Site Agent
WordPress MCP Tools.

Connect your coding agent to the WordPress site you’re working on. Site Agent is my free MCP plugin for reading content and working with the site’s code.

Access starts off. You decide which tools your agent can use.

Free and open source, with a free license for updates.

Site AgentExample MCP Session
Direct to WordPress

Read a Post Before Editing

Your agent gets the stored content and its SHA-256 hash. An update must include that hash so the plugin can detect a change made since the read.

Read access

New content starts as a draft. Publishing needs an explicit request.

MCP tool call
{
  "name": "site-agent-get-content",
  "arguments": {
    "post_id": 42
  }
}

Work With the Site’s Content and Code

Your agent can inspect the WordPress environment before proposing a change. You can then enable the tools that change requires.

Understand the Site

The site-context tool reports the active theme and plugins so your agent can work with what’s installed.

Work With Source

Your agent can read theme and plugin files. File writes check for intervening changes and validate PHP syntax before saving.

Use Developer Tools

PHP runs with WordPress loaded. WP-CLI runs foreground commands on your server. Each needs a separate opt-in.

WordPress AbilitiesNamed operations
Streamable HTTPDirect MCP connection
Application PasswordsNative authentication
Public SourceGPL-licensed

WordPress MCP Tools

Site Agent exposes 10 tools through WordPress Abilities and the official MCP Adapter.

You can start with site and content reads. Content writes and developer tools stay off until you enable their access groups in Tools → Site Agent.

Read WordPress

  • Site context
  • Content search
  • Raw content
  • Media discovery

Change Content

  • Create drafts
  • Update accessible posts and pages
  • Preserve omitted fields and block markup

Use Developer Tools

  • Browse and read source
  • Edit theme and plugin files
  • Execute PHP
  • Run foreground WP-CLI

Choose Your Agent’s Access

Every tool call checks the WordPress user’s permissions and the access groups you’ve enabled.

You can stop the connection by disabling Site Agent or revoking its dedicated Application Password. These controls remain in your WordPress admin.

Read the Access Model
Entry pointDefault
Content writesOff
Source inspectionOff
Source editingOff
PHP executionOff
WP-CLI executionOff
Connections are also off until enabled.

Developer Tools Need a Trusted Client

I recommend a development or staging site with a current backup. These tools have server privileges and aren’t a sandbox:

  • PHP can change the database and files.
  • Source edits can change executable code.
  • WP-CLI can change the WordPress installation.

Connect Your WordPress Site

Your MCP client needs Streamable HTTP and a custom Authorization header. Site Agent uses WordPress Application Passwords for authentication.

  • WordPress 6.9 or newer
  • PHP 8.0 or newer
  • HTTPS for remote connections
  • Administrator access; super administrator on multisite
1

Install the Plugin

Upload the complete ZIP in WordPress. Open Tools → Site Agent.

2

Select the Tools

Enable access and the groups your task needs. Save the settings.

3

Create a Password

Create a dedicated Application Password in your WordPress profile.

4

Connect the Client

Use the endpoint and authentication template shown in Site Agent.

Endpointhttps://your-site.com/wp-json/site-agent/v1/mcpUse the exact URL shown on your site.

Site Agent Is Free

The free checkout includes the complete plugin and a license for automatic updates.

The code is public and GPL-licensed. All tools work without license activation. The license connects your installation to the update service.

$0Free plugin + update license
Get Site Agent

Complete the free checkout to get the download and license key in your account.

Browse the Source on GitHub

Before You Connect

Check the client, privacy and developer-access boundaries before enabling tools.

Which AI clients can connect?

Use a client with Streamable HTTP and custom Authorization headers, or a compatible Application Password bridge. Site Agent doesn’t include OAuth. Clients that require an OAuth-only connection need a bridge.

Where does my site’s data go?

Your MCP client connects directly to WordPress. Site Agent has no hosted MCP proxy or telemetry. The client or AI provider handles tool results under its own privacy policy.

Automatic updates contact gauravtiwari.org with your license credentials, site URL and version information. PHP and WP-CLI can also make outbound requests when instructed.

Can I use developer tools on production?

Use a backed-up development or staging site for PHP execution, file editing and WP-CLI. These tools run with server privileges and can break a site. Syntax checks and access switches don’t contain arbitrary code or replace backups.

What can the file tools reach?

File tools are limited to theme and plugin directories. Hidden, configuration, credential and symlink paths are blocked. Source files can still contain sensitive data. Writes require the current file hash, or an explicit new-file value, and PHP syntax is checked before a write.

How do automatic updates work?

Complete the free checkout, then activate the license in Site Agent. FluentCart supplies update metadata and the protected download. The license affects automatic updates only. You can also install a complete release ZIP manually.

What isn’t included?

This version doesn’t include OAuth, an AI chat interface, background WP-CLI jobs or a recoverable PHP sandbox. The bundled official MCP Adapter is a pinned 0.7.0 prerelease. PHP runs in the WordPress request and isn’t isolated from the site.

Start With a Development Site

Connect your agent, check what it can read and enable more tools when your task needs them.

Site Agent is free and open source. Access starts disabled.