Atlas / MCP servers / msrbuilds / elementor-mcp

elementor-mcpBLOCK

mcp/msrbuilds/elementor-mcp

WordPress plugin that turns Elementor & WordPress into an MCP server. 500+ AI-ready tools for building, editing, and managing page designs programmatically.

Verdict
BLOCK
Grade
F
Trust score
52 /100
Exposed tools
2 2r · 0w · 0d
Transport
streamable-http
License
GPL-2.0
Stars
733
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MCP Tools for WordPress & Page Builders

[](https://github.com/msrbuilds/elementor-mcp/releases) [](LICENSE) [](https://php.net) [](https://wordpress.org) [](https://emcptools.com/docs/tools/overview/) [](CONTRIBUTING.md) [](https://github.com/msrbuilds/elementor-mcp/issues) [](https://github.com/msrbuilds/elementor-mcp)

[Docs](https://emcptools.com/docs/) · [Integrations](https://emcptools.com/integrations/) · [Changelog](https://emcptools.com/changelog) · [Pro](https://emcptools.com/pricing)

Turn your WordPress site into something an AI agent can actually operate.

EMCP Tools is a WordPress plugin that exposes your site as [MCP](https://modelcontextprotocol.io/) tools, so Claude, Cursor, and any other MCP client can build Elementor pages, write content, manage plugins and users, audit performance and security, and drive the plugins you already run. It builds on the WordPress MCP Adapter, which ships bundled.

EMCP Pro, 25% off for the GitHub community: use code `MSRGIT` at [emcptools.com/pricing](https://emcptools.co
Read from source at commit fe269a985b3eOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add emcp-tools-admin -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "emcp-tools-admin": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
emcp_list_sitesreadList the WordPress sites this proxy can connect to, and which one is active. Use emcp_use_site to switch.
emcp_use_sitereadSwitch the active WordPress site for subsequent tool calls. Pass the site alias from emcp_list_sites.
04

Trust audit

BLOCKgrade F · trust 52/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (6 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
includes/changes/class-change-codec.php:55
$rb = ( '' !== $hex && ctype_xdigit( $hex ) ) ? @unserialize( (string) hex2bin( $hex ), array( 'allowed_classes' => array( 'stdClass' ) ) ) : null;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
includes/class-filesystem-guard.php:94
'.netrc',
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
includes/class-filesystem-guard.php:95
'id_rsa',
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
includes/class-filesystem-guard.php:96
'id_ed25519',
Why it matters. touches a credential store
MEDIUMInventory / provenance · inv.binary · CWE-1104
includes/vendors/fremius/languages/freemius-cs_CZ.mo
freemius-cs_CZ.mo
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
includes/vendors/fremius/languages/freemius-da_DK.mo
freemius-da_DK.mo
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
includes/vendors/fremius/languages/freemius-de_DE.mo
freemius-de_DE.mo
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
includes/vendors/fremius/languages/freemius-es_ES.mo
freemius-es_ES.mo
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
includes/vendors/fremius/languages/freemius-fr_FR.mo
freemius-fr_FR.mo
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
assets/lib/swiper/swiper-bundle.min.css:13
@font-face{font-family:swiper-icons;src:url('data:application/font-woff;charset=utf-8;base64, d09GRgABAAAAAAZgABAAAAAADAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABGRlRNAAAGRAAAABoAAAAci6qHkUdERUYAAAWgAAAAIwAAAC
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.hidden_file · CWE-1104
.freemius.env.example
.freemius.env.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
tests/fixtures/change-log-redact.php:22
function maybe_unserialize( $v ) { return is_string( $v ) && ( 'b:0;' === $v || false !== @unserialize( $v ) ) ? unserialize( $v ) : $v; }
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
tests/support/class-change-memory-storage.php:146
$v = null === $raw ? array() : unserialize( $raw ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests-e2e/frame.spec.js:64
const links = await page.$$eval(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests-e2e/frame.spec.js:100
const links = await page.$$eval(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests-e2e/frame.spec.js:153
const small = await page.$$eval(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/McpServerRegistrationTest.php:7
exec( $command, $output, $exit );
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
admin-src/ui/components/form-css.test.js:13
path.join( __dirname, '../../shell/shell.css' ),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
admin-src/ui/styles/frame-polish.test.js:9
const root = path.join( __dirname, '../../..' );
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/e2e/admin-subtabs.test.cjs:8
const source = fs.readFileSync(path.join(__dirname, '../../assets/js/admin.js'), 'utf8');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/e2e/bricks-landing.php:30
$artifact = __DIR__ . '/../../bricks-json/forma-landing.json';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/e2e/bricks-landing.php:32
$state_file = __DIR__ . '/../../bricks-json/forma-state.json';
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
CHANGELOG.md:717
- **`web_fetch` is SSRF-guarded.** The fetch runs on your server, so every URL (and **every redirect hop**, followed manually rather than by the HTTP client) is validated first: `http(s)` only, no emb
Why it matters. cloud metadata endpoint: the classic SSRF credential grab

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha fe269a985b3efull audit observations/trust-audit/mcp-server/msrbuilds__elementor-mcp.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08fe269a985b3eBLOCKF52first audit
06

Questions

What is the elementor-mcp MCP server?

WordPress plugin that turns Elementor & WordPress into an MCP server. 500+ AI-ready tools for building, editing, and managing page designs programmatically.

What tools does elementor-mcp expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is elementor-mcp safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (52/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does elementor-mcp need?

No credential environment variables were found in its source, so it appears to need none.

How does elementor-mcp run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as emcp-tools-admin at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (fe269a985b3e), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement