{
  "data": {
    "a": {
      "slug": "contentstack",
      "name": "Contentstack",
      "vendor": "Contentstack Inc.",
      "vendorUrl": "https://www.contentstack.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Contentstack is a hosted headless CMS. Its Content Management API reads and writes entries, assets, content types, locales, releases and publishing across seven regional endpoints, and an official local MCP server wraps the same API for agents.",
      "url": "https://www.anchorterminal.com/tools/contentstack",
      "markdownUrl": "https://www.anchorterminal.com/tools/contentstack.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/contentstack.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/contentstack.json",
      "repo": "https://github.com/contentstack/contentstack-openapi",
      "license": "Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://api.contentstack.io",
      "packages": [
        {
          "registry": "npm",
          "name": "@contentstack/mcp"
        },
        {
          "registry": "npm",
          "name": "@contentstack/management"
        },
        {
          "registry": "pypi",
          "name": "contentstack-management"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access is self-serve. Sign up, create a stack, then create a management token in the stack's settings (stack Owner or Admin only) and send it in the `authorization` header with the stack's `api_key`. Management tokens can be read-only or read-write, limited to branches, and given an expiry date. OAuth 2.0 apps are created in Developer Hub, with authorisation code and client credentials grants, scopes per module and action, 60-minute tokens and a refresh grant. A user authtoken from the login endpoint also works. The MCP server uses OAuth through `npx @contentstack/mcp --auth`, or a management token for content tools.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 a month with no card and no expiry (one stack, three users, 100,000 API calls a month, 1,000 entries), so an agent's owner can start without a contract. Build is $29 a month and Growth $299 a month with extra users at $25 each. Enterprise is priced by quote. Build mentions pay-as-you-go overages, and no overage rate is shown on the pricing page (https://www.contentstack.com/pricing, checked 2026-10-07).",
      "priceSummary": "$29 / mo",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI file, the MCP package or the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": 206,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 43992,
        "pypiWeekly": 1504,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://www.contentstack.com/docs/developers/apis/content-management-api",
      "llmsTxt": "https://www.contentstack.com/llms.txt",
      "openapi": "https://github.com/contentstack/contentstack-openapi",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.localisation",
        "cms.schema"
      ],
      "tags": [
        "hosted",
        "official",
        "mcp",
        "openapi",
        "llms-txt",
        "oauth",
        "free-tier",
        "no-card",
        "closed-source",
        "webhooks",
        "typescript",
        "python",
        "java",
        "dotnet",
        "status-page",
        "soc2",
        "sla"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64,
        "grade": "B",
        "agentReady": false,
        "rank": 264,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 82,
          "payments": 30,
          "reliability": 71,
          "schema": 77,
          "security": 69,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-07"
        },
        "negative": -3,
        "negativeNotes": [
          "11 September 2026. The `limit` query parameter on delivery and management requests changed behaviour inside v3. `limit=0` used to return every matching record and now returns the default 100, so an integration relying on it gets a truncated result with a 200 status. The changelog entry is dated the same day and gives a migration path, and no earlier notice was found in the changelog feed. Deducted 3, the low end, because it was documented (https://www.contentstack.com/docs/changelog)."
