Description
Corsen Context publishes a bounded overview of selected public WordPress content and provides a read-only JSON-RPC endpoint for compatible MCP clients.
What it does
Your site gets two new capabilities:
-
Static Layer — Generates
/llms.txtwith a structured overview of selected public content. An optional, bounded/llms-full.txtexport can be enabled in settings. -
Dynamic Layer — Exposes a read-only Model Context Protocol (MCP) Streamable HTTP-style endpoint at
/wp-json/corsen-context/v1/mcpwith four content tools.
Key Features
- Safe defaults —
/llms.txtand the read-only endpoint are enabled; the heavier/llms-full.txtexport is opt-in. - MCP 2025-11-25 target — Supports
initialize,ping,tools/list,tools/call,resources/list,resources/read, andnotifications/initialized. The endpoint returns JSON responses and does not provide server-sent event streaming. - 4 AI tools —
search_site,get_page_content,list_content,get_sitemap. - SEO integration — Reads Yoast SEO and Rank Math metadata for better descriptions.
- Security built-in — Rate limiting, SSRF protection, input validation, security headers, optional API key auth.
- Admin settings page — Choose post types, exclude paths, set rate limits, toggle features.
- Dashboard widget — See your AI context status at a glance.
- Bounded generation — Total item and output-byte limits protect the optional full-content export.
- Content safety — Drafts, private posts, password-protected posts, excluded paths, and content vetoed by the exposure filter are not served.
- Credit line — « Powered by Corsen Context » in generated files (configurable).
Published Endpoints and Discovery Hints
When enabled, Corsen Context publishes:
- robots.txt —
MCP: https://yoursite.com/wp-json/corsen-context/v1/mcp - llms.txt — The credit line includes the MCP endpoint URL
- HTML head —
<link rel="mcp">meta tag added automatically - Direct URL —
/llms.txtremains available to clients that know the convention
These discovery hints are not universal standards and do not guarantee that a search engine or AI client will use the endpoint.
Requirements
- WordPress 6.0 or higher
- PHP 8.0 or higher
- Pretty permalinks enabled (Settings > Permalinks > anything except « Plain »)
Part of a Bigger Ecosystem
Corsen Context is an open-source project by Corsen AI. The project also provides packages for Next.js, Express, Astro, and Node.js. WordPress uses this dedicated PHP plugin.
Installation
From WordPress.org (recommended)
- Go to Plugins > Add New in your WordPress admin
- Search for « Corsen Context »
- Click « Install Now » then « Activate »
- Done! Visit Settings > Corsen Context to customize.
Manual Installation
- Download the plugin ZIP from GitHub Releases
- Go to Plugins > Add New > Upload Plugin
- Upload the ZIP file and activate
- Configure at Settings > Corsen Context
After Activation
Your site immediately has:
/llms.txt— Visithttps://yoursite.com/llms.txtto see it/llms-full.txt— Optional bounded content export (enable it in Settings > Corsen Context)- MCP endpoint —
https://yoursite.com/wp-json/corsen-context/v1/mcp - Dashboard widget — Check your admin dashboard
Important: Make sure pretty permalinks are enabled (Settings > Permalinks).
FAQ
-
What is MCP?
-
Model Context Protocol is an open protocol for communication between AI applications and external systems. Corsen Context targets the 2025-11-25 protocol version for its read-only JSON-RPC endpoint.
-
What is llms.txt?
-
A proposed convention where websites place a
/llms.txtfile containing a structured Markdown overview. Support varies by client and search engine, so it should be treated as an additional publishing surface rather than an indexing guarantee. -
Is my content safe?
-
The plugin limits output to selected public post types and rejects draft, pending, private, password-protected, trashed, or excluded content. Site owners can also veto individual posts with the
corsen_context_can_expose_postfilter. As with any public export, review the selected post types and exclusions before enabling it on a site with membership or conditional-visibility plugins. -
Does this slow down my site?
-
Normal pages only receive a small discovery link when MCP is enabled. Generated metadata may use bounded WordPress transients for anonymous, cookie-free requests. Rendered page content is not placed in the shared MCP cache, and
/llms-full.txtuses item, byte, and generation-lock limits. -
Does it work with page builders?
-
By default, Corsen Context reads stored public content without executing
the_content, dynamic blocks, or shortcodes. This avoids accidentally exporting personalized output. Site owners can opt into full rendering with thecorsen_context_render_modefilter; full-rendered output is never stored in the shared content cache. Compatibility depends on the page builder and should be tested on the site. -
Can I control which content is exposed?
-
Yes. In Settings > Corsen Context you can:
- Choose which post types to include (pages, posts, products, custom types)
- Exclude specific URL paths
- Disable MCP, llms.txt, or the entire plugin
-
Does it work with WooCommerce?
