{"id":300297,"date":"2026-05-08T12:14:09","date_gmt":"2026-05-08T12:14:09","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/mcp-manager\/"},"modified":"2026-08-13T20:15:19","modified_gmt":"2026-08-13T20:15:19","slug":"acrossai-mcp-manager","status":"publish","type":"plugin","link":"https:\/\/jv.wordpress.org\/plugins\/acrossai-mcp-manager\/","author":15295430,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.2.10","stable_tag":"0.2.10","tested":"7.0.4","requires":"7.0","requires_php":"8.1","requires_plugins":null,"header_name":"AcrossAI MCP Manager","header_author":"raftaar1191","header_description":"Enable\/Disable MCP Adapter Integration for WordPress","assets_banners_color":"ccdbfb","last_updated":"2026-08-13 20:15:19","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/acrossai.co\/","header_author_uri":"https:\/\/profiles.wordpress.org\/raftaar1191\/","rating":0,"author_block_rating":0,"active_installs":10,"downloads":1336,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.0.1":{"tag":"0.0.1","author":"raftaar1191","date":"2026-05-08 12:13:51"},"0.0.2":{"tag":"0.0.2","author":"raftaar1191","date":"2026-05-08 12:20:27"},"0.0.3":{"tag":"0.0.3","author":"raftaar1191","date":"2026-05-14 14:45:29"},"0.0.4":{"tag":"0.0.4","author":"raftaar1191","date":"2026-06-02 11:53:16"},"0.0.5":{"tag":"0.0.5","author":"raftaar1191","date":"2026-06-02 12:01:31"},"0.0.6":{"tag":"0.0.6","author":"raftaar1191","date":"2026-07-04 00:14:27"},"0.0.7":{"tag":"0.0.7","author":"raftaar1191","date":"2026-07-04 00:46:20"},"0.0.8":{"tag":"0.0.8","author":"raftaar1191","date":"2026-07-04 01:08:15"},"0.0.9":{"tag":"0.0.9","author":"raftaar1191","date":"2026-07-04 01:33:59"},"0.1.1":{"tag":"0.1.1","author":"raftaar1191","date":"2026-07-17 02:08:40"},"0.1.2":{"tag":"0.1.2","author":"raftaar1191","date":"2026-07-17 02:17:28"},"0.1.3":{"tag":"0.1.3","author":"raftaar1191","date":"2026-07-19 07:07:06"},"0.1.4":{"tag":"0.1.4","author":"raftaar1191","date":"2026-07-20 05:14:29"},"0.1.5":{"tag":"0.1.5","author":"raftaar1191","date":"2026-07-20 12:01:25"},"0.1.6":{"tag":"0.1.6","author":"raftaar1191","date":"2026-07-22 04:13:13"},"0.1.7":{"tag":"0.1.7","author":"raftaar1191","date":"2026-07-24 06:47:24"},"0.1.8":{"tag":"0.1.8","author":"raftaar1191","date":"2026-07-26 13:34:32"},"0.1.9":{"tag":"0.1.9","author":"raftaar1191","date":"2026-07-30 07:28:54"},"0.2.0":{"tag":"0.2.0","author":"raftaar1191","date":"2026-08-02 04:00:40"},"0.2.10":{"tag":"0.2.10","author":"raftaar1191","date":"2026-08-13 20:15:19"},"0.2.2":{"tag":"0.2.2","author":"raftaar1191","date":"2026-08-02 17:04:02"},"0.2.3":{"tag":"0.2.3","author":"raftaar1191","date":"2026-08-04 14:49:36"},"0.2.4":{"tag":"0.2.4","author":"raftaar1191","date":"2026-08-08 09:11:01"},"0.2.5":{"tag":"0.2.5","author":"raftaar1191","date":"2026-08-09 12:51:41"},"0.2.6":{"tag":"0.2.6","author":"raftaar1191","date":"2026-08-10 14:06:58"},"0.2.7":{"tag":"0.2.7","author":"raftaar1191","date":"2026-08-10 14:15:32"},"0.2.8":{"tag":"0.2.8","author":"raftaar1191","date":"2026-08-13 16:16:12"},"0.2.9":{"tag":"0.2.9","author":"raftaar1191","date":"2026-08-13 18:39:57"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon.svg":{"filename":"icon.svg","revision":3595613,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3614699,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3614699,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.0.1","0.0.2","0.0.3","0.0.4","0.0.5","0.0.6","0.0.7","0.0.8","0.0.9","0.1.1","0.1.2","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9","0.2.0","0.2.10","0.2.2","0.2.3","0.2.4","0.2.5","0.2.6","0.2.7","0.2.8","0.2.9"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3614210,"resolution":"1","location":"assets","locale":"","width":3268,"height":1874},"screenshot-10.png":{"filename":"screenshot-10.png","revision":3614210,"resolution":"10","location":"assets","locale":"","width":3268,"height":1874},"screenshot-11.png":{"filename":"screenshot-11.png","revision":3614210,"resolution":"11","location":"assets","locale":"","width":3268,"height":1874},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3614210,"resolution":"2","location":"assets","locale":"","width":3268,"height":1874},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3614210,"resolution":"3","location":"assets","locale":"","width":3268,"height":1874},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3614210,"resolution":"4","location":"assets","locale":"","width":3268,"height":1874},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3614210,"resolution":"5","location":"assets","locale":"","width":3268,"height":1874},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3614210,"resolution":"6","location":"assets","locale":"","width":3268,"height":1874},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3614210,"resolution":"7","location":"assets","locale":"","width":3268,"height":1874},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3614210,"resolution":"8","location":"assets","locale":"","width":3268,"height":1874}},"screenshots":{"1":"Settings page with client tabs for easy configuration","2":"Copy-paste ready JSON configuration","3":"One-click password generation","4":"Per-provider configuration file locations and top-level keys"}},"plugin_section":[],"plugin_tags":[2353,216196,229563,21364,242115],"plugin_category":[44,54],"plugin_contributors":[140910],"plugin_business_model":[],"class_list":["post-300297","plugin","type-plugin","status-publish","hentry","plugin_tags-ai","plugin_tags-chatgpt","plugin_tags-claude","plugin_tags-cursor","plugin_tags-mcp","plugin_category-discussion-and-community","plugin_category-security-and-spam-protection","plugin_contributors-raftaar1191","plugin_committers-raftaar1191"],"banners":{"banner":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/banner-772x250.png?rev=3614699","banner_2x":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/banner-1544x500.png?rev=3614699","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/icon.svg?rev=3595613","icon":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/icon.svg?rev=3595613","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-1.png?rev=3614210","caption":"Settings page with client tabs for easy configuration"},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-2.png?rev=3614210","caption":"Copy-paste ready JSON configuration"},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-3.png?rev=3614210","caption":"One-click password generation"},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-4.png?rev=3614210","caption":"Per-provider configuration file locations and top-level keys"},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-5.png?rev=3614210","caption":""},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-6.png?rev=3614210","caption":""},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-7.png?rev=3614210","caption":""},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-8.png?rev=3614210","caption":""},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-10.png?rev=3614210","caption":""},{"src":"https:\/\/ps.w.org\/acrossai-mcp-manager\/assets\/screenshot-11.png?rev=3614210","caption":""}],"raw_content":"<!--section=description-->\n<p>MCP Manager connects your WordPress site to any MCP-compatible AI client \u2014 Claude, ChatGPT, Cursor, VS Code, GitHub Copilot, Gemini, and more \u2014 so those clients can safely read, edit, and act on your site.<\/p>\n\n<p>Every headline section below links to the full documentation at <a href=\"https:\/\/acrossai.co\/doc-category\/mcp-manager\/\">acrossai.co\/doc-category\/mcp-manager<\/a> \u2014 the docs are the source of truth and get updated first. Source and issues live at <a href=\"https:\/\/github.com\/acrossai-co\/acrossai-mcp-manager\">github.com\/acrossai-co\/acrossai-mcp-manager<\/a>.<\/p>\n\n<h4>Key Features<\/h4>\n\n<ul>\n<li><strong>Multiple MCP servers per site<\/strong> \u2014 create, enable, disable, and configure independently. \u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-servers\/\">Docs<\/a><\/li>\n<li><strong>Multi-client connection guides<\/strong> \u2014 copy-paste-ready configs for Claude Desktop, VS Code + Copilot, GitHub Copilot, ChatGPT, Cursor, Gemini CLI, and custom clients. \u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-connect-a-client\/\">Docs<\/a><\/li>\n<li><strong>CLI browser-approval flow<\/strong> \u2014 let terminal users connect with one command; approval happens in a browser tab. \u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-cli-connections\/\">Docs<\/a><\/li>\n<li><strong>WP-CLI (STDIO) transport<\/strong> \u2014 local clients can connect through a WP-CLI subprocess with no network credential transmission. \u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-wp-cli-stdio\/\">Docs<\/a><\/li>\n<li><strong>Application Passwords under the hood<\/strong> \u2014 WordPress-native credentials, one-click generation, and revocation from the user profile page. \u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-application-passwords\/\">Docs<\/a><\/li>\n<li><strong>Per-server tool and ability curation<\/strong> \u2014 pick exactly which WordPress abilities each MCP server exposes as callable tools. \u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-tools-and-abilities\/\">Docs<\/a><\/li>\n<li><strong>Per-server access control<\/strong> \u2014 gate every MCP request by user, role, capability, or your own policy provider. \u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-access-control\/\">Docs<\/a><\/li>\n<li><strong>Frontend embeds<\/strong> \u2014 shortcode + block to show your users how to connect their AI clients from your own site. \u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-embeds-shortcode-block\/\">Docs<\/a><\/li>\n<\/ul>\n\n<h4>How It Works<\/h4>\n\n<ol>\n<li>Install and activate the plugin (<a href=\"https:\/\/acrossai.co\/docs\/mcp-install-and-activate\/\">step-by-step<\/a>)<\/li>\n<li>Open <strong>AcrossAI \u2192 MCP<\/strong> in your WordPress admin<\/li>\n<li>Pick your AI client tab (Claude, VS Code, ChatGPT, Cursor, Gemini, GitHub Copilot, or Custom)<\/li>\n<li>Generate a new Application Password with one click<\/li>\n<li>Copy the ready-made JSON config and paste it into your client<\/li>\n<li>Restart your client \u2014 it now sees your site's abilities<\/li>\n<\/ol>\n\n<p>Longer walkthrough with screenshots: <a href=\"https:\/\/acrossai.co\/docs\/mcp-getting-started\/\">Getting started \u2192 connect your first AI client<\/a>.<\/p>\n\n<h4>Connection Types<\/h4>\n\n<p>MCP Manager ships with three connection styles out of the box, plus one optional paid add-on:<\/p>\n\n<ul>\n<li><strong>MCP Client (npx bridge)<\/strong> \u2014 the default. Paste a JSON config into Claude Desktop, VS Code, Cursor, etc. Uses <code>@automattic\/mcp-wordpress-remote@latest<\/code> with a WordPress Application Password. \u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-connect-a-client\/\">Docs<\/a><\/li>\n<li><strong>CLI Connections (browser approval)<\/strong> \u2014 one command in the terminal, one click in the browser, zero password copying. \u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-cli-connections\/\">Docs<\/a><\/li>\n<li><strong>WP-CLI (STDIO)<\/strong> \u2014 local subprocess, no network credential transmission. Best for CI or local dev boxes. \u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-wp-cli-stdio\/\">Docs<\/a><\/li>\n<li><strong>AI Connectors (paid add-on)<\/strong> \u2014 one-click Claude, ChatGPT, and Grok hosted-OAuth connectors. Requires the separate <a href=\"https:\/\/acrossai.co\/ai-connectors\/\">AcrossAI AI Connectors plugin<\/a> (14-day money-back). \u2192 <a href=\"https:\/\/acrossai.co\/docs\/mcp-ai-connectors\/\">Docs<\/a><\/li>\n<\/ul>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li>WordPress 7.0 or higher<\/li>\n<li>PHP 8.1 or higher<\/li>\n<li>WordPress Application Passwords support (built-in since WP 5.6)<\/li>\n<\/ul>\n\n<h3>Support<\/h3>\n\n<ul>\n<li><strong>Docs hub<\/strong> \u2014 <a href=\"https:\/\/acrossai.co\/doc-category\/mcp-manager\/\">acrossai.co\/doc-category\/mcp-manager<\/a><\/li>\n<li><strong>Troubleshooting &amp; FAQ<\/strong> \u2014 <a href=\"https:\/\/acrossai.co\/docs\/mcp-faq-troubleshooting\/\">acrossai.co\/docs\/mcp-faq-troubleshooting<\/a><\/li>\n<li><strong>Source code + issue tracker<\/strong> \u2014 <a href=\"https:\/\/github.com\/acrossai-co\/acrossai-mcp-manager\">github.com\/acrossai-co\/acrossai-mcp-manager<\/a><\/li>\n<\/ul>\n\n<h3>Support &amp; Contribution<\/h3>\n\n<p>For issues, feature requests, or contributions, visit the plugin repository.<\/p>\n\n<p>Questions? Check the FAQ section or look for documentation in the plugin settings page.<\/p>\n\n<h3>Development<\/h3>\n\n<p>This plugin follows WordPress coding standards and best practices:\n- PHP 7.4+ compatible\n- Full object-oriented architecture\n- Secure nonce verification\n- Proper capability checks\n- Sanitized input validation\n- Escaped output<\/p>\n\n<h3>License<\/h3>\n\n<p>This plugin is licensed under the GPL-2.0-or-later license. See LICENSE file for details.<\/p>\n\n<h3>Credits<\/h3>\n\n<p>MCP Manager is built with:\n- WordPress native APIs\n- Automattic's MCP WordPress Remote package\n- WordPress Application Passwords system<\/p>\n\n<p>Developed with \u2764\ufe0f for the WordPress community.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin directory to <code>\/wp-content\/plugins\/<\/code><\/li>\n<li>Activate the plugin through the 'Plugins' menu in WordPress<\/li>\n<li>Navigate to Settings \u2192 MCP Manager to configure<\/li>\n<\/ol>\n\n<p>Or:<\/p>\n\n<ol>\n<li>Go to Admin \u2192 Plugins \u2192 Add New<\/li>\n<li>Search for \"MCP Manager\"<\/li>\n<li>Click \"Install Now\" then \"Activate\"<\/li>\n<\/ol>\n\n<!--section=faq-->\n<p>Full FAQ + troubleshooting lives at <a href=\"https:\/\/acrossai.co\/docs\/mcp-faq-troubleshooting\/\">acrossai.co\/docs\/mcp-faq-troubleshooting<\/a>. Quick answers below.<\/p>\n<dl>\n<dt id=\"are%20my%20credentials%20secure%3F\"><h3>Are my credentials secure?<\/h3><\/dt>\n<dd><p>Yes. MCP Manager uses WordPress's native Application Passwords \u2014 each one is generated by WordPress, tied to your user, revocable from the profile page, and never stored in this plugin's own tables. Full detail: <a href=\"https:\/\/acrossai.co\/docs\/mcp-application-passwords\/\">Application passwords &amp; security<\/a>.<\/p><\/dd>\n<dt id=\"can%20i%20connect%20multiple%20ai%20clients%20to%20the%20same%20site%3F\"><h3>Can I connect multiple AI clients to the same site?<\/h3><\/dt>\n<dd><p>Yes \u2014 generate a separate password (or CLI approval) per client. You can also run multiple MCP servers on the same site with different tool\/ability sets and per-server access rules. See <a href=\"https:\/\/acrossai.co\/docs\/mcp-servers\/\">MCP servers<\/a>.<\/p><\/dd>\n<dt id=\"which%20ai%20clients%20are%20supported%3F\"><h3>Which AI clients are supported?<\/h3><\/dt>\n<dd><p>Claude Desktop, ChatGPT, Cursor, VS Code (with Copilot), GitHub Copilot, Gemini CLI, and any custom MCP-compatible client. Adding a new client is a filter callback. See <a href=\"https:\/\/acrossai.co\/docs\/mcp-connect-a-client\/\">Connecting an AI client<\/a>.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20multisite%3F\"><h3>Does it work on multisite?<\/h3><\/dt>\n<dd><p>Yes \u2014 each site in the network configures independently.<\/p><\/dd>\n<dt id=\"do%20i%20need%20the%20paid%20ai%20connectors%20add-on%3F\"><h3>Do I need the paid AI Connectors add-on?<\/h3><\/dt>\n<dd><p>Only if you want the one-click hosted-OAuth flow for Claude, ChatGPT, or Grok. All other connection styles (MCP Client, CLI, WP-CLI STDIO) are free and shipped with this plugin. See <a href=\"https:\/\/acrossai.co\/ai-connectors\/\">AI Connectors add-on<\/a>.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.2.10<\/h4>\n\n<ul>\n<li><strong>Admin \u2014 Embeds tab hidden from the per-server-edit page.<\/strong> The <strong>Embeds<\/strong> tab (formerly reached at <code>?page=acrossai_mcp_manager&amp;action=edit&amp;server=&lt;id&gt;&amp;tab=embeds<\/code>) is no longer registered in <code>Registry::all_tabs()<\/code> and its self-registration in <code>Main::define_public_hooks()<\/code> (<code>EmbedsTab::register()<\/code>) is now commented out \u2014 so the tab's REST controller (<code>\/acrossai-mcp-manager\/v1\/servers\/{server_id}\/embeds<\/code>) and its React bundle (<code>build\/js\/embeds.js<\/code> + <code>.css<\/code>, ~389 KiB) no longer enqueue on the server-edit screen. Direct URL access to <code>?tab=embeds<\/code> falls through to Registry's default (first surviving tab = Overview) rather than 404 \u2014 same graceful-fallback path any unknown slug takes. Built-in tab count: 12 \u2192 11. The <code>admin\/Partials\/ServerTabs\/EmbedsTab.php<\/code> class file, the underlying <code>[acrossai_mcp_embed]<\/code> shortcode, the block, and the <code>AbstractEmbedTransport<\/code> transports in <code>includes\/Embeds\/<\/code> are all retained \u2014 hiding is admin-UI-only; the frontend embed rendering pipeline is unaffected. Re-enabling the tab is a two-line change (re-add <code>EmbedsTab::instance()<\/code> to Registry + uncomment the <code>register()<\/code> call). Tests in <code>tests\/phpunit\/Admin\/ServerTabs\/RegistryTest.php<\/code> updated: expected counts adjusted (12 \u2192 11 for canonical + database-source servers; 10 \u2192 9 for plugin-source servers); ordering array + docblock counts refreshed; a new <code>assertNotContains( 'embeds', $slugs )<\/code> line locks in the invariant.<\/li>\n<li><strong>Internal: <code>ACROSSAI_MCP_MANAGER_VERSION<\/code> constant + <code>Stable tag<\/code> bumped to <code>0.2.10<\/code> matching the plugin header.<\/strong><\/li>\n<\/ul>\n\n<h4>0.2.9<\/h4>\n\n<ul>\n<li><strong>Dependencies \u2014 bump <code>acrossai-co\/main-menu<\/code> <code>0.0.31<\/code> \u2192 <code>0.0.33<\/code>.<\/strong> The upstream vendor renamed its \"AI Connectors\" baseline Add-ons entry to <strong>AcrossAI Pro<\/strong> in <code>0.0.32<\/code> \u2014 the shared Add-ons page (<code>admin.php?page=acrossai-addons<\/code>) and Dashboard card now advertise the renamed plugin (<code>acrossai-pro\/acrossai-pro.php<\/code> install folder, <code>acrossai-pro<\/code> registry slug) instead of the former AI Connectors listing. <code>0.0.33<\/code> refreshed the AcrossAI Pro card copy \u2014 description now also mentions user access control across AcrossAI plugins \u2014 and points every AcrossAI Pro CTA (Add-ons card <code>more_url<\/code> \/ <code>learn_more_url<\/code>, Dashboard primary\/secondary CTAs) at <code>https:\/\/acrossai.co\/pricing\/#pricing<\/code>. <strong>No changes required in this plugin:<\/strong> MCP Manager's <code>AddonsFilter::remove_self()<\/code> filters the <code>acrossai_addons<\/code> list by its own slug (<code>acrossai-mcp-manager<\/code>), so the vendor's baseline entry rename doesn't affect what shows on the Add-ons page here. The per-server-edit <strong>Connectors\/Integrations<\/strong> tab still points at the separate <code>acrossai-ai-connectors<\/code> WordPress plugin (WP plugin folder slug, distinct from the vendor's addons-registry slug), so the promo card + CTA are unaffected. Transitive: <code>automattic\/jetpack-autoloader<\/code> <code>v5.0.21<\/code> \u2192 <code>v5.0.23<\/code> (patch).<\/li>\n<li><strong>Internal: <code>ACROSSAI_MCP_MANAGER_VERSION<\/code> constant + <code>Stable tag<\/code> bumped to <code>0.2.9<\/code> matching the plugin header.<\/strong><\/li>\n<\/ul>\n\n<h4>0.2.8<\/h4>\n\n<ul>\n<li><strong>\u26a0\ufe0f Security \u2014 Behavior change \u2014 MCP <code>resources\/read<\/code> and <code>prompts\/get<\/code> requests are now gated by the per-server Access Control rule (F1 fix).<\/strong> Prior to 0.2.8 the plugin only hooked the vendor's <code>mcp_adapter_pre_tool_call<\/code> filter. The two sibling pre-dispatch filters \u2014 <code>mcp_adapter_pre_resource_read<\/code> (<code>vendor\/wordpress\/mcp-adapter\/includes\/Handlers\/Resources\/ResourcesHandler.php:138<\/code>) and <code>mcp_adapter_pre_prompt_get<\/code> (<code>...\/Prompts\/PromptsHandler.php:157<\/code>) \u2014 had no subscriber. Combined with the Feature 042 transport layer intentionally deferring to F015 for rule-configured servers (returning the vendor <code>'read'<\/code> default so any authenticated user passes the transport gate, on the assumption that F015 would then enforce), any authenticated user could <code>POST {\"method\":\"resources\/read\",\"params\":{\"uri\":\"\u2026\"}}<\/code> (or <code>{\"method\":\"prompts\/get\"}<\/code>) against a server configured \"Editors only\" and the operator's rule was <strong>never consulted<\/strong>. 0.2.8 extracts the enforcement body of <code>gate_mcp_tool_call<\/code> into a shared private <code>apply_ac_gate()<\/code> helper and adds two sibling public callbacks \u2014 <code>gate_mcp_resource_read<\/code> + <code>gate_mcp_prompt_get<\/code> \u2014 wired adjacent to the existing tool-call filter in <code>Main::define_public_hooks()<\/code>. Deny path returns a <code>WP_Error<\/code> with a <code>gate<\/code> value of <code>mcp_resource_read<\/code> \/ <code>mcp_prompt_get<\/code> (previously always <code>mcp_tool_call<\/code>). Observability hooks are reused: <code>acrossai_mcp_access_control_denied<\/code> and <code>acrossai_mcp_access_control_missing_server<\/code> now fire from three MCP boundary sites \u2014 the <code>$context<\/code> arg discriminates and the <code>$subject<\/code> arg is polymorphic (tool name \/ resource URI \/ prompt name depending on which gate fired). New PHPUnit coverage at <code>tests\/phpunit\/Includes\/AccessControl\/McpDispatchGatesTest.php<\/code> \u2014 fail-open parity per gate, missing-server observability hook subject-arg carries URI\/prompt name, three-context deny-hook contract, all three vendor filter registrations verified.\n\n<ul>\n<li><strong>Operator action if you were relying on the resource\/prompt bypass<\/strong>: audit any server that exposes MCP resources or prompts AND has a rule configured. Non-privileged users who previously succeeded on <code>resources\/read<\/code> \/ <code>prompts\/get<\/code> will now receive HTTP 403 with the same <code>acrossai_mcp_access_denied<\/code> error code the tool-call gate has emitted since 0.0.7. Broaden the rule in the <strong>Access Control<\/strong> tab if the previous fail-open was intended (unlikely \u2014 most operators wanted the rule to apply).<\/li>\n<\/ul><\/li>\n<li><strong>\u26a0\ufe0f Security \u2014 Behavior change \u2014 F042 transport layer now fails CLOSED when the wpb-access-control vendor package is unavailable (F2 fix).<\/strong> Prior to 0.2.8 both access-control gates failed OPEN under the same condition: <code>AcrossAI_MCP_Access_Control::gate_mcp_tool_call<\/code> returned <code>$args<\/code> (allow) when <code>class_exists( AccessControlManager::class )<\/code> was false; <code>TransportPermissionDefault::filter_default_capability<\/code> returned the vendor <code>'read'<\/code> default under the mirror condition (<code>class_exists( RuleQuery::class )<\/code>). Because both gates degraded in the same direction, a single dependency failure \u2014 composer breakage, autoloader race on <code>rest_api_init<\/code>, missed dependency after site clone, vendor package rename \u2014 collapsed the entire two-gate stack, letting every authenticated user reach every tool on every server. 0.2.8 inverts F042's missing-vendor branch to return <code>'manage_options'<\/code> instead. Paired with F015's fail-open on the same condition, the stack now degrades to <strong>admin-only<\/strong> rather than \"wide open to every logged-in user\" when the vendor library is missing. Class docblock on <code>TransportPermissionDefault<\/code> explicitly documents the intentional asymmetry \u2014 \"F015 fails open + F042 fails closed = admin-only when the vendor breaks\" \u2014 so the invariant survives future refactors. The <code>class_exists()<\/code> call is now behind a protected <code>has_access_control_library()<\/code> seam to enable direct test coverage (<code>tests\/phpunit\/Includes\/AccessControl\/TransportPermissionMissingVendorTest.php<\/code>).\n\n<ul>\n<li><strong>Operator action<\/strong>: none in the healthy-vendor case (Composer install intact). If your deploy pipeline can produce a state where <code>vendor\/wpboilerplate\/access-control<\/code> is absent, non-admin MCP traffic will now receive 401 instead of full access. Restore the vendor package and MCP endpoints resume normal per-rule enforcement.<\/li>\n<\/ul><\/li>\n<li><strong>Admin \u2014 Server list at <code>?page=acrossai_mcp_manager<\/code> redesigned for a tighter, more actionable layout.