Skip to content

MCP in Lite - #3294

Open
Crabcyborg wants to merge 34 commits into
masterfrom
mcp
Open

Crabcyborg wants to merge 34 commits into
masterfrom
mcp

Conversation

@Crabcyborg

@Crabcyborg Crabcyborg commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Pro functionality https://github.com/Strategy11/formidable-pro/pull/6580
Views functionality https://github.com/Strategy11/formidable-views/pull/751
Landing pages functionality https://github.com/Strategy11/formidable-landing/pull/57
Coupons functionality https://github.com/Strategy11/formidable-coupons/pull/33
Logs functionality https://github.com/Strategy11/formidable-logs/pull/61
WPML functionality https://github.com/Strategy11/formidable-wpml/pull/155

Related MCP Skill update Strategy11/formidable-mcp-skill#7

API add-on compatibility https://github.com/Strategy11/formidable-api/pull/237

Lite includes the following abilities:

DOMAIN         #   ABILITIES
forms          5   list-forms  get-form  create-form  update-form  delete-form
fields         4   list-fields  create-field  update-field  delete-field
entries        3   list-entries  get-entry  delete-entry
styles         3   list-styles  get-style  update-style
form-actions   5   list-form-actions  get-form-action  create-form-action update-form-action  delete-form-action
payments       4   list-payments  get-payment  delete-payment  refund-payment
subscriptions  4   list-subscriptions  get-subscription  delete-subscription  cancel-subscription

@coderabbitai

coderabbitai Bot commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Too many files!

This PR contains 345 files, which is 245 over the limit of 100.

To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.

Upgrade to a paid plan to raise the limit.

Usage-priced reviews support at most 300 files.

⚙️ Run configuration

Configuration used: Repository: Strategy11/formidable-forms/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 91737874-2d96-4aeb-bfc8-a6273dee201b

📥 Commits

Reviewing files that changed from the base of the PR and between 6b58fff and 063b942.

⛔ Files ignored due to path filters (4)
  • images/icons.svg is excluded by !**/*.svg
  • images/mcp-claude.svg is excluded by !**/*.svg
  • images/mcp-codex.svg is excluded by !**/*.svg
  • images/mcp-cursor.svg is excluded by !**/*.svg
📒 Files selected for processing (345)
  • .github/workflows/syntax.yml
  • .gitignore
  • _typos.toml
  • bin/zip-plugin.sh
  • classes/controllers/FrmAbilitiesController.php
  • classes/controllers/FrmAbilitiesEntriesController.php
  • classes/controllers/FrmAbilitiesFieldsController.php
  • classes/controllers/FrmAbilitiesFormActionsController.php
  • classes/controllers/FrmAbilitiesFormsController.php
  • classes/controllers/FrmAbilitiesPaymentsController.php
  • classes/controllers/FrmAbilitiesStylesController.php
  • classes/controllers/FrmAbilitiesSubscriptionsController.php
  • classes/controllers/FrmHooksController.php
  • classes/controllers/FrmMcpController.php
  • classes/controllers/FrmMcpMissingAbilityController.php
  • classes/controllers/FrmMcpSettingsController.php
  • classes/controllers/FrmMcpSkillEnvController.php
  • classes/controllers/FrmMcpUsageController.php
  • classes/helpers/FrmAbilitiesHelper.php
  • classes/models/FrmMcpAbilityRegistry.php
  • classes/models/FrmMcpCompat.php
  • classes/models/FrmMcpConnection.php
  • classes/models/FrmSettings.php
  • classes/models/FrmStyle.php
  • classes/views/frm-settings/mcp.php
  • css/frm_admin.css
  • css/frm_testing_mode.css
  • js/admin/settings.js
  • js/formidable-web-components.js
  • js/formidable_admin.js
  • js/src/web-components/frm-border-radius-component/frm-border-radius-component.css
  • js/src/web-components/frm-colorpicker-component/frm-colorpicker-component.css
  • js/src/web-components/frm-dropdown-component/frm-dropdown-component.css
  • js/src/web-components/frm-range-slider-component/frm-range-slider-component.css
  • js/src/web-components/frm-tab-navigator-component/frm-tab-navigator-component.css
  • js/src/web-components/frm-typography-component/frm-typography-component.css
  • lib/composer.json
  • lib/vendor/autoload.php
  • lib/vendor/automattic/jetpack-autoloader/LICENSE.txt
  • lib/vendor/automattic/jetpack-autoloader/src/AutoloadFileWriter.php
  • lib/vendor/automattic/jetpack-autoloader/src/AutoloadGenerator.php
  • lib/vendor/automattic/jetpack-autoloader/src/AutoloadProcessor.php
  • lib/vendor/automattic/jetpack-autoloader/src/CustomAutoloaderPlugin.php
  • lib/vendor/automattic/jetpack-autoloader/src/ManifestGenerator.php
  • lib/vendor/automattic/jetpack-autoloader/src/autoload.php
  • lib/vendor/automattic/jetpack-autoloader/src/class-autoloader-handler.php
  • lib/vendor/automattic/jetpack-autoloader/src/class-autoloader-locator.php
  • lib/vendor/automattic/jetpack-autoloader/src/class-autoloader.php
  • lib/vendor/automattic/jetpack-autoloader/src/class-container.php
  • lib/vendor/automattic/jetpack-autoloader/src/class-hook-manager.php
  • lib/vendor/automattic/jetpack-autoloader/src/class-latest-autoloader-guard.php
  • lib/vendor/automattic/jetpack-autoloader/src/class-manifest-reader.php
  • lib/vendor/automattic/jetpack-autoloader/src/class-path-processor.php
  • lib/vendor/automattic/jetpack-autoloader/src/class-php-autoloader.php
  • lib/vendor/automattic/jetpack-autoloader/src/class-plugin-locator.php
  • lib/vendor/automattic/jetpack-autoloader/src/class-plugins-handler.php
  • lib/vendor/automattic/jetpack-autoloader/src/class-shutdown-handler.php
  • lib/vendor/automattic/jetpack-autoloader/src/class-version-loader.php
  • lib/vendor/automattic/jetpack-autoloader/src/class-version-selector.php
  • lib/vendor/composer/ClassLoader.php
  • lib/vendor/composer/InstalledVersions.php
  • lib/vendor/composer/LICENSE
  • lib/vendor/composer/autoload_classmap.php
  • lib/vendor/composer/autoload_namespaces.php
  • lib/vendor/composer/autoload_psr4.php
  • lib/vendor/composer/autoload_real.php
  • lib/vendor/composer/autoload_static.php
  • lib/vendor/composer/installed.json
  • lib/vendor/composer/installed.php
  • lib/vendor/composer/platform_check.php
  • lib/vendor/wordpress/mcp-adapter/.gitignore
  • lib/vendor/wordpress/mcp-adapter/LICENSE.md
  • lib/vendor/wordpress/mcp-adapter/includes/Abilities/DiscoverAbilitiesAbility.php
  • lib/vendor/wordpress/mcp-adapter/includes/Abilities/ExecuteAbilityAbility.php
  • lib/vendor/wordpress/mcp-adapter/includes/Abilities/GetAbilityInfoAbility.php
  • lib/vendor/wordpress/mcp-adapter/includes/Abilities/McpAbilityExposure.php
  • lib/vendor/wordpress/mcp-adapter/includes/Abilities/McpAbilityHelperTrait.php
  • lib/vendor/wordpress/mcp-adapter/includes/Autoloader.php
  • lib/vendor/wordpress/mcp-adapter/includes/Cli/McpCommand.php
  • lib/vendor/wordpress/mcp-adapter/includes/Cli/StdioServerBridge.php
  • lib/vendor/wordpress/mcp-adapter/includes/Core/McpAdapter.php
  • lib/vendor/wordpress/mcp-adapter/includes/Core/McpComponentRegistry.php
  • lib/vendor/wordpress/mcp-adapter/includes/Core/McpServer.php
  • lib/vendor/wordpress/mcp-adapter/includes/Core/McpTransportFactory.php
  • lib/vendor/wordpress/mcp-adapter/includes/Core/McpVersionNegotiator.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Contracts/McpComponentInterface.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Prompts/Contracts/McpPromptBuilderInterface.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Prompts/McpPrompt.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Prompts/McpPromptBuilder.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Prompts/McpPromptValidator.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Prompts/RegisterAbilityAsMcpPrompt.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Resources/McpResource.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Resources/McpResourceValidator.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Resources/RegisterAbilityAsMcpResource.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Tools/McpTool.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Tools/McpToolValidator.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Tools/RegisterAbilityAsMcpTool.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Utils/AbilityArgumentNormalizer.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Utils/ContentBlockHelper.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Utils/McpAnnotationMapper.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Utils/McpNameSanitizer.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Utils/McpValidator.php
  • lib/vendor/wordpress/mcp-adapter/includes/Domain/Utils/SchemaTransformer.php
  • lib/vendor/wordpress/mcp-adapter/includes/Handlers/HandlerHelperTrait.php
  • lib/vendor/wordpress/mcp-adapter/includes/Handlers/Initialize/InitializeHandler.php
  • lib/vendor/wordpress/mcp-adapter/includes/Handlers/Prompts/PromptsHandler.php
  • lib/vendor/wordpress/mcp-adapter/includes/Handlers/Resources/ResourcesHandler.php
  • lib/vendor/wordpress/mcp-adapter/includes/Handlers/System/SystemHandler.php
  • lib/vendor/wordpress/mcp-adapter/includes/Handlers/Tools/ToolsHandler.php
  • lib/vendor/wordpress/mcp-adapter/includes/Infrastructure/ErrorHandling/Contracts/McpErrorHandlerInterface.php
  • lib/vendor/wordpress/mcp-adapter/includes/Infrastructure/ErrorHandling/ErrorLogMcpErrorHandler.php
  • lib/vendor/wordpress/mcp-adapter/includes/Infrastructure/ErrorHandling/McpErrorFactory.php
  • lib/vendor/wordpress/mcp-adapter/includes/Infrastructure/ErrorHandling/NullMcpErrorHandler.php
  • lib/vendor/wordpress/mcp-adapter/includes/Infrastructure/Observability/ConsoleObservabilityHandler.php
  • lib/vendor/wordpress/mcp-adapter/includes/Infrastructure/Observability/Contracts/McpObservabilityHandlerInterface.php
  • lib/vendor/wordpress/mcp-adapter/includes/Infrastructure/Observability/ErrorLogMcpObservabilityHandler.php
  • lib/vendor/wordpress/mcp-adapter/includes/Infrastructure/Observability/FailureReason.php
  • lib/vendor/wordpress/mcp-adapter/includes/Infrastructure/Observability/McpObservabilityHelperTrait.php
  • lib/vendor/wordpress/mcp-adapter/includes/Infrastructure/Observability/NullMcpObservabilityHandler.php
  • lib/vendor/wordpress/mcp-adapter/includes/Plugin.php
  • lib/vendor/wordpress/mcp-adapter/includes/Servers/DefaultServerFactory.php
  • lib/vendor/wordpress/mcp-adapter/includes/Transport/Contracts/McpRestTransportInterface.php
  • lib/vendor/wordpress/mcp-adapter/includes/Transport/Contracts/McpTransportInterface.php
  • lib/vendor/wordpress/mcp-adapter/includes/Transport/HttpTransport.php
