For agency teams

WordPress MCP for agencies.
Keep each client’s rules.

WPGuard connects your AI to named WordPress sites. Preview supported edits, keep each client’s requirements in the right scope, and review the result before moving to the next site.

Self-hosted · MIT licensed · Bring your own AI client

Fewer repeated explanations.

Turn explicit requirements into checks at the narrowest useful scope. A new task can use the requirement without inheriting another client’s preferences.

Keep the required wording

Turn a specific requirement into a check for a named site and field. Supported edits are checked against active rules before they write.

Keep exceptions where they belong

A rule for one page stays on that page. A client preference does not become a rule for every site you manage.

See why a check exists

Keep the originating correction alongside the rule. Review, test, or retire it when the requirement changes.

Bring your own history

Keep a private record of requests and corrections so your assistant can retrieve earlier work for the right client.

Keep the work easy to review.

Make each request about a named site and target. Retain the proposal, approval and verification result.

Inspect

Read the site context and the value you plan to change. Choose a supported action for that site and transport.

Preview

See the previous and proposed value. Review the exact target and any applicable correction checks.

Approve and apply

Approve the change packet, then apply the matching request. Pass the preview’s state check to catch edits made in the meantime.

Verify

Read the stored result back, then capture desktop and mobile screenshots with checks for expected text, overflow, headings, and broken images.

Start with one site. Expand when it fits.

Core is free to self-host. The Agency plan adds shared access for 5 teammates across 25 sites.

Agency offer

$79/month or $790/year. Includes 25 sites, 5 seats, and one year of Cloud history.

Founding offer

The first 20 agencies receive 50% off for 12 months: $39 per month with onboarding included and no setup fee.

Keep each client's sites apart.

Client separation is something you set up. Here is how.

One instance per client when it matters

Token scopes apply to the whole instance. If one client must not be reachable from another client's work, give it its own instance, registry, state directory and credentials.

A client filter is not a permission

History queries match the client name exactly. That keeps retrieval tidy. It does not stop a caller from asking about another client on the same instance.

Rules stay on their target

A correction applies to one registered site and one target, such as a single post body. It does not spread to other pages or other clients.

A dedicated WordPress user per site

For the companion plugin, create a dedicated administrator and an Application Password. Revoke that password in WordPress to cut off access.

Bring the history you already have.

Past requests and corrections can inform the next task without becoming instructions.

Import packet exports

Load packet, status and category CSVs from earlier work. Repeating an identical import changes nothing. Changed records keep their earlier versions.

Import richer session records

Episode JSONL files need an episode ID, client and site on each record. Extra evidence fields are kept.

Imports stay historical

Imported status labels remain reports. Turning one into an active check is a separate step that needs a failing and a passing example.

Imports stay private

Records stay in the instance's state directory. A query sends the selected records to your connected AI client, so choose that client with care.

Test on staging, then touch production.

Routine maintenance runs the same way on every client site.

Stage a page change

Register staging and production as separate sites. The staged run applies only to staging, captures desktop and mobile evidence, and returns a fresh production preview. Production still needs its own approval.

Update one plugin or theme

On SSH sites, an update previews the installed and target versions. After an approved update, WPGuard checks WordPress, PHP and the public site. It restores the prior version if a check fails.

Keep scheduled work narrow

Admins can create a preapproval policy tied to one site, source, set of verbs, target pattern and maximum risk. Anything outside it stays blocked.

Cloud adds the shared record

Core keeps records on your instance. Cloud adds shared packet history, approval decisions and team seats. Cloud never holds SSH keys, Application Passwords or plugin keys. A person sets up billing; there is no self-serve checkout yet.

Bring us a real maintenance workflow.

Tell us how your team handles WordPress changes and which sites you need to connect.