Corsen Context
Publish selected public WordPress content through llms.txt and an MCP-style JSON-RPC endpoint, with owner-controlled tool extensions.
Solid choice
Corsen Context is a solid plugin choice in 2026, with a few things worth checking first. It runs on 90+ sites and was last updated 4 weeks ago, and scores 63/100 on our health check.
- Actively developed — last update 4 weeks ago
- Momentum — downloads up 288.6% vs the previous 30 days
- Small user base (90+ active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Corsen Context stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| AI | >100 |
| ai-native | >100 |
| llms.txt | #81 |
| mcp | >100 |
| model context protocol | #15 |
Version adoption
Share of active sites per release.
About Corsen Context
From the official readme · v1.5.16Description
Corsen Context publishes a bounded overview of selected public WordPress content and provides four core read-only content tools through a JSON-RPC endpoint. Five further extension tools are opt-in and owner-controlled: get_product (live price, stock, images and variants via WooCommerce, plus an agentPurchase policy the agent must respect), get_sections (a page outline plus one bounded section per call), get_structured_data (typed JSON-LD blocks), check_agent_access (reads the result of the owner’s latest agent-access self-test) and request_expert_call (a human-only expert intake, annotated readOnlyHint:false and refused server-side for AI callers with error code human_only). 1.5.0 also registers the enabled tools through the experimental WebMCP browser API when the site owner opts in and the browser exposes that API, and through the WordPress Abilities API on WordPress 6.9 or newer.
What it does
The plugin provides three separate surfaces:
-
Static Layer — Generates
/llms.txtwith a structured overview of selected public content. An optional, bounded/llms-full.txtexport can be enabled in settings. -
Dynamic Layer — Exposes the enabled tools through a Model Context Protocol (MCP) JSON-RPC endpoint at the canonical URL generated by WordPress. The four core tools and four WordPress read extensions are read-only; the optional human-only expert intake is explicitly non-read-only and refuses agent calls server-side. The endpoint targets protocol version 2025-11-25 with JSON responses and no server-sent event stream.
-
In-Page Layer (opt-in) — Registers the enabled tools through WebMCP
document.modelContext, including explicit per-tool annotations. Serving the bridge does not enable WebMCP in every browser: a compatible browser/client and, where applicable, current trial enrollment or a development flag are also required.
Key Features
- Default surfaces —
/llms.txtand the public read-only endpoint are enabled; the heavier/llms-full.txtexport and WebMCP bridge are opt-in. - MCP 2025-11-25 target — Supports
initialize,ping,tools/list,tools/call,resources/list,resources/read, andnotifications/initialized. The endpoint returns JSON responses and does not provide server-sent event streaming. - 4 core read-only tools —
search_site,get_page_content,list_content,get_sitemap; every other surface tool is an opt-in extension, off by default. - SEO integration — Reads Yoast SEO and Rank Math metadata for better descriptions.
- Request controls — Rate limiting, strict input validation, same-site content URL checks, defensive MCP response headers, and optional API-key authentication.
- Admin settings page — Choose public post types, exclude paths, set rate limits, toggle surfaces, and select any subset of the tools.
- Control Center (Settings > Corsen Context Control) — one card per surface and tool, honest exposed/needs-config/off badges, what-agents-see preview, and a bounded local audit log with a one-click purge.
- Dashboard widget — See your AI context status at a glance.
- Bounded generation — Total item and output-byte limits protect the optional full-content export.
- Content safety — Drafts, private posts, password-protected posts, excluded paths, and content vetoed by the exposure filter are not served.
- Credit line — “Powered by Corsen Context” in generated files (configurable).
Published Endpoints and Discovery Hints
When the corresponding settings are enabled, Corsen Context publishes:
- robots.txt — An
MCP:line containing the canonical endpoint URL generated by WordPress - llms.txt — When MCP is enabled, the generated file includes its canonical endpoint URL; the separate promotional credit remains optional
- HTML head —
<link rel="mcp">link element added automatically - Direct URL —
/llms.txtremains available to clients that know the convention
These are project discovery hints, not universally consumed standards. They do not guarantee that a search engine or client will discover or use the endpoint.
