Wpwriter Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Wpwriter Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<!-- mcp-name: com.wpwriter/wordpress -->
WordPress MCP server. Connect your self-hosted WordPress site to AI assistants (Claude, ChatGPT, Cursor, VS Code / GitHub Copilot, Gemini, and any MCP client) and run the full content loop: generate SEO-optimized posts and pages, edit and patch existing content, create AI featured and inline images, manage media, categories, tags and menus, manage WooCommerce products, run autoblogging, and track SEO and Search Console rankings — all on your own site, with your own credentials.
WPWriter is a Model Context Protocol (MCP) server for WordPress. 163 tools across 33 categories. Remote Streamable HTTP with OAuth 2.0 (keyless) or a wpw_ API key.https://mcp.wpwriter.com/mcpWPWriter is a remote MCP server — no install, no local process. Point your client at the endpoint and authenticate.
https://mcp.wpwriter.com/mcp (Streamable HTTP)wpw_ Bearer API key from your WPWriter dashboard.
{
"mcpServers": {
"wpwriter": {
"url": "https://mcp.wpwriter.com/mcp"
}
}
}OAuth runs automatically on first connect. To use an API key instead:
{
"mcpServers": {
"wpwriter": {
"url": "https://mcp.wpwriter.com/mcp",
"headers": { "Authorization": "Bearer wpw_YOUR_KEY" }
}
}
}One-click: [Add to Cursor](https://www.wpwriter.com/docs/mcp) (deeplink on the docs page), or add the url above in Cursor's MCP settings.
Extensions view → @mcp → search WordPress / WPWriter, or add the remote url in your MCP config. (Listing in progress.)
Full per-client instructions: https://www.wpwriter.com/docs/mcp
| Area | Example tools |
|---|---|
| Content generation | generate_content, improve_content, create_post, replace_post_content, patch_post_content |
| Posts & pages | list_posts, list_pages, publish_post, schedule_post, update_post_title, update_post_excerpt |
| SEO | get_seo_scores, update_post_seo, generate_meta_description, get_posts_seo_overview |
| Search Console / rankings | get_post_rankings, get_ranking_history, get_search_insights, sync_rankings |
| AI images & media | generate_image, generate_featured_image, upload_media, optimize_media, update_media_alt_text |
| Autoblogging / automation | autoblog_configure, autoblog_trigger_run, automation_status, get_automation_queue |
| Taxonomies & menus | create_category, create_tag, list_categories, create_menu, add_menu_item |
| WooCommerce | search_products, get_product, update_product, update_product_category |
| Site config & management | get_site_settings, update_site_settings, set_homepage, install_plugin, install_theme |
| Editorial & analytics | get_editorial_calendar, suggest_internal_links, find_broken_links, get_content_analytics |
Read operations are read-only; destructive operations require explicit user intent.
WPWriter does not wrap or resell a third-party API. Each user connects their own self-hosted WordPress site with their own credentials (user-owned infrastructure). WPWriter provides the AI content-generation and SEO infrastructure. Credentials are encrypted at rest; OAuth tokens are scoped per user.
https://mcp.wpwriter.com/.well-known/mcp/server-card.jsonMIT — see LICENSE. (This repository hosts the MCP server's public metadata and documentation; the server itself runs at mcp.wpwriter.com.)
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.