Flex MCP – Connect ChatGPT, Claude and AI agents with MCP, Undo, Abilities and Tools.
Flex MCP – Connect ChatGPT, Claude and AI agents with MCP, Undo, Abilities and Tools.
Description
Flex MCP is the most secure MCP Server for WordPress with built-in Undo. Connect ChatGPT, Claude Desktop, Gemini, and other MCP clients safely, roll back changes when needed, and manage your site through natural conversation without losing control.
π°οΈ Manage many WordPress MCP sites from one place (free and open source)
If you are an agency or manage many WordPress installations, WP MCP Hub gives you one local central point for managing multiple WordPress MCP servers.
- Open source and free β no paid hub, site limits, or subscription
- One stable AI client setup β connect once and route to the right site
- Local-first architecture β credentials stay in your operating system vault
Explore WP MCP Hub:
* https://andromedanova.com/wp-mcp-hub.html
* https://github.com/estebanstifli/wp-mcp-hub
Choose the layers your site needs without loading the rest:
- MCP Server (always active) β Connect ChatGPT, Claude Desktop, or any MCP client directly to your site. Includes Multimedia and Logs & Roll Back.
- AI Copilot (optional addon) β A floating assistant inside the Gutenberg and Classic editors that writes, rewrites, and optimizes your content in real time.
- AI Chat Agent (optional addon) β A full conversational interface to manage posts, WooCommerce, settings, and more.
- Automations, SEO, and Plugin Integrations (optional addons) β Enable only the workflows and integrations used on your site.
On first activation, a setup screen lets you select the addons to load. The default is the MCP Server layer only. You can change the selection later from Flex MCP MCP Server Add-ons.
π¬ Video: Claude to WordPress MCP Connector in 1 Minute
π Documentation
Released in December 2025, Flex MCP was the first MCP plugin for WordPress and remains the most complete WordPress MCP platform for ChatGPT, Claude Desktop, and other MCP clients.
It starts with 122+ built-in MCP tools, and with supported integrations such as All Sources Images, Stifli Backup Tools, AiPatch Security Scanner, Notification for Telegram, WPCode, Code Snippets, Woody Snippets, Advanced Custom Fields, Yoast SEO, Rank Math, WPForms, Gravity Forms, Forminator, The Events Calendar, and Elementor, it can exceed 200 total tools depending on the plugins you install.
π‘ MCP Server β Connect ChatGPT, Claude Desktop, and Other MCP Clients
Flex MCP includes a full standards-compliant MCP server for WordPress, so ChatGPT, Claude Desktop, LibreChat, and other MCP clients can connect directly to your site and use real WordPress tools through OAuth 2.1.
- ChatGPT β Connect through Apps & Connectors with OAuth 2.1 authentication
- Claude Desktop β Connect through Connectors with automatic OAuth flow
- LibreChat and other MCP clients β Use the same MCP endpoint and discovery flow
- Zero shared secrets β No custom API keys or passwords for external MCP clients
- Standards-based β Automatic discovery, registration, and authentication with OAuth 2.1, PKCE, RFC 9728, RFC 8414, and RFC 7591
Just copy the SSE URL from the Settings page, paste it into ChatGPT, Claude Desktop, or another MCP client, and authorize.
βοΈ AI Copilot β Your Writing Assistant Inside the Editor
The AI Copilot lives as a floating widget right inside the WordPress post and page editor. It understands the full context of what you’re editing β title, content, categories, tags, featured image, and even WooCommerce product fields β and helps you write better, faster.
- Rewrite, expand, or optimize content β Ask the Copilot to improve your text and it applies the changes directly into the editor
- One-click quick actions β “β‘ Optimize content”, “π·οΈ Generate tags”, “π Write excerpt”, “πΌοΈ Generate image” β one tap, instant results
- Real-time editing β The Copilot sets titles, excerpts, tags, slugs, and categories directly in the editor. No copy-pasting
- Content block operations β Insert, update, replace, or delete Gutenberg blocks through conversation
- Visual feedback β Changed fields and blocks are highlighted with a green border so you always see what the AI modified
- Keep or Undo β Every change shows a floating banner: keep it or undo with a single click. You stay in control
- Image generation β Ask the Copilot to generate an image and it sets it as the featured image or inserts it as a block, automatically
- Works with Gutenberg and Classic Editor β Full support for both editors
- Context-aware β The Copilot reads your current post content, blocks, metadata, and editor state to give relevant suggestions
- WooCommerce-aware β When editing a product, the Copilot sees prices, stock, SKU, attributes, and product type
Choose OpenAI (GPT-5.4), Anthropic (Claude 4.6 Opus/Sonnet), or Google (Gemini 3.1 Pro/Flash), and optionally use WordPress AI Client connectors like OpenRouter and Mistral when installed. No complex setup β just your API key or connector credentials.
π‘ What Can You Do With the Copilot?
Here are just a few examples of what you can ask while editing a post or page:
- βοΈ “Rewrite the introduction to sound more professional and engaging”
- π “Add a comparison table below the second paragraph with pros and cons”
- πΌοΈ “Generate an image that illustrates the idea in paragraph four and insert it right above”
- π “Write a compelling meta description and set it as the excerpt”
- π “Update the product short description to highlight free shipping and set the sale price to $19.99”
The Copilot reads your full content, understands context, and applies changes directly in the editor β no copy-pasting, no switching tabs.
π€ AI Chat Agent β Your WordPress AI Assistant
The built-in AI Chat Agent gives you a powerful conversational interface to manage your entire WordPress site:
- Talk to your site β “Show me the last 5 orders”, “Create a blog post about SEO tips”, “What plugins are installed?”
- Multi-provider β Built-in OpenAI (GPT-5.4, GPT-5.3), Anthropic (Claude 4.6 Opus/Sonnet, Claude 4.5 Haiku), Google (Gemini 3.1 Pro, Gemini 3 Flash) + optional WordPress AI Client connectors (OpenRouter, Mistral)
- 122+ MCP tools at its disposal β The AI agent can read posts, create content, manage WooCommerce products, check orders, inspect SEO data, update settings, and much more
- Smart suggestions β After each response, get contextual follow-up suggestions
- Conversation history β Auto-saved across sessions with multi-tab support
- Safe by design β Choose “Always Allow” or “Ask User” mode for tool execution confirmations
- Advanced tuning β Control temperature, max tokens, top_p, system prompts
π‘ What Can You Do With It?
Here are just a few examples of what you can ask your AI agent:
- π “Write a 500-word blog post about healthy eating and publish it as draft”
- π “Show me today’s WooCommerce orders and their total revenue”
- π “What are the top 10 most commented posts on my site?”
- π “List all products with stock below 5 units”
- π¨ “Generate a hero image for my latest blog post about technology”
The AI agent understands context, chains multiple operations, and works with your site’s real data in real time.
π¨ AI Image & Video Generation
Generate stunning images and videos directly from your AI agent or the dedicated Multimedia Settings page:
- Image Generation β “Generate a hero image for my blog post about AI” using OpenAI (GPT Image family + DALLΒ·E 2/3) or Google Gemini (Gemini Image + Imagen 4)
- Image Search β “Find a real stock image for my post” with
wp_search_image(Unsplash, Pexels, Pixabay) including attribution metadata - Video Generation β “Create a 5-second product showcase video” using OpenAI Sora or Google Veo 2/3
π§© Code Snippet Management β Design and Develop Through Conversation
Create, edit, activate, and manage code snippets on your WordPress site entirely through AI β no manual coding required. Compatible with the three most popular snippet plugins: WPCode, Code Snippets, and Woody Code Snippets.