-
Yes. Enable the « Products » post type in settings and your WooCommerce products will be included in llms.txt and available through the MCP tools.
-
How do I protect the MCP endpoint?
-
You can set an API key by defining
CORSEN_CONTEXT_API_KEYin yourwp-config.php:define('CORSEN_CONTEXT_API_KEY', 'your-secret-key-here');Requests must then include
X-MCP-Key: your-secret-key-hereheader. -
Can I remove the credit line?
-
Yes. Uncheck « Show Credit » in Settings > Corsen Context. However, the credit helps grow the open-source ecosystem and we appreciate keeping it enabled.
Avis
Il n’y a aucun avis sur cette extension.
Contributeurs & développeurs
« Corsen Context » est un logiciel libre. Les personnes suivantes ont contribué à cette extension.
ContributeursTraduisez « Corsen Context » dans votre langue.
Le développement vous intéresse ?
Parcourir le code, consulter le SVN dépôt, ou s’inscrire au journal de développement par RSS.
Historique des changements
1.2.1 – 2026-07-21
- Security: Enforced the global kill switch across llms.txt, llms-full.txt, MCP routes, discovery tags, and dashboard state.
- Security: Safe rendering no longer executes
the_content, dynamic blocks, or shortcodes by default; full rendering is explicit opt-in and never shared-cacheable. - Security: Added same-origin browser checks, HMAC cache/rate-limit keys, conservative path normalization, Markdown URL neutralization, and an exposure veto filter.
- Security: Disabled llms-full.txt by default and added global item, byte, cache-safety, regeneration-lock, and background-generation controls.
- Privacy: Author display names are omitted by default and can be enabled separately.
- MCP: Added protocol-version validation, 202 notification responses, GET/POST transport handling, bounded resources pagination, signed cursors, and prompt-injection trust-boundary notices.
- Quality: Added PHP unit/integration tests and made WordPress coding standards blocking in CI.
- Documentation: Replaced unsupported universal-discovery, zero-overhead, page-builder, and full-compliance claims with precise behavior and limitations.
- Routing: Keeps
/llms.txtand/llms-full.txtfree of canonical trailing-slash redirects and refreshes rewrite rules once per plugin version.
1.2.0 – 2026-07-13
- Security: Rate limiter now uses REMOTE_ADDR by default; forwarding headers (X-Forwarded-For/X-Real-IP) are only trusted behind a proxy you opt into via CORSEN_CONTEXT_TRUST_PROXY. Closes a spoofable rate-limit bypass.
- Security: Rate limiter uses the object cache’s atomic INCR when a persistent cache (Redis/Memcached) is present, preventing burst overshoot.
- Security: Rate limiting now runs before authentication, so the API key can’t be brute-forced unthrottled.
- Security: resources/read and get_page_content now validate the URI resolves to a same-site, non-excluded, http(s) URL before returning content.
- Security: Settings sanitization restricts post types to publicly-registered types.
- Performance: MCP tool responses are cached (transients) and invalidated when content changes — bounds compute on the public endpoint.
- Fix: resources/list preserves query strings in resource URIs (parity with the core library).
- Improvement: Configurable enabled tool set via the corsen_context_enabled_tools filter.
- Improvement: Loads the plugin text domain so strings are translatable.
- Improvement: Uninstall now also clears cached MCP response transients.
1.1.0 – 2026-04-12
- Security: SSRF protection now fails closed when DNS resolution fails
- Security: Fixed PHP ReDoS crash on large HTML payloads (preg_replace null safety)
- Security: Fixed rate limiter TTL renewal bug that converted per-minute into per-session limits
- Fix: Added max_pages setting to admin UI (was only configurable in code)
- Fix: Uninstall now cleans up all rate-limit transients from database
- Improvement: Added hourly WP-Cron garbage collector for expired rate-limit transients
- Improvement: Better rate limit window tracking with remaining TTL preservation
1.0.0 – 2026-04-08
- Initial release
- Read-only MCP-style JSON-RPC endpoint with 4 tools
initialize,ping,notifications/initializedsupporttools/list,tools/call,resources/list,resources/read- llms.txt and llms-full.txt generation with auto-caching
- Admin settings page with post type selection and path exclusion
- Dashboard widget showing AI context status
- Yoast SEO and Rank Math metadata integration
- Rate limiting (configurable, default 100 req/min)
- SSRF protection blocking all private IP ranges
- Security headers on all responses
- Optional API key authentication (timing-safe comparison)
- Cache invalidation on post save/delete
<link rel="mcp">meta tag in HTML head- Clean uninstall (removes all options and transients)