AI Chatbot & Support Agent
You already know the old kind. A visitor asks a real question, the bot replies with a link to your FAQ page, and the visitor leaves. This is the other kind. Ultimo Bots puts a real AI support agent on your WordPress site. It answers from your own content, and then it does the actual work: books the meeting, looks up the order, saves the lead, and pulls you into the conversation when it matters. You describe it. It builds itself. There is no canvas to drag boxes around on. You open the builder and type what should happen, in your own words: “When someone asks about pricing, explain the plans and offer a demo call. If they want one, book it in my Cal.com and send the lead to HubSpot.” That is the entire build step. The agent is configured from that sentence. No code, no flowcharts, no developer, no agency. Changed your mind? Tell it. That is the edit step too. It doesn’t just answer. It acts. Connect the tools you already run, and the agent uses them mid-conversation: Books appointments in Cal.com, including reschedule and cancel, or hands over your Calendly link Takes payments and manages subscriptions through Stripe links. It can list, change, or cancel a subscription. Card details never enter the chat Saves and finds contacts in HubSpot, and subscribes visitors to Mailchimp with proper double opt-in Answers from your product catalog, with prices and stock, so “do you have this in blue” gets a real answer Calls your own API with your own credentials when you need something nobody else offers Captures leads inside the conversation and emails them to you the second they land Before the agent touches anything private, it emails the visitor a six-digit code and waits for it. Verified first, every time. One agent. Every channel. The same agent runs on your WordPress site, on a shareable chat link, in Facebook Messenger, Instagram DMs, Telegram, and Slack. You train it once and it shows up everywhere. Nothing to duplicate, nothing to keep in sync. It knows your business, and it will not invent Point it at your WordPress site and it reads it. Add PDFs, Word files, spreadsheets, Google Drive, OneDrive, Notion. Every answer is built from your material, and one click re-scans your site whenever it changes. When it does not know something, it says so and offers you instead. That one habit is why people trust it on a live site. It detects the language your visitor is writing in and answers in it. You configure nothing. You stay in control Write your rules in plain words and the agent holds them, even when a visitor pushes back. Watch conversations as they happen and jump in yourself with one click. The agent goes quiet the moment you start typing and picks up again when you leave. Get pinged in Slack, Telegram, Teams, or email whenever someone wants a human. Everything is included Every capability above is on every plan. Plans differ in volume, not in what your agent can do. No per-seat pricing, no per-resolution fees, no “contact sales”. Start with a free trial, then from $19 a month. Live in about two minutes Activate the plugin, answer a few questions, and your agent is on your site. That is the whole setup. External services This plugin connects to external services operated by Ultimo Bots to function. The integration is required to register your site securely and render your AI assistant. Below are the services, what they are used for, and what data is transmitted. Policies for all of them: Terms of Service: https://www.ultimo-bots.com/terms – Privacy Policy: https://www.ultimo-bots.com/privacy 1) Ultimo Bots Portal API – site registration What: https://portal.ultimo-bots.com/api/auth/wordpress/save_secret When: On plugin activation (and retried if the first attempt failed). Purpose: Register your WordPress site and exchange a site-specific identifier used for secure operations. Data sent: site_id (random UUID generated in your WordPress site), site_url (your WordPress home URL), site_secret (random secret generated in your WordPress site), and the admin user’s email, first_name, last_name (used only to prefill the onboarding form; transferred server-side, never placed in a URL). Data received: wordpress_secret_id (an internal identifier) and a one-time connect code (valid 15 minutes, single use). 