Atlas / MCP servers / deus-h / Claudeus WordPress

Claudeus WordPressSAFE

mcp/deus-h/claudeus-wordpress

Claudeus WordPress MCP Server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
155 77r · 59w · 19d
Transport
sse · stdio
License
NOASSERTION
Stars
162
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

"The Most Comprehensive WordPress MCP Server - 145 Tools, Zero Compromise!" 🖤

[](https://github.com/deus-h/claudeus-wp-mcp/stargazers) [](https://www.npmjs.com/package/claudeus-wp-mcp) [](https://github.com/deus-h/claudeus-wp-mcp)

🔥 The Complete WordPress AI Powerhouse

145 Production-Ready Tools covering every aspect of WordPress management, from content creation to site health monitoring, all powered by AI and built with enterprise-grade quality.

╔═══════════════════════════════════════════════════════╗
║         🎯 COMPLETE WORDPRESS COVERAGE 🎯            ║
╚═══════════════════════════════════════════════════════╝

✅ Content Management          25 tools
✅ Media & Assets              6 tools
✅ Taxonomies                  12 tools
✅ User Management             10 tools
✅ Comments & Moderation       8 tools
✅ Menus & Navigation          10 tools
✅ Full Site Editing (FSE)     27 tools
✅ Astra Pro Integration       11 tools
✅ Site Configuration          15 tools
✅ Site Health & Diagnostics   8 tools
✅ Search & Discovery          5 tools
✅ WooCommerce                 3 tools
✅ System Discovery            5 tools

📊 TOTAL: 145 PRODUCTION-READY TOOLS

⚡ What Makes It Legendary?

🎸 Complete WordPress Ecosystem Coverage

  • Content Mastery: Full CRUD for Posts, Pages, Blocks with revisions & autosaves
  • FSE Powerhouse: Templates, Global Sty
Read from source at commit d5da1d144006OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add claudeus-wp-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "claudeus-wp-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (155)

