WordPress MCP plugins compared

Which WordPress MCP plugins exist in 2026?

As of 5 October 2026, fourteen plugins in the WordPress.org directory ship a working MCP server for WordPress, and the three biggest AI plugins in the directory — AI Engine, Angie, and the official AI plugin — sit beside them rather than among them, because MCP is either one module of a larger product or not shipped at all. The table lists every one of them with live numbers from the WordPress.org plugin API and the facts each vendor states in its own listing. Nothing in it is an editorial score: installs, ratings, and dates are the directory's; tool counts are the vendors' own claims; and the undo, endpoint, OAuth, and Abilities API columns summarise the listing text on the fetch date, with Cowboy MCP (this site) held to exactly the same wording.

Two things help when reading it. Active installs are WordPress.org's rounded buckets, so "10,000+" means somewhere between ten and twenty thousand. And the category is young: the oldest entry was added in December 2025 and thirteen of the fourteen arrived in 2026 — the official MCP Adapter only on 2 October, so the install column measures momentum at least as much as maturity.

WordPress.org MCP plugins compared — directory data and listing-stated facts, 2026-10-05
PluginActive installsRating (n)AddedModel / priceTools (vendor claim)Undo / rollbackWhere the endpoint runsOAuthAbilities APILive Preview
WPVibe (opens in new tab)50,000+100 (97)2026-04-20Free plugin; the hosted relay service is freemium — the free plan includes every tool with a daily allowance of WordPress actions, and optional paid plans raise the allowance—Theme-file backup on publish and trash for deletes; no per-change undoWPVibe cloud relay (Cloudflare-hosted) forwarding to your site's REST APIRelay sign-in by magic link; no on-site OAuth serverConsumes abilities registered by other pluginsNo
MCP Adapter (opens in new tab)40,000+— (0)2026-10-02Free; the official WordPress.org plugin (AI Building Blocks for WordPress), in the directory since 2 October 2026; requires WordPress 6.9+—None statedYour site — built-in HTTP transport (plus STDIO)Not stated — clients authenticate as a WordPress userBuilt on it — the official Abilities-to-MCP bridgeNo
Royal MCP (opens in new tab)10,000+100 (7)2026-01-14Free (GPL) core; paid Royal MCP Pro tier (launched September 2026, per-site and agency licences)200+ (90 core + 136 integration)Undo tokens reverse the last delete or reorder within 72 hours (mcp_undo_last_operation)Your site — /wp-json/royal-mcp/v1/mcpYes — OAuth 2.0 with dynamic client registration, or API-key headerConsumes — surfaces abilities registered by other plugins alongside its own toolsYes
Easy MCP AI (opens in new tab)10,000+100 (11)2026-03-25Free; listing states no paid tiers and no usage limits; acquired by Themeisle (September 2026)280+Change history with before/after snapshots and diffs; no undo tool statedYour site — /wp-json/easy-mcp-ai/v1/mcpYes — OAuth 2.0/2.1 with PKCE and dynamic client registration, or Bearer tokenConsumes — exposes the abilities you select from other pluginsNo
Enable Abilities for MCP (opens in new tab)4,000+100 (12)2026-03-24Free; requires WordPress 6.9+ and the MCP Adapter plugin112 abilities in 21 categoriesNone statedYour site, served by the official MCP AdapterYes — embedded OAuth 2.1 server (since 2.1), or Application Password / Bearer tokenBuilt on itNo
StifLi Flex MCP (opens in new tab)800+100 (4)2025-12-08Free (optional Copilot/Chat on your own AI key)122+ built-in (200+ with integrations)Before/after snapshot change log with one-click rollback, redo, and session rollback; no database checkpointsYour siteYes — OAuth 2.1 with PKCE and dynamic client registration, or Application PasswordConsumes — imports abilities registered by other pluginsNo
WSP MCP – AI Agents Connector (opens in new tab)2,000+100 (5)2026-07-13Free190+None stated; audit log in your own database (90-day retention since 2.7)Your site — native endpoint (Streamable HTTP)Yes — built-in OAuth 2.1 server (since 2.8, off until an admin enables it), or plugin key / Application PasswordNo — the adapter/Abilities path was removed in 2.2No
miniOrange Secure MCP Server (opens in new tab)5,000+100 (7)2026-06-04Free; listing states all features included with no restrictions300+None stated; audit trail and post-revision restore toolsYour site — /wp-json/mosmcp/v1/mcpYes — self-hosted OAuth 2.1 with PKCE and dynamic client registration, or API keyBuilt on it ("Abilities API native")No
NIBWP (opens in new tab)300+100 (2)2026-06-19Free core; paid NibWP Pro adds plugin integrations and skills—None statedYour site, bundled official MCP AdapterNo — WordPress Application PasswordsBuilt on itNo
AtlasMCP (opens in new tab)200+— (0)2026-01-02Free core; paid Pro with a 7-day trial—None stated; Pro adds a backups manager for its error-fix flowYour site — /wp-json/awfah_mcp/mcp, bundled MCP AdapterYes — OAuth 2.1 with PKCE and dynamic client registration, or JWT / Application PasswordBuilt on it; consumes other plugins’ abilities in the free versionYes
Agent Abilities for MCP (opens in new tab)500+90 (2)2026-07-02Free; listing states no paid tier179 governed abilities (85 core + 94 integrations)None stated; deletes go to trash; audit logYour site, served by the official MCP AdapterYes — OAuth, or Application PasswordBuilt on itYes
Cowboy MCP (opens in new tab) (this site)600+100 (4)2026-07-03Free; no Pro tier203Per-change undo journal, one-click database checkpoints, audit logYour site — /wp-json/cowboy-mcp/v1/endpointYes — OAuth 2.1 (optional), or API keyBoth ways since 1.6.4 — registers its tools as abilities and consumes other plugins’ abilitiesYes
Invizo MCP (opens in new tab)100+100 (1)2026-06-19Free; no paid tier stated in listing—None stated; dry-run previews and confirm flags for destructive operationsYour site — /wp-json/mcp/invizo, bundled official MCP AdapterNo — WordPress Application Passwords (administrator-only)Built on itNo
AICOM – AI Commander (opens in new tab)60+100 (1)2026-04-21Free; no paid tier stated in listing87+Automatic snapshot before every update, trash, delete, or edit; one-call restore of the previous version or one-click restore of a whole sessionYour site — /wp-json/aicom/v1/mcp (fallback /?aicom=1); also an OpenAPI schemaNo — scoped API keys stored as bcrypt hashes (Bearer)Not statedNo
Context: the three biggest AI plugins in the directory — adjacent, not standalone MCP servers
AI Engine (opens in new tab)90,000+98 (869)2022-12-27Free core; paid Pro — MCP is one module of a chatbot/AI framework—Approval dialog before changes in its Workspace; no undo statedYour siteYes — OAuth for desktop clients, or bearer tokenConsumes — an MCP setting turns registered abilities into MCP toolsNo
Angie – Agentic AI (opens in new tab)100,000+62 (18)2025-09-17Free tier with daily renewing credits; in-admin agent by Elementor—Test Mode preview and manual approval to production; snippet revisionsIn-admin agent backed by a cloud service; an 'Angie MCP' connection for external MCP clients arrived in the 1.1.x releases (August 2026)n/aBoth — registers its tools as abilities (1.1.12) and discovers abilities other plugins registerNo
AI (WordPress canonical plugin) (opens in new tab)50,000+92 (9)2025-12-02Free canonical plugin; MCP is listed under "Developer Tools Coming Soon" — no MCP server today; the official MCP Adapter is a separate directory plugin since October 2026—n/an/a — no MCP servern/aBuilt on it (Abilities Explorer)Yes

Data: WordPress.org plugin API, fetched 5 October 2026 (active installs, rating, number of ratings, date added, and Live Preview from the directory; everything else from each plugin's own listing text on that date). The machine-readable version, including 30-day downloads, last-updated dates, and tested-up-to versions, is at /data/wordpress-mcp-plugins.json.

What about MCP options outside the WordPress.org directory?

Several of the most-discussed WordPress MCP servers are not in the directory at all — they ship from GitHub, from a vendor's own site, or as part of a hosting platform — so a directory-only view would miss the most-starred community projects, the paid builder-focused servers, and every hosted option. The figures are vendor claims from the linked primary sources, not directory data, checked on 5 October 2026. The official WordPress MCP Adapter used to sit here; it joined the directory on 2 October 2026 and now appears in the first table.

WordPress MCP options outside the WordPress.org directory, 2026-10-05
OptionWhere you get itModel / priceTools (vendor claim)Undo / rollbackNotesSource
NovamiraGitHub release ZIP, installed by hand (opens in new tab)Free core under AGPL-3.0; paid Pro add-on from €49 a year (Personal) to €149 a year (Agency)38 abilitiesNo undo journal or checkpoints; README guidance is dev/staging with backupsSelf-hosted; built on the Abilities API and the bundled official MCP Adapter; execute-php, WP-CLI, and file abilities; OAuth sign-inREADME (opens in new tab)
WordPress.com MCPBuilt into WordPress.com (opens in new tab)Included on every paid WordPress.com plansee tools referenceNone statedHosted platform; OAuth 2.1; the same Automattic family covers WooCommerce and Pressabletools reference (opens in new tab)
InstaWP InstaMCPBuilt into InstaWP hosting (opens in new tab)Sandbox plan and above43None stated for MCP itself (staging sites recommended)Hosted platform; one dashboard toggle; connection URL with an embedded tokenproduct page (opens in new tab)
EMCP ToolsGitHub (free) + Freemius (Pro) (opens in new tab)Free up to 196 MCP tools; paid Pro unlocks all 277, annual or lifetime licences196 free / 277 ProSnapshots before brand-kit changes with rollback; a change ledger (vendor claim)Self-hosted; Elementor-focused plus WordPress core; OAuth 2.1 sign-inemcptools.com (opens in new tab)
RespiraDirect from respira.press (opens in new tab)Paid per-site tiers from €71 a year (1 site) to €451 a year (25 sites), with a 7-day full trial210+ (catalog of 320+)SafeEdit preview/approve and TimeSnap rollback (vendor claim)Self-hosted; 17 page builders; the MCP server is open source on GitHubGitHub (opens in new tab)
NibWP ProDirect from nibwp.com (opens in new tab)Paid upgrade to the free NIBWP directory plugin — €49 a year per site, or €79 with all skills190+ across 66 integrationsNone statedSelf-hosted; adds schema-typed integrations (WooCommerce, Elementor, Bricks, ACF, Yoast, Rank Math…) and builder skillsnibwp.com (opens in new tab)

The self-hosted vs hosted comparison explains what separates the platform rows from the plugin rows: who sits in the data path, whether a Node.js process is involved, and what happens to local and staging sites.

How should you choose?

The right WordPress MCP plugin depends on what you need the agent to be trusted with, and the directory now holds a credible option for each of five distinct needs. Grouping by need is fairer than ranking, because these plugins optimise for different things.

How does Cowboy MCP compare head-to-head?

Cowboy MCP's own position in the table is easy to state: it sits in the lower half of the table by installs, added to the directory in July 2026; it is free with no Pro tier; the endpoint stays on your site with OAuth optional; it ships 203 typed tools; and it is one of the few plugins in the category with a per-change undo journal and database checkpoints. Since 1.6.4 it also bridges to the Abilities API in both directions — its tools are registered as abilities, and other plugins’ abilities appear as tools — while keeping its own registry. For the detailed trade-offs against individual rivals, this site publishes seven comparisons, each with a dated, sourced table:

How is this data collected?

Every number in the first table comes from two public WordPress.org endpoints, and every qualitative cell is a paraphrase of the plugin's own listing, so anyone can re-run the collection and check the result. The directory numbers come from the plugin information API (active installs, rating, number of ratings, date added, last updated, tested-up-to) and the 30-day download totals from the download-stats API, summed over the trailing thirty days; Live Preview is read from the public listing page. The model, tool-count, undo, endpoint, OAuth, and Abilities API columns are taken from each listing's description, FAQ, and changelog on the fetch date, and where a listing does not state something the cell says so rather than guessing. Tool counts are labelled vendor claims because they are not independently counted and vendors count differently — some count abilities, some count tools, some add a plus. Cowboy MCP's figure is the count published on this site.

The result is published as a dataset at /data/wordpress-mcp-plugins.json, with a generated date, the source endpoints, and one record per plugin holding the raw numbers and the same listing-sourced fields as the table, so it can be loaded into a spreadsheet or cited directly. The page and the file are refreshed monthly, and the date at the top of the page changes when they are. If you find an error, or a vendor ships a change between refreshes, open an issue on the Cowboy MCP GitHub repository (opens in new tab) with a link to the primary source and the row will be corrected.

FAQ

Is there an official WordPress MCP plugin?

Yes, since 2 October 2026. The MCP Adapter, published by WordPress.org as part of the AI Building Blocks for WordPress initiative, is now a directory plugin; it turns the abilities a site registers into MCP tools, resources, and prompts, but provides no AI features of its own, so it needs abilities from core or another plugin to be useful. WordPress core itself still ships no MCP endpoint, and the canonical AI plugin lists MCP under its coming-soon developer tools; WordPress 7.2 (due 9 December 2026) adds core content abilities for querying, creating, updating, and deleting content. Several directory plugins build on the adapter and the Abilities API, including Enable Abilities for MCP, Agent Abilities for MCP, NIBWP, AtlasMCP, and miniOrange.

Which WordPress MCP plugins are free?

Nine directory plugins state in their listings that they are free with no paid tier mentioned: Cowboy MCP, Easy MCP AI, Enable Abilities for MCP, StifLi Flex MCP, WSP MCP, miniOrange Secure MCP Server, Agent Abilities for MCP, AICOM, and Invizo MCP. The official MCP Adapter has no paid tier either. Royal MCP, NIBWP, AtlasMCP, and AI Engine are free at the core with a paid Pro tier, and WPVibe's plugin is free but its relay service meters actions per day on the free plan. Outside the directory, Novamira's core is free, while WordPress.com MCP, InstaWP, Respira, EMCP Pro, and NibWP Pro are paid.

Which WordPress MCP plugins work on localhost?

Any plugin whose endpoint runs on your own site works on a local install with clients that run on the same machine — Claude Code, Cursor, Codex, and Gemini CLI — because they connect over plain HTTP with an API key or application password and need no public URL, and Claude Desktop can reach a local endpoint through the small mcp-remote bridge. Relay and platform options cannot: WPVibe needs a URL its cloud can reach, and WordPress.com and InstaWP MCP exist only on those platforms.

Which WordPress MCP plugins need a public HTTPS site?

Anything that connects from a vendor's servers rather than from your machine. The claude.ai and ChatGPT custom connectors authorise over OAuth from Anthropic's and OpenAI's backends, so every plugin with an on-site OAuth server needs a public HTTPS address for that path, and several listings warn that hosting firewalls or Cloudflare's AI-bot blocking can break it. WPVibe's relay likewise needs a reachable site, and the hosted platforms are public by nature. Terminal clients, and Claude Desktop through a local bridge, are the exception.

Do I still need an MCP plugin now that the official MCP Adapter is in the directory?

Usually, and you can run both. The adapter is infrastructure: it exposes only the abilities a site registers and opts in, and leaves confirmation, undo, and logging to the abilities and the client. If you need a working toolset with a way back, install a directory plugin alongside it; Cowboy MCP has registered its tools as public abilities since 1.6.4, so with the adapter active those tools appear through it as well, and nothing you set up is wasted.

How often is this comparison updated?

Monthly. The numbers are re-fetched from the WordPress.org plugin API, the qualitative columns are re-checked against each listing at the same time, and the page's last-updated date and the generated field in the JSON file record the fetch date. If a vendor changes pricing, adds undo, or ships OAuth between refreshes, open an issue on the Cowboy MCP GitHub repository with a link to the source and the row will be corrected.