| 开发者 | cultureclub |
|---|---|
| 更新时间 | 2026年10月3日 18:00 |
| PHP版本: | 8.0 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
alphabridge-mcp folder to /wp-content/plugins/ (or install the ZIP via Plugins → Add New → Upload).https://your-site.tld/wp-json/alphabridge/v1/mcp instead. In ChatGPT: Plugins → Add → Create MCP app with the endpoint and OAuth.Every request needs a token bound to a WordPress user; each tool enforces the matching WordPress capability, including object-level checks for the specific post, attachment or taxonomy (non-public taxonomies additionally require that taxonomy's own capability). Out of the box the plugin only reads: every tool that creates, changes or deletes, and every reading tool noted «only with write access» (in this plugin the reader of user profile fields), is refused until an administrator switches on write access at the top of Settings → AlphaBridge MCP, at the site owner's own risk; single tools and whole groups can then be switched off again under «Fine-tuning». All calls are logged. Arbitrary option or transient values cannot be read through this plugin at all — only a fixed list of common site settings is exposed, and the settings of registered widgets through wp_get_widgets, without the values whose key the credential guard below refuses. Post, term and user meta is layered-protected: protected ("_"-prefixed) keys, keys flagged by is_protected_meta(), and two kinds of credential-shaped key are refused: keys whose whole name is a credential word, singular or plural (token, secret, password, passphrase, passcode, pwd, otp, credential), and keys containing one of a fixed list of compound credential patterns (api_key, access_token, client_secret, license_key, oauth, _token, secret, password, passwd, …). Case and surrounding whitespace are ignored. The list is matched literally, which makes this guard deliberately conservative rather than exhaustive: token_count, password_hint, credential_type, api_version, counters such as maxTokens and camelCase spellings such as accessToken all pass it, and the layers around it do the real work — and every generic post, term and user meta read or write additionally passes WordPress's own per-key meta capability (edit_post_meta / edit_term_meta / edit_user_meta), which honours auth_callback rules that other plugins register via register_meta() (the media and SEO tools read only their own fixed keys). A key you may not edit is not exposed over MCP either. Page-builder data that ends up in the page as markup or code, also where a builder keeps it under a key without "" (such as panels_data, dslc_code, pagelayer-data, brizy, mfn-page-items or tve_updated_post), is written through the meta argument of wp_create_post and wp_update_post only for accounts with the unfiltered_html capability; for any other account the call is refused before anything is written, and the answer names the ways that remain. One read-only tool reaches further, by design: wp_get_builder_layout, for an account that may edit the post, reads the page builder's own stored data of that post, protected (""-prefixed) keys included, to recognise the builder and outline the page — and returns only the visible text, link and image fields of its elements, never the raw meta, code, styling or attributes; separate keys that hold a page's own scripts or CSS are not read at all. wp_duplicate_post copies protected keys too, into the new draft only and only for an account that may edit the original: WordPress' own page template, featured image and list of removed hooked blocks, and — for accounts with the unfiltered_html capability, because it holds markup — the post meta of page builders (Elementor, Beaver Builder, SiteOrigin, Themify, Zion, Live Composer, Brizy, Visual Composer, SeedProd, Pagelayer), each builder's keys together or not at all. Credential-shaped keys, the original's editing state (edit lock, former slugs, trash data), the meta of a revision, builder caches and other plugins' protected keys are not copied. Tokens are accepted via the Authorization or X-Api-Key header — header authentication is the default. An admin can optionally enable a connector URL that carries the token in its path (served with Referrer-Policy: no-referrer and Cache-Control: no-store); this is off by default, because a token in a URL leaks more easily. Query-string tokens are never accepted. If you turn the connector URL on, treat it like a password: it contains the token — rotate the connection if the URL is shared, logged or pasted anywhere.
Yes. It is pure PHP and uses the WordPress REST API. PHP 8.0+ and HTTPS are recommended.
wp_get_builder_layout reads a page as an outline: its elements in page order, with their visible text, link and image fields. Elements that cannot be read safely, such as code, forms or unknown elements, are listed as locked, with the reason and without their content. wp_get_post says which builder a page was made with. As of 1 October 2026:
wp_update_post refuses a change to the content while the builder is active, because it would not show, and says how to change the page instead. Called without content, it still changes the title, status, excerpt and the other fields.