<\/strong> Column changes: <strong>removed<\/strong> Slug (redundant with the Route\/Route Namespace columns and the Name column's inline edit link), Route Namespace + Route <strong>merged<\/strong> into a single <code>Route<\/code> column displayed as <code>&lt;namespace&gt;\/&lt;route&gt;<\/code> with duplicate slashes at the join collapsed, <strong>removed<\/strong> Version (still surfaced on the per-server-edit Overview tab). Final column order: <code>\u2610 | Name | Status | Registered From | Route | Actions<\/code>. <strong>Actions column extended<\/strong> \u2014 the existing Enable\/Disable toggle is now bundled with 5 quick-access buttons: <strong>Edit<\/strong> (primary-styled) links to the server-edit page, and four per-tab quick-links (<strong>Connectors<\/strong>, <strong>Access Control<\/strong>, <strong>Abilities<\/strong>, <strong>MCP Clients<\/strong>) jump directly to the corresponding tab on the edit page. Quick-links render as subtle rounded pill-badges with a dashicon prefix (<code>dashicons-admin-plugins<\/code> \/ <code>dashicons-shield<\/code> \/ <code>dashicons-superhero-alt<\/code> \/ <code>dashicons-admin-users<\/code>) \u2014 lighter than full buttons but more scannable than plain text links. New <code>.acrossai-actions-cell<\/code> flex wrapper in <code>src\/scss\/backend.scss<\/code> keeps the button cluster wrapping cleanly on narrow viewports; Status + Registered From columns capped at 120px so the freed horizontal space flows to Route + Actions. Preserves the existing per-row nonce on the Enable\/Disable toggle. No DB or REST changes.<\/li>\n<li><strong>UI \u2014 AI Connectors tab renamed to \"Connectors\/Integrations\".<\/strong> The per-server-edit tab label at <code>?page=acrossai_mcp_manager&amp;action=edit&amp;server=&lt;id&gt;&amp;tab=ai-connectors<\/code> now reads <strong>Connectors\/Integrations<\/strong> instead of \"AI Connectors\". Tab slug (<code>ai-connectors<\/code>) is intentionally unchanged so the last-wins tab-registration override from the <code>acrossai-ai-connectors<\/code> companion plugin keeps landing on the same placeholder \u2014 no companion-plugin coordination required. <code>AiConnectorEmbedTransport::label()<\/code> (a separate F037 embed transport) is left as-is; only the per-server-edit tab label is affected.<\/li>\n<li><strong>Internal: <code>ACROSSAI_MCP_MANAGER_VERSION<\/code> constant + <code>Stable tag<\/code> bumped to <code>0.2.8<\/code> matching the plugin header.<\/strong><\/li>\n<\/ul>\n\n<h4>0.2.7<\/h4>\n\n<ul>\n<li><strong>Docs \u2014 Fixes for the WordPress.org plugin import.<\/strong> Trimmed the <code>Tags:<\/code> header from 8 tags to 5 (<code>mcp, ai, claude, chatgpt, cursor<\/code>) \u2014 WordPress.org silently drops any tag past the fifth; the surplus (<code>copilot<\/code>, <code>vscode<\/code>, <code>gemini<\/code>) never showed up in the plugin listing anyway. Condensed the changelog for versions prior to <code>0.2.0<\/code> into a single \"Earlier versions\" pointer to the GitHub Releases page so the full changelog stays under WordPress.org's 5,000-word cap (previously ~8,258 words \u2192 the older entries were truncated on import and never rendered on the plugin page). Same information, still discoverable \u2014 just hosted on GitHub instead of duplicated in <code>README.txt<\/code>.<\/li>\n<li><strong>Internal: <code>ACROSSAI_MCP_MANAGER_VERSION<\/code> constant + <code>Stable tag<\/code> bumped to <code>0.2.7<\/code> matching the plugin header.<\/strong><\/li>\n<\/ul>\n\n<h4>0.2.6<\/h4>\n\n<ul>\n<li><strong>Refactor \u2014 <code>ConnectionMethodRegistry::get_ai_connectors()<\/code> now sources its DTOs from a new WordPress filter <code>acrossai_mcp_manager_discovery_ai_connectors<\/code> instead of calling the companion plugin's <code>ConnectorProfileRegistry<\/code> class directly.<\/strong> The paid companion (<code>acrossai-pro<\/code> 0.8.0+) hooks the new filter and returns the same DTO shape from its own registry \u2014 Discovery's <code>ai_connector<\/code> category behaves identically for end users. Removes a hardcoded FQN string (<code>\\AcrossAI_AI_Connectors\\Includes\\Connectors\\ConnectorProfileRegistry<\/code>) from the free plugin so future companion renames \/ restructures don't silently break Discovery. Fail-safe unchanged: with no companion active, the filter returns an empty array and the <code>ai_connector<\/code> category is omitted from Discovery \u2014 no fatal, no warning.<\/li>\n<li><strong>Internal: <code>ACROSSAI_MCP_MANAGER_VERSION<\/code> constant + <code>Stable tag<\/code> bumped to <code>0.2.6<\/code> matching the plugin header.<\/strong><\/li>\n<\/ul>\n\n<h4>0.2.5<\/h4>\n\n<ul>\n<li><strong>\u26a0\ufe0f Security \u2014 Behavior change \u2014 MCP endpoints default to administrators only when no Access Control rule is set (Feature 042).<\/strong> Previously, an MCP server with no rule configured in its <strong>Access Control<\/strong> tab was fail-open at the tool-call layer \u2014 any authenticated user could reach the server's <code>\/wp-json\/{namespace}\/{route}<\/code> endpoint. Starting with 0.2.5, a new runtime filter (<code>mcp_adapter_default_transport_permission_user_capability<\/code>, hooked by the new <code>\\AcrossAI_MCP_Manager\\Includes\\AccessControl\\TransportPermissionDefault<\/code> singleton) hard-blocks non-admins at the REST <code>permission_callback<\/code> stage whenever the wpb-access-control dropdown reads <strong>\"No user access added by admin\"<\/strong>. Together with the existing F015 <code>mcp_adapter_pre_tool_call<\/code> gate, this ships a <strong>two-filter, per-server permission stack<\/strong> (defense-in-depth): filter 1 hard-stops non-admin traffic on rules-less servers; filter 2 does precise per-rule enforcement on rule-configured servers. <strong>Neither filter has any hardcoded server slug or \"default server special case\"<\/strong> \u2014 both resolve the current server independently per request (filter 1 via URL route \u2192 <code>MCPServerQuery<\/code> lookup; filter 2 via <code>$server-&gt;get_server_id()<\/code>). Adding a server via <strong>Add New Server<\/strong> applies both filters automatically. <strong>Zero DB writes<\/strong> \u2014 the runtime filter approach replaced an earlier DB-row-seeding attempt (dropped via force-push on PR #71) that conflicted with the vendor UI's admin state model. Ships with a static info banner on the <strong>Access Control<\/strong> tab describing the default policy + how to broaden access via the vendor dropdown (Anyone \/ Authenticated users \/ role \/ user \/ capability). <strong>26 PHPUnit tests<\/strong> across 2 files at <code>tests\/phpunit\/Includes\/AccessControl\/<\/code> (<code>TransportPermissionDefaultTest<\/code> + <code>TransportPermissionRoleMatrixTest<\/code>) cover every filter-callback branch in isolation plus 6 user roles \u00d7 4 rule shapes \u00d7 \u22654 servers per test end-to-end (including a 5\u00d74 truth-table matrix proving per-server independence).