{"_id":"@adsim/wordpress-mcp-server","_rev":"19-3979effcbbf63fcbd24be453938fd4a9","name":"@adsim/wordpress-mcp-server","dist-tags":{"latest":"6.2.1"},"versions":{"1.0.0":{"name":"@adsim/wordpress-mcp-server","version":"1.0.0","keywords":["mcp","wordpress","rest-api","claude","anthropic","model-context-protocol","seo","rankmath","yoast","content-management","wp-api"],"author":{"url":"https://adsim.be","name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@1.0.0","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/GeorgesAdSim/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/GeorgesAdSim/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"dist/index.js"},"dist":{"shasum":"8bf3928f848ae7a3b8cdca7a9d6f8a924df2a5b9","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-1.0.0.tgz","fileCount":43,"integrity":"sha512-FdZRmYcyDDkMNkeTemQzZA66Qwl4rJdYI7LhuGeFZnjNG2wqy3n7yC6zIXyuwBaQD4i2j2edfcQuNLuVxMu4Kg==","signatures":[{"sig":"MEYCIQDrYEiwrMCQ+RA0a1/cn/4gFFcaYk3XKnLEJJPmiyWqsAIhAMjSeclSNj0OOePtuBUOeKAGtuw84sh2Cmpv2s5P8wiy","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":119564},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.0.0"},"scripts":{"dev":"tsc --watch","build":"tsc","clean":"rm -rf dist","start":"node dist/index.js","prepublishOnly":"npm run build"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/GeorgesAdSim/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"MCP Server for WordPress REST API — Manage posts, pages, categories, tags, SEO metadata, and more via Claude Desktop or any MCP-compatible client.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"^3.23.0","@modelcontextprotocol/sdk":"^1.12.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_1.0.0_1771320355302_0.9001979021406492","host":"s3://npm-registry-packages-npm-production"}},"3.0.0":{"name":"@adsim/wordpress-mcp-server","version":"3.0.0","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@3.0.0","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/adsimbe/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/adsimbe/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"index.js"},"dist":{"shasum":"218f1b0a768640283754e6e2c9106f66baf60bc6","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-3.0.0.tgz","fileCount":24,"integrity":"sha512-1Cxut99m5SJR4HRbVgJjYQeUoNm8QxtAurLwZJj3nHi4VRsxJ5fCeC3Di3wNVIR8JdWPNvglbbd7yInZEjy9WA==","signatures":[{"sig":"MEUCIDaizuu2r6HfFzrWDNNc2X7hZskHCPkt/9mAlmOPay8JAiEAoFvLYXIUEQnuOJLui4Xcs1QlCq03yudK6G3crOt00LY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":251360},"main":"index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"0867d447c984e757c87d5319fd8b4be806b0376b","scripts":{"test":"vitest run","start":"node index.js","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/adsimbe/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"A Model Context Protocol (MCP) server for WordPress REST API integration. Manage posts, search content, and interact with your WordPress site through any MCP-compatible client.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"node-fetch":"^3.3.2","@modelcontextprotocol/sdk":"^1.26.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_3.0.0_1771519022602_0.3951366858716945","host":"s3://npm-registry-packages-npm-production"}},"3.1.0":{"name":"@adsim/wordpress-mcp-server","version":"3.1.0","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@3.1.0","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/adsimbe/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/adsimbe/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"index.js"},"dist":{"shasum":"1833e5e4454212c889aa9b9deed89a297bb5323d","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-3.1.0.tgz","fileCount":27,"integrity":"sha512-vJorksnxHITiQP9vsM9nfLi/pW2jA4HjMvM1JK1pa2xnxEGY573E0NkYBitW8CmxPxk/SFnf0Hzt3yvWzLpz0A==","signatures":[{"sig":"MEUCIQCoLmYT4Pd71sKaps6Nw1Onysv61Svm3SEqYdVqAHcL9QIgan/a4EeZgoMQzUoTENK0iOIvPQtOorUVi88cPaL+Mcs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":260157},"main":"index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"50117cdba5ea2bc5676ca2cbf8a60b69b8273772","scripts":{"test":"vitest run","start":"node index.js","build:mcpb":"bash dxt/build-mcpb.sh","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/adsimbe/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"A Model Context Protocol (MCP) server for WordPress REST API integration. Manage posts, search content, and interact with your WordPress site through any MCP-compatible client.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"node-fetch":"^3.3.2","@modelcontextprotocol/sdk":"^1.26.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_3.1.0_1771519962628_0.8945757839909141","host":"s3://npm-registry-packages-npm-production"}},"4.4.0":{"name":"@adsim/wordpress-mcp-server","version":"4.4.0","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@4.4.0","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/adsimbe/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/adsimbe/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"index.js"},"dist":{"shasum":"b894de6c8544593421ddb269243ee873ce2ed3ec","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-4.4.0.tgz","fileCount":53,"integrity":"sha512-92VSNP4ia+D3gNkIzD8u1GxWSXpmb8/3zkO6cQT/MF/vLx2qIwGUI5K7/KsjwJPeAu3tui3/QCdpy8fAe7+cjw==","signatures":[{"sig":"MEUCIHXR7jjHmA6PKlqQwNo3Tsud1e+j3SDt2ybYpJhnEkBrAiEAtIDYsueKbHAsvVbZeV2S/edrDGSGl+qmDY6JILzPGt4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":773636},"main":"index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"4792fcb740655355672b0201d57721b457d4931b","scripts":{"test":"vitest run","start":"node index.js","build:mcpb":"bash dxt/build-mcpb.sh","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/adsimbe/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"A Model Context Protocol (MCP) server for WordPress REST API integration. Manage posts, search content, and interact with your WordPress site through any MCP-compatible client.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"node-fetch":"^3.3.2","@modelcontextprotocol/sdk":"^1.26.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_4.4.0_1771700499217_0.8964745101188587","host":"s3://npm-registry-packages-npm-production"}},"4.5.0":{"name":"@adsim/wordpress-mcp-server","version":"4.5.0","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@4.5.0","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/adsimbe/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/adsimbe/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"index.js"},"dist":{"shasum":"44a88f003e5a38509d87c3196495c80e2b4760e4","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-4.5.0.tgz","fileCount":56,"integrity":"sha512-m2WtnfIQGCggr06tslf0NmW+zZo5qbFT1iH8IunSNmVRWo2LeBAaXUqPtF8B+dd0xTMv6TLKPs0rsQVE6IfUeQ==","signatures":[{"sig":"MEUCIQDs3b6wlfIXGujHp/XQdLVXZLX+JA/zpRUa37RVmfVZ2AIgLqRRRZNuXNLxx4Akrt/WxTMtVZpHzu9BNhTQ8Zu4DdY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":849752},"main":"index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"b8cc5d990f1535ff358bf60bd9c2bada769b6a5b","scripts":{"test":"vitest run","start":"node index.js","build:mcpb":"bash dxt/build-mcpb.sh","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/adsimbe/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"A Model Context Protocol (MCP) server for WordPress REST API integration. Manage posts, search content, and interact with your WordPress site through any MCP-compatible client.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"node-fetch":"^3.3.2","@modelcontextprotocol/sdk":"^1.26.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_4.5.0_1771703277216_0.28572875433007794","host":"s3://npm-registry-packages-npm-production"}},"4.5.1":{"name":"@adsim/wordpress-mcp-server","version":"4.5.1","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@4.5.1","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/adsimbe/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/adsimbe/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"index.js"},"dist":{"shasum":"947d209d6896177f9c17aab45896ed771705c0fb","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-4.5.1.tgz","fileCount":58,"integrity":"sha512-RgGiawQdOJ7L3OzzUDsd9ia47/dIdw9MlGi9olSI2TYi4CxRI4OdD3TQsny0v2HuI4lSbDVZH2iPNhRMI/ZV5A==","signatures":[{"sig":"MEUCIQDB8zFNVNooO7qmi2qywtaUrJSNeJOxrBF/U1oZPD23DAIgX2ZXXoFy+xzmAWrFYVjZj5BMJQET/uNkcIsHSOYD8n0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":877279},"main":"index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"1f4aea5a87357ccdfdfbb0994ebf24f5c57d5adf","scripts":{"test":"vitest run","start":"node index.js","build:mcpb":"bash dxt/build-mcpb.sh","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/adsimbe/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"A Model Context Protocol (MCP) server for WordPress REST API integration. Manage posts, search content, and interact with your WordPress site through any MCP-compatible client.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"node-fetch":"^3.3.2","@modelcontextprotocol/sdk":"^1.26.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_4.5.1_1771708699398_0.09683224579564786","host":"s3://npm-registry-packages-npm-production"}},"4.6.0":{"name":"@adsim/wordpress-mcp-server","version":"4.6.0","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@4.6.0","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/adsimbe/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/adsimbe/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"index.js"},"dist":{"shasum":"19cf214b339bafe40932505f837610bf5c786f92","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-4.6.0.tgz","fileCount":71,"integrity":"sha512-SmSo9ecQPUdUcbNMywXDK/6YKfLGTpmim9W/ddao9to98a/UiQcdD4XbrclwYBSZ5tFEHnmzjkE6sQS9IWBY7w==","signatures":[{"sig":"MEUCIQCSUaoOkELYU5dak8sCz0cMaDhZkZrn7u1/MvZF1b3/CQIgCQmZLFppTlpl5BsTco6VQk/4+1DWCPqGq2uzUqfbULs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":941676},"main":"index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"50bf3976f64eea7e4cbd8b08c465930586b5c0f7","scripts":{"test":"vitest run","start":"node index.js","build:mcpb":"bash dxt/build-mcpb.sh","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/adsimbe/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"A Model Context Protocol (MCP) server for WordPress REST API integration. Manage posts, search content, and interact with your WordPress site through any MCP-compatible client.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"node-fetch":"^3.3.2","@modelcontextprotocol/sdk":"^1.26.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_4.6.0_1771720270600_0.4048753060978356","host":"s3://npm-registry-packages-npm-production"}},"5.1.0":{"name":"@adsim/wordpress-mcp-server","version":"5.1.0","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms","seo","woocommerce","schema-org","multilingual","security-audit","performance","enterprise","full-site-editing"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@5.1.0","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/GeorgesAdSim/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/GeorgesAdSim/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"index.js"},"dist":{"shasum":"b218a135bfbbab86a1bf0c853f71d123944bd9a4","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-5.1.0.tgz","fileCount":111,"integrity":"sha512-zSXfMVPr2OkvvYx1wsm11JEgBTn/SLJmift2gHlMpr/p18vXqDXBrqxsuLrERkogiydKTutcXuWcwMR8dpRK/g==","signatures":[{"sig":"MEUCIQDOV4gObjRqCmttDPn+serAm9oxGNuLv+bYnquro0A1MAIgXLXmjroZjvYtLAyfRHmpLlDZHmzvN8K5eEHTXy9fg+w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1556578},"main":"index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"32bcab4a7be63d96e00d2410d9053c21f620e2d1","scripts":{"test":"vitest run","start":"node index.js","build:mcpb":"bash dxt/build-mcpb.sh","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/GeorgesAdSim/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"Enterprise WordPress MCP Server — 180 tools, modular architecture, governance, audit trail, WooCommerce, Schema.org, multilingual.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"node-fetch":"^3.3.2","@modelcontextprotocol/sdk":"^1.26.