{
  "data": {
    "a": {
      "slug": "payload",
      "name": "Payload",
      "vendor": "Payload CMS, Inc. (Figma)",
      "vendorUrl": "https://payloadcms.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Payload is an open-source, code-first headless CMS and application framework for Node.js and Next.js, now part of Figma. Agents manage content, drafts, versions and locales through generated REST and GraphQL APIs or an official MCP plugin.",
      "url": "https://www.anchorterminal.com/tools/payload",
      "markdownUrl": "https://www.anchorterminal.com/tools/payload.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/payload.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/payload.json",
      "repo": "https://github.com/payloadcms/payload",
      "license": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "payload"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/plugin-mcp"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve keys on your own instance, with no app review or partner approval. REST and GraphQL take a per-user API key sent as `Authorization: {collection-slug} API-Key {key}` once `auth.useAPIKey` is set on an auth collection. The key signs requests in as that user under the collection's access control, doesn't expire, is shown once, and can be regenerated or revoked by an admin. The MCP plugin has its own keys, created in the admin panel under MCP API Keys with find, create, update and delete switches per collection, sent as `Authorization: Bearer {key}`. Changing `PAYLOAD_SECRET` invalidates every key.",
      "pricing": "free",
      "pricingNotes": "Free to self-host under the MIT licence, with no account at Payload and no card, so an agent can start without a contract. Enterprise (SSO, publishing workflows, visual editor, dedicated support) is sold through sales with no public price. Payload Cloud has paused deployment of new projects since Payload joined Figma (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the 3.x documentation, the get-started page or the MCP plugin source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 45151,
        "npmWeekly": 1108564,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://payloadcms.com/docs",
      "llmsTxt": "https://payloadcms.com/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.localisation",
        "cms.assets",
        "cms.schema"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "mcp",
        "llms-txt",
        "graphql",
        "rest",
        "typescript",
        "nextjs"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.2,
        "grade": "C",
        "agentReady": false,
        "rank": 516,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -10,
        "negativeNotes": [
          "18 September to 8 October 2026. Payload published 38 security advisories in three weeks, 49 in the 12 months to 8 October 2026 (8 critical, 23 high, 18 medium). They include remote code execution through the first-register operation (GHSA-97rh-rhh2-7vjv), SQL injection on Postgres and SQLite (GHSA-v49j-62m6-pgrr), unauthorised document updates on orderable collections (GHSA-f7hx-52q9-hcrf) and four in `@payloadcms/plugin-mcp`, one an account takeover through the experimental password recovery tool (GHSA-h5rh-4jwf-738p). All are fixed in 3.90.0 or earlier, each was published by the vendor with affected versions and a workaround, and we found no report of exploitation, so we deduct 10 of a possible 15. https://github.com/payloadcms/payload/security/advisories"
        ],
        "verdict": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.",
        "bestFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "strengths": [
          "MIT core with drafts, version history and restore through `POST /api/{collection-slug}/versions/:id`, none of it behind a paid plan",
          "MCP API keys carry find, create, update and delete switches per collection, and the key's user still passes through the collection's access control",
          "New documents default to `_status: 'draft'`, so nothing is published unless the request sets `_status: 'published'`",
          "MCP find tools default to 10 documents and depth 0, cap at 100, and take `select` to return named fields only",
          "llms.txt per major version, llms-full.txt and a Markdown copy of every docs page"
        ],
        "weaknesses": [
          "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026",
          "No OpenAPI file is published or generated by the core packages, and REST error responses have no reference page",
          "REST and MCP API keys don't expire, and rate limiting is left to the owner's own hooks or proxy",
          "No idempotency keys, and the MCP tools set no `readOnlyHint` or `destructiveHint` annotations",
          "Payload Cloud is closed to new projects, Enterprise is priced by sales, and no status page or security.txt was found"
        ],
        "agentNotes": [
          "Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing",
          "Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate",
          "To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written",
          "Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented",
          "Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.2
          }
        ],
        "editorialScores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 74
        },
        "provenanceScore": 50
      },
      "connect": {
        "install": "npx create-payload-app",
        "http": "curl 'http://localhost:3000/api/pages' \\\n  -H \"Authorization: users API-Key $PAYLOAD_API_KEY\"",
        "claudeCode": "claude mcp add --transport http Payload http://127.0.0.1:3000/api/mcp \\\n  --header \"Authorization: Bearer MCP-USER-API-KEY\"",
        "config": {
          "mcpServers": {
            "Payload": {
              "headers": {
                "Authorization": "Bearer MCP-USER-API-KEY"
              },
              "type": "http",
              "url": "http://localhost:3000/api/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/payload"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Self-hosted Payload",
          "unit": "month",
          "usd": 0,
          "note": "MIT, you pay for your own hosting and database"
        }
      ],
      "provenance": {
        "legalEntity": "Payload CMS, Inc.",
        "domain": "payloadcms.com",
        "domainRegistered": "2018-04-02",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "https://payloadcms.com/privacy",
        "statusPage": "",
        "changelog": "https://github.com/payloadcms/payload/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "No `terms` is recorded. The only terms on payloadcms.com are the Payload Cloud terms at https://payloadcms.com/cloud-terms, which govern a hosted service closed to new projects. The software an agent uses is under the MIT licence in LICENSE.md.",
          "The privacy policy (effective 28 March 2024) names Payload CMS, Inc. as controller. The Cloud terms call it a Delaware corporation with an address at 624 Stocking Ave. NW, Grand Rapids, Michigan 49504. LICENSE.md names Payload CMS, LLC.",
          "The site says Payload has joined Figma. The privacy policy and the Cloud terms don't mention Figma.",
          "A self-hosted install answers on its owner's domain.",
          "https://payloadcms.com/.well-known/security.txt and https://payloadcms.com/security.txt returned 404 on 8 October 2026. SECURITY.md gives security@payloadcms.com.",
          "No status page is linked from the site footer, the security page or the get-started page, and status.payloadcms.com didn't resolve.",
          "RDAP for payloadcms.com gives a registration date of 2018-04-02."
