AlphaBridge MCP — the free WordPress plugin: a native MCP server with 39 structured tools. Source of the version published on WordPress.org.
- ✓License: GPL-2.0
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
git clone https://github.com/CultureClub-dev/alphabridge-mcp-freeResumen de MCP Servers
# AlphaBridge MCP — free plugin
[](https://mcpservers.org/servers/alphabridge-mcp-com)
**Your WordPress site, managed in conversation.** AlphaBridge MCP turns a WordPress site into a
native [Model Context Protocol](https://modelcontextprotocol.io) server. Claude, ChatGPT and other
MCP clients connect over one authenticated HTTPS endpoint. They write and edit posts, pages,
media, categories and tags, reply to and moderate comments, and read widgets, site settings and
the outline of pages built with blocks or a common page builder. Every tool checks WordPress
capabilities on every single call.
The site only reads until an administrator turns on one switch for write access. Then every tool
is on; each connection keeps its access level (full, content only or read only). Switching it
off takes one click.
This repository holds the **source of the free plugin**, published on the WordPress.org plugin
directory. It is the same code WordPress.org ships.
- **Plugin page:** https://wordpress.org/plugins/alphabridge-mcp/
- **Website & documentation:** https://alphabridge-mcp.com
- **Tool reference:** https://alphabridge-mcp.com/docs.html
- **Security model:** https://alphabridge-mcp.com/security.html
## What it does
- **Native MCP endpoint** — JSON-RPC 2.0 over HTTP POST at `/wp-json/alphabridge/v1/mcp`
(protocol versions 2024-11-05, 2025-03-26, 2025-06-18 and the stateless 2026-07-28, side by
side; the newest one can be switched off). Pure PHP inside WordPress: no Node middleware, no
external service, nothing extra to host.
- **40 structured tools** across content, media, taxonomies, comments, widgets, site settings,
site info, SEO reads and search.
- **Page builders** — `wp_get_builder_layout` reads a page as an outline: its elements in page
order, with their visible text, link and image fields; elements that cannot be read safely,
such as code, forms or unknown elements, are listed as locked, with the reason and without
their content. As of 1 October 2026:
- Read: WordPress blocks, Elementor, Beaver Builder, SiteOrigin Page Builder, SeedProd,
GenerateBlocks, Kadence Blocks, Spectra, Stackable, Pagelayer, Otter Blocks and CoBlocks
(both as plain blocks), WPBakery Page Builder, Divi 4, Avada (Fusion Builder), Flatsome (UX
Builder) and Enfold (Avia Layout Builder).
- Read from the vendors' documentation and code, not yet checked on a live installation (the
answer says so): WPBakery Page Builder, Divi 4, Avada, Flatsome and Enfold.
- Recognised, not read: Brizy, Themify Builder, Zion Builder, Live Composer, Cornerstone,
Thrive Architect, Bricks, Breakdance, Oxygen 6, Oxygen Classic, BeTheme (BeBuilder), Visual
Composer Website Builder, Divi 5 and Etch.
Where a builder shows its own data and post_content is only a copy — Elementor, Beaver
Builder, SiteOrigin Page Builder and Enfold — `wp_update_post` refuses a change to the content
while the builder is active, because it would not show, and says how to change the page
instead.
`wp_get_post` names the builder a post was made with (`built_with`), `wp_list_posts` filters
by it, and `wp_duplicate_post` copies a page with its custom fields and builder data
(Elementor elements get new ids where the layout can be read, otherwise it is copied unchanged
and the answer says so; builder data only for accounts with `unfiltered_html`).
- **OAuth 2.1 with PKCE** — connect from Claude without copying tokens; the consent screen is
your own login-protected site and offers Read only, Content and Full access, each described in
one sentence, with Full preselected; the switch for write access on the site decides whether
the connection may write. Apps register with the site (RFC 7591) or identify themselves with a client
metadata document (CIMD), which the site fetches only once a logged-in user who may approve
connections opens the consent screen; that can be switched off. Header authentication
(`Authorization` / `X-Api-Key`) for clients without a Connect button.
- **Answers that name the way** — where AlphaBridge's own checks refuse a call or report a
failure, the answer says what did not work, why, and what does: the tool that finds an id, the
right it takes, the switch, the accepted values. A refusal because write access is off, the
access level or the role does not reach, or a tool is switched off adds the steps for the
person, a direct link and the request to pass it on kindly and try again; a tool of the separate
AlphaBridge MCP Pro is named as such instead of «Unknown tool». Errors WordPress itself reports
are passed on as WordPress words them.
- **Free means free** — no license keys, no registration, no usage limits, no locked features.
## Security model
Handing an AI access to a site should feel safe, so control comes first:
- **Write access off out of the box.** A new site, and every site after updating from a version
before 4.4.0, starts with *write access off*: assistants can read content, media, terms,
comments, settings and the structure of the site. Every tool that creates, changes or deletes is
refused, and so is every reading tool noted *only with write access* (in this plugin the reader
of user profile fields), with an answer that says why and leads to the switch. The main
switch *Write access for AI assistants* at the top of Settings → AlphaBridge MCP holds for every
connection (Claude, ChatGPT, Cursor and all others); an administrator switches it on after
confirming, with a ticked box, that changes take effect immediately, that it is at the site
owner's own risk and that a current backup exists. The account, the time, the version of that
notice and its wording are recorded. Switching on switches every tool on; switching off takes
one click.