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_5.1.0_1773240507713_0.35190043829830175","host":"s3://npm-registry-packages-npm-production"}},"5.3.1":{"name":"@adsim/wordpress-mcp-server","version":"5.3.1","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms","seo","woocommerce","schema-org","multilingual","security-audit","performance","enterprise","full-site-editing"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@5.3.1","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/GeorgesAdSim/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/GeorgesAdSim/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"index.js"},"dist":{"shasum":"8274322be4741ce442a53e7e645e36bf1dd93eca","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-5.3.1.tgz","fileCount":112,"integrity":"sha512-WI0ovqCvnKEu5rh2BeldYwSE1qAyW+6BV5frwaSJJmeY+fGb9H88QkJsqZ2x5L39l785MzvjXmNuUPVQVAwuEQ==","signatures":[{"sig":"MEUCIQDSeFJzHxQxwwaT1WIbP5MZRSvfZHTGrre0YMKW+tLACgIgP9hY1u/Ca+dgjT2HYmD9lzhXMEIcqpJ6xXqOyQ4y8Ko=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1567839},"main":"index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"32bcab4a7be63d96e00d2410d9053c21f620e2d1","scripts":{"test":"vitest run","start":"node index.js","build:mcpb":"bash dxt/build-mcpb.sh","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/GeorgesAdSim/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"Enterprise WordPress MCP Server — 180 tools, modular architecture, governance, audit trail, WooCommerce, Schema.org, multilingual.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"node-fetch":"^3.3.2","@modelcontextprotocol/sdk":"^1.26.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_5.3.1_1773245872454_0.2433151134012832","host":"s3://npm-registry-packages-npm-production"}},"5.4.0":{"name":"@adsim/wordpress-mcp-server","version":"5.4.0","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms","seo","woocommerce","schema-org","multilingual","security-audit","performance","enterprise","full-site-editing"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@5.4.0","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/GeorgesAdSim/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/GeorgesAdSim/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"index.js"},"dist":{"shasum":"d81f124f2b9b76c7289066f7d09c70fdbde5fd66","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-5.4.0.tgz","fileCount":112,"integrity":"sha512-h6vjDtgYs26Pdp80KR/HzeTm2Ln5mDo3r7zqbGgreEip/LZzn8B86zKPrf1Pt9uEmOUH4sxPRySc13uvFq3FEQ==","signatures":[{"sig":"MEUCIBHWKLWllmESKOJ9oehyRI296o2c71e7lfeKOLIsYEziAiEApY+y4W7MAQMt/2gwDmIGFSbRY4A474l5wxDOb3aVQqU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1580197},"main":"index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"767eaa40b6842ee7623f145f4e9f739a00bffa5b","scripts":{"test":"vitest run","start":"node index.js","build:mcpb":"bash dxt/build-mcpb.sh","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/GeorgesAdSim/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"Enterprise WordPress MCP Server — 180 tools, modular architecture, governance, audit trail, WooCommerce, Schema.org, multilingual.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"node-fetch":"^3.3.2","@modelcontextprotocol/sdk":"^1.26.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_5.4.0_1785076336994_0.9213385538902479","host":"s3://npm-registry-packages-npm-production"}},"5.5.0":{"name":"@adsim/wordpress-mcp-server","version":"5.5.0","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms","seo","woocommerce","schema-org","multilingual","security-audit","performance","enterprise","full-site-editing"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@5.5.0","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/GeorgesAdSim/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/GeorgesAdSim/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"index.js"},"dist":{"shasum":"e6431020518acd01d2fc4a8169a545c4b0e654cb","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-5.5.0.tgz","fileCount":112,"integrity":"sha512-KlA8Km1fiO93pDO022RBr5WueyGKYI68GAo8bRhu85FpgwzhV1hPU3ZB+e04lKlmXkobea0y21+7M6rQC4LUrg==","signatures":[{"sig":"MEQCIGIlhyckUWewnnrNGkG9hk6cFwbQvlViOY9vR26n/6HhAiAs9v+i9edVrn+7sUExxclzHKZ7TdbXvrhcI+8zS0Ntlw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1607488},"main":"index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"44acb54bf2012671fa67b44ae5492ab1a79c910e","scripts":{"test":"vitest run","start":"node index.js","build:mcpb":"bash dxt/build-mcpb.sh","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/GeorgesAdSim/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"Enterprise WordPress MCP Server — 180 tools, modular architecture, governance, audit trail, WooCommerce, Schema.org, multilingual.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"node-fetch":"^3.3.2","@modelcontextprotocol/sdk":"^1.26.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_5.5.0_1785088546188_0.056653285932807496","host":"s3://npm-registry-packages-npm-production"}},"5.6.0":{"name":"@adsim/wordpress-mcp-server","version":"5.6.0","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms","seo","woocommerce","schema-org","multilingual","security-audit","performance","enterprise","full-site-editing"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@5.6.0","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/GeorgesAdSim/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/GeorgesAdSim/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"index.js"},"dist":{"shasum":"a84ada24e24bd3c82f72338f37354eb8de0579d6","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-5.6.0.tgz","fileCount":113,"integrity":"sha512-CRMw8NkpY6ocxZjr9FMYLSksJRqQZcoe9b8mXp+GvJTKIY1+BYQQ4dAAMgQ6E7wRPwbE0iddAxqnTW8FMxfL1g==","signatures":[{"sig":"MEYCIQD8MzSCpQzWYbLxzd1d7JBAJbpN0ZSiIQz362sNbaH4bQIhAIKQAr1yumz8Y98wsrQiO1XQ3soT1OXr+Ew4n7dJ3HE4","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1629327},"main":"index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"e9da98aadfbab54853d3b54c17370d8d521ca060","scripts":{"test":"vitest run","start":"node index.js","build:mcpb":"bash dxt/build-mcpb.sh","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/GeorgesAdSim/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"Enterprise WordPress MCP Server — 180 tools, modular architecture, governance, audit trail, WooCommerce, Schema.org, multilingual.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"node-fetch":"^3.3.2","@modelcontextprotocol/sdk":"^1.26.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_5.6.0_1785162530003_0.4898456466271863","host":"s3://npm-registry-packages-npm-production"}},"5.7.0":{"name":"@adsim/wordpress-mcp-server","version":"5.7.0","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms","seo","woocommerce","schema-org","multilingual","security-audit","performance","enterprise","full-site-editing"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@5.7.0","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/GeorgesAdSim/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/GeorgesAdSim/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"index.js"},"dist":{"shasum":"52f2268574e923163c769342dda4502b584089bf","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-5.7.0.tgz","fileCount":44,"integrity":"sha512-I6qE8DEteiZbCqKvrudxsVZcPKpCvSXdsTMFFDv1PDmpourfhOhL8hEpMqXWwc/oIL/n+AjLTVmsr7jbp3zEkw==","signatures":[{"sig":"MEUCICiOPaZO5E5NmJ3vpxo9ro9WVLjkpAB/6bsge+1fYaJFAiEAsWVhD7g8+dBIPLbL2LsYpSvMTypaawQxBItiue6a8o8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":829663},"main":"index.js","type":"module","engines":{"node":">=20.0.0"},"gitHead":"d36afc0530c805efd40183890f5f121285c9aff7","scripts":{"test":"vitest run","start":"node index.js","build:mcpb":"bash dxt/build-mcpb.sh","test:watch":"vitest","verify:mcpb":"node scripts/verify-mcpb.js","sync:metadata":"node scripts/sync-metadata.js","test:coverage":"vitest run --coverage","check:metadata":"node scripts/sync-metadata.js --check","verify:package":"node scripts/verify-package.js"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/GeorgesAdSim/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"Enterprise WordPress MCP Server — 176 tools, modular architecture, governance, audit trail, WooCommerce, Schema.org, multilingual.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"node-fetch":"^3.3.2","@modelcontextprotocol/sdk":"^1.26.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_5.7.0_1785233134711_0.4704206998761389","host":"s3://npm-registry-packages-npm-production"}},"5.7.1":{"name":"@adsim/wordpress-mcp-server","version":"5.7.1","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms","seo","woocommerce","schema-org","multilingual","security-audit","performance","enterprise","full-site-editing"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@5.7.1","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/GeorgesAdSim/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/GeorgesAdSim/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"index.js"},"dist":{"shasum":"c66704cdb5339c1c9f374b2fce974bed5c110352","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-5.7.1.tgz","fileCount":44,"integrity":"sha512-oMt6aRacYcwlCFycn3Poxg0GxcNFRYlOPwayXXgc32fo5OqL27vW09e7+WRz8BIF6/EnRfPFCqtHPPA18yqP9A==","signatures":[{"sig":"MEYCIQC5ic4qsgaUrBlMgkGYULsXVw5XQ+gWcNcXvgznazaDMwIhAJzL429n9OM6wVQn4GrgGQ1qddcTB9/83bsEKJ+YaVWy","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":830944},"main":"index.js","type":"module","engines":{"node":">=20.0.0"},"gitHead":"7b373f0c5964114647b65c91683ede417a136114","scripts":{"test":"vitest run","start":"node index.js","build:mcpb":"bash dxt/build-mcpb.sh","test:watch":"vitest","verify:mcpb":"node scripts/verify-mcpb.js","sync:metadata":"node scripts/sync-metadata.js","test:coverage":"vitest run --coverage","check:metadata":"node scripts/sync-metadata.js --check","verify:package":"node scripts/verify-package.js"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/GeorgesAdSim/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"Enterprise WordPress MCP Server — 176 tools, modular architecture, governance, audit trail, WooCommerce, Schema.org, multilingual.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"node-fetch":"^3.3.2","@modelcontextprotocol/sdk":"^1.26.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_5.7.1_1785239148161_0.15393263877409402","host":"s3://npm-registry-packages-npm-production"}},"5.9.0":{"name":"@adsim/wordpress-mcp-server","version":"5.9.0","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms","seo","woocommerce","schema-org","multilingual","security-audit","performance","enterprise","full-site-editing"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@5.9.0","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/GeorgesAdSim/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/GeorgesAdSim/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"index.js"},"dist":{"shasum":"8023b190f8e6d67d70fad00d553a18440fac68dd","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-5.9.0.tgz","fileCount":47,"integrity":"sha512-5GBJTHw+TKjYqYSf/5wYjv4U3+0LI1bVt8cUbZo4VhD90Y07tSSWeTYHDONv/qoEGoOGmh1WFBpOxvt3Zv02jQ==","signatures":[{"sig":"MEUCIQC2yNAipekUIIoi/lQw74MvpjOoCDc3/kONOyWCtQTHbQIgLu9YWl9OaFRBtoY6kjnygPfUSCRnufAf8OWD7qCRspQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":860426},"main":"index.js","type":"module","engines":{"node":">=20.0.0"},"gitHead":"5591cbc761b16ba3f5b57b62ccfcba5f2b491c6e","scripts":{"test":"vitest run","start":"node index.js","build:mcpb":"bash dxt/build-mcpb.sh","test:watch":"vitest","verify:mcpb":"node scripts/verify-mcpb.js","sync:metadata":"node scripts/sync-metadata.js","test:coverage":"vitest run --coverage","check:metadata":"node scripts/sync-metadata.js --check","verify:package":"node scripts/verify-package.js"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/GeorgesAdSim/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"Enterprise WordPress MCP Server — 178 tools, modular architecture, governance, audit trail, WooCommerce, Schema.org, multilingual.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"node-fetch":"^3.3.2","@modelcontextprotocol/sdk":"^1.26.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_5.9.0_1785244159588_0.38785262731560755","host":"s3://npm-registry-packages-npm-production"}},"6.0.0":{"name":"@adsim/wordpress-mcp-server","version":"6.0.0","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms","seo","woocommerce","schema-org","multilingual","security-audit","performance","enterprise","full-site-editing"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@6.0.0","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/GeorgesAdSim/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/GeorgesAdSim/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"index.js"},"dist":{"shasum":"c35a6a7d3da467fe305c6c42848640bd313d76b7","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-6.0.0.tgz","fileCount":51,"integrity":"sha512-T/ZtzjW3GqKQ85HTZI/IHtjbJRyY3cighQVzIzSx+wsXDrdsrBgqy4WY1NGT91wN2x+1C4YTYJ0WEOsbY4nytA==","signatures":[{"sig":"MEYCIQDaMYfWAXe/6p4G6A+d0G3nug0j+ZmoapEjR4d84DHQXAIhAKCnV+uEgg72J3aOUTomKe64iwEBuL0yzxfTOiLqkgji","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":885062},"main":"index.js","type":"module","engines":{"node":">=20.0.0"},"gitHead":"6353d280dc88e16f80466f090e129b770fcf4a4d","scripts":{"test":"vitest run","start":"node index.js","build:mcpb":"bash dxt/build-mcpb.sh","test:watch":"vitest","verify:mcpb":"node scripts/verify-mcpb.js","sync:metadata":"node scripts/sync-metadata.js","test:coverage":"vitest run --coverage","check:metadata":"node scripts/sync-metadata.js --check","verify:package":"node scripts/verify-package.js"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/GeorgesAdSim/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"Enterprise WordPress MCP Server — 137 tools, modular architecture, governance, audit trail, WooCommerce, Schema.org, multilingual.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"node-fetch":"^3.3.2","@modelcontextprotocol/sdk":"^1.26.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_6.0.0_1785252418995_0.6767108362431966","host":"s3://npm-registry-packages-npm-production"}},"6.1.0":{"name":"@adsim/wordpress-mcp-server","version":"6.1.0","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms","seo","woocommerce","schema-org","multilingual","security-audit","performance","enterprise","full-site-editing"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@6.1.0","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/GeorgesAdSim/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/GeorgesAdSim/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"index.js"},"dist":{"shasum":"d348271f7cabb1962d2c6282361da4e63ea83fc3","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-6.1.0.tgz","fileCount":52,"integrity":"sha512-qh5Ar5P01VlOdCrKORt6yKnRMAOpZqKYl03k/rW52sWkkYI0NnP/7MMeufAf/r0/R7Rq5lIfwQsZmdaL0KIQMg==","signatures":[{"sig":"MEUCIQD2RewqaB6lqhXKHdp2pVEGp+1AmWKRqFyby0QyMBNrEQIgRvFw09tTU+fjIU4On9353IXyRxMmsGvWI+W8eHopFhE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":896582},"main":"index.js","type":"module","engines":{"node":">=20.0.0"},"gitHead":"dcf4226b92e9d5826ed63279e7c08429dc22ae77","scripts":{"test":"vitest run","start":"node index.js","build:mcpb":"bash dxt/build-mcpb.sh","test:watch":"vitest","verify:mcpb":"node scripts/verify-mcpb.js","verify:audit":"node scripts/verify-audit-chain.js","sync:metadata":"node scripts/sync-metadata.js","test:coverage":"vitest run --coverage","check:metadata":"node scripts/sync-metadata.js --check","integration:up":"bash tests/integration/setup.sh","verify:package":"node scripts/verify-package.js","integration:down":"bash tests/integration/setup.sh down","test:integration":"vitest run --config vitest.integration.config.js"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/GeorgesAdSim/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"Enterprise WordPress MCP Server — 137 tools, modular architecture, governance, audit trail, WooCommerce, Schema.org, multilingual.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"node-fetch":"^3.3.2","@modelcontextprotocol/sdk":"^1.26.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_6.1.0_1785317825620_0.14045610552655274","host":"s3://npm-registry-packages-npm-production"}},"6.2.0":{"name":"@adsim/wordpress-mcp-server","version":"6.2.0","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms","seo","woocommerce","schema-org","multilingual","security-audit","performance","enterprise","full-site-editing"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","_id":"@adsim/wordpress-mcp-server@6.2.0","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"homepage":"https://github.com/GeorgesAdSim/wordpress-mcp-server#readme","bugs":{"url":"https://github.com/GeorgesAdSim/wordpress-mcp-server/issues"},"bin":{"wordpress-mcp-server":"index.js"},"dist":{"shasum":"4a42c2a5cdd1c8f53f5d12cd07784b5cfb39e6e9","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-6.2.0.tgz","fileCount":53,"integrity":"sha512-OKXFBSM2c9BhHqL+J+VQa1YKvq++hP7SNquKQc/n9yJkyK72REnv+epWR++kJL1A/vph74+GQoMaZbh6UQsLcw==","signatures":[{"sig":"MEUCIQCzIA1WCS21KehtDIukXghbHf+hNdwJ2MuYEOyW08JpQQIgH9Z4B5Q1UHxZMIxkgi+zjcFpeMyhi/NXU8Hg7PPwLWo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":912492},"main":"index.js","type":"module","engines":{"node":">=20.0.0"},"gitHead":"2bbbfb02fcbb7271b1a76d4dbe90790202693f34","scripts":{"test":"vitest run","start":"node index.js","build:mcpb":"bash dxt/build-mcpb.sh","test:watch":"vitest","verify:mcpb":"node scripts/verify-mcpb.js","verify:audit":"node scripts/verify-audit-chain.js","sync:metadata":"node scripts/sync-metadata.js","test:coverage":"vitest run --coverage","check:metadata":"node scripts/sync-metadata.js --check","integration:up":"bash tests/integration/setup.sh","verify:package":"node scripts/verify-package.js","integration:down":"bash tests/integration/setup.sh down","test:integration":"vitest run --config vitest.integration.config.js"},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"repository":{"url":"git+https://github.com/GeorgesAdSim/wordpress-mcp-server.git","type":"git"},"_npmVersion":"10.9.2","description":"Enterprise WordPress MCP Server — 137 tools, modular architecture, governance, audit trail, WooCommerce, Schema.org, multilingual.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"node-fetch":"^3.3.2","@modelcontextprotocol/sdk":"^1.26.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/wordpress-mcp-server_6.2.0_1785319110385_0.8794150175142397","host":"s3://npm-registry-packages-npm-production"}},"6.2.1":{"name":"@adsim/wordpress-mcp-server","version":"6.2.1","description":"Enterprise WordPress MCP Server — 137 tools, modular architecture, governance, audit trail, WooCommerce, Schema.org, multilingual.","type":"module","main":"index.js","bin":{"wordpress-mcp-server":"index.js"},"scripts":{"start":"node index.js","test":"vitest run","test:watch":"vitest","test:coverage":"vitest run --coverage","sync:metadata":"node scripts/sync-metadata.js","check:metadata":"node scripts/sync-metadata.js --check","build:mcpb":"bash dxt/build-mcpb.sh","verify:mcpb":"node scripts/verify-mcpb.js","verify:package":"node scripts/verify-package.js","verify:audit":"node scripts/verify-audit-chain.js","test:integration":"vitest run --config vitest.integration.config.js","integration:up":"bash tests/integration/setup.sh","integration:down":"bash tests/integration/setup.sh down"},"keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms","seo","woocommerce","schema-org","multilingual","security-audit","performance","enterprise","full-site-editing"],"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/GeorgesAdSim/wordpress-mcp-server.git"},"bugs":{"url":"https://github.com/GeorgesAdSim/wordpress-mcp-server/issues"},"homepage":"https://github.com/GeorgesAdSim/wordpress-mcp-server#readme","engines":{"node":">=20.0.0"},"dependencies":{"@modelcontextprotocol/sdk":"^1.26.0","node-fetch":"^3.3.2"},"devDependencies":{"vitest":"^4.0.18"},"_id":"@adsim/wordpress-mcp-server@6.2.1","gitHead":"ebaf489a907b6355987c550289d404ce45522f9d","_nodeVersion":"22.14.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-v3o/HytMZ/InwJwmaWKajbhvKSOvyNi94liIa7pklK6pA+LqP1NTybbTRpNn8McIY8heILqwvFRboyn+sY6FKw==","shasum":"e437d29f87fd838748399e38cd9ae38bd5de0556","tarball":"https://registry.npmjs.org/@adsim/wordpress-mcp-server/-/wordpress-mcp-server-6.2.1.tgz","fileCount":53,"unpackedSize":921639,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIBTLIpNIt7Ftb5ASRHm8NOSDCVsI448h21P/3bU/aJ7qAiEAmFHF5gdsZne7SwrwvALW5sP/5iBRaRdlGH1JG5EPOOY="}]},"_npmUser":{"name":"adsim","email":"georgescordewiener@gmail.com"},"directories":{},"maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/wordpress-mcp-server_6.2.1_1785326858732_0.6246412944610893"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-17T09:25:55.159Z","modified":"2026-07-29T12:07:39.040Z","1.0.0":"2026-02-17T09:25:55.432Z","3.0.0":"2026-02-19T16:37:02.750Z","3.1.0":"2026-02-19T16:52:42.795Z","4.4.0":"2026-02-21T19:01:39.536Z","4.5.0":"2026-02-21T19:47:57.446Z","4.5.1":"2026-02-21T21:18:19.649Z","4.6.0":"2026-02-22T00:31:10.832Z","5.1.0":"2026-03-11T14:48:27.922Z","5.3.1":"2026-03-11T16:17:52.757Z","5.4.0":"2026-07-26T14:32:17.149Z","5.5.0":"2026-07-26T17:55:46.391Z","5.6.0":"2026-07-27T14:28:50.152Z","5.7.0":"2026-07-28T10:05:34.902Z","5.7.1":"2026-07-28T11:45:48.370Z","5.9.0":"2026-07-28T13:09:19.787Z","6.0.0":"2026-07-28T15:26:59.130Z","6.1.0":"2026-07-29T09:37:05.775Z","6.2.0":"2026-07-29T09:58:30.543Z","6.2.1":"2026-07-29T12:07:38.865Z"},"bugs":{"url":"https://github.com/GeorgesAdSim/wordpress-mcp-server/issues"},"author":{"name":"Georges Cordewiener","email":"georges@adsim.be"},"license":"MIT","homepage":"https://github.com/GeorgesAdSim/wordpress-mcp-server#readme","keywords":["mcp","model-context-protocol","wordpress","wordpress-api","rest-api","claude","ai","automation","cms","seo","woocommerce","schema-org","multilingual","security-audit","performance","enterprise","full-site-editing"],"repository":{"type":"git","url":"git+https://github.com/GeorgesAdSim/wordpress-mcp-server.git"},"description":"Enterprise WordPress MCP Server — 137 tools, modular architecture, governance, audit trail, WooCommerce, Schema.org, multilingual.","maintainers":[{"name":"adsim","email":"georgescordewiener@gmail.com"}],"readme":"# WordPress MCP Server\n\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\n[![Node.js](https://img.shields.io/badge/Node.js-%3E%3D20-green.svg)](https://nodejs.org/)\n[![MCP SDK](https://img.shields.io/badge/MCP-SDK-blue.svg)](https://github.com/anthropics/mcp)\n[![Tests](https://img.shields.io/badge/tests-1268%20passing-brightgreen.svg)](https://github.com/GeorgesAdSim/wordpress-mcp-server/actions)\n[![npm](https://img.shields.io/npm/v/@adsim/wordpress-mcp-server.svg)](https://www.npmjs.com/package/@adsim/wordpress-mcp-server)\n\n**Governance · Audit Trail · Multi-Site · No plugin for the core operations**\n\nThe enterprise governance layer for Claude-to-WordPress integrations — secure, auditable, and multi-site.\n\n**v6.2.1 Enterprise** · 137 tools · 1268 Vitest tests · GitHub Actions CI\n\n---\n\n## Table of Contents\n\n- [Architecture](#architecture)\n- [Why This Server](#why-this-server)\n- [Safety Model](#safety-model)\n- [Data Retention](#data-retention)\n- [Quick Start](#quick-start)\n- [HTTP Streamable Transport](#http-streamable-transport)\n- [MCPB Bundle](#mcpb-bundle--claude-desktop-one-click-install)\n- [Available Tools (137)](#available-tools-137)\n- [Enterprise Controls](#enterprise-controls)\n- [MU-Plugin Companion](#mu-plugin-companion)\n- [SEO Metadata](#seo-metadata)\n- [WooCommerce Setup](#woocommerce-setup)\n- [Testing](#testing)\n- [Structured Audit Log](#structured-audit-log)\n- [Multi-Target](#multi-target)\n- [Health & Reliability](#health--reliability)\n- [Security](#security)\n- [Troubleshooting](#troubleshooting)\n- [Development](#development)\n- [Changelog](#changelog)\n- [Roadmap](#roadmap)\n- [Contributing](#contributing)\n- [License](#license)\n- [Credits](#credits)\n\n---\n\n## Architecture\n\n```\n┌─────────────────────────────┐\n│       Claude Client         │  Claude Desktop · Claude Code · Any MCP client\n└──────────────┬──────────────┘\n               │ MCP Protocol (stdio or HTTP Streamable)\n┌──────────────▼──────────────┐\n│    WordPress MCP Server     │  Node.js · Standalone · No plugin for core operations\n├─────────────────────────────┤\n│  index.js (~498 lines)      │  Orchestration only: MCP transport, enterprise controls, dispatch\n├─────────────────────────────┤\n│  src/tools/ (18 modules)    │  180 tool definitions + handlers by category\n├─────────────────────────────┤\n│  src/shared/                │  utils · api · audit · governance · context\n├─────────────────────────────┤\n│  src/plugins/               │  PluginRegistry · ACF · auto-detected via REST namespaces\n├─────────────────────────────┤\n│  Tool Profile Filter        │  editorial by default · shop · site · maintenance · all\n├─────────────────────────────┤\n│  Execution Controls         │  Read-only · Draft-only · Plugin mgmt · Type/status allowlists\n├─────────────────────────────┤\n│  Audit Logging              │  JSON on stderr · 79+ instrumentation points\n├─────────────────────────────┤\n│  Rate Limiting              │  Client-side · Configurable per-minute cap\n├─────────────────────────────┤\n│  HTTP Transport             │  Bearer auth · Session management · Origin validation\n└──────────────┬──────────────┘\n               │ HTTPS + WordPress Application Password (Basic Auth over TLS)\n┌──────────────▼──────────────┐\n│    WordPress REST API       │  Single site or multi-target\n├─────────────────────────────┤\n│  MCP Diagnostics mu-plugin  │  Optional · Debug log · Cron · Schema · Security endpoints\n└─────────────────────────────┘\n```\n\n## Why This Server\n\nMost WordPress MCP servers focus on what you can do. This one focuses on what you **should be allowed to do** — and who can verify it happened.\n\nIn regulated environments — financial services, healthcare, legal, government — AI-powered content operations need guardrails. This server supplies a governance layer: read-only and draft-only modes, an approval workflow, dry-run previews, before/after diffs, undo, and a sequenced, hash-chained audit trail.\n\nIt is one component, not a compliance product. Read the [Safety Model](#safety-model) before quoting it in a tender: the controls live in this process, the audit log needs somewhere durable to land, and the security boundary remains the WordPress account you give it.\n\n**No MCP plugin required.** Posts, pages, media, taxonomies, comments, users and revisions work against a standard WordPress with nothing added for this server. What the rest needs is what you would expect: WooCommerce tools need WooCommerce, SEO tools need an SEO plugin and its fields exposed over REST (see [SEO Metadata](#seo-metadata)), multilingual tools need WPML, Polylang or TranslatePress, PageSpeed and WPScan checks need their API keys. The durable change journal, the debug log, file permissions, database diagnostics and schema injection need the [companion mu-plugin](#mu-plugin-companion) — one file, no composer, no build.\n\nThe promise is that nothing MCP-specific has to be installed to start working, not that 137 tools run on a bare WordPress.\n\nWith 137 tools across 21 categories, agencies load only what a deployment needs: the `editorial` profile is the default, `shop`, `site`, `maintenance` and `all` cover the rest, and `WP_TOOL_CATEGORIES` picks categories directly. Beyond narrowing ListTools from ~16.2k to ~4-12k tokens, a profile stops user management, plugin activation and file-permission tools being offered to an agent that only writes articles — and with `WP_TOOL_ENFORCE_PROFILE=true` it refuses them outright rather than merely hiding them.\n\n## Safety Model\n\nThese controls are **operational guardrails, not a security boundary.** They are enforced pre-flight inside the MCP server process, which protects against agent error — the dominant risk in practice — but not against an operator. Anyone who can relaunch the server can relaunch it with different environment variables. The security boundary remains the capabilities of the WordPress account behind the Application Password: scope that account to what the deployment actually needs, and treat the controls below as defence in depth on top of it.\n\n- **Deletes go to the trash by default** — a permanent delete needs `force=true`. Blocking\n  deletion outright (`WP_DISABLE_DELETE`) and requiring a signed confirmation\n  (`WP_CONFIRM_DESTRUCTIVE`) are off unless you turn them on\n- **Configurable execution modes** — read-only, draft-only, or full access per deployment\n- **Pre-flight enforcement** — all guardrails checked before any API call is made\n- **Audit trail** — every action logged with timestamp, target, outcome and latency, as structured JSON on stderr. Entries are sequenced and hash-chained; with `WP_MCP_SECRET` set the chain is keyed with HMAC-SHA-256. That detects alteration, loss and reordering — see [Sequence and hash chain](#sequence-and-hash-chain). It does not make stderr immutable storage, and there is no delivery guarantee: ship it somewhere append-only if you need one\n- **Credential isolation** — secrets never appear in logs or error outputs\n- **Multi-tenant ready** — independent auth and config per WordPress target\n\n## Data Retention\n\nThere are three levels, and they are worth keeping apart.\n\n**1 — The server process writes nothing to disk.** No cache, no database, no state file. That is true unconditionally. Audit logs go to stderr in real time and can be disabled (`WP_AUDIT_LOG=off`) or redirected to any pipeline.\n\n**2 — One thing is held in memory: the change journal.** To let you undo a write, the server keeps the previous value of the fields that write changed — the last 20 by default, oldest dropped, gone when the process ends. `WP_CHANGE_JOURNAL=off` disables it; a number resizes it. An entry too large to restore safely is refused rather than truncated, and says why.\n\n**3 — With the companion installed, those snapshots are also stored in WordPress.** They then survive a restart and are visible from another machine. This is real persistence, and it belongs in your data map — but it lands in the same database the content came from, not in a second place under our control. The companion prunes after 30 days or 500 entries. `WP_CHANGE_JOURNAL_DURABLE=off` opts out.\n\nEverything else is stateless: content flows through the server and is not retained beyond the tool call that fetched it.\n\n> Before 5.9 this section claimed zero retention outright. Undo is not possible without keeping something. 6.2 added the durable half, so the claim is now split three ways rather than stated as an absolute.\n\n---\n\n## Quick Start\n\n### Requirements\n\n- Node.js >= 20 — tested on 20, 22 and 24\n- WordPress site with REST API enabled (default since WP 4.7)\n- WordPress Application Password (WP 5.6+)\n- HTTPS endpoint (required for production)\n- WooCommerce 3.5+ (optional, for WooCommerce tools)\n\n### Install from npm\n\nPublished as [`@adsim/wordpress-mcp-server`](https://www.npmjs.com/package/@adsim/wordpress-mcp-server).\nNothing to install: MCP clients launch the server themselves, and `npx` fetches it on\nfirst use.\n\n```bash\nnpx -y @adsim/wordpress-mcp-server\n```\n\n**Pin a version for anything that matters.** A governance component that silently moves\nunder you is a governance component you cannot vouch for: a new release can change which\ntools exist, what the defaults refuse, and what a workflow does. Shared agency configs, CI\nand client work should name a version:\n\n```bash\nnpx -y @adsim/wordpress-mcp-server@6.2.1\n```\n\nUnpinned is fine for trying it out or for a throwaway session — it always resolves the\nlatest release:\n\n```bash\nnpx -y @adsim/wordpress-mcp-server\n```\n\nInstall globally only if you intend to run it by hand:\n\n```bash\nnpm install -g @adsim/wordpress-mcp-server\nwordpress-mcp-server --verbose\n```\n\nThe published package holds the runtime and nothing else — 44 files, no tests, no build\ntooling. Requires Node 20 or later; the version is enforced by `engines`, so npm warns you\non an older runtime rather than failing obscurely later.\n\n### Install from GitHub\n\nUse the repository when you want to read the tests, change something, or run an unreleased\ncommit. [github.com/GeorgesAdSim/wordpress-mcp-server](https://github.com/GeorgesAdSim/wordpress-mcp-server)\n\n```bash\ngit clone https://github.com/GeorgesAdSim/wordpress-mcp-server.git\ncd wordpress-mcp-server\nnpm install\nnpm test\n```\n\nEvery release is tagged, so a specific version is one checkout away:\n\n```bash\ngit checkout v6.2.1\n```\n\n| What | Where |\n|---|---|\n| Releases and tags | [/releases](https://github.com/GeorgesAdSim/wordpress-mcp-server/releases) |\n| Report a bug | [/issues](https://github.com/GeorgesAdSim/wordpress-mcp-server/issues) |\n| Report a vulnerability | [SECURITY.md](.github/SECURITY.md) — privately, not in an issue |\n| Trademarks and forks | [TRADEMARK.md](TRADEMARK.md) |\n\nPoint a client at a clone with an absolute path instead of `npx`:\n\n```json\n{ \"command\": \"node\", \"args\": [\"/absolute/path/to/wordpress-mcp-server/index.js\"] }\n```\n\nUseful scripts:\n\n```bash\nnpm test                  # unit suite — no network calls, fully mocked\nnpm run integration:up    # disposable WordPress in Docker\nnpm run test:integration  # real HTTP against it\nnpm run integration:down  # tear it down, volumes included\nnpm run check:metadata    # fails if any published figure has drifted from the code\nnpm run build:mcpb        # build the Claude Desktop bundle\nnpm run verify:mcpb       # unpack it and boot the server out of it\nnpm run verify:package    # install the npm tarball in a clean project and boot it\n```\n\n### Configure\n\nCreate a `.env` file:\n```env\nWP_API_URL=https://yoursite.com\nWP_API_USERNAME=your-username\nWP_API_PASSWORD=xxxx xxxx xxxx xxxx xxxx xxxx\n\n# Optional: WooCommerce (generate at WooCommerce → Settings → Advanced → REST API)\nWC_CONSUMER_KEY=ck_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx\nWC_CONSUMER_SECRET=cs_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx\n\n# Tool surface (optional — defaults to the editorial profile)\nWP_TOOL_PROFILE=editorial                 # editorial · shop · site · maintenance · all\nWP_TOOL_CATEGORIES=seo,content,schema     # Pick categories directly, wins over the profile\nWP_COMPACT_JSON=true                      # Compact JSON output (default)\n```\n\nTo generate an Application Password: WordPress Admin → Users → Profile → Application Passwords → Add New.\n\n### Connect to Claude Desktop\n\nAdd to `claude_desktop_config.json`:\n\n- macOS: `~/Library/Application Support/Claude/claude_desktop_config.json`\n- Windows: `%APPDATA%\\Claude\\claude_desktop_config.json`\n```json\n{\n  \"mcpServers\": {\n    \"wordpress\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@adsim/wordpress-mcp-server\"],\n      \"env\": {\n        \"WP_API_URL\": \"https://yoursite.com\",\n        \"WP_API_USERNAME\": \"your-username\",\n        \"WP_API_PASSWORD\": \"xxxx xxxx xxxx xxxx xxxx xxxx\"\n      }\n    }\n  }\n}\n```\n\n### Connect to Claude Code\n```bash\nclaude mcp add wordpress \\\n  -e WP_API_URL=https://yoursite.com \\\n  -e WP_API_USERNAME=your-username \\\n  -e WP_API_PASSWORD=\"xxxx xxxx xxxx xxxx xxxx xxxx\" \\\n  -- npx -y @adsim/wordpress-mcp-server\n```\n\n---\n\n## HTTP Streamable Transport\n\n> **New in v3.0.0** — Run the server over HTTP instead of (or alongside) stdio, following the MCP spec 2025-03-26.\n\n### Start in HTTP mode\n```bash\nMCP_TRANSPORT=http \\\nMCP_HTTP_PORT=3000 \\\nMCP_AUTH_TOKEN=your-secret-token \\\nWP_API_URL=https://yoursite.com \\\nWP_API_USERNAME=your-username \\\nWP_API_PASSWORD=\"xxxx xxxx xxxx xxxx\" \\\nnpx -y @adsim/wordpress-mcp-server\n```\n\n### Dual mode (stdio + HTTP simultaneously)\n```bash\nMCP_TRANSPORT=http \\\nMCP_DUAL_MODE=true \\\nMCP_AUTH_TOKEN=your-secret-token \\\nnpx -y @adsim/wordpress-mcp-server\n```\n\n### HTTP environment variables\n\n| Variable              | Default     | Description                                          |\n|-----------------------|-------------|------------------------------------------------------|\n| `MCP_TRANSPORT`       | `stdio`     | Set to `http` to enable HTTP Streamable transport    |\n| `MCP_HTTP_PORT`       | `3000`      | HTTP server port                                     |\n| `MCP_HTTP_HOST`       | `127.0.0.1` | Bind address                                         |\n| `MCP_AUTH_TOKEN`      | _(none)_    | Bearer token for authentication (required in HTTP mode) |\n| `MCP_ALLOWED_ORIGINS` | _(none)_    | Comma-separated allowed origins (anti-DNS-rebinding) |\n| `MCP_SESSION_TIMEOUT_MS` | `3600000` | Session TTL in milliseconds (1 hour)                |\n| `MCP_DUAL_MODE`       | `false`     | Run stdio and HTTP transports simultaneously         |\n\n### Health check\n```bash\ncurl http://localhost:3000/health\n# → { \"status\": \"ok\", \"version\": \"6.2.1\", \"transport\": \"http\" }\n```\n\n### Connect an MCP client via HTTP\n```json\n{\n  \"mcpServers\": {\n    \"wordpress-http\": {\n      \"url\": \"http://localhost:3000/mcp\",\n      \"headers\": {\n        \"Authorization\": \"Bearer your-secret-token\"\n      }\n    }\n  }\n}\n```\n\n---\n\n## MCPB Bundle — Claude Desktop One-Click Install\n\n> **New in v3.1.0** — Package the server as a `.mcpb` bundle for Claude Desktop distribution.\n\nThe bundle stores WordPress credentials securely in the OS keychain (`sensitive: true`) — no manual JSON editing required.\n\n### Build the bundle\n```bash\nnpm run build:mcpb\n# → wordpress-mcp-server.mcpb\n```\n\n### Install in Claude Desktop\n\nDouble-click `wordpress-mcp-server.mcpb` — Claude Desktop will prompt for:\n- WordPress Site URL\n- WordPress Username\n- WordPress Application Password _(stored in OS keychain)_\n\n---\n\n## Available Tools (137)\n\n### Reading the numbers\n\nSeveral counts appear in this document and they are not the same count.