Requirements
- WordPress 6.0 or higher
- PHP 8.0 or higher
- A web-server configuration that routes the published
/llms.txtpath to WordPress. Pretty permalinks are recommended for this static path. The MCP REST endpoint itself uses WordPress’s canonical URL and can use the?rest_route=/corsen-context/v1/mcpform with Plain permalinks.
WebMCP additionally needs a browser and agent/client that implement the evolving API. Chrome’s development flag and public origin-trial path can change; follow the current browser setup guide.
Part of a Bigger Ecosystem
Corsen Context is an open-source project by Corsen AI. The project also provides TypeScript packages for Node.js, Next.js, and Astro, plus a reference Express server. WordPress uses this dedicated PHP plugin.
Installation
From WordPress.org (published stable channel)
- Go to Plugins > Add New in your WordPress admin
- Search for “Corsen Context”
- Click “Install Now” then “Activate”
- Visit Settings > Corsen Context and review the exposed post types, paths, and surfaces.
Check the version displayed by WordPress.org before installation. A stable version older than 1.5.14 does not contain the complete current Control Center, extension-tool hardening, and Abilities API schemas documented here.
Manual release installation
- Obtain the GitHub release asset for version 1.5.16, or build a ZIP from
packages/wordpress-plugin/corsen-contextin the public repository at tagv1.5.16. - The ZIP must contain one top-level
corsen-contextfolder withcorsen-context.php,includes/,uninstall.php, andreadme.txt; do not upload the monorepo ZIP. - Go to Plugins > Add New > Upload Plugin, upload that plugin ZIP, and activate it.
- Confirm version 1.5.16 on the Plugins screen, then review Settings > Corsen Context before enabling WebMCP.
After Activation
With the default settings, activation publishes:
/llms.txt— Visithttps://yoursite.com/llms.txtto see it- MCP endpoint — Copy the exact URL displayed under Settings > Corsen Context or exposed by the site’s MCP discovery hints
-
Dashboard widget — Check your admin dashboard
/llms-full.txt is not enabled by default. WebMCP is also opt-in and requires a compatible browser/client in addition to the WordPress setting.
Important: Do not construct the MCP endpoint by appending /wp-json/. WordPress commonly returns https://yoursite.com/wp-json/corsen-context/v1/mcp, but Plain permalinks can return https://yoursite.com/?rest_route=/corsen-context/v1/mcp, and a site can filter the REST prefix. Use the URL displayed by the plugin or published in robots.txt, the HTML <link rel="mcp">, or the generated /llms.txt when MCP is enabled. If the separate /llms.txt path is unavailable, review the site’s rewrite and permalink configuration.
Frequently asked questions
What is MCP?
Model Context Protocol is an open protocol for communication between AI applications and external systems. Corsen Context targets the 2025-11-25 protocol version for its read-only JSON-RPC endpoint.
What is llms.txt?
A proposed convention where websites place a /llms.txt file containing a structured Markdown overview. Support varies by client and search engine, so it should be treated as an additional publishing surface rather than an indexing guarantee.
Is my content safe?
The plugin limits output to selected public post types and rejects draft, pending, private, password-protected, trashed, or excluded content. Site owners can also veto individual posts with the corsen_context_can_expose_post filter. As with any public export, review the selected post types and exclusions before enabling it on a site with membership or conditional-visibility plugins.
Does this slow down my site?
When MCP is enabled, normal pages receive a small discovery link. When WebMCP is also enabled, the plugin emits an origin-trial meta tag if configured and an inline registration script. Generated metadata may use bounded WordPress transients for anonymous, cookie-free requests. Rendered page content is not placed in the shared MCP cache, and /llms-full.txt uses item, byte, and generation-lock limits. Measure representative pages on your own hosting rather than assuming zero impact.
Does it work with page builders?
