ElementorBLOCK
WordPress plugin that turns Elementor & WordPress into an MCP server. 500+ AI-ready tools for building, editing, and managing page designs programmatically.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP Tools for WordPress & Page Builders
[](https://github.com/msrbuilds/elementor-mcp/releases) [](LICENSE) [](https://php.net) [](https://wordpress.org) [](https://emcptools.com/docs/tools/overview/) [](CONTRIBUTING.md) [](https://github.com/msrbuilds/elementor-mcp/issues) [](https://github.com/msrbuilds/elementor-mcp)
[Docs](https://emcptools.com/docs/) · [Integrations](https://emcptools.com/integrations/) · [Changelog](https://emcptools.com/changelog) · [Pro](https://emcptools.com/pricing)
Turn your WordPress site into something an AI agent can actually operate.
EMCP Tools is a WordPress plugin that exposes your site as [MCP](https://modelcontextprotocol.io/) tools, so Claude, Cursor, and any other MCP client can build Elementor pages, write content, manage plugins and users, audit performance and security, and drive the plugins you already run. It builds on the WordPress MCP Adapter, which ships bundled.
EMCP Pro, 25% off for the GitHub community: use code `MSRGIT` at [emcptools.com/pricing](https://emcptools.co
3e00f64b76e6OBSERVED · 2026-09-29Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add emcp-proxy -- npx -y @msrbuilds/[email protected]
{
"mcpServers": {
"emcp-proxy": {
"command": "npx",
"args": [
"-y",
"@msrbuilds/[email protected]"
]
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
emcp_list_sites | read | List the WordPress sites this proxy can connect to, and which one is active. Use emcp_use_site to switch. |
emcp_use_site | read | Switch the active WordPress site for subsequent tool calls. Pass the site alias from emcp_list_sites. |
Trust audit
BLOCKgrade D · trust 67/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (25)
'.netrc',
'id_rsa',
'id_ed25519',
freemius-cs_CZ.mo
freemius-da_DK.mo
freemius-de_DE.mo
freemius-es_ES.mo
freemius-fr_FR.mo
streamable-http
.freemius.env.example
.gitmodules
const source = fs.readFileSync(path.join(__dirname, '../../assets/js/admin.js'), 'utf8');
$artifact = __DIR__ . '/../../bricks-json/forma-landing.json';
$state_file = __DIR__ . '/../../bricks-json/forma-state.json';
- **`web_fetch` is SSRF-guarded.** The fetch runs on your server, so every URL (and **every redirect hop**, followed manually rather than by the HTTP client) is validated first: `http(s)` only, no emb
**5. OAuth loopback fix.** A CLI app registers `http://localhost:PORT` and returns on `http://127.0.0.1:PORT`. `EMCP_Tools_OAuth_Util::is_loopback_host()` now treats `localhost`/`127.0.0.1`/`::1` as o
$m = $this->manifest( 'http://192.168.1.10:8080' );
3. Implement native draft creation, graph editing, responsive styles, staged saves, publication and version restoration. Require fresh content hashes, native full access and WordPress capabilities.
as native full access. Global writes also require `edit_theme_options`.
- **WordPress Users tools (beyond Elementor, domain 5).** Four MCP tools for safe user management: `list-users` and `get-user` (read; admin-gated, never expose passwords/auth data) plus `create-user`
* Added: WordPress Users tools (beyond Elementor, domain 5). Four MCP tools for safe user management: list-users and get-user (read; admin-gated, never expose passwords/auth data) plus create-user and
**Prior status: v3.7.0 (tagged) — the Sandbox Blocks + Agent Project Memory release.** Two Pro features: (1) **Gutenberg Block authoring in the Sandbox** — the Sandbox parent page is now a 3-card over
**Phase 2 (v3.13.0, BUILT + live-validated) — connector + migration.** A **Migrate** sub-tab pushes this site to a live server without a manual upload. The source (Pro) streams the `.emcp` to a standa
- New: **Agents can inspect a page's public front-end HTML** (#132). The read-only `get-page-html` tool accepts a same-origin URL or published post ID (defaulting to the front page), returns theme and
Credentials, payment execution, form submission records, remote template sync and WooCommerce template assignment are outside this integration. WooCommerce block schemas can be discovered and authored
Gates applied: no_behavioural_pass.
3e00f64b76e6full audit observations/trust-audit/mcp-server/msrbuilds__elementor.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | 3e00f64b76e6 | BLOCK | D | 67 | first audit |
Questions
What is the Elementor MCP server?
WordPress plugin that turns Elementor & WordPress into an MCP server. 500+ AI-ready tools for building, editing, and managing page designs programmatically.
What tools does Elementor expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Elementor safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (67/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Elementor need?
No credential environment variables were found in its source, so it appears to need none.
How does Elementor run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @msrbuilds/emcp-proxy at 1.11.0.
How current is this page?
The grade is for one exact copy of the source (3e00f64b76e6), read on 2026-09-29. The repository is watched and re-audited when it changes.