77 read · 59 write · 19 destructive. Blast radius: 19 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
analyze-post-seowriteAnalyze a post
bulk-update-postswritePlan and execute bulk updates to multiple posts
claudeus_wp_astra__create_custom_layoutwriteCreate a new Astra custom layout. Create custom headers, footers, or hook-based layouts with conditional display rules.
claudeus_wp_astra__delete_custom_layoutdestructiveDelete an Astra custom layout. Removes the custom header, footer, or hook layout.
claudeus_wp_astra__disable_mega_menuwriteDisable Astra mega menu for a menu item. Reverts the menu item to standard dropdown behavior.
claudeus_wp_astra__enable_mega_menuwriteEnable Astra mega menu for a menu item with default settings. Quick way to turn a regular menu item into a mega menu.
claudeus_wp_astra__get_custom_layoutreadGet a specific Astra custom layout by ID. View configuration, content, and display rules.
claudeus_wp_astra__get_custom_layoutsreadGet all Astra custom layouts (headers, footers, hooks). List all conditional layout overrides.
claudeus_wp_astra__get_mega_menureadGet Astra mega menu configuration for a specific menu item. Shows columns, content, and display settings for advanced dropdown menus.
claudeus_wp_astra__get_settingsreadGet all Astra theme settings. Returns complete theme configuration including header, footer, colors, typography, layout, and more.
claudeus_wp_astra__update_custom_layoutwriteUpdate an existing Astra custom layout. Modify content, display rules, or settings.
claudeus_wp_astra__update_mega_menuwriteCreate or update Astra mega menu configuration. Configure columns, content, display mode, and styling for advanced dropdown menus.
claudeus_wp_astra__update_settingswriteUpdate Astra theme settings. Configure header, footer, colors, typography, layout settings, and more.
claudeus_wp_comments__approvereadApprove a comment. Change comment status to
claudeus_wp_comments__create_commentwriteCreate a new comment on a post. Requires post ID and comment content.
claudeus_wp_comments__delete_commentdestructiveDelete a comment permanently or move to trash.
claudeus_wp_comments__get_commentreadGet a single comment by ID. Retrieve detailed information about a specific comment.
claudeus_wp_comments__get_commentswriteGet a list of comments with optional filters. Retrieve comments by post, author, status, date range, and more.
claudeus_wp_comments__spamreadMark a comment as spam. Removes it from public view and marks it for spam filtering.
claudeus_wp_comments__trashwriteMove a comment to trash. Comment can be restored later or permanently deleted.
claudeus_wp_comments__update_commentwriteUpdate an existing comment. Modify comment content, author info, or status.
claudeus_wp_content__create_blockwriteCreate a new reusable block
claudeus_wp_content__create_block_autosavewriteCreate an autosave for a reusable block
claudeus_wp_content__create_pagewriteCreate a new page
claudeus_wp_content__create_page_autosavewriteCreate an autosave for a page
claudeus_wp_content__create_postwriteCreate a new post
claudeus_wp_content__create_post_autosavewriteCreate an autosave for a post
claudeus_wp_content__delete_blockdestructiveDelete a reusable block
claudeus_wp_content__delete_block_revisiondestructiveDelete a specific block revision permanently
claudeus_wp_content__delete_pagedestructiveDelete a page
claudeus_wp_content__delete_page_revisiondestructiveDelete a specific page revision permanently
claudeus_wp_content__delete_postdestructiveDelete a post
claudeus_wp_content__delete_post_revisiondestructiveDelete a specific post revision permanently
claudeus_wp_content__get_block_autosavereadGet a specific autosave of a reusable block
claudeus_wp_content__get_block_autosavesreadGet all autosaves of a reusable block
claudeus_wp_content__get_block_revisionreadGet a specific revision of a reusable block
claudeus_wp_content__get_block_revisionsreadGet all revisions of a reusable block with pagination
claudeus_wp_content__get_blocksreadGet a list of reusable blocks
claudeus_wp_content__get_page_autosavereadGet a specific autosave of a page
claudeus_wp_content__get_page_autosavesreadGet all autosaves of a page
claudeus_wp_content__get_page_revisionreadGet a specific revision of a page
claudeus_wp_content__get_page_revisionsreadGet all revisions of a page with pagination
claudeus_wp_content__get_pagesreadGet a list of pages with optional filters
claudeus_wp_content__get_post_autosavewriteGet a specific autosave of a post
claudeus_wp_content__get_post_autosaveswriteGet all autosaves of a post
claudeus_wp_content__get_post_revisionwriteGet a specific revision of a post
claudeus_wp_content__get_post_revisionswriteGet all revisions of a post with pagination
claudeus_wp_content__get_postsreadGet a list of posts with optional filters
