cd /news/ai-agents/wsp-mcp-free-mcp-plugin-for-wordpres… · home › topics › ai-agents › article
[ARTICLE · art-145908] src=github.com ↗ pub= topic=ai-agents verified=true sentiment=↑ positive

WSP MCP – Free MCP Plugin for WordPress

WebSensePro released WSP MCP, a free WordPress plugin that connects Claude, ChatGPT, Cursor and other MCP clients to a WordPress site through the Model Context Protocol, exposing 190+ tools with no paid tier. The plugin requires WordPress 6.9+ and PHP 7.4+, ships every tool off by default with per-tool switches and a built-in audit log, and removed the legacy MCP-Adapter/Abilities-API path and MCP > Config Files page in v2.2, requiring users to recreate connections via the native endpoint on MCP > Connection.

read11 min views1 publishedOct 6, 2026
WSP MCP – Free MCP Plugin for WordPress
Image: Michielbdejong (auto-discovered)

Connect Claude, ChatGPT, Cursor & any AI agent to WordPress, and manage your site by chat.

By WebSensePro — Official Shopify Partner & WordPress Agency WSP MCP is a free MCP plugin for WordPress. Install it, connect your AI app, and just ask:

  • "Write a blog post about our summer sale and save it as a draft."
  • "Find every page missing a meta description and suggest one."
  • "Show me this week's WooCommerce orders and mark the shipped ones as completed."
  • "Add a Contact link to the main menu."

Why WSP MCP?

  • 💸 100% free — every feature and all 190+ tools, no paid version.
  • 🔌 Everything built in — no companion plugin, MCP Adapter, or account needed.
  • 🤖 Works with your AI app — Claude (web, desktop, mobile), ChatGPT, Cursor, Codex, Google Antigravity, OpenClaw, OpenCode, and any other MCP client.
  • 🛡️ Safe by default — every tool has its own on/off switch, anything that changes your site is off until you turn it on, and the AI can only do what its WordPress user is allowed to do.
  • 📋 See everything the AI did — a built-in Audit Log and usage dashboard, stored in your own database.

What is MCP? The Model Context Protocol is the standard way AI assistants connect to other apps. Once your site has an MCP plugin, any AI app that supports MCP can read and update your site — with your permission.

Prerequisites: WordPress 6.9+ (7.0.3 or 6.9.6+ recommended), PHP 7.4+ — that's it. Claude Desktop and OpenClaw use the mcp-remote bridge, which needs Node.js 18+; Cursor, Codex, Antigravity, and OpenCode connect natively.

  1. Install & activate this plugin
  2. Go to MCP > Settings in wp-admin and enable the abilities you need
  3. Go to MCP > Connection and pick your client:
  • Claude (claude.ai, Desktop, or mobile): enable the OAuth server on theClaude Connectors tab, then paste just the server URL intoCustomize > Connectors > Add custom connector and sign in with your WordPress account
  • Everything else (Cursor, Codex, Antigravity, OpenClaw, OpenCode): use the Configuration Generator, thenCopy orDownload the snippet — the endpoint URL and credentials are already filled in — and paste it into your client's config (Cursor also gets a one-clickConnect Cursor Automatically button)
  1. Reconnect / restart the client and start prompting your AI agent
  2. Review what your agent actually did under MCP > Audit Log , and check usage and response times underMCP > Analytics

Upgrading from before v2.0? The legacy MCP-Adapter / Abilities-API path and the MCP > Config Files page were removed in v2.2. Re-create your connection using the native endpoint on MCP > Connection.

ChatGPT: ChatGPT connects through the same OAuth sign-in as Claude Connectors — enable the OAuth server on MCP > Connection, then add your site's MCP URL as a connector in ChatGPT.

| Client | Guide |

|---|---|
| Claude (claude.ai / Desktop / mobile) | [Full tutorial](https://youtu.be/kD2FSvL7EE0) | 
| OpenClaw | [Video](https://youtu.be/GLyLzxVOxm4) | 
| Google Antigravity | [Video](https://youtu.be/2gRIRcqqOpo) | 
| Codex | [Video](https://youtu.be/hxhjs3IUYQE) | 
| All tutorials & abilities directory | [wspmcp.com](https://wspmcp.com/) | 
  • 🗂️ Custom Post Types tool group — five new tools: list your public custom post types, then list, create, update, and trash their items. Each item is checked against the post type's own permissions (a Contributor can't edit others' items or publish; an Author can't touch types like products that need extra rights).Off by default. Contributed by@dulaj44 in#43 .