  • lib/vendor/wordpress/mcp-adapter/includes/Transport/Infrastructure/HttpRequestContext.php
  • lib/vendor/wordpress/mcp-adapter/includes/Transport/Infrastructure/HttpRequestHandler.php
  • lib/vendor/wordpress/mcp-adapter/includes/Transport/Infrastructure/HttpSessionValidator.php
  • lib/vendor/wordpress/mcp-adapter/includes/Transport/Infrastructure/JsonRpcResponseBuilder.php
  • lib/vendor/wordpress/mcp-adapter/includes/Transport/Infrastructure/McpTransportContext.php
  • lib/vendor/wordpress/mcp-adapter/includes/Transport/Infrastructure/McpTransportHelperTrait.php
  • lib/vendor/wordpress/mcp-adapter/includes/Transport/Infrastructure/RequestRouter.php
  • lib/vendor/wordpress/mcp-adapter/includes/Transport/Infrastructure/SessionManager.php
  • lib/vendor/wordpress/mcp-adapter/mcp-adapter.php
  • lib/vendor/wordpress/php-mcp-schema/.gitignore
  • lib/vendor/wordpress/php-mcp-schema/LICENSE.md
  • lib/vendor/wordpress/php-mcp-schema/phpstan.neon
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/DTO/BooleanSchema.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/DTO/ElicitRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/DTO/ElicitRequestFormParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/DTO/ElicitRequestFormParamsRequestedSchema.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/DTO/ElicitRequestURLParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/DTO/ElicitResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/DTO/ElicitationCompleteNotification.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/DTO/ElicitationCompleteNotificationParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/DTO/LegacyTitledEnumSchema.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/DTO/NumberSchema.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/DTO/StringSchema.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/DTO/TitledMultiSelectEnumSchema.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/DTO/TitledMultiSelectEnumSchemaItems.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/DTO/TitledSingleSelectEnumSchema.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/DTO/UntitledMultiSelectEnumSchema.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/DTO/UntitledMultiSelectEnumSchemaItems.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/DTO/UntitledSingleSelectEnumSchema.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/Factory/ElicitRequestParamsFactory.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/Factory/EnumSchemaFactory.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/Factory/MultiSelectEnumSchemaFactory.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/Factory/PrimitiveSchemaDefinitionFactory.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/Factory/SingleSelectEnumSchemaFactory.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/Union/ElicitRequestParamsInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/Union/EnumSchemaInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/Union/MultiSelectEnumSchemaInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/Union/PrimitiveSchemaDefinitionInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Elicitation/Union/SingleSelectEnumSchemaInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Lifecycle/DTO/ClientCapabilities.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Lifecycle/DTO/ClientCapabilitiesElicitation.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Lifecycle/DTO/ClientCapabilitiesRoots.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Lifecycle/DTO/ClientCapabilitiesSampling.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Lifecycle/DTO/ClientCapabilitiesTasks.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Lifecycle/Union/ClientResultInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Roots/DTO/ListRootsRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Roots/DTO/ListRootsResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Roots/DTO/Root.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Roots/DTO/RootsListChangedNotification.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Sampling/DTO/CreateMessageRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Sampling/DTO/CreateMessageRequestParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Sampling/DTO/CreateMessageResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Sampling/DTO/ModelHint.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Sampling/DTO/ModelPreferences.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Sampling/DTO/SamplingMessage.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Sampling/DTO/ToolChoice.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Sampling/DTO/ToolResultContent.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Sampling/DTO/ToolUseContent.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Tasks/DTO/CreateTaskResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Tasks/DTO/RelatedTaskMetadata.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Tasks/DTO/Task.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Tasks/DTO/TaskMetadata.php
  • lib/vendor/wordpress/php-mcp-schema/src/Client/Tasks/Enum/TaskStatus.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/AbstractDataTransferObject.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/AbstractEnum.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Content/DTO/AudioContent.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Content/DTO/ImageContent.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Content/DTO/TextContent.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Contracts/BaseMetadataInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Contracts/IconsInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Contracts/JSONRPCNotificationInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Contracts/JSONRPCRequestInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Contracts/NotificationParamsInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Contracts/PaginatedRequestInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Contracts/PaginatedResultInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Contracts/RequestParamsInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Contracts/ResourceContentsInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Contracts/ResourceRequestParamsInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Contracts/ResultInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Contracts/TaskAugmentedRequestParamsInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Contracts/WithArrayTransformationInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Contracts/WithJsonSchemaInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Core/DTO/Icon.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/JsonRpc/DTO/Error.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/JsonRpc/DTO/JSONRPCErrorResponse.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/JsonRpc/DTO/JSONRPCNotification.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/JsonRpc/DTO/JSONRPCRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/JsonRpc/DTO/JSONRPCResultResponse.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/JsonRpc/DTO/Notification.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/JsonRpc/DTO/NotificationParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/JsonRpc/DTO/Request.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/JsonRpc/DTO/RequestParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/JsonRpc/DTO/RequestParamsMeta.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/JsonRpc/Union/JSONRPCMessageInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/JsonRpc/Union/JSONRPCResponseInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Lifecycle/DTO/Implementation.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/McpConstants.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/Annotations.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/BaseMetadata.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/BlobResourceContents.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/CancelledNotification.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/CancelledNotificationParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/EmbeddedResource.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/EmptyResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/GetTaskPayloadRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/GetTaskPayloadRequestParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/GetTaskPayloadResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/Icons.