Operations server or WordPress Abilities bridge

Choose WPGuard when you need the workflow, not another integration layer.

WPGuard arrives with named WordPress tools, guarded previews, persistent corrections, rollback checks, and desktop and mobile evidence. Connect a site and start with a real maintenance task.

What is the WordPress MCP Adapter?

The WordPress MCP Adapter is an official WordPress AI Team package. It converts registered WordPress Abilities into MCP tools, resources, and prompts. The available business operations depend on the Abilities that core or installed plugins register and expose.

QuestionWordPress MCP AdapterWPGuard
What layer is it?An adapter between the WordPress Abilities API and MCP. Developers can use its default server or register custom MCP servers.A standalone MCP server with a built-in WordPress operations surface and two connection transports.
What does installation require?Current documentation requires WordPress 6.9 or newer and PHP 7.4 or newer.Core requires Python 3.10 or newer. The companion plugin declares WordPress 5.6 or newer and PHP 8.0 or newer. SSH transport requires WP-CLI on the target host.
What does the default server expose?Three meta-tools discover public Abilities, inspect one Ability’s schema, and execute an Ability.Named tools inspect sites, content, fields, plugins, themes, settings, files, blocks, packets, snapshots, and correction records.
How are operations selected?Abilities are private by default. A developer opts them into MCP with public metadata, and each Ability keeps its permission callback.The server defines its tool catalog. Token tiers determine which tools a caller can access, and the registered site determines the WordPress connection.
What safety lifecycle is included?The adapter documents transport authentication, per-Ability permissions, error handling, and observability. Generic preview, human approval, verification, snapshot, and rollback behavior must come from the Ability, plugin, client, or surrounding workflow.Three value-mutation tools include preview, packet/state checks, applicable correction checks, and prior-value capture. Other exposed operations do not inherit all of those controls.

How does the Adapter expose WordPress Abilities?

The default server uses a discover, inspect, and execute pattern instead of turning every Ability into a top-level tool.

Discover public Abilities

An Ability is not exposed automatically. Its registration must opt into public or MCP-public access. The default server then lists the Abilities available to the authenticated WordPress user.

Inspect the Ability schema

The client requests details for a named Ability before execution. The Ability supplies its input and output schema, description, and permission behavior.

Execute under WordPress permissions

The default server requires an authenticated user with read access. The selected Ability also runs its own permission callback. A custom server can define a different transport permission callback.

Choose HTTP or WP-CLI STDIO

The Adapter documents Streamable HTTP at a WordPress REST endpoint and STDIO through WP-CLI. Its HTTP examples use the Automattic remote proxy with WordPress authentication.

When should you use the Adapter or WPGuard?

Choose by the extension model you need. The Adapter is a protocol bridge for Abilities. WPGuard is an operator-facing server with a ready-made tool catalog.

Use the Adapter to expose WordPress-native Abilities

It fits plugin developers and platform teams already building on the Abilities API. They can keep WordPress schemas and permission callbacks close to the code that implements each operation.

Use WPGuard for packaged maintenance operations

It fits operators who want inspection and mutation tools without first authoring Abilities. It can connect sites over SSH or the companion plugin and keep its ledger outside WordPress.

Do not infer operations from the protocol

Installing the Adapter does not create generic post, plugin, theme, or file CRUD by itself. Those actions exist only when WordPress core or another plugin registers and exposes the required Abilities.

Do not infer universal safety from either product

The Adapter’s permission callbacks do not create a universal approval or rollback system. WPGuard’s correction and packet controls cover named value mutations, not every tool. Test the exact action and recovery path.

Choose the layer your WordPress stack needs.

Build and expose an Ability, or connect WPGuard Core and inspect one supported site change.