wordpress-mcp-elementor-wppilot
WordPress MCP server for Claude, ChatGPT, Cursor and Codex: 168 typed abilities, free Elementor MCP editing, OAuth 2.1, safety profiles, human approval and verified undo. Pro adds WooCommerce MCP, 10 page builders, backups, security hardening and safe updates across 88 integrations.
Install
https://{site}/wp-json/mcp/wppilotTransport: streamable-http
Authorizationrequired · secret — Basic credentials with a WordPress Application Password, or a WPPilot access token as a Bearer token. Create either under WPPilot > Connect.
WPPilot - WordPress MCP Server, Elementor MCP and WooCommerce MCP
Connect Claude, ChatGPT, Claude Code, Codex, Cursor or Antigravity to your WordPress site and let an AI agent build pages, Elementor layouts, block content, menus, taxonomies, media and SEO metadata through typed abilities your permissions still govern.
Installs straight into Plugins - Add New - Upload Plugin. That link always resolves to the newest release, so it does not go stale. Older versions are on the releases page. GitHub's own Source code (zip) is not installable: it has no vendor/ and uses a versioned folder name.
WPPilot turns your WordPress site into an MCP server, built on the WordPress Abilities API and the official WordPress MCP Adapter. AI clients discover, inspect and execute typed WordPress abilities through a compact three-tool interface instead of loading hundreds of one-off endpoints into context.
The free plugin is the WordPress MCP server, and since 1.10.0 it is also a working Elementor MCP server: 17 abilities that read an Elementor document, report the widgets and style properties your install actually offers, and add, edit, move, duplicate, reorder and delete elements in the tree. No licence, no key, no Pro install. WPPilot Pro then extends that same endpoint into a WooCommerce MCP server and a Bricks, Divi, Oxygen, Etch or WPBakery MCP server, and adds Elementor's authoring layer on top: whole-page composition, templates and theme parts, popups, forms, dynamic tags, global classes and variables.
How WPPilot compares to other WordPress MCP servers
WordPress MCP servers differ most in what happens after an agent writes: who confirms a destructive call, whether a change can be undone, and whether the server runs on your own site or through someone else's relay. WPPilot is self-hosted with no call caps. It can require a person, not the model, to confirm destructive calls. It records every write in a change ledger, and its undo checks the restored state against the before-image instead of assuming it worked. The free plugin covers Elementor editing, accessibility and content audits, and search and replace with undo.
Other servers lead elsewhere, and the comparisons say so. Every competitor fact is sourced and dated:
Best WordPress MCP servers in 2026 · vs Respira · vs Easy MCP AI · vs EMCP · vs Elementor's MCP · vs WPVibe · vs Royal MCP · vs AI Engine · vs the WordPress MCP Adapter · Undo and rollback, compared
Looking for an Elementor, Divi or Beaver Builder MCP server?
This is it, with one server instead of one per plugin. Elementor editing is free, in this repository, and needs nothing else installed - see Elementor MCP in the free plugin. WPPilot Pro adds the builder-aware layer on top of the same endpoint, so an agent that connects once can work in whichever editor the site actually uses:
Elementor MCP · Bricks MCP · Divi MCP · Beaver Builder MCP · Oxygen MCP · Breakdance MCP · WPBakery MCP · Etch MCP · Mosaic MCP
Beyond page builders, Pro also covers WooCommerce, FunnelKit, UpdraftPlus, Duplicator, BackWPup, Wordfence, Solid Security, Advanced Custom Fields, Meta Box, JetEngine, Pods, ACPT, WPForms, Gravity Forms, Fluent Forms, Formidable, Contact Form 7, Ninja Forms, Forminator, WS Form, Yoast SEO, Rank Math, AIOSEO, SEOPress, The SEO Framework, Slim SEO, SmartCrawl, WPML, Polylang, Weglot, The Events Calendar, Tutor LMS, Paid Memberships Pro and BuddyPress. Full table below: 88 integrations.
