Atlas / MCP servers / prathammanocha / WordPress

WordPressSAFE

mcp/prathammanocha/wordpress-5

This is the most comprehensive wordpress mcp server. Includes functionality to perform CRUD operations on Users, Blogs, Categories and much more. Get specialised stats as well.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
29 16r · 9w · 4d
Transport
stdio
License
MIT
Stars
50
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/prathammanocha-wordpress-mcp-server)

A comprehensive Model Context Protocol (MCP) server that enables AI assistants to interact with WordPress sites through the WordPress REST API. This server provides tools for managing all aspects of WordPress programmatically, including posts, users, comments, categories, tags, and custom endpoints.

Features

Post Management

  • Create, retrieve, update, and delete WordPress posts
  • Filter posts by various parameters
  • Pagination support for post listings

User Management

  • Retrieve user information by ID or login
  • Update user details
  • Delete users

Comments Management

  • Create, retrieve, update, and delete comments
  • Filter comments by post
  • Pagination support for comment listings

Taxonomy Management

  • Manage categories and tags
  • Create, retrieve, update, and delete taxonomies
  • Find categories and tags by slug

Site Information

  • Retrieve general WordPress site information

Custom Requests

  • Support for custom REST API endpoints
  • Custom HTTP methods (GET, POST, PUT, DELETE)
  • Custom data and parameters

Prerequisites

  • Node.js v18 or higher
  • A WordPress site with REST API enabled
  • WordPress application password for authentication

Installation

  1. Clone this repository:
git clone [repository-url]
cd wordpress-mcp-server
  1. Install dependencies:
npm install
  1. Build the server:
npm run build

WordPress Configuration

Before using the server, you need to set up your WordPress site:

  1. Ensure your WordPress site has REST API enabled (enabled by default in Wor
Read from source at commit f0ac6b06d9f1OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add prathammanocha-comprehensive-wp-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "prathammanocha-comprehensive-wp-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (29)

16 read · 9 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
create-categorywriteCreate a new WordPress category
create-commentwriteCreate a new comment on a WordPress post
create-postwriteCreate a new WordPress post
create-userwriteCreate a new WordPress user
delete-categorydestructiveDelete a WordPress category
delete-postdestructiveDelete a WordPress post
delete-userdestructiveDelete a WordPress user
get-categoryreadGet a specific category by ID
get-clicksreadView a site
get-commentsreadGet a list of comments from a WordPress site
get-country-viewsreadView a site
get-postwriteGet a specific post by ID
get-post-statswriteView a specific post
get-referrersreadView a site
get-search-termsreadView search terms used to find the site
get-site-statsreadGet comprehensive stats for a WordPress site
get-stats-highlightsreadGet highlight metrics for a WordPress site from the last seven days
get-stats-summaryreadView a site
get-streak-statsreadGet stats for Calendar Heatmap showing publishing activity
get-top-postsreadView a site
get-userreadGet a specific user by ID
get-usersreadGet a list of users from a WordPress site with advanced filtering options
list-categoriesreadGet a list of categories with filtering options
list-postsreadGet a list of posts with comprehensive filtering options
remove-referrer-spamdestructiveUnreport a referrer as spam
report-referrer-spamreadReport a referrer as spam
update-categorywriteUpdate an existing WordPress category
update-postwriteUpdate an existing WordPress post
update-userwriteUpdate an existing WordPress user
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete-category, delete-post, delete-user, remove-referrer-spam
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, zod, @types/node, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f0ac6b06d9f1full audit observations/trust-audit/mcp-server/prathammanocha__wordpress-5.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08f0ac6b06d9f1SAFEB89first audit
06

Questions

What is the WordPress MCP server?

This is the most comprehensive wordpress mcp server. Includes functionality to perform CRUD operations on Users, Blogs, Categories and much more. Get specialised stats as well.

What tools does WordPress expose?

29 in total: 16 read-only, 9 that write, and 4 that can delete or overwrite (delete-category, delete-post, delete-user, remove-referrer-spam). Every one is listed on this page with its risk.

Is WordPress safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does WordPress need?

No credential environment variables were found in its source, so it appears to need none.

How does WordPress run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as prathammanocha-comprehensive-wp-mcp at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (f0ac6b06d9f1), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement