{"id":358639,"date":"2026-09-16T20:01:48","date_gmt":"2026-09-16T20:01:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/flavors-engine\/"},"modified":"2026-09-26T14:45:48","modified_gmt":"2026-09-26T14:45:48","slug":"flavors-engine","status":"publish","type":"plugin","link":"https:\/\/kab.wordpress.org\/plugins\/flavors-engine\/","author":23554846,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.1","stable_tag":"1.0.1","tested":"7.1.2","requires":"6.9","requires_php":"8.0","requires_plugins":null,"header_name":"Flavors Engine","header_author":"FlavorsWP","header_description":"A WordPress MCP server for AI agents, plus 150+ Elementor widgets and a theme builder. Elementor is optional.","assets_banners_color":"60676f","last_updated":"2026-09-26 14:45:48","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/flavorswp.com","header_author_uri":"https:\/\/flavorswp.com\/about","rating":0,"author_block_rating":0,"active_installs":0,"downloads":297,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"flavorswp","date":"2026-09-16 20:01:40","revision":3699196},"1.0.1":{"tag":"1.0.1","author":"flavorswp","date":"2026-09-26 14:45:48","revision":3714344}},"upgrade_notice":{"1.0.1":"<p>Fixes Post Masonry, sliders and several security issues. Existing theme templates keep working; new single, archive, search and 404 templates need a display condition.<\/p>","1.0.0":"<p>First release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3699192,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3699192,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3699192,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3699192,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3699192,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3699192,"resolution":"1","location":"assets","locale":"","width":1280,"height":800},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3699192,"resolution":"2","location":"assets","locale":"","width":1280,"height":800},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3699192,"resolution":"3","location":"assets","locale":"","width":1280,"height":800},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3699192,"resolution":"4","location":"assets","locale":"","width":1280,"height":800}},"screenshots":{"1":"The MCP server dashboard - safety profile, connected clients, skills and the change ledger at a glance.","2":"The widget catalogue - all 151 widgets, modules and extensions with per-item switches; anything off is never registered.","3":"The Theme Builder - headers, footers and templates built in Elementor, with the display rules that decide where each applies.","4":"The Abilities screen - every typed operation exposed to AI agents, grouped by provider, each individually switchable under the active safety profile."}},"plugin_section":[],"plugin_tags":[143165,145606,242115,260626,139733],"plugin_category":[],"plugin_contributors":[281137],"plugin_business_model":[],"class_list":["post-358639","plugin","type-plugin","status-publish","hentry","plugin_tags-elementor-addons","plugin_tags-elementor-widgets","plugin_tags-mcp","plugin_tags-mcp-server","plugin_tags-theme-builder","plugin_contributors-flavorswp","plugin_committers-flavorswp"],"banners":{"banner":"https:\/\/ps.w.org\/flavors-engine\/assets\/banner-772x250.png?rev=3699192","banner_2x":"https:\/\/ps.w.org\/flavors-engine\/assets\/banner-1544x500.png?rev=3699192","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/flavors-engine\/assets\/icon.svg?rev=3699192","icon":"https:\/\/ps.w.org\/flavors-engine\/assets\/icon.svg?rev=3699192","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/flavors-engine\/assets\/screenshot-1.png?rev=3699192","caption":"The MCP server dashboard - safety profile, connected clients, skills and the change ledger at a glance."},{"src":"https:\/\/ps.w.org\/flavors-engine\/assets\/screenshot-2.png?rev=3699192","caption":"The widget catalogue - all 151 widgets, modules and extensions with per-item switches; anything off is never registered."},{"src":"https:\/\/ps.w.org\/flavors-engine\/assets\/screenshot-3.png?rev=3699192","caption":"The Theme Builder - headers, footers and templates built in Elementor, with the display rules that decide where each applies."},{"src":"https:\/\/ps.w.org\/flavors-engine\/assets\/screenshot-4.png?rev=3699192","caption":"The Abilities screen - every typed operation exposed to AI agents, grouped by provider, each individually switchable under the active safety profile."}],"raw_content":"<!