0
/ 100
1 month ago
glama

TanukiMCP

A comprehensive MCP server for WordPress automation that enables users to manage content, themes, and site configurations using AI-driven workflows and the WordPress REST API. It provides a wide array of tools for site planning, management, and optimization compatible with tools like Cursor and Claude.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: WP_APP_PASSWORD. We can’t prove the destination matches the brand the credential belongs to.
🚨
Known vulnerabilities in dependencies: 1 critical, 14 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 6 credentials: ENCRYPTION_KEY, OPENAI_API_KEY, REQUIRE_API_KEY, TANUKIMCP_MASTER_KEY, WP_APP_PASSWORD, WP_MAIN_PASSWORD
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical14 high15 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalform-data@4.0.0GHSA-fjxv-7rqg-78g4

form-data uses unsafe random function in form-data for choosing boundary

highaxios@1.6.2GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

highaxios@1.6.2GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

highaxios@1.6.2GHSA-43fc-jf86-j433

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

highaxios@1.6.2GHSA-4hjh-wcwx-xvwj

Axios is vulnerable to DoS attack through lack of data size check

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configANALYSIS_CACHE_TTL
configANALYTICS_DETAILED_LOGGING
configANALYTICS_SAVE_INTERVAL_MS
configAPI_KEY_CACHE_TTL
configCLEANUP_INTERVAL_MS
configCONNECTION_TIMEOUT
configCONTEXT_CACHE_TTL
configCORS_ALLOW_HEADERSContent-Type,Authorization,Accept,Origin,X-Requested-With,X-Api-Key
configCORS_ALLOW_METHODSGET,HEAD,PUT,PATCH,POST,DELETE,OPTIONS
configCORS_ALLOW_ORIGIN(allows requests from any origin)
configDEFAULT_BATCH_SIZE
configDEFAULT_BUFFER_SIZE
configDEFAULT_CONCURRENCY
configDEFAULT_PAGE_SIZE
configENABLE_STREAM_COMPRESSION
🔐 secretENCRYPTION_KEY
configHEADLESStrue (optional, for browser automation)
configLOG_LEVEL
configMAX_API_CONNECTIONS
configMAX_BROWSER_CONNECTIONS
configMAX_CONCURRENT_API_REQUESTS
configMAX_CONCURRENT_BROWSER_REQUESTS
configMCP_PROTOCOL_VERSION
configOPENAI_ADVANCED_MODEL
🔐 secretOPENAI_API_KEYyour_openai_api_key
configOPENAI_BASIC_MODELgpt-4.1-mini
configOPENAI_MAX_CONTEXT_TOKENS
configOPENAI_MAX_TOKENS
configOPENAI_MODEL
configOPENAI_NANO_MODELgpt-4.1-nano
configOPENAI_TEMPERATURE
configPORT3001 (optional, defaults to 3001)
configRATE_LIMIT_MAX_REQUESTS
configRATE_LIMIT_WINDOW_MS
🔐 secretREQUIRE_API_KEYtrue (recommended for production)
configRESOURCE_MAX_OPERATIONS
configRESOURCE_SAMPLING_INTERVAL_MS
configRESOURCE_SAVE_INTERVAL_MS
configRESOURCE_THRESHOLD_CPU
configRESOURCE_THRESHOLD_MEMORY
configRESOURCE_THRESHOLD_OPERATION_TIME
configRESOURCE_THRESHOLD_RESPONSE_TIME
configRESOURCE_TRACKING_ENABLED
configSLOWMO
🔐 secretTANUKIMCP_MASTER_KEYyour_master_api_key
🔐 secretWP_APP_PASSWORD
🔐 secretWP_MAIN_PASSWORD
configWP_SITE_URL
configWP_USERNAME
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/applejax2-wordpress-mcp-1qt8yr)](https://m8ven.ai/mcp/applejax2-wordpress-mcp-1qt8yr)
commit: 5fc418c7fc25f713822aa4eac16c08a1d121e44a
code hash: dbc675de19067d330efd4ccdf08c55617a4b13a03ffa4a199e626252f50ae5b5
verified: 6/12/2026, 11:15:08 AM
view raw JSON →