No. Every feature in this plugin works without payment, registration or license keys, and there are no plan-based, cumulative or time-based usage limits. A uniform security throttle (120 requests/minute, identical for every user) protects your server from abusive request bursts.
No. It contacts no external service on its own. Outbound requests happen only when you explicitly ask a tool to fetch a file from a URL you provide, and when an app you are connecting identifies itself with the address of its client metadata document and you, logged in, open its consent screen (see External services).
wp_get_user_meta). The description, the installation steps and the FAQ now say so. The description also says that each connection keeps its access level (Full, Content or Read only) when write access is on./mcp?token=… and a token field in the body were taken as the token too; only the path /mcp/<token> was meant. Now only the path counts, as the FAQ says. Header authentication is unchanged.wp_get_builder_layout works on every site. The list of what AlphaBridge MCP Pro adds says that its test requests run after PHP code is saved and catch the fatal errors they hit, not every error.read, full), the option and the PHP interface stay as they were. Switching on opens a small window at the switch with the notice and a box to tick (without JavaScript the same fields stand in the page); switching off takes one click. The notice is new (version 2): changes take effect immediately, they can create, change and also delete, not everything can be undone, at your own risk, a current backup. A confirmation of the notice of 4.4.0 stays valid; nobody has to confirm again.ab_mcp_reset_switches (write access switched on), the filters ab_mcp_unavailable_tool_message and ab_mcp_tool_label (a tool's short name), the action ab_mcp_fine_save (one save for the fine-tuning), the helpers AB_MCP_Admin::fine_row_html(), fine_sub_html(), count_badges() and addon_text(), and the class AB_MCP_Guidance with role_refusal().wp_get_builder_layout recognises the builder a page was made with and reads the page as an outline. For an account that may edit the post, it lists the page's elements in page order, each with its id, type and parent, and with its visible text, heading, HTML, link and image fields. Code, forms, global parts and elements it does not know are listed as locked, with the reason and without their content; the raw builder data, styling, attributes and scripts are never handed out. The answer also names the builder, whether it is active, what the site shows (storage), where copies of the page are kept, a hash of the layout to compare before and after a change, and the tools that change the page with a visible effect (write_via). Read, as of 1 October 2026: WordPress blocks, Elementor (classic and atomic elements), Beaver Builder, SiteOrigin Page Builder, SeedProd, GenerateBlocks, Kadence Blocks, Spectra, Stackable, Pagelayer, Otter Blocks and CoBlocks (both as plain blocks), WPBakery Page Builder, Divi 4, Avada, Flatsome and Enfold — the last five from the vendors' documentation and code, not yet checked on a live installation, which the answer says. Further builders, among them Bricks, Breakdance, Oxygen and Divi 5, are recognised but not read; the dated list is in the FAQ. An Elementor element that Elementor has not registered is listed as locked with the way: the plugin that provides it; for a container while Elementor's Container feature is off, the switch under Elementor › Settings › Features; for an atomic element while Elementor's Atomic Editor is off, the switch under Elementor › Settings › Atomic Editor. A guided prompt, edit_builder_page, takes an assistant through recognising, reading, previewing, applying and checking a change.wp_get_post says which page builder a post was made with. The new field built_with names the builder, whether it is active, its version, what the site shows and the tools that change the page with a visible effect, with a note where post_content is not simply the page.wp_list_posts filters by page builder. built_with takes a builder id as wp_get_post names it, any for every known builder or none for posts without one. The totals count only matching posts, and each listed post names the builder found on it.wp_update_post refuses a change to the content only where the builder shows its own data. Where an active builder renders a page from its own data — Elementor, Beaver Builder, SiteOrigin Page Builder or Enfold, and only on a page that has such data — post_content is a copy the site does not show, so a change to it would not appear. Such a call is refused before anything is written, and the answer says how to change the page instead; title, status, excerpt and the other fields still change when the call leaves the content out. Where the builder is inactive, restores its own copy on its next save, or may or may not show its own data, the change is saved and the answer says what to expect.wp_duplicate_post copies a page with its custom fields and page builder data. A copy used to carry only title, content, excerpt, parent, order and