WordPress has put its MCP Adapter plugin in the WordPress.org plugin directory, giving site owners a sanctioned route for linking AI tools to a WordPress install. Search Engine Journal reported on October 7 that the directory’s first published release is version 0.70. Until now, the plugin was distributed only through a GitHub releases page.

The adoption history is already substantial. According to Search Engine Journal, the plugin has more than 40,000 installations, a figure it attributes to the GitHub distribution. The directory listing puts it on the same path as any other plugin, so it can be installed from the WordPress admin dashboard.

MCP, the Model Context Protocol, is an open standard that Anthropic developed. It allows AI systems to reach websites, plugins, applications, data, and tools, so they can pull information and take actions. On WordPress, that means an AI system can interact with a site, its plugins, and its functions, which Search Engine Journal describes as small pieces of PHP code that handle particular jobs, such as publishing a post.

Automattic’s Jason Adams, its Director of Engineering for AI, announced the release on X. He called it “the canonical MCP plugin for WordPress, carefully architected for backwards-compatibility with MCP versions.” He added that it “makes use of the Abilities API to avoid functional redundancy while handling authorization.”

A commenter noted that compatibility matters because plugins can stay installed for years. Adams agreed. He said WordPress cannot control how the MCP protocol itself handles compatibility, so building a path for it inside the WordPress ecosystem is important.

The coverage leaves several operational questions open. It does not describe which actions an AI system can take by default, how site owners scope those actions, or whether the plugin records what an agent did. It also offers no independent testing of the plugin. Adams’s description of the authorization design is the only account of how permissions work, and it comes from the person promoting the release.

For site and SEO teams, an official plugin changes the question from whether an agent can reach the CMS to who decides what it may do there. Publishing posts is one of the example functions the source names, and a site that exposes such functions to an AI system has handed that system a route into live content. Governance of what an agent may publish or edit should be settled before installation: which roles and abilities the connection can use, whether drafts require human approval before going live, and who reviews the permission setup after plugin updates.

Logging belongs in the same conversation. If an agent edits titles, canonical tags, or internal links, the team needs a record of which account performed the change and when, so a ranking or indexing problem can be traced back to its cause. Teams should confirm what the adapter and their hosting stack actually record before relying on either. Where the answer is nothing, a separate audit trail is worth building.

WordPress security has been in the news recently. Our October 7 report on WordPress 7.1.3’s security fixes covers a different matter, but it is a reminder that every added integration widens the surface a site team must keep patched and reviewed.

Teams planning agent-driven publishing should run the plugin on a staging site first and document the permissions it grants. Settle the approval and logging rules before any production site is connected.

Search Engine Journal, Roger Montti, October 7, 2026.