SitePilot MCP
Public source of the SitePilot MCP WordPress plugin: guarded OAuth and MCP operations for WordPress. GPL-2.0-or-later.
by SitePilot · github.com/jim788e/sitepilot-mcp-plugin · website
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/jim788e/sitepilot-mcp-plugin/archive/refs/heads/main.zipSitePilot MCP, WordPress plugin
Guarded OAuth 2.1 and Model Context Protocol (MCP) operations for WordPress. SitePilot lets an AI assistant inspect a site and propose changes, while WordPress keeps the final say: scoped credentials, risk tiers, human approvals, audit records and rollback.
- Product site: https://sitepilot.tools/
- Documentation: https://docs.sitepilot.tools/
- Download the signed release ZIP: https://sitepilot.tools/download/
- License: GPL-2.0-or-later (see LICENSE and NOTICE.md)
What this repository is
This is the public source of the plugin as released. Development and the full test suite live in a private repository, and each release is published here as a single commit with a matching tag. The files in the repository root are the plugin: the folder you would put in wp-content/plugins/sitepilot-mcp.
The vendor/ directory is not committed. Run composer install --no-dev to produce it, or use the release ZIP, which already contains it.
Documentation
See docs/: the plugin guide, security model, API reference, architecture, and the Elementor and Enfold guides.
Security
Report vulnerabilities privately to security@sitepilot.tools or through a private GitHub Security Advisory. Please do not open a public issue for a security problem.