Webmastery Site Toolkit for MCP adds 70+ permission-aware abilities across 16 areas that AI agents and MCP clients can call through the official MCP Adapter plugin. It works with popular MCP clients including Claude, ChatGPT, GitHub Copilot, and Gemini.
The MCP Adapter provides the transport layer. This plugin provides the site-management vocabulary: posts, pages, media, comments, taxonomy, custom post types, post meta, content hygiene, SEO checks, public webmaster verification, site info, health, security, users, plugins, database, performance, and backup status.
Core editorial workflows work well with a dedicated Editor service account. Sensitive workflows such as plugin management, user auditing, site health, database health, backup status, performance status, and security audits require a separate Administrator service account.
Highlights:
All abilities enforce WordPress capability checks. If the connected account cannot perform the equivalent WordPress action, the ability fails instead of bypassing WordPress permissions. List abilities for posts, pages, custom post types, media, and SEO scores also filter each returned object before exposing full details, so private, trashed, draft, pending, and scheduled content follows WordPress object/status permissions.
For full setup instructions, ability tables, and the deeper security model, visit:
https://www.virtuallyboring.com/webmastery-site-toolkit-for-mcp/