{
  "data": {
    "a": {
      "slug": "ghost",
      "name": "Ghost",
      "vendor": "Ghost Foundation",
      "vendorUrl": "https://ghost.org",
      "kind": "http-api",
      "category": "cms",
      "summary": "Ghost is an open-source publishing platform for websites, newsletters and paid memberships, self-hosted or run by the Ghost Foundation as Ghost(Pro). Agents create, edit and publish posts and pages and upload images through its Admin API.",
      "url": "https://www.anchorterminal.com/tools/ghost",
      "markdownUrl": "https://www.anchorterminal.com/tools/ghost.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/ghost.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ghost.json",
      "repo": "https://github.com/TryGhost/Ghost",
      "license": "MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "ghost"
        },
        {
          "registry": "npm",
          "name": "@tryghost/admin-api"
        },
        {
          "registry": "npm",
          "name": "ghost-cli"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve, with no app review or partner approval. An owner or administrator creates a custom integration in Ghost Admin and copies its Admin API key, an id and a hex secret joined by a colon. The client signs an HS256 JSON Web Token with the secret (`kid` the id, `aud` `/admin/`, expiry at most 5 minutes) and sends it as `Authorization: Ghost \u003ctoken\u003e`. Integrations hold one fixed permission set with no scopes. A staff access token from a user's profile works the same way and carries that user's role. Session login with email and password is meant for clients where the user is present. On Ghost(Pro) the Admin API and custom integrations need the Publisher plan or above.",
      "pricing": "freemium",
      "pricingNotes": "The software is free under MIT to self-host, so an agent's owner can start without a contract or a card. Ghost(Pro) lists Starter at $18, Publisher at $29 and Business at $199 a month billed yearly for up to 1,000 members, rising with audience size, and Custom through sales. The Admin API isn't included in Starter. Plans show a free trial, and we couldn't read whether it needs a card (checked 2026-10-08).",
      "priceSummary": "$18 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the documentation index, the pricing page or the repository's file list (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 55500,
        "npmWeekly": 23628,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.ghost.org/admin-api",
      "llmsTxt": "https://docs.ghost.org/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "hosted",
        "rest",
        "llms-txt",
        "webhooks",
        "newsletter",
        "memberships",
        "nodejs",
        "status-page"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 58.3,
        "grade": "C",
        "agentReady": false,
        "rank": 404,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 85,
          "payments": 50,
          "reliability": 80,
          "schema": 51,
          "security": 56,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -7,
        "negativeNotes": [
          "3 September to 1 October 2026. Ghost published 20 security advisories in five weeks, one critical, ten high, eight moderate and one low. They include GHSA-q734-xjgc-vpj9 (critical, suspended staff could reactivate accounts through password reset), GHSA-788w-68h3-cvxp (high, CVSS 8.8, remote code execution through bookmark card images in 6.56.0 to 6.65.0, fixed in 6.67.0) and GHSA-jj74-hc2q-xrvm (high, remote code execution through theme translation files). Several could be triggered by any staff user, Contributors included. All were published by the vendor with a fixed version, and we found no report of exploitation in the advisories we read, so we deduct 7 of a possible 15. https://github.com/TryGhost/Ghost/security/advisories ; https://github.com/TryGhost/Ghost/security/advisories/GHSA-788w-68h3-cvxp"
        ],
        "verdict": "A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.",
        "bestFor": "A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.",
        "strengths": [
          "Admin API keys sign JSON Web Tokens that last at most 5 minutes and travel in the Authorization header, so the key itself is never sent",
          "A staff access token carries its user's role, and a Contributor can add and edit drafts but can't change a post's status",
          "Every PUT must send the post's current `updated_at`, which Ghost uses for collision detection",