\n\n| | Count | What it is |\n|---|---|---|\n| Definitions in the code | 180 | Everything declared, retired names included |\n| Retired but still routable | 43 | Absent from ListTools, still answer when called by name |\n| **Advertised** | **137** | The most ListTools can offer — the headline figure |\n| Conditional | 29 | Withheld until their own switch is on: 20 WooCommerce (`WC_CONSUMER_KEY`), 3 approval (`WP_REQUIRE_APPROVAL`), 6 plugin intelligence (`WP_ENABLE_PLUGIN_INTELLIGENCE`) |\n| Profile `all`, out of the box | 108 | 137 − 29 |\n| Profile `editorial`, out of the box | 68 | What a fresh install shows |\n\nHow 6.0 got from one catalogue to the other:\n\n```\n178  advertised before 6.0\n− 43  names retired (21 audits, 22 Full Site Editing)\n+  2  tools that replaced them (wp_audit, wp_site_design)\n= 137\n```\n\nThe 6.0 changelog reported the 43 removals and not the 2 additions, which made the\nsubtraction look wrong. Today's 180 definitions already include both, so `180 − 43 = 137`\nfalls out directly.\n\n**Three kinds of conditionality**, which the table above does not distinguish and which\naccount for the rest of the questions people ask:\n\n| Kind | Effect | Examples |\n|---|---|---|\n| Gated in ListTools | Not offered at all until the switch is on | The 29 above |\n| Offered but degraded | Always listed; returns less without a key | `wp_audit_page_speed` without `PAGESPEED_API_KEY`, `wp_audit_plugin_vulnerabilities` without `WPSCAN_API_KEY` |\n| Appears on detection | Added at runtime when the plugin's REST namespace is found | ACF and Elementor tools, counted separately from the 137 |\n| Listed but needs the companion | Listed and callable; fails cleanly without the mu-plugin | Debug log, file permissions, database diagnostics, durable journal |\n\nRegistry-level figures — 180, 43, 137, 29 — are generated and checked by\n`npm run check:metadata`, which fails CI when they drift. The profile counts are measured\nand written by hand, because they depend on runtime configuration rather than on the\nregistry.\n\n### Content Management (13)\n\n| Tool              | Description                                                                                    |\n|-------------------|------------------------------------------------------------------------------------------------|\n| `wp_list_posts`   | List posts with pagination, filtering by status/category/tag/author, and search                |\n| `wp_get_post`     | Get a post by ID with full content, meta fields, and taxonomy info                             |\n| `wp_create_post`  | Create a post (defaults to draft). Supports HTML, categories, tags, featured image, meta       |\n| `wp_update_post`  | Update any post field. Only provided fields are modified                                       |\n| `wp_delete_post`  | Move to trash by default. Permanent deletion requires `force=true`. Confirmation token when `WP_CONFIRM_DESTRUCTIVE=true` |\n| `wp_search`       | Full-text search across all content types                                                      |\n| `wp_list_pages`   | List pages with hierarchy (parent/child), templates, and menu order                            |\n| `wp_get_page`     | Get page content, template, and hierarchy info                                                 |\n| `wp_create_page`  | Create a page with parent, template, and menu_order support                                    |\n| `wp_update_page`  | Update any page field                                                                          |\n| `wp_validate_block_structure` | Validate Gutenberg block HTML before saving. Detects unclosed blocks, malformed JSON, invalid nesting, deprecated blocks |\n| `wp_bulk_update`  | Bulk update content across multiple posts/pages. Supports text replacement, meta updates, status changes, content append. Dry-run by default |\n| `wp_get_post_meta` | Read post meta fields. Use for ACF data if `acf/v3` unavailable, or for any custom meta (`_elementor_data`, `_yoast_wpseo_*`). Returns all meta if `meta_key` omitted |\n\n### Media Library (3)\n\n| Tool              | Description                                                              |\n|-------------------|--------------------------------------------------------------------------|\n| `wp_list_media`   | Browse media with type filtering (image/video/audio/document)            |\n| `wp_get_media`    | Get URL, dimensions, alt text, caption, and all available sizes          |\n| `wp_upload_media` | Upload a file from a public URL to the WordPress media library           |\n\n### Taxonomies & Structure (5)\n\n| Tool                     | Description                                                          |\n|--------------------------|----------------------------------------------------------------------|\n| `wp_list_categories`     | List categories with hierarchy, post count, and descriptions         |\n| `wp_list_tags`           | List tags with post count                                            |\n| `wp_create_taxonomy_term`| Create a new category or tag                                         |\n| `wp_list_post_types`     | Discover all registered post types (including custom ones)           |\n| `wp_list_custom_posts`   | List content from any custom post type (products, portfolio, events) |\n\n### Engagement (2)\n\n| Tool               | Description                                            |\n|---------------------|--------------------------------------------------------|\n| `wp_list_comments`  | List comments with filtering by post, status, and author |\n| `wp_create_comment` | Create a comment or reply on any post                  |\n\n### Users & Security (10)\n\n> **New in v4.7.0** — Full user CRUD, role/capability inspection, password reset, and application password management.\n\n| Tool                                | Description                                                                                |\n|-------------------------------------|--------------------------------------------------------------------------------------------|\n| `wp_list_users`                     | List users with roles, search, pagination. Supports full/summary/ids_only modes            |\n| `wp_get_user`                       | Full user profile: login, email, role, meta, registration date, avatar                     |\n| `wp_create_user`                    | Create user with username, email, password, role. Requires `confirm=true`. Write            |\n| `wp_update_user`                    | Update email, display_name, role, bio, meta. Write                                          |\n| `wp_delete_user`                    | Delete user with mandatory post reassignment. Requires `confirm=true`. Blocked by `WP_DISABLE_DELETE` |\n| `wp_list_user_roles`                | All available roles with their capabilities listed                                          |\n| `wp_get_user_capabilities`          | Active capabilities for a specific user                                                     |\n| `wp_reset_user_password`            | Trigger password reset email. Requires mu-plugin companion. Write                           |\n| `wp_list_user_application_passwords`| List app passwords with name, UUID, created date, last used. Read-only                      |\n| `wp_revoke_application_password`    | Revoke an application password by UUID. Write                                               |\n\n### SEO Metadata (2)\n\nAuto-detects Yoast, RankMath, SEOPress, AIOSEO.\n\n| Tool               | Description                                                                                  |\n|---------------------|----------------------------------------------------------------------------------------------|\n| `wp_get_seo_meta`   | Read SEO title, description, focus keyword, canonical, robots, Open Graph                    |\n| `wp_update_seo_meta`| Update SEO metadata with automatic plugin detection                                          |\n\n### Audits (1) — consolidated in v6.0\n\nOne tool, one check per call. Twenty-one separate audit tools used to differ only by which\ncheck they ran; folding them here leaves the model one decision instead of twenty-one.\nTheir original names are no longer advertised but remain callable, so existing scripts\nkeep working.\n\n| Check | What it looks for |\n|---|---|\n| `seo` | Site-wide SEO metadata quality, scored 0-100, with missing fields |\n| `media_seo` | Missing alt text, oversized images, filename quality |\n| `orphan_pages` | Published content no internal link points to |\n| `heading_structure` | H1-H6 hierarchy of one post, keyword placement |\n| `thin_content` | Posts below a word count, weighted by age |\n| `canonicals` | Missing, self-referencing or staging-domain canonicals |\n| `eeat_signals` | Author bio, dates, citations, outbound authority |\n| `broken_internal_links` | Internal links returning 404 or redirecting |\n| `keyword_cannibalization` | Posts competing on the same intent (TF-IDF + cosine) |\n| `taxonomies` | Empty, duplicated or near-duplicate terms |\n| `outbound_links` | External profile: low-authority domains, missing nofollow |\n| `translation_coverage` | Untranslated content per language |\n| `missing_seo_translations` | SEO fields present in the source but absent in translations |\n| `readability` | Sentence length, passive voice, transition words |\n| `update_frequency` | Content gone stale past a threshold |\n| `anchor_texts` | Generic, repeated or over-optimised anchors |\n| `schema_markup` | Presence and validity of JSON-LD |\n| `content_structure` | Section balance, list and media density |\n| `duplicate_content` | Near-duplicate posts by cosine similarity |\n| `content_gaps` | Taxonomy terms with too little content |\n| `cta_presence` | Posts without a call to action |\n\n`wp_audit(check, post_type?, limit?, post_id?, options?)`. `options` carries the settings\nspecific to a check — `min_words` for `thin_content`, `similarity_threshold` for\n`duplicate_content`, `authoritative_domains` for `eeat_signals`.\n\n### Schema.org Intelligence (7) — New in v4.9\n\nGeneration + injection + local validation end-to-end.\n\n| Tool                             | Description                                                                                |\n|----------------------------------|--------------------------------------------------------------------------------------------|\n| `wp_generate_schema_article`     | Generates Article JSON-LD from post data with `_embed` for author and featured image       |\n| `wp_generate_schema_faq`         | Detects Q&A from Gutenberg FAQ blocks, RankMath, AIOSEO, `<details>`, or H3+paragraph     |\n| `wp_generate_schema_howto`       | Detects steps from ordered lists or numbered headings. Extracts totalTime, estimatedCost   |\n| `wp_generate_schema_localbusiness`| Pulls business data from ACF, Yoast Local SEO, or WP options                             |\n| `wp_generate_schema_breadcrumb`  | Rebuilds full breadcrumb hierarchy: Home > Category/Parent > Post                          |\n| `wp_inject_schema`               | Injects JSON-LD into `_custom_schema_jsonld` post meta. Supports `dry_run=true`. Requires mu-plugin |\n| `wp_validate_schema_live`        | Fetches live URL, extracts all JSON-LD blocks, validates structure and required fields     |\n\n### Content Intelligence (8) — New in v4.4\n\nAll read-only, always allowed regardless of governance flags.\n\n| Tool                          | Description                                                                              |\n|-------------------------------|------------------------------------------------------------------------------------------|\n| `wp_get_content_brief`        | Editorial brief aggregator: SEO + structure + links in 1 call                            |\n| `wp_extract_post_outline`     | H1-H6 outline extraction with category-level pattern analysis                           |\n| `wp_build_link_map`           | Internal link matrix with simplified PageRank scoring (0-100)                            |\n| `wp_extract_faq_blocks`       | FAQ inventory: JSON-LD, Gutenberg blocks, HTML patterns                                  |\n| `wp_extract_entities`         | Regex/heuristic named entity extraction (brands, locations, persons, organizations)      |\n| `wp_get_publishing_velocity`  | Publication cadence by author/category with trend detection                              |\n| `wp_compare_revisions_diff`   | Textual diff between revisions with amplitude scoring                                    |\n| `wp_list_posts_by_word_count` | Posts sorted by length with 6-tier segmentation                                          |\n\n### Editorial Intelligence (6) — New in v4.13\n\nBatch processing up to 500 posts, reuses TF-IDF engine. All read-only.