{"id":343832,"date":"2026-07-27T19:05:48","date_gmt":"2026-07-27T19:05:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/mindio-magic-mcp\/"},"modified":"2026-09-27T19:28:16","modified_gmt":"2026-09-27T19:28:16","slug":"mindio-magic-mcp","status":"closed","type":"plugin","link":"https:\/\/ga.wordpress.org\/plugins\/mindio-magic-mcp\/","author":23536284,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.7.1","stable_tag":"0.7.1","tested":"7.1.2","requires":"6.4","requires_php":"8.0","requires_plugins":null,"header_name":"Mindio Magic MCP","header_author":"Mohammad Askari <farvisun@gmail.com>","header_description":"A secure MCP server for WordPress that supports Flatsome UX Builder, content automation, and site management.","assets_banners_color":"","last_updated":"2026-09-27 19:28:16","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/farvisun\/mindio-magic-mcp","header_author_uri":"https:\/\/profiles.wordpress.org\/farvisun\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":160,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.5.5":{"tag":"0.5.5","author":"farvisun","date":"2026-07-27 19:05:16","revision":3625070},"0.5.6":{"tag":"0.5.6","author":"farvisun","date":"2026-07-27 19:46:55","revision":3625102},"0.7.1":{"tag":"0.7.1","author":"farvisun","date":"2026-09-27 19:28:16","revision":3715999}},"upgrade_notice":{"0.7.1":"<p>Security release. Fixes an authenticated (Subscriber+) exposure of password-protected post content and restricts approval requests and changesets to their owners. Update immediately.<\/p>","0.7.0":"<p>Adds MCP resources and prompts, dry-run previews, revertible changesets, per-credential budgets, a multi-builder page blueprint, a human approval queue, SSE streaming, and audit export. Existing credentials keep working; the database schema is upgraded on activation.<\/p>","0.6.0":"<p>The REST namespace is now mindio-magic-mcp\/v1 and the API key header is X-Mindio-Magic-MCP-Key. The previous names stay available, so existing clients keep working, but new clients should use the canonical ones.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3625102,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3625102,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.5.5","0.5.6","0.7.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3625102,"resolution":"1","location":"assets","locale":"","width":1298,"height":1043},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3625102,"resolution":"2","location":"assets","locale":"","width":1298,"height":1050},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3625102,"resolution":"3","location":"assets","locale":"","width":1298,"height":1318}},"screenshots":{"1":"System overview with MCP connection endpoints, environment readiness, onboarding guidance, and recent tool activity.","2":"Granular tool governance with searchable groups, per-tool exposure controls, operation policy, and scope indicators.","3":"Security and runtime settings for request limits, browser origins, retention, developer capabilities, and uninstall behavior."}},"plugin_section":[],"plugin_tags":[2353,569,143513,242115,2061],"plugin_category":[38],"plugin_contributors":[273532],"plugin_business_model":[],"class_list":["post-343832","plugin","type-plugin","status-closed","hentry","plugin_tags-ai","plugin_tags-automation","plugin_tags-flatsome","plugin_tags-mcp","plugin_tags-oauth","plugin_category-authentication","plugin_contributors-farvisun","plugin_committers-farvisun"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/mindio-magic-mcp.svg","icon_2x":false,"generated":true},"screenshots":[{"src":"https:\/\/ps.w.org\/mindio-magic-mcp\/assets\/screenshot-1.png?rev=3625102","caption":"System overview with MCP connection endpoints, environment readiness, onboarding guidance, and recent tool activity."},{"src":"https:\/\/ps.w.org\/mindio-magic-mcp\/assets\/screenshot-2.png?rev=3625102","caption":"Granular tool governance with searchable groups, per-tool exposure controls, operation policy, and scope indicators."},{"src":"https:\/\/ps.w.org\/mindio-magic-mcp\/assets\/screenshot-3.png?rev=3625102","caption":"Security and runtime settings for request limits, browser origins, retention, developer capabilities, and uninstall behavior."}],"raw_content":"<!--section=description-->\n<p>Mindio Magic MCP exposes WordPress operations to compatible AI agents through the Model Context Protocol.<\/p>\n\n<p>Mindio Magic MCP is independently developed and is not affiliated with or endorsed by UX Themes. Flatsome is a trademark of its respective owner.