terms, so a builder page came out as a text page. For an account that may edit the original, the copy now also gets the custom fields, the page template, the featured image and WordPress' list of removed hooked blocks. Page builder data — Elementor, Beaver Builder, SiteOrigin, Themify, Zion, Live Composer, Brizy, Visual Composer, SeedProd and Pagelayer — holds markup, so it is copied only for an account with the unfiltered_html capability, and each builder's keys together or not at all. Elementor elements get new ids where the layout can be read; otherwise it is copied unchanged, and the answer says so. Other builders' data is copied byte for byte, and the answer says so. Builder caches, credential-shaped keys, the original's editing state and other plugins' protected keys are not copied; the answer lists what stayed behind and why.meta argument needs the unfiltered_html capability. wp_create_post and wp_update_post wrote keys without "_" in which a page builder keeps markup or code — panels_data, dslc_code, pagelayer-data, brizy, mfn-page-items, tve_updated_post and others — for any account that may edit posts. For an account without unfiltered_html such a call is now refused before anything is written; the answer names who has the capability, the builder's own editor, the tools that change the page's texts, and the call without the key for the other fields. Other keys behave as before. Site owners can change the list with the ab_mcp_builder_markup_meta_keys filter._meta is answered in it, with server/discover, result types, cache hints and the checks of the MCP-Protocol-Version, Mcp-Method and Mcp-Name headers, and without a session. initialize and the requests of the revisions 2024-11-05, 2025-03-26 and 2025-06-18 are answered as before, apart from one new field in the site's self-description (protocol_versions). The newer revision can be switched off under Settings → AlphaBridge MCP → Your connections → «MCP protocol 2026-07-28 (advanced)», or with the ab_mcp_modern_protocol filter; the site then answers in the older revisions only.ab_mcp_oauth_cimd filter, and it is off while WordPress blocks outgoing requests. Details under External services.wp_undo included, and so is every tool marked Mighty that reads code, files, the database, logs or credentials, with an answer saying why and that an administrator can switch to Full at the top of Settings → AlphaBridge MCP. That switch is the first thing on the page. Switching to Full takes a ticked box under a notice that it can be destructive and is at the site owner's own risk; the account, the time, the version and the wording of the notice and the plugin version are recorded in the plugin's settings and in its log, the last 20 switches also in a history that clearing the log leaves alone, and the page shows since when and by whom — or that code set Full and nobody confirmed it there. In Full every tool is on, the powerful ones marked Mighty included, unless an administrator switches it off under «Fine-tuning (for advanced users)». Back to Read takes one click. The server instructions and the consent screen say when a site is in Read; the tools it refuses stay listed there, as writing tools did under the former read-only mode, and are refused when called. After the update, administrators see a notice that explains the change until one of them dismisses it or switches the mode. The global read-only switch is gone, Read replaces it; switches saved before no longer hold writing Mighty tools off, while a Mighty tool that only reads and was switched off stays off in Full until an administrator switches it on under Fine-tuning. The texts of the modes come in German with the plugin (de_DE, de_DE_formal, de_AT, de_CH, de_CH_informal); a language pack from translate.wordpress.org takes precedence. The access levels per connection (Read only, Content, Full) are unchanged.AB_MCP_BUILDER_API (1), with the filters ab_mcp_builder_adapters, ab_mcp_builder_signatures, ab_mcp_builder_block_profiles, ab_mcp_builder_write_via and ab_mcp_builder_content_update_guard. AB_MCP_Site_Mode says which mode a site is in (get(), is_full(), allows()), and the action ab_mcp_site_mode_changed fires when an administrator switches. A connection with Content access may run an add-on's wp_update_builder_element.ab_mcp_affiliate_invite decides whether the line shows.ab_mcp_admin_side_boxes), between the box about AlphaBridge MCP Pro and the guides.wp_update_post saves a page whose page template is gone like any other. WordPress saves a post's page template along on every save; where that template no longer exists — after a theme switch, say — the tool reported «Invalid page template» although the change was already saved, and the hooks after the save did not run: a scheduled post got no schedule, caches were not cleared. Now WordPress falls back to the default template, as the classic editor does, and finishes the save; the page already looked that way.wp_update_post, a file that would take its visibility from its parent needs the right to publish — also through «draft» or another parent. WordPress stores a file with any status