BetterShield
MCPAI assistantsAgent activity

WordPress MCP: connecting an AI assistant to your site safely

BetterShield team · · 10 min read

A WordPress MCP connection lets an AI assistant such as Claude, ChatGPT, Cursor or Codex work with your site directly. Ask it which findings matter most, and it reads the answer from the site instead of guessing. That is useful, and worth a moment’s thought: something outside your dashboard can now reach into it.

Six questions cover it, from what it can read to how you end it. If one has no plain answer, keep the assistant read-only until it does.

Below, BetterShield 1.1.0 answers each one with its built-in MCP server, which is free and off until you turn it on.

Quick summary

  • Your assistant connects to your own site, and every step of Three steps to a connected assistant, under BetterShield › Agents › Connect, stays off until you turn it on.
  • Reading and changing are separate decisions. A read-only credential gets 18 read-only abilities and changes nothing.
  • With changes allowed, seven reversible fixes apply directly, heavier changes need a plan you agree to, and three fixes are never applied by an assistant.
  • Every call is recorded, and Agent activity shows what ran and what was refused.
  • Rotate replaces the credential. Disconnect ends it, along with every app that signed in.

What a WordPress MCP connection actually does

MCP, the Model Context Protocol, lets an AI assistant call tools in another system while it answers you.

In BetterShield, those tools are WordPress abilities: actions a plugin describes so an agent can call them. WordPress builds them in from 6.9, and BetterShield includes them for the earlier versions it supports. Any plugin can register abilities, so what an assistant can do depends on which exist and what your credential allows. Most of a WordPress MCP server’s security is about the connection, not the assistant.

Six questions to ask before you connect

  1. What can it read? And what never leaves the site.
  2. What can it change? As a separate choice from reading.
  3. Who agrees to a change? A small reversible fix and a sign-in change are not the same size.
  4. What stays off-limits? Even with everything switched on.
  5. What is recorded? Refused calls included.
  6. How do I end it? Quickly, and completely.

What can it read?

Nothing, until you turn on Let my agent read security information, under Allow agents to read this site on BetterShield › Agents › Connect. Then an assistant can use 18 read-only abilities, in plain words:

  • Your posture: the score, grade and findings with their explanations, any single audit check, which fixes are on, and the vulnerability state, which in 1.1.0 says plainly that no data source is connected.
  • People and sign-in: login protection settings (counts, never addresses), two-factor and passkey rules, users and roles by display name (no email addresses or login names), and one member’s session times (no tokens or IP addresses).
  • What happened: the activity log, agent activity, and incidents with their timelines.
  • Files and upkeep: the file check and quarantine list (no file contents), scheduled task health and installed backup plugins.
  • Agents: which plugins offer abilities, and where AI connector keys are stored (never the keys).

None of them change anything.

What can it change?

Nothing, unless two things are true: Let agents act: changes that can be undone right away, anything heavier once you agree is on, under Allow agents to apply a change, and the credential is allowed to change the site. A read-only connection cannot propose changes at all.

With both, these seven fixes apply directly, each with a way back:

  • Disable XML-RPC
  • Disable the dashboard file editor
  • Block public user listing
  • Stop publishing the WordPress version
  • Send security response headers
  • Find out what a content policy would break
  • Tell browsers to refuse plain HTTP, in its five-minute, this-domain-only form

The way back is written down before the change is made. There is a ceiling too: 5 changes of one kind and 30 plans per hour. Anything past either is refused, not queued.

Who agrees to a change?

You do, for anything heavier: the six Signing in fixes, the six-month or all-subdomains form of the HTTPS fix, taking any fix off, and putting a changed file back.

BetterShield writes out a plan first: what would change, and whether it can be put back. The plan reaches your assistant with a single-use confirmation, and the assistant is told to show you the plan and act only after you agree in the conversation. The plan expires after 15 minutes, and the site is checked again before anything moves. A sign-in change also needs your recovery link verified within the last day (Protect › Recovery).

What stays off-limits?

Three fixes are never applied by an assistant: Stop PHP running in uploads, Stop uploads directories listing their contents and Hide sensitive files from visitors. They write files on your server, so they stay your own switch. An assistant can neither apply them nor ask for a plan.

On Agents › Permissions, What stays yours lists what no assistant can do, whatever is switched on: make an account or a credential, change your recovery link or printed codes, weaken two-factor or alerting, lift a lockout, remove rows from the log, or write wp-config.php or .htaccess.

The assistant also runs as the account that connected it, so it never reaches further than that account can.

What is recorded?

Every tool call over the connection is written to the activity log. On WordPress 7.1 or newer, Record what agents do on this site (on by default) also fills Activity › Agent activity with every ability call on the site, from any plugin, refused calls included.

