Claudeus WordPressSAFE
Claudeus WordPress MCP Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
"The Most Comprehensive WordPress MCP Server - 145 Tools, Zero Compromise!" 🖤
[](https://github.com/deus-h/claudeus-wp-mcp/stargazers) [](https://www.npmjs.com/package/claudeus-wp-mcp) [](https://github.com/deus-h/claudeus-wp-mcp)
🔥 The Complete WordPress AI Powerhouse
145 Production-Ready Tools covering every aspect of WordPress management, from content creation to site health monitoring, all powered by AI and built with enterprise-grade quality.
╔═══════════════════════════════════════════════════════╗ ║ 🎯 COMPLETE WORDPRESS COVERAGE 🎯 ║ ╚═══════════════════════════════════════════════════════╝ ✅ Content Management 25 tools ✅ Media & Assets 6 tools ✅ Taxonomies 12 tools ✅ User Management 10 tools ✅ Comments & Moderation 8 tools ✅ Menus & Navigation 10 tools ✅ Full Site Editing (FSE) 27 tools ✅ Astra Pro Integration 11 tools ✅ Site Configuration 15 tools ✅ Site Health & Diagnostics 8 tools ✅ Search & Discovery 5 tools ✅ WooCommerce 3 tools ✅ System Discovery 5 tools 📊 TOTAL: 145 PRODUCTION-READY TOOLS
⚡ What Makes It Legendary?
🎸 Complete WordPress Ecosystem Coverage
- Content Mastery: Full CRUD for Posts, Pages, Blocks with revisions & autosaves
- FSE Powerhouse: Templates, Global Sty
d5da1d144006OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add claudeus-wp-mcp -- npx -y [email protected]
{
"mcpServers": {
"claudeus-wp-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (155)
77 read · 59 write · 19 destructive. Blast radius: 19 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
analyze-post-seo | write | Analyze a post |
bulk-update-posts | write | Plan and execute bulk updates to multiple posts |
claudeus_wp_astra__create_custom_layout | write | Create a new Astra custom layout. Create custom headers, footers, or hook-based layouts with conditional display rules. |
claudeus_wp_astra__delete_custom_layout | destructive | Delete an Astra custom layout. Removes the custom header, footer, or hook layout. |
claudeus_wp_astra__disable_mega_menu | write | Disable Astra mega menu for a menu item. Reverts the menu item to standard dropdown behavior. |
claudeus_wp_astra__enable_mega_menu | write | Enable Astra mega menu for a menu item with default settings. Quick way to turn a regular menu item into a mega menu. |
claudeus_wp_astra__get_custom_layout | read | Get a specific Astra custom layout by ID. View configuration, content, and display rules. |
claudeus_wp_astra__get_custom_layouts | read | Get all Astra custom layouts (headers, footers, hooks). List all conditional layout overrides. |
claudeus_wp_astra__get_mega_menu | read | Get Astra mega menu configuration for a specific menu item. Shows columns, content, and display settings for advanced dropdown menus. |
claudeus_wp_astra__get_settings | read | Get all Astra theme settings. Returns complete theme configuration including header, footer, colors, typography, layout, and more. |
claudeus_wp_astra__update_custom_layout | write | Update an existing Astra custom layout. Modify content, display rules, or settings. |
claudeus_wp_astra__update_mega_menu | write | Create or update Astra mega menu configuration. Configure columns, content, display mode, and styling for advanced dropdown menus. |
claudeus_wp_astra__update_settings | write | Update Astra theme settings. Configure header, footer, colors, typography, layout settings, and more. |
claudeus_wp_comments__approve | read | Approve a comment. Change comment status to |
claudeus_wp_comments__create_comment | write | Create a new comment on a post. Requires post ID and comment content. |
claudeus_wp_comments__delete_comment | destructive | Delete a comment permanently or move to trash. |
claudeus_wp_comments__get_comment | read | Get a single comment by ID. Retrieve detailed information about a specific comment. |
claudeus_wp_comments__get_comments | write | Get a list of comments with optional filters. Retrieve comments by post, author, status, date range, and more. |
claudeus_wp_comments__spam | read | Mark a comment as spam. Removes it from public view and marks it for spam filtering. |
claudeus_wp_comments__trash | write | Move a comment to trash. Comment can be restored later or permanently deleted. |
claudeus_wp_comments__update_comment | write | Update an existing comment. Modify comment content, author info, or status. |
claudeus_wp_content__create_block | write | Create a new reusable block |
claudeus_wp_content__create_block_autosave | write | Create an autosave for a reusable block |
claudeus_wp_content__create_page | write | Create a new page |
claudeus_wp_content__create_page_autosave | write | Create an autosave for a page |
claudeus_wp_content__create_post | write | Create a new post |
claudeus_wp_content__create_post_autosave | write | Create an autosave for a post |
claudeus_wp_content__delete_block | destructive | Delete a reusable block |
claudeus_wp_content__delete_block_revision | destructive | Delete a specific block revision permanently |
claudeus_wp_content__delete_page | destructive | Delete a page |
claudeus_wp_content__delete_page_revision | destructive | Delete a specific page revision permanently |
claudeus_wp_content__delete_post | destructive | Delete a post |
claudeus_wp_content__delete_post_revision | destructive | Delete a specific post revision permanently |
claudeus_wp_content__get_block_autosave | read | Get a specific autosave of a reusable block |
claudeus_wp_content__get_block_autosaves | read | Get all autosaves of a reusable block |
claudeus_wp_content__get_block_revision | read | Get a specific revision of a reusable block |
claudeus_wp_content__get_block_revisions | read | Get all revisions of a reusable block with pagination |
claudeus_wp_content__get_blocks | read | Get a list of reusable blocks |
claudeus_wp_content__get_page_autosave | read | Get a specific autosave of a page |
claudeus_wp_content__get_page_autosaves | read | Get all autosaves of a page |
claudeus_wp_content__get_page_revision | read | Get a specific revision of a page |
claudeus_wp_content__get_page_revisions | read | Get all revisions of a page with pagination |
claudeus_wp_content__get_pages | read | Get a list of pages with optional filters |
claudeus_wp_content__get_post_autosave | write | Get a specific autosave of a post |
claudeus_wp_content__get_post_autosaves | write | Get all autosaves of a post |
claudeus_wp_content__get_post_revision | write | Get a specific revision of a post |
claudeus_wp_content__get_post_revisions | write | Get all revisions of a post with pagination |
claudeus_wp_content__get_posts | read | Get a list of posts with optional filters |
claudeus_wp_content__update_block | write | Update an existing reusable block |
claudeus_wp_content__update_page | write | Update an existing page |
claudeus_wp_content__update_post | write | Update an existing post |
claudeus_wp_discover_endpoints | read | Discover available WordPress REST API endpoints |
claudeus_wp_global_styles__get | read | Get the current global styles for the site. Returns the customized theme.json settings and styles. |
claudeus_wp_global_styles__get_revision | read | Get a specific revision of global styles. View a past version of global styles. |
claudeus_wp_global_styles__get_revisions | read | Get revision history for global styles. View all past changes to global styles. |
claudeus_wp_global_styles__get_theme | read | Get the default global styles for a specific theme. Returns the theme\ |
claudeus_wp_global_styles__get_variations | read | Get available style variations for a theme. Returns all pre-defined style variations. |
claudeus_wp_global_styles__update | write | Update global styles for the site. Modify colors, typography, spacing, and other design settings. |
claudeus_wp_health__get_directory_sizes | read | Get directory sizes. Retrieve storage usage for WordPress directories (core, themes, plugins, uploads, database). |
claudeus_wp_health__run_all_tests | write | Run all site health tests. Execute all available health checks in parallel and return comprehensive results. |
claudeus_wp_health__test_auth | read | Test authorization header. Verify that REST API authentication is working correctly. |
claudeus_wp_health__test_background_updates | read | Test background updates. Check if WordPress can perform background updates for core, plugins, and themes. |
claudeus_wp_health__test_dotorg_communication | read | Test WordPress.org communication. Verify that the site can connect to WordPress.org for updates and resources. |
claudeus_wp_health__test_https | read | Test HTTPS status. Check if the site is using HTTPS correctly and if SSL certificate is valid. |
claudeus_wp_health__test_loopback | read | Test loopback requests. Verify that the site can make HTTP requests to itself (required for WP-Cron and other features). |
claudeus_wp_health__test_page_cache | read | Test page cache configuration. Check if page caching is working correctly. |
claudeus_wp_media__delete | destructive | Delete a media item |
claudeus_wp_media__get_media | read | Get a list of media items with optional filters |
claudeus_wp_media__update | write | Update media item metadata |
claudeus_wp_media__upload | write | Upload a new media item |
claudeus_wp_menus__create_menu | write | Create a new navigation menu. Set up a new menu that can be assigned to theme locations. |
claudeus_wp_menus__create_menu_item | write | Create a new menu item. Add a link, page, post, or custom item to a menu. |
claudeus_wp_menus__delete_menu | destructive | Delete a navigation menu. Remove a menu and unassign it from all locations. |
claudeus_wp_menus__delete_menu_item | destructive | Delete a menu item. Remove an item from a menu. |
claudeus_wp_menus__get_locations | read | Get all menu locations registered by the active theme. Shows where menus can be displayed. |
claudeus_wp_menus__get_menu | read | Get a single menu by ID. Retrieve detailed information about a specific navigation menu. |
claudeus_wp_menus__get_menu_items | read | Get a list of menu items. Retrieve items from all menus or filter by specific menu ID. |
claudeus_wp_menus__get_menus | read | Get a list of navigation menus. Retrieve all WordPress menus with pagination and filtering. |
claudeus_wp_menus__update_menu | write | Update an existing navigation menu. Modify menu properties, name, or location assignments. |
claudeus_wp_menus__update_menu_item | write | Update an existing menu item. Modify text, URL, order, parent, or other properties. |
claudeus_wp_patterns__get_categories | read | Get all pattern categories. Lists categories like |
claudeus_wp_patterns__get_local | read | Get all registered block patterns from the site. Includes patterns from core, active theme, and plugins. |
claudeus_wp_patterns__search_directory | read | Search the WordPress.org pattern directory. Browse thousands of patterns from the community. |
claudeus_wp_plugins__activate | write | Activate a plugin. Enable a currently inactive plugin. |
claudeus_wp_plugins__deactivate | write | Deactivate a plugin. Disable a currently active plugin without deleting it. |
claudeus_wp_plugins__delete | destructive | Delete a plugin. Permanently remove an inactive plugin from the site. Plugin must be deactivated first. |
claudeus_wp_plugins__get | read | Get details for a specific plugin. View name, version, author, description, status, and update availability. |
claudeus_wp_plugins__list | read | List all installed WordPress plugins. View active, inactive, and network-active plugins with details. |
claudeus_wp_search__block_directory | read | Search WordPress.org block directory. Find and discover blocks available for installation from the official block directory. |
claudeus_wp_search__get_url_details | read | Get URL metadata for block editor. Retrieve page title, description, icon, and image for creating rich link previews in blocks. |
claudeus_wp_search__oembed | read | Get oEmbed data for a URL. Retrieve rich embed data (video, images, metadata) for embedding external content. |
claudeus_wp_search__oembed_proxy | read | Get oEmbed data via proxy. Retrieve oEmbed data for external URLs through WordPress proxy. |
claudeus_wp_search__search | read | Universal search across all content. Search posts, pages, categories, tags, and other content types in a single request. |
claudeus_wp_settings__get | read | Get all WordPress site settings. Returns site title, tagline, email, timezone, date/time formats, and more. |
claudeus_wp_settings__get_post_statuses | write | Get all registered post statuses. Returns publish, draft, pending, private, and custom statuses with their properties. |
claudeus_wp_settings__get_post_type | write | Get details for a specific post type. View capabilities, labels, taxonomies, and configuration for any post type. |
claudeus_wp_settings__get_post_types | write | Get all registered post types. Returns built-in types (post, page, attachment) and custom post types with their capabilities and settings. |
claudeus_wp_settings__update | write | Update WordPress site settings. Modify site title, tagline, email, timezone, formats, default category, posts per page, and more. |
claudeus_wp_shop__get_orders | read | Get a list of orders with optional filters |
claudeus_wp_shop__get_products | read | Get a list of products with optional filters |
claudeus_wp_shop__get_sales | read | Get sales statistics with optional filters |
claudeus_wp_taxonomy__create_category | write | Create a new category |
claudeus_wp_taxonomy__create_tag | write | Create a new tag |
claudeus_wp_taxonomy__delete_category | destructive | Delete a category |
claudeus_wp_taxonomy__delete_tag | destructive | Delete a tag |
claudeus_wp_taxonomy__get_categories | read | Get a list of categories with optional filters. Categories are hierarchical terms used to organize posts. |
claudeus_wp_taxonomy__get_category | read | Get a single category by ID |
claudeus_wp_taxonomy__get_tag | read | Get a single tag by ID |
claudeus_wp_taxonomy__get_tags | read | Get a list of tags with optional filters. Tags are non-hierarchical terms used to organize posts. |
claudeus_wp_taxonomy__get_taxonomies | read | Get all registered taxonomies on the WordPress site |
claudeus_wp_taxonomy__get_taxonomy | read | Get a specific taxonomy by slug |
claudeus_wp_taxonomy__update_category | write | Update an existing category |
claudeus_wp_taxonomy__update_tag | write | Update an existing tag |
claudeus_wp_templates__create_template | write | Create a new custom template. Create templates for posts, pages, or custom post types. |
claudeus_wp_templates__create_template_part | write | Create a new template part. Create custom headers, footers, sidebars, or general template parts. |
claudeus_wp_templates__delete_template | destructive | Delete a custom template. Removes user-created templates (theme templates cannot be deleted). |
claudeus_wp_templates__delete_template_part | destructive | Delete a custom template part. Removes user-created template parts (theme template parts cannot be deleted). |
claudeus_wp_templates__get_template | read | Get a specific template by ID. Template IDs are in slug format (e.g., |
claudeus_wp_templates__get_template_part | read | Get a specific template part by ID. Retrieve header, footer, or other template part. |
claudeus_wp_templates__get_template_parts | read | Get a list of template parts (headers, footers, etc.). List all available template parts for the active theme. |
claudeus_wp_templates__get_templates | read | Get a list of block theme templates (FSE). List all available templates for the active theme. |
claudeus_wp_templates__update_template | write | Update an existing template. Modify template content, title, or other properties. |
claudeus_wp_templates__update_template_part | write | Update an existing template part. Modify template part content, area, or other properties. |
claudeus_wp_theme__activate | read | Activate a theme by stylesheet name |
claudeus_wp_theme__get_active | read | Get the currently active theme |
claudeus_wp_theme__get_custom_css | read | Get theme custom CSS |
claudeus_wp_theme__get_customization | read | Get theme customization settings including custom CSS and theme mods |
claudeus_wp_theme__list | read | Get a list of installed themes |
claudeus_wp_theme__update_custom_css | write | Update theme custom CSS |
claudeus_wp_theme__update_customization | write | Update theme customization settings |
claudeus_wp_users__create_app_password | write | Create a new application password for a user. Application passwords allow authentication without exposing the user\ |
claudeus_wp_users__create_user | write | Create a new WordPress user. Requires username, email, and password. |
claudeus_wp_users__delete_user | destructive | Delete a WordPress user. Can reassign their content to another user. |
claudeus_wp_users__get_me | read | Get the currently authenticated user. Returns information about the user making the request. |
claudeus_wp_users__get_user | read | Get a single user by ID. Retrieve detailed information about a specific WordPress user. |
claudeus_wp_users__get_users | read | Get a list of users with optional filters. Retrieve WordPress users with pagination and filtering. |
claudeus_wp_users__introspect_password | read | Validate and introspect the current application password. Checks if the application password in the current request is valid. |
claudeus_wp_users__list_app_passwords | read | List all application passwords for a user. Shows all active application passwords and when they were last used. |
claudeus_wp_users__revoke_app_password | destructive | Revoke (delete) a specific application password. Immediately invalidates the password. |
claudeus_wp_users__update_user | write | Update an existing WordPress user. Modify user details, roles, or profile information. |
claudeus_wp_widgets__create_widget | write | Create a new widget and add it to a sidebar. Add text widgets, category lists, recent posts, custom HTML, and more. |
claudeus_wp_widgets__delete_widget | destructive | Delete a widget. Remove widget instance from its sidebar permanently. |
claudeus_wp_widgets__get_sidebar | read | Get a specific sidebar by ID. View sidebar configuration and all widgets assigned to it. |
claudeus_wp_widgets__get_sidebars | read | Get all registered sidebars. List all widget areas with their configuration and assigned widgets. |
claudeus_wp_widgets__get_widget | read | Get a specific widget by ID. View widget type, settings, sidebar placement, and rendered HTML. |
claudeus_wp_widgets__get_widgets | read | Get all widgets. List all widget instances across all sidebars with their settings and rendered output. |
claudeus_wp_widgets__update_widget | write | Update an existing widget. Modify widget settings, move to different sidebar, or change configuration. |
create-blog-post | write | Generate a blog post with SEO optimization |
criteria | write | Criteria to select posts for update (JSON) |
keywords | read | Target SEO keywords (comma-separated) |
post_id | write | ID of the post to analyze |
target_keywords | read | Target keywords to check against |
tone | read | Writing tone (e.g. professional, casual, technical) |
topic | write | Main topic or subject of the blog post |
updates | write | Updates to apply to selected posts (JSON) |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (8 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
claudeus_wp_astra__delete_custom_layout, claudeus_wp_comments__delete_comment, claudeus_wp_content__delete_block, claudeus_wp_content__delete_block_revision, claudeus_wp_content__delete_page, claudeus
import { McpServer } from '../../../mcp/server.js';import { TestTransport, JsonRpcMessage } from '../../utils/test-transport.js';import { McpServer } from '../../mcp/server.js';import { AstraApiClient } from '../../api/astra.js';import { AstraMegaMenuData, AstraCustomLayoutData } from '../../types/index.js';@modelcontextprotocol/sdk, axios, cors, dotenv, express, form-data, tailwindcss, zod
**Administrator role has all capabilities** - recommended for full access.
# Permanent (add to ~/.zshrc or ~/.bashrc)
Gates applied: no_behavioural_pass.
d5da1d144006full audit observations/trust-audit/mcp-server/deus-h__claudeus-wordpress.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d5da1d144006 | SAFE | B | 89 | first audit |
Questions
What is the Claudeus WordPress MCP server?
Claudeus WordPress MCP Server
What tools does Claudeus WordPress expose?
155 in total: 77 read-only, 59 that write, and 19 that can delete or overwrite (claudeus_wp_astra__delete_custom_layout, claudeus_wp_comments__delete_comment, claudeus_wp_content__delete_block, claudeus_wp_content__delete_block_revision, claudeus_wp_content__delete_page). Every one is listed on this page with its risk.
Is Claudeus WordPress safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 19 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Claudeus WordPress need?
No credential environment variables were found in its source, so it appears to need none.
How does Claudeus WordPress run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as claudeus-wp-mcp at 3.0.2.
How current is this page?
The grade is for one exact copy of the source (d5da1d144006), read on 2026-10-07. The repository is watched and re-audited when it changes.