- Add functionality instantly β “Add a PHP snippet that redirects users after login based on their role”
- Custom CSS on demand β “Create a CSS snippet that hides the sidebar on mobile devices”
- JavaScript injection β “Add a JS snippet that shows a sticky banner with a 10% discount code”
- Full lifecycle management β List, create, edit, activate, deactivate, and delete snippets from conversation
- Safe by design β PHP code is sanitized automatically, removing stray
<?phptags and markdown artifacts from AI-generated output
This opens up powerful possibilities: customize your theme’s appearance, add tracking scripts, inject schema markup for SEO, modify WooCommerce checkout behavior, add custom shortcodes β all through natural language. Ask your AI agent to build it, test it, and activate it, without ever touching a code editor.
π§ WordPress Abilities Integration (WordPress 6.9+)
Automatically discover and import abilities registered by other plugins into your AI agent’s toolkit. If a plugin supports the WordPress Abilities API, Flex MCP can detect, import, and expose it as an AI tool β zero configuration needed.
β° Automation Tasks β Let AI Work While You Sleep
Schedule AI-powered tasks to run automatically on your WordPress site:
- Scheduled Tasks β Create daily, weekly, or monthly automated workflows
- Templates β Quick-start with pre-built templates (Daily Sales Report, Trending Article, Weekly Summary)
- Smart Scheduling β Flexible presets from “Every hour” to “Monthly” with custom times and timezones
- Detected Tools Mode β AI automatically identifies which tools are needed, saving tokens significantly
- Output Actions β Send results via email, webhook, draft post, or custom hooks
- Execution Logs β Full history with token usage, duration, and detailed results
π― Event Automations β Trigger AI on WordPress Events
Run AI workflows automatically when specific events happen
βͺ Roll Back β The Only MCP Server With Undo
Mistakes happen. You asked ChatGPT to update your landing page and the result isn’t what you expected? No problem β roll back the change with one click and your site is restored instantly.
Flex MCP is the only MCP server for WordPress that tracks every change and lets you undo it. Every modification made by any AI β whether from ChatGPT, Claude Desktop, the built-in Chat Agent, the Copilot, or automated tasks β is recorded with a full before/after snapshot.
- One-click Undo β Roll back any change from the Logs & Roll Back page in your admin panel
- Redo support β Changed your mind? Re-apply a rolled-back change just as easily
- Session rollback β Undo an entire AI conversation’s changes at once, in the correct order
- Full audit trail β See exactly what was changed, when, by whom, and from which source
- Works across everything β Posts, pages, products, orders, options, menus, media, code snippets, and more
- AI-accessible β Your AI agent can also query and rollback changes through dedicated tools
π‘ Real-world examples:
- π “ChatGPT updated all my product prices but used the wrong currency β roll it back!”
- π “Claude rewrote my About page and I prefer the original β undo!”
- βοΈ “An automation changed my site settings at 3 AM β I can see exactly what happened and revert it”
- π¨ “The AI-generated image doesn’t match my brand β remove it and restore the previous one”
- π “I told the AI to delete a menu item by mistake β bring it back!”
π‘οΈ Security β OAuth 2.1 Built In
Flex MCP uses OAuth 2.1 with PKCE β the latest industry-standard security protocol β to authenticate external AI clients. No API keys to copy, no passwords to share. Just paste the URL, authorize once, and you’re connected.
- OAuth 2.1 with PKCE (S256) β The most modern and secure authentication standard, used by Google, Microsoft, and GitHub
- Dynamic Client Registration (RFC 7591) β AI clients register automatically, no manual setup needed
- Auto-discovery (RFC 9728 + RFC 8414) β Clients find your server’s auth endpoints automatically
- Token auto-refresh β Sessions stay active for up to 90 days without re-authorization
- Application Passwords fallback β Still supported for advanced setups and legacy clients
- Per-tool capability checks linked to WordPress roles
- Profile-based tool restrictions (8 predefined profiles + custom)
- Tool execution confirmations in AI Chat Agent
π Tool Profiles
- WordPress Read Only β safe read-only access
- WordPress Full Management β complete CRUD operations
- WooCommerce Read Only β query store data
- WooCommerce Store Management β products, orders, coupons
- Complete E-commerce β all WooCommerce tools
- Complete Site β all 122+ tools enabled
- Safe Mode β non-sensitive reads only
- Development/Debug β diagnostic tools
π Supported AI Platforms
Flex MCP integrates with:
Built-in AI Chat Agent + WordPress AI Client connectors:
* OpenAI β GPT-5.4, GPT-5.3, GPT-5.4 Mini
* Anthropic Claude β Opus, Sonnet, Haiku
* Google Gemini β Pro, Flash, Flash-Lite
* OpenRouter and Mistral β via WordPress AI Client connectors (when installed)
MCP Server (External Clients via OAuth 2.1):
* Claude Desktop, ChatGPT, LibreChat, Cursor, Cline, Roo Code, Windsurf, Claude Code
Cloud & Local Providers (via MCP clients):
* Groq, Azure OpenAI, AWS Bedrock
* Ollama, LM Studio, self-hosted solutions
π MCP Spec Compliance
Flex MCP implements the Model Context Protocol (MCP) 2025-11-25 specification for lifecycle and tool operations over JSON-RPC 2.0, while keeping legacy SSE compatibility for older MCP clients.
External Services
This plugin connects to third-party AI services to power the AI Chat Agent, AI Copilot, image generation, and video generation features. No data is transmitted until you explicitly configure an API key and initiate a request.
What data is sent: Your WordPress content (post text, metadata, product details) as included in AI prompts, and MCP tool execution results when using the MCP server with external AI clients.
When data is sent: Only when you have configured an API key for a provider AND actively send a message to the AI agent or Copilot, or when an external MCP client makes an authenticated request to the MCP server endpoint.
Supported services and their policies:
-
OpenAI β Used for GPT models (AI Chat Agent, AI Copilot), GPT Image / DALLΒ·E (image generation), and Sora (video generation)
Terms of Use | Privacy Policy -
Anthropic Claude β Used for Claude AI models (AI Chat Agent, AI Copilot)
Terms of Service | Privacy Policy -
Google Gemini β Used for Gemini AI models (AI Chat Agent, AI Copilot), Gemini Image + Imagen 4 (image generation), and Veo 2/3 (video generation)
Terms of Service | Privacy Policy -
Google Search Console – Used only when you connect your Google account in the SEO settings, for read-only site/search performance data.
Terms of Service | Privacy Policy
When using the MCP server with external AI clients (ChatGPT, Claude Desktop, LibreChat, etc.), API requests are made by the AI client’s backend servers to your WordPress MCP endpoint. The plugin itself does not send data to third parties in this scenario β the external MCP client initiates all communication.
Installation
Quick Start (MCP Server)
- Upload the
stifli-flex-mcpfolder to/wp-content/plugins/or install from the WordPress plugin directory - Activate the plugin
- Choose the addons you want on the first-activation screen. Leave them unchecked for the lightweight MCP Server-only setup.
