WordPress MCP plugin — connect Claude, Cursor & AI agents. PHP, WP-CLI, files, posts, Elementor skills. Expert Suite included. Staging/dev only.
Agent2Wp demonstrates solid tool definition quality with complete JSON schemas, clear descriptions, and proper parameter constraints. All 12 tools have input/output schemas and descriptions. Naming follows verb_noun conventions (create-post, get-post, list-posts, update-post, delete-post, edit-file, delete-file, disable-file, enable-file, create-upload-link, create-admin-access-link, discover-abilities). However, several parameter descriptions lack detail about constraints, formats, and error recovery guidance. Output schemas are documented but generic (success/error pattern). Error handling descriptions are minimal, tools don't guide LLMs on recovery steps or categorize errors as retryable vs fatal. Some tools (disable-file, enable-file) have narrow, specialized use cases that could confuse LLM selection. File operation tools (edit-file, delete-file) lack explicit path traversal and injection attack warnings in descriptions.
Creates a temporary, one-time WordPress admin access exchange for browser automation tools. Use this when an agent needs to inspect or operate wp-admin through a browser MCP without asking the user for a password. POST the returned token and nonce in headers to receive a short-lived one-time login URL.
Creates a WordPress post or page.
Creates a temporary upload endpoint and header-only bearer token that external tools can use to upload one file into the WordPress filesystem. Useful when the agent has a local ZIP, plugin, theme, or media file and wants to upload it with curl or another external tool. The endpoint accepts raw PUT/POST bodies and multipart/form-data with a field named "file".
Deletes a file or directory from the server filesystem. Non-empty directories require the recursive flag. Critical WordPress directories (ABSPATH root, wp-admin, wp-includes) are protected from deletion. Idempotent: deleting a non-existent path succeeds with deleted=false.
Deletes a WordPress post or page.
discover-abilities tool has no visible input schema in source code.
File operation tools (edit-file, delete-file, disable-file, enable-file) lack explicit security warnings in descriptions about path traversal, injection attacks, and protected directories. Descriptions should state 'Relative paths are resolved from ABSPATH; absolute paths outside ABSPATH are rejected.'
Error handling descriptions are generic. Tools return {success, error} but descriptions don't guide LLMs on recovery. E.g., create-post should say 'On failure, error field contains reason (e.g., "Title required"). Retry with valid title or call list-posts to verify post_type.'
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 59 | 2026-07-28+ | v2 |
Disables a file in the sandbox (wp-content/agent2wp-sandbox/) by appending ".disabled" to its filename. The file is preserved on disk but no longer loaded by the sandbox loader. Use the same path with ".disabled" removed to re-enable. Only operates on files inside the sandbox directory. Idempotent: disabling an already-disabled file succeeds with disabled=false.
Edits an existing file by replacing an exact string match with new content. Works like the edit tool in AI code agents: specify the old text to find and the new text to replace it with. The old string must be unique in the file unless replace_all is set.
Re-enables a previously disabled sandbox file by removing the ".disabled" suffix from its filename. Only operates on files inside the sandbox directory (wp-content/agent2wp-sandbox/). Idempotent: enabling a file that is not disabled succeeds with enabled=false.
Retrieves a WordPress post or page by ID.
Lists WordPress posts or pages with optional filters.
Updates an existing WordPress post or page.
Discover all available WordPress abilities in the system. Returns a list of all registered abilities with their basic information, plus Agent2Wp environment instructions.
disable-file and enable-file have narrow, specialized semantics (sandbox-only operations) that may confuse LLM selection. Descriptions should explicitly state 'Only operates on files inside wp-content/agent2wp-sandbox/. Use edit-file or delete-file for other files.'
Parameter descriptions lack format/constraint details. E.g., 'path' in edit-file should state 'Relative paths resolved from ABSPATH; must be readable and writable. Max 4096 chars.' 'old_string' should note 'Must match exactly including whitespace; use replace_all=true for multiple occurrences.'