xpay✦ Commerce
Directory
WooCommerce plugins
StifLi Flex MCP – MCP Server with undo for ChatGPT, Claude & Gemini
StifLi Flex MCP – MCP Server with undo for ChatGPT, Claude & Gemini
The most secure MCP Server for WordPress with Undo, plus AI Copilot & Chat Agent. ChatGPT, Claude, Gemini, OpenRouter & Mistral.
5.0
(4 ratings)Will this break my store?
What the WordPress.org registry says about keeping StifLi Flex MCP – MCP Server with undo for ChatGPT, Claude & Gemini running.
Tested to 7.0.2
Tested against the WordPress branch in use today.2 days ago
At least 56.9 releases a year since launch. WordPress.org only lists versions still available for download, so the real number may be higher.7.4
Your host must be running at least this version.5.9
1
A single maintainer. Worth knowing if the plugin is load-bearing for your store.Maintenance & trust
Scored on how StifLi Flex MCP – MCP Server with undo for ChatGPT, Claude & Gemini is looked after — not on how many stores run it.
96
out of 100Maintenance
35 / 35WordPress compatibility
20 / 20Support responsiveness
Not enough dataMerchant satisfaction
11 / 15Listing transparency
10 / 10Ratings
5.0
4 ratingsStifLi Flex MCP is the most secure MCP Server for WordPress with built-in Undo. Connect ChatGPT, Claude Desktop, Gemini, and other MCP clients safely, roll back changes when needed, and manage your site through natural conversation without losing control.
Choose the layers your site needs without loading the rest:
- MCP Server (always active) — Connect ChatGPT, Claude Desktop, or any MCP client directly to your site. Includes Multimedia and Logs & Roll Back.
- AI Copilot (optional addon) — A floating assistant inside the Gutenberg and Classic editors that writes, rewrites, and optimizes your content in real time.
- AI Chat Agent (optional addon) — A full conversational interface to manage posts, WooCommerce, settings, and more.
- Automations, SEO, and Plugin Integrations (optional addons) — Enable only the workflows and integrations used on your site.
On first activation, a setup screen lets you select the addons to load. The default is the MCP Server layer only. You can change the selection later from StifLi Flex MCP → MCP Server → Add-ons.
🎬 Video: Claude to WordPress MCP Connector in 1 Minute
📚 Documentation
Released in December 2025, StifLi Flex MCP was the first MCP plugin for WordPress and remains the most complete WordPress MCP platform for ChatGPT, Claude Desktop, and other MCP clients.
It starts with 122+ built-in MCP tools, and with supported integrations such as All Sources Images, Stifli Backup Tools, AiPatch Security Scanner, Notification for Telegram, WPCode, Code Snippets, Woody Snippets, Advanced Custom Fields, Yoast SEO, Rank Math, WPForms, Gravity Forms, Forminator, The Events Calendar, and Elementor, it can exceed 200 total tools depending on the plugins you install.
📡 MCP Server — Connect ChatGPT, Claude Desktop, and Other MCP Clients
StifLi Flex MCP includes a full standards-compliant MCP server for WordPress, so ChatGPT, Claude Desktop, LibreChat, and other MCP clients can connect directly to your site and use real WordPress tools through OAuth 2.1.
- ChatGPT — Connect through Apps & Connectors with OAuth 2.1 authentication
- Claude Desktop — Connect through Connectors with automatic OAuth flow
- LibreChat and other MCP clients — Use the same MCP endpoint and discovery flow
- Zero shared secrets — No custom API keys or passwords for external MCP clients
- Standards-based — Automatic discovery, registration, and authentication with OAuth 2.1, PKCE, RFC 9728, RFC 8414, and RFC 7591
Just copy the SSE URL from the Settings page, paste it into ChatGPT, Claude Desktop, or another MCP client, and authorize.
✍️ AI Copilot — Your Writing Assistant Inside the Editor
The AI Copilot lives as a floating widget right inside the WordPress post and page editor. It understands the full context of what you’re editing — title, content, categories, tags, featured image, and even WooCommerce product fields — and helps you write better, faster.
- Rewrite, expand, or optimize content — Ask the Copilot to improve your text and it applies the changes directly into the editor
- One-click quick actions — “⚡ Optimize content”, “🏷️ Generate tags”, “📝 Write excerpt”, “🖼️ Generate image” — one tap, instant results
- Real-time editing — The Copilot sets titles, excerpts, tags, slugs, and categories directly in the editor. No copy-pasting
- Content block operations — Insert, update, replace, or delete Gutenberg blocks through conversation
- Visual feedback — Changed fields and blocks are highlighted with a green border so you always see what the AI modified
- Keep or Undo — Every change shows a floating banner: keep it or undo with a single click. You stay in control
- Image generation — Ask the Copilot to generate an image and it sets it as the featured image or inserts it as a block, automatically
- Works with Gutenberg and Classic Editor — Full support for both editors
- Context-aware — The Copilot reads your current post content, blocks, metadata, and editor state to give relevant suggestions
- WooCommerce-aware — When editing a product, the Copilot sees prices, stock, SKU, attributes, and product type
Choose OpenAI (GPT-5.4), Anthropic (Claude 4.6 Opus/Sonnet), or Google (Gemini 3.1 Pro/Flash), and optionally use WordPress AI Client connectors like OpenRouter and Mistral when installed. No complex setup — just your API key or connector credentials.
💡 What Can You Do With the Copilot?
Here are just a few examples of what you can ask while editing a post or page:
- ✏️ “Rewrite the introduction to sound more professional and engaging”
- 📊 “Add a comparison table below the second paragraph with pros and cons”
- 🖼️ “Generate an image that illustrates the idea in paragraph four and insert it right above”
- 📝 “Write a compelling meta description and set it as the excerpt”
- 🛒 “Update the product short description to highlight free shipping and set the sale price to $19.99”
The Copilot reads your full content, understands context, and applies changes directly in the editor — no copy-pasting, no switching tabs.
🤖 AI Chat Agent — Your WordPress AI Assistant
The built-in AI Chat Agent gives you a powerful conversational interface to manage your entire WordPress site:
- Talk to your site — “Show me the last 5 orders”, “Create a blog post about SEO tips”, “What plugins are installed?”
- Multi-provider — Built-in OpenAI (GPT-5.4, GPT-5.3), Anthropic (Claude 4.6 Opus/Sonnet, Claude 4.5 Haiku), Google (Gemini 3.1 Pro, Gemini 3 Flash) + optional WordPress AI Client connectors (OpenRouter, Mistral)
- 122+ MCP tools at its disposal — The AI agent can read posts, create content, manage WooCommerce products, check orders, inspect SEO data, update settings, and much more
- Smart suggestions — After each response, get contextual follow-up suggestions
- Conversation history — Auto-saved across sessions with multi-tab support
- Safe by design — Choose “Always Allow” or “Ask User” mode for tool execution confirmations
- Advanced tuning — Control temperature, max tokens, top_p, system prompts
💡 What Can You Do With It?
Here are just a few examples of what you can ask your AI agent:
- 📝 “Write a 500-word blog post about healthy eating and publish it as draft”
- 🛒 “Show me today’s WooCommerce orders and their total revenue”
- 🔍 “What are the top 10 most commented posts on my site?”
- 📊 “List all products with stock below 5 units”
- 🎨 “Generate a hero image for my latest blog post about technology”
The AI agent understands context, chains multiple operations, and works with your site’s real data in real time.
🎨 AI Image & Video Generation
Generate stunning images and videos directly from your AI agent or the dedicated Multimedia Settings page:
- Image Generation — “Generate a hero image for my blog post about AI” using OpenAI (GPT Image family + DALL·E 2/3) or Google Gemini (Gemini Image + Imagen 4)
- Image Search — “Find a real stock image for my post” with
wp_search_image(Unsplash, Pexels, Pixabay) including attribution metadata - Video Generation — “Create a 5-second product showcase video” using OpenAI Sora or Google Veo 2/3
🧩 Code Snippet Management — Design and Develop Through Conversation
Create, edit, activate, and manage code snippets on your WordPress site entirely through AI — no manual coding required. Compatible with the three most popular snippet plugins: WPCode, Code Snippets, and Woody Code Snippets.
- Add functionality instantly — “Add a PHP snippet that redirects users after login based on their role”
- Custom CSS on demand — “Create a CSS snippet that hides the sidebar on mobile devices”
- JavaScript injection — “Add a JS snippet that shows a sticky banner with a 10% discount code”
- Full lifecycle management — List, create, edit, activate, deactivate, and delete snippets from conversation
- Safe by design — PHP code is sanitized automatically, removing stray
<?phptags and markdown artifacts from AI-generated output
This opens up powerful possibilities: customize your theme’s appearance, add tracking scripts, inject schema markup for SEO, modify WooCommerce checkout behavior, add custom shortcodes — all through natural language. Ask your AI agent to build it, test it, and activate it, without ever touching a code editor.
