{"id":340729,"date":"2026-07-18T08:35:19","date_gmt":"2026-07-18T08:35:19","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/open-for-agents-ai-mcp-toolkit\/"},"modified":"2026-08-27T21:27:30","modified_gmt":"2026-08-27T21:27:30","slug":"open-for-agents-ai-toolkit-with-mcp","status":"publish","type":"plugin","link":"https:\/\/en-gb.wordpress.org\/plugins\/open-for-agents-ai-toolkit-with-mcp\/","author":14414319,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.3.49","stable_tag":"0.3.49","tested":"7.1","requires":"6.4","requires_php":"8.1","requires_plugins":null,"header_name":"Open for Agents: AI Toolkit with MCP","header_author":"Enoki Limited","header_description":"Review, govern, and publish safe WordPress capabilities across agent discovery and execution formats.","assets_banners_color":"c4c5c7","last_updated":"2026-08-27 21:27:30","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/www.openforagents.com\/","header_author_uri":"https:\/\/www.enoki.nz\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":519,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.3.18":{"tag":"0.3.18","author":"mdotk","date":"2026-07-18 09:47:31","revision":3612473},"0.3.19":{"tag":"0.3.19","author":"mdotk","date":"2026-07-19 08:26:06","revision":3613350},"0.3.21":{"tag":"0.3.21","author":"mdotk","date":"2026-07-21 21:28:47","revision":3617714},"0.3.26":{"tag":"0.3.26","author":"mdotk","date":"2026-07-23 04:40:22","revision":3619401},"0.3.27":{"tag":"0.3.27","author":"mdotk","date":"2026-07-24 23:38:57","revision":3622016},"0.3.29":{"tag":"0.3.29","author":"mdotk","date":"2026-07-28 03:15:55","revision":3625310},"0.3.30":{"tag":"0.3.30","author":"mdotk","date":"2026-08-13 21:34:51","revision":3646322},"0.3.31":{"tag":"0.3.31","author":"mdotk","date":"2026-08-17 08:55:42","revision":3650733},"0.3.44":{"tag":"0.3.44","author":"mdotk","date":"2026-08-23 22:57:02","revision":3662405},"0.3.45":{"tag":"0.3.45","author":"mdotk","date":"2026-08-24 23:22:26","revision":3664376},"0.3.46":{"tag":"0.3.46","author":"mdotk","date":"2026-08-25 04:18:08","revision":3664537},"0.3.49":{"tag":"0.3.49","author":"mdotk","date":"2026-08-27 21:27:30","revision":3669534}},"upgrade_notice":{"0.3.49":"<p>Improves agent product browsing, decimal-price comparisons and continuation without changing cart approval requirements.<\/p>","0.3.48":"<p>Keeps MCP site search useful on themes whose rendered search pages exceed the transport safety limit.<\/p>","0.3.47":"<p>Keeps MCP discovery metadata aligned with the callable read-only tool surface.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3612390,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3612390,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3664376,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3664376,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{"blueprint.json":{"filename":"blueprint.json","revision":3669537,"resolution":false,"location":"assets","locale":"","contents":"{\"$schema\":\"https:\\\/\\\/playground.wordpress.net\\\/blueprint-schema.json\",\"landingPage\":\"\\\/wp-admin\\\/admin.php?page=open-for-agents\",\"preferredVersions\":{\"php\":\"8.3\",\"wp\":\"latest\"},\"phpExtensionBundles\":[\"kitchen-sink\"],\"steps\":[{\"step\":\"login\",\"username\":\"admin\",\"password\":\"password\"},{\"step\":\"installPlugin\",\"pluginData\":{\"resource\":\"wordpress.org\\\/plugins\",\"slug\":\"open-for-agents-ai-toolkit-with-mcp\"},\"options\":{\"activate\":true}},{\"step\":\"setSiteOptions\",\"options\":{\"blogname\":\"Open for Agents Preview\",\"blogdescription\":\"Try owner-reviewed WordPress tools for compatible AI agents\"}}]}"}},"all_blocks":[],"tagged_versions":["0.3.18","0.3.19","0.3.21","0.3.26","0.3.27","0.3.29","0.3.30","0.3.31","0.3.44","0.3.45","0.3.46","0.3.49"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3664376,"resolution":"1","location":"assets","locale":"","width":1250,"height":850},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3664376,"resolution":"2","location":"assets","locale":"","width":1250,"height":850},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3664376,"resolution":"3","location":"assets","locale":"","width":1250,"height":850},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3664376,"resolution":"4","location":"assets","locale":"","width":1250,"height":850}},"screenshots":{"1":"See a compatible agent use a reviewed public Core capability; the separately deployed Assistant shown is optional and is not included in Core.","2":"Review each capability's visibility, risk and execution policy before publication.","3":"Publish and verify the selected tools through the public routes agents use.","4":"Confirm tested provider support and distinguish lower-confidence discovery."