<\/p>\n\n<p>Highlights:<\/p>\n\n<ul>\n<li>Stateless MCP Streamable HTTP endpoint with optional server-sent event streaming and progress notifications<\/li>\n<li>MCP resources and site-aware prompts alongside tools, including a configurable brand voice<\/li>\n<li>API keys, OAuth 2.1 authorization code flow, PKCE S256, and WordPress authentication<\/li>\n<li>Hierarchical read-only, editor, and administrator scopes, plus per-credential allow\/deny patterns and daily call budgets<\/li>\n<li>Preview any write with dry_run, group writes into a revertible changeset, and park high-risk calls in a human approval queue<\/li>\n<li>One builder-neutral page blueprint that renders through Flatsome UX Builder, Elementor, or core blocks<\/li>\n<li>Structured Gutenberg block discovery and revision-safe block-tree editing<\/li>\n<li>explain_page semantic outlines with stable node IDs, heading structure, and accessibility gaps<\/li>\n<li>Post, media, comments, users, SEO, settings, plugin, theme, webhook, search, and diagnostics tools<\/li>\n<li>Official-directory plugin\/theme search, installation, updates, deletion, generic theme settings, and Flatsome settings<\/li>\n<li>Free integrations for ACF, BetterDocs, Contact Form 7, WooCommerce, Yoast SEO, and Rank Math with fixed operation catalogs<\/li>\n<li>Opt-in, bounded, read-only filesystem and database inspection<\/li>\n<li>Native-first Flatsome sections, rows, columns, and 29 typed UX Builder components with reported HTML fallback<\/li>\n<li>Persian content support and RTL-safe generated layouts<\/li>\n<li>Conditional WooCommerce and multisite tools<\/li>\n<li>Rate limits, strict schemas, audit logs, SSRF controls, and destructive-action confirmations<\/li>\n<li>Audit export to a webhook or syslog every five minutes, with anomaly alerts for failure spikes, permission probing, destructive bursts, exhausted budgets, and credentials used from a new address<\/li>\n<li>Responsive flat enterprise admin console with compact 2\u20134px geometry and separate Overview, Tools, Credentials, Approvals, Webhooks, Activity, and Settings tabs<\/li>\n<li>Searchable, grouped per-site tool exposure policy with individual, group, and enable\/disable-all controls<\/li>\n<li>Expandable per-operation integration policy; reads start enabled and writes start disabled<\/li>\n<li>Searchable diagnostics, copy-ready endpoints, accessible controls, and WordPress.org language-pack support<\/li>\n<\/ul>\n\n<p>The core single-site plugin registers 95 MCP tool names. Each installed supported integration adds read and write dispatchers; all six integrations add 12 names and 147 fixed operations. Active WooCommerce adds 6 compatible legacy tools and WordPress multisite adds 2 tools.<\/p>\n\n<p>No prompt or content is sent to an external AI provider by default. Generation and translation integrations are opt-in through documented WordPress filters.<\/p>\n\n<p>Development source and reproducible release tooling are available at https:\/\/github.com\/farvisun\/mindio-magic-mcp.<\/p>\n\n<h3>External services<\/h3>\n\n<p>Mindio Magic MCP does not contact an external service merely because it is installed or activated, and it includes no telemetry or tracking.<\/p>\n\n<ul>\n<li>WordPress.org directory services: When an authorized administrator or MCP agent explicitly searches for, installs, or updates a plugin or theme, Mindio Magic MCP uses the WordPress.org APIs and official download servers. Search terms, package slugs, and standard HTTP connection metadata are sent to WordPress.org. Service: https:\/\/wordpress.org\/ \u2014 Privacy policy: https:\/\/wordpress.org\/about\/privacy\/.<\/li>\n<li>Administrator-selected media URLs: The upload_media tool can download a file from a URL supplied in that individual request. The selected server receives a normal HTTPS request from the WordPress site. No site content is added to that request.<\/li>\n<li>Administrator-configured webhooks: After an administrator registers and enables a webhook URL, subscribed WordPress events send a signed JSON payload to that URL. Payloads contain the site name and URL plus event-specific identifiers and metadata. The administrator is responsible for the destination service and its privacy terms.<\/li>\n<li>HTTPS OAuth Client ID Metadata: When an MCP client identifies itself with an HTTPS Client ID URL, Mindio Magic MCP retrieves that URL to validate the client's redirect metadata before authorization. The client host receives a normal HTTPS request from the WordPress site.<\/li>\n<li>Optional automation providers: Mindio Magic MCP ships without an AI provider. A site owner may connect one through documented WordPress filters; data handling and terms then depend on that site-specific integration.<\/li>\n<\/ul>\n\n<h3>Privacy<\/h3>\n\n<p>Mindio Magic MCP stores credentials, OAuth client registrations, per-site policies, webhook configuration, and bounded audit\/delivery logs in the WordPress database. Secrets are hashed or encrypted where they must be recoverable. The plugin does not sell data, display public credits, or track usage. Administrators control retention periods and can opt into full plugin-data removal on uninstall.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin ZIP from Plugins &gt; Add New &gt; Upload Plugin.<\/li>\n<li>Activate Mindio Magic MCP.