Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

WordPress MCP lets a compatible AI client use tools exposed by a WordPress service or site. Depending on the route and permissions, those tools can read site information and make changes—not just answer questions. Start by identifying which WordPress MCP route fits your site and task, then limit access, review proposed changes, and keep a person in control of publishing and other consequential actions.

What is WordPress MCP?

MCP, or Model Context Protocol, is an open standard for connecting AI applications to external systems. In practice, an MCP server makes certain tools and information available to a compatible client such as Claude, Cursor, or ChatGPT. The client can use those tools to fetch context for an answer or, if write tools are available and authorized, carry out an action. The protocol is an interface, not a security guarantee.

WordPress.com describes a flow in which the AI client interprets your request, selects an available tool, asks to use it, and adds the returned information to the model request. That description applies to the WordPress.com service; other servers and AI providers may handle requests and data differently.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which WordPress MCP route do you need?

“WordPress MCP” can mean several different projects. Choose based on what you want the assistant to access, not just which AI client you use.

Route What it is for What it does not mean
WordPress.com MCP Managing a WordPress.com site or a self-hosted site connected through Jetpack, subject to eligibility, permissions, and enabled tools. Its documented endpoint is https://public-api.wordpress.com/wpcom/v2/mcp/v1; the hosted setup uses browser-based OAuth 2.1. It is not automatically available to every site, account, or user role.
WordPress.org Plugin Directory MCP Plugin Directory work such as reading plugin guidelines, validating a readme, checking submission status, and submitting a plugin. It is not a general remote-control server for an arbitrary self-hosted WordPress site. Plugin submissions still go through the regular review process.
MCP Adapter A developer route that exposes registered WordPress Abilities as MCP tools and resources. It does not make every custom ability safe merely by exposing it; the ability implementation still needs appropriate permission checks.
WordPress Studio MCP A local development route for Studio sites, including operations such as creating, starting, or stopping a local site, running WP-CLI commands, and taking screenshots. It is not the same as giving an external agent access to a public production site.

For WordPress.com MCP, the official setup documentation, as of October 7, 2026, says access is available on paid WordPress.com plans; a free site has access for its first 30 days after creation. A self-hosted site connected through Jetpack needs Jetpack AI or Jetpack Complete. These eligibility terms can change, so check current WordPress.com setup and plan documentation before connecting.

WordPress.com documents different setup routes for different clients: Claude Desktop uses its connector directory, ChatGPT uses its plugin, and other clients use the MCP endpoint with their own setup instructions. The documentation lists Claude Desktop, Claude Code, ChatGPT, Cursor, Codex, and VS Code, but support and steps vary by client. Do not copy a configuration snippet intended for one client into another without checking its current instructions.

The Plugin Directory server has separate prerequisites: the WordPress Plugin Handbook quick setup requires a WordPress.org account, an MCP-compatible client, and Node.js 18 or later. Its documented quick setup currently detects Claude Desktop, Claude Code, Cursor, and VS Code. WordPress Studio is configured through Studio settings. These are distinct setups, not interchangeable ways to attach any AI client to any WordPress site.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What can an AI assistant do on a WordPress site?

The following nine jobs group operation families documented in WordPress.com’s tool catalog. They are possible workflows, not a promise that every connected site exposes every tool: availability depends on plan, hosting platform, user permissions, and tool settings. The live server’s tool catalog is the relevant list for a particular connection.

1. Build a site inventory

Ask the assistant to report supported site settings, installed plugins, plugin versions, and available updates. Keep the first request read-only: have it list what it found, then ask for recommendations separately. This gives you a chance to spot unfamiliar plugins or an update that needs investigation before any change is proposed.

2. Summarize basic site statistics

Request supported totals or a summary for a selected date range, such as views, visitors, or publishing activity. The documented statistics operation does not cover every analytics question: it does not promise breakdowns such as top posts or per-URL data. Ask for the specific measures the connected tool supports rather than treating a short summary as a full analytics report.

3. Find an existing post or page

Ask the assistant to search public published content, list content with filters, or retrieve a particular post or page. If you need a draft, private item, or pending post, use a list operation with the relevant status filter; public-content search is not a substitute for searching every status.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Prepare a post or page as a draft

Have the assistant create a draft, then inspect the result in WordPress. Check factual claims, links, tone, formatting, and whether the content fits the intended page before publishing. In the documented WordPress.com authoring catalog, new posts and pages default to draft; publishing is a separate consequential write and should happen only after you explicitly approve the finished content.

