Free and open source

Install it on your terms.

WPGuard Core is MIT-licensed. Run it on infrastructure you control and connect the AI client you already use.

Self-hosted · MIT licensed · Bring your own AI client

Everything in Core is available without Cloud.

Site inspection, supported WordPress edits, local change records and scoped correction checks are included in the open-source repository.

Run the server

Follow the installation guide for source installation or a local Docker build. Set a strong bearer token and keep the server reachable only by intended clients.

Connect WordPress

Register a site using SSH and WP-CLI, or install the companion PHP plugin and configure its HTTPS connection.

Inspect first

List registered sites and read the site context. Confirm the site and target before preparing a change.

Preview one edit

Choose a small content or settings change. Review the proposed value, approve the matching packet, and verify the result.

Install the server and the WordPress connection.

WPGuard runs outside WordPress. Each site connects through infrastructure you choose and control.

Pull the published container

Version 0.4.0 is available as a public Linux amd64 and arm64 image at ghcr.io/cgallic/wpguard-mcp:0.4.0. Bind port 8642 to loopback, mount persistent state, and provide a generated server token at runtime.

Or install from source

Python 3.10 or newer can install the repository in an isolated environment. The same wpguard-mcp command starts the authenticated Streamable HTTP endpoint used by compatible clients.

Use SSH when WP-CLI is available

The SSH transport runs named WP-CLI operations through a host and WordPress path you register. Mount or forward only the SSH credentials that installation needs; the site registry stores references rather than copying private keys.

Use the companion when SSH is unavailable

Install the versioned companion ZIP from the GitHub release and set its shared secret. The plugin exposes an allowlist of REST operations for trusted operators. It does not expose raw PHP evaluation.

Read the code behind the promise.

The source, tests and limitations are public.

Check what you need first.

A short list. Most WordPress developers already have it.

Python 3.10 or newer and Git

You install WPGuard from the cloned repository into a virtual environment. Commands for Windows PowerShell, macOS and Linux are in the setup guide. Docker Compose can build the same checkout instead.

SSH and WP-CLI, or plugin access

The SSH connection needs an SSH client on the server machine and WP-CLI on the WordPress host. The companion connection needs permission to install and activate a plugin.

A staging site for the first edit

Register a staging copy first. Check the result there before you use the same workflow on production.

A client that speaks Streamable HTTP

Point the client at http://127.0.0.1:8642/mcp and send an Authorization: Bearer header with your server token. A hosted client cannot reach your computer through its own 127.0.0.1.

Pick the lowest token scope that works.

The server will not start without a token. Each scope reaches a different set of tools.

Recon

WPGUARD_TOKEN_RECON covers discovery and read tools. It is not strictly read-only. It can read secret options, and magic login creates a WordPress login link.

Mutate

WPGUARD_TOKEN_MUTATE adds named edits, site registration and packet approval. A mutate caller can approve its own packet.

Admin

WPGUARD_TOKEN_ADMIN adds correction rules and the raw PHP and WP-CLI tools. Use it only where those tools are needed.

Scopes cover the whole instance

A token can reach every site registered on that instance. To keep clients apart, run separate instances with separate state and credentials.

Know what Core does not cover.

The limits are written down so you can plan around them.

Checks cover named edits only

Correction checks run on option, post-meta, post-content, full-page, block and revision writes. Raw PHP, SQL, file edits, new posts and changes made outside WPGuard use different safeguards.

Saved values are not backups

Supported edits save the prior value. Not every operation can be undone. Keep your regular site backups.

The local ledger has one writer

Packet and snapshot records live in the state directory of one instance. They are not a shared database for a team.

Rendered checks are bounded

Render verification catches HTTP failures, overflow, broken images and missing text. It does not judge design or click through the page. Read the full boundaries →

Make your first useful edit.

Connect one site. Inspect it. Preview one useful change.