\n\n<ul>\n<li><strong>Operator action if you were relying on the fail-open default<\/strong>: open each MCP server's <strong>Access Control<\/strong> tab, set the \"Who can access\" dropdown to the intended rule (e.g. <code>WordPress role \u2192 Editor<\/code> or <code>Anyone<\/code> for the previous behavior), and Save. Rules-less servers are now admin-only until you configure them.<\/li>\n<\/ul><\/li>\n<li><strong>UX \u2014 Cache-exclusion warning surfaces in the shared Notices submenu when the CLI (npm\/npx) connection flow is enabled (Feature 041).<\/strong> When <strong>Settings \u2192 MCP \u2192 Allow CLI connections via npm \/ npx<\/strong> (<code>acrossai_mcp_npm_login_enabled<\/code>) is ON, a persistent warning card now appears in the AcrossAI <strong>Notices<\/strong> submenu (and in the WP-native dismissible summary) instructing operators to exclude the CLI auth URL (<code>https:\/\/&lt;site&gt;\/acrossai-mcp-manager\/<\/code>) from page caching. The URL carries per-request nonces + single-use auth codes; caching plugins that treat it as static content silently break the login flow. The existing inline banner in the settings section is preserved \u2014 this feature adds a second, higher-visibility surface that co-admins and future visitors see even if they never open the specific settings section. Notice id <code>acrossai_mcp_manager_cli_auth_cache_exclusion<\/code>, source <code>MCP Manager<\/code>, gated on the option value. Uses <code>FrontendAuth::get_base_url()<\/code> for the URL \u2014 any future change to the CLI landing route propagates automatically.<\/li>\n<li><strong>Internal: <code>ACROSSAI_MCP_MANAGER_VERSION<\/code> constant + <code>Stable tag<\/code> bumped to <code>0.2.5<\/code> matching the plugin header.<\/strong><\/li>\n<\/ul>\n\n<h4>0.2.4<\/h4>\n\n<ul>\n<li><strong>Dependencies \u2014 bump <code>wpboilerplate\/wpb-access-control<\/code> <code>2.0.0<\/code> \u2192 <code>3.1.0<\/code>.<\/strong> Two vendor changes surface in the per-server <strong>Access Control<\/strong> tab (<code>?tab=access-control<\/code>): (1) new <strong>\"Any logged-in user\"<\/strong> option in the <em>Who can access<\/em> dropdown \u2014 backed by the new <code>TYPE_AUTHENTICATED<\/code> sentinel in <code>AccessControlManager<\/code> (returns <code>true<\/code> iff <code>$user_id &gt; 0<\/code>), and (2) the existing \"Everyone (no restriction)\" option is relabelled <strong>\"Public (no login required)\"<\/strong> \u2014 pure UI relabel, same underlying behavior (<code>TYPE_EVERYONE<\/code> unchanged, existing rules unaffected). v3.0.0 also removed the built-in <code>BuddyBossProfileTypeProvider<\/code> + <code>MemberPressMembershipProvider<\/code> (moved to a separate <code>acrossai\/user-access-pro<\/code> add-on); this plugin never wired them into the <em>Who can access<\/em> dropdown, so removal has no visible effect here. Docblock at <code>includes\/Main.php<\/code> refreshed to drop the stale BuddyBoss\/MemberPress reference. No data migration required.<\/li>\n<li><strong>Internal: <code>ACROSSAI_MCP_MANAGER_VERSION<\/code> constant + <code>Stable tag<\/code> bumped to <code>0.2.4<\/code> matching the plugin header.<\/strong><\/li>\n<\/ul>\n\n<h4>0.2.3<\/h4>\n\n<ul>\n<li><strong>UX \u2014 In-context nudges to install the AcrossAI Abilities Manager add-on.<\/strong> When the sibling <code>acrossai-abilities-manager<\/code> plugin is not active, the server-edit <strong>Abilities<\/strong> and <strong>Tools<\/strong> tabs (<code>?tab=abilities<\/code> \/ <code>?tab=tools<\/code>) now surface a small WordPress-native <code>notice-info<\/code> block above the picker with a link to the shared Add-ons page (<code>admin.php?page=acrossai-addons<\/code>). Without the add-on both pickers only list the three core abilities WordPress ships by default (<code>core\/get-environment-info<\/code>, <code>core\/get-site-info<\/code>, <code>core\/get-user-info<\/code>); the add-on registers a rich library of built-in abilities that populate both surfaces. Detection is a plain <code>is_plugin_active()<\/code> check \u2014 same message + same link covers both \"not installed\" and \"installed-but-off\" states. Placed after the existing \"Server is disabled\" warning and before the <code>wp_get_abilities()<\/code> capability check, so the nudge is visible even when the abilities API itself is missing.<\/li>\n<li><strong>UI \u2014 AcrossAI brand logo on the AI Connectors placeholder tab.<\/strong> Replaces the hand-rolled interconnected-nodes SVG on the AI Connectors placeholder promo (<code>?tab=ai-connectors<\/code> when the <code>acrossai-ai-connectors<\/code> companion is missing \/ inactive) with the same brand SVG the vendor uses on the shared Add-ons page (<code>https:\/\/acrossai.co\/wp-content\/uploads\/2026\/07\/acrossai-logo-2.svg<\/code>). New <code>LOGO_URL<\/code> class constant on <code>AIConnectorsPromoTab<\/code>; icon markup swapped from an inline <code>&lt;svg&gt;<\/code> inside a gradient tile to a plain <code>&lt;img alt=\"AcrossAI\"&gt;<\/code> tag; deleted the private <code>render_network_svg()<\/code> method (dead code). CSS: dropped <code>.acai-aic-promo__icon<\/code> (gradient background + colored SVG) in favor of <code>.acai-aic-promo__logo<\/code> (<code>height: 48px; max-width: 180px; object-fit: contain<\/code>) so the brand mark sits cleanly without a decorative background box.<\/li>\n<li><strong>Refactor \u2014 Renamed the \"MCP Tracker\" tab to \"Logs\".