# evoMCP changelog

> Version history of evoMCP, newest first, listing what changed in each release for the people who use it: tools, panel, OAuth, licensing and security fixes.

# evoMCP changelog

Dates are those of the matching commit in the repository. Versions before 0.7.1 were used during development. \[PENDIENTE: confirm from which version public downloads exist, and their release dates\]

## 0.7.1 (2026-10-10)

- The package is built with the evoaddons.com licence server and its public key. On update, Joomla switches evoMCP's update site to evoaddons.com.
- No changes to the tools or the panel.

## 0.7.0 (2026-10-10)

- A Connect tab in the panel: the MCP server address with a copy button, pre-flight warnings (HTTPS, public address, server enabled, approval "none", advanced layer) and the steps for Claude, ChatGPT, Claude Code and token clients.
- The component options link to that guide.

## 0.6.2 (2026-10-10)

- The updates XML is open, like any other extension's. The Download ID is required when downloading the ZIP, through Joomla's "Download Key" field, and the XML URL carries no key.

## 0.6.1 (2026-10-10)

- The Download ID is pasted into Joomla's update site. The extension picks it up, activates the domain and copies it to the download URL.
- The License tab now shows only the licence status.

## 0.6.0 (2026-10-09)

Full control of Joomla and YOOtheme, in four layers:

- Entities and options: generic tools over Joomla's models with 18 built-in entities, options of any component, and pre-change backups with restore.
- YOOtheme in depth: element catalogue, and adding, moving, duplicating, removing and replacing nodes with hierarchy validation; creating pages; theme settings with a backup first.
- System operations (super users only): information, updates, installation from an allowed URL, uninstalling, global configuration with a backup, cache, logs and scheduled tasks.
- An advanced SQL and files layer, disabled by default and behind three locks.

Other changes in this version:

- The `evomcp_capabilities` tool, which explains which permissions the connection has and which components exist without being granted.
- OAuth consent stores only what the user unticks, so new components reach connectors that were already authorised.
- Pre-validation with `dry_run` before an action is held for approval.
- evoLeadGate, evoOrigin and evoYTAccess add control tools.
- Independent security review applied to the SQL tools, files, component options, backups, entities and approval of administration actions.
- A new table for pre-change backups, created on update.

## 0.5.2 (2026-10-07)

- The licence client finds the update site by the product in its URL rather than by name, which changed when the extensions were renamed.

## 0.5.1 (2026-10-07)

- Fixes a fatal error in evoMCP's task plugin that stopped Joomla's task plugin group from loading.

## 0.5.0 (2026-10-05)

- YOOtheme Pro tools: structure of page builder pages, node search and property changes.
- The Joomla text filter of the connection user's group is taken into account when changing builder pages.

## 0.4.0 (2026-10-05)

- Compatibility of the evo extensions with evoMCP, with Joomla's REST API and with the privacy tools.
- A daily maintenance task: audit retention, approval expiry, OAuth clean-up and an alert at 80% of the monthly quota.
- Fix for clients using protocol 2026-07-28: every result declares `resultType` and the tool list declares its caching.
- Final security review of the server, OAuth, approvals and the audit log, which no longer stores texts containing personal data; third-party results are flagged as untrusted.
- The package also enables the task plugin on first installation.

## 0.3.0 (2026-10-05)

- Human approval of writes, with three modes per connection, `dry_run` and provenance for content created by agents.
- Content write tools, plus tools for menus, modules, media, users, extensions, templates, configuration and scheduled tasks.

## 0.2.0 (2026-10-05)

- OAuth 2.1: discovery, dynamic registration and registration by metadata document, a consent screen where you pick the connection, PKCE, refresh with rotation and revocation from the panel.

## 0.1.0 (2026-10-05)

- First version: the `/mcp` endpoint, connections with a token and a per-component permission matrix, an audit log with a hash chain, usage metering, the administration panel and content read tools.

---

https://evoaddons.com/en/documentation/evomcp-changelog