<\/li>\n<li>Open Settings &gt; Mindio Magic MCP.<\/li>\n<li>Generate an API key for a WordPress user using the least-privileged suitable scope.<\/li>\n<li>Configure your MCP client with the displayed REST endpoint.<\/li>\n<\/ol>\n\n<p>Use HTTPS in production. Flatsome or a Flatsome child theme must be active for UX Builder tools.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20require%20flatsome%3F\"><h3>Does this require Flatsome?<\/h3><\/dt>\n<dd><p>No for general WordPress tools. Flatsome is required for page generation and editing. list_flatsome_components remains available when the theme is inactive so agents can diagnose compatibility.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20call%20an%20ai%20service%3F\"><h3>Does the plugin call an AI service?<\/h3><\/dt>\n<dd><p>No. Content generation and translation fail closed until a site owner connects a provider through the documented filters. Summarization has a local extractive fallback.<\/p><\/dd>\n<dt id=\"does%20it%20support%20oauth%3F\"><h3>Does it support OAuth?<\/h3><\/dt>\n<dd><p>Yes. It includes OAuth 2.1 authorization code flow with PKCE S256, dynamic client registration, rotating refresh tokens, MCP protected-resource metadata, and a standalone translated consent\/result experience. Enter the MCP endpoint in your client; OAuth discovery URLs are used automatically.<\/p><\/dd>\n<dt id=\"are%20developer%20tools%20enabled%20by%20default%3F\"><h3>Are developer tools enabled by default?<\/h3><\/dt>\n<dd><p>No. Read-only filesystem inspection, fixed-shape database schema inspection, and in-process WP-CLI commands must be enabled separately by an administrator and remain tightly allowlisted.<\/p><\/dd>\n<dt id=\"can%20administrators%20disable%20individual%20mcp%20tools%3F\"><h3>Can administrators disable individual MCP tools?<\/h3><\/dt>\n<dd><p>Yes. Open the Tools tab to control the MCP surface per site. Disabled tools disappear from discovery and direct calls are rejected without changing existing credentials or scopes. ACF, BetterDocs, Contact Form 7, Yoast, Rank Math, and WooCommerce dispatchers also expose individual operation switches. Their write operations are disabled by default.<\/p><\/dd>\n<dt id=\"when%20are%20plugin%20integration%20controls%20shown%3F\"><h3>When are plugin integration controls shown?<\/h3><\/dt>\n<dd><p>Only when WordPress detects that integration plugin as installed. Installed but inactive plugins remain configurable, although their MCP operations cannot execute until the plugin is activated. Saved policy is retained if a plugin is later removed and restored if it is installed again.<\/p><\/dd>\n<dt id=\"does%20it%20support%20gravity%20forms%3F\"><h3>Does it support Gravity Forms?<\/h3><\/dt>\n<dd><p>No. Gravity Forms is a separate commercial plugin and is not bundled, required, or feature-gated by Mindio Magic MCP. There is no paid Mindio Magic MCP tier that unlocks it.<\/p><\/dd>\n<dt id=\"does%20mindio%20magic%20mcp%20execute%20arbitrary%20code%3F\"><h3>Does Mindio Magic MCP execute arbitrary code?<\/h3><\/dt>\n<dd><p>No. It provides no PHP or JavaScript editor, file manager, arbitrary command runner, or AI-generated executable-code path. Agent-supplied HTML is filtered through the WordPress KSES allowlist. WP-CLI is limited to four fixed in-process maintenance commands with no shell, and child-theme creation writes only a fixed plugin-owned bootstrap template that accepts no executable-code input.<\/p><\/dd>\n<dt id=\"does%20it%20download%20executable%20code%3F\"><h3>Does it download executable code?<\/h3><\/dt>\n<dd><p>Only when an authorized administrator explicitly requests a plugin or theme install\/update. Packages must resolve to verified HTTPS URLs on downloads.wordpress.org and are installed by WordPress core upgraders. Mindio Magic MCP does not fetch executable code from any other service.<\/p><\/dd>\n<dt id=\"is%20any%20included%20functionality%20restricted%20by%20payment%2C%20a%20license%2C%20or%20a%20trial%3F\"><h3>Is any included functionality restricted by payment, a license, or a trial?<\/h3><\/dt>\n<dd><p>No. The plugin contains no license check, paywall, feature gate, time limit, usage cutoff, or remote activation dependency. Optional integrations appear only when their independently distributed WordPress plugins are installed.<\/p><\/dd>\n<dt id=\"how%20is%20this%20different%20from%20other%20mcp%20plugins%3F\"><h3>How is this different from other MCP plugins?<\/h3><\/dt>\n<dd><p>Its primary distinction is native-first Flatsome UX Builder generation and editing across 29 typed components, combined with revision-safe Gutenberg operations, granular per-tool and per-operation policy, OAuth 2.1, Persian localization, and RTL-safe generated layouts.