Easy MCP AI logo
Agents Orchestration Frameworks · Api Tools

Easy MCP AI

Easy MCP AI is a free WordPress plugin that turns any site into a Model Context Protocol server, exposing 240 tools so Claude, ChatGPT, Cursor, n8n or any MCP client can manage content, WooCommerce, SEO and analytics.

Active Free plan Free API available 13+ Verified by Guidaio
Overview

What is Easy MCP AI?

Easy MCP AI is a free WordPress plugin, published on the official WordPress.org directory under the slug easy-mcp-ai and licensed GPL-2.0-or-later. Its purpose is narrow and practical: it turns a WordPress installation into a Model Context Protocol server, the open standard created by Anthropic that lets AI assistants reach external tools and data sources. Once the plugin is active, any MCP client can operate the site directly.

The architecture is deliberately plain. Everything is pure PHP running inside WordPress — no Node.js, no proxy, no long-running process, no external service — so standard shared hosting is enough. Communication uses Streamable HTTP over a single endpoint, https://yoursite.com/wp-json/easy-mcp-ai/v1/mcp, authenticated with a bearer token.

The plugin ships 240 tools: 96 covering WordPress core, 90 covering third-party plugins and 54 covering data integrations. The core set spans posts, pages, media, users, comments, categories, tags, menus, site settings, plugins, themes, blocks, custom post types, templates, global styles, post and term meta, revisions, search, history and taxonomies. Every tool is publicly catalogued and flagged read-only or destructive. Plugin coverage includes WooCommerce, Yoast SEO, Rank Math, SEOPress, Slim SEO, The SEO Framework, Advanced Custom Fields, BuddyPress and The Events Calendar; data coverage includes Google Analytics 4, Google Search Console, DataForSEO, Semrush, SE Ranking and Ahrefs.

A bridge to the WordPress 6.9 Abilities API extends the reach further: any plugin that registers its abilities through wp_register_ability() becomes usable as MCP tools automatically, and the publisher advertises a directory of more than 100 plugins and 2,000 tools built on that mechanism.

Sixteen client guides are published — among them Claude Desktop, Claude Code, Claude Connectors, ChatGPT, Cursor, n8n, Gemini CLI, GitHub Copilot, Windsurf and Zed — and the publisher states that any framework speaking MCP over HTTP connects the same way. The site claims more than 8,000 active installations and 52 admin languages. Vertigo Studio S.A., based in Bucharest, publishes it and states no affiliation with WordPress or Automattic.

What it does

  • Expose 240 WordPress tools to any MCP-compatible AI client
  • Create, edit, publish and delete posts, pages, media, users and menus by conversation
  • Push SEO metadata to Yoast SEO, Rank Math or SEOPress in the same step
  • Manage a WooCommerce catalogue and its orders
  • Pull keyword volumes and competitor gaps from DataForSEO, Semrush, SE Ranking or Ahrefs
  • Read Google Analytics 4 and Search Console figures inside the chat
  • Restrict each API token to a precise subset of tools, with a full audit log
Audience

When to use Easy MCP AI / When not to

A quick filter to help you decide if Easy MCP AI is the right fit.

When to use Easy MCP AI

  • WordPress site owners and administrators who already work daily with an AI assistant
  • Content and SEO teams pushing metadata to Yoast SEO, Rank Math or SEOPress
  • WooCommerce merchants who want catalogue and order work handled through conversation
  • Agencies and freelancers maintaining several WordPress installations at once
  • Plugin developers adopting the WordPress 6.9 Abilities API

When not to use Easy MCP AI

  • Anyone whose site does not run on self-hosted WordPress
  • WordPress.com plans that do not allow third-party plugins to be installed
  • Sites served without HTTPS, which the documentation treats as a hard requirement
  • Teams looking for a content generator: the plugin exposes tools, it does not write
  • Buyers expecting bundled SEO data, since DataForSEO, Semrush, SE Ranking and Ahrefs are billed separately
Get started

How to use Easy MCP AI

A typical end-to-end flow, from setup to results.

