MCP Logs
AI agents talk to WordPress sites directly now. Claude, ChatGPT, Cursor, and a growing list of MCP clients can connect to your site, read content, place orders, edit posts, or call any custom tool you expose. The Model Context Protocol (MCP) is the open standard that makes this possible. The problem is that by default you cannot see any of it. Requests arrive, things change, and there is no record of what an agent did, when it did it, or which user it acted as. MCP Logs writes a row for every MCP request the moment it hits your site. You get the route, the ability that was called, the user it acted as, the request body, the response, and whether it succeeded. All of it is browsable in a React admin page built with @wordpress/components, so it looks and behaves like the rest of WordPress. Version 1.1.0 adds the other half: detection rules that watch the traffic as it arrives, email alerts when one trips, and a kill switch that stops all MCP access in one click. A log you can actually search Filter by date range, ability name, and user. Sort any column, set page size between 10 and 500, and run full-text search across stored request and response bodies. Click a row to open the request and response in collapsible panels, copy either to your clipboard, or trace a single agent session end to end. Export the current view to CSV when you need to hand findings to someone else. Detection rules that run on every request Three rules evaluate after each logged request: Request velocity per session. Catches an agent stuck in a loop. Destructive tool use. Watches a list of abilities you nominate. It can populate that list for you by scanning previously seen tool names for delete, remove, and drop. Error storms. Catches an integration that has started failing. Each rule has its own enable toggle, threshold, time window, severity, and auto-disable setting. Detected events land in a Security Events tab with filters, stat cards, CSV export, and a per-event “mark as reviewed” so your queue reflects what you have already handled. Open any event and Session Replay steps through the full request timeline for that MCP session. Alerts arrive as HTML email stating whether the offending request ran or was blocked, with a one-click, nonce-protected link to disable MCP access. A 15-minute cooldown per rule and per session stops an alert storm. There is an optional daily digest, separate recipient lists for alerts and digests, and a test button so you can confirm delivery before you rely on it. A kill switch that keeps the record Turn off all MCP access from the admin screen, or let a detection rule trip it for you. Blocked requests are still logged before they are rejected, so the audit trail stays complete while access is off. Callers get a 503 explaining why access was disabled and when. A site-wide admin notice stays up until you turn it back on. Works with whichever MCP server you run MCP Logs is not an MCP server for your site and does not expose your content to agents. It detects requests by the Mcp-Session-Id header, which is part of the MCP transport spec, so traffic from any compliant server lands in the same table. If your site runs more than one, you get one log instead of several. Built for both halves of the audience If you run the site: install, activate, and open Tools then MCP Logs. There is no setup screen and no configuration. Logging starts the moment an MCP client makes a request. If you build on it: there is a full REST API covering every admin feature, authenticated via WordPress Application Passwords or WooCommerce API keys. The plugin is also MCP-aware itself, registering a server with ten abilities so an agent can introspect its own activity log. Source ships under src/ and builds with npm run build. Why log deletion is not exposed to AI agents The plugin registers ten MCP abilities. The two log-deletion abilities, clear-old-logs and clear-all-logs, are deliberately left out of that set. The same tool set reads log content that an untrusted caller can influence. Pairing that with a one-call wipe would let planted text steer an administrator’s agent into erasing the audit trail. Deletion stays available in the admin screen and over REST, where a human is doing it. Sites that accept the trade-off can re-add the abilities with the alfmcp_mcp_server_abilities filter. REST API Eighteen endpoints under /wp-json/activity-log-for-mcp/v1/: GET /requests for a list with filters, sort, and pagination GET /stats for totals, success rate, and calls per ability GET /sessions/{id} for every request in a session, in order GET /search for full-text search across routes, abilities, and bodies GET /errors for recent failed executions and HTTP errors GET /tool-performance for per-ability call count, error rate, and unique users GET /filters for distinct ability names and users GET /export-csv for a server-side streamed CSV download DELETE /requests to clear all logs DELETE /retention to delete logs older than a given date GET /security-events for detected events with filters and pagination GET /security-events/stats for alert counts, active sessions, and top rule over 7 days GET /security-events/export-csv for a CSV of detected events PUT /security-events/{id}/acknowledge to mark an event reviewed DELETE /security-events/clear-acknowledged to remove reviewed events GET|PUT /security-settings to read or update detection and alerting settings POST /security-settings/test-alert to send a test alert email MCP abilities The plugin registers an MCP server (activity-log-for-mcp-server) with ten abilities: get-activity for paginated log retrieval with filters get-stats for summary metrics with an optional date range get-activity-by-session for a full session trace, with optional body exclusion for lighter payloads search-activity for full-text search across stored requests and responses analyze-errors for recent errors with full details get-tool-performance for per-ability performance metrics get-security-events for detected events with filters get-security-stats for alert counts, active sessions, and top rule over 7 days acknowledge-event to mark a security event reviewed test-alert to send a test alert email Privacy and data handling Everything stays in your WordPress database. Logs live in {prefix}alfmcp_requests and detected events in {prefix}alfmcp_security_events. There is no telemetry, no third-party call, and no external dependency at runtime. Credential-bearing headers including Authorization, Cookie, and X-Api-Key are replaced with [redacted] before anything is written, so the log never becomes a store of replayable credentials. Add your own header names with the alfmcp_sensitive_headers filter. Request and response bodies are stored up to 64 KB each and truncated beyond that, adjustable with alfmcp_max_body_bytes. You control retention and can clear everything from the admin screen or over REST. Disclaimer MCP Logs is not affiliated with, endorsed by, or sponsored by any AI provider or the Model Context Protocol project. “MCP” and “Model Context Protocol” are referenced solely to describe the open protocol that this plugin observes. Privacy Policy MCP Logs records REST API requests that contain the Mcp-Session-Id header. Logged data includes request routes, methods, headers, bodies, response data, user IDs, and timestamps. Credential-bearing headers are redacted before storage. All data is stored in your WordPress database and is never transmitted to external services.
