RevUpNow MCP – MCP Server for Claude, ChatGPT, Elementor & AI Agents

Açıklama

Revi turns your WordPress site into a Model Context Protocol server, so an
AI assistant can work in your site directly instead of you copying text back and forth.

Connect Claude Desktop, Claude Code, ChatGPT, Cursor, Windsurf, Cline, Gemini CLI or any other MCP-capable
client. Your AI can then read, create, update and publish content, manage media, edit pages in Elementor and
Gutenberg, handle taxonomies and comments, update SEO metadata, and work with WooCommerce products and orders –
all in natural language, and all inside permissions you set.

Works locally, with optional connected services

Install it, connect your AI client, and you are working. Every local MCP tool works without connecting the
site to RevUp Now.

The optional Account & Sync screen can connect the site to revupnow.ai. Nothing is sent before an
administrator explicitly starts and completes that connection. After connection, aggregate MCP usage and
WooCommerce customer contact sync remain active while the site is connected. Disconnecting the site stops both.

Usage reporting does not limit Lite

When enabled, usage reporting sends one daily aggregate: the number of completed MCP tool calls. Prompts,
arguments, results, WordPress users, URLs and IP addresses are not included. Reporting is analytics only;
it never caps, disables or unlocks Lite functionality.

Safety comes first

An AI that can edit your site is only reasonable if you decide what “edit” means. Every request is checked
several times over:

  • HTTPS is required. A request over plain HTTP is refused before anything else happens.
  • Two authentication methods – a static API key for CLI-style clients, or OAuth 2.1 with PKCE for clients
    that support it. Requests carrying neither are rejected.
  • Five safety modes – from Read Only, through Safe Editor, up to Full Access. The AI can never exceed the
    mode you pick, whatever it is asked to do.
  • Granular permission scopes – turn individual capabilities on or off independently of the safety mode.
  • WordPress capability checks – every tool declares the capability it needs, and it is checked against the
    connecting user on every call. An AI can never do something its user could not do by hand.
  • Administrator approval – require a human to sign off before destructive actions, or before anything is
    published.
  • A full audit log – every tool call, what it changed, and whether it was allowed.

The plugin never writes to WordPress core, to themes, or to plugin files. It works on content.

What your AI can do

  • Posts, pages and custom post types – read, draft, update, schedule and publish
  • Media library – upload, edit metadata, attach to content
  • Elementor and Gutenberg – read and edit real page structure, not just HTML
  • Taxonomies and comments
  • SEO metadata, including Yoast
  • WooCommerce products, orders and coupons
  • Read-only site status

Revi Pro

Revi Pro is a separate, paid plugin for people who want their assistant to reach
further than content:

  • Developer Mode – lets the assistant read and write your own theme and plugin files, and run read-only
    SQL against your database. WordPress core, wp-config.php and .htaccess are refused outright, and the
    plugin files it may touch are restricted to an allowlist you set.
  • Figma to WordPress – converts a Figma frame into a native page across five builders.
  • The AI Design System – builds and maintains a consistent design across a site.
  • Priority support.

None of that code is in this download. Not disabled, not hidden, not waiting behind a key – simply not
included, so there is nothing here to unlock and nothing extra running on your site.

External services

This plugin can connect to RevUp Now, operated by RevUp Now AI at https://revupnow.ai/.

No request is sent to this service until an administrator explicitly chooses to connect the site and
confirms their email. After connection:

  • Usage reporting sends daily aggregate counts of completed MCP tool calls. It does not send prompts, tool
    arguments, results, WordPress users, URLs or IP addresses.
  • WooCommerce customer sync sends customer name, email address, phone number, local customer identifiers and
    account type. It does not send orders, products, postal addresses, payments or subscriptions.

Both services remain active while the site is connected. Disconnecting stops both, and the administrator can
request immediate deletion of that store’s synchronized customer records.

Privacy policy: https://revupnow.ai/privacy-policy/
Terms: https://revupnow.ai/terms-and-conditions/

Yükleme

  1. Install and activate the plugin.
  2. Go to Revi in your WordPress admin. The setup wizard opens automatically.
  3. Choose a safety mode. Start with Read Only if you want to watch what the AI does before letting it
    write anything.
  4. Generate an API key, or connect via OAuth if your client supports it.
  5. Copy the connection details into your AI client’s MCP settings.
  6. Ask your assistant to list your recent posts. If it can, you are connected.

The wizard shows client-specific instructions for Claude Desktop, Claude Code, Cursor and others, so you do
not need to hand-write a config file.

SSS

Does this send my content anywhere?

Local MCP requests go directly to your WordPress site. Optional aggregate usage reporting and WooCommerce
customer contact sync contact revupnow.ai only after an administrator explicitly connects the site. The
Account & Sync screen shows the exact data before connection. Both services remain active until the site is
disconnected.

Do I need an account or an API key from you?

No. Every local MCP feature works without an account or licence. Connecting the site is optional and enables
only the disclosed dashboard usage and customer-sync services.

Is there a limit on how much I can use it?

No. Lite does not cap MCP tool calls. If aggregate usage reporting is enabled, the count is analytics only.

Which AI clients work with it?

Any client that speaks the Model Context Protocol. That includes Claude Desktop, Claude Code, ChatGPT, Cursor,
Windsurf, Cline and Gemini CLI. Clients that support OAuth 2.1 can connect without a manual key.

Can the AI break my site?

It is constrained by the safety mode and scopes you set and cannot exceed them – Read Only genuinely means
read only. Every tool also checks the WordPress capability it needs against the connecting user, so the AI can
never do something that user could not do by hand. You can require administrator approval before destructive
actions or before anything is published, and every action is recorded in the audit log.

The plugin does not write to WordPress core, themes or plugin files at all.

What happens if someone finds my API key?

They would be able to make requests as the user that key belongs to, inside that user’s capabilities and the
safety mode you set – so a key on a Read Only site cannot be used to change anything. Keys can be revoked at
any time from the Connection screen, and every call made with one appears in the audit log. Requests are
refused entirely unless they arrive over HTTPS.

Is Revi affiliated with Anthropic, OpenAI, or any AI vendor?

No. Claude, ChatGPT, Cursor and the others are named only to describe which clients can connect. Revi is an
independent plugin and is not endorsed by or affiliated with any of them.

What is not included here?

Developer Mode, Figma to WordPress, the AI Design System and priority support are part of Revi Pro, a separate
paid plugin. That code is not in this download at all. Everything else – all the content, media, builder, SEO
and WooCommerce tools, every safety mode and the full audit log – is here.

İncelemeler

6 Ekim 2026
This plugin is a game changer you easly can do what ever you want by just connecting your Ai model i am really happy that i can easily manage my store using this Revi MCP plugin, Keep up the good work team.
1 incelemeyi oku

Katkıda Bulunanlar ve Geliştiriciler

“RevUpNow MCP – MCP Server for Claude, ChatGPT, Elementor & AI Agents” açık kaynaklı yazılımdır. Aşağıdaki kişiler bu eklentiye katkıda bulunmuşlardır.

Katkıda bulunanlar

Değişiklik Kaydı

1.2.3

  • Removed incomplete Beaver Builder snapshot tools from the review package.
  • Fixed a health-check warning for the removed support-access scheduler.
  • Removed obsolete administrative mode controls and corrected the Guide and setup wizard to describe content-only access.
  • Migrated old administrative mode settings to content editing and discarded unsupported scopes.
  • Enforced a fixed content-tool manifest and authenticated request context at dispatch.
  • Removed legacy Elementor REST routes and the externally initiated customer resync route; Elementor content tools remain on the authenticated MCP endpoint.
  • Kept dashboard-only credential and permission management separate from remote content access.

1.2.2

  • Remote API-key and OAuth requests have a content-only capability ceiling, including administrator-linked credentials.
  • Removed remote site-settings, menu-management, and customer-user listing tools.
  • Remote requests cannot manage plugins, themes, users, credentials, site settings, or unfiltered HTML.
  • Sanitize nested Elementor content and reject internal configuration post types.
  • Load the connected-services panel CSS from a bundled stylesheet.

1.2.1

  • Diagnostics/usage reporting is no longer enabled by default: the Welcome wizard’s checkbox starts unchecked,
    and a site where the choice was never made is now treated as not opted in. WooCommerce customer sync and
    aggregate usage reporting likewise stay off after connecting a licence until separately and explicitly
    turned on – connecting alone no longer enables either.
  • The Account & Sync panel’s styles are now added with wp_add_inline_style() instead of a raw inline
    tag.
  • Fixed two hardcoded /wp-json/ REST paths (license and store-sync connections on local/dev installs) to use
    rest_url() instead, so they respect a site’s own REST URL prefix.
  • update_site_settings no longer accepts permalink_structure. Changing the permalink structure rewrites every
    URL on the site, which is a critical/administrative setting rather than the non-sensitive settings (site
    title, tagline, timezone, date/time format) this tool is scoped to; it is no longer reachable remotely.

1.1.0

  • Plugin name adjusted to meet WordPress.org’s restricted-term rules.
  • Added an optional site connection for aggregate MCP usage reporting and WooCommerce customer contact sync.
  • Added explicit disclosure, automatically active post-connection services, manual backfill, disconnect and
    remote customer-data deletion controls.
  • Lite MCP functionality no longer has a request cap and remains available without connecting.

1.0.9

  • Renamed. The plugin is now RevUpNow MCP, published under the
    revupnow-mcp slug.
  • Removed the last unreachable licence surfaces left over from earlier
    builds, so nothing in the package refers to keys, plans or upgrades.
  • The plugin file’s direct-access guard now runs before any other code.
  • Admin JavaScript is enqueued rather than printed inline.

1.0.8

  • Database queries now carry a complete, correctly placed annotation
    explaining that table names come from $wpdb->prefix and never from user
    input, with every value passed as a placeholder.

1.0.7

  • Addressed every issue reported by the official Plugin Check tool.
  • Security: all output escaped, POST arrays sanitised element by element,
    and database queries annotated so the table-name interpolation is
    reviewable.
  • Uses wp_is_writable() rather than is_writable(), which also reports
    correctly on Windows hosts.
  • Removed a dead auto-update toggle left over from the licence screen.
  • Fixed mixed line endings and a Domain Path header pointing at a folder
    that was not shipped.

1.0.6

  • The plugin no longer has any licence, account or connection to an external
    service. It makes no outbound requests at all.
  • Removed licence activation, the Licence screen, usage reporting, WooCommerce
    customer sync and the diagnostics opt-in.
  • Fixed: the 100-requests-a-day allowance is now actually enforced. A build
    fault meant the counter was read but never incremented, so the limit never
    applied. It is now a self-contained local check with no external dependency.
  • Documentation rewritten to match what the plugin does.

1.0.5

  • Removed the Plugin URI header, which duplicated the Author URI.

1.0.4

  • Corrected readme claims that did not match the shipped build.
  • Tested up to WordPress 7.1.

1.0.3

  • The setup wizard shows connection settings without requiring anything first.

1.0.2

  • Fixed a setup wizard step that could not be completed.

1.0.1

  • Fixed: the plugin no longer requires a licence to run.

1.0.0

  • First release.