New

Elementor 4, Divi 4 & 5 and one-click rollback are now part of WP MCP.Elementor 4 & Divi 5 support

Changelog

What’s new in WP MCP. Explore the latest features, improvements, and fixes—release by release.

v2.11.4

Latest release
  • The header icon is now the updated WP MCP mark in the brand orange

v2.11.3

  • The admin header now shows the WP MCP icon instead of a generic bolt; the image is bundled with the plugin

v2.11.2

  • The note beside Save settings now says activation, as well as installation and editing, needs extension access

v2.11.1

  • Fixed: in the Security tab the API key field and the key-in-URL showed the word full instead of the key (a variable was reused by the new access level picker). The stored key was never changed; it displays correctly again. If you copied the key from 2.11.0, copy it again.
  • No focus outline is left on icon buttons after a mouse click

v2.11.0

  • Access levels for connected apps: Read only, Read and edit, or Full access, chosen when you approve an app (Read and edit is preselected) and changeable any time in Connected apps
  • Apps are only offered the tools their level allows; refused calls say which level is needed; undoing a change needs the level that could have made it
  • The API key has its own level in the Security tab
  • Existing connections and the API key stay at Full access until you change them

v2.10.2

  • New Works with section on the Connect tab: Gutenberg, Elementor 3 and 4, Divi 4 and 5, content, caches and settings, showing what is active on the site
  • Health checks moved to the System tab; optional items such as Elementor, Divi and page caches show as information, not warnings
  • The blue focus ring WordPress adds after clicking a button or link is gone; keyboard focus keeps a coral outline

v2.10.1

  • Notices from other plugins no longer appear on the WP MCP screen
  • Removed the server status pill and footer credit; the blue focus box on tabs is gone
  • The Tools tab is a compact list; hover a row for what a tool does
  • Show and copy are icon buttons, and collapsible sections use a chevron

v2.10.0

  • Block editor (Gutenberg) tools: read blocks as an outline or one block at a time, and write block markup with replace, append, prepend, insert and replace-block modes; markup is validated before saving
  • Divi 4 tools: read and write shortcode layouts section by section with nesting checks; Divi 5 sites are pointed at the block tools
  • Clear caches from the assistant: object cache, transients, Elementor, Divi and eleven page cache plugins
  • Read and change common site settings, validated together and rollback-able
  • Activate or deactivate plugins and switch themes (off until you turn on Allow activation)
  • wp_ping and wp_get_content now say which editor built each page and which cache plugins are installed
  • 31 tools in total

v2.9.2

  • Cleaner typography: the admin screen now uses the Inter typeface, bundled with the plugin (no external font requests), with regular, medium, semibold and bold weights used consistently

v2.9.1

  • Removed the headline banner from the Connect tab so the connect panel is the first thing you see

v2.9.0

  • New look for the admin screen: warm off-white with coral and outlined buttons, a headline banner on the Connect tab, and icons throughout
  • A sidebar on every tab with an update notice, What’s new (read from the changelog), a health checklist and links to documentation and issues
  • After each update a What’s new banner shows the latest changes, with a Got it button to dismiss it

v2.8.0

  • New History tab: every change made through WP MCP is recorded (which app, what changed, when) and can be rolled back from the admin screen
  • Rollback restores only what the change touched: content fields, custom fields, terms, featured image and Elementor layouts; created items are trashed; deleted items come back (permanent deletes keep the same ID); uploads and terms are removed; file edits restore their pre-edit snapshot
  • If an item was edited after the change, rollback asks before overwriting those edits
  • AI apps can use the new wp_list_history and wp_rollback tools
  • Fixed: backslashes in post content and custom fields were removed when saving through WP MCP

v2.7.0

  • Redesigned admin screen with four tabs: Connect, Tools, Security and System
  • Connect: status tiles, connect an AI app, connected apps with Revoke
  • Tools: all 20 tools with what each does, its access level and whether it is currently on
  • Security: switches, API key and built-in protection
  • System: version and update check, site details, endpoints, file safety and recovery
  • Header shows when an update is available; the main screen no longer has sidebar panels or long sections

v2.6.2

  • After clicking Connect with Claude, the WP MCP page watches for the connection to finish, tries to close the Claude tab it opened, and reloads with a connected notice and an updated Connected apps list

v2.6.1

  • Connect with Claude is now a single button that opens Claude’s add-connector dialog with this site’s name and server URL already filled in
  • Link for Claude Team and Enterprise organization owners
  • Server URL moved under Manual setup

v2.6.0

  • New connect screen: choose Claude, ChatGPT, Claude Code, Cursor, VS Code or another app and follow one-click steps (copy URL and open, ready-made command, Add to Cursor / Add to VS Code links)
  • Connected apps list with a Revoke button that cuts access immediately
  • Setting to turn OAuth sign-in on or off; the API key now lives under Advanced
  • Consent page recognizes Cursor and VS Code return addresses

v2.5.0

  • Connect AI apps with OAuth: add the server URL as a connector, click Connect and approve in wp-admin. No API key to copy.
  • Only administrators can approve; the app acts as that administrator.
  • Requests with no credentials now get a 401 challenge that starts the sign-in flow. A wrong API key is still 403 and API keys keep working.
  • Discovery documents at /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource.

v2.4.2

  • New Check for updates link on the Plugins screen: looks up the latest GitHub release immediately and reports whether an update is available

v2.4.1

  • Update checks refresh hourly instead of every six hours
  • Dashboard > Updates > Check Again now bypasses the update cache

v2.4.0

  • Missing or invalid API keys return 403 on every route
  • API keys in URLs are off by default on new installs (existing sites unchanged)
  • Ten invalid keys from one address in 15 minutes block that address for 15 minutes (HTTP 429)
  • Own top-level WP MCP admin menu, plus a Settings link before Deactivate on the Plugins screen
  • Update notices from GitHub releases in the WordPress Plugins screen