Back to Home
M4F-S icon

WP-WC-MCP

Verified Safe

by M4F-S

Overview

Enables LLMs like Claude to interact with and manage WordPress and WooCommerce sites via natural language.

Installation

Run Command
npm start

Environment Variables

  • WORDPRESS_URL
  • WORDPRESS_USERNAME
  • WORDPRESS_APP_PASSWORD
  • NODE_ENV
  • LOG_LEVEL
  • MCP_TRANSPORT
  • RATE_LIMIT_GLOBAL
  • RATE_LIMIT_WINDOW_MS
  • REQUEST_TIMEOUT
  • MAX_RETRIES
  • RETRY_DELAY

Security Notes

This project implements a 'security-first' architecture with robust measures. It features extensive input validation using Zod schemas and custom `InputValidator` for SSRF protection (blocking internal IPs and dangerous protocols), SQL injection, XSS, and path traversal prevention. Authentication uses WordPress Application Passwords with a circuit breaker pattern and re-authentication logic. Authorization is enforced via WordPress capability checks mapped to specific tools. Sensitive data is automatically redacted from logs using Winston. Rate limiting (token bucket algorithm), batch operation limits, and secure Docker configurations (non-root user, resource limits, dropped capabilities) are also in place. Error messages are sanitized to prevent information disclosure. While highly secure, no system is 100% impervious to all possible attack vectors, hence a 9.

Similar Servers

Stats

Interest Score0
Security Score9
Cost ClassMedium
Avg Tokens750
Stars0
Forks0
Last Update2026-01-19

Tags

wordpresswoocommercemcpllm-agente-commerce