<\/strong> The per-server tab formerly reached at <code>?tab=mcp-tracker<\/code> is now <code>?tab=mcp-log<\/code>, and the tab-bar label reads <strong>Logs<\/strong> instead of <strong>MCP Tracker<\/strong>. Priority slot 80 preserved so the tab-bar ordering is unchanged. Class name <code>McpTrackerTab<\/code> kept (internal identifier) along with the body copy that identifies the third-party <a href=\"https:\/\/wordpress.org\/plugins\/mcp-tracker\/\">MCP Tracker plugin on WordPress.org<\/a> (WPVMCPT) product name \u2014 those aren't the tab label, they're a specific product reference. Deep links to the old <code>?tab=mcp-tracker<\/code> fall through to Registry's \"first surviving tab\" default (Overview) rather than 404. Test fixture updated: five <code>'mcp-tracker'<\/code> occurrences in <code>RegistryTest.php<\/code> migrated to <code>'mcp-log'<\/code>.<\/li>\n<li><strong>Docs \u2014 Rewrote <code>README.txt<\/code> as a lean docs-hub pointer.<\/strong> The plugin's WordPress.org readme now defers to <a href=\"https:\/\/acrossai.co\/doc-category\/mcp-manager\/\">acrossai.co\/doc-category\/mcp-manager<\/a> as the source of truth for every feature description \u2014 copy lives in one place instead of drifting between two. Description condensed to a two-line multi-client pitch; <strong>Key Features<\/strong> reshaped to reflect the current feature set (multiple servers per site, per-server tool\/ability curation, per-server access control, frontend embeds, CLI + WP-CLI STDIO transports) with each bullet linking to its docs page; <strong>How It Works<\/strong> trimmed to the 6-step get-started path; new <strong>Connection Types<\/strong> section calls out the four supported paths (MCP Client, CLI Connections, WP-CLI STDIO, and the paid <a href=\"https:\/\/acrossai.co\/ai-connectors\/\">AI Connectors add-on<\/a>); <strong>Requirements<\/strong> bumped to WordPress 7.0+ \/ PHP 8.1+ (matches the plugin header \u2014 old readme had drifted to 5.9 \/ 7.4); FAQ trimmed from 7 questions to 5 with a new \"Do I need the paid AI Connectors add-on?\" entry; new <strong>Support<\/strong> section links to docs hub, FAQ page, and GitHub issue tracker. Header tags expanded (<code>chatgpt<\/code>, <code>cursor<\/code>, <code>gemini<\/code> added). Deleted the stale post-F040 <strong>Experimental Direct Claude Connectors<\/strong> section, the CLI-flow deep dive, and the Provider Configuration Paths list \u2014 those live in the docs now.<\/li>\n<li><strong>Internal: <code>ACROSSAI_MCP_MANAGER_VERSION<\/code> constant + <code>Stable tag<\/code> bumped to <code>0.2.3<\/code> matching the plugin header.<\/strong><\/li>\n<\/ul>\n\n<h4>0.2.2<\/h4>\n\n<ul>\n<li><strong>Notices \u2014 migrated persistent-condition banners to the cross-plugin <code>acrossai_notices<\/code> filter.<\/strong> The \"MCP adapter package missing\" and \"wpb-access-control library missing\" warnings no longer render as inline <code>admin_notices<\/code> banners on every screen. They're pushed into the shared collection introduced in <code>acrossai-co\/main-menu<\/code> 0.0.30, which surfaces them in two consolidated places: (1) a <strong>Notices submenu<\/strong> under the AcrossAI parent menu (with a count bubble; the page also stays reachable when the count is zero and renders an \"All clear\" empty state per the 0.0.31 fix) and (2) a <strong>single WP-native dismissible summary<\/strong> on every other admin page. Dismissal is now fingerprint-based (per-user meta <code>_acrossai_notices_summary_fp<\/code>) \u2014 adding, resolving, or renaming a notice re-shows the summary automatically. <strong>Deletions<\/strong>: <code>Notices::render_missing_adapter_notice<\/code>, <code>Notices::handle_adapter_notice_dismissal<\/code>, <code>ADAPTER_DISMISS_META_KEY<\/code>, <code>ADAPTER_DISMISS_NONCE_ACTION<\/code>, <code>AcrossAI_MCP_Access_Control::maybe_show_library_notice<\/code>, and the US4 dismiss-persistence handler in <code>src\/js\/backend.js<\/code> \u2014 all obsoleted by the shared summary. <strong>Additions<\/strong>: <code>Notices::register_shared_notices()<\/code> returns records with ids <code>acrossai_mcp_manager_adapter_missing<\/code> (type <code>error<\/code>) and <code>acrossai_mcp_manager_wpb_access_control_missing<\/code> (type <code>warning<\/code>), both scoped with <code>source: 'MCP Manager'<\/code>. One-shot action-result flashes (<code>?notice=&lt;slug&gt;<\/code>) stay on the standard <code>admin_notices<\/code> hook \u2014 page-scoped transient messages don't fit the shared collection model.<\/li>\n<li><strong>UI \u2014 Redesigned the AI Connectors placeholder tab as a centered sales card.<\/strong> When the <code>acrossai-ai-connectors<\/code> companion add-on is not installed or not active, the AI Connectors tab on the server-edit page (<code>?page=acrossai_mcp_manager&amp;action=edit&amp;server=&lt;id&gt;&amp;tab=ai-connectors<\/code>) now renders a vertically-centered polished card sourced from https:\/\/acrossai.co\/ai-connectors\/ \u2014 headline (\"Connect WordPress to Claude, ChatGPT &amp; Grok in one click\"), supported-client pills (Claude \u00b7 ChatGPT \u00b7 Grok), four benefit bullets, a purple CTA (\"Install add-on\" \/ \"Activate add-on\" depending on companion state), a \"Learn more\" link, and a 14-day money-back trust line. State resolution unchanged \u2014 Registry's last-wins dedup at priority 35 still swaps the placeholder out for the companion's real <code>AIConnectorsTab<\/code> the moment the add-on activates.<\/li>\n<li><strong>Dependencies: bump <code>acrossai-co\/main-menu<\/code> <code>0.0.29<\/code> \u2192 <code>0.0.31<\/code>.<\/strong> 0.0.30 shipped the shared <code>acrossai_notices<\/code> filter + Notices submenu + <code>SummaryNoticeEmitter<\/code>. 0.0.31 fixed a \"Sorry, you are not allowed to access this page.\" error on direct visits to <code>admin.php?page=acrossai-notices<\/code> when the notice count was zero (page callback is now always wired; empty-state sidebar row is hidden via inline <code>&lt;style&gt;<\/code> on <code>admin_head<\/code> rather than <code>remove_submenu_page()<\/code>, which had desynced <code>$_registered_pages<\/code>).<\/li>\n<li><strong>Internal: <code>ACROSSAI_MCP_MANAGER_VERSION<\/code> constant + <code>Stable tag<\/code> bumped to <code>0.2.2<\/code> matching the plugin header<\/strong> (backfills the <code>Stable tag<\/code> drift that persisted since 0.2.0).<\/li>\n<\/ul>\n\n<h4>0.2.1<\/h4>\n\n<ul>\n<li><strong>Security \u2014 Defended REST + AJAX response paths against full-page cache poisoning.