WordPress MCP plugins compared
Which WordPress MCP plugins exist in 2026?
As of 22 August 2026, eleven plugins in the WordPress.org directory ship a working MCP server for WordPress, and the three biggest AI plugins in the directory — AI Engine, Angie, and the official AI plugin — sit beside them rather than among them, because MCP is either one module of a larger product or not shipped at all. The table lists every one of them with live numbers from the WordPress.org plugin API and the facts each vendor states in its own listing. Nothing in it is an editorial score: installs, ratings, and dates are the directory's; tool counts are the vendors' own claims; and the undo, endpoint, OAuth, and Abilities API columns summarise the listing text on the fetch date, with Cowboy MCP (this site) held to exactly the same wording.
Two things help when reading it. Active installs are WordPress.org's rounded buckets, so "10,000+" means somewhere between ten and twenty thousand. And the category is young: the oldest entry was added in December 2025 and ten of the eleven arrived in 2026, so the install column measures momentum at least as much as maturity.
| Plugin | Active installs | Rating (n) | Added | Model / price | Tools (vendor claim) | Undo / rollback | Where the endpoint runs | OAuth | Abilities API | Live Preview |
|---|---|---|---|---|---|---|---|---|---|---|
| WPVibe (opens in new tab) | 10,000+ | 96 (24) | 2026-04-20 | Free plugin; the hosted relay service is freemium — a free plan with a daily WordPress-action allowance, paid plans raise it | — | Theme-file backup on publish and trash for deletes; no per-change undo | WPVibe cloud relay (Cloudflare-hosted) forwarding to your site's REST API | Relay sign-in by magic link; no on-site OAuth server | Consumes abilities registered by other plugins | No |
| Royal MCP (opens in new tab) | 10,000+ | 100 (7) | 2026-01-14 | Free (GPL) core; paid Royal MCP Pro tier | 85 core + 80 integration | Undo tokens reverse the last delete or reorder within 72 hours (mcp_undo_last_operation) | Your site — /wp-json/royal-mcp/v1/mcp | Yes — OAuth 2.0 with dynamic client registration, or API-key header | Own tool registry; Abilities API mentioned only in the FAQ | Yes |
| Easy MCP AI (opens in new tab) | 8,000+ | 100 (8) | 2026-03-25 | Free; listing states no paid tiers and no usage limits | 243 | Change history with before/after snapshots and diffs; no undo tool stated | Your site — /wp-json/easy-mcp-ai/v1/mcp | Yes — OAuth 2.0/2.1 with PKCE and dynamic client registration, or Bearer token | Consumes — auto-exposes abilities registered by other plugins | No |
| Enable Abilities for MCP (opens in new tab) | 2,000+ | 100 (8) | 2026-03-24 | Free; requires WordPress 6.9+ and the MCP Adapter plugin | 84 abilities in 18 categories | None stated | Your site, served by the official MCP Adapter | Yes — embedded OAuth 2.1 server (since 2.1), or Application Password / Bearer token | Built on it | No |
| StifLi Flex MCP (opens in new tab) | 1,000+ | 100 (4) | 2025-12-08 | Free (optional Copilot/Chat on your own AI key) | 122+ built-in (200+ with integrations) | Before/after snapshot change log with one-click rollback, redo, and session rollback; no database checkpoints | Your site | Yes — OAuth 2.1 with PKCE and dynamic client registration, or Application Password | Consumes — imports abilities registered by other plugins | No |
| WSP MCP – AI Agents Connector (opens in new tab) | 800+ | 100 (4) | 2026-07-13 | Free | — | None stated; audit log in your own database | Your site — native endpoint (Streamable HTTP) | No — Application Password or plugin API key | No — the adapter/Abilities path was removed in 2.2 | No |
| miniOrange Secure MCP Server (opens in new tab) | 400+ | 100 (2) | 2026-06-04 | Free; listing states all features included with no restrictions | 300+ | None stated; audit trail and post-revision restore tools | Your site — /wp-json/mosmcp/v1/mcp | Yes — self-hosted OAuth 2.1 with PKCE and dynamic client registration, or API key | Built on it ("Abilities API native") | No |
| NIBWP (opens in new tab) | 100+ | 100 (1) | 2026-06-19 | Free core; paid NibWP Pro adds plugin integrations and skills | — | None stated | Your site, bundled official MCP Adapter | No — WordPress Application Passwords | Built on it | No |
