Linux 软件免费装
Banner图

AlphaBridge MCP – Connect Claude and ChatGPT to WordPress

开发者 cultureclub
更新时间 2026年10月3日 18:00
PHP版本: 8.0 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

ai chatgpt claude mcp mcp-server

下载

4.2.3 4.3.3 4.2.2 4.3.2 4.3.6 4.3.0 4.2.0 4.3.1 4.3.4 4.3.5 4.3.8 4.3.9 4.4.0 4.3.11 4.3.7 4.5.0 4.3.10 4.5.1

详情介绍:

Claude and ChatGPT on your WordPress site. Read-only until you flip one switch, then full power. Free. AlphaBridge MCP turns your WordPress site into a native MCP server (Model Context Protocol). An AI assistant such as Claude — on Claude.ai, in Claude Desktop, Claude Code or Cursor — connects over one authenticated HTTPS endpoint. ChatGPT connects the same way, as an MCP app on the Plus, Pro, Business, Enterprise and Edu plans. The assistant writes and edits posts, pages, media, categories and tags, and replies to and moderates comments. It reads widgets, site settings and the outline of pages built with blocks or a common page builder. Every tool checks WordPress permissions on every single call. Tell Claude what you want done — "draft a post from these notes, add last week's photos, file it under the right categories and schedule it for Friday" — and it happens on your site, not through screen-clicking or raw admin access. One switch, full power Out of the box AlphaBridge MCP only reads: write access for AI assistants is off. Assistants can read content, media, terms, comments, settings and the structure of the site. Every tool that creates, changes or deletes is refused, and so is every reading tool noted «only with write access» under Fine-tuning: in this plugin that is the reader of user profile fields. The answer says why, what the person can do and links straight to the switch. The main switch «Write access for AI assistants» at the top of Settings → AlphaBridge MCP holds for every connection — Claude, ChatGPT, Cursor and all others. Switching write access on switches every tool on; each connection keeps its access level (Full, Content or Read only). Switching it off takes one click. Before switching on, an administrator ticks a box: changes take effect immediately, it is at the site owner's own risk, and a current backup exists. The account, the time, the version of that notice and its wording are recorded. Connected in two minutes In Claude, connect «AlphaBridge MCP for WordPress» from the connector directory. Enter your site's address and approve on your own site's login-protected consent screen. There is no endpoint or token to copy: it is standard OAuth 2.1 with PKCE, the login is your WordPress login, and you need no account with us. This entry runs through the AlphaBridge Connect hub described below. To connect directly, paste your endpoint URL into Claude as a custom connector instead. ChatGPT connects the same way: add the endpoint as an MCP app (Plugins → Add → Create MCP app, authentication OAuth) and approve on your site. This was checked on 26 September 2026 with ChatGPT Pro, directly and through the hub. For clients without a Connect button, create a token manually and paste one ready-made config. The whole way in one minute — install, connect from Claude's directory, approve on your site, give Claude a first task: https://www.youtube.com/watch?v=DlMJ9tfrqJg In German: Claude mit WordPress verbinden AlphaBridge Connect: up to 10 sites in one chat, free The entry «AlphaBridge MCP for WordPress» in Claude's connector directory is the hosted hub at connect.alphabridge-mcp.com. You enter your site's address instead of copying the endpoint, and you approve the site on its own login screen. Through the hub, up to 10 sites work from one chat, in every edition including this free plugin: add a site from the chat and keep working in the same conversation. Each site keeps its own rights and its own audit log. The hub is optional and free, and this plugin never contacts it on its own. The hub connects to your site for authorization, connection setup and management, and to forward the tool calls you make through it. It stores the site's access key encrypted and passes content through without storing it. The details are in its privacy notice (https://connect.alphabridge-mcp.com/legal/privacy) and its data processing agreement (https://connect.alphabridge-mcp.com/legal/dpa). Nothing extra to host Unlike bridge-based solutions, AlphaBridge speaks MCP directly in PHP inside WordPress. With a direct connection there is no Node middleware, no external service and nothing else to run or pay for — it works on ordinary WordPress hosting. The hub above is the one optional exception, and you choose whether to use it. Free means free Everything in this plugin is fully functional: no license keys, no registration, no plan-based, cumulative or time-based usage limits, no locked features. What's inside How it compares A dated comparison with other WordPress MCP plugins, every cell checked against the vendors' own pages: https://alphabridge-mcp.com/compare.html Need more? AlphaBridge MCP Pro and Agency A separate commercial add-on, AlphaBridge MCP Pro, lets the assistant do more: The Agency plan adds Site Deploy for agencies and developers: files, themes and whole builds published over SFTP onto the server this site runs on. ZIP deploys can run atomically, with rollback when the swap fails. Pro can be tried free for 7 days, no card needed. Both are entirely optional — this free plugin is complete on its own and stays fully functional without them. Details are on the plugin website. AlphaBridge is our own product brand for this project. MCP (Model Context Protocol) is an open protocol standard; this plugin is an independent implementation and is not affiliated with or endorsed by the protocol's authors or by any other vendor.