<\/strong> Full-page caches (LiteSpeed Cache, WP Rocket, W3 Total Cache, WP Super Cache, host-level FastCGI cache) don't honor arbitrary <code>Cache-Control: no-store<\/code> headers when making caching decisions \u2014 they gate on <code>DONOTCACHEPAGE<\/code> (WordPress-community convention) and their admin exclusion list. Companion fix to <code>acrossai-ai-connectors<\/code> 0.5.3 PR #13 (<code>DEC-OAUTH-DONOTCACHEPAGE-PATTERN<\/code>). New <code>includes\/Utilities\/CacheHeaders.php<\/code> \u2014 port of the utility from <code>acrossai-ai-connectors<\/code> \u2014 applies a three-pronged defense (constant + headers + WP filter) on every per-session and per-server response emission surface: <code>GET \/servers\/{id}\/abilities<\/code>, <code>GET \/servers\/{id}\/tools<\/code>, <code>GET \/auth\/status<\/code>, <code>GET \/servers<\/code>, <code>POST \/auth\/start<\/code>, <code>POST \/auth\/exchange<\/code>, <code>POST \/generate-app-password<\/code>, and the <code>wp_ajax_acrossai_mcp_dismiss_adapter_notice<\/code> AJAX endpoint. Prevents cross-server data leaks (per-server ability\/tool rosters bleeding into other sessions) and stale-response classes (cached <code>{approved:false}<\/code> served after the flip to <code>true<\/code>). Also fixes plugin-header vs <code>ACROSSAI_MCP_MANAGER_VERSION<\/code> constant drift \u2014 B5 bug pattern (constant lagged at 0.1.9 while header sat at 0.2.0). Both now aligned at 0.2.1.<\/li>\n<\/ul>\n\n<h4>0.2.0<\/h4>\n\n<ul>\n<li><strong>Dependencies: bump <code>acrossai-co\/main-menu<\/code> <code>0.0.27<\/code> \u2192 <code>0.0.29<\/code>.<\/strong> Picks up the shared main-menu package's latest baseline for the 0.2.0 release cycle.<\/li>\n<li><strong>Feature 040 \u2014 Migrated the AI Connectors + OAuth stack to the companion plugin <code>acrossai-ai-connectors<\/code> (v0.5.0+).<\/strong> MCP Manager now ships only the free-tier <code>tab=npm<\/code> and <code>tab=clients<\/code> connection paths; the OAuth click-to-connect flow (Claude Web, ChatGPT connectors, Grok) plus the AI Connectors admin tab now live in the paid <code>acrossai-ai-connectors<\/code> add-on. Token \/ client \/ auth_code storage is unchanged \u2014 same table names (<code>wp_acrossai_mcp_oauth_clients<\/code>, <code>_tokens<\/code>, <code>_auth_codes<\/code>, <code>wp_acrossai_mcp_connector_approved_users<\/code>), same BerlinDB <code>db_version_key<\/code>s, no data migration. REST namespace kept as <code>acrossai-mcp-manager\/v1<\/code> for RFC 8414 discovery compatibility. Existing Claude\/ChatGPT\/Grok OAuth connections continue to authenticate transparently when the add-on is installed \u2014 zero re-authorization required. <strong>Free users updating without the add-on are undisturbed<\/strong> (mcp-manager remains standalone-activatable; the AI Connectors tab simply doesn't appear). <strong>Deletions<\/strong>: entire <code>includes\/OAuth\/<\/code>, <code>includes\/Connectors\/<\/code>, <code>includes\/Database\/{OAuthClients,OAuthTokens,OAuthAuthCodes,ConnectorApprovedUsers}\/<\/code>, <code>admin\/Partials\/ServerTabs\/AIConnectorsTab.php<\/code>, <code>templates\/oauth\/consent.php<\/code>, <code>src\/js\/ai-connectors.js<\/code>, <code>src\/scss\/ai-connectors.scss<\/code>, all <code>build\/js\/ai-connectors.*<\/code> artifacts, and all associated PHPUnit tests. <strong>Modifications<\/strong>: <code>Activator.php<\/code>, <code>Deactivator.php<\/code> (retains unconditional cron-clear as belt-and-suspenders per FR-004), <code>Main.php<\/code> (drops all OAuth REST route + infra wiring + 4 OAuth-table bootstrap\/reconcile calls), <code>admin\/Main.php<\/code> (drops <code>maybe_enqueue_ai_connectors_app()<\/code>), <code>admin\/Partials\/ServerTabs\/Registry.php<\/code> (drops built-in <code>AIConnectorsTab<\/code> entry \u2014 companion re-registers via existing <code>acrossai_mcp_manager_server_tabs<\/code> filter at priority 35), <code>uninstall.php<\/code> (drops OAuth DROP TABLE lines + cron-clear + narrows the <code>acrossai_mcp_%<\/code> option sweep to exclude <code>acrossai_mcp_connector_%<\/code>), <code>webpack.config.js<\/code> (drops <code>js\/ai-connectors<\/code> entry), and <code>public\/Discovery\/ConnectionMethodRegistry.php<\/code> (FR-019: swaps <code>ConnectorProfileRegistry<\/code> FQN to the companion namespace and guards with <code>class_exists()<\/code> so the discovery API returns an empty <code>ai_connector<\/code> category when the add-on is absent). <strong>Coordination invariant<\/strong>: the companion at v0.5.0+ has been audited across 44 checks (23 structural readiness + 21 wiring counterparts) and is deployable \u2014 the migration is atomic via the companion's <code>class_exists( '\\AcrossAI_MCP_Manager\\Includes\\OAuth\\AuthorizationController' )<\/code> self-disable probe. <strong>No compat shim, no <code>Requires Plugins:<\/code> header, no admin notice<\/strong> \u2014 per clarifications Q4\/Q5\/Q6, this feature adds ZERO new code (pure deletions + header version bump). Durable lesson captured: when a subsystem gets its own plugin, prefer code-only migration (identical table names, identical version keys, byte-identical BerlinDB Table subclass declarations) over data-migration.<\/li>\n<\/ul>\n\n<h4>Earlier versions<\/h4>\n\n<ul>\n<li>For changelog entries prior to 0.2.0 (versions 0.1.9 \u2192 0.0.1), see the full release history on GitHub: https:\/\/github.com\/acrossai-co\/acrossai-mcp-manager\/releases<\/li>\n<\/ul>","raw_excerpt":"Connect WordPress to Claude, ChatGPT, Cursor, VS Code, Copilot, Gemini and any MCP-compatible AI client \u2014 with per-server access control.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/300297","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=300297"}],"author":[{"embeddable":true,"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/raftaar1191"}],"wp:attachment":[{"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=300297"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=300297"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=300297"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=300297"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=300297"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=300297"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}