          "19 versions reached npm between 10 July and 8 October 2026, with 6.69.0 on 7 October",
          "MIT licence, with llms.txt, llms-full.txt and a Markdown copy of every docs page"
        ],
        "weaknesses": [
          "No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository",
          "A custom integration has one fixed permission set covering posts, members, settings, themes and users, with no scopes and no read-only Admin key",
          "20 advisories were published from 3 September to 1 October 2026, one critical and ten high, including remote code execution through bookmark card images",
          "No content locales or custom content types, and the Admin API has no documented route for restoring a post revision",
          "On Ghost(Pro) the Admin API and custom integrations start at the Publisher plan, not Starter"
        ],
        "agentNotes": [
          "Sign a fresh HS256 token for each batch of calls. Decode the hex secret to bytes, set `kid` to the key id, `aud` to `/admin/` and `exp` at most 5 minutes ahead",
          "Set `status` to `draft` on every create unless told to publish, and publish later with a PUT that sets `status` to `published`",
          "GET the post before each PUT and send its `updated_at` back. Tags and authors in a PUT replace the existing lists",
          "Send content as a Lexical JSON string, or add `?source=html` and send `html`. The HTML conversion is lossy unless wrapped in an HTML card",
          "Page through lists with `limit` up to 100 and `page`. Since Ghost 6.0 `limit=all` returns 100 items without an error"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 58.3
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 85,
          "payments": 50,
          "reliability": 80,
          "schema": 51,
          "security": 56,
          "transparency": 76
        },
        "provenanceScore": 68
      },
      "connect": {
        "install": "npm install @tryghost/admin-api",
        "http": "curl -H \"Authorization: Ghost $token\" -H \"Accept-Version: $version\" https://{admin_domain}/ghost/api/admin/{resource}/"
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/ghost"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Self-hosted Ghost",
          "unit": "month",
          "usd": 0,
          "note": "MIT, you pay for your own hosting and email delivery"
        },
        {
          "item": "Ghost(Pro) Starter",
          "unit": "month",
          "usd": 18,
          "note": "billed yearly, up to 1,000 members, no Admin API"
        },
        {
          "item": "Ghost(Pro) Publisher",
          "unit": "month",
          "usd": 29,
          "note": "billed yearly, up to 1,000 members, 3 staff users, Admin API included"
        },
        {
          "item": "Ghost(Pro) Business",
          "unit": "month",
          "usd": 199,
          "note": "billed yearly, up to 1,000 members, 15 staff users"
        }
      ],
      "provenance": {
        "legalEntity": "Ghost Foundation Ltd",
        "domain": "ghost.org",
        "domainRegistered": "2005-06-25",
        "endpointOnVendorDomain": false,
        "terms": "https://ghost.org/terms/",
        "privacy": "https://ghost.org/privacy/",
        "statusPage": "https://ghoststatus.org",
        "changelog": "https://github.com/TryGhost/Ghost/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms govern the Ghost.org website, the Ghost software and the hosted service, and name the Ghost Foundation as owner and operator under the law of England and Wales. The privacy policy names Ghost Foundation Ltd. Neither page showed a dated revision that we could read.",
          "The privacy policy covers Ghost Foundation's own website and services. Content on a self-hosted site stays on its owner's server and isn't covered by it.",
          "A self-hosted install answers on its owner's domain. Ghost(Pro) sites use a `*.ghost.io` admin domain.",
          "https://ghost.org/.well-known/security.txt returned 404 on 8 October 2026. SECURITY.md in the repository and https://docs.ghost.org/security give security@ghost.org and a disclosure policy.",
          "RDAP for ghost.org gives a registration date of 2005-06-25 and a transfer on 2013-09-12.",
          "status.ghost.org redirects to ghoststatus.org, an incident.io page for Ghost(Pro), not for self-hosted installs. It listed three minor incidents between 10 July and 8 October 2026."
        ],
        "score": 68
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/ghost.json",
      "live": {
        "slug": "ghost",
        "vendorStatus": {
          "page": "https://ghoststatus.org",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:06:40.232515614Z"
        },
        "pages": [
          {
            "url": "https://ghost.org/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:20:39.9398284Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6de86a225cdd"
          },
          {
            "url": "https://ghost.org/terms/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:20:42.180060747Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "673039b71aa4"
          }
        ],
        "updatedAt": "2026-10-08T19:06:40.232515614Z"
      }
    },
    "answer": "WordPress scores 64.8 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories.",
    "b": {
      "slug": "wordpress",
      "name": "WordPress",
      "vendor": "WordPress.org (open-source project)",
      "vendorUrl": "https://wordpress.org",
      "kind": "http-api",
      "category": "cms",
      "summary": "WordPress is an open-source content management system that its owner hosts. Agents create, revise and publish posts, pages and media through the built-in REST API, WP-CLI or the official MCP Adapter plugin.",
      "url": "https://www.anchorterminal.com/tools/wordpress",
      "markdownUrl": "https://www.anchorterminal.com/tools/wordpress.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/wordpress.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/wordpress.json",
      "repo": "https://github.com/WordPress/wordpress-develop",
      "license": "GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too",
      "transports": [
        "http",
        "stdio"
      ],
      "packages": [],
      "auth": "api-key",
      "authNotes": "Self-serve on your own site, with no app review or approval by WordPress.org. A user creates an Application Password on their profile, through `/wp/v2/users/\u003cid\u003e/application-passwords` or with `wp user application-password create`, and the agent sends it as Basic auth over HTTPS. A password has no scopes or expiry and carries every capability of its user, so access is set by the user's role. Each password can be revoked on its own. The MCP Adapter's HTTP transport takes the same credential, and its STDIO transport runs as the user named in `--user`.",
      "pricing": "free",
      "pricingNotes": "Free software with nothing to buy from WordPress.org, so an agent can start without a contract or a card. The owner pays for their own hosting. WordPress.com and other hosts sell hosted WordPress under their own prices, which aren't graded here (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the REST API handbook, wordpress.org/llms.txt or the core and MCP Adapter repositories (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 21460,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.wordpress.org/rest-api/",
      "llmsTxt": "https://wordpress.org/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "rest",
        "mcp",
        "cli",
        "php",
        "llms-txt",
        "security-txt",
        "bug-bounty"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.8,
        "grade": "B",
        "agentReady": false,
        "rank": 249,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 83,
          "payments": 60,
          "reliability": 78,
          "schema": 65,
          "security": 62,
          "transparency": 68
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -5,
        "negativeNotes": [
          "22 September 2026. WordPress 7.1.2 fixed a critical flaw, CVE-2026-87902 (GHSA-7hp8-65ch-5whp), in which an unauthenticated attacker could, where server and theme conditions were met, make template resolution include a local PHP file and reach remote code execution. 7.1.1 on 17 September and 7.1.3 on 6 October fixed 18 further security issues. All were published by the project with the fix and backported, and we found no report of exploitation in the release posts, so we deduct 5 of a possible 15. https://wordpress.org/news/2026/09/wordpress-7-1-2-release/ ; https://wordpress.org/news/2026/10/wordpress-7-1-3-maintenance-and-security-release/"
        ],
        "verdict": "The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026.",
        "bestFor": "Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.",
        "strengths": [
          "Posts created without `status` are saved as drafts, and DELETE moves a post to the Trash unless `force=true` is passed",
          "Every REST or WP-CLI update to a post writes a revision that `/wp/v2/posts/\u003cid\u003e/revisions` lists with author and date",
          "`_fields` trims responses down to nested properties, with `per_page` up to 100 and X-WP-Total headers on every list",
          "Six stable releases between 6 August and 6 October 2026, and security fixes backported to 4.7",
          "GPL-2.0-or-later, free to self-host, with a valid security.txt and a HackerOne programme for core"
        ],
        "weaknesses": [
          "Application Passwords have no scopes or expiry. Each one carries every capability of its user",
          "The revisions route supports GET and DELETE only, so a rollback means writing the old content back as a new update",
          "Core has no rate limit, no idempotency keys and no log of API calls beyond revisions and a password's last use",
          "A critical flaw (CVE-2026-87902) fixed in 7.1.2 on 22 September 2026 allowed remote code execution under certain server and theme conditions",
          "No published OpenAPI file. Each site describes its own routes at `/wp-json`, and core has no content localisation"
        ],
        "agentNotes": [
          "Ask the owner for a dedicated user with the lowest role that fits. A Contributor can draft and edit its own posts but can't publish them",
          "Send the Application Password as Basic auth over HTTPS only. Core disables Application Passwords on plain HTTP outside a local environment",
          "Upload a file with POST `/wp-json/wp/v2/media` first, then set `featured_media` or reference the returned URL in the post content",
          "To roll back, GET `/wp/v2/posts/\u003cid\u003e/revisions/\u003crev\u003e?context=edit` and POST its title and content to the post. There's no restore route",
          "Pass `_fields=id,status,link,modified` on lists and read X-WP-TotalPages. `per_page` stops at 100"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.8
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 83,
          "payments": 60,
          "reliability": 78,
          "schema": 65,
          "security": 62,
          "transparency": 72
        },
        "provenanceScore": 63
      },
      "connect": {
        "install": "wp core download \u0026\u0026 wp core install --url=\u003curl\u003e --title=\u003ctitle\u003e --admin_user=\u003cuser\u003e --admin_email=\u003cemail\u003e",
        "http": "curl --user \"USERNAME:PASSWORD\" https://HOSTNAME/wp-json/wp/v2/users?context=edit",
        "config": {
          "mcpServers": {
            "wordpress": {
              "args": [
                "--path=/path/to/your/wordpress/site",
                "mcp-adapter",
                "serve",
                "--server=mcp-adapter-default-server",
                "--user=admin"
              ],
              "command": "wp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/wordpress"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "WordPress, self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "GPL, you pay for your own hosting"
        }
      ],
      "provenance": {
        "legalEntity": "WordPress.org, an open-source project. The WordPress trademark belongs to the WordPress Foundation",
        "domain": "wordpress.org",
        "domainRegistered": "2003-03-28",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "https://wordpress.org/about/privacy/",
        "statusPage": "",
        "changelog": "https://wordpress.org/news/category/releases/",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "No terms of service govern the software. It is licensed under GPL version 2 or later, and no service agreement or API terms were found, so `terms` is left out.",
          "The privacy policy covers the WordPress.org websites and names api.wordpress.org, the service installations call to check for updates. It names no company, and gives dpo@wordpress.org as the contact. It doesn't cover content held on a self-hosted site.",
          "The REST API answers on each owner's own domain.",
          "https://wordpress.org/.well-known/security.txt returned 200 with Contact https://hackerone.com/wordpress and Expires 2027-06-30.",
          "RDAP for wordpress.org gives a registration date of 2003-03-28.",
          "The make.wordpress.org footer says the WordPress trademark is the intellectual property of the WordPress Foundation. `license.txt` gives copyright to the contributors.",
          "No status page applies to self-hosted software."
        ],
        "score": 63
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/wordpress.json",
      "live": {
        "slug": "wordpress",
        "pages": [
          {
            "url": "https://wordpress.org/news/category/releases/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:52.505193763Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cbd71d93d029"
          },
          {
            "url": "https://wordpress.org/about/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:50.079319583Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "61575a1b129f"
          }
        ],
        "updatedAt": "2026-10-08T18:25:52.505193763Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Ghost Foundation",
        "b": "WordPress.org (open-source project)",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, stdio",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms",
        "b": "GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-07",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "56k stars, 24k npm/wk",
        "b": "21k stars",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "WordPress scores 64.8 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories.",
        "question": "Which is better for AI agents, Ghost or WordPress?"
      },
      {
        "answer": "Both need an API key.",
        "question": "Do Ghost and WordPress need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Ghost. WordPress runs on your own machine, with no hosted endpoint listed.",
        "question": "Can an agent call Ghost and WordPress without installing anything?"
      },
      {
        "answer": "Yes. Ghost is open source (MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms). WordPress is open source (GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too).",
        "question": "Are Ghost and WordPress open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": null,
        "goodFor": "A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.",
        "slug": "ghost",
        "watchFor": "No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 65 against 51",
          "Agent ergonomics, 74 against 69",
          "Security \u0026 auth, 62 against 56",
          "Payments \u0026 pricing, 60 against 50"
        ],
        "also": [
          "Runs on your own machine"
        ],
        "goodFor": "Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.",
        "slug": "wordpress",
        "watchFor": "Application Passwords have no scopes or expiry. Each one carries every capability of its user"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-ghost.json",
        "title": "Contentstack vs Ghost",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress.json",
        "title": "Contentstack vs WordPress",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-sanity.json",
        "title": "Ghost vs Sanity",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-storyblok.json",
        "title": "Ghost vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-strapi.json",
        "title": "Ghost vs Strapi",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-webflow.json",
        "title": "Ghost vs Webflow",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sanity-vs-wordpress.json",
        "title": "Sanity vs WordPress",
        "url": "https://www.anchorterminal.com/compare/sanity-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/storyblok-vs-wordpress.json",
        "title": "Storyblok vs WordPress",
        "url": "https://www.anchorterminal.com/compare/storyblok-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/strapi-vs-wordpress.json",
        "title": "Strapi vs WordPress",
        "url": "https://www.anchorterminal.com/compare/strapi-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/webflow-vs-wordpress.json",
        "title": "Webflow vs WordPress",
        "url": "https://www.anchorterminal.com/compare/webflow-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 2,
        "edge": "ghost",
        "ghost": 80,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16,
        "wordpress": 78
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 14,
        "edge": "wordpress",
        "ghost": 51,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13,
        "wordpress": 65
      },
      {
        "by": 5,
        "edge": "wordpress",
        "ghost": 69,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13,
        "wordpress": 74
      },
      {
        "by": 6,
        "edge": "wordpress",
        "ghost": 56,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14,
        "wordpress": 62
      },
      {
        "by": 10,
        "edge": "wordpress",
        "ghost": 50,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10,
        "wordpress": 60
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "edge": "ghost",
        "ghost": 85,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7,
        "wordpress": 83
      },
      {
        "by": 4,
        "edge": "ghost",
        "ghost": 72,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7,
        "wordpress": 68
      }
    ],
    "summary": "WordPress scores 64.8 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Both do cms content.",
    "verdicts": {
      "ghost": "A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.",
      "wordpress": "The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/ghost-vs-wordpress",
    "json": "https://www.anchorterminal.com/compare/ghost-vs-wordpress.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/ghost-vs-wordpress.md",
    "slim": "https://www.anchorterminal.com/compare/ghost-vs-wordpress.min.md"
  },
  "markdown": "WordPress scores 64.8 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Both do cms content.\n\n- Ghost: grade C, 58.3/100, rank #404 of 629. Markdown https://www.anchorterminal.com/tools/ghost.md · JSON https://www.anchorterminal.com/api/v1/tools/ghost.json\n- WordPress: grade B, 64.8/100, rank #249 of 629. Markdown https://www.anchorterminal.com/tools/wordpress.md · JSON https://www.anchorterminal.com/api/v1/tools/wordpress.json\n\n## Which one, for what\n\n### Ghost (C)\n\nGood for: A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.\n\nWatch for: No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository\n\n### WordPress (B)\n\nGood for: Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.\n\nAhead on:\n- Schema \u0026 documentation, 65 against 51\n- Agent ergonomics, 74 against 69\n- Security \u0026 auth, 62 against 56\n- Payments \u0026 pricing, 60 against 50\n\nAlso in its favour:\n- Runs on your own machine\n\nWatch for: Application Passwords have no scopes or expiry. Each one carries every capability of its user\n\n\n## Score by category\n\n| Category | Weight | Ghost | WordPress | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 80 | 78 | Ghost +2 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 51 | 65 | WordPress +14 |\n| Agent ergonomics | 13% (16.2 this run) | 69 | 74 | WordPress +5 |\n| Security \u0026 auth | 14% (17.5 this run) | 56 | 62 | WordPress +6 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 50 | 60 | WordPress +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 85 | 83 | Ghost +2 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 72 | 68 | Ghost +4 |\n| Negative events | ≤15 | -7 | -5 | |\n| **Total** | | **58.3 · C** | **64.8 · B** | |\n\n## Facts side by side\n\n| Fact | Ghost | WordPress |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Ghost Foundation | WordPress.org (open-source project) |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP | HTTP, stdio |\n| Auth | API key | API key |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms | GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-07 | 2026-10-06 |\n| Terms last updated | no date given | no document linked |\n| Privacy policy last updated | no date given | no date given |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | yes |  |\n| Terms restrict benchmarking | not found in the text |  |\n| Terms or service can change without notice | not found in the text |  |\n| Arbitration or class-action waiver | not found in the text |  |\n| Popularity | 56k stars, 24k npm/wk | 21k stars |\n\n## Verdicts\n\n**Ghost.** A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.\n\n**WordPress.** The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026.\n\n## Before you call either\n\n### Ghost\n\n1. Sign a fresh HS256 token for each batch of calls. Decode the hex secret to bytes, set `kid` to the key id, `aud` to `/admin/` and `exp` at most 5 minutes ahead\n2. Set `status` to `draft` on every create unless told to publish, and publish later with a PUT that sets `status` to `published`\n3. GET the post before each PUT and send its `updated_at` back. Tags and authors in a PUT replace the existing lists\n4. Send content as a Lexical JSON string, or add `?source=html` and send `html`. The HTML conversion is lossy unless wrapped in an HTML card\n5. Page through lists with `limit` up to 100 and `page`. Since Ghost 6.0 `limit=all` returns 100 items without an error\n\n### WordPress\n\n1. Ask the owner for a dedicated user with the lowest role that fits. A Contributor can draft and edit its own posts but can't publish them\n2. Send the Application Password as Basic auth over HTTPS only. Core disables Application Passwords on plain HTTP outside a local environment\n3. Upload a file with POST `/wp-json/wp/v2/media` first, then set `featured_media` or reference the returned URL in the post content\n4. To roll back, GET `/wp/v2/posts/\u003cid\u003e/revisions/\u003crev\u003e?context=edit` and POST its title and content to the post. There's no restore route\n5. Pass `_fields=id,status,link,modified` on lists and read X-WP-TotalPages. `per_page` stops at 100\n\n## Questions\n\n### Which is better for AI agents, Ghost or WordPress?\n\nWordPress scores 64.8 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories.\n\n### Do Ghost and WordPress need an API key?\n\nBoth need an API key.\n\n### Can an agent call Ghost and WordPress without installing anything?\n\nNo hosted endpoint is listed for Ghost. WordPress runs on your own machine, with no hosted endpoint listed.\n\n### Are Ghost and WordPress open source?\n\nYes. Ghost is open source (MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms). WordPress is open source (GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/ghost-vs-wordpress.json, and with the fewest tokens: https://www.anchorterminal.com/compare/ghost-vs-wordpress.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"ghost\", \"b\": \"wordpress\"}`. From a terminal: `anchor compare ghost wordpress`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/ghost.json and https://www.anchorterminal.com/api/v1/tools/wordpress.json\n\n## Other comparisons with Ghost or WordPress\n\n- [Contentstack vs Ghost](https://www.anchorterminal.com/compare/contentstack-vs-ghost.md)\n- [Contentstack vs WordPress](https://www.anchorterminal.com/compare/contentstack-vs-wordpress.md)\n- [Ghost vs Sanity](https://www.anchorterminal.com/compare/ghost-vs-sanity.md)\n- [Ghost vs Storyblok](https://www.anchorterminal.com/compare/ghost-vs-storyblok.md)\n- [Ghost vs Strapi](https://www.anchorterminal.com/compare/ghost-vs-strapi.md)\n- [Ghost vs Webflow](https://www.anchorterminal.com/compare/ghost-vs-webflow.md)\n- [Sanity vs WordPress](https://www.anchorterminal.com/compare/sanity-vs-wordpress.md)\n- [Storyblok vs WordPress](https://www.anchorterminal.com/compare/storyblok-vs-wordpress.md)\n- [Strapi vs WordPress](https://www.anchorterminal.com/compare/strapi-vs-wordpress.md)\n- [Webflow vs WordPress](https://www.anchorterminal.com/compare/webflow-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Ghost vs WordPress",
        "url": ""
      }
    ],
    "description": "WordPress scores 64.8 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Ghost C 58.3",
      "WordPress B 64.8",
      "scores"
    ],
    "h1": "Ghost vs WordPress",
    "image": "https://www.anchorterminal.com/assets/og/compare-ghost-vs-wordpress.png",
    "path": "/compare/ghost-vs-wordpress",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Ghost vs WordPress for AI agents, C 58.3 vs B 64.8 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/ghost-vs-wordpress"
  },
  "tokens": {
    "markdown": 2000,
    "slim": 630
  },
  "version": 1
}
