A longer security list vs a single free tier

Agent Abilities vs miniOrange Secure MCP Server

Of everything we compare against, miniOrange Secure MCP Server is the closest to us in shape. It runs on your own site, it builds on the WordPress 6.9 Abilities API, and its listing says every MCP request runs as a genuine WordPress user account so core capability checks apply. That is our own model in their words. So this comparison is narrower than the others. It comes down to what each of us advertises on top of that model, how much an agent can reach, and whether there is a paid plan above the free one.

Summary and contents

The short version

Both are real WordPress MCP plugins. miniOrange and Agent Abilities weigh differently, so this is a priorities decision, not a better-or-worse one.

In common
Both install free from WordPress.org, both build on the WordPress 6.9 Abilities API, both run the agent as a real WordPress user with core capability checks, both let you switch tools on and off one at a time, both keep an activity log, and neither puts a service of its own between the agent and your site.
miniOrange wins on
A much larger advertised catalog, a security feature list well past ours, and five times the installs.
Agent Abilities wins on
One free tier with nothing above it, every ability off until you switch it on, a narrower write surface, and published counts that agree with each other.
miniOrange today
400+ active installs, 2 ratings (WordPress.org, checked 21 August 2026)

What each one optimizes for

The two plugins pull in different directions on purpose. Here is the honest shape of each.

miniOrange sells identity and access management for a living, and the plugin reads like it. The listing advertises more than 300 tools across content, WooCommerce, Yoast SEO, users, comments, three form plugins and site administration, wrapped in self-hosted OAuth 2.1 with PKCE and role-based ability policies they call an NHI Registry. Above that sits a set of controls we do not attempt at all: human approvals on risky actions, data rules and DLP, prompt-injection detection, behavioral anomaly detection, agent reputation scoring, multisite policy and ready-made policy templates. Their pricing page measures the paid plan against enterprise AI security platforms rather than against other WordPress plugins, which tells you who they are aiming at.

Agent Abilities sells governance. Nothing is exposed until you switch it on, the agent connects as a real WordPress user with only that user's permissions, every call is re-checked and written to an audit log in your own database, and the plugin makes no outbound calls of its own. If a tight, auditable boundary around the agent is what you want, that is the trade this plugin makes.

Neither approach is wrong. The rest of this page lays out the specifics, including where miniOrange genuinely reaches further than we do.

Side by side

Their claims are quoted from the WordPress.org listing and the miniOrange pricing page at plugins.miniorange.com/mcp-server-ai-policy-enforcement-wordpress, verified 21 August 2026, and stated as their claims. Ours trace to the plugin readme.

DimensionminiOrange Secure MCP ServerAgent Abilities
PriceA Free plan at 0 USD and a Premium plan their pricing page lists as starting at 249 USD a month, sold through a Contact Us form rather than a checkoutFree on WordPress.org. No paid tier, no API key to buy, no usage limits.
Default postureTheir 1.4.0 changelog says core content, users and comments abilities are "always available", and that the sets for WooCommerce, ACF, Yoast and the form plugins "activate automatically when those plugins are present". Every tool then carries a global on and off toggle, so narrowing is something you do afterwardsOff by default. You enable one ability at a time; an update never widens access on its own.
Agent connects asA real WordPress user. Their listing says every MCP request runs as a genuine WordPress user account, over self-hosted OAuth 2.1 with PKCE, or with an API key for automationA real WordPress user, never a key this plugin mints with a scope of its own. With an Application Password you point it at the dedicated low-privilege user the plugin creates for you. Over OAuth it takes the capabilities of whichever account approves in the browser, so approve as the account you want it limited to.
Capability checkYes, and described the way we describe ours: because the request runs as a real WordPress user, core capability checks apply. Role-based ability policies sit on top of thatTwo layers: a connection only sees the tools its user can run, and WordPress itself re-checks that user’s capability before every call.
Audit logYes. Their listing says every MCP tool call, OAuth grant and ability change is logged and searchableEvery call, denials included, with the principal, the argument keys, and the identifiers it touched but never free-text content, in your own database.
Rate limitAdvertised as rate limits and quotas per agentOptional, per minute. Off until you set it.
Approvals, DLP and threat detectionAdvertised: human approvals on risky actions, data rules and DLP, prompt-injection detection, behavioral anomaly detection, agent reputation scoring, multisite policy and pre-built policy templatesNone of it. We govern who may call what, and we record what was called. We do not inspect prompts, score agents, or hold an action for sign-off.
Reach of the write surfaceWider, by their own listing: activating, deactivating, deleting and updating plugins, resetting passwords, invalidating sessions, deleting users, and writing site settingsNarrower on purpose. We can list installed plugins and never activate, deactivate or change one. Site settings are a short allowlist that can never reach the site URL, admin email or default role. Deletes go to Trash where WordPress supports it, and the last administrator can never be removed.
Tool catalogAdvertises more than 300 MCP tools. The 1.4.0 changelog on the same listing calls the bundled library 260-plus abilities153 governed abilities (83 core, 70 integration), plus a bridge for abilities other active plugins register.
AI clientsClaude.ai, Claude Desktop, Claude Code, ChatGPT, Cursor, Windsurf, Gemini CLI, Google Antigravity and n8n, per their listing9 today, including ChatGPT, Claude.ai, and Manus through custom connectors. The Gemini app is not supported yet, stated plainly.
Outbound callsTheir pricing page says call logs, policy configuration and audit records live entirely on your WordPress installation and that miniOrange does not access, relay or process any of it. Their comparison table says a Node.js or external service is never neededZero outbound calls of any kind. No connectors, no telemetry. Nothing leaves your site on the plugin’s initiative.
Business modelA free plugin from an identity and access management vendor, with a Premium plan quoted on enquiryOpen source. No affiliate links, no agency upsell, no partner directory shown to your users.
Vendor in the chainNo service of theirs in the data path, which matches ours. What sits above the free plugin is a commercial plan, not a relayNothing between the agent and WordPress belongs to a vendor. No token of ours carrying its own scope, no service of ours in the path, and no licence that can lapse and stop your automation.
Install base400+ active installs and 2 ratings, listed June 2026Smaller. WordPress.org showed 100+ active installs and 2 ratings for us (checked 29 August 2026). They are ahead of us on reach.

