AI Chatbot & Support Agent
You already know the old kind. A visitor asks a real question, the bot replies with a link to your FAQ page, and the visitor leaves. This is the other kind. Ultimo Bots puts a real AI support agent on your WordPress site. It answers from your own content, and then it does the actual work: books the meeting, looks up the order, saves the lead, and pulls you into the conversation when it matters. You describe it. It builds itself. There is no canvas to drag boxes around on. You open the builder and type what should happen, in your own words: “When someone asks about pricing, explain the plans and offer a demo call. If they want one, book it in my Cal.com and send the lead to HubSpot.” That is the entire build step. The agent is configured from that sentence. No code, no flowcharts, no developer, no agency. Changed your mind? Tell it. That is the edit step too. It doesn’t just answer. It acts. Connect the tools you already run, and the agent uses them mid-conversation: Books appointments in Cal.com, including reschedule and cancel, or hands over your Calendly link Takes payments and manages subscriptions through Stripe links. It can list, change, or cancel a subscription. Card details never enter the chat Saves and finds contacts in HubSpot, and subscribes visitors to Mailchimp with proper double opt-in Answers from your product catalog, with prices and stock, so “do you have this in blue” gets a real answer Calls your own API with your own credentials when you need something nobody else offers Captures leads inside the conversation and emails them to you the second they land Before the agent touches anything private, it emails the visitor a six-digit code and waits for it. Verified first, every time. One agent. Every channel. The same agent runs on your WordPress site, on a shareable chat link, in Facebook Messenger, Instagram DMs, Telegram, and Slack. You train it once and it shows up everywhere. Nothing to duplicate, nothing to keep in sync. It knows your business, and it will not invent Point it at your WordPress site and it reads it. Add PDFs, Word files, spreadsheets, Google Drive, OneDrive, Notion. Every answer is built from your material, and one click re-scans your site whenever it changes. When it does not know something, it says so and offers you instead. That one habit is why people trust it on a live site. It detects the language your visitor is writing in and answers in it. You configure nothing. You stay in control Write your rules in plain words and the agent holds them, even when a visitor pushes back. Watch conversations as they happen and jump in yourself with one click. The agent goes quiet the moment you start typing and picks up again when you leave. Get pinged in Slack, Telegram, Teams, or email whenever someone wants a human. Everything is included Every capability above is on every plan. Plans differ in volume, not in what your agent can do. No per-seat pricing, no per-resolution fees, no “contact sales”. Start with a free trial, then from $19 a month. Live in about two minutes Activate the plugin, answer a few questions, and your agent is on your site. That is the whole setup. External services This plugin connects to external services operated by Ultimo Bots to function. The integration is required to register your site securely and render your AI assistant. Below are the services, what they are used for, and what data is transmitted. Policies for all of them: Terms of Service: https://www.ultimo-bots.com/terms – Privacy Policy: https://www.ultimo-bots.com/privacy 1) Ultimo Bots Portal API – site registration What: https://portal.ultimo-bots.com/api/auth/wordpress/save_secret When: On plugin activation (and retried if the first attempt failed). Purpose: Register your WordPress site and exchange a site-specific identifier used for secure operations. Data sent: site_id (random UUID generated in your WordPress site), site_url (your WordPress home URL), site_secret (random secret generated in your WordPress site), and the admin user’s email, first_name, last_name (used only to prefill the onboarding form; transferred server-side, never placed in a URL). Data received: wordpress_secret_id (an internal identifier) and a one-time connect code (valid 15 minutes, single use). 2) Ultimo Bots Portal API – connect code What: https://portal.ultimo-bots.com/api/auth/wordpress/connect_code When: When you click “Connect to Ultimo Bots” in the plugin settings, and right before the one-time onboarding redirect. Purpose: Mint a fresh one-time connect code so the onboarding can be opened without any personal data in the URL. Data sent: site_id, site_secret, and the admin user’s email, first_name, last_name (prefill, server-side only). Data received: a one-time connect code. 3) Ultimo Bots Portal API – assistant lookup What: https://portal.ultimo-bots.com/api/wordpress/my_bot When: On WP-Admin page loads (throttled to once per 5 minutes), on the plugin settings page, and once daily via WP-Cron. Purpose: Fetch the ID of the assistant connected to this site, so the assistant activates automatically after onboarding. Data sent: site_id, site_secret. Data received: bot_id and its creation status. 