Title: Flavors Engine &#8211; MCP Server for Claude &amp; ChatGPT, 151 Elementor Addons &amp; Theme Builder
Author: flavorswp
Published: <strong>16 ខែ​កញ្ញា, 2026</strong>
Last modified: 26 ខែ​កញ្ញា, 2026

---

ស្វែងរក កម្មវិធីបន្ថែម

![](https://ps.w.org/flavors-engine/assets/banner-772x250.png?rev=3699192)

![](https://ps.w.org/flavors-engine/assets/icon.svg?rev=3699192)

# Flavors Engine – MCP Server for Claude & ChatGPT, 151 Elementor Addons & Theme Builder

 By [flavorswp](https://profiles.wordpress.org/flavorswp/)

[Download](https://downloads.wordpress.org/plugin/flavors-engine.1.0.1.zip)

 * [Details](https://km.wordpress.org/plugins/flavors-engine/#description)
 * [Reviews](https://km.wordpress.org/plugins/flavors-engine/#reviews)
 *  [Installation](https://km.wordpress.org/plugins/flavors-engine/#installation)
 * [Development](https://km.wordpress.org/plugins/flavors-engine/#developers)

 [Support](https://wordpress.org/support/plugin/flavors-engine/)

## Description

Flavors Engine is two tools in one plugin, and each half works on its own:

 1. **A WordPress MCP server** that lets the AI client you already use (Claude, ChatGPT,
    Cursor, Codex, Copilot and others) build and manage your site directly, under rules
    you set.
 2. **An Elementor addon** with 151 widgets and a complete theme builder, free, with
    nothing locked.

The MCP server runs on any site: Elementor, Bricks, Divi, a block theme or headless.
If Elementor is not installed, the widget half simply stays off.

No AI model is bundled and none runs on your server. Your MCP client brings its 
own model access, and every decision about what it may do is enforced here, on your
install. There are no credits, no usage limits and no relay service in between.

#### MCP server for Claude, ChatGPT, Cursor and any AI agent

Connect an AI agent and it works through typed abilities instead of guessing: 97
on a fresh install and 130 once Elementor is active, built on the WordPress Abilities
API and the official MCP Adapter. One prompt from you becomes many small, checked
calls from the agent.

 * **Content** – list, search, read, create, update, trash, restore and delete posts,
   pages and public custom post types. New content is created as a draft unless 
   you ask otherwise.
 * **Elementor pages** – read and write a page’s Elementor document, and add, edit
   or delete a single element.
 * **Theme builder** – create headers, footers and templates and set where they 
   apply.
 * **Taxonomies, media, comments and menus** – terms, image import and alt text,
   moderation, menu structure and locations.
 * **Revisions, users and site settings** – revision restore, privacy-minimised 
   user reads, an explicit settings allowlist.
 * **Plugins and themes** – search the WordPress.org directory, activate, deactivate,
   update and switch, each behind an explicit confirmation.
 * **Block editor** – Gutenberg content through staged changes that the editor itself
   validates.
 * **Design tokens, skills and prompts** – a design library, reusable skills that
   also appear as MCP prompts, and a prompt library.

#### Why it is not a typical MCP plugin

Most MCP plugins open your site to an agent and stop there. Flavors Engine is built
for handing an agent real work on a live site:

 * **Safety profiles.** Read Only blocks every change. Production Safe, the default,
   allows normal content and design work and blocks raw PHP, WP-CLI, filesystem 
   and database access. Developer Full Access enables those surfaces, and critical
   calls still need explicit confirmation.
 * **Undo.** Supported changes are recorded in a change ledger that you can roll
   back.
 * **Your permissions still apply.** Every call is checked against the connected
   user’s WordPress capabilities, abilities can be switched off one by one, and 
   writes are rate limited per connection.
 * **Real OAuth.** OAuth 2.1 with PKCE, a read-only grant for clients that only 
   need to look, and every connection listed under Connected Apps so you can revoke
   it. Application Passwords remain available for clients that cannot open a browser.
 * **Elementor aware.** The agent builds with the same widgets and theme builder
   you use, not raw HTML.

#### 151 free Elementor addons and widgets

Headings, buttons, info boxes, icon lists, tabs, accordions, FAQs and toggles. Galleries,
sliders, carousels, image comparison, hotspots and Lottie. Testimonials, team members,
pricing tables and switchers, counters and progress bars. Post grids, lists, carousels,
timelines and news tickers. Navigation menus, breadcrumbs, table of contents and
scroll navigation. Creative effects such as image trail, scramble text, aurora background,
bento grid, marquee, tilt cards and custom cursors. Styling for Contact Form 7, 
Mailchimp, login and search forms, plus a cookie consent banner.

Every widget can be switched off, and a widget that is off is never loaded.

#### Free Elementor theme builder

A full header and footer builder and template builder in the free plugin: header,
footer, single, archive, search results, 404, popup, loop item, template part and
login templates, each with display conditions that decide where it applies. Fifty
theme-builder widgets cover site logo and title, menus, post title, content, meta
and comments, archive posts and pagination, search, author box, related posts, reading
time, dark mode toggle and more. You can preview a template with a real post or 
archive while you edit it.

None of the template types is reserved for a paid version.

#### Flavors Engine Pro

Pro is a separate plugin from [flavorswp.com](https://flavorswp.com/). It does not
unlock anything in this download: everything described above is already running,
with no limits.

 * **AI whole-site builder** – the agent plans and builds a complete site (pages,
   header, footer, templates, menus and design system) as a resumable task list 
   you can review.
 * **More than 1,000 plugin-aware abilities** – WooCommerce, Bricks, Divi, Oxygen,
   Breakdance, Beaver Builder, Gravity Forms, WPForms, Fluent Forms, Yoast, Rank
   Math, ACF, JetEngine, WPML, Polylang and more.
 * **Agent memory and an approval queue** – the agent remembers your conventions,
   and changes can wait for your approval.
 * **Extra widget packs** – WooCommerce widgets and WooCommerce theme builder, GSAP
   animation widgets, loop builder, mega menu, popups, charts, store locator and
   events calendar.
 * **Forms Suite** – form builder, submissions, conditional logic, SMTP and payments.

Claude, ChatGPT, Cursor and Elementor are trademarks of their respective owners.
Flavors Engine is not affiliated with or endorsed by them.

### External Services

This plugin contacts no external service on its own. Every service below is reached
only when you act: by pressing a button, by connecting an AI client, or by adding
a widget and entering your own API key for it. A default install, with nothing configured,
makes no outbound request at all.

**Google Fonts** – On the Design screen, when a saved design names a font your browser
does not have installed, the preview shows a note explaining that it is not displaying
the design’s real fonts, alongside a **Preview with Google Fonts** button. Pressing
that button loads a stylesheet from `https://fonts.googleapis.com` so the preview
can render the font. Nothing is requested until you press it, nothing is requested
on your site’s front end, and no data about your site or your visitors is sent –
the request contains the font name and, as with any browser request, your IP address
and user agent. Google’s terms: https://policies.google.com/terms – Google’s privacy
policy: https://policies.google.com/privacy

**The WordPress.org plugin directory** – The `search-extensions` and `get-extension`
abilities query `https://api.wordpress.org` for plugin and theme information, exactly
as your WordPress dashboard does. These run only when an AI client you have connected
calls them. WordPress.org’s privacy policy: https://wordpress.org/about/privacy/

**Openverse** – The `search-images` ability queries `https://api.openverse.org` 
for openly licensed photographs, the same catalogue the block editor’s own openly-
licensed media search uses. It runs only when an AI client you have connected calls
it, the request contains only your search terms and filters, and no account or API
key is involved. The ability returns links; it does not download anything. A file
is only fetched and added to your Media Library if you then ask for `import-media-
url`, which downloads from whichever URL is passed to it. Openverse is a WordPress.
org project. Openverse terms of service: https://docs.openverse.org/terms_of_service.
html – Openverse privacy policy: https://openverse.org/privacy

The remaining services are reached only by widgets you place on a page, and only
after you enter your own API key or access token for them. None of them is contacted
on a default install, because without your credential the request is never made.

**Mailchimp** – The Mailchimp Form widget sends a subscription to `https://<dc>.
api.mailchimp.com` when a visitor submits the form, where `<dc>` is the data-centre
suffix of your own API key. This one sends visitor data: the email address the visitor
typed, and any merge fields your form collects, together with your API key. It runs
only on a form you added and configured with your key. Mailchimp’s terms: https://
mailchimp.com/legal/terms/ – Mailchimp’s privacy policy: https://mailchimp.com/legal/
privacy/

**YouTube Data API** – The YouTube TV widget and the YouTube mode of the Social 
Feed widget request channel and video listings from `https://www.googleapis.com/
youtube/v3/`, using a Google API key you supply. The request contains your key and
the channel or playlist you configured. Responses are cached, and no visitor data
is sent. Google’s terms: https://policies.google.com/terms – Google’s privacy policy:
https://policies.google.com/privacy – YouTube API Services terms: https://developers.
google.com/youtube/terms/api-services-terms-of-service

**The YouTube player (loaded in the visitor’s browser)** – A page containing the
YouTube TV widget loads YouTube’s iframe player API from `https://www.youtube.com/
iframe_api` and embeds the player itself from youtube.com. This is the only script
this plugin loads from another domain, and it has to be: YouTube’s terms require
the player API to be served from their domain rather than bundled. It happens in
the visitor’s browser, on pages where you placed the widget, and it gives YouTube
the visitor’s IP address and user agent as any embed does – nothing is sent from
your server. Google’s terms: https://policies.google.com/terms – privacy policy:
https://policies.google.com/privacy – YouTube API Services terms: https://developers.
google.com/youtube/terms/api-services-terms-of-service

**Instagram** – The Instagram mode of the Social Feed widget uses the Instagram 
API with Instagram Login (Business or Creator accounts). It requests your own recent
media from `https://graph.instagram.com`, using an Instagram access token you supply,
and about once a week refreshes that token through `https://graph.instagram.com/
refresh_access_token` so it does not expire. The requests contain your token and
a post count. Responses are cached, and no visitor data is sent. Meta Platform Terms:
https://developers.facebook.com/terms – Meta Privacy Policy: https://privacycenter.
instagram.com/policy

**OpenWeatherMap** – The plugin registers a weather proxy endpoint that requests
current conditions from `https://api.openweathermap.org` for a location you configure,
using an OpenWeatherMap API key you supply. The widget that uses it is part of Flavors
Engine Pro, so on this plugin alone the endpoint exists but nothing calls it; it
is listed here because the code ships. Responses are cached and no visitor data 
is sent. OpenWeatherMap’s terms: https://openweathermap.org/terms – privacy policy:
https://openweather.co.uk/privacy-policy

**The AI client’s own domain, during sign-in (OAuth Client ID Metadata)** – When
an AI client connects and identifies itself with an https URL as its client id, 
the plugin fetches that URL once to read the client’s metadata document (its name,
its redirect addresses), caches the result, and uses it to decide whether the sign-
in may proceed. The host contacted is therefore the client’s, not ours, and which
host that is depends on which client you connect. The request is a plain GET with
no body and no data about your site beyond the fact that it was made; redirects 
are validated one hop at a time and private or loopback addresses are refused. Nothing
is fetched until you connect a client that uses this form of identifier. For Claude,
that host is claude.ai or claude.com – Anthropic’s terms: https://www.anthropic.
com/legal/consumer-terms – privacy policy: https://www.anthropic.com/legal/privacy

**Your own site (self-diagnostics, not an external service)** – The Troubleshoot
screen checks that the MCP endpoint, the OAuth discovery documents and the REST 
API are reachable by requesting them from your own site’s address, and it sends 
a handful of AI-client user agents at one of those addresses to detect a hosting
bot filter that would block real clients. Every one of these requests goes to your
own domain. They are listed here because they are outbound HTTP requests and a reader
auditing the code will see them; no third party is involved and no data leaves your
server.

**AI model providers** – This plugin bundles no AI model and contacts no model provider.
Your MCP client connects directly to your site and brings its own model access; 
the plugin never sees a provider API key. The MCP endpoint is self-hosted and there
is no relay.

