Offers validation and security checking for PHP code, with the ability to detect issues like prefix violations and apply custom coding standards to PHP files.
Provides code review tools for WordPress development, including fetching coding guidelines, validating code against WordPress standards, and checking for security vulnerabilities in WordPress code.
WordPress Code Review MCP Server v2.0
A lightweight, configurable MCP (Model Context Protocol) server for development teams. Fetches coding guidelines, security rules, and validation patterns from external sources or URL where you have hosted your custom guidelines.
🚀 Key Features
- ✅ No hardcoded rules - Fetch guidelines from any URL
- ✅ Dynamic configuration - Specify source via environment variables
- ✅ Custom validation - Add your own coding standards and security rules
- ✅ Lightweight - External guidelines, minimal codebase
📋 Available Tools
get_guidelines
- Fetch development guidelines by categoryvalidate_code
- Validate code against configured standardssecurity_check
- Security vulnerability scanning
📋 Prerequisites
- Node.js installed (v18+)
🛠 Installation & Setup
Step 1: Clone Repository
Step 2: Install Dependencies & Build
Step 3: Host Your Guidelines
Host the files from sample-guidelines/html/
on your web server and configure your base URL, for example: https://yourdomain.com/guidelines/
The MCP server will fetch:
https://yourdomain.com/guidelines/guidelines.md
https://yourdomain.com/guidelines/validation-rules.md
https://yourdomain.com/guidelines/security-rules.md
Step 4: Configure Cursor
Add to your Cursor settings (Ctrl+Shift+P
→ "Preferences: Open User Settings (JSON)"):
Replace /path/to/wp-code-review-mcp-server
with your actual path (e.g., /home/wp-code-review-mcp-server
)
Why the path? Unlike published npm packages, this is a local MCP server. The path tells Cursor exactly where to find your built server file.
If you don't see MCP server connected, restart Cursor and the MCP server will be available.
Guidelines Format
Your guidelines server should serve these files:
/guidelines.md
- Main development guidelines/validation-rules.md
- Code validation rules/security-rules.md
- Security scanning rules
Step 5: Test in Cursor
- Open any PHP file in Cursor
- Ask the AI: "Check this code for security issues:
class mo_Test {}
" - The AI should detect the short prefix violation!
🔧 Troubleshooting
Having configuration issues? See the Configuration Troubleshooting Guide for common mistakes and solutions.
📝 Customizing Guidelines
Edit the files in sample-guidelines/html/
to add your own:
- Coding standards
- Validation rules
- Security patterns
- Company-specific guidelines
The MCP server automatically uses updated rules without restart.
📄 License
MIT License
Built for Dynamic, Maintainable Development Guidelines 🛡️
You must be authenticated.
A lightweight, configurable server that fetches coding guidelines, security rules, and validation patterns from external sources to help development teams maintain code quality standards in WordPress projects.
Related MCP Servers
- -securityAlicense-qualityinteract with your WordPress site (s) using this MCP WordPress Server 100% created with Cline. If you use Cline you can have it evaluate the code by pointing it to the repository and asking if the code is safe to use. See the READ.me for a detailed overview. Enjoy!Last updated -14JavaScriptMIT License
- -securityFlicense-qualityA server enabling seamless interaction between AI models and WordPress sites with secure, standardized communication using the WordPress REST API for comprehensive site management.Last updated -99TypeScript
- -securityAlicense-qualityA server that provides standardized development rules and context for Business Central projects, optimized for use with Cursor editor.Last updated -JavaScriptMIT License
- -securityAlicense-qualityA Message Control Protocol server that runs PHP tests and static analysis tools automatically for developers, providing results directly to AI assistants in Cursor editor.Last updated -1TypeScriptMIT License