| AtlasAI Connector (opens in new tab) | 100+ | — (0) | 2026-01-02 | Free core; paid Pro with a 7-day trial | 80+ abilities | None stated; Pro adds a backups manager for its error-fix flow | Your site — /wp-json/awfah_mcp/mcp, bundled MCP Adapter | Yes — OAuth 2.1 with PKCE and dynamic client registration, or JWT / Application Password | Built on it; third-party ability discovery is Pro | Yes |
| Agent Abilities for MCP (opens in new tab) | 80+ | 90 (2) | 2026-07-02 | Free; listing states no paid tier | 153 governed abilities (83 core + 70 integrations) | None stated; deletes go to trash; audit log | Your site, served by the official MCP Adapter | Yes — OAuth, or Application Password | Built on it | Yes |
| Cowboy MCP (opens in new tab) (this site) | 30+ | 100 (1) | 2026-07-03 | Free; no Pro tier | 168 | Per-change undo journal, one-click database checkpoints, audit log | Your site — /wp-json/cowboy-mcp/v1/endpoint | Yes — OAuth 2.1 (optional), or API key | No — own tool registry | Yes |
| Context: the three biggest AI plugins in the directory — adjacent, not standalone MCP servers | ||||||||||
| AI Engine (opens in new tab) | 100,000+ | 98 (860) | 2022-12-27 | Free core; paid Pro — MCP is one module of a chatbot/AI framework | — | Approval dialog before changes in its Workspace; no undo stated | Your site | Yes — OAuth for desktop clients, or bearer token | Not stated | No |
| Angie – Agentic AI (opens in new tab) | 100,000+ | 60 (15) | 2025-09-17 | Free tier with daily renewing credits; in-admin agent by Elementor | — | Test Mode preview and manual approval to production; snippet revisions | In-admin agent backed by a cloud service; an 'Angie MCP' client connection was added in 1.1.12 | n/a | Registers its tools as abilities (1.1.12) | No |
| AI (WordPress canonical plugin) (opens in new tab) | 40,000+ | 92 (8) | 2025-12-02 | Free canonical plugin; MCP is listed under "Developer Tools Coming Soon" — no MCP server today | — | n/a | n/a — no MCP server | n/a | Built on it (Abilities Explorer) | Yes |
Data: WordPress.org plugin API, fetched 22 August 2026 (active installs, rating, number of ratings, date added, and Live Preview from the directory; everything else from each plugin's own listing text on that date). The machine-readable version, including 30-day downloads, last-updated dates, and tested-up-to versions, is at /data/wordpress-mcp-plugins.json.
What about MCP options outside the WordPress.org directory?
Several of the most-discussed WordPress MCP servers are not in the directory at all — they ship from GitHub, from a vendor's own site, or as part of a hosting platform — so a directory-only view would miss the official adapter, the most-starred community projects, and every hosted option. The figures are vendor claims from the linked primary sources, not directory data, checked on 22 August 2026.
| Option | Where you get it | Model / price | Tools (vendor claim) | Undo / rollback | Notes | Source |
|---|---|---|---|---|---|---|
| Novamira | GitHub release ZIP, installed by hand (opens in new tab) | Free core under AGPL-3.0; paid Pro add-on from €49 a year | 38 abilities | No undo journal or checkpoints; README guidance is dev/staging with backups | Self-hosted; built on the Abilities API and the bundled official MCP Adapter; execute-php, WP-CLI, and file abilities; OAuth sign-in | README (opens in new tab) |
| WordPress MCP Adapter | GitHub / Composer (official WordPress project) (opens in new tab) | Free, open source; version 0.6.1 released 13 August 2026 | whatever abilities the site registers | None | Self-hosted; the official Abilities-to-MCP bridge; many clients connect through the mcp-wordpress-remote Node.js proxy | repository (opens in new tab) |
| WordPress.com MCP | Built into WordPress.com (opens in new tab) | Included on every paid WordPress.com plan | see tools reference | None stated | Hosted platform; OAuth 2.1; the same Automattic family covers WooCommerce and Pressable | tools reference (opens in new tab) |
| InstaWP InstaMCP | Built into InstaWP hosting (opens in new tab) | Sandbox plan and above | 43 | None stated for MCP itself (staging sites recommended) | Hosted platform; one dashboard toggle; connection URL with an embedded token | product page (opens in new tab) |
| EMCP Tools | GitHub (free) + Freemius (Pro) (opens in new tab) | Free up to 209 MCP tools; paid Pro unlocks all 267, annual or lifetime licences | 209 free / 267 Pro | Snapshots before brand-kit changes with rollback; a change ledger (vendor claim) | Self-hosted; Elementor-focused plus WordPress core; OAuth 2.1 sign-in | emcptools.com (opens in new tab) |
| Respira | Direct from respira.press (opens in new tab) | Paid per-site tiers (1, 10, or 250 sites) with a 7-day full trial | 210+ (catalog of 320+) | SafeEdit preview/approve and TimeSnap rollback (vendor claim) | Self-hosted; 17 page builders; the MCP server is open source on GitHub | GitHub (opens in new tab) |
| NibWP Pro | Direct from nibwp.com (opens in new tab) | Paid upgrade to the free NIBWP directory plugin | integrations for 30+ plugins | None stated | Self-hosted; adds schema-typed integrations (WooCommerce, Elementor, Bricks, ACF, Yoast, Rank Math…) and builder skills | nibwp.com (opens in new tab) |
The self-hosted vs hosted comparison explains what separates the platform rows from the plugin rows: who sits in the data path, whether a Node.js process is involved, and what happens to local and staging sites.
How should you choose?
The right WordPress MCP plugin depends on what you need the agent to be trusted with, and the directory now holds a credible option for each of five distinct needs. Grouping by need is fairer than ranking, because these plugins optimise for different things.
- Production safety and reversibility. If the agent will touch a live site, look for a stated way back. Cowboy MCP journals every change and takes one-click database checkpoints; StifLi Flex MCP records a before-and-after snapshot per change with one-click undo, redo, and whole-session rollback; Royal MCP issues undo tokens that reverse the last delete or reorder within 72 hours. Outside the directory, EMCP Tools and Respira both advertise snapshots with rollback.
- Free with no metering. If you want no paid tier and no daily cap, Easy MCP AI has the largest free toolset, Agent Abilities for MCP ships everything off by default at no cost, and Cowboy MCP is free with no Pro tier — and WSP MCP, miniOrange, and Enable Abilities for MCP say the same in their listings. WPVibe's plugin is free but its relay meters actions per day on the free plan; Royal MCP, NIBWP, and AtlasAI Connector keep part of the product behind a paid tier.
- Hosted convenience. If you would rather not run an endpoint, WPVibe's relay gives one-click authorisation for any self-hosted site, WordPress.com includes MCP on every paid plan, and InstaWP's InstaMCP is a dashboard toggle on its platform. The trade is a third party in the data path, which the self-hosted vs hosted page weighs in detail.
- Raw power on staging. If the job is building rather than operating, Novamira hands the agent PHP execution, WP-CLI, and file access and tells you to use it on dev and staging copies with backups; Angie's opt-in Super Admin Mode opens the file system, database, and PHP layer from inside wp-admin; Cowboy MCP's Power mode lifts its WP-CLI and file guardrails while keeping the checkpoints and undo journal in place.
- Official and Abilities-first. If staying closest to core matters most, the WordPress MCP Adapter is the official bridge, and Enable Abilities for MCP, Agent Abilities for MCP, NIBWP, AtlasAI Connector, and miniOrange all build on the Abilities API; Easy MCP AI, StifLi, and WPVibe consume abilities that other plugins register. Cowboy MCP does not: it uses its own typed tool registry, a deliberate trade of core alignment for guardrails and undo.
How does Cowboy MCP compare head-to-head?
Cowboy MCP's own position in the table is easy to state: it is the smallest entry by installs, added to the directory in July 2026; it is free with no Pro tier; the endpoint stays on your site with OAuth optional; it ships 168 typed tools; and it is one of the few plugins in the category with a per-change undo journal and database checkpoints. It is not built on the Abilities API. For the detailed trade-offs against individual rivals, this site publishes seven comparisons, each with a dated, sourced table:
- Cowboy MCP vs WPVibe — native endpoint or hosted relay, and what metering means day to day.
- Cowboy MCP vs AI Engine — a focused MCP plugin against a broad AI framework whose MCP server is one module.
- Cowboy MCP vs InstaWP MCP — any self-hosted site against a platform-integrated toggle.
- Cowboy MCP vs the WordPress MCP Adapter — tools against abilities, and the Node.js proxy question.
- Cowboy MCP vs Novamira — guardrails and undo against direct PHP execution on staging.
- Cowboy MCP vs StifLi Flex MCP — the two directory plugins that both lead with undo.
- Self-hosted vs hosted WordPress MCP — the four architectures and who is in your data path.
How is this data collected?
Every number in the first table comes from two public WordPress.org endpoints, and every qualitative cell is a paraphrase of the plugin's own listing, so anyone can re-run the collection and check the result. The directory numbers come from the plugin information API (active installs, rating, number of ratings, date added, last updated, tested-up-to) and the 30-day download totals from the download-stats API, summed over the trailing thirty days; Live Preview is read from the public listing page. The model, tool-count, undo, endpoint, OAuth, and Abilities API columns are taken from each listing's description, FAQ, and changelog on the fetch date, and where a listing does not state something the cell says so rather than guessing. Tool counts are labelled vendor claims because they are not independently counted and vendors count differently — some count abilities, some count tools, some add a plus. Cowboy MCP's figure is the count published on this site.
The result is published as a dataset at /data/wordpress-mcp-plugins.json, with a generated date, the source endpoints, and one record per plugin holding the raw numbers and the same listing-sourced fields as the table, so it can be loaded into a spreadsheet or cited directly. The page and the file are refreshed monthly, and the date at the top of the page changes when they are. If you find an error, or a vendor ships a change between refreshes, open an issue on the Cowboy MCP GitHub repository (opens in new tab) with a link to the primary source and the row will be corrected.
FAQ
Is there an official WordPress MCP plugin?
No. WordPress core does not ship an MCP server and the WordPress.org directory has no official MCP plugin; WordPress 7.1 added Abilities API lifecycle hooks but no MCP endpoint. The official route is the WordPress MCP Adapter, a GitHub and Composer package from the WordPress project that exposes registered abilities over MCP, and the canonical AI plugin lists MCP under its coming-soon developer tools. Several directory plugins build on that adapter and the Abilities API, including Enable Abilities for MCP, Agent Abilities for MCP, NIBWP, AtlasAI Connector, and miniOrange.
Which WordPress MCP plugins are free?
Seven directory plugins state in their listings that they are free with no paid tier mentioned: Cowboy MCP, Easy MCP AI, Enable Abilities for MCP, StifLi Flex MCP, WSP MCP, miniOrange Secure MCP Server, and Agent Abilities for MCP. Royal MCP, NIBWP, AtlasAI Connector, and AI Engine are free at the core with a paid Pro tier, and WPVibe's plugin is free but its relay service meters actions per day on the free plan. Outside the directory, the WordPress MCP Adapter and Novamira's core are free, while WordPress.com MCP, InstaWP, Respira, EMCP Pro, and NibWP Pro are paid.
Which WordPress MCP plugins work on localhost?
Any plugin whose endpoint runs on your own site works on a local install with clients that run on the same machine — Claude Code, Cursor, Codex, and Gemini CLI — because they connect over plain HTTP with an API key or application password and need no public URL, and Claude Desktop can reach a local endpoint through the small mcp-remote bridge. Relay and platform options cannot: WPVibe needs a URL its cloud can reach, and WordPress.com and InstaWP MCP exist only on those platforms.
Which WordPress MCP plugins need a public HTTPS site?
Anything that connects from a vendor's servers rather than from your machine. The claude.ai and ChatGPT custom connectors authorise over OAuth from Anthropic's and OpenAI's backends, so every plugin with an on-site OAuth server needs a public HTTPS address for that path, and several listings warn that hosting firewalls or Cloudflare's AI-bot blocking can break it. WPVibe's relay likewise needs a reachable site, and the hosted platforms are public by nature. Terminal clients, and Claude Desktop through a local bridge, are the exception.
How often is this comparison updated?
Monthly. The numbers are re-fetched from the WordPress.org plugin API, the qualitative columns are re-checked against each listing at the same time, and the page's last-updated date and the generated field in the JSON file record the fetch date. If a vendor changes pricing, adds undo, or ships OAuth between refreshes, open an issue on the Cowboy MCP GitHub repository with a link to the source and the row will be corrected.