The operator’s brief
Make the request checkable
Describe the change, its boundary, and the evidence that will show whether the work is done.
1
State the desired change
Use plain language for the requested edit and identify the objects it touches. The wording should tell you what to look for afterward.
2
Match the operation
Match the request to the site’s own records, then use the operation that can complete it.
3
Mark the boundaries
Name the pages, posts, comments, or other objects in scope, then record what must stay unchanged. That boundary lets you detect drift.
4
Compare the before and after
Inspect the affected material against the brief before widening the job. The documented example made phone numbers clickable tel: links across 25 articles in 30 seconds, an example rather than a general speed claim.
Ownership test
Keep vendor integrations in their own lane
Before acting, decide whether the instruction belongs to the site’s own data or to a vendor service.
Core
Native records
This package covers tasks for the site’s own WordPress content and settings. It does not claim product-specific behavior from third-party systems.
Add-ons
When an add-on is the right layer
A third-party feature belongs in its publisher’s add-on, which provides the needed integration.
Capability map
79 WordPress operations grouped by the work they complete
Ask for the outcome in front of you; these groups show which native WordPress work the assistant can perform and where the boundaries remain.
7
Comments, 7 abilities
Review the conversation, open an individual comment, add a comment or reply, change its moderation status or author URL, and remove a comment when moderation requires.
27
Content, 27 abilities
Create categories, pages, posts, and tags; inspect pages, posts, and revisions and find the next post; list categories, media, pages, posts, revisions, tags, and users; search; patch pages or posts; update categories, discussion status, pages, posts, or tags; restore posts or revisions; and delete pages or posts.
5
Media, 5 abilities
Inspect an attachment, upload media from a URL or validated file data, update its record, or delete it.
8
Menus, 8 abilities
List or create menus, assign one to a theme location, inspect its entries, add or update an item, create or update without a duplicate, or remove an item.
3
Post metadata, 3 abilities
Read, update, or delete one named post metadata key under the shared policy.
3
Options, 3 abilities
List available options, read one option, or make a targeted change within the permitted set. Protected startup settings remain outside that set.
11
Plugins, 11 abilities
Review installed plugins and pending updates, search the official directory, activate or deactivate a plugin or switch its requested state, install from the directory, upload a package from a remote address or validated data, update a plugin, or remove it.
4
System diagnostics, 4 abilities
Inspect operation timings and the debug log, read one named transient, and read or toggle the site’s debug state.
1
Taxonomy, 1 ability
Associate one native taxonomy with one post type.
7
Users, 7 abilities
List, inspect, create, update, or delete users; create a restricted WordPress Application Password or revoke the Application Password used by the current authenticated request.
3
Widgets, 3 abilities
List available widgets, list registered sidebars, or inspect one sidebar configuration.
What the connection needs
Three components connect the assistant to WordPress
These named components are required for the assistant to reach the operations described above.
WordPress 6.9 or later
WordPress Abilities API in WordPress 6.9 or laterRegisters and executes the core abilities available on the site.
PHP 8.0 or later
PHP 8.0 or laterRuns the MCP Expose Abilities plugin code.
Required for MCP client access
WordPress MCP AdapterConnects an authenticated MCP client to the operations registered on the site.
Safety controls
The site keeps control of consequential requests
Permission and protected settings limit what an authenticated MCP request can change.
Permission
The site permission gate
By default, an MCP request needs the WordPress manage_options capability. Without that permission, the request cannot use these operations.
Protected options
Theme startup remains intact
Settings such as template and stylesheet can affect theme startup, so MCP refuses requests to change those names.
Download the plugin
Make the WordPress operations available to your AI client
Download the MCP Expose Abilities ZIP to give an authenticated AI client native WordPress operations for the specific task you name. After download, your client can use those operations on the content you choose.