安装:

  1. Upload the alphabridge-mcp folder to /wp-content/plugins/ (or install the ZIP via Plugins → Add New → Upload).
  2. Activate the plugin.
  3. In Claude, open Connectors, find «AlphaBridge MCP for WordPress» in the directory and connect: enter your site's address and approve on your own site's login-protected consent screen. Done. To connect directly, without the AlphaBridge Connect hub in between, add a custom connector with the endpoint https://your-site.tld/wp-json/alphabridge/v1/mcp instead. In ChatGPT: Plugins → Add → Create MCP app with the endpoint and OAuth.
  4. For clients without a Connect button (Cursor, Claude Code, scripts): open Settings → AlphaBridge MCP, create a connection manually and copy its token.
  5. The plugin starts with write access off: assistants can read content, media, terms, comments, settings and the structure of the site. To let them create, change and delete, and read user profile fields, switch on «Write access for AI assistants» at the top of Settings → AlphaBridge MCP. Changes then take effect immediately and not everything can be undone; you switch it on at your own risk, so make sure you have a current backup.

屏幕截图:

  • The moment you create a connection, the plugin shows what you need once — the Bearer token and a copy-paste config for Cursor / Claude Code, and the connector URL if connector-URL authentication is switched on — with a reminder to save it, because the token is shown in full only once.
  • Optional advanced settings for a connection: a label, the WordPress user it acts as, full, content-only or read-only access, and an optional expiry in days.
  • Switch all tools, a group or a single tool; open a group to see its tool groups and what each tool does, whether it reads or writes, or search for one. These switches sit under «Fine-tuning», below the main switch for write access at the top of the page.
  • Connect from Claude is on by default: Claude discovers the site, you approve on a login-protected consent screen, and the approved connection appears in the list, revocable any time. Switching it off removes the OAuth endpoints. A second box lets apps identify themselves with a metadata document instead of registering.
  • Connector-URL authentication is off by default, because a token in a URL leaks more easily than one in a header; the setting explains the trade-off before you switch it on.

升级注意事项:

4.5.0 The box with Read and Full becomes the main switch «Write access for AI assistants», for every connection. Switching it on switches every tool on; a confirmation of 4.4.0 stays valid. New connections start with the full access level. 4.4.0 After this update AlphaBridge MCP only reads until an administrator switches to Full at the top of Settings → AlphaBridge MCP, at the site owner's own risk. In Full, writing Mighty tools are on, also ones that were off before.

常见问题:

Is it secure?

