Cursor + WordPress

Connect Cursor to WordPress.

Add WPGuard to Cursor’s MCP configuration, keep the bearer token in your environment, and give Cursor a structured path from site inspection to a reviewed WordPress change.

Self-hosted · Cursor project or global config · Environment-backed token

How do I add a WordPress MCP server to Cursor?

Create .cursor/mcp.json for one project or ~/.cursor/mcp.json for every local workspace. Cursor accepts a remote server URL and custom headers in either location.

.cursor/mcp.json
{
  "mcpServers": {
    "wpguard": {
      "url": "http://127.0.0.1:8642/mcp",
      "headers": {
        "Authorization": "Bearer ${env:WPGUARD_TOKEN_ADMIN}"
      }
    }
  }
}

Keep the token outside JSON

Cursor expands ${env:NAME} inside remote-server headers. Set WPGUARD_TOKEN_ADMIN in the environment that launches Cursor. Remote HTTP entries do not load an envFile, so restarting Cursor may be required after changing the environment.

Use Cursor’s remote-server shape

A Cursor HTTP entry uses url and optional headers; it does not need Claude Code’s type field. Confirm the current format in the official Cursor MCP documentation →

Test Cursor with a read-only WordPress task first.

Make the connection visible in Cursor, then use a small discovery call to separate MCP setup problems from WordPress access problems.

Find the server in Cursor

Open Cursor’s MCP or Available Tools view and confirm that wpguard is connected. Cursor shows tool failures in chat. Use the MCP Logs output when the server does not initialize or the tool catalog is missing.

List sites before selecting one

Ask Cursor to call site_list. Register a staging site when the list is empty. Then call wp_site_context so Cursor can identify the site transport, active theme, plugins, fields, and available tools before suggesting an edit.

Distinguish local and cloud Cursor

A local Cursor process can reach 127.0.0.1 on the same computer. A cloud or remote agent cannot reach your laptop through its own loopback address. Give that environment an authenticated HTTPS route to WPGuard instead.

Keep tool approval visible

Cursor asks for MCP tool approval by default. Review the exact tool and arguments, especially for a write. Cursor approval lets the call run; it does not replace WPGuard’s packet, correction, or state checks.

Use Cursor for the file context and WPGuard for the WordPress state.

Cursor can reason across the project in your editor. WPGuard reads the registered WordPress site and returns the stored value that a supported tool would change.

Preview against the current value

Ask for apply=False on supported value changes. Check the returned old value, new value, correction result, state tag, and digest. Apply only the matching request after approval.

Inspect the browser result

A successful read-back confirms the stored WordPress value. It does not confirm responsive layout, JavaScript behavior, link health, or visual regressions. Open the published page separately after the write.

Use the repository’s Cursor configuration with the published WPGuard security boundaries.

Connect Cursor to a staging site.

Confirm the MCP server, inspect WordPress, and preview one exact field change.