WordPress MCP server and protocol support
WPPilot serves both protocol revisions during the migration window:
| Revision | State | How it is served |
|---|---|---|
2026-07-28 |
Stateless. No initialize, no session. Each request carries its version and client capabilities in _meta. |
includes/mcp/, dispatched ahead of the adapter |
2025-11-25 |
Legacy. initialize handshake and Mcp-Session-Id sessions. |
The bundled MCP Adapter, unchanged |
A request is served under the modern revision only when it carries modern per-request _meta; everything else reaches the adapter untouched. Existing users do not need to reconnect unless their client requires the newer revision.
server/discover is implemented and advertises both versions plus the capabilities actually registered on the site. Subscriptions, the tasks extension and logging are deliberately not advertised, WPPilot has no change-notification producer, so subscriptions/listen is not implemented.
For OAuth, Client ID Metadata Documents are the preferred registration mechanism; RFC 7591 Dynamic Client Registration remains available as a compatibility fallback. Application Passwords and access tokens stay independent fallbacks for clients that run no OAuth flow.
Full detail: docs/wordpress-mcp.md.
It is a control layer, not an AI wrapper. No AI model is bundled: external MCP clients bring their own model access, and policy is enforced server-side on your install.
What an agent can actually build
One prompt from you becomes hundreds of typed calls from the agent, each checked against your WordPress capabilities and the active safety profile before it runs.
Free covers the core surface: posts and pages, block-editor content, Elementor documents, taxonomies, menus and menu locations, media with alt text, users, site settings including the front page, plus design documents, skills and a change ledger with rollback.
You do not have to phrase anything in a particular way. A client's first call is discovery, and WPPilot answers with every ability registered on your install plus a catalogue of the skills available for them, carrying one instruction: if a skill matches the request, load its full instructions before starting the work. So "rebuild the pricing page and keep our spacing" already pulls in the right build skill, the element schemas and your existing design tokens without you naming any of it. Write your own prompts; the routing is on the site.
The library is a shortcut, not a dependency. WPPilot ships a prompt library in wp-admin: ten complete landing-page briefs, one per industry, because "build me a bakery site" and "build me a law firm site" should not produce the same page. Each brief fixes a flat palette, a type pairing, a design signature that makes the page its own, the sections it must communicate, and the facts to use verbatim, then closes with one shared standards block: WCAG 2.1 AA, real photography in every slot, one SVG icon set, builder-native construction, and no half-built pages. Pick Elementor or the block editor on the screen and the brief is written for it. WPPilot Pro adds 300 more, across 18 sectors and covering whole multi-page sites, stores, booking sites, courses and membership sites rather than single landing pages - every one with its own palette, type pairing and design signature, because three hundred briefs that share a look are one brief with three hundred names.
WPPilot Pro adds plugin-aware modules, page builders, WooCommerce, forms, custom fields, SEO, themes, each with its own ability chains.
- 🌐 Website: https://wppilot.co
- 🧱 What it builds: https://wppilot.co/build
- 📚 Documentation: https://wppilot.co/docs
- 🔌 Client setup guides: https://wppilot.co/wordpress-mcp
- 𝕏 Release notes and build demos: https://x.com/WPPilotMCP
Quick start
- Download
wppilot.zipand install it aswp-content/plugins/wppilot, or upload it in Plugins - Add New - Upload Plugin. A GitHub “Source code (zip)” download is not installable, it lacksvendor/and uses the wrong folder name. - Activate WPPilot.
- Open WPPilot → Configuration and leave Production Safe selected.
- Open WPPilot → Connect, choose your AI client, and follow the OAuth or Application Password route.
Canonical MCP endpoint:
https://example.com/wp-json/mcp/wppilot
OAuth-authenticated clients use /wp-json/mcp/wppilot-oauth. Application passwords and access tokens both authenticate on the canonical route. The older /wp-json/mcp/mcp-adapter-default-server route still resolves as a legacy alias, but new configurations should use the canonical path above.
Supported AI clients: connect Claude, ChatGPT, Cursor and more to WordPress
Claude Code · Claude Desktop · Claude on the web · ChatGPT · Codex CLI · Codex desktop app · Cursor · VS Code · GitHub Copilot · Gemini CLI · Devin Desktop (formerly Windsurf) · Factory Droid · Antigravity CLI · Antigravity IDE · Zed · Cline · Roo Code · Kilo Code · Amazon Q · OpenCode · OpenClaw · Qwen Code · Kimi Code CLI · ZCode (GLM) · Mistral Le Chat · Perplexity · Manus
Plus programmatic callers with no browser: the Claude Messages API MCP connector, the OpenAI Responses API mcp tool, cron jobs and curl, using an access token.