        ],
        "verdict": "The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.",
        "bestFor": "Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.",
        "strengths": [
          "OAuth 2.0 scopes separate read, write, publish and unpublish for entries and assets, with 60-minute tokens and a refresh grant",
          "Management tokens can be read-only, limited to named branches, given an expiry date and given their own per-second rate limits",
          "Free plan at $0 with no card and no expiry (one stack, three users, 100,000 API calls a month), launched 16 September 2026",
          "Public OpenAPI 3.0.0 file for the Content Management API (138 paths, 221 operations) and public JSON Schema for all 206 MCP tools at mcp.contentstack.com",
          "Stack audit log readable through /v3/audit-logs, and entry and asset version history through the API",
          "Uptime commitment of 99.50 or 99.95 per cent by plan, with service credits, published in the Services Description"
        ],
        "weaknesses": [
          "The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch",
          "On 11 September 2026 `limit=0` stopped returning every record and now returns the default 100. The changelog entry is dated the same day",
          "The OpenAPI file documents only 200 responses and has no enums or component schemas. Request bodies are shown as examples",
          "No idempotency keys and no Retry-After header were found. The docs name only X-RateLimit-Limit and X-RateLimit-Remaining",
          "No security.txt and no bug bounty were found, and no deprecation policy with a notice period",
          "Nine incidents with customer impact on status.contentstack.com between 9 July and 7 October 2026, each in one or two regions"
        ],
        "agentNotes": [
          "Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts",
          "Send `api_key` and `authorization` headers on every Content Management API call. Ask for a read-only management token when the task only reads",
          "Page with `limit` (100 at most), `skip` and `include_count=true`. `limit=0` no longer returns everything",
          "Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch `X-RateLimit-Remaining` and back off on 429",
          "Start the MCP server with `--groups cma` only, and add `cma-extended` when the task needs audit logs or version history. Publishing and deleting need no confirmation"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 82,
          "payments": 30,
          "reliability": 71,
          "schema": 77,
          "security": 69,
          "transparency": 59
        },
        "provenanceScore": 87
      },
      "connect": {
        "install": "npx -y @contentstack/mcp",
        "http": "curl \"https://api.contentstack.io/v3/content_types\" \\\n  -H \"api_key: $CONTENTSTACK_API_KEY\" -H \"authorization: $CONTENTSTACK_MANAGEMENT_TOKEN\"",
        "config": {
          "mcpServers": {
            "contentstack": {
              "args": [
                "-y",
                "@contentstack/mcp"
              ],
              "command": "npx",
              "env": {
                "CONTENTSTACK_API_KEY": "\u003cYOUR_STACK_API_KEY\u003e",
                "GROUPS": "cma"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/contentstack"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Build",
          "unit": "month",
          "usd": 29,
          "note": "3 users, 250,000 API calls a month"
        },
        {
          "item": "Growth",
          "unit": "month",
          "usd": 299,
          "note": "10 users, 1M API calls a month"
        },
        {
          "item": "Growth, each extra user",
          "unit": "seat-month",
          "usd": 25,
          "note": "beyond the 10 included"
        }
      ],
      "provenance": {
        "legalEntity": "Contentstack Inc.",
        "domain": "contentstack.com",
        "domainRegistered": "2011-10-29",
        "domainNote": "The AWS North America API is on api.contentstack.io. The other six regions and the MCP tool definitions are on contentstack.com hosts.",
        "endpointOnVendorDomain": true,
        "terms": "https://www.contentstack.com/legal/terms-of-service",
        "privacy": "https://www.contentstack.com/legal/privacy",
        "statusPage": "https://status.contentstack.com",
        "changelog": "https://www.contentstack.com/docs/changelog",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Master Agreement (last updated 17 July 2026) names Contentstack Inc., a Delaware corporation at 1023 Springdale Rd., Bldg. 14A, Austin, TX 78721. The privacy policy is dated 30 June 2026.",
          "The online Terms of Service carry an effective date of August 2022. Paid subscriptions are governed by the Master Agreement and the Services Description (last updated 28 July 2026).",
          "www.contentstack.com/.well-known/security.txt and /security.txt both return 404. SECURITY.md in Contentstack's GitHub repositories sends reports to security@contentstack.com.",
          "RDAP for contentstack.com gives a registration date of 2011-10-29.",
          "The npm package @contentstack/mcp names github.com/contentstack/mcp as its repository. That repository asked for credentials when we tried to clone it, so it isn't public."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/contentstack.json",
      "live": {
