For most WordPress sites, the MCP Adapter is the starting point, not a complete content-management toolset. It connects the Model Context Protocol (MCP) to abilities registered by WordPress core, plugins, or custom code. Add Agent Abilities for MCP when you want a broad, selectable catalog; consider Agent Toolbelt for site diagnostics and guarded maintenance. The right choice depends on what you want an AI client to do and which WordPress user’s permissions it will inherit.
This comparison reflects project documentation checked on October 3, 2026. Plugin feature counts, compatibility statements, and client lists below are claims from the projects’ own documentation, not results of independent testing.
What each WordPress MCP option does
MCP is the connection protocol; WordPress abilities are the site actions and information exposed through that connection. The MCP Adapter supplies the bridge and server transports. By itself, it should not be mistaken for a large catalog of editorial, commerce, or maintenance tools.
| Option | What it adds | Capabilities and exposure | Authentication and compatibility notes |
|---|---|---|---|
| WordPress MCP Adapter | The official bridge from WordPress Abilities API registrations to MCP tools, resources, and prompts. Its repository describes HTTP and STDIO transports, multiple servers, and per-server and per-ability controls. | Three default meta-tools discover abilities, retrieve ability information, and execute an ability. Core provides a small baseline for site, authenticated-user, and environment information; additional capabilities come from plugins or custom code. Abilities are private by default on the default server. | Official guidance describes local STDIO through WP-CLI and HTTP through a remote proxy using application passwords or custom OAuth. The adapter documentation identifies WordPress 6.9 as the release shipping the Abilities API; check the exact adapter release and client path before relying on a version pairing. |
| Agent Abilities for MCP | A governed ability catalog layered on the Abilities API and official adapter, including a bridge for abilities registered by other plugins. | Its WordPress.org listing advertises 179 abilities: 85 core abilities and 94 from auto-detected integrations. Listed areas include WordPress tasks, WooCommerce, ACF, SEO, events, and tickets. The listing says abilities are disabled until enabled, capability-checked, and logged. Counts and feature descriptions are publisher claims. | The listing states WordPress 6.9+ and PHP 7.4+. It describes OAuth or a low-privilege user with an Application Password, and names Claude clients, ChatGPT custom connectors, Cursor, VS Code, Windsurf, Gemini CLI, and Manus. It says hosted Gemini is not supported; ChatGPT connector availability depends on Developer Mode/custom connector access and an eligible plan. |
| Agent Toolbelt | A set of site diagnostics and operations abilities exposed through the official adapter. | The listing describes read-only status, health, logs, updates, cron, and checksum checks, plus higher-risk update, rollback, toggle, and database-cleanup operations. It says destructive actions are disabled by default and that high-risk execution uses dry runs and a confirmation token. | The listing gives an Application Password setup for an MCP endpoint and says the adapter handles transport. WooCommerce 10.9+ is described as bundling the same adapter when its MCP integration feature is enabled. This does not establish a general WordPress/PHP/client compatibility matrix. |
Automattic wordpress-mcp (legacy) |
A historical implementation, not a current recommendation. | Do not base a new connection on this archived repository. | The repository says it is deprecated and archived and points to WordPress/mcp-adapter for ongoing development. |
Which option fits your use case?
Choose the MCP Adapter for a bridge or a custom build
Use the official adapter if your priority is connecting MCP to abilities you have registered yourself or supplied through other plugins. Its three meta-tools provide a way to find and run available abilities; they do not imply that every site-management action is included. For a new custom integration, treat ability registration and exposure policy as part of the implementation, not as an automatic consequence of installing the adapter.
#1 Best Overall
Choose Agent Abilities for a broad, governed catalog
Its listing is aimed at site owners who want a larger set of prebuilt abilities and integrations, with explicit enablement and capability checks. The advertised 179-ability catalog and integrations are the plugin publisher’s stated inventory, not an independent measure of completeness or quality. Review which abilities you enable, especially those connected to commerce or customer information.
Choose Agent Toolbelt for operational checks and maintenance
Toolbelt is oriented toward diagnostics and administration rather than a general editorial catalog. Its documented scope includes read-only checks as well as operations that can alter plugins, themes, or database records. Dry runs and confirmation tokens are controls described by the listing; they do not remove the need to assess the consequences of each enabled operation.
Rank #2
- Book - 1, 000 books to read before you die: a life-changing list (1000 before you die)
- Language: english
- Binding: hardcover
How authentication and permissions work
Local connections: STDIO with WP-CLI
The official developer guidance shows local STDIO use with wp mcp-adapter serve and a selected WordPress user. This requires WP-CLI to be available in that local environment. The client’s calls operate in the context of that WordPress user, so choose a dedicated account with only the capabilities needed for the intended abilities.
HTTP connections: credentials through a proxy or integration
For HTTP, official guidance describes the @automattic/mcp-wordpress-remote proxy with WordPress Application Password credentials, and notes that custom OAuth implementations are possible. Agent Abilities for MCP separately describes OAuth or Application Password access. Agent Toolbelt’s listing explains an Application Password setup; do not infer that it supports OAuth merely from interoperability language.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #3
An Application Password is a WordPress credential whose effective reach follows the account’s role and capabilities. Agent Abilities for MCP says OAuth tokens issued for its endpoint are endpoint-specific, while Application Password access follows the WordPress account. These are the plugin listing’s descriptions of credential scope, not an independent security audit.
Keep access narrow and reviewable
WordPress developer guidance recommends dedicated limited-capability users, careful permission callbacks, monitoring and logging, and read-only abilities for publicly exposed HTTP servers. Avoid unrestricted permission callbacks for destructive operations. Agent Abilities for MCP says its enabled calls are capability-checked and logged; Agent Toolbelt describes audit records and confirmation controls. Treat these as documented safeguards, not a guarantee that every configuration or workflow is safe.
Rank #4
Data sensitivity matters as much as the transport. Agent Abilities for MCP warns that WooCommerce and ACF operations may reach real order, customer, or personal data. Enable only the specific abilities required, and evaluate whether the connected user should be able to access that information at all.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.WordPress versions, client support, and compatibility limits
Version claims describe different things and should not be collapsed into a single compatibility promise. The adapter article identifies WordPress 6.9 as the release that ships the Abilities API. Agent Abilities for MCP lists WordPress 6.9+ and PHP 7.4+. Agent Toolbelt states that WooCommerce 10.9+ includes the adapter when its MCP feature is enabled; that is a WooCommerce-specific condition, not evidence that every WordPress installation has the adapter bundled.
Free tools Windows power users keep installed
One-click scans. No signup required.
Agent Abilities for MCP names Claude clients, ChatGPT custom connectors, Cursor, VS Code, Windsurf, Gemini CLI, and Manus, while its listing says hosted Gemini is unsupported. It also ties ChatGPT connection availability to Developer Mode/custom connector access and an eligible ChatGPT plan. These product capabilities can change, so confirm the current client documentation and plan requirements before choosing an architecture.
The available project documentation does not establish a tested, release-by-release matrix spanning every plugin version, PHP version, WordPress version, transport, and MCP client. Check the current release notes for the exact versions you plan to combine, then validate the connection and intended abilities on a staging site.
What happened to the older wordpress-mcp repository?
Automattic’s wordpress-mcp repository is explicitly archived and deprecated; its guidance points to WordPress/mcp-adapter as the maintained direction. It is not the same as the WordPress.org Plugin Directory’s MCP server, which is for plugin-directory workflows such as guidelines, README validation, submission status, and submission actions—not for exposing abilities on your own WordPress site.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