Which route each client takes: docs/ai-client-compatibility.md. Per-client setup guides: https://wppilot.co/wordpress-mcp
Authentication
Three methods, chosen on WPPilot → Connect:
- OAuth 2.1 with PKCE and dynamic client registration. Access tokens last 1 hour, refresh tokens 14 days, and every authorization is listed under Connected Apps in WordPress so it can be revoked individually. Recommended wherever the client can open a browser.
- Application Passwords as a fallback for clients that cannot run a browser flow. Sent as HTTP Basic.
- Access tokens - a long-lived
Authorization: Bearer wpp_…credential for callers with no browser and no interactive session: the Claude Messages API MCP connector, the OpenAI Responses APImcptool, cron jobs, automation platforms,curl. Created with an optional expiry, shown once, stored only as a SHA-256 digest, and revocable per token. It authenticates on the canonical/wp-json/mcp/wppilotendpoint, so the URL is the same one every other snippet uses.
An access token borrows the capabilities of the user who created it, and that check is re-run on every request rather than frozen at creation - demoting or deleting the user closes the token in the same moment.
None of the three is a product licence. WPPilot needs no activation key, entitlement check or subscription service to run.
Local connection over WP-CLI (stdio)
A client that runs on the same machine as the site - Claude Code, Cursor, a CI job - can start WPPilot itself instead of connecting over HTTP, with no credential to create. wp wppilot mcp serve serves the same MCP server as /wp-json/mcp/wppilot over stdin/stdout, as the WordPress user named in WP-CLI's --user, with the same abilities, safety profile, confirmations and permission checks:
# Claude Code
claude mcp add wppilot-local -- wp --path=/var/www/html wppilot mcp serve --user=admin
# WordPress in Docker
claude mcp add wppilot-local -- docker exec -i <container> wp --path=/var/www/html wppilot mcp serve --user=admin
Cursor and other clients that take a command (.cursor/mcp.json):
{
"mcpServers": {
"wppilot-local": {
"command": "wp",
"args": ["--path=/var/www/html", "wppilot", "mcp", "serve", "--user=admin"]
}
}
}
The Connect screen shows these with this site's path and your login filled in. Nothing is written to stdout except protocol messages, and each process is one agent session on the Changes screen.
Safety model
| Profile | What it allows |
|---|---|
| Read Only | Discovery and inspection. Every state-changing ability is blocked. |
| Production Safe | Normal content, design, SEO, forms and commerce work, plus plugin activation and updates with confirmation. Blocks raw PHP, WP-CLI, filesystem, database, plugin/theme installation and deletion, and temporary admin access. |
| Developer Full Access | Every enabled ability, including privileged surfaces. Critical calls still require explicit confirmation. |
On top of the profile: WordPress user capabilities still apply, individual abilities can be switched off, destructive operations require an explicit confirmation flag, writes are rate-limited per credential, and supported changes are recorded in a redacted change ledger with rollback.
Undo a whole agent session. Every write an agent makes is filed under its session - one MCP connection, one wp wppilot mcp serve process, or one credential and client until it has been idle for 30 minutes. wppilot/undo-session (or Undo session on the Changes screen) takes back everything that session did, newest first, verifying each change against its before-image. It refuses without touching anything when something else changed a target after the session did, stops at the first change that fails verification and says exactly what was and was not undone, and never skips a change that cannot be undone without saying so. wppilot/redo-session puts an undone session back, under the same checks. wppilot/list-sessions shows each session and what undo and redo would do right now.
Every ledger entry names the agent behind the write, not only the WordPress user. Claude Code, Cursor and Codex usually connect as the same administrator, so the user alone cannot answer which of them made a change: the OAuth client id or application-password UUID can, and it is what the ledger records, alongside the client name the agent introduced itself with. A write with no agent behind it - wp-admin, WP-CLI, cron - is recorded as direct rather than credited to the last agent seen. OAuth client ids are stored hashed.
