BOSSCORE MCP PACK (bosserpnext/bosscore-mcp-pack) is an MCP server listed on the M8ven Trust Index. M8ven graded this before, but the code is no longer public at the location we read it, so we cannot re-check it. No publisher has claimed this listing.
Modular MCP capabilities package for the BOSS ecosystem, enabling WordPress site management, file reading, and cPanel deployment with 63 tools across three profiles (wordpress, files, full) and two transport modes (stdio and HTTP/SSE).
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
bosserpnext
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
wp_list_pagesList all WordPress pages
wp_get_pageGet a page by ID with content and meta
wp_create_pageCreate a new WordPress page
wp_update_pageUpdate a page: title, content, status, or meta
wp_delete_pageDelete a page permanently
wp_list_postsList WordPress blog posts
wp_get_postGet a blog post by ID
wp_create_postCreate a new blog post
wp_update_postUpdate a blog post
wp_delete_postDelete a blog post permanently
wp_list_mediaList media library items
wp_get_mediaGet media item by ID with URLs
wp_upload_mediaUpload media from a public URL
wp_update_mediaUpdate media metadata (title, alt text, caption)
wp_delete_mediaDelete a media item permanently
wp_list_usersList users (may require elevated permissions)
wp_get_userGet user by ID
wp_get_user_meGet current authenticated user info
wp_create_userCreate a new WordPress user
wp_update_userUpdate a user (name, email, password, roles)
wp_delete_userDelete a user, reassigning content to another user
wp_list_commentsList recent comments, optionally filtered by post
wp_create_commentCreate a new comment on a post
wp_update_commentModerate a comment (approve/trash/spam)
wp_list_categoriesList all categories
wp_create_categoryCreate a new category
wp_update_categoryUpdate a category name or description
wp_delete_categoryDelete a category permanently
wp_list_tagsList all tags
wp_create_tagCreate a new tag
wp_list_menusList navigation menus
wp_get_menuGet a navigation menu by ID
wp_create_menuCreate a new navigation menu
wp_get_menu_itemsGet items for a menu
wp_create_menu_itemAdd item to a menu
wp_get_menu_locationsGet all menu locations and their assigned menus
wp_get_settingsGet site settings (title, description, timezone, etc.)
wp_update_settingsUpdate site settings
wp_get_site_infoGet WordPress site info: version, routes, namespaces
wp_list_blocksList reusable blocks/patterns
wp_get_blockGet a reusable block by ID with content
wp_create_blockCreate a reusable block
wp_update_blockUpdate a reusable block content
wp_searchSearch posts, pages, and other content by query
wp_list_themesList themes (active + available)
wp_astra_get_settingsGet all Astra theme settings (header, footer, colors, typography)
wp_astra_update_settingsUpdate Astra theme settings. Use merge=true (default) to merge, false to replace.
wp_astra_set_menu_locationAssign a menu to an Astra header/footer location
wp_astra_get_settingGet a single Astra setting by key name (e.g. header-button1-text)
wp_astra_get_header_builderGet the current header builder layout - slot assignments for desktop and mobile
wp_astra_set_header_itemSet component(s) in a header slot. e.g. area=desktop, section=primary, slot=primary_right, items=["button-1"]
wp_astra_configure_buttonBatch-configure a header button: text, link, colors, radius, size.
wp_astra_configure_accountConfigure the Astra account widget - shows login link when logged out, profile link when logged in.
wp_raw_requestMake any authenticated WP REST API request. endpoint=/wp/v2/pages or full URL
wp_get_rest_indexGet the WP REST API index (all available routes)
file_reader_read_fileRead any file: PDF, DOCX, PPTX, XLSX, images, audio, text, CSV, HTML, Markdown. Auto-detect format.
file_reader_read_imageRead an image file and return base64 data with MIME type
file_reader_convert_to_markdownConvert any document (PDF, DOCX, PPTX, XLSX, HTML) to clean markdown text
file_reader_list_directoryList files and subdirectories in a directory
file_reader_get_file_infoGet metadata about a file (size, type, modified date)
file_reader_search_in_fileSearch for a pattern in a file's content (supports PDF, DOCX, etc.)
boss_deployDeploie le code BOSS sur cPanel (git pull + rsync). repo: bosscore (plugin), telet (theme), ou all (les deux).
BOSSCORE_MCP_SERVER_URLBOSSCORE_MCP_ENFORCE_AUTHEn production, activer =1.BOSSCORE_MCP_PROFILEBOSSCORE_WORKSPACE$env: = "H:\...\companies"DEPLOY_TOKEN$env: = "..."DEPLOY_URLBOSSCORE_MCP_STORE_DIR1. doit pointer vers un répertoire persistant etBOSSCORE_MCP_ALLOWED_ORIGINSBOSSCORE_MCP_ACCESS_TOKEN_TTLBOSSCORE_MCP_REFRESH_TOKEN_TTLBOSSCORE_MCP_AUTH_CODE_TTLBOSSCORE_MCP_OAUTH_STOREBOSSCORE_MCP_OAUTH_CLIENT_IDBOSSCORE_MCP_OAUTH_CLIENT_SECRETBOSSCORE_MCP_OAUTH_REDIRECT_URISBOSSCORE_MCP_OAUTH_SCOPESBOSSCORE_PLAN_STORE_LOCK_TIMEOUTBOSSCORE_DEPLOY_PLAN_TTL2. vaut 1800 secondes par défaut.WORDPRESS_URL$env: = "https://core.bosserpnext.com"BOSSCORE_EXEC_ALLOWED_PATHSBOSSCORE_EXEC_MAX_OUTPUTBOSSCORE_EXEC_TIMEOUTBOSSCORE_EXEC_PLAN_TTLBOSSCORE_FILE_ROOTSWORDPRESS_USERNAME$env: = "boss"WORDPRESS_APP_PASSWORD$env: = "..."BOSSCORE_MAX_FILE_BYTESBOSSCORE_MAX_OUTPUT_CHARSOLLAMA_URLTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
62/62 tools missing one or more hints — wp_list_pages (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); wp_get_page (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); wp_create_page (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +59 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
License file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Tests exist
No test files found
Add tests that exercise each declared tool.
Shell command execution
1 child_process call — runs shell commands
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/bosserpnext/bosscore-mcp-pack)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check