Secure MCP Server for Claude, ChatGPT, Gemini and other AI providers
by miniOrange 5 (4 reviews)

Secure MCP Server for Claude, ChatGPT, Gemini and other AI providers

The #1 secure WordPress MCP server for connecting Claude, ChatGPT, & AI agents (MCP Clients) with 300+ tools for WooCommerce, Elementor, audit log …

Secure MCP Server for Claude, ChatGPT, Gemini and other AI… ranks #3,904 among WordPress.org plugins with 3,000+ active installations, is #1,020 of 1,584 in the Authentication category, a 5/5 rating from 4 reviews, and was last updated Sep 16, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1.1
v1.4.12 Current Version v1.4.12
Updated 1 day ago Last Update on 16 Sep, 2026
Refreshed 9 hours ago Last Refreshed on
#1,020 of 1,584 in Authentication Downloads -18.8% this week
View on WordPress.org
Rank
#3,904
No change
Active Installs
3K+
+846.4%
KW Avg Position
82.7
0.4 worse
Downloads
14K
+60 today
Support Resolved
0%
No change
Rating
100%
Review 5 out of 5
5 (4 reviews)

Next Milestone 4K

Total Progress 89.4%
3K+ 4K+
260
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 106 more installs to reach 4K+

Rank Changes

3,866 3,953 4,040 4,126 4,213 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026
3,516 4,361 5,207 6,053 6,898 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026
Current #3,904
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 200 400 600 800 1K 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026
0 200 400 600 800 1K 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

5.0
4 reviews
Overall 100%
5
4 (100%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Security History

Source: WPVulnerability

No known vulnerabilities on record for Secure MCP Server for Claude, ChatGPT, Gemini and other AI…. Checked 1 month ago.

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress administrators who want to let AI assistants like ChatGPT and Claude interact with their site in a controlled way. It solves the problem of exposing site capabilities to AI clients securely, by turning the WordPress Abilities API into an OAuth-protected MCP server bounded by user permissions.

  • Abilities viewer admin screen
  • Connect to AI guide
  • Create Post ability
  • Update Post ability
  • MCP server via Streamable HTTP
  • Self-hosted OAuth 2.1 server
  • Dynamic Client Registration support
  • Authorization Code flow with PKCE

Frequently Asked Questions

Common questions about Secure MCP Server for Claude, ChatGPT, Gemini and other AI providers

Add a custom connector pointing at your MCP endpoint, https://YOUR-SITE/wp-json/mosmcp/v1/mcp. The client discovers the OAuth endpoints automatically, registers itself, walks you through logging in to WordPress and approving access, and then connects. The site must be reachable over HTTPS (cloud clients cannot reach localhost); for local development, expose the site through an HTTPS tunnel such as ngrok or cloudflared.
Yes. To run the OAuth server it creates three database tables for registered clients, short-lived authorization codes, and access/refresh tokens. Tokens and client secrets are stored only as keyed hashes, never in plaintext. A single options row holds the plugin's hash salt. All of this is removed when the plugin is deleted. My server returns 401 even with a valid token. Some Apache configurations strip the Authorization header before it reaches PHP. Add the following to your WordPress root .htaccess: RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
The Abilities API does not record which plugin registered a given ability. The namespace prefix (the part before the slash in the ability name) is the most reliable indicator of where an ability comes from.

More plugins by miniOrange

Sign In / Register

You need to sign in or register to use this feature.