What the free plugin can do
216 registered abilities, plus one MCP prompt per skill you save. The WooCommerce, SEO, form, backup and security abilities register only while their plugin is active, and developer abilities only under Developer Full Access, so a fresh install with none of those plugins registers 154 on the default profile. The WordPress ones are grouped under a single WordPress category in the Abilities screen and can be switched off individually.
| Domain | Abilities | What it covers |
|---|---|---|
| Content | 8 |
List, search and read posts, pages and public custom post types. Create, update, trash, restore, and permanently delete with explicit confirmation. |
| Taxonomies | 7 |
Discover taxonomies, list and read terms, create, update, delete with confirmation, and assign terms to content. |
| Media | 10 |
List, read, import from a URL, search openly-licensed stock, update metadata and alt text, set and clear featured images, attach and detach, delete with confirmation. |
| Comments | 6 |
List and read with commenter email and IP withheld below moderate_comments. Reply, edit, approve, hold, spam, unspam, trash, restore, delete with confirmation. |
| Menus | 10 |
Create, rename and delete menus, add, update, reorder and remove items, list theme locations and assign menus to them. |
| Revisions | 3 |
List with autosaves distinguished, read against the live post, and restore. |
| Users | 4 |
Privacy-minimized reads. Login name, roles and registration date need list_users; the email address needs edit_users. |
| Site | 2 |
Site information and an explicit settings allowlist. |
| Plugins and themes | 12 |
Search the WordPress.org directory and read one extension in detail. Activate, deactivate, update and switch themes with explicit confirmation. Install and delete are Developer Full Access only: they write executable code to the server. |
| Gutenberg | 11 |
Block-editor content, staged pending changes and browser finalization for native blocks. |
| Elementor | 17 |
Read a document, inspect the widgets and style properties this install offers, and edit the element tree: add, edit, move, duplicate, reorder and delete. Page settings included. Detail below. |
| Design system | 19 |
Typed design tokens, saved designs and activation, plus the checks that grade a built page against them: contrast, composition, layout grammars and a rendered-page verification pass. |
| Preview | 8 |
Compute what a write would change without performing it, then apply the reviewed result. Plus a view link, so an agent with a browser can look at the page it built - including one still in draft - and a capture store that compares two screenshots of a page and reports which regions moved. |
| Skills | 4 + prompts |
Reusable skills and site-wide instructions. Each saved skill also registers one MCP prompt, so this grows with the skills you write. |
| Changes | 8 |
Read the redacted change ledger, attributed to the agent credential that made each write, export it as rows for a client report or an audit, roll a change back, and undo or redo everything one agent session did. |
| Diagnostics | 4 |
Scoped health, performance and configuration-security checks, and a Connection Doctor that finds what blocks an MCP client (firewalls, a stripped Authorization header, disabled Application Passwords) and names the fix. |
| Search and replace | 4 |
Preview a search-and-replace across posts and their meta (serialized and builder JSON included) as a reviewed plan, apply only posts unchanged since, 100 per call or as a background job, cancel it, and undo one post or the whole run. |
| Media and accessibility | 5 |
Resize, crop, rotate or flip an image as a copy or in place, with undo. Audit a served page against WCAG 2.2, find images with missing or filename alt text, show an image to the model so it can write real alt text, and set alt text in bulk with undo. |
| Content audit | 2 |
Broken internal links, orphan pages, thin content, missing SEO descriptions and structured-data problems across the site, as a background job. |
| Block Notes | 4 |
Leave a note on a block for a person, reply, resolve, and read the notes they resolved. Every one can be undone. |
| Site tools | 8 |
WP-Cron list, run and delete (undoable), Site Health tests, transient flush, and - on Developer Full Access, audited - an options explorer and a read-only database SELECT with redaction. |
| Multisite | 2 |
List a network's sites and run an ability on one of them through that site's own safety profile and gates. Loads only on a multisite network. |
| WooCommerce | 13 |
Check the setup, list and read products, variations, categories, tags and store settings, read orders and customers, and edit one product's name, description, prices and stock with undo. Pro adds bulk prices and stock, order and customer writes, refunds, coupons, reports and full product editing. |
| SEO | 14 |
One post's SEO title, meta description and robots in Yoast SEO, Rank Math, All in One SEO, SEOPress, The SEO Framework, Slim SEO and SmartCrawl, read and set with undo. Pro adds focus keywords, canonicals, social previews, schema, redirects and bulk SEO. |
| Forms | 8 |
List the forms of WPForms, Contact Form 7, Gravity Forms and Forminator and read their entries with email addresses, phone numbers and sensitive fields withheld. Pro adds full values, exports and form editing. |
| Backups and security | 5 |
Backup status and history (UpdraftPlus, Duplicator, BackWPup); security plugin status, scan findings and lockouts with IPs shown as networks (Wordfence, Solid Security). Pro starts backups, holds risky calls until a fresh backup exists, hardens settings and blocks IPs. |
| Scheduled audits | 5 |
Routines that run the accessibility, content and alt-text audits on a schedule, store each report, compare it with the last and email what changed. |
| Developer | 13 |
PHP execution, WP-CLI, filesystem and temporary admin access. Blocked outside Developer Full Access, and excluded entirely from the WordPress.org build. |
Content creation is draft-first: an absent, blank or malformed status resolves to draft before any capability check, so nothing is published by accident. Capabilities are read from each post type's and taxonomy's own capability object, so a custom type declaring its own set is enforced on its own terms.
