NV Digital Open Operator System (NV oOS)
OfficialIntegrates Cloudflare's AI models for language processing and inference.
Provides a toolkit and dashboard for managing Cloudways hosting environments, including server management and deployment.
Offers adapters for integrating the system with Craft CMS, enabling content management and AI-powered features.
Provides Elementor widgets that allow users to add AI-powered chat and content generation to Elementor-built pages.
Integrates Google Gemini AI models for multimodal understanding, content generation, and chat.
Provides access to Hugging Face's model inference API for a wide range of AI models.
Offers adapters for integrating the system with Laravel applications, enabling AI capabilities within Laravel projects.
Integrates NVIDIA NIM for accelerated AI model inference and content generation.
Provides integration with Ollama to run local AI models for chat, generation, and agentic tasks.
Primary AI provider integration providing access to GPT models, including streaming, function calling, and agentic loops.
Allows building Telegram Mini Apps that interface with the system's AI capabilities for chat and automation.
Core integration enabling AI-powered management of WordPress sites, including posts, pages, media, user interactions, and site settings.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@NV Digital Open Operator System (NV oOS)publish a new blog post about AI trends"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
NV Digital Open Operator System (NVoOS)
Version: 1.1.91 Release Date: 2026-10-01
See ยง Release History for the 12 most recent releases; every older release is in the Previous Releases table. Full detail: CHANGELOG.md.
๐ v1.1.91 Highlights: FlowHub MCP mode, MCP App OAuth discovery, and OAuth redirect allowlists. FlowHub Connection MCP mode (#6836) โ a flowhub_mode selector on FlowHub Remote Sites connections (MCP mode designates the connection as the FlowHub toolkit MCP server backend) with proxy inheritance: MCP-triggered refresh/sync calls route through the explicit-connection path (decrypted credentials + the connection's encrypted proxy via http_api_curl); explicit connection_id always wins and the seam is generic. MCP App OAuth discovery per MCP spec (#6835) โ the full discovery chain (RFC 8414 + ยง3.2 path insertion, RFC 9728 protected-resource metadata, 401 WWW-Authenticate probe, OIDC + WordPress REST fallbacks) with per-attempt diagnostics surfacing real transport errors. OAuth redirect allowlists (#6831/#6832) โ LinkedIn, QuickBooks, Mailjet, and Yahoo connect buttons no longer bounce to wp-admin. JSON envelope protection (#6827) โ orchestration CCTs gate on the physical table and the new WP_MCP_AI_Db_Output_Guard wraps central tool dispatch. Security-events display + double-render fixed (#6829/#6830). Dependency advisories (#6833/#6834) โ nodemailer 10.x + fast-uri floors. Tool count: ~347 base + ~1,301 Pro (~1,648 total; unchanged). Stale 1.1.89 build ZIPs removed (30 files).
MCP Specification: 2026-07-28 (Stateless Core, Full Compliance)
Maintained by NV Digital
License: GPLv3 or later
Requires: WordPress 6.0+, PHP 7.4+
Patent Status: Patent Pending (Application #19/410,504)
Documentation: Grade A (95/100) โ 1,617 files across 12 directories, 108 admin screenshots, 100% feature coverage
๐ For Reviewers & Auditors
New to this repo? Start here โ
docs/project/FOR_REVIEWERS.mdThat document answers every common question in one place: what the project is, current security posture, what's production vs experimental, PHP version requirements, AI development methodology, compliance status, and scoping advice for a limited-budget review.
Quick links for reviewers:
Addon Inventory โ what each of 28 addons does and its status
Security Posture โ current state of all 50 audit findings
Compliance Traceability โ every .org rejection reason โ commit โ verification command
AI-Assisted Development โ methodology, transparency, and what to scrutinize
Architecture Overview โ component diagram and data flow
Related MCP server: WP MCP Ultimate
๐ Table of Contents
Getting Started
Core Functionality
Addons & Extensions
Orchestration & AI Features
AI Providers & Integration
Performance & Optimization
Remote MCP Setup
Assistant Management
Development
Reference
Changelog
๐บ Repository Map
Directory | Purpose |
| Core plugin classes โ admin, assistants, tools, services, REST, security (10 infrastructure classes), providers (~15 AI backends), harness, data, markup, measurement, skills, professions, teams, slash-commands, A2A/ACP protocols, federation, elementor, blocks, crawler, integrations |
| Framework-agnostic AI orchestration engine (nvoos/core): 32 domain contracts, 21 WordPress adapters, ChatOrchestrator, ProviderRouter, ToolRegistry, SkillRegistry โ PHP 8.1+ |
| 28 installable addons (Pro, Chat SPA, Docs Hub, SaaS Controller, Cloud Worker, Cloudways Dashboard, Toolkit Shell, Canvas, Canvas Toolkit, Document Editor, Media Studio, Media Worker, Graphify, Comic Reader, Funiq Bridge, Fleet Operator, Algorave, Cornerstone3D, Crocoblock DS, Embedded, Fantasy Football, LibreChat, Schedule Anything Platform, Schedule Anything SPA, Tenant Router, Page Agent, Checkout API, mcp-wordpress-gateway) |
| Frontend JS/CSS, images, CSV templates, examples |
| 61 coding-time agent skills for Zed editor (20 wp-* WordPress plugin development patterns + 33 design-* skills + mcp-ai-wpoos-plugin operational guide + mcp-ai-wpoos-test-suite repair guide + mcp-ai-wpoos-updates maintenance guide + mcp-ai-wpoos-wporg-submission wp.org readiness guide + mcp-ai-wpoos-ecosystem-port port-loop guide + mcp-ai-wpoos-assistant-portability export/import guide + mcp-ai-wpoos-playground-demos Playground demo blueprint guide + mcp-ai-wpoos-dependabot-loop alert-triage guide) |
| 6 BMAD workflow agent YAML definitions + team composition config |
| Subsystem context files (10 topics + 5 templates) for agent session loading |
| Standalone plugins: NVOOS Content Graph, NVOOS Content Graph AI, NVOOS Content Graph AI Platform |
| 23 NPM packages under |
| TMA (Telegram Mini App) builders + workflow builder source |
| Shared source code across builds |
| Standalone "core" distribution ( |
| Site blueprints |
| Agent and workflow example code |
| Hermes WebUI dashboard extensions (fleet monitoring/control plane, backup-download, external-app-tab, mcp-tool-shortcuts) |
| PHPUnit test suite |
| Comprehensive documentation (~1,600 files across 12 directories) |
| Development and deployment scripts |
| Docker Compose configuration |
| Translation files (.pot/.po/.mo) |
| Dependency patches |
| CI/CD workflows (~30 pipelines), custom agents, Copilot instructions |
๐งฉ Overview
Real-time AI Orchestration Toolkit / Harness for Wordpress - NV oOS is a modular AI framework (Object-Oriented System) for WordPress that connects your site's data with 15 language-model providers: OpenAI, Gemini, Anthropic, DeepSeek, OpenRouter, Baseten, Kimi (Moonshot), Z.AI (GLM), DigitalOcean, NVIDIA NIM, Cloudflare Worker AI, Ollama, LM Studio, Hugging Face, and Flowhub. It allows you to create and manage AI Assistants that can interact with users, access WordPress data, and perform custom tool functions.
โจ What's New at a Glance (v1.1.91)
๐ FlowHub Connection MCP mode (PR #6836). FlowHub Remote Sites connections gain a
flowhub_modeselector (apidefault |mcp) โ MCP mode designates the connection as the backend for the FlowHub toolkit MCP server.WP_MCP_AI_FlowHub_Connection_Helper::get_mcp_connection_id()resolves the first enabled MCP-mode connection and the toolkit MCP REST controller injects its ID into tool arguments only when the caller passes none โ MCP-triggered refresh/sync calls now route through the explicit-connection path so credentials and the connection's encrypted proxy apply viahttp_api_curl. Explicitconnection_idalways wins; without an MCP-designated connection, behavior is byte-for-byte unchanged. The seam is generic (WP_MCP_AI_Toolkit_Server_Base::get_mcp_connection_id()).๐ MCP App OAuth discovery per MCP spec (PR #6835).
discover_metadata()now walks the full chain โ RFC 8414 metadata (+ ยง3.2 path insertion for path-scoped servers), RFC 9728 protected-resource metadata (trying everyauthorization_serversentry), the 401WWW-Authenticateprobe, OIDC fallback for Auth0/Okta/Cognito, and WordPress REST fallback. RFC 8414 docs are accepted only with both endpoints; every attempt is logged and the metabox failure alert surfaces the real transport error; server-advertiseddefault_scopeis honored; multi-challengeWWW-Authenticateparsing; 10 s per-probe cap.๐ OAuth redirect allowlists (PRs #6831, #6832). LinkedIn, QuickBooks, Mailjet, and Yahoo Sports connect buttons no longer silently bounce to wp-admin โ each flow now allowlists its consent-page host (
www.linkedin.com,appcenter.intuit.com,app.mailjet.com,api.login.yahoo.com) via theallowed_redirect_hostsfilter, with matching ports in the Content Graph AI platform.๐ก JSON envelope protection (PR #6827). Orchestration CCT reads gate on the physical table (
table_exists()โis_storage_ready(): table + every required column โ schema drift trips the gate and falls back to transients); the newWP_MCP_AI_Db_Output_Guardwraps the central tool dispatch (execute_tool()+ both REST tool handlers) so no surface can leak$wpdberror HTML into a JSON response again โ the 5-second orchestration dashboard poll'sparsererror: Unexpected token '<'failure is gone.๐ Security events display + double-render fixed (PRs #6829, #6830). The Security tab's "Recent Security Events (last 10)" table and the compliance CSV exporter now read the canonical
event_type/ip_addresskeys (with legacy fallbacks), label known event slugs, and show display names; the orchestration dashboard no longer renders twice (a duplicate loader instantiation registered two callbacks on the same page hook).๐งฉ RF-DETR presets + coverage manifest (PR #6828).
rfdetr_catalog_searchjoins theecommercepreset;rfdetr_detectstays gated behind the vision-analysis toolkit (matching its siblings); the Pro tool coverage manifest is regenerated โ the RF-DETR cluster's CI failures are closed.๐ Dependency advisories (PRs #6833, #6834).
nodemailer^9.1.1โ^10.0.9inaddons/pro+addons/media-worker(GHSA-g57g-f23g-4646 โ vendor bundle refreshed with the oldlib/removed);fast-urioverride floor โ>=4.1.5across the four alert-bearing trees (GHSA-jvvf-x445-j334) โ four Dependabot alerts closed each.๐ Ecosystem port (PR #6825). The RF-DETR vision cluster (Roboflow service,
rfdetr_detect, count normalizer, e-commerce catalog search, dHash copy, standalone init) ports byte-identical intonvoos-content-graph-proโ Wave F3 sub-cluster 1 complete, tracker row appended.๐ฆ Versioning โ bumped to 1.1.91 across all version-bearing files. Pro addon: 1.1.91. Media Worker: v3.2.0 (unchanged โ the nodemailer bump carries no version change). SaaS Controller: 0.3.0 (unchanged). Design System addon: 0.3.0 (unchanged). nvoos-content-graph: 1.0.8 (unchanged). nvoos-content-graph-ai: 1.0.4 (unchanged). nvoos-content-graph-ai-platform: 2.0.0 (unchanged โ OAuth ports + build refresh). nvoos-content-graph-pro: 1.0.0 (unchanged โ two in-feature ports landed). Checkout API: 0.1.2 (unchanged). Docs Hub: 0.5.1 (unchanged). Comic Reader: 0.5.0 (unchanged). Chat SPA: 0.7.0 + Canvas Toolkit: 0.2.0 (unchanged). Model catalog: v2026.09.22 (unchanged). Tool count: ~347 base + ~1,301 Pro (~1,648 total โ unchanged). Provider count: 15 chat providers (unchanged). Addon count: 28 (unchanged). Bundled skills: 75 base + 41 Pro (unchanged). Coding-time agent skills: 61 (unchanged). Stale build ZIPs removed: the 1.1.89 build set (30 files).
๐ฏ Mission: Modernizing Small to Medium Business Websites
NV oOS is specifically designed to help small to medium-sized businesses fast-track their outdated, stale, or insecure company websites to modern technology standardsโwithout the need to add yet another wrapper around API calls. Instead, we're trying to peel back decades of API wrappers with the help of AI, providing:
Direct AI Integration - No middleware required. Connect directly to OpenAI, Gemini, Anthropic, Hugging Face, Cloudflare Worker AI, Ollama, LM Studio, OpenRouter, and DeepSeek without custom development
Security-First Architecture - Built-in protection against nefarious usage with active monitoring and prevention systems
Enterprise-Grade Features - Access to capabilities typically requiring expensive custom development
Compliance & Audit Tools - Comprehensive logging, rate limiting, and usage tracking built-in
Zero Technical Debt - Modern codebase following WordPress standards, ready for current technology stacks
๐ก Active Security Monitoring
NV oOS actively prevents and monitors against nefarious behavior. The plugin includes:
Nefarious Usage Monitor - Real-time detection of suspicious patterns and automatic emergency shutdown capabilitiesใF:includes/class-wp-mcp-ai-nefarious-usage-monitor.phpโ L1-L676ใ
Root Security Key - Optional emergency authentication layer to prevent unauthorized reactivation after security incidentsใF:docs/features/security/root-security-key.mdโ L1-L511ใ
Granular Capability Controls - Every tool and API endpoint enforces WordPress capabilities to prevent unauthorized access
Rate Limiting - Built-in protection against abuse with configurable limits per user, model, and time period
Comprehensive Audit Logging - Track all API calls, tool executions, and security events for compliance and forensic analysis
Input Sanitization & Output Escaping - All user input sanitized, all output escaped following WordPress security best practices
This is not a tool for circumventing security or promoting bad practices. Every feature is designed with security, transparency, and responsible AI usage as core principles. The plugin actively works to stop and prevent misuse before it happens.
Latest audit: See docs/operations/compliance/SECURITY_AUDIT_2026_04.md โ the published summary of the April 2026 security & compliance code review (no Critical findings; 5 High items, 3 Fixed and 2 Partially Fixed). Full deliverables under docs/project/audits/2026-04/.
WordPress.org compliance hardening (May 9, 2026): docs/operations/compliance/WORDPRESS_ORG_COMPLIANCE_2026_05_09.md โ findings B3, B8, B10, B13, and production vendor remap all resolved.
โ Warranty & Safe Use
We make every effort to keep NV oOS safe and secure โ but by design, it can be destructive and resource-intensive when not properly configured.
NV oOS grants AI assistants access to powerful WordPress operations. The same capability that automates real work can cause irreversible harm if misconfigured:
Destructive tools โ bulk content deletion, user management, file writes, mass email, WP-CLI, direct database operations
API billing exposure โ uncapped AI provider calls can exhaust quotas and trigger unexpected charges
Server resource exhaustion โ concurrent agentic loops and SSE streams can saturate CPU/memory on shared hosting
Before going live: test on staging, take verified backups, apply least-privilege tool permissions, enable rate limiting, and review the system prompt of every public-facing assistant.
๐ Full details: WARRANTY.md โ security commitment, "AS IS" disclaimer, destructive-operations table, resource-consumption guide, and mitigation checklist aligned with OWASP, NIST SP 800-53, ISO/IEC 27001, and the WordPress Plugin Developer Handbook.
Patent Pending
NV oOS is the subject of a pending patent application for its novel System and Method for Dynamic AI Orchestration Layer with Real-Time Capability Gating and Resource Budgeting.
Application Number: 19/410,504
The patent covers NV oOS's innovative approach to implementing sophisticated AI orchestration in WordPress's request-based PHP architectureโa platform not designed for real-time streaming, asynchronous operations, or persistent state management. This technical achievement enables enterprise-grade AI capabilities on WordPress by recreating event-driven behavior within PHP's synchronous execution model.
Key Innovations Covered:
Dynamic resource budget allocation during streaming operations
Capability-based access control for AI tool execution
Registry-state-based scheduling in stateless environments
Metrics-driven budget adjustment for real-time optimization
Persistent-behavior illusion in request-based architectures
The orchestration layer makes NV oOS unique in the WordPress ecosystem by solving fundamental architectural limitations that prevent traditional WordPress plugins from supporting advanced AI features. See the System Architecture section below for technical details on how these innovations work together.
๐ System Architecture
NV oOS implements a comprehensive orchestration layer for managing AI operations during real-time streaming events. The system architecture comprises:
15 language-model providers โ OpenAI, Gemini, Anthropic, DeepSeek, OpenRouter, Baseten, Kimi (Moonshot), Z.AI (GLM), DigitalOcean, NVIDIA NIM, Cloudflare Worker AI, Ollama, LM Studio, Hugging Face, Flowhub
~1,648 tool classes (~347 base + ~1,301 Pro; live count via
WP_MCP_AI_Tool_Registry::get_tools()is authoritative) registered through a singleton Tool Registry36 REST controllers (16 base + 20 pro) under the
mcp-ai/v1namespace64 service classes powering orchestration, budgets, and workflows
5 authentication methods โ WordPress nonce, assistant credentials, mesh keys, Auth0 JWT, guest tokens
Toolkit MCP servers โ per-toolkit JSON-RPC 2.0 servers exposed under
/wp-json/mcp-ai-pro/v1/mcp/{slug}; discoverable at/.well-known/mcp8 inline-async-tick consumers โ cooperative tick-lock pattern eliminates WP-Cron startup latency for background jobs (transcript mining, async tool executor, SaaS Apply, Crawl4AI, Docs Hub rebuild, Graphify reindex, Harness eval, Gemini Veo polling)
7 LLM Harness layers (+ 1 Pro) โ opt-in epistemic layers AโH activated per-assistant via the LLM Harness metabox
Orchestration Phases 1โ7 โ HITL approval queue, prompt-injection detector, structured output, OTel exporter, DAG builder, durable runs, triggers/webhooks, sub-agents
๐ For a detailed explanation of how NV oOS extends standard SSE and MCP protocols with novel orchestration features, see ORCHESTRATION-LAYER-ARCHITECTURE.md
Core Orchestration Layer: Overcoming PHP's Limitations
Critical Context: Most real-time AI streaming systems are built with Node.js, Python FastAPI, or Go โ platforms designed for asynchronous, event-driven operations. These platforms natively support:
Long-lived connections and persistent state
Non-blocking I/O and parallel execution
Event loops and asynchronous callbacks
WebSocket protocols and SSE streaming
NV oOS achieves the same capabilities in PHP/WordPress โ an environment fundamentally not designed for these patterns โ through a sophisticated orchestration layer that creates a "persistent-behavior illusion":
Real-Time Budget Enforcement - Monitors token/memory usage during streaming, prevents exhaustion through predictive allocation
Capability-Based Tool Gating - WordPress role-based access control for AI tool execution
Predictive Optimization - Analyzes usage patterns to prevent resource overruns before they occur
Distributed Orchestration - Multi-provider support with policy-aware routing
Auditability & Compliance - Complete governance layer with logging and rate limiting
Cron-Based Task Orchestration - Extends orchestration to async operations with budget inheritance
Multi-Agent Orchestration Enhancement (DeepSeek V4-Inspired)
Added: January 2026 (v1.1.0)
Building upon the core orchestration layer, NV oOS now includes a sophisticated multi-agent coordination framework inspired by DeepSeek V4's orchestration patterns:
Key Components:
Agent Role System - Four specialized roles (Planner, Executor, Critic, Specialist) with role-specific capabilities
Team Composition - Automated team assembly based on task requirements and profession expertise
Coordinated Workflows - Multi-step workflows with agent delegation, result aggregation, and validation
Team CPT Integration - Persistent team configurations with orchestration modes (single/sequential/parallel/swarm)
Profession-Based Discovery - 296 professions auto-assigned agent roles via intelligent seeding across 17 knowledge bases
Example Multi-Agent Workflow:
// 1. Compose research team (planner + executors + critic)
$orchestrator = new WP_MCP_AI_Agent_Team_Orchestrator();
$team = $orchestrator->compose_team( array( 'task_type' => 'research' ) );
// 2. Execute coordinated workflow
// Planner decomposes task โ Executors research subtasks โ
// Communication service aggregates โ Critic validates quality
$result = $orchestrator->execute_team_workflow( $team, $task, $context );Documentation:
See Multi-Agent Orchestration for complete technical details
See DEEPSEEK-V4-README.md for documentation suite overview
See DEEPSEEK-V4-USAGE-GUIDE.md for practical examples
Why This Architecture Is Novel: Overcoming PHP's Limitations
Event loops and background workers
PHP/WordPress, by contrast, is fundamentally request-based:
Every HTTP request spawns a new process that dies after responding
I/O operations block execution
No persistent memory between requests
No native event loop or async coordination
NV oOS solves this by implementing an orchestration layer that creates a "persistent-behavior illusion" โ effectively recreating Node.js's event loop behavior within WordPress's synchronous, request-based architecture. This architectural compensation is the system's core technical innovation:
PHP Limitation | NV oOS Solution |
No persistent state | Registry & policy engine maintain state via database/cache |
No event loop | Cron Manager extends orchestration across time-shifted operations |
Blocking I/O | Predictive budget allocator prevents blocking operations |
Request-based lifecycle | SSE controller implements streaming within request boundaries |
No background workers | WordPress cron system simulates async job processing |
This makes NV oOS patent-worthy as a technical workaround โ it achieves sophisticated AI orchestration in an environment specifically not designed for such patterns. See ORCHESTRATION-LAYER-ARCHITECTURE.md for the complete technical analysis.
Computer-Implemented Resource Management
The system operates as a computer-implemented method executing on a processor with memory, performing:
Dynamic Resource Budget Allocation: The orchestration layer dynamically allocates token and memory budgets to tool execution requests based on real-time system capacity and operation requirements. The
WP_MCP_AI_Resource_Managercontinuously monitors server resources (PHP memory limits, execution time constraints) and automatically adjusts operational parameters.Capability-Based Access Control: Tool execution endpoints enforce granular capability-based access controls. Each tool in the registry declares required WordPress capabilities, and the REST API controller validates user permissions before allowing execution. This ensures secure, policy-driven access to all operations.
Registry-State-Based Scheduling: The
WP_MCP_AI_Tool_Registrymaintains tool availability state and schedules execution based on policy constraints. Tools are loaded conditionally based on dependency availability, and execution is scheduled according to assistant configuration and user permissions.Metrics-Driven Budget Adjustment: The system continuously monitors execution metrics (memory usage, API response times, token consumption) and adjusts resource budgets in response to prevent resource exhaustion and reduce latency. The
WP_MCP_AI_Token_Budget_Managerimplements safety margins and dynamic chunking to prevent API limit overruns.
System Components
The system comprises a processor and memory storing instructions that:
Monitor real-time resource availability through PHP runtime introspection
Enforce capability checks at REST endpoint boundaries
Schedule tool execution through a centralized registry
Adjust token and memory budgets based on detected system metrics
Maintain operation logs for audit and optimization
This architecture is embodied in non-transitory computer-readable media (PHP source files) that, when executed by a web server processor, cause the system to perform the complete resource management workflow. The implementation prioritizes stability, security, and efficient resource utilization across diverse hosting environments.
Symfony Process Integration (December 2025)
NV oOS Pro addon integrates the Symfony Process component for secure external command execution. This modern framework replaces direct exec() calls in 6 Pro tools and 2 supporting services, providing:
Enhanced Security: Proper argument escaping and command validation
Timeout Management: Configurable timeouts with graceful handling
Better Error Handling: Comprehensive exception catching and WordPress-friendly error reporting
Process Control: Real-time output streaming and cancellation support
Migrated Tools & Services:
FFmpeg operations (video frame extraction, metadata reading)
Python rembg (background removal)
WP-CLI execution
Meta AI Jukebox (music generation)
Supporting services for video and audio processing
The Process Service (WP_MCP_AI_Process_Service) provides WordPress-friendly wrappers with WP_Error integration, making external process execution consistent with WordPress coding standards.ใF:includes/services/class-wp-mcp-ai-process-service.phpโ L1-L220ใใF:docs/history/2025/implementations/symfony-phases/SYMFONY_PHASE2B_PROCESS_INTEGRATION.mdโ L1-L100ใ
๐ Release History
The 12 most recent releases are documented in full below. Every older release has a one-line summary in the Previous Releases table, and complete per-release detail lives in CHANGELOG.md.
v1.1.91 โ October 1, 2026
FlowHub MCP Mode, OAuth Discovery & JSON Envelope Protection
๐ FlowHub Connection MCP mode (PR #6836). FlowHub Remote Sites connections gain a
flowhub_modeselector (apidefault |mcp) โ MCP mode designates the connection as the backend for the FlowHub toolkit MCP server.WP_MCP_AI_FlowHub_Connection_Helper::get_mcp_connection_id()resolves the first enabled MCP-mode connection; the toolkit MCP REST controller injects itsconnection_idinto tool arguments only when the caller passes none โ MCP-triggered refresh/sync calls route through the explicit-connection path so decrypted credentials and the connection's encrypted proxy apply viahttp_api_curl. Explicitconnection_idalways wins; without an MCP-designated connection, behavior is byte-for-byte unchanged; the seam is generic (WP_MCP_AI_Toolkit_Server_Base::get_mcp_connection_id()).๐ MCP App OAuth discovery per MCP spec (PR #6835).
WP_MCP_AI_MCP_App_OAuth_Client::discover_metadata()walks the full chain โ RFC 8414 metadata (+ ยง3.2 path insertion for path-scoped servers), RFC 9728 protected-resource metadata (trying everyauthorization_serversentry), the 401WWW-Authenticate: Bearer resource_metadataprobe, OIDC fallback, and WordPress REST fallback. RFC 8414 documents are accepted only with both endpoints; every attempt is recorded (URL โ HTTP status / transport error) and the metabox failure alert surfaces the real transport error; server-advertiseddefault_scopeis honored;parse_www_authenticate()splits multiple challenges per RFC 7235 ยง2.1; 10 s per-probe cap.๐ OAuth redirect allowlists (PRs #6831, #6832). LinkedIn, QuickBooks, Mailjet, and Yahoo Sports connect buttons no longer silently bounce to wp-admin โ each flow allowlists its consent-page host (
www.linkedin.com,appcenter.intuit.com,app.mailjet.com,api.login.yahoo.com) via theallowed_redirect_hostsfilter, deriving the host from the provider's authorize-endpoint filter; matching ports land in the Content Graph AI platform.๐ก JSON envelope protection (PR #6827). Orchestration CCT reads gate on the physical table โ
table_exists()probe โis_storage_ready()(table present and every required column; schema drift trips the gate โ transients fallback, logged; per-request cache with areset_storage_cache()seam). The newWP_MCP_AI_Db_Output_Guard::run()suppresses$wpdberror output around callbacks (logging failures with the last query) and wraps the central tool dispatch โexecute_tool()+ both REST tool handlers โ so no surface can leak database error HTML into a JSON response again; the four agent-command-center read AJAX handlers gainwith_suppressed_db_errors().๐ Security events display + double-render fixed (PRs #6829, #6830). The Security tab's "Recent Security Events (last 10)" table and the compliance CSV exporter now read the canonical
event_type/ip_addresskeys (with legacy fallbacks), label known event slugs, and show user display names (Guest for unauthenticated) โ stored entries were always correct, only the display keys were wrong. The orchestration dashboard no longer renders twice: the self-instantiating class gained a duplicatenewin the bootstrap loader, registering two distinct callbacks on the same page hook (duplicate DOM IDs breaking the auto-refresh JS) โ the redundantnewis removed.๐งฉ RF-DETR presets + coverage manifest (PR #6828).
rfdetr_catalog_searchjoins theecommercepreset ("Product operations");rfdetr_detectstays deliberately out of presets (gated behindenable_vision_analysis_toolkit, matching its siblings); the Pro tool coverage manifest is regenerated with the two missing class basenames.๐ Dependency advisories (PRs #6833, #6834).
nodemailer^9.1.1โ^10.0.9inaddons/pro+addons/media-worker(GHSA-g57g-f23g-4646, alerts #977/#978 โ quoted local-part envelope injection) with the vendor copy spec switched todist/(nodemailer 10 ships no top-levellib/) and the vendor bundle refreshed 8.0.5 โ 10.0.9;fast-urioverride floor โ>=4.1.5across the four alert-bearing trees (GHSA-jvvf-x445-j334, alerts #979โ#982 โ mailto header injection), verified additive-only via npm-pack diff.๐ Ecosystem port (PR #6825). The RF-DETR vision cluster ports byte-identical into
nvoos-content-graph-proโ the Roboflow inference service (three trust tiers, fail-closed credentials, SSRF/HTTPS discipline),WP_MCP_AI_Tool_Rfdetr_Detect, the vision count normalizer, the e-commerce catalog search (44-tool e-commerce registration), the D8-compat image-dHash copy, and the slim standalone init with thetoolkit_vision_analysismodule gate โ dual-matrix green with the documented deviations; tracker row F3 appended (sub-cluster 1 complete).๐ฆ Versioning โ bumped to 1.1.91 across all version-bearing files. Pro addon: 1.1.91. Media Worker: v3.2.0 (unchanged โ the #6833 nodemailer bump carries no version change). SaaS Controller: 0.3.0 (unchanged). Design System addon: 0.3.0 (unchanged). nvoos-content-graph: 1.0.8 (unchanged). nvoos-content-graph-ai: 1.0.4 (unchanged). nvoos-content-graph-ai-platform: 2.0.0 (unchanged โ OAuth ports + build refresh). nvoos-content-graph-pro: 1.0.0 (unchanged โ two in-feature ports landed: the RF-DETR cluster (#6825) and the FlowHub MCP-mode mirrors (#6836)). Checkout API: 0.1.2 (unchanged). Docs Hub addon: 0.5.1 (unchanged). Comic Reader addon: 0.5.0 (unchanged). Chat SPA addon: 0.7.0 + Canvas Toolkit addon: 0.2.0 (unchanged). Model catalog: v2026.09.22 (unchanged โ no model PRs in-window). Tool count: ~347 base + ~1,301 Pro (~1,648 total โ unchanged) โ no tool registrations in-window (FlowHub MCP mode is a connection-binding seam; #6828 only wires the existing RF-DETR pair into presets/manifest; live registry authoritative). Provider count: 15 chat providers (unchanged). Addon count: 28 (unchanged). Bundled skills: 75 base + 41 Pro (unchanged). Coding-time agent skills: 61 (unchanged). Stale build ZIPs removed: the 1.1.89 build set (30 files: 9 in
build/incl. 3.sha256, 2 inbuild/optional-components/, 19 inbuild/toolkit-addons/).
v1.1.90 โ September 30, 2026
RF-DETR Vision Cognition, Strict MCP Scope & Memory Identity Closure
๐ RF-DETR vision cognition (PR #6824, Proposal 049). New Pro
WP_MCP_AI_Roboflow_Inference_Serviceโ one HTTP client across three trust tiers (key-less self-hosted Docker Inference server on loopback/private hosts; dedicated deployments; Serverless Cloud API) with fail-closed credentials (va_roboflow_api_keyas the rawAuthorizationheader for serverless/dedicated, HTTPS enforced off-loopback, every URL passes the SSRF guard, operator-allowlist seam). Two new Pro tools โrfdetr_detect(task=detect|segment|keypoints: ranked boxes, instance-segmentation mask polygons, 17-COCO person keypoints) andrfdetr_catalog_search(fine-tuned catalog models by alias or workspace/project/version, per-model + dHash 5-min transient cache) โ returning the canonical{label, confidence, box, mask_points?, keypoints?}shape. Theroboflowprovider joinsanalyze_image_objects(detector-owns-the-count invariant, no new slug);identify_imagerung 3c reportsrfdetr_detectionsas an additional source (class-guarded โ Base installs skip withpro_addon_required/not_configured, zero behavior change). Apache-2.0 aliases by default; XL/2XL (PML 1.0) behind theva_roboflow_allow_pmlconsent toggle. RF-DETR settings section (Vision Analysis) + deployment guide (docs/operations/deployment/roboflow-inference-server-setup.md).๐ผ Upwork MCP as first-class MCP Apps references (PR #6823). Upwork-in-MCP-mode Remote Sites connections now appear in the assistant MCP Apps metabox "Add from Remote Sites" dropdown (labelled
Name (Upwork MCP โ https://mcp.upwork.com/mcp)) with the full OAuth login UI (web login / loopback paste-back / authenticated state).resolve_connection_ref()resolves Upwork refs at chat time viabuild_upwork_mcp_app_config()(official gateway + decrypted centralmcp_oauth); the import validator no longer auto-disables Upwork refs;finalize_oauth_flow()persists the reference entry onto the assistant so it survives the post-login reload.๐ง Memory identity resolution + cross-agent access closure (PR #6815). All eight memory tools (
retrieve_agent_memory,store_agent_context,recall_memory,wake_up_context,semantic_context_search,mine_agent_memory,manage_context_lifecycle,batch_manage_memory) accept an optionalagent_idand otherwise resolve the caller's identity from the execution context viaWP_MCP_AI_Agent_Identity_Resolver. Cross-agent access gated behindmanage_options(403mcp_ai_memory_scope_deniedโ the IDOR closed); 400mcp_ai_memory_no_agentwhen no identity resolves; every success envelope echoesresolved_agent_id+resolution_source.store_agent_contextscans for credential patterns (incl. the plugin's owncred_โฆ<secret>format) flaggedsensitive_patterns/contains_sensitive;retrieve_agent_memorycarries expiry signalling (expires_in,expires_soonโค7 days).๐ก Strict MCP assistant-scope toggle (PR #6819). Opt-in
mcp_require_assistant_scope(Security โ Access & Identity, default OFF): MCPtools/list+tools/callfail closed with HTTP 403 (wp_mcp_ai_assistant_scope_required) when no assistant resolves (no explicitassistant_id, no token-bound assistant, no default assistant). Sharedmaybe_enforce_strict_scope()gatesmcp_tools_list()after the resolve/scope chain andmcp_tools_call()before the tool executor; the 403 special-case is scoped to this one error code (all other errors keep the HTTP 200 JSON-RPC envelope). Closes #6769.โ๏ธ Letterhead email personalization (PR #6816). The letterhead template renders
Dear {{to_name}},; the renderer gains{{#to_name}}โฆ{{/to_name}}conditional blocks (bare addresses never emitDear ,);get_builtin_html()prefers thedirectfilesystem transport with a plain local-read fallback โ bundled templates no longer silently no-op on hosts wheredirectis unavailable.๐ Dependency advisories (PR #6817).
js-yamloverrides โ>=5.4.1across 13 package trees (lockfiles โ 5.4.2) + scopedwebpack-dev-middleware@^8โ>=8.3.0(root +addons/pro/assets/spa) โ 15 of 17 open Dependabot alerts resolved; 13 lockfiles regenerated +npm ci --dry-runverified; the AI SDK 2.x-line advisory stays open intentionally (syncโasync signature change would breakuseChat) โ tracked as #6818.๐ฆ Versioning โ bumped to 1.1.90 across all version-bearing files. Pro addon: 1.1.90. Media Worker: v3.2.0 (unchanged). SaaS Controller: 0.3.0 (unchanged). Design System addon: 0.3.0 (unchanged โ the letterhead/registry fix ships on the 0.3.0 line). nvoos-content-graph: 1.0.8 (unchanged). nvoos-content-graph-ai: 1.0.4 (unchanged). nvoos-content-graph-ai-platform: 2.0.0 (unchanged). nvoos-content-graph-pro: 1.0.0 (unchanged โ the RF-DETR ecosystem port is open as #6825). Checkout API: 0.1.2 (unchanged). Docs Hub addon: 0.5.1 (unchanged). Comic Reader addon: 0.5.0 (unchanged). Chat SPA addon: 0.7.0 + Canvas Toolkit addon: 0.2.0 (builds refreshed in-window). Model catalog: v2026.09.22 (unchanged โ Roboflow is a vision inference service outside the catalog). Tool count: ~347 base + ~1,301 Pro (~1,648 total; +2 Pro) โ the RF-DETR pair; the
roboflowprovider is no new slug andidentify_imagerung 3c is additive-only (live registry authoritative). Provider count: 15 chat providers (unchanged). Addon count: 28 (unchanged). Bundled skills: 75 base + 41 Pro (unchanged). Coding-time agent skills: 61 (+1 โ the dependabot-loop skill). Stale build ZIPs removed: the 1.1.88 build set (30 files: 9 inbuild/incl. 3.sha256, 2 inbuild/optional-components/, 19 inbuild/toolkit-addons/).
v1.1.89 โ September 29, 2026
Google Classroom ECA, Design System Rename + Email Templates & Upwork MCP Mode
๐ Google Classroom integration for the ECA toolkit (PR #6809, Proposal 046). Shared
includes/google/Classroom foundation mirroring the Calendar stack โScopes(restricted-scope discipline, granular-consent implication checks),Client(REST v1, repeated-parameter building, page-token pagination,RESOURCE_EXHAUSTEDbackoff, terminal@MissingGrant,updateMaskPATCH),Credentials(Pro Remote Sites resolution, decrypt-on-read, quota-user attribution),Push(Pub/Sub webhook with shared-secret verification, ack-fast cron deferral, weekly renewal). Newgoogle_classroomRemote Sites connection type (OAuth on the shared service, realcourses.listtest probe withneeds_reconnect). 12 new ECA tools (list_classroom_courses,sync_classroom_roster_to_students,sync_classroom_courses_to_ecas,link_classroom_course_to_eca,create_classroom_course,update_classroom_course,post_classroom_announcement,create_classroom_coursework,list_classroom_submissions,classroom_course_analytics,list_classroom_guardians,manage_classroom_push_watch) behindenable_eca_classroom_integration(default off) with a nightly jittered sync engine + push-delta roster/course reconciliation. New base REST routemcp-ai/v1/google-classroom/webhook.๐จ Design System addon rename + token-driven email templates (PR #6810, Proposals 047 + 048).
addons/crocoblock-ds/โaddons/nvoos-design-system/(0.1.0 โ 0.3.0, zero-breakage:--cds-*/.cds-*aliases, one-way option migration,class_alias, legacy admin-post action). Token-driven email module: 5 built-in accessible templates, globalwp_mailwrapper (sentinel double-wrap guard, full-document + text/plain skips), 15-tokenemailsgroup with dark-mode pairs, WCAG/EMC audit gates (contrast math, BLOCK gates, 100 KB budget), multipartAltBodypairing, opt-in WooCommerce rebrand, Paper Store mirror/import bridge. 8 admin-gatednds_*tools (generate/list/preview/audit/set-active/test-send/export/import) โ addon-provided viawp_mcp_ai_register_tools, not counted in base/Pro totals. Two latent addon bugs fixed (double-prefixed CSS vars that never matched component CSS; a broken integration autoloader that silently disabled all four integrations).๐ผ Upwork MCP connection mode (PR #6804). Third
upwork_mode(mcp) alongsideapiandweb_searchโ talks to the official Upwork MCP gateway (https://mcp.upwork.com/mcp, 51upwork__*tools) through a sessionfulWP_MCP_AI_Upwork_MCP_Bridge(upwork__find_jobs/upwork__list_accounts, defensive normalization);search_upwork_jobs/import_upwork_projectbranch to the bridge with_external_source_id/_external_source_platformdedupe meta; real-handshake Test Connection;upwork_org_uidresolution; OAuth login reuses the MCP Apps flow (connection_refon/oauth/init) with tokens in the encrypted centralmcp_oauthstore.๐ผ Vision + remote reliability + EZuite integrity (PR #6805).
submit_document_promptroutes image attachments through theinput_imagevision segment path (previously rejected on every provider) with provider-bound client selection;WP_MCP_AI_DeepSeek_Clientconvertsinput_imageto OpenAI-compatibleimage_urlblocks fordeepseek-flash(thewp_mcp_ai_deepseek_supports_visionfilter gates the payload); DeepSeek gains avisionlane. Remote connections check access controls against canonical slugs (page/attachment) and surface actionablerest_no_routeguidance; EZuite enforces the requesteditem_codeclient-side (no more wrong-product stock/pricing) and fixes "Untitled Product" cards; the model catalog migration now rewrites per-provider model settings (deepseek_model,default_gemini_model,anthropic_model,kimi_model) at the next catalog bump.โก MCP legacy-dialect handshake cache (PR #6802).
WP_MCP_AI_MCP_App_Client::handshake()caches a 24h per-URL legacy hint (wp_mcp_ai_mcp_app_legacy_<md5(url)>) so strict 2025-era gateways skip the doomedserver/discoverprobe; stale hints self-heal on stateless rejections;test_connection()+ registrydiscover_tools()delegate to it. Upwork Test Connection: ~24.9s โ ~8.5s steady state.๐ก Security (PRs #6807 + #6806). All 38 CodeQL alerts closed โ 0 open code scanning alerts (DOM XSS escaping in the diagnostic page, CSPRNG OAuth1 nonces in the twitter-api-v2 vendor bundle,
health-consolidate.jshardening, yfinance cleanup);ip-addressโ 10.7.2 (NAT64 SSRF),undicifloors 7.29.1/8.10.2/6.28.1 (WebSocket DoS),multerโ 2.4.0 (orphaned writes) across every affected tree.๐ฆ Versioning โ bumped to 1.1.89 across all version-bearing files. Pro addon: 1.1.89. Media Worker: v3.2.0 (unchanged). SaaS Controller: 0.3.0 (unchanged). Design System addon: 0.1.0 โ 0.3.0 (own track โ the in-window inventory row said 0.2.0, corrected this pass). nvoos-content-graph: 1.0.8 (unchanged). nvoos-content-graph-ai: 1.0.4 (unchanged). nvoos-content-graph-ai-platform: 2.0.0 (unchanged). nvoos-content-graph-pro: 1.0.0 (unchanged โ one byte-identical in-feature port: the product-card trait, #6805). Checkout API: 0.1.2 (unchanged). Docs Hub addon: 0.5.1 (unchanged). Comic Reader addon: 0.5.0 (unchanged). Model catalog: v2026.09.22 (unchanged). Tool count: ~347 base + ~1,299 Pro (~1,646 total) โ +12 Pro (the classroom tools; the 8
nds_*tools are addon-provided and not counted; live registry authoritative). Provider count: 15 chat providers (unchanged). Addon count: 28 (unchanged โ rename, not addition). Bundled skills: 75 base + 41 Pro (unchanged). Coding-time agent skills: 60 (unchanged โ four updated in place). Stale build ZIPs removed: the 1.1.87 build set (30 files: 9 inbuild/incl. 3.sha256, 2 inbuild/optional-components/, 19 inbuild/toolkit-addons/).
v1.1.88 โ September 28, 2026
Decision-Model Orchestration, MCP Apps Hardening & SaaS Controller 0.3.0
๐ง Decision-model orchestration Phase A (PR #6792, Proposal 045). The TypeSafe Jev decision model wires into the router and orchestration layers for the first time. Base:
WP_MCP_AI_Verification_Cascadeimplements the SDE-cascade pattern (build_battery()per-field nouls framed bad=true, one batched decision call chunked at 50, max aggregation, single-rung escalation, injectableInterface_WP_MCP_AI_Decision_Client, filterablewp_mcp_ai_cascade_escalate_thresholddefault 0.7) plus the newwp_mcp_ai_execution_depth_confidencefilter seam inexecute_with_depth(). Pro: opt-inenable_jev_tier_routingtier routing (code-owned(2 โ complexity)/2confidence, neutral 0.65 fallback, caller signals always win,decision_modelmetadata) and opt-inenable_jev_citation_escalationcitation cascade (two-head battery per claim,escalate_flagged_citations()verification-tier revision capped viawp_mcp_ai_citation_escalation_max) wired intoresearch_eca+generate_research_report. Fail-open everywhere, off by default, only the first user message ever reaches Jev, thresholds stay in PHP. Gap review:docs/project/audits/2026-09/decision-model-orchestration-gap-review.md. Deferred: extraction cascade + G2/G3/G4/G6โG8.๐ MCP Apps OAuth + credential hardening (PRs #6794/#6795/#6798). Upwork accepts only loopback redirect URIs โ
initiate_oauth()falls back toredirect_mode: manual_loopbackon DCRinvalid_redirect_uriand the admin pastes the localhost callback into the newPOST mcp-ai/v1/mcp-apps/oauth/completeendpoint (10-minute state TTL, sharedfinalize_oauth_flow(), JSON-first with form-encoded retry on 415).client_idis sent in token-exchange/refresh bodies (Upwork requires it) and the paste-back box survives reloads. Inline MCP App secrets (token,oauth_data) + Remote Sitesverify_token/verification_tokenare now encrypted at rest (AES-256-CBC) and masked in forms; rotated tokens persist (inline meta,update_mcp_oauth(), tool-bridge re-hydration); Test/Discover restores stored OAuth credentials (fixes "No OAuth access token available");mcp_oauth_refreshactivity events carry metadata only.๐ก Toolkit MCP servers gated on assistant grants (PR #6796). Deny-by-default:
handle_jsonrpc()requires an explicit grant for assistant-scoped requests (params.assistant_id) โ non-granted servers return-32601 "Server not granted to this assistant";initialize/pingstay ungated andtoolkitServersalways reflects the exact grant list (empty allowlist = no grants, per the corrected UI copy); assistant_id-less requests bypass the gate; the server-level toggle is unchanged. CG Pro mirror byte-identical.๐ MCP App transport fixes (PRs #6799 + #6800). Strict 2025-era gateways that reject the
server/discoverprobe with a bare HTTP 400 (no JSON-RPC envelope) now trigger the legacyinitializefallback (400/404/405/501), and legacy sessions omit the 2026-onlyMCP-Protocol-Version/Mcp-Methodheaders +_metaenvelope; HTTP-errorWP_Errors carry a 400-char body snippet. SSE-answering gateways (Envoy AI Gateway / Agent Router) no longer fail enumeration with "invalid JSON" โsend_request()detects SSE via Content-Type ordata:sniffing andparse_sse_payload()extracts themessageevent (dedicatedwp_mcp_ai_mcp_app_empty_ssefor empty streams).๐ Upwork job-link canonicalisation round-trip (PRs #6790 + #6793). The canonical marketplace form is restored to
https://www.upwork.com/jobs/<slug>_~<jobId>/(per vanooo/upwork-mcp's live-SPA scraper โ #6790's/freelance-jobs/apply/form still produced wrong links); login-walled SPA surfaces (/nx/โฆ,/o/jobs/โฆ,/r/โฆ) are dropped as non-listings (except/nx/search/jobs/details/~<jobId>โ bare-id form); tracking query strings dropped; MCP OAuth web login surfaces real errors and the callback route renders the friendly error page for auth-server denials.๐ฉน PayHere/Flowhub guarded requires (PR #6801). A production install missing
includes/class-wp-mcp-ai-payhere-client.phpfatalled on every request duringplugins_loadedโ all 8 affected tool files nowfile_exists()-guard their dependency requires sois_available()self-reports unavailable, and the 7 Flowhub tools return canonicalWP_Errors (wp_mcp_ai_flowhub_client_missing/wp_mcp_ai_flowhub_helper_missing) instead of fatals.โ๏ธ SaaS Controller 0.1.0 โ 0.3.0 (PRs #6791 + #6797) + gateway express bump (#6787). 0.2.0 ships the production NV oOS Cloud worker (byte-identical port from
addons/cloud-worker/src/,diff -qverified;compatibility_flags: ['nodejs_compat'];worker:dryrunfixed; jest + flat eslint repaired). 0.3.0 (Phase 12) folds Worker secrets + D1 schema into Plan/Apply (worker_secretrows resolve from the encrypted credential store at Apply time, values never in plans or audit logs; comment/PRAGMA-stripped idempotentCREATE TABLE IF NOT EXISTSvia the D1/rawendpoint) โ the whole NV oOS Cloud deployment runs from WP-Admin. The mcp-wordpress gateway pinsexpress@4.22.3, closing Dependabot alerts #897/#899/#900/#902 (0 vulnerabilities, 22/22 tests).๐ฆ Versioning โ bumped to 1.1.88 across all version-bearing files. Pro addon: 1.1.88. Media Worker: v3.2.0 (unchanged). SaaS Controller: 0.1.0 โ 0.3.0 (own track). nvoos-content-graph: 1.0.8 (unchanged). nvoos-content-graph-ai: 1.0.4 (unchanged). nvoos-content-graph-ai-platform: 2.0.0 (unchanged). nvoos-content-graph-pro: 1.0.0 (unchanged โ three byte-identical in-feature ports: Upwork URL round-trip #6790/#6793, toolkit grant gating #6796). Checkout API: 0.1.2 (unchanged). Docs Hub addon: 0.5.1 (unchanged). Comic Reader addon: 0.5.0 (unchanged). Model catalog: v2026.09.22 (unchanged). Tool count: ~347 base + ~1,287 Pro (~1,634 total) โ unchanged (no tools added or removed; live registry authoritative). Provider count: 15 chat providers (unchanged). Addon count: 28 (unchanged). Bundled skills: 75 base + 41 Pro (unchanged). Coding-time agent skills: 60 (unchanged โ
design-crm+design-elementor-mcp-connectionreconciled in place). Stale build ZIPs removed: the 1.1.86 build set (30 files: 9 inbuild/incl. 3.sha256, 2 inbuild/optional-components/, 19 inbuild/toolkit-addons/).
v1.1.87 โ September 27, 2026
Parity Suite, Image Identification & Outbound Booking
๐ง mcp-wordpress parity suite โ 30 native base tools (PR #6777). Comment CRUD (
list_comments/get_comment/create_comment/update_comment/delete_comment), user CRUD (list_users/create_user/update_user/delete_user), content/media/terms (get_post_revisions,get_term,delete_term,get_media,upload_media,update_media,delete_media), site settings + application passwords (get_site_settings/update_site_settingsallowlist-only,list_application_passwords/create_application_passwordlog-masked/delete_application_password), and a 9-tool SEO toolkit (seo_analyze_contentthroughseo_keyword_research). Capability checks, multisite guards, chat-client restriction trait on sensitive write tools, and newcomment_id/user_id/attachment_idID-handoff contracts (gap matrix:docs/developer/mcp-wordpress-tool-parity.md).๐ผ๏ธ Non-LLM image identification ladder (PRs #6780 + #6785, Proposal 043).
identify_imageorchestrates a cheap-first deterministic ladder โ WordPress metadata โ pure-PHP dHash media lookup โ classic Cloud Vision detection โ deterministic layout description โ optional reverse-image web search โ and never calls a vision LLM (confidence + escalation hint). Five new base tools join the Media Generation preset (identify_image,get_image_metadata,find_similar_media,detect_image_content,describe_image_layout); two new Pro tools (ocr_image_classictesseract-only OCR,search_similar_imagesBing Visual Search / SerpApi Google Lens) sit on the sharedWP_MCP_AI_Cloud_Vision_Client. Every external rung is key-gated and fails closed โ missing credentials = skipped, never an error, never an HTTP request; SSRF guards on server-side fetches.๐ Outbound appointment booking toolkit (PR #6786, Proposal 044). New Pro toolkit gated by
enable_outbound_booking_toolkit: ICP list building (CSV โmcp_ai_lead, ICP-scored, sequence enrollment), an hourly cron engine overmcp_ai_sequencesteps with send windows / daily caps / consent attestation, email + LinkedIn/Instagram DM channels behind a human approval board, themcp_ai_oa_angleangle bank with champion/challenger A/B + weekly promotion, booking links +[nvoos_oa_booking]shortcode + a rate-limited honeypotted consent-gated public booking endpoint, a pipeline dashboard + Slack notifications + daily digest, and three new Pro tools (outbound_get_pipeline_stats,outbound_import_leads,outbound_manage_angle).๐ mcp-wordpress gateway addon (PR #6778).
addons/mcp-wordpress-gateway/โ an auth-gated Streamable HTTP MCP server on pinned docdyhr/mcp-wordpress internals for Cloudways Velocity (timing-safeX-MCP-Tokenโฅ32 chars with rotation overlap, 1 MB body cap, deny-winsMCP_TOOLS_ALLOW/MCP_TOOLS_DENYregistration-time policy), deployed via subtree split to thenvoos-mcp-wordpressmirror.๐ฆ Per-session budget warnings (PR #6776). Blocked-session messages report session state + the real reset path (Restricted Users /
wp mcp-ai restrictions lift); the dormant 75%wp_mcp_ai_session_limit_approachinghook is wired to a one-shot warning on the next chat turn; newwp_mcp_ai_chat_messagesfilter on both chat paths; Token Manager reset semantics documented. The two untracked Elementor bundled skills are committed โ the 75-skill base bundle is now genuinely tracked.๐งน Restriction admin notice fixed (PR #6779). One queue entry per user (re-flag refreshes), render-time sweep of expired windows + unrestricted users + legacy dedupe, lift pruning, and a new
count_active_users()distinct-user counter โ the Pro command-center banner is fixed too.๐ Upwork search + in-place workflow editing (PR #6784).
update_pro_schedulegainsworkflow_steps(replace semantics โ no more delete-and-recreate);search_upwork_jobsgainsexclude_keywords, anallsentinel, quoted-OR fallback skills, tier + budget parsing, and criteria echoing;upwork_job_discovery_scanpreset carries academic-noise exclusions; byte-identical CG Pro port; thedesign-pro-schedule-manager+design-crmcoding-time skills updated.๐ฆ Versioning โ bumped to 1.1.87 across all version-bearing files. Pro addon: 1.1.87. Media Worker: v3.2.0 (unchanged). nvoos-content-graph: 1.0.8 (unchanged โ explorer motion/UX + remote-source driver fixes landed in-window on its own track). nvoos-content-graph-ai: 1.0.4 (unchanged). nvoos-content-graph-ai-platform: 2.0.0 (unchanged). nvoos-content-graph-pro: 1.0.0 (unchanged โ one byte-identical tool port in-window). Checkout API: 0.1.2 (unchanged). Docs Hub addon: 0.5.1 (unchanged). Comic Reader addon: 0.5.0 (unchanged). Model catalog: v2026.09.22 (unchanged โ no model PRs in-window). Tool count: ~347 base + ~1,287 Pro (~1,634 total) โ +35 base (30 parity + 5 image) and +5 Pro (2 image + 3 outbound); live count via
WP_MCP_AI_Tool_Registry::get_tools()is authoritative. Provider count: 15 chat providers (unchanged). Addon count: 27 โ 28 (newmcp-wordpress-gateway). Bundled skills: 75 base + 41 Pro (counts unchanged โ now genuinely tracked). Coding-time agent skills: 60 (unchanged). Stale build ZIPs removed: the 1.1.85 build set (30 files: 9 inbuild/incl. 3.sha256, 2 inbuild/optional-components/, 19 inbuild/toolkit-addons/).
v1.1.86 โ September 25, 2026
MCP Server Connections, Higgsfield Media Provider, Log Filters & Delivery Templates
๐ MCP Apps as a Remote Sites connection type โ PR #6761 (Proposal 041). New
mcp_serverconnection type with AES-256-CBC-encrypted central credentials (including themcp_oauthblob), a real JSON-RPC handshake Test Connection, tool discovery with persisted snapshots, restricted-host enforcement, and activity logging; auth mappingbasic_auth/application_passwordโ MCPbasic(Elementor application passwords),custom_headerโheader,bearer,oauth. Reference mode โ assistant entries carry aconnection_refresolved decrypt-on-use at chat time (credentials never written back to post meta); missing refs skip with error-status snapshots; imported bundles with missing refs auto-disable with a warning (wp_mcp_ai_mcp_apps_validate_imported_refs). Portability hardening โtoken/oauth_dataredacted on export + stripped on import (opt-out filters); stored credentials survive overwrite imports; the metabox gains "Add from Remote Sites" reference rows + read-only "Managed in Remote Sites" rows. New coding-time skilldesign-elementor-mcp-connection.๐ฌ Higgsfield video & image provider โ PR #6772 (Proposal 042). Four new base tools:
generate_higgsfield_video(five verified models โ Cinema Studio 4.0, Seedance 2.5/2.0, Wan 3.0, Kling 3.0 โ behind onemodelparameter with per-model payload mapping/clamping, image/video/audio references, cinematic controls),generate_higgsfield_image(SOUL V2 + SOUL Cinema workflows, batch 1|4,style_idgating),check_higgsfield_request,cancel_higgsfield_request. SharedWP_MCP_AI_Higgsfield_Client(two-partKey ID:SECRETauth, submit/status/cancel lifecycle, backoff+jitter polling 2sโ10s, immediate download against the 7-day retention; settings โ env โ constants credential chain) + provider settings section + 480 s async-executor timeout override;check_video_statusresolvesasync_*job IDs;lib/coredual-layer wrappers viaoos-bridge. Also fixes the TypeSafe tool schemas + Pro coverage manifest and suppresses a benign Sora phpcs warning.๐
get_system_logssince/levels/search filters โ PR #6768. Optional AND-combinedsince(relative "2h"/"30m"/"3d"/"45 minutes" or absolute ISO 8601 /Y-m-d H:i:sUTC; bare number = minutes; malformed โwp_mcp_ai_invalid_since),levels(critical/error/warning/notice/deprecated), andsearch(case-insensitive, 200-char cap, mb-safe) filters over the structured NV oOS buffers + file logs; responses carry a filters summary (resolved UTC cutoff) and per-filefiltered_outcounts; timestamp-less lines kept conservatively;parse_since()is the shared canonical parser; CG AI ports base-identical.๐จ Action-items template + smart excerpts โ PR #6773. Scheduled digests no longer blind-trim the first 80 words: the new
action_itemsdelivery template (email + chat) sends only the actionable section with graceful fallbacks, and thesummaryexcerpt prefers the response's own distillation ("Summary"/"TL;DR"/"Key points"/"Results"), then the action block, then centroid-ranked sentences (MEAD-style centrality ร positional decay), with a lead trim as final fallback.๐ฐ Tool costs reach the final response label โ PR #6771. New
build_tool_cost_envelope()emits the top-leveltoolResult.costshape (cost_usd/is_estimated/provider/model) on both the agentic loop and the SSE streaming path; the client's sharedaggregateToolUsageBadgeData()aggregates it with legacy-shape fallbacks and carries tool model/provider into the badge; tool bubbles render the same usage/cost badges.๐ฉบ Environment status fixed โ PR #6767. The always-on "no assistants published" warning and the never-firing default-assistant branch were an envelope-key mismatch (
summarise_assistants()wraps underenvironment,build_warnings()read flat keys) โ both repaired, base + CG port in sync; DeepSeek joins the provider warning maps; newplugin.default_provider_modelresolves the effective per-provider model; the default assistant entry carries its provider/model meta.๐ฆ Versioning โ bumped to 1.1.86 across all version-bearing files. Pro addon: 1.1.86. Media Worker: v3.2.0 (unchanged). nvoos-content-graph: 1.0.8 (unchanged). nvoos-content-graph-ai: 1.0.4 (unchanged โ ZIP rebuilt in-window). nvoos-content-graph-ai-platform: 2.0.0 (unchanged). nvoos-content-graph-pro: 1.0.0 (unchanged โ no port waves in-window). Checkout API: 0.1.2 (unchanged). Docs Hub addon: 0.5.1 (unchanged). Comic Reader addon: 0.5.0 (unchanged). Model catalog: v2026.09.22 (unchanged โ no model PRs in-window). Tool count: ~312 base + ~1,282 Pro (~1,594 total) โ +4 base (the Higgsfield quartet, #6772); the
lib/corewrappers are the core registry's own tools and are not counted; live count viaWP_MCP_AI_Tool_Registry::get_tools()is authoritative. Provider count: 15 chat providers (unchanged โ Higgsfield is a media-generation provider, not a model-catalog provider). Addon count: 27. Bundled skills: 75 base + 41 Pro (unchanged). Coding-time agent skills: 59 โ 60 (newdesign-elementor-mcp-connection, #6761). Stale build ZIPs removed: the 1.1.84 wp.org package set (6 files: 3 ZIPs + 3.sha256).
v1.1.85 โ September 24, 2026
MCP Apps Connection & Exposure Wave, Docs Hub 0.5.1, README Consolidation
๐ MCP Apps connection diagnostics + correctness โ PR #6753. Per-row Test Connection / Discover Tools buttons with inline results (negotiated protocol, handshake type, server info, session state, latency, live tool count, verbatim errors); persisted
_wp_mcp_ai_mcp_app_statusbadge + tool-count chip; Test All. Basic auth end-to-end (rawuser:passauto-encoded or pre-encoded base64) with token masking โ stored credentials never echoed into the metabox HTML, empty = keep.Mcp-Session-Idcapture + echo; legacy-handshake fallback on-32601/-32600/session errors; JSON-RPC error decoding on HTTP 4xx; spec-compliantAccept;stdClass-params coercion fix; mcpServers JSON import; loopback detection with a PHP-FPM deadlock warning. Security Center โ Network & Headers: MCP App Allowed Hosts (constant hard override โ filter + saved setting merged).๐ค Negotiated protocol header after session fallback โ PR #6754. The client advertises the negotiated
protocolVersionon post-initialize requests and suppresses the 2026-only_metaenvelope once a legacy session is established โ sessionful servers no longer rejecttools/list. Test infra: PHPUnit 11 one-class-per-file discovery fixed (the #6753 registry/REST suites now genuinely execute).๐ Bridge tools reach the chat payload โ PR #6755. New base
wp_mcp_ai_chat_effective_toolsfilter seam inbuild_tools_payload()(after attention-based filtering, before the per-tool capability check; empty selection no longer short-circuits before the filters); Prowp_mcp_ai_mcp_apps_expose_tools()appends the enabled apps'mcp_app_<label>_<tool>slugs; registry gainscollect_remote_tools()+get_remote_tool_slugs().โก In-process same-site bridge โ PR #6756. Same-origin MCP endpoints dispatch via
rest_do_request()โ no outbound socket, no TLS handshake, no second PHP-FPM worker (ends the self-request TLS deadlock); outbound HTTP kept for remote hosts, unregistered routes, and thewp_mcp_ai_mcp_app_disable_inprocess_bridgefilter.๐จ
rest_post_dispatchparity โ PR #6757. The in-process path re-applies the filter afterrest_do_request()(mirroringserve_request()), so response-side session headers (e.g. EMCP'sMcp-Session-Id) reach the client and tool enumeration stops failing.๐งฐ Bridge tools on every chat tool surface โ PR #6758. The seam carries a third
$assistant_idargument applied onhandle_tools_list(),handle_tool_request(),execute_tool_call_internal(), and thelist_mcp_toolscatalogue filter; Pro exposure registers bridges in the local registry (idempotent, transient-cached discovery);rest_pre_dispatchregisters bridges before REST arg validation; 60 s negative discovery cache;save_apps()invalidates the/toolsREST list cache.๐ Docs Hub 0.5.1 โ PRs #6749/#6750/#6759. 0.5.0 went local-first by default (
sources = ['uploads'], zero remote calls) with the GitHub importer as an explicit opt-in service (enable_remote_repos, off by default, server-side enforced);is_path_safe()symlink-escape hardening (0 blocking Plugin Check errors); 0.5.1 moves uploads to the slug-namednvoos-docs-hub/content/folder with a one-time non-destructive migration of the legacyuploads/docspath.๐ README anchors + consolidation โ PRs #6751/#6752. Six VS16-fallback TOC anchors fixed;
bin/validate-readme-anchors.pyrepaired to GitHub's real anchor rules (leading hyphens kept, no collapsing, emoji/VS16/ZWJ stripped, full-file scan) + CI enforcement on README changes; one## ๐ Release Historysection keeps the 12 most recent releases in full plus a complete Previous Releases table (README 4,423 โ 3,301 lines); the 12-entry maintenance rule codified in the README + the updates skill.๐ฆ Versioning โ bumped to 1.1.85 across all version-bearing files. Pro addon: 1.1.85. Media Worker: v3.2.0 (unchanged). nvoos-content-graph: 1.0.8 (unchanged). nvoos-content-graph-ai: 1.0.4 (unchanged). nvoos-content-graph-ai-platform: 2.0.0 (unchanged). nvoos-content-graph-pro: 1.0.0 (unchanged โ no port waves in-window). Checkout API: 0.1.2 (unchanged). Docs Hub addon: 0.4.7 โ 0.5.1 (#6749 โ 0.5.0, #6750 hardening, #6759 โ 0.5.1). Comic Reader addon: 0.5.0 (unchanged). Model catalog: v2026.09.22 (unchanged โ no model PRs in-window). Tool count: ~308 base + ~1,282 Pro (~1,590 total) โ unchanged, no static registrations in-window (the MCP App bridge slugs are dynamic chat-time registrations); live count via
WP_MCP_AI_Tool_Registry::get_tools()is authoritative. Provider count: 15 chat providers (unchanged). Addon count: 27. Bundled skills: 75 base + 41 Pro (unchanged). Coding-time agent skills: 59 (unchanged โ the updates skill gained the README-anchor guardrail + 12-entry maintenance rule, #6751/#6752). Stale build ZIPs removed: the 1.1.83 set (30 files: 9 inbuild/incl. 3.sha256, 2 inbuild/optional-components/, 19 inbuild/toolkit-addons/) + the superseded docs-hub 0.4.7 and 0.5.0 ZIPs (0.5.1 is current).
v1.1.84 โ September 22, 2026
TypeSafe Jev Enhancement Wave: Fidelity, Guardrails & Decision Tools
๐ฎ API fidelity (Phase 0, PR #6747) โ noul criteria + structured EntryType fields with a recursive two-gate sanitisation walk; bounded 429/5xx retries honouring
retry-afteron the native client + the OpenRouter decisions bridge (4xx/transport never retried; the bridge defaults totypesafe/jev-1.13); an opt-in advisory decision cache (enable_typesafe_cache,cached: true+ zeroed usage on hits);typesafe_endpointoverride;jev-previewalias (catalog + settings +list_models());min_confidence,weights, advisory token warnings, and usage aliases ontypesafe_decide.๐ก๏ธ Base
typesafe_guardrail(Phase 1, PR #6747) โ one noul question per hazard category โ advisory pass/review/block verdicts;ai_mlpreset + coverage manifest + tool-status. New bundled skillmcp-ai-wpoos-jev-decisions(bundled skills 74 โ 75 base).๐งฉ Pro Jev integrations (Phase 2, PR #6747) โ opt-in fail-open guest-chat guardrail (
enable_jev_guest_guardrailon the Layer Iwp_mcp_ai_pre_chat_messagefilter); advisory citation checking ongenerate_research_report/research_eca; three newmanage_options-gated tools โtypesafe_rerank,typesafe_eval(+WP_MCP_AI_Pro_Jev_Eval),typesafe_skill_select.โ
typesafe_decidecapability alignment (PR #6745) โ declaredmanage_optionsmatches the enforced gate (metadata-only, CI-pinned).๐ Proposal + plan 040 (PR #6746) โ six API-fidelity fixes, official TypeSafe patterns, cost/reach workstreams; extraction tools, the CG port cluster, and NV Cloud passthrough deferred.
๐ฆ Versioning โ bumped to 1.1.84 across all version-bearing files. Pro addon: 1.1.84. Media Worker: v3.2.0 (unchanged). nvoos-content-graph: 1.0.8 (unchanged). nvoos-content-graph-ai: 1.0.4 (unchanged). nvoos-content-graph-ai-platform: 2.0.0 (unchanged). nvoos-content-graph-pro: 1.0.0 (unchanged โ no port waves in-window). Checkout API: 0.1.2 (unchanged). Docs Hub addon: 0.4.7 (unchanged). Comic Reader addon: 0.5.0 (unchanged). Model catalog: v2026.09.22 (+1
jev-previewdecision entry, #6747). Tool count: ~308 base + ~1,282 Pro (~1,590 total) โ +1 base (typesafe_guardrail) +3 Pro (typesafe_rerank,typesafe_eval,typesafe_skill_select), #6747; live count viaWP_MCP_AI_Tool_Registry::get_tools()is authoritative. Provider count: 15 chat providers (TypeSafe Jev remains decision-only, separate from chat). Addon count: 27. Bundled skills: 75 base + 41 Pro (+1mcp-ai-wpoos-jev-decisions). Coding-time agent skills: 59 (unchanged). Stale build ZIPs: none removed this pass โ the 1.1.83 wp.org package set is retained as current; removal moves to the next catch-up after the 1.1.84 packages build.
v1.1.83 โ September 21, 2026
Tool Guidance Everywhere, Jev Decisions, Assistant Builder, ID-Handoff Contracts
๐ง TypeSafe Jev Decision Provider + Pro Integrations โ PR #6728. Jev joins as a first-class decision provider (typed choice/score/noul over state; 70โ500 ms; $0.042/M input, output free) via a new decision-client contract, the native TypeSafe client, the OpenRouter Decisions bridge, and the new base tool
typesafe_decide(canonical envelope, adversarial-state caveat,manage_options-gated). Pro gains the fail-open Jev classifier (cascade routing viajev_routingon the Parallel Model Dispatcher) and an opt-in research source filter; fixes the pre-existing dispatcherchat_completion()bug.๐ ๏ธ "The Assistant Builder" Meta-Assistant โ PR #6727. Seeded on activation (roster 6 โ 7): a seven-phase build workflow + 10-component prompt framework for designing, building, and verifying other assistants; one-shot backfill for existing installs.
๐ P3 ID-Handoff Data Contracts โ PRs #6729โ#6739. Every ID-bearing tool family (post, cron, term, assistant, vector store, batch, Pro schedule, toolkit_cpt, medical record, plan, calendar, WPCode, session, member, webchat room) declares
produces/consumescontracts, enforced by permanent manifest-driven honesty + round-trip suites; in-wave fixes forformat_code_prettierenvelopes and the webchatlog_activity()latent fatal.๐ง Usage Monitor Saves Again โ PR #6726. The dashboard save handler now applies the monitor bridge filter (raw input, pre-sanitize), so the toggle and limits persist and sites flipped "Disabled" by the pre-#6632 merge bug can re-enable.
๐ Webchat SQL + Guidance Close-Out โ PRs #6738, #6740.
get_webchat_messagesrebuilds its queries with explicit placeholders (root cause of the phpcs warnings); the last three webchat tools and the CG Pro member mirrors gain usage guidance; the CG interface copy gains the guidance interface (standalone-resolution fatal fix).๐งญ Tool Description Engineering โ PRs #6686, #6695, #6687โ#6723. Model-facing usage guidance on every base+Pro tool class (~1,487 tools; 1,584/1,584 files clean): a guidance interface assembles a
[Usage: โฆ]suffix on the model-facing payload, legacy classes opt in through the wrapper, and the sniff is enforced at severity 5. Opt-in adaptive tool cap + lazy schema loading (tool_slug,include_schemas).๐ก๏ธ Pro Bootstrap + Telegram + Gmail/Skill/OKF Hardening โ PR #6677. Partial Pro deploys degrade to an admin notice instead of a site-wide fatal; Telegram messages over 4,096 chars auto-chunk;
connection_id: "settings"resolves to the settings fallback; skill/OKF errors append the available options.๐ Upwork & Workflow Delivery โ PRs #6678, #6679, #6680, #6682, #6684. Mode + credential gating, category-page dropping, always-on broad second pass,
sort/locationargs; workflow deliveries ship the full 50-item result set with URLs/budget/recency as a single properly numbered list; steps render as a compact execution log.๐งช Playground Ollama Demo โ PR #6683. Permalink seed fix ends the fresh-install landing 404; local
npxis the primary test path; capture harness rewritten (REST-index wait + cookie jar).๐ npm Advisories โ PR #6681. adm-zip 0.6.1, js-yaml 4.3.2, colord 2.10.0 across five lockfile trees.
๐ Canonical Envelope Migrations โ PRs #6689, #6737. Five regulatory tools and
format_code_prettiermove to the canonicalWP_Errorenvelope.๐ฆ Versioning โ bumped to 1.1.83 across all version-bearing files. Pro addon: 1.1.83. Media Worker: v3.2.0 (unchanged). nvoos-content-graph: 1.0.8 (unchanged; ZIP rebuilt in-window). nvoos-content-graph-ai: 1.0.4 (unchanged; ZIP rebuilt in-window). nvoos-content-graph-ai-platform: 2.0.0 (unchanged). nvoos-content-graph-pro: 1.0.0 (unchanged โ mirror patches only, no port waves). Checkout API: 0.1.2 (unchanged). Docs Hub addon: 0.4.7 (unchanged). Comic Reader addon: 0.5.0 (unchanged). Model catalog: v2026.09.21 (+3 Jev decision entries โ
jev-1.13.0,jev-latest, OpenRoutertypesafe/jev-1.13, #6728). Tool count: ~307 base + ~1,279 Pro (~1,586 total) โ +1 base (typesafe_decide, #6728); the P3 ID-handoff waves are contract annotations on existing tools; live count viaWP_MCP_AI_Tool_Registry::get_tools()is authoritative. Provider count: 15 chat providers (TypeSafe Jev joins as a decision-only provider, separate from chat). Addon count: 27. Bundled skills: 74 base + 41 Pro. Coding-time agent skills: 59 (unchanged โ no new skills; the test-suite skill gained patterns 49โ50 and the ecosystem-port skill gained the CG interface-port rule, #6742). Stale build ZIPs removed: the 1.1.81 set (30 files), then the 1.1.82 set (30 files) after the 1.1.83 wp.org packages rebuilt.
v1.1.82 โ September 18, 2026
WordPress Playground Demos, Pro SPA Fixes, Token-Tracking & Delivery Hardening
๐ฎ One-Click Playground Demos โ PRs #6662, #6663, #6666, #6670, #6673, #6674. Content Graph "Project Asteria" (seeded universe, deterministic build, 49 nodes / 255 edges) and NV oOS Complete ร local Ollama (pre-wired provider, Oma assistant, Test Lab page) blueprints; generator auto-discovers the newest bundle ZIP; build workflow regenerates the blueprint on every build; README demo button +
docs/user-guides/playground-demo.mdwalkthrough (#6671).๐งฐ Pro SPA:
cron_monitorflag + model-store seeding โ PRs #6665, #6672.[nvoos_pro_spa cron_monitor="0"]no-ops the blocking SSE cron-status stream + REST poll; embedded mode seeds the model store from the assistant's real config instead of hardcodedgpt-4o.๐ ๏ธ Token Tracking Table Hardened โ PR #6669. Verify-then-version + hourly retry backoff + quiet failure + graceful reads for SQLite-backed environments; ported 1:1 to
nvoos-content-graph-ai(ecosystem matrix 13/13).โ๏ธ Result Delivery Dedupe + Metadata Redaction โ PR #6661.
delivery_safe_data()strips the duplicatedresponsecopy andassistant_id/is_agenticbefore rendering; summary/SMS prefix dedupe; no empty## Details.๐ก
[ollama_status]Banner Fixed โ PR #6668. Footer-enqueued checker JS replaces the texturize-mangled inline script (&&โ&&).๐ก๏ธ Portability Coverage Guards Repaired โ PR #6645. Preset + 9 AJAX tests + regenerated manifests; CI run 35096081494's 4 guard failures closed.
๐ Skill #59 + Updates Track C โ PRs #6664, #6656.
mcp-ai-wpoos-playground-demoscodifies the blueprint playbook; the updates skill gains the PR deferred-item sweep.๐ฅ Docs Hub 0.4.7 โ PRs #6659, #6667. Third wp.org reviewer pass; 0 blocking Plugin Check errors.
๐ฆ Versioning โ bumped to 1.1.82 across all version-bearing files. Pro addon: 1.1.82. Media Worker: v3.2.0 (unchanged). nvoos-content-graph: 1.0.8 (unchanged; ZIP built in-window). nvoos-content-graph-ai: 1.0.4 (unchanged; ZIP built in-window). nvoos-content-graph-ai-platform: 2.0.0 (unchanged). nvoos-content-graph-pro: 1.0.0 (unchanged โ no port waves in-window). Checkout API: 0.1.2 (unchanged). Docs Hub addon: 0.4.7 (was 0.4.6). Comic Reader addon: 0.5.0 (unchanged). Model catalog: v2026.09.10 (unchanged). Tool count: ~306 base + ~1,279 Pro (~1,585 total) โ unchanged, no tool registrations in-window; live count via
WP_MCP_AI_Tool_Registry::get_tools()is authoritative. Provider count: 15. Addon count: 27. Bundled skills: 74 base + 41 Pro. Coding-time agent skills: 59 (+1 โmcp-ai-wpoos-playground-demos). Stale build ZIPs removed: the 1.1.80 set (30 files) + the superseded docs-hub 0.4.6 ZIP.
v1.1.81 โ September 17, 2026
Shopify UCP Tool Routing, FlowHub Connections, JobNavigator CRM, OpenTerminal Financial Resilience
๐๏ธ Shopify UCP Mode-Aware Tools + Image Cards โ PRs #6634, #6638. Live UCP queries for
shopify_products/shopify_catalogon storefront/global connections (no caching,live: true), actionable hints from admin-only tools, UCP passthrough + clamps,tools/listhandshake validation, and image cards (images[]+ markdown, 10-card cap) on every product-returning path. Byte-identical CG Pro ports with dual-matrix suites.๐ FlowHub Connection Resolution + Proxy โ PRs #6635, #6637. Shared resolver chain reads Remote Sites connections (explicit ID, settings, sync connections, first enabled); live requests honor the connection proxy. New base helper
WP_MCP_AI_FlowHub_Connection_Helper.๐งฉ JobNavigator CRM + Gmail Poller โ PRs #6636, #6640, #6641. Five new CRM tools (bulk stage moves, reply recording, handover, pipeline digest, tracked links), stage history, lead dedup, reply signals; cron-driven Gmail reply classification with sentiment + optional stage advancement; digest scheduling recipe for Workflow Builder + Pro Schedule Manager.
design-crmskill updated.๐น OpenTerminal Financial Toolkit โ PR #6639. Eight new tools (screener, macro, economic/earnings calendars, options, crypto, portfolio ledger, price alerts), fallback chains + SWR caching, keyless auth, technical indicators, news de-dup.
tool-status.txt+8.โ๏ธ Multi-Recipient Result Delivery Email โ PR #6643. Comma/semicolon/whitespace lists, normalized on save, sanitized + deduped at the boundary, fanned out via Nodemailer +
wp_mail.๐ฆ Versioning โ bumped to 1.1.81 across all version-bearing files. Pro addon: 1.1.81. Media Worker: v3.2.0 (unchanged). nvoos-content-graph: 1.0.8 (unchanged). nvoos-content-graph-ai: 1.0.4 (unchanged). nvoos-content-graph-ai-platform: 2.0.0 (unchanged). nvoos-content-graph-pro: 1.0.0 (unchanged โ byte-identical port batches only). Checkout API: 0.1.2 (unchanged). Docs Hub addon: 0.4.6 (unchanged). Comic Reader addon: 0.5.0 (unchanged). Model catalog: v2026.09.10 (unchanged). Tool count: ~306 base + ~1,279 Pro (~1,585 total); live count via
WP_MCP_AI_Tool_Registry::get_tools()is authoritative โ +13 Pro (#6636 +5, #6639 +8). Provider count: 15. Addon count: 27. Bundled skills: 74 base + 41 Pro. Coding-time agent skills: 58 (unchanged). Stale build ZIPs removed: the 1.1.79 set (30 files) + superseded docs-hub 0.4.3/0.4.4/0.4.5 ZIPs.
v1.1.80 โ September 15, 2026
Assistant Portability, Shopify UCP Catalog, Security Usage Monitor, WP-CLI Repair
๐ฆ Assistant Export/Import Everywhere โ PR #6628. One engine, every surface: WP-CLI (
export|import, legacy-compatible), REST (POST /mcp-ai/v1/assistants/export|import), an admin Import/Export page, and tools (export_assistant,import_assistant,duplicate_assistant, Proexport_assistant_blueprint). Credential hashes never leave the site and are stripped on import. Bundle spec:docs/assistant-import-export.md; skill:.agents/skills/mcp-ai-wpoos-assistant-portability/.๐ก๏ธ Security Center Usage Monitor โ PR #6632. New
usage_monitorsub-tab: triage log, status cards, shutdown recovery, editable config, REST clear routes; the admin notice deep-links and shows the latest violation. Monitor sanitize-clobber bug fixed; malformed patterns hardened.๐๏ธ Shopify Catalog Trilogy โ PRs #6623, #6624, #6630. REST Catalog 401s fixed (60-min token cap, scope validation, purge-and-retry) and the JetEngine sync gate unified with System Status; two keyless UCP modes (Storefront + Global Catalog) replace the deprecated REST API on Pro and CG Pro, with the public UCP agent-profile route and byte-identical ports.
๐ป WP-CLI Repairs + Streaming โ PRs #6625, #6626. PHP 8+ fatals gone from
provider list/chatand every base-class command;chat --streamstreams natively (cURL SSE) or simulates chunks, honoring the shared streaming filters. Live-validated in the Design Stack.๐ข Remote Sites & OKF โ PRs #6622, #6631. WhatsApp webhook self-tests (verification/signature/subscription) on the connection edit form; OKF editor saves keep their bundle/concept context.
๐ Skills โ PRs #6621, #6627, #6629. Docs Hub syntax/anchor color fixes; agent skills corrected to the verified plugin surface; new
design-brand-assistant-provisioningskill; brand template phpcs-clean.๐ฆ Versioning โ bumped to 1.1.80 across all version-bearing files. Pro addon: 1.1.80. Media Worker: v3.2.0 (unchanged). nvoos-content-graph: 1.0.8 (unchanged). nvoos-content-graph-ai: 1.0.4 (unchanged). nvoos-content-graph-ai-platform: 2.0.0 (unchanged). nvoos-content-graph-pro: 1.0.0 (unchanged โ byte-identical port patches only). Checkout API: 0.1.2 (unchanged). Docs Hub addon: 0.4.6 (unchanged โ CSS fix, no bump). Comic Reader addon: 0.5.0 (unchanged). Model catalog: v2026.09.10 (unchanged โ no model PRs in-window). Tool count: ~306 base + ~1,266 Pro (~1,572 total); live count via
WP_MCP_AI_Tool_Registry::get_tools()is authoritative โ +3 base +1 Pro from #6628). Provider count: 15. Addon count: 27. Bundled skills: 74 base + 41 Pro. Coding-time agent skills: 58 (newdesign-brand-assistant-provisioning+mcp-ai-wpoos-assistant-portability). Stale 1.1.78 build ZIPs removed (30 files).
๐ Previous Releases
For full details on all releases, see CHANGELOG.md.
Version | Date | Highlights |
v1.1.79 | Sep 2026 | Imaging symlink-deletion hardening ( |
v1.1.78 | Sep 2026 | Slash commands as declarative tool wrappers (~10,400 โ ~1,000 lines, 36 commands mapped to real slugs, |
v1.1.77 | Sep 2026 | DeepSeek V4.1 Flash refresh ( |
v1.1.76 | Sep 2026 | Chat delivery full-report + per-channel formats (Telegram HTML/MarkdownV2 escaping, WhatsApp/Slack/Discord/Teams Markdown, Messenger/Google Chat plain); comic-creation toolkit toggle; NV oOS Complete checkout consent + buyer email + EU billing + Stripe metadata; manual-install primary + legal docs (privacy/AUP/ToS/compliance); playbook-seeder idempotency; security sweeps (tiptap/multer/csv-parse/react-router-dom/svgo/hono/vitest); Docs-Hub ZIP markdown exclusion; Wave F2 port clusters complete |
v1.1.75 | Sep 2026 | Telegram delivery fixes (credential normalization + tier-4 Remote Sites fallback); Content Graph memory bridge (write/read graph projection) + NV oOS Complete checkout (conflict-guarded, chunked); Wave F2 financial-planning/social-media/MCP-server/slice-batch ports; nvoos-content-graph 1.0.4 โ 1.0.6 |
v1.1.74 | Sep 2026 | Google Calendar query encoding fix (raw |
v1.1.73 | Sep 2026 | Woo tool upgrades ( |
v1.1.72 | Sep 2026 | Woo price/qty tools ( |
v1.1.71 | Sep 2026 | REST rate-limit fixed-window rework + Restrictions-tab unlock; MemPalace wing-scope enforcement; September model catalog (217 โ 228 models); Content Graph 1.0.4 visual experience; platform E2 queue layer; new |
v1.1.70 | Sep 2026 | exec-disabled host shell-call hardening; fifth PHPUnit repair wave (~29 test PRs) with production fixes across transcripts, charts, presets, mesh, memory, REST, and K16 |
v1.1.69 | Sep 2026 | Vision Analysis toolkit (Pro); tagDiv admin compat + metabox crash fix; DeepSeek empty-schema 400 fix; ZipSlip guard revival; fourth PHPUnit repair wave |
v1.1.68 | Sep 2026 | Pro SPA v2 shortcode + embedded mode; Hermes fleet extensions ( |
v1.1.67 | Sep 2026 | Content Graph Platform extraction v2.0.0 standalone; ecosystem port Wave D + D-UI (Content Graph AI 1.0.4); Google Workspace Gmail/Drive read tools (6 new); ~100-PR PHPUnit repair wave |
v1.1.66 | Aug 2026 | ~100-PR PHPUnit suite repair campaign + new |
v1.1.65 | Aug 2026 | OpenAI reasoning-model parameter fix; Media Worker full-Crawl4AI proxy; security-posture findings closed (#5972); chat/REST/transcript hardening; Content Graph wp.org refresh |
v1.1.64 | Aug 2026 | Google Calendar connection + shared |
v1.1.63 | Aug 2026 | Artifact Evolution Phases AโG (gated Darwinian self-improvement loop); Pro Addons install page; chat storage worker offload; test-suite exit-trap sweep ( |
v1.1.62 | Aug 2026 | OKF Bundle Management Phases AโH (10-tool surface + Bundle Manager screen); Pro OKF skills drawer; vector-store tools migrated to the OpenAI Responses API |
v1.1.61 | Aug 2026 | Agent identity bridging in memory store/recall; OKF skill-knowledge bundle generator; undici ^7.29.0 jsdom pin; Content Graph wp.org review reply |
v1.1.60 | Aug 2026 | Restricted-user flagging + unblocking (Restriction Registry, Restrictions tab, WP-CLI); conversation import to transcript CCT; tool schema normalization |
v1.1.59 | Aug 2026 | Media Worker crawling + Crawl4AI facade (v3.2.0); research tools multi-provider hardening; Docs Hub 0.4.1 rebuild + broken-link fixes; ~32 orphaned tools re-registered |
v1.1.58 | Aug 2026 | Composio Connect subsystem (6 beta tools); OOS runtime consolidation Phases 0โ5.8; standalone plugins renamed to Content Graph |
v1.1.57 | Aug 2026 | Plugin updater base-only in-place install rework; Hermes async chat submit/poll; Fleet Operator agent context; provider detection via Credential_Resolver |
v1.1.56 | Aug 2026 | Media Worker v3.0.0 multi-tenant shared-worker mode + per-site provider keys; worker routing expansion; Hermes WebUI MCP server + SSH bridge + skill sync |
v1.1.55 | Aug 2026 | MCP agent compatibility (HTTP 200 error envelopes, legacy HTTP+SSE transport, settings-driven tool rate limiter); Fleet Operator addon; Media Worker v2.2.0 hardening; DB connection pooling (Proposal 023) |
v1.1.54 | Aug 2026 | MCP async tool-response fix; updater integrity check v2; API-key merged-settings fix across 20 research tools; design-skills audit (44 coding-time skills); README TOC anchor fixes |
v1.1.53 | Aug 2026 | Shared Analytics Service (7 platform adapters, DTOs, caching, rate limiter); circuit-breaker + backpressure hardening on all 15 providers; agent-skills sync; SSE backoff fixes |
v1.1.52 | Aug 2026 | Paper Store remote-site support + REST controller; remote-connection CPT auto-discovery; design-system tool preset (72 tools); post-install integrity check |
v1.1.51 | Aug 2026 | Orchestration/harness gap remediation (OWASP LLM Top 10 20% โ 60%, EU AI Act 17% โ 67%); MCP protocol version negotiation; Media Worker dependency security bumps |
v1.1.50 | Aug 2026 | Media Worker sidecar addon (Docker Node.js, 11 service handlers, queue module); Site Health redeclaration fix; npm security fixes; BMAD agent conventions |
v1.1.49 | Aug 2026 | Gemini model-resolution fix; update reactivation + release-ZIP cleanup |
v1.1.48 | Aug 2026 | Shopify Sync toolkit 7 fixes; PHPCS 3.13.6 (CVE-2026-67434); default skill catalogues; 3 Graphify standalone plugin ZIPs |
v1.1.47 | Aug 2026 | MySQL connection exhaustion fix (Cloudways cron overhaul); update-checker cache-bust; Mermaid CVE fixes in canvas-toolkit |
v1.1.46 | Aug 2026 | Backup & Restore (Proposal 020, 11 export providers); GitHub-based plugin updater; Abilities API (Proposal 019); status-page fixes; PHPCS cleanup |
v1.1.44 | Aug 2026 | CCT stability (4 fixes: mutex lock, FlowHub duplicate, base-plugin fatal w/out lib/core, Veo async context), API key resolution (Gemini video + Veo fallback), Proposal 016 security & architecture hardening (all waves, 277 autoload optimizations, phpcs sweep), Proposal 017 polling/queue/load-balancing hardening (12 weaknesses), Deferred security items #5755 (post meta, term escaping, REST field filtering), npm security (undici >=8.10.0, fast-uri >=3.1.4, ip-address >=10.4.0 across 11 pkg), Docs: FOR_REVIEWERS v1.1.43 update, 16 broken links fixed, Graphify ecosystem audit |
v1.1.43 | Aug 2026 | MCP 2026-07-28 stateless core upgrade, Security v1.1.43 hardening (SSRF/CSRF/SQL/XSS/info-disclosure across 16 files), OKF v0.2 trust-signal support, ICP System (Pro CRM Phase G, 7-dimension scoring), Pro Module Registry (PSR-4, 625-line monolithic init decomposed), Hexagonal architecture purity (PlatformFlushInterface), 7 playbook/profession sync fixes, Phase 3 operational security hardening, WPCS 3.4.1 (CVE-2026-45293) |
v1.1.42 | Jul 2026 | Security Infrastructure (7 classes, 21 posture signals A-F), Framework-Agnostic Core (lib/core/, 32 contracts, 21 adapters), Status Page & Incident Communication (Pro), 21 Agent Skills + 6 BMAD Agents, Algorave addon (9 tools), Security Hardening (12 fixes, 13 unit tests) |
v1.1.41 | Jul 2026 | OKF v0.1 integration (6 tools); security compliance (11 HIGH/P0 fixes); playbook sync fixes; model credential resolution; dependency security bumps |
v1.1.40 | Jul 2026 | Content format awareness helper; research โ Paper Store โ draft pipeline; settings credential split; July model catalog; SSE HTTP/2 fixes |
v1.1.39 | Jul 2026 | Meta-Harness auto-optimization (7 phases); agent delegation rework; Pro SPA v2 polish (20+ PRs); tool presets refactor; Veo 2.0 โ Gemini Omni Flash |
v1.1.38 | Jul 2026 | Page Agent addon v0.1.0 (AI browser page control copilot), Pro SPA v2 major parity & polish (voice pipeline, tasks drawer, workflow tracker, file attachments, tool shortcuts, slash commands, mobile hamburger, autoscroll/viewport fixes, cache-busting, assistant preloading), Per-user chat memory toggle, create_post/save_post Markdown-to-HTML + taxonomy suggestions, Workflow blueprint existing-content awareness, SPA accessibility: annotation pills, ZAP medium findings triaged |
v1.1.37 | Jul 2026 | JetEngine Meta Helper universal (25 CPTs, REST, ECA fields), Places enrichment tools, RabbitMQ + queue infrastructure (custom DB tables, health endpoint, worker), Multi-tenant DB isolation Phase 0โ4, DSpark admin UI + speculative orchestration, Crocoblock Design System addon (5 phases), Test coverage: 329 tools across 28 toolkits, Docs Hub broken link engine, OWASP ZAP DAST, 30+ bug fixes |
v1.1.36 | Jul 2026 | EZuite Inventory Sync Pro Toolkit, Ralph Loop CCT migration + circuit breaker, JetBooking/JetAppointment (8 tools), Moonshot/Z.AI provider parity (15 total), Unified Sync Log Manager, Tool Presets Auto-Select + Chips Bar, HTTrack Cache + Place-to-Service Bridge, Generate Default Mapping + read-only sync, 45+ bug fixes |
v1.1.35 | Jun 2026 | FlowHub Inventory Sync Pro Toolkit (6 tools), Shopify Sync Pro Toolkit (5 tools), Necessity Gate Layer J (irreversibility-weighted safety), Local Voice Embedded STT (3 backends, offline-first), Remote Site Administrator blueprint (22 tools), Places & Calendar bulk import, CLI site-import subcommand, voice realtime auto-detect, 7 bug fixes |
v1.1.34 | Jun 2026 | GPT-Realtime-2 voice models with WebRTC + Translate/Whisper + reasoning, multi-channel result delivery UI (11 channels, up from 4), pro scheduler AI/workflow delivery, Graphify ecosystem: remote drivers, WP 7.0 Connectors, wp.org compliance, 3 reasoning-tool fatal bugs fixed, CRM deal import + multi-source auto-import, Upwork/LinkedIn mode toggle, Docs Hub REST + settings sync fixes, http-proxy-middleware CVE, Gemini cache fix, GPT image routing fix, FastAPI porting plan |
v1.1.33 | Jun 2026 | WP 7.0 Connectors credential integration across all 17 AI clients with source badges, nvoos-graphify v1.0.0 release (Plugin Check compliant), 3 guzzlehttp CVEs + undici override, 29 npm alerts across 14 packages, 2 bug fixes (Pro tool paths, JSON-RPC warning leak), 15 dependabot bumps |
v1.1.32 | Jun 2026 | Content Format Templates + Featured Image Service (3-provider fallback), Result Delivery Pipeline (8 channels), ECA document generation, duplicate posts fix, 6 provider clients timeout fix, schedule trigger stability, Paper Store delete fix, ECA settings/attachment fix, npm CI & Jest resilience, 14 dependabot bumps + 8 npm audit CVEs |
v1.1.31 | Jun 2026 | Media Command Center, Pro SPA v2 (rich rendering, assistant scoping, agent selector, v2.0.1), 34 workflow preset tools, npm audit CVEs (12 resolved), Gemini 3.1 flash image default, Media toolkit blueprints & presets, stream_options, agentic-loop cost tracking, Vite CVEs, 1,658 PHPCS lint fixes, CI disk space, data integrity fixes |
v1.1.30 | Jun 2026 | Chat SPA Phase 8, PM Toolkit AโD, CRM duplicates/hygiene/analytics, DietPi Pro Toolkit, LibreChat Addon, Layer I Guardrails, Context Window Management, WP 7.0 Bridge, Pro Toolkit Optimizations, OAuth disconnect, 30+ fixes |
v1.1.29 | Jun 2026 | Bug-fix & stabilisation sweep: chat bubble assistant dropdown, context-window pre-flight validation (13 providers), OpenAI SSE |
v1.1.28 | Jun 2026 | CRM Phase C complete (IMAP, SMS, WhatsApp ingestion), Customer CPT + 360 dashboard, Support Ticket module (10 AI tools + SLA), QKV Attention Routing, Funiq Bridge addon, NVOOS Graphify ecosystem (3 standalone plugins), NV Platform AI addon, automated demo video pipeline, TF-IDF + BM25 relevance search |
v1.1.27 | Jun 2026 | Real-time SSE streaming for all OpenAI-compatible providers, 35 new OOS core tools migrated, JFB submission tools โ 8 fixes, Extended Cognition vision recognition, DeepSeek agentic tool handling, 9 HIGH-severity security findings fixed, 95% PHPUnit failures resolved |
v1.1.26 | Jun 2026 | Cross-Platform Extraction Engine Phases 0โ2, Site-Builder Node-Graph Pipeline, SPA a11y hardening (WCAG 2.1 AA), 108 admin screenshots, docs reorganized into 12 directories |
v1.1.25 | May 2026 | Unified Blueprint System (55 blueprints across 25 toolkits), Cloudways Pro Toolkit (60 tools), CRM Toolkit Phases AโE (70+ tools), Chat UI 7-feature enhancement, Unix-theory Phase 4โ5 |
v1.1.24 | May 2026 | Chat SPA fixes, Unix Theory P0/P1 refinement, CVE patches (tmp, symfony/cache), Paper Store admin CRUD, folder README convention |
v1.1.23 | May 2026 | Zed-inspired SPA architecture, Antigravity Interactions API rewrite, TypeScript upgrade, Comic Reader & Media Studio v0.3.0 |
v1.1.22 | May 2026 | Baseten provider (11th), CoSAI secure-by-design agentic system, Continual Harness P5, SaaS Controller P2/P4, npm VAD/Chat-Bubble/Memory-UI packages |
v1.1.21 | May 2026 | WP.org compliance complete (50/50 findings), canonical return envelope enforced, semantic compression, AI prompt caching layer |
v1.1.20 | May 2026 | Memory Layer 2026 Phase 7 โ chat memory drawer UI complete |
v1.1.19 | May 2026 | Kimi provider (10th), ACP Server, MCP Bridge, Unix Theory P7, 9 HIGH security findings fixed, chat bubble sweep |
v1.1.18 | May 2026 | Unix Theory P0โP6, DigitalOcean Serverless Inference (9th provider), async chat continuation, jobs/tasks drawer, Toolkit MCP Servers Phase 7 |
v1.1.17 | May 2026 | WP.org compliance (42/50), Chat SPA Phases 1โ7, Docs Hub v0.3.8, coverage campaign |
v1.1.16 | May 2026 | SaaS Controller Addon v0.1.0, structured logging integration, WP.org compliance hardening (B3, B8, B10, B13) |
v1.1.15 | May 2026 | OpenRouter + DeepSeek providers (7th & 8th), Orchestration Phases 1โ7, LLM Harnessing GA, Memory Bridge G-series, Graphify data-source bridge |
v1.1.14 | May 2026 | Agent Skills v2 (45 skills), Markup Subsystem (Base), MemPalace Capture Framework, Graphify CPT/CCT suite |
v1.1.13 | May 2026 | OpenAI Images 2.0 (gpt-image-2), durable agent-memory bridge Phase 4a/4b, AI Harmonization toolkit, production Composer autoloader |
v1.1.12 | Apr 2026 | Architectural Design Toolkit Phases AโE, Graphify Federation/RAG, Tier 4 Browser-AI Runtime (Transformers.js v3.8.1), security patches |
v1.1.11 | Apr 2026 | WP.org compliance hardening |
v1.1.10 | Apr 2026 | Security audit summary (0 Critical, 5 High), production vendor autoload, Veo 3.1 fix |
v1.1.9 | Apr 2026 | Measurement Subsystem GA, PHPUnit 11 upgrade, Graphify v0.5.0 restored, orchestration reference |
v1.1.8 | Apr 2026 | Erlang C workforce tools, full tool-reference audit, WP.org compliance re-audit, MCP Apps per-assistant remote connections, CRE Debt toolkit (57 tools), 36 Pro professions + 17 teams, A2A protocol, Agent Command Center, floating chat bubble, JetEngine 3.8 MCP Server bridge, Anthropic/Gemini subscription tier support |
๐ Features
Note: Some features require third-party plugins (WooCommerce, JetEngine, Elementor, etc.). See ๐ What You Lose Without Third-Party Plugins for details.