}},"plugin_section":[],"plugin_tags":[246305,601,242115,258453,286],"plugin_category":[42,45],"plugin_contributors":[272160],"plugin_business_model":[],"class_list":["post-340729","plugin","type-plugin","status-publish","hentry","plugin_tags-ai-agents","plugin_tags-forms","plugin_tags-mcp","plugin_tags-webmcp","plugin_tags-woocommerce","plugin_category-contact-forms","plugin_category-ecommerce","plugin_contributors-mdotk","plugin_committers-mdotk"],"banners":{"banner":"https:\/\/ps.w.org\/open-for-agents-ai-toolkit-with-mcp\/assets\/banner-772x250.png?rev=3664376","banner_2x":"https:\/\/ps.w.org\/open-for-agents-ai-toolkit-with-mcp\/assets\/banner-1544x500.png?rev=3664376","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/open-for-agents-ai-toolkit-with-mcp\/assets\/icon-128x128.png?rev=3612390","icon_2x":"https:\/\/ps.w.org\/open-for-agents-ai-toolkit-with-mcp\/assets\/icon-256x256.png?rev=3612390","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/open-for-agents-ai-toolkit-with-mcp\/assets\/screenshot-1.png?rev=3664376","caption":"See a compatible agent use a reviewed public Core capability; the separately deployed Assistant shown is optional and is not included in Core."},{"src":"https:\/\/ps.w.org\/open-for-agents-ai-toolkit-with-mcp\/assets\/screenshot-2.png?rev=3664376","caption":"Review each capability's visibility, risk and execution policy before publication."},{"src":"https:\/\/ps.w.org\/open-for-agents-ai-toolkit-with-mcp\/assets\/screenshot-3.png?rev=3664376","caption":"Publish and verify the selected tools through the public routes agents use."},{"src":"https:\/\/ps.w.org\/open-for-agents-ai-toolkit-with-mcp\/assets\/screenshot-4.png?rev=3664376","caption":"Confirm tested provider support and distinguish lower-confidence discovery."}],"raw_content":"<!--section=description-->\n<p>Publish WordPress content, forms and WooCommerce capabilities as MCP and WebMCP tools for compatible AI agents. You choose what agents may discover, and supported changes require approval before they run.<\/p>\n\n<p>Install the plugin, enable Standard Tools, review the catalog, then publish and verify it. Core works without an Open for Agents account, AI API key or paid license, and nothing is published merely because the plugin was activated.<\/p>\n\n<p>Open for Agents is for website owners who want agents to use reviewed site capabilities. It is not unrestricted WordPress administration.<\/p>\n\n<h4>What you can do<\/h4>\n\n<ul>\n<li>Publish reviewed public content, navigation, search, supported forms and WooCommerce capabilities.<\/li>\n<li>Give compatible agents one owner-approved catalog instead of exposing arbitrary WordPress actions.<\/li>\n<li>Verify the selected tools through the same public routes agents use.<\/li>\n<li>Keep private, dangerous, unsupported and unapproved actions out of public exports.<\/li>\n<li>Require trusted, argument-bound visitor approval before supported changes run.<\/li>\n<\/ul>\n\n<h4>Your first useful result<\/h4>\n\n<ol>\n<li>Install and activate Open for Agents.<\/li>\n<li>Open <strong>Open for Agents &gt; Setup<\/strong> and enable Standard Tools.<\/li>\n<li>Review the catalog and confirm what may be public.<\/li>\n<li>Choose <strong>Publish Safe Public and verify<\/strong>.<\/li>\n<li>Ask a currently verified compatible agent a tested question, such as requesting the site's public information, and confirm the expected result.<\/li>\n<\/ol>\n\n<h4>Safe by default<\/h4>\n\n<p>Activation alone publishes nothing. Public publishing and the browser runtime are disabled by default, and detected forms or endpoints do not become tools automatically.<\/p>\n\n<p>Safe Public includes only the reviewed public selection. An exact session-bound read such as cart inspection can be enabled without cart changes. Write tools still require the write framework and trusted, argument-bound visitor approval. Checkout, payment, order placement and account changes remain unavailable.<\/p>\n\n<p>Core requires no Open for Agents account, model API key, paid license or hosted service. Every included capability remains available without a paid upgrade.<\/p>\n\n<h4>Supported content, forms and commerce<\/h4>\n\n<ul>\n<li>WordPress public site information, post types, navigation, posts, search, individual posts and terms.<\/li>\n<li>WooCommerce 10.5.1 and 10.9.4: tested product discovery, session-bound cart inspection, visitor-approved reversible cart tools and declared HPOS compatibility.<\/li>\n<li>Contact Form 7 6.1.5 and 6.1.6: tested detection, reviewed publication, and certified execution for supported single-page contact and choice fields.<\/li>\n<li>WPForms Lite 1.9.9.2 and 1.10.2.1: tested detection, reviewed publication, and certified execution for supported single-page contact, number, choice, name and address fields.<\/li>\n<\/ul>\n\n<p>Executable forms exclude captcha, consent, payment, upload, account, signature, calculation and multi-page workflows. Generic REST and AJAX mining is lower-confidence discovery for administrator review, not native provider support. Detection never means automatic publication; execution requires provider enablement, exact per-form opt-in and a trusted approval verifier.<\/p>\n\n<h4>How agents discover the catalog<\/h4>\n\n<p>MCP lets compatible external clients discover and call reviewed tools through a bounded server endpoint. WebMCP makes the same reviewed capabilities available to compatible browser agents on the relevant pages.<\/p>\n\n<p>Core can also publish the owner-approved catalog through <code>llms.txt<\/code>, an API Catalog, an MCP Server Card, Agent Skills and optional Agentic Resource Discovery output. AI crawler controls for <code>robots.txt<\/code>, validation, diagnostics and scan history help administrators understand the published surface.<\/p>\n\n<h4>Optional Assistant<\/h4>\n\n<p>The separately distributed Open for Agents Assistant is optional and is not included in this WordPress.org package. It is available only for approved deployments, not general public download. Core works without it.<\/p>\n\n<h4>Documentation and demonstration<\/h4>\n\n<p>https:\/\/www.youtube.com\/watch?v=G1JDZRRWRBk<\/p>\n\n<ul>\n<li><a href=\"https:\/\/www.openforagents.com\/docs\/getting-started\">Getting started guide<\/a><\/li>\n<li><a href=\"https:\/\/www.openforagents.com\/docs\">Documentation<\/a><\/li>\n<li><a href=\"https:\/\/demo.openforagents.com\/\">Live WordPress demonstration<\/a><\/li>\n<li><a href=\"https:\/\/www.openforagents.com\/\">Open for Agents website<\/a><\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>Core does not contact an external service operated by Enoki Limited or another provider.<\/p>\n\n<p>Published MCP Server Card and Agent Skills documents contain <code>$schema<\/code> identifiers at <code>static.modelcontextprotocol.io<\/code> and <code>schemas.agentskills.io<\/code>. The plugin does not request those URLs, transmit data to them or require them to be available.<\/p>\n\n<p>Deep scan is an optional developer integration point, not a bundled service. When enabled, the plugin passes a page URL and non-secret request settings only to locally installed code attached to <code>open_for_agents_deep_scan_report<\/code>; it never passes authentication cookies, authorization headers or WordPress nonces. A developer who connects an external renderer must disclose that separate service, its data, terms and privacy policy. Without an integration, the plugin uses its same-site static scan and sends nothing externally.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Core does not create an Enoki Limited account, load remote tracking code or transmit site data to an Open for Agents service.<\/p>\n\n<p>Normal scanning and verification make HTTP requests to the WordPress site's own public or administrator-authorized same-origin URLs. Authenticated scan cookies are used only for same-origin requests during that scan and are never included in public output.<\/p>\n\n<p>Any configured third-party renderer may process page URLs, request context or rendered content and must be governed separately.<\/p>\n\n<p>Privacy policy: <a href=\"https:\/\/www.openforagents.com\/privacy\">Open for Agents privacy policy<\/a><\/p>\n\n<p>Terms: <a href=\"https:\/\/www.openforagents.com\/terms\">Open for Agents terms<\/a><\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate Open for Agents.<\/li>\n<li>Open <strong>Open for Agents &gt; Setup<\/strong> and enable Standard Tools.<\/li>\n<li>Optionally scan for supported site-specific workflows.<\/li>\n<li>Review the catalog, visibility, risk and execution policy.<\/li>\n<li>Choose <strong>Publish Safe Public and verify<\/strong> to check, publish and verify the selected public tools.<\/li>\n<\/ol>\n\n<p>Upgrading preserves existing settings, reviewed actions, scan history and publication state.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20activation%20immediately%20expose%20my%20site%20to%20agents%3F\"><h3>Does activation immediately expose my site to agents?<\/h3><\/dt>\n<dd><p>No. Public publishing and the browser runtime are disabled by default. An administrator must review and enable them.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20send%20my%20content%20or%20credentials%20to%20open%20for%20agents%3F\"><h3>Does the plugin send my content or credentials to Open for Agents?<\/h3><\/dt>\n<dd><p>No. Core sends no site content, credentials, scan results or visitor data to Enoki Limited or Open for Agents. A separately configured deep-scan renderer controls its own data handling.<\/p><\/dd>\n<dt id=\"do%20i%20need%20an%20ai%20api%20key%3F\"><h3>Do I need an AI API key?<\/h3><\/dt>\n<dd><p>No. Scanning, review, validation, publication, discovery endpoints, MCP and WebMCP runtime support do not require a model API key.<\/p><\/dd>\n<dt id=\"which%20integrations%20are%20supported%3F\"><h3>Which integrations are supported?<\/h3><\/dt>\n<dd><p>The scanner supports WordPress core, WooCommerce core, Contact Form 7 and WPForms Lite. Selected custom REST and AJAX surfaces appear as lower-confidence review candidates.<\/p><\/dd>\n<dt id=\"can%20an%20agent%20place%20an%20order%20or%20make%20a%20payment%3F\"><h3>Can an agent place an order or make a payment?<\/h3><\/dt>\n<dd><p>No. Checkout, payment, order placement and account changes are excluded. Cart inspection is an exact opt-in session read. Cart changes remain disabled by default and require trusted, argument-bound visitor approval.<\/p><\/dd>\n<dt id=\"what%20is%20published%3F\"><h3>What is published?<\/h3><\/dt>\n<dd><p>Only the administrator-approved public catalog and enabled discovery formats. Private scan evidence, cookies, credentials, nonces, logs and admin-only data are not published.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.3.49<\/h4>\n\n<ul>\n<li>Return compact product-tool summaries with accurate counts and resumable pages. Add numeric price ordering using current sellable offers, while retaining full product details and existing safety limits.<\/li>\n<\/ul>\n\n<h4>0.3.48<\/h4>\n\n<ul>\n<li>Return bounded structured results when MCP clients use the reviewed WordPress site-search form.<\/li>\n<\/ul>\n\n<h4>0.3.47<\/h4>\n\n<ul>\n<li>Keep MCP server-card and live tool-list schemas and safety annotations identical.<\/li>\n<\/ul>","raw_excerpt":"Publish WordPress content, forms and WooCommerce tools for AI agents through MCP and WebMCP, with owner review and approval for changes.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/340729","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=340729"}],"author":[{"embeddable":true,"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/mdotk"}],"wp:attachment":[{"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=340729"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=340729"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=340729"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=340729"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=340729"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=340729"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}