
Easy MCP AI
Easy MCP AI is a free WordPress plugin that turns any site into a Model Context Protocol server, exposing 240 tools so Claude, ChatGPT, Cursor, n8n or any MCP client can manage content, WooCommerce, SEO and analytics.
What is Easy MCP AI?
Easy MCP AI is a free WordPress plugin, published on the official WordPress.org directory under the slug easy-mcp-ai and licensed GPL-2.0-or-later. Its purpose is narrow and practical: it turns a WordPress installation into a Model Context Protocol server, the open standard created by Anthropic that lets AI assistants reach external tools and data sources. Once the plugin is active, any MCP client can operate the site directly.
The architecture is deliberately plain. Everything is pure PHP running inside WordPress — no Node.js, no proxy, no long-running process, no external service — so standard shared hosting is enough. Communication uses Streamable HTTP over a single endpoint, https://yoursite.com/wp-json/easy-mcp-ai/v1/mcp, authenticated with a bearer token.
The plugin ships 240 tools: 96 covering WordPress core, 90 covering third-party plugins and 54 covering data integrations. The core set spans posts, pages, media, users, comments, categories, tags, menus, site settings, plugins, themes, blocks, custom post types, templates, global styles, post and term meta, revisions, search, history and taxonomies. Every tool is publicly catalogued and flagged read-only or destructive. Plugin coverage includes WooCommerce, Yoast SEO, Rank Math, SEOPress, Slim SEO, The SEO Framework, Advanced Custom Fields, BuddyPress and The Events Calendar; data coverage includes Google Analytics 4, Google Search Console, DataForSEO, Semrush, SE Ranking and Ahrefs.
A bridge to the WordPress 6.9 Abilities API extends the reach further: any plugin that registers its abilities through wp_register_ability() becomes usable as MCP tools automatically, and the publisher advertises a directory of more than 100 plugins and 2,000 tools built on that mechanism.
Sixteen client guides are published — among them Claude Desktop, Claude Code, Claude Connectors, ChatGPT, Cursor, n8n, Gemini CLI, GitHub Copilot, Windsurf and Zed — and the publisher states that any framework speaking MCP over HTTP connects the same way. The site claims more than 8,000 active installations and 52 admin languages. Vertigo Studio S.A., based in Bucharest, publishes it and states no affiliation with WordPress or Automattic.
What it does
- Expose 240 WordPress tools to any MCP-compatible AI client
- Create, edit, publish and delete posts, pages, media, users and menus by conversation
- Push SEO metadata to Yoast SEO, Rank Math or SEOPress in the same step
- Manage a WooCommerce catalogue and its orders
- Pull keyword volumes and competitor gaps from DataForSEO, Semrush, SE Ranking or Ahrefs
- Read Google Analytics 4 and Search Console figures inside the chat
- Restrict each API token to a precise subset of tools, with a full audit log
When to use Easy MCP AI / When not to
A quick filter to help you decide if Easy MCP AI is the right fit.
When to use Easy MCP AI
- WordPress site owners and administrators who already work daily with an AI assistant
- Content and SEO teams pushing metadata to Yoast SEO, Rank Math or SEOPress
- WooCommerce merchants who want catalogue and order work handled through conversation
- Agencies and freelancers maintaining several WordPress installations at once
- Plugin developers adopting the WordPress 6.9 Abilities API
When not to use Easy MCP AI
- Anyone whose site does not run on self-hosted WordPress
- WordPress.com plans that do not allow third-party plugins to be installed
- Sites served without HTTPS, which the documentation treats as a hard requirement
- Teams looking for a content generator: the plugin exposes tools, it does not write
- Buyers expecting bundled SEO data, since DataForSEO, Semrush, SE Ranking and Ahrefs are billed separately
How to use Easy MCP AI
A typical end-to-end flow, from setup to results.