\n\n| Tool                             | Description                                                                              |\n|----------------------------------|------------------------------------------------------------------------------------------|\n| `wp_suggest_content_updates`     | Finds stale posts needing updates. Prioritizes by age, outdated date references, thin content |\n| `wp_audit_author_consistency`    | Profiles each author: post count, avg word count, frequency, readability, media usage    |\n| `wp_build_editorial_calendar`    | Analyzes 12 months of history for seasonality, best days, scheduled posts, gaps           |\n| `wp_find_pillar_content_gaps`    | Identifies topics with 3+ posts without a dedicated pillar page                          |\n| `wp_audit_internal_link_equity`  | Builds link graph, identifies orphans, over-linked pages, equity distribution 0-100      |\n| `wp_suggest_content_cluster`     | Clusters content by TF-IDF + cosine similarity around a keyword or post_id seed          |\n\n### Multilingual Intelligence EU (4) — New in v4.10\n\nWPML · Polylang Pro · Polylang Free (hreflang fallback) · TranslatePress.\n\n| Tool                              | Description                                                                            |\n|-----------------------------------|----------------------------------------------------------------------------------------|\n| `wp_detect_multilingual_plugin`   | Auto-detects WPML > Polylang Pro > Polylang Free > TranslatePress                     |\n| `wp_list_languages`               | Lists configured languages with code, name, locale, URL prefix, flag                  |\n| `wp_get_post_translations`        | Gets all translations with post IDs, titles, URLs, statuses, SEO meta per language     |\n| `wp_sync_seo_meta_translations`   | Copies SEO meta from source to translations. `dry_run=true` by default. Write          |\n\n### Performance & Core Web Vitals (6) — New in v4.9\n\n| Tool                                | Description                                                                            |\n|--------------------------------------|----------------------------------------------------------------------------------------|\n| `wp_audit_page_speed`                | Google PageSpeed Insights: Core Web Vitals (LCP, CLS, INP, FCP, TTFB), score, opportunities. Requires `PAGESPEED_API_KEY` |\n| `wp_find_render_blocking_resources`  | Detects render-blocking `<link>` and `<script>` in `<head>` (excludes defer/async)     |\n| `wp_audit_image_optimization`        | Media library audit: non-WebP, large files (>100KB), missing alt text                 |\n| `wp_check_caching_status`            | Detects caching plugins (WP Rocket, W3TC, LiteSpeed) and cache HTTP headers           |\n| `wp_audit_database_bloat`            | Revisions, expired transients, auto-drafts, spam, orphan postmeta. Requires mu-plugin |\n| `wp_get_plugin_performance_impact`   | Ranks active plugins by estimated performance impact (~50 plugin database)             |\n\n### Security Audit (6) — New in v4.11\n\nAll read-only. Optional `WPSCAN_API_KEY` for CVE data.\n\n| Tool                             | Description                                                                              |\n|----------------------------------|------------------------------------------------------------------------------------------|\n| `wp_audit_user_security`         | Audits admin accounts: default usernames, inactive accounts, generic emails, missing 2FA |\n| `wp_check_file_permissions`      | Checks wp-config.php, .htaccess, uploads/ permissions. Requires mu-plugin                |\n| `wp_list_recently_modified_files`| Recently modified files with suspicious detection: PHP in uploads, hex filenames         |\n| `wp_audit_plugin_vulnerabilities`| Scans plugins against WPScan API. CVEs with CVSS scores. Without API key: version list   |\n| `wp_check_ssl_certificate`       | TLS validation (expiry, issuer, SAN), security headers (HSTS, CSP). Grades A+ to F      |\n| `wp_audit_login_security`        | Login security score /100: XML-RPC, user enumeration, 2FA, brute force protection        |\n\n### Site Health & Diagnostics (8) — New in v4.7\n\n`wp_get_debug_log` and `wp_get_active_hooks` require mu-plugin companion.\n\n| Tool                       | Description                                                                            |\n|----------------------------|----------------------------------------------------------------------------------------|\n| `wp_get_site_health_status`| Overall health score (good/recommended/critical) with issue counts by severity         |\n| `wp_list_site_health_issues`| All health issues with label, description, severity, and badge                        |\n| `wp_get_site_health_info`  | System info: PHP version, MySQL, memory limit, extensions, WP constants                |\n| `wp_get_debug_log`         | Read last N lines of `debug.log` filtered by level. Max 500 lines. Requires mu-plugin  |\n| `wp_get_cron_events`       | List all WP-Cron events with hook, schedule, next run, and overdue detection           |\n| `wp_get_transients`        | List database transients with key, expiration, size. Filter by expired/active          |\n| `wp_check_php_compatibility`| Check each plugin's PHP version requirement vs current PHP                            |\n| `wp_get_active_hooks`      | Inventory of registered actions and filters with callbacks and priorities. Requires mu-plugin |\n\n### Site Design — FSE (1) — consolidated in v6.0\n\nTwenty-two tools that were list/get/create/update/delete repeated across five resource\ntypes. Pure CRUD, so the resource became a parameter. The original names are no longer\nadvertised but remain callable.\n\n`wp_site_design(action, resource, id?, options?)`\n\n| Resource | Actions | What it is |\n|---|---|---|\n| `template` | list · get · create · update · delete | Page-level layouts: single, archive, 404, front-page |\n| `template_part` | list · get · create · update · delete | Reusable fragments: header, footer |\n| `global_styles` | list · get · update | Theme design tokens: palette, typography, spacing. `list` returns the theme's style variations |\n| `block_pattern` | list · get · create · delete | Block compositions offered in the editor. WordPress has no update |\n| `navigation_menu` | list · get · create · update · delete | Block-based menus |\n\nReads are always allowed. `create` and `update` are refused by `WP_READ_ONLY`, `delete`\nalso by `WP_DISABLE_DELETE` — the tool gates itself per action rather than being refused\nwhole, so a read-only deployment can still inspect a theme.\n\nFull Site Editing applies to block themes only. A site built with Elementor or a classic\ntheme has no block templates; use the widgets tools below and the Elementor plugin layer.\n\n### Widgets (4)\n\nSidebar widgets belong to the classic theme system, not to Full Site Editing — they were\nfiled under `fse` until v6.0, which hid four classic-theme tools behind a block-theme\nlabel. They now have their own category, in the `site` profile.\n\n| Tool | Description |\n|---|---|\n| `wp_list_widgets` | List widgets, filterable by sidebar |\n| `wp_get_widget` | Read a single widget |\n| `wp_update_widget` | Update settings or move to another sidebar. Write |\n| `wp_delete_widget` | Delete a widget. Blocked by `WP_DISABLE_DELETE` |\n\n### Plugin Intelligence Layer (up to 7) — New in v4.5-v4.6\n\nActivates only when plugin detected via REST namespace discovery. Disable all: `WP_DISABLE_PLUGIN_LAYERS=true`\n\n**ACF (Advanced Custom Fields)** — requires `/acf/v3` namespace\n\n| Tool                 | Description                                                              |\n|----------------------|--------------------------------------------------------------------------|\n| `acf_get_fields`     | Get ACF custom fields for a post/page with key filtering and raw/compact/summary modes |\n| `acf_list_field_groups` | List all configured ACF field groups                                  |\n| `acf_get_field_group`| Get full detail of an ACF field group by ID                              |\n| `acf_update_fields`  | Update ACF custom fields. Write — blocked by `WP_READ_ONLY`             |\n\n**Elementor** — requires `/elementor/v1` namespace\n\n| Tool                        | Description                                                            |\n|-----------------------------|------------------------------------------------------------------------|\n| `elementor_list_templates`  | List Elementor templates (page, section, block, popup)                 |\n| `elementor_get_template`    | Get full template content and elements. Context-guarded at 50k chars   |\n| `elementor_get_page_data`   | Elementor editor data: widgets used, elements count                    |\n\n### Plugin Intelligence (6) — New in v4.5\n\nRequires `WP_ENABLE_PLUGIN_INTELLIGENCE=true`. Read-only (except write modes noted).\n\n| Tool                      | Description                                                                              |\n|---------------------------|------------------------------------------------------------------------------------------|\n| `wp_get_rendered_head`    | Fetch real `<head>` HTML via RankMath/Yoast headless endpoint. Compare rendered vs stored |\n| `wp_audit_rendered_seo`   | Bulk rendered-vs-stored SEO divergence detection with per-post scoring                   |\n| `wp_get_pillar_content`   | Read or set RankMath cornerstone/pillar flag. Write blocked by `WP_READ_ONLY`            |\n| `wp_audit_schema_plugins` | Validate JSON-LD from SEO plugin native fields (rank_math_schema or yoast_head_json)     |\n| `wp_get_seo_score`        | Read RankMath native SEO score (0-100) with bulk mode distribution stats                 |\n| `wp_get_twitter_meta`     | Read/write Twitter Card meta for RankMath, Yoast, SEOPress. Write blocked by `WP_READ_ONLY` |\n\n### Plugins & Themes (5)\n\n| Tool                  | Description                                                                          |\n|-----------------------|--------------------------------------------------------------------------------------|\n| `wp_list_plugins`     | List installed plugins with status, version, author. Requires `activate_plugins`     |\n| `wp_activate_plugin`  | Activate a plugin. Blocked by `WP_READ_ONLY` and `WP_DISABLE_PLUGIN_MANAGEMENT`     |\n| `wp_deactivate_plugin`| Deactivate a plugin. Blocked by `WP_READ_ONLY` and `WP_DISABLE_PLUGIN_MANAGEMENT`   |\n| `wp_list_themes`      | List installed themes with active theme detection                                     |\n| `wp_get_theme`        | Get theme details by stylesheet slug                                                  |\n\n### Revisions (4)\n\n| Tool                 | Description                                                                              |\n|----------------------|------------------------------------------------------------------------------------------|\n| `wp_list_revisions`  | List revisions of a post or page (metadata only)                                         |\n| `wp_get_revision`    | Get a specific revision with full content                                                |\n| `wp_restore_revision`| Restore a post to a previous revision                                                    |\n| `wp_delete_revision` | Permanently delete a revision. Blocked by `WP_READ_ONLY`, `WP_DISABLE_DELETE`, `WP_CONFIRM_DESTRUCTIVE` |\n\n### Editorial Workflow & Visual Staging (9) — v3.2 / v4.15 / v5.1\n\nRequires `WP_REQUIRE_APPROVAL=true`.\n\n| Tool                   | Description                                                              |\n|------------------------|--------------------------------------------------------------------------|\n| `wp_submit_for_review` | Transition a draft post to pending status (author action)                |\n| `wp_approve_post`      | Transition a pending post to publish (editor/admin action)               |\n| `wp_reject_post`       | Return a pending post to draft with a mandatory rejection reason         |\n\n**Visual Staging (5)** — New in v4.15. Requires `WP_VISUAL_STAGING=true` for interception.\n\n| Tool | Description |\n|------|-------------|\n| `wp_create_staging_draft` | Clone a published page/post into a shadow draft for safe editing |\n| `wp_list_staging_drafts` | List all pending staging drafts, optionally filtered by source |\n| `wp_get_staging_preview_url` | Get native WordPress preview URL for a staging draft |\n| `wp_merge_staging_to_live` | Merge validated staging draft content to the live page (two-step) |\n| `wp_discard_staging_draft` | Permanently delete a staging draft without touching the live page |\n\n**Workflow Orchestrator (1)** — New in v5.1.\n\n| Tool | Description |\n|------|-------------|\n| `wp_run_workflow` | Execute named or custom tool sequences in a single call. Built-in: seo_audit_and_stage, site_health_report, content_publish_safe, wc_product_audit |\n\n### Internal Link Intelligence (2) — New in v3.3\n\n| Tool                        | Description                                                                            |\n|-----------------------------|----------------------------------------------------------------------------------------|\n| `wp_analyze_links`          | Audit all internal/external links in a post. HEAD verification per link                |\n| `wp_suggest_internal_links` | Semantic link suggestions scored by category, freshness, SEO keyword, title match      |\n\n### WooCommerce Core (6) — New in v3.4\n\nRequires `WC_CONSUMER_KEY` and `WC_CONSUMER_SECRET`.\n\n| Tool               | Description                                                                          |\n|---------------------|--------------------------------------------------------------------------------------|\n| `wc_list_products`  | List products with filtering by status, category, search, and sorting                |\n| `wc_get_product`    | Get product by ID with full details and variations summary                           |\n| `wc_list_orders`    | List orders with filtering by status, customer, and date                             |\n| `wc_get_order`      | Get order by ID with line items, shipping, billing, and payment details              |\n| `wc_list_customers` | List customers with search and role filtering                                        |\n| `wc_price_guardrail`| Analyze a price change for safety (read-only). Returns safe/unsafe                   |\n\n### WooCommerce Intelligence (4) — New in v3.5\n\n| Tool                      | Description                                                                        |\n|---------------------------|------------------------------------------------------------------------------------|\n| `wc_inventory_alert`      | Identify low-stock and out-of-stock products below threshold, sorted by urgency    |\n| `wc_order_intelligence`   | Customer purchase history: lifetime value, average order, favourite products        |\n| `wc_seo_product_audit`    | Audit product listings for SEO issues (descriptions, images, alt text, slugs)      |\n| `wc_suggest_product_links`| Suggest WooCommerce products to link from blog posts based on keyword relevance    |\n\n### WooCommerce Advanced Intelligence (7) — New in v4.12\n\nAll read-only.\n\n| Tool                               | Description                                                                        |\n|-------------------------------------|------------------------------------------------------------------------------------|\n| `wc_audit_product_seo`             | Product SEO score /100: title, description, slug, image alt, schema presence       |\n| `wc_find_abandoned_carts_pattern`  | Abandoned cart patterns: hourly/daily trends, top products, revenue loss            |\n| `wc_audit_checkout_friction`       | Checkout friction score 0-10: guest checkout, required fields, coupon, multi-step  |\n| `wc_get_product_performance`       | Product metrics with trend comparison: units sold, revenue, refund rate            |\n| `wc_audit_stock_alerts`            | Out-of-stock and low-stock audit with last sale dates. Includes variations         |\n| `wc_find_duplicate_products`       | Duplicates by SKU, title/slug Levenshtein similarity. Union-find grouping          |\n| `wc_audit_pricing_consistency`     | Pricing errors: sale >= regular, zero sale, minimal discounts, expired sales       |\n\n### WooCommerce Write (3) — New in v3.6\n\nAll blocked by `WP_READ_ONLY`.\n\n| Tool                  | Description                                                                          |\n|-----------------------|--------------------------------------------------------------------------------------|\n| `wc_update_product`   | Update product fields. Subject to `wc_price_guardrail` threshold enforcement         |\n| `wc_update_stock`     | Update stock quantity of a product or variation                                       |\n| `wc_update_order_status`| Transition order status (e.g., processing → completed)                             |\n\n### Operations (5)\n\n| Tool                   | Description                                                                          |\n|------------------------|--------------------------------------------------------------------------------------|\n| `wp_set_target`        | Switch active WordPress site in multi-target mode                                    |\n| `wp_site_info`         | Site info, current user, post types, enterprise controls, tool_categories, plugin_layer |\n| `wp_get_site_options`  | Read WordPress site settings (title, tagline, language, timezone) via /wp/v2/settings |\n| `wp_list_changes`      | What writes changed during this session, and whether each can be undone              |\n| `wp_rollback_change`   | Undo a listed change, restoring the fields it modified to their previous values      |\n\n---\n\n## Enterprise Controls\n\nConfigure execution policy via environment variables. All restrictions are enforced before any API call is made.\n\n| Control                        | Default     | Effect                                                                         |\n|--------------------------------|-------------|--------------------------------------------------------------------------------|\n| `WP_READ_ONLY`                 | `false`     | Blocks all write operations                                                    |\n| `WP_DRAFT_ONLY`                | `false`     | Restricts to draft and pending statuses only                                   |\n| `WP_DISABLE_DELETE`            | `false`     | Blocks all delete operations                                                   |\n| `WP_DISABLE_PLUGIN_MANAGEMENT` | `false`     | Blocks plugin activate/deactivate (list still allowed)                         |\n| `WP_REQUIRE_APPROVAL`          | `false`     | Blocks direct publish. Forces draft → pending → publish workflow               |\n| `WP_CONFIRM_DESTRUCTIVE`       | `false`     | Requires token confirmation before delete operations                           |\n| `WP_MCP_SECRET`                | _(ephemeral)_ | Signing secret for confirmation tokens. Unset = a random per-process secret is generated, so tokens stop being valid after a restart. Required when `WP_CONFIRM_DESTRUCTIVE=true` in HTTP mode |\n| `WP_VISUAL_STAGING`             | `false`     | When true, direct edits to published pages are intercepted. AI must use staging workflow: `wp_create_staging_draft` → edit draft → `wp_merge_staging_to_live` |\n| `WP_VALIDATE_BLOCKS`            | `false`     | When true, auto-validates Gutenberg block structure on `wp_update_post`/`wp_update_page`. Blocks update if errors found |\n| `WP_ALLOWED_TYPES`             | `all`       | Restricts to specific post types (e.g., `post,page`)                           |\n| `WP_ALLOWED_STATUSES`          | `all`       | Restricts to specific statuses (e.g., `draft,pending`)                         |\n| `WP_MAX_CALLS_PER_MINUTE`      | unlimited   | Client-side rate limiting                                                      |\n| `WP_AUDIT_LOG`                 | `on`        | Structured JSON audit trail                                                    |\n| `WP_AUDIT_CHAIN`               | `on`        | Adds `seq`, `prev` and `hash` to each audit entry. Keyed by `WP_MCP_SECRET` when it is set. Verify with `npm run verify:audit` |\n| `WP_COMPACT_JSON`              | `true`      | Compact JSON output (~30% token reduction). `false` for debugging              |\n| `WP_WRITE_DIFF`                | `auto`      | Compare a resource before and after each write. `auto` = posts and pages, `all` = every single-resource endpoint, `off` = disabled. Costs one extra GET per write |\n| `WP_CHANGE_JOURNAL_DURABLE`    | `auto`      | With the MCP Diagnostics companion installed, snapshots are also stored in WordPress and survive a restart. `off` skips the probe |\n| `WP_CHANGE_JOURNAL`            | `20`        | How many changes to keep in memory for `wp_list_changes`. `off` disables retention entirely. Never written to disk, lost on restart. See [Data Retention](#data-retention) |\n| `WP_TOOL_ENFORCE_PROFILE`      | `false`     | When true, a tool outside the active scope is refused instead of merely hidden. Off by default because the previous behaviour was documented |\n| `WP_TOOL_PROFILE`              | `editorial` | Named set of categories to expose: `editorial` · `shop` · `site` · `maintenance` · `all`. See [Tool profiles](#tool-profiles) |\n| `WP_TOOL_CATEGORIES`           | _(none)_    | Comma-separated categories to expose. **Takes precedence over `WP_TOOL_PROFILE`.** Always includes `core`. Categories: content · revisions · media · taxonomy · engagement · users · seo · audit · schema · intelligence · editorial · fse · widgets · plugins · pluginlayer · workflow · links · woocommerce · security · performance · health |\n| `PAGESPEED_API_KEY`             | _(none)_    | Google PageSpeed Insights API key. Optional — `wp_audit_page_speed` degrades gracefully |\n| `WPSCAN_API_KEY`                | _(none)_    | WPScan vulnerability database API key. Optional — free at wpscan.com/register  |\n\n### Previewing and verifying writes\n\nEvery tool that mutates something accepts `dry_run`. Nothing is sent: the server reports\nthe request it would have made and stops.\n\n```json\n{ \"dry_run\": true, \"status\": \"preview\", \"tool\": \"wp_update_post\",\n  \"would\": { \"method\": \"POST\", \"endpoint\": \"/posts/42\", \"body\": { \"title\": \"New title\" } } }\n```\n\nInterception lives in the API layer rather than in each tool, so it holds for writes\nreached indirectly and for any tool added later. A dry run bypasses `WP_READ_ONLY`,\n`WP_DISABLE_DELETE` and `WP_DISABLE_PLUGIN_MANAGEMENT` — nothing is sent, so those\ncontrols have nothing to protect, and seeing what a read-only deployment *would* do is\nwhat makes it auditable. Execution stops at the first write, so a tool performing several\nwrites shows only the first; `wp_bulk_update` and `wp_run_workflow` implement their own\nfuller previews.\n\nWrites that do run are compared against the resource as it was. `WP_WRITE_DIFF=auto`\n(the default) covers posts and pages, at the cost of one extra GET per write:\n\n```json\n{ \"success\": true,\n  \"changes\": { \"resource\": \"/posts/42\", \"effective\": true,\n               \"fields\": { \"title\": { \"before\": \"Old\", \"after\": \"New\" },\n                           \"content\": { \"lines_added\": 3, \"lines_removed\": 1 } } } }\n```\n\nThe field that matters is `effective`. A write can succeed and change nothing — the value\nsent was identical, WordPress rejected it silently, or a page builder masks it, which is\nexactly the Elementor failure the 5.6 guard was built for. A handler cannot tell you that\nabout itself; the comparison can.\n\n### Resources\n\nReference material addressed by URI, so an agent does not spend a tool call rediscovering\nit at the start of every conversation.\n\n| URI | What it holds |\n|---|---|\n| `wp://site` | Name, URL, timezone, and the account this server authenticates as |\n| `wp://post-types` | Registered post types and REST bases — the valid `post_type` values |\n| `wp://taxonomies` | Taxonomies, the types they apply to, their REST bases |\n| `wp://governance` | Which controls are on, which tools are exposed, what happens to a write |\n\n`wp://governance` answers \"why was that blocked\" with no round trip — it reads no network\nand works even when the site is unreachable.\n\nOnly genuinely referential data belongs here. An audit is a computation, not a document:\n`wp_audit(check, post_id)` takes arguments, a resource does not, so the audits stayed\ntools.\n\n### Prompts\n\nThe four built-in workflows are also exposed as MCP prompts, so a person can pick one in\ntheir client instead of describing it. They are generated from the workflow definitions,\nwhich means a prompt cannot describe a sequence the server does not run.\n\n| Prompt | Arguments | Steps |\n|---|---|---|\n| `seo_audit_and_stage` | `post_id` | content brief → heading audit → staging draft |\n| `site_health_report` | — | health status → issues → environment info |\n| `content_publish_safe` | `post_id`, `content` | validate blocks → publish |\n| `wc_product_audit` | — | product SEO → stock alerts |\n\nA prompt resolves to the same `wp_run_workflow` call an agent would make, with the\narguments filled in. Prompts are user-initiated: a model running on its own never invokes\none, and does not need to — the tool is there for it.\n\n### Undoing a write\n\nEach recorded change carries a `change_id`. `wp_list_changes` shows what this session\nchanged and whether each one can be undone; `wp_rollback_change` writes the previous\nvalues back.\n\n```json\n{ \"success\": true, \"rolled_back\": \"chg_3\", \"restored\": [\"title\", \"_yoast_wpseo_title\"],\n  \"undo_id\": \"chg_4\" }\n```\n\nA rollback is itself a write, so it lands in the journal as its own change — the undo can\nbe undone. Rolling the same change back twice is refused: the snapshot no longer describes\nthe resource.\n\nThree things are declared unrollbackable **when they are recorded**, not when you try:\n\n| Case | Why |\n|---|---|\n| The write changed nothing | There is nothing to put back |\n| Permanent deletion (`force=true`) | The resource, its ID and its relations are gone |\n| Previous state above 256 kB | Restoring a truncated payload would corrupt the resource |\n\nThe journal holds the last 20 changes in memory and loses them on restart — see\n[Data Retention](#data-retention). `wp_restore_revision` remains the separate, durable\npath for WordPress's own revisions, which cover post content but never meta.\n\n### Destructive confirmation flow\n\nWhen `WP_CONFIRM_DESTRUCTIVE=true`, `wp_delete_post` and `wp_delete_revision` return a stateless confirmation token on the first call instead of executing. Pass it back on a second call to confirm.\n\n```\nmcp_trash_42_1785250649_cf49af092d438e1b\n```\n\nHMAC-SHA-256 over the post, action and timestamp, truncated to 64 bits, compared in constant time, valid for 60 seconds, never stored. **Changed in 6.0** — the signature was 16 bits until then, which is a guardrail against an agent's mistake but not against a brute-force.\n\nTokens are signed with `WP_MCP_SECRET`. When it is not set the server generates a random secret at startup — tokens stay unforgeable, but they stop being valid after a restart and cannot be validated by a second instance. In stdio mode this only costs you pending tokens on restart, and the server logs a warning. In HTTP mode, where restarts and multiple instances are expected, the server refuses to start rather than offer a control it cannot honour.\n\n```bash\nWP_MCP_SECRET=$(openssl rand -hex 32)\n```\n\nThis is a guardrail against accidental deletion by the agent, not an authorisation mechanism — see [Safety Model](#safety-model).\n\nGovernance priority order: `WP_READ_ONLY` → `WP_DISABLE_DELETE` → `WP_CONFIRM_DESTRUCTIVE`\n\n### Deployment profiles\n\n**Agency content production** — writers can create and edit, but never publish or delete:\n```env\nWP_DRAFT_ONLY=true\nWP_DISABLE_DELETE=true\nWP_ALLOWED_STATUSES=draft,pending\nWP_MAX_CALLS_PER_MINUTE=30\n```\n\n**Editorial review workflow** — forces human approval before publication:\n```env\nWP_REQUIRE_APPROVAL=true\nWP_DISABLE_DELETE=true\nWP_AUDIT_LOG=on\n```\n\n**Compliance monitoring** — read-only access for auditing existing content:\n```env\nWP_READ_ONLY=true\nWP_AUDIT_LOG=on\n```\n\n**Regulated publishing** — restrict to specific content types in a controlled environment:\n```env\nWP_ALLOWED_TYPES=post\nWP_ALLOWED_STATUSES=draft,pending,publish\nWP_DISABLE_DELETE=true\nWP_AUDIT_LOG=on\n```\n\n**Locked infrastructure** — content operations allowed, but no plugin/theme changes:\n```env\nWP_DISABLE_PLUGIN_MANAGEMENT=true\nWP_DISABLE_DELETE=true\n```\n\n**E-commerce safe mode** — WooCommerce read and intelligence, no writes:\n```env\nWP_READ_ONLY=true\nWC_CONSUMER_KEY=ck_xxx\nWC_CONSUMER_SECRET=cs_xxx\n```\n\n**Locked down — nothing gets deleted:**\n```env\nWP_DISABLE_DELETE=true\nWP_DISABLE_PLUGIN_MANAGEMENT=true\nWP_REQUIRE_APPROVAL=true\nWP_TOOL_ENFORCE_PROFILE=true         # the profile refuses, it does not merely hide\nWP_VISUAL_STAGING=true\nWP_VALIDATE_BLOCKS=true\nWP_WRITE_DIFF=all\nWP_CHANGE_JOURNAL=50\nWP_MAX_CALLS_PER_MINUTE=30\n```\n\n**Deletion allowed, but never by accident** — the same, with deletion re-enabled behind a\nsigned confirmation:\n```env\nWP_DISABLE_DELETE=false\nWP_CONFIRM_DESTRUCTIVE=true\nWP_MCP_SECRET=<a stable secret>      # or tokens stop working after a restart\n```\n\nThe two are separate on purpose. The priority order is `WP_READ_ONLY` →\n`WP_DISABLE_DELETE` → `WP_CONFIRM_DESTRUCTIVE`, so turning on both `WP_DISABLE_DELETE` and\n`WP_CONFIRM_DESTRUCTIVE` is not stricter than the first alone — the confirmation is simply\nnever reached.\n\nNone of this replaces a narrowly scoped WordPress account — see [Safety Model](#safety-model).\n\n### Tool profiles\n\nA profile decides which categories reach ListTools. `editorial` is the default: it covers\nan article from brief to published and optimised, and leaves out the surface an editorial\nagent has no business touching — user management, plugin activation, file permissions,\nFull Site Editing, WooCommerce.\n\nThat is a reduction of surface first and of context second — but be precise about what\nkind of reduction.\n\n**By default a profile shapes ListTools, not the router.** A tool the profile withholds is\ninvisible to the model, so it will not be chosen by accident — and accident is the dominant\nrisk. It is *not* refused: a client that already knows the name can still call it. Until\n6.0 this page claimed the withholding was the stronger guarantee, which was true of\nmistakes and false of anyone deliberate.\n\nSet **`WP_TOOL_ENFORCE_PROFILE=true`** and the profile becomes a refusal:\n\n```\nBlocked: \"wp_delete_user\" is outside the active tool scope (profile \"editorial\"),\nand WP_TOOL_ENFORCE_PROFILE=true. Widen the scope to allow it.\n```\n\nIt stays opt-in because the previous behaviour was documented and someone may rely on it.\nTurn it on for anything shared or remote. The names retired in 6.0 resolve to their\nreplacement first, so `wp_audit_seo` is allowed exactly when `wp_audit` is in scope —\nenforcement does not quietly cancel the compatibility promise.\n\nEven enforced, this is a control inside the MCP process, not a WordPress permission: an\noperator who can restart the server can restart it without the flag. See\n[Safety Model](#safety-model).\n\nTwo columns, because a profile alone does not decide how many tools you see. **Out of the\nbox** is what a fresh install shows. **Fully enabled** adds the three conditional groups —\n`WC_CONSUMER_KEY`, `WP_REQUIRE_APPROVAL`, `WP_ENABLE_PLUGIN_INTELLIGENCE` — each of which\ngates its own tools regardless of profile.\n\n| Profile | Categories | Out of the box | Fully enabled |\n|---|---|---|---|\n| `editorial` *(default)* | content · revisions · seo · audit · schema · intelligence · editorial · media · taxonomy · links · engagement · workflow · pluginlayer | **68** · ~8.9k | 77 · ~9.9k |\n| `shop` | editorial + woocommerce | 68 · ~8.9k | **97** · ~12.0k |\n| `site` | content · revisions · media · taxonomy · fse · widgets · plugins · pluginlayer | 40 · ~5.2k | 40 · ~5.2k |\n| `maintenance` | health · performance · security · plugins · users | 40 · ~4.0k | 40 · ~4.0k |\n| `all` | everything | 108 · ~13.1k | 137 · ~16.2k |\n\n`core` is always exposed on top of the selected categories. `shop` shows the same 68 tools\nas `editorial` until WooCommerce credentials are configured — the profile admits the\ncategory, the credentials release the tools. `site` and `maintenance` contain none of the\nconditional groups, so their two columns are identical.\n\n```env\n# Default — no configuration needed\n# WP_TOOL_PROFILE=editorial\n\n# Everything, as before profiles existed\nWP_TOOL_PROFILE=all\n\n# Or pick categories directly — this always wins over WP_TOOL_PROFILE\nWP_TOOL_CATEGORIES=seo,content,schema\n```\n\n**A tool left out of the profile stays callable by default.** Profiles shape what is\nadvertised in ListTools, not what the server executes — nothing you scripted against stops\nworking. Set `WP_TOOL_ENFORCE_PROFILE=true` to make the profile refuse instead.\n\n**Existing deployments are unaffected.** `WP_TOOL_CATEGORIES` takes precedence over\n`WP_TOOL_PROFILE`, so a configuration written before profiles existed keeps its exact\nbehaviour. Only deployments that set neither move from the full catalogue to `editorial`.\nThe active profile and the exposed count are logged at startup and reported by\n`wp_site_info`.\n\nBlocked actions return a clear error message explaining which control prevented execution, and are logged in the audit trail with status `blocked`.\n\n---\n\n## MU-Plugin Companion\n\nSome tools require the optional MCP Diagnostics companion mu-plugin to access data not available via the WordPress REST API.\n\n### Installation\n```bash\ncp companion/mcp-diagnostics.php /path/to/wp-content/mu-plugins/\n```\n\n### Exposed endpoints\n\n**Diagnostics** — require `manage_options`\n\n| Endpoint                                    | Method | Description                              |\n|---------------------------------------------|--------|------------------------------------------|\n| `/mcp-diagnostics/v1/debug-log`             | GET    | Last N lines of `debug.log` by level     |\n| `/mcp-diagnostics/v1/cron-events`           | GET    | All scheduled WP-Cron events             |\n| `/mcp-diagnostics/v1/transients`            | GET    | Database transients with expiration/size  |\n| `/mcp-diagnostics/v1/hooks`                 | GET    | Registered actions and filters            |\n\n**Security** — require `manage_options`\n\n| Endpoint                                    | Method | Description                              |\n|---------------------------------------------|--------|------------------------------------------|\n| `/mcp-diagnostics/v1/user-activity`         | GET    | Admin last login timestamps              |\n| `/mcp-diagnostics/v1/file-permissions`      | GET    | Critical file permission checks          |\n| `/mcp-diagnostics/v1/modified-files`        | GET    | Recently modified file listing           |\n\n**Performance** — requires `manage_options`\n\n| Endpoint                                    | Method | Description                              |\n|---------------------------------------------|--------|------------------------------------------|\n| `/mcp-diagnostics/v1/database-bloat`        | GET    | Database bloat analysis                  |\n\n**WooCommerce** — requires `manage_options`\n\n| Endpoint                                    | Method | Description                              |\n|---------------------------------------------|--------|------------------------------------------|\n| `/mcp-diagnostics/v1/wc-abandoned-carts`    | GET    | Abandoned cart data from available sources|\n\n**Schema** — requires `edit_posts`\n\n| Endpoint                                    | Method | Description                              |\n|---------------------------------------------|--------|------------------------------------------|\n| `/mcp-diagnostics/v1/schema/{post_id}`      | GET    | Read `_custom_schema_jsonld` meta        |\n| `/mcp-diagnostics/v1/schema/{post_id}`      | POST   | Write schema meta. Blocked by `WP_READ_ONLY` |\n| `/mcp-diagnostics/v1/schema/{post_id}`      | DELETE | Remove schema meta. Blocked by `WP_READ_ONLY` |\n\n**Polylang Free** — public (no auth required)\n\n| Endpoint                                             | Method | Description                      |\n|------------------------------------------------------|--------|----------------------------------|\n| `/mcp-diagnostics/v1/polylang/languages`             | GET    | Polylang languages list          |\n| `/mcp-diagnostics/v1/polylang/translations/{post_id}`| GET    | Post translations by language    |\n\n**Users** — requires `manage_options`\n\n| Endpoint                                    | Method | Description                              |\n|---------------------------------------------|--------|------------------------------------------|\n| `/mcp-diagnostics/v1/password-reset`        | POST   | Trigger password reset email             |\n\nDiagnostics endpoints require `manage_options` (Administrator). The change journal below requires `edit_others_posts` instead — restoring a snapshot rewrites content, so it is g","readmeFilename":"README.md"}