- Continue to Flex MCP MCP Server
- Copy the SSE URL and connect your MCP client through OAuth 2.1
Multimedia tools and Logs & Roll Back are included in the MCP Server layer and are always available. Addons can be changed later from MCP Server Add-ons; disabled addons do not load their PHP classes, menus, hooks, or background jobs.
Quick Start (AI Copilot)
- Enable AI Copilot on the first-activation screen or from MCP Server Add-ons
- Go to Flex MCP AI Copilot and make sure itβs enabled
- Go to Flex MCP AI Chat Agent Settings and enter your API key
- Open any post or page in the editor β the Copilot widget appears automatically
- Start writing with AI!
Quick Start (AI Chat Agent)
- Enable AI Chat Agent on the first-activation screen or from MCP Server Add-ons
- Go to Flex MCP AI Chat Agent
- Open the Settings tab and select your AI provider (OpenAI, Claude, Gemini, or installed WordPress AI Client connectors like OpenRouter/Mistral)
- Enter your API key
- Start chatting!
That’s it β no external tools, no complex configuration. Your AI agent is ready.
Connect External MCP Clients
To connect external AI clients (ChatGPT, Claude Desktop, LibreChat):
- Go to Flex MCP MCP Server
- Copy the SSE URL shown on the Settings page
- Paste it in your AI client:
- Claude Desktop: Customize Connectors Add custom connector Paste the URL
- ChatGPT: Settings Apps & Connectors Advanced settings Enable Developer mode Create app Paste the URL Choose OAuth
- A browser window will open β log in to WordPress and click “Authorize”
- Done! Your AI client can now manage your WordPress site
No API keys, no passwords β OAuth 2.1 handles everything securely and automatically.
Screenshots

AI Copilot - Floating assistant inside the WordPress editor with quick actions

AI Chat Agent - Chat with AI directly from WordPress admin

AI Chat Agent - Settings and provider configuration

MCP Server - Endpoint URLs and authentication setup

MCP Server - Tool profiles management

MCP Server - WordPress and WooCommerce tools management

MCP Server - Plugin Integrations
Faq
The AI Copilot is a floating assistant that appears inside the WordPress editor (Gutenberg or Classic). It reads the context of what youβre editing and helps you write, rewrite, optimize, generate tags, create excerpts, and even generate images β all without leaving the editor. Every change can be undone with one click.
The Copilot lives inside the post/page editor and is focused on writing and content editing. It works directly with the editor fields (title, content blocks, excerpt, tags, etc.).
The Chat Agent is a standalone admin page where you can manage your entire WordPress site through conversation β create posts, manage WooCommerce orders, check settings, install plugins, and more.
Both use the same AI provider and API key.
- Go to Flex MCP AI Chat Agent Settings
- Choose your AI provider (OpenAI, Claude, Gemini, or installed WordPress AI Client connectors like OpenRouter/Mistral)
- Enter your API key (you get this from your AI provider’s website)
- Go to the Chat tab and start talking!
OpenAI, Claude, and Gemini all work great, and you can also use OpenRouter or Mistral via WordPress AI Client connectors. Here’s a quick comparison:
- OpenAI (GPT-4o / GPT-4.5) β Best overall balance of speed and quality
- Claude (Opus / Sonnet) β Excellent at understanding complex instructions and writing
- Gemini (2.5 Pro / Flash) β Great value, fast responses
You can switch providers at any time from the Settings tab.
The agent has access to 122+ tools covering:
- Content β Create, edit, delete posts, pages, and comments
- Media β Upload, list, and manage images and files
- AI Generation β Generate images (DALLΒ·E, Imagen) and videos (Sora, Veo) with AI
- WooCommerce β Products, orders, coupons, customers, shipping, taxes
- Taxonomies β Categories, tags, custom taxonomies
- Settings β Site options, menus, navigation
- System β Plugins, themes, site health
You control which tools are available through Profiles.
Yes, with multiple layers of protection:
- OAuth 2.1 with PKCE β Industry-standard secure authentication for external AI clients, no shared passwords
- Tool confirmations β In “Ask User” mode, you approve every action before it executes
- Permission checks β Every tool verifies WordPress capabilities before running
- Profiles β Restrict which tools are available (e.g., “Read Only” profiles)
- Token management β Revoke access for any client instantly from the admin panel
Model Context Protocol (MCP) is a standard for connecting AI agents to data sources and tools. This plugin implements an MCP server so external AI clients like ChatGPT or Claude Desktop can discover and use your WordPress tools. This is in addition to the built-in AI Chat Agent.
Yes! The plugin includes 61 WooCommerce tools. They activate automatically when WooCommerce is installed. Ask your AI agent “Show me today’s orders” and it just works.
Yes, through WordPress Abilities. Legacy Custom Tools have been retired for security reasons; use plugins that register WordPress Abilities with explicit schemas and permission callbacks, then import them from the Abilities tab.
No worries β Flex MCP is the only MCP server with a built-in Roll Back system. Every change made by any AI (ChatGPT, Claude, the Chat Agent, Copilot, or automations) is tracked with a full before/after snapshot. Go to Logs & Roll Back in your admin panel and undo any change with one click. You can even roll back an entire session at once.
Yes! The wp_generate_image tool supports multiple providers:
- OpenAI β gpt-image-1 (default), gpt-image-1.5, gpt-image-2, gpt-image-1-mini, DALLΒ·E 3, DALLΒ·E 2
- Google Gemini β gemini-2.5-flash-image (default), gemini-3.1-flash-image-preview, gemini-3-pro-image-preview, Imagen 4
Just ask your AI agent “Generate an image of…” or configure defaults in Flex MCP Multimedia Settings Images.
Yes! The optional wp_search_image tool can search Unsplash, Pexels, and Pixabay and return one image with rich attribution metadata.
The tool response includes both text JSON and structured output with fields such as:
url,thumbnail_url,caption,alt_textauthor,author_url,source_url- image dimensions, license/metadata fields, and provider-specific fields like Unsplash
download_location
Configure everything in Flex MCP Multimedia Settings Search Image:
- Global enable/disable toggle for
wp_search_image - Per-provider enable + API keys (Unsplash, Pexels, Pixabay)
- Preferred Image Bank (specific provider or random)
- Image Selection mode:
most_relevant,random_top10,random_top20 - Extra parameters: orientation, safe search, Pixabay language, Pexels locale, and timeout
Yes! The wp_generate_video tool supports:
- OpenAI Sora β Text-to-video and image-to-video generation
- Google Veo β Veo 2 and Veo 3 models
Video generation runs asynchronously in the background. Configure providers and API keys in Flex MCP Multimedia Settings Videos.
Go to Flex MCP Multimedia Settings. API keys are shared between the Images and Videos tabs β enter your OpenAI or Gemini key once and it works for both.
WordPress 6.9 introduced the Abilities API, letting plugins register standardized capabilities. If you have plugins that support Abilities, Flex MCP can auto-discover and import them from MCP Server Abilities tab.