4) Ultimo Bots Widget Configuration API What: https://portal.ultimo-bots.com/api/widget_configuration/{bot_id} When: On public page views where the assistant is displayed, and on activation to check whether an existing Bot ID is active. Purpose: Retrieve the widget configuration for your Bot ID (colors, sizes, welcome messages). Data sent: bot_id (path parameter); optionally host_url when provided by the widget for basic operational analytics. Data received: widget configuration JSON. 5) Ultimo Bots Widget Script Host – static asset What: https://robert-kloepsch.github.io/ultimo-bots-widget/dist/bundle.js When: On public page views where the assistant is displayed. Purpose: Load the widget client code. Data sent: standard CDN/HTTP request metadata (IP, user agent) as with any static asset request. Important: This plugin does not accept or store arbitrary HTML/JS/CSS from users. It only stores a Bot ID and generates safe markup internally. The widget script is properly enqueued via WordPress functions. Privacy This plugin communicates with Ultimo Bots services as described in External services. Please review: – Terms of Service: https://www.ultimo-bots.com/terms – Privacy Policy: https://www.ultimo-bots.com/privacy
Top keywords
- site19×1.78%
- wordpress12×1.12%
- agent11×1.03%
- data11×1.03%
- id11×1.03%
- com10×0.94%
- api9×0.84%
- bots9×0.84%
- https9×0.84%
- ultimo9×0.84%
- ultimo bots9×0.84%
- bot8×0.75%
WEBO MCP
WEBO MCP is a WordPress MCP server — a complete Model Context Protocol gateway for WordPress. It lets AI agents and MCP-compatible clients (Claude Desktop, Cursor, Windsurf, n8n, and more) call well-defined tools over REST using JSON-RPC, instead of scraping the admin or sharing broad credentials. Official WEBO MCP website, documentation, and ecosystem hub: https://webomcp.com Why use WEBO MCP as your WordPress MCP server? Token-optimized unified tools: every domain exposes two abilities — *-query (all reads) and *-mutate (all writes) — with a single action discriminator. tools/list payload is up to 70% smaller than per-operation APIs, which means less of the model’s context window is consumed by tool schemas, lower cost per session, and fewer hallucinated tool names. Primary router endpoint: POST /wp-json/mcp/v1/router Standard MCP-style flow: initialize → tools/list → tools/call Session lifecycle for clients (pass session_id or Mcp-Session-Id after initialize) Built-in tool registry for common WordPress operations (posts, media, terms, menus, options, and more) Bundled Abilities API + MCP Adapter integration, with automatic bridging from registered abilities to MCP tools (configurable) WordPress 7.0/Core-aware bridge mode that uses Core Abilities/API surfaces when available and falls back only when needed Public tool policy controls (category filters and optional allowlists) plus optional internal tool exposure for private environments Bounded MCP audit log, optional per-user/role/client tool allowlists, and a read-only administrator health/status tool Security model (high level) MCP access requires a real WordPress user context: Application Password over HTTP Basic, or an existing logged-in session. Optional site-wide or per-user API key and HMAC can be enabled in Settings as an additional gate (they do not replace WordPress authentication). Generate/rotate from Settings → Security; by default they are skipped for Application Password and Bearer clients unless you enable “Require for App Password / Bearer”. Do not put the normal WEBO API key in URLs. For clients that cannot send headers, create a short-lived scoped mcp_token URL connector token in Settings -> WEBO MCP. Default access expectations for the router and GET /wp-json/webo-mcp/v1/tools: users who are super admins, can manage_options, or can edit_posts, consistent with typical site operator and editor workflows (filterable). Client guidance Always discover tools before calling them: run tools/list, pick an exact tool name from the response, validate required arguments, then call tools/call. This reduces mistakes and keeps automation predictable in production. Further documentation and optional integrations Official website, documentation, and ecosystem notes: https://webomcp.com Optional n8n community node (separate package): https://www.npmjs.com/package/n8n-nodes-webo-mcp Release notes and migration map: see