Assistant & conversation tools
๐ง Create AI Assistants via a custom post type (
mcp_ai_assistant)๐ Professional & Team Templates - Deploy assistants from ~311 pre-built profession templates spanning 12 industry categories, or create entire teams of specialists with one click. Includes backend testing for professions, teams, and assistants before public deployment.
๐ Getting Started Wizard - Guided 4-step onboarding (
/wp-admin/admin.php?page=wp-mcp-ai-getting-started) that walks new users through provider setup and use-case selection. Selecting a preset (Content Creator, Customer Support, E-commerce, SEO & Research, Developer Copilot, Media & Creative Studio, Site Administrator, or General Purpose) seeds a fully-configured assistant with tools, system prompt, and tuned temperature โ ready to use immediately.ใF:includes/admin/class-wp-mcp-ai-onboarding-wizard.phpโ L1-L53ใใF:assets/js/onboarding-wizard.jsโ L1-L303ใ๐ Automatic synchronization to JetEngine Custom Content Types when available (CPT โ CCT)
๐ฌ Chat interface via
[mcp_ai_chat assistant="ID"]๐งฐ Per-assistant defaults for model, temperature, system prompt, and knowledge attachments with permission-aware download URLs
โก Build reusable prompt shortcuts with optional tool targeting and inline descriptions so operators can trigger common tasks with one click.ใF:includes/assistants/class-wp-mcp-ai-assistant-cpt.phpโ L893-L1048ใใF:includes/class-wp-mcp-ai-shortcode.phpโ L430-L693ใใF:assets/js/chat.jsโ L600-L666ใ
๐ง Elementor widgets for embedding chat surfaces, onboarding content, and MCP dashboards inside Elementor
Language routing & knowledge management
๐ Route conversations through OpenAI or Gemini using a provider-aware language model router
๐ฏ Enhanced Gemini API integration: list models dynamically, count tokens for budget management, create embeddings for RAG/semantic search, and streaming support for real-time responsesใF:docs/reference/api/gemini/gemini-api-enhancements.mdโ L1-L100ใ
๐ง Assistant knowledge base management with Media Library files and optional vector store IDs
๐ OKF (Open Knowledge Format v0.1) engine with 6 MCP tools for curated, deterministic knowledge with cross-link navigation โ complementary to vector/RAG stores
๐ Perform lightweight web searches (DuckDuckGo or Brave) without leaving the assistant conversation
๐ Crawl4AI job runner tool for large-scale content gathering workflows
Media generation & transcription
๐ Generate speech audio via OpenAI's Text-to-Speech API and save the result to the Media Library
๐ต Generate instrumental music using Google Gemini Lyria with controls for genre, mood, tempo, and instrumentation
๐จ Generate on-brand imagery with OpenAI's Images API, honouring the configured response format (including GPT-Image-1's
urlresponses) and storing the files as WordPress attachments๐ผ๏ธ Generate images with Cloudflare Workers AI using Stable Diffusion, Flux-2 Dev, Leonardo AI (Lucid Origin, Phoenix 1.0), and other text-to-image models with configurable dimensions and generation parameters
๐ผ๏ธ Vectorize raster images (PNG, JPEG, WebP, GIF) to SVG format using @neplex/vectorizer with configurable quality settings - perfect for logos and icons
๐จ Comprehensive graphic editing with Graphic Editor Plus combining local operations (logo overlay, smart resize) and AI-powered features (style transfer, background removal, enhancement)
๐๏ธ Pro: Generate professional architectural drawings (floor plans, elevations, sections) with building codes, dimensions, and material specifications - designed for construction professionals
๐ง Transcribe or translate uploaded audio with OpenAI's speech-to-text endpoints
Commerce & finance workflows
๐ WooCommerce-aware tools (fetch orders or products, requires WooCommerce)
๐ Finance-ready QuickBooks Online reporting tool for surfacing Profit and Loss, Balance Sheet, and other statements inside assistant conversationsใF:includes/tools/class-wp-mcp-ai-tool-get-quickbooks-report.phpโ L15-L214ใใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L906-L955ใ
๐ฅ๏ธ Pro: QuickBooks Desktop sync via QODBC relay API โ connect to QuickBooks Desktop through a Windows relay server for data synchronization
๐ Pro: Shopify integration with auto-resolved connections โ
connection_idauto-resolved from assistant context, covering products, orders, customers, inventory, and catalog tools๐ Pro: Vehicle estimation tools โ VIN decode (NHTSA vPIC), image-to-repair-estimate pipeline, and car wash package pricing engine (always available)
๐ธ Pro: Listing image download tools โ bulk-download Google Maps, Facebook, and Instagram business listing images into the Media Library or ZIP
Slash Commands & Workflow Automation โญ NEW
โก 8 Core Commands:
/help,/next-task,/ship,/clean-content,/optimize-perf,/sync-docs,/workflow- Command-line style interface for content management๐ Workflow Orchestrator: Multi-step workflow execution with state management, conditional logic, and human-in-the-loop checkpoints
๐ ๏ธ 21 Pro Toolkit Commands: Specialized commands for E-commerce (6), Social Media (6), and Video Production (6) toolkits
๐ฏ 7 Automated Workflows: Pre-built workflow templates for abandoned cart recovery, social media campaigns, video marketing, inventory management, and more
๐ Security: Capability-based authorization, rate limiting, comprehensive audit logging
๐ก Integration: JavaScript autocomplete, REST API endpoint, WP-CLI support
Chat Channels & Messaging Integration โญ NEW
๐ฌ Chat Channels Toolkit (47 Tools): Integrate with 11 platforms - Telegram, WhatsApp, Slack, Discord, Microsoft Teams, Facebook Messenger, Apple Messages for Business, Google Chat/Spaces, Twitter/X, Office 365 (Outlook + OneDrive), iCloud Drive
๐ง Office 365 Integration โญ NEW: Send and retrieve Outlook mail, list/download/upload OneDrive files via Microsoft Graph API (5 tools)
โ๏ธ iCloud Drive Integration โญ NEW: List, download, and upload iCloud Drive files via a configurable gateway service (3 tools)
๐ Unified Broadcasting: Send messages across multiple platforms simultaneously with
unified_channel_broadcasttool๐ WebChat Rooms: Custom post type for real-time collaborative chat rooms with AI assistant assignment
๐ Message Persistence: JetEngine CCT integration for permanent message history
๐ WebRTC Support: Self-hosted WebRTC signaling via WordPress REST API for voice/video
๐ค AI-Powered Rooms: Assign dedicated assistants to chat rooms for automated support
Communications & outreach
โ๏ธ Mailjet-powered outbound email automation with granular capability enforcement and sender defaults configurable in the MCP settings.ใF:includes/tools/class-wp-mcp-ai-tool-send-mailjet-email.phpโ L19-L405ใใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L1008-L1054ใ
๐ Google Workspace automations for creating calendar events and searching connected Gmail inboxes directly from assistant workflows.ใF:includes/tools/class-wp-mcp-ai-tool-create-google-calendar-event.phpโ L1-L200ใใF:includes/tools/class-wp-mcp-ai-tool-search-gmail.phpโ L1-L200ใ
๐งพ JetFormBuilder orchestration for listing forms, reviewing submissions, and proxying REST calls on behalf of assistants (requires JetFormBuilder)
๐ JetEngine REST route reference tool for surfacing endpoint metadata inside AI workflows
๐งฑ Ready for extension with ChatKit integration
Integrations, security & controls
๐ง Tool Registry for registering PHP functions callable by the AI
โ๏ธ JetEngine integration for dynamic content queries (requires JetEngine)
๐ JetEngine 3.8 MCP Server Bridge โญ NEW - JSON-RPC 2.0 client bridges NV oOS into JetEngine's native MCP Server with 7 new Pro tools for CPT/taxonomy/meta field creation, relations management, site context grounding, and prompt template access. MCP-first dispatch with REST v2 fallback.
๐ค Agent-to-Agent (A2A) Protocol โญ NEW - Full A2A protocol making NV oOS assistants discoverable and interoperable with any A2A-compliant agent.
/.well-known/agent.jsondiscovery, JSON-RPC 2.0 server with task state machine, A2A client for remote agent delegation, push notification webhooks.๐ Agent Command Center โญ NEW - Unified agent management dashboard with 7 tabs: Overview (KPI cards, live status), Activity Log, Active Tasks, Approvals (human-in-the-loop), Analytics (Chart.js with real per-agent metrics), Uptime & Health, and Strategy (efficiency scoring with recommendations).
๐ฌ Floating Chat Bubble โญ NEW - Configurable floating chat bubble widget for Elementor and Gutenberg. 4 position variants, 3 sizes, bounce/pulse animations, dark mode, WCAG focus states, sessionStorage persistence.
๐งท Granular control over allowed attachment MIME types for chat uploads
๐ Secure REST API endpoints
๐ Root Security Key - Optional wp-config.php constant that can be enabled during emergency shutdown to require authentication before re-initializing the plugin. Provides an additional layer of protection against unauthorized reactivation after security incidents.ใF:docs/features/security/root-security-key.mdโ L1-L511ใใF:includes/class-wp-mcp-ai-root-security-key.phpโ L1-L360ใ
๐ฐ Assistant directory endpoint that advertises MCP tool/resource capabilities and negotiates Server-Sent Events handshakes for clients such as LM Studio or Claude Desktop.ใF:includes/class-wp-mcp-ai-rest.phpโ L520-L666ใใF:includes/class-wp-mcp-ai-rest.phpโ L1690-L1772ใ
๐ Full JSON-RPC 2.0 MCP endpoint (
/mcp) for standards-compliant remote client communication๐ Configurable API credentials and defaults for OpenAI, Gemini, and Anthropic (with subscription tier support for Team/Enterprise plans and custom base URLs)
๐ค ChatGPTโs connector beta currently requires an Auth0 tenant; the pluginโs assistant credentials are compatible with LM Studio, Claude, and other MCP clients that support bearer headers directly.ใF:docs/reference/api/mcp-server-authentication.mdโ L22-L46ใ
๐ Mesh networking for distributed compute pooling across multiple WordPress sites. Server-to-server architecture enables anonymous and authenticated users to benefit from shared AI resources, budget pooling, and workload distribution across 100+ trusted peer sites. Backend assistants coordinate mesh operations via secure inter-site keys while maintaining user attribution and audit trails for compliance.ใF:docs/features/federation/mesh-compute-pooling.mdโ L1-L615ใใF:includes/tools/class-wp-mcp-ai-tool-query-remote-site.phpโ L1-L237ใ
๐ Federation & Discovery - Decentralized AI capability network allowing WordPress sites to publish their capabilities via well-known endpoints (
/.well-known/ai-peer) and discover peer sites through directory services. Supports peer registration, health verification, search & ranking by capability/region/policy, and automatic cron-based health monitoring. Enable federation to join the network or run your own directory service for private peer discovery.ใF:docs/features/federation/federation-discovery.mdโ L1-L511ใใF:FEDERATION-IMPLEMENTATION-SUMMARY.mdโ L1-L381ใ๐งพ Optional logging of chat interactions, tool executions, and API errors
๐งฎ Built-in per-user usage tracking for provider/model billing summaries
๐งฉ Developer hooks and filters for integrating custom behaviours
โฑ Per-site request timeout control with sensible minimum enforcement
๐ Toggleable uninstall cleanup to purge stored assistants and settings automatically
Performance & reliability
โก Client-side message bundling (800ms window) to reduce API calls and server loadใF:docs/user-guides/chat/message-bundling-feature.mdโ L1-L80ใ
๐ฏ Intelligent token overflow handling with automatic model switching (gpt-4.1-mini โ Gemini 2.0 Flash)ใF:docs/features/tools/presets/high-token-tool-handling.mdโ L1-L80ใ
๐ก Server-Sent Events (SSE) support for real-time streaming responses and job notificationsใF:docs/features/streaming/ENABLE-SSE-STREAMING.mdโ L1-L100ใ
๐ Real-time job status updates via SSE streaming and webhook notifications for async operationsใF:docs/features/async-jobs/job-notification-system.mdโ L1-L100ใ
๐ง Symfony Process Component - Modern process execution framework replacing direct
exec()calls in Pro addon tools for enhanced security, timeout management, and error handlingใF:includes/services/class-wp-mcp-ai-process-service.phpโ L1-L220ใใF:docs/history/2025/implementations/symfony-phases/SYMFONY_PHASE2B_PROCESS_INTEGRATION.mdโ L1-L100ใ๐ Server-side WP-Cron polling for long-running tasks (Crawl4AI, background jobs)
๐พ Chat history persistence with localStorage (24h) and optional JetEngine CCT storageใF:docs/user-guides/chat/chat-history-persistence.mdโ L1-L50ใ
โ๏ธ Optimized settings page with external CSS stylesheet (240 lines added to admin-settings.css) and request-level caching for improved admin performanceใF:assets/css/admin-settings.cssโ L1-L984ใใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L27-L32ใ
Settings Management โญ NEW
๐ง Robust Settings System - 7-step save process with automatic backups, validation, and cache management ensures settings persist correctly across all tabs and subtabsใF:includes/admin/class-wp-mcp-ai-settings-dashboard.phpโ L262-L410ใ
๐ Health Check - Run 6 diagnostic checks to verify settings integrity, provider configuration, and system status with GOOD/WARNING/CRITICAL status indicatorsใF:includes/admin/sections/class-wp-mcp-ai-section-advanced.phpโ L1500-L1650ใ
๐พ Export Settings - Download all plugin settings as timestamped JSON files for backup or migration to other sitesใF:docs/admin-guides/settings-management.mdโ L40-L80ใ
๐ค Import Settings - Upload and validate settings from previously exported backups with automatic pre-import backup and 5-step validationใF:docs/admin-guides/settings-management.mdโ L85-L135ใ
๐๏ธ Clear Cache - One-click clearing of static cache, object cache, and transients when settings changes don't take effectใF:docs/admin-guides/settings-management.mdโ L140-L165ใ
โฉ๏ธ Reset to Defaults - Safely reset all settings to default values with automatic backup before resetใF:docs/admin-guides/settings-management.mdโ L170-L200ใ
๐ Security - File size validation (max 5MB), MIME type checking, JSON validation, and comprehensive input sanitizationใF:includes/admin/class-wp-mcp-ai-settings-dashboard.phpโ L970-L1030ใ
๐ Automatic Backups - Every save operation creates a timestamped backup (keeps last 5) for emergency recoveryใF:includes/admin/class-wp-mcp-ai-settings-dashboard.phpโ L285-L295ใ
๐ก๏ธ Data Protection - 3-layer protection (section filtering, merge strategy, sensitive key filtering) prevents accidental data loss when saving from tabs/subtabsใF:docs/admin-guides/settings-management.mdโ L230-L280ใ
๐ Pro Toolkits - Enable and configure 8 specialized Pro toolkits (650+ tools) including Project Management, Document Generation, Health & Wellness, CRE Debt & Securitization, and moreใF:docs/admin-guides/pro-settings-toolkits.mdโ L1-L650ใ
โก๏ธ Complete Documentation: Settings Management Guide | Quick Reference | Visual UI Guide | Pro Toolkits Guide
๐ง Memory & Tool Stack Overview
Model defaults
Global settings capture the default provider, model, and timeout used when assistants are created, ensuring every conversation inherits stable generation behaviour until explicitly overridden. These defaults ship with sensible values for OpenAI and Gemini out of the box and can be tailored from the NV oOS settings screen.ใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L36-L77ใ
Base knowledge
Each assistant can preload Media Library files and optionally link to an external vector store, giving the model persistent project context before a chat begins. Editors manage these knowledge sources from the assistant post type via the โBase Knowledgeโ meta box, which supports multiple attachments and vector store identifiers.ใF:includes/assistants/class-wp-mcp-ai-assistant-cpt.phpโ L892-L1002ใ
Available tools
The tool registry boots with a curated catalogue of content, commerce, automation, and research utilities, then exposes hooks so developers can register their own providers. During initialisation the registry loads each bundled tool classโranging from JetEngine accessors to Crawl4AI jobs and Mailjet automationsโand makes them callable within conversations.ใF:includes/class-wp-mcp-ai-tool-registry.phpโ L74-L220ใ
Chat-client Memory Drawer
The chat front-end exposes a persistent Memory Drawer (assets/js/chat-memory-drawer.js) with three tabs:
Memories โ browse, pin, and delete stored context items; ๐ง badge auto-appears on any assistant message that used a memory tool.
Scope โ set the active wing/room scope for subsequent memory operations in the current session.
Audit โ lazy-loaded audit trail from
WP_MCP_AI_REST_Chat_Memory_Controller::audit().
The drawer is wired to the REST proxy at /mcp-ai/v1/chat-memory/ and receives real-time updates via the memory_event SSE frame emitted by the agentic loop. Pagehide auto-capture stores the session state before tab close. Two gates control access: site-wide filter wp_mcp_ai_chat_memory_enabled and per-user meta wp_mcp_ai_chat_memory_enabled. Full reference: docs/features/memory/chat-client-integration.md.
Retroactive Transcript Mining
WP_MCP_AI_Transcript_Mining_Job retrospectively extracts memories from past chat transcripts. Enqueue a job via POST /mcp-ai/v1/transcript-mining/jobs (admin-only), poll progress with GET /jobs/{id}, or cancel with POST /jobs/{id}/cancel. Full reference: docs/features/memory/transcript-mining.md.
LLM Harnessing Subsystem
Seven opt-in per-request layers (includes/harness/) improve response quality without changing existing tool behaviour. Activated per-assistant via the LLM Harness metabox. Layers: A Prompt/Cue โ B Reasoning Trace โ C Tool Routing โ D Retrieval โ E Self-Refine โ F Memory Scoping + PII Filter โ G Eval Scheduler. Pro Layer H exports fine-tune curricula as OpenAI JSONL. Full reference: docs/features/llm-harness.md.
Workflow families & tool combos
The core plugin ships with a centrally registered tool catalogue that lets assistants mix and match capabilities into cohesive workflows without additional coding. Teams can chain authoring, media, research, commerce, marketing, and operational tools to deliver end-to-end outcomes inside a single conversation.
Content & knowledge production โ Combine
submit_document_prompt,search_content, andsearch_attachmentsto gather source material, then follow up withsave_post,create_wpcode_snippet, orget_rankmath_seofor structured drafting and optimisation.Media generation & transcription โ Pair
generate_openai_image,generate_gemini_image,vectorize_image, orgraphic_editor_pluswithgenerate_openai_speechandtranscribe_openai_audioto build multimedia assets that flow into editorial or marketing outputs. Usevectorize_imageto convert logos to scalable vectors, andgraphic_editor_plusfor comprehensive image editing with both local and AI-powered operations.Research & situational awareness โ Chain discovery helpers like
web_search,run_crawl4ai_job,reliefweb_reports,get_gdacs_events, andget_nhc_active_stormsto assemble briefing packs before drafting follow-up actions.Commerce & finance operations โ Use WooCommerce and finance tools such as
create_woo_product,get_woo_products,get_woo_recent_orders,crawl4ai_price_lookup,get_import_duty, andquickbooks_reportto coordinate merchandising, pricing, and bookkeeping reviews.Marketing & analytics insights โ Combine measurement tools including
google_analytics_report,get_google_business_insights,get_facebook_instagram_insights,get_linkedin_insights, andget_tiktok_insightsto guide campaigns and reporting.Publishing & outreach automations โ Trigger distribution via
post_facebook_instagram,post_google_business_update,post_linkedin_update,post_tiktok_video,send_group_email,send_mailjet_email,send_telegram_message,send_whatsapp_message, andschedule_notify_smsonce plans are ready.Integrations & scheduling โ Connect external systems with
create_google_calendar_event,search_gmail,list_jetengine_rest_routes,invoke_jetengine_route, andrun_openai_external_actionas part of larger automations.Operations & diagnostics โ Close the loop with
create_cron_job,list_cron_jobs,get_cron_job,delete_cron_job,check_wp_cli,purge_cache,purge_cloudflare_cache,purge_varnish_cache,get_site_summary,get_site_health,get_system_logs,get_update_status, and OpenAI usage/log review helpers for monitoring and maintenance.Automation & scheduling workflows โ Agents can autonomously schedule background tasks with
create_cron_job, monitor scheduled operations vialist_cron_jobsandget_cron_job, and clean up outdated automations withdelete_cron_job. Combine with cache management tools (purge_cache,purge_cloudflare_cache,purge_varnish_cache) to orchestrate content publishing workflows where agents schedule posts, then automatically invalidate caches at publication time.
๐ Built-in tools & automations
The assistant registry ships with a comprehensive catalogue of editorial, marketing, commerce, and operational helpers. The tables below outline every bundled tool and the slug assistants call when orchestrating workflows.
Content & knowledge workflows
Tool | Slug | Summary |
Submit Document Prompt |
| Uploads WordPress attachments or OpenAI file IDs alongside an instruction so multimodal prompts reach the Responses API with the required file context.ใF:includes/tools/class-wp-mcp-ai-tool-submit-document-prompt.phpโ L20-L214ใ |
Search Content |
| Queries public post types with optional taxonomy and meta filters to surface structured post metadata for the assistant.ใF:includes/tools/class-wp-mcp-ai-tool-search-content.phpโ L12-L280ใ |
Search Attachments |
| Scans the Media Library with keyword or MIME filters while honouring attachment capability checks and signed download URLs.ใF:includes/tools/class-wp-mcp-ai-tool-search-attachments.phpโ L15-L207ใ |
Get Recent Posts |
| Returns the latest entries for a given post type with titles, permalinks, excerpts, and timestamps for quick editorial summaries.ใF:includes/tools/class-wp-mcp-ai-tool-get-recent-posts.phpโ L12-L104ใ |
Get Elementor Templates |
| Lists Elementor library templates with status, type, and edit links when Elementor is available and the caller has access.ใF:includes/tools/class-wp-mcp-ai-tool-get-elementor-templates.phpโ L12-L239ใ |
Get JetEngine Items |
| Retrieves JetEngine-managed content with capability-aware access checks for each registered custom post type.ใF:includes/tools/class-wp-mcp-ai-tool-get-jetengine-items.phpโ L12-L118ใ |
Get JetFormBuilder Forms |
| Proxies JetFormBuilder REST controllers to return paginated form metadata with automatic REST/HTTP fallbacks.ใF:includes/tools/class-wp-mcp-ai-tool-get-jetformbuilder-forms.phpโ L15-L155ใ |
Get JetFormBuilder Submissions |
| Lists recent JetFormBuilder entries with normalised field snapshots and capability enforcement.ใF:includes/tools/class-wp-mcp-ai-tool-get-jetformbuilder-submissions.phpโ L15-L154ใ |
Save Post |
| Drafts or updates posts and custom post types with sanitised Gutenberg content, slug/title overrides, and edit links.ใF:includes/tools/class-wp-mcp-ai-tool-save-post.phpโ L15-L268ใ |
Create WPCode Snippet ๐ |
| Provisions or updates WPCode-managed snippets, validating code types, insert locations, and activation status. Pro addon tool.ใF:addons/pro/includes/src/Tools/class-wp-mcp-ai-pro-tool-create-wpcode-snippet.phpโ L15-L224ใ |
Get Rank Math SEO Overview |
| Surfaces Rank Math SEO scores, focus keywords, robots metadata, and schema details for a specific post when the plugin is active.ใF:includes/tools/class-wp-mcp-ai-tool-get-rankmath-seo.phpโ L15-L220ใ |
Get User Information |
| Inspects the acting user or a supplied account while respecting multisite membership and capability requirements.ใF:includes/tools/class-wp-mcp-ai-tool-get-user-info.phpโ L12-L89ใ |
Media generation & transcription
Tool | Slug | Summary |
Generate OpenAI Image |
| Calls the OpenAI Images API with configurable defaults, saving the rendered asset to the Media Library with optional overrides.ใF:includes/tools/class-wp-mcp-ai-tool-generate-openai-image.phpโ L17-L218ใ |
Generate Gemini Image |
| Uses Geminiโs multimodal image endpoint to render creative, aspect-ratio-aware visuals that are persisted as WordPress attachments.ใF:includes/tools/class-wp-mcp-ai-tool-generate-gemini-image.phpโ L17-L200ใ |
Generate Cloudflare AI Image |
| Creates images using Cloudflare Workers AI text-to-image models including Stable Diffusion XL, Flux-2 Dev, Leonardo AI (Lucid Origin, Phoenix 1.0), and Dreamshaper with configurable dimensions, steps, and guidance parameters. |
Vectorize Image |
| Converts raster images (PNG, JPEG, WebP, GIF) to SVG vector format with configurable quality settings using @neplex/vectorizer. Perfect for logos, icons, and graphics. Requires Node.js 14+.ใF:includes/tools/class-wp-mcp-ai-tool-vectorize-image.phpโ L1-L430ใ |
Graphic Editor Plus |
| Comprehensive image editing with local operations (logo overlay, resize) and AI-powered features (style transfer, background removal, enhancement). Combines speed with intelligent transformations.ใF:includes/tools/class-wp-mcp-ai-tool-graphic-editor-plus.phpโ L1-L784ใ |
Generate Architectural Drawing ๐ |
| [PRO] Creates professional architectural drawings (floor plans, elevations, sections, details) for construction projects. Supports 10 drawing types, 6 presentation styles (technical, sketched, rendered), dimensional specifications, building codes (IBC, IRC, NBC, Eurocode), and material lists. Outputs PNG or SVG with automatic vectorization. Perfect for architects, engineers, and construction professionals.ใF:addons/pro/includes/tools/class-wp-mcp-ai-tool-generate-architectural-drawing.phpโ L1-L1136ใ |
Generate OpenAI Speech |
| Converts text to audio via OpenAIโs text-to-speech models, honouring default voice/format selections and storing results in the Media Library.ใF:includes/tools/class-wp-mcp-ai-tool-generate-openai-speech.phpโ L17-L199ใ |
Generate Music |
| Creates instrumental music from text descriptions using Google Gemini Lyria model with controls for genre, mood, duration, and tempo. |
Transcribe OpenAI Audio |
| Sends uploaded audio to OpenAIโs transcription/translation endpoints and returns structured transcripts with language and duration metadata.ใF:includes/tools/class-wp-mcp-ai-tool-transcribe-openai-audio.phpโ L17-L195ใ |
Research & situational awareness
Tool | Slug | Summary |
Web Search |
| Performs lightweight lookups against DuckDuckGo or Brave, normalising related topics and enforcing per-user result caps.ใF:includes/tools/class-wp-mcp-ai-tool-web-search.phpโ L12-L320ใ |
Run Crawl4AI Job |
| Executes Crawl4AI harvests locally or remotely, collecting Markdown, HTML, and error payloads for long-form content ingestion workflows.ใF:includes/tools/class-wp-mcp-ai-tool-run-crawl4ai-job.phpโ L32-L745ใ |
ReliefWeb Reports |
| Queries ReliefWebโs humanitarian dataset by country or disaster type and returns structured report metadata for situational updates.ใF:includes/tools/class-wp-mcp-ai-tool-reliefweb-reports.phpโ L15-L234ใ |
Get GDACS Events |
| Fetches Global Disaster Alert and Coordination System events with optional date filters and capability checks for emergency planning.ใF:includes/tools/class-wp-mcp-ai-tool-get-gdacs-events.phpโ L12-L200ใ |
Get NHC Active Storms |
| Retrieves the National Hurricane Centerโs active storm feed, sanitising advisory data for assistant consumption.ใF:includes/tools/class-wp-mcp-ai-tool-get-nhc-active-storms.phpโ L15-L146ใ |
Get Open-Meteo Forecast |
| Pulls hourly weather data from Open-Meteo with coordinate, timezone, and variable controls for itinerary-aware responses.ใF:includes/tools/class-wp-mcp-ai-tool-get-open-meteo-forecast.phpโ L15-L309ใ |
Vision Product Search |
| Searches for similar products using Google Cloud Vision API Product Search feature. Note: Requires proper Google Cloud authentication credentials to succeed.ใF:includes/tools/class-wp-mcp-ai-tool-vision-product-search.phpโ L1-L200ใ |
Vision Object Localization |
| Detects and localizes multiple objects in images using Google Cloud Vision API. Note: Requires proper Google Cloud authentication credentials to succeed.ใF:includes/tools/class-wp-mcp-ai-tool-vision-object-localization.phpโ L1-L200ใ |
Commerce & finance operations
Tool | Slug | Summary |
Create WooCommerce Product Draft |
| Builds draft WooCommerce products with merchandising copy, pricing, images, and brand metadata when WooCommerce is active.ใF:includes/tools/class-wp-mcp-ai-tool-create-woo-product.phpโ L15-L258ใ |
Get WooCommerce Products |
| Surfaces catalogue listings with pricing, stock status, and optional SKU/status filters for merchandiser reviews.ใF:includes/tools/class-wp-mcp-ai-tool-get-woo-products.phpโ L12-L140ใ |
Get Woo Recent Orders |
| Summarises recent WooCommerce orders with totals, billing details, and ISO timestamps for fulfilment teams.ใF:includes/tools/class-wp-mcp-ai-tool-get-woo-recent-orders.phpโ L12-L117ใ |
Update WooCommerce Product Price ๐ |
| Updates regular/sale prices across all product types (simple, variable via variations, grouped, external) with sale-date scheduling, validation, and automatic variable-parent sync. Pro addon tool.ใF:addons/pro/includes/tools/ecommerce/class-wp-mcp-ai-tool-update-woo-product-price.phpโ L1-L50ใ |
Update WooCommerce Product Quantity ๐ |
| Updates stock quantity across all stock-managed types with set/increase/decrease operations, canonical low-stock notifications (suppressible per call via |
Wholesale Club Price Lookup |
| Uses Crawl4AIโs web search endpoint to compare BJโs, Samโs Club, and Costco pricing for a given product query.ใF:includes/tools/class-wp-mcp-ai-tool-crawl4ai-price-lookup.phpโ L17-L189ใ |
Lookup Import Duty ๐ |
| Queries the ITA Tariff Rates API for HS codes or descriptions to surface import duty rates for supported countries. Pro addon tool.ใF:addons/pro/includes/src/Tools/class-wp-mcp-ai-pro-tool-get-import-duty.phpโ L15-L152ใ |
QuickBooks Online Report ๐ |
| Requests Profit & Loss, Balance Sheet, or custom QuickBooks Online reports with optional date ranges and accounting methods. Pro addon tool.ใF:addons/pro/includes/src/Tools/class-wp-mcp-ai-pro-tool-get-quickbooks-report.phpโ L15-L214ใ |
Marketing & analytics insights
Tool | Slug | Summary |
Google Analytics Report ๐ |
| Runs GA4 Analytics Data API queries with metrics, dimensions, date ranges, and aggregation controls to monitor site performance. Pro addon tool.ใF:addons/pro/includes/src/Tools/class-wp-mcp-ai-pro-tool-get-google-analytics-report.phpโ L15-L158ใ |
Google Business Insights |
| Fetches Google Business Profile metrics for a location using OAuth tokens, time ranges, and timezone hints. Pro addon tool.ใF:addons/pro/includes/src/Tools/class-wp-mcp-ai-pro-tool-get-google-business-insights.phpโ L15-L149ใ |
Meta Social Insights |
| Pulls Facebook Page or Instagram business metrics via the Graph API with selectable periods and metric sets. Pro addon tool.ใF:addons/pro/includes/src/Tools/class-wp-mcp-ai-pro-tool-get-facebook-instagram-insights.phpโ L15-L146ใ |
LinkedIn Insights |
| Queries LinkedIn organizational share statistics with optional timeframe and granularity filters. Pro addon tool.ใF:addons/pro/includes/src/Tools/class-wp-mcp-ai-pro-tool-get-linkedin-insights.phpโ L15-L138ใ |
TikTok Insights |
| Calls the TikTok Open API to return account performance metrics across configurable windows and granularities. Pro addon tool.ใF:addons/pro/includes/src/Tools/class-wp-mcp-ai-pro-tool-get-tiktok-insights.phpโ L15-L136ใ |
Get Cross-Platform Analytics ๐ |
| [NEW Jan 2026] Unified social media metrics dashboard aggregating data from Facebook, Instagram, Twitter, LinkedIn, and YouTube. Provides engagement rates, follower growth, post performance, and comparative analytics across all platforms. Built-in 12-hour caching. Pro addon tool (623 lines). |
Track Hashtag Performance ๐ |
| [NEW Jan 2026] Comprehensive hashtag analysis tracking reach, engagement, impressions, and trend data across Facebook, Instagram, Twitter, LinkedIn, and YouTube. Identifies top-performing hashtags and provides optimization recommendations. Pro addon tool (586 lines). |
Competitor Analysis ๐ |
| [NEW Jan 2026] Track competitor social media metrics and benchmark performance against your profiles. Monitors follower growth, engagement rates, posting frequency, and content strategies across all major platforms. Pro addon tool (711 lines). |
Influencer Identification ๐ |
| [NEW Jan 2026] Discover brand influencers and potential collaboration partners based on reach, engagement criteria, audience demographics, and content relevance. Searches across Facebook, Instagram, Twitter, LinkedIn, and YouTube. Pro addon tool (759 lines). |
Publishing & outreach
Tool | Slug | Summary |
Publish Meta Social Post ๐ |
| Publishes Facebook Page or Instagram business posts through the Meta Graph API with message, caption, and media controls. Pro addon tool.ใF:addons/pro/includes/src/Tools/class-wp-mcp-ai-pro-tool-post-facebook-instagram.phpโ L15-L170ใ |
Publish Google Business Update ๐ |
| Creates Google Business Profile local posts with summaries, language codes, and optional call-to-action links. Pro addon tool.ใF:addons/pro/includes/src/Tools/class-wp-mcp-ai-pro-tool-post-google-business-update.phpโ L15-L168ใ |
Publish LinkedIn Update ๐ |
| Sends LinkedIn UGC posts for members or organisations with optional share URLs via the LinkedIn Marketing API. Pro addon tool.ใF:addons/pro/includes/src/Tools/class-wp-mcp-ai-pro-tool-post-linkedin-update.phpโ L15-L160ใ |
Publish TikTok Video ๐ |
| Submits hosted video assets to TikTokโs Open API share endpoint with optional captions. Pro addon tool.ใF:addons/pro/includes/src/Tools/class-wp-mcp-ai-pro-tool-post-tiktok-video.phpโ L15-L152ใ |
Send Group Email |
| Orchestrates structured or free-form email campaigns with capability-based audience limits and logging hooks. Full documentation.ใF:includes/tools/class-wp-mcp-ai-tool-send-group-email.phpโ L16-L650ใ |
Send Mailjet Email ๐ |
| Delivers transactional and marketing emails through Mailjet with sender defaults, CC/BCC routing, and response metadata. Pro addon tool.ใF:addons/pro/includes/src/Tools/class-wp-mcp-ai-pro-tool-send-mailjet-email.phpโ L19-L405ใ |
Send Telegram Message ๐ |
| Posts formatted updates to Telegram chats or channels with capability filters and audit logging. Pro addon tool.ใF:addons/pro/includes/src/Tools/class-wp-mcp-ai-pro-tool-send-telegram-message.phpโ L16-L232ใ |
Send WhatsApp Message ๐ |
| Sends WhatsApp Cloud API text messages with preview controls using phone-number specific access tokens. Pro addon tool.ใF:addons/pro/includes/src/Tools/class-wp-mcp-ai-pro-tool-send-whatsapp-message.phpโ L15-L178ใ |
Schedule Notify.lk SMS ๐ |
| Queues Notify.lk SMS messages for future delivery using the official SDK and site cron orchestration. Pro addon tool.ใF:addons/pro/includes/src/Tools/class-wp-mcp-ai-pro-tool-schedule-notify-sms.phpโ L15-L180ใ |
Integrations & scheduling
Tool | Slug | Summary |
Create Google Calendar Event |
| Builds calendar events with attendees, reminders, and timeout overrides using OAuth tokens or service accounts.ใF:includes/tools/class-wp-mcp-ai-tool-create-google-calendar-event.phpโ L17-L378ใ |
Search Gmail Messages |
| Performs delegated Gmail queries with optional label filters and pagination, returning normalised message metadata. Pro addon tool.ใF:addons/pro/includes/src/Tools/class-wp-mcp-ai-pro-tool-search-gmail.phpโ L1-L200ใ |
List JetEngine REST Routes |
| Enumerates JetEngine REST endpoints with method, callback, and capability metadata for developers.ใF:includes/tools/class-wp-mcp-ai-tool-list-jetengine-routes.phpโ L12-L151ใ |
Invoke JetEngine REST Route |
| Proxies JetEngine CRUD operations using the authenticated user context with REST/HTTP fallbacks.ใF:includes/tools/class-wp-mcp-ai-tool-invoke-jetengine-route.phpโ L12-L133ใ |
Run OpenAI External Action |
| Triggers OpenAI Responses API workflows or assistants with payload sanitisation, timeout overrides, and structured errors.ใF:includes/tools/class-wp-mcp-ai-tool-run-openai-external-action.phpโ L17-L211ใ |
Operations & diagnostics
Tool | Slug | Summary |
Cron Management Suite | AI agents can autonomously schedule, monitor, and manage WordPress background tasks | |
Create Cron Job |
| Schedules one-off or recurring WP-Cron events with duplicate detection and sanitised hooks/arguments. Agents can automate periodic maintenance, content publishing, or custom workflows by scheduling actions to run at specific times or intervals.ใF:includes/tools/class-wp-mcp-ai-tool-create-cron-job.phpโ L16-L168ใ |
List Cron Jobs |
| Lists all scheduled WordPress cron jobs with details about schedule, next run time, and creator. Enables agents to provide visibility into scheduled automation tasks and audit what background processes are running.ใF:includes/tools/class-wp-mcp-ai-tool-list-cron-jobs.phpโ L17-L141ใ |
Get Cron Job |
| Retrieves detailed information about a specific WordPress cron job by its job ID, including schedule interval details and execution metadata. Allows agents to inspect individual scheduled tasks for troubleshooting or reporting.ใF:includes/tools/class-wp-mcp-ai-tool-get-cron-job.phpโ L17-L145ใ |
Delete Cron Job |
| Deletes a scheduled WordPress cron job and removes it from both the plugin tracking and WP-Cron. Enables agents to cancel outdated or unnecessary automation tasks on behalf of operators.ใF:includes/tools/class-wp-mcp-ai-tool-delete-cron-job.phpโ L17-L90ใ |
Cache Management | AI agents can coordinate multi-layer cache invalidation | |
Purge Cache |
| Master cache purge tool that coordinates multi-layer cache clearing (Cloudflare, Varnish, etc.) in the correct order. Agents can ensure content updates are properly reflected across all caching layers.ใF:includes/tools/class-wp-mcp-ai-tool-purge-cache.phpโ L17-L150ใ |
Purge Cloudflare Cache |
| Sends targeted or full-zone invalidations to Cloudflare with configurable timeouts and admin-only access controls.ใF:includes/tools/class-wp-mcp-ai-tool-purge-cloudflare-cache.phpโ L17-L292ใ |
Purge Varnish Cache |
| Purges the local Varnish cache with support for full-cache bans and specific URL purges. Agents can clear server-side caching to ensure immediate content updates.ใF:includes/tools/class-wp-mcp-ai-tool-purge-varnish-cache.phpโ L17-L150ใ |
System Monitoring & Diagnostics | ||
Check Site Security |
| Checks if the WordPress site has security vulnerabilities that make it unsafe to use this AI plugin. Scans for common security issues and provides remediation guidance for administrators.ใF:includes/tools/class-wp-mcp-ai-tool-check-site-security.phpโ L1-L200ใ |
Check WP-CLI Status |
| Scans for the WordPress CLI binary, returning detected paths, version output, and environment warnings.ใF:includes/tools/class-wp-mcp-ai-tool-check-wp-cli.phpโ L17-L309ใ |
Count Tokens |
| Estimates token counts for text and messages using heuristic estimation (approximately 4 characters per token) for planning and budgeting purposes. Helps with capacity planning before sending requests to AI providers.ใF:includes/tools/class-wp-mcp-ai-tool-count-tokens.phpโ L1-L200ใ |
Get Site Summary |
| Provides high-level site metadata, content counts, and admin contact details for context-aware assistants.ใF:includes/tools/class-wp-mcp-ai-tool-get-site-summary.phpโ L12-L66ใ |
Get MCP Environment Status |
| Summarises WordPress versions, MCP defaults, assistant counts, and dependency warnings for incident response.ใF:includes/tools/class-wp-mcp-ai-tool-get-environment-status.phpโ L12-L178ใ |
Get Site Health Status |
| Runs WordPress Site Health diagnostics and returns grouped pass/warn/fail tests with remediation guidance.ใF:includes/tools/class-wp-mcp-ai-tool-get-site-health.phpโ L12-L255ใ |
Get System Logs |
| Aggregates NV oOS logs, WordPress/PHP error logs, and plugin log files to aid in debugging workflows.ใF:includes/tools/class-wp-mcp-ai-tool-get-system-logs.phpโ L12-L352ใ |
Get Update Status |
| Reports pending core, plugin, and theme updates with version and download metadata for maintenance planning.ใF:includes/tools/class-wp-mcp-ai-tool-get-update-status.phpโ L12-L182ใ |
Testing & Validation | ||
Probe Assistant Chat |
| Issues a chat probe against a published assistant to confirm sanitisation, configuration, and REST handling without consuming model tokens.ใF:includes/tools/class-wp-mcp-ai-tool-probe-chat.phpโ L12-L178ใ |
Probe Remote MCP REST |
| Reuses the remote connectivity tester to exercise |
Mesh Networking | Distributed compute pooling across WordPress sites | |
Query Remote Site |
| Executes chat requests on peer WordPress sites in a mesh network. Requires |
Query Mesh (Intelligent Routing) |
| Send a prompt to the mesh network with AI-powered peer selection and automatic failover. The system intelligently routes requests to the optimal peer site based on current load, response times, and task complexity. Provides resilient distributed compute with automatic retry logic.ใF:includes/tools/class-wp-mcp-ai-tool-query-mesh-intelligent.phpโ L1-L300ใ |
Provider Dashboards | ||
Open OpenAI Logs |
| Returns dashboard shortcuts for reviewing OpenAI request logs in the provider console.ใF:includes/tools/class-wp-mcp-ai-tool-open-openai-logs.phpโ L12-L66ใ |
Open OpenAI Usage |
| Provides direct links to OpenAI usage dashboards so admins can audit consumption quickly.ใF:includes/tools/class-wp-mcp-ai-tool-open-openai-usage.phpโ L12-L66ใ |
Authentication | ||
Generate Simple JWT Token |
| Generates a Simple JWT Login bearer token for the current user, enabling authenticated API access across sessions. Agents can help users obtain authentication tokens for headless WordPress integrations.ใF:includes/tools/class-wp-mcp-ai-tool-generate-simple-jwt-token.phpโ L15-L120ใ |
What the Cron Manager means to AI agents
The Cron Management Suite transforms AI assistants from reactive responders into proactive automation orchestrators. By providing full control over WordPress's background task scheduler, agents can:
Autonomous Task Scheduling
Schedule content publishing workflows to go live at optimal times without human intervention
Automate recurring maintenance tasks like cache clearing, database optimization, or backup operations
Coordinate multi-step operations that span hours or days by chaining scheduled hooks
Intelligent Monitoring & Self-Management
List and inspect all scheduled tasks to understand what automation is currently active
Audit who created each task and when it's scheduled to run next
Identify and remove outdated or redundant scheduled tasks to maintain system health
Real-World Agent Workflows
Content Calendar Automation - An agent helping with content strategy can schedule posts to publish at researched optimal engagement times, set up recurring social media cross-posts, and schedule follow-up email campaigns.
Site Maintenance Orchestration - When troubleshooting performance issues, agents can schedule off-peak cache purges, coordinate database cleanup tasks, and set up recurring health check notifications.
Business Process Automation - Agents can schedule recurring report generation, periodic data syncs with external systems, and automated backup verification checks.
Technical Implementation
The cron manager tracks all scheduled tasks in wp_mcp_ai_cron_jobs option with full audit trails including:
Job ID for unique identification
Hook name and sanitized arguments
Schedule type (single-run or recurring interval)
Creation timestamp and user attribution
Next execution time for monitoring
Jobs are automatically pruned when they complete (single-run) or are manually removed (recurring), keeping the tracking database clean. All cron operations require manage_options capability, ensuring only authorized users can delegate automation authority to agents.ใF:includes/class-wp-mcp-ai-cron-manager.phpโ L12-L280ใ
Each tool inherits the assistant context and authenticated user from the REST layer, making it easy to layer custom permissions or extend behaviour via the documented filters and actions.ใF:includes/class-wp-mcp-ai-rest.phpโ L236-L360ใใF:includes/class-wp-mcp-ai-rest.phpโ L1124-L1198ใ
Need per-tool prerequisites or capability callouts? Consult docs/reference/tools/tool-reference.md for a detailed matrix of every bundled integration.
Tool Status Labels
The Tools Manager page displays status labels beside tool names to indicate their development stage and stability:
Status | Display Label | Description | Auto-Disable |
stable | STA | Production-ready, fully tested tools safe for all environments | No |
beta | BET | Testing phase, mostly stable but may have minor issues | No |
dev | DEV | In active development, may have bugs or incomplete features | No |
experimental | EXP | New features that may change significantly | No |
bug | BUG | Known issues exist, use with caution | Yes |
deprecated | DEP | Will be removed in future versions | No |
Status labels are displayed as 3-letter abbreviations (e.g., "STA" for stable, "BET" for beta) to keep the UI compact.
Important: Tools marked with the bug status are automatically disabled when the plugin loads. This prevents problematic tools from being used until issues are resolved. Administrators can manually re-enable them from the Tools Manager if needed for testing.
Status labels are managed via the tool-status.txt file in the repository. To assign a status label to a tool:
Open
docs/tool-status.txtin a text editorAdd a line in the format:
tool_slug = status_labelSave the file - changes appear immediately in the Tools Manager
Example:
create_post = stable
web_search = beta
generate_openai_image_validated = experimental
problematic_tool = bugThis file-based approach allows quick status updates without code changes, making it easy for maintainers to reflect tool maturity as development progresses. The automatic disabling of buggy tools provides an additional safety layer to prevent issues in production environments.
๐จ Front-end chat surfaces
NV oOS ships multiple ways to embed assistants on the front end:
Classic chat shortcode โ
[mcp_ai_chat]renders the bundled interface with attachment uploads, tool invocation feedback, and optional guest access viaallow_guests="true". When guest mode is enabled, the shortcode provisions a temporary token and injects it into the JavaScript bootstrap so visitors without WordPress accounts can continue chatting while still respecting capability checks and attachment safety limits.ใF:includes/class-wp-mcp-ai-shortcode.phpโ L132-L258ใใF:includes/class-wp-mcp-ai-shortcode.phpโ L188-L226ใFloating chat bubble โญ NEW โ A configurable floating button that sits at a screen corner and opens a chat panel powered by the
[mcp_ai_chat]shortcode. Available as both an Elementor widget and a Gutenberg block. Supports 4 position variants, 3 sizes, auto-open delay, session persistence, dark mode, and WCAG keyboard navigation.ใF:includes/elementor/class-wp-mcp-ai-elementor-chat-bubble-widget.phpโ L1-L200ใใF:includes/blocks/chat-bubble/block.jsonโ L1-L50ใElementor widgets โ Drop the chat UI anywhere Elementor is active, pair it with intro/FAQ blocks, and surface dashboard telemetry without custom code. The chat widget mirrors the shortcode controls (including
allow_guests), and companion widgets expose onboarding content, usage timers, provider quick links, and activity feeds for operational views.ใF:includes/elementor/class-wp-mcp-ai-elementor-widget.phpโ L79-L138ใใF:includes/class-wp-mcp-ai-elementor-integration.phpโ L48-L98ใใF:includes/elementor/class-wp-mcp-ai-elementor-chat-intro-widget.phpโ L47-L140ใใF:includes/elementor/class-wp-mcp-ai-elementor-chat-usage-timer-widget.phpโ L48-L226ใใF:includes/elementor/class-wp-mcp-ai-elementor-dashboard-activity-feed-widget.phpโ L48-L167ใ
Guest tokens are honoured by the REST endpoints through the X-WP-MCP-AI-Guest header or guest_token parameter, allowing the chat shortcode and Elementor widget to make authenticated requests on behalf of public visitors without exposing persistent credentials.ใF:includes/class-wp-mcp-ai-rest.phpโ L289-L307ใใF:includes/class-wp-mcp-ai-rest.phpโ L2088-L2104ใ
Chat History Persistence
The chat interface automatically persists conversation history to the browser's localStorage, preventing data loss when users navigate away or refresh the page. Conversations are:
Automatically saved after each user message and assistant response
Automatically restored when returning to the chat page (within 24 hours)
Stored per assistant so different assistant conversations remain separate
Server-side storage available with JetEngine - See note below about optional JetEngine integration
Server-Side Chat Transcript Storage (Requires JetEngine)
โ ๏ธ Third-Party Plugin Required: JetEngine (not included with NV oOS)
Without JetEngine, chat conversations are only stored in browser localStorage (client-side, 24-hour retention). To enable permanent server-side chat transcript archiving:
Install and activate the JetEngine plugin (third-party, paid plugin from Crocoblock)
Enable the Custom Content Types module in JetEngine settings
NV oOS will automatically provision the
ai_chat_transcriptsCCT for permanent storage
What you get with JetEngine:
โ Permanent server-side chat transcript storage
โ Cross-device conversation access
โ Admin visibility into chat history
โ Database-backed chat logs for compliance/auditing
Without JetEngine:
โ ๏ธ Chat history only stored in browser localStorage
โ ๏ธ Limited to 24-hour retention
โ ๏ธ No cross-device synchronization
โ ๏ธ Lost if browser data is cleared
See docs/user-guides/chat/chat-history-persistence.md for complete details on the persistence mechanism, data structure, and troubleshooting.
๐ฆ Installation
โน๏ธ Plugin Directory Status
This plugin is currently pending approval in the WordPress Plugin Directory. We are committed to maintaining high quality and security standards throughout the review process. You can install the plugin manually from our GitHub repository or wait for the official WordPress Plugin Directory listing.
๐ Getting Started Wizard
After activating the plugin, you'll be redirected to a 4-step setup wizard that walks you through connecting an AI provider, choosing a use case, and creating your first assistant โ all in under 2 minutes. The wizard creates fully-configured assistants with tools, system prompts, and tuned temperatures so your site is working out of the box. You can access the wizard any time at NV oOS โ Getting Started or directly at/wp-admin/admin.php?page=wp-mcp-ai-getting-started.
๐ฑ Try It on Your PC
No live site. No API costs. No risk. The primary way to test NV oOS is a one-command demo that boots WordPress and the Complete bundle locally via WordPress Playground and wires the chat to your local Ollama โ no API key, no server, and no prompts leave your machine.
โก Fastest: One Command (Playground + Local Ollama)
One-time prerequisites:
Install Ollama and pull a model:
ollama pull llama3.1:8bAllow the local origin, then restart Ollama:
Windows:
setx OLLAMA_ORIGINS "https://playground.wordpress.net,http://localhost,http://127.0.0.1", then quit Ollama from the system tray and relaunch it.macOS / Linux:
OLLAMA_ORIGINS="https://playground.wordpress.net,http://localhost,http://127.0.0.1" ollama serve
Then run this command (requires Node.js 20+):
npx -y @wp-playground/cli@3.1.54 server --blueprint=https://raw.githubusercontent.com/nvdigitalsolutions/mcp-ai-wpoos/alpha-working/blueprints/ollama-demo.json --loginOpen the printed local URL (e.g. http://127.0.0.1:9400/ollama-test-lab/). The first boot takes a few minutes while it downloads and installs the whole stack โ after that you land on the Ollama Test Lab: a live status banner plus a chat that answers from your local model. Admin login: admin / password.
Full walkthrough, browser quick-preview link, and troubleshooting: docs/user-guides/playground-demo.md.
๐งฐ Classic 3-Step Install (Local, Studio, XAMPP, etc.)
Prefer a traditional local WordPress install? Follow the full walkthrough on the NV Digital Solutions blog: How to Test NV oOS on Your Own PC Using Local + Downloading the Plugin โ
Install a local WordPress environment โ Local by WP Engine or WordPress Studio is the easiest option (one-click install, no server config). Alternatives: XAMPP, MAMP, or DevKinsta.
Download the NV oOS plugin zip โ grab the latest release from GitHub Releases (look for
mcp-ai-wpoos-x.x.x.zip), or use the Code โ Download ZIP button for the current development snapshot.Upload, activate, and run the wizard โ in your local WordPress dashboard go to Plugins โ Add New โ Upload Plugin, select the zip, activate it, and follow the ๐ Getting Started Wizard. For a free local AI model (no API key needed), install LM Studio and point the wizard at
http://localhost:1234.
๐บ Single-file auto-installer (roadmap) โ A single cross-platform installer that bootstraps the entire stack automatically is on the roadmap. See the App / Plugin Distribution Proposal for current status and the plan.
Requirements
Minimum Requirements:
WordPress 6.0+
PHP 7.4+ (PHP 8.0+ recommended)
MySQL 5.7+ or MariaDB 10.3+
Optional Requirements for Enhanced Features:
Node.js 14+: Required for image vectorization tools (
vectorize_imagetool)PHP Functions:
proc_open,proc_close,proc_terminate(for Node.js integration and Process Service)These functions are often disabled on shared hosting for security
Can be enabled on Cloudways via Application Settings (see troubleshooting guide)
JetEngine Plugin: For CCT storage and advanced content management tools
WooCommerce: For e-commerce integration tools
Elementor: For visual page builder widgets
Note: The plugin works without optional requirements, but some features will be disabled. See deployment troubleshooting for enabling disabled PHP functions.
For Developers (GitHub Clone)
โ Production-Ready Repository
This repository includes production-optimized vendor dependencies with classmap-authoritative autoloading configured by default in composer.json. You can clone and activate immediately without running composer. Thecomposer installcommand is only needed if you want to update dependencies or add development tools.
โก Use a shallow clone
A full clone of this repository is ~10 GB due to its long history. Use--depth 1to download only the latest snapshot (~500 MB) โ much faster and smaller. If you later need the full history, rungit fetch --unshallow.git clone --depth 1 https://github.com/nvdigitalsolutions/mcp-ai-wpoos.git
If you're cloning from GitHub:
Option 1: Cloudways and Managed Hosting (Recommended)
For Cloudways and similar managed hosting platforms, clone directly into the WordPress plugins directory:
# SSH into your server
# Navigate to WordPress plugins directory
cd /home/master/applications/YOURAPP/public_html/wp-content/plugins/
# Clone the repository (production-ready, no composer needed!)
# Use --depth 1 for a fast shallow clone (recommended for production)
git clone --depth 1 https://github.com/nvdigitalsolutions/mcp-ai-wpoos.git
cd mcp-ai-wpoos
# Verify you're in the correct directory
pwd # Should show the plugins path
# Optional: Only needed for frontend asset rebuilding or development
# npm install && npm run build
# Optional: Only run if you need to update dependencies or add dev tools
# Note: Autoloader optimization is now configured by default in composer.json
# composer install --no-devโ ๏ธ Cloudways Important Notes:
Always clone directly into
/home/master/applications/YOURAPP/public_html/wp-content/plugins/Do NOT clone elsewhere and then move/copy - this causes
getcwd() failederrorsReplace
YOURAPPwith your actual Cloudways application name
Option 2: Local Development or VPS
For local development or standard VPS hosting:
# Option A: Clone directly into WordPress plugins directory (recommended, production-ready!)
cd /path/to/wordpress/wp-content/plugins/
# Use --depth 1 for a fast shallow clone (recommended for production)
git clone --depth 1 https://github.com/nvdigitalsolutions/mcp-ai-wpoos.git
cd mcp-ai-wpoos
# Ready to activate! No composer or npm needed for production use.
# Option B: Clone and copy (also production-ready!)
# Use --depth 1 for a fast shallow clone (recommended for production)
git clone --depth 1 https://github.com/nvdigitalsolutions/mcp-ai-wpoos.git
cd mcp-ai-wpoos
cp -r . /path/to/wordpress/wp-content/plugins/mcp-ai-wpoos/For Development Only:
# Only if you need to rebuild assets or modify dependencies:
npm install && npm run build
# Note: Autoloader optimization is now configured by default in composer.json
composer install --no-devOptional: Strip Dev Files for Production
If you are deploying via git clone to a production server with anti-malware / EDR scanning, the working tree will contain test fixtures that embed verbatim attack-payload literals (XSS canaries, SQL-injection samples, prompt-injection strings) used by the security test suite. These can occasionally trip signature-based scanners.
For a clean production tree, run the bundled strip script after cloning:
# Preview what would be removed
bin/strip-dev-files.sh --dry-run
# Remove tests/, docs/, bin/, .github/, .bmad/, .context/, examples/,
# phpunit.xml.dist, phpcs.xml.dist, dev configs, etc.
bin/strip-dev-files.shThe script mirrors the exclusion list in .distignore (used for the WordPress.org SVN deploy) and the export-ignore rules in .gitattributes (used for GitHub-distributed ZIPs). It is idempotent and refuses to run on a working tree with uncommitted changes (override with --force).
Note: Do not run this on a development checkout โ it removes the test suite, docs, and build tooling. It is intended for deploy targets that only run the plugin.
Final Steps
Activate Open Operator System Complete (NV oOS) from WordPress admin
You now have the complete version with all ~1,648 tools (~347 base + ~1,301 Pro; live count via
WP_MCP_AI_Tool_Registry::get_tools()is authoritative)
What you get from the repository clone:
โ The full codebase โ all ~1,648 built-in tools ready to use (~347 base + ~1,301 Pro; live count via
WP_MCP_AI_Tool_Registry::get_tools()is authoritative)โ Single plugin activation (not separate base + pro)
โ Pro features automatically available (no separate Pro plugin to install)
Notes:
The repository includes
mcp-ai-wpoos-base.phpandaddons/pro/mcp-ai-wpoos-pro.phpwhich are used for building separate distributions but do NOT appear as separate plugins when cloningOnly the main plugin file (
mcp-ai-wpoos.php) has a plugin header in the repositoryThe build script adds headers to the other files when creating standalone distributions
Standard Installation
Upload
mcp-ai-wpoos.zipto/wp-content/plugins/Activate NV oOS from the WordPress admin
Go to Settings โ NV oOS
Enter your OpenAI API key
Create a new โAI Assistantโ in AI Assistants
Add
[mcp_ai_chat assistant="123"]to a page or post
Optional: JetEngine Integration
โ ๏ธ Third-Party Plugin (Not Included): JetEngine is a paid plugin from Crocoblock
JetEngine is completely optional - NV oOS works perfectly without it. However, if you want server-side chat transcript storage:
Purchase and install JetEngine separately
Enable the Custom Content Types module in JetEngine settings
NV oOS will automatically provision the
ai_chat_transcriptsCCT for permanent chat storage
What works WITHOUT JetEngine:
โ All core AI assistant features
โ Chat interface and conversations
โ ~300 base tools (more with optional third-party plugins)
โ MCP server functionality (
/wp-json/mcp-ai/v1/)โ Browser-based chat history (localStorage, 24 hours)
โ OpenAI/Gemini/Anthropic/Ollama/Hugging Face/Cloudflare integrations
What requires JetEngine:
โ Server-side chat transcript storage (chat history only in browser without it)
โ 5 JetEngine-specific tools (see ๐ Optional Tools & Dependencies)
๐ What You Lose Without Third-Party Plugins
NV oOS works perfectly with vanilla WordPress, but certain features require third-party plugins (sold separately). Here's exactly what you lose without each plugin:
Without JetEngine (Crocoblock - Paid Plugin)
Lost Features:
โ AI metaboxes for JetEngine CPTs/Taxonomies - No AI assistant integration on JetEngine edit screens
โ Research & Add pages - No AI-powered content creation with automatic field mapping
โ Server-side chat transcript storage - Chat history only stored in browser localStorage (24 hours)
โ Cross-device chat synchronization - No database-backed conversation history
โ Admin chat history access - Cannot view/audit conversations from admin panel
โ Assistant CCT synchronization - Assistants only in WordPress CPT (MCP server still works perfectly)
Lost Tools (5 tools):
get_jetengine_items- Query JetEngine custom post typeslist_jetengine_rest_routes- List JetEngine REST API routesinvoke_jetengine_route- Execute JetEngine REST operationsget_jetformbuilder_forms- List JetFormBuilder forms (also requires JetFormBuilder)get_jetformbuilder_submissions- Get form submissions (also requires JetFormBuilder)
โ Still Works: All core features, MCP server, ~300 base tools, AI conversations
Without WooCommerce (Free Plugin)
Lost Features:
โ E-commerce automation - Cannot create or manage products via AI
โ Order management - Cannot query or analyze orders
โ Product catalog access - Cannot search or update product data
Lost Tools (3 tools):
create_woo_product- Build draft WooCommerce products with AI-generated descriptions, pricing, and imagesget_woo_products- Search and retrieve product catalog with pricing and stock statusget_woo_recent_orders- Summarize recent orders with billing details and totals
Use Cases Lost: E-commerce content generation, order fulfillment assistance, product merchandising
Without Elementor (Freemium Plugin)
Lost Features:
โ Template management - Cannot list or reference Elementor templates via AI
โ Elementor widgets - Cannot use pre-built chat/dashboard widgets (shortcodes still work)
Lost Tools (2 tools):
get_elementor_templates- List Elementor library templates with status, type, and edit linksimport_elementor_template_kit- Import Elementor template kits
Lost UI Components:
Elementor Chat Widget
Elementor Chat Intro Widget
Elementor Dashboard Widgets (Tool Matrix, User Capabilities, Activity Feed, etc.)
โ
Still Works: Standard [mcp_ai_chat] shortcode, all AI features
Without Rank Math SEO (Freemium Plugin)
Lost Features:
โ SEO analysis - Cannot query SEO scores or optimization recommendations
โ Schema data access - Cannot retrieve structured data for posts
Lost Tools (1 tool):
get_rankmath_seo- Get SEO scores, focus keywords, robots metadata, and schema details for posts
Use Cases Lost: AI-powered SEO content optimization, SEO audit assistance
Without WPCode (Freemium Plugin)
Lost Features:
โ Code snippet management - Cannot create or update code snippets via AI
โ Custom functionality automation - Cannot automate adding hooks, filters, or custom code
Lost Tools (1 tool):
create_wpcode_snippet- Create or update code snippets with validation and activation control
Use Cases Lost: AI-assisted custom development, automated code snippet generation
Without Simple JWT Login (Free Plugin)
Lost Features:
โ JWT token generation - Cannot generate JWT bearer tokens for headless WordPress integrations
Lost Tools (1 tool):
generate_simple_jwt_token- Generate JWT bearer tokens for authenticated API access
Use Cases Lost: Headless WordPress authentication, mobile app integration, SPA authentication
Summary: Third-Party Plugin Dependencies
Plugin | Type | Tools Lost | Key Feature Lost |
JetEngine | Paid (Crocoblock) | 5 | Server-side chat transcript storage |
WooCommerce | Free | 3 | E-commerce automation |
Freemium | 2 + Widgets | Elementor template integration | |
Rank Math | Freemium | 1 | SEO analysis |
WPCode | Freemium | 1 | Code snippet management |
Simple JWT Login | Free | 1 | JWT token generation |
Total Impact: Without these plugins, you lose 13 tools but retain ~300 base tools and all essential AI assistant functionality.
Base Version (Default)
NV oOS runs in Base Version mode by default, providing ~300 essential tools that work with vanilla WordPress without requiring any third-party plugins:
Base Version includes ~300 essential tools that work with vanilla WordPress:
Content management (search, save posts, attachments)
AI media generation (images via OpenAI/Gemini, speech, transcription, video)
Research tools (web search, weather, disaster alerts)
Site operations (health checks, logs, cron jobs, cache management)
WordPress-native email (via wp_mail)
Image manipulation (resize, crop, rotate, convert, vectorize to SVG)
Graphic editing (local operations and AI-powered transformations)
Profession and assistant management
GitHub integration tools
Google Maps Platform tools
Base Version excludes 31 tools requiring third-party plugins or external APIs:
Third-party WordPress plugins (13 tools) - See ๐ What You Lose Without Third-Party Plugins for details
WooCommerce tools (3)
JetEngine/JetFormBuilder tools (5)
Elementor tools (2)
RankMath/WPCode/Simple JWT Login tools (3)
External API services (18 tools) - Require API credentials
Google services (5)
Social media integrations (8)
External messaging services (4)
QuickBooks (1)
Full Version Installation (Opt-in)
To enable the Full Version with all third-party integrations and external API tools, add this constant to your wp-config.php file:
define( 'WP_MCP_AI_BASE_VERSION', false );๐ See BASE-VERSION.md for the complete tool list and customization options.
When to use Base Version:
Starting fresh with WordPress
Testing or development environments
Simpler installations without external dependencies
Sites that don't need e-commerce or advanced integrations
Don't want to purchase/install third-party plugins
When to use Full Version:
Production sites with WooCommerce, JetEngine, or Elementor already installed
Sites needing social media automation (requires API credentials)
Advanced workflows requiring external APIs
Need server-side chat transcript storage (requires JetEngine)
๐ See detailed breakdown: ๐ What You Lose Without Third-Party Plugins
๐ Documentation
NV oOS includes comprehensive documentation covering all aspects of the plugin. Documentation reorganized June 2026 โ Unix-theory separation of concerns. All docs sorted into 12 purpose-driven directories with zero content loss.
๐ Documentation Hub
Documentation Hub โญ Start here - Central navigation with organized categories
Documentation Index - Complete map of all 1,600+ documentation files
Architecture Overview - System architecture (15 providers, ~1,648 tool classes, 36 REST controllers)
Request Flow Walkthrough - End-to-end chat request lifecycle trace
Quick Reference Guide - Fast access to common tasks and commands
Essential References
Tool Reference - All ~1,648 tools documented (~347 base + ~1,301 Pro; live count via
WP_MCP_AI_Tool_Registry::get_tools()is authoritative)REST API Documentation - Complete API reference with examples
Testing & Quality Report - Test results and code quality analysis
๐ฆ Archive
Historical Documentation โ 50+ archived files from 2024-2025 development
Docs Archive - Consolidated implementation history and superseded documentation
For New Users
๐ Getting Started Wizard โญ NEW โ 4-step guided setup that connects your AI provider, selects a use case, and creates a ready-to-use assistant in under 2 minutes. 8 presets available: Content Creator, Customer Support, E-commerce, SEO & Research, Developer Copilot, Media & Creative Studio, Site Administrator, General Purpose.
Use Cases & Quickstart Guides โญ NEW - Comprehensive guide covering 7 major use cases with step-by-step quickstarts
5-Minute Quick Start - Get started immediately: from zero to first chat
Setup Checklist - Step-by-step installation and configuration
Remote Client Quickstart - Connect Claude Desktop, LM Studio, or other MCP clients
Best Practices - Recommended usage patterns and optimization tips
For Developers
Testing & Quality Report - Test suite results (2,106 tests, 73.4% pass rate), code quality analysis, security audit
Code Review Master - Comprehensive code quality analysis (95/100 score)
Action Items - Prioritized development tasks (180+ hours)
Authentication Guide - Authentication methods and security
MCP JSON-RPC 2.0 Endpoint - Model Context Protocol implementation
For Administrators
Deployment Troubleshooting - Common issues and solutions
Multisite Support - WordPress multisite configuration
Rate Limit Protection - API rate limiting setup
Mesh Routing Guide - Intelligent compute routing across sites and providers
Federation & Discovery - Decentralized AI capability network with peer discovery and well-known endpoints
Performance & Optimization
Message Bundling - Client-side message optimization
High Token Tool Handling - Agentic loop token management
Job Notification System - Real-time async job updates
Chat Performance Optimizations - Complete performance guide
Mesh Routing Guide - Intelligent compute routing across sites and providers
Historical Documentation
Archive Directory - 95+ historical documents organized by category:
implementations/- Implementation summaries and technical detailsphases/- Development phase documentsfixes/- Bug fix summaries and issue resolutionsfeatures/- Feature documentationcode-reviews/- Code review reportstesting/- Test infrastructure documentation
โ Configuration Checklist (Action Items)
Complete these after installation to unlock every integration point:
Add your OpenAI API key in Settings โ NV oOS โ OpenAI API Key so API calls are authorised.
Add your Gemini API key in Settings โ NV oOS โ Gemini API Key if you plan to route assistants through Gemini.
Confirm or override the default model via Settings โ NV oOS โ Default Model (
gpt-4.1ships as the default).Set a default Gemini model under Settings โ NV oOS โ Default Gemini Model when Gemini is enabled.
Choose the default provider from Settings โ NV oOS โ Default Provider so new assistants know whether to use OpenAI or Gemini by default.
Adjust the request timeout under Settings โ NV oOS โ Request Timeout (minimum 5โฏs, default 30โฏs) to match your hosting environment.
Select a default assistant with Settings โ NV oOS โ Default Assistant so REST and shortcode requests have a fallback.
Decide on logging with Settings โ NV oOS โ Enable Logging when you need verbose diagnostics.
Monitor token usage in Settings โ NV oOS โ Token Usage Statistics to track API consumption across users, providers, and models for billing and budget management.
Choose your uninstall behaviour via Settings โ NV oOS โ Remove Data on Uninstall if this site should purge assistants and settings during cleanup.
Configure Crawl4AI access in Settings โ NV oOS โ Tools when you want the Crawl4AI tool to be available to assistants.
Review attachment MIME overrides in Settings โ NV oOS โ Attachments before enabling file uploads for end users.
Review Send Group Email permissions in Settings โ NV oOS โ Tools to choose the capability and recipient cap for the group email automation.ใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L348-L359ใใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L938-L953ใ
Connect Gmail under Settings โ NV oOS โ Tools โ Connections โ Gmail to enable Gmail search tools with OAuth 2.0. See Google OAuth Setup Guide for complete configuration steps.
Connect QuickBooks Online under Settings โ NV oOS โ QuickBooks Company ID / API Key so the bundled reporting tool can fetch finance statements for authorised operators.ใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L906-L955ใ
Configure Mailjet credentials in Settings โ NV oOS โ Mailjet API Key / Secret / From Email / From Name before enabling Mailjet-powered tools or Elementor widgets that send email on behalf of assistants.ใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L1008-L1054ใ
Enable Federation & Discovery (Optional) in Settings โ NV oOS โ Federation & Discovery to publish your site's AI capabilities via
/.well-known/ai-peerand optionally run a directory service for peer discovery. Configure regions, data tags, and rate limits to control how your site participates in the decentralized AI network.ใF:docs/features/federation/federation-discovery.mdโ L1-L511ใใF:FEDERATION-IMPLEMENTATION-SUMMARY.mdโ L1-L381ใConfigure Root Security Key (Optional) by adding
define( 'WP_MCP_AI_ROOT_SECURITY_KEY', 'your-secure-key' );to wp-config.php. This provides an additional security layer that can be enabled during emergency shutdown to require authentication before re-initializing the plugin.ใF:docs/features/security/root-security-key.mdโ L1-L511ใEnable Pro Dashboard (Optional) by adding
define( 'WP_MCP_AI_PRO_DASHBOARD_ENABLED', true );to wp-config.php. This activates the dedicated Pro Dashboard with ISO/IEC 27001 compliance monitoring, reporting, and management tools. See Pro Dashboard Documentation for details.
๐ง Language Model Providers (OpenAI, Gemini, Anthropic, Baseten, DeepSeek, OpenRouter, Kimi, DigitalOcean, NVIDIA NIM, Ollama, LM Studio, Hugging Face, Cloudflare)
A dedicated router transparently forwards chat completions to the active provider, allowing each request to target OpenAI, Gemini, Anthropic, DeepSeek, OpenRouter, Baseten, Kimi, DigitalOcean, NVIDIA NIM, a local Ollama instance, LM Studio, Hugging Face, or Cloudflare Worker AI while sharing the same assistant UX.ใF:includes/class-wp-mcp-ai-language-model-router.phpโ L12-L86ใ Configure the required API keys, default models, and the global default provider in Settings โ NV oOS so new assistants inherit sensible defaults and administrators can switch providers without code changes.ใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L124-L333ใใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L505-L530ใ Assistants can still override provider, model, and generation parameters on a per-post basis.
Privacy & Terms: All AI providers have specific terms and privacy policies:
Ollama/LM Studio: Self-hosted (no external data transmission)
LM Studio Support
LM Studio with Function Calling - Full support for OpenAI-compatible function calling with local LM Studio instances:
OpenAI-compatible message structure preserved for tool calls
Tools/functions can be invoked by LM Studio models (e.g., qwen/qwen3-coder-30b)
Streaming automatically disabled when tools are present for reliable execution
Full backward compatibility with non-tool scenarios
Connect via JSON-RPC endpoint (recommended) or SSE streaming
See LM Studio setup guide for configuration details
Provider Priority List & Automatic Fallback
The plugin includes an intelligent provider priority system that automatically tries alternative providers when the primary one fails or is unavailable. In Settings โ NV oOS, you can:
Drag and drop providers to set your preferred order
Automatic fallback - if the first provider fails, the system tries the next one
Visual management - see all available providers (OpenAI, Gemini, Anthropic, Baseten, DeepSeek, OpenRouter, Kimi, DigitalOcean, NVIDIA NIM, Ollama, LM Studio, Hugging Face, Cloudflare) in one sortable list
Flexible prioritization - adjust based on cost, performance, or availability needs
The first provider in the list serves as the default. If any provider returns an error, the router automatically attempts the next provider in the list until one succeeds. This ensures maximum uptime and resilience without manual intervention. All fallback attempts are logged for debugging and monitoring.
Local AI with Ollama
The Ollama provider enables privacy-focused, cost-free AI processing by connecting to a local Ollama or LM Studio instance running on your server or development machine. This is ideal for:
Privacy-sensitive deployments where data must stay on-premises
Development and testing without incurring API costs
Custom or fine-tuned models not available through cloud providers
Air-gapped environments without internet access
To configure Ollama:
Install Ollama on your server or local machine
Pull a model (e.g.,
ollama pull llama2)Navigate to Settings โ NV oOS โ Ollama Configuration
Enter your Ollama endpoint URL (default:
http://localhost:11434)Click "Test Connection" to verify connectivity
Click "Fetch Models" to see available models
Select a model from the list or manually enter a model name
Set "Default Provider" to "Ollama (Local AI)" if you want it as the system default
The Ollama client supports the standard chat completion flow and automatically normalizes responses to match the OpenAI format for downstream compatibility. Note that some advanced features like tool calling may vary depending on the specific Ollama model you're using.
OpenAI model coverage
The plugin ships with presets for OpenAIโs current Responses, Reasoning, Audio, and Image APIs so site owners can choose the right model for each workflow. Token windows describe the maximum request size (messages, attachments, and tool payloads) the OpenAI API will accept for that model, while output limits reflect the largest single response the service will stream back. Leave a safety margin below each ceiling so assistants can add system instructions, tool calls, and knowledge snippets without hitting provider limits.
Capability | Model | Max context tokens | Max output tokens | Notes |
Responses (flagship) |
| 400,000 | 128,000 | Latest flagship multimodal model with 400K context window (Dec 2025). Ideal for large documents and complex workflows. |
Responses (pro reasoning) |
| 400,000 | 128,000 | Advanced reasoning variant with enhanced capabilities for mission-critical tasks requiring maximum accuracy. |
Responses (high throughput) |
| 400,000 | 128,000 | High-volume optimized variant for customer support and content generation at scale. |
Responses (deep analysis) |
| 400,000 | 128,000 | Deeper analysis variant with reasoning time dial for multi-step analysis and research tasks. |
Responses (general) |
| 128,000 | 16,384 | Flagship multimodal model that balances quality and latency for production chat, tool, and multimodal calls. |
Responses (cost optimised) |
| 128,000 | 16,384 | Budget-friendly 4.1 variant recommended for day-to-day assistants and background automations. |
Responses (advanced) |
| 128,000 | 16,384 | Previous generation multimodal model with strong reasoning capabilities. |
Responses (legacy) |
| 128,000 | 16,384 | Lower-latency 4o tier that keeps the larger context window while reducing cost for iterative workflows. |
Reasoning |
| 128,000 | 32,768 | Deliberate reasoning model suited to multi-step planning and analysis; expect slower responses while it โthinksโ. |
Reasoning (fast) |
| 128,000 | 32,768 | Lighter o1 variant that trades some reasoning depth for responsiveness in operational assistants. |
Media and multimodal defaults
Capability | Model | Size or duration limits | Notes |
Image generation |
| Up to 2048ร2048 output (square) or 2048ร1152 / 1152ร2048 (16:9 / 9:16) for |
|
Text-to-speech |
| Up to ~4,096 input tokens per request | Generates natural-sounding speech in multiple voices; longer scripts should be chunked into multiple calls. |
Speech-to-text |
| Optimised for recordings โค 90 minutes | Handles multilingual transcription and translation; large files are automatically chunked client-side before upload. |
OpenAI regularly revises token policies and media limits, so review the model specification dashboard before rolling out new assistants or increasing attachment budgets. Updating your defaults in Settings โ NV oOS keeps every assistant aligned with the latest provider guidance.ใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L36-L105ใใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L2298-L2398ใ
๐งฑ ChatKit Integration
The ChatKit module now ships with the core NV oOS plugin, so no separate add-on installation is required. Once enabled it self-registers through ChatKitโs filter and action APIs as soon as both plugins load, exposing the mcp-ai/v1 REST namespace while advertising chat, tool invocation, attachment download, and guest token support without any manual bootstrapping. Return false from the wp_mcp_ai_chatkit_is_available filter if you need to disable the automatic registration for bespoke environments.ใF:includes/class-wp-mcp-ai-chatkit-integration.phpโ L30-L204ใใF:includes/class-wp-mcp-ai-rest.phpโ L16-L2104ใ
From the ChatKit dashboard configure the NV oOS integration and supply at least one assistant ID so ChatKit knows which conversation to join. Optional fields let you override the system prompt or preload tool shortcut payloads for operators; capability checks inherit the wp_mcp_ai_chat_capability filter, so you can align ChatKit access with the same policies used for shortcodes or REST calls.ใF:includes/class-wp-mcp-ai-chatkit-integration.phpโ L182-L210ใใF:mcp-ai-wpoos.phpโ L25-L72ใ
Consult docs/developer/integration/chatkit-integration.md for a full configuration walkthrough, JSON examples for shortcut presets, and notes on extending the definition via filters.
๐ Crawl4AI Integration
Administrators with manage_options capabilities can run the Run Crawl4AI Job tool without any external service: when no Crawl4AI endpoint is configured the plugin performs the crawl directly on the WordPress server using the built-in HTTP client, extracts headings and text as Markdown, and records the raw HTML and response metadata for the assistant.ใF:includes/tools/class-wp-mcp-ai-tool-run-crawl4ai-job.phpโ L32-L745ใ Errors for individual URLs are captured in the response metadata so partial crawls still return useful context. When a remote Crawl4AI endpoint is configured the request now returns immediately with a task token while WP-Cron powered background polling captures the final payload and makes it available to the assistant UI once the crawl finishes.ใF:includes/crawler/class-wp-mcp-ai-crawler.phpโ L1-L214ใใF:assets/js/chat.jsโ L1-L2200ใ
Configure remote endpoints or API keys under Settings โ NV oOS โ Tools to tailor how the Crawl4AI integration runs across environments.ใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L248-L521ใ
Supplying a Crawl4AI base URL (and optional API key) switches the tool back to proxying crawl jobs to the remote Crawl4AI REST API, preserving backwards compatibility with existing deployments.ใF:includes/tools/class-wp-mcp-ai-tool-run-crawl4ai-job.phpโ L206-L339ใใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L248-L521ใ Local environments can still feed a custom endpoint to the integration through the WP_MCP_AI_CRAWL4AI_BASE_URL or CRAWL4AI_BASE_URL environment variable when you want to test against a dedicated Crawl4AI service.ใF:mcp-ai-wpoos.phpโ L54-L96ใ
๐ก Job Notification System
NV oOS includes a general-purpose infrastructure for real-time notifications on async WordPress jobs, providing SSE streaming and webhook support for external integrations.ใF:docs/features/async-jobs/job-notification-system.mdโ L1-L100ใ
Architecture
Async Job โ WordPress Action โ Job Notifier โ [SSE | Webhooks]
โ โ
Frontend ExternalAutomatic Crawl4AI Integration
The system automatically hooks into Crawl4AI jobs via the wp_mcp_ai_crawl4ai_job_completed action, providing real-time status updates as crawls progress. No additional code is neededโCrawl4AI jobs automatically trigger notifications.ใF:includes/crawler/class-wp-mcp-ai-crawler.phpโ L1-L214ใ
Frontend SSE Subscription
JavaScript clients can subscribe to job status updates using Server-Sent Events:
const jobId = 'crawl_abc123';
const eventSource = new EventSource(
`/wp-json/mcp-ai/v1/jobs/${jobId}/stream?max_duration=300&poll_interval=2`
);
eventSource.addEventListener('status', (e) => {
const status = JSON.parse(e.data);
console.log('Job status:', status.status, status.progress);
updateProgressBar(status.progress);
});
eventSource.addEventListener('complete', (e) => {
const data = JSON.parse(e.data);
console.log('Job completed:', data.final_status);
eventSource.close();
});Webhook Registration
External systems can receive HTTP callbacks when jobs complete:
WP_MCP_AI_Job_Notifier::register_webhook(
'crawl_abc123',
'https://example.com/webhook',
array( 'completed', 'failed' )
);โก๏ธ See docs/features/async-jobs/job-notification-system.md for complete implementation details.
๐ง Elementor Widgets
Sites running Elementor automatically register a suite of MCP blocks so you can assemble onboarding pages, operational dashboards, and standalone chat layouts without writing markup.ใF:includes/class-wp-mcp-ai-elementor-integration.phpโ L12-L98ใ The integration only boots when Elementor is present, so non-Elementor installs avoid any overhead.ใF:includes/class-wp-mcp-ai-elementor-integration.phpโ L29-L46ใ
Chat surfaces and companion blocks
NV oOS Chat โ Renders the assistant interface with the same controls exposed by the
[mcp_ai_chat]shortcode, including theallow_gueststoggle for minting temporary visitor tokens.ใF:includes/elementor/class-wp-mcp-ai-elementor-widget.phpโ L17-L138ใNV oOS Chat Bubble โญ NEW โ Floating chat bubble that sits at a configurable screen corner and opens a chat panel powered by the existing
[mcp_ai_chat]shortcode. Also available as a Gutenberg block (wp:mcp-ai-wpoos/chat-bubble). 5 control sections: Chat Settings, Bubble Settings (position/size/animation/tooltip/badge/auto-open), Panel Settings, Bubble Style, Panel Style. BEM CSS with 4 positions, 3 sizes, bounce/pulse animations, dark mode, full-screen mobile (<480px),prefers-reduced-motion, WCAG focus states. Public API atwindow.wpMcpAiChatBubble.ใF:includes/elementor/class-wp-mcp-ai-elementor-chat-bubble-widget.phpโ L1-L200ใใF:includes/blocks/chat-bubble/block.jsonโ L1-L50ใNV oOS Chat Intro โ Adds a configurable hero block above the conversation with headings, talking points, and an optional call-to-action button to guide visitors before they engage the model.ใF:includes/elementor/class-wp-mcp-ai-elementor-chat-intro-widget.phpโ L47-L190ใ
NV oOS Chat FAQ โ Surfaces a repeater-driven FAQ list alongside the chat so product teams can document policies and best practices in context.ใF:includes/elementor/class-wp-mcp-ai-elementor-chat-faq-widget.phpโ L47-L150ใ
NV oOS Usage & Timer โ Combines a focus timer with per-user token totals, gracefully handling logged-out visitors, disabled tracking, and empty usage histories.ใF:includes/elementor/class-wp-mcp-ai-elementor-chat-usage-timer-widget.phpโ L48-L340ใ
Operations dashboards
NV oOS Tool Matrix โ Pulls the tool registry, groups integrations by focus area, and highlights the required capability for each assistant tool so administrators can plan enablement safely. The Send Group Email row now mirrors the capability and recipient limit configured in the MCP settings so editorial policies stay front-of-mind.ใF:includes/elementor/class-wp-mcp-ai-elementor-dashboard-tool-matrix-widget.phpโ L48-L440ใ
NV oOS User Capability Snapshot โ Summarises the signed-in operatorโs profile, common capabilities, JetEngine access, and multisite memberships to support governance reviews. It also surfaces the configured Send Group Email capability and limit so administrators immediately know whether the current user can trigger bulk mail jobs.ใF:includes/elementor/class-wp-mcp-ai-elementor-dashboard-user-capability-widget.phpโ L48-L392ใ
NV oOS Theme Preview โ Renders a mock conversation using the saved chat color tokens and optionally displays a legend of every branding token for quick QA during rollouts.ใF:includes/elementor/class-wp-mcp-ai-elementor-dashboard-theme-preview-widget.phpโ L48-L198ใ
NV oOS Provider Quick Links โ Reuses the OpenAI usage/log tools to populate external billing and telemetry shortcuts that open in new tabs for rapid debugging.ใF:includes/elementor/class-wp-mcp-ai-elementor-dashboard-provider-links-widget.phpโ L48-L166ใ
NV oOS Activity Feed โ Streams the latest MCP log entries (tool runs, chat interactions, and optional provider requests), collapsing raw context into expandable JSON blocks for deeper analysis.ใF:includes/elementor/class-wp-mcp-ai-elementor-dashboard-activity-feed-widget.phpโ L48-L210ใ
๐งฎ Usage Tracking
Privacy-First Analytics (v1.2.0+)
The plugin includes optional, privacy-first activation tracking to help us understand plugin usage and improve development priorities. This feature is:
Privacy Features:
โ No PII collected - No personal information or identifiable data
โ Site URLs hashed - Non-reversible SHA-256 hash with WordPress salts
โ No IP storage - IP addresses are not logged or stored
โ Local dev excluded - Automatically disabled for localhost and common dev domains
โ Opt-out available - Easy to disable via settings or filter hook
โ GDPR compliant - Meets all privacy regulations
โ Fully transparent - All code is open source and documented
Data Collected:
Plugin variant (complete, base, pro, or core)
Plugin version number
WordPress version
PHP version
Site locale (language)
Multisite status
Hashed site identifier (non-reversible)
Timestamp
How to Opt Out:
Via Settings: Settings โ NV oOS โ General โ Log Management โ Disable Activation Tracking
Via Filter Hook:
add_filter( 'wp_mcp_ai_enable_usage_tracking', '__return_false' );
Full Privacy Details: See EXTERNAL_SERVICES.md for complete documentation.
The plugin records aggregate token usage per user, provider, and model whenever responses include usage metadata, simplifying internal reconciliation or billing workflows. Usage data is stored as user meta and automatically purged when accounts are deleted, and hooks are exposed for custom reporting pipelines.ใF:includes/class-wp-mcp-ai-usage-tracker.phpโ L12-L119ใ
Token Usage Management Dashboard
Administrators with manage_options capability can view comprehensive token usage statistics in Settings โ NV oOS:
Global Statistics (All Users):
Total requests across all users
Total tokens consumed (prompt + completion)
Prompt tokens used
Completion tokens generated
Cached tokens (for providers supporting prompt caching)
Reset all usage data button (with confirmation)
Individual User Statistics:
Your personal token consumption
Per-user breakdown of requests and tokens
Reset personal usage data button
Detailed Breakdown:
Usage by provider (OpenAI, Gemini, Anthropic, NVIDIA NIM, Ollama, LM Studio, Hugging Face, Cloudflare)
Usage by specific model (e.g.,
gpt-4.1-mini,gemini-2.0-flash)Request counts per provider/model combination
Last used timestamp for each model
Comprehensive table view with all metrics
The usage tracking system automatically:
Records usage from all API responses that include usage metadata
Aggregates data by user, provider, and model
Updates in real-time as conversations occur
Supports the Open OpenAI Usage tool for quick access to provider dashboards
Provides AJAX-powered reset functionality for administrators
๐งท Attachment MIME Controls
Administrators can override the default image and file MIME allowlists used by the chat uploader. The settings screen accepts one MIME type per line, and the attachment helper merges the overrides with its defaults before enforcing them on upload and shortcode configuration.ใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L225-L669ใใF:includes/class-wp-mcp-ai-message-attachments.phpโ L503-L559ใ Leave the fields empty to fall back to the bundled safe defaults.
โก Message Bundling
NV oOS implements client-side message bundling to optimize API usage and reduce server load. When enabled, messages sent within an 800ms window are automatically grouped into a single API request, reducing costs and improving performance for users who send multiple messages in quick succession.ใF:docs/user-guides/chat/message-bundling-feature.mdโ L1-L80ใ
How It Works
User sends a message โ Displayed immediately in the chat UI
800ms timer starts โ System waits for additional messages
More messages arrive โ Timer resets with each new message
Timer expires โ All queued messages sent together in one request
Visual Feedback
"Preparing to sendโฆ" - Messages are being queued during the bundling window
"Sendingโฆ" - Bundled messages are being transmitted to the server
Benefits
Reduced API costs - Fewer requests mean lower costs for pay-per-request APIs
Lower server load - Fewer requests to process and respond to
Better mobile experience - Ideal for users who type in short bursts
Backward compatible - Server code unchanged, same payload format
Configuration
Message bundling is enabled by default and requires no configuration. To disable for debugging:
window.wpMcpAiChatDebugMode = true;โก๏ธ See docs/user-guides/chat/message-bundling-feature.md for configuration options and implementation details.
๐ฏ Agentic Loop Token Management
NV oOS includes intelligent handling for tools that return large responses, preventing token overflow errors during agentic loops (where the AI automatically calls multiple tools).ใF:docs/features/tools/presets/high-token-tool-handling.mdโ L1-L80ใ
The Problem
Tools like run_crawl4ai_job can return 100,000+ tokens of content. In agentic loops, each API call includes all previous messages, causing token counts to grow rapidly and exceed model limits (e.g., gpt-4.1-mini's 200k TPM limit).
The Solution: Three-Tier Strategy
Tier 1: Token Limit Detection
Estimates total tokens before each API call
Checks against model's TPM (Tokens Per Minute) limit
Prevents requests that would exceed limits
Tier 2: Automatic Model Switching
When limits exceeded, auto-switches to fallback model
Default fallback: Gemini 2.0 Flash (1-2 million token capacity)
Preserves full context without data loss
Transparent to the user
Tier 3: Message Truncation
If even fallback model can't handle tokens
Truncates older messages from conversation
Always preserves system prompts and recent context
Logs what was truncated for debugging
Configuration
Automatic model switching is enabled by default. Configure fallback model under Settings โ NV oOS:
// Default fallback model
'fallback_model' => 'gemini-2.0-flash-exp'โก๏ธ See docs/features/tools/presets/high-token-tool-handling.md for complete technical details and examples.
๐ Chat Performance Optimizations
NV oOS includes several performance optimizations to enhance the chat experience:
Message bundling - Reduces API calls by grouping rapid user inputs
Token budget management - Prevents API limit overruns with safety marginsใF:docs/features/performance/tpm-limit-validation.mdโ L1-L50ใ
Chat history persistence - LocalStorage (24h) + optional JetEngine CCT storageใF:docs/user-guides/chat/chat-history-persistence.mdโ L1-L50ใ
Automatic model switching - Seamlessly handles token overflow scenarios
Rate limit protection - Intelligent retry with exponential backoffใF:docs/features/performance/rate-limit-protection.mdโ L1-L50ใ
โก๏ธ See docs/features/chat/chat-performance-optimizations.md for detailed performance tuning guide.
๐ Mesh Compute Routing
NV oOS includes intelligent mesh compute routing that automatically distributes AI workload across multiple sites OR multiple providers using AI-powered decision-making. This feature works in two modes:
Multi-Site Mesh: Distribute load across multiple WordPress installations
Single-Site Multi-Provider: Balance load across OpenAI, Gemini, Anthropic, NVIDIA NIM, Hugging Face, Cloudflare, and Ollama on one site
Both modes use the same AI-powered routing engine to optimize for cost, performance, and reliability.
Key Capabilities
AI-Optimized Routing - Analyzes prompt complexity and routes to optimal provider/site
Cost Optimization - Use GPT-4o-mini for simple queries, GPT-4o for complex tasks
Automatic Failover - Switch providers on rate limits or outages
Compute Hubs - Designate powerful servers for heavy workloads
Rate Limit Management - Auto-switch to alternative providers when limits hit
Privacy Control - Route sensitive data to local Ollama instances
Quick Start Examples
Single-Site Setup (No mesh required):
Configure multiple AI providers (OpenAI + Gemini + Anthropic + Hugging Face + Cloudflare + Ollama)
Set assistant routing strategy to "AI Optimized"
Save 90% on costs by routing simple queries to cheaper models
Multi-Site Setup (Distributed compute):
Enable mesh networking on all sites
Designate compute hubs with larger models
Automatic load balancing across peer sites
Cross-server compute pooling for Cloudways, SiteGround, etc.
โก๏ธ See docs/features/federation/mesh-routing-guide.md for complete setup guide, routing strategies, and use cases. โก๏ธ See docs/features/federation/mesh-compute-pooling.md for architecture and authentication details.
๐ Federation & Discovery System
NV oOS includes a decentralized AI capability network that allows WordPress sites to publish their capabilities and discover peer sites. Think of it as "npm for AI tools" โ sites can advertise what they offer and find complementary capabilities from trusted peers.
Overview
The Federation & Discovery system provides three deployment modes:
Publisher Mode: Publish your site's capabilities via
/.well-known/ai-peerDirectory Mode: Run a discovery service for peer registration and search
Consumer Mode: Query directories to find and use peer capabilities
Quick Start
Enable Federation (Publisher Mode):
Navigate to Settings โ NV oOS โ Federation & Discovery
Check Enable federation
Configure regions (e.g.,
us, eu, ap) and data tags (e.g.,no_pii, gdpr_ok)Your capabilities are now published at
https://yoursite.com/.well-known/ai-peer
Enable Directory Service (Optional):
In the same settings section, check Enable directory service
Your directory API is now available at
https://yoursite.com/wp-json/ai-dir/v1Automatic hourly health checks verify registered peers
Key Features
๐ก Well-Known Endpoints - Standards-based capability publishing
๐ Peer Discovery - Search by capability, region, and data policy
โ Health Monitoring - Automatic cron-based peer verification
๐ Smart Ranking - Scores peers by region, latency, and policy match
๐ JWKS Verification - Built-in security with public key discovery
โ๏ธ Conditional Loading - Zero overhead when disabled
API Endpoints
Directory REST API (/wp-json/ai-dir/v1):
POST /peers/register- Register a new peerGET /peers- List all peers with health statusGET /peers/{id}- Get peer detailsGET /search- Search peers by capability/region/policyPOST /reverify/{id}- Manually trigger health checkPOST /report/{id}- Report peer issues
Well-Known Endpoints:
GET /.well-known/ai-peer- Your site's capability manifestGET /.well-known/jwks.json- Public keys for verification
Use Cases
Private Organization Network:
Multiple WordPress sites within one organization
Share AI capabilities across internal sites
Central directory for discovery
Private peer network with secure authentication
Public Directory Service:
Community-run capability discovery
Accept registrations from external sites
Provide search API for consumers
Build an ecosystem marketplace
Capability Consumer:
Query public directories for needed capabilities
Integrate with mesh router for automatic peer selection
No need to publish your own capabilities
Access specialized tools from the network
Configuration Options
Regions: Geographic locations (e.g.,
us, eu, ap, global)Data Tags: Compliance policies (e.g.,
no_pii, gdpr_ok, hipaa_like)QPS Limit: Queries per second (default: 5)
Burst Capacity: Simultaneous requests (default: 10)
โก๏ธ Complete Documentation: docs/features/federation/federation-discovery.md โก๏ธ Implementation Summary: FEDERATION-IMPLEMENTATION-SUMMARY.md
๐ต Code Review
The 2025-10-31 internal review confirms the hardening of the group email automation (header filtering and attachment caps) and the case-sensitive variable handling in the OpenAI external action tool, and only flags a low-severity performance concern around guest token transient churn for public chat embeds. These findings have been consolidated into the master code review document. One follow-up action item recommends re-using or rate-limiting guest tokens to keep the options table tidy on cache-less hosts.
โก๏ธ See docs/developer/best-practices/CODE-REVIEW-MASTER.md for the complete code quality assessment.
๐ MCP Server Authentication
Remote MCP assistants should authenticate with Auth0-issued bearer tokens (Authorization: Bearer YOUR_TOKEN) whose audience and scope align with the values configured under Settings โ NV oOS. Same-origin experiences (the dashboard editor and shortcode UI) continue to rely on the X-WP-Nonce header tied to the logged-in WordPress session. Review docs/reference/api/mcp-server-authentication.md for a complete setup guide plus a breakdown of the structured error responses returned on failure, and keep the deployment troubleshooting checklist handy when diagnosing capability or credential regressions.
MCP transports (v1.1.55+): POST /wp-json/mcp-ai/v1/mcp speaks JSON-RPC 2.0 over Streamable HTTP by default. Legacy HTTP+SSE clients (SSE-only Accept: text/event-stream or ?stream=true) get a credential-bound session handshake from GET /mcp and receive responses as event: message on the GET stream โ enable with WP_MCP_AI_LEGACY_SSE_ENABLED. JSON-RPC errors return HTTP 200 with the {"jsonrpc","id","error"} envelope so agent SDKs that drop non-2xx bodies relay tool errors instead of hanging; auth/permission failures keep real HTTP statuses. Assistant credential headers may be sent as Authorization: Bearer cred_xxxxx.SECRET or raw Authorization: cred_xxxxx.SECRET. Tool-call traffic is governed by the settings-driven tool rate limiter (credential tokens exempt by default), and GET/HEAD discovery probes never consume the request quota. See docs/developer/implementation-plan-mcp-agent-compat.md and docs/developer/legacy-sse-transport-plan.md for the full rationale.
Using NV oOS as an MCP server
Install the plugin and create assistants. Each WordPress instance that activates NV oOS exposes an MCP-ready assistant directory backed by the
ai_assistantcustom post type, so every published assistant becomes available to remote clients once credentials are issued.ใF:includes/assistants/class-wp-mcp-ai-assistant-cpt.phpโ L460-L620ใConfigure the REST and connector settings. Populate the Auth0, model provider, and optional integration credentials under Settings โ NV oOS so the REST controller can advertise the correct namespace URLs and enforce bearer tokens per your tenant, scope, and provider defaults.ใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L36-L118ใ
Expose the MCP directory endpoints. The REST layer publishes
/assistants,/chat,/tools, and an SSE-compatible/ssehandshake inside thewp-json/mcp-ai/v1namespace, automatically scoping responses to the authenticated assistant or returning every assistant the caller may read.ใF:includes/class-wp-mcp-ai-rest.phpโ L234-L703ใ Hand-held clients can subscribe to the streaming directory event or call the JSON routes directly using the base URLs returned in the directory payload.ใF:includes/class-wp-mcp-ai-rest.phpโ L653-L703ใRegister any additional tools. Extend the serverโs capabilities by hooking into
wp_mcp_ai_register_toolsand loading custom tool classes; registered slugs flow through the assistant directory and tool execution endpoint without extra wiring.ใF:includes/class-wp-mcp-ai-tool-registry.phpโ L75-L195ใVerify the deployment before sharing credentials. Run
wp mcp-ai remote https://example.com/wp-json/mcp-ai/v1 --token=YOUR_TOKENfrom any WP-CLI environment to confirm authentication, assistant scope, and chat probes succeed before you hand tokens to operators or client teams.ใF:includes/class-wp-mcp-ai-cli-command.phpโ L137-L220ใ
Operating multiple MCP deployments
Provision a separate WordPress site (or network site) for each MCP server you need, activate NV oOS, and repeat the configuration steps above with environment-specific Auth0 audiences, scopes, and provider keys. Because the assistant directory response includes the resolved REST base and namespace metadata, MCP clients can be pointed at different deployments simply by swapping the base URL and the bearer credential minted for that siteโs assistants.ใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L48-L118ใใF:includes/class-wp-mcp-ai-rest.phpโ L653-L703ใ
Sites that enable the Simple JWT Login integration can now reuse those bearer tokens alongside Auth0 credentials. The plugin validates tokens with Simple JWT Loginโs native services, falls back to manual JWT decoding when the dependency cannot resolve a user, and automatically scopes REST requests to the assistant encoded in the token so cross-assistant hops are blocked with actionable errors.ใF:includes/class-wp-mcp-ai-simple-jwt-login-integration.phpโ L47-L214ใใF:includes/integrations/class-wp-mcp-ai-integration-simple-jwt.phpโ L240-L378ใใF:includes/class-wp-mcp-ai-rest.phpโ L2769-L2808ใ
๐ Connecting Remote MCP Clients
NV oOS works seamlessly with popular MCP clients including Claude Desktop, LM Studio, and ChatGPT connectors. Each client connects to your WordPress site via the MCP REST API at /wp-json/mcp-ai/v1 and can access assistants, execute tools, and interact with your WordPress data remotely.
SSE Support: All MCP endpoints support Server-Sent Events (SSE) for real-time streaming. Enable SSE in your client configuration for better response times and real-time updates. See the SSE Streaming Support section for details.
Quick Start
Generate an assistant credential from any published assistant's API Credentials meta box
Copy the token (format:
cred_xxxxx.SECRET) โ shown only once!Configure your MCP client with your site's base URL and the credential
Test the connection using the provided test script or WP-CLI command
Claude Desktop setup
Claude Desktop supports MCP servers through a JSON configuration file. Add your WordPress site:
{
"mcpServers": {
"wordpress-site": {
"url": "https://your-site.com/wp-json/mcp-ai/v1",
"headers": {
"Authorization": "Bearer cred_xxxxx.SECRET"
},
"sse": true
}
}
}See the complete Claude Desktop setup guide and example configurations for multi-assistant deployments.
LM Studio Setup
โ ๏ธ Having SSE content-type errors? Use the JSON-RPC endpoint instead!
LM Studio can connect using two methods:
Method 1: JSON-RPC (Recommended - No SSE)
Use this if you're getting SSE error: Invalid content type, expected "text/event-stream":
{
"servers": [
{
"id": "wordpress-mcp",
"name": "WordPress Site",
"url": "https://your-site.com/wp-json/mcp-ai/v1/mcp",
"auth": {
"type": "bearer",
"token": "cred_xxxxx.SECRET"
},
"timeout": 30000
}
]
}Configure in LM Studio:
Server Name: WordPress Site
URL:
https://your-site.com/wp-json/mcp-ai/v1/mcpAuth Type: Bearer Token
Token:
cred_xxxxx.SECRETDo NOT enable SSE
Method 2: SSE Streaming (Optional)
If you want to use SSE for real-time updates:
Base URL:
https://your-site.com/wp-json/mcp-ai/v1Enable SSE: โ (checked)
SSE Endpoint:
/sse
See the complete LM Studio setup guide and example configurations:
lmstudio-mcp-without-sse.json - Recommended
lmstudio-config.json - With SSE
ChatGPT connector setup
โ ๏ธ Note: ChatGPT connectors currently require Auth0 authentication. Assistant-issued credentials are not yet supported by OpenAI's ChatGPT platform.
To connect via ChatGPT:
Configure Auth0 in Settings โ NV oOS
Generate an Auth0 access token with the configured audience
Add the MCP server in ChatGPT's connector settings
See the ChatGPT connector guide for detailed Auth0 setup steps.
Testing your connection
Use the built-in test script to verify connectivity:
./bin/test-remote-connection.sh \
-u https://your-site.com/wp-json/mcp-ai/v1 \
-t cred_xxxxx.SECRETOr use WP-CLI:
wp mcp-ai remote https://your-site.com/wp-json/mcp-ai/v1 \
--token=cred_xxxxx.SECRETExpected output confirms the server is reachable and lists available assistants.
Complete documentation
For comprehensive setup guides, troubleshooting, and advanced configurations, see:
MCP Client Configurations โ โญ NEW: Complete guide for all MCP clients (LM Studio, Claude Desktop, Cursor, Continue.dev, Cline, OpenAI)
Remote Client Setup Guide โ Step-by-step instructions for Claude Desktop, LM Studio, and ChatGPT
MCP Server Authentication โ Authentication methods and credential management
REST API Reference โ Endpoint documentation and payload examples
Example Configurations โ Ready-to-use config files for all major MCP clients
๐ซ Token Management UI
NV oOS 1.0.0 introduces a centralized Token Manager for managing all external agent access tokens across your assistants. Access it via NV oOS โ Token Manager in the admin menu.
Features
Centralized Control - Manage all assistant credentials in one place
Security Best Practice - Tokens shown only once after creation (cannot be retrieved later)
Lifecycle Management - Create, view, revoke, and delete credentials
Audit Trail - Track who created/revoked each token and when
Metadata Display - See creation date, status (active/revoked), associated assistant
Bulk Visibility - View credentials across all assistants at a glance
How It Works
The Token Manager follows industry standards similar to GitHub Personal Access Tokens, Stripe API keys, and Auth0 credentials:
Create Token - Generate new credentials from the assistant editor
Copy Immediately - Token shown once and cannot be retrieved later
Use in MCP Clients - Configure external applications (Codex CLI, MCP clients, custom integrations)
Revoke When Needed - Disable compromised tokens without deleting audit history
Delete When Done - Permanently remove tokens and all metadata
Security Notes
Tokens are hashed before storage (only hash stored, never plaintext)
Requires
manage_optionscapabilityAll actions logged with user attribution
Revoked tokens cannot be reactivated (must create new)
HTTPS strongly recommended for token transmission
Usage Example
# In assistant editor: Create credential โ Copy token immediately
# Token format: cred_[YOUR_PREFIX].[YOUR_SECRET_KEY_HERE]
# Example format only - never share real tokens!
# Configure MCP client (e.g., Codex CLI)
export WPOOS_BEARER_TOKEN="your_token_here"
codex chat --assistant 123 "Hello world"
# Later: Revoke from Token Manager UI if compromised
# Or: Delete entirely when integration removedโ ๏ธ Security Warning: The examples above use placeholder tokens. Never share real tokens publicly or commit them to version control.
Access Requirements
Capability:
manage_options(administrators only)Menu Location: NV oOS โ Token Manager
REST API:
/wp-json/mcp-ai/v1/token-manager/*
For complete documentation, see Token Management Guide.
๐ค ChatGPT Connector
OpenAIโs ChatGPT connector beta currently authenticates exclusively through Auth0. Because NV oOS issues its own assistant-scoped bearer credentials, you can connect LM Studio, Claude Desktop, and other MCP-aware clients today, while ChatGPT support will require either Auth0 bridging or native bearer support from OpenAI. Weโll update this section as soon as ChatGPT adds compatibility with first-party tokens.ใF:docs/reference/api/mcp-server-authentication.mdโ L22-L46ใ
๐ฐ REST API Endpoints
All front-end chat surfaces ultimately call the MCP REST namespace at /wp-json/mcp-ai/v1, which exposes dedicated endpoints for chat completions and direct tool execution. Both routes share the same authentication rules described above: supply an Auth0 bearer token, a plugin-issued assistant credential, or a WordPress REST nonce for same-origin requests. Guest tokens issued by the shortcode or Elementor widget continue to be honoured when allow_guests="true" is enabled.ใF:includes/class-wp-mcp-ai-rest.phpโ L230-L322ใใF:includes/class-wp-mcp-ai-rest.phpโ L289-L343ใใF:includes/class-wp-mcp-ai-rest.phpโ L1288-L1336ใ
GET /assistantsโ Returns a directory of accessible assistants with provider defaults, tool counts, capability metadata, and implementation details so remote clients can choose which assistant to call. Credential tokens are automatically scoped to their issuing assistant while Auth0 tokens and REST nonces surface every published assistant the caller can read.ใF:includes/class-wp-mcp-ai-rest.phpโ L238-L666ใ The endpoint also supports Server-Sent Events for MCP clients that expect streaming discovery payloads, emitting a singledirectoryevent with cache-busting headers before closing the stream.ใF:includes/class-wp-mcp-ai-rest.phpโ L1690-L1772ใGET /sseโ Mirrors the assistant directory response but forces a Server-Sent Events handshake so MCP clients that negotiate/ssesubscriptions receive the streamingdirectorypayload without additional query parameters.ใF:includes/class-wp-mcp-ai-rest.phpโ L400-L715ใPOST /chatโ Normalises structuredmessages, injects assistant defaults, auto-enables the Submit Document Prompt tool when uploads are present, and forwards the request through the language model router. Responses include the assistant ID and the raw provider payload so clients can stream or render messages as needed.ใF:includes/class-wp-mcp-ai-rest.phpโ L230-L322ใใF:includes/class-wp-mcp-ai-rest.phpโ L931-L1095ใPOST /toolsโ Executes a specific registered tool outside of a chat turn. The endpoint enforces assistant tool allowlists, scopes credential-based requests to the issuing assistant, merges assistant defaults (such as external action identifiers), and returns the tool result with execution metadata.ใF:includes/class-wp-mcp-ai-rest.phpโ L264-L322ใใF:includes/class-wp-mcp-ai-rest.phpโ L1162-L1321ใ
See docs/reference/api/rest-api.md for payload examples, attachment handling rules, and troubleshooting tips when integrating custom clients.
๐ SSE Streaming Support
NV oOS includes comprehensive Server-Sent Events (SSE) support for real-time streaming responses, enabling faster perceived response times and better user experience.
What is SSE?
Server-Sent Events provide unidirectional server-to-client streaming over HTTP, allowing the server to push updates as they become available rather than waiting for the complete response.
Benefits:
โก Faster perceived response time - Users see content immediately as it's generated
๐ Real-time updates - Progressive loading for long-running operations
๐ถ Connection keep-alive - Prevents timeouts during lengthy responses
๐ฏ Better UX - ChatGPT-style typing effect for AI responses
SSE-Enabled Endpoints
1. Assistant Directory Streaming (GET /assistants)
Stream the assistant directory for MCP clients expecting SSE handshakes:
curl -H "Accept: text/event-stream" \
https://your-site.com/wp-json/mcp-ai/v1/assistantsThe endpoint emits a single directory event with all accessible assistants, then closes the connection.
2. Dedicated SSE Endpoint (GET /sse)
Force SSE mode for MCP clients that specifically probe the /sse endpoint:
curl https://your-site.com/wp-json/mcp-ai/v1/sseThis mirrors the /assistants response but always uses SSE format, ensuring compatibility with LM Studio and Claude Desktop.
3. Job Status Streaming (GET /jobs/{job_id}/stream)
Subscribe to real-time updates for async operations like Crawl4AI jobs:
const eventSource = new EventSource(
`/wp-json/mcp-ai/v1/jobs/${jobId}/stream?max_duration=300&poll_interval=2`
);
eventSource.addEventListener('status', (e) => {
const status = JSON.parse(e.data);
console.log('Progress:', status.progress + '%');
});
eventSource.addEventListener('complete', (e) => {
console.log('Job finished:', e.data);
eventSource.close();
});SSE Configuration
Enable POST Method for SSE (LM Studio Compatibility)
By default, SSE uses the standard GET method. For clients with SSE bugs (like LM Studio), enable POST support:
Go to Settings โ NV oOS โ Assistant Settings
Enable "Enable POST Method on SSE Endpoint"
Save settings
โ ๏ธ Note: Standard SSE specification uses GET. Only enable POST if you experience client compatibility issues.
Modern SSE Features (2024-2025)
The SSE implementation includes current best practices:
Automatic reconnection with
retry:directive (3-second interval)Event IDs for tracking reconnection state
HTTP/2 compatibility for multiplexing
Proper CORS headers for cross-origin requests
Cache-Control directives to prevent proxy buffering
Heartbeat messages to keep connections alive
Frontend Integration
Enable SSE streaming in your JavaScript client:
// Request streaming in chat
const response = await fetch('/wp-json/mcp-ai/v1/chat', {
method: 'POST',
headers: {
'Content-Type': 'application/json',
'Accept': 'text/event-stream',
'X-WP-Nonce': wpMcpAi.nonce
},
body: JSON.stringify({
assistant_id: 123,
messages: [{ role: 'user', content: 'Hello' }],
stream: true
})
});
// Process SSE stream
const reader = response.body.getReader();
const decoder = new TextDecoder();
let buffer = '';
while (true) {
const { done, value } = await reader.read();
if (done) break;
buffer += decoder.decode(value, { stream: true });
const events = buffer.split('\n\n');
buffer = events.pop();
for (const event of events) {
if (event.startsWith('data: ')) {
const data = JSON.parse(event.substring(6));
// Update UI with streaming chunk
updateChatUI(data);
}
}
}Documentation
For complete SSE implementation details, configuration options, and troubleshooting:
SSE Streaming Guide - Complete implementation guide with code examples
MCP and SSE - Understanding SSE benefits for MCP protocol
Job Notification System - Real-time job status via SSE
REST API Reference - SSE endpoint specifications
๐ MCP JSON-RPC 2.0 Endpoint
NV oOS implements a dedicated /mcp endpoint that follows the Model Context Protocol specification version 2024-11-05 using JSON-RPC 2.0 for bidirectional communication with AI assistants and tools.ใF:docs/reference/api/mcp-endpoint.mdโ L1-L80ใ
MCP Version: 2024-11-05
Compliance: Full MCP 2024-11-05 โ all 11 protocol methods, OAuth 2.1, Streamable HTTP, JSON-RPC batching, tool annotations, session management
What's New in MCP 2024-11-05
The latest specification is fully implemented:
OAuth 2.1 Security: PKCE, token rotation, mandatory HTTPS
Streamable HTTP Transport: Better reconnection and bidirectional communication
JSON-RPC Batching: Efficient parallel task processing (up to 20 messages per batch)
Tool Annotations:
readOnlyHint,destructiveHint,idempotentHint,openWorldHintmetadataProgress Notifications: Descriptive status updates during tool execution
Completions: Argument autocompletion for tools and prompts
Session Management: State recovery via
Mcp-Session-Idheader (1h TTL)Logging: Client-controlled log verbosity via
logging/setLevelCancellation: Request cancellation via
notifications/cancelled
Endpoint URL
POST /wp-json/mcp-ai/v1/mcpJSON-RPC 2.0 Format
All requests must use standard JSON-RPC 2.0 format:
{
"jsonrpc": "2.0",
"id": "unique-request-id",
"method": "initialize",
"params": {}
}Supported Methods
initialize- Initialize MCP connection and retrieve server capabilitiesping- Server liveness checktools/list- List available tools with annotations for the authenticated assistanttools/call- Execute a specific tool with progress notifications supportresources/list- List available resources (knowledge files, etc.) with metadataresources/read- Read resource content by URI with MIME-typed responsesprompts/list- List available prompt shortcutsprompts/get- Get full prompt content with system instructions and argument valuescompletion/complete- Argument autocompletion (enum/boolean for tools, slug matching for prompts)logging/setLevel- Client-controlled log verbosity (8 standard levels)notifications/cancelled- Cancel a pending request
Authentication (OAuth 2.1 Enhanced)
The MCP endpoint uses enhanced authentication aligned with MCP 2024-11-05 security standards:
WordPress Nonce (
X-WP-Nonceheader)Bearer Tokens (
Authorization: Bearer <token>) with rotation supportAssistant Credentials (generated from assistant editor, OAuth 2.1 compliant)
Auth0 JWT (for enterprise authentication)
Session Management (
Mcp-Session-Idheader for reconnection)
Error Handling
Enhanced Error System (Phase 3):
Severity Levels: CRITICAL, ERROR, WARNING, INFO, DEBUG for categorized logging
User-Friendly Messages: Automatic translation of technical errors into actionable guidance
Recovery Suggestions: Built-in troubleshooting steps for common failure scenarios
Centralized Error Handler: Consistent error creation with automatic logging
Comprehensive Logging: Track errors, tool executions, and chat interactions
Sensitive Data Protection: Automatic redaction of API keys and tokens in logs
See Error Handling Documentation for detailed usage.
MCP Standard Error Codes:
-32700: Parse error (invalid JSON)
-32600: Invalid Request (malformed JSON-RPC)
-32601: Method not found
-32603: Internal error
Use Cases
Scenario | Use Endpoint | Method | MCP 2024-11-05 Feature |
Remote MCP client connection |
| POST | OAuth 2.1, Sessions |
Real-time streaming responses |
| GET | Traditional SSE |
Streamable HTTP (new) |
| POST | Bidirectional streaming |
Standard chat interface |
| POST | N/A |
Direct tool execution |
| POST | Tool annotations |
Learn More
โก๏ธ Complete MCP Documentation:
MCP Endpoint Reference - Complete method documentation and 2024-11-05 features
MCP and SSE Explained - Understanding transport layers and protocol updates
MCP Server Authentication - OAuth 2.1 and security enhancements
MCP Client Configurations - Connect LM Studio, Claude Desktop, etc.
๐ Assistant Editor Overview
Assistant posts ship with dedicated controls that map directly to runtime behaviour:
Available Tools โ Choose which registered tools (core, WooCommerce, JetEngine, or custom) the model may invoke. Dependency-aware notices explain why certain tools are unavailable, and you can now disable the pre-built prompt shortcuts that tools normally contribute.
Quick Tool Selection Presets โ one-click presets group the current live registry by use-case (๐ค Agentic Workflow, ๐ E-commerce, โ๏ธ Healthcare, ๐ฌ Communication, ๐ป Development, ๐ Registration & Compliance, and more). Click a preset to add its tools to the current selection; click again to remove them. Combine multiple presets freely. Use โ Select All / โ Clear All for bulk actions. Implemented in
includes/helpers/class-wp-mcp-ai-tool-presets-helper.php.Model Defaults โ Provide assistant-specific overrides for the OpenAI model, temperature (0โ2), and system prompt applied to every conversation.
Base Knowledge โ Attach Media Library items that are chunked, truncated, and streamed as memory context, and optionally store an external Vector Store ID to coordinate retrieval workflows.
Prompt Shortcuts โ Capture labelled prompts with optional descriptions and tool affinities; they render as accessible quick actions in the chat UI so operators can seed conversations instantly.ใF:includes/assistants/class-wp-mcp-ai-assistant-cpt.phpโ L893-L1048ใใF:includes/class-wp-mcp-ai-shortcode.phpโ L430-L693ใใF:assets/js/chat.jsโ L600-L666ใ
If an API or shortcode request omits the assistant parameter, the plugin automatically uses the default assistant configured in the global settings.
๐ Assistant Storage: CPT vs CCT
NV oOS uses a Custom Post Type (CPT) as the primary storage for AI assistants, with automatic synchronization to a JetEngine Custom Content Type (CCT) when JetEngine is available.
Storage Architecture
CPT (
mcp_ai_assistant): The authoritative source for all assistant dataFull-featured WordPress editor with 14 meta fields
Supports credentials, shortcuts, memory files, and advanced features
Always available in both Base and Full versions
Primary REST endpoint:
/wp-json/mcp-ai/v1/
CCT (
assistants): Synchronized secondary storage (Full Version only)Receives automatic updates when CPT is saved
7 basic fields: title, description, provider, model, system_prompt, temperature, tools
Available via JetEngine REST endpoint:
/wp-json/jet-cct/assistantsIdeal for JetEngine-based integrations and queries
Automatic Synchronization (v1.0.0+)
When you save an assistant through the WordPress admin:
CPT is updated with all settings
CCT is automatically synced (if JetEngine is active)
Link is maintained via
_wp_mcp_ai_cct_item_idmetaDeletion cascades - removing CPT also removes linked CCT item
What gets synced: Basic configuration (title, description, provider, model, system_prompt, temperature, tools)
What's CPT-only: Advanced features (credentials, shortcuts, memory files, role rules, vector store, external actions)
When to Use Each Endpoint
Use CPT endpoint (/wp-json/mcp-ai/v1/) for:
Chat, tools, and directory interactions
Full assistant configuration access
Credential-based authentication
Primary integration scenarios
Use CCT endpoint (/wp-json/jet-cct/assistants) for:
JetEngine-specific queries and filters
Building JetEngine relations
Integrating with JetEngine dashboards
Querying basic assistant metadata
โก๏ธ Read the complete CPT vs CCT guide for detailed comparisons, code examples, and migration information.
โก Assistant Tool Shortcuts
Every assistant exposes a Prompt Shortcuts meta box so editors can curate prewritten instructions, scope them to registered tools, and add operator-facing descriptions that appear as tooltips and screen reader hints in the chat UI.ใF:includes/assistants/class-wp-mcp-ai-assistant-cpt.phpโ L893-L1048ใใF:includes/class-wp-mcp-ai-shortcode.phpโ L430-L693ใใF:assets/js/chat.jsโ L600-L666ใ The shortcode merges these custom prompts with each toolโs declared shortcut tasks and always appends a safe fallback so assistants remain usable even without bespoke entries.ใF:includes/class-wp-mcp-ai-shortcode.phpโ L430-L693ใ
Developers can extend or replace these prompts with filters such as wp_mcp_ai_assistant_custom_tool_shortcuts and wp_mcp_ai_default_tool_shortcut, letting sites tailor default quick actions per assistant or environment.ใF:includes/class-wp-mcp-ai-shortcode.phpโ L444-L692ใ
โก๏ธ Read the full guide to assistant prompt shortcuts.
๐ง Agent Skills
Agent Skills (agentskills.io) are reusable, portable behaviour packages that extend any assistant without touching its system prompt. Each skill is a SKILL.md file โ a standard Markdown document with a small YAML frontmatter block โ that lives in wp-content/uploads/mcp-ai-skills/{skill-name}/SKILL.md. When an assistant loads a skill, its instructions are automatically injected into the conversation context so the model knows exactly when and how to use that capability.
67 Pre-Built Skills (Base Plugin)
The base plugin ships with 67 pre-built skills that are automatically installed to wp-content/uploads/mcp-ai-skills/ on first activation. No Pro add-on is required โ they are available on every install out of the box. The skills include 24 general-purpose tools (document handling, design, testing), 22 WordPress developer skills (security, APIs, plugin patterns), 21 design-* skills (analytics through video creation), and the bundled mcp-ai-wpoos-plugin skill.
Skill slug | What it does |
| Generates algorithmic art with p5.js, seeded randomness, and interactive parameters |
| Applies Anthropic's official brand colours and typography to any artifact |
| Creates beautiful visual art in PNG/PDF documents using design philosophy |
| Guides users through a structured co-authoring workflow for documentation |
| Creates, reads, edits, and manipulates Word |
| Produces distinctive, production-grade frontend interfaces with high design quality |
| Drafts all kinds of internal communications (memos, announcements, updates) |
| Guides creation of high-quality MCP (Model Context Protocol) servers |
| Handles any PDF task โ creation, reading, editing, and form filling |
| Handles any |
| Creates, modifies, and measures the performance of other skills |
| Creates animated GIFs optimised for Slack with design best practices |
| Applies consistent visual themes to slides, docs, and other artifacts |
| Comprehensive UI/UX design system with component libraries, color palettes, typography scales, and stack-specific guidelines (React, Vue, Angular, Laravel, etc.) |
| Builds elaborate multi-component HTML artifacts for Claude.ai |
| Tests local web applications using Playwright browser automation |
| Handles any spreadsheet file as primary input or output |
How Skills Are Loaded
Skills are selected per-assistant via the Skills meta box in the assistant editor. Whichever skills are checked, their combined instructions are prepended to the system prompt under an # Active Skills heading at inference time. This means skills are composable โ you can combine pdf + xlsx + doc-coauthoring on a single document-specialist assistant.
Skills are stored as plain text files and can be customised in-place. The original bundled content can be restored at any time from Settings โ Advanced โ Skill Management โ Force Reinstall Bundled Skills.
Managing Skills
Base plugin โ Skill management is available under Settings โ Advanced โ Skill Management:
View installed skills and their metadata
Refresh the skill index
Install or force-reinstall the 16 bundled skills
Pro add-on โ The dedicated Skill Manager admin page (Assistants โ Skill Manager) adds:
Upload a
SKILL.mdfile or a ZIP archive containing a skill directoryInstall a skill from a remote URL
Inline CodeMirror editor to create or edit
SKILL.mdcontent directly in the browserDelete / uninstall skills
SKILL.md Format
---
name: my-skill
description: One-line description of what this skill does.
compatibility: claude-3-5-sonnet, claude-3-opus
---
# My Skill
Detailed instructions for the model go here in standard Markdown.
Use headings, lists, code blocks โ whatever best conveys the behaviour.The name field (max 64 chars) becomes the skill's slug. The description field (max 1 024 chars) is shown in the admin UI. The compatibility field is optional and informational.
โก๏ธ See Agent Skills reference for the complete specification, filters, and developer API.
๐ Professional & Team Layers
NV oOS includes an enterprise-grade template system for rapid assistant deployment through Professions and Teams. Instead of manually configuring each assistant from scratch, administrators can:
Select from ~311 pre-built professional templates spanning 12 industry categories
Create custom profession templates with reusable configurations
Deploy entire teams of specialized assistants with one click
Test everything from the backend before exposing to end users
๐ Professional Templates
Professions are reusable assistant templates with pre-configured:
Role descriptions and expertise areas
Default tools curated for each profession
Knowledge bases with industry-specific best practices
AI model defaults (provider, model, temperature)
Warnings and disclaimers for professional contexts
Available Categories (~311 professions across 12 categories):
Methodology note: the current sanity check counts 311 profession knowledge documents; runtime availability can vary with seeders, filters, and installed features.
๐พ Agriculture & Natural Resources
๐จ Art, Media & Entertainment
๐ผ Business & Finance
๐ Education
๐ฅ Healthcare & Medicine
โ๏ธ Law & Public Safety
๐ฌ Science & Engineering
๐ฝ๏ธ Service Industry
๐ป Technology
๐ง Trades & Manual Labor
๐ Transportation
๐ Miscellaneous
Example Professions:
Software Developer, Web Developer, Data Scientist
Accountant, Financial Advisor, Marketing Consultant
Registered Nurse, Physician, Pharmacist
Attorney, Paralegal, Mediator
Content Writer, Graphic Designer, Social Media Manager
And ~180 more, depending on active seeders and installed features...
Creating Assistants from Templates
Navigate to AI Assistants โ Add New to browse the visual profession grid:
Browse by category or search for a specific role
Click "Create" on any profession to open a customization modal
Customize the assistant name and AI settings (or use defaults)
Deploy your configured assistant instantly
Each profession template includes:
Pre-written system prompts with role-specific expertise
Curated tool selections appropriate for the profession
Industry knowledge bases and best practices
Recommended model settings for optimal performance
๐ฅ Team Deployments
Teams group multiple professionals for coordinated workflows. Deploy an entire team of specialists with one click:
Pre-Built Teams:
Engineering Team - Software, Mechanical, Electrical, Civil Engineers
Pharmaceutical Development Team - Pharmacist, Researcher, Clinical Pharmacologist, Regulatory Affairs
Research & Data Science Team - Data Scientist, Research Scientist, Statistician, Computer Scientist
Marketing & Growth Team - Marketing Consultant, Content Creator, Graphic Designer, Business Consultant
Team Features:
Centralized configuration - Set provider, model, and temperature for all team members
One-click deployment - Creates all team member assistants simultaneously
Consistent settings - Team defaults override individual profession defaults
Custom teams - Create your own teams with any combination of professions
Navigate to Teams โ Add Team to deploy a pre-configured team or create custom team combinations.
๐งช Backend Testing
Test assistants, professions, and teams directly from the WordPress admin before deploying to end users:
Test Assistant (Admin โ AI Assistants โ Test Assistant)
Full feature parity with frontend chat interfaces
All tools enabled including sensitive/restricted tools (admin-only)
File upload support with complete MIME type configuration
Transcript saving for debugging and analysis
Tool shortcuts pre-loaded from assistant configuration
Streaming responses with real-time feedback
Test Profession (Admin โ Professions โ Test Profession)
Preview profession templates before creating assistants
Validate role descriptions and expertise areas
Test default tool selections in live conversations
Verify knowledge base content and accuracy
Assess AI model performance with profession-specific tasks
Test Team (Admin โ Teams โ Test Team)
Test entire teams before deployment
Validate team member coordination and role separation
Verify shared settings propagate correctly
Multi-assistant conversations to test team dynamics
Performance benchmarking across team members
Security Note: All test pages require manage_options capability and are restricted to WordPress administrators. Sensitive tools are enabled in test environments because administrators already have full site access.