Each row shows the ability, the time, the account, how it came in (MCP, REST, WP-CLI or PHP) and the outcome. Inputs are kept only as a digest, because an input can carry a secret. The docs cover it in Agent activity.

With email alerts on their defaults, you also hear straight away when an assistant is connected and when an agent changes something on its own.

How do I end it?

  • Pause it. Turn off Let an assistant connect to this site. The site answers no assistant, and nothing is revoked.
  • Rotate. A new credential; the old one stops working at once. It is also how you move a credential to read-only.
  • Disconnect. Ends the credential and every app that signed in through the browser.
  • Revoke. Under Connected apps, ends one app.

To keep reading but stop changes, turn off Let agents act: changes that can be undone right away, anything heavier once you agree on Agents › Permissions. Changes stop at once, even for a credential allowed to make them.

How to connect an assistant

On BetterShield › Agents › Connect, Three steps to a connected assistant has a switch for each step, all off by default:

  1. Allow agents to read this site: turn on Let my agent read security information. Until it is on, nothing is offered to agents at all, and turning it off also turns off step 2.
  2. Allow agents to apply a change: turn on Let agents act: changes that can be undone right away, anything heavier once you agree. Optional, and needs step 1.
  3. Connect an assistant: turn on Let an assistant connect to this site. While it is off, the site answers no assistant.

Then press Connect and copy the Connection credential. It is shown once, and the site keeps only a fingerprint of it. Untick Allow this credential to change the site for a read-only credential; with Allow agents to apply a change off, every credential is read-only anyway.

In Set up your assistant, pick your app and copy what it shows. To connect Claude or ChatGPT, add the Address to paste and approve on the page that opens; untick Allow it to change this site there for read-only. Then press Test connection.

Full steps: Connect an AI assistant.

See what else can reach your site

Agents › Surface looks past BetterShield’s own abilities:

  • Registered abilities: every ability any plugin offers agents. One that writes, is reachable over REST and is Open to lower roles is raised as a finding.
  • Application passwords: each account’s, marked stale after 90 days unused. Limit… holds one to certain REST routes, an address range, or both.
  • Retire application passwords that have gone unused: a daily sweep, off by default, after 180 days (30 at least). Removal cannot be undone.
  • Keep a decoy credential on my account: an application password nobody is given. Any use is refused and alerts you.
  • Decoy URL: an Unused path that shows your normal 404 page and raises an urgent alert when requested. A hit can mean probing or a stray visit; it does not prove a break-in.
  • Connector credentials: where AI connector keys are stored and how many plugins can read them, never the values.

Managing many sites through BetterShield Hub

BetterShield Hub is a free, optional dashboard for people with several sites. Connect each site from its own BetterShield › Hub screen, choose Read this site and apply fixes that can be undone or Read this site only, and approve it on that site’s consent page.

Connect your assistant to the hub once, and it can look across every site in your workspace. A change still goes site by site and is recorded in that site’s activity log, and a change to how people sign in, or taking a protection off, waits for a person to agree each time.

The site never contacts the hub. To end the connection, press Disconnect on the site; removing a site inside the hub does not end it. See Connect to BetterShield Hub.

Common mistakes

  • Turning on changes before you have looked. Start read-only, then decide whether Allow agents to apply a change earns its place.
  • Saying yes without reading the plan. You agree in the chat, so read the plan first, including whether it can be put back.
  • Expecting a new WordPress password to end the connection. It does not. Rotate, Disconnect or Revoke does; rotate if the credential lands somewhere shared.
  • Checking only BetterShield’s own abilities. Its switches govern its own abilities, not other plugins’. Check Agents › Surface with Open to lower roles selected.

Frequently asked questions

Which assistants can connect to my WordPress site?

Set up your assistant has steps for Claude, Claude Desktop, ChatGPT, Cursor and Codex, and other MCP assistants can use the same address. Claude and ChatGPT need pretty permalinks (Settings › Permalinks).

Which WordPress version do I need?

The assistant connection works on every WordPress version BetterShield supports, 6.7 or newer. Agent activity recording needs 7.1, and Connector credentials needs 7.0.

Does the connection send my site’s data anywhere?

BetterShield never contacts the assistant; the assistant calls your site, once you connect it. What it reads becomes part of your conversation, so choose an assistant you are comfortable sharing that with.

Can an assistant see passwords or email addresses?

No. Users come by display name and role, without email addresses, and connector keys only by where they are stored. Session times carry no tokens, and file contents are never returned.

Conclusion

An AI assistant can be a useful second pair of eyes on your site, as long as you decide what it sees and touches. Start read-only, and turn on changes when you have a reason to.

BetterShield is free on WordPress.org. Then follow Connect an AI assistant step by step.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield