The Pro tier of Royal MCP: 90+ tools for solo devs, freelancers, and agencies. Built on top of the Free plugin: Divi 4 + Divi 5 native authoring, Elementor Pro depth, WooCommerce bulk ops, SEO Agency Suite, FormForge Pro operations, Royal Affiliate Pro operations, ACF Setup Suite, cross-plugin composers, custom Endpoint Profiles, universal audit log, and 72-168 hour undo tokens.
Free is safety-first WordPress MCP: reads, single-op writes, diagnostic tools. Pro is the reversible-runtime layer: depth, bulk ops, custom endpoints, composers, and every write logged with a 72-168 hour rollback path. One plugin, three tiers: Personal, Professional, Agency.
Royal MCP Pro works with every MCP-capable client out of the box and with any other AI platform via WordPress’s REST API.
The full walkthrough — every Pro capability end-to-end.
Every Pro tool call is logged, undoable, and scoped by role. Here's what that looks like in your WordPress admin.
Every MCP tool invocation logged with tool name, user, status, and undo state. Filter by tool, user, date range, or search. Export as CSV. Cross-linked into Royal AI Firewall for at-a-glance AI activity.
Every destructive Pro tool call within the 72-168 hour undo window is listed here with an active Undo button. One click reverses the operation — no CLI, no rollback SQL.
Ship a locked-down Content Writer profile for a contractor, a read-only SEO Auditor for a client, or a full WooCommerce Manager for your team — each with its own scoped endpoint URL, all from the same install.
Configure access-token time-to-live per WordPress role. Tighter windows for administrators, looser for contributors. Multi-role users default to the longest applicable TTL, filterable via royal_mcp_pro_oauth_role_ttl_policy.
Free runs your AI's tools against WordPress. Pro governs every destructive call — universal audit, undo function, per-role OAuth TTL, and scoped Custom Endpoint Profiles. Runtime alone isn't enough for production.
The runtime. 155 core tools that read your site and make safe single-op writes, with format-aware handling across Divi, Elementor, and Gutenberg. Free on WordPress.org, forever.
Everything Free does, wrapped in production-grade guardrails. Every write logged. Every destructive call reversible. Every session scoped. Plus deeper Divi, Elementor, WooCommerce, and SEO tools for real workflows at any scale.
One-plugin install, three tiers. Everything in Free plus these workflow layers.
Both builder generations first-class. 9 Free-tier tools cover the read + safe-write surface — page clone, format detection, outline, image swap, template import, library reads, layout validation, find-and-replace. Pro adds 6 more on top: library CRUD (create / update / delete), divi_apply_global_preset for design-token bulk-apply, divi_convert_shortcodes_to_blocks for D4→D5 migration at scale, and native Divi 5 module authoring via divi5_scaffold_block.
Widget CRUD, Theme Builder operations, display conditions, template ops, bulk widget setting replace, plus V4 authoring: global variables and reusable classes as first-class tools, bulk atomic element operations (up to 50 create / update / move / delete per call with all-or-nothing rollback), and JSON-driven section composition. Additive to Elementor's own MCP module — not competitive.
Read the Elementor Pro guide →Bulk product update / delete, bulk stock management, bulk category assign, bulk price update (two-step commit), bulk order status, bulk variation updates, WC Subscriptions bulk price updates, plus first-class grouped-product children CRUD (list, set, add, remove simple-product members). HPOS-compatible. Store management at scale with an undo token on every batch.
Read the WooCommerce guide →Tools that compose across the Royal Plugins family — seo_optimize_for_launch (audit + auto-fix meta + schema verify + 301 redirects + IndexNow + GSC push + cache purge in one call, full LIFO rollback), wp_publish_and_promote_pro (publish + optional SEO automation block), wp_prepare_for_launch, wp_monthly_maintenance_report, wp_migrate_theme_assets. Plus wp_bulk_find_and_replace across post content, meta keys, Elementor JSON, and Gutenberg blocks — two-step commit, per-post pre-op snapshots, 72-168 hour undo.
Build your own AI-facing REST surface — pick which tools each profile exposes, gate by role or scope, filter what shows up in tools/list. Ship a locked-down "content-editor" profile for a client's site alongside your own full-access agency profile from the same install.
Pre-launch audit workflow that sweeps SEO gaps, broken links, missing schema, permalink issues, and redirect coverage in one composer call. Rollup report, rollback path via SiteVault snapshot integration, and IndexNow + Search Console push on the go-live step.
Read the launch readiness guide →Read individual entries and per-form analytics, paginated bulk entry export, bulk delete entries with 72-168 hour undo, form duplication, spin up new forms from templates, and re-fire email notifications for a batch of entries. Preview before every destructive write.
Affiliate performance snapshots, referral records with filter and pagination, fraud incident review, bulk approve affiliates with undo, bulk update referral status with undo, bulk generate payout rows, bulk WooCommerce coupons per affiliate or by tag, plus full observability across campaigns, creatives, payouts, and activity log. Agency-scale affiliate program management from your AI client.
Ed25519-signed NDJSON audit exports with a standalone offline verifier, Legal Hold that survives retention pruning, GDPR field redaction with chain-of-custody event log, and Endpoint Profile templates + per-session version pinning. The compliance layer your auditor is going to ask about the first time an AI writes to a client’s site.
Field group CRUD (create, clone, update, delete), JSON round-trip import and export, field-level operations (add, update definition, delete, reorder), introspection (read full group config, list every supported field type), plus site-setup primitives — options pages, custom post types via ACF Pro’s CPT UI, and ACF Blocks that render via existing template files. Set up ACF end-to-end from your LLM of choice.
SEO Agency Suite, the Reversible Runtime layer (audit logs, undo function & OAuth TTLs), and the Governance layer each have their own sections below.
Portfolio-scale audits, bulk meta writers across every major SEO plugin, and Redirection plugin ops — all with two-step dry-run and full audit trail. Whichever SEO plugin your site (or your client’s site) already uses, your AI writes to it natively.
Two-step dry-run + commit token on every write — preview the diff, then commit if it looks right. Per-post rollback if you change your mind.
The universal fear with AI on WordPress: what if it deletes the wrong thing or wrecks a client’s site? Every destructive Pro tool issues an undo token. Every write goes to the universal audit log. Every session runs under a per-role OAuth time limit. This is the reversibility half of agentic WordPress — the safety net that comes standard.
Every write captured with tool, user, MCP session, target, response status, and undo-token linkage. 90-day default retention. Admin viewer with filters + CSV export. GDPR-aware — deleted_user hook scrubs identifiers.
Every destructive Pro tool issues a 72-168h undo token. One-shot consumption. Cap-checked against the actor who ran the original operation. Dedicated royal_mcp_undo_last_operation tool for reversal.
Batch operations reverse in a single call. Builder-session collision guard soft-errors write tools when someone’s mid-edit in Divi, Elementor, or the block editor (_edit_lock detection).
Time-limit OAuth sessions per role — tokens can’t outlive their scope. Combines with Custom Endpoint Profiles to gate exactly which tools each connection can touch, per role, per site.
The MCP wave is coming to WordPress. WooCommerce is exploring one. Elementor has one behind an experimental flag. Every major plugin author is asking the same question — “should we ship our own MCP server?” — and for most of them the honest answer is yes.
Which puts the burden on you. Every plugin that ships its own MCP is another endpoint to configure in Claude Desktop, another OAuth flow to walk through, another token to rotate, another health surface to babysit. Multiply that across the plugins on a typical WordPress site, times the AI clients your team uses, times the number of client sites you manage — and you’re running a fleet of connectors instead of your actual work.
One connector, one OAuth, one health surface — running your whole plugin fleet. Whether that’s your one site, five client sites, or a hundred. That’s Royal MCP Pro.
Every architectural decision aimed at agencies that ship real client work — not usage caps you have to buy your way out of.
No per-day quotas. No metered rate limits. Every tool call is included at every tier — a real agency automation session doesn't hit an artificial ceiling.
Claude, ChatGPT, and Cursor connect to your WordPress site directly. No third-party relay in the loop. Your AI traffic never routes through our servers — we can't see it, log it, or throttle it.
Every Divi tool works on both format versions — no "primary vs fallback" lane, no Divi 4 as legacy tail. Native block emission for Divi 5, native shortcode authoring for Divi 4, with a per-post format detector that reads _et_builder_version instead of guessing from the theme.
The universal fear with AI on WordPress: "what if it deletes the wrong thing or wrecks a client's site?" Endpoint Profiles let you pre-set exactly which tools an AI connection can touch — read-only for one profile, content edits for another, full agency access for you. Scoped per profile, per role, per site. The safety net comes standard.
Same plugin, three tiers. Whether you run one site or a hundred, the Pro toolset scales to your workflow.
“Own site, own edits, own AI stack.”
“Direct MCP. Read every line. Extend via hooks.”
“Fleet-scale flat rate. Every write reversible.”
90+ Pro-tier tools exposed via MCP JSON-RPC, grouped by integration. Click any category to see the exact tool names your AI client will see.
Every plugin Royal MCP Pro extends. Click any card to see the exact Pro-tier tools that light up when the plugin is installed.
Divi 4 + Divi 5 both first-class. Per-post format detector reads _et_builder_version.
Additive to Elementor's own MCP module — not competitive. Both work side by side. Includes V4 authoring: global variables, reusable classes, bulk atomic element ops (up to 50 per call), and JSON section composition.
Set up ACF end-to-end from your LLM of choice — field groups, JSON round-trip, field-level CRUD, custom post types, options pages, and ACF Blocks. Options pages, blocks, and CPT UI require ACF Pro (6.1+ for CPT).
HPOS-compatible. Bulk delete has two-step confirm above 10 products + active-subscriptions safety guard. Grouped-product children (list, set, add, remove) now first-class CRUD.
5 read/write tools bundled from Free 1.4.44 + yoast_bulk_update_meta from the Pro SEO Agency Suite.
Requires FormForge Pro (separate Royal Plugin). Pro-tier tools light up automatically when installed.
Requires Royal Affiliate Pro (separate Royal Plugin). Pro-tier tools light up automatically when installed. Full observability surface across campaigns, creatives, payouts, and activity log.
Async dispatch pattern so the MCP transport doesn't time out on big backups.
Submission access requires WPForms Pro (Lite installs return an unavailable state).
Also detects iThemes Security and Kadence Security Basic (same underlying class).
Submission access requires the Flamingo companion plugin.
Integration tools auto-load only when the host plugin is active — no overhead if you don't use them.
Reversibility protects the site. Governance protects the story you tell about the site. Every activity row hash-chains to the previous one. Every export carries a cryptographic signature auditors can verify offline. Every retention rule respects Legal Hold overrides and GDPR erasure paths. This is what your compliance officer is going to ask about the first time an AI writes to a client’s WordPress install.
Newline-delimited JSON audit exports with an Ed25519 signature on every row and the manifest. A standalone verifier script ships in bin/ — an auditor validates the whole chain offline without touching the site. Chain integrity via sha256(prev_row_hash + canonical_json(row)).
Flag any row with a reason, timestamp, and who placed it. Held rows survive the retention prune regardless of age — useful the moment an investigation opens. Release requires the royal_mcp_pro_audit_unhold capability, granted separately from manage_options.
Surgical erasure of PII fields (IP, args, response text) inside audit rows. A companion event log records the SHA-256 of what was removed — chain-of-custody evidence without keeping the sensitive value. Redaction target is an allowlist so structural fields stay intact.
Endpoint Profile templates seed reusable per-client configurations with controlled override slots — ship the same governance baseline to every client, allow per-client customization only where you allow it. Version pinning freezes the profile shape per AI session so mid-flight edits don’t affect running conversations.
Walk-throughs for the workflows you'll build once and repeat weekly — Divi authoring, store bulk ops, SEO writes, plus the write history behind every AI edit.
_et_builder_version rather than guessing from the theme, so mixed-format sites work correctly. Divi 4 is not a "legacy fallback" lane — it's a shipping target on equal footing with Divi 5./wp-json/royal-mcp/v1/mcp past your cache and security plugin once, and it keeps working as we add more integrations. Your AI still sees "your WordPress site," not a growing list of URLs to babysit. And if a plugin ships its own MCP and you'd rather use their tools directly, Royal MCP Pro doesn't interfere — you can run both side by side.Founder rates rotate as seats fill. Whichever rate is live when you check out is what you'll pay every year at renewal — auto-applied at cart, no codes to remember. Every future Pro release included.
30-day money-back guarantee · Cancel any time · See all tiers