Elementor MCP
Since 1.10.0, editing an Elementor page is free. The Elementor abilities load automatically when Elementor 3.6 or newer is active and stay unregistered otherwise, so an agent is never offered a tool that cannot work on this site.
Writing generated HTML into post_content does not change an Elementor page. The layout lives in postmeta as a typed element tree, and Elementor renders from that and ignores the markup. These abilities work on the tree itself.
| Ability | What it does |
|---|---|
wppilot/elementor-check-setup |
Elementor and Elementor Pro versions, whether the v4 atomic runtime, the style schema, global classes, variables and interactions are available on this install. The call an agent should make first. |
wppilot/elementor-get-schema |
Discover widgets, or describe named ones in compact form: which controls exist, their types and their allowed values. Filterable by category, by name and by whether a widget is atomic. |
wppilot/elementor-get-style-schema |
The 73 style properties Elementor's atomic engine accepts, with the value shape each one takes. |
wppilot/elementor-get-widget-params |
The parameters one widget accepts, without reading its whole schema. |
wppilot/elementor-get-content |
Read the element tree of a document, as structure or in full. |
wppilot/elementor-find-elements |
Locate elements by type, by widget, by id or by the text they contain. |
wppilot/elementor-set-content |
Replace a document's tree in one call. Invalid properties are dropped and reported rather than failing the whole page; pass strict to refuse instead. |
wppilot/elementor-add-element |
Insert a widget, a container or a whole subtree at a position you choose, with settings and per-element styles validated against the schema first. |
wppilot/elementor-edit-element |
Change one element's settings or styles in place, leaving the page around it untouched. |
wppilot/elementor-move-element |
Move an element to a new parent or a new position. |
wppilot/elementor-duplicate-element |
Copy an element, with fresh ids throughout its subtree. |
wppilot/elementor-reorder-children |
Reorder a container's children in one call. |
wppilot/elementor-delete-element |
Remove an element and its subtree. |
wppilot/elementor-get-page-settings · set-page-settings |
Read and write document-level settings: page layout, title visibility, background, and the rest. |
wppilot/elementor-clear-document-cache |
Regenerate Elementor's CSS for a document after a write. |
Full detail, including the read-before-write sequence: docs/elementor-mcp.md.
Both element models are supported: Elementor v4 atomic elements (e-div-block, e-heading, e-paragraph, e-button, e-image and the rest, with the atomic style schema) and classic v3 widgets and containers, with the settings keys each one actually uses.
What Pro adds on top
The free abilities are the primitives, and they compose. What Pro adds is the authoring layer above them, plus everything Elementor keeps outside a single document:
Composition: elementor-build-page builds a whole page from one compact description instead of a dozen round trips; elementor-compile-spec and elementor-build-from-spec turn a reproduction spec into global classes and a matching tree. Reuse: templates, theme parts and display conditions, popups, global classes, v4 variables and v3 global colours and typography. Content: Elementor Pro forms and submissions, dynamic tags, interactions, SVG upload, stock-image placement, and site-wide custom code.
The dividing line is simple: free can edit an Elementor page, Pro can compose one.
WPPilot Pro: plugin-aware abilities across 88 integrations
The free plugin in this repository is a complete WordPress MCP server: connection, authentication, safety profiles, Gutenberg workflows, Elementor editing, the design system, diagnostics, change evidence and 216 abilities, including the whole WordPress core surface: content, taxonomies, media, comments, revisions, menus, user reads, allowlisted settings and the plugin/theme lifecycle. Free needs no licence, entitlement service or Pro install.
