MCPDO finds bounded WooCommerce operational issues, preserves the evidence behind each finding, and lets supported AI clients prepare exact product fixes without bypassing WordPress permissions or human approval.
Free V1 focuses on one complete outcome loop: find it prove it preview a fix approve apply verify recover when safe.
MCPDO does not claim conversion or revenue causality from the V1 audit signals. Product content, inventory, pending/failed order status, coupons, and supported WooCommerce configuration values are reported as observations only.
WooCommerce is not required to activate MCPDO. When WooCommerce is unavailable or below the supported commerce boundary, MCPDO remains active and reports commerce features as unavailable.
MCPDO includes a bounded native MCP endpoint and registers WordPress Abilities for supported operations. Supported clients authenticate with MCPDO OAuth 2.1 Authorization Code + PKCE. OAuth bearer tokens are accepted only by the dedicated MCPDO endpoint and do not create a WordPress login session or authenticate general WordPress REST API routes. MCPDO persists only one-way token hashes needed to validate and rotate grants.
The human-readable admin source used to build the distributed JavaScript and CSS is included in the plugin under assets/src/. The deployed package also includes package.json, pnpm-lock.yaml, and tsconfig.admin.json; see source.txt for the pinned toolchain and rebuild command.
MCPDO stores operational audit, finding, evidence, operation, recovery, task, and activity records in the site’s WordPress database.
MCPDO core does not require an MCPDO Cloud account, does not use a TopHive remote administration control plane, and does not proxy site data through TopHive servers by default. The OAuth authorization/token endpoints and native MCP endpoint are hosted by the merchant’s own WordPress site.
An external AI/MCP client is optional and is selected/configured by the site administrator. MCPDO does not initiate outbound requests to those AI providers in Core V1; the configured client connects to the site’s MCP endpoint. Data the administrator chooses to expose through that client is governed by the administrator’s client choice and that client’s own terms and privacy policy.