🧠 WordPress Abilities Integration (WordPress 6.9+)
Automatically discover and import abilities registered by other plugins into your AI agent’s toolkit. If a plugin supports the WordPress Abilities API, StifLi Flex MCP can detect, import, and expose it as an AI tool — zero configuration needed.
⏰ Automation Tasks — Let AI Work While You Sleep
Schedule AI-powered tasks to run automatically on your WordPress site:
- Scheduled Tasks — Create daily, weekly, or monthly automated workflows
- Templates — Quick-start with pre-built templates (Daily Sales Report, Trending Article, Weekly Summary)
- Smart Scheduling — Flexible presets from “Every hour” to “Monthly” with custom times and timezones
- Detected Tools Mode — AI automatically identifies which tools are needed, saving tokens significantly
- Output Actions — Send results via email, webhook, draft post, or custom hooks
- Execution Logs — Full history with token usage, duration, and detailed results
🎯 Event Automations — Trigger AI on WordPress Events
Run AI workflows automatically when specific events happen
⏪ Roll Back — The Only MCP Server With Undo
Mistakes happen. You asked ChatGPT to update your landing page and the result isn’t what you expected? No problem — roll back the change with one click and your site is restored instantly.
StifLi Flex MCP is the only MCP server for WordPress that tracks every change and lets you undo it. Every modification made by any AI — whether from ChatGPT, Claude Desktop, the built-in Chat Agent, the Copilot, or automated tasks — is recorded with a full before/after snapshot.
- One-click Undo — Roll back any change from the Logs & Roll Back page in your admin panel
- Redo support — Changed your mind? Re-apply a rolled-back change just as easily
- Session rollback — Undo an entire AI conversation’s changes at once, in the correct order
- Full audit trail — See exactly what was changed, when, by whom, and from which source
- Works across everything — Posts, pages, products, orders, options, menus, media, code snippets, and more
- AI-accessible — Your AI agent can also query and rollback changes through dedicated tools
💡 Real-world examples:
- 🛒 “ChatGPT updated all my product prices but used the wrong currency — roll it back!”
- 📝 “Claude rewrote my About page and I prefer the original — undo!”
- ⚙️ “An automation changed my site settings at 3 AM — I can see exactly what happened and revert it”
- 🎨 “The AI-generated image doesn’t match my brand — remove it and restore the previous one”
- 🔗 “I told the AI to delete a menu item by mistake — bring it back!”
🛡️ Security — OAuth 2.1 Built In
StifLi Flex MCP uses OAuth 2.1 with PKCE — the latest industry-standard security protocol — to authenticate external AI clients. No API keys to copy, no passwords to share. Just paste the URL, authorize once, and you’re connected.
- OAuth 2.1 with PKCE (S256) — The most modern and secure authentication standard, used by Google, Microsoft, and GitHub
- Dynamic Client Registration (RFC 7591) — AI clients register automatically, no manual setup needed
- Auto-discovery (RFC 9728 + RFC 8414) — Clients find your server’s auth endpoints automatically
- Token auto-refresh — Sessions stay active for up to 90 days without re-authorization
- Application Passwords fallback — Still supported for advanced setups and legacy clients
- Per-tool capability checks linked to WordPress roles
- Profile-based tool restrictions (8 predefined profiles + custom)
- Tool execution confirmations in AI Chat Agent
📋 Tool Profiles
- WordPress Read Only — safe read-only access
- WordPress Full Management — complete CRUD operations
- WooCommerce Read Only — query store data
- WooCommerce Store Management — products, orders, coupons
- Complete E-commerce — all WooCommerce tools
- Complete Site — all 122+ tools enabled
- Safe Mode — non-sensitive reads only
- Development/Debug — diagnostic tools
🌐 Supported AI Platforms
StifLi Flex MCP integrates with:
Built-in AI Chat Agent + WordPress AI Client connectors:
* OpenAI — GPT-5.4, GPT-5.3, GPT-5.4 Mini
* Anthropic Claude — Opus, Sonnet, Haiku
* Google Gemini — Pro, Flash, Flash-Lite
* OpenRouter and Mistral — via WordPress AI Client connectors (when installed)
MCP Server (External Clients via OAuth 2.1):
* Claude Desktop, ChatGPT, LibreChat, Cursor, Cline, Roo Code, Windsurf, Claude Code
Cloud & Local Providers (via MCP clients):
* Groq, Azure OpenAI, AWS Bedrock
* Ollama, LM Studio, self-hosted solutions
📐 MCP Spec Compliance
StifLi Flex MCP implements the Model Context Protocol (MCP) 2025-11-25 specification for lifecycle and tool operations over JSON-RPC 2.0, while keeping legacy SSE compatibility for older MCP clients.
