<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: WPPilot</title>
    <description>The latest articles on DEV Community by WPPilot (@wppilot).</description>
    <link>https://dev.to/wppilot</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4146044%2F9683ff12-1324-4aae-a2b9-b052644e9a39.png</url>
      <title>DEV Community: WPPilot</title>
      <link>https://dev.to/wppilot</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/wppilot"/>
    <language>en</language>
    <item>
      <title>WordPress MCP for Beginners: 9 Real Jobs You Can Hand to Claude, Cursor or ChatGPT (Safely)</title>
      <dc:creator>WPPilot</dc:creator>
      <pubDate>Sun, 27 Sep 2026 21:56:43 +0000</pubDate>
      <link>https://dev.to/wppilot/wordpress-mcp-for-beginners-9-real-jobs-you-can-hand-to-claude-cursor-or-chatgpt-safely-20d0</link>
      <guid>https://dev.to/wppilot/wordpress-mcp-for-beginners-9-real-jobs-you-can-hand-to-claude-cursor-or-chatgpt-safely-20d0</guid>
      <description>&lt;p&gt;Read the WordPress and WooCommerce forums for a week and the same requests keep coming up. People want to rewrite thousands of stale product descriptions. They want every missing meta description written. They want an Elementor edit that doesn't wreck the layout, and a weekly check-up on the site. Alongside those requests you see the same fear: &lt;em&gt;"One of my clients asked me to install Claude MCP onto their WordPress site and I'm terrified."&lt;/em&gt; The usual advice in those threads is sensible: start read-only, use staging, keep credentials easy to revoke, and make sure you can undo things.&lt;/p&gt;

&lt;p&gt;This guide is built around those requests. We'll connect an AI client to WordPress through the &lt;strong&gt;Model Context Protocol (MCP)&lt;/strong&gt;, set up the safety controls first, and then go through nine common jobs. For each job you get the exact tools the AI calls, a prompt to paste, what happens to your site, whether you can undo it, and whether it needs the free or the paid edition.&lt;/p&gt;

&lt;p&gt;The server we'll use is &lt;a href="https://wppilot.co" rel="noopener noreferrer"&gt;WPPilot&lt;/a&gt;, a GPL WordPress plugin (Free 1.13.0 and Pro 1.7.0 at the time of writing). Everything below was checked against its live docs and &lt;a href="https://github.com/wppilot-labs/wordpress-mcp-elementor-wppilot" rel="noopener noreferrer"&gt;GitHub repository&lt;/a&gt;. Jobs are labelled &lt;strong&gt;Free&lt;/strong&gt; or &lt;strong&gt;Pro&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  MCP in 60 seconds
&lt;/h2&gt;

&lt;p&gt;MCP is a standard way for an AI app (the &lt;strong&gt;client&lt;/strong&gt;) to find and call tools that a &lt;strong&gt;server&lt;/strong&gt; exposes. Once they're connected, you write normal sentences and the client picks the tools itself.&lt;/p&gt;

&lt;p&gt;For WordPress this means two things:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;The AI works on real WordPress data.&lt;/strong&gt; Drafts, menus and Elementor elements show up in wp-admin. You don't paste HTML around.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The rules live on the server.&lt;/strong&gt; Telling the model "don't delete anything" is just a request. A server-side permission is enforced whatever the model decides.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;WPPilot runs on your own site, with no relay service in between and no per-request fees. It doesn't bundle a model, because your client brings its own. It's built on the WordPress Abilities API and the official MCP Adapter. The client sees three tools (&lt;code&gt;discover-abilities&lt;/code&gt;, &lt;code&gt;get-ability-info&lt;/code&gt;, &lt;code&gt;execute-ability&lt;/code&gt;), and behind them sit typed "abilities" such as &lt;code&gt;wppilot/update-post&lt;/code&gt;. Free ships 141 of them. Pro adds plugin-specific ones for WooCommerce, SEO suites, page builders, forms and more.&lt;/p&gt;

&lt;h2&gt;
  
  
  Install and connect (Free)
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Requirements:&lt;/strong&gt; self-hosted WordPress 6.9+, PHP 8.0+, HTTPS for anything outside your own machine, and a staging copy or backup.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Download &lt;code&gt;wppilot.zip&lt;/code&gt; from the &lt;a href="https://github.com/wppilot-labs/wordpress-mcp-elementor-wppilot/releases/latest" rel="noopener noreferrer"&gt;latest GitHub release&lt;/a&gt;. The plugin isn't on WordPress.org, and GitHub's "Source code (zip)" won't install because it has no &lt;code&gt;vendor/&lt;/code&gt; folder.&lt;/li&gt;
&lt;li&gt;Go to &lt;strong&gt;Plugins → Add New → Upload Plugin&lt;/strong&gt;, then activate it.&lt;/li&gt;
&lt;li&gt;Create a &lt;strong&gt;dedicated WordPress user&lt;/strong&gt; for the AI with the smallest role that works, for example Editor for content work. Every call inherits that user's capabilities.&lt;/li&gt;
&lt;li&gt;Open &lt;strong&gt;WPPilot → Connect&lt;/strong&gt;, turn on AI abilities, pick your client, and copy the config it generates. It already contains your real URL.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;WPPilot serves two routes:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;https://your-site.com/wp-json/mcp/wppilot-oauth   # OAuth 2.1 (preferred)
https://your-site.com/wp-json/mcp/wppilot         # Application Password or wpp_ access token
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;OAuth uses PKCE, one-hour access tokens and 14-day refresh tokens. Every app shows up under &lt;strong&gt;Connected Apps&lt;/strong&gt; and can be revoked there, which makes it the easy-to-revoke credential the forums ask for. Application Passwords never expire, so revoke them yourself when you're done.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Claude Code&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;claude mcp add &lt;span class="nt"&gt;--transport&lt;/span&gt; http wppilot https://your-site.com/wp-json/mcp/wppilot-oauth
&lt;span class="c"&gt;# then run /mcp inside Claude Code to finish the browser sign-in&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Claude Desktop / claude.ai:&lt;/strong&gt; go to Settings → Connectors → Add custom connector and paste the &lt;code&gt;wppilot-oauth&lt;/code&gt; URL.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Cursor&lt;/strong&gt; (&lt;code&gt;~/.cursor/mcp.json&lt;/code&gt;):&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"mcpServers"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"wppilot"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"url"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"https://your-site.com/wp-json/mcp/wppilot-oauth"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;VS Code 1.101+&lt;/strong&gt; (&lt;code&gt;.vscode/mcp.json&lt;/code&gt;):&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"servers"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"wppilot"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"http"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"url"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"https://your-site.com/wp-json/mcp/wppilot-oauth"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Codex CLI&lt;/strong&gt; (&lt;code&gt;~/.codex/config.toml&lt;/code&gt;, then &lt;code&gt;codex mcp login wppilot&lt;/code&gt;):&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight toml"&gt;&lt;code&gt;&lt;span class="nn"&gt;[mcp_servers.wppilot]&lt;/span&gt;
&lt;span class="py"&gt;url&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s"&gt;"https://your-site.com/wp-json/mcp/wppilot-oauth"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;ChatGPT:&lt;/strong&gt; enable Developer mode on ChatGPT web, create an app with the OAuth URL, and switch it on in each chat. It connects from OpenAI's cloud, so your site needs public HTTPS.&lt;/p&gt;

&lt;p&gt;Clients such as Zed, Cline or Windsurf use the &lt;code&gt;mcp-remote&lt;/code&gt; bridge (&lt;code&gt;npx -y mcp-remote &amp;lt;oauth url&amp;gt;&lt;/code&gt;), which needs Node.js. Setup guides for all 27 supported clients are on &lt;a href="https://wppilot.co/wordpress-mcp" rel="noopener noreferrer"&gt;wppilot.co/wordpress-mcp&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;If the connection fails:&lt;/strong&gt; most failures are network problems, not WordPress bugs. Your CDN, WAF or security plugin has to let &lt;code&gt;/wp-json/mcp/*&lt;/code&gt; and &lt;code&gt;/.well-known/oauth-*&lt;/code&gt; through without caching them, and the site must answer on a single canonical URL. If sign-in succeeds but calls are still unauthenticated, something is stripping the &lt;code&gt;Authorization&lt;/code&gt; header. &lt;strong&gt;WPPilot → Diagnostics&lt;/strong&gt; tests the connection the way a client would.&lt;/p&gt;

&lt;h2&gt;
  
  
  Safety setup (before any job)
&lt;/h2&gt;

&lt;p&gt;This part answers the "I'm terrified" thread. Everything in this section is Free.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. Pick a safety profile.&lt;/strong&gt; The server enforces it, not the prompt.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Profile&lt;/th&gt;
&lt;th&gt;What it allows&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Read Only&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Inspection only. Every write is blocked. Use it for your first connection and for audits.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Production Safe&lt;/strong&gt; (installation default)&lt;/td&gt;
&lt;td&gt;Normal content, design and store work. Plugin activate, deactivate and update need confirmation. PHP, WP-CLI, filesystem, database access and plugin/theme install or delete are blocked.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Developer Full Access&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Everything that's enabled, including PHP and WP-CLI. Staging only.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;strong&gt;2. Layers on top of the profile:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;WordPress capability checks on every call&lt;/li&gt;
&lt;li&gt;per-ability switches under &lt;strong&gt;WPPilot → Abilities&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;per-credential write rate limits&lt;/li&gt;
&lt;li&gt;draft-first creation&lt;/li&gt;
&lt;li&gt;destructive calls that refuse to run without &lt;code&gt;"confirm": true&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;3. Preview before write.&lt;/strong&gt; For post, page and media edits, settings changes and deletions, the agent can call &lt;code&gt;preview-ability&lt;/code&gt;. You get a field-by-field diff and nothing is written. Then &lt;code&gt;apply-preview&lt;/code&gt; runs it, but only after checking that nobody changed the same fields in the meantime. You can make previews mandatory for the whole site; that setting is off by default.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;4. The change ledger and rollback.&lt;/strong&gt; Every write is logged with the credential, the ability and redacted inputs. You read the log with &lt;code&gt;list-changes&lt;/code&gt; and &lt;code&gt;get-change&lt;/code&gt;. &lt;code&gt;rollback-change&lt;/code&gt; reverses &lt;em&gt;supported&lt;/em&gt; operations. The docs are clear that "rollback is never universal", and it isn't a backup. Each job below says whether its changes can be undone.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Prove it with one read (Read Only):&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Use the wppilot MCP server. Change nothing.
1. Report the active safety profile and the abilities you can see.
2. Call get-site-settings, then list-content for the five newest pages,
   then get-content on one of them.
3. Name every ability you called and every WordPress ID you read.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Job 1: Read-only site and security audit (Free)
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Abilities:&lt;/strong&gt; &lt;code&gt;security-audit&lt;/code&gt;, &lt;code&gt;list-extensions&lt;/code&gt;, &lt;code&gt;get-extension&lt;/code&gt;, &lt;code&gt;list-users&lt;/code&gt;, &lt;code&gt;get-site-settings&lt;/code&gt;, &lt;code&gt;list-changes&lt;/code&gt;, &lt;code&gt;agent-context&lt;/code&gt;, &lt;code&gt;system-status&lt;/code&gt;, &lt;code&gt;performance-audit&lt;/code&gt;.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Do a read-only security review. Change nothing.
1. Run security-audit and explain each finding, most serious first.
2. List plugins and themes with updates; flag inactive ones that could go.
3. List administrator accounts and point out any that look unexpected.
4. Summarise list-changes for the last 30 days.
5. Finish with a numbered fix list and say which items need a developer.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;What happens:&lt;/strong&gt; Only reads run, and Read Only stays on the whole time, so there's nothing to undo. Keep in mind that &lt;code&gt;security-audit&lt;/code&gt; reviews configuration. It is &lt;strong&gt;not&lt;/strong&gt; a malware scan.&lt;/p&gt;

&lt;h2&gt;
  
