A WordPress MCP server lets an AI client like Claude, Cursor, or Codex work on your site directly: read posts, check plugins, write drafts, fix SEO. In 2026 there are a dozen ways to get one, and they differ more than the “300+ tools” headlines suggest. Some run inside WordPress, some run on your laptop, one only works on a single host, and one will happily run arbitrary PHP on your server.
We compared ten by what matters when you hand an AI the keys: how it signs in, what it can change, what it costs, and how you undo a mistake. We make PressBot, so it’s on the list, and we say where the others do better.
Checked September 24, 2026 on each project’s WordPress.org page, GitHub repository, or pricing page. Tool counts are the vendors’ own. Every project counts “tools” differently, so compare them loosely.
The Short Version
- The official standard: WordPress MCP Adapter
- Your site is on WordPress.com: WordPress.com MCP
- Free MCP with write tools, inside a popular AI plugin: AI Engine
- Free and the most tools with an undo: Royal MCP
- Per-role tool permissions for a team: miniOrange Secure MCP Server
- Page builders (Elementor, Divi, and others): Respira
- One MCP server for several sites, from your laptop: InstaWP mcp-wp
- The same tools in your editor, your dashboard, and Telegram: PressBot
All Ten Compared
| Server | Price | Tools (vendor count) | Sign-in | Runs |
|---|---|---|---|---|
| WordPress MCP Adapter | Free | Whatever abilities your plugins expose | Application Passwords | Plugin (GitHub), HTTP or WP-CLI |
| WordPress.com MCP | Included with paid WordPress.com plans | Reads plus 19 write abilities | OAuth 2.1 | Hosted by WordPress.com |
| AI Engine | Free; Pro $79/yr adds more tools | 50+ | OAuth or bearer token | Plugin, HTTP |
| Royal MCP | Free; Pro from $99/yr | 200+ | OAuth 2.0, API key, or bearer token | Plugin, HTTP |
| miniOrange Secure MCP Server | Free (100 requests/day); paid from $79/yr | 300+ | OAuth 2.1 (self-hosted) | Plugin, HTTP |
| Easy MCP AI | Free | 200+ | OAuth 2.1 or API token | Plugin, HTTP |
| PressBot | Free (read-only); Pro $29/yr | 11 free, 115 Pro | Application Passwords | Plugin, HTTP |
| Respira | From €71/yr | 240+ | API key or OAuth | Plugin plus a local package or HTTP |
| InstaWP mcp-wp | Free, open source | ~40–50, by category | Application Passwords | On your computer (npx) |
| Novamira | Free, open source | PHP, WP-CLI, database, files | Application Passwords or OAuth | Plugin |
1. WordPress MCP Adapter (official)
The MCP Adapter is WordPress’s own answer, built on the Abilities API that landed in WordPress 6.9. Plugins register “abilities” (actions with a schema and a permission check), and the adapter serves them to MCP clients over HTTP at /wp-json/mcp/mcp-adapter-default-server, or over WP-CLI with wp mcp-adapter serve.
Clients see three meta-tools, mcp-adapter/discover-abilities, get-ability-info, and execute-ability, and reach every ability through them. Abilities are private until a plugin marks them public for MCP, so what you can do depends entirely on which of your plugins register public abilities. Core itself only ships a few read-only ones, like site and environment info. The latest release is v0.6.1 (August 2026). It installs from GitHub or Composer and isn’t on WordPress.org. A helper plugin, Enable Abilities for MCP, lets you choose which abilities are exposed.
Pick it if you’re a developer who wants the standard route and you’re registering your own abilities. Skip it if you want a big set of admin tools today. It’s plumbing, not a toolbox.
2. WordPress.com MCP
If your site is on WordPress.com, this is built in. Connect https://public-api.wordpress.com/wpcom/v2/mcp/v1 to your client and sign in with your WordPress.com account over OAuth. Since March 2026 it can write too: 19 abilities across posts, pages, comments, categories, tags, and media. It asks for your confirmation before each change. It’s included on all paid plans, and self-hosted sites get it through Jetpack AI or Jetpack Complete.
Pick it if you’re on WordPress.com. Skip it if you need plugins, WooCommerce, or SEO tools; it covers content, not site operations.
3. AI Engine
AI Engine by Meow Apps (90,000+ active installs) is an AI toolkit for chatbots and content generation that also ships an MCP server with 50+ tools in the free version. It uses Streamable HTTP, and desktop clients can sign in with OAuth or a bearer token. Pro ($79/yr for one site) adds tools for plugins, themes, the database, WooCommerce, WPML, and Polylang.
Pick it if you want free MCP writes from a large, actively maintained plugin you might use anyway. Skip it if you want a small plugin that only does MCP.
4. Royal MCP
Royal MCP (10,000+ installs) is free on WordPress.org and claims 200+ tools: 85 for WordPress core plus 124 for integrations. It signs in with OAuth 2.0 with PKCE, an API key, or a bearer token. Its standout is an undo: destructive operations return a token that reverses them for 72 hours (longer on Pro). Pro starts at $99/yr for one site.
Pick it if you want a large free tool set with a safety net. Skip it if you’d rather not manage another sign-in system on top of WordPress.
5. miniOrange Secure MCP Server
miniOrange’s server (4,000+ installs) leans on security and administration: a self-hosted OAuth 2.1 server, and role-based access so each WordPress role gets its own set of the 300+ tools. The free tier allows 100 requests a day, and miniOrange’s MCP pricing page lists paid plans from $79/yr (early-bird).
Pick it if several people or agents need different permissions. Skip it if you’re one person running one site; the policy layer is overhead.
6. Easy MCP AI
Easy MCP AI (10,000+ installs) is a free plugin that turns a site into an MCP server with OAuth 2.1 and hashed API tokens. Its WordPress.org page claims 244 tools and its GitHub README says 214. Either way, it’s a big free catalog.
Pick it if you want a free, MCP-only plugin with a wide tool list.
7. PressBot
PressBot is a WordPress AI plugin (visitor chatbot, admin agent, Telegram bot) whose tools are also served over MCP at /wp-json/pressbot/v1/mcp. It signs in with WordPress Application Passwords, so there’s no extra OAuth server, and only administrators can connect. The free plugin exposes 11 read-only tools: posts, plugins, comments, chatbot conversations, knowledge search, and five site-health checks. Pro ($29/yr for one site) exposes all 115 tools, including content, plugins, WooCommerce, Yoast, ACF, Google Analytics, Search Console, and security.
What’s different: the same tools run in the WordPress dashboard agent and the Telegram bot, with the same permission checks, and your knowledge base entries are available to MCP clients as resources. Destructive tools are flagged so your client asks before running them. For bulk SEO and content changes, the agent can prepare a reviewable plan with before-and-after values that you can restore later.
Where others do better: the free version is read-only, so AI Engine, Royal MCP, and Easy MCP AI give you more for free. It has fewer tools than the 200+ catalogs. And it doesn’t use the Abilities API for MCP (Pro registers a few abilities, but its MCP server is its own). Setup is in our Cursor and Claude Code tutorial.
Pick it if you want one set of tools across your editor, wp-admin, and your phone, at the lowest paid price here.
8. Respira
Respira is paid (from €71/yr for one site, with a 7-day trial) and built around page builders: it supports 17, including Elementor and Divi. It keeps a snapshot before each change and lets you undo for 90 days. It claims 240+ core tools, though its own pages give several different totals.
Pick it if your AI work is mostly editing page-builder layouts.
9. InstaWP mcp-wp
mcp-wp is open source and runs on your computer (npx -y @instawp/mcp-wp), talking to your site’s REST API with an Application Password. One process can manage several sites. InstaWP’s separate hosted product, InstaMCP, only works for sites hosted on InstaWP.
Pick it if you want nothing installed on the site and you’re comfortable with Node on your laptop.
10. Novamira
Novamira (open source, AGPL) gives an AI agent raw power: it runs PHP with database access, runs WP-CLI, queries the database, and edits files. Its own README says it’s for development and staging, “with backups.”
Pick it if you’re building a site locally with an AI pair programmer. Never point it at production.
Avoid: Automattic/wordpress-mcp
Older tutorials still point to Automattic/wordpress-mcp. It was deprecated and archived on September 17, 2026, and the repository sends users to the MCP Adapter. Don’t start a new project on it.
What to Check Before You Connect Any of Them
- Sign-in you can revoke. Application Passwords, OAuth, and API tokens can all be revoked per client. Never paste your main WordPress password into a config file.
- Who can connect. Does the server respect WordPress roles, or does every token act as an admin?
- Destructive tools are marked. Your client can only ask before deleting something if the server says the tool deletes things.
- A way back. Undo tokens (Royal MCP), snapshots (Respira), reviewable plans (PressBot), or at minimum a backup.
- No code execution on production. A tool that runs arbitrary PHP or SQL can do anything, including things you didn’t ask for.
FAQ
Does WordPress have a built-in MCP server?
Not in core. WordPress 6.9 added the Abilities API that MCP servers build on, and the official MCP Adapter is a separate plugin. WordPress.com sites have a hosted MCP server built in.
What’s the best free WordPress MCP server?
For free write access, AI Engine, Royal MCP, and Easy MCP AI all include writing tools in their free versions. For a read-only connection with health checks, PressBot’s free server is enough. For the standard approach, use the MCP Adapter with plugins that register abilities.
Can I run more than one MCP server on a site?
Yes. They use different endpoints, so the adapter, PressBot, and another plugin can run side by side. Add each one to your client under its own name, and don’t give an agent more tools than the job needs.
Which AI clients work with WordPress MCP servers?
Any client that supports remote MCP servers: Claude Code, Cursor, Codex, VS Code, and Claude through custom connectors. Servers that sign in with OAuth are the easiest to add to Claude’s web and desktop apps; servers that use Application Passwords need a custom header, which editors like Claude Code and Cursor support directly.