Woocommerce Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Woocommerce Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A small, read-only Model Context Protocol server for WordPress + WooCommerce. It lets Claude (or any MCP client) answer questions about a live store — products, orders, sales, and blog posts — over the official REST APIs. No writes, no plugins to install on the store: it talks to the existing WordPress/WooCommerce REST endpoints.
Built and maintained by WPPoland — senior WordPress & WooCommerce engineering.
| Tool | What it does | Needs WooCommerce keys |
|---|---|---|
list_products | List / search products (name, sku, price, stock, permalink) | yes |
get_product | Full details for one product by id | yes |
list_orders | Recent orders, newest first, optional status filter | yes |
sales_report | Sales totals for a period (week / month / last_month / year) | yes |
search_posts | Search published blog posts (public WP REST API) | no |
Everything is read-only. The server never creates, edits, or deletes anything in the store.
git clone https://github.com/wppoland/woocommerce-mcp.git
cd woocommerce-mcp
npm install
npm run buildSet three environment variables:
| Var | Required | Example |
|---|---|---|
WP_URL | yes | https://shop.example.com |
WC_CONSUMER_KEY | for wc_* tools | ck_xxx |
WC_CONSUMER_SECRET | for wc_* tools | cs_xxx |
Create the WooCommerce keys in WooCommerce → Settings → Advanced → REST API → Add key with Read permission. search_posts works without keys against any public WordPress site.
The keys are sent to your own store over HTTPS as REST query auth. Use HTTPS, and give the key Read access only.
Add to your MCP client config (e.g. claude_desktop_config.json):
{
"mcpServers": {
"woocommerce": {
"command": "node",
"args": ["/absolute/path/to/woocommerce-mcp/dist/index.js"],
"env": {
"WP_URL": "https://shop.example.com",
"WC_CONSUMER_KEY": "ck_xxx",
"WC_CONSUMER_SECRET": "cs_xxx"
}
}
}
}Then ask things like "What were last month's WooCommerce sales?" or "List the 5 most recent orders that are on hold."
npm run check # builds, then asserts all five tools register (no network/credentials needed)fetch).MIT © WPPoland
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.