miniOrange Secure MCP Server
by miniOrange 1 (4 reviews)

miniOrange Secure MCP Server

AI governance for WordPress: expose your Abilities API as a secure, OAuth-protected MCP server for AI clients like ChatGPT and Claude.

miniOrange Secure MCP Server ranks #3,775 among WordPress.org plugins with 1+ active installations, is #1,020 of 1,587 in the Authentication category, a 1/5 rating from 4 reviews, and was last updated Jun 17, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7 (Current: 7.1.1)
v1.1.0 Current Version v1.1.0
Updated 3 months ago Last Update on 17 Jun, 2026
Refreshed 8 hours ago Last Refreshed on
#1,020 of 1,587 in Authentication Downloads -37% this week
View on WordPress.org
Rank
#3,775
+88 this week
Active Installs
1+
-99.8%
KW Avg Position
83.3
No change
Downloads
14.4K
+259 today
Support Resolved
0%
No change
Rating
20%
Review 1 out of 5
1 (4 reviews)

Next Milestone 10

Total Progress 100%
0+ 10+
3,071
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 0 more installs to reach 10+

Rank Changes

3,724 3,834 3,944 4,054 4,164 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026
3,432 4,175 4,919 5,662 6,405 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026
Current #3,775
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

200 400 600 800 1K 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026
200 400 600 800 1K 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

1.0
4 reviews
Overall 20%
5
4 (100%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Support Threads Overview

Resolved
Unresolved
1
Total Threads
0
Resolved
1
Unresolved
0%
Resolution Rate

Security History

Source: WPVulnerability

No known vulnerabilities on record for miniOrange Secure MCP Server. Checked 1 month ago.

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress administrators who want to let AI assistants like ChatGPT and Claude interact with their site in a controlled way. It solves the problem of exposing site capabilities to AI clients securely, by turning the WordPress Abilities API into an OAuth-protected MCP server bounded by user permissions.

  • Abilities viewer admin screen
  • Connect to AI guide
  • Create Post ability
  • Update Post ability
  • MCP server via Streamable HTTP
  • Self-hosted OAuth 2.1 server
  • Dynamic Client Registration support
  • Authorization Code flow with PKCE

Frequently Asked Questions

Common questions about miniOrange Secure MCP Server

Add a custom connector pointing at your MCP endpoint, https://YOUR-SITE/wp-json/mosmcp/v1/mcp. The client discovers the OAuth endpoints automatically, registers itself, walks you through logging in to WordPress and approving access, and then connects. The site must be reachable over HTTPS (cloud clients cannot reach localhost); for local development, expose the site through an HTTPS tunnel such as ngrok or cloudflared.
Yes. To run the OAuth server it creates three database tables for registered clients, short-lived authorization codes, and access/refresh tokens. Tokens and client secrets are stored only as keyed hashes, never in plaintext. A single options row holds the plugin's hash salt. All of this is removed when the plugin is deleted. My server returns 401 even with a valid token. Some Apache configurations strip the Authorization header before it reaches PHP. Add the following to your WordPress root .htaccess: RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
The Abilities API does not record which plugin registered a given ability. The namespace prefix (the part before the slash in the ability name) is the most reliable indicator of where an ability comes from.

More plugins by miniOrange

Sign In / Register

You need to sign in or register to use this feature.