WSP WordPress MCP

Free WordPress MCP For Connecting AI Coding Agents

Documentation

WSP WordPress MCP — Connect AI Agents to WordPress

By WebSensePro — Official Shopify Partner & WordPress Agency

Version YouTube License

Turn any WordPress site into a Model Context Protocol (MCP) server so AI agents — Claude, Cursor, Codex, Antigravity, OpenClaw, OpenCode — can read and edit your posts, pages, media, menus, WooCommerce store, forms, SEO meta, and Elementor layouts. The MCP server is built in: no companion plugin, no MCP Adapter, no Node.js bridge for natively-supported clients. Every ability is an individual on/off switch in wp-admin, write abilities are off by default, and every call is recorded in a self-hosted audit log.


🎬 Watch the Tutorial

WSP WordPress MCP — Full Tutorial


🚀 Quick Start

Prerequisites: WordPress 6.9+ (7.0.3 or 6.9.6+ recommended), PHP 7.4+ — that's it. Claude Desktop and OpenClaw use the mcp-remote bridge, which needs Node.js 18+; Cursor, Codex, Antigravity, and OpenCode connect natively.

  1. Install & activate this plugin
  2. Go to MCP > Settings in wp-admin and enable the abilities you need
  3. Go to MCP > Connection and pick your client:
    • Claude (claude.ai, Desktop, or mobile): enable the OAuth server on the Claude Connectors tab, then paste just the server URL into Customize > Connectors > Add custom connector and sign in with your WordPress account
    • Everything else (Cursor, Codex, Antigravity, OpenClaw, OpenCode): use the Configuration Generator, then Copy or Download the snippet — the endpoint URL and credentials are already filled in — and paste it into your client's config (Cursor also gets a one-click Connect Cursor Automatically button)
  4. Reconnect / restart the client and start prompting your AI agent
  5. Review what your agent actually did under MCP > Audit Log, and check usage and response times under MCP > Analytics

Upgrading from before v2.0? The legacy MCP-Adapter / Abilities-API path and the MCP > Config Files page were removed in v2.2. Re-create your connection using the native endpoint on MCP > Connection.

Connection guides by client

ClientGuide
Claude (claude.ai / Desktop / mobile)Full tutorial
OpenClawVideo
Google AntigravityVideo
CodexVideo
All tutorials & abilities directorywspmcp.com

✨ What's New in v2.9.2

  • Minor updates.

v2.9.1

  • 👥 Create / Update Users — add new users (password auto-generated if you don't supply one, role defaults to subscriber) and edit email, display name, role, or password. Require create_users / edit_users; off by default.
  • ⚙️ Update Site Info & Permalinks — change the site title, tagline, and admin email, and set the permalink structure (e.g. /%postname%/). Require manage_options; off by default.
  • 🔌 Activate / Deactivate Plugins — toggle any installed plugin by its file path (e.g. akismet/akismet.php). This plugin refuses to deactivate itself so the MCP connection can't cut itself off. Require activate_plugins; off by default.
  • 🎨 Themes tool group — list installed themes and switch the active theme. Require switch_themes; off by default.

Contributed by @dulaj44 in #42.

v2.9.0

  • 🧭 Navigation Menus tool group — nine new tools to list menus and their items, create and delete menus, add / update / remove menu items (custom links, posts, pages, categories), list your theme's menu locations, and assign or unassign a menu to a location. Require edit_theme_options; off by default. Contributed by @dulaj44 in #41.
  • 📄 Read Post tool — fetch a single post by ID in any status (draft, pending, private, trash) with its full content, so an agent can review a draft before updating it. Enforces per-post read permission; off by default. Closes #38.
  • 🐛 Audit Log accuracy — permission-denied results from the new Read Post tool are now logged as denied, not success.
  • 🐛 Add Menu Item validation — an object_id whose post type doesn't match the requested type is now rejected instead of silently stored.

Recent releases: v2.9.0 — Navigation Menus tool group + Read Post tool · v2.8.0 — one-click Claude Connector sign-in (OAuth 2.1) + Analytics dashboard · v2.7.1 — object-level authorization on write tools (Patchstack) · v2.7.0 — Audit Log · v2.6.x — WPForms, Contact Form 7, Gravity Forms, UAE, Elementor design tools.

📋 Full history: see CHANGELOG.md.


🔐 Security model

  • Off by default — every write ability is disabled until an administrator enables it in MCP > Settings.
  • Per-tool capability checks — each tool declares the WordPress capability it requires (edit_posts, manage_options, manage_woocommerce, …) and runs as the connected WordPress user, so an agent can only do what that account can do.
  • Per-object guards — tools that take a post/page/media ID additionally enforce ownership (edit_post / delete_post / read_post) and post type, matching WordPress core's own REST checks.
  • Three auth methods — OAuth 2.1 (one-click Claude Connector, off by default), WordPress Application Passwords, or a plugin-generated API key.
  • Audit Log — every tools/call is stored in wp_wsp_mcp_audit_log with user, IP, outcome (success / denied / error), and duration. Nothing leaves your server. Auto-pruned after 90 days.