External Services
This plugin connects to third-party AI services to power the AI Chat Agent, AI Copilot, image generation, and video generation features. No data is transmitted until you explicitly configure an API key and initiate a request.
What data is sent: Your WordPress content (post text, metadata, product details) as included in AI prompts, and MCP tool execution results when using the MCP server with external AI clients.
When data is sent: Only when you have configured an API key for a provider AND actively send a message to the AI agent or Copilot, or when an external MCP client makes an authenticated request to the MCP server endpoint.
Supported services and their policies:
-
OpenAI — Used for GPT models (AI Chat Agent, AI Copilot), GPT Image / DALL·E (image generation), and Sora (video generation)
Terms of Use | Privacy Policy -
Anthropic Claude — Used for Claude AI models (AI Chat Agent, AI Copilot)
Terms of Service | Privacy Policy -
Google Gemini — Used for Gemini AI models (AI Chat Agent, AI Copilot), Gemini Image + Imagen 4 (image generation), and Veo 2/3 (video generation)
Terms of Service | Privacy Policy -
Google Search Console – Used only when you connect your Google account in the SEO settings, for read-only site/search performance data.
Terms of Service | Privacy Policy
When using the MCP server with external AI clients (ChatGPT, Claude Desktop, LibreChat, etc.), API requests are made by the AI client’s backend servers to your WordPress MCP endpoint. The plugin itself does not send data to third parties in this scenario — the external MCP client initiates all communication.
The AI Copilot is a floating assistant that appears inside the WordPress editor (Gutenberg or Classic). It reads the context of what you’re editing and helps you write, rewrite, optimize, generate tags, create excerpts, and even generate images — all without leaving the editor. Every change can be undone with one click.
The Copilot lives inside the post/page editor and is focused on writing and content editing. It works directly with the editor fields (title, content blocks, excerpt, tags, etc.).
The Chat Agent is a standalone admin page where you can manage your entire WordPress site through conversation — create posts, manage WooCommerce orders, check settings, install plugins, and more.
Both use the same AI provider and API key.
- Go to StifLi Flex MCP → AI Chat Agent → Settings
- Choose your AI provider (OpenAI, Claude, Gemini, or installed WordPress AI Client connectors like OpenRouter/Mistral)
- Enter your API key (you get this from your AI provider’s website)
- Go to the Chat tab and start talking!
OpenAI, Claude, and Gemini all work great, and you can also use OpenRouter or Mistral via WordPress AI Client connectors. Here’s a quick comparison:
- OpenAI (GPT-4o / GPT-4.5) — Best overall balance of speed and quality
- Claude (Opus / Sonnet) — Excellent at understanding complex instructions and writing
- Gemini (2.5 Pro / Flash) — Great value, fast responses
You can switch providers at any time from the Settings tab.
The agent has access to 122+ tools covering:
- Content — Create, edit, delete posts, pages, and comments
- Media — Upload, list, and manage images and files
- AI Generation — Generate images (DALL·E, Imagen) and videos (Sora, Veo) with AI
- WooCommerce — Products, orders, coupons, customers, shipping, taxes
- Taxonomies — Categories, tags, custom taxonomies
- Settings — Site options, menus, navigation
- System — Plugins, themes, site health
You control which tools are available through Profiles.
Yes, with multiple layers of protection:
- OAuth 2.1 with PKCE — Industry-standard secure authentication for external AI clients, no shared passwords
- Tool confirmations — In “Ask User” mode, you approve every action before it executes
- Permission checks — Every tool verifies WordPress capabilities before running
- Profiles — Restrict which tools are available (e.g., “Read Only” profiles)
- Token management — Revoke access for any client instantly from the admin panel
Model Context Protocol (MCP) is a standard for connecting AI agents to data sources and tools. This plugin implements an MCP server so external AI clients like ChatGPT or Claude Desktop can discover and use your WordPress tools. This is in addition to the built-in AI Chat Agent.
Yes! The plugin includes 61 WooCommerce tools. They activate automatically when WooCommerce is installed. Ask your AI agent “Show me today’s orders” and it just works.
Yes, through WordPress Abilities. Legacy Custom Tools have been retired for security reasons; use plugins that register WordPress Abilities with explicit schemas and permission callbacks, then import them from the Abilities tab.
No worries — StifLi Flex MCP is the only MCP server with a built-in Roll Back system. Every change made by any AI (ChatGPT, Claude, the Chat Agent, Copilot, or automations) is tracked with a full before/after snapshot. Go to Logs & Roll Back in your admin panel and undo any change with one click. You can even roll back an entire session at once.
Yes! The wp_generate_image tool supports multiple providers:
- OpenAI — gpt-image-1 (default), gpt-image-1.5, gpt-image-2, gpt-image-1-mini, DALL·E 3, DALL·E 2
- Google Gemini — gemini-2.5-flash-image (default), gemini-3.1-flash-image-preview, gemini-3-pro-image-preview, Imagen 4
Just ask your AI agent “Generate an image of…” or configure defaults in StifLi Flex MCP → Multimedia Settings → Images.
Yes! The optional wp_search_image tool can search Unsplash, Pexels, and Pixabay and return one image with rich attribution metadata.
The tool response includes both text JSON and structured output with fields such as:
url,thumbnail_url,caption,alt_textauthor,author_url,source_url- image dimensions, license/metadata fields, and provider-specific fields like Unsplash
download_location
Configure everything in StifLi Flex MCP → Multimedia Settings → Search Image:
- Global enable/disable toggle for
wp_search_image - Per-provider enable + API keys (Unsplash, Pexels, Pixabay)
- Preferred Image Bank (specific provider or random)
- Image Selection mode:
most_relevant,random_top10,random_top20 - Extra parameters: orientation, safe search, Pixabay language, Pexels locale, and timeout
Yes! The wp_generate_video tool supports:
- OpenAI Sora — Text-to-video and image-to-video generation
- Google Veo — Veo 2 and Veo 3 models
Video generation runs asynchronously in the background. Configure providers and API keys in StifLi Flex MCP → Multimedia Settings → Videos.
Go to StifLi Flex MCP → Multimedia Settings. API keys are shared between the Images and Videos tabs — enter your OpenAI or Gemini key once and it works for both.
WordPress 6.9 introduced the Abilities API, letting plugins register standardized capabilities. If you have plugins that support Abilities, StifLi Flex MCP can auto-discover and import them from MCP Server → Abilities tab.
It takes less than a minute:
- Go to StifLi Flex MCP → MCP Server and copy the SSE URL
- Paste it in your AI client:
- Claude Desktop: Customize → Connectors → Add custom connector
- ChatGPT: Settings → Apps & Connectors → Advanced settings → Enable Developer mode → Create app → Paste the URL → Choose OAuth
- Authorize when the browser window opens (you only need to do this once)
The plugin uses OAuth 2.1 — no API keys or passwords needed. Your session stays active for up to 90 days.
This is usually caused by Cloudflare’s “Block AI Bots” setting (enabled by default on new domains) or similar WAF rules from Sucuri, Wordfence, SiteGround, WP Engine, etc.
What happens: The OAuth consent screen works fine (it runs in your browser), but after the token exchange, the AI backend servers (Anthropic, OpenAI) try to reach your MCP endpoint — and the firewall blocks them as bot traffic, returning a 403 before the request ever reaches WordPress.
How to confirm: Check your firewall logs. You’ll see the OAuth/token requests succeed but subsequent MCP requests from Anthropic or OpenAI IPs are blocked.
Option 1 — Disable AI bot blocking:
- Cloudflare: Dashboard → Security → Settings → turn off “Block AI Bots”. Note: this is all-or-nothing — you cannot allow only Anthropic/OpenAI while blocking others.
- Sucuri / Wordfence / other WAFs: Whitelist the AI provider’s IP ranges or user agents (e.g.,
python-httpxfor Anthropic,ChatGPT-Userfor OpenAI).
Option 2 — Use Application Passwords (bypasses the firewall):
If you cannot change your firewall settings, use WordPress Application Passwords instead of OAuth. This connects directly from Claude Desktop on your machine, bypassing the AI provider’s proxy entirely:
- Go to Users → Your Profile in WordPress admin
- Scroll to Application Passwords section
- Enter a name (e.g., “Claude Desktop”) and click Add New Application Password
- Copy the generated password (shown only once)
- In
claude_desktop_config.json, configure the MCP server with your username and the application password as HTTP Basic Auth headers
This method works even behind strict firewalls because all requests come from your own computer.
Categories
Plugin details
Tags on WordPress.org
