Understand the Site
The site-context tool reports the active theme and plugins so your agent can work with what’s installed.
Connect your coding agent to the WordPress site you’re working on. Site Agent is my free MCP plugin for reading content and working with the site’s code.
Access starts off. You decide which tools your agent can use.
Your agent gets the stored content and its SHA-256 hash. An update must include that hash so the plugin can detect a change made since the read.
Read accessNew content starts as a draft. Publishing needs an explicit request.
{
"name": "site-agent-get-content",
"arguments": {
"post_id": 42
}
}Your agent can inspect the WordPress environment before proposing a change. You can then enable the tools that change requires.
The site-context tool reports the active theme and plugins so your agent can work with what’s installed.
Your agent can read theme and plugin files. File writes check for intervening changes and validate PHP syntax before saving.
PHP runs with WordPress loaded. WP-CLI runs foreground commands on your server. Each needs a separate opt-in.
Site Agent exposes 10 tools through WordPress Abilities and the official MCP Adapter.
You can start with site and content reads. Content writes and developer tools stay off until you enable their access groups in Tools → Site Agent.
Every tool call checks the WordPress user’s permissions and the access groups you’ve enabled.
You can stop the connection by disabling Site Agent or revoking its dedicated Application Password. These controls remain in your WordPress admin.
Read the Access ModelI recommend a development or staging site with a current backup. These tools have server privileges and aren’t a sandbox:
Your MCP client needs Streamable HTTP and a custom Authorization header. Site Agent uses WordPress Application Passwords for authentication.
Upload the complete ZIP in WordPress. Open Tools → Site Agent.
Enable access and the groups your task needs. Save the settings.
Create a dedicated Application Password in your WordPress profile.
Use the endpoint and authentication template shown in Site Agent.
https://your-site.com/wp-json/site-agent/v1/mcpUse the exact URL shown on your site.The free checkout includes the complete plugin and a license for automatic updates.
The code is public and GPL-licensed. All tools work without license activation. The license connects your installation to the update service.
Complete the free checkout to get the download and license key in your account.
Browse the Source on GitHubCheck the client, privacy and developer-access boundaries before enabling tools.
Use a client with Streamable HTTP and custom Authorization headers, or a compatible Application Password bridge. Site Agent doesn’t include OAuth. Clients that require an OAuth-only connection need a bridge.
Your MCP client connects directly to WordPress. Site Agent has no hosted MCP proxy or telemetry. The client or AI provider handles tool results under its own privacy policy.
Automatic updates contact gauravtiwari.org with your license credentials, site URL and version information. PHP and WP-CLI can also make outbound requests when instructed.
Use a backed-up development or staging site for PHP execution, file editing and WP-CLI. These tools run with server privileges and can break a site. Syntax checks and access switches don’t contain arbitrary code or replace backups.
File tools are limited to theme and plugin directories. Hidden, configuration, credential and symlink paths are blocked. Source files can still contain sensitive data. Writes require the current file hash, or an explicit new-file value, and PHP syntax is checked before a write.
Complete the free checkout, then activate the license in Site Agent. FluentCart supplies update metadata and the protected download. The license affects automatic updates only. You can also install a complete release ZIP manually.
This version doesn’t include OAuth, an AI chat interface, background WP-CLI jobs or a recoverable PHP sandbox. The bundled official MCP Adapter is a pinned 0.7.0 prerelease. PHP runs in the WordPress request and isn’t isolated from the site.
Connect your agent, check what it can read and enable more tools when your task needs them.