WP Manifestindependent plugin directory
manifest / ai / sitehook

Sitehook

Exposes an MCP server giving authenticated AI agents PHP execution and sandboxed file access to this WordPress install, gated behind an off-by-default toggle.

by Sitehook · github.com/sumitislearning/sitehook

★ 0stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/sumitislearning/sitehook/archive/refs/heads/main.zip

Exposes an MCP server giving authenticated AI agents PHP execution and sandboxed file access to this WordPress install, gated behind an off-by-default toggle.

  • Requires at least: WordPress 6.9
  • Tested up to: WordPress 7.0
  • Requires PHP: 8.0
  • Stable tag: 0.1.0
  • License: GPLv2 or later

Description

Sitehook registers 5 abilities via the WordPress Abilities API and exposes them as MCP tools on a dedicated server at /wp-json/mcp/sitehook:

  • sitehook/run-php
  • sitehook/list-sandbox-files
  • sitehook/read-sandbox-file
  • sitehook/write-sandbox-file
  • sitehook/delete-sandbox-file

Every ability requires the admin-bar toggle to be turned on (off by default) and the calling user to hold manage_options. Sandbox file abilities are confined to wp-content/uploads/sitehook-sandbox/.

Installation

  1. Install via a release ZIP that bundles vendor/, or run composer install in the plugin directory after a source install.
  2. Activate the plugin.
  3. Turn on the "Sitehook AI" toggle in the admin bar (requires manage_options).
  4. Connect an MCP client using a WordPress Application Password.

Changelog

0.1.0

Initial release: run-php and the 4 sandboxed file abilities.