A clear WordPress outcome
Turn a repetitive correction into one controlled result
Describe the WordPress result you want, then keep the request narrow enough to check when it is done.
1
Name the result
State the content change in reader terms, such as making phone numbers clickable tel: links across 25 articles.
2
Use the native WordPress surface
MCP Expose Abilities exposes 79 registered WordPress abilities through MCP, giving an AI assistant the native operation relevant to the result.
3
Set the scope
Tell the assistant which content is in scope and what must stay unchanged. Keep the request narrow enough to check when it is done.
4
Verify the result
Check the affected content against the task you named before expanding the request. The documented example made phone numbers clickable tel: links across 25 articles in 30 seconds; it is an example, not a general performance promise.
Ownership and access
Keep the WordPress outcome clear and the product boundary honest
This plugin exposes WordPress-native work. Vendor-specific behavior belongs elsewhere, so choose the surface that owns the result.
Core
Core WordPress ownership
MCP Expose Abilities provides the WordPress-native outcomes on this page. It does not claim product-specific behavior from third-party systems.
Add-ons
Optional vendor add-ons
Vendor-specific behavior belongs in separate optional add-on plugins. Choose an add-on only when the result depends on that vendor’s product.
Complete native surface
79 abilities across eleven WordPress outcome groups
Each group below states its exact ability count and the complete reader outcomes in that group.
7
Comments, 7 abilities
List comments, inspect one comment, create a comment or reply, update its status or author URL, or delete one comment.
27
Content, 27 abilities
Create a category, page, post, or tag. Delete a page or post. Find the next post, or inspect one page, post, or revision. List categories, media, pages, posts, revisions, tags, or users. Apply a bounded patch to a page or post. Restore a post or one revision. Search content. Update a category, discussion state, page, post, or tag.
5
Media, 5 abilities
Inspect one media attachment, upload media from a URL, upload validated file bytes, update an attachment, or delete an attachment.
8
Menus, 8 abilities
List menus, create a menu, assign it to a theme location, inspect its items, add an item, create or update one item without creating a duplicate, update an existing item, or remove an item.
3
Post metadata, 3 abilities
Read one named post metadata key, update that key, or delete that key under the shared metadata policy.
3
Options, 3 abilities
List available options, read one option, or make a targeted option update.
11
Plugins, 11 abilities
List installed plugins, list available updates, search the official plugin directory, activate a plugin, deactivate one, switch one plugin to the requested activation state, install from the directory, upload a package from a URL, upload validated package bytes, update a plugin, or delete one.
4
System diagnostics, 4 abilities
Inspect ability timings, inspect the debug log, read one named transient, or read and toggle the bounded debug state.
1
Taxonomy, 1 ability
Associate one native taxonomy with one post type.
7
Users, 7 abilities
Create, delete, inspect, list, or update users. Create a restricted WordPress Application Password, or revoke the Application Password used by the current authenticated request.
3
Widgets, 3 abilities
List available widgets, list registered sidebars, or inspect the configuration of one sidebar.
Required stack
Dependencies
These three components provide the native ability, runtime, and MCP connection layers.
WordPress 6.9 or later
WordPress Abilities API in WordPress 6.9 or laterProvides the native registration and execution interfaces used by all 79 core abilities.
PHP 8.0 or later
PHP 8.0 or laterRuns the MCP Expose Abilities plugin code.
Required for MCP client access
WordPress MCP AdapterExposes registered WordPress abilities to authenticated MCP clients.
Permission and protected settings
Let WordPress control what the assistant can change
The plugin keeps its most consequential boundary in WordPress itself: the authenticated MCP request must cross the site’s permission check, and protected bootstrap settings remain out of reach.
Permission
MCP transport permission
The MCP transport defaults to the WordPress manage_options capability. An authenticated request without that capability does not cross the default transport boundary.
Protected options
Protected bootstrap settings stay unchanged
Options such as template and stylesheet can affect theme bootstrap, so they are protected from MCP updates. The options update operation rejects protected option names instead of changing them through MCP.
Ready for a defined WordPress result
Download MCP Expose Abilities for one defined WordPress result
Download the stable MCP Expose Abilities ZIP to give an AI assistant a native WordPress surface for one defined result. You then have the plugin package to connect to your MCP client for the named WordPress change.