It takes less than a minute:
- Go to Flex MCP MCP Server and copy the SSE URL
- Paste it in your AI client:
- Claude Desktop: Customize Connectors Add custom connector
- ChatGPT: Settings Apps & Connectors Advanced settings Enable Developer mode Create app Paste the URL Choose OAuth
- Authorize when the browser window opens (you only need to do this once)
The plugin uses OAuth 2.1 β no API keys or passwords needed. Your session stays active for up to 90 days.
This is usually caused by Cloudflare’s “Block AI Bots” setting (enabled by default on new domains) or similar WAF rules from Sucuri, Wordfence, SiteGround, WP Engine, etc.
What happens: The OAuth consent screen works fine (it runs in your browser), but after the token exchange, the AI backend servers (Anthropic, OpenAI) try to reach your MCP endpoint β and the firewall blocks them as bot traffic, returning a 403 before the request ever reaches WordPress.
How to confirm: Check your firewall logs. You’ll see the OAuth/token requests succeed but subsequent MCP requests from Anthropic or OpenAI IPs are blocked.
Option 1 β Disable AI bot blocking:
- Cloudflare: Dashboard Security Settings turn off “Block AI Bots”. Note: this is all-or-nothing β you cannot allow only Anthropic/OpenAI while blocking others.
- Sucuri / Wordfence / other WAFs: Whitelist the AI provider’s IP ranges or user agents (e.g.,
python-httpxfor Anthropic,ChatGPT-Userfor OpenAI).
Option 2 β Use Application Passwords (bypasses the firewall):
If you cannot change your firewall settings, use WordPress Application Passwords instead of OAuth. This connects directly from Claude Desktop on your machine, bypassing the AI provider’s proxy entirely:
- Go to Users Your Profile in WordPress admin
- Scroll to Application Passwords section
- Enter a name (e.g., “Claude Desktop”) and click Add New Application Password
- Copy the generated password (shown only once)
- In
claude_desktop_config.json, configure the MCP server with your username and the application password as HTTP Basic Auth headers
This method works even behind strict firewalls because all requests come from your own computer.
Reviews
Excelente plugin, funcional e acima das expectativas!
By Fernando Pimenta (fernandopimenta) on April 11, 2026
Estou avaliando com 5 estrelas porque este plugin me proporcionou exatamente a experiΓͺncia que eu buscava: conectar a IA via MCP de forma simples e eficiente. Funcionou perfeitamente e foi muito fΓ‘cil configurar. AgradeΓ§o ao desenvolvedor pela dedicaΓ§Γ£o e por entregar um plugin tΓ£o completo, com muitas funcionalidades que ainda pretendo explorar aos poucos. Excelente trabalho!
Thank you
By deynadc9 on March 20, 2026
I use LibreChat with StifLi Flex MCP to run my entire e-commerce operation conversationally
Excelente!
By gravatar25k on February 14, 2026
I connected Claude to my WooCommerce store in minutes. Now I manage products, orders, and inventory just by chatting. 117 tools? Insane power!
Perfect!
By amilysdqr on January 16, 2026
As a developer, the granular permissions and custom profiles are perfect
Changelog
3.5.4
- Branding: Renamed the user-facing plugin name from StifLi Flex MCP to Flex MCP across WordPress metadata, admin screens, MCP server identity, messages, and documentation; technical slugs and integration identifiers remain unchanged.
- Fix: MCP Server, Multimedia, SEO, Plugin Integrations, Logs, Automation Tasks, and Event Automations admin assets now load reliably with the current Flex MCP page hooks, preserve compatibility with legacy hooks, invalidate stale browser caches with the plugin version, preserve native WordPress table layout for tool rows, and keep legacy OAuth tab links fully styled and interactive.
- MCP: The
2025-11-25initialize response now advertises the WordPress Site Icon through the protocol-standardserverInfo.iconsstructure and reports the plugin version on both direct and SSE transports; older negotiated protocol versions remain unchanged. - MCP: Unknown methods now return the standard JSON-RPC
-32601code consistently across direct and legacy SSE flows, including task methods, preventing strict clients from treating probes as reconnect failures. - OAuth: Discovery now accepts RFC path-scoped metadata URLs for the MCP
sseandmessagesresources, including WordPress installations hosted in subdirectories. - Compatibility:
mcp_ping,wp_get_posts, andwp_get_postnow advertiseoutputSchemaand return matchingstructuredContentwhile preserving their legacy text output. - WooCommerce: Product and variation reads now include additive ISO 8601 lifecycle and sale-window dates plus stable catalog, tax, stock, and purchasing fields; subscription details are included only when supported by the product runtime.
- WooCommerce: Coupon reads now include ISO 8601 dates and non-personal usage, amount, product, and category restrictions, while order reads expose additive ISO 8601 lifecycle aliases without removing existing date fields.
- New: Added
cf7_list_formsandcf7_get_formfor Contact Form 7 form discovery and normalized field schemas. - New: Added optional
flamingo_get_submissionssensitive reads with strict result caps and redaction of email, phone, IP, and secret fields; the tool is hidden when Flamingo storage is unavailable. - Reliability: Failed database schema upgrades now pause automatic retries for 24 hours to prevent repeated queries and log flooding on incompatible hosts; plugin reactivation clears the cooldown for an immediate retry.
- Developer: Added 3.5.4 upgrade seeding and separate Contact Form 7 and Flamingo integration catalog entries.
3.5.2
- Reliability: Post meta, Yoast, Rank Math, ACF, and featured-image mutations now complete through the standard WordPress post-update lifecycle after effective metadata changes, refreshing modification dates, caches, and save listeners.
- New: Added
yoast_get_schemafor resolved Yoast JSON-LD and enrichedyoast_get_metawith stored/resolved values, social fallbacks, robots data, and explicit SEO/readability analysis status. - New: Added
wpforms_get_formandwpforms_get_entry; WPForms reads now normalize choices and timestamps, redact sensitive keys, paginate deterministically, and fail cleanly when entry storage is unavailable in WPForms Lite. - Improvement:
wp_set_featured_imagenow accepts optional attachment alt text, handles unchanged requests idempotently, and post reads expose non-breakingfeatured_media_idandfeatured_media_urlaliases. - Improvement:
divi_validate_layoutacceptsraw_contentand can validate shortcode structure without Divi Builder or a Divi theme being active. - Improvement: The Help tab now reports the live enabled-tool count, prioritizes OAuth 2.1, includes current WAF/schema troubleshooting, and provides copy-safe diagnostics without credentials or request payloads.
- Developer: Added
scripts/audit-tool-schemas.ps1to validate livetools/listschemas, including active WooCommerce and optional integration tools, for strict MCP clients.
3.5.1
- New: Added undo-aware
divi_clone_page,divi_replace_image, anddivi_apply_library_templatetools, preserving Divi content and_et_*metadata for Divi 4 and alternate Divi 5 storage. - New: Added
elementor_apply_template_to_pagewith replace and append modes, including support for ordinary pages that do not yet contain Elementor data. - New: Added single and bulk Elementor render repair tools that validate and re-save existing builder data, restore required metadata, searchable fallback content, and caches without inventing missing layouts.
- New: Added undoable
wp_update_permalink_structurewith native token validation, exact write verification,%XXpreservation, and rewrite-rule refresh on update, rollback, and redo. - Improvement:
elementor_replace_textnow supports an expected-count guard, nested image alt/title/caption replacement, and optional synchronization to editable Media Library attachments. - Improvement: Elementor clones now populate
post_contentwith a safe textual fallback extracted from builder widgets so WordPress core search can find cloned content. - Improvement: URL write sanitization now detects input mangling before Elementor or Divi changes and preserves percent-encoded and templated URL segments.
- Fix: Tool schema normalization now supplies a valid
itemsschema for every array and normalizes schema-valuedadditionalPropertiesfor strict MCP clients. - Security: MCP debug logs now redact sensitive arguments and decoded payloads and no longer store raw request bodies.
- Developer: Added
stifli_flex_mcp_oauth_metadata_urlto override OAuth and OpenID metadata probe URLs on hosts that intercept/.well-known/routes.
3.5.0
- New: Added optional Divi integration with six MCP tools for page format inspection, layout outlines, shortcode validation, local template discovery, Divi Library retrieval, and structure-safe text replacement with dry-run support.
- New: Added
wp_publish_and_promoteto publish draft, pending, or scheduled content and add it to a navigation menu in one undoable workflow. - New: Added
wp_create_menuand extendedwp_create_nav_menuwith optional theme-location assignment. - New: Added
wp_create_preview_linkfor expiring, cryptographically protected public previews of non-public content, with no-cache and noindex headers. - Improvement: Post revision results now include Unicode-aware content length for safer revision selection and restoration workflows.
- Improvement: Elementor and Divi text replacement tools now warn when replacement text contains literal escape sequences, helping prevent accidental escaped markup or formatting.
- Improvement: OAuth diagnostics now identify Sucuri/CloudProxy blocks, provide provider-specific guidance, offer a nonce-protected Re-check now action, and retry blocked checks sooner.
- Improvement: Added upgrade seeding, profile registration, optional integration discovery, and complete undo/redo tracking for the new editorial and Divi tools.
3.4.9
- New: Added
wc_get_orderfor detailed retrieval of one WooCommerce order, including customer addresses, line items, fee lines, shipping lines, totals, customer note, and raw payment method ID. - Improvement: Added
wc_get_orderto WooCommerce Read Only, WooCommerce Store Management, Complete E-commerce, and Safe Mode profiles, with an upgrade migration for existing installations. - Improvement:
wc_update_orderandwc_update_productnow reload and return the actual persisted object after saving, improving write verification. - Fix:
elementor_replace_textcase-insensitive matching now supports Unicode text, including accented characters.
3.4.8
- Fix: Restored legacy SSE response delivery so Claude Desktop connectors receive
initializeand other JSON-RPC responses through their active SSE session.
3.4.7
- Fix: Restored the Continue to MCP Server action on the first-activation layer selection screen for new installations.
3.4.6
- Security: Strengthened MCP access controls for sensitive read operations.
3.4.5
- New: Added WP MCP Hub links and a free, open-source multi-site management message to the plugin documentation.
- New: Added a dismissible WP MCP Hub notice and a persistent footer message across Flex MCP admin pages.
3.4.4
- New: Added
elementor_update_widgetto update Elementor widget settings byelement_idwith undo compatibility. - New: Added
elementor_export_templateto export Elementor template/page data as JSON for portability workflows. - New: Added
wc_bulk_assign_product_categoriesandwc_bulk_delete_productsfor WooCommerce bulk product operations. - Improvement: Expanded
wc_batch_update_productsto supportcreate,update, anddeleteoperations (plus legacyupdatescompatibility). - Improvement: Added compatibility aliases for automation scripts (
wc_batch_update_products.update[].idas alias ofproduct_id, andelementor_export_template.post_idas alias oftemplate_id). - Improvement: Expanded
mcp_pingwithconnection_contextandbuilder_versionsto improve connector diagnostics. - Improvement:
mcp_ping.connection_context.session_idnow falls back to the active ChangeTracker session when transport context is empty, improvingmcp_rollback_sessionoperability. - Improvement: Added
session_idfilter tomcp_get_changelogschema and runtime filtering, so rollback targets can be discovered from tool outputs. - Improvement: Added enriched
sflmcp_tool_contexthook payload while preserving legacy hook compatibility. - Improvement: Hardened
wp_update_postandwp_update_pageresponses with requested-vs-saved checks, including dropped-field reporting. - Improvement: Added
.mcpbone-click bundle download flow from OAuth settings to simplify Claude Desktop connector setup. - Improvement: Added
README.mdoptimized for GitHub rendering, including linked video thumbnail preview.
3.4.3
- Fix: WordPress 6.9+ Abilities compatibility for schema-less abilities. When no arguments are provided and the ability has no effective input schema, MCP now calls
execute(null)instead ofexecute([]). - Fix: Plugin Integrations tab CSS now uses the same base visual style as the Tools tabs, restoring card/table layout consistency in
admin.php?page=sflmcp-server&tab=plugins.
3.4.2
- New: Added
wp_get_cron_scheduleto inspect scheduled WP-Cron events with next-run timestamps, overdue status, and optional hook filtering. - New: Added
wp_get_error_log_tailto read recent lines fromwp_debugor plugin logs with optional keyword filtering. - Improvement: Added proactive OAuth notices for Plain permalink mode and stale static
.well-knownmetadata files that can break connector discovery.
3.4.1
- Improvement: Enhanced post and page management tools.
- Improvement: Improved search results and WooCommerce order listings.
- Improvement: Improved WordPress taxonomy and post metadata tools.
- Improvement: Added integration refinements for MCP tool execution.
3.4.0
- New: Added modular installation with a first-activation selector for AI Chat Agent, AI Copilot, Automations, SEO, and Plugin Integrations.
- Improvement: New installations load only MCP Server by default, including Multimedia and Logs & Roll Back; disabled addons no longer register their PHP classes, menus, hooks, cron workers, or automation tables.
- Improvement: Added an Add-ons tab under MCP Server settings so administrators can change layers at any time while preserving all modules on existing installations until explicitly changed.
3.3.13
- Security: Retired legacy Custom Tools runtime execution to prevent lower-privileged users from invoking administrator-defined custom workflows through tool execution endpoints.
- Security: Existing legacy Custom Tools are disabled automatically during upgrade, and
custom_*tool calls now return a deprecation error instead of dispatching HTTP requests or WordPress action hooks. - Improvement: Removed Custom Tools from MCP tool discovery and admin surfaces. Use WordPress Abilities for custom MCP extensions with explicit permission callbacks.
3.3.12
- Security: Hardened
elementor_add_widgetraw settings path by requiringunfiltered_htmlbefore accepting caller-supplied rawsettings. - Security: Tightened non-curated widget validation to fail closed when Elementor widget registry is unavailable, preventing permissive fallback acceptance.
- Improvement: Updated tool schema/docs to explicitly state the raw settings capability requirement.
3.3.11
- New: Added
elementor_add_widget, a structural Elementor write tool for inserting widgets or containers into existing Elementor pages. - Improvement: Supports raw Elementor settings for registered widget slugs and curated flat parameters for container, heading, text-editor, button, image, image-box, icon-box, icon-list, video, divider, and spacer widgets.
- Security: Validates
edit_poston the target page, validates parent containers/sections/columns whenparent_idis supplied, and rejects unknown non-curated widget types unless Elementor’s registry is unavailable.