5. Revise one section without rewriting the page

The catalog supports listing top-level content blocks and replacing, inserting, or removing a selected block. A careful workflow is to retrieve the target section, ask for a proposed replacement, review it, and then confirm the edit. A block-level operation is not necessarily a visual preview, so inspect the saved page in the editor or on the site to catch layout and formatting effects.

6. Review comments and prepare moderation

Available comment operations include listing, retrieving, creating, updating, and deleting comments. Use the assistant to assemble a moderation shortlist or draft replies first. Posting a reply, changing a comment, or deleting one changes what is visible to visitors, so keep those actions behind your review and approval.

7. Inspect media and improve text metadata

Media tools can list and retrieve items and update fields such as alt text and captions. Ask for suggested wording and review it before saving: a media-field change may appear wherever that image is used. Uploading, generating, and deleting media are also documented operations, but deletion can remove a file that existing content depends on.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

8. Check recent activity and site status

Site operations include recent activity, backup readiness and storage information, and Jetpack Scan status; an authorized scan can also be queued. These checks can help you notice a status or decide what to investigate next. They are not a complete security audit, nor do a reported backup or scan status guarantee that a site can be recovered or is free of problems.

9. Inspect design context before proposing a visual change

The site editor context can provide the active theme, design presets, applied styles, and registered blocks. Ask what styles and blocks the site already uses before requesting a design edit. The catalog recommends using theme-aligned preset slugs instead of hard-coded colors and sizes, and checking content warnings after saves.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How do you connect WordPress MCP safely?

For WordPress.com MCP, check permissions before connecting. WordPress.com says enabling MCP turns on both Read and Write tool groups by default. Administrators can customize tools and groups, site-level settings override account defaults, and the authenticated user’s role also limits which tools are available. A successful connection therefore does not mean the connection is read-only.

  1. Identify the target and task. Decide whether you are connecting a WordPress.com or Jetpack-connected site, working with the Plugin Directory, developing custom abilities, or using a local Studio site. Do not use a Plugin Directory or Studio setup as if it were a hosted-site management connection.
  2. Check the current eligibility and client instructions. For the hosted route, confirm the site and plan qualify and follow the instructions for your specific client. WordPress.com’s documented hosted flow uses browser-based OAuth 2.1; other routes have their own setup requirements.
  3. Inspect the available tools and permissions. For WordPress.com MCP, review the account and site-level tool settings, the user role, and the live tool catalog. Start with only the read tools needed to explore. If a task requires writes, enable only the specific tools needed when the service allows that level of control, using an account with no more authority than the task requires.
  4. Ask for a proposal before an action. Request a list of intended changes, the affected post, block, comment, or media item, and the exact proposed content. Review the target as well as the wording before approving.
  5. Confirm consequential changes deliberately. In WordPress.com’s documented catalog, the agent must explain a write, update, or delete, request explicit user confirmation, and send user_confirmed: true. Destructive operations require the target to be presented before confirmation. This is a safeguard in that catalog, not a rule that every MCP server enforces.
  6. Verify the result in WordPress. Check the saved content, site display, or relevant status after the tool reports completion. Keep a human review step before publishing or making changes that affect visitors.

Is it safe to let ChatGPT edit a WordPress site?

It depends on the tools and permissions you grant, the client and server involved, and the action. MCP itself is not a read-only mode. A prompt asking an assistant to “be careful” is not a replacement for limiting tools and checking what the assistant is about to change.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Keep early exploration read-only. Enable only necessary read access where the service permits it, and ask for findings before asking for edits.
  • Use drafts and small, reviewable changes. A draft or section-level edit is easier to inspect than a broad rewrite, but neither should be accepted without checking its result.
  • Pause before publishing or deleting. The catalog notes that publishing changes can go live immediately. Some deletions—including certain media, categories, tags, and terms—may be permanent with no trash or recovery path. Verify the exact target and effect before authorizing them.
  • Consider what site data enters the AI request. Tool results and site content can be included as context in a model request. WordPress.com states that its MCP tool data is not used to train AI models and is used once as part of the original request. That is a WordPress.com statement, not a privacy guarantee for other MCP servers, clients, plans, or AI providers.
  • For custom abilities, enforce permissions in the ability. The official MCP Adapter exposes registered abilities; developers should define typed input and output schemas, enforce capabilities in a permission callback, and implement the operation in an execution callback. Exposing an ability through MCP does not by itself secure it.

For developers, the WordPress Developer Blog describes three default WordPress 6.9 Abilities—core/get-site-info, core/get-user-info, and core/get-environment-info. That is a version-specific implementation detail, not a guarantee that every site exposes the same abilities through every server.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.