WPGuard Core

A WordPress MCP server for reviewable AI edits.

WPGuard connects Claude, Cursor and Codex to WordPress through SSH with WP-CLI or a companion plugin. Inspect stored values, preview supported edits, check scoped requirements, and read back the result.

Self-hosted · MIT licensed · Bring your own AI client

What can this WordPress MCP server change?

WPGuard supports selected content, settings and field edits. Name the page or stored value, inspect its current state, and preview the exact change before applying it.

Update the offer, keep the terms

Preview a text replacement on a selected page while preserving the required booking terms. Save those terms as a check for later supported edits.

Fix the link, keep the answer

Replace a specific broken link in stored post content. Review the matching text and proposed replacement before applying it.

Find the field before changing it

Inspect the site, its active plugins, options and post metadata. Identify the actual value behind the requested change.

Show what changed

Review the saved prior value and change record. Then run WPGuard’s desktop and mobile render check and keep the screenshot receipt.

Protect the requirements you already settled.

Correction rules are explicit and scoped. They check supported edits before writing; they do not automatically turn every chat message into site policy.

Keep the required wording

Turn a specific requirement into a check for a named site and field. Supported edits are checked against active rules before they write.

Keep exceptions where they belong

A rule for one page stays on that page. A client preference does not become a rule for every site you manage.

See why a check exists

Keep the originating correction alongside the rule. Review, test, or retire it when the requirement changes.

Bring your own history

Keep a private record of requests and corrections so your assistant can retrieve earlier work for the right client.

Choose the connection your site supports.

Use SSH with WP-CLI, or install the companion plugin for its supported HTTPS operations.

SSH + WP-CLI

Use a host you operate and a WordPress path you have verified. Raw PHP execution is a separate privileged operation.

Companion plugin

Install the PHP companion and configure its shared secret. It exposes an allowlist of WordPress operations for sites where SSH is unavailable; keep its key private.

Work across registered sites

Connect WordPress through SSH with WP-CLI or the companion plugin, then use the tools supported by that connection.

Connect your AI client to WordPress.

WPGuard runs on infrastructure you control. Install Core, connect one staging site, then use the setup guide for your AI client.

Read the Core installation guide and the approval and verification limits before connecting a production site.

Give your next WordPress task to your AI.

Connect one site. Inspect it. Preview one useful change.