Free tools Windows power users keep installed
One-click scans. No signup required.
WordPress MCP is not one single product. It can mean a plugin that lets compatible AI clients use capabilities on a self-hosted WordPress site, WordPress.com’s hosted MCP service for eligible sites, or WordPress.org’s separate server for plugin-directory tasks. In each case, MCP provides a connection between a client and a service; what the client can do depends on the capabilities and permissions available through that particular route.
What does WordPress MCP mean?
MCP, or Model Context Protocol, is a shared interface that allows a compatible AI client to communicate with an external service. In WordPress, the term is used for three distinct offerings:
- WordPress MCP Adapter: A plugin and server layer for connecting a self-hosted WordPress site’s registered capabilities to MCP-compatible clients.
- WordPress.com MCP Server: A hosted service at https://public-api.wordpress.com/wpcom/v2/mcp/v1 for eligible WordPress.com sites and self-hosted sites connected through Jetpack.
- WordPress.org MCP Server: A server for WordPress.org Plugin Directory work, including checking guidelines, validating plugin readmes, and handling review submissions. It is not a general connector to arbitrary WordPress site content.
These options solve different problems, so the right answer to “What is the best WordPress MCP server?” depends on whether you want an AI client to work with a site, connect WordPress.com sites, or assist with plugin development.
How the WordPress MCP Adapter works
The Adapter connects MCP to WordPress’s Abilities API. The Abilities API lets WordPress core and plugins register machine-readable capabilities. The Adapter maps eligible abilities to MCP features: tools perform actions, resources provide readable context, and prompts guide workflows. Depending on what the site has registered, a capability might fetch information, update a post, or run a diagnostic.
#1 Best Overall
The default server includes tools to discover available abilities, retrieve information about an ability, and execute one. It does not automatically make every WordPress function available: abilities must exist, and they must be made public for MCP access through the default server. A compatible AI client can only use what is exposed and permitted.
It is a bridge, not an AI assistant
The official MCP Adapter plugin FAQ puts it plainly: “MCP Adapter is the server and transport layer. It does not provide any AI features itself.” Installing it does not supply an AI model or create a ready-made catalog of site actions. The site needs useful abilities registered by WordPress core or installed plugins, and an MCP-compatible client must connect to them.
Permissions still matter
Ability exposure is opt-in for the default server, and WordPress checks the current user’s permissions before an ability runs. MCP does not bypass WordPress authorization, but it should not be assumed to be read-only either: an exposed ability may make changes if the connected user is allowed to perform them. Decide which abilities to expose and which account to use accordingly.
Which WordPress MCP route fits your goal?
| Goal | Route | What to check |
|---|---|---|
| Connect an AI client to a self-hosted WordPress site | WordPress MCP Adapter | Whether the site has useful registered abilities, whether you can install and configure the plugin, and what permissions the connecting account has. |
| Connect sites in a WordPress.com account | WordPress.com MCP Server | Plan eligibility, the hosted endpoint, and its browser-based OAuth 2.1 authorization. |
| Work on a plugin for the WordPress.org directory | WordPress.org MCP Server | Its plugin-development scope and WordPress.org account authorization. It does not replace directory review or the author’s responsibility for submitted code. |
How to connect an AI client to a self-hosted WordPress site
The Adapter plugin listing describes installation through the WordPress dashboard or WP-CLI. Once it is active, you still need abilities on the site and a transport that your client can use.
- Check compatibility. The WordPress.org plugin listing accessed on October 4, 2026, identifies MCP Adapter version 0.7.0, dated October 2, 2026. It lists WordPress 6.9 or later and PHP 7.4 or later, and says “Tested up to” WordPress 7.1.2. These are time-sensitive requirements; check the current plugin listing before installing.
- Install and activate the plugin. In the dashboard, go to Plugins > Add New, search for “MCP Adapter,” then install and activate it. Alternatively, run
wp plugin install mcp-adapter --activatewith WP-CLI. - Make sure the site has abilities to offer. Register the capabilities your client needs, or install plugins that register them. Review which are made public for MCP access; installing the Adapter alone does not provide those capabilities.
- Choose a transport. For local development, the developer guide describes WP-CLI over STDIO, which requires WP-CLI on the local machine. For a publicly accessible site, or when STDIO is not suitable, it documents HTTP through the
@automattic/mcp-wordpress-remoteproxy. - Authorize the connection. The documented HTTP example uses a WordPress username and application password; the guide also describes a custom OAuth implementation. Follow the current WordPress MCP Adapter developer guide for client configuration rather than reusing example credentials.
Use a dedicated WordPress account with only the capabilities the integration needs, protect its credentials, and expose only the abilities required for the task. The Adapter’s permission checks limit what that user can do, but the account’s privileges still determine the potential impact of an action.
How WordPress.com MCP access works
WordPress.com provides the hosted endpoint https://public-api.wordpress.com/wpcom/v2/mcp/v1. Its documentation says one connection can reach every site on the user’s account. A self-hosted WordPress site connected through Jetpack uses the same server.
Rank #4
WordPress.com documents MCP access for paid plans, a 30-day access period for new free sites, and Jetpack AI or Jetpack Complete for self-hosted sites connected through Jetpack. Authorization uses browser-based OAuth 2.1. Plan entitlements and product details can change, so check the WordPress.com MCP information page for current eligibility before setting up a connection.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the WordPress.org MCP Server does
WordPress.org’s MCP server is aimed at plugin authors working with the Plugin Directory, not at giving an agent general access to a WordPress site. Its documented tasks include reading plugin guidelines and developer resources, validating readmes, checking review status, submitting a plugin for review, and responding to review feedback.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Best Value
The quick setup uses npx -y @wporg/mcp and browser authorization to create an application password. WordPress.org says the password is shown once and can be revoked through account security settings. Using the server does not replace the directory’s review process or its guidelines; the plugin author remains responsible for the code submitted. See the WordPress.org MCP Server documentation for its scope and setup details.
Version and protocol compatibility
In the plugin listing accessed October 4, 2026, MCP Adapter 0.7.0 documents protocol revisions 2025-11-25 and 2026-07-28. Clients proposing 2025-06-18 or 2024-11-05 are served through the 2025-11-25 schema. This compatibility information can change with releases; check the listing and the project’s current documentation when configuring a client.
Quick Recap
Security checks before connecting
- Confirm the exact MCP server and its purpose; the WordPress.org plugin workflow server is not the self-hosted site Adapter.
- Review the abilities being exposed and whether each can read data or make changes.
- Use an account with only the permissions needed for the connection.
- Protect application passwords and other credentials, and revoke access if it is no longer needed.
- For WordPress.com, verify current plan eligibility and authorization details with WordPress.com before connecting.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