WPPilot Pro adds plugin-aware abilities across 88 integrations (the plugins, themes and builders in the table below plus 26 caching and optimization layers), typed operations that understand each plugin's own data model rather than writing generic content. Modules load only when their plugin is detected, and each loads in isolation, so a missing or broken plugin cannot stop the rest of the registry from registering.
| Category | Integrations · ability count |
|---|---|
| Page builders | Elementor 51 · Bricks 49 · Breakdance 33 · Divi 47 · Oxygen 37 · Beaver Builder 21 · WPBakery 18 · Etch 60 · Mosaic 41 · Flatsome UX Builder 11 |
| Blocks and site design | GenerateBlocks 3 · Kadence Blocks 5 · Spectra 20 · Spectra One 22 |
| Themes | Astra 34 · Avada 16 · GeneratePress 23 · Kadence 5 · OceanWP 15 · WordPress Block Themes 4 · Blocksy 4 · Neve 4 · WoodMart 4 |
| Commerce | WooCommerce 53 · FunnelKit 4 |
| Forms | WPForms 27 · Gravity Forms 27 · Fluent Forms 37 · Formidable Forms 39 · Contact Form 7 8 · Ninja Forms 21 · Forminator 3 · WS Form 4 |
| SEO suites | AIOSEO 12 · Rank Math 8 · SEOPress 16 · Yoast SEO 10 · The SEO Framework 3 · Slim SEO 3 · SmartCrawl 3 |
| Custom data | Advanced Custom Fields 23 · ACPT 24 · Admin and Site Enhancements 18 · JetEngine 26 · Meta Box 32 · Pods 25 · Dynamic Shortcodes 9 |
| Localization | Weglot 19 · WPML 8 · Polylang 6 |
| Backups | UpdraftPlus 1 · Duplicator 1 · BackWPup 1 (start a backup, and an optional "require a fresh backup" hold on destructive calls; status and history are free) |
| Security | Wordfence 5 · Solid Security 5 (a hardening plan you confirm, IP blocks and scans, all undoable; status, findings and lockouts are free) |
| Site maintenance | Safe plugin and theme updates 3 (checks pages before and after, rolls back on its own) · Content fixes 2 |
| Site operations | The Events Calendar 7 · Paid Memberships Pro 5 · Tutor LMS 7 · BuddyPress 8 |
| Developer tools | Code Snippets 11 · Bricksforge 21 |
| WordPress platform | WordPress extras 23 · Brand Kit 8 · Agent Memory 4 · Pro skill library 1 (skills themselves are free) |
Why plugin-aware matters
A page builder does not store a page as HTML. It stores an element tree, references to shared classes and design tokens, template rules and dynamic bindings. Writing generated markup into that store is how a layout stops opening in its own editor.
Pro gives the agent that builder's own vocabulary: bricks-patch-elements, elementor-create-atomic-widget, divi-apply-global-preset, etch-get-query-preview, so it can read a schema before it proposes a change.
Where each builder keeps its layout, and what that means for an agent: docs/page-builder-mcp.md.
Page builder MCP servers
One endpoint covers every builder below. The agent gets that builder's own vocabulary rather than being handed raw HTML to guess at.
| Builder | Abilities | Free / Pro | Guide |
|---|---|---|---|
| Elementor | 68 | 17 free · 51 Pro | MCP for Elementor |
| Etch | 60 | Pro | MCP for Etch |
| Bricks | 49 | Pro | MCP for Bricks |
| Divi | 47 | Pro | MCP for Divi |
| Mosaic | 41 | Pro | MCP for Mosaic |
| Oxygen | 37 | Pro | MCP for Oxygen |
| Breakdance | 33 | Pro | MCP for Breakdance |
| Beaver Builder | 21 | Pro | MCP for Beaver Builder |
| WPBakery | 18 | Pro | MCP for WPBakery |
| Flatsome UX Builder | 11 | Pro | All integrations |
Elementor MCP server
Elementor is the one builder whose editing surface is free. The 17 abilities in this repository read the document, report the widgets and the 73 style properties your install actually offers, and add, edit, move, duplicate, reorder and delete elements in the tree - v4 atomic elements and classic v3 widgets alike. See Elementor MCP above for the full list.
Pro's 51 add the authoring layer on the same endpoint: whole-page composition from a description or a reproduction spec, templates and theme parts, display conditions, popups, forms and submissions, dynamic tags, interactions, global classes, v4 variables and v3 global colours and typography.