Where miniOrange leads

Said plainly, because pretending otherwise would not help you decide.

Controls we have not built

Human approvals before a risky action runs, data rules and DLP that keep emails and secrets away from the model, prompt-injection detection, behavioral anomaly detection, agent reputation scoring, dry-run policy simulation, multisite policy and ready-made policy templates. We have none of these, and we are not going to pretend the list is decoration. If what worries you is an agent being manipulated or drifting over time, they have built for that and we have not.

A far bigger catalog

They advertise more than 300 tools, including 45 for WooCommerce, 8 for Yoast SEO, and 40 across Contact Form 7, WPForms and Gravity Forms. We ship 153. Our WooCommerce coverage is actually a little deeper at 52, but across the whole catalog they are well ahead, and we have no form plugin coverage at all.

More installs, and an identity vendor behind it

WordPress.org showed 400+ active installs for them (checked 21 August 2026) against our 100+ (checked 29 August 2026), both of us on 2 ratings. miniOrange has been selling identity and access management for years, and the OAuth 2.1 work in this plugin reads like it.

The same identity model, so it is not our edge

Their listing says every MCP request runs as a genuine WordPress user account, so all core capability checks apply. That is our model, stated in their words. Per-tool toggles and building on the WordPress 6.9 Abilities API are shared too. On the things this site used to lead with, we do not lead here, and saying so is more useful to you than a claim you could check in a minute.

The trade-offs in miniOrange

Real, evidenced trade-offs a security-minded owner would weigh. Not a knock, just the other side of their design.

Trade-off

Where the free plan stops is unclear from their own pages

Their WordPress.org listing says role-based AI permissions, per-tool on and off, self-hosted OAuth 2.1 and full activity logs are "all included, with no restrictions". Their pricing page lists Role Based Policy Enforcement and Audit Trails under the Premium plan instead. Those may well be different features wearing similar names, and we are not going to settle it for them. The point is that you cannot tell from the outside which controls a free install keeps, so ask them before you plan around it. Both pages checked 21 August 2026.

Trade-off

Their own counts disagree

The listing headline says 300-plus MCP tools. The 1.4.0 changelog further down the same page calls the bundled library 260-plus abilities. Ours come from one place, so they cannot contradict each other. It is a small thing, and it is still the kind of small thing worth noticing on a plugin you are handing an agent.

Trade-off

On first, narrowed afterwards

Per their changelog, core content, users and comments abilities are always available, and integration sets switch on by themselves when their host plugin is present. The per-tool toggle then lets you turn things off. Ours starts at nothing and only widens when you choose. Both can end up in a sensible place, but the default is what most sites will actually run.

Trade-off

A wider write surface

Their listing includes activating, deactivating, deleting and updating plugins, resetting passwords, invalidating sessions and deleting users. They have hardened parts of it, and their 1.4.0 notes say reserved user-meta keys can never be read or written and role grants are capped at what the caller already holds. It is still more ground for a bad call to reach. We can list plugins and never change one.

