WordPress MCP Server & CLI

A free, open source WordPress MCP server and CLI that lets Claude Code, Codex, Cursor and other AI agents work on posts, pages, media, Elementor and Rank Math SEO.

Navid Moazzezby Navid Moazzez·Updated 30 set 2026·13 min read
~/wordpress-mcp-cli
$ claude
Claude Code v2.1.220
>
Rate this tool

This free WordPress MCP server and CLI gives your AI real access to your WordPress site. It works with posts, pages, custom post types, media, categories, Elementor layouts, Rank Math SEO and redirects, across several sites.

It's one install with 2 ways in. Claude, Codex, Cursor or any other MCP app calls its 42 tools for you, and the same tools work as a CLI that agents like Claude Code, Codex and OpenCode run, or that you type yourself.

Here's what the WordPress MCP server and CLI is, how to set it up in each app, and every tool it has.

What is the WordPress MCP server & CLI?

The WordPress MCP server & CLI is a free, open source program that lets AI agents work on your WordPress site for you, in 2 ways. The MCP server is what an AI app like Claude, Codex or Cursor connects to, through MCP (Model Context Protocol), the open standard AI apps use to call outside tools.

You ask in plain language. Your AI picks the right tool, and the server makes the call to your site's REST API.

The CLI is the same program as commands. wordpress-cli wp-list-posts runs the same code your AI runs when you ask what's on your blog, whether an agent like Claude Code runs it or you do.

What can you ask it?

Once it's set up, you ask the way you'd ask an assistant. These are real prompts it handles:

Try asking
Draft a post about the launch, file it under Marketing, and leave it as a draft.
Which posts are missing a meta description?
Find every page that mentions the old pricing and show me where.
Duplicate the services page so I can rewrite it without touching the live one.
Redirect the old blog URL to the new one, permanently.
Upload this image, set the alt text, and make it the featured image on post 412.

The second one shows why this is useful. WordPress hides the fields where Rank Math keeps its SEO settings and Elementor keeps a page's layout, and with the helper plugin your AI can read and write them.

How to install the WordPress MCP server

Pick your app in the box at the top of this page. Each one is a single command or a pasted block, and they all run through npx, so there's nothing to install first.

Before you start0/4

Pro tip: Give your AI its own WordPress user with the Editor role. Editor covers almost everything here, and you can revoke that user without touching your own login.

Set up your WordPress site

The server signs in with an application password. It isn't your login password: WordPress makes one per program, you can revoke each on its own, and it carries the role of its user.

Make an application password0/5

WordPress shows the password in groups with spaces. It works with or without them.

The role decides what your AI can do

RoleWhat your AI can do
AdministratorEverything, including site settings and permanent deletes
EditorEverything with content: publish, edit anyone's posts and upload media
AuthorIts own posts only

Add the helper plugin for the full set

30 of the 42 tools work with nothing installed. The other 12, for Elementor, Rank Math, redirects, hidden fields and bulk edits, need the small helper plugin from the repo.

Copy plugin/mcp-wordpress-helper.php into wp-content/mu-plugins/ on your site. Files there load on their own, so there's nothing to activate, and every route checks the same permissions WordPress itself would.

Check that it works

Run the doctor. It checks HTTPS, the password's shape, the sign-in, the user's role and the helper plugin, in that order, and stops at the first real problem.

npx -y @thenavidm/wordpress-mcp-cli doctor

"Application password is 12 characters" means you used a login password, since application passwords are 24. "Can publish posts: no" means the role is too low, so use an Editor or Administrator.

Use the WordPress CLI

The CLI is the same 42 tools as commands. AI agents that run commands, like Claude Code, Codex and OpenCode, use it on their own, and you can type the same commands in a terminal or a script.