--section=description-->\n<p>Flavors Engine is two tools in one plugin, and each half works on its own:<\/p>\n\n<ol>\n<li><strong>A WordPress MCP server<\/strong> that lets the AI client you already use (Claude, ChatGPT, Cursor, Codex, Copilot and others) build and manage your site directly, under rules you set.<\/li>\n<li><strong>An Elementor addon<\/strong> with 151 widgets and a complete theme builder, free, with nothing locked.<\/li>\n<\/ol>\n\n<p>The MCP server runs on any site: Elementor, Bricks, Divi, a block theme or headless. If Elementor is not installed, the widget half simply stays off.<\/p>\n\n<p>No AI model is bundled and none runs on your server. Your MCP client brings its own model access, and every decision about what it may do is enforced here, on your install. There are no credits, no usage limits and no relay service in between.<\/p>\n\n<h4>MCP server for Claude, ChatGPT, Cursor and any AI agent<\/h4>\n\n<p>Connect an AI agent and it works through typed abilities instead of guessing: 97 on a fresh install and 130 once Elementor is active, built on the WordPress Abilities API and the official MCP Adapter. One prompt from you becomes many small, checked calls from the agent.<\/p>\n\n<ul>\n<li><strong>Content<\/strong> - list, search, read, create, update, trash, restore and delete posts, pages and public custom post types. New content is created as a draft unless you ask otherwise.<\/li>\n<li><strong>Elementor pages<\/strong> - read and write a page's Elementor document, and add, edit or delete a single element.<\/li>\n<li><strong>Theme builder<\/strong> - create headers, footers and templates and set where they apply.<\/li>\n<li><strong>Taxonomies, media, comments and menus<\/strong> - terms, image import and alt text, moderation, menu structure and locations.<\/li>\n<li><strong>Revisions, users and site settings<\/strong> - revision restore, privacy-minimised user reads, an explicit settings allowlist.<\/li>\n<li><strong>Plugins and themes<\/strong> - search the WordPress.org directory, activate, deactivate, update and switch, each behind an explicit confirmation.<\/li>\n<li><strong>Block editor<\/strong> - Gutenberg content through staged changes that the editor itself validates.<\/li>\n<li><strong>Design tokens, skills and prompts<\/strong> - a design library, reusable skills that also appear as MCP prompts, and a prompt library.<\/li>\n<\/ul>\n\n<h4>Why it is not a typical MCP plugin<\/h4>\n\n<p>Most MCP plugins open your site to an agent and stop there. Flavors Engine is built for handing an agent real work on a live site:<\/p>\n\n<ul>\n<li><strong>Safety profiles.<\/strong> Read Only blocks every change. Production Safe, the default, allows normal content and design work and blocks raw PHP, WP-CLI, filesystem and database access. Developer Full Access enables those surfaces, and critical calls still need explicit confirmation.<\/li>\n<li><strong>Undo.<\/strong> Supported changes are recorded in a change ledger that you can roll back.<\/li>\n<li><strong>Your permissions still apply.<\/strong> Every call is checked against the connected user's WordPress capabilities, abilities can be switched off one by one, and writes are rate limited per connection.<\/li>\n<li><strong>Real OAuth.<\/strong> OAuth 2.1 with PKCE, a read-only grant for clients that only need to look, and every connection listed under Connected Apps so you can revoke it. Application Passwords remain available for clients that cannot open a browser.<\/li>\n<li><strong>Elementor aware.<\/strong> The agent builds with the same widgets and theme builder you use, not raw HTML.<\/li>\n<\/ul>\n\n<h4>151 free Elementor addons and widgets<\/h4>\n\n<p>Headings, buttons, info boxes, icon lists, tabs, accordions, FAQs and toggles. Galleries, sliders, carousels, image comparison, hotspots and Lottie. Testimonials, team members, pricing tables and switchers, counters and progress bars. Post grids, lists, carousels, timelines and news tickers. Navigation menus, breadcrumbs, table of contents and scroll navigation. Creative effects such as image trail, scramble text, aurora background, bento grid, marquee, tilt cards and custom cursors. Styling for Contact Form 7, Mailchimp, login and search forms, plus a cookie consent banner.<\/p>\n\n<p>Every widget can be switched off, and a widget that is off is never loaded.<\/p>\n\n<h4>Free Elementor theme builder<\/h4>\n\n<p>A full header and footer builder and template builder in the free plugin: header, footer, single, archive, search results, 404, popup, loop item, template part and login templates, each with display conditions that decide where it applies. Fifty theme-builder widgets cover site logo and title, menus, post title, content, meta and comments, archive posts and pagination, search, author box, related posts, reading time, dark mode toggle and more. You can preview a template with a real post or archive while you edit it.<\/p>\n\n<p>None of the template types is reserved for a paid version.<\/p>\n\n<h4>Flavors Engine Pro<\/h4>\n\n<p>Pro is a separate plugin from <a href=\"https:\/\/flavorswp.com\/\">flavorswp.com<\/a>. It does not unlock anything in this download: everything described above is already running, with no limits.<\/p>\n\n<ul>\n<li><strong>AI whole-site builder<\/strong> - the agent plans and builds a complete site (pages, header, footer, templates, menus and design system) as a resumable task list you can review.<\/li>\n<li><strong>More than 1,000 plugin-aware abilities<\/strong> - WooCommerce, Bricks, Divi, Oxygen, Breakdance, Beaver Builder, Gravity Forms, WPForms, Fluent Forms, Yoast, Rank Math, ACF, JetEngine, WPML, Polylang and more.<\/li>\n<li><strong>Agent memory and an approval queue<\/strong> - the agent remembers your conventions, and changes can wait for your approval.<\/li>\n<li><strong>Extra widget packs<\/strong> - WooCommerce widgets and WooCommerce theme builder, GSAP animation widgets, loop builder, mega menu, popups, charts, store locator and events calendar.<\/li>\n<li><strong>Forms Suite<\/strong> - form builder, submissions, conditional logic, SMTP and payments.<\/li>\n<\/ul>\n\n<p>Claude, ChatGPT, Cursor and Elementor are trademarks of their respective owners. Flavors Engine is not affiliated with or endorsed by them.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>This plugin contacts no external service on its own. Every service below is reached only when you act: by pressing a button, by connecting an AI client, or by adding a widget and entering your own API key for it. A default install, with nothing configured, makes no outbound request at all.<\/p>\n\n<p><strong>Google Fonts<\/strong> - On the Design screen, when a saved design names a font your browser does not have installed, the preview shows a note explaining that it is not displaying the design's real fonts, alongside a <strong>Preview with Google Fonts<\/strong> button. Pressing that button loads a stylesheet from <code>https:\/\/fonts.googleapis.com<\/code> so the preview can render the font. Nothing is requested until you press it, nothing is requested on your site's front end, and no data about your site or your visitors is sent - the request contains the font name and, as with any browser request, your IP address and user agent. Google's terms: https:\/\/policies.google.com\/terms - Google's privacy policy: https:\/\/policies.google.com\/privacy<\/p>\n\n<p><strong>The WordPress.org plugin directory<\/strong> - The <code>search-extensions<\/code> and <code>get-extension<\/code> abilities query <code>https:\/\/api.wordpress.org<\/code> for plugin and theme information, exactly as your WordPress dashboard does. These run only when an AI client you have connected calls them. WordPress.org's privacy policy: https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<p><strong>Openverse<\/strong> - The <code>search-images<\/code> ability queries <code>https:\/\/api.openverse.org<\/code> for openly licensed photographs, the same catalogue the block editor's own openly-licensed media search uses. It runs only when an AI client you have connected calls it, the request contains only your search terms and filters, and no account or API key is involved. The ability returns links; it does not download anything. A file is only fetched and added to your Media Library if you then ask for <code>import-media-url<\/code>, which downloads from whichever URL is passed to it. Openverse is a WordPress.org project. Openverse terms of service: https:\/\/docs.openverse.org\/terms_of_service.html - Openverse privacy policy: https:\/\/openverse.org\/privacy<\/p>\n\n<p>The remaining services are reached only by widgets you place on a page, and only after you enter your own API key or access token for them. None of them is contacted on a default install, because without your credential the request is never made.<\/p>\n\n<p><strong>Mailchimp<\/strong> - The Mailchimp Form widget sends a subscription to <code>https:\/\/&lt;dc&gt;.api.mailchimp.com<\/code> when a visitor submits the form, where <code>&lt;dc&gt;<\/code> is the data-centre suffix of your own API key. This one sends visitor data: the email address the visitor typed, and any merge fields your form collects, together with your API key. It runs only on a form you added and configured with your key. Mailchimp's terms: https:\/\/mailchimp.com\/legal\/terms\/ - Mailchimp's privacy policy: https:\/\/mailchimp.com\/legal\/privacy\/<\/p>\n\n<p><strong>YouTube Data API<\/strong> - The YouTube TV widget and the YouTube mode of the Social Feed widget request channel and video listings from <code>https:\/\/www.googleapis.com\/youtube\/v3\/<\/code>, using a Google API key you supply. The request contains your key and the channel or playlist you configured. Responses are cached, and no visitor data is sent. Google's terms: https:\/\/policies.google.com\/terms - Google's privacy policy: https:\/\/policies.google.com\/privacy - YouTube API Services terms: https:\/\/developers.google.com\/youtube\/terms\/api-services-terms-of-service<\/p>\n\n<p><strong>The YouTube player (loaded in the visitor's browser)<\/strong> - A page containing the YouTube TV widget loads YouTube's iframe player API from <code>https:\/\/www.youtube.com\/iframe_api<\/code> and embeds the player itself from youtube.com. This is the only script this plugin loads from another domain, and it has to be: YouTube's terms require the player API to be served from their domain rather than bundled. It happens in the visitor's browser, on pages where you placed the widget, and it gives YouTube the visitor's IP address and user agent as any embed does - nothing is sent from your server. Google's terms: https:\/\/policies.google.com\/terms - privacy policy: https:\/\/policies.google.com\/privacy - YouTube API Services terms: https:\/\/developers.google.com\/youtube\/terms\/api-services-terms-of-service<\/p>\n\n<p><strong>Instagram<\/strong> - The Instagram mode of the Social Feed widget uses the Instagram API with Instagram Login (Business or Creator accounts). It requests your own recent media from <code>https:\/\/graph.instagram.com<\/code>, using an Instagram access token you supply, and about once a week refreshes that token through <code>https:\/\/graph.instagram.com\/refresh_access_token<\/code> so it does not expire. The requests contain your token and a post count. Responses are cached, and no visitor data is sent. Meta Platform Terms: https:\/\/developers.facebook.com\/terms - Meta Privacy Policy: https:\/\/privacycenter.instagram.com\/policy<\/p>\n\n<p><strong>OpenWeatherMap<\/strong> - The plugin registers a weather proxy endpoint that requests current conditions from <code>https:\/\/api.openweathermap.org<\/code> for a location you configure, using an OpenWeatherMap API key you supply. The widget that uses it is part of Flavors Engine Pro, so on this plugin alone the endpoint exists but nothing calls it; it is listed here because the code ships. Responses are cached and no visitor data is sent. OpenWeatherMap's terms: https:\/\/openweathermap.org\/terms - privacy policy: https:\/\/openweather.co.uk\/privacy-policy<\/p>\n\n<p><strong>The AI client's own domain, during sign-in (OAuth Client ID Metadata)<\/strong> - When an AI client connects and identifies itself with an https URL as its client id, the plugin fetches that URL once to read the client's metadata document (its name, its redirect addresses), caches the result, and uses it to decide whether the sign-in may proceed. The host contacted is therefore the client's, not ours, and which host that is depends on which client you connect. The request is a plain GET with no body and no data about your site beyond the fact that it was made; redirects are validated one hop at a time and private or loopback addresses are refused. Nothing is fetched until you connect a client that uses this form of identifier. For Claude, that host is claude.ai or claude.com - Anthropic's terms: https:\/\/www.anthropic.com\/legal\/consumer-terms - privacy policy: https:\/\/www.anthropic.com\/legal\/privacy<\/p>\n\n<p><strong>Your own site (self-diagnostics, not an external service)<\/strong> - The Troubleshoot screen checks that the MCP endpoint, the OAuth discovery documents and the REST API are reachable by requesting them from your own site's address, and it sends a handful of AI-client user agents at one of those addresses to detect a hosting bot filter that would block real clients. Every one of these requests goes to your own domain. They are listed here because they are outbound HTTP requests and a reader auditing the code will see them; no third party is involved and no data leaves your server.<\/p>\n\n<p><strong>AI model providers<\/strong> - This plugin bundles no AI model and contacts no model provider. Your MCP client connects directly to your site and brings its own model access; the plugin never sees a provider API key. The MCP endpoint is self-hosted and there is no relay.<\/p>\n\n<p><strong>AI client sign-in addresses (no request is made)<\/strong> - The Connect screen shows the sign-in address of the AI client you choose, and the OAuth flow lists that client's callback address as an allowed redirect target. For Claude those addresses are on the claude.ai and claude.com domains; other clients have their own. These are destinations your own browser is sent to when you press \"connect\", and addresses the plugin checks a returning request against. The plugin itself never opens a connection to any of them, and no data is sent to them by the plugin. They are listed here only because the addresses appear in the code and a reader should know why. Anthropic's terms: https:\/\/www.anthropic.com\/legal\/consumer-terms - privacy policy: https:\/\/www.anthropic.com\/legal\/privacy<\/p>\n\n<h3>Source Code<\/h3>\n\n<p>Everything in this plugin is readable source except the third-party libraries listed below, and this section is where to find the source for each compressed file.<\/p>\n\n<p><strong>This plugin's own code.<\/strong> All PHP is source. Under <code>assets\/<\/code>, every minified file ships beside the unminified file it was built from (<code>x.min.js<\/code> next to <code>x.js<\/code>), and <code>SCRIPT_DEBUG<\/code> makes WordPress load the readable one. Nine scripts have no separate minified twin because none was ever built: they were inherited as single-line files with no build step, so they ship reformatted in place, and each carries a header saying exactly that. Note that <code>assets\/js\/library\/<\/code> is not exclusively third-party: <code>aos<\/code>, <code>gradient-bg<\/code>, <code>shape-divider<\/code>, <code>tabs<\/code> and <code>list-actions<\/code> are this plugin's own code and each ships with its readable source beside the minified file.<\/p>\n\n<p><strong>The chat interface.<\/strong> <code>includes\/assets\/chat\/index.js<\/code> is compiled from <code>src\/chat\/index.tsx<\/code>, which ships inside this plugin. Build it with the <code>@wordpress\/scripts<\/code> toolchain that <code>package.json<\/code> declares:<\/p>\n\n<pre><code>npm install &amp;&amp; npm run build:chat\n<\/code><\/pre>\n\n<p><strong>Third-party libraries.<\/strong> Each is shipped in the minified form its own project distributes. The readable source for every one is published by that project at the address below, which is also where any modification should be taken from.<\/p>\n\n<ul>\n<li><strong>Slick Carousel<\/strong> - MIT - https:\/\/github.com\/kenwheeler\/slick (carousel and slider widgets)<\/li>\n<li><strong>Prism<\/strong> - MIT - https:\/\/github.com\/PrismJS\/prism (code-highlight widget)<\/li>\n<li><strong>Salvattore<\/strong> - MIT - https:\/\/github.com\/rnmp\/salvattore (column layout for the Post Masonry widget). Shipped as a readable adaptation in <code>assets\/js\/library\/flavor-columns.js<\/code>, credited in its header.<\/li>\n<li><code>assets\/js\/library\/table.min.js<\/code> is five libraries concatenated and minified, all MIT, listed in the file's own header and here:\n\n<ul>\n<li><strong>DataTables<\/strong> - https:\/\/github.com\/DataTables\/DataTables<\/li>\n<li><strong>DataTables Buttons<\/strong> - https:\/\/github.com\/DataTables\/Buttons<\/li>\n<li><strong>JSZip<\/strong> - https:\/\/github.com\/Stuk\/jszip<\/li>\n<li><strong>pdfmake<\/strong> - https:\/\/github.com\/bpampuch\/pdfmake<\/li>\n<li><strong>jquery-csv<\/strong> - https:\/\/github.com\/typeiii\/jquery-csv<\/li>\n<\/ul><\/li>\n<li>The Lottie animation widget ships three MIT libraries:\n\n<ul>\n<li><strong>lottie-web<\/strong> - https:\/\/github.com\/airbnb\/lottie-web<\/li>\n<li><strong>lottie-interactivity<\/strong> - https:\/\/github.com\/LottieFiles\/lottie-interactivity<\/li>\n<li><strong>lottie-player<\/strong> - https:\/\/github.com\/LottieFiles\/lottie-player<\/li>\n<\/ul><\/li>\n<li><strong>Jarallax<\/strong> - MIT - https:\/\/github.com\/nk-o\/jarallax (the parallax background extension; <code>assets\/js\/library\/parallax-bg.min.js<\/code>)<\/li>\n<li><strong>Animate.css<\/strong> 4.1.1 - MIT - https:\/\/github.com\/animate-css\/animate.css (entrance animations)<\/li>\n<li><strong>AOS<\/strong> (Animate On Scroll) - MIT - https:\/\/github.com\/michalsnik\/aos (scroll-triggered animations; the bundled file is a reduced reimplementation, readable as shipped)<\/li>\n<\/ul>\n\n<p>Masonry and imagesLoaded are not bundled: the plugin uses the copies WordPress core itself ships and registers. GreenSock (GSAP) is not bundled either - its licence is not GPL-compatible, so the widgets that need it are not part of this plugin.<\/p>\n\n<p>Server-side PHP dependencies are managed with Composer and declared in <code>composer.json<\/code>; each carries its own LICENSE file inside <code>vendor\/<\/code>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate Flavors Engine.<\/li>\n<li>For the MCP server: open <strong>Flavors Engine \u2192 Connect<\/strong>, leave <strong>Production Safe<\/strong> selected, choose your AI client and follow the OAuth or Application Password route.<\/li>\n<li>For the widgets: install Elementor 3.13 or newer, then open any page in the Elementor editor.<\/li>\n<\/ol>\n\n<p>The MCP endpoint is:<\/p>\n\n<pre><code>https:\/\/example.com\/wp-json\/mcp\/flavors-engine\n<\/code><\/pre>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20is%20an%20mcp%20server%2C%20and%20why%20would%20i%20want%20one%3F\"><h3>What is an MCP server, and why would I want one?<\/h3><\/dt>\n<dd><p>MCP (Model Context Protocol) is the standard AI clients such as Claude, ChatGPT and Cursor use to work with outside tools. With an MCP server on your site, you can ask your AI client to write a page, build a header or tidy up your menus, and it does the work in WordPress instead of giving you code to paste.<\/p><\/dd>\n<dt id=\"how%20do%20i%20connect%20claude%2C%20chatgpt%20or%20cursor%3F\"><h3>How do I connect Claude, ChatGPT or Cursor?<\/h3><\/dt>\n<dd><p>Open Flavors Engine, then Connect. Choose your client and follow the OAuth sign-in, or create an Application Password for clients that cannot open a browser. Your site's MCP address is shown on that screen.<\/p><\/dd>\n<dt id=\"is%20it%20safe%20to%20let%20an%20ai%20edit%20my%20site%3F%20can%20i%20undo%20changes%3F\"><h3>Is it safe to let an AI edit my site? Can I undo changes?<\/h3><\/dt>\n<dd><p>The default Production Safe profile blocks raw PHP, filesystem and database access, every call runs with your own WordPress permissions, and supported changes are recorded in a change ledger you can roll back. You can also connect with read-only access or switch individual abilities off.<\/p><\/dd>\n<dt id=\"are%20there%20usage%20limits%20or%20credits%3F\"><h3>Are there usage limits or credits?<\/h3><\/dt>\n<dd><p>No. The server runs on your own site, so there is nothing to meter. Any cost is between you and your AI client.<\/p><\/dd>\n<dt id=\"can%20i%20use%20it%20with%20other%20elementor%20addons%20or%20elementor%20pro%3F\"><h3>Can I use it with other Elementor addons or Elementor Pro?<\/h3><\/dt>\n<dd><p>Yes. The widgets and theme builder work alongside other addons and alongside Elementor Pro.<\/p><\/dd>\n<dt id=\"do%20i%20need%20elementor%3F\"><h3>Do I need Elementor?<\/h3><\/dt>\n<dd><p>No. The MCP server is fully functional without it. Elementor is only needed for the widget library and theme builder.<\/p><\/dd>\n<dt id=\"do%20i%20need%20an%20api%20key%20or%20a%20subscription%3F\"><h3>Do I need an API key or a subscription?<\/h3><\/dt>\n<dd><p>No. The plugin needs no activation key and talks to no licence service. Your MCP client supplies its own model access.<\/p><\/dd>\n<dt id=\"is%20my%20content%20sent%20anywhere%3F\"><h3>Is my content sent anywhere?<\/h3><\/dt>\n<dd><p>The MCP endpoint is self-hosted; there is no relay. Your AI client connects directly to your site.<\/p><\/dd>\n<dt id=\"is%20anything%20locked%20behind%20an%20upgrade%3F\"><h3>Is anything locked behind an upgrade?<\/h3><\/dt>\n<dd><p>Nothing in this download is disabled or greyed out. Flavors Engine Pro is a separate plugin that adds plugin-aware abilities for other page builders, WooCommerce, forms, SEO and custom fields, along with an extra widget pack.<\/p><\/dd>\n<dt id=\"does%20the%20cookie%20consent%20widget%20support%20google%20consent%20mode%3F\"><h3>Does the Cookie Consent widget support Google Consent Mode?<\/h3><\/dt>\n<dd><p>Yes, Consent Mode v2, and it is off by default. Turn on \"Google Consent Mode v2\" in the widget's Google Consent Mode section and the widget sets the analytics, advertising and personalisation consent types to denied before your Google tags run, then sends an update when a visitor accepts, rejects or changes a category. These signals only reach Google tags you have already installed yourself (for example Google Analytics or Google Ads through Site Kit or Tag Manager). The plugin loads no Google script, contacts no Google server and tracks no one.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Fixed: Post Masonry showed no posts with the default skin.<\/li>\n<li>Fixed: slider and carousel arrows and dots never appeared, and autoplay could not be turned off.<\/li>\n<li>Fixed: a malformed cookie could stop pages with the Post Views widget from loading.<\/li>\n<li>Fixed: the Cookie Consent centre modal left the page unclickable after a choice.<\/li>\n<li>Fixed: dozens of widget settings that had no effect, including accordion multi-open, marquee pause, pricing and bento responsive columns, stats alignment and blend modes on both cursors.<\/li>\n<li>Fixed: the OAuth MCP endpoint is registered at the address the Connect screen shows.<\/li>\n<li>Security: the MCP endpoint refuses anonymous callers and respects the on\/off switch; OAuth tokens are accepted on REST requests only, and read-only grants cannot run write abilities.<\/li>\n<li>Security: theme templates now need the Edit Theme Options capability to create, import or preview.<\/li>\n<li>Security: hardened HTML tag settings, links and several scripts that built markup from settings.<\/li>\n<li>Accessibility: keyboard support, labels, focus rings, pause controls and reduced-motion support across many widgets.<\/li>\n<li>Uninstall keeps your data unless you tick \"Delete all Flavors Engine data when the plugin is deleted\" in the settings.<\/li>\n<li>Theme builder: a new single, archive, search or 404 template needs a display condition before it applies, as in Elementor Pro. Templates you already have keep working: the update gives each one without conditions the site-wide condition for its type.<\/li>\n<li>New: \"Preview Settings\" for theme-builder templates, so a single or archive template can be edited with a real post or archive in the preview.<\/li>\n<li>New: optional Google Consent Mode v2 signals in the Cookie Consent widget (off by default; loads no Google script).<\/li>\n<li>Changed: the Social Feed widget's Instagram source uses the Instagram API with Instagram Login and refreshes its token automatically. The old Basic Display API was shut down by Meta.<\/li>\n<li>Fixed: the OAuth MCP endpoint also speaks the current MCP protocol, and read-only connections only see read tools.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First release of Flavors Engine, combining the MCP server and the Elementor widget library into one plugin.<\/li>\n<li>Elementor is an optional dependency: the MCP server runs on sites that do not have it.<\/li>\n<li>Theme builder with header, footer, single, archive, search, 404, popup, loop item, template part and login templates, plus display conditions. Every non-WooCommerce theme-builder widget ships free; the WooCommerce widgets are in Pro.<\/li>\n<li>Elementor content abilities are part of the free plugin: read and write a page's Elementor document, and add, edit or delete a single element, over MCP.<\/li>\n<li>One accent colour and one centred container across every admin screen.<\/li>\n<\/ul>","raw_excerpt":"Self-hosted MCP server for Claude, ChatGPT and Cursor with safety profiles and undo. Plus 151 Elementor widgets and a free theme builder.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/kab.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/358639","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kab.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/kab.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/kab.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=358639"}],"author":[{"embeddable":true,"href":"https:\/\/kab.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/flavorswp"}],"wp:attachment":[{"href":"https:\/\/kab.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=358639"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/kab.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=358639"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/kab.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=358639"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/kab.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=358639"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/kab.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=358639"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/kab.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=358639"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}