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.7.1<\/h4>\n\n<ul>\n<li>Security: fixed an authenticated (Subscriber+) sensitive data exposure. Password-protected posts and pages are no longer listed, searched, or returned by <code>list_posts<\/code>, <code>get_post<\/code>, <code>search_content<\/code>, block\/page\/Flatsome readers, summaries, SEO and ACF readers, MCP post resources, or prompts unless the caller can edit that entry.<\/li>\n<li>Security: revisions and autosaves are only readable by users who can edit the parent entry, and published entries of non-public post types (for example form configurations or coupons) are only readable by users who can edit them.<\/li>\n<li>Security: the ACF field reader only resolves real ACF fields and never protected (<code>_<\/code>-prefixed) post meta.<\/li>\n<li>Security: <code>list_approvals<\/code> and <code>get_approval<\/code> now only return the caller's own approval requests unless the caller is an administrator.<\/li>\n<li>Security: changeset tools now only list, read, close, or revert the caller's own changesets unless the caller is an administrator.<\/li>\n<li>Security: <code>list_posts<\/code> no longer reveals matches in other authors' unpublished entries through result totals; exact WordPress and PHP versions, SEO focus keywords, and revision IDs are only returned to users entitled to see them; credential allow lists and daily budgets now also apply to <code>resources\/read<\/code> and <code>prompts\/get<\/code>.<\/li>\n<li>Tested with WordPress 7.1.<\/li>\n<\/ul>\n\n<h4>0.7.0<\/h4>\n\n<ul>\n<li>Added MCP resources and site-aware prompts, plus a brand voice setting that flows into both.<\/li>\n<li>Added <code>dry_run<\/code> to every previewable write tool: the call runs inside a database transaction, reports the exact changes, and is rolled back.<\/li>\n<li>Added changesets that group write calls under one ID and revert them as a unit, covering meta, terms, options, comments, and users.<\/li>\n<li>Added per-credential allow\/deny tool patterns and daily call budgets, enforced in discovery and execution.<\/li>\n<li>Added a builder abstraction so one neutral blueprint renders through Flatsome UX Builder, Elementor, or core blocks.<\/li>\n<li>Added <code>explain_page<\/code> for structured page outlines with stable node IDs, heading structure, and accessibility gaps.<\/li>\n<li>Added an optional human approval queue with a new Approvals tab; gated calls park for review and replay with an issued approval ID.<\/li>\n<li>Added server-sent event streaming with <code>notifications\/progress<\/code> when the client sends <code>Accept: text\/event-stream<\/code>.<\/li>\n<li>Added audit log export to a webhook or syslog with HMAC-SHA256 signing, plus anomaly detection and <code>export_audit_log<\/code>.<\/li>\n<\/ul>\n\n<h4>0.6.0<\/h4>\n\n<ul>\n<li>Renamed the REST namespace to <code>mindio-magic-mcp\/v1<\/code> and kept <code>flatsome-mcp\/v1<\/code> registered as a deprecated alias.<\/li>\n<li>Renamed the API key header to <code>X-Mindio-Magic-MCP-Key<\/code> and the webhook headers to <code>X-Mindio-Magic-MCP-*<\/code>, keeping the previous names readable or emitted for compatibility.<\/li>\n<li>Renamed the main plugin file, admin and OAuth asset handles, and the OAuth consent page slug to the plugin's own identity.<\/li>\n<\/ul>\n\n<h4>0.5.6<\/h4>\n\n<ul>\n<li>Added 9 BetterDocs Free operations for documents, categories, and tags.<\/li>\n<li>Preserved BetterDocs REST hooks and role capabilities while filtering writes and confirming deletion.<\/li>\n<li>Added BetterDocs integration coverage and refreshed WordPress.org release assets.<\/li>\n<\/ul>\n\n<p>For the complete release history, see https:\/\/github.com\/farvisun\/mindio-magic-mcp\/blob\/main\/CHANGELOG.md.<\/p>","raw_excerpt":"A secure MCP server for WordPress that supports Flatsome UX Builder, content automation, and site management.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ga.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/343832","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ga.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ga.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ga.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=343832"}],"author":[{"embeddable":true,"href":"https:\/\/ga.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/farvisun"}],"wp:attachment":[{"href":"https:\/\/ga.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=343832"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ga.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=343832"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ga.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=343832"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ga.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=343832"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ga.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=343832"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ga.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=343832"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}