WSP MCP โ€“ Free MCP Plugin for WordPress WebSensePro released WSP MCP, a free WordPress plugin that connects Claude, ChatGPT, Cursor and other MCP clients to a WordPress site through the Model Context Protocol, exposing 190+ tools with no paid tier. The plugin requires WordPress 6.9+ and PHP 7.4+, ships every tool off by default with per-tool switches and a built-in audit log, and removed the legacy MCP-Adapter/Abilities-API path and MCP > Config Files page in v2.2, requiring users to recreate connections via the native endpoint on MCP > Connection. Connect Claude, ChatGPT, Cursor & any AI agent to WordPress, and manage your site by chat. By WebSensePro https://websensepro.com โ€” Official Shopify Partner & WordPress Agency WSP MCP is a free MCP plugin for WordPress . Install it, connect your AI app, and just ask: - "Write a blog post about our summer sale and save it as a draft." - "Find every page missing a meta description and suggest one." - "Show me this week's WooCommerce orders and mark the shipped ones as completed." - "Add a Contact link to the main menu." Why WSP MCP? - ๐Ÿ’ธ 100% free โ€” every feature and all 190+ tools, no paid version. - ๐Ÿ”Œ Everything built in โ€” no companion plugin, MCP Adapter, or account needed. - ๐Ÿค– Works with your AI app โ€” Claude web, desktop, mobile , ChatGPT, Cursor, Codex, Google Antigravity, OpenClaw, OpenCode, and any other MCP client. - ๐Ÿ›ก๏ธ Safe by default โ€” every tool has its own on/off switch, anything that changes your site is off until you turn it on, and the AI can only do what its WordPress user is allowed to do. - ๐Ÿ“‹ See everything the AI did โ€” a built-in Audit Log and usage dashboard, stored in your own database. What is MCP? The Model Context Protocol is the standard way AI assistants connect to other apps. Once your site has an MCP plugin, any AI app that supports MCP can read and update your site โ€” with your permission. Prerequisites: WordPress 6.9+ 7.0.3 or 6.9.6+ recommended , PHP 7.4+ โ€” that's it. Claude Desktop and OpenClaw use the mcp-remote bridge, which needs Node.js 18+; Cursor, Codex, Antigravity, and OpenCode connect natively. 1. Install & activate this plugin 2. Go to MCP Settings in wp-admin and enable the abilities you need 3. Go to MCP Connection and pick your client: - Claude claude.ai, Desktop, or mobile : enable the OAuth server on the Claude Connectors tab, then paste just the server URL into Customize Connectors Add custom connector and sign in with your WordPress account - Everything else Cursor, Codex, Antigravity, OpenClaw, OpenCode : use the Configuration Generator, then Copy or Download the snippet โ€” the endpoint URL and credentials are already filled in โ€” and paste it into your client's config Cursor also gets a one-click Connect Cursor Automatically button 4. Reconnect / restart the client and start prompting your AI agent 5. Review what your agent actually did under MCP Audit Log , and check usage and response times under MCP Analytics Upgrading from before v2.0? The legacy MCP-Adapter / Abilities-API path and the MCP Config Files page were removed in v2.2. Re-create your connection using the native endpoint on MCP Connection . ChatGPT: ChatGPT connects through the same OAuth sign-in as Claude Connectors โ€” enable the OAuth server on MCP Connection , then add your site's MCP URL as a connector in ChatGPT. | Client | Guide | |---|---| | Claude claude.ai / Desktop / mobile | Full tutorial https://youtu.be/kD2FSvL7EE0 | | OpenClaw | Video https://youtu.be/GLyLzxVOxm4 | | Google Antigravity | Video https://youtu.be/2gRIRcqqOpo | | Codex | Video https://youtu.be/hxhjs3IUYQE | | All tutorials & abilities directory | wspmcp.com https://wspmcp.com/ | - ๐Ÿ—‚๏ธ Custom Post Types tool group โ€” five new tools: list your public custom post types, then list, create, update, and trash their items. Each item is checked against the post type's own permissions a Contributor can't edit others' items or publish; an Author can't touch types like products that need extra rights . Off by default. Contributed by @dulaj44 https://github.com/dulaj44 in 43 https://github.com/bilalnaseer/wsp-wordpress-mcp/pull/43 . - ๐Ÿ‘‹ About Us page under MCP, plus Settings | Connection | About Us links on the Plugins screen. - โœ๏ธ Plain-language name, description and readme โ€” "WSP MCP - Free MCP Plugin for WordPress: Connect Claude, ChatGPT & AI Agents". - Minor updates. - ๐Ÿ‘ฅ Create / Update Users โ€” add new users password auto-generated if you don't supply one, role defaults to subscriber and edit email, display name, role, or password. Require create users / edit users ; off by default . - โš™๏ธ Update Site Info & Permalinks โ€” change the site title, tagline, and admin email, and set the permalink structure e.g. /%postname%/ . Require manage options ; off by default . - ๐Ÿ”Œ Activate / Deactivate Plugins โ€” toggle any installed plugin by its file path e.g. akismet/akismet.php . This plugin refuses to deactivate itself so the MCP connection can't cut itself off. Require activate plugins ; off by default . - ๐ŸŽจ Themes tool group โ€” list installed themes and switch the active theme. Require switch themes ; off by default . Contributed by @dulaj44 https://github.com/dulaj44 in 42 https://github.com/bilalnaseer/wsp-wordpress-mcp/pull/42 . - ๐Ÿงญ Navigation Menus tool group โ€” nine new tools to list menus and their items, create and delete menus, add / update / remove menu items custom links, posts, pages, categories , list your theme's menu locations, and assign or unassign a menu to a location. Require edit theme options ; off by