🛠️ Available Abilities

Core WordPress

AbilityAccess
Read / Get / Create / Update / Delete Postsread / write
Read / Create / Update / Delete Pagesread / write
Read Categories & Tags / Createread / write
Read / Approve / Delete Commentsread / write
List / Get / Count Mediaread
Update / Delete / Upload Media (from URL or base64)write
Read Usersread
Create / Update Userswrite
Search Contentread
Read Site Info & Active Pluginsread
Update Site Info (title, tagline, admin email) / Permalink Structurewrite
Activate / Deactivate Pluginswrite
Read Themesread
Switch Themewrite
Read Menus / Menu Items / Menu Locationsread
Create / Delete Menu, Add / Update / Delete Menu Item, Assign Locationwrite

Yoast SEO (requires Yoast SEO plugin)

AbilityAccess
Get Yoast SEO Meta (title, meta description, focus keyphrase)read
Update Yoast SEO Metawrite

Rank Math SEO (requires Rank Math plugin)

AbilityAccess
Get Rank Math SEO Meta (title, description, focus keyword, score)read
Update Rank Math SEO Metawrite

Elementor (requires Elementor plugin)

AbilityAccess
List Elementor Pages / Templatesread
Get Page Structure / Element Settings / Find Elementread
Update Element, Add Widget, Add Container / Section, Remove Elementwrite
Duplicate / Move Element, Copy Element Styleswrite
Get / Update Active Kit (global colors, fonts, layout)read / write
Get / Update Page Settingsread / write
Get Widget Schema / Breakpointsread
Convert CSS to Elementor Settingswrite
Regenerate CSSwrite

20 tools. update-active-kit and regenerate-css require manage_options; the rest require edit_posts. All writes run through wsp_elementor_sanitize_settings().

Ultimate Addons for Elementor (requires UAE plugin)

AbilityAccess
List UAE Widgets / Check Widget Usageread
Activate / Deactivate / Bulk Toggle Widgetswrite
List / Get Header, Footer & Blocks Templatesread
Create / Duplicate / Update / Trash / Restore Templatewrite
Add Section / Add Column / Move Element / Build Layout from JSONwrite
Get UAE Settings / Theme Info / Extensions / Design Tokensread
Update UAE Settings / Design Tokenswrite

45 tools, off by default. Writes require edit_posts, publish_posts, or manage_options.

WooCommerce (requires WooCommerce plugin)

AbilityAccess
List / Get Productsread
Create Product / Create Variation / Update Productwrite
List Orders / Update Order Statusread / write
Refund Order (requires manage_woocommerce)write
Create / List Coupons (requires manage_woocommerce)write / read
Create Order Notewrite
List Customers (requires manage_woocommerce)read
Sales Report / Low-Stock Alertsread
Moderate Product Reviewswrite

Advanced Custom Fields (requires ACF plugin)

AbilityAccess
List / Get Field Groupsread
Create / Update / Delete / Import Field Groupwrite
List / Get Fieldsread
Create / Update / Delete / Duplicate Field, Force Syncwrite
Get / Get-All / Get Field Object (values)read
Update Deep (dot-notation) / Bulk Update / Delete Valuewrite
List Post Types / Taxonomiesread
Create Custom Post Type / Taxonomy (ACF 6.1+)write
List / Create Options Page (create needs ACF Pro)read / write
Get / Update Option Valueread / write

27 tools. Value reads/writes accept a post/page ID, user_<id>, term_<id>, or options and enforce per-object capabilities. Structural changes require manage_options.

Gravity Forms (requires Gravity Forms plugin)

AbilityAccess
List / Get Formsread
Create / Update / Delete Form, Update Form Settingswrite
List / Get Entriesread
Update / Delete Entrywrite
Get / Create / Update / Delete Notificationsread / write
Get / Create / Update / Delete Confirmationsread / write

18 tools. List Forms and Get Form are ON by default. Uses Gravity Forms' own capabilities.

Contact Form 7 (requires Contact Form 7 plugin)

AbilityAccess
List / Get Formsread
Create / Update / Delete Formwrite
List / Get Entries (requires Flamingo)read
Validate Formread
Get Integrations (modules, reCAPTCHA status)read
Moderate Entry (spam / unspam / trash / untrash)write

10 tools. List Forms and Get Form are ON by default. Uses CF7's own capabilities; get-integrations requires manage_options.

WPForms (requires WPForms Lite or Pro)

AbilityAccess
List / Get Forms, Describe Schema, Get Form Statsread
Create Form, Update Form Settings, Add / Update Field, Delete Formwrite
List / Get / Delete Entries (WPForms Pro)read / write

12 tools. List Forms, Get Form, Describe Schema, and Get Form Stats are ON by default. Uses WPForms' own capabilities.


🏢 About WebSensePro

Built by WebSensePro — WordPress & Shopify agency from Queens, NY.