Enable Abilities for MCP
Enable Abilities for MCP gives you full control over which WordPress Abilities are available to AI assistants through the MCP (Model Context Protocol) Adapter. WordPress 6.9 introduced the Abilities API, allowing external tools to discover and execute actions on your site. This plugin extends that functionality by registering a comprehensive set of content management abilities and providing a simple admin interface to toggle each one on or off. Connect from claude.ai with just a URL Since version 2.1 the plugin ships an embedded OAuth 2.1 server built for claude.ai custom connectors. Add your site in claude.ai → Settings → Connectors, log in with your WordPress user, approve the consent screen — connected. No Client ID, no Application Password, no local configuration. Works from the claude.ai web app, mobile apps, and Claude Desktop Each team member authenticates with their own WordPress account and role — a subscriber can never do what only an editor should Every ability execution lands in the activity log under the real user’s name Works on single sites, subdirectory installs, and multisite networks (network-activate so the main site serves the OAuth discovery documents for every subsite) Prefer tokens? Application Passwords (per-user) and a single-admin Bearer token connect Claude Desktop / Claude Code, OpenAI Codex CLI, and Google Antigravity — the Connection tab generates ready-to-paste configuration for each client, and fills in your credentials automatically. Features 91 abilities organized in 18 categories: Core, Read, Write, SEO (Rank Math), SEO (SEOPress), SEO (Yoast), Navigation Menus, Utility, Multilanguage, Custom Post Types, WooCommerce, The Events Calendar, Code Snippets, JetEngine Options Pages, Elementor, LearnDash, Tutor LMS, and AI Agent Readiness (llms.txt) WooCommerce integration — dedicated abilities to manage products, orders, and customers using the native WooCommerce API (HPOS-compatible, formally declared) The Events Calendar integration — list, get, create, and update events with venue, organizer, and date filters claude.ai OAuth custom connector — connect from claude.ai (web, mobile, or desktop) with zero local setup: an embedded OAuth 2.1 server with Client ID Metadata Document (CIMD) support lets each user log in with their own WordPress account and role Admin dashboard with toggle switches for each ability Per-ability control — expose only what you need Third-party ability control — abilities registered by other MCP-ready plugins (e.g. Fluent Forms) appear in the same dashboard, grouped by plugin, with the same per-ability toggles; disabling one removes it from every MCP server on the site Secure by design — proper capability checks, input sanitization, and per-post permission validation WPCS compliant — fully passes WordPress Coding Standards (phpcs) MCP-ready — all abilities include show_in_rest and mcp.public metadata Available Abilities Read (safe, query-only): Get posts with filters (status, category, tag, search) Get single post details (content, SEO meta, featured image) Get categories, tags, pages, comments, media, and users Write (create & modify): Create, update, and delete posts Create categories and tags Create pages Moderate comments Reply to comments as the authenticated user Upload images from external URLs to the media library (with optional auto-assign as featured image) Duplicate any post, page, or custom post type item — including all post meta (ACF, SEO, featured image) and taxonomy terms; saved as a draft by default SEO — Rank Math: Get full Rank Math metadata for any post/page (title, description, keywords, robots, Open Graph, SEO score) Update Rank Math metadata: SEO title, description, focus keyword, canonical URL, robots, Open Graph, primary category, pillar content SEO — SEOPress: Get full SEOPress metadata for any post/page (title, description, focus keyword, robots, canonical, Open Graph, Twitter Card) Update SEOPress metadata: SEO title, description, focus keyword, canonical URL, robots directives, Open Graph, Twitter Card SEO — Yoast SEO: Get full Yoast SEO metadata for any post/page (title, description, focus keyphrase, canonical, robots, Open Graph, Twitter Card) Update Yoast SEO metadata: SEO title, description, focus keyphrase, canonical URL, robots (noindex, nofollow, advanced), Open Graph, Twitter Card Get Yoast sitemap index — fetch and parse the sitemap index, returning all registered sitemap URLs with last modification date Custom Post Types: List all registered custom post types with configuration and taxonomies Get items from any CPT with filtering, search, and taxonomy queries Get full details of a CPT item including all meta fields (WooCommerce, ACF, JetEngine, etc.) Create, update, and delete CPT items with taxonomy and meta field support Get CPT taxonomies with their terms Assign taxonomy terms to CPT items WooCommerce: List products with price, SKU, stock status, categories, and type Get full product detail including gallery, attributes, and variations Update product price, sale price, stock quantity, and status List orders with customer, total, status, and date (HPOS-compatible) Get full order detail: line items, billing/shipping, totals, and notes Update order status with optional note List customers with email, name, total spent, and order count The Events Calendar: List events with start/end date, venue, organizer, and date range filter Get full event detail with resolved venue address and organizer contact Create new events with title, description, dates, venue, and organizer Update existing events Navigation