**AI client sign-in addresses (no request is made)** – The Connect screen shows 
the sign-in address of the AI client you choose, and the OAuth flow lists that client’s
callback address as an allowed redirect target. For Claude those addresses are on
the claude.ai and claude.com domains; other clients have their own. These are destinations
your own browser is sent to when you press “connect”, and addresses the plugin checks
a returning request against. The plugin itself never opens a connection to any of
them, and no data is sent to them by the plugin. They are listed here only because
the addresses appear in the code and a reader should know why. Anthropic’s terms:
https://www.anthropic.com/legal/consumer-terms – privacy policy: https://www.anthropic.
com/legal/privacy

### Source Code

Everything in this plugin is readable source except the third-party libraries listed
below, and this section is where to find the source for each compressed file.

**This plugin’s own code.** All PHP is source. Under `assets/`, every minified file
ships beside the unminified file it was built from (`x.min.js` next to `x.js`), 
and `SCRIPT_DEBUG` makes WordPress load the readable one. Nine scripts have no separate
minified twin because none was ever built: they were inherited as single-line files
with no build step, so they ship reformatted in place, and each carries a header
saying exactly that. Note that `assets/js/library/` is not exclusively third-party:`
aos`, `gradient-bg`, `shape-divider`, `tabs` and `list-actions` are this plugin’s
own code and each ships with its readable source beside the minified file.

**The chat interface.** `includes/assets/chat/index.js` is compiled from `src/chat/
index.tsx`, which ships inside this plugin. Build it with the `@wordpress/scripts`
toolchain that `package.json` declares:

    ```
    npm install && npm run build:chat
    ```

**Third-party libraries.** Each is shipped in the minified form its own project 
distributes. The readable source for every one is published by that project at the
address below, which is also where any modification should be taken from.

 * **Slick Carousel** – MIT – https://github.com/kenwheeler/slick (carousel and 
   slider widgets)
 * **Prism** – MIT – https://github.com/PrismJS/prism (code-highlight widget)
 * **Salvattore** – MIT – https://github.com/rnmp/salvattore (column layout for 
   the Post Masonry widget). Shipped as a readable adaptation in `assets/js/library/
   flavor-columns.js`, credited in its header.
 * `assets/js/library/table.min.js` is five libraries concatenated and minified,
   all MIT, listed in the file’s own header and here:
    - **DataTables** – https://github.com/DataTables/DataTables
    - **DataTables Buttons** – https://github.com/DataTables/Buttons
    - **JSZip** – https://github.com/Stuk/jszip
    - **pdfmake** – https://github.com/bpampuch/pdfmake
    - **jquery-csv** – https://github.com/typeiii/jquery-csv
 * The Lottie animation widget ships three MIT libraries:
    - **lottie-web** – https://github.com/airbnb/lottie-web
    - **lottie-interactivity** – https://github.com/LottieFiles/lottie-interactivity
    - **lottie-player** – https://github.com/LottieFiles/lottie-player
 * **Jarallax** – MIT – https://github.com/nk-o/jarallax (the parallax background
   extension; `assets/js/library/parallax-bg.min.js`)
 * **Animate.css** 4.1.1 – MIT – https://github.com/animate-css/animate.css (entrance
   animations)
 * **AOS** (Animate On Scroll) – MIT – https://github.com/michalsnik/aos (scroll-
   triggered animations; the bundled file is a reduced reimplementation, readable
   as shipped)

Masonry and imagesLoaded are not bundled: the plugin uses the copies WordPress core
itself ships and registers. GreenSock (GSAP) is not bundled either – its licence
is not GPL-compatible, so the widgets that need it are not part of this plugin.

Server-side PHP dependencies are managed with Composer and declared in `composer.
json`; each carries its own LICENSE file inside `vendor/`.

## Screenshots

[⌊The MCP server dashboard - safety profile, connected clients, skills and the change
ledger at a glance.⌉⌊The MCP server dashboard - safety profile, connected clients,
skills and the change ledger at a glance.⌉[

The MCP server dashboard – safety profile, connected clients, skills and the change
ledger at a glance.

[⌊The widget catalogue - all 151 widgets, modules and extensions with per-item switches;
anything off is never registered.⌉⌊The widget catalogue - all 151 widgets, modules
and extensions with per-item switches; anything off is never registered.⌉[

The widget catalogue – all 151 widgets, modules and extensions with per-item switches;
anything off is never registered.

[⌊The Theme Builder - headers, footers and templates built in Elementor, with the
display rules that decide where each applies.⌉⌊The Theme Builder - headers, footers
and templates built in Elementor, with the display rules that decide where each 
applies.⌉[

The Theme Builder – headers, footers and templates built in Elementor, with the 
display rules that decide where each applies.

[⌊The Abilities screen - every typed operation exposed to AI agents, grouped by 
provider, each individually switchable under the active safety profile.⌉⌊The Abilities
screen - every typed operation exposed to AI agents, grouped by provider, each individually
switchable under the active safety profile.⌉[

The Abilities screen – every typed operation exposed to AI agents, grouped by provider,
each individually switchable under the active safety profile.

## Installation

 1. Install and activate Flavors Engine.
 2. For the MCP server: open **Flavors Engine  Connect**, leave **Production Safe**
    selected, choose your AI client and follow the OAuth or Application Password route.
 3. For the widgets: install Elementor 3.13 or newer, then open any page in the Elementor
    editor.

The MCP endpoint is:

    ```
    https://example.com/wp-json/mcp/flavors-engine
    ```

## FAQ

### What is an MCP server, and why would I want one?

MCP (Model Context Protocol) is the standard AI clients such as Claude, ChatGPT 
and Cursor use to work with outside tools. With an MCP server on your site, you 
can ask your AI client to write a page, build a header or tidy up your menus, and
it does the work in WordPress instead of giving you code to paste.

### How do I connect Claude, ChatGPT or Cursor?

Open Flavors Engine, then Connect. Choose your client and follow the OAuth sign-
in, or create an Application Password for clients that cannot open a browser. Your
site’s MCP address is shown on that screen.

### Is it safe to let an AI edit my site? Can I undo changes?

The default Production Safe profile blocks raw PHP, filesystem and database access,
every call runs with your own WordPress permissions, and supported changes are recorded
in a change ledger you can roll back. You can also connect with read-only access
or switch individual abilities off.

### Are there usage limits or credits?

No. The server runs on your own site, so there is nothing to meter. Any cost is 
between you and your AI client.

### Can I use it with other Elementor addons or Elementor Pro?

Yes. The widgets and theme builder work alongside other addons and alongside Elementor
Pro.

### Do I need Elementor?

No. The MCP server is fully functional without it. Elementor is only needed for 
the widget library and theme builder.

### Do I need an API key or a subscription?

No. The plugin needs no activation key and talks to no licence service. Your MCP
client supplies its own model access.

### Is my content sent anywhere?

The MCP endpoint is self-hosted; there is no relay. Your AI client connects directly
to your site.

### Is anything locked behind an upgrade?

Nothing in this download is disabled or greyed out. Flavors Engine Pro is a separate
plugin that adds plugin-aware abilities for other page builders, WooCommerce, forms,
SEO and custom fields, along with an extra widget pack.

### Does the Cookie Consent widget support Google Consent Mode?

Yes, Consent Mode v2, and it is off by default. Turn on “Google Consent Mode v2”
in the widget’s Google Consent Mode section and the widget sets the analytics, advertising
and personalisation consent types to denied before your Google tags run, then sends
an update when a visitor accepts, rejects or changes a category. These signals only
reach Google tags you have already installed yourself (for example Google Analytics
or Google Ads through Site Kit or Tag Manager). The plugin loads no Google script,
contacts no Google server and tracks no one.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Flavors Engine – MCP Server for Claude & ChatGPT, 151 Elementor Addons & Theme 
Builder” is open source software. The following people have contributed to this 
plugin.

Contributors

 *   [ flavorswp ](https://profiles.wordpress.org/flavorswp/)

“Flavors Engine – MCP Server for Claude & ChatGPT, 151 Elementor Addons & Theme 
Builder” has been translated into 1 locale. Thank you to [the translators](https://translate.wordpress.org/projects/wp-plugins/flavors-engine/contributors)
for their contributions.

[Translate “Flavors Engine – MCP Server for Claude & ChatGPT, 151 Elementor Addons & Theme Builder” into your language.](https://translate.wordpress.org/projects/wp-plugins/flavors-engine)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/flavors-engine/), check
out the [SVN repository](https://plugins.svn.wordpress.org/flavors-engine/), or 
subscribe to the [development log](https://plugins.trac.wordpress.org/log/flavors-engine/)
by [RSS](https://plugins.trac.wordpress.org/log/flavors-engine/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.1

 * Fixed: Post Masonry showed no posts with the default skin.
 * Fixed: slider and carousel arrows and dots never appeared, and autoplay could
   not be turned off.
 * Fixed: a malformed cookie could stop pages with the Post Views widget from loading.
 * Fixed: the Cookie Consent centre modal left the page unclickable after a choice.
 * Fixed: dozens of widget settings that had no effect, including accordion multi-
   open, marquee pause, pricing and bento responsive columns, stats alignment and
   blend modes on both cursors.
 * Fixed: the OAuth MCP endpoint is registered at the address the Connect screen
   shows.
 * Security: the MCP endpoint refuses anonymous callers and respects the on/off 
   switch; OAuth tokens are accepted on REST requests only, and read-only grants
   cannot run write abilities.
 * Security: theme templates now need the Edit Theme Options capability to create,
   import or preview.
 * Security: hardened HTML tag settings, links and several scripts that built markup
   from settings.
 * Accessibility: keyboard support, labels, focus rings, pause controls and reduced-
   motion support across many widgets.
 * Uninstall keeps your data unless you tick “Delete all Flavors Engine data when
   the plugin is deleted” in the settings.
 * Theme builder: a new single, archive, search or 404 template needs a display 
   condition before it applies, as in Elementor Pro. Templates you already have 
   keep working: the update gives each one without conditions the site-wide condition
   for its type.
 * New: “Preview Settings” for theme-builder templates, so a single or archive template
   can be edited with a real post or archive in the preview.
 * New: optional Google Consent Mode v2 signals in the Cookie Consent widget (off
   by default; loads no Google script).
 * Changed: the Social Feed widget’s Instagram source uses the Instagram API with
   Instagram Login and refreshes its token automatically. The old Basic Display 
   API was shut down by Meta.
 * Fixed: the OAuth MCP endpoint also speaks the current MCP protocol, and read-
   only connections only see read tools.

#### 1.0.0

 * First release of Flavors Engine, combining the MCP server and the Elementor widget
   library into one plugin.
 * Elementor is an optional dependency: the MCP server runs on sites that do not
   have it.
 * Theme builder with header, footer, single, archive, search, 404, popup, loop 
   item, template part and login templates, plus display conditions. Every non-WooCommerce
   theme-builder widget ships free; the WooCommerce widgets are in Pro.
 * Elementor content abilities are part of the free plugin: read and write a page’s
   Elementor document, and add, edit or delete a single element, over MCP.
 * One accent colour and one centred container across every admin screen.

## មេតា

 *  Version **1.0.1**
 *  Last updated **22 ម៉ោង មុន**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.9 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 8.0 or higher **
 *  Languages
 * [English (US)](https://wordpress.org/plugins/flavors-engine/) and [Lao](https://lo.wordpress.org/plugins/flavors-engine/).
 *  [Translate into your language](https://translate.wordpress.org/projects/wp-plugins/flavors-engine)
 * Tags
 * [elementor addons](https://km.wordpress.org/plugins/tags/elementor-addons/)[elementor widgets](https://km.wordpress.org/plugins/tags/elementor-widgets/)
   [mcp](https://km.wordpress.org/plugins/tags/mcp/)[mcp-server](https://km.wordpress.org/plugins/tags/mcp-server/)
   [theme builder](https://km.wordpress.org/plugins/tags/theme-builder/)
 *  [Advanced View](https://km.wordpress.org/plugins/flavors-engine/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/flavors-engine/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/flavors-engine/reviews/)

## Contributors

 *   [ flavorswp ](https://profiles.wordpress.org/flavorswp/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/flavors-engine/)