
Cowboy MCP
io.github.februalityv1.7.0更新于 Oct 7, 2026
Self-hosted WordPress MCP server with per-change undo and 203 tools. Free, no relay, no Pro tier.
概览
把自建 WordPress 站点变成 MCP 服务器,让助手管理内容、插件、WooCommerce 等,并支持撤销。
- 功能
- 这是一个 WordPress 插件,通过 Streamable HTTP 把站点暴露为 MCP 服务器,内置最多 203 个工具,覆盖文章、页面、分类法、评论、媒体、菜单、Gutenberg 与站点编辑器区块、用户、插件、主题、文件、数据库、WP-CLI、诊断、SEO 插件、WooCommerce、Wordfence、页面构建器和表单。两个网关工具(cowboy_discover、cowboy_run)让代理按需加载工具定义。更改会记入撤销日志,并配有数据库检查点和审计日志,每个写入工具都支持试运行。
- 适用场景
- 当你希望 AI 客户端用自然语言操作自己掌控的 WordPress 站点时使用,包括内容编辑、插件与主题管理、WooCommerce 管理和诊断;在正式站点上使用前,可依靠逐次撤销和检查点降低风险。
- 运行要求
- 自建 WordPress 站点,需 WordPress 6.2+ 和 PHP 8.0+。插件从 WordPress.org 目录安装并启用。需在“设置 → Cowboy MCP”生成 Bearer API 密钥,并通过 Authorization 请求头发送;OAuth 连接器需要公网 HTTPS 站点,本地站点的终端工具可用普通 HTTP。本地 Claude Desktop 需要 mcp-remote 桥接。
安装
在 SourceWeft 中
- 打开 控制台中的 Cowboy MCP,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。
其他 MCP 客户端
把它添加到你客户端的 mcpServers 配置中。
{
"mcpServers": {
"cowboy-mcp": {
"type": "http",
"url": "https://{site_host}/wp-json/cowboy-mcp/v1/endpoint"
}
}
}README
Cowboy MCP 🤠 — Free WordPress MCP Server with Undo
Cowboy MCP is a free, open-source WordPress plugin that turns any WordPress site into a Model Context Protocol (MCP) server over Streamable HTTP, so Claude, ChatGPT, Cursor, Claude Code, Codex, Gemini and any other MCP client can manage the site in plain English — with per-change undo, database checkpoints and an audit log, so it can be trusted on a live site.
[Version] [WordPress] [PHP] [Tested] [License]
Install: WordPress.org plugin directory (one click, auto-updates) · Try it in your browser: Live Preview · Website & guides: cowboymcp.com · Questions: support forum · Bugs: issues
Why Cowboy MCP?
- Every tool is free. Up to 203 built-in tools plus every ability your plugins register through the WordPress Abilities API — content, Gutenberg/Site Editor, WooCommerce, users, media, menus, plugins, themes, files, database, WP-CLI, diagnostics, revisions, SEO (Yoast, Rank Math, AIOSEO, SEOPress), The Events Calendar, ACF, Elementor, Beaver Builder, SiteOrigin, Wordfence, caching, forms — GPL-licensed, no Pro tier, no credits, no usage meter.
- Every change is undoable. A per-change undo journal (before-state snapshots, conflict detection, batch undo) plus one-click database checkpoints, with an always-on audit log. Plugin and theme updates take a file backup and a checkpoint first and auto-restore if the post-update health check fails.
- Nothing in the middle. The MCP endpoint runs inside your WordPress install. No hosted relay, no account, no telemetry — your AI client connects straight to your site.
- Safe by default. Safe mode (confirmation for destructive tools), dry run on every write tool, per-credential read-only/custom scoping, hashed keys shown once, per-key rate limits, denylists for sensitive options / dangerous SQL / WP-CLI commands, SSRF protection, path confinement to
wp-content, and a Power mode only a human can enable in wp-admin. - Two ways to connect. A Bearer-token endpoint for terminal agents and editors, and a one-click OAuth 2.1 connector (admin consent, scope choice) for the Claude desktop/web apps and ChatGPT.
- Works locally too. Local, Studio, MAMP, DevKinsta, wp-env: terminal tools connect with a key as on a live site; Claude Desktop connects through an
mcp-remotebridge the Connections tab generates for you. - Context-efficient.
tools/listreturns two gateway tools (cowboy_discover,cowboy_run); the agent discovers and runs the other tools on demand instead of loading 203 schemas into its context. On WordPress 6.9+ every tool is also acowboy-mcp/*ability for WP-CLI, REST and the official MCP Adapter — with undo. - Zero dependencies. Native WordPress APIs only — no Composer, no npm, no build step, no
wp-admin/includesat request time. Works on hosts without WP-CLI orshell_exec().
"More access than any other MCP offers, easy to use, LOVE the change journal and the checkpoints — safe if you break something." — WordPress.org review
Tool coverage
Plus 17 read-only resources (incl. wordpress://tools/catalog), 4 resource templates (wordpress://posts/{id}, wordpress://options/{name}, wordpress://plugins/{slug}, wordpress://users/{id}) and 8 workflow prompts with argument auto-completion. Integrations register only when their plugin is active.
Requirements
- WordPress 6.2+ (tested up to 7.1)
- PHP 8.0+
- HTTPS for the OAuth connector and for cloud clients (claude.ai, ChatGPT); plain HTTP is fine for terminal tools on a local site
Installation
- Plugins → Add New, search for Cowboy MCP, install and activate — or download from WordPress.org.
- Settings → Cowboy MCP → Generate API Key. Copy it — it is shown once and stored hashed.
- Connect your client (below). The Connection tab shows every snippet pre-filled with your site's endpoint.
Updates arrive through the normal WordPress updates screen.
Connecting an agent
The endpoint is https://yoursite.com/wp-json/cowboy-mcp/v1/endpoint (JSON-RPC 2.0 over Streamable HTTP, MCP 2025-06-18).
Claude Code
Claude desktop & web, ChatGPT (one-click, no key) — turn on Settings → Cowboy MCP → Settings → Desktop Connector, add the endpoint as a custom connector in the app (for Claude, the Add to Claude button on the Connections tab fills it in for you), approve the consent screen on your site (choose full, read-only or custom access). Requires a public HTTPS site.
Claude Desktop on a local site — use the mcp-remote bridge config shown on the Connections tab:
Cursor / Windsurf (Devin Desktop) (~/.cursor/mcp.json, ~/.config/devin/mcp_config.json)
Cline: add "type": "streamableHttp" to the entry. VS Code (.vscode/mcp.json): use servers instead of mcpServers and add "type": "http". Zed: put the same url + headers under context_servers in its settings.
Codex CLI — Codex reads the key each time it starts, so add the export to your shell profile too.
Gemini CLI
Any client that speaks Streamable HTTP with a Bearer header works the same way (n8n, Opencode, LibreChat, your own agent). Opencode: set "oauth": false on the remote server so it uses the key. Step-by-step guides per client: cowboymcp.com.
Quick smoke test with curl
Safety model
- Safe mode (default on): tools annotated
destructiveHintrefuse to run until the call is resent withconfirm: true; the refusal includes a preview. - Dry run: every non-read-only tool accepts
dry_run: trueand reports exactly what would change. - Undo journal: before-state snapshots for journaled changes (posts, options, users, media, menus, terms, comments, WooCommerce objects, SEO meta, Gutenberg/FSE edits, search-replace rows, plugin/theme packages);
wp_list_changes/wp_undo_change, batch undo, conflict detection, redo-on-undo; 7-day retention by default. - Database checkpoints: prefix-scoped dump of the site's tables, atomic restore; up to 5 kept; taken automatically before plugin/theme updates and mutating WP-CLI commands. Checkpoints restore tables, not uploaded files or code.
- Audit log: every tool call, error and auth event in
{prefix}cowboy_mcp_audit_log(key, tool, arguments, result, IP); pruned after 30 days; secrets redacted on read. - Scoped credentials: API keys and OAuth connections carry
{mode: full|read_only|custom, allowed_tools[]}; enforced at dispatch, also for tools called throughcowboy_runand batches.readOnlyHintis treated as a security boundary. - Keys & limits: keys stored as one-way hashes, shown once, revocable individually; per-key rate limit (120/min default); request
Originallowlist; OAuth tokens stored hashed, off by default, admin consent required. - Guardrails: protected-option denylist (
siteurl,active_plugins, credentials, the plugin's own settings…), dangerous-SQL and WP-CLI blocklists (eval,shell,db drop, …) applied on a shell-style tokenizer, SSRF validation on outbound requests,wp-contentpath confinement with atomic writes, a PHP syntax check before every file write and nomu-pluginswrites without Power mode, self-delete and last-administrator protection. - Power mode: an admin-only checkbox that lifts the curated guardrails for one-off jobs; it can never be enabled through the API, and it never lifts credential-option protection, secret redaction or self-protection.
- Connection Doctor: one-click self-test (HTTPS, reachability, REST, OAuth discovery, host blockers such as Cloudflare challenges, ModSecurity-style WAFs, LiteSpeed caching) with fingerprinted causes and fixes; also
wp cowboy-mcp doctorand thewp_connection_doctortool.
How it compares
Factual, dated comparisons live on the site: all WordPress MCP plugins compared · vs Novamira · vs AI Engine · vs WPVibe · vs InstaWP · vs the WordPress MCP Adapter · self-hosted vs hosted. Short version: the endpoint is self-hosted with no relay or metering, every tool is free, and undo + checkpoints + audit log ship together.
Architecture
Tool descriptions and error messages returned to agents are intentionally English; the admin UI is translated.
Extensibility
cowboy_mcp_toolsfilter — register your own tool definitions and handlers.cowboy_mcp_tool_allowedfilter — block specific tools per request.cowboy_mcp_allowed_originsfilter — extend the requestOriginallowlist.
Development
No build step. Pull requests welcome — keep the WordPress.org review invariants (no wp-admin/includes requires, no path constants, prepared/validated $wpdb queries, escaped output).
Support, reviews, security
- Questions and connection problems: the WordPress.org support forum — paste your Connection Doctor report; topics are usually answered within a day.
- Bugs and feature requests: GitHub issues.
- Security issues: please report privately through this repository's Security tab (private vulnerability reporting) rather than a public issue.
- Reviews: if Cowboy MCP saves you time, a review on WordPress.org helps other site owners find it.
License
GPL-2.0-or-later. © Andrew Ivanov (februality).
来源:README.md,提交 61ff4b5
工具
0版本历史
1- v1.7.0最新Oct 7, 2026

