wphealthkit-mcp
@wphealthkit/mcp-server v0.4.0
An MCP (Model Context Protocol) server that gives AI assistants direct access to WP HealthKit's plugin audit API. Once configured, tools like Claude Desktop, Claude Code, and Cursor can trigger security audits, retrieve findings, fetch AI-ready fix prompts, bulk-audit entire plugin directories, and flag false positives — all without leaving the chat interface.
Setup
Required environment variable
WPHK_API_KEY=your_api_key_hereGet your API key from wphealthkit.com/dashboard.
Claude Desktop
Add the following to your claude_desktop_config.json (usually at ~/Library/Application Support/Claude/claude_desktop_config.json on macOS):
{
"mcpServers": {
"wphealthkit": {
"command": "npx",
"args": ["-y", "@wphealthkit/mcp-server"],
"env": {
"WPHK_API_KEY": "your_api_key_here"
}
}
}
}Claude Code
Add to your project's .mcp.json:
{
"mcpServers": {
"wphealthkit": {
"command": "npx",
"args": ["-y", "@wphealthkit/mcp-server"],
"env": {
"WPHK_API_KEY": "your_api_key_here"
}
}
}
}Cursor
Open Cursor Settings > MCP > Add Server and use:
{
"wphealthkit": {
"command": "npx",
"args": ["-y", "@wphealthkit/mcp-server"],
"env": {
"WPHK_API_KEY": "your_api_key_here"
}
}
}Related MCP server: VibeCheck MCP Server
Available tools
Tool | Description |
| Trigger a security audit for a wp.org plugin by slug. Returns an audit ID. |
| Trigger an audit from a local ZIP file. Returns an audit ID. |
| Audit all plugin ZIP files in a local directory. Submits in batches of 10, streams results as each completes, and prints a final summary with risk breakdown and links to top findings. |
| Poll the status and full results of an audit by its ID. |
| Get paginated findings, with optional filters for severity and category. |
| Get AI-ready fix prompts for an audit's findings, batched by severity. |
| Look up a plugin's security grade, risk level, and findings count from the directory. |
| Check your current usage — audits used this month, tier, and limits. |
| Flag a finding as a false positive. The report goes to the WP HealthKit team for review; confirmed patterns result in a scanner rule update that prevents that pattern in all future audits. |
Tool reference
audit_plugin
Triggers a security audit for any plugin hosted on wp.org.
Parameters
Parameter | Type | Required | Description |
|
| Yes | The wp.org plugin slug (e.g. |
|
| No | Audit engines to run. Defaults to all engines. |
Example
audit_plugin({ slug: "contact-form-7" })
// Returns: { auditId: "abc-123", status: "queued" }audit_plugin_zip
Triggers an audit from a local ZIP file. Useful for plugins not on wp.org or pre-release builds.
Parameters
Parameter | Type | Required | Description |
|
| Yes | Absolute path to the ZIP file on disk. |
|
| No | Audit engines to run. Defaults to all engines. |
Example
audit_plugin_zip({ path: "/Users/me/plugins/my-plugin.zip" })
// Returns: { auditId: "def-456", status: "queued" }audit_plugins_bulk
Audits all plugin ZIP files in a local directory. Submissions are batched in groups of 10. Results stream as each audit completes, and a final summary table is printed with a risk breakdown and links to top findings.
Parameters
Parameter | Type | Required | Description |
|
| Yes | Absolute path to the directory containing plugin ZIPs. |
|
| No | Audit engines to run (e.g. |
|
| No | Glob pattern to match files. Defaults to |
Example
audit_plugins_bulk({ directory: "/Users/me/plugins", engines: [] })Output
Results stream to the conversation as each plugin completes. Once all audits finish, the tool prints a summary table:
Plugin Risk Findings Report
---------------------- -------- --------- ----------------------------------------
my-plugin.zip CRITICAL 14 https://wphealthkit.com/report/abc-123
another-plugin.zip LOW 2 https://wphealthkit.com/report/def-456
legacy-plugin.zip HIGH 7 https://wphealthkit.com/report/ghi-789
Summary: 3 plugins audited — 1 CRITICAL, 1 HIGH, 0 MEDIUM, 1 LOWget_report
Polls the status and full results of an audit. Call this after audit_plugin or audit_plugin_zip to wait for completion and retrieve the report.
