WordPressSAFE
This is the most comprehensive wordpress mcp server. Includes functionality to perform CRUD operations on Users, Blogs, Categories and much more. Get specialised stats as well.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/prathammanocha-wordpress-mcp-server)
A comprehensive Model Context Protocol (MCP) server that enables AI assistants to interact with WordPress sites through the WordPress REST API. This server provides tools for managing all aspects of WordPress programmatically, including posts, users, comments, categories, tags, and custom endpoints.
Features
Post Management
- Create, retrieve, update, and delete WordPress posts
- Filter posts by various parameters
- Pagination support for post listings
User Management
- Retrieve user information by ID or login
- Update user details
- Delete users
Comments Management
- Create, retrieve, update, and delete comments
- Filter comments by post
- Pagination support for comment listings
Taxonomy Management
- Manage categories and tags
- Create, retrieve, update, and delete taxonomies
- Find categories and tags by slug
Site Information
- Retrieve general WordPress site information
Custom Requests
- Support for custom REST API endpoints
- Custom HTTP methods (GET, POST, PUT, DELETE)
- Custom data and parameters
Prerequisites
- Node.js v18 or higher
- A WordPress site with REST API enabled
- WordPress application password for authentication
Installation
- Clone this repository:
git clone [repository-url] cd wordpress-mcp-server
- Install dependencies:
npm install
- Build the server:
npm run build
WordPress Configuration
Before using the server, you need to set up your WordPress site:
- Ensure your WordPress site has REST API enabled (enabled by default in Wor
f0ac6b06d9f1OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add prathammanocha-comprehensive-wp-mcp -- npx -y [email protected]
{
"mcpServers": {
"prathammanocha-comprehensive-wp-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (29)
16 read · 9 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
create-category | write | Create a new WordPress category |
create-comment | write | Create a new comment on a WordPress post |
create-post | write | Create a new WordPress post |
create-user | write | Create a new WordPress user |
delete-category | destructive | Delete a WordPress category |
delete-post | destructive | Delete a WordPress post |
delete-user | destructive | Delete a WordPress user |
get-category | read | Get a specific category by ID |
get-clicks | read | View a site |
get-comments | read | Get a list of comments from a WordPress site |
get-country-views | read | View a site |
get-post | write | Get a specific post by ID |
get-post-stats | write | View a specific post |
get-referrers | read | View a site |
get-search-terms | read | View search terms used to find the site |
get-site-stats | read | Get comprehensive stats for a WordPress site |
get-stats-highlights | read | Get highlight metrics for a WordPress site from the last seven days |
get-stats-summary | read | View a site |
get-streak-stats | read | Get stats for Calendar Heatmap showing publishing activity |
get-top-posts | read | View a site |
get-user | read | Get a specific user by ID |
get-users | read | Get a list of users from a WordPress site with advanced filtering options |
list-categories | read | Get a list of categories with filtering options |
list-posts | read | Get a list of posts with comprehensive filtering options |
remove-referrer-spam | destructive | Unreport a referrer as spam |
report-referrer-spam | read | Report a referrer as spam |
update-category | write | Update an existing WordPress category |
update-post | write | Update an existing WordPress post |
update-user | write | Update an existing WordPress user |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
delete-category, delete-post, delete-user, remove-referrer-spam
@modelcontextprotocol/sdk, axios, zod, @types/node, typescript
Gates applied: no_behavioural_pass.
f0ac6b06d9f1full audit observations/trust-audit/mcp-server/prathammanocha__wordpress-5.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | f0ac6b06d9f1 | SAFE | B | 89 | first audit |
Questions
What is the WordPress MCP server?
This is the most comprehensive wordpress mcp server. Includes functionality to perform CRUD operations on Users, Blogs, Categories and much more. Get specialised stats as well.
What tools does WordPress expose?
29 in total: 16 read-only, 9 that write, and 4 that can delete or overwrite (delete-category, delete-post, delete-user, remove-referrer-spam). Every one is listed on this page with its risk.
Is WordPress safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does WordPress need?
No credential environment variables were found in its source, so it appears to need none.
How does WordPress run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as prathammanocha-comprehensive-wp-mcp at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (f0ac6b06d9f1), read on 2026-10-08. The repository is watched and re-audited when it changes.