Head to head · Cms content · October 2026 research run

Ghost vs WordPress

WordPress scores 64.8 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Both do cms content.

Which one, for what

Ghost C

Good for A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository

WordPress B

Good for Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.

Ahead on

  • Schema & documentation, 65 against 51
  • Agent ergonomics, 74 against 69
  • Security & auth, 62 against 56
  • Payments & pricing, 60 against 50

Also in its favour

  • Runs on your own machine

Watch for

Application Passwords have no scopes or expiry. Each one carries every capability of its user

Score by category

CategoryWeight this runGhostWordPressEdge
Reliability16%208078Ghost +2
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.25165WordPress +14
Agent ergonomics13%16.26974WordPress +5
Security & auth14%17.55662WordPress +6
Payments & pricing10%12.55060WordPress +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88583Ghost +2
Transparency & trust7%8.87268Ghost +4
Negative events≤15-7-5
Total58.3 · C64.8 · B

Facts side by side

FactGhostWordPress
KindHTTP APIHTTP API
VendorGhost FoundationWordPress.org (open-source project)
Hosted endpointno (local only)no (local only)
TransportsHTTPHTTP, stdio
AuthAPI keyAPI key
PricingFreemiumFree
x402nono
LicenceMIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's termsGPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-072026-10-06
Terms last updatedno date givenno document linked
Privacy policy last updatedno date givenno date given
Customer content may train modelsnot found in the text
Terms restrict automated accessyes
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity56k stars, 24k npm/wk21k stars

Verdicts

Ghost

A create needs only a title, updates are checked against updated_at so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.

WordPress

The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026.

Before you call either

Ghost

  1. Sign a fresh HS256 token for each batch of calls. Decode the hex secret to bytes, set kid to the key id, aud to /admin/ and exp at most 5 minutes ahead
  2. Set status to draft on every create unless told to publish, and publish later with a PUT that sets status to published
  3. GET the post before each PUT and send its updated_at back. Tags and authors in a PUT replace the existing lists
  4. Send content as a Lexical JSON string, or add ?source=html and send html. The HTML conversion is lossy unless wrapped in an HTML card
  5. Page through lists with limit up to 100 and page. Since Ghost 6.0 limit=all returns 100 items without an error

WordPress

  1. Ask the owner for a dedicated user with the lowest role that fits. A Contributor can draft and edit its own posts but can't publish them
  2. Send the Application Password as Basic auth over HTTPS only. Core disables Application Passwords on plain HTTP outside a local environment
  3. Upload a file with POST /wp-json/wp/v2/media first, then set featured_media or reference the returned URL in the post content
  4. To roll back, GET /wp/v2/posts/<id>/revisions/<rev>?context=edit and POST its title and content to the post. There's no restore route
  5. Pass _fields=id,status,link,modified on lists and read X-WP-TotalPages. per_page stops at 100

Questions

Which is better for AI agents, Ghost or WordPress?

WordPress scores 64.8 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories.

Do Ghost and WordPress need an API key?

Both need an API key.

Can an agent call Ghost and WordPress without installing anything?

No hosted endpoint is listed for Ghost. WordPress runs on your own machine, with no hosted endpoint listed.

Are Ghost and WordPress open source?

Yes. Ghost is open source (MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms). WordPress is open source (GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too).

Other comparisons with Ghost or WordPress

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.