Menus: List menus with item counts and theme locations, and get one menu’s full item hierarchy Create a new menu, and add pages, posts, categories, tags, or custom URLs as items (with parent and position) Update an item’s title, URL, parent, or position Remove an item, assign a menu to a theme location, or delete a menu entirely (opt-in — destructive) Tutor LMS: Read a lesson’s video source configuration (type, value, and runtime) Set a lesson’s video source (external URL, YouTube, Vimeo, HTML5, or a third-party source such as Bunny.net) using Tutor’s own storage function — avoids the string-only limitation of the generic Update Post Meta ability, which Tutor cannot read back List courses, and get a single course’s full detail with its topics/lessons hierarchy Get a user’s enrollment status and completion progress for a course Get a user’s quiz attempt results, optionally filtered to a single quiz Enroll a user in a course, and unenroll them (both opt-in, manage_options only) Utility: Search and replace text in post content Site statistics overview (includes custom post type counts) Update any post meta field by exact key (with protected internal key blocklist) Requirements WordPress 6.9 or later (Abilities API) MCP Adapter plugin installed and configured PHP 8.0 or later
Top keywords
- seo15×1.44%
- post14×1.34%
- update12×1.15%
- abilities10×0.96%
- full10×0.96%
- claude9×0.86%
- ai8×0.77%
- custom8×0.77%
- list8×0.77%
- metadata8×0.77%
- title8×0.77%
- description7×0.67%
SiteSkite MCP AI – Connector for Claude, ChatGPT, Cursor & WordPress WebOps
SiteSkite is a WebOps for WordPress built for agencies, developers, and site owners who manage one site or many. Connect your sites for backups, updates, monitoring, sandboxes, and team workflows — and, with SiteSkite AI, edit a live WordPress site using assistants like Claude, ChatGPT, and Cursor. Live on-site edits with WordPress AI do not use SiteSkite AI Site Studio credits. Whether you manage 1 site or 100+, SiteSkite simplifies WordPress maintenance and scales with your workflow. Important: SiteSkite only manages your website after you connect it with a secure API key. Plugin installs, activations, and maintenance actions are initiated from your SiteSkite account so you stay in control. What SiteSkite Helps You Do ✔️ Manage multiple WordPress sites from one dashboard ✔️ Automate backups and restore anytime ✔️ Edit live sites with AI (Claude, ChatGPT, Cursor) via SiteSkite MCP ✔️ Choose Off, WordPress AI, or Platform AI per linked site ✔️ Create pages, menus, forms, and page-builder layouts with WordPress AI ✔️ Privacy-minded SiteSkite AI Chat for portal workflows ✔️ Advanced Site Recovery: keep working even after many fatal errors ✔️ Snapshot and incremental backups ✔️ Create blueprints for rapid deployment ✔️ Launch sandbox sites ✔️ Spin up new sites from existing backups (on SiteSkite servers) ✔️ Store backups in your own cloud (bring your own storage) ✔️ Vulnerability detection guard ✔️ Monitor uptime and site health across all sites ✔️ Bulk update, activate, deactivate, and delete plugins/themes ✔️ Roll back plugin and theme versions safely ✔️ Add team members and organize sites into workspaces ✔️ WP Canvas tools (maintenance mode, debug, search & replace, indexing, WP Reset, and more) ✔️ Manage WP admin users and roles ✔️ Track Core Web Vitals performance ✔️ Install curated plugin presets with WP Essentials ✔️ White-label the plugin for agency clients ✔️ Automated reports for your customers ✔️ Clear views for error, debug, and custom logs ✔️ and much more… Built to simplify workflows and scale your WordPress operations without stress. Get started in minutes. SiteSkite AI & MCP (new in 2.1.0) Connect once at https://mcp.siteskite.com, sign in with your SiteSkite account, and use Quick Connect for Claude or ChatGPT (Cursor and other clients supported too). This gives your assistant the whole platform — every connected site, plus backups, sandboxes, and logs. No account? SiteSkite MCP is free to use without one. Open SiteSkite → AI MCP → Connect in wp-admin and connect Claude, ChatGPT, or Cursor straight to this one site. No sign-up, no API key, nothing metered. You approve each app in your own WordPress admin and can cut it off there at any time. Sign in later and the same connector gains the platform tools and the rest of your sites. Per site, pick how AI works: – Off — AI will not change that site – WordPress AI — edit the live website (pages, menus, forms, Gutenberg, Elementor, WPBakery, and more) – Platform AI — SiteSkite portal tools (backups, sandboxes, AI Site Studio, and more) Only one mode can be active at a time. With WordPress AI you can: – Create, edit, and publish pages – Install and toggle plugins – Edit with the WordPress block editor (keep the Block Editor Queue page open while the assistant works) – Build Elementor and WPBakery layouts – Manage menus and add images from a URL – List forms and create Contact Form 7 forms You stay in control: – Turn individual AI actions on or off in Abilities – Switch Advanced Power Tools off if you would rather withhold deeper server-side actions (PHP, WP-CLI, files) – Add site notes in Context so the AI follows your preferences – Use Skills (ready-made playbooks) for Gutenberg, Elementor, WPBakery, and more Key Features Backups, Restore, Site Migrate/Clone Stay in control of your site backups: – On-demand, daily, or weekly backups – Full, database-only, or file-only backups – Incremental backups (resource-efficient) – Classic snapshot backups (full archive) – Restore with a click – Migrate or clone a site from