3.3.10
- Security: Added object-level
edit_postanddelete_postchecks to post, page, and media MCP tools before mutating or deleting specific content. - Improvement: Single-object post, media, post meta, and SEO tools now accept common ID aliases (
ID,id,post_id, andattachment_idwhere relevant) for better MCP client compatibility. - Improvement: Post, page, media, and term update tools now preserve existing text fields when optional text arguments are sent as empty strings.
- Improvement: Rank Math and Yoast SEO tools now read and update the WordPress slug, returning the slug actually saved by WordPress.
- Cleanup: Expanded uninstall cleanup to remove OAuth, automation, event, ability, changelog, and dynamic plugin options across single-site and multisite installs.
3.3.9
- Security: Added explicit WordPress capability enforcement for sensitive WooCommerce read tools, including orders, order notes, refunds, reports, taxes, shipping, payment gateways, system status, settings, webhooks, and coupons.
- Improvement: Enriched ACF MCP responses with field group metadata, field definitions, labels, types, return formats, nested sub-fields, structuredContent, and normalized object values for posts, users, terms, dates, and plugin objects.
3.3.8
- New: Added
wp_css_get_globaltool to read active theme Additional CSS (Customizer) with hash and optional metadata/statistics output. - New: Added
wp_css_set_globalandwp_css_set_scopedtools to manage global and scoped CSS with validation, optimistic concurrency (expected_hash), and dry-run mode (validate_only). - Improvement: Integrated
wp_css_set_globalandwp_css_set_scopedwith ChangeTracker so they appear in Logs (sflmcp-logs) with rollback/redo support.
3.3.7
- New: Added optional
wp_search_imagemodule (class-search-image.php) with lazy loading from the model only when enabled insflmcp_tools, protected byupload_filescapability. - New:
wp_search_imagenow returns MCP-friendly output in both text JSON andstructuredContent, including URL, thumbnail URL, caption, alt text, author, author URL, source URL, dimensions, license/metadata, and provider-specific fields such as Unsplashdownload_location. - New: Added a dedicated Search Image tab in Multimedia Settings with tool toggle, provider toggles + API keys (Unsplash/Pexels/Pixabay), preferred bank, image selection mode (
most_relevant,random_top10,random_top20), and extra search parameters (orientation, safe search, language/locale, timeout).
3.3.6
- New: Added SEO optimization tools for GSC-backed post context, title/meta suggestions, and safe Yoast/Rank Math metadata updates with rollback support.
- New: Added MCP resources for site info, post types, recent posts, and SEO summary through resources/list and resources/read.
- Improvement: SEO and Google Search Console modules now load lazily only when enabled, connected, or opened in the SEO admin page.
3.3.5
- New: Added Google Search Console support under a new SEO admin page, with Google OAuth connection, encrypted tokens, connection testing, cache controls, tool toggles, and 5 read-only SEO data tools.
- Improvement: Google Search Console performance queries now return compact summaries with capped row output to prevent excessive MCP token usage.
- New: Added Elementor compatibility as a plugin integration with 7 dedicated tools for cloning pages, replacing text/images/links, reading page outlines, listing local templates, and importing templates.
- Improvement: Various reliability and compatibility improvements across WordPress content handling, WooCommerce order tools, OAuth discovery, and plugin integrations.
3.3.4
- Improvement: Various improvements and content updates in the plugin documentation and onboarding resources.
3.3.3
- Improvement: Upgraded the Abilities admin table with sortable columns, row selection, and bulk actions (enable, disable, remove).
- Improvement: Upgraded Discover Abilities with category filtering and bulk import actions for selected or visible abilities.
- Improvement: Added a dedicated bulk abilities backend action and reused shared import/category normalization logic.
- Fix: Moved the OAuth global reset action to the visible Connected Clients area in MCP Server Settings and removed duplicate placement.
- Fix: Hardened
wp_update_nav_menu_itemupdates with a safer merge flow that preserves existing values unless explicitly changed.
3.3.2
- Fixed:
wp_create_postandwp_update_postnow correctly applypost_categoryandtax_input(includingpost_tag) when creating or updating posts.
3.3.1
- Improvement: Enhanced “Alternative: Application Passwords” with in-page generation from MCP Server Settings (no navigation to profile required).
3.3.0
- New: Compatibility with The Events Calendar plugin, including integrated event tools for listing, reading, creating/updating, and trashing events and related entities.
3.2.9
- Improvement: Updated image generation model catalog in Multimedia Settings. Added new OpenAI and Gemini image models while keeping previous models available for user selection.
- Improvement: Set default image models to cost-effective options (
gpt-image-1andgemini-2.5-flash-image) and refreshed pricing guidance in the UI. - New tools:
wc_get_variation,wc_batch_update_variations,wc_get_product_attributes,wc_get_attribute_terms,wc_create_product_attribute,wc_set_product_attributes,wc_get_coupon,wc_get_coupon_count,wc_empty_coupon_trash. - Tool improvements:
wp_get_taxonomies(slug/name/label output),wp_get_term_meta(structured payload with secret redaction),wc_get_product_variations(normalized variation rows),wc_update_product_variation(ownership validation),wc_delete_product_variation(ownership validation),wc_get_coupons(status filtering, including trash),wc_delete_coupon(clear trash vs permanent outcome),wc_get_coupon_count(status-based counting, including trash).
3.2.8
- Improvement: Official compatibility update for WordPress 7.0 with WordPress AI Client integration in AI Chat Agent.
- Improvement: Improved compatibility with external AI Client connectors such as OpenRouter and Mistral (plus any installed AI Client provider).
3.2.7
- Improvement: Updated MCP protocol reference and compatibility to the 2025-11-25 specification.
- Improvement: Improved
wp_generate_imagereliability with async task handling plus safer media persistence/post-processing. - Improvement: Improved
wp_generate_videoreliability with async task handling, atomic file save, and background metadata processing.
3.2.6
- New: Expanded
mcp_pingwith optional diagnostics (diagnostics,timeout_sec) to surface site URL, REST endpoint, HTTPS state, DNS resolution, and lightweight reachability checks without forcing remote calls by default. - New: Upgraded
wp_get_posts,wp_get_post,wp_get_comments,wp_get_users,search,wc_get_products, andwc_get_orderswith richer optional outputs and standardizedinclude_paginationmetadata wrappers. - New: Added opt-in enrichment flags for common read tools, including author, featured media, taxonomy context, avatar/registration data, product images/categories/attributes, and order item or totals summaries.
- New: Improved
searchandfetchwith broader filters, query-param support, custom request/response headers, and targeted remote inspection controls (head_only,include_headers,extract_text,max_bytes,timeout_sec).
3.2.5
- New: The AI Chat Agent token usage panel now shows three separate bars for billable input tokens, cached tokens, and output tokens.
- Improvement: Normalized token accounting across OpenAI, Claude, and Gemini providers so the three bars reflect provider-specific cache semantics more truthfully.
- New: Upgraded
wp_get_site_healthinto a richer site audit tool with selectable depth levels (0basic,1medium,2deep) to balance diagnostic detail and timeout risk.
3.2.4
- New: Added
wp_get_plugin_settingsto inspect plugin-relatedwp_optionsbyplugin_slug/prefixes with prepared SQL + limit controls and strict recursive redaction of secrets/tokens/passwords. - New: Generalized term tools – added
wp_update_termand extendedwp_create_term/wp_delete_termwith optional slug/parent/description plus per-taxonomy capability checks (existingwp_*_categoryandwp_*_tagtools kept as aliases).