  
  Job 2: Refresh old posts and draft new ones (Free)
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Abilities:&lt;/strong&gt; &lt;code&gt;search-content&lt;/code&gt;, &lt;code&gt;list-content&lt;/code&gt;, &lt;code&gt;get-content&lt;/code&gt;, &lt;code&gt;get-page-snapshot&lt;/code&gt;, &lt;code&gt;create-post&lt;/code&gt;, &lt;code&gt;update-post&lt;/code&gt;, &lt;code&gt;list-revisions&lt;/code&gt;, &lt;code&gt;restore-revision&lt;/code&gt;, &lt;code&gt;create-term&lt;/code&gt;, &lt;code&gt;assign-terms&lt;/code&gt;.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Find posts mentioning "2024 pricing". For each, show the paragraph that
needs updating and propose new wording. Preview each update-post change
and wait for my OK. Then draft a new post from these bullet points: [...]
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;What happens:&lt;/strong&gt; The agent searches, then previews each edit. You approve, and &lt;code&gt;apply-preview&lt;/code&gt; writes it. New posts are created as drafts. A post edit can be rolled back from the ledger, and WordPress revisions give you a second safety net.&lt;/p&gt;

&lt;h2&gt;
  
  
  Job 3: Bulk image alt text (Free)
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Abilities:&lt;/strong&gt; &lt;code&gt;list-media&lt;/code&gt;, &lt;code&gt;update-media&lt;/code&gt;, &lt;code&gt;verify-rendered-page&lt;/code&gt;.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;List images with empty alt text. For each, read its title, caption, filename
and parent post, and write alt text of 125 characters or fewer. If you can't
tell what it shows, add it to a "needs review" list instead of guessing.
Save with update-media, 25 per batch, and pause after each batch.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;What happens:&lt;/strong&gt; Each &lt;code&gt;update-media&lt;/code&gt; call gets its own ledger entry, so one bad description can be &lt;strong&gt;rolled back&lt;/strong&gt; without touching the rest of the batch. One catch: posts that already embed an image keep the old alt text in their HTML. Fixing those means editing each post.&lt;/p&gt;

&lt;h2&gt;
  
  
  Job 4: Comment triage (Free)
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Abilities:&lt;/strong&gt; &lt;code&gt;list-comments&lt;/code&gt;, &lt;code&gt;get-comment&lt;/code&gt;, &lt;code&gt;moderate-comment&lt;/code&gt;, &lt;code&gt;create-comment&lt;/code&gt;, &lt;code&gt;update-comment&lt;/code&gt;, &lt;code&gt;delete-comment&lt;/code&gt; (needs confirmation).&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Sort held comments into spam, approve and needs-me, with reasons for needs-me.
Mark spam, approve the rest, never delete permanently. Draft replies to
questions and show me before posting any.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;What happens:&lt;/strong&gt; The WordPress user needs &lt;code&gt;moderate_comments&lt;/code&gt;, which Editor has, so no admin rights are required. Moderation can be reversed with &lt;code&gt;rollback-change&lt;/code&gt;. A reply you've posted can be trashed, but anyone notified has already seen it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Job 5: Plugin updates and weekly maintenance (Free)
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Abilities:&lt;/strong&gt; &lt;code&gt;list-extensions&lt;/code&gt;, &lt;code&gt;update-plugin&lt;/code&gt;, &lt;code&gt;activate-plugin&lt;/code&gt;, &lt;code&gt;deactivate-plugin&lt;/code&gt; (all writes need confirmation), plus &lt;code&gt;security-audit&lt;/code&gt; and &lt;code&gt;system-status&lt;/code&gt;.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;List plugins with updates available, with current and new versions.
Recommend an order, lowest risk first. Update only the one I choose,
then re-check system-status and the home page with verify-rendered-page.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;What happens:&lt;/strong&gt; Under Production Safe, each update asks for confirmation. Updates are recorded but &lt;strong&gt;can't be rolled back&lt;/strong&gt;, so take a backup or test on staging first. Installing or deleting plugins is only possible under Developer Full Access, because it writes code to your server.&lt;/p&gt;

&lt;h2&gt;
  
  
  Job 6: Edit Elementor pages and build landing pages (Free edits, Pro composes)
&lt;/h2&gt;

&lt;p&gt;Forum threads say generic AI edits "produce broken layouts on Elementor" and that Elementor "will silently drop malformed widgets". Typed, element-level abilities are the fix.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Free abilities&lt;/strong&gt; (Elementor 3.6.0+, Elementor Pro not required): &lt;code&gt;elementor-check-setup&lt;/code&gt;, &lt;code&gt;elementor-get-content&lt;/code&gt; (a compact skeleton by default), &lt;code&gt;elementor-find-elements&lt;/code&gt;, &lt;code&gt;elementor-get-widget-params&lt;/code&gt;, &lt;code&gt;elementor-edit-element&lt;/code&gt;, &lt;code&gt;elementor-duplicate-element&lt;/code&gt;, &lt;code&gt;elementor-delete-element&lt;/code&gt; (needs confirmation), &lt;code&gt;elementor-set-content&lt;/code&gt; (needs confirmation), plus &lt;code&gt;get-active-design&lt;/code&gt;, &lt;code&gt;check-design&lt;/code&gt;, &lt;code&gt;verify-rendered-page&lt;/code&gt;, &lt;code&gt;get-page-view-link&lt;/code&gt; and &lt;code&gt;capture-page&lt;/code&gt;.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;On the Pricing page (draft): read it as a compact skeleton first.
Change every "Get started" button to "Book a demo", keep the links.
Make "Plans for every team" an H2. Change nothing else.
Give me a preview link and the element ids you changed.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;What happens:&lt;/strong&gt; Only the targeted elements change. Unknown controls abort the write instead of corrupting it, and &lt;code&gt;capture-page&lt;/code&gt; can attach a screenshot to the ledger entry. &lt;strong&gt;Rollback:&lt;/strong&gt; "On Free alone these edits are recorded without a way back". With Pro active, the ledger keeps a copy of the document so the edit can be rolled back. On Free, work on a draft or a duplicate.&lt;/p&gt;

&lt;p&gt;For a landing page, the agent can read your design, create a &lt;strong&gt;draft&lt;/strong&gt; with &lt;code&gt;create-post&lt;/code&gt;, write the layout with &lt;code&gt;elementor-set-content&lt;/code&gt; (or a Gutenberg batch, see below), then check it with &lt;code&gt;check-design&lt;/code&gt; and &lt;code&gt;verify-rendered-page&lt;/code&gt;. &lt;strong&gt;Pro&lt;/strong&gt; adds &lt;code&gt;elementor-build-page&lt;/code&gt; (whole-page composition), templates, popups, global classes and variables.&lt;/p&gt;

&lt;p&gt;On the block editor side, Gutenberg edits are staged with &lt;code&gt;gutenberg-create-pending-batch&lt;/code&gt; and finished by the editor itself from a Block Editor Queue tab, so live content isn't touched until then. That's Free too.&lt;/p&gt;

&lt;h2&gt;
  
  
  Job 7: Bulk SEO titles and meta descriptions (Pro)
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Abilities:&lt;/strong&gt; &lt;code&gt;yoast-get-post-seo&lt;/code&gt; / &lt;code&gt;yoast-edit-post-seo&lt;/code&gt;, &lt;code&gt;rank-math-get-post-seo&lt;/code&gt; / &lt;code&gt;rank-math-edit-post-seo&lt;/code&gt;, plus the AIOSEO and SEOPress equivalents, term-archive SEO, and the Free &lt;code&gt;list-content&lt;/code&gt; and &lt;code&gt;verify-rendered-page&lt;/code&gt;.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Check which SEO plugin is active. List published pages with their SEO
title, description, canonical and robots. Report duplicates, empty
descriptions and titles over 60 characters. Change nothing yet.
For the ten worst, propose a title and description from the page content.
After I approve, write only those two fields, then verify-rendered-page.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;What happens:&lt;/strong&gt; Steps 1–3 run fine in Read Only. Switch to Production Safe for the writes. &lt;strong&gt;SEO edits are recorded but have no rollback&lt;/strong&gt;, which is why the prompt reads the old values first. Save that table. Redirect abilities depend on the SEO plugin's own paid tier (Yoast Premium, AIOSEO Pro, SEOPress Pro).&lt;/p&gt;