claudeus_wp_content__update_blockwriteUpdate an existing reusable block
claudeus_wp_content__update_pagewriteUpdate an existing page
claudeus_wp_content__update_postwriteUpdate an existing post
claudeus_wp_discover_endpointsreadDiscover available WordPress REST API endpoints
claudeus_wp_global_styles__getreadGet the current global styles for the site. Returns the customized theme.json settings and styles.
claudeus_wp_global_styles__get_revisionreadGet a specific revision of global styles. View a past version of global styles.
claudeus_wp_global_styles__get_revisionsreadGet revision history for global styles. View all past changes to global styles.
claudeus_wp_global_styles__get_themereadGet the default global styles for a specific theme. Returns the theme\
claudeus_wp_global_styles__get_variationsreadGet available style variations for a theme. Returns all pre-defined style variations.
claudeus_wp_global_styles__updatewriteUpdate global styles for the site. Modify colors, typography, spacing, and other design settings.
claudeus_wp_health__get_directory_sizesreadGet directory sizes. Retrieve storage usage for WordPress directories (core, themes, plugins, uploads, database).
claudeus_wp_health__run_all_testswriteRun all site health tests. Execute all available health checks in parallel and return comprehensive results.
claudeus_wp_health__test_authreadTest authorization header. Verify that REST API authentication is working correctly.
claudeus_wp_health__test_background_updatesreadTest background updates. Check if WordPress can perform background updates for core, plugins, and themes.
claudeus_wp_health__test_dotorg_communicationreadTest WordPress.org communication. Verify that the site can connect to WordPress.org for updates and resources.
claudeus_wp_health__test_httpsreadTest HTTPS status. Check if the site is using HTTPS correctly and if SSL certificate is valid.
claudeus_wp_health__test_loopbackreadTest loopback requests. Verify that the site can make HTTP requests to itself (required for WP-Cron and other features).
claudeus_wp_health__test_page_cachereadTest page cache configuration. Check if page caching is working correctly.
claudeus_wp_media__deletedestructiveDelete a media item
claudeus_wp_media__get_mediareadGet a list of media items with optional filters
claudeus_wp_media__updatewriteUpdate media item metadata
claudeus_wp_media__uploadwriteUpload a new media item
claudeus_wp_menus__create_menuwriteCreate a new navigation menu. Set up a new menu that can be assigned to theme locations.
claudeus_wp_menus__create_menu_itemwriteCreate a new menu item. Add a link, page, post, or custom item to a menu.
claudeus_wp_menus__delete_menudestructiveDelete a navigation menu. Remove a menu and unassign it from all locations.
claudeus_wp_menus__delete_menu_itemdestructiveDelete a menu item. Remove an item from a menu.
claudeus_wp_menus__get_locationsreadGet all menu locations registered by the active theme. Shows where menus can be displayed.
claudeus_wp_menus__get_menureadGet a single menu by ID. Retrieve detailed information about a specific navigation menu.
claudeus_wp_menus__get_menu_itemsreadGet a list of menu items. Retrieve items from all menus or filter by specific menu ID.
claudeus_wp_menus__get_menusreadGet a list of navigation menus. Retrieve all WordPress menus with pagination and filtering.
claudeus_wp_menus__update_menuwriteUpdate an existing navigation menu. Modify menu properties, name, or location assignments.
claudeus_wp_menus__update_menu_itemwriteUpdate an existing menu item. Modify text, URL, order, parent, or other properties.
claudeus_wp_patterns__get_categoriesreadGet all pattern categories. Lists categories like
claudeus_wp_patterns__get_localreadGet all registered block patterns from the site. Includes patterns from core, active theme, and plugins.
claudeus_wp_patterns__search_directoryreadSearch the WordPress.org pattern directory. Browse thousands of patterns from the community.
claudeus_wp_plugins__activatewriteActivate a plugin. Enable a currently inactive plugin.
claudeus_wp_plugins__deactivatewriteDeactivate a plugin. Disable a currently active plugin without deleting it.
claudeus_wp_plugins__deletedestructiveDelete a plugin. Permanently remove an inactive plugin from the site. Plugin must be deactivated first.
claudeus_wp_plugins__getreadGet details for a specific plugin. View name, version, author, description, status, and update availability.
claudeus_wp_plugins__listreadList all installed WordPress plugins. View active, inactive, and network-active plugins with details.
claudeus_wp_search__block_directoryreadSearch WordPress.org block directory. Find and discover blocks available for installation from the official block directory.
claudeus_wp_search__get_url_detailsreadGet URL metadata for block editor. Retrieve page title, description, icon, and image for creating rich link previews in blocks.
