MCP WordPress Server
[](https://mcptoplist.com/server/glama%2Fdocdyhr%2Fmcp-wordpress)
<div align="right">
<a href="https://railway.com?referralCode=QhjuBc">
<img width="160" src="https://raw.githubusercontent.com/docdyhr/.github/main/assets/railway-corner-v2@2x.png" alt="Deploy on Railway โ $20 free credits">
</a>
</div>
# ๐ MCP WordPress Server
<div align="center">
<img src="images/wordpress-mcp-logo.png" width="50%" alt="WordPress MCP Logo">
**The Most Comprehensive WordPress MCP Server**
Manage WordPress sites with natural language through AI tools like Claude Desktop
[Quick Start](#-quick-start) โข [Why This MCP Server?](#-why-this-mcp-server)
[Installation Options](#-installation-options) โข [Documentation](#-documentation) โข [Examples](#-examples)
[](https://github.com/docdyhr/mcp-wordpress/actions/workflows/main-ci.yml)
[](https://github.com/docdyhr/mcp-wordpress/stargazers)
[](https://www.npmjs.com/package/mcp-wordpress)
[](https://www.npmjs.com/package/mcp-wordpress)
[](https://www.npmjs.com/package/mcp-wordpress)
[](https://hub.docker.com/r/docdyhr/mcp-wordpress)
[](https://codecov.io/gh/docdyhr/mcp-wordpress)
[](https://github.com/docdyhr/mcp-wordpress)
[](https://github.com/docdyhr/mcp-wordpress/actions/workflows/codeql-analysis.yml)
[](https://hub.docker.com/r/docdyhr/mcp-wordpress)
[](https://github.com/docdyhr/mcp-wordpress/blob/main/LICENSE)
<!-- Badges updated: 2025-12-23 -->
### ๐ **v3.3.21** - CI-Tested on Node 20/22/24
</div>
## ๐ฏ Why This MCP Server?
**Transform WordPress management** from complex admin panels to simple conversations:
```text
โ Before: Login โ Admin Panel โ Navigate โ Click โ Fill Forms โ Save
โ
After: "Create a new blog post about AI trends with SEO optimization"
```
**Key Advantages:**
- ๐ **Most Complete**: 71 tools vs 20-30 in alternatives
- โก **Fastest Setup**: 2-click Claude Desktop installation via DXT
- ๐ **CI-Tested**: 2750+ tests across Node 20/22/24, CodeQL + Trivy security scanning
- ๐ฏ **TypeScript Native**: 100% type safety, best-in-class developer experience
- ๐ **Multi-Site**: Manage up to 50 WordPress sites from one place
## ๐ Quick Start
Get up and running in **under 5 minutes**:
### Prerequisites
- **WordPress**: Version 5.6+ with REST API enabled
- **Claude Desktop**: Latest version installed
- **Application Password**: Generated from WordPress admin panel
### 3-Step Setup
**1๏ธโฃ Generate WordPress Application Password**
```text
WordPress Admin โ Users โ Profile โ Application Passwords โ Add New
```
**2๏ธโฃ Install MCP Server (Choose One)**
**Option A: DXT Extension (Easiest)**
```bash
# Download and install in Claude Desktop
curl -L https://github.com/docdyhr/mcp-wordpress/releases/latest/download/mcp-wordpress.dxt -o mcp-wordpress.dxt
# Then: Claude Desktop โ Extensions โ Install โ Select DXT file
```
**Option B: NPM Global Install**
```bash
npm install -g mcp-wordpress
```
**3๏ธโฃ Test Your Connection**
```text
In Claude: "Test my WordPress connection"
Response: "โ
Authentication successful! Connected to: Your Site Name"
```
๐บ **[Watch 2-minute Setup Video](https://github.com/docdyhr/mcp-wordpress/wiki/setup-video)** | ๐
**[Detailed Setup Guide](docs/INSTALLATION.md)**
## โก Installation Options
### ๐ Recommended: Claude Desktop Extension (DXT)
**Easiest installation - just 2 clicks!**
1. **Download**:
[`mcp-wordpress.dxt`](https://github.com/docdyhr/mcp-wordpress/releases/latest/download/mcp-wordpress.dxt) (3.4MB)
2. **Install**: Claude Desktop โ Extensions โ Install โ Select DXT file
3. **Configure**: Enter your WordPress site URL and credentials
โ
**Zero command line required** โ
**Easy updates** โ
**Built-in security**
**[๐ Complete DXT Setup Guide โ](docs/integrations/claude-desktop.md)**
### ๐ Alternative: NPX (Power Users)
```bash
# Run directly - always latest version
npx -y mcp-wordpress
# Interactive setup wizard
npm run setup
```
### ๐ง Other Options
- ๐ป **[NPM Setup](docs/user-guides/NPM_SETUP.md)** - Local development
- ๐ณ **[Docker Setup](docs/user-guides/DOCKER_SETUP.md)** - Production deployment
- ๐ง **[Manual Build](docs/developer/BUILD_SYSTEM.md)** - Custom builds
## ๐ Configuration
**Single Site (.env)**
```bash
WORDPRESS_SITE_URL=https://myblog.com
WORDPRESS_USERNAME=admin
WORDPRESS_APP_PASSWORD=xxxx xxxx xxxx xxxx xxxx xxxx
```
**Claude Desktop Config**
```json
{
"mcpServers": {
"mcp-wordpress": {
"command": "npx",
"args": ["-y", "mcp-wordpress"],
"env": {
"WORDPRESS_SITE_URL": "https://myblog.com",
"WORDPRESS_USERNAME": "admin",