  • 👋 About Us page under MCP, plusSettings | Connection | About Us links on the Plugins screen.

  • ✏️ Plain-language name, description and readme — "WSP MCP - Free MCP Plugin for WordPress: Connect Claude, ChatGPT & AI Agents".

  • Minor updates.

  • 👥 Create / Update Users — add new users (password auto-generated if you don't supply one, role defaults tosubscriber ) and edit email, display name, role, or password. Requirecreate_users /edit_users ;off by default .

  • ⚙️ Update Site Info & Permalinks — change the site title, tagline, and admin email, and set the permalink structure (e.g./%postname%/ ). Requiremanage_options ;off by default .

  • 🔌 Activate / Deactivate Plugins — toggle any installed plugin by its file path (e.g.akismet/akismet.php ). This plugin refuses to deactivate itself so the MCP connection can't cut itself off. Requireactivate_plugins ;off by default .

  • 🎨 Themes tool group — list installed themes and switch the active theme. Requireswitch_themes ;off by default .

Contributed by @dulaj44 in #42.

  • 🧭 Navigation Menus tool group — nine new tools to list menus and their items, create and delete menus, add / update / remove menu items (custom links, posts, pages, categories), list your theme's menu locations, and assign or unassign a menu to a location. Requireedit_theme_options ;off by default . Contributed by@dulaj44 in#41 .
  • 📄 Read Post tool — fetch a single post by ID inany status (draft, pending, private, trash) with its full content, so an agent can review a draft before updating it. Enforces per-post read permission;off by default . Closes#38 .
  • 🐛 Audit Log accuracy — permission-denied results from the new Read Post tool are now logged as denied, not success.
  • 🐛 Add Menu Item validation — anobject_id whose post type doesn't match the requestedtype is now rejected instead of silently stored.

Recent releases: v2.9.0 — Navigation Menus tool group + Read Post tool · v2.8.0 — one-click Claude Connector sign-in (OAuth 2.1) + Analytics dashboard · v2.7.1 — object-level authorization on write tools (Patchstack) · v2.7.0 — Audit Log · v2.6.x — WPForms, Contact Form 7, Gravity Forms, UAE, Elementor design tools.

📋 Full history: see CHANGELOG.md.

  • Off by default — every write ability is disabled until an administrator enables it inMCP > Settings .
  • Per-tool capability checks — each tool declares the WordPress capability it requires (edit_posts ,manage_options ,manage_woocommerce , …) and runs as the connected WordPress user, so an agent can only do what that account can do.
  • Per-object guards — tools that take a post/page/media ID additionally enforce ownership (edit_post /delete_post /read_post ) and post type, matching WordPress core's own REST checks.
  • Three auth methods — OAuth 2.1 (one-click Claude Connector, off by default), WordPress Application Passwords, or a plugin-generated API key.
  • Audit Log — everytools/call is stored inwp_wsp_mcp_audit_log with user, IP, outcome (success / denied / error), and duration. Nothing leaves your server. Auto-pruned after 90 days.
Ability Access
Read / Get / Create / Update / Delete Posts read / write
Read / Create / Update / Delete Pages read / write
Read Categories & Tags / Create read / write
Read / Approve / Delete Comments read / write
List / Get / Count Media read
Update / Delete / Upload Media (from URL or base64) write
Read Users read
Create / Update Users write
Search Content read
Read Site Info & Active Plugins read
Update Site Info (title, tagline, admin email) / Permalink Structure write
Activate / Deactivate Plugins write
Read Themes read
Switch Theme write
Read Menus / Menu Items / Menu Locations read
Create / Delete Menu, Add / Update / Delete Menu Item, Assign Location write
Ability Access
Read Post Types / Read Items read
Create / Update / Trash Item write

5 tools, off by default. Each item is checked against its post type's own permissions, so the AI can't edit other people's items or publish unless its user could do that in wp-admin.

Ability Access
Get Yoast SEO Meta (title, meta description, focus keyphrase) read
Update Yoast SEO Meta write
Ability Access
Get Rank Math SEO Meta (title, description, focus keyword, score) read
Update Rank Math SEO Meta write
Ability Access
List Elementor Pages / Templates read
Get Page Structure / Element Settings / Find Element read
Update Element, Add Widget, Add Container / Section, Remove Element write
Duplicate / Move Element, Copy Element Styles write
Get / Update Active Kit (global colors, fonts, layout) read / write
Get / Update Page Settings read / write
Get Widget Schema / Breakpoints read
Convert CSS to Elementor Settings write
Regenerate CSS write

20 tools. update-active-kit and regenerate-css require manage_options; the rest require edit_posts. All writes run through wsp_elementor_sanitize_settings().

Ability Access
List UAE Widgets / Check Widget Usage read
Activate / Deactivate / Bulk Toggle Widgets write
List / Get Header, Footer & Blocks Templates read
Create / Duplicate / Update / Trash / Restore Template write
Add Section / Add Column / Move Element / Build Layout from JSON write
Get UAE Settings / Theme Info / Extensions / Design Tokens read
Update UAE Settings / Design Tokens write

45 tools, off by default. Writes require edit_posts, publish_posts, or manage_options.

Ability Access
List / Get Products read
Create Product / Create Variation / Update Product write
List Orders / Update Order Status read / write
Refund Order (requires manage_woocommerce) write
Create / List Coupons (requires manage_woocommerce) write / read
Create Order Note write
List Customers (requires manage_woocommerce) read
Sales Report / Low-Stock Alerts read
Moderate Product Reviews write
Ability Access
List / Get Field Groups read
Create / Update / Delete / Import Field Group write
List / Get Fields read
Create / Update / Delete / Duplicate Field, Force Sync write
Get / Get-All / Get Field Object (values) read
Update Deep (dot-notation) / Bulk Update / Delete Value write
List Post Types / Taxonomies read
Create Custom Post Type / Taxonomy (ACF 6.1+) write
List / Create Options Page (create needs ACF Pro) read / write
Get / Update Option Value read / write

27 tools. Value reads/writes accept a post/page ID, user_<id>, term_<id>, or options and enforce per-object capabilities. Structural changes require manage_options.

Ability Access
List / Get Forms read
Create / Update / Delete Form, Update Form Settings write
List / Get Entries read
Update / Delete Entry write
Get / Create / Update / Delete Notifications read / write
Get / Create / Update / Delete Confirmations read / write

18 tools. List Forms and Get Form are ON by default. Uses Gravity Forms' own capabilities.

Ability Access
List / Get Forms read
Create / Update / Delete Form write
List / Get Entries (requires Flamingo) read
Validate Form read
Get Integrations (modules, reCAPTCHA status) read
Moderate Entry (spam / unspam / trash / untrash) write

10 tools. List Forms and Get Form are ON by default. Uses CF7's own capabilities; get-integrations requires manage_options.

Ability Access
List / Get Forms, Describe Schema, Get Form Stats read
Create Form, Update Form Settings, Add / Update Field, Delete Form write
List / Get / Delete Entries (WPForms Pro) read / write

12 tools. List Forms, Get Form, Describe Schema, and Get Form Stats are ON by default. Uses WPForms' own capabilities.

Built by WebSensePro — an AI-powered digital media agency delivering web development, WordPress, Shopify, SEO and AI automation for growing businesses, with offices in Denver, CO, Queens Village, NY and Karachi, Pakistan.

1,200+ projects delivered · 850+ websites launched · 500+ clients worldwide · 120+ AI automations deployed · 10+ years in digital services

- 🏆 [Official Shopify Partner](https://www.shopify.com/partners/directory/partner/websensepro1)
- 🎥 [140K+ YouTube Subscribers](https://m.youtube.com/websensepro)
- 🤖 [Official n8n Creator](https://n8n.io/creators/websensepro/)
- 📧 [info@websensepro.com](mailto:info@websensepro.com)
── more in #ai-agents 4 stories · sorted by recency
── more on @websensepro 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/wsp-mcp-free-mcp-plu…] indexed:0 read:11min 2026-10-06 · —