EMCP Tools 3.19.0
Ten Pro plugin integrations, from Polylang and Tutor LMS to Amelia and MailPoet, each with undo, plus security hardening, management access control and Cloud onboarding.
-
Security: MCP post writes check the post type's own capabilities. Creating a post checks that post type's create and publish capabilities (a WooCommerce product needs the product capabilities, not just
edit_posts), assigning another author checks itsedit_otherscapability, and changing a status to published, scheduled or private checks its publish capability.restore-contentand History undo also need edit rights on the post they write to. -
Security: Sitewide Elementor templates need theme-management rights. Editing or deleting an Elementor header, footer, single, archive, search, 404, popup or loop item template, or any template with display conditions or popup triggers, now needs
edit_theme_options, in Elementor's editor, the REST API and EMCP alike. Editors without that capability can no longer change those templates. EMCP's theme-template and popup tools check the same rule and confirm the target is the right kind of template. -
Security: EMCP Themer templates that run PHP are protected. Once a PHP template is attached, only administrators with
unfiltered_htmlcan edit or delete the Themer template, and only they can attach, swap or remove its PHP template. -
Security: OAuth tokens and the Cloud Gateway credential are changed one at a time per client. Code exchange, refresh rotation and revocation take a per-client lock, so a revoke cannot lose a race with a refresh, and a deleted client can no longer exchange a code. Gateway provisioning, re-issue and revocation are serialized the same way, a failed upload no longer leaves a live credential behind, and a lost response keeps the previous credential so a retry is safe. Databases that do not support MySQL named locks use an options-table lock instead, so sign-in keeps working there.
-
Fixed: Integration write arguments and recovery reports match the installed plugins. FluentCRM contact imports refuse unknown row and address keys before writing. LifterLMS quiz limits require their enabling switches. MailPoet block-editor newsletters accept a separate campaign name, default it to the subject, and restore it on undo. FunnelKit accepts scratch step types and JSON step designs, resolves checkout embed templates, and reports missing builders or incomplete imports. If a hook throws after a step is stored, the failure is recorded without replay; observed new step IDs are marked unverified until their ownership is checked.
-
Changed: Plugins and Themes tabs on the Tools screen are one compact row per integration. Each row shows the integration's Read and Write switches side by side with their operation counts and any requirement ("Needs Polylang"); opening a row shows each tool's description, slug and operations and the integration's note. Integrations that share a group sit under one heading, and the per-group Enable and Disable buttons are gone from these two tabs (Bulk Actions still applies). Other tabs keep the card grid.
-
New: Site-local management access policy. An optional administrator allowlist decides who may open EMCP's screens and use its admin endpoints, with the same checks on every screen, REST route, admin-post and AJAX action, protection against stale updates and self-lockout, and host WP-CLI recovery (
wp emcp management-access recover). While a list is set, EMCP Themer follows it too: templates have their own capabilities, so anyone off the list, administrators and editors alike, loses the Themer menu, list, editors, REST routes and Themer tools; with the default policy editors keep page-level access to Themer as before, and the Themer condition search works for them again. The list can also be set in wp-config.php withdefine( 'EMCP_TOOLS_MANAGEMENT_ADMINS', '1,5' );(or an array of IDs, or'all'to keep every administrator): the constant overrides the saved setting, the screen shows it read-only and flags listed IDs that are not administrators, saves and WP-CLI recovery refuse to change it, and an invalid value keeps management closed until it is fixed. Other MCP execution identities and permissions stay separate, and settings sync never overwrites the local policy. -
New: Managed configuration for Cloud profiles. Read-only inspection of a fixed settings allowlist (no credentials, licences or free-text context), confirmed apply with a durable receipt, and conflict-aware rollback, written atomically with before-images. Needs the matching Cloud and Gateway rollout; deployment is off by default in Cloud.
-
New: Unattended Cloud enrollment. Workspace owners can issue short-lived grants with a fixed site allowance.
wp emcp cloud onboard --phase=enrolland the manifest runner consume grants from the environment, preserve workspace and clone checks, and resume after transient failures. Enabling Gateway requires explicit consent. Requires bulk enrollment enabled in the matching Cloud deployment. -
Fixed: Connection step 3 with an existing application password. The chosen password stays selected while the setup opens, and the screen explains that WordPress keeps only a hash, so the saved password is pasted once and the configs fill in. The paste field is now a plain text field that appears only after a password is chosen, so browsers no longer fill it with the WordPress login password, and the configs fill only from text in WordPress's application password format (a login password filled in earlier ended up in the Basic header). The ChatGPT App form guide is laid out as an aligned table again, the "Copy it now" notice no longer runs into the steps below it, and the password list fills its field.
