PluginBench
MCP Server
Active

com.royalplugins/royal-mcp MCP Server

com.royalplugins/royal-mcp

Security-first WordPress MCP server with 129 tools for Claude, ChatGPT, and Gemini. Free on WordPress.org.

What is the com.royalplugins/royal-mcp MCP server?

Royal MCP is an open-source WordPress plugin that connects AI agents like Claude, ChatGPT, and Gemini to your WordPress site via the Model Context Protocol. It provides 129 security-gated, rate-limited, and audit-logged tools for reading and writing posts, pages, media, users, WooCommerce orders, Elementor pages, and integrations with 20+ popular WordPress plugins.

Royal MCP bridges WordPress and AI agents with fine-grained capability gating, OAuth 2.1 support, and activity logging. Every tool call is rate-limited and logged. It covers WordPress core (posts, pages, media, users, menus, taxonomies, comments, SEO plugins) and auto-registers conditional tools when plugins like WooCommerce, Elementor, Divi, ACF, and 17 others are active. Install free from WordPress.org; connect via Claude.ai web, Claude Desktop, ChatGPT, or raw HTTP.

How to install com.royalplugins/royal-mcp

Copy-paste configuration for popular MCP clients.

transport: http
Config generated by PluginBench — verify against the source before use.
~/.cursor/mcp.json
{
  "mcpServers": {
    "royal-mcp": {
      "url": "https://demo.royalplugins.com/wp-json/royal-mcp/v1/mcp"
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • Posts, Pages & Custom Post Types — Full CRUD operations, revisions, featured images for all post types
  • Taxonomies — Read/write categories, tags, custom taxonomies, term meta, and post-term linking
  • Media — Browse, upload (URL or base64), update metadata, delete media files
  • Comments — Create comments and moderate (approve, spam, trash)
  • Users — Read display names and roles (emails and usernames not exposed)
  • Menus — Read, create menu items, reorder, update with destructive-write guardrails
  • Theme — Custom CSS, theme mods, active theme detection
  • Site Info — Permalink structure, allowlisted options, site diagnostics
  • Search — Cross-content search by query
  • SEO Meta — Read/write Yoast, Rank Math, and AIOSEO metadata
  • Diagnostics — Site status (WP/PHP/MySQL/plugins/themes/cron), PHP error-log tail, WP cron schedule, connection health
  • WooCommerce — Products, variations, attributes, coupons, orders (create/update/notes), customers, store stats (29 tools)
  • Elementor — Clone pages, replace text, swap images, get outline, read elements, list/import templates, add widgets, rebuild content, widget/dynamic-tag discovery (14 tools)
  • Divi — Format detection, page outline, layout validation, library operations, find/replace, clone, image swap (9 tools)
  • GuardPress — Security score, failed logins, blocked IPs, vulnerability scans, audit log (7 tools)
  • SiteVault — Trigger backups, monitor progress, list schedules (6 tools)
  • Royal AI Firewall — Dashboard stats, recent bot hits, per-bot policies, daily rollups (6 tools)
  • Yoast SEO — Read/write Yoast meta, capture JSON-LD schema, list indexed links, list Premium redirects (5 tools)
  • Redirection — List redirects with filters, create/update redirects (301/302/307/regex), list groups (4 tools)
  • Royal Ledger — Software costs, renewal dates, license key tracking (4 tools)

Use cases

  • Automate WordPress content creation, editing, and publishing via Claude or ChatGPT
  • Manage WooCommerce products, orders, and customer data through AI agents
  • Clone and customize Elementor or Divi pages using natural language instructions
  • Monitor site security, backups, and performance metrics via AI queries
  • Bulk edit post metadata, featured images, and SEO fields across your site

com.royalplugins/royal-mcp MCP server FAQ

What is Royal MCP?

Royal MCP is a free WordPress plugin that connects AI agents (Claude, ChatGPT, Gemini) to your WordPress site via the Model Context Protocol. It exposes 129 security-gated tools for reading and writing posts, pages, media, users, WooCommerce orders, Elementor pages, and integrations with 20+ plugins.

Is Royal MCP free?

Yes. The core plugin is free and available on WordPress.org with auto-updates. Royal MCP Pro is a paid tier for agencies and multi-site operators, adding Divi Pro tools, deeper Elementor support, universal audit logs, and 72-hour undo on destructive operations.

