October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk6 min

WSP WordPress MCP: Connect AI Coding Agents to Your WordPress Site

WSP MCP adds an MCP server to WordPress so compatible AI clients can use selected site abilities. Here’s how to connect it, limit permissions, and check alternatives.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

WSP MCP is a WordPress plugin that lets compatible AI clients call selected abilities on your site through the Model Context Protocol (MCP). You install it on WordPress, choose which abilities to expose, and connect a supported client using the plugin’s instructions. Installing it does not, according to the project, automatically enable every write action: write abilities are disabled by default, and requests run with the connected WordPress user’s permissions.

That makes the key setup decision less about connecting an agent and more about deciding what it should be able to do. Start with a narrowly privileged account, enable only the tools needed for the task, and verify the connection with low-risk requests before considering write access.

As an Amazon Associate I earn from qualifying purchases.

What WSP WordPress MCP does

WSP MCP adds an MCP server to a WordPress installation and exposes selected site operations to compatible AI clients. The project documents abilities covering areas such as posts, pages, media, menus, WooCommerce, forms, SEO metadata, and Elementor layouts. The actual tools available depend on the installed plugin version and which integrations are enabled.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The project describes a built-in server, so natively supported clients do not need a separate MCP Adapter or a Node.js bridge. Some client connection methods may use the mcp-remote bridge; check the current WSP installation guide and the chosen client’s documentation for that client’s requirements. The plugin’s supported clients and implementation details can change, so confirm them in the current WordPress.org listing and the project repository.

The WordPress.org listing describes WSP MCP as free and open source. Check the current listing and repository for up-to-date release, license, compatibility, and installation information rather than assuming those details remain unchanged.

How to connect an AI client to WSP MCP

  1. Install and activate WSP MCP. Use the WordPress dashboard or the project’s installation instructions. The project guide lists WordPress 6.9+ and PHP 7.4+ as prerequisites at the time it was accessed; confirm current requirements before installing.
  2. Choose the abilities the task requires. Open the plugin’s MCP settings and enable only the relevant tool groups. Begin with read-oriented abilities where possible.
  3. Open the connection page for your client. Follow the plugin’s generated configuration or setup instructions. The project describes a browser-based OAuth connector for Claude and generated configuration for other clients; use the current instructions for the client and release you have.
  4. Reconnect or restart the AI client. Then try a small, low-risk request and check that the client can access only the expected site information or operation.
  5. Inspect the plugin’s audit log and analytics. Use these to review recorded agent activity and how requests behaved. Do not treat an audit log as a substitute for reviewing the resulting WordPress content or settings.

Keep connection credentials private. Do not paste secrets into public prompts, shared configuration files, or support posts. For a first connection, staging is a safer place to check that the client sees the intended tools and that the workflow behaves as expected.

How do I connect Claude to WordPress?

For WSP MCP, install and activate the plugin, enable only the abilities needed, then follow its connection page’s Claude instructions. The project describes a browser OAuth connector for Claude. Complete the authorization in the browser and reconnect the client if prompted. The exact screens and requirements may change, so use the current plugin instructions rather than copying an old configuration from another version.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Before authorizing, check which WordPress account is being connected and what abilities have been enabled. Afterward, test with a harmless request and review the audit log.

Is it safe to give an AI agent access to my WordPress site?

There is no blanket yes: the risk depends on the account, enabled abilities, authentication setup, client, and whether changes are reviewed. WSP’s documentation says write abilities are off by default, tools check the connected WordPress user’s relevant capabilities, and object operations apply ownership and object checks. It also documents OAuth 2.1, WordPress Application Passwords, or a plugin-generated API key as authentication options. These are controls described by the project, not an independent security audit or a guarantee that the entire WordPress installation or third-party client is secure.

The plugin listing also describes OAuth-related measures including administrator opt-in, disconnect-on-disable behavior, visibility of the consent-page origin, protection against framing, client-registration limits, and a response to refresh-token replay. Those descriptions are useful to review, but they do not establish the security of every deployment.

Reduce the blast radius before enabling writes

  • Connect a WordPress user with only the capabilities needed for the work. Avoid using an all-powerful administrator account for routine agent tasks when a narrower account can do the job.
  • Enable tool groups one at a time. Avoid exposing unrelated store, publishing, design, or administrative functions to an agent that does not need them.
  • Start with read-only requests, then review the proposed change yourself before permitting consequential edits or publishing.
  • Keep a recoverable backup and test the workflow on staging before enabling write abilities on a production site. WSP’s own safety guidance recommends staging.
  • After use, review the audit log and inspect changed content or settings directly in WordPress. Revoke or disconnect access you no longer need.

Which AI apps work with WSP MCP?

The project lists Claude, Cursor, Codex, Google Antigravity, OpenClaw, and OpenCode. That list is project-reported and may change; the current plugin listing and connection guide are the best places to verify availability and client-specific setup. Support for a client does not mean every feature or transport works identically across clients.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

WSP MCP vs. WordPress’s other MCP options

“WordPress MCP” can refer to different products and development approaches. These options are not interchangeable:

Best Value
hosting servers
  • easy to use
  • Free app
  • Compatible with all devices
  • It gives the best comparison between ten different hosts
Option What it is Best fit
WSP MCP A ready-to-install WordPress plugin with its own MCP server and a user interface for enabling site abilities. Its tool coverage depends on version and enabled integrations. Site owners or developers seeking a plugin-based way to expose selected site operations to compatible AI clients.
WordPress MCP Adapter An official developer package that connects the WordPress Abilities API to MCP tools, resources, and prompts. Its README says abilities are private by default and must be explicitly made public; it supports HTTP and STDIO transports. Developers building or integrating MCP support around WordPress abilities, rather than users seeking the same packaged experience as WSP.
WordPress.com MCP A hosted endpoint using OAuth 2.1. Official documentation says it is available on paid WordPress.com plans, for the first 30 days of a newly created free site, and for eligible self-hosted WordPress sites connected through Jetpack with Jetpack AI or Jetpack Complete plans. Eligibility may change. Users whose site and plan qualify for WordPress.com’s hosted service.
WordPress.org MCP server A separate service for plugin-directory workflows, including guidelines, readme validation, submission status, and submission workflows. Plugin developers working with the WordPress.org plugin directory, not people seeking direct management of their own site.

When comparing them, consider whether you want a plugin running on your site or a hosted endpoint, a ready-made interface or a developer framework, which abilities are exposed, how access is granted and revoked, whether your AI client is supported, and how you can audit activity.

What to verify before enabling write access

  • Compatibility: Check the current WSP release’s WordPress and PHP requirements, along with any bridge requirement for your chosen client. The documented WordPress 6.9+ and PHP 7.4+ minimums are time-sensitive.
  • Available abilities: Confirm the tools shown by your installed version and enabled integrations match the work you intend to delegate.
  • Account scope: Verify the connected WordPress user has appropriate capabilities and does not have unnecessary privileges.
  • Authentication and revocation: Confirm which authentication method the client setup uses, where credentials are stored, and how to disconnect or revoke access.
  • Change review and recovery: Test on staging, retain a usable backup, and decide how a human will inspect consequential changes before they reach visitors or customers.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.