74
/ 100
1 month ago
glama

MCP WordPress Server

Enables comprehensive WordPress site management through natural language in Claude Desktop, supporting multiple sites with 59 tools for content creation, media management, user administration, and performance monitoring.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 1 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 9 credentials: GOOGLE_CLIENT_SECRET, GOOGLE_REFRESH_TOKEN, NPM_TOKEN, WORDPRESS_API_KEY, WORDPRESS_APP_PASSWORD, WORDPRESS_JWT_PASSWORD, WORDPRESS_JWT_SECRET, WORDPRESS_PASSWORD, WP_APP_PASSWORD
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

highform-data@4.0.5GHSA-hmw2-7cc7-3qxx

form-data: CRLF injection in form-data via unescaped multipart field names and filenames

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configALLOW_PRIVATE_URLS
configBASELINE_FILE
configCACHE_DISABLED
configCACHE_MAX_ITEMS
configCACHE_MAX_MEMORY_MB
configCACHE_TTL
configCOVERAGE_MIN_BRANCHES
configCOVERAGE_MIN_FUNCTIONS
configCOVERAGE_MIN_LINES
configCOVERAGE_MIN_STATEMENTS
configCOVERAGE_PHASE
configCOVERAGE_STRICT
configCOVERAGE_TOLERANCE
configDISABLE_CACHE
configGITHUB_ACTIONS
configGITHUB_SHA
configGOOGLE_CLIENT_IDxxx GOOGLE_CLIENT_SECRET=yyy node scripts/google-auth.mjs
🔐 secretGOOGLE_CLIENT_SECRETGOOGLE_CLIENT_ID=xxx =yyy node scripts/google-auth.mjs
🔐 secretGOOGLE_REFRESH_TOKEN1//your-refresh-token
configJSON_OUTPUT
configLEGACY_ERROR_LOGS
configLOG_LEVEL
configMCP_UPLOAD_BASE_DIR
🔐 secretNPM_TOKEN
configPERFORMANCE_TEST
configPORT
configRATE_LIMIT
configRATE_LIMIT_ENABLED
configRATE_LIMIT_REQUESTS
configRATE_LIMIT_WINDOW
configSECURITY_STRICT_MODE
configSEO_BULK_OPERATION_SIZE
configSEO_CACHE_ANALYSIS_TTL
configSEO_CACHE_AUDIT_TTL
configSEO_CACHE_KEYWORDS_TTL
configSEO_CACHE_SCHEMA_TTL
configSEO_DESCRIPTION_MAX_LENGTH
configSEO_DESCRIPTION_MIN_LENGTH
configSEO_ENABLED
configSEO_MAX_CONCURRENT_ANALYSIS
configSEO_MAX_KEYWORD_DENSITY
configSEO_MIN_READABILITY_SCORE
configSEO_MIN_WORD_COUNT
configSEO_PROVIDER_AHREFS
configSEO_PROVIDER_DATAFORSEO
configSEO_PROVIDER_SEARCH_CONSOLE
configSEO_RATE_LIMIT_PER_MINUTE
configSEO_TARGET_KEYWORD_DENSITY
configSEO_TITLE_MAX_LENGTH
configSKIP_PACT_TESTS
configTRAVIS
🔐 secretWORDPRESS_API_KEY
🔐 secretWORDPRESS_APP_PASSWORDxxxx xxxx xxxx xxxx xxxx xxxx
configWORDPRESS_APP_PASSWORD_2
configWORDPRESS_AUTH_METHODapp-password
configWORDPRESS_COOKIE_NONCE
🔐 secretWORDPRESS_JWT_PASSWORD
🔐 secretWORDPRESS_JWT_SECRET
configWORDPRESS_MAX_RETRIES
🔐 secretWORDPRESS_PASSWORD"": "user-password",
configWORDPRESS_SITE_URL"": "https://myblog.com",
configWORDPRESS_SITE_URL_2
configWORDPRESS_TIMEOUT
configWORDPRESS_USERNAME"": "admin",
configWORDPRESS_USERNAME_2
configWP_USER
🔐 secretWP_APP_PASSWORD
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/docdyhr-mcp-wordpress-tbiq6b)](https://m8ven.ai/mcp/docdyhr-mcp-wordpress-tbiq6b)
commit: c325b5ebeb8a3e12220df8784944cd76a8b7a9bc
code hash: abd1e6492ee06a6bae7e5aacbe29060585e9a389862deb194883c6945a4dde44
verified: 6/18/2026, 11:52:56 AM
view raw JSON →