Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

WSP MCP is a WordPress plugin that lets compatible AI clients use selected abilities on your site through the Model Context Protocol (MCP). Install it, enable only the tools your task requires, then connect your client using the setup instructions it provides. Keep write tools off until you have checked the connected account’s permissions and tested the workflow on staging.

What WSP MCP does

WSP MCP adds an MCP server to a WordPress installation. An MCP-capable client can use the abilities you enable to work with parts of the site. The project describes abilities covering posts, pages, media, menus, WooCommerce, forms, SEO metadata and Elementor layouts. The precise tools depend on the installed version and enabled integrations, so check the current WordPress.org plugin listing and project documentation for the release you plan to use.

The project lists Claude, Cursor, Codex, Google Antigravity, OpenClaw and OpenCode among supported clients. Support and connection methods can vary by client and plugin release. WSP describes a built-in MCP server, so natively supported clients do not need a separate MCP Adapter or Node.js bridge; some client configurations may nevertheless use the mcp-remote bridge. Consult the current installation guide and your client’s own documentation before installing prerequisites.

How to connect an AI client to WordPress

  1. Install and activate WSP MCP. Use the current instructions in the project guide. That guide listed WordPress 6.9 or later and PHP 7.4 or later when accessed; check it again because version requirements can change. If your chosen client uses mcp-remote, the guide says Node.js 18 or later may be required for that bridge.
  2. Choose the abilities for the job. In the plugin’s MCP settings, enable only the relevant tool groups. Start with read-only access where possible; leave write abilities disabled until you have a specific, reviewed reason to turn them on.
  3. Open the connection page for your client. Follow the generated configuration or client-specific instructions. WSP describes a browser-based OAuth connector for Claude and generated configuration for other clients. Treat setup details as release- and client-dependent rather than assuming one configuration fits every application.
  4. Reconnect the client and try a low-risk request. Restart or reconnect as the instructions require. Begin with a read-only task, such as asking the agent to retrieve a page or list content, and confirm it can access only the expected site information.
  5. Review what happened. Check WSP’s audit log and analytics after requests. Confirm the client used the expected account and abilities before enabling additional tools.

Is it safe to give an AI agent access?

Access depends on both the tools you enable and the WordPress user connected to the client. WSP says write abilities are disabled by default, that each tool checks the connected user’s relevant WordPress capability, and that object operations apply ownership and object checks. Those are controls described by the project, not an independent security audit or a guarantee that the whole site, client, or workflow is secure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Reduce the impact of mistakes

  • Use a WordPress account with only the capabilities the task needs, rather than an administrator account by default.
  • Enable one relevant tool group at a time and begin with read-only requests.
  • Review proposed changes yourself, especially edits, publishing, deletion, purchases, or other consequential operations.
  • Keep a recoverable backup and test the connection and any write workflow on staging before using it on production. WSP’s safety guidance recommends staging.
  • After use, inspect the audit log and disconnect access you no longer need. Keep credentials private and follow the current project instructions for revoking them.

The plugin listing also describes OAuth-related measures: administrator opt-in, disconnecting on disable, showing the consent-page origin, framing protection, client-registration limits and a response to refresh-token replay. These are features attributed to the listing; their presence does not establish that every component in your setup has been independently assessed.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

WSP MCP, the WordPress MCP Adapter and WordPress.com MCP

These names refer to different approaches. WSP is the ready-to-install plugin discussed here; the WordPress MCP Adapter is a developer framework; and WordPress.com MCP is a hosted service with plan and connection eligibility rules.

Option What it is Who it may suit Important distinction
WSP MCP A WordPress plugin with a built-in MCP server and a settings interface for enabling site abilities. Site owners and developers who want a packaged plugin and client connection flow. Available abilities and client setup depend on the installed version and integrations. See the plugin listing and project guide.
WordPress MCP Adapter An official developer package that connects WordPress’s Abilities API to MCP tools, resources and prompts. Developers building or integrating MCP support around WordPress abilities. The README says abilities are private by default and must be explicitly made public; it supports HTTP and STDIO transports. It is an integration layer, not the same packaged experience as WSP. See the Adapter README.
WordPress.com MCP A hosted MCP endpoint that uses OAuth 2.1. Eligible WordPress.com customers, or self-hosted site owners who meet the documented Jetpack conditions. WordPress.com’s documentation says it is available on paid WordPress.com plans, for the first 30 days of a newly created free site, and for self-hosted WordPress sites connected through Jetpack with eligible Jetpack AI or Jetpack Complete plans. Eligibility may change. See WordPress.com’s MCP documentation.
WordPress.org MCP server A separate service for plugin-directory work, including guidelines, readme validation, submission status and submission workflows. People working on WordPress.org plugin submissions rather than managing a site’s content. It is not the direct site-management product covered here. See the WordPress.org MCP server guide.

When choosing, compare whether you want a self-hosted plugin or hosted endpoint, a packaged connection flow or a developer framework, the abilities available for your tasks, permission controls, authentication and revocation, client-specific setup, plan eligibility and audit visibility.

Best Value
hosting servers
  • easy to use
  • Free app
  • Compatible with all devices
  • It gives the best comparison between ten different hosts

What to verify before enabling writes

  • Confirm the plugin’s current version, minimum WordPress and PHP versions, and the specific abilities included in that release.
  • Check your AI client’s current connection instructions and whether it needs a bridge or additional runtime.
  • Verify which WordPress user the client authenticates as and which capabilities that user has.
  • Test the intended actions on staging; confirm both the result and the corresponding audit-log entry.
  • Decide how you will review changes, recover from errors and revoke access when the task is complete.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.