but «private», «trash» or «auto-draft» as «inherit», and a file with «inherit» is as visible as its parent: public without one, and public the moment the parent is published. wp_update_post asked for the right to publish only when the status asked for would publish, so an account without that right could make a private file public by asking for «draft» or «pending», or make a file that a draft kept hidden public by giving it another parent. Now a save that makes a file «inherit», or leaves a file «inherit» or in the trash (from where it comes back as «inherit») under another parent, needs the right to publish — whatever the parent's status is now, since a draft that is published later shows the file too. The parent that counts is the one WordPress stores: none where a loop would run through the file, which any save can cause, a title alone included. A save that leaves status and parent as they are needs no such right. This is stricter than it would have to be in some cases, on purpose: an account without the right to publish can no longer move a file from one published post to another. «Visible» means the attachment page, the file's entry in the REST API and its title, caption and description: WordPress never protects the uploaded file itself, whose address stays reachable.wp_create_post and wp_duplicate_post make no files. A file created or copied there had no file behind it: an attachment page with whatever text was given, stored as «inherit» — public without a parent — and a copy of a private file showed its title, caption and description. Files are added with wp_upload_media or wp_upload_media_from_url. A copy WordPress could not save is now reported as an error; it came back as a copy with the id 0.wp_update_post took a parent given as null or a list as none — a file came off its post, a page moved to the top level — and wp_create_post took a list as post 1. Both are refused now. A file goes under another post only where the account may edit that post, as with the upload tools, and never under a revision or another file.wp_update_post gives a status comes out the way WordPress takes one out: its comments get their states back, the notes the trash keeps are removed, and the hooks other plugins listen to run; a plugin may also keep it in the trash. It is still one save, with the status, date and fields asked for.wp_update_media reports a save that failed instead of «updated», and follows the rule of wp_update_post for files.wp_delete_post puts every kind of post into the trash unless force is set. It promised the trash, but WordPress moves only posts and pages there: a product, an event or a post of any other type was deleted for good, and a file together with the file on the server. Without force any post now goes to the trash. A file is deleted with wp_delete_media or with force, since the media library has no trash unless a site turns it on. A post already in the trash, or on a site without a trash, needs force to be deleted for good.wp_list_posts keeps a steady order when several posts share the same date to the second, as posts created by an import or a script often do. Such posts came back in whatever order the database chose, which could change from one call to the next, so paging through a list could show one of them twice and leave another out. Posts that tie on the field being sorted by — date, title, modified or menu order — are now also sorted by their id, in the same direction, so a tie no longer shifts posts between pages. Sorting by id is unchanged. Found while recording a setup video on 27 September 2026, on a demo site where several posts carry the same date.wp_update_post takes a date, in the forms wp_create_post takes: site time, or RFC 3339 with an offset. Neither tool publishes a post, or takes one off the site, unless the call asks for it. WordPress decides between «publish» and «future» by the date: a post saved as «future» whose date is not at least a minute ahead is published at once. Until now «future» without a date did exactly that to a draft, which takes the time of the save. Such a save is now refused before anything is written, with the date it would have had and what to pass instead — a later date to schedule, status «publish» to publish, status «future» to schedule a published post. An edit to a scheduled post whose date has passed is refused the same way rather than publishing it. Both tools schedule a post only for a date at least five minutes ahead: WordPress publishes a scheduled post at once whenever it is saved less than a minute before its date, and a schedule closer than that margin could be lost to a save still running, or to another plugin saving the same post again. When wp_update_post publishes a draft that has no date of its own, or wp_create_post publishes a post without a date, the plugin dates it at the save, the local and the UTC time taken from one reading of the clock; WordPress would derive the UTC time from the local one, which is an hour off in the hour the clocks go back. A date that would schedule a published post needs the right to publish, as asking for «future» does. In