Head to head · Cms content · October 2026 research run

Contentstack vs WordPress

WordPress and Contentstack score within a point of each other on agent readiness, 64.8 (B) and 64 (B). Contentstack leads on schema & documentation, security & auth and transparency & trust. Both do cms content.

Which one, for what

Contentstack B

Good for Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.

Ahead on

  • Schema & documentation, 77 against 65
  • Security & auth, 69 against 62
  • Transparency & trust, 73 against 68

Also in its favour

  • A hosted endpoint, with nothing to install
  • Free to start without a card

Watch for

The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch

WordPress B

Good for Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.

Ahead on

  • Reliability, 78 against 71
  • Agent ergonomics, 74 against 67
  • Payments & pricing, 60 against 30

Also in its favour

  • Open source

Watch for

Application Passwords have no scopes or expiry. Each one carries every capability of its user

Score by category

CategoryWeight this runContentstackWordPressEdge
Reliability16%207178WordPress +7
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27765Contentstack +12
Agent ergonomics13%16.26774WordPress +7
Security & auth14%17.56962Contentstack +7
Payments & pricing10%12.53060WordPress +30
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88283WordPress +1
Transparency & trust7%8.87368Contentstack +5
Negative events≤15-3-5
Total64 · B64.8 · B

Facts side by side

FactContentstackWordPress
KindHTTP APIHTTP API
VendorContentstack Inc.WordPress.org (open-source project)
Hosted endpointhttps://api.contentstack.iono (local only)
TransportsHTTP, stdioHTTP, stdio
AuthOAuth or keyAPI key
PricingFreemiumFree
x402nono
LicenceProprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MITGPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too
Tools exposed206none
Read-only variant documentedyesno
llms.txtyesyes
Last release2026-09-222026-10-06
Terms last updated2022-08-01no document linked
Privacy policy last updated2026-06-30no date given
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waiveryes
Popularity44k npm/wk, 1.5k PyPI/wk21k stars

Verdicts

Contentstack

The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the limit=0 behaviour changed on 11 September 2026 without advance notice.

WordPress

The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026.

Before you call either

Contentstack

  1. Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts
  2. Send api_key and authorization headers on every Content Management API call. Ask for a read-only management token when the task only reads
  3. Page with limit (100 at most), skip and include_count=true. limit=0 no longer returns everything
  4. Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch X-RateLimit-Remaining and back off on 429
  5. Start the MCP server with --groups cma only, and add cma-extended when the task needs audit logs or version history. Publishing and deleting need no confirmation

WordPress

  1. Ask the owner for a dedicated user with the lowest role that fits. A Contributor can draft and edit its own posts but can't publish them
  2. Send the Application Password as Basic auth over HTTPS only. Core disables Application Passwords on plain HTTP outside a local environment
  3. Upload a file with POST /wp-json/wp/v2/media first, then set featured_media or reference the returned URL in the post content
  4. To roll back, GET /wp/v2/posts/<id>/revisions/<rev>?context=edit and POST its title and content to the post. There's no restore route
  5. Pass _fields=id,status,link,modified on lists and read X-WP-TotalPages. per_page stops at 100

Questions

Which is better for AI agents, Contentstack or WordPress?

WordPress and Contentstack score within a point of each other on agent readiness, 64.8 (B) and 64 (B). Contentstack leads on schema & documentation, security & auth and transparency & trust.

Do Contentstack and WordPress need an API key?

Contentstack takes an API key or an OAuth sign-in. WordPress needs an API key.

Can an agent call Contentstack and WordPress without installing anything?

Contentstack has a hosted endpoint at https://api.contentstack.io. WordPress runs on your own machine, with no hosted endpoint listed.

Are Contentstack and WordPress open source?

No open-source release is listed for Contentstack. WordPress is open source (GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too).

Other comparisons with Contentstack or WordPress

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.