claudeus_wp_search__oembedreadGet oEmbed data for a URL. Retrieve rich embed data (video, images, metadata) for embedding external content.
claudeus_wp_search__oembed_proxyreadGet oEmbed data via proxy. Retrieve oEmbed data for external URLs through WordPress proxy.
claudeus_wp_search__searchreadUniversal search across all content. Search posts, pages, categories, tags, and other content types in a single request.
claudeus_wp_settings__getreadGet all WordPress site settings. Returns site title, tagline, email, timezone, date/time formats, and more.
claudeus_wp_settings__get_post_statuseswriteGet all registered post statuses. Returns publish, draft, pending, private, and custom statuses with their properties.
claudeus_wp_settings__get_post_typewriteGet details for a specific post type. View capabilities, labels, taxonomies, and configuration for any post type.
claudeus_wp_settings__get_post_typeswriteGet all registered post types. Returns built-in types (post, page, attachment) and custom post types with their capabilities and settings.
claudeus_wp_settings__updatewriteUpdate WordPress site settings. Modify site title, tagline, email, timezone, formats, default category, posts per page, and more.
claudeus_wp_shop__get_ordersreadGet a list of orders with optional filters
claudeus_wp_shop__get_productsreadGet a list of products with optional filters
claudeus_wp_shop__get_salesreadGet sales statistics with optional filters
claudeus_wp_taxonomy__create_categorywriteCreate a new category
claudeus_wp_taxonomy__create_tagwriteCreate a new tag
claudeus_wp_taxonomy__delete_categorydestructiveDelete a category
claudeus_wp_taxonomy__delete_tagdestructiveDelete a tag
claudeus_wp_taxonomy__get_categoriesreadGet a list of categories with optional filters. Categories are hierarchical terms used to organize posts.
claudeus_wp_taxonomy__get_categoryreadGet a single category by ID
claudeus_wp_taxonomy__get_tagreadGet a single tag by ID
claudeus_wp_taxonomy__get_tagsreadGet a list of tags with optional filters. Tags are non-hierarchical terms used to organize posts.
claudeus_wp_taxonomy__get_taxonomiesreadGet all registered taxonomies on the WordPress site
claudeus_wp_taxonomy__get_taxonomyreadGet a specific taxonomy by slug
claudeus_wp_taxonomy__update_categorywriteUpdate an existing category
claudeus_wp_taxonomy__update_tagwriteUpdate an existing tag
claudeus_wp_templates__create_templatewriteCreate a new custom template. Create templates for posts, pages, or custom post types.
claudeus_wp_templates__create_template_partwriteCreate a new template part. Create custom headers, footers, sidebars, or general template parts.
claudeus_wp_templates__delete_templatedestructiveDelete a custom template. Removes user-created templates (theme templates cannot be deleted).
claudeus_wp_templates__delete_template_partdestructiveDelete a custom template part. Removes user-created template parts (theme template parts cannot be deleted).
claudeus_wp_templates__get_templatereadGet a specific template by ID. Template IDs are in slug format (e.g.,
claudeus_wp_templates__get_template_partreadGet a specific template part by ID. Retrieve header, footer, or other template part.
claudeus_wp_templates__get_template_partsreadGet a list of template parts (headers, footers, etc.). List all available template parts for the active theme.
claudeus_wp_templates__get_templatesreadGet a list of block theme templates (FSE). List all available templates for the active theme.
claudeus_wp_templates__update_templatewriteUpdate an existing template. Modify template content, title, or other properties.
claudeus_wp_templates__update_template_partwriteUpdate an existing template part. Modify template part content, area, or other properties.
claudeus_wp_theme__activatereadActivate a theme by stylesheet name
claudeus_wp_theme__get_activereadGet the currently active theme
claudeus_wp_theme__get_custom_cssreadGet theme custom CSS
claudeus_wp_theme__get_customizationreadGet theme customization settings including custom CSS and theme mods
claudeus_wp_theme__listreadGet a list of installed themes
claudeus_wp_theme__update_custom_csswriteUpdate theme custom CSS
claudeus_wp_theme__update_customizationwriteUpdate theme customization settings
claudeus_wp_users__create_app_passwordwriteCreate a new application password for a user. Application passwords allow authentication without exposing the user\
claudeus_wp_users__create_userwriteCreate a new WordPress user. Requires username, email, and password.
claudeus_wp_users__delete_userdestructiveDelete a WordPress user. Can reassign their content to another user.
claudeus_wp_users__get_mereadGet the currently authenticated user. Returns information about the user making the request.
