Tell your AI what you need. It handles WordPress.
No dashboard clicking, no code. Not a chatbot or a writing tool — a real agent that talks to your site over MCP and does the work, safely, with every action logged. New to MCP? Start with the WordPress MCP server guide.
Up and running in minutes.
The plugin walks you through the rest.
-
1
Install the plugin
In WordPress, open Plugins → Add New, search for Cowboy MCP, and click Install then Activate.
-
2
Connect your AI
Open Settings → Cowboy MCP and follow the guided setup — from an app or your terminal.
-
3
Just ask
Tell your agent what you need in plain English — Cowboy MCP handles WordPress.
// connect your client
Any client that speaks MCP works — Windsurf, Cline, Zed, VS Code & n8n included.
Full control, in plain English.
Content Management
Write, edit, schedule, and bulk-update posts, pages, and media.
Site Administration
Update plugins and themes, manage users, and change site settings.
Page Building
Build pages with the block editor or Elementor, and manage templates.
SEO
Read, write, and audit Yoast SEO and Rank Math meta across the site — titles, descriptions, robots, social cards.
Custom Fields
Read and write ACF fields, field groups, repeaters, and options pages.
E-Commerce
Run your WooCommerce store — products, orders, coupons, and stock.
Forms
Detect the active forms plugin — WPForms, Gravity Forms, or Contact Form 7 — so the agent knows what it is working with.
Performance
Flush and preload caches and read cache settings for WP Rocket, LiteSpeed Cache, and W3 Total Cache.
Security
Run Wordfence scans, manage the firewall, and review blocked IPs.
Checkpoints & Safe Updates
One-click database checkpoints, file backups before every plugin or theme update, and a health check that restores automatically if an update breaks the site.
Your site stays locked down.
You're handing an AI the keys to your site. Every operation is guarded, reversible, and accounted for.
Destructive operations (delete, update) require explicit confirmation. No accidental nuking.
Preview what any tool will do before it does it. See the blast radius before you pull the trigger.
Every MCP action is logged with timestamp, user, tool, and parameters. Full accountability trail.
120 requests per minute by default. Configurable per-key. Prevents runaway agents.
Keys are stored only as one-way hashes, never in plain text — the plain key can't be recovered from your database, even in a breach.
Every change lands in an undo journal, and one-click database checkpoints restore your site's database tables. Roll back one edit — or all of it.
Comparing WordPress MCP plugins? See all options compared, or head-to-head: Novamira · AI Engine · WPVibe.
Questions, answered.
Everything you need to know about running WordPress from an AI agent with Cowboy MCP.
What is Cowboy MCP, and how is it different from other WordPress AI plugins?
Cowboy MCP is a free, open-source WordPress plugin. It turns your site into an MCP (Model Context Protocol) server, so AI agents can manage it in plain English. Most rivals just bundle a chatbot or focus on content and SEO. Cowboy MCP manages the whole site — posts, WooCommerce, Wordfence security, plugin and theme updates, Elementor, ACF, and caching — and every change can be undone. And every risky action asks first, with a dry-run preview you can check before it runs.
Can ChatGPT or Claude actually edit my WordPress site, or just write drafts?
Actually edit it. Cowboy MCP gives your AI real tools — it creates and updates posts and pages, changes WooCommerce products and prices, updates plugins, runs Wordfence scans, takes backups, and more, directly on your live site. It's not a writing assistant that hands you text to paste; it does the work. And because safe mode is on by default, anything destructive asks for your confirmation first, with a dry-run preview.
Will this work on my self-hosted WordPress site, or only on WordPress.com?
Any self-hosted WordPress site — version 6.2 or newer, on PHP 8.0+ — where you can install plugins. That's the kind of site hosted on Bluehost, SiteGround, your own server, and so on. It isn't limited to WordPress.com and doesn't depend on any particular host. You install one plugin and connect your AI, and everything runs on your own server.
Is Cowboy MCP a chatbot for my visitors?
No. It's not a customer-facing chat widget, and it's not an AI writing plugin. Cowboy MCP connects the AI assistant you already use — Claude, ChatGPT, Codex — to your site's admin so it can manage WordPress for you behind the scenes. Your visitors never see it.
Can the AI accidentally break or delete things on my site?
It's hard to. Safe mode is on by default, so destructive tools won't run without your confirmation. Any write tool can also do a dry run first, to preview the change. Every call is recorded in an audit log. Sensitive settings and risky database or WP-CLI commands are blocklisted. And the most powerful tools stay behind an admin-only "power mode" that only a human can switch on in wp-admin.
Can I undo what the AI changed?
Yes. Every change lands in a per-change undo journal, so you can roll back a single edit without touching anything else. Before bigger moves, take a one-click database checkpoint and restore your site's database tables to it if needed. Plugin and theme updates get the same treatment — backup first, health check after, one-command undo if anything breaks.
Does my content or data get sent to a third party?
Cowboy MCP runs entirely on your own server. It adds no outside service and sends your data nowhere on its own. Your AI client connects straight to your site, so the only thing that sees your content is the AI tool you picked. There's no Cowboy cloud, proxy, or tracking in between.
Which AI tools can connect to it?
Two ways. From a desktop or web app — Claude Desktop, Claude.ai, ChatGPT, or the Codex app — add Cowboy MCP as a custom connector and sign in through your browser. No terminal needed. From a terminal tool — Claude Code, Codex, or Opencode — register your site as an MCP server with its endpoint URL and an API key. Any client that speaks the Streamable HTTP transport works — Cursor, Windsurf, Cline, Zed, VS Code, Gemini, and n8n included.
How do I connect my WordPress site to ChatGPT or Claude?
In your WordPress dashboard, go to Plugins → Add New, search for Cowboy MCP, and click Install then Activate. After that, connect an app or a terminal tool — the Get started section above has the full two-path walkthrough.
Do I need Node.js, a config file, or any coding to set it up?
No. Install the plugin, open Settings → Cowboy MCP, and follow the guided setup. The no-terminal path lets you add your site as a connector in Claude, ChatGPT, or the Codex app and approve a browser sign-in — no Node.js, no JSON config, no command line. Power users can still connect a terminal tool with an API key if they prefer.
How do API keys work, and can I revoke access?
You create keys in the plugin settings. They're stored only as one-way hashes — the raw key is shown once, never again, and can't be recovered from your database. You can issue several keys, name them, and revoke any one of them. Each key is rate-limited (120 requests per minute by default) to keep a runaway agent in check.
What are the requirements?
A self-hosted WordPress site (version 6.2 or newer, on PHP 8.0+) where you can install plugins. Nothing else — no Composer, npm, build step, or outside service. Integrations like WooCommerce, ACF, Elementor, Yoast or Rank Math, Wordfence, and the major caching plugins turn on automatically when those plugins are active.
Is it really free?
Yes. Cowboy MCP is free and open source under the GPL-2.0 license — no pro tier, paywalled tools, or usage limits. Install it from the WordPress plugin directory, activate it on your site, and connect your agent.