"WORDPRESS_APP_PASSWORD": "xxxx xxxx xxxx xxxx xxxx xxxx"
}
}
}
}
```
๐ **[Complete Configuration Guide](docs/CONFIGURATION.md)** โ multi-site, JWT, Docker, production environments
## ๐ Authentication
WordPress Application Passwords are recommended:
1. **WordPress Admin** โ **Users** โ **Profile** โ **Application Passwords** โ **Add New**
2. Copy the generated password into your config
Alternative methods: JWT, Basic Auth, API Key โ see
**[Authentication Configuration](docs/CONFIGURATION.md#authentication-configuration)**
## ๐ What Makes This Special
| Feature | This Server | Competition |
| -------------------------- | ---------------------------------- | --------------- |
| **Tools Available** | 71 tools | 20-30 tools |
| **Claude Desktop DXT** | โ
2-click install | โ Manual setup |
| **Multi-Site Support** | โ
Up to 50 sites | โ Single site |
| **TypeScript** | โ
100% TypeScript, strict mode | โ ๏ธ Partial/None |
| **Performance Monitoring** | โ
Real-time analytics | โ Basic only |
| **Test Coverage** | โ
2750+ tests, ~76% line coverage | โ ๏ธ Limited |
| **Security Scanning** | โ
CodeQL + Trivy in CI | โ ๏ธ Unknown |
## ๐ Available Tools (71 Tools)
### Content Management
- **๐ Posts** (6 tools) - Create, edit, delete, list posts and revisions
- **๐ Pages** (6 tools) - Manage static pages and revisions
- **๐ผ๏ธ Media** (5 tools) - Upload, manage media library and files
- **๐ SEO** (11 tools) - Content analysis, metadata, schema markup, SERP tracking, keyword research
### User & Community
- **๐ฅ Users** (6 tools) - User management and profiles
- **๐ฌ Comments** (7 tools) - Comment moderation and management
- **๐ท๏ธ Taxonomies** (10 tools) - Categories and tags management
### Site Management
- **โ๏ธ Site Settings** (6 tools) - Site configuration and statistics
- **๐ Authentication** (3 tools) - Auth testing and management
- **โก Cache Management** (4 tools) - Performance caching control
- **๐ Performance Monitoring** (6 tools) - Real-time metrics and optimization
- **๐ ๏ธ System** (1 tool) - Version checking
๐ **[Complete Tool Documentation](docs/api/README.md)** | **[Live API Reference](docs/developer/API_REFERENCE.md)**
## ๐ค Examples
```text
๐ฌ "Create a new blog post about AI trends with SEO optimization"
๐ฌ "Check my WordPress site performance and provide optimization recommendations"
๐ฌ "Find all draft posts older than 30 days and provide a summary"
๐ฌ "Batch update all client sites with the new privacy policy footer"
๐ฌ "List all posts from my client-blog site"
```
๐ **[More Examples](docs/examples/)** | **[Real-World Workflows](docs/examples/use-case-workflows.md)**
## ๐งช Testing & Security
```bash
npm test # Full test suite (2750/2750 passing, 94 files)
npm run test:security # Security tests (371/371 passing)
npm run health # System health check
```
๐ **[Security Documentation](docs/SECURITY.md)** โ OWASP coverage, penetration testing, compliance
## ๐ ๏ธ Troubleshooting
```bash
npm run health # System check
DEBUG=true npm run dev # Debug logging
npm run fix:rest-auth # Fix WordPress 401 errors
```
| Error | Solution |
| -------------------- | ---------------------------------- |
| `401 Unauthorized` | Regenerate application password |
| `403 Forbidden` | Check user role (Editor+ required) |
| `404 Not Found` | Verify `WORDPRESS_SITE_URL` |
| `Connection Timeout` | Check WordPress REST API access |
๐ **[Full Troubleshooting Guide](docs/TROUBLESHOOTING.md)**
## ๐ Documentation
### Getting Started
- **[Quick Start Guide](#-quick-start)** - Get running in 5 minutes
- **[Installation Guide](docs/INSTALLATION.md)** - Detailed setup instructions
- **[Configuration Guide](docs/CONFIGURATION.md)** - All configuration options
- **[Authentication Setup](docs/SECURITY.md#authentication)** - WordPress auth methods
### User Guides
- **[Basic Usage](docs/examples/single-site-setup.md)** - Common tasks and workflows
- **[Advanced Workflows](docs/examples/use-case-workflows.md)** - Complex automation
- **[Multi-Site Management](docs/examples/multi-site-setup.md)** - Managing multiple sites
- **[Troubleshooting](docs/TROUBLESHOOTING.md)** - Common issues and solutions
### Integration Guides
- **[Claude Desktop](docs/integrations/claude-desktop.md)** - Complete Claude integration
- **[VS Code](docs/integrations/vs-code.md)** - VS Code extension setup
- **[Cline](docs/integrations/cline.md)** - Cline AI assistant integration
- **[Developer Guide](docs/developer/README.md)** - Build your own MCP client
