Title: Postnova for MCP
Author: afatyo
Published: <strong>May 21, 2026</strong>
Last modified: August 1, 2026

---

Search plugins

![](https://ps.w.org/postnova-for-mcp/assets/banner-772x250.png?rev=3541784)

![](https://ps.w.org/postnova-for-mcp/assets/icon-256x256.png?rev=3541784)

# Postnova for MCP

 By [afatyo](https://profiles.wordpress.org/afatyo/)

[Download](https://downloads.wordpress.org/plugin/postnova-for-mcp.2.2.1.zip)

 * [Details](https://srd.wordpress.org/plugins/postnova-for-mcp/#description)
 * [Reviews](https://srd.wordpress.org/plugins/postnova-for-mcp/#reviews)
 *  [Installation](https://srd.wordpress.org/plugins/postnova-for-mcp/#installation)
 * [Development](https://srd.wordpress.org/plugins/postnova-for-mcp/#developers)

 [Support](https://wordpress.org/support/plugin/postnova-for-mcp/)

## Description

Postnova for MCP registers 27 blog publishing abilities for use with the WordPress
MCP Adapter plugin. AI agents can create, edit, preview, revise, restore, schedule,
and manage posts directly without needing WP Admin access.

Postnova includes per-ability controls, object-level permission checks, a content-
free activity log, dependency diagnostics, and dry-run previews for safer AI-assisted
editing.

Requires the MCP Adapter plugin (WordPress/mcp-adapter). On WordPress 6.9+, the 
Abilities API is built-in. On 6.8, install the Abilities API plugin separately.

## Installation

 1. Install and activate the MCP Adapter plugin.
 2. Upload postnova-for-mcp.zip via Plugins > Add New > Upload Plugin.
 3. Activate the plugin.
 4. Configure your MCP client to connect to your WordPress REST API endpoint.

## Reviews

![](https://secure.gravatar.com/avatar/877ac99010ca0dda92c01104f3571c7fa3a7ef7c8aba484c714cb7a00dad3d0b?
s=60&d=retro&r=g)

### 󠀁[This plugin helps me write blog posts faster](https://wordpress.org/support/topic/this-plugin-helps-me-write-blog-posts-faster/)󠁿

 [rafiharli](https://profiles.wordpress.org/rafiharli/) May 22, 2026

It’s easy to use, just set up the application passwords and configure the MCP adapter,
and you’re good to go.

 [ Read all 1 review ](https://wordpress.org/support/plugin/postnova-for-mcp/reviews/)

## Contributors & Developers

“Postnova for MCP” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ afatyo ](https://profiles.wordpress.org/afatyo/)

[Translate “Postnova for MCP” into your language.](https://translate.wordpress.org/projects/wp-plugins/postnova-for-mcp)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/postnova-for-mcp/),
check out the [SVN repository](https://plugins.svn.wordpress.org/postnova-for-mcp/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/postnova-for-mcp/)
by [RSS](https://plugins.trac.wordpress.org/log/postnova-for-mcp/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 2.2.1

 * Security: Enforced publish_posts for publishing and scheduling, and delete_post
   for trash transitions.
 * Security: Protected comment emails and moderation actions with moderate_comments
   and object-level edit_comment checks.
 * Security: Fixed attachment IDOR in blog/delete-media and parent-post IDOR in 
   blog/upload-media.
 * Security: Filtered post and media listings through object-level read_post checks.
 * Security: Prevented unauthorized category creation through create-post and update-
   post.
 * Security: Replaced custom URL checks with WordPress safe URL validation and limited
   remote media downloads to the configured upload limit or 20 MB.
 * Privacy: Site administrator email is returned only to users with manage_options.

#### 2.2.0

 * New: blog/list-revisions — list recent revisions for a post.
 * New: blog/get-revision — retrieve the content and metadata of a revision.
 * New: blog/restore-revision — safely restore a post to a previous revision.
 * New: dry-run previews for blog/update-post, including field and taxonomy changes.
 * New: activity log for the latest 100 ability executions without storing post 
   content or raw inputs.
 * New: admin diagnostics for the Abilities API, MCP Adapter, and default MCP endpoint.
 * Improved: dependency notices and graceful handling when the Abilities API is 
   unavailable.
 * Improved: empty tag or category arrays can now intentionally clear the assigned
   taxonomy.

#### 2.1.1

 * Security: Fixed SSRF vulnerability in blog/upload-media — URL now validated to
   block internal/private IP ranges and non-HTTP(S) schemes.
 * Security: Fixed IDOR vulnerability — all post-level operations (update, get, 
   schedule, duplicate, set-featured-image, delete) now enforce object-level capability
   checks via current_user_can(‘edit_post’, $id).

#### 2.1.0

 * New: blog/list-media — browse Media Library with optional search and MIME type
   filter.
 * New: blog/delete-media — permanently delete a media attachment by ID.
 * New: blog/get-site-info — retrieve site name, URL, timezone, language, and WP
   version.
 * New: blog/get-stats — get post/comment/media counts broken down by status.
 * Settings page now shows all 24 abilities.

#### 2.0.0

 * New: Admin settings page (Postnova menu) to enable/disable individual abilities.
 * New: Disabled abilities are not registered to MCP at all, as if they don’t exist.
 * New: Settings stored globally in wp_options under postnova_disabled_abilities.

#### 1.6.2

 * Fix: update-comment no longer errors when status is already the same.
 * Tested up to WordPress 7.0.

#### 1.6.1

 * Fix: schedule-post now correctly retains future status instead of publishing 
   immediately.

#### 1.6.0

 * Initial public release with 20 blog post abilities.

## Meta

 *  Version **2.2.1**
 *  Last updated **5 days ago**
 *  Active installations **10+**
 *  WordPress version ** 6.8 or higher **
 *  Tested up to **7.0.2**
 *  PHP version ** 7.4 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/postnova-for-mcp/)
 * Tags
 * [AI](https://srd.wordpress.org/plugins/tags/ai/)[automation](https://srd.wordpress.org/plugins/tags/automation/)
   [content management](https://srd.wordpress.org/plugins/tags/content-management/)
   [mcp](https://srd.wordpress.org/plugins/tags/mcp/)[publishing](https://srd.wordpress.org/plugins/tags/publishing/)
 *  [Advanced View](https://srd.wordpress.org/plugins/postnova-for-mcp/advanced/)

## Ratings

 5 out of 5 stars.

 *  [  1 5-star review     ](https://wordpress.org/support/plugin/postnova-for-mcp/reviews/?filter=5)
 *  [  0 4-star reviews     ](https://wordpress.org/support/plugin/postnova-for-mcp/reviews/?filter=4)
 *  [  0 3-star reviews     ](https://wordpress.org/support/plugin/postnova-for-mcp/reviews/?filter=3)
 *  [  0 2-star reviews     ](https://wordpress.org/support/plugin/postnova-for-mcp/reviews/?filter=2)
 *  [  0 1-star reviews     ](https://wordpress.org/support/plugin/postnova-for-mcp/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/postnova-for-mcp/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/postnova-for-mcp/reviews/)

## Contributors

 *   [ afatyo ](https://profiles.wordpress.org/afatyo/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/postnova-for-mcp/)