- Every connection acts as a **real WordPress user**; every tool enforces the matching
capability, including object-level checks. What that user may not do, the AI cannot do.
- **Scoped connections** — read-only or content-only keys with optional expiry, rotatable in
one click.
- **Fine-tuning** — every tool is on, and switching write access on switches every tool on
again; switch single tools or whole groups off, and they vanish from the MCP surface until write
access is switched on the next time. Each tool shows a short name in the admin's language and
says whether it reads or writes.
Code reads the switch through `AB_MCP_Site_Mode` (`get()`, `is_full()`, `allows()`,
`runs_in_read()`; the slugs `read` and `full` are write access off and on); a tool that reads
code, files, the database, logs or credentials is marked with `'dangerous' => true`, which
keeps it out while write access is off. The action `ab_mcp_site_mode_changed` fires when write
access is switched, `ab_mcp_reset_switches` when a switch from off to on switched everything on
(add-ons switch their own items on there). The fine-tuning takes an add-on's fields into its one form
(filter `ab_mcp_fine_group_html`, action `ab_mcp_fine_save`).
- **Positive allowlists instead of blocklists** — arbitrary options and transients cannot be
read at all; only a fixed list of common site settings is exposed, and the settings of
registered widgets through `wp_get_widgets`, without the values whose key the credential guard
below refuses.
- **Layered meta protection** — protected keys, `is_protected_meta()` keys and two kinds of
credential-shaped key are refused: keys whose whole name is a credential word, singular or
plural (`token`, `secret`, `password`, `passphrase`, `passcode`, `pwd`, `otp`, `credential`),
and keys containing one of a fixed list of compound patterns (`api_key`, `access_token`,
`client_secret`, `license_key`, `oauth`, `_token`, `_secret`, `_password`, …). The list is
matched literally, which makes the guard deliberately conservative rather than exhaustive:
ordinary keys such as `token_count`, `password_hint` and counters such as `maxTokens` pass it,
and so do camelCase spellings such as `accessToken`. It is defence-in-depth, not the primary
control. Generic meta access additionally passes WordPress's own per-key meta capability
(`edit_post_meta` / `edit_term_meta` / `edit_user_meta`), which honours `auth_callback` rules
registered by other plugins — that is the layer doing the real work. Page-builder data that
ends up in the page as markup or code, also where a builder keeps it under a key without `_`
(such as `panels_data`, `dslc_code`, `pagelayer-data`, `brizy`, `mfn-page-items` or
`tve_updated_post`), is written through the `meta` argument of `wp_create_post` and
`wp_update_post` only for accounts with the `unfiltered_html` capability; for any other
account the call is refused before anything is written. One read-only tool
reaches further, by design: `wp_get_builder_layout`, for an account that may edit the post,
reads the page builder's own stored data of that post, protected keys included, and returns
only the visible text, link and image fields of its elements — never the raw meta, code,
styling or attributes; separate keys that hold a page's own scripts or CSS are not read at
all.
`wp_duplicate_post` copies protected keys too, into the new draft only and only for an
account that may edit the original: WordPress's own page template, featured image and list of
removed hooked blocks, and — with the `unfiltered_html` capability, because it holds markup —
the post meta of page builders, each builder's keys together or not at all. Credential-shaped
keys, the original's editing state, the meta of a revision,
builder caches and other plugins' protected keys are not copied.
- **Audit log** of every tool call, plus a fixed rate limit against request bursts.
Details: https://alphabridge-mcp.com/security.html
## Requirements
WordPress 6.5+ (tested up to 7.1) · PHP 8.0+
## Installation
Install **AlphaBridge MCP** from youLo que la gente pregunta sobre alphabridge-mcp-free
¿Qué es CultureClub-dev/alphabridge-mcp-free?
+
CultureClub-dev/alphabridge-mcp-free es mcp servers para el ecosistema de Claude AI. AlphaBridge MCP — the free WordPress plugin: a native MCP server with 39 structured tools. Source of the version published on WordPress.org. Tiene 0 estrellas en GitHub y su última actualización registrada es del 2026-10-03.
¿Cómo se instala alphabridge-mcp-free?
+
Puedes instalar alphabridge-mcp-free clonando el repositorio (https://github.com/CultureClub-dev/alphabridge-mcp-free) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar CultureClub-dev/alphabridge-mcp-free?
+
Nuestro agente de seguridad ha analizado CultureClub-dev/alphabridge-mcp-free y le ha asignado un Trust Score de 85/100 (tier: Trusted). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene CultureClub-dev/alphabridge-mcp-free?
+
CultureClub-dev/alphabridge-mcp-free es mantenido por CultureClub-dev. La última actividad registrada en GitHub es del 2026-10-03, con 1 issues abiertos.
¿Hay alternativas a alphabridge-mcp-free?
+
Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.
Despliega alphabridge-mcp-free en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/cultureclub-dev-alphabridge-mcp-free)<a href="https://claudewave.com/repo/cultureclub-dev-alphabridge-mcp-free"><img src="https://claudewave.com/api/badge/cultureclub-dev-alphabridge-mcp-free" alt="Featured on ClaudeWave: CultureClub-dev/alphabridge-mcp-free" width="320" height="64" /></a>Más MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.