wp_update_post a status passed as null is refused too; WordPress would have stored it as «draft». Found on 28 September 2026 while checking what the setup video had turned up.wp_list_media keeps a steady order in the same way. Files uploaded in the same second — a batch, an import — came back in whatever order the database chose, so paging through the media library could show one of them twice and leave another out. Without a search they are now also sorted by their id, newest first. A search keeps WordPress' own order by relevance, which WordPress applies only when no order is named.notifications/tools/list_changed; if a change is not visible in such a client, refresh its tool list or reconnect it. The message after saving and a note under the Save button say so. Found by the acceptance test of 25 September 2026, where a newly enabled tool stayed invisible to a connected client until it reconnected.text-2 followed by a newline was split into its base and number (the pattern ended in $, which also matches before a trailing newline) but never found in the sidebar map, so a delete removed the settings row and left the sidebar entry behind. Found while re-reading the widget tools after the September 2026 security review.wp_upload_media_from_url now says what it does. The site itself downloads the file from a public http(s) URL through WordPress' safe-URL check (private and internal hosts refused unless WordPress itself allows them, such as the site's own host; checked on every redirect), with at most 3 redirects, 20 seconds per request and 20 MB by default; the URL or the content type must say JPEG, PNG, GIF, WebP or PDF, and WordPress then checks the file as for any upload. Behaviour unchanged; the description is what Claude reads before choosing a tool, and the automatic check in Anthropic's connector portal asked for a description that names the source.edit_user right for the account the connection acts as; on multisite a network administrator's connection can only be issued by a network administrator. Existing entries are left as they are: if connections for other users exist, look through the list. Found by an external code review in September 2026.wp_get_post and wp_duplicate_post checked read_post, which for a published post means "may read the site" and does not look at the post password; a revision of such a post carries the text but never the password, so it had the same gap. Both tools now require the right to edit the post when a password is set, and a revision — its text as well as its excerpt in any listing — is available only to someone who may edit its parent, the rule the WordPress REST API applies in its edit context. wp_list_revisions follows the same rule, wp_list_posts lists revisions only for one post at a time and only for someone who may edit it, and wp_search does not search revisions at all — a bare count of matches would already tell of the text. Same review.MAX_CLIENTS with eviction keeps the client store from filling up.wp_update_post, wp_update_media, wp_update_term and wp_moderate_comment reported destructiveHint: false, which the Model Context Protocol defines as "performs only additive updates". Clients use that hint to decide whether to ask you before a call, so an overwrite could run without a prompt. All four now report destructiveHint: true. The hint no longer comes from the "off by default" flag, which answers a different question: anything that writes counts as destructive unless it only ever adds (create, upload, duplicate, reply).wc_list_orders becomes wp_wc_list_orders, and so on for all nine. Same reason as below, and the same one-time move of any per-tool on/off override you had set.seo_detect becomes wp_seo_detect and seo_get becomes wp_seo_get. Every other tool already carried the wp_ prefix; these two did not. The prefix is what keeps a WordPress tool from colliding with a same-named tool from another CMS when a client reaches several sites at once — without it, two different tools merge into one and one of the two sites gets a description that does not fit it. If you have saved instructions or automations that call the tools by name, change those two names. Nothing else about what they do has changed. If you had switched one of them off in the settings, it stays off — the stored override moves to the new name during the update./wp-json/alphabridge/v1/oauth/revoke. A client that holds a connection token can now hand it back and end the connection itself, instead of the connection lingering until somebody deletes it in the settings. The endpoint is announced in the discovery document, so clients find it without being told the path. It answers the same way whether or not the token existed, which is what the standard requires: the answer must not reveal whether a token is valid.initialize response now carries a short self-description under _meta — which CMS answered, its version, the plugin version, the licensed edition and the scope of the token that was used. A hub or client that speaks to several sites can tell them apart without guessing from version strings. Nothing about your content is included.