elementor-mcpBLOCK
WordPress plugin that turns Elementor & WordPress into an MCP server. 500+ AI-ready tools for building, editing, and managing page designs programmatically.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP Tools for WordPress & Page Builders
[](https://github.com/msrbuilds/elementor-mcp/releases) [](LICENSE) [](https://php.net) [](https://wordpress.org) [](https://emcptools.com/docs/tools/overview/) [](CONTRIBUTING.md) [](https://github.com/msrbuilds/elementor-mcp/issues) [](https://github.com/msrbuilds/elementor-mcp)
[Docs](https://emcptools.com/docs/) · [Integrations](https://emcptools.com/integrations/) · [Changelog](https://emcptools.com/changelog) · [Pro](https://emcptools.com/pricing)
Turn your WordPress site into something an AI agent can actually operate.
EMCP Tools is a WordPress plugin that exposes your site as [MCP](https://modelcontextprotocol.io/) tools, so Claude, Cursor, and any other MCP client can build Elementor pages, write content, manage plugins and users, audit performance and security, and drive the plugins you already run. It builds on the WordPress MCP Adapter, which ships bundled.
EMCP Pro, 25% off for the GitHub community: use code `MSRGIT` at [emcptools.com/pricing](https://emcptools.co
fe269a985b3eOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add emcp-tools-admin -- npx -y [email protected]
{
"mcpServers": {
"emcp-tools-admin": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
emcp_list_sites | read | List the WordPress sites this proxy can connect to, and which one is active. Use emcp_use_site to switch. |
emcp_use_site | read | Switch the active WordPress site for subsequent tool calls. Pass the site alias from emcp_list_sites. |
Trust audit
BLOCKgrade F · trust 52/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
$rb = ( '' !== $hex && ctype_xdigit( $hex ) ) ? @unserialize( (string) hex2bin( $hex ), array( 'allowed_classes' => array( 'stdClass' ) ) ) : null;
'.netrc',
'id_rsa',
'id_ed25519',
freemius-cs_CZ.mo
freemius-da_DK.mo
freemius-de_DE.mo
freemius-es_ES.mo
freemius-fr_FR.mo
@font-face{font-family:swiper-icons;src:url('data:application/font-woff;charset=utf-8;base64, d09GRgABAAAAAAZgABAAAAAADAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABGRlRNAAAGRAAAABoAAAAci6qHkUdERUYAAAWgAAAAIwAAACstreamable-http
.freemius.env.example
.gitmodules
function maybe_unserialize( $v ) { return is_string( $v ) && ( 'b:0;' === $v || false !== @unserialize( $v ) ) ? unserialize( $v ) : $v; }$v = null === $raw ? array() : unserialize( $raw ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions
const links = await page.$$eval(
const links = await page.$$eval(
const small = await page.$$eval(
exec( $command, $output, $exit );
path.join( __dirname, '../../shell/shell.css' ),
const root = path.join( __dirname, '../../..' );
const source = fs.readFileSync(path.join(__dirname, '../../assets/js/admin.js'), 'utf8');
$artifact = __DIR__ . '/../../bricks-json/forma-landing.json';
$state_file = __DIR__ . '/../../bricks-json/forma-state.json';
- **`web_fetch` is SSRF-guarded.** The fetch runs on your server, so every URL (and **every redirect hop**, followed manually rather than by the HTTP client) is validated first: `http(s)` only, no emb
Gates applied: no_behavioural_pass.
fe269a985b3efull audit observations/trust-audit/mcp-server/msrbuilds__elementor-mcp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | fe269a985b3e | BLOCK | F | 52 | first audit |
Questions
What is the elementor-mcp MCP server?
WordPress plugin that turns Elementor & WordPress into an MCP server. 500+ AI-ready tools for building, editing, and managing page designs programmatically.
What tools does elementor-mcp expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is elementor-mcp safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (52/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does elementor-mcp need?
No credential environment variables were found in its source, so it appears to need none.
How does elementor-mcp run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as emcp-tools-admin at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (fe269a985b3e), read on 2026-10-08. The repository is watched and re-audited when it changes.