Self-hosted server or hosted relay

Choose WPGuard when the work must stay reviewable and repeatable.

WPGuard runs on infrastructure you control, preserves page-specific corrections, gates supported writes, and returns desktop and mobile evidence for the finished page.

What is the difference between WPGuard and WPVibe?

WPVibe hosts the MCP service at https://mcp.wpvibe.ai/mcp and relays authorized HTTPS requests to WordPress. WPGuard Core is the MCP service, so its operator owns the runtime, tokens, site registrations, and local records.

QuestionWPVibeWPGuard
How does setup start?Add WPVibe’s remote MCP URL, sign in by emailed code, and authorize the site from wp-admin.Install Core, set a server token, add its Streamable HTTP URL to the client, and register a site.
How does it reach WordPress?WPVibe documents HTTPS requests through its hosted relay. The authorized WordPress user’s capabilities constrain site operations.WPGuard uses SSH with WP-CLI or the WPGuard companion plugin. Each transport carries its own credentials and boundaries.
What is the main work surface?WPVibe documents REST operations, media, Abilities, WP-CLI-style commands, rendered-page inspection, skills, and a draft-theme lifecycle.WPGuard exposes named inspection and mutation tools, local change packets, snapshots for supported writes, imported history, and exact-target correction checks.
How does preview work?WPVibe’s theme workflow uses an isolated draft, a private preview URL, an explicit publish step, and a backup of the previous theme.Guarded value-mutation tools preview the old and proposed value. After the write, WPGuard can capture desktop and mobile screenshots and check measurable rendering failures.
How is risk handled?WPVibe documents dry runs and browser approval for destructive or high-risk operations. Content deletes prefer WordPress trash.Guarded value writes use packet approval, state checks, and applicable correction checks. Advanced PHP, SQL, file, and CLI operations have different safeguards.

WPVibe’s draft theme is a specific preview workflow.

WPVibe’s strongest documented preview path applies to theme work. It should not be generalized into a universal rollback promise.

Draft, preview, publish

WPVibe documents an isolated draft clone for theme changes. An authorized user can open a tokenized private preview. Publication requires an explicit instruction and keeps a backup of the previous theme files.

Content and REST work

WPVibe also exposes WordPress REST operations and a broader plugin toolset. The product’s public safety material describes WordPress trash, risk-based approval, and dry-run behavior for selected high-risk actions.

WPGuard value previews

WPGuard previews supported option, post-meta, and post-content replacements before apply. It can compare the live value to the preview state and block an out-of-date request.

WPGuard correction checks

An explicit rule can preserve required text, a scalar or JSON value, or an HTML link on its named site and field. The rule does not automatically extend to files, raw PHP, SQL, new posts, or another site.

Which service should manage your WordPress site?

Choose the operating boundary first. Then test the exact editor, plugin, field, and recovery path your work requires.

Choose WPVibe for a managed remote connector

WPVibe fits a site owner who wants one hosted MCP URL, email sign-in, wp-admin authorization, broad WordPress tools, and a draft-first theme workflow without running a separate MCP server.

Choose WPGuard for server ownership

WPGuard fits an operator who wants to self-host the MCP layer, control its state directory and credentials, connect sites over SSH or a companion plugin, and retain exact-target correction records.

Check the site’s network path

WPVibe needs a WordPress REST API its cloud service can reach. A local-only site needs a tunnel. WPGuard can run beside a local client or on a reachable server, but the operator must configure that route securely.

Keep recovery claims narrow

A draft-theme backup, WordPress trash, or a saved prior value can help with specific actions. None of those proves universal rollback. Keep normal backups and test the recovery procedure for the exact operation.

Compare one real task on staging.

Use the same target, acceptance condition, approval rule, browser check, and recovery test.