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/InitializeRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/InitializeRequestParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/InitializeResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/InitializedNotification.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/PaginatedRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/PaginatedRequestParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/PaginatedResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/PingRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/ProgressNotification.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/ProgressNotificationParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/Result.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/TextResourceContents.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/DTO/URLElicitationRequiredError.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/Enum/Role.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/Factory/ClientNotificationFactory.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/Factory/ClientRequestFactory.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/Factory/ContentBlockFactory.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/Factory/SamplingMessageContentBlockFactory.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/Factory/ServerRequestFactory.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/Union/ClientNotificationInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/Union/ClientRequestInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/Union/ContentBlockInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/Union/SamplingMessageContentBlockInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Protocol/Union/ServerRequestInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Tasks/DTO/CancelTaskRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Tasks/DTO/CancelTaskRequestParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Tasks/DTO/CancelTaskResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Tasks/DTO/GetTaskRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Tasks/DTO/GetTaskRequestParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Tasks/DTO/GetTaskResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Tasks/DTO/ListTasksRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Tasks/DTO/ListTasksResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Tasks/DTO/TaskAugmentedRequestParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Tasks/DTO/TaskStatusNotification.php
  • lib/vendor/wordpress/php-mcp-schema/src/Common/Traits/ValidatesRequiredFields.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Core/DTO/CompleteRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Core/DTO/CompleteRequestParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Core/DTO/CompleteRequestParamsArgument.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Core/DTO/CompleteRequestParamsContext.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Core/DTO/CompleteResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Core/DTO/CompleteResultCompletion.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Core/DTO/PromptReference.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Core/DTO/ResourceTemplateReference.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Lifecycle/DTO/ServerCapabilities.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Lifecycle/DTO/ServerCapabilitiesPrompts.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Lifecycle/DTO/ServerCapabilitiesResources.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Lifecycle/DTO/ServerCapabilitiesTasks.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Lifecycle/DTO/ServerCapabilitiesTools.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Lifecycle/Factory/ServerNotificationFactory.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Lifecycle/Union/ServerNotificationInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Lifecycle/Union/ServerResultInterface.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Logging/DTO/LoggingMessageNotification.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Logging/DTO/LoggingMessageNotificationParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Logging/DTO/SetLevelRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Logging/DTO/SetLevelRequestParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Logging/Enum/LoggingLevel.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Prompts/DTO/GetPromptRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Prompts/DTO/GetPromptRequestParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Prompts/DTO/GetPromptResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Prompts/DTO/ListPromptsRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Prompts/DTO/ListPromptsResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Prompts/DTO/Prompt.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Prompts/DTO/PromptArgument.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Prompts/DTO/PromptListChangedNotification.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Prompts/DTO/PromptMessage.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/ListResourceTemplatesRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/ListResourceTemplatesResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/ListResourcesRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/ListResourcesResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/ReadResourceRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/ReadResourceRequestParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/ReadResourceResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/Resource.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/ResourceContents.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/ResourceLink.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/ResourceListChangedNotification.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/ResourceRequestParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/ResourceTemplate.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/ResourceUpdatedNotification.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/ResourceUpdatedNotificationParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/SubscribeRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/SubscribeRequestParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/UnsubscribeRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Resources/DTO/UnsubscribeRequestParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Tools/DTO/CallToolRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Tools/DTO/CallToolRequestParams.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Tools/DTO/CallToolResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Tools/DTO/ListToolsRequest.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Tools/DTO/ListToolsResult.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Tools/DTO/Tool.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Tools/DTO/ToolAnnotations.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Tools/DTO/ToolExecution.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Tools/DTO/ToolInputSchema.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Tools/DTO/ToolListChangedNotification.php
  • lib/vendor/wordpress/php-mcp-schema/src/Server/Tools/DTO/ToolOutputSchema.php
  • resources/scss/admin/base/_variables.scss
  • resources/scss/admin/components/button/_button.scss
  • resources/scss/admin/components/settings/_global-settings.scss
  • resources/scss/admin/media-queries/_screen-laptop.scss
  • stripe/controllers/FrmTransLitePaymentsController.php
  • stripe/controllers/FrmTransLiteSubscriptionsController.php
  • stripe/models/FrmTransLiteDb.php
  • stubs.php
  • tests/phpunit/abilities/test_FrmAbilitiesContract.php
  • tests/phpunit/abilities/test_FrmAbilitiesFormActionsController.php
  • tests/phpunit/abilities/test_FrmAbilitiesPaymentsController.php
  • tests/phpunit/abilities/test_FrmAbilitiesSubscriptionsController.php
  • tests/phpunit/abilities/test_FrmMcpSkillEnvController.php
  • tests/phpunit/abilities/test_FrmMcpUsageController.php
  • tests/phpunit/entries/test_FrmAbilitiesEntriesController.php
  • tests/phpunit/fields/test_FrmAbilitiesFieldsController.php
  • tests/phpunit/forms/test_FrmAbilitiesFormsController.php
  • tests/phpunit/styles/test_FrmAbilitiesStylesController.php

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@deepsource-io

deepsource-io Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 6b58fff...063b942 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

Important

Some issues found as part of this review are outside of the diff in this pull request and aren't shown in the inline review comments due to GitHub's API limitations. You can see those issues on the DeepSource dashboard.

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
PHP Oct 1, 2026 3:21p.m. Review ↗
JavaScript Oct 1, 2026 3:21p.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

*
* @var string
*/
const CATEGORY = 'formidable-forms';

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Visibility should be explicitly set for `CATEGORY` constant


Visibility (also know as Access Modifiers) can be used to define where it can be accessed. There are three access modifiers available in PHP:

  • public - The class members can be accessed from everywhere. This is default.
  • protected - The class members can be accessed within the class and by classes derived from that class.
  • private - The class members can only be accessed within the class.

The class members(properties, constants, or methods) declared without any explicit visibility keyword are by default considered as public. It is recommended to set visibility explicitly, which increases code readability. In addition, it gives the developer a mental model of where the class member would be accessible, which also leads to a better API design and makes sure that you are not making something public which isn't supposed to be.
Also, as per PSR-12: Extended Coding Style, visibility should be explicitly declared with all class properties, constants and methods.

*
* @var array
*/
const REQUIRED_CLASSES = array(

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Visibility should be explicitly set for `REQUIRED_CLASSES` constant


Visibility (also know as Access Modifiers) can be used to define where it can be accessed. There are three access modifiers available in PHP:

  • public - The class members can be accessed from everywhere. This is default.
  • protected - The class members can be accessed within the class and by classes derived from that class.
  • private - The class members can only be accessed within the class.

The class members(properties, constants, or methods) declared without any explicit visibility keyword are by default considered as public. It is recommended to set visibility explicitly, which increases code readability. In addition, it gives the developer a mental model of where the class member would be accessible, which also leads to a better API design and makes sure that you are not making something public which isn't supposed to be.
Also, as per PSR-12: Extended Coding Style, visibility should be explicitly declared with all class properties, constants and methods.

*
* @var array
*/
const CREATE_SERVER_PARAMS = array(

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Visibility should be explicitly set for `CREATE_SERVER_PARAMS` constant


Visibility (also know as Access Modifiers) can be used to define where it can be accessed. There are three access modifiers available in PHP:

  • public - The class members can be accessed from everywhere. This is default.
  • protected - The class members can be accessed within the class and by classes derived from that class.
  • private - The class members can only be accessed within the class.

The class members(properties, constants, or methods) declared without any explicit visibility keyword are by default considered as public. It is recommended to set visibility explicitly, which increases code readability. In addition, it gives the developer a mental model of where the class member would be accessible, which also leads to a better API design and makes sure that you are not making something public which isn't supposed to be.
Also, as per PSR-12: Extended Coding Style, visibility should be explicitly declared with all class properties, constants and methods.

*
* @var array
*/
const REQUIRED_ABILITY_FUNCTIONS = array(

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Visibility should be explicitly set for `REQUIRED_ABILITY_FUNCTIONS` constant


Visibility (also know as Access Modifiers) can be used to define where it can be accessed. There are three access modifiers available in PHP:

  • public - The class members can be accessed from everywhere. This is default.
  • protected - The class members can be accessed within the class and by classes derived from that class.
  • private - The class members can only be accessed within the class.

The class members(properties, constants, or methods) declared without any explicit visibility keyword are by default considered as public. It is recommended to set visibility explicitly, which increases code readability. In addition, it gives the developer a mental model of where the class member would be accessible, which also leads to a better API design and makes sure that you are not making something public which isn't supposed to be.
Also, as per PSR-12: Extended Coding Style, visibility should be explicitly declared with all class properties, constants and methods.

*
* @var int
*/
const MIN_PHP_ID = 70400;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Visibility should be explicitly set for `MIN_PHP_ID` constant


Visibility (also know as Access Modifiers) can be used to define where it can be accessed. There are three access modifiers available in PHP:

  • public - The class members can be accessed from everywhere. This is default.
  • protected - The class members can be accessed within the class and by classes derived from that class.
  • private - The class members can only be accessed within the class.

The class members(properties, constants, or methods) declared without any explicit visibility keyword are by default considered as public. It is recommended to set visibility explicitly, which increases code readability. In addition, it gives the developer a mental model of where the class member would be accessible, which also leads to a better API design and makes sure that you are not making something public which isn't supposed to be.
Also, as per PSR-12: Extended Coding Style, visibility should be explicitly declared with all class properties, constants and methods.

*
* @var string
*/
const SERVER_ID = 'formidable-mcp';

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Visibility should be explicitly set for `SERVER_ID` constant


Visibility (also know as Access Modifiers) can be used to define where it can be accessed. There are three access modifiers available in PHP:

  • public - The class members can be accessed from everywhere. This is default.
  • protected - The class members can be accessed within the class and by classes derived from that class.
  • private - The class members can only be accessed within the class.

The class members(properties, constants, or methods) declared without any explicit visibility keyword are by default considered as public. It is recommended to set visibility explicitly, which increases code readability. In addition, it gives the developer a mental model of where the class member would be accessible, which also leads to a better API design and makes sure that you are not making something public which isn't supposed to be.
Also, as per PSR-12: Extended Coding Style, visibility should be explicitly declared with all class properties, constants and methods.

/**
* @var string
*/
const ROUTE_NAMESPACE = 'mcp';

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Visibility should be explicitly set for `ROUTE_NAMESPACE` constant


Visibility (also know as Access Modifiers) can be used to define where it can be accessed. There are three access modifiers available in PHP:

  • public - The class members can be accessed from everywhere. This is default.
  • protected - The class members can be accessed within the class and by classes derived from that class.
  • private - The class members can only be accessed within the class.

The class members(properties, constants, or methods) declared without any explicit visibility keyword are by default considered as public. It is recommended to set visibility explicitly, which increases code readability. In addition, it gives the developer a mental model of where the class member would be accessible, which also leads to a better API design and makes sure that you are not making something public which isn't supposed to be.
Also, as per PSR-12: Extended Coding Style, visibility should be explicitly declared with all class properties, constants and methods.

* @return bool
*/
private static function logged_recently( $ability_name, $status ) {
$key = 'frm_mcp_missing_' . md5( $ability_name . '|' . $status );

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Use of insecure md5() function found


Using md5(), sha1() function is not recommended to generate secure passwords. Due to its fast nature to compute passwords too quickly, these functions can become really easy to crack a password using brute force attack.

It is recommended to use PHP's password hashing function password_hash() to create a secure password hash.

*
* @var string
*/
const SKILL_RELEASE_TRANSIENT = 'frm_mcp_skill_release';

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Visibility should be explicitly set for `SKILL_RELEASE_TRANSIENT` constant


Visibility (also know as Access Modifiers) can be used to define where it can be accessed. There are three access modifiers available in PHP:

  • public - The class members can be accessed from everywhere. This is default.
  • protected - The class members can be accessed within the class and by classes derived from that class.
  • private - The class members can only be accessed within the class.

