{"id":301757,"date":"2026-07-07T07:11:11","date_gmt":"2026-07-07T07:11:11","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/sproutos\/"},"modified":"2026-07-26T08:02:37","modified_gmt":"2026-07-26T08:02:37","slug":"sproutos","status":"publish","type":"plugin","link":"https:\/\/ca.wordpress.org\/plugins\/sproutos\/","author":15954481,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.0","stable_tag":"1.2.0","tested":"7.0.2","requires":"6.9","requires_php":"8.0","requires_plugins":null,"header_name":"SproutOS \u2013 MCP Server, AI Agents & AI Website Creator","header_author":"Posimyth","header_description":"AI-powered WordPress workflow tools with admin controls, analytics, notifications, and safer advanced site management.","assets_banners_color":"2e195b","last_updated":"2026-07-26 08:02:37","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/sproutos.ai","header_author_uri":"https:\/\/posimyth.com","rating":0,"author_block_rating":0,"active_installs":20,"downloads":677,"num_ratings":0,"support_threads":3,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.0.10":{"tag":"0.0.10","author":"sandip111","date":"2026-07-08 10:35:36"},"0.0.11":{"tag":"0.0.11","author":"sandip111","date":"2026-07-08 16:12:16"},"0.0.8":{"tag":"0.0.8","author":"posimyththemes","date":"2026-07-07 07:10:39"},"0.0.9":{"tag":"0.0.9","author":"sandip111","date":"2026-07-08 01:49:46"},"1.1.0":{"tag":"1.1.0","author":"sandip111","date":"2026-07-10 11:12:47"},"1.1.1":{"tag":"1.1.1","author":"sandip111","date":"2026-07-13 10:48:06"},"1.1.2":{"tag":"1.1.2","author":"sandip111","date":"2026-07-13 11:17:06"},"1.1.3":{"tag":"1.1.3","author":"sandip111","date":"2026-07-17 12:17:11"},"1.1.5":{"tag":"1.1.5","author":"sandip111","date":"2026-07-22 18:14:17"},"1.2.0":{"tag":"1.2.0","author":"sandip111","date":"2026-07-26 08:02:37"}},"upgrade_notice":{"1.2.0":"<p>Major revamp: the abilities-based engine is replaced by a self-contained, API-based MCP setup. Memory, the sandbox environment, and bundled page-builder integrations are removed.<\/p>","1.1.1":"<p>UI improvements, dark mode for the dashboard, and minor bug fixes and performance improvements.<\/p>","0.0.11":"<p>Code cleanup and optimizations.<\/p>","0.0.10":"<p>Dashboard rebuilt in React (same design), inline application-password management, and an admin-bar indicator toggle.<\/p>","0.0.9":"<p>Dashboard design and layout improvement.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3598577,"resolution":"128x128","location":"assets","locale":"","width":257,"height":257},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3598577,"resolution":"256x256","location":"assets","locale":"","width":129,"height":129}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3605746,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3605746,"resolution":"772x250","location":"assets","locale":"","width":1544,"height":500}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.0.10","0.0.11","0.0.8","0.0.9","1.1.0","1.1.1","1.1.2","1.1.3","1.1.5","1.2.0"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"One workspace for modern WordPress agencies: a WordPress control API plus AI site creation.","2":"MCP Connect: link Claude, ChatGPT, Cursor, or any client over HTTPS with an Application Password.","3":"Activity: every API call logged by session with risk levels and alerts.","4":"Settings: notifications, webhooks, and GDPR privacy controls.","5":"Manage a fleet of sites (coming soon).","6":"Create Mode: build sites the agency way, Scope to Sitemap to Design to Export."}},"plugin_section":[],"plugin_tags":[2353,232494,569,242115,260626],"plugin_category":[],"plugin_contributors":[153210,191589,264640],"plugin_business_model":[],"class_list":["post-301757","plugin","type-plugin","status-publish","hentry","plugin_tags-ai","plugin_tags-ai-agent","plugin_tags-automation","plugin_tags-mcp","plugin_tags-mcp-server","plugin_contributors-posimyththemes","plugin_contributors-sagarpatel124","plugin_contributors-sandip111","plugin_committers-posimyththemes","plugin_committers-sandip111","plugin_support_reps-divyangposimyth","plugin_support_reps-mohitahuja"],"banners":{"banner":"https:\/\/ps.w.org\/sproutos\/assets\/banner-772x250.png?rev=3605746","banner_2x":"https:\/\/ps.w.org\/sproutos\/assets\/banner-1544x500.png?rev=3605746","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/sproutos\/assets\/icon-128x128.png?rev=3598577","icon_2x":"https:\/\/ps.w.org\/sproutos\/assets\/icon-256x256.png?rev=3598577","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>SproutOS is the AI Operating System for modern WordPress agencies, from the team behind plugins running on 500,000+ WordPress sites. It exposes your site to AI assistants and automation tools through a clean, versioned REST control API, with your guardrails in place.