MCPDO — AI Operations Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
MCPDO finds bounded WooCommerce operational issues, preserves the evidence behind each finding, and lets supported AI clients prepare exact product fixes without bypassing WordPress permissions or human approval.
Free V1 focuses on one complete outcome loop: find it prove it preview a fix approve apply verify recover when safe.
- Run a read-only Store Health Audit.
- Review deterministic findings with evidence, method, limitations, and evidence quality.
- Preview exact reversible product changes before anything is written.
- Update supported product name, short/full description, publication status, categories, tags, existing-media featured image, and inventory fields.
- Require explicit approval before every supported write.
- Verify the observed result independently after the write.
- Recover only the captured MCPDO fields when recovery is still safe and no newer merchant edit would be overwritten.
- Restrict every connection with granular scopes and per-tool switches.
- Review an immutable operational activity timeline.
MCPDO does not claim conversion or revenue causality from the V1 audit signals. Product content, inventory, pending/failed order status, coupons, and supported WooCommerce configuration values are reported as observations only.
WooCommerce is not required to activate MCPDO. When WooCommerce is unavailable or below the supported commerce boundary, MCPDO remains active and reports commerce features as unavailable.
Safety by default
- Global writes are off by default.
- Free V1 writes are limited to the explicit reversible WooCommerce product-field allowlist; arbitrary WordPress, PHP, SQL, shell, filesystem, order, customer, or financial mutation is not exposed.
- Preview, permission checks, approval, verification, and recovery rules remain server-authoritative.
- No raw PHP, SQL, shell, filesystem, bulk financial mutation, or automatic customer messaging ability is exposed.
- Evidence and activity metadata are sanitized before persistence.
MCP connectivity
MCPDO includes a bounded native MCP endpoint and registers WordPress Abilities for supported operations. Supported clients authenticate with MCPDO OAuth 2.1 Authorization Code + PKCE. OAuth bearer tokens are accepted only by the dedicated MCPDO endpoint and do not create a WordPress login session or authenticate general WordPress REST API routes. MCPDO persists only one-way token hashes needed to validate and rotate grants.
Development source
The human-readable admin source used to build the distributed JavaScript and CSS is included in the plugin under assets/src/. The deployed package also includes package.json, pnpm-lock.yaml, and tsconfig.admin.json; see source.txt for the pinned toolchain and rebuild command.
Privacy
MCPDO stores operational audit, finding, evidence, operation, recovery, task, and activity records in the site’s WordPress database.
- No mandatory telemetry is sent to TopHive.
- MCPDO does not store plaintext OAuth bearer/refresh tokens and does not create WordPress Application Passwords for external MCP clients.
- Supported PII and secret-shaped values are redacted before evidence persistence.
- WordPress privacy export and erasure tools can export or unlink user references from MCPDO operational history.
- Default retention is 90 days for activity, 30 days for evidence, 30 days for completed task details, and 14 days for recoverable ChangeSets.
- Administrators can change supported retention windows in MCPDO settings.
- MCPDO never removes WooCommerce store data during uninstall.
External services
MCPDO core does not require an MCPDO Cloud account, does not use a TopHive remote administration control plane, and does not proxy site data through TopHive servers by default. The OAuth authorization/token endpoints and native MCP endpoint are hosted by the merchant’s own WordPress site.
An external AI/MCP client is optional and is selected/configured by the site administrator. MCPDO does not initiate outbound requests to those AI providers in Core V1; the configured client connects to the site’s MCP endpoint. Data the administrator chooses to expose through that client is governed by the administrator’s client choice and that client’s own terms and privacy policy.
Screenshots
No screenshots provided