The class members(properties, constants, or methods) declared without any explicit visibility keyword are by default considered as public. It is recommended to set visibility explicitly, which increases code readability. In addition, it gives the developer a mental model of where the class member would be accessible, which also leads to a better API design and makes sure that you are not making something public which isn't supposed to be.
Also, as per PSR-12: Extended Coding Style, visibility should be explicitly declared with all class properties, constants and methods.

*
* @var string
*/
const SKILL_DOWNLOAD_META = 'frm_mcp_skill_download';

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Visibility should be explicitly set for `SKILL_DOWNLOAD_META` constant


Visibility (also know as Access Modifiers) can be used to define where it can be accessed. There are three access modifiers available in PHP:

  • public - The class members can be accessed from everywhere. This is default.
  • protected - The class members can be accessed within the class and by classes derived from that class.
  • private - The class members can only be accessed within the class.

The class members(properties, constants, or methods) declared without any explicit visibility keyword are by default considered as public. It is recommended to set visibility explicitly, which increases code readability. In addition, it gives the developer a mental model of where the class member would be accessible, which also leads to a better API design and makes sure that you are not making something public which isn't supposed to be.
Also, as per PSR-12: Extended Coding Style, visibility should be explicitly declared with all class properties, constants and methods.

@Crabcyborg
Crabcyborg marked this pull request as ready for review September 3, 2026 00:25
@garretlaxton

garretlaxton commented Sep 8, 2026 •

Copy link
Copy Markdown

delete-style and get-style also seem to operate on any WordPress post, not just Formidable styles.

Initialize an MCP session:

SID=$(curl -s -i -u "admin:YOUR_APP_PASS" -X POST "http://ff.local/wp-json/mcp/formidable-mcp" \
  -H "Content-Type: application/json" -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"curl","version":"1.0"}}}' \
  | grep -i '^mcp-session-id:' | awk '{print $2}' | tr -d '\r')
echo "$SID"

Call get-style with that unrelated post's ID (read-only):

curl -s -u "admin:YOUR_APP_PASS" -X POST "http://ff.local/wp-json/mcp/formidable-mcp" \
  -H "Content-Type: application/json" -H "Accept: application/json, text/event-stream" \
  -H "Mcp-Session-Id: $SID" \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"mcp-adapter-execute-ability","arguments":{"ability_name":"formidable-forms/get-style","parameters":{"id":1}}}}'

This will return "success":true with a fabricated style object named "Hello world!" / post_name: "hello-world", instead of a 404 "invalid style ID" error.

Call delete-style with the same ID:

curl -s -u "admin:YOUR_APP_PASS" -X POST "http://ff.local/wp-json/mcp/formidable-mcp" \
  -H "Content-Type: application/json" -H "Accept: application/json, text/event-stream" \
  -H "Mcp-Session-Id: $SID" \
  -d '{"jsonrpc":"2.0","id":3,"method":"tools/call","params":{"name":"mcp-adapter-execute-ability","arguments":{"ability_name":"formidable-forms/delete-style","parameters":{"id":1}}}}'

This returns "success":true claiming a style was deleted, but the post was actually moved to the trash.


assign-style-to-form has a similar issue.

  • Assign the Sample Page's ID (id=2) as your form's style:
curl -s -u "admin:YOUR_APP_PASS" -X POST "http://ff.local/wp-json/mcp/formidable-mcp" \
  -H "Content-Type: application/json" -H "Accept: application/json, text/event-stream" \
  -H "Mcp-Session-Id: $SID" \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"mcp-adapter-execute-ability","arguments":{"ability_name":"formidable-forms/assign-style-to-form","parameters":{"form_id":YOUR_FORM_ID,"style_id":2}}}}'

Returns "success": true, "style_id": 2 but it should have rejected 2 since it's not a style.


add-item-to-application reports false success for mismatched item types.

Add a real form's ID, but with the WRONG item_type (it's a form, tag it as view):

curl -s -u "admin:YOUR_APP_PASS" -X POST "http://ff.local/wp-json/mcp/formidable-mcp" \
  -H "Content-Type: application/json" -H "Accept: application/json, text/event-stream" \
  -H "Mcp-Session-Id: $SID" \
  -d '{"jsonrpc":"2.0","id":5,"method":"tools/call","params":{"name":"mcp-adapter-execute-ability","arguments":{"ability_name":"formidable-forms/add-item-to-application","parameters":{"application_id":APP_ID,"item_id":YOUR_FORM_ID,"item_type":"view"}}}}'

This returns "success": true, "message": "Item added to application successfully." You can check the application as well to see nothing was ever added.

@garretlaxton

Copy link
Copy Markdown

Every ability fails on empty parameters ({}). list-forms, list-views, list-view-layouts, and list-coupons all fail with a generic error when called with parameters: {}, but succeed instantly if you add literally any key, even a made-up one like {"zzz": 1}.

@Crabcyborg Crabcyborg added this to the 6.36 milestone Sep 16, 2026
@vivi-the-going-merry vivi-the-going-merry Bot added vivi-working Vivi is actively working this and removed vivi-pickup labels Sep 17, 2026
@vivi-the-going-merry

Copy link
Copy Markdown
Contributor

Scoped both non-bot findings on this PR:

delete-style/get-style operating on any post (garretlaxton, Sep 8): already fixed on this branch — FrmAbilitiesStylesController::get_style() guards with is_style_post() before returning. delete-style itself isn't registered here at all; this PR's Styles controller only registers list/get/update-style, matching the PR description. Delete lives in Pro (formidable-pro#6580), tracked separately there.

Empty {} params failing on list-forms/list-views/list-view-layouts/list-coupons (garretlaxton, Sep 10): traced to AbilityArgumentNormalizer::normalize() in the vendored mcp-adapter package (lib/vendor/wordpress/mcp-adapter), not Formidable's own code. For a schema with properties but no top-level default, it returns [] for both null and {} input — the ability's own execute callback never sees a distinction. list-forms (the only one of the four actually registered in this repo) has no top-level default, so it hits this path. list-views/list-view-layouts/list-coupons aren't registered here at all (formidable-views/formidable-coupons). Out of scope for a fix in this repo — either a mcp-adapter fix upstream, or each affected ability adding a top-level schema default (which changes normalizer behavior to return null, letting WP_Ability apply that default instead).

Not claiming further action on either — clearing labels back.

@vivi-the-going-merry vivi-the-going-merry Bot removed the vivi-working Vivi is actively working this label Sep 17, 2026
@codecov

codecov Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 71.58868% with 1014 lines in your changes missing coverage. Please review.
✅ Project coverage is 33.94%. Comparing base (38ec34b) to head (99d5fcc).
⚠️ Report is 35 commits behind head on master.

Files with missing lines Patch % Lines
classes/models/FrmMcpAbilityRegistry.php 0.00% 171 Missing ⚠️
...sses/controllers/FrmAbilitiesEntriesController.php 69.68% 124 Missing ⚠️
classes/models/FrmMcpConnection.php 0.00% 118 Missing ⚠️
classes/models/FrmMcpCompat.php 0.00% 114 Missing ⚠️
classes/controllers/FrmMcpSettingsController.php 3.53% 109 Missing ⚠️
classes/controllers/FrmMcpController.php 10.90% 98 Missing ⚠️
...ses/controllers/FrmMcpMissingAbilityController.php 0.00% 84 Missing ⚠️
...asses/controllers/FrmAbilitiesFieldsController.php 86.59% 65 Missing ⚠️
classes/helpers/FrmAbilitiesHelper.php 66.66% 27 Missing ⚠️
.../controllers/FrmAbilitiesFormActionsController.php 94.94% 25 Missing ⚠️
... and 8 more
Additional details and impacted files
@@             Coverage Diff              @@
##             master    #3294      +/-   ##
============================================
+ Coverage     28.64%   33.94%   +5.29%     
- Complexity     9845    10604     +759     
============================================
  Files           160      175      +15     
  Lines         33026    36594    +3568     
============================================
+ Hits           9461    12422    +2961     
- Misses        23565    24172     +607     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@franky-the-going-merry franky-the-going-merry Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the authored surface of this PR (33 non-vendor files, ~10.8k new lines; the remaining ~292 changed files are the vendored lib/vendor/wordpress/php-mcp-schema / mcp-adapter / automattic/jetpack-autoloader / composer dependency trees this feature is built on, not hand-written here).

Verified: the MCP boot/registration gating (FrmMcpController, FrmAbilitiesController) and its interop with an older API add-on; the permission model across all 7 ability domains (forms/fields/entries/styles/form-actions/payments/subscriptions) — every mutating ability has a permission_callback mapped to a sensible frm_view_*/frm_edit_*/frm_delete_* capability (or administrator), no domain found with a missing or over-permissive check; the settings-page download handler (FrmMcpSettingsController::download_skill) has both a capability check and a nonce check; and the payments/subscriptions list query builder (build_list_query) — table names go through %i, values through %s/%d, and order_by/order are passed through the existing FrmDb::esc_order()/esc_order_by() allow-list before reaching SQL, so user-supplied sort input can't inject.

One CI-confirmed blocking issue (inline below): FrmAbilitiesFormActionsController::execute_list_form_actions() queries with numberposts => -1 (VIP-lint NoPaging, currently the one real PHPCS failure on this PR) where the existing, otherwise-identical query shape in FrmFormAction::action_args() already uses a bounded default ($limit = 99) — this is a new unbounded variant of a pattern the codebase already solved bounded.

One non-blocking gap: the new architectural/wiring code — FrmMcpCompat (492 lines), FrmMcpAbilityRegistry (519 lines), FrmMcpConnection (394 lines), FrmMcpSettingsController, FrmHooksController, FrmAbilitiesHelper — has no new PHPUnit coverage. The 7 domain ability controllers and a shared contract test are well covered; this ~2000-line core layer (including FrmMcpController::is_enabled()'s three-way own-setting/inherited-setting/filtered-default fallback, which is exactly the kind of branching logic worth a direct test) isn't. CI is otherwise green (PHPUnit passes on PHP 7.4 and 8, syntax/CS-Fixer/Rector/Psalm/PHPStan/Mago/ESLint/Stylelint/Oxlint/Typos all pass).

Not exercised this pass (disclosing per review scope, not asking for anything): line-by-line read of the individual CRUD bodies of the Fields/Entries/Forms/Styles/Subscriptions ability controllers (only Payments was read in full as the representative), the vendored MCP adapter/schema source itself, stubs.php, the two touched Stripe-Lite files, and DeepSource's own PHP findings (its check failed but the review comment carries no body and the dashboard link needs a JS-rendered/authenticated session this pass couldn't reach). No live MCP-client exercise — this is a backend API surface with no visual/UX component to screenshot.

// Draft actions are disabled but still configured on the form, so
// list them alongside published ones unless a status filter is set.
'post_status' => '' !== $status ? $status : array( 'publish', 'draft' ),
'numberposts' => -1,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PHPCS is currently red on this line (WordPressVIPMinimum.Performance.NoPaging.posts_per_page_numberposts): numberposts => -1 disables pagination on a get_posts() call.

The existing, same-shape query in FrmFormAction::action_args() already solved this bounded rather than unbounded:

public static function action_args( $form_id = 0, $limit = 99 ) {
	$args = array(
		'post_type'   => FrmFormActionsController::$action_post_type,
		'post_status' => 'publish',
		'numberposts' => $limit,

Suggest matching that precedent here instead of introducing a new unbounded variant — e.g. reuse FrmFormAction::action_args()'s bound, or give this ability its own bounded default (this endpoint's sibling list abilities already cap page_size at 200, so a comparable cap here would be consistent).