2) Ultimo Bots Portal API – connect code What: https://portal.ultimo-bots.com/api/auth/wordpress/connect_code When: When you click “Connect to Ultimo Bots” in the plugin settings, and right before the one-time onboarding redirect. Purpose: Mint a fresh one-time connect code so the onboarding can be opened without any personal data in the URL. Data sent: site_id, site_secret, and the admin user’s email, first_name, last_name (prefill, server-side only). Data received: a one-time connect code. 3) Ultimo Bots Portal API – assistant lookup What: https://portal.ultimo-bots.com/api/wordpress/my_bot When: On WP-Admin page loads (throttled to once per 5 minutes), on the plugin settings page, and once daily via WP-Cron. Purpose: Fetch the ID of the assistant connected to this site, so the assistant activates automatically after onboarding. Data sent: site_id, site_secret. Data received: bot_id and its creation status. 4) Ultimo Bots Widget Configuration API What: https://portal.ultimo-bots.com/api/widget_configuration/{bot_id} When: On public page views where the assistant is displayed, and on activation to check whether an existing Bot ID is active. Purpose: Retrieve the widget configuration for your Bot ID (colors, sizes, welcome messages). Data sent: bot_id (path parameter); optionally host_url when provided by the widget for basic operational analytics. Data received: widget configuration JSON. 5) Ultimo Bots Widget Script Host – static asset What: https://robert-kloepsch.github.io/ultimo-bots-widget/dist/bundle.js When: On public page views where the assistant is displayed. Purpose: Load the widget client code. Data sent: standard CDN/HTTP request metadata (IP, user agent) as with any static asset request. Important: This plugin does not accept or store arbitrary HTML/JS/CSS from users. It only stores a Bot ID and generates safe markup internally. The widget script is properly enqueued via WordPress functions. Privacy This plugin communicates with Ultimo Bots services as described in External services. Please review: – Terms of Service: https://www.ultimo-bots.com/terms – Privacy Policy: https://www.ultimo-bots.com/privacy
Top keywords
- site19×1.78%
- wordpress12×1.12%
- agent11×1.03%
- data11×1.03%
- id11×1.03%
- com10×0.94%
- api9×0.84%
- bots9×0.84%
- https9×0.84%
- ultimo9×0.84%
- ultimo bots9×0.84%
- bot8×0.75%
WEBO MCP
WEBO MCP securely connects authenticated AI agents and MCP-compatible clients to WordPress through JSON-RPC tools over REST. It provides bounded access to content, media, users, settings, site health, and extensible WordPress abilities while preserving native capability checks. Use Application Passwords or an authenticated WordPress session, discover tools with tools/list, and invoke exact tools through tools/call. Optional API-key, HMAC, scoped connector-token, allowlist, and audit controls are available for administrators. Documentation and ecosystem details: https://webomcp.com Privacy This plugin does not phone home or send telemetry. MCP traffic is initiated by clients you configure. Some tools may perform outbound HTTP requests only when a client invokes them (for example seo/article-analysis may request keyword suggestions from a third-party suggest API unless you pass no_autocomplete). The plugin stores the following options in the WordPress database when configured: – webo_mcp_api_key: API key used to authenticate MCP requests. – webo_mcp_hmac_secret: HMAC secret used to sign and validate MCP requests. – webo_mcp_require_secondary_credentials: when enabled, also require API key/HMAC for Application Password and Bearer clients (off by default so standard connectors are not blocked). – webo_mcp_url_connector_tokens: hashed, expirable, revocable URL connector tokens for clients that cannot send headers. Raw tokens are shown once and are not stored. – webo_mcp_tool_allowlist_enabled and webo_mcp_tool_allowlist_rules: optional administrator-configured MCP tool allowlist policy. – webo_mcp_audit_log_enabled, webo_mcp_audit_log_max_entries, and webo_mcp_audit_log: bounded MCP tool-call audit log settings and compact audit events. Audit entries include user/tool/action/status data, anonymized IPs, and hashed session IDs; they do not store request payloads, API keys, HMAC secrets, or Application Passwords. – webo_mcp_installed_at and webo_mcp_review_notice: local timestamps/state for an optional WordPress.org review request notice (not sent off-site; dismissible). These options are removed when the plugin is uninstalled via the WordPress Plugins screen. External services This plugin can connect to Google Suggest (Autocomplete) when a client calls the seo/article-analysis tool and does not set no_autocomplete to true. This external request is used to return related keyword suggestions for SEO analysis. Service provider: Google LLC (Google Suggest / Autocomplete API endpoint). Data sent and when: – Sent only when seo/article-analysis is called with autocomplete enabled. – Sends the analysis query text to https://suggestqueries.google.com/complete/search as the q parameter. – Sends standard HTTP request metadata such as IP address and User-Agent as part of the web request. Terms of Service: https://policies.google.com/terms Privacy Policy: https://policies.google.com/privacy Developer Hooks The plugin exposes the following actions and filters for developers: Actions webo_mcp_register_tools Fired during plugin bootstrap after standalone tools are registered. Use this to register custom MCP tools from other plugins. Filters webo_mcp_current_user_can_use_mcp (bool $allowed, int $user_id) Gate for all MCP REST access. Default: super admin OR manage_options OR edit_posts. Override to tighten (e.g. super-admin only) in hardened installs. webo_mcp_secondary_credentials_exempt (bool $exempt, WP_REST_Request $request) When true, skip optional API key / HMAC after WordPress auth. Default true for Application Password (Basic) and Bearer sessions unless Settings → Security → “Require for App Password / Bearer” is enabled. Return false to always enforce X-WEBO-* headers. webo_mcp_allow_internal_tools (bool $allow_internal, WP_REST_Request $request) Controls whether internal tools are included in tools/list responses. Defaults to false for public environments. webo_mcp_public_categories (array $categories, WP_REST_Request $request, array $tool) Filters which tool categories are exposed as public. Defaults to array( ‘wordpress’ ). webo_mcp_rate_limit_per_hour (int $limit, string $client, array|null $profile) Adjust effective hourly limit (fallback for both buckets). webo_mcp_rate_limit_read_per_hour / webo_mcp_rate_limit_mutate_per_hour (int $limit, string $client, array|null $profile) Per-bucket limits after admin/profile resolution. webo_mcp_tool_is_mutating (bool $is_mutating, string $tool_name, array|null $tool_definition, array $arguments) Override mutating classification for rate limits and read-only profiles. webo_mcp_tool_arguments_allow_extra (bool $allow, string $tool_name, array $schema, array $arguments) When true, unknown tool argument keys are passed through (default false). webo_mcp_disallow_url_token_query (bool $disallowed) Block URL connector tokens in query strings (admin setting is the default source). webo_mcp_rest_bom_guard_json_api_requests (bool $activate, string $uri_raw) Opt-in BOM sanitizer for all /wp-json/ responses (default false; MCP routes only). webo_mcp_bridge_deny_patterns (array $patterns) Controls which abilities are excluded when auto-bridging abilities into MCP tools (e.g. bulk, themes/, multisite/). webo_mcp_auto_bridge_abilities (bool $enabled) Enables or disables automatic bridging of registered abilities into MCP tools. Defaults to true; bridge mode still controls whether the bridge is off, layered, or full. webo_mcp_bridge_mode (string $mode) Controls Abilities bridge mode after the WEBO_MCP_BRIDGE_MODE constant and before the stored option. Values: off, layered, full. Default: layered. webo_mcp_enable_adapter (bool $enabled) Enables or disables the bundled WordPress MCP Adapter runtime. Defaults to true. webo_mcp_validate_media_fetch_url (true|\WP_Error $ok, string $url, array $parsed) Reject unsafe URLs for webo/media-mutate upload action (return WP_Error to block). webo_mcp_tool_allowlist_allowed (bool $allowed, string $tool_name, WP_REST_Request $request, array $params, array $allowed_tools) Filters the optional per-user/role/client allowlist decision. Quick start Upload the plugin folder to /wp-content/plugins/webo-mcp Run composer install inside the plugin folder Activate the plugin in WordPress Admin Send JSON-RPC requests to POST /wp-json/mcp/v1/router For release packaging, use scripts/build-release.ps1 to create a clean zip with .distignore exclusions. Credits Special thanks to the authors and open source projects that contributed to this plugin: – WordPress (https://wordpress.org) – Abilities API (https://github.com/WordPress/abilities-api) Reference: https://make.wordpress.org/ai/2025/07/17/abilities-api/ – MCP Adapter (https://github.com/WordPress/mcp-adapter) Reference: https://make.wordpress.org/ai/2025/07/17/mcp-adapter/ – Composer (https://getcomposer.org) – Other PHP and JS libraries from the community If you use this plugin, please give credit to the authors of these libraries. License This plugin is licensed under the GPLv2 or later. See https://www.gnu.org/licenses/gpl-2.0.html for details.