By default, Corsen Context reads stored public content without executing the_content, dynamic blocks, or shortcodes. This avoids accidentally exporting personalized output. Site owners can opt into full rendering with the corsen_context_render_mode filter; full-rendered output is never stored in the shared content cache. Compatibility depends on the page builder and should be tested on the site.
Can I control which content is exposed?
Yes. In Settings > Corsen Context you can: Choose which post types to include (pages, posts, products, custom types) Exclude specific URL paths Choose which tools MCP, WebMCP and the Abilities API advertise and allow (extension tools stay off until you enable them) Disable MCP, llms.txt, or the entire plugin
Does it work with WooCommerce?
The standard public product post type can be selected. The plugin exports its stored public content under the same rendering and exclusion rules as other post types. Themes, product add-ons, memberships, prices, variations, and dynamic shortcodes can change what a visitor sees, so test the required WooCommerce fields and visibility rules on the target site before claiming compatibility. When you enable it, the get_product extension tool additionally serves live price, sale, stock, image, and (for variable products) variant data through WooCommerce APIs; it requires WooCommerce to be active…
How do I protect the MCP endpoint?
You can set an API key by defining CORSEN_CONTEXT_API_KEY in your wp-config.php: define('CORSEN_CONTEXT_API_KEY', 'your-secret-key-here'); Server-side requests must then include X-MCP-Key: your-secret-key-here or Authorization: Bearer your-secret-key-here. The supplied WebMCP bridge intentionally sends no key, cookies, or visitor credentials. Do not embed the key in page source. Use either a public, read-only, rate-limited endpoint for WebMCP or a key-protected endpoint for configured server-side MCP clients with WebMCP disabled.
How do I enable WebMCP in a browser?
Enable WebMCP in Settings > Corsen Context, then use a browser and agent/client that implement the experimental API. Serving the registration script alone is not enough. For local Chrome testing, follow the current documented flag. For a public trial, enroll the exact HTTPS origin and use its current, unexpired token. See the browser setup and verification guide. An origin-trial token is delivered to browsers and is not an MCP credential. Successful registration also does not prove the endpoint or content policy: execute search_site, pass one result to get_page_content, and inspect the…
Can I remove the credit line?
Yes. Uncheck “Show Credit” in Settings > Corsen Context. However, the credit helps grow the open-source ecosystem and we appreciate keeping it enabled.
Changelog
The agent conduct policy now spells out the allowed purchase path (cart, checkout, account creation) next to the human-only rules, so a well-behaved agent completes what the owner permits and hands the rest to a person.
1.5.16 – 2026-09-03
- Agent conduct policy states what an agent may do, not only what it must not: for a product whose
agentPurchaseisallowed, an agent acting for its user may complete the store’s ordinary checkout, including creating the customer account it requires; everything outside those explicit per-product permissions stays human-only, and the agent is told to stop and report the page URL to its user. The same sentence is rendered inllms.txt, the[corsen_agent_policy]page, the machine-readable policy JSON, theget_productdescription, and the default per-product reason.
1.5.15 – 2026-09-03
- “Hide user enumeration” now flips anonymous author archives to 404 on
pre_handle_404, insideWP::main()and before thewpaction, instead of ontemplate_redirect. The previous hook returned the right status but SEO plugins andwp_get_document_title()had already resolved the author, so the 404 page’s<title>and Open Graph tags still printed the author’s nicename and archive URL. The queried user is also dropped from the main query, and the integration test now asserts the document title,is_author(), and the queried object.
1.5.14 – 2026-09-02
get_structured_datanow uses WordPress’s safe HTTP transport, refuses redirects, and caps the loopback response while downloading it. Stored markup is capped before parsing, JSON-LD clips stay valid UTF-8, multi-type entities are counted correctly, duplicate blocks no longer create a false truncation flag, and every returned block now stays within the documented byte budget.- WordPress Abilities output schemas now match the executor:
search_sitedeclaresrank, sitemap fields reflect its actual payload, nullable product values are explicit, and the section and structured-data schemas include their real optional fields. - All WordPress extension readers now honor the same membership and visibility veto filter as the four core tools. Section ids reserve the synthetic
topentry and ignore heading-like lines inside fenced code. The expert handoff requires an owner-configured same-origin form URL, and uninstall/purge removes the complete private expert inbox (including trashed requests), agent-access snapshot, lock, and product policy metadata. - Extension input schemas now match their validators (required URIs, exact slug-or-URI product selection, and bounded section offsets), including Unicode-aware string limits. The agent-access check validates real llms.txt/MCP response shapes and is described honestly as a same-site loopback using representative bot User-Agent strings, not a full external-agent test.
