Sitehook
Exposes an MCP server giving authenticated AI agents PHP execution and sandboxed file access to this WordPress install, gated behind an off-by-default toggle.
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/sumitislearning/sitehook/archive/refs/heads/main.zipExposes an MCP server giving authenticated AI agents PHP execution and sandboxed file access to this WordPress install, gated behind an off-by-default toggle.
- Requires at least: WordPress 6.9
- Tested up to: WordPress 7.0
- Requires PHP: 8.0
- Stable tag: 0.1.0
- License: GPLv2 or later
Description
Sitehook registers 5 abilities via the WordPress Abilities API and exposes them as MCP tools on a dedicated server at /wp-json/mcp/sitehook:
sitehook/run-phpsitehook/list-sandbox-filessitehook/read-sandbox-filesitehook/write-sandbox-filesitehook/delete-sandbox-file
Every ability requires the admin-bar toggle to be turned on (off by default) and the calling user to hold manage_options. Sandbox file abilities are confined to wp-content/uploads/sitehook-sandbox/.
Installation
- Install via a release ZIP that bundles
vendor/, or runcomposer installin the plugin directory after a source install. - Activate the plugin.
- Turn on the "Sitehook AI" toggle in the admin bar (requires
manage_options). - Connect an MCP client using a WordPress Application Password.
Changelog
0.1.0
Initial release: run-php and the 4 sandboxed file abilities.