Documentation:
Test Assistant Feature Enhancements - Complete testing capabilities guide
Dynamic Assistant Creation System - Visual guide to profession and team architecture
Custom Professions & Teams
Administrators can create custom profession templates and teams:
Create Custom Profession:
Navigate to Professions โ Add New
Set title, description, and category
Define expertise areas and role description
Select default tools from the registry
Add knowledge base content
Configure AI model defaults
Publish for use in assistant creation
Create Custom Team:
Navigate to Teams โ Add New
Set team name and description
Select profession members from your library
Configure team-wide defaults (provider, model, temperature)
Publish to enable one-click team deployment
Benefits
For Organizations:
โ Rapid assistant deployment without manual configuration
โ Consistent configurations across similar roles
โ Template library grows with your organization
โ Share profession templates across sites
โ Professional-grade assistant quality out of the box
For Administrators:
โ Test everything safely from the backend
โ No coding required for template-based assistants
โ Visual template selection interface
โ Reusable configurations reduce errors
โ Full control over custom templates
For Developers:
โ JSON-based knowledge base system
โ Extensible via filters and hooks
โ WordPress standard CPT architecture
โ REST API access for profession and team data
โ Automated seeding from knowledge base files
๐ Assistant API credentials
Administrators can issue per-assistant access tokens from the API Credentials meta box that appears on every assistant edit screen. Tokens are only available to users with the manage_options capability, surface the credential history in a table, and expose one-click revoke and delete actions for rapid cleanup.ใF:includes/assistants/class-wp-mcp-ai-assistant-cpt.phpโ L483-L595ใ When you click Generate Credential the plugin produces a single-use token in the form cred_xxxxx.SECRET, hashes the secret server-side, and records the issuer so you have an audit trail of who created each credential.ใF:includes/class-wp-mcp-ai-credentials.phpโ L94-L135ใ
Remote integrations can authenticate by sending that token in the standard Authorization: Bearer headerโno Auth0 dependency required. The REST layer validates the credential, emits structured errors when a token is revoked or malformed, and scopes the request to the assistant that issued the token so clients cannot hop between assistants without an explicit credential for each one.ใF:includes/class-wp-mcp-ai-rest.phpโ L316-L444ใใF:includes/class-wp-mcp-ai-rest.phpโ L1282-L1321ใใF:includes/class-wp-mcp-ai-credentials.phpโ L242-L297ใ
๐ณ Local Development with Docker
Spin up a disposable WordPress instance that mounts the plugin source directly into the container:
docker compose up -dWordPress will be available at http://localhost:8000.
The plugin source in this repository is mounted to
/var/www/html/wp-content/plugins/mcp-ai-wpoosinside the container, so edits on your machine are reflected immediately.The MySQL service is provisioned with the
wordpressdatabase, user, and password (wordpress/wordpress).
Visit the site in your browser to complete the standard WordPress installation flow, using the database credentials above when prompted. When you're finished developing, stop the stack with docker compose down.
๐ Codex environment startup script
If you are working inside an OpenAI Codex environment, add bin/codex-startup.sh to your workspace start-up tasks so a fresh WordPress install is provisioned automatically for every session โ no Docker required.
bin/codex-startup.shThe script performs the following steps:
Downloads WP-CLI locally (if necessary) and uses it to fetch the latest WordPress core files into
.codex-wordpress/wordpress.Installs the SQLite Database Integration plugin so WordPress can run without a MySQL server.
Symlinks this repository into the new install's
wp-content/plugins/mcp-ai-wpoosdirectory.Installs Composer development dependencies (when available) and provisions the WordPress test suite so
composer run testworks immediately.Runs
wp core install, activates the NV oOS plugin, enables pretty permalinks, and sets a default site tagline.Boots a development server on port
8000viawp serverand logs output to.codex-wordpress/wp-server.log.
Default credentials:
Setting | Value |
Site URL |
|
Admin user |
|
Admin password |
|
Admin email |
|
Override any of these values by exporting the environment variables WORDPRESS_URL, WORDPRESS_TITLE, WORDPRESS_ADMIN_USER, WORDPRESS_ADMIN_PASSWORD, WORDPRESS_ADMIN_EMAIL, or WORDPRESS_PORT before running the script.
๐งโ๐ป Development Tooling
Install the PHP development dependencies (including PHP_CodeSniffer, the WordPress Coding Standards ruleset, and PHPUnit) with:
bin/setup-dev.shThe script runs composer install and makes the following Composer scripts available:
Purpose | Command |
WordPress coding standards lint |
|
PHP compatibility checks (PHP 7.4โ8.3) |
|
Auto-fix coding standards violations |
|
Generate the translation template |
|
Install the WordPress unit test scaffolding |
|
Execute the PHPUnit suite |
|
These commands automatically resolve the bundled vendor/bin tools (such as phpcs, phpcbf, and phpunit), so a global installation is no longer required.
Thetest:install script prefers the Composer-provided wp-phpunit/wp-phpunit package for the WordPress test suite. Run composer install before invoking it, especially on networks where develop.svn.wordpress.org is inaccessible.
NPM Dependencies & Bundling
For details on how NPM dependencies are managed and bundled for both the base plugin and Pro addon, see DEPENDENCIES_BUNDLING.md.
Quick Reference:
Base plugin dependencies:
@microsoft/fetch-event-source,dompurify,marked,ky,chart.js,@neplex/vectorizer,@langchain/*,@mlc-ai/web-llmBuild commands:
npm run build:js,npm run install:chartjs,npm run install:vectorizer,npm run build:js:proPro addon has separate
addons/pro/package.jsonfor Pro-specific dependencies
๐ฆ NPM Packages
Twenty-three standalone browser-utility packages have been extracted from the oOS chat UI and published to the NPM registry under the @nvdigitalsolutions scope. Each package is independently usable in any JavaScript/TypeScript project (no WordPress required).
Package | Description | Dependencies |
Async JSON via Web Worker โ prevents main-thread blocking for large data | Zero | |
XSS-safe markdown renderer with configurable allowed-tags profile |
| |
SSE client with POST support + mitt-compatible job event bus |
| |
HTTP client with automatic retry, exponential backoff, and request hooks |
| |
| Zero | |
IndexedDB offline-first sync with automatic server sync on reconnect | Zero | |
Slash command system with fuzzy-search autocomplete and execution engine | Zero | |
Browser audio I/O: TTS, STT, translation, voice chat with VAD | Zero | |
| Zero | |
Typed REST API client โ endpoint builders, request helpers, and payload constructors | Zero | |
File attachment helpers: type detection, validation, normalisation, segment builders | Zero | |
Floating chat bubble widget โ accessibility, sessionStorage, badge notifications, MutationObserver | Zero | |
Promise-based REST client for AI chat memory bridge (wake-up, recall, store, audit, preferences) | Zero | |
Chat memory drawer UI โ side panel for viewing, editing, scoping, and exporting long-term AI memories | Zero | |
Browser-native AI tool registry (summarize, sentiment, translate, embed, image, audio) using Transformers.js | Zero | |
SSE-first cron/job status monitor with REST polling fallback | Zero | |
Web Worker manager for non-blocking LLM operations | Zero | |
Progressive AI model loading UI with 4-stage progress tracking | Zero | |
TypeScript-native SSE connection manager with lifecycle tracking, per-connection status, automatic cleanup | Zero | |
MediaRecorder-based audio recording + tool-call transcription pipeline for AI chat surfaces | Zero | |
HuggingFace Transformers.js task wrapper (summarization, sentiment, NER, translation, QA, embeddings) | Zero | |
Canonical TypeScript type definitions โ AI providers, chat messages, tool execution, SSE streaming, attachments, history, memory, agents, WordPress global augmentations | Zero | |
Browser Voice Activity Detection (VAD) using the Web Audio API | Zero |
Installation
# Tier 1 โ Core utilities
npm install @nvdigitalsolutions/nvoos-storage
npm install @nvdigitalsolutions/nvoos-markdown marked dompurify
npm install @nvdigitalsolutions/nvoos-events @microsoft/fetch-event-source
npm install @nvdigitalsolutions/nvoos-types
# Tier 2 โ Extended browser utilities
npm install @nvdigitalsolutions/nvoos-http-client ky
npm install @nvdigitalsolutions/nvoos-clipboard
npm install @nvdigitalsolutions/nvoos-offline-sync
npm install @nvdigitalsolutions/nvoos-sse-client
npm install @nvdigitalsolutions/nvoos-api
npm install @nvdigitalsolutions/nvoos-attachments
# Tier 3 โ Chat UI utilities
npm install @nvdigitalsolutions/nvoos-slash-commands
npm install @nvdigitalsolutions/nvoos-audio
npm install @nvdigitalsolutions/nvoos-dom-batcher
npm install @nvdigitalsolutions/nvoos-chat-bubble
npm install @nvdigitalsolutions/nvoos-chat-memory
npm install @nvdigitalsolutions/nvoos-chat-memory-ui
npm install @nvdigitalsolutions/nvoos-cron-status
npm install @nvdigitalsolutions/nvoos-vad
npm install @nvdigitalsolutions/nvoos-transcription
# Tier 4 โ AI runtime utilities
npm install @nvdigitalsolutions/nvoos-client-tools
npm install @nvdigitalsolutions/nvoos-llm-worker
npm install @nvdigitalsolutions/nvoos-model-loader
npm install @nvdigitalsolutions/nvoos-transformers-clientPublishing
Two GitHub Actions workflows handle NPM publishing automatically:
Workflow | Trigger | Tag pattern |
| Push tag or |
|
| Push tag or |
|
Setup โ only one secret is required: add an NPM_TOKEN to the repository at Settings โ Secrets and variables โ Actions.
Adding a new package: update the PACKAGES environment variable in both workflow files and place the package directory under packages/.
See packages/README.md for a full package listing and API overview, and packages/QUICK_START.md for usage examples.
๐งช Testing & QA
composer run testexecutes the PHPUnit suite bundled withwp-phpunit/wp-phpunitand Yoastโs polyfills, covering REST, tooling, and helper contracts.ใF:composer.jsonโ L16-L23ใRun
composer run test:installonce per environment to provision the WordPress test scaffolding before the first test pass.ใF:composer.jsonโ L16-L23ใFor offline or air-gapped environments, use
./bin/package-vendor-dev.shto create a downloadable test framework package (~140 MB), then./bin/install-vendor-dev.shto deploy it without requiring composer or internet access.
Coding standards & static analysis
Enforce the WordPress Coding Standards with
composer run lint; auto-fix what you can withcomposer run format.ใF:composer.jsonโ L16-L23ใValidate cross-version compatibility (PHP 7.4โ8.3) via
composer run lint:compatprior to release builds.ใF:composer.jsonโ L16-L23ใ
Manual smoke tests
Follow the scenarios in ## โ Manual QA Scenarios after significant changes to chat flows, tool execution, or authentication wiring.
For logging-centric debugging, enable logging in the NV oOS settings and reference the retrieval commands in ๐ชต Logging.
โ CI/CD Pipelines
The repository runs ~30 automated GitHub Actions workflows on every push and PR:
Workflow | Purpose |
| PHPUnit test suite (PHP 8.1, MySQL 8.0) |
| Jest-based JS test suite |
| PHPCS + PHP compatibility (7.4โ8.3) |
| Dependency vulnerability scanning |
| Security regression tests |
| Build all SPA addon ZIPs |
| Canvas addon ZIP build |
| Comic Reader addon ZIP build |
| Graphify standalone plugin builds (3 workflows) |
| NPM package publishing (stable + alpha) |
| GitHub Release automation |
| Cross-provider chat parity testing |
| End-to-end QA tests |
| WCAG 2.1 AA accessibility checks |
| SPA bundle size monitoring |
| Documentation link validation |
| Cloud Worker integration tests |
| Post-deployment health checks |
| Monorepo subtree sync to standalone repos (9 workflows) |
| Stale issue/PR management |
| Automated PR labeling |
| GitHub project board automation |
๐ฌ Frontend Shortcode
Embed a published assistant anywhere on the site with the shortcode. Replace 123 with the post ID of the assistant you created under AI Assistants.
[mcp_ai_chat assistant="123"]How it works
The shortcode renders a lightweight chat UI that talks to the plugin's REST API endpoints.
Scripts and styles are enqueued automatically and include REST nonces plus the selected assistant ID.
Responses are displayed inline, including tool invocation feedback when the model requests a registered tool.
Requirements
The assistant post must be published and, by default, the current user must have the
edit_postscapability (matching the REST permission check). Addallow_guests="true"to the shortcode when you want anonymous visitors to participate in the chat.An OpenAI API key and default model must be configured in Settings โ NV oOS.
Tips
Omit the
assistantattribute to fall back to the default assistant configured in the settings screen.Multiple shortcodes can be added to the same page; each chat instance maintains its own conversation context on the client.
Use
allow_guests="true"to expose the chat UI to logged-out visitors. Each render issues a short-lived guest token that authorises REST requests without a WordPress login.REST interactions rely on the
[wp_rest]nonce, so caching plugins should avoid caching pages for logged-in editors running the chat.
Elementor widget
Elementor sites automatically gain an NV oOS Chat widget that mirrors the shortcode controls, including the optional assistant selector and the guest access toggle.ใF:includes/elementor/class-wp-mcp-ai-elementor-widget.phpโ L17-L109ใ
Leaving the assistant control blank falls back to the default assistant configured in the plugin settings, and enabling Allow Guests injects the same temporary tokens used by the shortcode flow.ใF:includes/elementor/class-wp-mcp-ai-elementor-widget.phpโ L45-L110ใใF:includes/class-wp-mcp-ai-shortcode.phpโ L132-L224ใ
The Elementor chat widget can surface everything saved on the assistant postโmodel defaults, knowledge files, prompt shortcuts, and assigned toolsโso you can build documentation and dashboards without copying values manually.ใF:includes/elementor/class-wp-mcp-ai-elementor-widget.phpโ L95-L845ใ
๐งต REST Chat Payloads & Attachments
The /wp-json/mcp-ai/v1/chat endpoint accepts rich, multi-part messages. Each message object still requires a role, but the
content may now be either a plain string or an array of structured segments that map to OpenAI's multimodal contract.
{
"assistant_id": 123,
"messages": [
{
"role": "user",
"content": [
{ "type": "text", "text": "Describe this photo" },
{ "type": "input_image", "attachment_id": 456, "detail": "high" }
]
}
],
"options": {
"response_format": { "type": "json_schema", "json_schema": { "name": "caption" } }
}
}Supported segment types
textโ Free-form text (textproperty). Strings supplied directly tocontentare automatically wrapped in this format. For backwards compatibility, existinginput_textpayloads sent to the REST API are still accepted and normalised to the new schema.input_imageโ Reference an uploaded WordPress attachment (attachment_id) or provide a remoteurl. Optionaldetailhints (low,auto,high) andcaptionfields are preserved. (Fixed in v1.0.0: Chat client attachments now properly processed)input_fileโ Reference an uploaded attachment that should be streamed to the model. (Fixed in v1.0.0: Chat client file attachments now properly processed)
The REST controller validates attachment ownership/permissions, enforces a default 5โฏMB size cap (filterable via
wp_mcp_ai_max_attachment_bytes), and only allows safe MIME types by default. Text and structured data formats include
Markdown, CSV/TSV, HTML, JSON/JSONL/NDJSON, and XML; binary documents cover PDFs and Microsoft Word/PowerPoint/Excel variants;
and audio/video uploads accept AAC/FLAC/M4A/MP3/OGG/OPUS/WAV/WEBM plus MP4 or QuickTime sources. ใF:includes/class-wp-mcp-ai-message-attachments.phpโ L642-L709ใ
Whenever attachments are present, the plugin automatically inlines the asset data when sending requests to OpenAI's Responses API. Image segments are converted to data URLs and file segments include the base64-encoded payload alongside the original filename, so integrators do not need to upload assets manually before invoking a model.
REST requests that include attachments automatically gain access to the bundled Submit Document Prompt tool so the files reach OpenAI even when the assistant has the tool disabled in its configuration.ใF:includes/class-wp-mcp-ai-rest.phpโ L22-L29ใใF:includes/class-wp-mcp-ai-rest.phpโ L963-L991ใ
Assistant memory files configured on the post (memory_files) are also promoted to structured text segments on the
system channel, retaining the existing chunking/truncation safeguards.
Need to relax or tighten the allowed file types? Administrators can override the image and file MIME lists directly in Settings โ NV oOS โ Attachments, and the same values are used by shortcode-driven chat surfaces (including the Elementor widget) when building upload restrictions.ใF:includes/admin/class-wp-mcp-ai-admin-settings.phpโ L225-L267ใใF:includes/class-wp-mcp-ai-message-attachments.phpโ L456-L565ใใF:includes/class-wp-mcp-ai-shortcode.phpโ L197-L218ใ When JSON Lines support is enabled in the allowlist the plugin also registers .jsonl and .ndjson extensions with WordPress so uploads succeed without additional filters.ใF:mcp-ai-wpoos.phpโ L236-L272ใ
Assistants can also query existing knowledge files with the Search Attachments tool, which reuses WP_MCP_AI_Message_Attachments::user_can_access_attachment() so only publicly accessible or user-owned media is returned alongside download URLs and file metadata for the model to reuse.ใF:includes/tools/class-wp-mcp-ai-tool-search-attachments.phpโ L15-L207ใใF:includes/class-wp-mcp-ai-message-attachments.phpโ L480-L575ใ
๐ JetEngine Capability Reference
When the plugin interacts with JetEngine objects it defers to the capabilities enforced by JetEngineโs own REST handlers and editor interfaces. Use the following table to review the specific capability checks that gate each object type:
Object / Context | Capability string(s) | Notes |
Custom Post Type editor & REST endpoints |
| Editing built-in post types and all CPT REST endpoints require the user to have |
Custom Taxonomy editor & REST endpoints |
| Built-in taxonomy edits and every taxonomy REST endpoint enforce the |
Relation management UI & REST endpoints |
| Creating, editing, listing, or deleting relations through the admin REST handlers requires |
Relation REST access settings ( | Stored capability string or | The public REST controller checks a capability stored in relation args; if blank or |
Relation object type โPostsโ |
| Editing or deleting related post items requires the corresponding post capability for the specific post ID. |
Relation object type โTaxonomy Termsโ |
| Term relations check the matching term capabilities for the targeted term ID. |
Relation object type โMix โ Usersโ |
| Editing user relations needs |
Relation object type โCustom Content Types (CCT)โ | Configured capability (defaults to | Relation checks defer to the CCTโs |
๐ฐ JetEngine REST API Reference
๐ Review the full endpoint catalogue in
docs/reference/api/jet-engine-rest-routes.mdfor route paths, callbacks, and required parameters.๐ค When JetEngine is active, assistants can invoke the List JetEngine REST Routes tool to retrieve the same metadata directly inside a conversation (requires a user with the
manage_optionscapability).
๐ชต Logging
Enable or disable logging from Settings โ NV oOS โ Enable Logging.
When logging is enabled the plugin records:
Chat requests and responses processed by the REST API.
Tool executions (including permission denials).
Errors returned from the OpenAI API and internal validation.
Log entries are written via PHP's
error_log()and can be filtered withwp_mcp_ai_log_entryto route them elsewhere.ใF:includes/class-wp-mcp-ai-logger.phpโ L16-L137ใRecent errors and activity snapshots are also persisted in the
wp_mcp_ai_recent_errors(50 entries) andwp_mcp_ai_recent_activity(100 entries) options for dashboards and widgets, keeping autoload disabled to avoid bloating frontend requests.ใF:includes/class-wp-mcp-ai-logger.phpโ L611-L662ใRetrieve those rolling buffers quickly with WP-CLI when debugging production incidents:
wp option get wp_mcp_ai_recent_errors --format=json wp option get wp_mcp_ai_recent_activity --format=json
๐งพ JetEngine REST Endpoint Report Helper
Use the JetEngine report helper to surface the CRUD coverage matrix that was compiled during the REST endpoint audit. The helper exposes the underlying endpoint metadata as a structured array so you can reuse it in documentation, dashboards, or custom checks.
$report = wp_mcp_ai_get_jetengine_endpoint_report();
foreach ( $report['coverage'] as $resource => $operations ) {
printf( "%s supports: %s\n", ucfirst( $resource ), implode( ', ', array_keys( array_filter( $operations ) ) ) );
}
if ( empty( $report['missing'] ) ) {
echo "All CRUD operations are covered.";
}The helper is filterable via:
wp_mcp_ai_jetengine_endpoint_routesโ Adjust the source routes before the coverage matrix is derived.wp_mcp_ai_jetengine_endpoint_coverageโ Modify the generated CRUD coverage.wp_mcp_ai_jetengine_missing_operationsโ Override the derived list of missing operations per resource.
Each filter receives the full data set so you can extend or replace the output when JetEngine adds new endpoints or when your project needs to surface additional metadata.
๐ Optional Tools & Dependencies
NV oOS works perfectly with vanilla WordPress - you don't need any third-party plugins for core functionality.
However, certain features require third-party plugins (sold separately). The plugin automatically detects which plugins are active and enables the corresponding tools:
Plugin Detection & Tool Loading
JetEngine (5 tools) โ Server-side chat transcripts, JetEngine content access, JetFormBuilder integration
WooCommerce (3 tools) โ E-commerce automation, product/order management
Elementor (1 tool + widgets) โ Template management, pre-built chat widgets
Rank Math SEO (1 tool) โ SEO analysis and schema data access
WPCode (1 tool) โ Code snippet management and automation
๐ See the complete breakdown: ๐ What You Lose Without Third-Party Plugins
How It Works
Each tool description in the admin UI shows which plugin it requires
Tools are automatically hidden when their dependency is missing
Administrators see informational notices explaining unavailable tools
No errors occur - the plugin gracefully handles missing dependencies
โ Manual QA Scenarios
The project currently relies on manual verification. Run these checks after updating the plugin:
Baseline (no optional plugins)
Deactivate WooCommerce and JetEngine.
Load the AI Assistant edit screen and confirm only core tools appear. No PHP notices or fatal errors should occur.
Visit the WordPress dashboard to confirm the informational notices explain why optional tools are disabled.
WooCommerce enabled
Activate WooCommerce.
Reload the Assistant editor and ensure the WooCommerce Orders and Products tools appear and can be selected.
Trigger each tool (e.g., via an assistant conversation) and confirm recent orders and product summaries return without errors.
JetEngine enabled
Activate JetEngine.
Confirm the JetEngine Items tool appears for assistants and returns data for a configured JetEngine post type.
Tool call retry resilience
Initiate a chat conversation that triggers a tool call (for example, request an operation that requires either WooCommerce tool).
After the tool output appears, send a follow-up message that prompts the assistant to continue without invoking another tool.
Confirm the follow-up succeeds without a JavaScript console error referencing a missing
tool_call_id.
Document the results of each scenario when preparing releases to ensure optional integrations remain stable.
๐งฉ Hooks & Filters
Use the following hooks to extend the plugin:
Hook | Type | Description |
| Action | Fires before a chat request is sent to OpenAI. |
| Action | Fires after a chat response is received. |
| Filter | Modify the OpenAI request options before dispatch. |
| Filter | Adjust the capability required to use the chat shortcode and REST endpoints (defaults to |
| Action | Runs immediately before a tool executes. |
| Filter | Inspect or transform tool output before it is returned. |
| Action | Runs after a tool completes execution. |
| Filter | Intercept or redirect logging output. |
| Filter | Add, remove, or modify onboarding wizard use-case presets. Each preset defines tools, system prompt, temperature, and assistant name. |
| Action | Fires after the onboarding wizard creates assistant CPT posts from selected presets. |
๐งฐ WP-CLI Commands
Manage the NV oOS environment from the command line when WP-CLI is available.
Command | Description |
| Summarises WordPress core details, PHP version, and NV oOS supported plugin coverage. |
| Probes a remote MCP REST namespace (such as |
| Lists optional dependencies (WooCommerce, JetEngine, etc.) with install and activation state. |
| Activates a supported plugin; pass |
| Deactivates a supported plugin; pass |
| Sends a one-shot chat message to an assistant via the language model router. Accepts |
| Recalls agent memory entries. Use |
| Lists chat threads. Use |
| Lists all 15 AI providers with enabled/disabled status. Also supports |
| Lists scheduled cron jobs tracked by NV oOS. Also supports |
| Lists transcripts eligible for mining. Use |
| Lists pending human-in-the-loop approval items. Accepts |
| Lists all registered tools with status, capability, and toolkit metadata. Accepts |
| Lists all published AI assistants. Accepts |
| Lists API credentials configured for an assistant. |
| Lists registered slash commands. |
| Retrieves all NV oOS settings. |
| Clears the NV oOS object cache. |
wp mcp-ai remote accepts additional flags so you can mirror the authentication mode used by your deployment while exercising TLS and timeout controls:
--token=<token>โ Include an Auth0 access token or assistant-issued credential via theAuthorizationheader.--guest-token=<token>โ Attach a guest token when testing public chat surfaces that rely on theX-WP-MCP-AI-Guestheader.--nonce=<nonce>โ Supply a WordPress REST nonce for same-origin checks.--assistant-id=<id>โ Hint which assistant to load when the directory endpoint supports scoped tokens.--timeout=<seconds>โ Override the default 15-second timeout when probing slow networks.--verify-ssl=<boolean>โ Toggle certificate validation (defaults totrue).--user-agent=<agent>โ Send a custom user agent instead of the built-inWP-MCP-AI-Remote-Tester/<version>signature.
Filter wp_mcp_ai_supported_plugins to expose additional managed dependencies to the CLI helpers.
Each hook receives sanitized data and respects the current user's permissions and multisite membership.
๐ Getting Help & Support
Documentation Resources
Start with the comprehensive documentation before seeking additional support:
Quick Reference Guide - Fast answers to common questions and tasks
Documentation Index - Navigate all 1,600+ documentation files
Troubleshooting Guide - Solutions to common issues
REST API Reference - Complete API documentation
Before Reporting Issues
When encountering problems, please:
Check the troubleshooting guide
Enable logging in Settings โ NV oOS to capture detailed errors
Review the common issues section below
Search existing GitHub issues
Test with a default assistant to isolate configuration issues
Common Issues
npm EACCES Permission Error (package-lock.json)
If you get EACCES: permission denied, open '.../package-lock.json' when running npm install:
This means you do NOT need to run npm install.
The plugin distributes pre-built minified assets (.min.js/.min.css files) so npm install is never required for production use. You only need npm if you are a developer modifying JavaScript source files.
Solutions:
If installing from ZIP: Simply upload and activate the plugin. No npm commands needed.
If cloning the repository for production use: Activate the plugin as-is. The pre-built assets in the repository are ready for production.
If you need to rebuild assets (development only): Run npm on a development machine where you have write access, then deploy the built files.
If you must run npm in a restricted directory (e.g., during CI or scripted deployments), use:
npm install --no-package-locknpm/Composer Install Error After Cloning
If you get ENOENT: no such file or directory, uv_cwd (npm) or getcwd() failed (composer) errors:
For Cloudways Users (Most Common):
These errors occur when you try to run npm or composer from a directory that has been moved, deleted, or no longer exists. This commonly happens when you clone outside the WordPress plugins directory and then move/copy files while your shell session is still in the original location.
Solution: Always clone directly into the plugins directory:
# SSH into your Cloudways server
cd /home/master/applications/YOURAPP/public_html/wp-content/plugins/
# Clone directly (replace YOURAPP with your application name)
git clone https://github.com/nvdigitalsolutions/mcp-ai-wpoos.git
cd mcp-ai-wpoos
# Verify you're in the right place
pwd # Should show the full plugins path
# NOTE: npm install is NOT required for production use.
# Activate the plugin in WordPress admin - it is ready to use.
# Only run composer if you need to update PHP dependencies (development only):
# composer install --no-devFor Local Development or VPS:
Ensure you're in the correct directory - Run
pwdto verify you're in themcp-ai-wpoosdirectoryDo not run commands from a moved/deleted directory - If you moved files, open a new terminal session in the new location
Production workflow (no npm or composer needed):
# Clone the repository git clone https://github.com/nvdigitalsolutions/mcp-ai-wpoos.git # Copy to WordPress plugins directory cp -r mcp-ai-wpoos /path/to/wordpress/wp-content/plugins/ # Plugin is ready to activate - no build step required.Development workflow (only if you need to rebuild JS/CSS assets):
# Clone the repository on your development machine (not the server) git clone https://github.com/nvdigitalsolutions/mcp-ai-wpoos.git cd mcp-ai-wpoos # Install dev dependencies and rebuild assets npm install && npm run build composer install --no-dev # Deploy built files to the serverAlternative: Clone directly into WordPress - This avoids copy/move issues:
cd /path/to/wordpress/wp-content/plugins/ git clone https://github.com/nvdigitalsolutions/mcp-ai-wpoos.git # Activate the plugin - it is production-ready without any npm or composer commands.
Chat Not Working
Verify OpenAI API key is configured in Settings โ NV oOS
Ensure assistant is published
Check user has
edit_postscapability or addallow_guests="true"to shortcodeEnable logging and check browser console for errors
Tool Execution Failures
Verify tool is enabled for the assistant
Check required dependencies are installed (WooCommerce, JetEngine, etc.)
Ensure user has necessary capabilities
Review tool-specific requirements in tool reference
Remote Client Connection Issues
Verify credentials are correct and not expired
Test with remote client quickstart guide
Use WP-CLI command:
wp mcp-ai remote <url> --token=<token>Review authentication documentation
Reporting Issues
When creating a GitHub issue, please include:
Plugin version (found in WordPress admin)
WordPress version and PHP version
Error messages from logs (enable logging in settings)
Steps to reproduce the issue
Expected behavior vs actual behavior
Screenshots if applicable
Create issues at: https://github.com/nvdigitalsolutions/mcp-ai-wpoos/issues
Contributing
We welcome contributions! Please see:
CONTRIBUTING.md - Contribution guidelines
MASTER_CONSOLIDATION_2025.md โญ START HERE - Complete consolidation of ALL fixes, summaries, and code reviews (98/100 score)
CONSOLIDATION_MAP.md - Detailed map showing what was consolidated from where
CODE-REVIEW-MASTER.md - Code quality standards with historical reviews
ACTION_ITEMS.md - Current development priorities
Documentation
Comprehensive documentation is available:
MASTER_CONSOLIDATION_2025.md โญ PRIMARY REFERENCE - Single source of truth for all 2025 work
CONSOLIDATION_MAP.md - Navigation guide and source document mapping
DOCUMENTATION_INDEX.md - Complete documentation index (535+ files)
CODE-REVIEW-MASTER.md - Master code review (98/100)
TESTING_AND_QUALITY_REPORT.md - Testing & quality analysis
For Historical Reference:
CONSOLIDATED_BUGS_AND_FIXES.md - All bugs and fixes (superseded by MASTER_CONSOLIDATION_2025.md)
CONSOLIDATED_SESSION_SUMMARIES.md - Development history (superseded by MASTER_CONSOLIDATION_2025.md)
Security Vulnerabilities
For security issues, please review our Security Policy and report vulnerabilities responsibly.
Do not create public GitHub issues for security vulnerabilities.
Community & Updates
GitHub Repository: https://github.com/nvdigitalsolutions/mcp-ai-wpoos
Maintained by: NV Digital Solutions
License: GPLv3 or later
๐ License
NV oOS ships under a three-tier license model:
Component | License |
Base plugin (root + | |
| AGPL-3.0-or-later (bundles |
| Proprietary โ ยฉ NV Digital Solutions, all rights reserved |
The base plugin's GPL-3 grant is in LICENSE. Bundled third-party
dependencies retain their upstream licenses; see CREDITS.md
for the full attribution index.
Thank you for using Open Operator System!
This server cannot be deployed
Maintenance
Related MCP Connectors
Security-first WordPress MCP server. 129 tools for Claude, ChatGPT, Gemini. Free on wp.org.
Manage WordPress blogs and WooCommerce shops from Claude, ChatGPT, Cursor and other MCP apps.
Secure MCP Server for WordPress connects AI assistants and agents to WordPress with secure, controlled access. It lets AI interact with WordPress through MCP while helping organizations manage access, enforce policies, protect non-human identities (NHI), and require human approval for sensitive actions. Use it to securely connect tools such as ChatGPT, Claude, and Cursor with WordPress. Marketplace Link: https://wordpress.org/plugins/miniorange-secure-mcp-server/ Official website: https://plugins.miniorange.com/mcp-server-ai-policy-enforcement-wordpress ChatGpt Marketplace: https://chatgpt.com/plugins/plugin_asdk_app_6a312802286c8191bad0a7278a4e53ef Claude Marketplace: https://claude.ai/directory/miniorange-mcp-for-wordpress Cursor Marketplace: https://cursor.com/marketplace/miniorange
WordPress MCP server: generate SEO posts, AI images, autoblog & WooCommerce on your self-hosted site
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to manage and interact with WordPress sites through MCP, providing tools for content creation, moderation, WooCommerce operations, and governance.47GPL 2.0
- AlicenseNot gradedqualityBmaintenanceA self-contained MCP server plugin that connects WordPress to AI, providing 58 abilities for managing posts, pages, media, users, plugins, menus, comments, and more through any MCP-compatible AI client.164GPL 2.0
- AlicenseNot gradedqualityAmaintenanceTurns any WordPress site into an MCP server, allowing AI clients to directly control files, database, WP-CLI, PHP, content, and more through declarative abilities without writing code.2GPL 2.0
- AlicenseNot gradedqualityAmaintenanceA free WordPress plugin that turns your site into a governed MCP server, exposing 153 curated WordPress abilities (posts, media, users, WooCommerce, ACF, SEO) as tools for AI agents like Claude and Cursor. Every ability is off by default, scoped to a least-privilege user, capability-gated, and logged.4GPL 2.0