Parameters
Parameter | Type | Required | Description |
|
| Yes | The audit ID returned by |
Example
get_report({ auditId: "abc-123" })
// Returns: { status: "completed", grade: "C", riskLevel: "HIGH", findingsCount: 7, reportUrl: "..." }get_findings
Returns paginated findings for a completed audit. Supports filtering by severity and category.
Parameters
Parameter | Type | Required | Description |
|
| Yes | The audit ID. |
|
| No | Filter by severity: |
|
| No | Filter by category (e.g. |
|
| No | Page number for pagination. Defaults to |
Example
get_findings({ auditId: "abc-123", severity: "CRITICAL" })get_fix_prompt
Returns AI-ready fix prompts for an audit's findings, grouped and batched by severity. Pass the output directly to a coding assistant to generate patches.
Parameters
Parameter | Type | Required | Description |
|
| Yes | The audit ID. |
|
| No | Limit prompts to a specific severity level. |
Example
get_fix_prompt({ auditId: "abc-123", severity: "HIGH" })check_plugin
Looks up a plugin's current security grade, risk level, and findings count from the WP HealthKit directory without triggering a new audit.
Parameters
Parameter | Type | Required | Description |
|
| Yes | The wp.org plugin slug. |
Example
check_plugin({ slug: "woocommerce" })
// Returns: { grade: "B", riskLevel: "MEDIUM", findingsCount: 3, lastAudited: "2026-04-20" }list_usage
Returns your current billing period usage — audits consumed, tier, and remaining quota.
Parameters
None.
Example
list_usage()
// Returns: { auditsUsed: 47, auditsLimit: 100, tier: "pro", resetsAt: "2026-05-01" }flag_finding
Flags a finding as a false positive. The report is reviewed by the WP HealthKit team. If the pattern is confirmed as a false positive, the scanner rule is updated to prevent the same result from appearing in all future audits.
Parameters
Parameter | Type | Required | Description |
|
| Yes | UUID of the audit containing the finding. |
|
| Yes | ID of the finding to flag (e.g. |
|
| Yes | Title of the finding as shown in the report. |
|
| No | Explanation of why this is a false positive. |
Example
flag_finding({
auditId: "abc-123-def-456",
findingId: "finding-5",
findingTitle: "Named arguments used in internal function call",
reason: "These are positional args — the scanner is misidentifying the call signature"
})
// Returns: { flagged: true, reviewTicket: "FP-2891" }Usage flows
Audit a single plugin and get fix prompts
audit_plugin({ slug: "my-plugin" })
→ get_report({ auditId: "..." }) // poll until status === "completed"
→ get_findings({ auditId: "...", severity: "CRITICAL" })
→ get_fix_prompt({ auditId: "..." })Audit all plugins in a local directory
audit_plugins_bulk({ directory: "/Users/me/plugins" })
// streams per-plugin results as they complete
// prints final summary table with risk breakdownCheck a plugin before installing
check_plugin({ slug: "advanced-custom-fields" })
// returns grade, risk level, and findings count without consuming an audit creditFlag a false positive after reviewing findings
get_findings({ auditId: "...", severity: "HIGH" })
→ flag_finding({
auditId: "...",
findingId: "finding-12",
findingTitle: "Unescaped output in template",
reason: "Output is escaped upstream via wp_kses before reaching this call"
})Environment variables
Variable | Default | Description |
| — | Required. Your WP HealthKit API key. |
|
| Override to point at a self-hosted or staging instance. |
License
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityDmaintenanceAn AI-powered security audit tool that analyzes codebases for vulnerabilities using real-time MITRE CWE data and npm audit. It enables users to perform comprehensive scans for authentication issues, exposed secrets, and dependency risks with structured remediation steps.26MIT
- AlicenseAqualityDmaintenanceAn AI-powered security audit tool that analyzes codebases for vulnerabilities using real-time data from MITRE CWE and npm audit. It enables deep analysis of authentication, API security, and dependencies to provide structured findings and remediation steps.261MIT
- AlicenseAqualityBmaintenanceSecurity co-pilot for AI agents. Scans for vulnerabilities like prompt injection, infinite loops, and token bombing in AI Agents, audits MCP servers, verifies AGENTS.md governance, and generates EU AI Act compliance reports.10433Apache 2.0
- AlicenseAqualityDmaintenanceDependency security & health auditing for AI agents with no account or API key required.22MIT
Related MCP Connectors
Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Compliance & security scan for your app: secrets, exposed files, headers, privacy, AI-disclosure.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/BuiltByGo/wphealthkit-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server