by wppilot-labs
WordPress MCP server with free Elementor MCP editing. 133 typed abilities for Elementor, posts, pages, Gutenberg, media, menus and themes, with OAuth 2.1, safety profiles and rollback. Pro adds 1,042 builder-aware abilities: Elementor, Bricks, Divi, Oxygen, Beaver Builder, Etch, WPBakery and WooCommerce MCP.
# Add to your Claude Code skills
git clone https://github.com/wppilot-labs/wordpress-mcp-elementor-wppilotGuides for using mcp servers skills like wordpress-mcp-elementor-wppilot.
Last scanned: 8/27/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@opentelemetry/core: OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@opentelemetry/instrumentation-amqplib: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@opentelemetry/instrumentation-connect: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@opentelemetry/instrumentation-express: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@opentelemetry/instrumentation-fs: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@opentelemetry/instrumentation-hapi: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@opentelemetry/instrumentation-http: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@opentelemetry/instrumentation-koa: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@opentelemetry/instrumentation-mongoose: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@opentelemetry/instrumentation-mysql2: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@opentelemetry/instrumentation-pg: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@opentelemetry/instrumentation-undici: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@opentelemetry/resources: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@opentelemetry/sdk-trace-base: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@opentelemetry/sql-common: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@pmmmwh/react-refresh-webpack-plugin: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@puppeteer/browsers: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@sentry/node: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@wordpress/scripts: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "copy-webpack-plugin: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "extract-zip: extract-zip unvalidated symlink path traversal",
"severity": "high"
},
{
"type": "npm-audit",
"message": "lighthouse: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "linkify-it: LinkifyIt#match scan loop has quadratic algorithmic complexity",
"severity": "high"
},
{
"type": "npm-audit",
"message": "markdown-it: markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations",
"severity": "high"
},
{
"type": "npm-audit",
"message": "markdownlint: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "markdownlint-cli: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
"severity": "high"
},
{
"type": "npm-audit",
"message": "puppeteer-core: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "serialize-javascript: Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()",
"severity": "high"
},
{
"type": "npm-audit",
"message": "sockjs: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "webpack-dev-server: Vulnerability found",
"severity": "medium"
}
],
"status": "WARNING",
"scannedAt": "2026-08-27T15:04:20.199Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}wordpress-mcp-elementor-wppilot is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by wppilot-labs. WordPress MCP server with free Elementor MCP editing. 133 typed abilities for Elementor, posts, pages, Gutenberg, media, menus and themes, with OAuth 2.1, safety profiles and rollback. Pro adds 1,042 builder-aware abilities: Elementor, Bricks, Divi, Oxygen, Beaver Builder, Etch, WPBakery and WooCommerce MCP. It has 67 GitHub stars.
wordpress-mcp-elementor-wppilot returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/wppilot-labs/wordpress-mcp-elementor-wppilot" and add it to your Claude Code skills directory (see the Installation section above).
wordpress-mcp-elementor-wppilot is primarily written in PHP. It is open-source under wppilot-labs on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh wordpress-mcp-elementor-wppilot against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
Based on votes and bookmarks from developers who liked this skill
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Point Claude Code, Codex, Cursor or Antigravity at your WordPress site and let it build, pages, Elementor layouts, block content, menus, taxonomies, media, SEO metadata, through typed abilities your permissions still govern.
Installs straight into Plugins - Add New - Upload Plugin. That link always resolves to the newest release, so it does not go stale. Older versions are on the releases page. GitHub's own Source code (zip) is not installable: it has no vendor/ and uses a versioned folder name.
WPPilot turns your WordPress site into an MCP server, built on the WordPress Abilities API and the official WordPress MCP Adapter. AI clients discover, inspect and execute typed WordPress abilities through a compact three-tool interface instead of loading hundreds of one-off endpoints into context.
The free plugin is the WordPress MCP server, and since 1.10.0 it is also a working Elementor MCP server: 16 abilities that read an Elementor document, report the widgets and style properties your install actually offers, and add, edit, move, duplicate, reorder and delete elements in the tree. No licence, no key, no Pro install. WPPilot Pro then extends that same endpoint into a WooCommerce MCP server and a Bricks, Divi, Oxygen, Etch or WPBakery MCP server, and adds Elementor's authoring layer on top: whole-page composition, templates and theme parts, popups, forms, dynamic tags, global classes and variables.
This is it, with one server instead of one per plugin. Elementor editing is free, in this repository, and needs nothing else installed — see Elementor MCP in the free plugin. WPPilot Pro adds the builder-aware layer on top of the same endpoint, so an agent that connects once can work in whichever editor the site actually uses:
Elementor MCP · Bricks MCP · Divi MCP · Beaver Builder MCP · Oxygen MCP · Breakdance MCP · WPBakery MCP · Etch MCP · Mosaic MCP
Beyond page builders, Pro also covers WooCommerce, Advanced Custom Fields, Meta Box, JetEngine, Pods, ACPT, WPForms, Gravity Forms, Fluent Forms, Formidable, Contact Form 7, Ninja Forms, Yoast SEO, Rank Math, AIOSEO, SEOPress, WPML, Polylang, Weglot, The Events Calendar, Tutor LMS, Paid Memberships Pro and BuddyPress. Full table below: 51 integrations.
WPPilot serves both protocol revisions during the migration window:
| Revision | State | How it is served |
|---|---|---|
2026-07-28 |
Stateless. No initialize, no session. Each request carries its version and client capabilities in _meta. |
includes/mcp/, dispatched ahead of the adapter |
2025-11-25 |
Legacy. initialize handshake and Mcp-Session-Id sessions. |
The bundled MCP Adapter, unchanged |
A request is served under the modern revision only when it carries modern per-request _meta; everything else reaches the adapter untouched. Existing users do not need to reconnect unless their client requires the newer revision.
server/discover is implemented and advertises both versions plus the capabilities actually registered on the site. Subscriptions, the tasks extension and logging are deliberately not advertised, WPPilot has no change-notification producer, so subscriptions/listen is not implemented.
For OAuth, Client ID Metadata Documents are the preferred registration mechanism; RFC 7591 Dynamic Client Registration remains available as a compatibility fallback. Application Passwords and access tokens stay independent fallbacks for clients that run no OAuth flow.
It is a control layer, not an AI wrapper. No AI model is bundled: external MCP clients bring their own model access, and policy is enforced server-side on your install.
One prompt from you becomes hundreds of typed calls from the agent, each checked against your WordPress capabilities and the active safety profile before it runs.
Free covers the core surface: posts and pages, block-editor content, Elementor documents, taxonomies, menus and menu locations, media with alt text, users, site settings including the front page, plus design documents, skills and a change ledger with rollback.
You do not have to phrase anything in a particular way. A client's first call is discovery, and WPPilot answers with every ability registered on your install plus a catalogue of the skills available for them, carrying one instruction: if a skill matches the request, load its full instructions before starting the work. So "rebuild the pricing page and keep our spacing" already pulls in the right build skill, the element schemas and your existing design tokens without you naming any of it. Write your own prompts; the routing is on the site.
The library is a shortcut, not a dependency. WPPilot ships a prompt library in wp-admin: ten complete landing-page briefs, one per industry, because "build me a bakery site" and "build me a law firm site" should not produce the same page. Each brief fixes a flat palette, a type pairing, a design signature that makes the page its own, the sections it must communicate, and the facts to use verbatim, then closes with one shared standards block: WCAG 2.1 AA, real photography in every slot, one SVG icon set, builder-native construction, and no half-built pages. Pick Elementor or the block editor on the screen and the brief is written for it.
WPPilot Pro adds plugin-aware modules, page builders, WooCommerce, forms, custom fields, SEO, themes, each with its own ability chains.
wppilot.zip and install it as wp-content/plugins/wppilot, or upload it in Plugins - Add New - Upload Plugin.
A GitHub “Source code (zip)” download is not installable, it lacks vendor/ and uses the wrong folder name.Canonical MCP endpoint:
https://example.com/wp-json/mcp/wppilot
OAuth-authenticated clients use /wp-json/mcp/wppilot-oauth. Application passwords and access tokens both authenticate on the canonical route. The older /wp-json/mcp/mcp-adapter-default-server route still resolves as a legacy alias, but new configurations should use the canonical path above.
Claude Code · Claude Desktop · Claude on the web · Codex CLI · Codex desktop app · Cursor · VS Code · GitHub Copilot · Devin Desktop (formerly Windsurf) · Factory Droid · Antigravity CLI · Antigravity IDE · Zed · Cline · Roo Code · Kilo Code · Amazon Q · OpenCode · OpenClaw · Manus
Per-client setup guides: https://wppilot.co/wordpress-mcp
Three methods, chosen on WPPilot → Connect:
Authorization: Bearer wpp_… credential for callers with no browser and no interactive session: the Claude Messages API MCP connector, the OpenAI Responses API mcp tool, cron jobs, automation platforms, curl. Created with an optional expiry, shown once, stored only as a SHA-256 digest, and revocable per token. It authenticates on the canonical /wp-json/mcp/wppilot endpoint, so the URL is the same one every other snippet uses.An access token borrows the capabilities of the user who created it, and that check is re-run on every request rather than frozen at creation — demoting or deleting the user closes the token in the same moment.
None of the three is a product licence. WPPilot needs no activation key, entitlement check or subscription service to run.
| Profile | What it allows |
|---|---|
| Read Only | Discovery and inspection. Every state-changing ability is blocked. |
| Production Safe | Normal content, design, SEO, forms and commerce work, plus plugin activation and updates with confirmation. Blocks r |