On Page Navigation

Managed WordPress MCP Setup for Content WooCommerce SEO

Our WordPress plugin turns a site into an MCP server exposing 382 tools, across core, WooCommerce, Yoast, Rank Math, Contact Form 7, Elementor and Jetpack. It is free and it is on the plugin directory, so installing it costs you nothing at all. What nobody hands you is a decision about which of those 382 an agent should hold, which user it connects as, and what happens the first time it misreads an instruction. That is the part we run.

Cascadia engineer working across dual monitors.

Three hundred and eighty two tools, and a shorter list

What makes our managed WordPress MCP different

Installing the plugin takes an afternoon, and we built it to be that easy on purpose. Far fewer people will sit down first and work out what an agent should never be allowed to do. The second job is the one that matters once the agent can publish to a site your customers read.

So the setup below is mostly about boundaries. Which post types an agent may read, which it may draft, and what it is never allowed to publish without a person looking first. An application password scoped to its own user rather than an administrator account borrowed from somebody on your team. Revocation that takes one click and breaks nothing else. Every action logged and attributable. And a written scope you sign off before the connector touches a live site, because the alternative is finding the limits in public.

Why the short list beats the fast install

Managed WordPress MCP against wiring it up yourself

Most teams connect an agent the quickest way that works, which usually means an application password generated against whichever login already had administrator. Nothing goes wrong on day one. Every row below is about who carries the consequence later.

The agent connects as a user built for the job

Wiring it up in a hurry means generating an application password against whoever already held administrator. The agent inherits that reach permanently, and nobody goes back to narrow it.

Write access earned one tool at a time, after testing

The fast path enables all 382 tools at once, delete and publish included. That is fine until an agent reads a vague instruction generously and changes something a customer then reads before you do.

Somebody has read the capability list, not just set it

Capabilities and access profiles are both real protections, and both only work if a person reads them. Configured in a hurry, they become a permission set nobody can describe six months later.

A dropped connection repaired at no extra charge

Passwords get revoked, plugins update and clients stop authenticating. Coverage includes unlimited repairs on the connections we manage, with no charge per incident and no queue to join.

Plugin updates absorbed before they break things

The tool surface sits on top of core, WooCommerce and whichever SEO plugins you run, so any one of those updating can quietly alter what a tool returns. We test that on staging rather than hear about it from you.

One monthly picture of what the agents actually did

WordPress records revisions for every edit and almost nobody opens them. Without somebody reading them, a tool being used in a way nobody intended stays invisible until it matters.

Where this is worth the money

Who needs managed WordPress MCP most

This earns its place fastest where the site makes money, or where somebody is about to connect an agent and nobody has yet decided what it should be allowed to do.

How the install runs

How our managed WordPress MCP setup works

The first conversation is about what an agent must never be allowed to do. That is harder than installing the plugin, and it is the part that decides whether any of this goes well.

1

We cut the list before anything gets connected

Which of the 382 tools the agents genuinely need, which profile holds them, and which user the connection runs as. We argue for a far shorter list than most people start with, and write down what was left out and why.

2

We install it read only and test on a staging site

The plugin goes on able to look and not touch, connected under a dedicated user with its own application password and its own profile. Prompts run against a staging site so the failure modes show up well before production is involved.

3

We add write access slowly, and keep it that way

Write tools go on one at a time, each tested before the next, with publish, delete and user management last of all or not at all. After that it is monitoring, revision review, repairs when a connection drops, and a monthly note on what the agents actually did.

What managed WordPress MCP costs

Pricing

Managed WordPress MCP

Monthly Subscription

$300.00
/per month
One WordPress site covered

DETAILS

The plugin installed and scoped for one site, connected under a dedicated user with its own application password and access profile. Client setup for the tools your team uses, tool level allow lists, revision review, unlimited repairs on the connections we manage, and a monthly report in plain language.

Managed WordPress MCP - Plus

Monthly Subscription

$700.00
/per month
Multiple WordPress sites covered

DETAILS

Everything in the standard plan across more than one site, plus connections out to third party services where they earn their place, priority response, retesting ahead of major WordPress releases, and a quarterly review of what every agent is still allowed to reach.

Testimonials

Here's what others had to say

Everything included

Everything included in managed WordPress MCP

Cascadia Web Services logo

The Server Scoped Down From 382 Tools

The plugin exposes 382 tools across WordPress core, WooCommerce, Yoast, Rank Math, Contact Form 7, Elementor and Jetpack. Almost nobody needs all of them. We allow list the ones the work genuinely calls for, because every tool exposed is another thing an agent can do to a live site.
Cascadia Web Services logo

Profile Based Access Control, Configured Properly

The plugin ships profile based access control so different clients can hold different tool sets. Most installs leave every profile identical, which quietly removes the point of having them. We build a profile per client and per job rather than one profile for everything.
Cascadia Web Services logo

A Dedicated Application Password Per Client

WordPress Application Passwords are per user and individually revocable, which makes them the right mechanism and the one people misuse. One shared password across four clients cannot be revoked without breaking all four. Each client gets its own, recorded and rotated.
Cascadia Web Services logo

The Connecting User Is Never An Administrator

WordPress capabilities are role based, so an agent connected as an administrator can install plugins, edit users and change the site URL. We build a user whose role carries only the capabilities the work needs, so the ceiling is set on purpose rather than inherited.
Cascadia Web Services logo

OAuth With PKCE Read And Understood

ChatGPT connects over OAuth 2.0 with PKCE and other clients use Application Passwords, which are two different trust models sitting on the same site. We set both up deliberately, write down which client uses which, and do not leave an OAuth client registered for something nobody uses any more.
Cascadia Web Services logo

Read Only First, Write Added Deliberately

Every server starts able to look and not touch. Write tools go on one at a time, each tested before the next is added. Publishing, deleting and user management come last, because those are the three that produce a phone call rather than a support ticket.
Cascadia Web Services logo

WooCommerce Tools Treated As Financial Tools

Where WooCommerce is installed, the agent can reach orders, customers and refunds. Those are money and personal data rather than content, so they are scoped as a separate decision with a higher bar than posts and pages.
Cascadia Web Services logo

Tested On A Staging Site Before Production

Prompts run against a staging copy of the site first, so the interesting failures happen somewhere nobody is reading. What a model does with an ambiguous instruction is worth learning before it is holding your published content.
Cascadia Web Services logo

Prompt To Action Verification

We check what a plausible instruction actually does, not what it should do. Ask an agent to update the pricing page and it will sometimes find a different page with a similar name. The cases where that happens get found and constrained during setup.
Cascadia Web Services logo

Client Connections Configured And Documented

ChatGPT, Claude Desktop, Cursor and Windsurf all connect, and each has its own setup path. Every client your team uses gets configured, tested and written down so a new starter does not have to work it out from scratch.
Cascadia Web Services logo

Plugin And Core Updates Watched

The MCP surface sits on top of WordPress core, WooCommerce and whichever SEO and form plugins are installed. An update to any of those can change what a tool returns. We watch for that rather than hear about it from you, which is the same discipline we already run on maintenance.
Cascadia Web Services logo

Credentials Rotated On A Schedule

Application passwords and OAuth registrations get rotated rather than left in place indefinitely, and the rotation is logged. A credential that has been valid since setup is a credential nobody has thought about since setup.
Cascadia Web Services logo

A Written Map Of What The Agent Can Reach

One document listing every tool enabled, every profile configured, the user behind each connection and what that user can do. When somebody asks whether the agent can delete a page, the answer is a lookup rather than an investigation.
Cascadia Web Services logo

Monthly Report In Plain Language

What the agents did, what changed, what we adjusted and anything we think should be switched off. Written to be read in a few minutes by somebody who does not want to think about protocols.
Cascadia Web Services logo

Break And Fix On Every Connection

When a connection drops, a password expires or a client stops authenticating, it is ours to repair. Unlimited repairs on the connections under management, with no per incident charge and no ticket queue to join.
Cascadia Web Services logo

Clean Revocation Whenever You Want It

Ending the arrangement means revoking the application passwords, removing the OAuth registrations, disabling the service user and handing over the configuration document. The plugin is free and stays installed if you want it. Nothing is held hostage because nothing was ever ours.

Managed WordPress MCP questions we get asked most

Frequently asked questions
What is the WordPress MCP connector?
Our free WordPress plugin. It turns a WordPress site into a Model Context Protocol server, exposing 382 tools across WordPress core, WooCommerce, Yoast SEO, Rank Math SEO, Contact Form 7, Elementor and Jetpack, so an instruction in plain language becomes a real action on the site. We wrote it and it is distributed on the WordPress Plugin Directory.
Is the plugin free?
Yes, entirely. It is on the WordPress Plugin Directory, there is no licence and no paid tier, and installing it costs nothing. If you want to install it and wire it up yourself, go and do that. What you would be buying here is the scoping and the ownership afterwards, not the software.
Then what exactly am I paying you for?
Judgement about scope, and somebody answerable for it. Installing a plugin is easy and we made it easy on purpose. Deciding which of 382 tools an agent should hold, which profile it connects under, which user that maps to, and what happens when it misreads an instruction is the part that carries consequences. That work continues every month because your site does.
Should we buy this at all?
Often not, and now is a better time to find that out than month six. If one person there is comfortable reading WordPress capabilities, will test on staging before pointing anything at production, and has the hours, install it and keep the money. This starts making sense when the site earns money, when more than one person is connecting clients, and when nobody can say what the agents are allowed to do.
What can the agent actually reach?
Posts, pages, media, users, comments, menus and settings through core, plus WooCommerce orders and customers, Yoast and Rank Math SEO fields, Contact Form 7 submissions, Elementor content and Jetpack features where those plugins are installed. That is 382 tools in total, and part of the service is arguing you down to a much shorter list.
Can the agent change our site, or only read it?
Both, and that is the whole point of the protocol and the whole risk in it. An agent with the right tools can publish a post, edit a page or change a setting. Every server we run starts read only and write access is added one tool at a time after testing. Which write tools are live is recorded in your configuration document rather than left at a default.
Can an agent delete something or take the site down?
Only if you give it the tools to, and we will argue against most of them. Delete, user management and settings changes are the ones that produce a phone call rather than a ticket, so they go on last, only where the work truly needs them, and often not at all. An agent connected as an administrator could install a plugin, which is exactly why we never connect one as an administrator.
How does authentication work?
ChatGPT connects over OAuth 2.0 with PKCE. Other clients use WordPress Application Passwords, which are per user and individually revocable. Those are two different trust models on the same site, so we configure both deliberately, record which client uses which, and give every client its own credential rather than one shared password nobody can revoke safely.
Which AI clients does this work with?
ChatGPT, Claude Desktop, Cursor and Windsurf all connect, and so does anything else that speaks the protocol. We set up and document the clients your team actually uses. If you switch later that is a configuration change rather than a rebuild.
Do you need administrator access to our site?
Briefly, to install the plugin, create the service user and register the connections, and then no. The ongoing arrangement runs on the service account rather than an administrator login. Your site stays yours and we do not become a permanent administrator on it.
What happens when WordPress or a plugin updates?
We test it. The MCP surface sits on top of core, WooCommerce and whichever SEO and form plugins you run, so an update to any of those can change what a tool returns. Watching for that and absorbing it is included, and it is the same work we already do on WordPress maintenance.
Do you host anything?
No. The plugin runs on your own WordPress site, wherever that is hosted, and the connections belong to you. We manage it rather than own it, so leaving costs you a revocation and a handover document rather than a migration.
What is the difference between the two plans?
Standard covers one site with the install, scoping, profile and client setup, audit review, break and fix and monthly reporting. Plus covers multiple sites, adds third party service connections, priority response, retesting ahead of major WordPress releases and a quarterly scope review. Most businesses running one site belong on Standard and we will say so rather than selling up.
How long does the setup take?
The install itself takes an afternoon. The scoping conversation ahead of it is the part that takes real time, because narrowing 382 tools down to the ones you need requires somebody who knows the business rather than the protocol. Expect a fortnight before anything writes to production.
What if we want to leave?
Thirty days notice and nothing is stranded. We revoke the application passwords, remove the OAuth registrations, disable the service user and hand over the document describing every tool, profile and permission. The site and the plugin were always yours, and the plugin stays free and installed if you want to keep using it.
​Contact

Ask Us Anything

We’d love to hear from you!