Every tool name becomes a command with dashes, so wp_list_posts runs as wordpress-cli wp-list-posts.

npm install -g @thenavidm/wordpress-mcp-cli
wordpress-cli
wordpress-cli wp-list-posts
wordpress-cli wp-get-settings

The bare wordpress-cli lists every command, and wordpress-cli <command> --help shows what a command takes. Publishing, permanent deletes and bulk edits need --confirm, the terminal's version of the check your AI has to pass.

These flags work on every command:

FlagWhat it does
--jsonPrints JSON
--compactPrints the JSON on one line
--agentMachine mode: JSON, compact, no prompts and no color
--select a,b.cKeeps only those fields, and a dotted path goes deeper
--confirmLets a write that asks first go ahead

A script can branch on the exit code:

Exit codeWhat it means
0It worked
2The command was typed wrong, or a write needed --confirm
3It wasn't found
4WordPress rejected the credentials
5WordPress's API failed
7You hit a rate limit, so wait and try again
10Nothing is set up yet

MCP server or CLI: which one?

Both are the same program with the same 42 tools. The difference is when your AI pays for them, in the tokens it reads.

Every message, in an app that loads every tool
MCP server
23,300 tokens
CLI
Nothing
Every message, in Claude Code
MCP server
1,300 tokens
CLI
Nothing
When WordPress comes up
MCP server
Nothing more, or in Claude Code the tools it picks
CLI
4,000 tokens, once
20 messages with WordPress in 1, every tool loaded
MCP server
465,000 tokens
CLI
4,000 tokens
Works in Claude Desktop's chat
MCP server
Yes
CLI
No, there's no terminal there
Works in a script, a cron job or CI
MCP server
No
CLI
Yes

An app that loads every tool up front sends the full list with every message, whether you mention WordPress or not. Claude Code doesn't by default: its tool search sends only the tool names and the server's instructions, and loads a tool's full definition when your AI reaches for it.

The CLI costs nothing until WordPress comes up. Then your agent reads its skill file once and runs the commands it needs. With the skill added, Claude Code also lists its one-line description with every message, about 150 tokens.

When the whole conversation is about WordPress, the gap closes. Then the MCP server is the better experience, because you ask in plain language and your AI never has to look up a command.

Where the MCP server's tokens go

Part of the tool listShare
JSON Schema structure, like types, required lists and nesting42%
Argument descriptions38%
Tool descriptions20%

42% of it is MCP writing every tool out as JSON Schema, which any server with this many tools pays. The rest is the wording that lets your AI use each tool without guessing.

How to spend less

In Claude Code, leave tool search on, which it is unless you've set ENABLE_TOOL_SEARCH=false.

Turn the server off when you aren't editing the site. In Claude Code that's the /mcp panel, and every AI app has its own switch. WORDPRESS_READ_ONLY=1 cuts it to the 22 reading tools.

Or install the CLI and connect the server later, on the days it earns its place. Every tool stays in reach, and the standing cost drops to nothing.

Every number here was measured on September 27, 2026 in Claude Code 2.1.257 with Claude Opus 5. It's the same one-line prompt with and without the server connected, once with tool search off so every tool loads, and once with Claude Code's default. The skill was measured the same way, and other apps and models count tokens a little differently.

What to know about WordPress

Publishing is the only thing on a WordPress site you can't take back. Feeds, email plugins and social auto-posters pick up a published post within minutes, and setting it back to draft recalls nothing.

An Elementor page ignores its own post content, because the layout lives in a hidden field. Use wp_get_elementor and wp_update_elementor for those pages, or duplicate an existing one.

Posts take IDs, never names, so look up a category's ID before you file a post under it. Dates follow the site's time zone, not yours, and wp_get_settings shows which.

Every WordPress tool

All 42 tools, grouped the way the repo groups them. 22 only read, and 20 change something on your site.

