Recommended Free Tools
WSP MCP is a WordPress plugin that lets compatible AI clients call selected abilities on your site through the Model Context Protocol (MCP). You install it on WordPress, choose which abilities to expose, and connect a supported client using the plugin’s instructions. Installing it does not, according to the project, automatically enable every write action: write abilities are disabled by default, and requests run with the connected WordPress user’s permissions.
That makes the key setup decision less about connecting an agent and more about deciding what it should be able to do. Start with a narrowly privileged account, enable only the tools needed for the task, and verify the connection with low-risk requests before considering write access.
As an Amazon Associate I earn from qualifying purchases.
What WSP WordPress MCP does
WSP MCP adds an MCP server to a WordPress installation and exposes selected site operations to compatible AI clients. The project documents abilities covering areas such as posts, pages, media, menus, WooCommerce, forms, SEO metadata, and Elementor layouts. The actual tools available depend on the installed plugin version and which integrations are enabled.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →The project describes a built-in server, so natively supported clients do not need a separate MCP Adapter or a Node.js bridge. Some client connection methods may use the mcp-remote bridge; check the current WSP installation guide and the chosen client’s documentation for that client’s requirements. The plugin’s supported clients and implementation details can change, so confirm them in the current WordPress.org listing and the project repository.
#1 Best Overall
The WordPress.org listing describes WSP MCP as free and open source. Check the current listing and repository for up-to-date release, license, compatibility, and installation information rather than assuming those details remain unchanged.
How to connect an AI client to WSP MCP
- Install and activate WSP MCP. Use the WordPress dashboard or the project’s installation instructions. The project guide lists WordPress 6.9+ and PHP 7.4+ as prerequisites at the time it was accessed; confirm current requirements before installing.
- Choose the abilities the task requires. Open the plugin’s MCP settings and enable only the relevant tool groups. Begin with read-oriented abilities where possible.
- Open the connection page for your client. Follow the plugin’s generated configuration or setup instructions. The project describes a browser-based OAuth connector for Claude and generated configuration for other clients; use the current instructions for the client and release you have.
- Reconnect or restart the AI client. Then try a small, low-risk request and check that the client can access only the expected site information or operation.
- Inspect the plugin’s audit log and analytics. Use these to review recorded agent activity and how requests behaved. Do not treat an audit log as a substitute for reviewing the resulting WordPress content or settings.
Keep connection credentials private. Do not paste secrets into public prompts, shared configuration files, or support posts. For a first connection, staging is a safer place to check that the client sees the intended tools and that the workflow behaves as expected.
How do I connect Claude to WordPress?
For WSP MCP, install and activate the plugin, enable only the abilities needed, then follow its connection page’s Claude instructions. The project describes a browser OAuth connector for Claude. Complete the authorization in the browser and reconnect the client if prompted. The exact screens and requirements may change, so use the current plugin instructions rather than copying an old configuration from another version.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsBefore authorizing, check which WordPress account is being connected and what abilities have been enabled. Afterward, test with a harmless request and review the audit log.
Rank #3
Is it safe to give an AI agent access to my WordPress site?
There is no blanket yes: the risk depends on the account, enabled abilities, authentication setup, client, and whether changes are reviewed. WSP’s documentation says write abilities are off by default, tools check the connected WordPress user’s relevant capabilities, and object operations apply ownership and object checks. It also documents OAuth 2.1, WordPress Application Passwords, or a plugin-generated API key as authentication options. These are controls described by the project, not an independent security audit or a guarantee that the entire WordPress installation or third-party client is secure.
The plugin listing also describes OAuth-related measures including administrator opt-in, disconnect-on-disable behavior, visibility of the consent-page origin, protection against framing, client-registration limits, and a response to refresh-token replay. Those descriptions are useful to review, but they do not establish the security of every deployment.
Rank #4
Reduce the blast radius before enabling writes
- Connect a WordPress user with only the capabilities needed for the work. Avoid using an all-powerful administrator account for routine agent tasks when a narrower account can do the job.
- Enable tool groups one at a time. Avoid exposing unrelated store, publishing, design, or administrative functions to an agent that does not need them.
- Start with read-only requests, then review the proposed change yourself before permitting consequential edits or publishing.
- Keep a recoverable backup and test the workflow on staging before enabling write abilities on a production site. WSP’s own safety guidance recommends staging.
- After use, review the audit log and inspect changed content or settings directly in WordPress. Revoke or disconnect access you no longer need.
Which AI apps work with WSP MCP?
The project lists Claude, Cursor, Codex, Google Antigravity, OpenClaw, and OpenCode. That list is project-reported and may change; the current plugin listing and connection guide are the best places to verify availability and client-specific setup. Support for a client does not mean every feature or transport works identically across clients.
WSP MCP vs. WordPress’s other MCP options
“WordPress MCP” can refer to different products and development approaches. These options are not interchangeable:
Best Value
- easy to use
- Free app
- Compatible with all devices
- It gives the best comparison between ten different hosts
| Option | What it is | Best fit |
|---|---|---|
| WSP MCP | A ready-to-install WordPress plugin with its own MCP server and a user interface for enabling site abilities. Its tool coverage depends on version and enabled integrations. | Site owners or developers seeking a plugin-based way to expose selected site operations to compatible AI clients. |
| WordPress MCP Adapter | An official developer package that connects the WordPress Abilities API to MCP tools, resources, and prompts. Its README says abilities are private by default and must be explicitly made public; it supports HTTP and STDIO transports. | Developers building or integrating MCP support around WordPress abilities, rather than users seeking the same packaged experience as WSP. |
| WordPress.com MCP | A hosted endpoint using OAuth 2.1. Official documentation says it is available on paid WordPress.com plans, for the first 30 days of a newly created free site, and for eligible self-hosted WordPress sites connected through Jetpack with Jetpack AI or Jetpack Complete plans. Eligibility may change. | Users whose site and plan qualify for WordPress.com’s hosted service. |
| WordPress.org MCP server | A separate service for plugin-directory workflows, including guidelines, readme validation, submission status, and submission workflows. | Plugin developers working with the WordPress.org plugin directory, not people seeking direct management of their own site. |
When comparing them, consider whether you want a plugin running on your site or a hosted endpoint, a ready-made interface or a developer framework, which abilities are exposed, how access is granted and revoked, whether your AI client is supported, and how you can audit activity.
Quick Recap
What to verify before enabling write access
- Compatibility: Check the current WSP release’s WordPress and PHP requirements, along with any bridge requirement for your chosen client. The documented WordPress 6.9+ and PHP 7.4+ minimums are time-sensitive.
- Available abilities: Confirm the tools shown by your installed version and enabled integrations match the work you intend to delegate.
- Account scope: Verify the connected WordPress user has appropriate capabilities and does not have unnecessary privileges.
- Authentication and revocation: Confirm which authentication method the client setup uses, where credentials are stored, and how to disconnect or revoke access.
- Change review and recovery: Test on staging, retain a usable backup, and decide how a human will inspect consequential changes before they reach visitors or customers.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