  1. In the WordPress admin, open Plugins then Add New Plugin and search for Easy MCP AI
  2. Click Install Now and Activate, or upload the ZIP downloaded from WordPress.org
  3. Check that the site is served over HTTPS, which the documentation makes a hard requirement
  4. Open Easy MCP AI then API Tokens and click Create New Token
  5. Fill in the token name, the associated WordPress user, the allowed tools and an expiry date
  6. Choose the Administrator role for full write access, or Editor for content only
  7. Copy the token straight away: it is shown once and stored only as a SHA-256 hash
  8. Note the endpoint, always https://yoursite.com/wp-json/easy-mcp-ai/v1/mcp
  9. Follow the setup guide for your AI client, pasting the URL or editing its JSON configuration file
  10. If the endpoint answers 404, re-save Settings then Permalinks once to flush the rewrite rules
Quick read

Pros & Cons

Pros

  • Free and open source under GPL-2.0-or-later, distributed through the official WordPress directory
  • No infrastructure to run: pure PHP on ordinary shared hosting, no Node.js and no proxy
  • Unusually granular security for a free plugin, from per-token permissions to a full audit log
  • OAuth 2.1 with PKCE, rarely implemented in the WordPress plugin ecosystem
  • Client-agnostic: any MCP client works, so no lock-in to a single assistant
  • The plugin sends nothing back to the publisher, with no telemetry and no usage statistics
  • Explicit guardrails against destructive actions, including forced drafts and disabled delete tools

Cons

  • Of no use outside self-hosted WordPress
  • The SEO data integrations require paid third-party accounts, billed separately
  • Very young: the domain was registered in March 2026 and first archived in May 2026
  • No GDPR compliance claim, no published DPA and no named data protection officer
  • No hosting country or region is disclosed for the vendor's own site
  • The pre-release security review is explicitly not a third-party penetration test
  • No contractual support channel beyond the WordPress.org forum and a generic mailbox
Pricing

Pricing & Plans

Easy MCP AI is free of charge. The plugin is distributed at no cost through the official WordPress.org directory under the GPL-2.0-or-later licence, and the site publishes no pricing page, no paid tier and no premium edition; there is therefore no entry price and no billing currency to report. The only expenses a user may incur are external: the third-party search data providers used by the data integrations — DataForSEO, Semrush, SE Ranking and Ahrefs — are billed separately by their own vendors, as the homepage states.

Plan 1
  • Free plugin — the only tier
  • downloaded from the official WordPress.org directory under the GPL-2.0-or-later licence
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Easy MCP AI handles your data.

GDPR overview

There is no GDPR claim anywhere on the site: the acronym appears on none of the pages collected, no Data Processing Agreement is published and no Data Protection Officer is named. What the publisher does offer is a European footing — Vertigo Studio S.A. is established at 20 Povernei Street, Bucharest, Romania — and a privacy policy updated on 31 August 2026 that acknowledges rights of access, correction and deletion depending on where the visitor lives. Formal requests go to legal@vertistudio.com. Because no user accounts exist, the publisher argues that most requests can be settled by clearing browser cookies. The site is not directed at children under 13. Romanian law governs the terms, with exclusive jurisdiction in Bucharest. No Article 27 representative is designated, which is consistent with an establishment inside the Union.

Who owns the data?

Nothing leaves the user's server. The privacy policy states that the plugin does not collect, transmit or store any data from the WordPress site or its visitors, and that no data is ever sent to the publisher or to a third-party service; everything runs locally inside the installation. Content, tokens and audit logs therefore remain the site owner's, on the site owner's hosting. Separately, Vertigo Studio S.A. owns the text, design and graphics of the easymcpai.com website, while the plugin code itself is open source under GPL-2.0-or-later. Website analytics and server logs are the only data the publisher handles, and it undertakes not to sell them to any third party.

Reuse rights

The plugin's code is distributed under GPL-2.0-or-later, so it may be used, modified and redistributed under the terms of that licence without asking permission. The website content is treated differently: the terms reserve the text, design and graphics of easymcpai.com to Vertigo Studio S.A. and forbid reproducing or redistributing them without permission. Everything the plugin produces or touches — posts, pages, media, WooCommerce records, audit logs — stays inside the user's own WordPress database, so its reuse is governed by the user alone and needs no clearance from the publisher. On its own side the publisher states that it does not sell visitor data, but reserves the right to transfer website data to an acquirer in a merger, acquisition or sale of assets.

Data retention & training

Retention summary
No retention period is published. On the plugin side the question is largely moot: it stores nothing with the publisher, since it neither collects nor transmits any data, and the audit log it writes lives in the user's own WordPress database, kept or purged at the user's discretion. On the website side, the publisher records standard server logs — IP addresses, request timestamps and page URLs — for security and performance without stating how long they are kept, and uses analytics and advertising cookies whose lifetimes are not documented either. Because no user accounts exist, the publisher suggests that most deletion requests can be settled by clearing browser cookies; formal requests go to legal@vertistudio.com.
Trains on customer data
No
GDPR contact

Hosting summary

Two separate questions sit behind this one. For the plugin, hosting is simply the user's own: the privacy policy states that it does not collect, transmit or store any data from the WordPress site or its visitors, and that nothing is ever sent to the publisher's servers or to a third-party service. Content, tokens and audit logs stay in the user's database, under the user's own hosting jurisdiction. For the easymcpai.com website itself, no hosting country or region is disclosed; the privacy policy names hosting providers only as a category, with Cloudflare given as an example. A network lookup resolves the domain to 104.21.30.152, an anycast address on Cloudflare's AS13335 network with a node observed in San Francisco, which is a technical observation rather than a statement from the publisher. The company behind the site, Vertigo Studio S.A., is established in Bucharest, Romania, so Romanian and European law applies to it, but that says nothing about where visitor analytics or server logs physically sit.

Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Easy MCP AI.

  • An Administrator token gives an AI real write access to a live site: scope every token to the tools it truly needs
  • Tokens are displayed once and stored only as a hash, so a lost token has to be replaced rather than recovered
  • HTTPS is mandatory, since the token travels in a plain Authorization header
  • The seven delete tools are destructive: disable them globally or leave them out of the token's permissions
  • Turn on Force Draft on Create wherever published content must still pass a human review
  • No GDPR claim and no DPA are published, which has to be assessed before use in a regulated context
  • Handing routine site work to an assistant can quietly erode an operator's own grasp of the admin panel and of what actually changed
Setup

Setup & Integrations

Technical difficulty

Low on the WordPress side. The plugin installs in three clicks from the admin, and creating a token is a single form: name, associated user, allowed tools, expiry. Two prerequisites matter — HTTPS and pretty permalinks — and the documented pitfall is a 404 endpoint, fixed by re-saving the Permalinks settings once. Difficulty then depends on the AI client: Claude Connectors and ChatGPT only need the endpoint URL pasted in, while Claude Desktop, Cursor, Gemini CLI or Zed require editing a JSON configuration file. No server, no Node.js and no proxy are ever involved.

Deployment

PluginAPI

Integrations

WordPress WooCommerce Yoast SEO Rank Math SEOPress Slim SEO The SEO Framework Advanced Custom Fields BuddyPress The Events Calendar Google Analytics Google Search Console DataForSEO Semrush SE Ranking Ahrefs Claude Claude Code Claude Desktop ChatGPT Cursor Gemini CLI GitHub Copilot Google Antigravity Cline LibreChat Manus N8n Pydantic AI Roo Code Windsurf Zed

Supported languages

EnglishSpanishFrenchGermanPortugueseJapaneseChineseIndonesianArabic
Company

Behind Easy MCP AI

Company name
Vertigo Studio S.A.
Founded
13/05/2026
Country of origin
🇷🇴 Romania
Headquarters
20 Povernei Street, 4th Floor, Flat no. 9, 010641 Bucharest, Romania
UBO
Ionut Neagu
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Legal contact
Support contact
Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What is the Model Context Protocol?
MCP is an open standard created by Anthropic that lets AI assistants connect securely to external tools and data sources. The documentation notes that it is supported by Anthropic, OpenAI, Google and dozens of IDEs.
How much does Easy MCP AI cost?
Nothing. The plugin is free and open source under GPL-2.0-or-later, distributed through WordPress.org. Only the third-party SEO data providers, such as DataForSEO, Semrush, SE Ranking and Ahrefs, are billed separately.
Does it need Node.js or a special server?
No. The plugin is pure PHP and runs entirely inside WordPress on standard hosting. There are no long-running processes, no Node.js scripts and no external proxy service.
Is it safe to run on a live site?
The publisher says yes when used over HTTPS: every request is authenticated with a bearer token, rate-limited, checked against WordPress capabilities and written to an internal audit log.
How do I stop the AI from deleting content?
Two ways. Grant the token read-only tools when you create it, or switch on the global Disabled Delete Tools setting, which blocks all seven destructive delete tools for every token at once.
Why does the endpoint return a 404?
Go to Settings then Permalinks in the WordPress admin and click Save Changes to flush the rewrite rules. Pretty permalinks must be enabled for the REST endpoint to register.
Which AI clients can connect?
Any client that speaks MCP over HTTP. Sixteen setup guides are published, covering Claude Desktop, Claude Code, Claude Connectors, ChatGPT, Cursor, Cline, Gemini CLI, GitHub Copilot, Google Antigravity, LibreChat, Manus, n8n, Pydantic AI, Roo Code, Windsurf and Zed.
Does the plugin send my data to the publisher?
No. The privacy policy states that the plugin collects, transmits and stores nothing — no telemetry, no usage statistics and no phone-home requests. All functionality runs locally in your own installation.
Can I try it without installing anything?
Yes. The site offers a live demo on a throwaway TasteWP WordPress instance with the plugin already installed.
What should I do if I find a security flaw?
Report it through the Patchstack vulnerability disclosure programme. The publisher asks that flaws are not reported through public GitHub issues, the WordPress.org support forum or social media.
Conclusion

Should you pick Easy MCP AI?

Easy MCP AI does one thing and does it broadly: it plugs a WordPress site into the Model Context Protocol so that any AI client can operate it. The scope is genuinely wide — 240 catalogued tools across WordPress core, nine third-party plugins and six data sources — and the engineering choices are sober. Pure PHP on ordinary hosting removes the usual obstacle of running a separate MCP server, and the bridge to the WordPress 6.9 Abilities API means the surface grows as other plugins adopt the standard.

The security work is the surprise. A free plugin offering OAuth 2.1 with PKCE, SHA-256 token hashing, per-token tool permissions, capability checks, rate limiting, IP allowlisting and a full audit log is doing more than most paid alternatives, and the safety switches — Force Draft on Create, globally disabled delete tools — show that the publisher has thought about what an autonomous agent can break.

Two reservations remain. The first is maturity: the domain dates from March 2026, the first archive capture from May 2026, and the 8,000 active installations, while real, are still a small base. The second is documentation of the legal side — no GDPR claim, no DPA, no named data protection officer, no disclosed hosting jurisdiction for the vendor's own site — which matters less than usual here, since the plugin transmits nothing to the publisher, but will still weigh in a regulated setting.

For anyone who runs WordPress and already works through an AI assistant, the cost of trying is zero and the payoff is immediate. The real decision is not whether to install it but how tightly to scope the first token.