Top keywords
- mcp21×1.73%
- request13×1.07%
- abilities9×0.74%
- events8×0.66%
- logs8×0.66%
- requests8×0.66%
- log7×0.58%
- session7×0.58%
- admin6×0.49%
- filters6×0.49%
- rest6×0.49%
- server6×0.49%
Enable Abilities for MCP
Enable Abilities for MCP gives you full control over which WordPress Abilities are available to AI assistants through the MCP (Model Context Protocol) Adapter. WordPress 6.9 introduced the Abilities API, allowing external tools to discover and execute actions on your site. This plugin extends that functionality by registering a comprehensive set of content management abilities and providing a simple admin interface to toggle each one on or off. Connect from claude.ai with just a URL Since version 2.1 the plugin ships an embedded OAuth 2.1 server built for claude.ai custom connectors. Add your site in claude.ai → Settings → Connectors, log in with your WordPress user, approve the consent screen — connected. No Client ID, no Application Password, no local configuration. Works from the claude.ai web app, mobile apps, and Claude Desktop Each team member authenticates with their own WordPress account and role — a subscriber can never do what only an editor should Every ability execution lands in the activity log under the real user’s name Works on single sites, subdirectory installs, and multisite networks (network-activate so the main site serves the OAuth discovery documents for every subsite) Prefer tokens? Application Passwords (per-user) and a single-admin Bearer token connect Claude Desktop / Claude Code, OpenAI Codex CLI, and Google Antigravity — the Connection tab generates ready-to-paste configuration for each client, and fills in your credentials automatically. Features 102 abilities organized in 21 categories: Core, Read, Write, SEO (Rank Math), SEO (SEOPress), SEO (Yoast), Navigation Menus, Utility, Multilanguage, Custom Post Types, WooCommerce, The Events Calendar, Code Snippets, JetEngine Options Pages, JetEngine Query Builder, Elementor, LearnDash, Tutor LMS, AI Agent Readiness (llms.txt), FSE Block Templates, and Accessibility (WCAG) WooCommerce integration — dedicated abilities to manage products, orders, and customers using the native WooCommerce API (HPOS-compatible, formally declared) The Events Calendar integration — list, get, create, and update events with venue, organizer, and date filters claude.ai OAuth custom connector — connect from claude.ai (web, mobile, or desktop) with zero local setup: an embedded OAuth 2.1 server with Client ID Metadata Document (CIMD) support lets each user log in with their own WordPress account and role Admin dashboard with toggle switches for each ability Per-ability control — expose only what you need Third-party ability control — abilities registered by other MCP-ready plugins (e.g. Fluent Forms) appear in the same dashboard, grouped by plugin, with the same per-ability toggles; disabling one removes it from every MCP server on the site Secure by design — proper capability checks, input sanitization, and per-post permission validation WPCS compliant — fully passes WordPress Coding Standards (phpcs) MCP-ready — all abilities include show_in_rest and mcp.public metadata Available Abilities Read (safe, query-only): Get posts with filters (status, category, tag, search) Get single post details (content, SEO meta, featured image) Get categories, tags, pages, comments, media, and users Write (create & modify): Create, update, and delete posts Create categories and tags Create pages Moderate comments Reply to comments as the authenticated user Upload images from external URLs to the media library (with optional auto-assign as featured image) Duplicate any post, page, or custom post type item — including all post meta (ACF, SEO, featured image) and taxonomy terms; saved as a draft by default Assign a custom taxonomy’s terms to a post or page (e.g. a taxonomy registered by a companion plugin) SEO — Rank Math: Get full Rank Math metadata for any post/page (title, description, keywords, robots, Open Graph, SEO score) Update Rank Math metadata: SEO title, description, focus keyword, canonical URL, robots, Open Graph, primary category, pillar content SEO — SEOPress: Get full SEOPress metadata for any post/page (title, description, focus keyword, robots, canonical, Open Graph, Twitter Card) Update SEOPress metadata: SEO title, description, focus keyword, canonical URL, robots directives, Open Graph, Twitter Card SEO — Yoast SEO: Get full Yoast SEO metadata for any post/page (title, description, focus keyphrase, canonical, robots, Open Graph, Twitter Card) Update Yoast SEO metadata: SEO title, description, focus keyphrase, canonical URL, robots (noindex, nofollow, advanced), Open Graph, Twitter Card Get Yoast sitemap index — fetch and parse the sitemap index, returning all registered sitemap URLs with last modification date Custom Post Types: List all registered custom post types with configuration and taxonomies Get items from any CPT with filtering, search, and taxonomy queries Get full details of a CPT item including all meta fields (WooCommerce, ACF, JetEngine, etc.) Create, update, and delete CPT items with taxonomy and meta field support Get CPT taxonomies with their terms Assign taxonomy terms to CPT items Read term meta by exact key, or all meta for a term Write a term meta field by exact key Update a term’s core fields: name, slug, description, or parent WooCommerce: List products with price, SKU, stock status, categories, and type Get full product detail including gallery, attributes, and variations Update product price, sale price, stock quantity, and status List orders with customer, total, status, and date (HPOS-compatible) Get full order detail: line items, billing/shipping, totals, and notes Update order status with optional note List customers with email, name, total spent, and order count The Events Calendar: List events with start/end date, venue, organizer, and date range filter Get full event detail with resolved venue address and organizer contact Create new events with title, description, dates, venue, and organizer Update existing events Navigation Menus: List menus with item counts and theme locations, and get one menu’s full item hierarchy Create a new menu, and add pages, posts, categories, tags, or custom URLs as items (with parent and position) Update an item’s title, URL, parent, or position Remove an item, assign a menu to a theme location, or delete a menu entirely (opt-in — destructive) Tutor LMS: Read a lesson’s video source configuration (type, value, and runtime) Set a lesson’s video source (external URL, YouTube, Vimeo, HTML5, or a third-party source such as Bunny.net) using Tutor’s own storage function — avoids the string-only limitation of the generic Update Post Meta ability, which Tutor cannot read back List courses, and get a single course’s full detail with its topics/lessons hierarchy Get a user’s enrollment status and completion progress for a course Get a user’s quiz attempt results, optionally filtered to a single quiz Enroll a user in a course, and unenroll them (both opt-in, manage_options only) Multilanguage: Assign a language to an existing post via Polylang or WPML Link two posts as translations of each other in the same translation group Get the full translation map for a post: language, post ID, title, permalink, and status for each translation LearnDash: List courses with enrollment count, and get a single course’s full detail (lessons, topics, quizzes) Get a user’s enrollment status/progress and quiz results for a course Enroll or unenroll a user in a course (opt-in — write, manage_options) JetEngine Options Pages: List all registered Options Pages with their field schema Get all fields and current values for an Options Page by slug Update a single Options Page field, including repeater rows (opt-in — write) JetEngine Query Builder: List all Query Builder queries with id, name, and query type Get the full settings of one query by id Update an existing query’s name, type, or arguments — the missing counterpart to JetEngine’s own native “Add Query” MCP tool, which has no edit/get/list equivalent (opt-in — write) Elementor: Get a compact, read-only tree of an Elementor page/template (element ids, types, text preview) Update an Elementor element’s settings by id — single or batch edits (opt-in — write) Bind a widget setting to a dynamic tag: post title, or a JetEngine/meta field (opt-in — write) Code Snippets: Create a PHP code snippet via the Code Snippets plugin — always saved as inactive, activate manually from wp-admin. Validates PHP syntax and blocks dangerous functions (eval, exec, shell_exec, and more) AI Agent Readiness (llms.txt): Fetch and validate the site’s llms.txt against the llmstxt.org spec, with actionable issues Write llms.txt content — routes automatically to SEOPress Pro’s option when active, or serves it directly (opt-in — write) FSE Block Templates: List all wp_template and wp_template_part entries for the active theme, merging theme-file defaults with database overrides Get the full block markup for one template or template part by slug Write new block markup to a template or template part — creates a database override automatically when the target is still a theme default; rejects content with unbalanced block-comment delimiters (opt-in — write, edit_theme_options) Accessibility (WCAG): Scan the media library for images missing alt text (WCAG 1.1.1 Non-text Content), paginated Utility: Search and replace text in post content Site statistics overview (includes custom post type counts) Update any post meta field by exact key (with protected internal key blocklist) Requirements WordPress 6.9 or later (Abilities API) MCP Adapter plugin installed and configured PHP 8.0 or later