Description
WordPressMCP — the AI control layer for WordPress
WordPressMCP exposes your WordPress site to AI assistants (Claude, Cursor, and any MCP-compatible client) through a secure, standards-based Model Context Protocol endpoint. It ships with OAuth 2.1 authentication, bearer-token provisioning, a strict per-site license, and an admin panel to enable or disable individual tools. Every action runs through WordPress capability checks — the AI can only do what the authenticated user is allowed to do.
What it can do — ~90 tools across 21 capability areas
- Content — list, read, create, update, surgically patch, and delete posts/pages/any custom post type; discover content types; look up content by slug or URL.
- Taxonomy — discover taxonomies, manage terms, assign terms to content.
- Media — upload media, attach to content, manage metadata.
- Plugins — inspect, install, activate/deactivate, and read/write plugin files.
- Themes — inspect, switch, and read/write theme files.
- Users & Roles — list/create/update/delete users, manage roles and capabilities.
- Comments — list, create, update, delete, and moderate comments.
- Options & Settings — read/write options, transients, and theme mods.
- Menus — manage navigation menus, items, and menu locations.
- Widgets — manage classic and block widgets and sidebars.
- Block Patterns — manage patterns and reusable blocks.
- Customizer — read, update, and export Customizer settings.
- Cron — list, schedule, unschedule, and run scheduled events.
- Rewrites — list, flush, and add rewrite rules.
- Database — guarded queries, table info, optimize/repair, cleanup of revisions/spam/transients, and search-replace.
- Diagnostics — system info, Site Health, debug-log read/clear, hook inspection.
- SEO & Redirects — manage robots.txt, sitemap, and redirects.
- Export & Import — export/import content and back up the database.
- Audit Log — review and clear the record of recent AI tool calls.
- Multisite — network site and user management (on multisite installs).
- Code Execution — optional, off by default, gated behind an explicit constant for advanced operators.
Security & licensing
OAuth 2.1 with discovery endpoints and bearer tokens; every tool enforced against WordPress capabilities; an opt-in audit log of AI activity; and a strict per-site license — the MCP endpoint only serves on a licensed, activated install. Lifetime updates: every new release is included for as long as the product exists — there is no renewal and the license never expires.
Licensing tiers
Single Site, Agency (10 sites), and Unlimited — lifetime license with lifetime updates, choose at checkout.
Requires WordPress 6.0+ and PHP 8.2+.




Reviews
There are no reviews yet.