docs/RELEASE_NOTES_2.1.0.md and docs/MIGRATION_GUIDE_2.1.0.md in the GitHub repository Cross-addon dispatcher map (granular legacy names removed from discovery): docs/MCP_TOOL_MIGRATION.md Compatibility note: any MCP-capable client can be used; which large language model runs inside the client is outside this plugin. Standalone core tools included: – Site info – Content (posts/pages): webo/content-query (list, get, find-by-url, search-replace, list-revisions, get-revision; with author/date/taxonomy filters) and webo/content-mutate (create, update, delete, bulk-update-status, restore-revision, change-author) – Users: webo/list-users and webo/user-mutate (add-to-blog, set-role) – Media: webo/media-query (list with search/MIME/post_id filters, get) and webo/media-mutate (upload, update, delete) – Comments: webo/comment-query (list, get) and webo/comment-mutate (create, update, delete) – Taxonomy/Terms: webo/taxonomy-query (discover, list, get) and webo/taxonomy-mutate (create, update, delete) – Nav menus: list menus, list menu items (menu_order, db_id), add menu link from post (explicit post_id + menu_order required) – Plugins: webo/plugin-query (installed, active, updates, …) and webo/plugin-mutate (install, activate, deactivate; supports child-site site_id / blog_id activation for network admins) – Health: webo/health-status (REST/router status, Application Password support, permalinks, cron, object cache, plugin update summary, WordPress/PHP versions, and redacted MCP config) – Client health: webo/client-health-report (score 0–100, grade A–D, Markdown scoreboard for agency clients; hybrid foundation for Pro collectors later) – 404 logs: webo/get-404-logs (read-only Rank Math / Redirection 404 monitor: url, hits, accessed, referrer) – Abilities bridge: webo/ability-query and webo/ability-execute in default layered mode. Only abilities with meta.mcp.public === true are visible and executable through WEBO MCP. – Themes: webo/theme-query (installed themes) and webo/theme-mutate (install from WordPress.org by slug, switch installed theme) – Theme context: webo/theme-context (active theme info, block editor settings, style presets, registered blocks) – Block patterns: webo/block-patterns (list/get patterns, list/get synced patterns) – Site stats: webo/site-stats (overview, post counts, comment counts, user counts, media stats, activity summary) – Activity log: webo/activity-log (list events, summary, clear) – User profile: webo/user-profile (get own profile, update display name / bio / preferences) – Site settings: webo/site-settings (get and update the 20 most common WordPress options via MCP) – Content search: webo/content-search (full-text cross-post-type search with grouped results) – Menus: webo/menu-query, webo/menu-mutate (navigation menu items; not post/CPT list order) – Post/CPT order (optional): webo/reorder-query, webo/reorder-mutate when Webo Reorder is active — see docs/abilities/reorder.md – Options: get/update (safe allowlist only), set site icon/favicon from media – SEO (WordPress post): seo/article-analysis — requires post_id; merges Rank Math meta when available (same data path as webo-rank-math/get-post-seo-meta); optional related-keyword suggestions via outbound request unless no_autocomplete is true Excluded by default in standalone-safe mode: – Bulk/mass execution tools – Plugin/theme write-management abilities – Multisite-specific abilities Privacy This plugin does not phone home or send telemetry. MCP traffic is initiated by clients you configure. Some tools may perform outbound HTTP requests only when a client invokes them (for example seo/article-analysis may request keyword suggestions from a third-party suggest API unless you pass no_autocomplete). The plugin stores the following options in the WordPress database when configured: – webo_mcp_api_key: API key used to authenticate MCP requests. – webo_mcp_hmac_secret: HMAC secret used to sign and validate MCP requests. – webo_mcp_require_secondary_credentials: when enabled, also require API key/HMAC for Application Password and Bearer clients (off by default so standard connectors are not blocked). – webo_mcp_url_connector_tokens: hashed, expirable, revocable URL connector tokens for clients that cannot send headers. Raw tokens are shown once and are not stored. – webo_mcp_tool_allowlist_enabled and webo_mcp_tool_allowlist_rules: optional administrator-configured MCP tool allowlist policy. – webo_mcp_audit_log_enabled, webo_mcp_audit_log_max_entries, and webo_mcp_audit_log: bounded MCP tool-call audit log settings and compact audit events. Audit entries include user/tool/action/status data, anonymized IPs, and hashed session IDs; they do not store request payloads, API keys, HMAC secrets, or Application Passwords. – webo_mcp_installed_at and webo_mcp_review_notice: local timestamps/state for an optional WordPress.org review request notice (not sent off-site; dismissible). These options are removed when the plugin is uninstalled via the WordPress Plugins screen. External services This plugin can connect to Google Suggest (Autocomplete) when a client calls the seo/article-analysis tool and does not set no_autocomplete to true. This external request is used to return related keyword suggestions for SEO analysis. Service provider: Google LLC (Google Suggest / Autocomplete API endpoint). Data sent and when: – Sent only when seo/article-analysis is called with autocomplete enabled. – Sends the analysis query text to https://suggestqueries.google.com/complete/search as the q parameter. – Sends standard HTTP request metadata such as IP address and User-Agent as part of the web request. Terms of Service: https://policies.google.com/terms Privacy Policy: https://policies.google.com/privacy Developer Hooks The plugin exposes the following actions and filters for developers: Actions webo_mcp_register_tools Fired during plugin bootstrap after standalone tools are registered. Use this to register custom MCP tools from other plugins. Filters webo_mcp_current_user_can_use_mcp (bool $allowed, int $user_id) Gate for all MCP REST access. Default: super admin OR manage_options OR edit_posts. Override to tighten (e.g. super-admin only) in hardened installs. webo_mcp_secondary_credentials_exempt (bool $exempt, WP_REST_Request $request) When true, skip optional API key / HMAC after WordPress auth. Default true for Application Password (Basic) and Bearer sessions unless Settings → Security → “Require for App Password / Bearer” is enabled. Return false to always enforce X-WEBO-* headers. webo_mcp_allow_internal_tools (bool $allow_internal, WP_REST_Request $request) Controls whether internal tools are included in tools/list responses. Defaults to false for public environments. webo_mcp_public_categories (array $categories, WP_REST_Request $request, array $tool) Filters which tool categories are exposed as public. Defaults to array( ‘wordpress’ ). webo_mcp_rate_limit_per_hour (int $limit, string $client, array|null $profile) Adjust effective hourly limit (fallback for both buckets). webo_mcp_rate_limit_read_per_hour / webo_mcp_rate_limit_mutate_per_hour (int $limit, string $client, array|null $profile) Per-bucket limits after admin/profile resolution. webo_mcp_tool_is_mutating (bool $is_mutating, string $tool_name, array|null $tool_definition, array $arguments) Override mutating classification for rate limits and read-only profiles. webo_mcp_tool_arguments_allow_extra (bool $allow, string $tool_name, array $schema, array $arguments) When true, unknown tool argument keys are passed through (default false). webo_mcp_disallow_url_token_query (bool $disallowed) Block URL connector tokens in query strings (admin setting is the default source). webo_mcp_rest_bom_guard_json_api_requests (bool $activate, string $uri_raw) Opt-in BOM sanitizer for all /wp-json/ responses (default false; MCP routes only). webo_mcp_bridge_deny_patterns (array $patterns) Controls which abilities are excluded when auto-bridging abilities into MCP tools (e.g. bulk, themes/, multisite/). webo_mcp_auto_bridge_abilities (bool $enabled) Enables or disables automatic bridging of registered abilities into MCP tools. Defaults to true; bridge mode still controls whether the bridge is off, layered, or full. webo_mcp_bridge_mode (string $mode) Controls Abilities bridge mode after the WEBO_MCP_BRIDGE_MODE constant and before the stored option. Values: off, layered, full. Default: layered. webo_mcp_enable_adapter (bool $enabled) Enables or disables the bundled WordPress MCP Adapter runtime. Defaults to true. webo_mcp_validate_media_fetch_url (true|\WP_Error $ok, string $url, array $parsed) Reject unsafe URLs for webo/media-mutate upload action (return WP_Error to block). webo_mcp_tool_allowlist_allowed (bool $allowed, string $tool_name, WP_REST_Request $request, array $params, array $allowed_tools) Filters the optional per-user/role/client allowlist decision. Credits Special thanks to the authors and open source projects that contributed to this plugin: – WordPress (https://wordpress.org) – Abilities API (https://github.com/WordPress/abilities-api) Reference: https://make.wordpress.org/ai/2025/07/17/abilities-api/ – MCP Adapter (https://github.com/WordPress/mcp-adapter) Reference: https://make.wordpress.org/ai/2025/07/17/mcp-adapter/ – Composer (https://getcomposer.org) – Other PHP and JS libraries from the community If you use this plugin, please give credit to the authors of these libraries. License This plugin is licensed under the GPLv2 or later. See https://www.gnu.org/licenses/gpl-2.0.html for details.