Atlas / MCP servers / use-novamira / Novamira

NovamiraBLOCK

mcp/use-novamira/novamira

MCP server that gives AI agents full access to WordPress through PHP execution and filesystem operations

Verdict
BLOCK
Grade
F
Trust score
41 /100
Exposed tools
3 3r · 0w · 0d
Transport
stdio
License
AGPL-3.0
Stars
698
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Give your AI agents full access to your WordPress site. Nothing in between.

Website · Documentation · Novamira CLI · Videos · Download · Discord · Facebook Community

Novamira is an open-source WordPress plugin and MCP server that lets AI agents work directly inside WordPress. Agents can run PHP and WP-CLI commands, inspect the database, manage files, understand the active plugins and theme, and build working functionality against the real site.

The connection is direct between your AI client and your WordPress installation. Novamira is not a hosted proxy and your requests do not pass through Novamira servers.

[!WARNING] For dev and staging environments. With backups. Always.

Videos

See Novamira in real projects, tutorials, and walkthroughs from the WordPress community.

[Watch Novamira videos →](https://novamira.ai/video/)

What Novamira provides

  • Full WordPress access through PHP execution, including $wpdb, loaded plugins, themes, and WordPress APIs
  • WP-CLI commands with foreground and background execution
  • Filesystem inspection and editing, plus a recoverable sandbox for new PHP files
  • Native Block Editor workflows, media uploads, reusable skills, agent context, and design guidance
  • OAuth and WordPress Application Password authentication
  • Compatibility with Claude, Codex, Cursor, Gemini CLI, Antigravity, VS Code with GitHub Copilot, and other MCP clients
  • Novamira CLI for connecting terminal-based coding agents such as Cla
Read from source at commit 1435f18dd130OBSERVED · 2026-09-29
02

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
workspace_connection_inforead
workspace_requestread
workspace_statusread
03

Trust audit

BLOCKgrade F · trust 41/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (11 observation(s))
Network
declared (15 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
includes/abilities/execute-php.php:88
'- Code executed here via eval() is temporary and does not persist across requests.',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
includes/abilities/execute-php.php:144
$return_value = eval($code);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
includes/abilities/run-wp-cli.php:752
exec($command, $output, $return_var);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
includes/abilities/run-wp-cli.php:771
exec($command, $output, $return_var);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
includes/abilities/run-wp-cli.php:1062
exec($cmd, $pid_output, $rc);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
includes/connect-methods.php:1098
__('Global', domain: 'novamira') => '~/.aws/amazonq/mcp.json',
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
includes/connect-page.php:2438
__('Global', domain: 'novamira') => '~/.aws/amazonq/mcp.json',
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
novamira-visual/src/workspace-index.ts:706
{ label: "Amazon Q", desktop: false, path: "~/.aws/amazonq/mcp.json", code: mcpJson },
Why it matters. touches a credential store
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
includes/connect-page.php:1135
'<code>NODE_TLS_REJECT_UNAUTHORIZED=0</code>',
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
includes/connect-page.php:1655
'<code>NODE_TLS_REJECT_UNAUTHORIZED=0</code>',
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
includes/connect-page.php:1997
. '- Also set NODE_TLS_REJECT_UNAUTHORIZED="0" in env (this site uses a local self-signed TLS certificate).'
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
includes/connect-page.php:2218
$lines[] = 'NODE_TLS_REJECT_UNAUTHORIZED = "0"';
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills
.agents/skills
Why it matters. link not followed
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
novamira-visual/src/workspace-transport.ts:35
const response = await fetch(`http://127.0.0.1:${port}/bridge-token`);
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
novamira.php:625
icon_url: 'data:image/svg+xml;base64,PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz4KPHN2ZyBpZD0iTGF5ZXJfMiIgZGF0YS1uYW1lPSJMYXllciAyIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9Ii0
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
src/chat/style.css:177
-webkit-mask: url("data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyNCAyNCI+PHBhdGggZmlsbD0iIzAwMCIgZD0iTTYgMTljMCAxLjEuOSAyIDIgMmg4YzEuMSAwIDItLjkgMi0
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
src/chat/style.css:178
mask: url("data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyNCAyNCI+PHBhdGggZmlsbD0iIzAwMCIgZD0iTTYgMTljMCAxLjEuOSAyIDIgMmg4YzEuMSAwIDItLjkgMi0yVjdINnY
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
src/chat/style.css:1029
-webkit-mask: url("data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyNCAyNCI+PHBhdGggZmlsbD0iIzAwMCIgZD0iTTEyIDE0YzEuNjYgMCAzLTEuMzQgMy0zVjVjMC0xLjY2LTE
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
src/chat/style.css:1030
mask: url("data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyNCAyNCI+PHBhdGggZmlsbD0iIzAwMCIgZD0iTTEyIDE0YzEuNjYgMCAzLTEuMzQgMy0zVjVjMC0xLjY2LTEuMzQtMy0
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/oauth/KeyBootstrapTest.php:108
derive_public_key('-----BEGIN PRIVATE KEY-----not a key-----END PRIVATE KEY-----');
LOWInventory / provenance · inv.symlink · CWE-1104
AGENTS.md
AGENTS.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
GEMINI.md
GEMINI.md
Why it matters. link not followed
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
novamira-visual/src/tools/gutenberg/create-block.ts:2
import type { AgentTool } from "../../tool-types";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
novamira-visual/src/tools/gutenberg/delete-block.ts:2
import type { AgentTool } from "../../tool-types";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
novamira-visual/src/tools/gutenberg/get-block-attributes.ts:2
import type { AgentTool } from "../../tool-types";

Gates applied: no_behavioural_pass.

Audited 2026-09-29 · audit v0.4.1 · source sha 1435f18dd130full audit observations/trust-audit/mcp-server/use-novamira__novamira.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-291435f18dd130BLOCKF41first audit
05

Questions

What is the Novamira MCP server?

MCP server that gives AI agents full access to WordPress through PHP execution and filesystem operations

What tools does Novamira expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Novamira safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (41/100) and found 12 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Novamira need?

It reads NOVAMIRA_VISUAL_WORKSPACE_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Novamira run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (1435f18dd130), read on 2026-09-29. The repository is watched and re-audited when it changes.

Advertisement