Title: Picot MCP
Author: tsubu
Published: <strong>2026 年 8 月 31 日</strong>
Last modified: 2026 年 8 月 31 日

---

搜索插件

![](https://ps.w.org/picot-mcp/assets/banner-772x250.png?rev=3679508)

![](https://ps.w.org/picot-mcp/assets/icon-256x256.png?rev=3679508)

# Picot MCP

 作者：[tsubu](https://profiles.wordpress.org/tsubu/)

[下载](https://downloads.wordpress.org/plugin/picot-mcp.0.2.3.zip)

 * [详情](https://cn.wordpress.org/plugins/picot-mcp/#description)
 * [评价](https://cn.wordpress.org/plugins/picot-mcp/#reviews)
 *  [安装](https://cn.wordpress.org/plugins/picot-mcp/#installation)
 * [开发进展](https://cn.wordpress.org/plugins/picot-mcp/#developers)

 [支持](https://wordpress.org/support/plugin/picot-mcp/)

## 描述

Picot MCP turns your WordPress site into an MCP (Model Context Protocol) server 
so AI clients such as Cursor or Claude Code can work with content safely.

Architecture: the official WordPress MCP Adapter is the protocol runtime; Picot 
adds the product layer (API keys, scopes, admin UI, audit log).

 * One MCP URL and API keys to connect (plaintext shown only once at issue)
 * Multiple API keys with per-key scopes, optional expiry, and rate limits
 * Seven feature toggles (posts/pages, taxonomies, media, settings, plugins, themes,
   users)
 * Plugin/theme install and update from wordpress.org slugs only
 * Plugin/theme activation, deactivation, and ZIP package transfer are not available
   via MCP (use WordPress admin)
 * Audit log with user, key id, IP, and failure codes
 * Built on the WordPress Abilities API and official MCP Adapter

## 安装

 1. Upload the `picot-mcp` folder to `/wp-content/plugins/`
 2. Activate the plugin through the Plugins screen
 3. Open Settings  MCP, enable the server, review the site ceiling, issue an API key,
    and copy the key immediately (it cannot be shown again)

## 常见问题

### Does this plugin need Composer on the site?

No. Release packages already include the required MCP Adapter under `vendor/`.

### Who can manage API keys?

Only administrators (`manage_options`).

### What is the default MCP endpoint?

New installs use `/wp-json/picot-mcp/mcp-server` with MCP disabled until you enable
it. Existing sites keep their previously saved route until changed in Settings.

### Can I install custom plugin or theme ZIP packages via MCP?

No. Install and update are limited to packages from wordpress.org. There is no ZIP
install or ZIP export via MCP. Activate or deactivate plugins and themes in WordPress
admin.

### Can I copy an API key again later?

No. Keys are stored as irreversible hashes. Copy the plaintext when it is issued,
or create a new key.

## 评价

此插件暂无评价。

## 贡献者及开发者

「Picot MCP」是开源软件。 以下人员对此插件做出了贡献。

贡献者

 *   [ tsubu ](https://profiles.wordpress.org/tsubu/)

[帮助将「Picot MCP」翻译成简体中文。](https://translate.wordpress.org/projects/wp-plugins/picot-mcp)

### 对开发感兴趣吗?

您可以[浏览代码](https://plugins.trac.wordpress.org/browser/picot-mcp/)，查看[SVN仓库](https://plugins.svn.wordpress.org/picot-mcp/)，
或通过[RSS](https://plugins.trac.wordpress.org/log/picot-mcp/?limit=100&mode=stop_on_copy&format=rss)
订阅[开发日志](https://plugins.trac.wordpress.org/log/picot-mcp/)。

## 更新日志

#### 0.2.3

 * Audit: purge legacy zip_install from stored settings and API keys
 * Audit: block self-deletion of Picot MCP via the plugins ability
 * Audit: limit dependency/admin error notices to plugin-related admin screens

#### 0.2.2

 * Remove Plugin/theme ZIP export and the zip_install operation entirely

#### 0.2.1

 * WordPress.org review: remove arbitrary Base64 ZIP install for plugins/themes
 * WordPress.org review: remove MCP activate/deactivate for plugins and theme switch
 * Install/update remain wordpress.org-only; delete requires the plugin to already
   be inactive in admin
 * Contributors list uses WordPress.org username; translation files omitted from
   directory package

#### 0.2.0

 * Product hardening: safe defaults (MCP off; critical/plugins/themes/users off)
 * API keys are issue-once (hash-only; no reversible secret in the database)
 * Key expiry and per-key rate limiting
 * Stronger audit log (token id, IP, failure code/message; configurable retention)
 * Adapter runtime status, optional observability handler, admin warnings
 * Smoke tests for sanitize helpers and safe defaults (kept outside the plugin package
   for Plugin Check)

#### 0.1.12

 * Add “Copy all” for MCP connection snippet (site name, label, URL, key)

#### 0.1.11

 * Add Logs tab with recent MCP usage (who / feature / action, last 50)

#### 0.1.10

 * Add plugin/theme `export_zip` (ZIP  Base64) for MCP package transfer

#### 0.1.9

 * Add dedicated Plugin/theme ZIP install operation checkbox (site + per-key)

#### 0.1.8

 * Add plugin/theme ZIP install via Base64 (`install_zip`, optional overwrite)

#### 0.1.7

 * Security: enforce per-key critical for sensitive user operations
 * Security: object-level caps on media get/list; safer defaults (MCP off; picot-
   mcp route)
 * Fix: preserve key scopes when site features are temporarily disabled; flash key
   ID case handling
 * Fix: revoke/update save error handling; normalize legacy token permission maps

#### 0.1.6

 * WordPress.org packaging guardrails (distribution zip, i18n, Plugin Check cleanup)
 * Admin UI and security hardening for API key management

#### 0.1.0

 * Initial release

## 额外信息

 *  版本 **0.2.3**
 *  最后更新：**2 周前**
 *  活跃安装数量 **10+**
 *  WordPress 版本 ** 6.9 或更高版本 **
 *  已测试的最高版本为 **7.2**
 *  PHP 版本 ** 7.4 或更高版本 **
 *  语言
 * [English (US)](https://wordpress.org/plugins/picot-mcp/)
 * 标签
 * [abilities](https://cn.wordpress.org/plugins/tags/abilities/)[AI](https://cn.wordpress.org/plugins/tags/ai/)
   [api](https://cn.wordpress.org/plugins/tags/api/)[mcp](https://cn.wordpress.org/plugins/tags/mcp/)
   [rest-api](https://cn.wordpress.org/plugins/tags/rest-api/)
 *  [高级视图](https://cn.wordpress.org/plugins/picot-mcp/advanced/)

## 评级

尚未提交反馈。

[您的评价](https://wordpress.org/support/plugin/picot-mcp/reviews/#new-post)

[查看全部评论](https://wordpress.org/support/plugin/picot-mcp/reviews/)

## 贡献者

 *   [ tsubu ](https://profiles.wordpress.org/tsubu/)

## 支持

有话要说吗？是否需要帮助？

 [查看支持论坛](https://wordpress.org/support/plugin/picot-mcp/)