Core WordPress abilities for MCP. Content, menus, users, media, widgets, plugins, options, and system management.
This WordPress plugin MCP server exposes 20 tools with significant definition quality gaps. While all tools have names, descriptions, and visible schemas, the descriptions are often minimal (many under 100 chars) and lack guidance on when/why to use each tool or what to do on failure. Parameter descriptions are present but often generic (e.g., 'Post meta data'). No output schemas are documented. Security-critical operations (plugin install/update/delete, options update, elementor data) require confirmation tokens but lack clear guidance on obtaining them. The server accepts 'confirm_dangerous_action' as a parameter for irreversible operations, a security anti-pattern that leaks potential confirmation strategies into logs. Tool naming is clear and verb-first (create_post, update_page, delete-item), but some are overly specific to WordPress internals (meta/update-post-meta, menus/upsert-item) that may not be intuitive to non-WP agents. Schemas are present for all tools (good), but error handling and output documentation is entirely absent from the visible code.
Create a new page
Create a new post with optional meta and featured image support
Search for posts and pages
Update an existing page with content write mode support
Update an existing post
Update Elementor page builder data
Upload media from base64 encoded content
confirm_dangerous_action parameter exposed as tool input
No output schemas documented for any tool
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 58 | 2026-07-28+ | v2 |
Delete a menu item
Update an existing menu item
Create or update a menu item
Delete post meta data
Update post meta data
Update a WordPress option
Delete a plugin
Install a plugin from the official WordPress.org directory
Update a plugin to the latest version
Upload and install a plugin from URL
Upload and install a plugin from base64 encoded content
Create a restricted application password for a user
Revoke the current application password
Minimal parameter descriptions for meta, post_meta, and elementor data parameters
Descriptions under 100 characters lack context for LLM selection
No error handling guidance in any tool description
WordPress-specific parameter names may be opaque to non-WP agents
No distinction between required and optional parameters in descriptions
Upload tools accept base64 but no size limits or format constraints documented