3.2.3
- New: Generalized term tools β added
wp_update_termand extendedwp_create_term/wp_delete_termwith optional slug/parent/description plus per-taxonomy capability checks (existingwp_*_categoryandwp_*_tagtools kept as aliases). - New: Term meta tools
wp_get_term_meta(with secret redaction),wp_update_term_meta,wp_delete_term_meta. - New:
wp_reorder_menu_itemstool to batch-updatemenu_order/parentfor navigation menu items in one call (with one-click rollback). - Security:
wp_create_post/wp_update_postnow validatepost_typeexists and is public/show_ui, enforce post-type-aware capabilities, and requireedit_others_postscap when assigning a differentpost_author. - Infrastructure: New DB migration seeds the new tools into existing installs and attaches them to the “WordPress Full Management” profile.
3.2.2
- Security: Added centralized recursive secret redaction for MCP outputs.
- Security: Applied redaction to sensitive reads (
wp_get_option,wp_get_settings,wp_get_post_meta,wp_get_user_meta) and masked email/IP fields inwp_get_comments. - Security: Hardened
wp_update_optionandwp_update_settingswith hard denylist, sensitive-pattern blocking, and optional allowlist viasflmcp_writable_options. - Security: Removed
wp_delete_optiontool (destructive operation without reliable undo), including migration cleanup for existing installs. - Security: Hardened
wp_upload_image_from_urlwith SSRF protection (private/reserved IP blocking), HTTPS requirement, 20MB limit (filterable), MIME allowlist, and image validation. - New: Added
wp_set_featured_imagetool and support forfeatured_mediainwp_create_postandwp_update_post. - OAuth: Dynamic client registration now returns HTTP 500 on DB insert failures, logs internal DB errors, and avoids exposing SQL internals.
- Infrastructure: Added
sflmcp_db_versionupgrade flow for versioned DB migrations.
3.2.1
- fix bug
3.2.0
- ποΈ Tools UI overhaul β Tools are now organized into collapsible category groups with expand/collapse controls, read/write mode badges, and token count per category for easier management
- π§© New “Plugins” tab β Dedicated integrations hub with 12 pre-loaded plugin integrations ready to connect:
- All Sources Images β Find stock images and generate AI images; set featured or inline images in posts (Recommended)
- AiPatch Security Scanner β AI-powered security auditing and vulnerability scanning (Recommended)
- Notification for Telegram β Send Telegram notifications from MCP tools
- WPCode β Manage code snippets (insert headers/footers) via AI
- Code Snippets β Create, activate, and manage PHP/CSS/JS snippets via AI
- Woody Snippets β Alternative snippet provider with full snippet_* tool support
- Advanced Custom Fields (ACF) β Read and update ACF fields and field groups
- Yoast SEO β Read and update Yoast metadata; trigger reindexing
- Rank Math β Manage Rank Math SEO metadata and head output
- WPForms β List forms and read form entries
- Gravity Forms β List forms, read entries, and update submissions
- Forminator β List forms and read form entries
3.1.5
- Fixed: OAuth re-authorization crash when reconnecting previously authorized clients (ChatGPT, Claude Desktop)
3.1.4
- π WebMCP β Browser AI (Beta) β Use Chrome’s built-in Gemini Nano to edit posts directly, no API key needed!
- Note: Beta feature β Gemini Nano is a compact on-device model with limited reasoning; works best for simple editing tasks
3.1.3
- Fixed: Minor bug fixes and stability improvements
3.1.2
- βͺ Roll Back β Undo Any AI Change Instantly!
- New: Full change tracking β every modification by ChatGPT, Claude, AI Chat Agent, Copilot, or automations is recorded
- New: One-click rollback β undo any change from the Logs & Roll Back admin page
- New: Redo support β re-apply a rolled-back change if you change your mind
- New: Session rollback β undo all changes from an entire AI conversation at once (LIFO order)
- New: Before/after snapshots β see exactly what changed with full state comparison
- New: Source tracking β every change shows where it came from (MCP Connection, Chat Agent, Copilot, Automation, Event, WP Admin)
- New: 5 MCP tools β
mcp_get_changelog,mcp_get_change_detail,mcp_rollback_change,mcp_redo_change,mcp_rollback_session - New: Changelog admin page with filters, search, detail modal, CSV export, and automatic purge
- New: Works across 60+ mutating tools β posts, pages, products, orders, options, menus, media, snippets, and more
- New: File backup & restore β even deleted media files can be recovered
- Improved: The only MCP server for WordPress with built-in undo capabilities
3.1.1
- Compatibility: Tested with WordPress 7.0 RC
3.1.0
- π OAuth 2.1 Authentication β Connect ChatGPT, Claude Desktop, and any MCP client with one click!
- New: Full OAuth 2.1 implementation with PKCE (S256) β the most secure authentication standard
- New: Dynamic Client Registration (RFC 7591) β AI clients register automatically, zero manual setup
- New: Auto-discovery via RFC 9728 (Protected Resource Metadata) and RFC 8414 (Authorization Server Metadata)
- New: Automatic token refresh β sessions stay active for up to 90 days without re-authorization
- New: Auto-approve for returning clients β authorize once, connect instantly on future sessions
- New: Simplified Settings page β just copy the URL and paste it in your AI client
- New: “View More Details” panel with connected clients, active tokens, and troubleshooting
- New: One-click client deletion and token revocation from the admin panel
- Improved: No more API keys or passwords needed for external AI clients
- Improved: Full compatibility with Claude Desktop Connectors and ChatGPT Apps & Connectors
- Improved: Standards-compliant OpenID Connect discovery fallback for maximum client compatibility
- Security: PKCE S256 challenge on every authorization flow
- Security: Short-lived authorization codes (10 min) with single-use enforcement
- Security: Access tokens expire in 24 hours, refresh tokens in 90 days
- Security: Application Passwords still supported as fallback for advanced setups
3.0.3
- Fixed: MCP Server connection with Claude Desktop and other SSE-based clients now works correctly
- Fixed: Scheduled automation tasks running more frequently than configured and producing intermittent errors
3.0.2
- π§© Code Snippets Management β 7 new MCP tools for managing code snippets directly from AI agents!
- New: snippet_list, snippet_get, snippet_create, snippet_update, snippet_delete, snippet_activate, snippet_deactivate tools
- New: Multi-provider support β compatible with WPCode, Code Snippets (v2/v3), and Woody Code Snippets plugins
- New: Automatic provider detection β seamlessly works with whichever snippet plugin is installed
- New: LLM-friendly input normalization β maps common AI output variants for code_type, location, and scope parameters
- New: PHP code sanitization β automatically strips
<?php,?>tags and markdown code fences from AI-generated code - New: Code Snippets v3.x full namespace support β resolves namespaced functions and classes automatically
- New: Woody Code Snippets scope mapping β translates locations to Woody’s dual scope/location system
- Security: Rate limiting (30 requests/minute per IP) on MCP endpoints to prevent abuse
- Security: SSRF protection on fetch tool β blocks requests to private/reserved IP ranges (127.x, 10.x, 172.16.x, 192.168.x)
- Improved: Snippet tools added to WordPress Full Management profile (auto-migrated for existing installs)
3.0.1
- βοΈ AI Copilot β New floating writing assistant for the WordPress editor!
- New: AI Copilot widget available inside the Gutenberg and Classic editors
- New: Quick action chips β Optimize content, Generate tags, Write excerpt, Generate image
- New: Direct editing β the Copilot sets titles, excerpts, tags, categories, and slugs in the editor
- New: Block operations β insert, update, replace, and delete Gutenberg blocks through conversation
- New: Visual feedback β green highlight on changed fields and blocks with auto-dismiss
- New: Keep/Undo banner on every AI change for full user control
- New: Image generation workflow β generate an image and set it as featured or insert as block
- New: AI Copilot settings page with enable/disable toggle and tools mode selection
- New: Full context awareness β reads post content, blocks, metadata, and WooCommerce product fields
2.2.2
- π Token Usage Bars β Real-time speedometer-style token bars in the AI Chat Agent showing input, output, and cached tokens per interaction.
2.2.1
- π€ Updated AI Models for All Providers β Refreshed the full model catalog across OpenAI, Anthropic (Claude), and Google Gemini.
- New: OpenAI GPT-5.4 series β GPT-5.4 Pro, GPT-5.4, GPT-5.4 Mini, GPT-5.4 Nano (1M context, Computer Use support)
- New: OpenAI GPT-5.3 and GPT-5.3 Mini added as stable production models
- New: Anthropic Claude Sonnet 4.6 and Claude Opus 4.6 (1M context, 128K output, Extended Thinking)
- New: Anthropic Claude Sonnet 4.5, Claude Opus 4.5, and Claude Haiku 4.5
- New: Google Gemini 3.1 Pro, Gemini 3 Flash, and Gemini 3.1 Flash-Lite (latest generation)
- Updated: Google Gemini 2.5 Pro, Flash, and Flash-Lite remain as stable production models
- Updated: Default models changed β GPT-5.4 (OpenAI), Claude Sonnet 4.6 (Claude), Gemini 3 Flash (Gemini)
- Removed: Deprecated models β GPT-5 Nano, Gemini 2.0 Flash/Flash-Lite, older Claude 3.x aliases
2.2.0
- π AI Image Generation β Generate images directly from your AI agent using
wp_generate_image! - π AI Video Generation β Generate videos with
wp_generate_videousing cutting-edge AI models! - New: wp_generate_image tool with multi-provider support (OpenAI gpt-image-1, DALLΒ·E 2/3, Google Gemini Imagen 4)
- New: wp_generate_video tool with multi-provider support (OpenAI Sora, Google Veo 2/3)
- New: Multimedia Settings admin page with dedicated Images and Videos tabs
- New: Post-processing options β auto-save generated media to Media Library, auto-insert into posts
- New: Configurable default providers, models, image sizes, and quality settings
2.1.0
- π Automation Tasks β Schedule AI tasks to run automatically on a recurring basis!
- π Event Automations β Trigger AI workflows when WordPress events occur (new post, new user, etc.)
- New: Automation Tasks admin with create, edit, duplicate, delete, and run-now functionality
- New: 4 schedule presets (hourly, daily, weekly, monthly) with custom time and timezone support
- New: Pre-built automation templates (Daily Sales Report, Trending Article, Weekly Summary, and more)
- New: “Detected Tools” mode β AI identifies required tools during test, saves tokens significantly
- New: Output actions β Email, Webhook, Draft Post, or Custom Hook
- New: Execution Logs tab with full history, token usage, and detailed results
- New: Event Automations with WordPress triggers (post published, user registered, comment posted)
- New: Conditional logic for event triggers (post type, status, category filters)
- New: Dynamic placeholders in prompts (
{{post.title}},{{user.email}}, etc.) - New: Rate limiting per automation to prevent runaway executions
- New: Test mode for event automations β preview AI response with real trigger data
- New: Tools count display in AI Chat Agent header with quick configure link
- Improved: Cron tasks now execute with proper user permissions (task creator or admin fallback)
- Improved: Complete log entry format fixes for database consistency
- Improved: Database migration for automation logs table columns
- Technical: New tables
wp_sflmcp_automation_tasks,wp_sflmcp_automation_logs,wp_sflmcp_event_automations,wp_sflmcp_event_logs,wp_sflmcp_event_triggers
2.0.3
- ** Encrypted API Keys** – API keys are now stored encrypted (AES-256-CBC) in the database for improved security
- ** Prompt Caching (Claude)** – Enabled Anthropic prompt caching on system prompt and tools, reducing token usage and latency on repeated requests
- ** Provider Usage Logging** – Real-time logging of input/output/cached tokens for Claude, OpenAI, and Gemini
- ** Rate Limit Awareness** – Captures and logs rate limit headers from all three providers for better diagnostics on 429 errors
- New: Conversation history trimming with configurable “Max Tool Cycles in History” setting to control payload size
- New: Smart trim algorithm with safe cut points β never orphans tool_result references
- New: API key visibility toggle (eye icon) in chat settings
- New: Token estimation utilities (
estimateTokensFromString,estimateTokensFromJson) - Improved: Auto-save on all chat settings (removed manual “Save Settings” button)
- Improved: Compact request logging β summaries instead of full body dumps, reducing log noise
- Improved: HTTP request layer now returns headers and status code alongside body (
make_request_with_meta) - Improved: JSON encoding with
JSON_UNESCAPED_SLASHES | JSON_UNESCAPED_UNICODEfor cleaner payloads
2.0.2
- π WordPress Abilities Integration (WordPress 6.9+) – Auto-discover and import abilities from other plugins!
- New: Abilities tab in admin (appears only on WordPress 6.9+)
- New: Discover button to scan all registered abilities from themes/plugins
- New: Import, enable/disable, and delete individual abilities
- New: Abilities exposed as MCP tools (ability_* prefix) for AI agents
- New: Database table wp_sflmcp_abilities for persistent ability storage
- Improved: Plugin description updated to reflect 117+ tools
- Improved: Admin menu reordered β AI Chat Agent first, MCP Server second
- Improved: Renamed “AI Chat” to “AI Chat Agent” across the UI
- Technical: Uses wp_get_abilities(), wp_get_ability(), $ability->execute() APIs
2.0.1
- π Built-in AI Chat Client – Chat with AI directly from your WordPress admin panel!
- New: Multi-provider support – OpenAI, Claude (Anthropic), and Google Gemini
- New: Support for latest models including GPT-4.5, Claude 4 Opus/Sonnet, Gemini 2.5 Pro/Flash
- New: Smart suggestion chips that appear after AI responses
- New: Conversation history auto-saved per user (7-day retention)
- New: Stop button to cancel AI responses mid-generation
- New: Tool permission modes – “Always Allow” or “Ask User” for confirmations
- New: Advanced settings tab with temperature, max tokens, top_p, frequency/presence penalty
- New: Customizable system prompt for AI behavior
- New: Tool display options (Full details, Compact, or Hidden)
- New: Multilingual suggestions – AI responds in the same language you use
- Improved: Sequential tool execution for better reliability across all providers
- Improved: Claude 4.5 model compatibility (temperature/top_p handling)
- …