        "slug": "contentstack",
        "probe": {
          "target": "https://api.contentstack.io",
          "method": "get",
          "lastAt": "2026-10-08T19:08:44.104830955Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 575,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 540,
          "p95ms24h": 611,
          "samples24h": 42,
          "samples30d": 42,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 42,
              "ok": 42
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.contentstack.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:06:32.569528883Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@contentstack/management",
            "version": "1.31.2",
            "seenAt": "2026-10-08T16:06:51.377892172Z"
          },
          {
            "registry": "npm",
            "name": "@contentstack/mcp",
            "version": "0.9.0",
            "seenAt": "2026-10-08T16:06:47.529272792Z"
          },
          {
            "registry": "pypi",
            "name": "contentstack-management",
            "version": "1.11.2",
            "released": "2026-08-12",
            "seenAt": "2026-10-08T16:06:51.588548545Z"
          }
        ],
        "githubStars": 8,
        "npmWeekly": 380,
        "pypiWeekly": 1518,
        "securityTxt": {
          "url": "https://contentstack.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:44.745635489Z"
        },
        "pages": [
          {
            "url": "https://www.contentstack.com/docs/changelog",
            "kind": "changelog",
            "status": 404,
            "checkedAt": "2026-10-08T18:27:09.968657878Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.contentstack.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:17.384677543Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5dd89e546041"
          },
          {
            "url": "https://www.contentstack.com/legal/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:12.602685857Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "999e1b8c6308"
          },
          {
            "url": "https://www.contentstack.com/legal/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:16.022719984Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a9cc98c875af"
          }
        ],
        "updatedAt": "2026-10-08T19:08:44.104830955Z"
      }
    },
    "answer": "WordPress and Contentstack score within a point of each other on agent readiness, 64.8 (B) and 64 (B). Contentstack leads on schema \u0026 documentation, security \u0026 auth and transparency \u0026 trust.",
    "b": {
      "slug": "wordpress",
      "name": "WordPress",
      "vendor": "WordPress.org (open-source project)",
      "vendorUrl": "https://wordpress.org",
      "kind": "http-api",
      "category": "cms",
      "summary": "WordPress is an open-source content management system that its owner hosts. Agents create, revise and publish posts, pages and media through the built-in REST API, WP-CLI or the official MCP Adapter plugin.",
      "url": "https://www.anchorterminal.com/tools/wordpress",
      "markdownUrl": "https://www.anchorterminal.com/tools/wordpress.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/wordpress.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/wordpress.json",
      "repo": "https://github.com/WordPress/wordpress-develop",
      "license": "GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too",
      "transports": [
        "http",
        "stdio"
      ],
      "packages": [],
      "auth": "api-key",
      "authNotes": "Self-serve on your own site, with no app review or approval by WordPress.org. A user creates an Application Password on their profile, through `/wp/v2/users/\u003cid\u003e/application-passwords` or with `wp user application-password create`, and the agent sends it as Basic auth over HTTPS. A password has no scopes or expiry and carries every capability of its user, so access is set by the user's role. Each password can be revoked on its own. The MCP Adapter's HTTP transport takes the same credential, and its STDIO transport runs as the user named in `--user`.",
      "pricing": "free",
      "pricingNotes": "Free software with nothing to buy from WordPress.org, so an agent can start without a contract or a card. The owner pays for their own hosting. WordPress.com and other hosts sell hosted WordPress under their own prices, which aren't graded here (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the REST API handbook, wordpress.org/llms.txt or the core and MCP Adapter repositories (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 21460,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.wordpress.org/rest-api/",
      "llmsTxt": "https://wordpress.org/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "rest",
        "mcp",
        "cli",
        "php",
        "llms-txt",
        "security-txt",
        "bug-bounty"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.8,
        "grade": "B",
        "agentReady": false,
        "rank": 249,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 83,
          "payments": 60,
          "reliability": 78,
          "schema": 65,
          "security": 62,
          "transparency": 68
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -5,
        "negativeNotes": [
          "22 September 2026. WordPress 7.1.2 fixed a critical flaw, CVE-2026-87902 (GHSA-7hp8-65ch-5whp), in which an unauthenticated attacker could, where server and theme conditions were met, make template resolution include a local PHP file and reach remote code execution. 7.1.1 on 17 September and 7.1.3 on 6 October fixed 18 further security issues. All were published by the project with the fix and backported, and we found no report of exploitation in the release posts, so we deduct 5 of a possible 15. https://wordpress.org/news/2026/09/wordpress-7-1-2-release/ ; https://wordpress.org/news/2026/10/wordpress-7-1-3-maintenance-and-security-release/"
        ],
        "verdict": "The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026.",
        "bestFor": "Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.",
        "strengths": [
          "Posts created without `status` are saved as drafts, and DELETE moves a post to the Trash unless `force=true` is passed",
          "Every REST or WP-CLI update to a post writes a revision that `/wp/v2/posts/\u003cid\u003e/revisions` lists with author and date",
          "`_fields` trims responses down to nested properties, with `per_page` up to 100 and X-WP-Total headers on every list",
          "Six stable releases between 6 August and 6 October 2026, and security fixes backported to 4.7",
          "GPL-2.0-or-later, free to self-host, with a valid security.txt and a HackerOne programme for core"
        ],
        "weaknesses": [
          "Application Passwords have no scopes or expiry. Each one carries every capability of its user",
          "The revisions route supports GET and DELETE only, so a rollback means writing the old content back as a new update",
          "Core has no rate limit, no idempotency keys and no log of API calls beyond revisions and a password's last use",
          "A critical flaw (CVE-2026-87902) fixed in 7.1.2 on 22 September 2026 allowed remote code execution under certain server and theme conditions",
          "No published OpenAPI file. Each site describes its own routes at `/wp-json`, and core has no content localisation"
        ],
        "agentNotes": [
          "Ask the owner for a dedicated user with the lowest role that fits. A Contributor can draft and edit its own posts but can't publish them",
          "Send the Application Password as Basic auth over HTTPS only. Core disables Application Passwords on plain HTTP outside a local environment",
          "Upload a file with POST `/wp-json/wp/v2/media` first, then set `featured_media` or reference the returned URL in the post content",
          "To roll back, GET `/wp/v2/posts/\u003cid\u003e/revisions/\u003crev\u003e?context=edit` and POST its title and content to the post. There's no restore route",
          "Pass `_fields=id,status,link,modified` on lists and read X-WP-TotalPages. `per_page` stops at 100"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.8
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 83,
          "payments": 60,
          "reliability": 78,
          "schema": 65,
          "security": 62,
          "transparency": 72
        },
        "provenanceScore": 63
      },
      "connect": {
        "install": "wp core download \u0026\u0026 wp core install --url=\u003curl\u003e --title=\u003ctitle\u003e --admin_user=\u003cuser\u003e --admin_email=\u003cemail\u003e",
        "http": "curl --user \"USERNAME:PASSWORD\" https://HOSTNAME/wp-json/wp/v2/users?context=edit",
        "config": {
          "mcpServers": {
            "wordpress": {
              "args": [
                "--path=/path/to/your/wordpress/site",
                "mcp-adapter",
                "serve",
                "--server=mcp-adapter-default-server",
                "--user=admin"
              ],
              "command": "wp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/wordpress"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "WordPress, self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "GPL, you pay for your own hosting"
        }
      ],
      "provenance": {
        "legalEntity": "WordPress.org, an open-source project. The WordPress trademark belongs to the WordPress Foundation",
        "domain": "wordpress.org",
        "domainRegistered": "2003-03-28",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "https://wordpress.org/about/privacy/",
        "statusPage": "",
        "changelog": "https://wordpress.org/news/category/releases/",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "No terms of service govern the software. It is licensed under GPL version 2 or later, and no service agreement or API terms were found, so `terms` is left out.",
          "The privacy policy covers the WordPress.org websites and names api.wordpress.org, the service installations call to check for updates. It names no company, and gives dpo@wordpress.org as the contact. It doesn't cover content held on a self-hosted site.",
          "The REST API answers on each owner's own domain.",
          "https://wordpress.org/.well-known/security.txt returned 200 with Contact https://hackerone.com/wordpress and Expires 2027-06-30.",
          "RDAP for wordpress.org gives a registration date of 2003-03-28.",
          "The make.wordpress.org footer says the WordPress trademark is the intellectual property of the WordPress Foundation. `license.txt` gives copyright to the contributors.",
          "No status page applies to self-hosted software."
        ],
        "score": 63
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/wordpress.json",
      "live": {
        "slug": "wordpress",
        "pages": [
          {
            "url": "https://wordpress.org/news/category/releases/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:52.505193763Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cbd71d93d029"
          },
          {
            "url": "https://wordpress.org/about/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:50.079319583Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "61575a1b129f"
          }
        ],
        "updatedAt": "2026-10-08T18:25:52.505193763Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Contentstack Inc.",
        "b": "WordPress.org (open-source project)",
        "name": "Vendor"
      },
      {
        "a": "https://api.contentstack.io",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, stdio",
        "b": "HTTP, stdio",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT",
        "b": "GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too",
        "name": "Licence"
      },
      {
        "a": "206",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-22",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "2022-08-01",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2026-06-30",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "44k npm/wk, 1.5k PyPI/wk",
        "b": "21k stars",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "WordPress and Contentstack score within a point of each other on agent readiness, 64.8 (B) and 64 (B). Contentstack leads on schema \u0026 documentation, security \u0026 auth and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Contentstack or WordPress?"
      },
      {
        "answer": "Contentstack takes an API key or an OAuth sign-in. WordPress needs an API key.",
        "question": "Do Contentstack and WordPress need an API key?"
      },
      {
        "answer": "Contentstack has a hosted endpoint at https://api.contentstack.io. WordPress runs on your own machine, with no hosted endpoint listed.",
        "question": "Can an agent call Contentstack and WordPress without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Contentstack. WordPress is open source (GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too).",
        "question": "Are Contentstack and WordPress open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 77 against 65",
          "Security \u0026 auth, 69 against 62",
          "Transparency \u0026 trust, 73 against 68"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Free to start without a card"
        ],
        "goodFor": "Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.",
        "slug": "contentstack",
        "watchFor": "The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch"
      },
      {
        "aheadOn": [
          "Reliability, 78 against 71",
          "Agent ergonomics, 74 against 67",
          "Payments \u0026 pricing, 60 against 30"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.",
        "slug": "wordpress",
        "watchFor": "Application Passwords have no scopes or expiry. Each one carries every capability of its user"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-ghost.json",
        "title": "Contentstack vs Ghost",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-sanity.json",
        "title": "Contentstack vs Sanity",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-storyblok.json",
        "title": "Contentstack vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-strapi.json",
        "title": "Contentstack vs Strapi",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-webflow.json",
        "title": "Contentstack vs Webflow",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-wordpress.json",
        "title": "Ghost vs WordPress",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sanity-vs-wordpress.json",
        "title": "Sanity vs WordPress",
        "url": "https://www.anchorterminal.com/compare/sanity-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/storyblok-vs-wordpress.json",
        "title": "Storyblok vs WordPress",
        "url": "https://www.anchorterminal.com/compare/storyblok-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/strapi-vs-wordpress.json",
        "title": "Strapi vs WordPress",
        "url": "https://www.anchorterminal.com/compare/strapi-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/webflow-vs-wordpress.json",
        "title": "Webflow vs WordPress",
        "url": "https://www.anchorterminal.com/compare/webflow-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 7,
        "contentstack": 71,
