Secure MCP Server for Claude, ChatGPT, Gemini and other AI providers
by miniOrange 5 (5 reviews)

Secure MCP Server for Claude, ChatGPT, Gemini and other AI providers

The #1 secure WordPress MCP server for connecting Claude, ChatGPT, & AI agents (MCP Clients) with 300+ tools for WooCommerce, Elementor, audit log …

Secure MCP Server for Claude, ChatGPT, Gemini and other AI… ranks #3,664 among WordPress.org plugins with 3,000+ active installations, is #133 of 1,590 in the Authentication category, a 5/5 rating from 5 reviews, and was last updated Sep 16, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1.1
v1.4.12 Current Version v1.4.12
Updated 6 days ago Last Update on 16 Sep, 2026
Refreshed 10 hours ago Last Refreshed on
#133 of 1,590 in Authentication Top 5% by installs Downloads -19.7% this week Actively maintained
View on WordPress.org
Rank
#3,664
No change
Active Installs
3K+
+419.9%
KW Avg Position
84.3
1 worse
Downloads
15.3K
+185 today
Support Resolved
0%
No change
Rating
100%
Review 5 out of 5
5 (5 reviews)

Next Milestone 4K

Total Progress 99.1%
3K+ 4K+
20
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 9 more installs to reach 4K+

Rank Changes

3,657 3,744 3,830 3,916 4,003 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
3,494 3,934 4,373 4,812 5,252 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
Current #3,664
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 200 400 600 800 1K 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
0 200 400 600 800 1K 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

5.0
5 reviews
Overall 100%
5
5 (100%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Support Threads Overview

Resolved
Unresolved
1
Total Threads
0
Resolved
1
Unresolved
0%
Resolution Rate

Security History

Source: WPVulnerability

No known vulnerabilities on record for Secure MCP Server for Claude, ChatGPT, Gemini and other AI…. Checked 1 month ago.

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress administrators who want to let AI assistants like ChatGPT and Claude interact with their site in a controlled way. It solves the problem of exposing site capabilities to AI clients securely, by turning the WordPress Abilities API into an OAuth-protected MCP server bounded by user permissions.

  • Abilities viewer admin screen
  • Connect to AI guide
  • Create Post ability
  • Update Post ability
  • MCP server via Streamable HTTP
  • Self-hosted OAuth 2.1 server
  • Dynamic Client Registration support
  • Authorization Code flow with PKCE

Frequently Asked Questions

Common questions about Secure MCP Server for Claude, ChatGPT, Gemini and other AI providers

Add a custom connector pointing at your MCP endpoint, https://YOUR-SITE/wp-json/mosmcp/v1/mcp. The client discovers the OAuth endpoints automatically, registers itself, walks you through logging in to WordPress and approving access, and then connects. The site must be reachable over HTTPS (cloud clients cannot reach localhost); for local development, expose the site through an HTTPS tunnel such as ngrok or cloudflared.
Yes. To run the OAuth server it creates three database tables for registered clients, short-lived authorization codes, and access/refresh tokens. Tokens and client secrets are stored only as keyed hashes, never in plaintext. A single options row holds the plugin's hash salt. All of this is removed when the plugin is deleted. My server returns 401 even with a valid token. Some Apache configurations strip the Authorization header before it reaches PHP. Add the following to your WordPress root .htaccess: RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
The Abilities API does not record which plugin registered a given ability. The namespace prefix (the part before the slash in the ability name) is the most reliable indicator of where an ability comes from.

More plugins by miniOrange

Sign In / Register

You need to sign in or register to use this feature.