NovamiraBLOCK
MCP server that gives AI agents full access to WordPress through PHP execution and filesystem operations
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Give your AI agents full access to your WordPress site. Nothing in between.
Website · Documentation · Novamira CLI · Videos · Download · Discord · Facebook Community
Novamira is an open-source WordPress plugin and MCP server that lets AI agents work directly inside WordPress. Agents can run PHP and WP-CLI commands, inspect the database, manage files, understand the active plugins and theme, and build working functionality against the real site.
The connection is direct between your AI client and your WordPress installation. Novamira is not a hosted proxy and your requests do not pass through Novamira servers.
[!WARNING] For dev and staging environments. With backups. Always.
Videos
See Novamira in real projects, tutorials, and walkthroughs from the WordPress community.
[Watch Novamira videos →](https://novamira.ai/video/)
What Novamira provides
- Full WordPress access through PHP execution, including
$wpdb, loaded plugins, themes, and WordPress APIs - WP-CLI commands with foreground and background execution
- Filesystem inspection and editing, plus a recoverable sandbox for new PHP files
- Native Block Editor workflows, media uploads, reusable skills, agent context, and design guidance
- OAuth and WordPress Application Password authentication
- Compatibility with Claude, Codex, Cursor, Gemini CLI, Antigravity, VS Code with GitHub Copilot, and other MCP clients
- Novamira CLI for connecting terminal-based coding agents such as Cla
1435f18dd130OBSERVED · 2026-09-29Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
workspace_connection_info | read | |
workspace_request | read | |
workspace_status | read |
Trust audit
BLOCKgrade F · trust 41/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (11 observation(s))
- Network
- declared (15 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
'- Code executed here via eval() is temporary and does not persist across requests.',
$return_value = eval($code);
exec($command, $output, $return_var);
exec($command, $output, $return_var);
exec($cmd, $pid_output, $rc);
__('Global', domain: 'novamira') => '~/.aws/amazonq/mcp.json',__('Global', domain: 'novamira') => '~/.aws/amazonq/mcp.json',{ label: "Amazon Q", desktop: false, path: "~/.aws/amazonq/mcp.json", code: mcpJson },'<code>NODE_TLS_REJECT_UNAUTHORIZED=0</code>',
'<code>NODE_TLS_REJECT_UNAUTHORIZED=0</code>',
. '- Also set NODE_TLS_REJECT_UNAUTHORIZED="0" in env (this site uses a local self-signed TLS certificate).'
$lines[] = 'NODE_TLS_REJECT_UNAUTHORIZED = "0"';
.agents/skills
const response = await fetch(`http://127.0.0.1:${port}/bridge-token`);icon_url: 'data:image/svg+xml;base64,PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz4KPHN2ZyBpZD0iTGF5ZXJfMiIgZGF0YS1uYW1lPSJMYXllciAyIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9Ii0
-webkit-mask: url("data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyNCAyNCI+PHBhdGggZmlsbD0iIzAwMCIgZD0iTTYgMTljMCAxLjEuOSAyIDIgMmg4YzEuMSAwIDItLjkgMi0mask: url("data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyNCAyNCI+PHBhdGggZmlsbD0iIzAwMCIgZD0iTTYgMTljMCAxLjEuOSAyIDIgMmg4YzEuMSAwIDItLjkgMi0yVjdINnY-webkit-mask: url("data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyNCAyNCI+PHBhdGggZmlsbD0iIzAwMCIgZD0iTTEyIDE0YzEuNjYgMCAzLTEuMzQgMy0zVjVjMC0xLjY2LTEmask: url("data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyNCAyNCI+PHBhdGggZmlsbD0iIzAwMCIgZD0iTTEyIDE0YzEuNjYgMCAzLTEuMzQgMy0zVjVjMC0xLjY2LTEuMzQtMy0derive_public_key('-----BEGIN PRIVATE KEY-----not a key-----END PRIVATE KEY-----');AGENTS.md
GEMINI.md
import type { AgentTool } from "../../tool-types";import type { AgentTool } from "../../tool-types";import type { AgentTool } from "../../tool-types";Gates applied: no_behavioural_pass.
1435f18dd130full audit observations/trust-audit/mcp-server/use-novamira__novamira.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | 1435f18dd130 | BLOCK | F | 41 | first audit |
Questions
What is the Novamira MCP server?
MCP server that gives AI agents full access to WordPress through PHP execution and filesystem operations
What tools does Novamira expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Novamira safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (41/100) and found 12 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Novamira need?
It reads NOVAMIRA_VISUAL_WORKSPACE_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Novamira run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (1435f18dd130), read on 2026-09-29. The repository is watched and re-audited when it changes.