<\/p>\n\n<p>Connect an AI client, a no-code tool (n8n, Zapier), or your own SaaS backend using a standard WordPress Application Password, and it can read and manage the site programmatically: safely, and administrator-only.<\/p>\n\n<h4>A Self-Contained WordPress Control API<\/h4>\n\n<p>Most AI writes WordPress code in a vacuum. SproutOS gives AI direct, structured access to your live WordPress stack (content, media, plugins, themes and Elementor layouts) through a purpose-built REST API at \/wp-json\/sprout-os\/v1\/.<\/p>\n\n<p>It is fully self-contained: no MCP Adapter, no WordPress Abilities API, and no bundled third-party libraries. Every endpoint is written from scratch, administrator-gated, and covered by a safety layer. API areas include:<\/p>\n\n<ul>\n<li>Site: info, snapshot, server-readiness, resolved wp-config flags (never secrets), and a live capability manifest<\/li>\n<li>Content: posts, pages and any post type. Create, read, update, delete, plus post-meta<\/li>\n<li>Media: list and upload (URL sideload or base64), with executable-upload blocking<\/li>\n<li>Plugins: list, activate \/ deactivate, upgrade, and install from wordpress.org<\/li>\n<li>Themes: list, read \/ edit theme files, install and upgrade<\/li>\n<li>Inspection: users, database summary, settings, pending updates, theme docs, and a builder probe<\/li>\n<li>Elementor: whole-page read \/ write plus granular element get, edit, clone, move, delete and insert with widget-type validation<\/li>\n<\/ul>\n\n<p>Call GET \/manifest at any time for a live, self-describing list of everything your install exposes.<\/p>\n\n<h4>Two Editions: Choose The Right One<\/h4>\n\n<p>SproutOS comes in two editions built from one identical codebase. They differ in exactly one folder, the developer tools folder, so everything else works the same way in both.<\/p>\n\n<p><strong>SproutOS (this plugin, on WordPress.org).<\/strong> The safe, live-site edition. It exposes only the secure, purpose-built REST control API. Every route is administrator-gated and file access is deliberately limited, so this is the edition to run on production and client sites. This is the version you are reading about now.<\/p>\n\n<p><strong>SproutOS Developer Edition (on GitHub).<\/strong> Everything in this plugin, plus a native Model Context Protocol (MCP) server at \/wp-json\/mcp\/sproutos, so AI clients such as Claude, Claude Code and Cursor connect to your site directly, and an administrator-only PHP execution tool (sprout\/eval). The eval tool runs arbitrary PHP as an administrator: it can read, write and delete any WordPress file or folder, run any database query, and change anything on the site that PHP can reach. That is complete freedom, and complete responsibility for your entire WordPress setup. Run it on local, staging, or developer environments, keep good backups, and choose wisely.<\/p>\n\n<p>Because it ships arbitrary code execution, the Developer Edition is not distributed on WordPress.org. It is the most powerful build and is recommended only when you have backups and a staging workflow in place. Get it from GitHub: https:\/\/github.com\/posimyth\/sproutos<\/p>\n\n<p>The Developer Edition is a drop-in: when it is active, this build stands down automatically so there is never a duplicate registration.<\/p>\n\n<h4>Built For Control And Safety<\/h4>\n\n<p>Giving AI access to a live site should never be a leap of faith. SproutOS ships the guardrails first:<\/p>\n\n<ul>\n<li>Administrator-only access: every route checks manage_options<\/li>\n<li>Authentication with WordPress Application Passwords over HTTPS<\/li>\n<li>Domain lock: calls are rejected if the site URL drifts (anti-clone)<\/li>\n<li>Rate limiter: a per-user \/ IP token bucket<\/li>\n<li>Protected posts: pinned post IDs cannot be modified or deleted through the API<\/li>\n<li>Secret redaction: option and setting responses never leak keys that look like secrets, tokens or passwords<\/li>\n<li>Executable-upload block: media uploads reject .php and similar executable types<\/li>\n<li>Audit logging: every call, and every rejection, is recorded with the action, user, risk level, and timestamp<\/li>\n<li>Privacy and GDPR controls: IP anonymization, configurable data retention, CSV export, and a live summary of exactly what is collected<\/li>\n<\/ul>\n\n<p>Our advice: start on a staging site, and move to production once your guardrails are set. SproutOS is built to be used on live and client sites too.<\/p>\n\n<h4>Set Up In Three Steps<\/h4>\n\n<ol>\n<li>Install and activate SproutOS.<\/li>\n<li>Open SproutOS in the admin, create a WordPress Application Password, and copy the API base URL.<\/li>\n<li>Point your AI client, automation, or SaaS backend at the API and start giving it plain-English instructions.<\/li>\n<\/ol>\n\n<h4>Manage A Fleet Of Sites (Coming Soon)<\/h4>\n\n<p>This plugin connects one site. The SproutOS platform is being built to run your whole agency in one place:<\/p>\n\n<ul>\n<li>Connect many WordPress sites<\/li>\n<li>Agents: audits, maintenance, security, SEO, and client reports, on a schedule or on demand<\/li>\n<li>Connectors: each tool's actions in a clear Read, AI Draft, Approval Gate, Write, Verify flow<\/li>\n<li>Roles and permissions for your whole team<\/li>\n<li>Branded client reports<\/li>\n<\/ul>\n\n<p>Create a SproutOS account at https:\/\/sproutos.ai to get early access as these ship.<\/p>\n\n<h4>Create Sites With AI (Create Mode)<\/h4>\n\n<p>SproutOS also builds new WordPress sites from a prompt, the agency way. In Create Mode at https:\/\/sproutos.ai you turn a client brief into a Scope, a Sitemap, and an on-brand Design, then export production-ready WordPress to Elementor, Gutenberg, or Figma. Use this plugin to import those sites into WordPress.<\/p>\n\n<h4>Who It Is For<\/h4>\n\n<p>WordPress agencies, freelancers, and developers who already use Claude, ChatGPT, or Cursor and want AI to do real work on their sites, safely, without hand-coding every task.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>The control API runs on your own site using a WordPress Application Password over HTTPS. The SproutOS account features (fleet management and Create Mode) connect to the SproutOS service at https:\/\/sproutos.ai; site details and the content you choose to act on are sent there to perform the requested work. Terms: https:\/\/sproutos.ai\/privacy-policy?tab=terms . Privacy: https:\/\/sproutos.ai\/privacy-policy?tab=privacy .<\/p>\n\n<h3>Development<\/h3>\n\n<p>SproutOS is open source (GPLv2 or later) and nothing in it is obfuscated. The complete, human-readable source for the compiled dashboards is maintained publicly at https:\/\/github.com\/posimyth\/sproutos\/tree\/sproutos-source<\/p>\n\n<p>For the full compiled-file-to-source map and build steps, see the <code>Source-Readme.txt<\/code> file in the plugin root.<\/p>\n\n<p>Looking for the native MCP server and the PHP execution tool? Those live in the SproutOS Developer Edition on GitHub: https:\/\/github.com\/posimyth\/sproutos<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install SproutOS from Plugins &gt; Add New, or upload the plugin to \/wp-content\/plugins\/sproutos.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Open SproutOS in your WordPress admin, create a WordPress Application Password, and copy the API base URL.<\/li>\n<li>Point your AI client, no-code tool, or SaaS backend at \/wp-json\/sprout-os\/v1\/ using the Application Password over HTTPS. For direct MCP connections from Claude, Claude Code or Cursor, install the SproutOS Developer Edition from https:\/\/github.com\/posimyth\/sproutos .<\/li>\n<\/ol>\n\n<p>Requirements: WordPress 6.9+ and PHP 8.0+.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20does%20this%20plugin%20do%3F\"><h3>What does this plugin do?<\/h3><\/dt>\n<dd><p>It turns your WordPress site into a controllable REST API for AI assistants and automation tools. An AI client, a no-code tool, or your own backend authenticates with a WordPress Application Password and can then manage content, media, plugins, themes and Elementor layouts programmatically, administrator-only, with a safety layer around every write.<\/p><\/dd>\n<dt id=\"what%20is%20the%20difference%20between%20sproutos%20and%20sproutos%20developer%20edition%3F\"><h3>What is the difference between SproutOS and SproutOS Developer Edition?<\/h3><\/dt>\n<dd><p>One folder. Both editions are built from the same codebase; the Developer Edition adds a developer tools folder containing a native MCP server (\/wp-json\/mcp\/sproutos) and an administrator-only PHP execution tool. This WordPress.org edition keeps file access limited and secure for live sites. The Developer Edition, on GitHub, trades that for the unlimited freedom of raw PHP execution. Choose the one that matches where you are working.<\/p><\/dd>\n<dt id=\"what%20is%20the%20php%20execution%20%28eval%29%20tool%2C%20and%20why%20is%20it%20not%20here%3F\"><h3>What is the PHP execution (eval) tool, and why is it not here?<\/h3><\/dt>\n<dd><p>It is an administrator-only tool, in the Developer Edition only, that runs arbitrary PHP on your site, which means full access to your WordPress files, folders, and database. That power is exactly why it is not on WordPress.org: it belongs on local, staging, or developer environments where you keep backups. This live-site edition intentionally leaves it out.<\/p><\/dd>\n<dt id=\"do%20i%20need%20the%20wordpress%20mcp%20adapter%20or%20the%20abilities%20api%3F\"><h3>Do I need the WordPress MCP Adapter or the Abilities API?<\/h3><\/dt>\n<dd><p>No. SproutOS is completely standalone: no adapter, no Abilities API, and no bundled third-party libraries. Every endpoint is written from scratch.<\/p><\/dd>\n<dt id=\"can%20an%20ai%20client%20such%20as%20claude%20or%20cursor%20connect%20directly%20over%20mcp%3F\"><h3>Can an AI client such as Claude or Cursor connect directly over MCP?<\/h3><\/dt>\n<dd><p>Not with this build, which provides the REST control API. Direct MCP tools, plus an administrator-only PHP execution tool, ship in the SproutOS Developer Edition, a drop-in that takes over automatically when active.<\/p><\/dd>\n<dt id=\"which%20ai%20assistants%20and%20tools%20work%20with%20sproutos%3F\"><h3>Which AI assistants and tools work with SproutOS?<\/h3><\/dt>\n<dd><p>Any client that can send an authenticated HTTP request: Claude, ChatGPT, Cursor, no-code tools such as n8n or Zapier, or your own SaaS backend. Direct MCP clients (Claude, Claude Code, Cursor, VS Code, Windsurf) connect through the Developer Edition.<\/p><\/dd>\n<dt id=\"how%20do%20i%20connect%20it%3F\"><h3>How do I connect it?<\/h3><\/dt>\n<dd><p>Create a WordPress Application Password (Users &gt; Profile, or from the SproutOS admin page) and use it over HTTPS against \/wp-json\/sprout-os\/v1\/. Call GET \/manifest for the live list of everything the install exposes.<\/p><\/dd>\n<dt id=\"is%20it%20safe%20to%20use%20on%20a%20live%20wordpress%20site%3F\"><h3>Is it safe to use on a live WordPress site?<\/h3><\/dt>\n<dd><p>It is built for it. Access is administrator-only, every write is layered with domain lock, rate limiting and a protected-post guard, option responses redact anything that looks like a secret, executable uploads are blocked, and every call is logged with a risk level. We still recommend you start on staging until you trust the flow.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20elementor%3F\"><h3>Does it work with Elementor?<\/h3><\/dt>\n<dd><p>Yes. There are dedicated endpoints for Elementor: whole-page read\/write plus granular element get, edit, clone, move, delete and insert, with widget-type validation. WordPress core content (posts, pages, custom post types, taxonomies, media, menus, options) is covered too.<\/p><\/dd>\n<dt id=\"what%20does%20the%20plugin%20log%2C%20and%20what%20about%20privacy%20and%20gdpr%3F\"><h3>What does the plugin log, and what about privacy and GDPR?<\/h3><\/dt>\n<dd><p>Every API call is logged with the action, the user, a risk level, and a timestamp. Privacy controls include IP anonymization, configurable data retention, CSV export, and a live summary of exactly what is collected.<\/p><\/dd>\n<dt id=\"can%20i%20connect%20multiple%20wordpress%20sites%3F\"><h3>Can I connect multiple WordPress sites?<\/h3><\/dt>\n<dd><p>This plugin connects one site. Managing many sites from one place, with Agents and team roles, is coming to the SproutOS platform; create an account at https:\/\/sproutos.ai for early access.<\/p><\/dd>\n<dt id=\"how%20do%20i%20use%20create%20mode%3F\"><h3>How do I use Create Mode?<\/h3><\/dt>\n<dd><p>Sign in at https:\/\/sproutos.ai, turn a client brief into a Scope, Sitemap, and Design, and export production-ready WordPress to Elementor, Gutenberg, or Figma. Use this plugin to import those sites into WordPress.<\/p><\/dd>\n<dt id=\"do%20i%20need%20to%20know%20how%20to%20code%3F\"><h3>Do I need to know how to code?<\/h3><\/dt>\n<dd><p>No. You work in plain English through your AI client. Coding knowledge helps for advanced tasks, but it is not required.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20uninstall%20the%20plugin%3F\"><h3>What happens if I uninstall the plugin?<\/h3><\/dt>\n<dd><p>The API is removed and your AI client can no longer reach the site. Your WordPress content is untouched.<\/p><\/dd>\n<dt id=\"does%20it%20slow%20down%20my%20site%3F\"><h3>Does it slow down my site?<\/h3><\/dt>\n<dd><p>No. Endpoints run only when your AI client or automation calls them. There is no load on your visitors.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>New : API-based MCP architecture.<\/li>\n<li>Update : Major platform revamp from the abilities-based engine to an API-based MCP setup.<\/li>\n<li>Removed : Memory functionality.<\/li>\n<li>Removed : Sandbox environment.<\/li>\n<li>Removed : Integrations for Elementor, Bricks, ACF, Pods, Divi, Breakdance, Beaver Builder, Oxygen, ASE, and other page builder features.<\/li>\n<li>Improvement : Simplified and cleaned up the core architecture.<\/li>\n<li>Fix : Minor bug fixes and performance improvements.<\/li>\n<\/ul>\n\n<h4>1.1.5<\/h4>\n\n<ul>\n<li>Fix : Minor bug fixes and performance improvements.<\/li>\n<\/ul>\n\n<h4>1.1.3<\/h4>\n\n<ul>\n<li>Fix : Minor bug fixes and performance improvements.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Improvement : UI improvements across the dashboard.<\/li>\n<li>New : Dark mode option for the dashboard.<\/li>\n<li>Fix : Minor bug fixes and performance improvements.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>New : Create Mode Included<\/li>\n<li>Improvement : Code cleanup and optimizations and removed unused code<\/li>\n<\/ul>\n\n<h4>0.0.11<\/h4>\n\n<ul>\n<li>Improvement : Code cleanup and optimizations - removed unused server-rendered code and dead assets.<\/li>\n<\/ul>\n\n<h4>0.0.10<\/h4>\n\n<ul>\n<li>Improvement : Rebuilt the admin dashboard as a React app (same design, no feature changes).<\/li>\n<li>New : Setting to show or hide the \"AI ACTIVE\" indicator in the WordPress admin bar.<\/li>\n<\/ul>\n\n<h4>0.0.9<\/h4>\n\n<ul>\n<li>Improvement : Dashboard design and layout improvement.<\/li>\n<\/ul>\n\n<h4>0.0.8<\/h4>\n\n<ul>\n<li>Update : Removed theme file read and list abilities.<\/li>\n<li>Improvement : Reduced the filesystem surface further.<\/li>\n<\/ul>","raw_excerpt":"WordPress control API for Claude, ChatGPT, Cursor and AI agents. Manage content, media, plugins, themes and Elementor on live sites, admin-only.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ca.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/301757","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ca.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ca.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ca.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=301757"}],"author":[{"embeddable":true,"href":"https:\/\/ca.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/posimyththemes"}],"wp:attachment":[{"href":"https:\/\/ca.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=301757"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ca.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=301757"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ca.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=301757"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ca.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=301757"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ca.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=301757"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ca.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=301757"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}