- Product purchase policy can be managed on every WooCommerce product edit screen as well as the first 50-product quick editor. Invalid stored states fail closed, policy summaries honor every owner visibility veto, and human-handoff copy no longer claims that Corsen Context intercepts browser form submissions.
1.5.13 – 2026-09-01
- Policy honesty + hardening (second independent review): the REST meta
auth_callbackno longer callsedit_post_meta(which re-entered itself for registered protected meta) and checksedit_postinstead, as Core documents. The agent head banner renders only when the MCP channel is actually enabled — a disabled channel is never advertised. Long owner reasons are truncated without requiring mbstring.llms.txtopens with “START HERE for AI agents” and its policy block now distinguishes the server-enforced expert handoff (human_only) from the per-productagentPurchasecontract instruction; the plugin exposes no purchase tool and never intercepts human checkout. The human-only form notice is generated from the same table ([corsen_human_only_notice]), so the form copy is the wire copy.
1.5.12 – 2026-09-01
- Governed-agent policy: one server-side policy table composes the relevant MCP/WebMCP descriptions,
llms.txt, an HTML head banner for parsers, and the[corsen_agent_policy]page.request_expert_callbecomes human-only by policy: it stays advertised so an agent can read the rule, but every schema-valid invocation is refused with error codehuman_onlyplus a handoff URL before any throttle or storage side effect.get_productoutput carriesagentPurchase(allowed|forbidden) andagentPurchaseReasonfrom owner-set product meta, and the tool description states that a forbidden product must be handed to a human, never checked out by the agent. OPTIONS preflight matching also toleratesrest_routeand atypical permalink prefixes.
1.5.11 – 2026-09-01
tools/listnow emits WebMCP annotations (readOnlyHintper tool;request_expert_callis explicitlyreadOnlyHint: false) on the MCP transport, so SECURITY.md’s claim is backed on the wire and not only in the in-page bridge.get_sectionsdocuments"top"and now always lists and resolves it, even as a zero-byte intro. When “Hide user enumeration” is on,/?author=Nand/author/{login}archives also answer 404 to anonymous visitors instead of leaking logins through the classic doors. The MCP route’s OPTIONS preflight is answered by the plugin (POST, OPTIONS, no credentials) instead of core advertising every verb.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Corsen Context alternatives
All AI plugins →FAQ
Corsen Context: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 29, 2026
Is Corsen Context free?
Yes. Corsen Context is free to download and use from the official WordPress.org plugin directory.
Is Corsen Context safe to use in 2026?
Corsen Context is a solid plugin choice in 2026, with a few things worth checking first. It runs on 90+ sites and was last updated 4 weeks ago, and scores 63/100 on our health check.
How many websites use Corsen Context?
Corsen Context is active on 90+ WordPress websites and has been downloaded 1,262 times since it launched in July 2026. It was downloaded 886 times in the last 30 days.
Does Corsen Context work with WordPress 7.1?
Corsen Context is officially tested up to WordPress 7.0.6, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
What PHP version does Corsen Context need?
Corsen Context requires PHP 8.0 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Corsen Context last updated?
The latest version, 1.5.16, was released on September 3, 2026 (4 weeks ago).
Who makes Corsen Context?
Corsen Context is developed and maintained by corsenai.
What are the best alternatives to Corsen Context?
The most popular alternatives to Corsen Context are Elementor Website Builder (10M+ installs), All in One SEO (2M+ installs) and AI Agent by SiteGround (1M+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card