-
Changed: The Facebook community invitation moved into EMCP's announcement bar. It no longer appears as a banner on the WordPress Dashboard; it rotates with the other announcements on EMCP's own screens. The What's new announcement describes 3.19.0, and Management access sits below Page Builders in the sidebar.
-
Fixed: Meta Box and ACF switches on the Tools screen follow their plugin. Without Meta Box installed its Read and Write switches looked live, because a catalog entry with no availability flag counted as available (the tools themselves never registered). Both integrations now show "Needs Meta Box" or "Needs Advanced Custom Fields" and greyed-out switches until the plugin is active.
-
Fixed: Cloud refresh throttling no longer asks for reconnection. Temporary HTTP 408, 429 and server errors retain the saved connection and defer refresh using Retry-After, with a bounded fallback. Successful refresh clears the cooldown; rejected credentials still require reconnection.
-
New: Operator-run Cloud onboarding.
wp emcp cloud onboardprovides local preflight, workspace-pinned Cloud approval and resumable Gateway setup with a health check. The includedbin/cloud-onboard.mjsprocesses manifests one site at a time and reports partial results. The prepare flow requests browser approval for each site; unattended enrollment requires an owner-issued grant. Licence activation and WordPress Multisite are outside this workflow. Requires the matching Cloud service update. -
New: Cloud protection for cloned sites. Cloud connections record the WordPress home URL and block copied credentials when that URL changes. Connection > Cloud provides an explicit action to give the copy its own identity before reconnecting, preserving the source site's Cloud connection. Older connections without a recorded URL and copies using the same URL require manual separation. A legitimate URL move also requires reconnection.
Builds FunnelKit funnels and email automations over MCP (#143, #144), translates sites with Polylang and TranslatePress, builds TablePress tables, Tutor LMS and LifterLMS courses, The Events Calendar events, Amelia bookings, FluentCRM contacts, campaigns and automations, and MailPoet subscribers, newsletters and automations: new Pro tools drive each plugin through its own controllers, with confirm, dry run and History undo.
- New: FunnelKit Funnel Builder write tool (Pro, #143).
funnelkit-writecreates and changes funnels and steps, checkout products (with discounts) and fields, order bumps, upsells and downsells, opt-in and thank-you pages, A/B tests and the store checkout, and imports FunnelKit templates and funnel exports. Deletes needconfirm: true; creates and updates acceptdry_run: true, which reports the exact request and, for checkout products, the price a buyer pays. Every write is recorded in History and most can be undone there, including deleting a step with its order bumps. The tool ships disabled; enable it under Tools > Plugins > FunnelKit. - New: FunnelKit Automations read and write tools (Pro, #144).
funnelkit-automations-readlists automations and their stats, contacts (as compact rows: id, email, tags, lists), tags, lists, fields, audiences, broadcasts, templates, form feeds, link triggers, carts, email reports and allowlisted settings.funnelkit-automations-writebuilds automations step by step (event, delay, email, tag and other actions), manages contacts, tags, lists and fields, and drafts, schedules and sends broadcasts. Anything that sends or deletes needsconfirm: true; a broadcast's dry run reports how many contacts would receive it. API keys, connectors, licences and plugin installs are never reachable, and settings outside a short allowlist are refused. The write tool ships disabled. - New: History records actions it cannot undo, with the reason. Sending a broadcast, putting contacts into an automation, deleting automations with their contact runs and similar actions are listed in History with why they cannot be rolled back, and the tools say so before you confirm.
- Changed:
funnelkit-readcovers the whole funnel. Besides funnels, pages and checkout data it now reads order bumps, upsells and offers, A/B tests and their stats, funnel analytics, orders and leads, and exports funnels and the store checkout as JSON. - New:
emcp-funnelkitagent skill (Pro). How to build a funnel end to end, set up an automation and send a broadcast safely, and what History can and cannot undo. - New: Polylang read and write tools (Pro).
polylang-readreports languages and settings, translation groups, pages missing a translation and string translations.polylang-writesets up languages, the default language, menus per language and settings, assigns languages (in bulk for existing content), links existing translations and creates term translations. Works with Polylang free; the write tool ships disabled. - New: Translate a page in a few calls.
create-translationcopies a page into another language with its Elementor or block content, meta, template, password and featured image, maps its parent and categories to their translations and links it.get-page-textreturns every translatable string of the copy as one numbered list (Elementor widget text and links, Gutenberg block text, image alt text and captions, the title and the SEO title and description), andapply-page-textwrites the translated list back in one call. Writes are all or nothing: one bad segment and nothing changes, and a failed save puts back what it had written.set-statuspublishes the result. - New: Translations never change the original. Polylang can copy dates, menu order, custom fields and categories between translations. While EMCP writes a translation it holds that copying back for what it writes, so publishing the French page leaves the English one exactly as it was; if anything is copied anyway, the write is reversed and History holds an entry to restore the other page.
- New:
emcp-polylangagent skill (Pro). How to set up languages, translate a page end to end, and what History can and cannot undo. - New: TranslatePress read and write tools (Pro).
translatepress-readreturns every string of a page in the translation language, in page order, with the whole sentence each fragment belongs to (TranslatePress splits a sentence at every link or bold word), plus the theme and plugin strings on it, string search and translation progress.translatepress-writewrites up to 200 translations in one call and adds, updates, removes or sets the default language. Works with TranslatePress free; the write tool ships disabled. - New: TranslatePress translations are safe to write. Translations are saved as machine translated unless marked reviewed, and a reviewed translation is never overwritten without asking. A string that someone else changed since it was read is a conflict. One bad entry writes nothing, and the translations and their History entry are saved in one database transaction, so a translation that cannot be undone is never saved. Reading a page never starts TranslatePress's automatic translation.
- New:
emcp-translatepressagent skill (Pro). How to translate a page's fragments as whole sentences, what the free edition cannot translate, and what History can undo. - New: TablePress read and write tools (Pro).
tablepress-readlists tables and returns a table's cells, options and version, exports it as CSV, HTML or JSON, renders it with formulas worked out, finds the pages that show it and reads the custom CSS.tablepress-writecreates tables, changes them whole or cell by cell, inserts and deletes rows and columns, copies, renames and deletes tables, imports one CSV, HTML, JSON, XLSX or ODS file from pasted data or a URL, sets TablePress's custom CSS and puts a table on an Elementor or Gutenberg page. Works with TablePress free; the write tool ships disabled. - New: TablePress writes are safe to retry and undo. Every change to an existing table names the version it read, so a newer change is never overwritten by accident. A write TablePress leaves half done is put back, a write History cannot record is not kept, and every write can be undone in History, a deleted table coming back under its old id. A user without the unfiltered_html capability cannot save a table holding HTML only administrators may save, because TablePress would strip it from the whole table. Imports never let a file choose or rename a table, and archives are refused.
- New:
emcp-tablepressagent skill (Pro). How to build, edit, import and place a table, formulas and sanitizing, and what History can undo. - New: Tutor LMS read and write tools (Pro).
tutor-readlists courses and returns a course's details, curriculum (topics with their lessons and quizzes, in order) and version, a lesson, a quiz with its questions and answers, a course's students and one student's progress.tutor-writecreates and changes courses, topics, lessons (with video and attachments) and quizzes (true or false, single and multiple choice, open ended and fill in the blank), sets the curriculum order, publishes or trashes courses and enrols or un-enrols students in free courses. It runs Tutor's own course builder code, so Tutor validates and stores every change as its builder does. Works with Tutor LMS free; the write tool ships disabled. - New: Tutor LMS writes are partial, versioned and undoable. An update names only the fields it changes and keeps everything else, including the video, line breaks and the course's other details. Every change to an existing course, lesson or quiz names the version it read, so a newer change is never overwritten by accident, and a write Tutor leaves half done is put back. Every write can be undone in History, a deleted lesson or quiz coming back with its old id. Students' work is never touched: questions students answered cannot be changed or removed, a quiz with attempts cannot be deleted, and courses are only ever moved to the trash.
- New:
emcp-tutoragent skill (Pro). How to build a course end to end, the free question types, versions and conflicts, and what History can undo. - New: LifterLMS read and write tools (Pro).
lifterlms-readlists courses and memberships and returns a course's details, curriculum (sections with their lessons and quizzes, in order), access plans and version, a lesson, a quiz with its questions and choices, a course's or membership's students and one student's progress.lifterlms-writecreates and changes courses, sections, lessons and quizzes (choice, picture choice, true or false and content questions), sets the curriculum order, publishes or trashes courses, gives courses and memberships access plans, creates memberships and enrols or un-enrols students. It runs LifterLMS's own abilities and REST controllers, so LifterLMS validates and stores every change as its API does. Works with LifterLMS 10.1 or later; the write tool ships disabled. - New: LifterLMS writes are partial, versioned and undoable. An update names only the fields it changes and keeps everything else. Every change to an existing course or membership names the version it read, which also covers its access plans' prices, so a newer change is never overwritten by accident, and a write LifterLMS leaves half done is put back. A membership enrolment is one change with the course enrolments it gives or takes, and its undo puts every one of them back, triggers included. Every write can be undone in History. Students' work is never touched: courses, lessons, quizzes and memberships are only ever moved to the trash, a quiz students took stays, and an undo that would take away a student's progress or attempts is refused.
- New:
emcp-lifterlmsagent skill (Pro). How to build a course end to end, the free question types, access plans and memberships, versions and conflicts, and what History can undo. - New: The Events Calendar read and write tools (Pro).
events-calendar-readlists events by date range, status, category, venue, organizer or search, and returns an event with its venue, organizers, categories, tags, event status and version, plus venues, organizers and event categories.events-calendar-writecreates and changes events with their date, time zone (identifiers, UTC and offsets), venue, organizers, categories and tags, publishes them, marks them cancelled or postponed with a reason, moves events, venues and organizers to the trash, and creates and changes venues, organizers and event categories. Works with The Events Calendar 6.x; the write tool ships disabled. - New: The Events Calendar writes keep every field and the calendar right. An update changes only the fields it names (TEC's own REST update loses the cost, the organizers and the featured flag and publishes drafts), new events start as drafts, and every write is read back and checked against TEC's calendar tables, which are repaired through TEC when they lag behind. Every change names the version it read, drafts of other authors stay private to those who may edit them, a venue or organizer events still use is not trashed, and every write can be undone in History, never onto a venue or organizer that is gone or in the trash.
- New: Amelia read and write tools (Pro).
amelia-readreads the booking setup, service categories, services with their employees and prices, employees with their working week and days off, customers, appointments by date, employee, service, customer or status, free time slots, events with their periods and places left, and their attendees.amelia-writecreates and changes categories, services, employees (profile, services, working hours, days off) and customers, books, reschedules, approves, cancels and rejects appointments and single bookings, creates, opens and cancels events and books attendees. Times are site-local and durations in minutes. Works with Amelia 2.4 or later, Lite included; the write tool ships disabled. - New: Amelia writes run through Amelia's own controllers and email nobody unasked. Every write is validated first, names the version it read, goes through the controller Amelia's admin uses, and is read back; partial updates keep every other field even where Amelia replaces the whole object. No customer is emailed unless the call passes
notify: true, and every answer lists what Amelia sent. A throw inside Amelia never leaves a transaction open: a write Amelia saved is kept and reported, a half-saved one is put back, and rows EMCP did not write itself are never touched. Fields Amelia Lite never stores (buffer times, deposits, group capacities, event tags) are refused rather than silently dropped. Every write can be undone in History, never onto a slot, a place or an email someone else has taken since. - New: FluentCRM read and write tools (Pro).
fluentcrm-readreads the setup, contacts with FluentCRM's filters, tags, lists, custom fields, campaigns with their recipient estimate, email templates, email previews, and automations with their contacts.fluentcrm-writecreates, changes and erases contacts, imports and tags up to 200 contacts in one call, manages tags, lists, custom fields and notes, writes templates and campaign drafts, sends tests, schedules, unschedules, pauses and resumes campaigns, publishes automations and moves contacts in them. Works with FluentCRM 3.x and respects its own AI access switch; the write tool ships disabled. - New: FluentCRM writes run no automation and email nobody unasked. Every write goes through FluentCRM's own abilities or REST API, names the version it read, changes only the fields it names (clearing included), and is read back. FluentCRM's automation triggers are held for the call unless it passes
run_automations: true; nothing is emailed withoutconfirm: true, and a schedule must name the recipient count it expects. Writes that would change a linked administrator or a WordPress user's email are refused. Undo never makes a contact who opted out sendable again, never re-arms an automation, and a scheduled campaign is withdrawn only while none of its emails has left the queue. - New: Erasing a FluentCRM contact erases it from History too.
delete-contactcannot be undone, and every earlier History entry loses that contact's data: entries about the contact alone become not undoable, batch and tag entries keep working for the other contacts. A delete in FluentCRM's own admin does the same. The free History gains aredact()seam for this. - New: MailPoet read and write tools (Pro).
mailpoet-readreads the setup, subscribers with their lists, tags and custom fields, the list, tag and custom field registries, newsletters with their content, schedule and statistics, the live recipient count of a send, automations and forms.mailpoet-writeadds, changes, unsubscribes and erases subscribers, imports and tags up to 200 in one call, manages lists, tags and custom fields, writes newsletters in MailPoet's block email editor, sends tests to the user, sends, schedules, unschedules, pauses and resumes newsletters, and switches automations on or off. Works with MailPoet 5.x; every operation checks MailPoet's own capability for its domain; the write tool ships disabled. - New: MailPoet writes start nothing and email nobody unasked. Writes go through MailPoet's own code, name the version they read, change only the fields they name (clearing included) and never rewrite MailPoet's consent record. Automation triggers are held for the call, and the subscriber events MailPoet would fire when the request ends are fired inside it, still held, so a long-running MCP server starts nothing later either;
run_automations: truelets them run and lists the runs. No welcome or confirmation email goes out unless asked, tests go to the user only, and a send must name the recipient count it expects. Unscheduling runs in one locked transaction of its own and is refused once sending has started or within two minutes of it. - New: Erasing a MailPoet subscriber erases them from History too, whether the delete runs through EMCP, MailPoet's own admin or a WordPress privacy erasure request (History is redacted before MailPoet's eraser anonymizes the subscriber). Undo never resubscribes anyone, never puts a subscriber back on a list they left, and never reactivates an automation.
- Fixed: History offered some large FluentCRM, Amelia, LifterLMS and The Events Calendar entries as undoable when their blockers would refuse them. The pre-undo check could not read a before-image stored in the snapshot table; the undo itself was already refused.
- New: The Connection screen and the Dashboard name another plugin's MCP Adapter copy when it is the one loaded. Amelia loads its own older copy of the MCP Adapter before EMCP; EMCP keeps working with it, and now says so.
- New:
emcp-events-calendaragent skill (Pro). How to build an event with its venue and organizers, dates and time zones, cancelling and postponing, versions and conflicts, and what History can undo. - New:
emcp-ameliaagent skill (Pro). How to set up services, employees and working hours, book and manage appointments and events, who gets emailed, what Amelia Lite does not store, and what History can undo. - New:
emcp-fluentcrmagent skill (Pro). How to manage contacts, tags and lists, import in batches, schedule a campaign with its recipient count, keep automations still, handle consent and erasure, and what History can undo. - New:
emcp-mailpoetagent skill (Pro). How to manage subscribers, lists and tags, build and send newsletters with a recipient check, keep automations and welcome emails still, the consent rules, erasure, and what History can undo. - Changed: The
emcp-pluginsskill names the plugins with a skill of their own (FunnelKit, Polylang, TranslatePress, TablePress, Tutor LMS, LifterLMS, The Events Calendar, Amelia, FluentCRM and MailPoet), so an agent loads the right one before its first write or undo. - Changed: History can undo several rows as one. An undo whose rows must change together now restores them, marks the entry and records the undo in one database transaction: if any part fails, nothing changes and the undo can be tried again.
- Fixed: Themer Post Content respects password-protected posts. A Themer single template's Post Content printed the content of a password-protected post without asking for the password. It now shows WordPress's password form until the visitor unlocks the post, as themes do.
Downloads and updating
- Free: download the attached
emcp-tools-3.19.0.zip, or update from your WordPress dashboard. The admin source is in this repository at tagv3.19.0. - Pro: update through Freemius with an active license.
- Write tools for the new integrations ship switched off: turn on the ones you want under EMCP Tools > Tools > Plugins.
- Reconnect your AI clients after updating.
Requires WordPress 6.9+ and PHP 8.1+.