- In the WordPress admin, open Plugins then Add New Plugin and search for Easy MCP AI
- Click Install Now and Activate, or upload the ZIP downloaded from WordPress.org
- Check that the site is served over HTTPS, which the documentation makes a hard requirement
- Open Easy MCP AI then API Tokens and click Create New Token
- Fill in the token name, the associated WordPress user, the allowed tools and an expiry date
- Choose the Administrator role for full write access, or Editor for content only
- Copy the token straight away: it is shown once and stored only as a SHA-256 hash
- Note the endpoint, always https://yoursite.com/wp-json/easy-mcp-ai/v1/mcp
- Follow the setup guide for your AI client, pasting the URL or editing its JSON configuration file
- If the endpoint answers 404, re-save Settings then Permalinks once to flush the rewrite rules
Pros & Cons
Pros
- Free and open source under GPL-2.0-or-later, distributed through the official WordPress directory
- No infrastructure to run: pure PHP on ordinary shared hosting, no Node.js and no proxy
- Unusually granular security for a free plugin, from per-token permissions to a full audit log
- OAuth 2.1 with PKCE, rarely implemented in the WordPress plugin ecosystem
- Client-agnostic: any MCP client works, so no lock-in to a single assistant
- The plugin sends nothing back to the publisher, with no telemetry and no usage statistics
- Explicit guardrails against destructive actions, including forced drafts and disabled delete tools
Cons
- Of no use outside self-hosted WordPress
- The SEO data integrations require paid third-party accounts, billed separately
- Very young: the domain was registered in March 2026 and first archived in May 2026
- No GDPR compliance claim, no published DPA and no named data protection officer
- No hosting country or region is disclosed for the vendor's own site
- The pre-release security review is explicitly not a third-party penetration test
- No contractual support channel beyond the WordPress.org forum and a generic mailbox
Pricing & Plans
Easy MCP AI is free of charge. The plugin is distributed at no cost through the official WordPress.org directory under the GPL-2.0-or-later licence, and the site publishes no pricing page, no paid tier and no premium edition; there is therefore no entry price and no billing currency to report. The only expenses a user may incur are external: the third-party search data providers used by the data integrations — DataForSEO, Semrush, SE Ranking and Ahrefs — are billed separately by their own vendors, as the homepage states.
- Free plugin — the only tier
- downloaded from the official WordPress.org directory under the GPL-2.0-or-later licence
Data, GDPR & hosting
A consolidated view of how Easy MCP AI handles your data.
GDPR overview
There is no GDPR claim anywhere on the site: the acronym appears on none of the pages collected, no Data Processing Agreement is published and no Data Protection Officer is named. What the publisher does offer is a European footing — Vertigo Studio S.A. is established at 20 Povernei Street, Bucharest, Romania — and a privacy policy updated on 31 August 2026 that acknowledges rights of access, correction and deletion depending on where the visitor lives. Formal requests go to legal@vertistudio.com. Because no user accounts exist, the publisher argues that most requests can be settled by clearing browser cookies. The site is not directed at children under 13. Romanian law governs the terms, with exclusive jurisdiction in Bucharest. No Article 27 representative is designated, which is consistent with an establishment inside the Union.
Who owns the data?
Nothing leaves the user's server. The privacy policy states that the plugin does not collect, transmit or store any data from the WordPress site or its visitors, and that no data is ever sent to the publisher or to a third-party service; everything runs locally inside the installation. Content, tokens and audit logs therefore remain the site owner's, on the site owner's hosting. Separately, Vertigo Studio S.A. owns the text, design and graphics of the easymcpai.com website, while the plugin code itself is open source under GPL-2.0-or-later. Website analytics and server logs are the only data the publisher handles, and it undertakes not to sell them to any third party.
Reuse rights
The plugin's code is distributed under GPL-2.0-or-later, so it may be used, modified and redistributed under the terms of that licence without asking permission. The website content is treated differently: the terms reserve the text, design and graphics of easymcpai.com to Vertigo Studio S.A. and forbid reproducing or redistributing them without permission. Everything the plugin produces or touches — posts, pages, media, WooCommerce records, audit logs — stays inside the user's own WordPress database, so its reuse is governed by the user alone and needs no clearance from the publisher. On its own side the publisher states that it does not sell visitor data, but reserves the right to transfer website data to an acquirer in a merger, acquisition or sale of assets.
Data retention & training
Hosting summary
Two separate questions sit behind this one. For the plugin, hosting is simply the user's own: the privacy policy states that it does not collect, transmit or store any data from the WordPress site or its visitors, and that nothing is ever sent to the publisher's servers or to a third-party service. Content, tokens and audit logs stay in the user's database, under the user's own hosting jurisdiction. For the easymcpai.com website itself, no hosting country or region is disclosed; the privacy policy names hosting providers only as a category, with Cloudflare given as an example. A network lookup resolves the domain to 104.21.30.152, an anycast address on Cloudflare's AS13335 network with a node observed in San Francisco, which is a technical observation rather than a statement from the publisher. The company behind the site, Vertigo Studio S.A., is established in Bucharest, Romania, so Romanian and European law applies to it, but that says nothing about where visitor analytics or server logs physically sit.
Things to keep in mind
Risks and trade-offs to weigh before adopting Easy MCP AI.
- An Administrator token gives an AI real write access to a live site: scope every token to the tools it truly needs
- Tokens are displayed once and stored only as a hash, so a lost token has to be replaced rather than recovered
- HTTPS is mandatory, since the token travels in a plain Authorization header
- The seven delete tools are destructive: disable them globally or leave them out of the token's permissions
- Turn on Force Draft on Create wherever published content must still pass a human review
- No GDPR claim and no DPA are published, which has to be assessed before use in a regulated context
- Handing routine site work to an assistant can quietly erode an operator's own grasp of the admin panel and of what actually changed
Setup & Integrations
Technical difficulty
Low on the WordPress side. The plugin installs in three clicks from the admin, and creating a token is a single form: name, associated user, allowed tools, expiry. Two prerequisites matter — HTTPS and pretty permalinks — and the documented pitfall is a 404 endpoint, fixed by re-saving the Permalinks settings once. Difficulty then depends on the AI client: Claude Connectors and ChatGPT only need the endpoint URL pasted in, while Claude Desktop, Cursor, Gemini CLI or Zed require editing a JSON configuration file. No server, no Node.js and no proxy are ever involved.
Deployment
Integrations
Supported languages
Behind Easy MCP AI
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What is the Model Context Protocol?
How much does Easy MCP AI cost?
Does it need Node.js or a special server?
Is it safe to run on a live site?
How do I stop the AI from deleting content?
Why does the endpoint return a 404?
Which AI clients can connect?
Does the plugin send my data to the publisher?
Can I try it without installing anything?
What should I do if I find a security flaw?
Should you pick Easy MCP AI?
Easy MCP AI does one thing and does it broadly: it plugs a WordPress site into the Model Context Protocol so that any AI client can operate it. The scope is genuinely wide — 240 catalogued tools across WordPress core, nine third-party plugins and six data sources — and the engineering choices are sober. Pure PHP on ordinary hosting removes the usual obstacle of running a separate MCP server, and the bridge to the WordPress 6.9 Abilities API means the surface grows as other plugins adopt the standard.
The security work is the surprise. A free plugin offering OAuth 2.1 with PKCE, SHA-256 token hashing, per-token tool permissions, capability checks, rate limiting, IP allowlisting and a full audit log is doing more than most paid alternatives, and the safety switches — Force Draft on Create, globally disabled delete tools — show that the publisher has thought about what an autonomous agent can break.
Two reservations remain. The first is maturity: the domain dates from March 2026, the first archive capture from May 2026, and the 8,000 active installations, while real, are still a small base. The second is documentation of the legal side — no GDPR claim, no DPA, no named data protection officer, no disclosed hosting jurisdiction for the vendor's own site — which matters less than usual here, since the plugin transmits nothing to the publisher, but will still weigh in a regulated setting.
For anyone who runs WordPress and already works through an AI assistant, the cost of trying is zero and the payoff is immediate. The real decision is not whether to install it but how tightly to scope the first token.
- Choosing a selection results in a full page refresh.
- Opens in a new window.