Run the server
Follow the installation guide for source installation or a local Docker build. Set a strong bearer token and keep the server reachable only by intended clients.
WPGuard Core is MIT-licensed. Run it on infrastructure you control and connect the AI client you already use.
Self-hosted · MIT licensed · Bring your own AI client
Site inspection, supported WordPress edits, local change records and scoped correction checks are included in the open-source repository.
Follow the installation guide for source installation or a local Docker build. Set a strong bearer token and keep the server reachable only by intended clients.
Register a site using SSH and WP-CLI, or install the companion PHP plugin and configure its HTTPS connection.
List registered sites and read the site context. Confirm the site and target before preparing a change.
Choose a small content or settings change. Review the proposed value, approve the matching packet, and verify the result.
WPGuard runs outside WordPress. Each site connects through infrastructure you choose and control.
Version 0.4.0 is available as a public Linux amd64 and arm64 image at ghcr.io/cgallic/wpguard-mcp:0.4.0. Bind port 8642 to loopback, mount persistent state, and provide a generated server token at runtime.
Python 3.10 or newer can install the repository in an isolated environment. The same wpguard-mcp command starts the authenticated Streamable HTTP endpoint used by compatible clients.
The SSH transport runs named WP-CLI operations through a host and WordPress path you register. Mount or forward only the SSH credentials that installation needs; the site registry stores references rather than copying private keys.
Install the versioned companion ZIP from the GitHub release and set its shared secret. The plugin exposes an allowlist of REST operations for trusted operators. It does not expose raw PHP evaluation.
The source, tests and limitations are public.
A short list. Most WordPress developers already have it.
You install WPGuard from the cloned repository into a virtual environment. Commands for Windows PowerShell, macOS and Linux are in the setup guide. Docker Compose can build the same checkout instead.
The SSH connection needs an SSH client on the server machine and WP-CLI on the WordPress host. The companion connection needs permission to install and activate a plugin.
Register a staging copy first. Check the result there before you use the same workflow on production.
Point the client at http://127.0.0.1:8642/mcp and send an Authorization: Bearer header with your server token. A hosted client cannot reach your computer through its own 127.0.0.1.
The server will not start without a token. Each scope reaches a different set of tools.
WPGUARD_TOKEN_RECON covers discovery and read tools. It is not strictly read-only. It can read secret options, and magic login creates a WordPress login link.
WPGUARD_TOKEN_MUTATE adds named edits, site registration and packet approval. A mutate caller can approve its own packet.
WPGUARD_TOKEN_ADMIN adds correction rules and the raw PHP and WP-CLI tools. Use it only where those tools are needed.
A token can reach every site registered on that instance. To keep clients apart, run separate instances with separate state and credentials.
The limits are written down so you can plan around them.
Correction checks run on option, post-meta, post-content, full-page, block and revision writes. Raw PHP, SQL, file edits, new posts and changes made outside WPGuard use different safeguards.
Supported edits save the prior value. Not every operation can be undone. Keep your regular site backups.
Packet and snapshot records live in the state directory of one instance. They are not a shared database for a team.
Render verification catches HTTP failures, overflow, broken images and missing text. It does not judge design or click through the page. Read the full boundaries →
Connect one site. Inspect it. Preview one useful change.