Every request needs a token bound to a WordPress user; each tool enforces the matching WordPress capability, including object-level checks for the specific post, attachment or taxonomy (non-public taxonomies additionally require that taxonomy's own capability). Out of the box the plugin only reads: every tool that creates, changes or deletes, and every reading tool noted «only with write access» (in this plugin the reader of user profile fields), is refused until an administrator switches on write access at the top of Settings → AlphaBridge MCP, at the site owner's own risk; single tools and whole groups can then be switched off again under «Fine-tuning». All calls are logged. Arbitrary option or transient values cannot be read through this plugin at all — only a fixed list of common site settings is exposed, and the settings of registered widgets through wp_get_widgets, without the values whose key the credential guard below refuses. Post, term and user meta is layered-protected: protected ("_"-prefixed) keys, keys flagged by is_protected_meta(), and two kinds of credential-shaped key are refused: keys whose whole name is a credential word, singular or plural (token, secret, password, passphrase, passcode, pwd, otp, credential), and keys containing one of a fixed list of compound credential patterns (api_key, access_token, client_secret, license_key, oauth, _token, secret, password, passwd, …). Case and surrounding whitespace are ignored. The list is matched literally, which makes this guard deliberately conservative rather than exhaustive: token_count, password_hint, credential_type, api_version, counters such as maxTokens and camelCase spellings such as accessToken all pass it, and the layers around it do the real work — and every generic post, term and user meta read or write additionally passes WordPress's own per-key meta capability (edit_post_meta / edit_term_meta / edit_user_meta), which honours auth_callback rules that other plugins register via register_meta() (the media and SEO tools read only their own fixed keys). A key you may not edit is not exposed over MCP either. Page-builder data that ends up in the page as markup or code, also where a builder keeps it under a key without "" (such as panels_data, dslc_code, pagelayer-data, brizy, mfn-page-items or tve_updated_post), is written through the meta argument of wp_create_post and wp_update_post only for accounts with the unfiltered_html capability; for any other account the call is refused before anything is written, and the answer names the ways that remain. One read-only tool reaches further, by design: wp_get_builder_layout, for an account that may edit the post, reads the page builder's own stored data of that post, protected (""-prefixed) keys included, to recognise the builder and outline the page — and returns only the visible text, link and image fields of its elements, never the raw meta, code, styling or attributes; separate keys that hold a page's own scripts or CSS are not read at all. wp_duplicate_post copies protected keys too, into the new draft only and only for an account that may edit the original: WordPress' own page template, featured image and list of removed hooked blocks, and — for accounts with the unfiltered_html capability, because it holds markup — the post meta of page builders (Elementor, Beaver Builder, SiteOrigin, Themify, Zion, Live Composer, Brizy, Visual Composer, SeedProd, Pagelayer), each builder's keys together or not at all. Credential-shaped keys, the original's editing state (edit lock, former slugs, trash data), the meta of a revision, builder caches and other plugins' protected keys are not copied. Tokens are accepted via the Authorization or X-Api-Key header — header authentication is the default. An admin can optionally enable a connector URL that carries the token in its path (served with Referrer-Policy: no-referrer and Cache-Control: no-store); this is off by default, because a token in a URL leaks more easily. Query-string tokens are never accepted. If you turn the connector URL on, treat it like a password: it contains the token — rotate the connection if the URL is shared, logged or pasted anywhere.

Does it work on shared hosting?

Yes. It is pure PHP and uses the WordPress REST API. PHP 8.0+ and HTTPS are recommended.

Which page builders does it read?

wp_get_builder_layout reads a page as an outline: its elements in page order, with their visible text, link and image fields. Elements that cannot be read safely, such as code, forms or unknown elements, are listed as locked, with the reason and without their content. wp_get_post says which builder a page was made with. As of 1 October 2026:

  • Read: WordPress blocks, Elementor, Beaver Builder, SiteOrigin Page Builder, SeedProd, GenerateBlocks, Kadence Blocks, Spectra, Stackable, Pagelayer, Otter Blocks and CoBlocks (both as plain blocks), WPBakery Page Builder, Divi 4, Avada (Fusion Builder), Flatsome (UX Builder) and Enfold (Avia Layout Builder).
  • Read from the vendors' documentation and code, not yet checked on a live installation (the answer says so): WPBakery Page Builder, Divi 4, Avada, Flatsome and Enfold.
  • Recognised, not read: Brizy, Themify Builder, Zion Builder, Live Composer, Cornerstone, Thrive Architect, Bricks, Breakdance, Oxygen 6, Oxygen Classic, BeTheme (BeBuilder), Visual Composer Website Builder, Divi 5 and Etch.
Where a builder shows its own data and post_content is only a copy — Elementor, Beaver Builder, SiteOrigin Page Builder and Enfold — wp_update_post refuses a change to the content while the builder is active, because it would not show, and says how to change the page instead. Called without content, it still changes the title, status, excerpt and the other fields.

Is the free plugin limited?

No. Every feature in this plugin works without payment, registration or license keys, and there are no plan-based, cumulative or time-based usage limits. A uniform security throttle (120 requests/minute, identical for every user) protects your server from abusive request bursts.

Does the plugin send data anywhere?

No. It contacts no external service on its own. Outbound requests happen only when you explicitly ask a tool to fetch a file from a URL you provide, and when an app you are connecting identifies itself with the address of its client metadata document and you, logged in, open its consent screen (see External services).

更新日志:

4.5.1 4.5.0 4.4.0 4.3.11 4.3.10 4.3.9 4.3.8 4.3.7 4.3.6 4.3.5 4.3.4 4.3.3 4.3.2 4.3.1 4.3.0 4.2.3 4.2.2 4.2.0 4.1.6 4.1.5 4.1.4 4.1.3 4.1.2 4.1.1 4.1.0 4.0.0 3.0.0 2.0.0 1.x