claudeus_wp_users__get_userreadGet a single user by ID. Retrieve detailed information about a specific WordPress user.
claudeus_wp_users__get_usersreadGet a list of users with optional filters. Retrieve WordPress users with pagination and filtering.
claudeus_wp_users__introspect_passwordreadValidate and introspect the current application password. Checks if the application password in the current request is valid.
claudeus_wp_users__list_app_passwordsreadList all application passwords for a user. Shows all active application passwords and when they were last used.
claudeus_wp_users__revoke_app_passworddestructiveRevoke (delete) a specific application password. Immediately invalidates the password.
claudeus_wp_users__update_userwriteUpdate an existing WordPress user. Modify user details, roles, or profile information.
claudeus_wp_widgets__create_widgetwriteCreate a new widget and add it to a sidebar. Add text widgets, category lists, recent posts, custom HTML, and more.
claudeus_wp_widgets__delete_widgetdestructiveDelete a widget. Remove widget instance from its sidebar permanently.
claudeus_wp_widgets__get_sidebarreadGet a specific sidebar by ID. View sidebar configuration and all widgets assigned to it.
claudeus_wp_widgets__get_sidebarsreadGet all registered sidebars. List all widget areas with their configuration and assigned widgets.
claudeus_wp_widgets__get_widgetreadGet a specific widget by ID. View widget type, settings, sidebar placement, and rendered HTML.
claudeus_wp_widgets__get_widgetsreadGet all widgets. List all widget instances across all sidebars with their settings and rendered output.
claudeus_wp_widgets__update_widgetwriteUpdate an existing widget. Modify widget settings, move to different sidebar, or change configuration.
create-blog-postwriteGenerate a blog post with SEO optimization
criteriawriteCriteria to select posts for update (JSON)
keywordsreadTarget SEO keywords (comma-separated)
post_idwriteID of the post to analyze
target_keywordsreadTarget keywords to check against
tonereadWriting tone (e.g. professional, casual, technical)
topicwriteMain topic or subject of the blog post
updateswriteUpdates to apply to selected posts (JSON)
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (8 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
claudeus_wp_astra__delete_custom_layout, claudeus_wp_comments__delete_comment, claudeus_wp_content__delete_block, claudeus_wp_content__delete_block_revision, claudeus_wp_content__delete_page, claudeus
Why it matters. 19 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/test/unit/server/mcp-server.test.ts:2
import { McpServer } from '../../../mcp/server.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/test/unit/server/mcp-server.test.ts:3
import { TestTransport, JsonRpcMessage } from '../../utils/test-transport.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/test/utils/test-transport.ts:2
import { McpServer } from '../../mcp/server.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/astra/handlers.ts:1
import { AstraApiClient } from '../../api/astra.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/astra/handlers.ts:2
import { AstraMegaMenuData, AstraCustomLayoutData } from '../../types/index.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, cors, dotenv, express, form-data, tailwindcss, zod
Why it matters. 22 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
SETUP-GUIDE.md:282
**Administrator role has all capabilities** - recommended for full access.
INFOPrompt injection · prompt.persistence · CWE-94, CWE-1427
SETUP-GUIDE.md:381
# Permanent (add to ~/.zshrc or ~/.bashrc)
Why it matters. instructs the agent to persist itself in the user's environment

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha d5da1d144006full audit observations/trust-audit/mcp-server/deus-h__claudeus-wordpress.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07d5da1d144006SAFEB89first audit
06

Questions

What is the Claudeus WordPress MCP server?

Claudeus WordPress MCP Server

What tools does Claudeus WordPress expose?

155 in total: 77 read-only, 59 that write, and 19 that can delete or overwrite (claudeus_wp_astra__delete_custom_layout, claudeus_wp_comments__delete_comment, claudeus_wp_content__delete_block, claudeus_wp_content__delete_block_revision, claudeus_wp_content__delete_page). Every one is listed on this page with its risk.

Is Claudeus WordPress safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 19 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Claudeus WordPress need?

No credential environment variables were found in its source, so it appears to need none.

How does Claudeus WordPress run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as claudeus-wp-mcp at 3.0.2.

How current is this page?

The grade is for one exact copy of the source (d5da1d144006), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement