Cowboy MCP vs StifLi Flex MCP
What is StifLi Flex MCP?
StifLi Flex MCP is a free WordPress plugin from Andromeda Nova that turns a site into an MCP server with a built-in change log and rollback, and bundles an in-admin AI Chat Agent, an editor Copilot, and scheduled automations that run on your own AI provider key. It is listed in the WordPress.org plugin directory, added in December 2025 and at version 3.4.8 with 1,000+ active installations and a 5-star average from 4 reviews at the time of writing (listing (opens in new tab)). Its readme describes "122+ built-in MCP tools" that can "exceed 200 total tools" once plugin integrations are enabled, 61 of them for WooCommerce (FAQ (opens in new tab)).
Its undo story is the reason it is on this page. The listing positions it as "the only MCP server for WordPress that tracks every change and lets you undo it": every mutating tool call — from an external MCP client, the built-in Chat Agent, the Copilot, or an automation — is recorded with a before/after snapshot, and a Logs & Roll Back admin page offers one-click undo, redo, and a session rollback that reverts a whole conversation in reverse order (listing (opens in new tab)). Five MCP tools expose the same log and rollback to the agent itself (docs (opens in new tab)). Around that core sit OAuth 2.1 with PKCE for ChatGPT and Claude Desktop, eight predefined tool profiles, WordPress Abilities import on 6.9 and later, image and video generation, and a free companion, WP MCP Hub, that routes one AI client to many sites (GitHub (opens in new tab)).
Cowboy MCP also records every change in a per-change undo journal, and adds whole-database checkpoints and an always-on audit log on top. Rather than argue about the word "only", this page lays out what each plugin does, links a source for every claim, and lets you judge; the undo guide covers how undo for AI changes works in WordPress generally.
How do Cowboy MCP and StifLi Flex MCP differ?
The two plugins agree on the premise and differ on the shape of the safety net. Both are free, self-hosted WordPress MCP servers that record AI changes and let you roll them back; Cowboy MCP pairs its undo journal with whole-database checkpoints, safe mode and dry runs on every tool, and a catalogue that reaches WP-CLI, files, users, and the database, while StifLi Flex MCP pairs its change log with an in-admin chat agent, an editor Copilot, and automations, and deliberately keeps user management, plugin installation, and the filesystem out of the agent's reach. Every StifLi Flex MCP claim below links to a primary source.
Last verified: August 2026.
| Attribute | Cowboy MCP | StifLi Flex MCP |
|---|---|---|
| Distribution & price | WordPress.org directory; free under GPL-2.0, every tool included, no paid tier (listing (opens in new tab)) | WordPress.org directory; free under GPLv2 or later; the AI Copilot and Chat Agent are optional add-on layers of the same plugin, run on your own OpenAI, Anthropic, or Google key; no paid tier listed (listing (opens in new tab)) |
| Architecture & endpoint | Native MCP endpoint at /wp-json/cowboy-mcp/v1/endpoint over Streamable HTTP (MCP 2025-06-18); two gateway meta-tools let the agent browse a catalogue instead of loading every schema |
Native server reached through an SSE URL, typically /wp-json/stifli-flex-mcp/v1/sse; implements the 2025-11-25 spec for lifecycle and tools while keeping legacy SSE compatibility (getting started (opens in new tab)) |
| Requirements | WordPress 6.2 or later, PHP 8.0 or later; no Composer or Node.js | WordPress 5.9 or later, PHP 7.4 or later; HTTPS for production OAuth (listing (opens in new tab)) |
| What the agent gets | 168 typed tools across content, Gutenberg and FSE, users, media, menus, plugins and themes, WooCommerce, wp-content files, WP-CLI, database health, and diagnostics, each annotated read-only or destructive |
Vendor claim: "122+ built-in MCP tools", "200+" with integrations, 61 of them for WooCommerce, covering content, media, AI generation, taxonomies, settings, menus, plugins, themes, and site health; the docs say it intentionally excludes user creation or deletion, plugin and theme installation, and option deletion (tools catalog (opens in new tab)) |
| Per-change undo | Undo journal captures the before-state for posts, terms, comments, users, options, menus, media files, WooCommerce objects, ACF and SEO meta, wp-content files, and plugin and theme packages; undone from the Activity tab or wp_undo_change; undo is itself journaled, so it can be redone; kept 7 days by default |
Change log stores source, tool, and before/after state for every AI mutation; one-click rollback "when a before state is available", redo, and session rollback in reverse order; deleted media files are backed up; 5 MCP tools expose it to the agent; automatic purge, retention not stated (docs (opens in new tab)) |
| Whole-site rollback | One-click database checkpoints — a prefix-scoped SQL dump with atomic restore — taken automatically before mutating WP-CLI commands and plugin or theme updates; updates also keep a backup zip and health-check after the swap | Session rollback reverts a conversation's changes entry by entry; no database checkpoint or site-wide snapshot is described (listing (opens in new tab)) |
| Guardrails | Safe mode confirmation on destructive tools (on by default), dry_run on every writing tool, per-credential read-only or custom scope, protected-option denylist, WP-CLI command blocklist, SSRF validation, last-administrator and self-delete protection, Power mode opt-in |
Eight predefined tool profiles plus custom ones, per-tool WordPress capability checks, option-write denylist, secret redaction, SSRF protection, 30 requests per minute per IP; "Ask User" confirmations apply to the built-in Chat Agent; a validate-only dry run on its CSS tools (changelog (opens in new tab)) |
| Audit log | Always-on audit log of every tool call, error, and auth event, filterable in the Logs tab, auto-pruned after 30 days, readable by the agent | Logs & Roll Back page with filters, search, detail view, and CSV export; mcp_get_changelog tool; optional debug log file (listing (opens in new tab)) |
| Auth & connection | Hashed API key shown once, 120 requests a minute per key, scopable to read-only or a tool list; or the one-click OAuth connector for the Claude apps and ChatGPT (off by default); Claude Desktop on local sites via an mcp-remote bridge, with a Connection Doctor |
OAuth 2.1 with PKCE, dynamic client registration, RFC 9728 and 8414 discovery, tokens auto-refreshed for up to 90 days, a .mcpb bundle for Claude Desktop; Application Passwords as an HTTP Basic fallback (FAQ (opens in new tab)) |
| Clients named | Claude Code, Codex, Opencode, the Claude desktop and web apps, Cursor, Windsurf, Cline, Zed, VS Code, ChatGPT, Gemini, n8n | Claude Desktop, ChatGPT, LibreChat, Cursor, Cline, Roo Code, Windsurf, Claude Code; in-admin: OpenAI, Anthropic, Google, plus OpenRouter and Mistral through the WordPress AI Client (listing (opens in new tab)) |
| Integrations | WooCommerce (40 tools), Gutenberg and FSE (15 block, pattern, template, global-style, and navigation tools), ACF, Elementor, Wordfence, Yoast SEO, Rank Math, WP Rocket, LiteSpeed Cache, W3 Total Cache, forms detection | WooCommerce, ACF, Yoast SEO, Rank Math, Elementor, WPForms, Gravity Forms, Forminator, The Events Calendar, WPCode, Code Snippets, Woody Snippets, Google Search Console, All Sources Images, AiPatch Security Scanner, Telegram notifications, Abilities API import (listing (opens in new tab)) |
| In-admin chat or Copilot | None — Cowboy MCP is just the server; you bring your own MCP client | AI Chat Agent page, a floating Copilot inside the Gutenberg and Classic editors, scheduled and event automations, image and video generation, all on your own provider key (listing (opens in new tab)) |
| Live Preview | Yes — a WordPress Playground preview on the directory listing (try it (opens in new tab)) | No Live Preview on the listing at the time of writing (listing (opens in new tab)) |
Both sit on the self-hosted side of the comparison hub: the plugin is the server, the credentials live in your own database, and nothing routes through a vendor cloud. What separates them is how much the agent can touch, what stands between a bad instruction and a broken site, and whether you want the AI client bundled inside wp-admin or brought from outside.
When is StifLi Flex MCP the better choice?
StifLi Flex MCP earns the pick when you want the assistant inside WordPress, not just a server for one outside it. StifLi Flex MCP is the better choice when you want an in-admin chat agent and an editor Copilot on your own provider key, scheduled or event-driven AI automations, and a tool catalogue that stays away from users, plugin installation, and the filesystem by design. The same plugin that serves ChatGPT and Claude Desktop over OAuth gives a content team a writing assistant in the editor and an agency a Logs & Roll Back page to review after every session.
It is a strong fit for sites on older stacks — WordPress 5.9 and PHP 7.4 are supported — for teams that want image and video generation and stock-image search wired into the agent, for snippet-based customisation through WPCode or Code Snippets, and for anyone who prefers a narrower, role-checked toolset over terminal-level access. The tradeoffs follow from the same design: rollback is entry by entry with no whole-database checkpoint, confirmations live in the built-in agent rather than on the MCP endpoint, dry runs are limited to the CSS tools, and there is no WP-CLI, file, user, or database-repair tooling for the day the agent needs to fix a broken site rather than edit a working one.
When is Cowboy MCP the better choice?
Cowboy MCP is the stronger pick when the agent operates the whole site — content, store, back office, and the parts that break. Cowboy MCP is the better choice when you want per-change undo and database checkpoints behind every tool, safe mode and dry runs on the endpoint itself, and a catalogue that reaches WP-CLI, files, users, plugin updates, and diagnostics without a paid tier. It gives the agent 168 typed tools and lets it roll back a single edit or restore the entire database.
Its undo journal covers content, options, users, menus, media files, WooCommerce objects, SEO meta, and plugin and theme updates, which keep a backup zip and health-check themselves after the swap; database checkpoints are taken automatically before WP-CLI mutations and updates and restored in one click. Safe mode and dry_run apply to every client that connects, not just a bundled chat, and each API key or OAuth connection can be scoped to read-only or a hand-picked tool list, as the security page lays out. It installs and updates from WordPress.org (opens in new tab), runs on WordPress 6.2 and later, works first-class on local development sites, and is free under GPL-2.0 with every integration included. The WordPress MCP overview has the full tool map.
Can you run both at the same time?
Installing both is a valid setup rather than a conflict. Cowboy MCP and StifLi Flex MCP are independent plugins with separate endpoints, settings, tokens, and change logs, so they can coexist on one site — the natural split is StifLi Flex MCP for the in-admin Chat Agent, Copilot, and automations, and Cowboy MCP as the server your outside agents connect to. Each records just the changes made through its own tools, so a change made through one cannot be undone from the other.
In practice a content editor uses the Copilot in Gutenberg and keeps or undoes its suggestions there, while Claude Code or Cursor connects to the Cowboy MCP endpoint to publish, run the store, update plugins, and fix what breaks, with every change in Cowboy's journal and a checkpoint before the risky parts. If you would rather audit one rollback trail, pick one plugin and route every client through it. Neither relays traffic through a vendor server, so running both adds no new data path, just a second set of credentials to revoke when you are done.
FAQ
Is Cowboy MCP a good StifLi Flex MCP alternative?
Yes. Both are free, self-hosted WordPress MCP servers with rollback. Cowboy MCP gives the agent 168 typed tools including WP-CLI, files, users, plugin updates, and diagnostics, with safe mode, dry runs, a per-change undo journal, one-click database checkpoints, and an always-on audit log, and it runs on WordPress 6.2 and later. StifLi Flex MCP bundles an in-admin chat agent, editor Copilot, and automations that Cowboy MCP does not have.
Do both Cowboy MCP and StifLi Flex MCP undo AI changes?
Yes, in different shapes. StifLi Flex MCP records a before/after snapshot for each AI mutation and offers one-click rollback, redo, and session rollback from its Logs & Roll Back page, with five MCP tools for the agent. Cowboy MCP records a before-state for each change in an undo journal that the Activity tab or the wp_undo_change tool can revert, and adds whole-database checkpoints taken automatically before WP-CLI mutations and plugin or theme updates, so you can undo one edit or restore the entire site.
Is StifLi Flex MCP free?
Yes. StifLi Flex MCP is free and GPLv2 or later on the WordPress.org directory, and its listing describes no paid tier. The AI Chat Agent and AI Copilot are optional add-on layers of the same plugin that run on your own OpenAI, Anthropic, or Google API key, so you pay the provider for usage. Cowboy MCP is also free, under GPL-2.0, with every tool and integration included and no Pro tier.