        "edge": "wordpress",
        "key": "reliability",
        "name": "Reliability",
        "weight": 16,
        "wordpress": 78
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 12,
        "contentstack": 77,
        "edge": "contentstack",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13,
        "wordpress": 65
      },
      {
        "by": 7,
        "contentstack": 67,
        "edge": "wordpress",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13,
        "wordpress": 74
      },
      {
        "by": 7,
        "contentstack": 69,
        "edge": "contentstack",
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14,
        "wordpress": 62
      },
      {
        "by": 30,
        "contentstack": 30,
        "edge": "wordpress",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10,
        "wordpress": 60
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "contentstack": 82,
        "edge": "wordpress",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7,
        "wordpress": 83
      },
      {
        "by": 5,
        "contentstack": 73,
        "edge": "contentstack",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7,
        "wordpress": 68
      }
    ],
    "summary": "WordPress and Contentstack score within a point of each other on agent readiness, 64.8 (B) and 64 (B). Contentstack leads on schema \u0026 documentation, security \u0026 auth and transparency \u0026 trust. Both do cms content.",
    "verdicts": {
      "contentstack": "The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.",
      "wordpress": "The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress",
    "json": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress.md",
    "slim": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress.min.md"
  },
  "markdown": "WordPress and Contentstack score within a point of each other on agent readiness, 64.8 (B) and 64 (B). Contentstack leads on schema \u0026 documentation, security \u0026 auth and transparency \u0026 trust. Both do cms content.\n\n- Contentstack: grade B, 64/100, rank #264 of 629. Markdown https://www.anchorterminal.com/tools/contentstack.md · JSON https://www.anchorterminal.com/api/v1/tools/contentstack.json\n- WordPress: grade B, 64.8/100, rank #249 of 629. Markdown https://www.anchorterminal.com/tools/wordpress.md · JSON https://www.anchorterminal.com/api/v1/tools/wordpress.json\n\n## Which one, for what\n\n### Contentstack (B)\n\nGood for: Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.\n\nAhead on:\n- Schema \u0026 documentation, 77 against 65\n- Security \u0026 auth, 69 against 62\n- Transparency \u0026 trust, 73 against 68\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Free to start without a card\n\nWatch for: The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch\n\n### WordPress (B)\n\nGood for: Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.\n\nAhead on:\n- Reliability, 78 against 71\n- Agent ergonomics, 74 against 67\n- Payments \u0026 pricing, 60 against 30\n\nAlso in its favour:\n- Open source\n\nWatch for: Application Passwords have no scopes or expiry. Each one carries every capability of its user\n\n\n## Score by category\n\n| Category | Weight | Contentstack | WordPress | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 71 | 78 | WordPress +7 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 77 | 65 | Contentstack +12 |\n| Agent ergonomics | 13% (16.2 this run) | 67 | 74 | WordPress +7 |\n| Security \u0026 auth | 14% (17.5 this run) | 69 | 62 | Contentstack +7 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 60 | WordPress +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 82 | 83 | WordPress +1 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 73 | 68 | Contentstack +5 |\n| Negative events | ≤15 | -3 | -5 | |\n| **Total** | | **64 · B** | **64.8 · B** | |\n\n## Facts side by side\n\n| Fact | Contentstack | WordPress |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Contentstack Inc. | WordPress.org (open-source project) |\n| Hosted endpoint | `https://api.contentstack.io` | no (local only) |\n| Transports | HTTP, stdio | HTTP, stdio |\n| Auth | OAuth or key | API key |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT | GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too |\n| Tools exposed | 206 | none |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-22 | 2026-10-06 |\n| Terms last updated | 2022-08-01 | no document linked |\n| Privacy policy last updated | 2026-06-30 | no date given |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | not found in the text |  |\n| Terms restrict benchmarking | yes |  |\n| Terms or service can change without notice | not found in the text |  |\n| Arbitration or class-action waiver | yes |  |\n| Popularity | 44k npm/wk, 1.5k PyPI/wk | 21k stars |\n\n## Verdicts\n\n**Contentstack.** The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.\n\n**WordPress.** The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026.\n\n## Before you call either\n\n### Contentstack\n\n1. Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts\n2. Send `api_key` and `authorization` headers on every Content Management API call. Ask for a read-only management token when the task only reads\n3. Page with `limit` (100 at most), `skip` and `include_count=true`. `limit=0` no longer returns everything\n4. Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch `X-RateLimit-Remaining` and back off on 429\n5. Start the MCP server with `--groups cma` only, and add `cma-extended` when the task needs audit logs or version history. Publishing and deleting need no confirmation\n\n### WordPress\n\n1. Ask the owner for a dedicated user with the lowest role that fits. A Contributor can draft and edit its own posts but can't publish them\n2. Send the Application Password as Basic auth over HTTPS only. Core disables Application Passwords on plain HTTP outside a local environment\n3. Upload a file with POST `/wp-json/wp/v2/media` first, then set `featured_media` or reference the returned URL in the post content\n4. To roll back, GET `/wp/v2/posts/\u003cid\u003e/revisions/\u003crev\u003e?context=edit` and POST its title and content to the post. There's no restore route\n5. Pass `_fields=id,status,link,modified` on lists and read X-WP-TotalPages. `per_page` stops at 100\n\n## Questions\n\n### Which is better for AI agents, Contentstack or WordPress?\n\nWordPress and Contentstack score within a point of each other on agent readiness, 64.8 (B) and 64 (B). Contentstack leads on schema \u0026 documentation, security \u0026 auth and transparency \u0026 trust.\n\n### Do Contentstack and WordPress need an API key?\n\nContentstack takes an API key or an OAuth sign-in. WordPress needs an API key.\n\n### Can an agent call Contentstack and WordPress without installing anything?\n\nContentstack has a hosted endpoint at https://api.contentstack.io. WordPress runs on your own machine, with no hosted endpoint listed.\n\n### Are Contentstack and WordPress open source?\n\nNo open-source release is listed for Contentstack. WordPress is open source (GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/contentstack-vs-wordpress.json, and with the fewest tokens: https://www.anchorterminal.com/compare/contentstack-vs-wordpress.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"contentstack\", \"b\": \"wordpress\"}`. From a terminal: `anchor compare contentstack wordpress`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/contentstack.json and https://www.anchorterminal.com/api/v1/tools/wordpress.json\n\n## Other comparisons with Contentstack or WordPress\n\n- [Contentstack vs Ghost](https://www.anchorterminal.com/compare/contentstack-vs-ghost.md)\n- [Contentstack vs Sanity](https://www.anchorterminal.com/compare/contentstack-vs-sanity.md)\n- [Contentstack vs Storyblok](https://www.anchorterminal.com/compare/contentstack-vs-storyblok.md)\n- [Contentstack vs Strapi](https://www.anchorterminal.com/compare/contentstack-vs-strapi.md)\n- [Contentstack vs Webflow](https://www.anchorterminal.com/compare/contentstack-vs-webflow.md)\n- [Ghost vs WordPress](https://www.anchorterminal.com/compare/ghost-vs-wordpress.md)\n- [Sanity vs WordPress](https://www.anchorterminal.com/compare/sanity-vs-wordpress.md)\n- [Storyblok vs WordPress](https://www.anchorterminal.com/compare/storyblok-vs-wordpress.md)\n- [Strapi vs WordPress](https://www.anchorterminal.com/compare/strapi-vs-wordpress.md)\n- [Webflow vs WordPress](https://www.anchorterminal.com/compare/webflow-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Contentstack vs WordPress",
        "url": ""
      }
    ],
    "description": "WordPress and Contentstack score within a point of each other on agent readiness, 64.8 (B) and 64 (B). Contentstack leads on schema \u0026 documentation, security \u0026 auth and transparency \u0026 trust. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Contentstack B 64",
      "WordPress B 64.8",
      "scores"
    ],
    "h1": "Contentstack vs WordPress",
    "image": "https://www.anchorterminal.com/assets/og/compare-contentstack-vs-wordpress.png",
    "path": "/compare/contentstack-vs-wordpress",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Contentstack vs WordPress for AI agents, B 64 vs B 64.8",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress"
  },
  "tokens": {
    "markdown": 2200,
    "slim": 780
  },
  "version": 1
}