Writing generated markup into post_content does not change an Elementor page -
the layout lives in postmeta, and WPPilot refuses that write by name rather than
reporting a success that changes nothing.
Bricks MCP
Patches the Bricks element tree in place with bricks-patch-elements, so a
change to one section does not rewrite the page around it.
Divi MCP
Works with Divi modules and global presets through divi-apply-global-preset,
rather than flattening a layout into shortcodes.
Beaver Builder MCP
Beaver Builder keeps its layout in postmeta under _fl_builder_data, so writing
HTML into post_content changes nothing a visitor sees. Pro reads and writes
that store; the free plugin recognises the builder and refuses the write rather
than reporting a success that does nothing.
Oxygen MCP
Oxygen stores a JSON element tree in postmeta and renders from it, ignoring
post_content entirely. Pro's 37 abilities work against that tree.
WPBakery MCP
WPBakery is the exception that keeps its layout in post_content, as nested
shortcodes. Pro parses and edits those shortcodes instead of replacing the
markup around them.
Breakdance, Etch and Mosaic MCP
Breakdance (33 abilities), Etch (60) and Mosaic (41) each expose their own element model. Etch has the largest surface of any builder in Pro.
Gutenberg MCP
Block editing is in the free plugin, not Pro: parse, insert, move and replace blocks in the core block tree, with reusable blocks and patterns.
WooCommerce MCP
Products, variations, orders, coupons and stock as typed abilities rather than raw REST calls. An agent can query the catalogue, create a variable product with its attributes and variations, adjust stock, read orders and add order notes - each one capability-checked against the connected WordPress user, so an agent connected as a shop manager cannot do what that account could not do by hand.
Order status changes and anything touching money are classed destructive, so they require explicit confirmation and are recorded in the change ledger with rollback, the same as every other write.
Full detail: docs/woocommerce-mcp.md.
Beyond integrations
- Persistent agent memory, approved context that carries between sessions, so an agent does not relearn your stack every conversation.
- Human approval queue, holds an agent write until a person approves it, with email notification. The agent receives a structured “pending” response, not a false success.
- Integration health reporting: see which modules loaded, which were skipped, and why.
- Plugin-aware skill packs, guided sequences that encode the read-before-write workflow for the plugins you run.
Compare Free vs Pro · Pricing · All integrations
WPPilot Pro is a commercial plugin and is not distributed from this repository.
FAQ
What is a WordPress MCP server, and is this one a server or a client?
A server. Your site exposes typed WordPress abilities over MCP at https://example.com/wp-json/mcp/wppilot, and the AI client you already use connects to it. No model is bundled and no key is stored here; the client brings its own model access.
Is there an Elementor MCP server? Yes, and editing is free. The plugin in this repository registers 17 Elementor abilities as soon as Elementor 3.6 or newer is active: read the document, inspect the widget and style schemas, and add, edit, move, duplicate, reorder and delete elements in the tree, plus page settings. No licence and no Pro install. WPPilot Pro adds 51 more for the authoring layer - whole-page composition, templates and theme parts, popups, forms, dynamic tags, global classes and variables. Free can edit an Elementor page; Pro can compose one.
What about Bricks, Divi, Beaver Builder, Oxygen, Breakdance, WPBakery, Etch, Mosaic and Flatsome? Those are WPPilot Pro, which registers builder-aware abilities on the same endpoint. A page builder stores an element tree, shared classes, design tokens and dynamic bindings rather than HTML, so Pro gives the agent that builder's own vocabulary instead of writing markup into a store that will not open in its editor.
Is there a WooCommerce MCP server? Yes, in WPPilot Pro. Products, variations, orders, coupons and stock become typed abilities on the same endpoint, capability-checked against the connected WordPress user - an agent connected as a shop manager cannot do what that account could not do by hand. Anything touching money is classed destructive, so it needs explicit confirmation and lands in the change ledger with rollback.
Do I need Pro to use this? No. The free plugin in this repository is a complete WordPress MCP server with 216 abilities - including Elementor editing and the design system - and it needs no licence, activation key or entitlement service. Pro is additive.
Can an agent build an Elementor page with the free plugin?
It can build one element at a time, which is what elementor-add-element, elementor-edit-element and elementor-set-content are for, and the design system in free gives it the palette, the type and spacing ladders and the compositions to build against. The single-call whole-page builders, elementor-build-page and elementor-build-from-spec, are Pro.
How does it relate to the WordPress Abilities API and the official MCP Adapter? It is built on both. The Abilities API is where abilities are registered, and the MCP Adapter is bundled to serve the legacy protocol revision. WPPilot adds the parts an adapter does not: authentication, safety profiles, confirmation gates, rate limiting, a change ledger with rollback, and the abilities themselves.
How do I connect WordPress to Claude, Cursor or Codex? Claude Code, Claude Desktop, Claude on the web, Codex CLI and desktop, Cursor, VS Code, GitHub Copilot, Devin Desktop, Factory Droid, Antigravity CLI and IDE, Zed, Cline, Roo Code, Kilo Code, Amazon Q, OpenCode, OpenClaw and Manus. Setup guides: https://wppilot.co/wordpress-mcp.
Is it safe to point an agent at a production site? That is what the safety model is for. Read Only blocks every write, Production Safe blocks raw PHP, WP-CLI, filesystem, database and extension installation, destructive calls require an explicit confirmation flag, WordPress capabilities still apply on top, and supported changes are recorded in a ledger you can roll back. Start on Read Only and verify one call before enabling any write.
Is there a Gutenberg MCP server - can an agent write native blocks? Partly, and the plugin says so rather than failing silently. Core blocks are validated and serialised by the block editor's own JavaScript, so writes are staged as a pending batch and finalised through a browser session.
Is it on WordPress.org?
No. Distribution is GitHub releases for the free plugin and wppilot.co for Pro. Install wppilot.zip from Releases; the GitHub "Source code" archive is not installable.
Requirements
- WordPress 6.9 or newer, tested up to WordPress 7.1
- PHP 8.0 or newer
- HTTPS for any remotely reachable connection
- The Elementor abilities require Elementor 3.6 or newer, and register only when it is active. Elementor 4.0 or newer additionally unlocks the atomic style schema and global classes. Elementor Pro is not required for anything in the free plugin.
- WPPilot Chat additionally requires WordPress 7.0 and an AI provider configured through the WordPress AI Client
Privacy
The MCP endpoint is self-hosted; there is no WPPilot relay. When WPPilot Chat is used, WordPress sends conversation history, selected attachments, site instructions, tool definitions and relevant tool results to the AI provider you configured. Suggested policy text is available in Settings → Privacy → Policy Guide.
Documentation
| Guide | |
|---|---|
| Getting started | https://wppilot.co/docs/getting-started |
| Connect an AI client | https://wppilot.co/docs/connect-ai-client |
| OAuth 2.1 setup | https://wppilot.co/docs/oauth-setup |
| Application Passwords | https://wppilot.co/docs/application-passwords |
| Safety profiles | https://wppilot.co/docs/safety-profiles |
| Page builder workflows | https://wppilot.co/docs/page-builder-workflows |
| Change ledger and rollback | https://wppilot.co/docs/change-ledger-and-rollback |
| Troubleshooting | https://wppilot.co/docs/troubleshooting |
In this repository
| Document | What it covers |
|---|---|
docs/wordpress-mcp.md |
The WordPress MCP server itself: endpoints, protocol revisions, discovery, the three-tool interface. |
docs/elementor-mcp.md |
The free Elementor MCP surface: the 17 abilities, the v3 and v4 element models, a read-before-write sequence. |
docs/page-builder-mcp.md |
Where each builder stores a layout, and why an MCP server has to speak that store: Bricks, Divi, Oxygen, Beaver Builder, Breakdance, Etch, WPBakery, Mosaic. |
docs/woocommerce-mcp.md |
WooCommerce over MCP: capability checks, destructive classification, order and money handling. |
docs/ai-client-compatibility.md |
Which AI clients connect how - OAuth, application password or access token - and what each one needs. |
docs/ARCHITECTURE.md |
Request lifecycle, ability registration, where the code lives. |
docs/SAFETY.md |
Safety profiles, confirmation gates, rate limits, the change ledger. |
SECURITY.md |
Reporting a vulnerability, and hardening guidance. |
Index: docs/README.md
Security
Report suspected vulnerabilities privately, see SECURITY.md. Do not open a public issue for a vulnerability, and never include production credentials or customer data.
Licence
GPL-2.0-or-later. See LICENSE and LICENSES/ for the full SPDX texts.