Server A to Server B BYO Cloud Storage Use your own cloud storage, including: – Google Drive – Dropbox – AWS S3 – Backblaze B2 – pCloud Bring your own AI model Use your preferred AI where the platform supports it: – ChatGPT – Claude – Other supported models Connect Claude, ChatGPT & Cursor (MCP) One SiteSkite connection for everyday use Quick Connect for Claude and ChatGPT WordPress AI for live site edits; Platform AI for portal tools No per-site config files required for normal users Free to use, and works without a SiteSkite account if you only want the AI connector Bulk WordPress Actions Update plugins, themes, and core Activate, deactivate, or delete plugins and themes Rollback plugin and theme versions Install bulk plugins from presets Built-in Native Features Maintenance Mode WP Debug Search & Replace Permalink settings WP Reset Site indexing toggle Performance & Monitoring Uptime monitoring BirdEye status overview Core Web Vitals metrics Collaboration & Scaling Workspaces to group sites and clients Add users, team members, and clients White-label plugin branding Marketplace Browse tools, presets, and digital assets Wishlist and follow sellers 1GB free space Enjoy free cloud storage for your site backups Learn More Website: SiteSkite.com Documentation: Knowledgebase Who is SiteSkite for? WordPress website owners Agencies managing client sites Freelancers and developers Hosting providers offering WP upkeep Anyone who wants peace of mind and automation External services This plugin connects to external services to perform backups, restores, and operational callbacks. Below is a list of services, what they are used for, what data is sent, and relevant policies. Dropbox What it’s used for: Uploading and downloading backup archives to the site owner’s Dropbox. What data is sent and when: Backup file contents and related metadata (e.g., file name and size) during backup and restore operations initiated by the administrator. Endpoints: https://content.dropboxapi.com, https://api.dropboxapi.com Policies: Terms https://www.dropbox.com/terms · Privacy https://www.dropbox.com/privacy Google Drive What it’s used for: Uploading and downloading backup archives to the site owner’s Google Drive. What data is sent and when: Backup file contents and related metadata during backup and restore operations initiated by the administrator. Endpoints: https://www.googleapis.com/drive/v3/files and related upload endpoints such as https://www.googleapis.com/upload/drive/v3/files (resumable/multipart uploads). Policies: Terms https://policies.google.com/terms · Privacy https://policies.google.com/privacy Amazon S3 What it’s used for: Uploading and downloading backup archives to the site owner’s Amazon S3 bucket. What data is sent and when: Backup file contents and related metadata during backup and restore operations initiated by the administrator. Endpoints: Region-specific S3 REST API (e.g., https://s3. .amazonaws.com). Policies: Service Terms https://aws.amazon.com/service-terms/ · Privacy https://aws.amazon.com/privacy/ Backblaze B2 What it’s used for: Uploading and downloading backup archives to the site owner’s Backblaze B2 bucket. What data is sent and when: Backup file contents and related metadata during backup and restore operations initiated by the administrator. Endpoints: Backblaze B2 API (e.g., https://api.backblazeb2.com). Policies: Terms https://www.backblaze.com/company/legal/terms.html · Privacy https://www.backblaze.com/company/privacy.html pCloud What it’s used for: Uploading and downloading backup archives to the site owner’s pCloud storage. What data is sent and when: Backup file contents and related metadata during backup and restore operations initiated by the administrator. Endpoints: pCloud API (e.g., https://api.pcloud.com) and regional variants such as https://eapi.pcloud.com (EU) and https://asiaapi.pcloud.com (Asia). OAuth token exchange: https://my.pcloud.com/oauth2_token. Policies: Terms https://www.pcloud.com/terms.html · Privacy https://www.pcloud.com/privacy-policy.html SiteSkite endpoints (operational callbacks and validation) What it’s used for: Validating the plugin API key, linking a site, downloading managed assets, and sending operational status callbacks to SiteSkite services. Some staging endpoints may be used for validation or asset download during testing. When AI / MCP features are used, the SiteSkite platform may coordinate ability requests to this linked site using your Connect API key. What data is sent and when: Site identifier and operation status metadata (e.g., backup/restore status) during validation and callbacks. For asset downloads, only the requested asset path is transmitted. Backup contents are never sent to SiteSkite; only selected metadata required to coordinate operations. Policies: Terms https://www.siteskite.com/terms-of-service · Privacy https://www.siteskite.com/privacy-policy WordPress.org (downloads) What it’s used for: Downloading official WordPress core translation files when requested by an administrator. What data is sent and when: The request URL includes the WordPress core version and language code to retrieve the matching translation archive; no personal data is sent. Endpoints: https://downloads.wordpress.org/translation/core/ / .zip Policies: Terms https://wordpress.org/about/privacy/ · Privacy https://wordpress.org/about/privacy/ Notes: – Data is transmitted only when you initiate an action that requires it (e.g., starting a backup/restore, validating your API key, or downloading translations). – You choose and configure the cloud storage provider(s) to be used.