&lt;h2&gt;
  
  
  Job 8: WooCommerce catalogue edits (Pro)
&lt;/h2&gt;

&lt;p&gt;The "4k product descriptions" and "throttled after 50 products" threads keep ending with the same advice: small batches, logging, a human check.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Abilities&lt;/strong&gt; (WooCommerce 9.0+): &lt;code&gt;woocommerce-check-setup&lt;/code&gt;, &lt;code&gt;woocommerce-list-products&lt;/code&gt;, &lt;code&gt;woocommerce-get-product&lt;/code&gt;, &lt;code&gt;woocommerce-edit-product&lt;/code&gt; (partial updates), &lt;code&gt;woocommerce-list-product-variations&lt;/code&gt;, &lt;code&gt;woocommerce-edit-product-variation&lt;/code&gt;, &lt;code&gt;woocommerce-sales-summary&lt;/code&gt;, and &lt;code&gt;woocommerce-delete-product&lt;/code&gt; (needs confirmation).&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Run woocommerce-check-setup. List published products in Jackets with SKU,
regular price, sale price and stock. Propose a sale price 20% below regular
for items with more than 5 in stock; show the table and wait. After I approve,
set only sale_price, on each variation for variable products.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The same pattern works for descriptions: 25 products per batch, rewrite only &lt;code&gt;description&lt;/code&gt;, and pause between batches.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What happens:&lt;/strong&gt; Store settings, gateways, tax and shipping zones stay read-only under every profile. &lt;strong&gt;Product and variation edits have no rollback&lt;/strong&gt;, so export or note the old values first. For store-wide changes, Pro's &lt;strong&gt;approval queue&lt;/strong&gt; holds every write until a person signs off, and it emails the admin.&lt;/p&gt;

&lt;h2&gt;
  
  
  Job 9: Page speed and cache tuning (Pro)
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Abilities:&lt;/strong&gt; &lt;code&gt;cache-check-setup&lt;/code&gt;, &lt;code&gt;cache-begin-experiment&lt;/code&gt;, &lt;code&gt;cache-measure-page&lt;/code&gt;, &lt;code&gt;cache-set-settings&lt;/code&gt;, &lt;code&gt;cache-purge&lt;/code&gt;, &lt;code&gt;cache-warm&lt;/code&gt;, &lt;code&gt;cache-verify-in-browser&lt;/code&gt;, &lt;code&gt;cache-revert-experiment&lt;/code&gt;. They cover LiteSpeed, WP Rocket, W3 Total Cache and about two dozen other cache and optimisation plugins.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Start a cache experiment. Measure / and /shop/ three times as a baseline.
Propose the single lowest-risk change and wait. Apply it, purge, warm,
re-measure. If anything got worse, revert the experiment.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;What happens:&lt;/strong&gt; This is one of the better-covered areas. Each settings change can be rolled back on its own, and &lt;code&gt;cache-revert-experiment&lt;/code&gt; restores every layer at once.&lt;/p&gt;

&lt;h2&gt;
  
  
  Six mistakes that make AI + WordPress go wrong
&lt;/h2&gt;

&lt;p&gt;These come up again and again in forum threads, and each one has a simple fix.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Connecting as an administrator.&lt;/strong&gt; An Application Password isn't a separately scoped API key. It carries every capability of its user. Give the agent its own Editor-level account and raise it only when a job needs more.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Skipping the read-only pass.&lt;/strong&gt; Nearly every job above starts with a report. Let the agent show you what it found before it's allowed to change anything, and you'll catch wrong assumptions (the wrong SEO plugin, the wrong category, a variable product priced on its parent) while they still cost nothing.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Treating a successful tool call as a finished job.&lt;/strong&gt; A tool call that returns without error only means the request went through. Open the page in a browser, check mobile, and let &lt;code&gt;verify-rendered-page&lt;/code&gt; catch a cached or theme-overridden title.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Assuming everything can be undone.&lt;/strong&gt; Alt text, post edits, comment moderation and cache settings can be rolled back. SEO metadata, WooCommerce product edits and plugin updates can't. Neither can Elementor element edits on Free alone. Plan the job around that, not the other way round.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Huge batches.&lt;/strong&gt; Store owners in the "4k product descriptions" thread hit throttling after about 50 items. Batches of around 25 with a pause and a summary are easier to review, keep the ledger readable, and are less likely to hit your host's rate limits.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Fixing a refused write by switching to Developer Full Access.&lt;/strong&gt; If a write is refused, a requirement is missing: the capability, the ability switch, the companion plugin or the licence. Fix that one thing. Keep the most permissive profile for staging.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Free vs Pro at a glance
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Job / feature&lt;/th&gt;
&lt;th&gt;Free&lt;/th&gt;
&lt;th&gt;Pro&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;MCP server, OAuth / App Passwords, 27 client configs&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Safety profiles, confirmations, previews, ledger, rollback&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Audits: &lt;code&gt;security-audit&lt;/code&gt;, &lt;code&gt;system-status&lt;/code&gt;, &lt;code&gt;performance-audit&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Posts, pages, media / alt text, comments, menus, revisions&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Plugin activate / update (with confirmation)&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Gutenberg staged edits, design checks, screenshots&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Skills and site instructions&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Elementor element editing (17 abilities)&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Elementor rollback, whole-page composition, templates, global classes&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Yoast, Rank Math, AIOSEO, SEOPress&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;WooCommerce products, variations, coupons, orders&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cache and page-speed experiments&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Forms, ACF/custom fields, WPML/Polylang/Weglot, other page builders&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Page builder converter (new draft plus a loss report)&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Human approval queue with email, persistent memory, integration health&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Pro is a second plugin that registers extra abilities on the &lt;strong&gt;same&lt;/strong&gt; connection, so nothing you set up on Free is wasted. Each module loads only when its plugin is active.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to get each version
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Free:&lt;/strong&gt; download &lt;code&gt;wppilot.zip&lt;/code&gt; from the &lt;a href="https://github.com/wppilot-labs/wordpress-mcp-elementor-wppilot/releases/latest" rel="noopener noreferrer"&gt;GitHub releases&lt;/a&gt;. No account is needed and it's GPL.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Pro:&lt;/strong&gt; choose a plan on the &lt;a href="https://wppilot.co/pricing" rel="noopener noreferrer"&gt;pricing page&lt;/a&gt;. Plans differ only by the number of sites, and every tier has the same features. Keep Free installed, upload the Pro zip from the customer portal, and enter your licence key. Without an active licence, Pro modules stop loading and the site falls back to Free. Nothing is deleted.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;My advice: prove the workflow on Free (jobs 1–6) before paying for anything. Buy Pro only when the data you need lives in a plugin, such as WooCommerce, an SEO suite, forms or custom fields, or when you want an approval queue for agents that run unattended.&lt;/p&gt;

&lt;h2&gt;
  
  
  Wrapping up
&lt;/h2&gt;

&lt;p&gt;The pattern that answers the fears in those threads:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;staging first&lt;/li&gt;
&lt;li&gt;a dedicated user&lt;/li&gt;
&lt;li&gt;OAuth so the credential is revocable&lt;/li&gt;
&lt;li&gt;Read Only until one read works&lt;/li&gt;
&lt;li&gt;Production Safe for drafts&lt;/li&gt;
&lt;li&gt;previews for anything that matters&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;list-changes&lt;/code&gt; after every session&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Before you rely on rollback for a job, check whether that job supports it.&lt;/p&gt;

&lt;p&gt;The &lt;a href="https://wppilot.co/docs" rel="noopener noreferrer"&gt;WPPilot docs&lt;/a&gt; have the full ability reference and troubleshooting. Which job would you hand over first? Tell me in the comments.&lt;/p&gt;

</description>
      <category>wordpress</category>
      <category>ai</category>
      <category>mcp</category>
      <category>tutorial</category>
    </item>
  </channel>
</rss>