How do I install Royal MCP in Claude Desktop?

Download the `.mcpb` bundle from the latest GitHub release and double-click it — Claude Desktop opens the install prompt. Enter your site URL and API key. Alternatively, use `mcp-remote` with the endpoint URL in your `claude_desktop_config.json`.

How do I connect Royal MCP to Claude.ai web?

Go to Claude.ai → Settings → Connectors → Add Custom Connector. Paste your site's MCP endpoint URL (`https://yoursite.com/wp-json/royal-mcp/v1/mcp`). Claude handles OAuth consent and dynamic client registration automatically.

What authentication methods does Royal MCP support?

API keys (32-char hex via `X-Royal-MCP-API-Key` header), OAuth 2.1 with PKCE (RFC 7591 dynamic client registration), and raw HTTP with session IDs. OAuth is recommended for Claude.ai web and ChatGPT; API keys work for Claude Desktop and custom clients.

Does Royal MCP expose sensitive data like email addresses?

No. Royal MCP never exposes email addresses or usernames — only display names and roles. Activity logs record tool names and argument keys, never argument values (which may contain customer data). Every tool call is capability-gated and rate-limited.

README (reference)

Source of truth, from the repository.

<div align="center">

Royal MCP

Royal MCP is an open-source, security-first WordPress plugin that connects Claude, ChatGPT, Perplexity, Gemini, and any other MCP agent to your site.

WordPress PHP License Version

Download on WordPress.org · Documentation · Royal Plugins

</div>

Agents can read and write posts, pages, media, users, menus, WooCommerce orders, and Elementor pages over the Model Context Protocol. Every call is capability-gated, rate-limited, and audit-logged.

Capabilities

WordPress core (85 tools, always available)

  • Content — Posts, pages, custom post types (full CRUD + revisions + featured images)
  • Taxonomies — Categories, tags, custom taxonomies, term meta, post-term linking
  • Media — Browse, upload (URL or base64), update metadata, delete
  • Comments — Create, moderate (approve / spam / trash)
  • Users — Read display names + roles (emails and usernames are not exposed)
  • Menus — Read, create items, reorder, update with destructive-write guardrails
  • Theme — Custom CSS, theme mods, active theme detection
  • Site — Permalink structure, options (allowlisted), site info
  • Search — Cross-content search by query
  • SEO — Yoast / Rank Math / AIOSEO meta read/write where the plugin is active
  • Diagnostics — Site status (WP/PHP/MySQL/plugins/themes/cron in one call), PHP error-log tail, WP cron schedule, and MCP royal_mcp_connection_health (returns route, auth method, session ID, plugin version, and active page-builder versions for Divi + Elementor + Gutenberg)

Plugin integrations (124 tools, conditional)

Auto-register only when the integrated plugin is active.

PluginToolsWhat's covered
WooCommerce29Products, variations, attributes, coupons, orders (create/update/notes), customers, store stats
Elementor14Clone pages, replace text, swap images, get outline (with optional include-styles), read single element, list templates, import templates, add widget, rebuild post_content, widget-schema discovery, widget-list discovery, dynamic-tag discovery
Divi9Format detection (D4 shortcode vs D5 block), page outline, layout validation, library list + get, find/replace with builder-format awareness, clone, image swap, library apply
GuardPress7Security score, failed logins, blocked IPs, vulnerability scans, audit log
SiteVault6Trigger backups, monitor progress, list schedules
Royal AI Firewall6Dashboard stats, recent bot hits, per-bot policies (allow / block / challenge), daily rollups
Yoast SEO5Read/write Yoast meta (raw + resolved), capture JSON-LD schema graph, list indexed internal links, list Premium redirects
Redirection4List redirects with group + URL-substring filters, create + update redirects (301 / 302 / 307 / regex / groups), list redirect groups
Royal Ledger4Software costs, renewal dates, license keys (values never exposed)
Advanced Custom Fields4Read/write ACF fields with each field's Return Format respected (hydrated post objects, parsed repeater rows, image arrays); enumerate field groups
UpdraftPlus4List backup history, read per-backup status, trigger async backups with entity filtering, read schedule
WPForms4List forms, read a single form's parsed field schema, (Pro) list submissions, (Pro) read single submission
Solid Security4Read security status, list currently locked-out IPs, read the security event log, add an IP to the ban list
MonsterInsights4Read the analytics overview, top pages, traffic sources, and top Google Search Console queries
BuddyPress4List community members, read a single member profile, list groups, read the activity feed (same detection covers BuddyBoss Platform)
Contact Form 73List forms, read a single form's parsed field schema, list submissions (via Flamingo add-on)
W3 Total Cache3Read cache configuration across every module, purge cache (all / by URL / by post), read usage statistics
Duplicator3List migration packages, read per-package status, get the installer URL for a completed package
Royal Links3Branded short links, click stats
ForgeCache4Cache stats, clear cache, purge URL, real-user Core Web Vitals (INP/LCP/CLS/TTFB)

WordPress Abilities API bridge (WP 6.9+)

WordPress 6.9 shipped the Abilities API — a primitive that lets plugins register typed capabilities AI agents can call. As of 1.4.38, every Royal MCP tool also registers as a WordPress ability, giving you three ways to reach the same handlers:

  1. Native — Royal MCP's /wp-json/royal-mcp/v1/mcp Streamable HTTP endpoint (unchanged, always available).
  2. WP MCP Adapter — if the wordpress/mcp-adapter package is installed, Royal MCP registers a named royal-mcp-server on the mcp_adapter_init hook alongside adapter's default server.
  3. WP core REST — direct ability invocation at /wp-json/wp-abilities/v1/abilities/{name}/run for callers that prefer the core WP endpoint.

Same handlers, three transports, one set of per-tool capability gates. Bridge can be disabled with the royal_mcp_abilities_registration_enabled option (default: on).

What we don't do

Explicit scope boundaries — the integration model is "narrow tools that work reliably," not "expose every API surface."

  • No widget-level Elementor generation from scratch. Atomic widgets (Editor V4) pass through opaque; we never decode atomic schemas because Elementor itself may shift them.
  • No Beaver Builder / Bricks page-builder JSON writes. Standard post content is readable and writable; page-builder-specific JSON storage is opaque unless covered by a dedicated tool. (Elementor and Divi have dedicated tools — see the integration table above.)
  • No theme builder template creation (Elementor or otherwise).
  • No core file modifications — Royal MCP never writes to wp-content/themes, wp-includes, or wp-admin.
  • No plugin installation or upgrades via MCP. Discovery yes; install/activate/deactivate no.
  • No raw SQL. Queries go through WP_Query and $wpdb->prepare() only.

Connect

Install

  1. Install from WordPress.org (recommended — auto-updates via WP admin) or upload the GitHub release zip.
  2. Royal MCP → Settings → click Generate API Key.
  3. Pick a client below.

Claude.ai web (OAuth — recommended)

Easiest path — no config file edits, no API key in your client.

  1. In Claude.ai → Settings → Connectors → Add Custom Connector.
  2. URL: https://yoursite.com/wp-json/royal-mcp/v1/mcp
  3. Approve the OAuth consent screen when prompted. Claude.ai handles dynamic client registration + PKCE flow against your site.

Claude Desktop (.mcpb one-click bundle — new in 1.4.38)

Easiest Claude Desktop path — no mcp-remote, no npx, no config-file editing.

  1. Download royal-mcp-1.4.38.mcpb from the latest GitHub release.
  2. Double-click the .mcpb file — Claude Desktop opens the install prompt.
  3. Enter your site URL + API key when prompted. Connection is live.

The bundle ships a zero-dependency stdio-to-HTTPS bridge in Node ≥18, which Claude Desktop already includes. See Claude Desktop MCP Bundles for the .mcpb spec.

Claude Desktop (OAuth via mcp-remote)

{
  "mcpServers": {
    "my-wordpress": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://yoursite.com/wp-json/royal-mcp/v1/mcp"]
    }
  }
}

Config path: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows).

Claude Desktop (API key)

Skip OAuth and authenticate via header:

{
  "mcpServers": {
    "my-wordpress": {
      "command": "npx",
      "args": [
        "-y", "mcp-remote",
        "https://yoursite.com/wp-json/royal-mcp/v1/mcp",
        "--header", "X-Royal-MCP-API-Key:YOUR_API_KEY"
      ]
    }
  }
}

ChatGPT

ChatGPT's custom MCP connector takes the same URL as Claude.ai web. Follow ChatGPT's connector flow and paste https://yoursite.com/wp-json/royal-mcp/v1/mcp.

Raw HTTP (custom clients)

# 1. Initialize a session. -i prints headers so you can grab Mcp-Session-Id.
curl -i -X POST https://yoursite.com/wp-json/royal-mcp/v1/mcp \
  -H "X-Royal-MCP-API-Key: YOUR_KEY" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{
    "jsonrpc": "2.0",
    "method": "initialize",
    "id": 1,
    "params": {
      "protocolVersion": "2025-11-25",
      "capabilities": {},
      "clientInfo": {"name": "my-app", "version": "1.0"}
    }
  }'

# 2. List available tools using the session id from the response header.
curl -X POST https://yoursite.com/wp-json/royal-mcp/v1/mcp \
  -H "X-Royal-MCP-API-Key: YOUR_KEY" \
  -H "Mcp-Session-Id: <session_id>" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc": "2.0", "method": "tools/list", "id": 2}'

Security model

LayerWhat it does
API key32-char hex, timing-safe comparison. Sent via X-Royal-MCP-API-Key header. Regenerate from admin without server restart.
OAuth 2.1RFC 7591 Dynamic Client Registration, RFC 8414 metadata, PKCE S256 required, refresh tokens supported. No implicit grant. No client_credentials grant.
Capability gatingEvery tool checks WordPress capabilities. edit_posts for create/update, manage_options for site settings, edit_post per-post for individual operations.
Rate limiting60 requests/minute per IP, sliding window.
Session modelSliding 24h TTL with refresh-on-access. Cryptographically secure 32-byte session IDs.
Activity logEvery tool call writes a row to a database log. Records: tool name, argument keys, IP, User-Agent, errors. Never records argument values (they may contain customer data).
OAuth state recoveryOne-click Reset OAuth State admin button wipes all clients + tokens + auth codes, without affecting your API key or settings.
Discovery.well-known/oauth-authorization-server and .well-known/oauth-protected-resource served at site root per RFC 8414 + RFC 9728.

Full security architecture: royalplugins.com/support/royal-mcp/

Royal MCP Pro (paid)

The Free plugin is fully featured for individual site owners. Royal MCP Pro extends it for agencies and multi-site operators:

  • Divi Pro suite — page clone, image swap, template import, full library CRUD, D4→D5 Migrator, global preset bulk-apply (8 tools)
  • Elementor Pro depth — additional Elementor tools beyond the Free integration
  • Universal audit log — every AI operation logged with attribution + export
  • 72-hour undo on every write — every destructive Pro tool returns an undo token; reverse any operation within the window
  • License-gated updates through the standard WordPress updater — no runtime dependencies on external license servers

Learn more at royalplugins.com/royal-mcp-pro

Further reading

Related projects

License

GPLv2 or later — see LICENSE or the GNU site.

Royal MCP is provided as-is. API keys protect your endpoints; guard them like any other credential. You are responsible for the content, commands, and actions any AI platform is allowed to perform on your WordPress site.


<p align="center"> <strong>Built by <a href="https://royalplugins.com">Royal Plugins</a></strong><br/> Lightweight, security-first WordPress plugins.<br/> © 2026 Royal Plugins. </p>

Related MCP servers

HUhush logo

hush

Active

A secret store for AI agents where plaintext never reaches the transcript—inject secrets into commands without exposing them.

20
Shell
MIT
View repository →

Delegate 60 specialist work products: 20 WaveEngine, 20 RQM Studio, and 20 RQM Robotics jobs.

View repository →

Delegate 20 typed RQM Robotics jobs for validation, diagnosis, comparison, and optimization.

View repository →

Delegate 20 fail-closed RQM Studio quantum work products with fixed-request x402.

View repository →

Delegate 20 typed, evidence-backed WaveEngine signal work products with fixed-request x402.

View repository →

Search a curated RSS feed directory and fetch latest articles. EN/JA. Sign in to use favorites.

View repository →