Exposes a Model Context Protocol (MCP) server on WordPress sites, allowing AI agents to connect and interact with the site's REST API through an HTTP interface with OAuth 2.1 authorization.
WP MCP Server exposes only 2 tools with minimal to moderate schema definition. Both tools have descriptions, but parameter descriptions are either missing entirely or generic. Input schemas are present but lack proper type constraints and validation guidance. The wp_api tool is particularly concerning, it accepts freeform method/path parameters with no enum constraints, inviting hallucinated REST endpoints. No output schema documentation is visible. Error handling exists at the protocol level (JSON-RPC errors) but tools provide no recovery guidance. Security concerns: wp_api grants unrestricted access to WordPress REST API, creating a massive attack surface if misused. Overall, the server defines functional tools but falls short of production-grade quality.
Re-discover all WordPress REST API routes and update the tool list. Use this after registering new post types, installing plugins, or any change that adds/removes REST API endpoints.
Universal WordPress REST API tool for making arbitrary HTTP requests to REST endpoints. Supports GET, POST, PUT, PATCH, DELETE methods with query parameters, JSON body, and file uploads.
wp_api parameter 'method' accepts freeform string with no enum constraint (GET|POST|PUT|PATCH|DELETE). LLMs will hallucinate invalid methods like 'FETCH' or 'OPTIONS'. Description provides examples but no formal constraint.
wp_api parameter 'params' lacks description of payload structure and content type. Description says 'Query parameters for GET/DELETE or JSON body for POST/PUT/PATCH' but does not explain what structure is expected. LLMs cannot infer valid JSON shapes.
wp_api has no documented output schema. Callers have no way to know what structure the response will have (success vs error format, field names, types). This violates the documented return types baseline (100% of A+ tools).
wp_api grants unrestricted access to any WordPress REST endpoint. No validation of path, no permission scoping per endpoint, no rate limiting. A compromised agent could delete all posts, modify user permissions, or exfiltrate data. This is a critical security gap.
Inferred effective spec: 2026-07-28+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
refresh_tools and wp_api parameters 'params' and 'arguments' have object type with no properties schema defined. LLMs cannot determine what fields to include. Schema should define allowed keys and value types.
No error recovery guidance. If wp_api returns a 404, authentication failure, or permission denied, tools do not suggest corrective actions (e.g., 'Check your WordPress user role' or 'Verify the endpoint path with refresh_tools'). Errors are protocol-level only.
wp_api tool name is generic and does not follow verb_noun convention. 'call_wordpress_rest_api' or 'make_wordpress_request' would be more descriptive. Current name does not clearly signal what action is performed.
No documented pagination support or result limits. If wp_api returns large result sets (e.g., all posts, all users), responses could exceed context window. No guidance on limiting results with query parameters.