Posts

wp_list_posts
What it does
List posts, filtered by status, search term, category, tag, author or date range.
Kind
Reads
wp_get_post
What it does
Fetch a single post by ID, in edit context so the raw unrendered content comes back rather than the filtered output.
Kind
Reads
wp_create_post
What it does
Create a post.
Kind
Can ask first
wp_update_post
What it does
Update any field on an existing post.
Kind
Can ask first
wp_delete_post
What it does
Move a post to the trash, where it stays until emptied and can be restored from wp-admin in one click.
Kind
Can ask first
wp_duplicate_post
What it does
Duplicate any post, page or custom post type item as a draft, copying every meta field with it, including Elementor layouts, ACF fields and SEO settings.
Kind
Writes

Pages

wp_list_pages
What it does
List pages, filtered by status, search term, parent or slug.
Kind
Reads
wp_create_page
What it does
Create a page.
Kind
Can ask first
wp_update_page
What it does
Update any field on an existing page.
Kind
Can ask first

Custom post types

wp_list_post_types
What it does
List every post type registered on the site, built in and custom, with the REST base each one answers on, whether it is hierarchical, and which taxonomies apply to it.
Kind
Reads
wp_list_custom
What it does
List items of any post type by its REST base: products, listings, lessons, projects, or whatever the site has registered.
Kind
Reads
wp_get_custom
What it does
Fetch a single item of any post type by REST base and ID, in edit context so the raw content comes back rather than the rendered output.
Kind
Reads
wp_create_custom
What it does
Create an item in any post type by REST base.
Kind
Can ask first
wp_update_custom
What it does
Update any field on an item of any post type.
Kind
Can ask first
wp_delete_custom
What it does
Move an item of any post type to the trash, which is reversible, or delete it permanently with force: true, which is not.
Kind
Can ask first

Media

wp_list_media
What it does
List items in the media library, filtered by search term, MIME type or the post they are attached to.
Kind
Reads
wp_get_media
What it does
Fetch a single attachment by ID, with its full URL, dimensions, alt text, caption and every generated size.
Kind
Reads
wp_upload_media
What it does
Download a file from a publicly reachable URL and add it to the media library, then set its title, alt text and caption.
Kind
Writes
wp_delete_media
What it does
Delete an attachment.
Kind
Can ask first

Categories and tags

wp_list_categories
What it does
List the site's categories with their IDs, slugs, parents and post counts.
Kind
Reads
wp_create_category
What it does
Create a category and return its ID, ready to pass to wp_create_post.
Kind
Writes
wp_list_tags
What it does
List the site's tags with their IDs, slugs and post counts.
Kind
Reads
wp_create_tag
What it does
Create a tag and return its ID, ready to pass to wp_create_post.
Kind
Writes
wp_list_taxonomies
What it does
List every taxonomy registered on the site, built in and custom, with the REST base each one answers on and the post types it applies to.
Kind
Reads
wp_list_taxonomy_terms
What it does
List the terms in any taxonomy, custom or built in, by its REST base.
Kind
Reads

Rank Math SEO and redirects

wp_get_rankmath
What it does
Read every Rank Math field set on a post or page: SEO title, meta description, focus keywords, robots directives, canonical URL, the Open Graph and Twitter overrides, schema type, pillar-content flag, primary category and breadcrumb title, along with the stored SEO score.
Kind
Reads
wp_update_rankmath
What it does
Update Rank Math fields on a post or page.
Kind
Writes
wp_list_redirects
What it does
List the site's redirects with their IDs, sources, destinations and HTTP status codes.
Kind
Reads
wp_create_redirect
What it does
Create a redirect from one path to another.
Kind
Writes
wp_delete_redirect
What it does
Delete a redirect by ID, from wp_list_redirects.
Kind
Can ask first

Elementor

wp_get_elementor
What it does
Read the Elementor widget tree for a page or post, as the JSON Elementor itself stores.
Kind
Reads
wp_update_elementor
What it does
Replace the Elementor widget tree for a page or post.
Kind
Can ask first