default . Contributed by @dulaj44 https://github.com/dulaj44 in 41 https://github.com/bilalnaseer/wsp-wordpress-mcp/pull/41 . - ๐Ÿ“„ Read Post tool โ€” fetch a single post by ID in any status draft, pending, private, trash with its full content, so an agent can review a draft before updating it. Enforces per-post read permission; off by default . Closes 38 https://github.com/bilalnaseer/wsp-wordpress-mcp/issues/38 . - ๐Ÿ› Audit Log accuracy โ€” permission-denied results from the new Read Post tool are now logged as denied, not success. - ๐Ÿ› Add Menu Item validation โ€” an object id whose post type doesn't match the requested type is now rejected instead of silently stored. Recent releases: v2.9.0 โ€” Navigation Menus tool group + Read Post tool ยท v2.8.0 โ€” one-click Claude Connector sign-in OAuth 2.1 + Analytics dashboard ยท v2.7.1 โ€” object-level authorization on write tools Patchstack ยท v2.7.0 โ€” Audit Log ยท v2.6.x โ€” WPForms, Contact Form 7, Gravity Forms, UAE, Elementor design tools. ๐Ÿ“‹ Full history: see CHANGELOG.md https://github.com/bilalnaseer/wsp-wordpress-mcp/blob/main/CHANGELOG.md . - Off by default โ€” every write ability is disabled until an administrator enables it in MCP Settings . - Per-tool capability checks โ€” each tool declares the WordPress capability it requires edit posts , manage options , manage woocommerce , โ€ฆ and runs as the connected WordPress user, so an agent can only do what that account can do. - Per-object guards โ€” tools that take a post/page/media ID additionally enforce ownership edit post / delete post / read post and post type, matching WordPress core's own REST checks. - Three auth methods โ€” OAuth 2.1 one-click Claude Connector, off by default , WordPress Application Passwords, or a plugin-generated API key. - Audit Log โ€” every tools/call is stored in wp wsp mcp audit log with user, IP, outcome success / denied / error , and duration. Nothing leaves your server. Auto-pruned after 90 days. | Ability | Access | |---|---| | Read / Get / Create / Update / Delete Posts | read / write | | Read / Create / Update / Delete Pages | read / write | | Read Categories & Tags / Create | read / write | | Read / Approve / Delete Comments | read / write | | List / Get / Count Media | read | | Update / Delete / Upload Media from URL or base64 | write | | Read Users | read | | Create / Update Users | write | | Search Content | read | | Read Site Info & Active Plugins | read | | Update Site Info title, tagline, admin email / Permalink Structure | write | | Activate / Deactivate Plugins | write | | Read Themes | read | | Switch Theme | write | | Read Menus / Menu Items / Menu Locations | read | | Create / Delete Menu, Add / Update / Delete Menu Item, Assign Location | write | | Ability | Access | |---|---| | Read Post Types / Read Items | read | | Create / Update / Trash Item | write | 5 tools, off by default. Each item is checked against its post type's own permissions, so the AI can't edit other people's items or publish unless its user could do that in wp-admin. | Ability | Access | |---|---| | Get Yoast SEO Meta title, meta description, focus keyphrase | read | | Update Yoast SEO Meta | write | | Ability | Access | |---|---| | Get Rank Math SEO Meta title, description, focus keyword, score | read | | Update Rank Math SEO Meta | write | | Ability | Access | |---|---| | List Elementor Pages / Templates | read | | Get Page Structure / Element Settings / Find Element | read | | Update Element, Add Widget, Add Container / Section, Remove Element | write | | Duplicate / Move Element, Copy Element Styles | write | | Get / Update Active Kit global colors, fonts, layout | read / write | | Get / Update Page Settings | read / write | | Get Widget Schema / Breakpoints | read | | Convert CSS to Elementor Settings | write | | Regenerate CSS | write | 20 tools. update-active-kit and regenerate-css require manage options ; the rest require edit posts . All writes run through wsp elementor sanitize settings . | Ability | Access | |---|---| | List UAE Widgets / Check Widget Usage | read | | Activate / Deactivate / Bulk Toggle Widgets | write | | List / Get Header, Footer & Blocks Templates | read | | Create / Duplicate / Update / Trash / Restore Template | write | | Add Section / Add Column / Move Element / Build Layout from JSON | write | | Get UAE Settings / Theme Info / Extensions / Design Tokens | read | | Update UAE Settings / Design Tokens | write | 45 tools, off by default. Writes require edit posts , publish posts , or manage options . | Ability | Access | |---|---| | List / Get Products | read | | Create Product / Create Variation / Update Product | write | | List Orders / Update Order Status | read / write | | Refund Order requires manage woocommerce | write | | Create / List Coupons requires manage woocommerce | write / read | | Create Order Note | write | | List Customers requires manage woocommerce | read | | Sales Report / Low-Stock Alerts | read | | Moderate Product Reviews | write | | Ability | Access | |---|---| | List / Get Field Groups | read | | Create / Update / Delete / Import Field Group | write | | List / Get Fields | read | | Create / Update / Delete / Duplicate Field, Force Sync | write | | Get / Get-All / Get Field Object values | read | | Update Deep dot-notation / Bulk Update / Delete Value | write | | List Post Types / Taxonomies | read | | Create Custom Post Type / Taxonomy ACF 6.1+ | write | | List / Create Options Page create needs ACF Pro | read / write | | Get / Update Option Value | read / write | 27 tools. Value reads/writes accept a post/page ID, user