Head to head · Cms content · October 2026 research run
Contentstack vs WordPress
WordPress and Contentstack score within a point of each other on agent readiness, 64.8 (B) and 64 (B). Contentstack leads on schema & documentation, security & auth and transparency & trust. Both do cms content.
Which one, for what
Good for Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.
Ahead on
- Schema & documentation, 77 against 65
- Security & auth, 69 against 62
- Transparency & trust, 73 against 68
Also in its favour
- A hosted endpoint, with nothing to install
- Free to start without a card
Watch for
The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch
Good for Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.
Ahead on
- Reliability, 78 against 71
- Agent ergonomics, 74 against 67
- Payments & pricing, 60 against 30
Also in its favour
- Open source
Watch for
Application Passwords have no scopes or expiry. Each one carries every capability of its user
Score by category
| Category | Weight this run | Contentstack | WordPress | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 71 | 78 | WordPress +7 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 77 | 65 | Contentstack +12 |
| Agent ergonomics | 13%16.2 | 67 | 74 | WordPress +7 |
| Security & auth | 14%17.5 | 69 | 62 | Contentstack +7 |
| Payments & pricing | 10%12.5 | 30 | 60 | WordPress +30 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 82 | 83 | WordPress +1 |
| Transparency & trust | 7%8.8 | 73 | 68 | Contentstack +5 |
| Negative events | ≤15 | -3 | -5 | |
| Total | 64 · B | 64.8 · B |
Facts side by side
| Fact | Contentstack | WordPress |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Contentstack Inc. | WordPress.org (open-source project) |
| Hosted endpoint | https://api.contentstack.io | no (local only) |
| Transports | HTTP, stdio | HTTP, stdio |
| Auth | OAuth or key | API key |
| Pricing | Freemium | Free |
| x402 | no | no |
| Licence | Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT | GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too |
| Tools exposed | 206 | none |
| Read-only variant documented | yes | no |
| llms.txt | yes | yes |
| Last release | 2026-09-22 | 2026-10-06 |
| Terms last updated | 2022-08-01 | no document linked |
| Privacy policy last updated | 2026-06-30 | no date given |
| Customer content may train models | not found in the text | |
| Terms restrict automated access | not found in the text | |
| Terms restrict benchmarking | yes | |
| Terms or service can change without notice | not found in the text | |
| Arbitration or class-action waiver | yes | |
| Popularity | 44k npm/wk, 1.5k PyPI/wk | 21k stars |
Verdicts
Contentstack
The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the limit=0 behaviour changed on 11 September 2026 without advance notice.
WordPress
The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026.
Before you call either
Contentstack
- Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts
- Send
api_keyandauthorizationheaders on every Content Management API call. Ask for a read-only management token when the task only reads - Page with
limit(100 at most),skipandinclude_count=true.limit=0no longer returns everything - Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch
X-RateLimit-Remainingand back off on 429 - Start the MCP server with
--groups cmaonly, and addcma-extendedwhen the task needs audit logs or version history. Publishing and deleting need no confirmation
WordPress
- Ask the owner for a dedicated user with the lowest role that fits. A Contributor can draft and edit its own posts but can't publish them
- Send the Application Password as Basic auth over HTTPS only. Core disables Application Passwords on plain HTTP outside a local environment
- Upload a file with POST
/wp-json/wp/v2/mediafirst, then setfeatured_mediaor reference the returned URL in the post content - To roll back, GET
/wp/v2/posts/<id>/revisions/<rev>?context=editand POST its title and content to the post. There's no restore route - Pass
_fields=id,status,link,modifiedon lists and read X-WP-TotalPages.per_pagestops at 100
Questions
Which is better for AI agents, Contentstack or WordPress?
WordPress and Contentstack score within a point of each other on agent readiness, 64.8 (B) and 64 (B). Contentstack leads on schema & documentation, security & auth and transparency & trust.
Do Contentstack and WordPress need an API key?
Contentstack takes an API key or an OAuth sign-in. WordPress needs an API key.
Can an agent call Contentstack and WordPress without installing anything?
Contentstack has a hosted endpoint at https://api.contentstack.io. WordPress runs on your own machine, with no hosted endpoint listed.
Are Contentstack and WordPress open source?
No open-source release is listed for Contentstack. WordPress is open source (GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too).
Other comparisons with Contentstack or WordPress
Machine-readable
- This page as Markdown
/compare/contentstack-vs-wordpress.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/contentstack.json·/api/v1/tools/wordpress.json - From a terminal
anchor compare contentstack wordpress(the CLI) - Over MCP
compare_tools {"a": "contentstack", "b": "wordpress"}at/mcp, no key