Where Agent Abilities leads

The governance thesis, which is the reason to pick this plugin over a broader one.

Off by default

Every ability starts disabled. You open access one toggle at a time, and an update never widens it on its own.

Least-privilege identity

The agent connects as a real WordPress user through OAuth or an Application Password, never an admin-equivalent key. It takes that account’s capabilities, so you decide its reach by choosing which account approves the connection.

Two-layer capability gating

A connection only sees the tools its user can run, and the capability is re-checked before every call.

Zero outbound, single-sourced facts

No connectors, no telemetry, and every number on this site comes from one source so it never contradicts itself.

Where Agent Abilities falls short

The honest other side. If one of these matters most to you, miniOrange may be the better fit.

Where we fall short

A much smaller catalog

We ship 153 governed abilities plus the bridge, against their advertised 300-plus. We have nothing for Contact Form 7, WPForms or Gravity Forms, where they claim 40 tools, and our Yoast integration is 3 abilities against their 8. If your work lives in form entries, they cover ground we do not.

Where we fall short

None of the threat controls

No approval step at the moment of the call, no DLP, no prompt-injection detection, no anomaly detection, no agent reputation scoring, no multisite policy. If you want the agent itself watched rather than just bounded, they advertise all of that and we offer none of it.

Where we fall short

Far fewer installs

WordPress.org showed 400+ active installs for them on 21 August 2026 and 100+ for us on 29 August 2026. Both of us sit on 2 ratings, so neither has much review history, but more sites have tried theirs.

Where we fall short

A narrower job by design

No plugin management, no password resets, no session invalidation, no arbitrary settings writes. We chose that boundary and we would choose it again, and it does mean there is less an agent can do for you here.

Which should you choose

A short, honest rule of thumb.

Reach for miniOrange Secure MCP Server if what it leads on maps to your priorities: a much larger advertised catalog, a security feature list well past ours, and five times the installs.

Reach for Agent Abilities if you want an agent that starts with zero access, connects as a real WordPress account you choose rather than an admin key, is audited on every call including refusals, and makes no outbound requests. Governance and a tight boundary are the point.

Both are free, so the lowest-risk move is to install the one whose default matches how you want to start. See what a governed WordPress MCP server is, or read the governance model.

Frequently asked questions

Direct answers about how the two compare.

Is Agent Abilities for MCP a free alternative to miniOrange Secure MCP Server?

Both install free from WordPress.org. The difference is what sits above that. miniOrange also sells a Premium plan its pricing page lists as starting at 249 USD a month, quoted on enquiry. We have one tier and nothing above it. Their WordPress.org listing and their pricing page do not agree on which controls a free install keeps, so ask them before you plan around it. Checked 21 August 2026.

Which one has better security controls?

On paper theirs is the longer list, and we will say so plainly. miniOrange advertises human approvals before risky actions, data rules and DLP, prompt-injection detection, behavioral anomaly detection and agent reputation scoring. We have none of those. What we do instead is keep every ability off until you switch it on, run the agent as a WordPress user whose capability is re-checked on every call, log denials as well as successes, and keep the write surface narrow enough that a bad call cannot reach your plugins, your passwords or your sessions. Their listing describes the same capability model we use, so identity is not the difference. Breadth of protection against reach of the tools is.

Do both plugins keep my data on my own site?

Yes, by both accounts. Their pricing page says call logs, policy configuration and audit records live entirely on your WordPress installation and that miniOrange does not access, relay or process any of it, and their comparison table says a Node.js or external service is never needed. We make no outbound calls of any kind. Neither of us puts a relay in the path, which is not true of every plugin in this category.

Which should I choose?

Choose miniOrange if you want approvals, DLP and prompt-injection detection, if you need their form plugin or Yoast coverage, or if a paid support relationship matters to you. Choose Agent Abilities for MCP if you want one free tier with nothing above it, everything off until you turn it on, a write surface that stops at content and data, and published numbers that agree with each other.

Comparison based on each product's public documentation. miniOrange Secure MCP Server claims were verified against the WordPress.org listing and the miniOrange pricing page at plugins.miniorange.com/mcp-server-ai-policy-enforcement-wordpress in 21 August 2026 and are stated as their claims; their product may have changed since. Agent Abilities for MCP facts come from its own readme. Agent Abilities for MCP is not affiliated with, or endorsed by, miniOrange Secure MCP Server.

Start with everything off.

Install Agent Abilities for MCP, keep every ability disabled, and turn on one at a time. Requires WordPress 6.9+ and PHP 7.4+. Free on WordPress.org.

Off by default, least privilege, and nothing leaves your site without you.