Hidden fields

wp_get_all_meta
What it does
Read every meta field stored on a post, page or custom post type item, including the underscore-prefixed fields WordPress hides from the core REST API.
Kind
Reads
wp_update_meta
What it does
Write meta fields on a post, page or item, including protected underscore-prefixed keys that the core REST API refuses.
Kind
Writes

Bulk edits

wp_bulk_update
What it does
Apply the same changes to a list of posts in one call: change status, reassign the author, set a menu order, or write meta fields across all of them.
Kind
Can ask first
wp_bulk_delete
What it does
Move a list of posts to the trash, or delete them permanently with force: true.
Kind
Can ask first
wp_search
What it does
Search every searchable post type and term at once, returning IDs, titles, URLs and types.
Kind
Reads

Users and comments

wp_list_users
What it does
List the site's users with their IDs, names, slugs and roles.
Kind
Reads
wp_list_comments
What it does
List comments, filtered by post, status, search term or author.
Kind
Reads

Sites

wp_list_sites
What it does
List every WordPress site this server can reach, with the short name to pass as site, the URL, the user it acts as, and optionally whether the helper plugin is installed there.
Kind
Reads
wp_get_me
What it does
Show the WordPress user the application password belongs to, including the role and the capabilities that come with it.
Kind
Reads
wp_get_settings
What it does
Read the site's general settings: title, tagline, URL, admin email, timezone, date and time formats, start of week, language, and the default post category and format.
Kind
Reads

Is the WordPress MCP server safe?

Publishing is the point of the tool, so writes work from the start. 4 kinds of change ask first, because WordPress can't undo them: publishing or scheduling, permanent deletes, replacing an Elementor layout, and anything bulk. The tools that can do one of those are marked Can ask first in the tool tables above.

Trashing, drafting and ordinary edits don't ask, because each is one click to undo in wp-admin.

Make it read-only

Set WORDPRESS_READ_ONLY=1 and every write disappears from the tool list, leaving 22 reading tools. WORDPRESS_ALLOW_DESTRUCTIVE=0 is the middle setting: ordinary edits still work, and publishing and permanent deletes don't.

Keep a log of every write

Set WORDPRESS_AUDIT_LOG to a file path. The server writes one line per attempted write, allowed or blocked.

⚠️

Watch out: Comments and post content can be text other people wrote, and a comment can try to give your AI orders. Treat everything it reads as data, and use WORDPRESS_READ_ONLY=1 for an agent working on its own.

Your data

Nothing goes anywhere but your own site. Your application password stays in your app's config or your shell, and there's no tracking of any kind.

To disconnect, revoke the password under Users, then Profile, then Application Passwords. It stops working right away, and your login is untouched.

Connect more than one WordPress site

List your sites in WORDPRESS_SITES as JSON, each with its own address, username and application password. Pass site on any call, or set WORDPRESS_DEFAULT_SITE, because a call that names no site is refused rather than guessed at.

WordPress MCP server settings

Every setting is an environment variable, in your app's config or your shell.

WORDPRESS_SITE_URL
Default
none
What it does
Sets your site's address
WORDPRESS_USERNAME
Default
none
What it does
Sets the user the password belongs to
WORDPRESS_APP_PASSWORD
Default
none
What it does
Holds the application password, never your login
WORDPRESS_SITES
Default
none
What it does
Lists several sites, as JSON
WORDPRESS_DEFAULT_SITE
Default
none
What it does
Picks the site that acts when a call names none
WORDPRESS_READ_ONLY
Default
off
What it does
1 hides every write
WORDPRESS_ALLOW_DESTRUCTIVE
Default
on
What it does
0 blocks publishing and permanent deletes
WORDPRESS_AUDIT_LOG
Default
none
What it does
Logs every attempted write to a file
WORDPRESS_REQUEST_TIMEOUT_MS
Default
30000
What it does
Sets how long a request can take

Troubleshooting

Run the doctor first. It names the step that failed and the fix.

What you seeWhat to do
incorrect_password on every callYou used a login password, or the site runs on plain HTTP
rest_cannot_edit on some postsThe user is an Author, who only reaches their own posts. Use Editor or Administrator
rest_no_routeA security plugin blocks the REST API, or the post type isn't shown in REST
"needs the WordPress MCP Helper plugin"The tool needs the helper plugin in mu-plugins
"returned HTML rather than a REST response"A firewall, a security plugin or a maintenance page answered instead of WordPress
Edits to an Elementor page do nothingThe layout lives in a hidden field. Use wp_update_elementor
A post scheduled at the wrong hourDates use the site's time zone. Check wp_get_settings

If the server doesn't show up in your app at all, run the command your app runs, in a terminal, and read the error.

More free tools for your site

Check your site's structured data, or make the llms.txt file AI search reads.

WordPress MCP Server FAQs

Here are the questions people ask most about the WordPress MCP server and CLI.

The WordPress MCP server & CLI is a free, open source program that lets an AI app like Claude, Codex or Cursor work on your WordPress site.

It has 42 tools for posts, pages, custom post types, media, taxonomies, Elementor, Rank Math SEO, redirects and bulk edits, and the same tools run as a CLI that agents like Claude Code and Codex use, or that you type yourself.

An MCP server is a standard way to give an AI app real access to a tool, so it can act instead of guessing.

MCP stands for Model Context Protocol, and Claude, Codex, Cursor and many other AI apps speak it.

The WordPress CLI is the same program as the WordPress MCP server, run as commands.

AI agents like Claude Code, Codex and OpenCode run them for you, and you can type them in a terminal or a script.

Use the WordPress MCP server in an AI app with no terminal, like Claude Desktop's chat, and the CLI in a terminal, a script or a cron job.

In an AI app that can run commands, like Claude Code, Codex or Cursor, the CLI is the lighter choice, because it costs nothing until it runs.

Yes, the WordPress MCP server is free and open source under the MIT license, and so is its helper plugin.

The only thing you pay for is your own AI app.

The WordPress MCP server uses an application password because you can revoke it on its own and it carries only its user's role.

WordPress has made them since version 5.6, under Users, then Profile.

You need the WordPress helper plugin only for 12 of the tools: Elementor, Rank Math, redirects, hidden fields and bulk edits.

The other 30 work with nothing installed.

Yes, the WordPress MCP server reads and replaces Elementor layouts with wp_get_elementor and wp_update_elementor, through the helper plugin.

Replacing a layout asks for a confirm check first.

The WordPress MCP server publishes when you ask it to.

Publishing, permanent deletes, layout replacements and bulk edits only run once your AI passes a confirm check.

The WordPress MCP server works with any WordPress site on HTTPS, wherever it's hosted.

If you're choosing a host, I recommend Hostinger for WordPress.

Yes, the WordPress MCP server connects as many sites as you list in WORDPRESS_SITES.

Every call names its site, or uses the default you set.

The WordPress MCP server works with any app that speaks MCP.

That includes Claude Code, Claude Desktop, Codex, Cursor, VS Code, GitHub Copilot CLI, Gemini CLI, OpenCode, OpenClaw, Antigravity and Hermes.

Navid Moazzez built the WordPress MCP server and maintains it.

The code is on GitHub under the MIT license, and the package is on npm.

Navid Moazzez

AI business strategist & AI OS builder

Navid Moazzez helps creators and founders master AI and build their own AI Operating System (AI OS) to automate their business and life.

Navid.me is reader-supported. When you buy through links on this site, I may earn an affiliate commission. Learn more.

More MCP servers & CLIs

Free AI newsletter

The most actionable AI newsletter for founders

Every week, get proven AI strategies, curated tools, and step-by-step systems to grow your audience, create better content, and build a profitable creator business.

No fluff, no filler, no BS. Just five minutes each week that might level up your online business and life.

P.S. Sign up now to get free access to my ultimate AI tools guide for creators.

Loved by 10,000+ readers