### Developer Documentation
- **[API Reference](docs/developer/API_REFERENCE.md)** - Complete tool documentation
- **[Architecture](docs/ARCHITECTURE.md)** - System design and decisions
- **[Contributing](CONTRIBUTING.md)** - Development guidelines
- **[Build System](docs/developer/BUILD_SYSTEM.md)** - Build and release
### Deployment & Operations
- **[Docker Deployment](docs/DOCKER.md)** - Container deployment
- **[Publishing Troubleshooting](docs/PUBLISHING-TROUBLESHOOTING.md)** - Fix publishing issues
- **[Security Best Practices](docs/SECURITY.md)** - Production security
- **[Caching](docs/CACHING.md)** - Performance and caching guide
## ๐ง Requirements
- **WordPress 5.0+** with REST API enabled
- **HTTPS recommended** for production
- **Application Passwords enabled** (WordPress 5.6+)
| Role | Access |
| ----------------- | ----------------------------- |
| **Administrator** | Full access to all functions |
| **Editor** | Posts, pages, comments, media |
| **Author** | Own posts and media |
| **Contributor** | Own posts (drafts only) |
| **Subscriber** | Read only |
## ๐ Next Steps
**Ready to transform your WordPress management?**
1. **๐
[Download DXT Extension](https://github.com/docdyhr/mcp-wordpress/releases/latest/download/mcp-wordpress.dxt)** -
Easiest setup (2 minutes)
2. **โก [Try NPX Method](docs/user-guides/NPX_SETUP.md)** - Power user setup (5 minutes)
3. **๐ [Explore All Tools](docs/api/README.md)** - See what's possible
4. **๐ฌ [Join Discussions](https://github.com/docdyhr/mcp-wordpress/discussions)** - Get help and share ideas
---
## ๐ Similar Projects
- **[Automattic WordPress MCP](https://github.com/Automattic/wordpress-mcp)** - Official WordPress MCP server by
Automattic
---
## ๐ Changelog
### v3.3.21 (July 2026)
- **๐ Security Hardening** - SSRF denylist, HTTPS enforcement, logger redaction, dependency floor updates
- **๐ณ Docker Release Reliability** - Bounded publish-job timeouts and corrected retry-on-hang logic
- **๐ DOX Documentation** - Hierarchical AGENTS.md contract tree for per-directory work guidance
See [CHANGELOG.md](./CHANGELOG.md) for the complete, release-by-release history.
### v3.3.14 (June 2026)
- **๐ Security Updates** - Patch moderate Hono vulnerabilities, update allowlisted npm-bundled advisories
- **๐งช CI** - Smoke-test improvements and Node 24 validation
### v3.x Series (2025โ2026)
- **๐๏ธ Modular Architecture** - Domain-specific operation modules and composition pattern
- **๐ Fault Tolerance** - Circuit breaker pattern with automatic recovery
- **๐ 2200+ Tests** - Comprehensive test suite across security, cache, server, client, config, utils, tools, and
performance
- **โก Caching Layer** - `CachedWordPressClient` with configurable TTL; 50โ70% faster repeat requests
- **๐ Multi-Site** - Up to 50 WordPress sites from one configuration file
- **๐ 4 Auth Methods** - App Passwords (recommended), JWT, Basic, API Key
- **๐ณ Docker & DXT** - One-click Claude Desktop extension and Docker Hub image
For the full history see [CHANGELOG.md](CHANGELOG.md).
---
## ๐ Acknowledgments
Special thanks to **[Stephan Ferraro](https://github.com/ferraro)** for the upstream project that inspired this
implementation.
---
<div align="center">
**โญ Found this helpful? [Give us a star on GitHub!](https://github.com/docdyhr/mcp-wordpress) โญ**
</div>
TDQS
Scored across 27 tools
Most tools clearly target distinct resources such as comments, media, posts, categories, users, and settings. However, there is notable overlap among SEO tools: wp_seo_site_audit, wp_seo_analyze_content, wp_seo_get_live_data, and wp_seo_test_integration have fuzzy boundaries that could cause misselection.
The naming pattern is generally consistent with wp_ + verb + noun, e.g., wp_get_media, wp_delete_post, wp_create_user. SEO tools follow a readable wp_seo_ prefix pattern, though a few like wp_seo_site_audit use a noun phrase rather than a clear verb_action form.
At 27 tools, the server is above the comfortable range and feels bloated. Roughly a third of the tools are SEO-specific while core WordPress content operations are sparse, making the count high without corresponding breadth of fundamental functionality.
The core WordPress lifecycle has significant gaps: there is no post creation or editing, no media deletion/update, no user listing/updating, no comment moderation, and category support is limited to get/update. The SEO toolset is broad but does not compensate for these missing fundamental operations.