Suggested change
'numberposts' => -1,
'numberposts' => 200,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed -- capped at 200, matching the page_size cap the sibling list abilities (payments/subscriptions/styles) already use. This ability has no page_size input of its own to honor instead, so a hardcoded bound is the right fix here rather than reusing action_args()s 99 default. Pushed in 85096a3.

@vivi-the-going-merry

Copy link
Copy Markdown
Contributor

Method: in-place push
Pushed to: #3294 (branch mcp, unchanged PR number)

Fixed the one blocking finding: execute_list_form_actions()'s numberposts => -1 capped at 200, matching the page_size cap already used by the sibling list abilities. This ability has no page_size input of its own, so a hardcoded bound is the right fix rather than honoring an existing arg.

Left the non-blocking test-coverage gap (FrmMcpCompat/FrmMcpAbilityRegistry/FrmMcpConnection/etc.) to the PR's own author -- Franky split it out as non-blocking and this is an active human author's PR, not an orphaned-author handoff.

@vivi-the-going-merry vivi-the-going-merry Bot removed the vivi-working Vivi is actively working this label Sep 21, 2026

@franky-the-going-merry franky-the-going-merry Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-review at 85096a3 (my prior review was on 99d5fcc, CHANGES_REQUESTED).

Fix verified: execute_list_form_actions()'s numberposts => -1 is now 200, matching the page_size cap already used by the sibling list abilities (FrmAbilitiesPaymentsController/FrmAbilitiesSubscriptionsController, "capped at 200. Default 50."). Only this one line changed since my last review, so the permission-model/SQL-safety/boot-registration findings from that pass still hold. CI is now fully green — the PHPCS NoPaging failure that blocked the prior round is gone; PHPUnit (7.4/8), PHPCS, PHPStan, Psalm, Mago, Rector, CS-Fixer, ESLint, Oxlint, Stylelint, Typos, DeepScan, and Scrutinizer all pass.

Non-blocking, new this pass: DeepSource: PHP now fails — checked all 24 of its inline comments. 20 are PSR-12 "explicit visibility on class constant" style nits; one flags md5() in FrmMcpMissingAbilityController::logged_recently() (not security-sensitive — it's a transient-key hash for log dedup, no auth/crypto use); one flags an apply_filters() call with an extra optional arg (valid); two flag high cyclomatic complexity (get_endpoint 17, prepare_entry_data 19). None block — filing alongside the still-open test-coverage gap from my last review (FrmMcpCompat/FrmMcpAbilityRegistry/FrmMcpConnection/etc.), which Vivi's fix-push above left to the author.

Approving.

@Crabcyborg

Crabcyborg commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor Author

@garretlaxton I've pushed a bunch of updates, across the various plugins.

Lite includes some new endpoints:

payments       4   list-payments  get-payment  delete-payment  refund-payment
subscriptions  4   list-subscriptions  get-subscription  delete-subscription  cancel-subscription

No create/update as I don't think those are necessary.

There are also 2 new add-ons involved so people can use MCP to update translations and get information about / clean up their logs:

Also, I have updates for the skill in Strategy11/formidable-mcp-skill#7. It has new info for properly interacting with the new abilities.

Crabcyborg and others added 16 commits September 22, 2026 11:44
Setup steps
- Drop the card around the steps; they sit on the page, aligned with the
  toggle. Numbered markers sit in the heading row, and a finished step
  shows a green check circle.
- One primary action at a time: Download leads until a file exists, then
  Copy setup prompt until an assistant connects, then nothing. The
  download label and button styles update without a reload.
- Setup prompt, connection files and manual skill install move behind
  disclosures; disclosure content aligns with its label.
- The assistant picker is keyboard reachable (the radios were
  display:none) and no longer reuses the captcha's frm_captchas class,
  which admin.js targets.
- Copy setup prompt is a labelled button; Copied swaps to a check sized
  to match the copy icon.
- Waiting state shows a spinner (off under reduced motion) and the
  content staggers in when the server is switched on.
- Prose is capped at a readable measure; spacing uses the 8/16/24/32
  tokens.

Copy
- Shorter, plainer strings throughout, with descriptive links. The revoke
  note says why files must be revoked before deactivating Formidable.
  Error pages use "connection file" and say how to recover.
- MCP Connections keeps one description for every state.

Components
- Icon buttons (.button.frm-with-icon) now lay out as inline-flex, so the
  gap applies; WordPress core's inline-block used to win. 4px gap, 20px
  icons (16px small) per the Figma spec, icons at full strength.
- Add frm_file_download_icon from Figma to the sprite, and the
  --success-600 token from the design system.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Redesign the MCP settings setup steps
@garretlaxton

Copy link
Copy Markdown

delete-style succeeded on a style assigned to a form. However, the form's custom_style still pointed at the deleted ID, and its Submit button rendered unstyled. There is no warning or fallback.


Whenever you enable the MCP then click update, it shows MCP is turned on but not running. The MCP adapter could not be loaded., but refreshing the page clears this banner and everything works properly. I'm guessing this is a false positive?
image

@Crabcyborg

Copy link
Copy Markdown
Contributor Author

Thank you @garretlaxton!

I pushed new updates to Lite and Pro. Lite has the fix for the error you shared, and Pro has the update for re-assigning all forms to the default style when their previously selected style is deleted.

*
* @return string Escaped HTML for the release summary.
*/
private static function get_skill_status( $release, $download, $is_stale ) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

`get_skill_status` has a cyclomatic complexity of 16 with "High" risk


A function with high cyclomatic complexity can be hard to understand and
maintain. Cyclomatic complexity is a software metric that measures the number of
independent paths through a function. A higher cyclomatic complexity indicates
that the function has more decision points and is more complex.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants