installation)
 * [Development](https://twd.wordpress.org/plugins/bcs-mcp-manager/#developers)

 [Support](https://wordpress.org/support/plugin/bcs-mcp-manager/)

## Description

ByteCoreStack – MCP Connector for AI Tools turns your WordPress site into a Model
Context Protocol (MCP) server. Connect an MCP-compatible AI assistant and let it
work with your site through structured WordPress tools. Use familiar requests to
draft or update posts, review WooCommerce data, check SEO metadata, moderate comments,
or inspect site health. Actions follow the connected WordPress user’s capabilities.

The plugin includes 335+ tools for WordPress core and optional integrations. These
cover publishing and site administration, WooCommerce, SEO, forms, page builders,
backups, CRM, analytics, translation, membership, community, and security. Integration
tools appear when their supporting plugin is active, so the available tools match
your site.

Connect Claude.ai, Claude Desktop, ChatGPT, Cursor, or another compatible MCP client.
Guided setup shows client-specific instructions and your endpoint, with a read-only
prompt to verify the connection. Hosted AI clients generally require a publicly 
reachable HTTPS site.

Authentication uses OAuth 2.0 with PKCE; there is no shared API key. The server 
stays disabled until you enable it. Requests are rate-limited, and you can optionally
restrict access by IP address. Tool calls are recorded in the local Activity log
with sensitive-looking values redacted. You can enable an additional confirmation
step for supported destructive actions and revoke client access from the plugin 
settings.

Use the admin dashboard to check calls and connected clients, browse available tools,
and review recent activity. Connection health diagnostics help identify common setup
problems, including HTTPS, permalink, firewall, and OAuth discovery issues. The 
plugin also provides a light or dark admin appearance and keeps its interface scoped
to the plugin’s own screens.

No plugin-author telemetry is collected. See **External Services** for details about
optional outbound requests.

### External Services

This plugin does not send telemetry to the plugin author. Most features run on your
WordPress site. Two tool groups can contact external services when explicitly invoked
by an authenticated MCP client:

 * **Plugin/theme/core install and update tools:** use WordPress core installer 
   and updater classes to contact official WordPress.org APIs. Plugin and theme 
   installation accepts a directory slug, not an arbitrary download URL. Core update
   checks may send the standard WordPress version, locale, and environment details
   used by WordPress core.
 * **wp_upload_media_from_url:** makes an HTTP request to the image URL supplied
   to the tool to download that image into the Media Library. Private and loopback
   addresses are blocked, and the download is limited to 20 MB.

These requests are made only when the corresponding tool is called. Activity records
remain in your own WordPress database.

## Screenshots

[⌊Dashboard with server status, daily metrics, and recent activity.⌉⌊Dashboard with
server status, daily metrics, and recent activity.⌉[

Dashboard with server status, daily metrics, and recent activity.

[⌊WordPress tools browser with searchable tool categories.⌉⌊WordPress tools browser
with searchable tool categories.⌉[

WordPress tools browser with searchable tool categories.

[⌊Tool details with method and usage information.⌉⌊Tool details with method and 
usage information.⌉[

Tool details with method and usage information.

[⌊Connect & settings with a guided setup for supported AI clients.⌉⌊Connect & settings
with a guided setup for supported AI clients.⌉[

Connect & settings with a guided setup for supported AI clients.

[⌊Activity screen with filters and CSV export.⌉⌊Activity screen with filters and
CSV export.⌉[

Activity screen with filters and CSV export.

[⌊WordPress dashboard widget with recent MCP activity.⌉⌊WordPress dashboard widget
with recent MCP activity.⌉[

WordPress dashboard widget with recent MCP activity.

[⌊OAuth authorization screen for an AI client.⌉⌊OAuth authorization screen for an
AI client.⌉[

OAuth authorization screen for an AI client.

## Installation

 1. Install ByteCoreStack – MCP Connector for AI Tools from **Plugins  Add New Plugin**,
    or upload the bcs-mcp-manager folder to /wp-content/plugins/.
 2. Activate the plugin from **Plugins  Installed Plugins**.
 3. Open **ByteCoreStack – MCP Connector for AI Tools  Connect & settings** and enable
    the MCP server.
 4. Choose your AI client in the guided setup, copy the endpoint, and follow its connection
    instructions.
 5. Complete the OAuth authorization in your browser, then check **Connection health**
    or **Activity**.

Your site must be publicly reachable over HTTPS for most hosted AI clients. A local
site can be used with a compatible client running on the same computer, but cloud
AI services cannot reach localhost.

## FAQ

### Is the plugin free?

Yes. No paid tiers, license keys, usage caps, or feature paywalls.

### What is MCP? What can the AI tools do?

MCP lets AI clients call tools provided by other services. This plugin exposes WordPress
actions for content, orders, SEO, and site health, subject to the connected user’s
capabilities.

### Which AI clients can connect?

Guides are included for Claude.ai, Claude Desktop, ChatGPT, and Cursor. Other clients
need OAuth and Streamable HTTP support; compatible older clients can use legacy 
SSE. Follow the in-plugin guide.

### How do I connect an AI client?

Enable the server in **Connect & settings**, choose your client, copy the endpoint,
and follow the guide to authorize. Hosted clients generally require public HTTPS.
Keep OAuth credentials private.

### Why does my AI client show fewer than 335 tools?

The total includes optional integrations. Clients see tools for your site; WooCommerce,
ACF, forms, SEO, backups, CRM, page builders, and other tools appear when their 
supported plugin is active.

### Which plugins and features are integrated?

Integrations include WooCommerce, Easy Digital Downloads, ACF, Elementor, Bricks,
Divi, Gravity Forms, WPForms, Ninja Forms, Formidable Forms, Contact Form 7, UpdraftPlus,
FluentCRM, BuddyPress, bbPress, and The Events Calendar. SEO tools support Yoast
SEO, Rank Math, All in One SEO, SEOPress, Slim SEO, and The SEO Framework. Availability
depends on active plugins and configuration.

### Can an AI client change or delete content without permission?

Actions follow the connected user’s capabilities. The plugin cannot create users;
role changes require promote_users. You can require confirmation for supported destructive
actions. Activity is stored locally with sensitive-looking values redacted.

### Does the plugin send site data to ByteCoreStack or collect telemetry?

No plugin-author analytics or telemetry is collected. Activity stays in your database.
Only explicitly called install/update or image-download tools contact external services;
see **External Services**.

### Does the plugin support rate limits, IP restrictions, and multisite?

The MCP endpoint is limited to 60 requests per minute per IP; client registration
has a separate limit. An optional IP allowlist is available. On multisite, settings
and activity are per site.

### My client cannot connect. What should I check?

Run **Connection health  Run diagnostics**. Confirm the server is enabled, use HTTPS,
and avoid Plain permalinks. Save **Settings  Permalinks** once if needed. Security
plugins, firewalls, CDNs, or hosts can restrict REST API access or block `/.well-
known/` before WordPress loads. Follow the diagnostic’s allowlist guidance; ask 
your provider to allow the discovery paths, `/authorize`, `/token`, `/register`,
and `/wp-json/bcs-mcp/*` (including DELETE), and do not redirect OAuth POST requests.
Exclude MCP routes from caching.

### I restored a backup or want to disconnect a client. How do I reconnect?

Remove the connector from the AI client, then use **Reset OAuth State** in the plugin
to revoke registered clients. Add the endpoint again and authorize. This disconnects
all clients for that site.

### Can I add custom tools?

Developers can register tools with bcs_mcp_register_tool() or use the bcs_mcp_tools
filter. Callbacks should validate input and enforce WordPress capabilities.

### What happens when I uninstall the plugin?

The uninstall routine removes the plugin’s database tables, options, and transients.
Export any activity data you want to keep before uninstalling.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“ByteCoreStack – MCP Connector for AI Tools” is open source software. The following
people have contributed to this plugin.

Contributors

 *   [ ByteCore Stack ](https://profiles.wordpress.org/bytecorestack/)

[Translate “ByteCoreStack – MCP Connector for AI Tools” into your language.](https://translate.wordpress.org/projects/wp-plugins/bcs-mcp-manager)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/), 
check out the [SVN repository](https://plugins.svn.wordpress.org/bcs-mcp-manager/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/bcs-mcp-manager/)
by [RSS](https://plugins.trac.wordpress.org/log/bcs-mcp-manager/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.2.4

 * Security: Restrict user meta reads, writes, and deletes to safe profile fields.
   Writes and deletes require permission to promote users and reject array or object
   values, preventing role and capability changes through user meta. Role assignment
   also checks permission to edit the target user.

#### 1.2.3

 * Added guided setup for Claude.ai, Claude Desktop, ChatGPT, and Cursor, with client-
   specific instructions, endpoint copying, and a read-only connection-check prompt.
 * Reworked the compact admin page navigation and reorganized Connect & settings
   to make the setup flow easier to follow and reduce repeated endpoint details.
 * Added four dashboard metrics: Available Tools, Calls Today, Failed Today, and
   Connected Clients; refreshed the tool browser and recent activity presentation.
 * Improved Connection health status, diagnostic results, and the Run Diagnostics
   card; refreshed Activity filters and layout for easier scanning.
 * Polished the light and dark admin themes, card layouts, spacing, and button hover,
   focus, and active states.
 * Kept existing OAuth connections, settings, and activity history intact on upgrade;
   addressed WordPress coding-standard findings in translated strings and template
   variables.
 * Updated setup and troubleshooting documentation.

#### 1.2.2

 * Added 19 WordPress tools, optional confirmation for destructive actions, and 
   admin theme and tools-browser improvements.

#### 1.2.1

 * Improved OAuth/firewall diagnostics, connection-failure logging, credential redaction,
   and security-plugin compatibility.

#### 1.2.0

 * Added 96+ tools and integrations, including analytics and translation support;
   removed external font requests from admin pages.

#### 1.1.0

 * Added SEO, forms, LMS, e-commerce, page-builder, backup, CRM, community, and 
   events integrations plus diagnostics and admin improvements.

#### 1.0.0

 * Initial release with OAuth 2.0/PKCE, MCP transports, WordPress tools, dashboard,
   and activity log.

## Meta

 *  Version **1.2.4**
 *  Last updated **2 weeks ago**
 *  Active installations **30+**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 7.4 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/bcs-mcp-manager/)
 * Tags
 * [ai-automation](https://twd.wordpress.org/plugins/tags/ai-automation/)[ChatGPT](https://twd.wordpress.org/plugins/tags/chatgpt/)
   [Claude](https://twd.wordpress.org/plugins/tags/claude/)[mcp](https://twd.wordpress.org/plugins/tags/mcp/)
   [wordpress ai](https://twd.wordpress.org/plugins/tags/wordpress-ai/)
 *  [Advanced View](https://twd.wordpress.org/plugins/bcs-mcp-manager/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/bcs-mcp-manager/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/bcs-mcp-manager/reviews/)

## Contributors

 *   [ ByteCore Stack ](https://profiles.wordpress.org/bytecorestack/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/bcs-mcp-manager/)