        ],
        "score": 50
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/payload.json"
    },
    "answer": "WordPress scores 64.8 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on schema \u0026 documentation.",
    "b": {
      "slug": "wordpress",
      "name": "WordPress",
      "vendor": "WordPress.org (open-source project)",
      "vendorUrl": "https://wordpress.org",
      "kind": "http-api",
      "category": "cms",
      "summary": "WordPress is an open-source content management system that its owner hosts. Agents create, revise and publish posts, pages and media through the built-in REST API, WP-CLI or the official MCP Adapter plugin.",
      "url": "https://www.anchorterminal.com/tools/wordpress",
      "markdownUrl": "https://www.anchorterminal.com/tools/wordpress.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/wordpress.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/wordpress.json",
      "repo": "https://github.com/WordPress/wordpress-develop",
      "license": "GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too",
      "transports": [
        "http",
        "stdio"
      ],
      "packages": [],
      "auth": "api-key",
      "authNotes": "Self-serve on your own site, with no app review or approval by WordPress.org. A user creates an Application Password on their profile, through `/wp/v2/users/\u003cid\u003e/application-passwords` or with `wp user application-password create`, and the agent sends it as Basic auth over HTTPS. A password has no scopes or expiry and carries every capability of its user, so access is set by the user's role. Each password can be revoked on its own. The MCP Adapter's HTTP transport takes the same credential, and its STDIO transport runs as the user named in `--user`.",
      "pricing": "free",
      "pricingNotes": "Free software with nothing to buy from WordPress.org, so an agent can start without a contract or a card. The owner pays for their own hosting. WordPress.com and other hosts sell hosted WordPress under their own prices, which aren't graded here (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the REST API handbook, wordpress.org/llms.txt or the core and MCP Adapter repositories (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 21460,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.wordpress.org/rest-api/",
      "llmsTxt": "https://wordpress.org/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "rest",
        "mcp",
        "cli",
        "php",
        "llms-txt",
        "security-txt",
        "bug-bounty"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.8,
        "grade": "B",
        "agentReady": false,
        "rank": 272,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 83,
          "payments": 60,
          "reliability": 78,
          "schema": 65,
          "security": 62,
          "transparency": 68
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -5,
        "negativeNotes": [
          "22 September 2026. WordPress 7.1.2 fixed a critical flaw, CVE-2026-87902 (GHSA-7hp8-65ch-5whp), in which an unauthenticated attacker could, where server and theme conditions were met, make template resolution include a local PHP file and reach remote code execution. 7.1.1 on 17 September and 7.1.3 on 6 October fixed 18 further security issues. All were published by the project with the fix and backported, and we found no report of exploitation in the release posts, so we deduct 5 of a possible 15. https://wordpress.org/news/2026/09/wordpress-7-1-2-release/ ; https://wordpress.org/news/2026/10/wordpress-7-1-3-maintenance-and-security-release/"
        ],
        "verdict": "The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026.",
        "bestFor": "Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.",
        "strengths": [
          "Posts created without `status` are saved as drafts, and DELETE moves a post to the Trash unless `force=true` is passed",
          "Every REST or WP-CLI update to a post writes a revision that `/wp/v2/posts/\u003cid\u003e/revisions` lists with author and date",
          "`_fields` trims responses down to nested properties, with `per_page` up to 100 and X-WP-Total headers on every list",
          "Six stable releases between 6 August and 6 October 2026, and security fixes backported to 4.7",
          "GPL-2.0-or-later, free to self-host, with a valid security.txt and a HackerOne programme for core"
        ],
        "weaknesses": [
          "Application Passwords have no scopes or expiry. Each one carries every capability of its user",
          "The revisions route supports GET and DELETE only, so a rollback means writing the old content back as a new update",
          "Core has no rate limit, no idempotency keys and no log of API calls beyond revisions and a password's last use",
          "A critical flaw (CVE-2026-87902) fixed in 7.1.2 on 22 September 2026 allowed remote code execution under certain server and theme conditions",
          "No published OpenAPI file. Each site describes its own routes at `/wp-json`, and core has no content localisation"
        ],
        "agentNotes": [
          "Ask the owner for a dedicated user with the lowest role that fits. A Contributor can draft and edit its own posts but can't publish them",
          "Send the Application Password as Basic auth over HTTPS only. Core disables Application Passwords on plain HTTP outside a local environment",
          "Upload a file with POST `/wp-json/wp/v2/media` first, then set `featured_media` or reference the returned URL in the post content",
          "To roll back, GET `/wp/v2/posts/\u003cid\u003e/revisions/\u003crev\u003e?context=edit` and POST its title and content to the post. There's no restore route",
          "Pass `_fields=id,status,link,modified` on lists and read X-WP-TotalPages. `per_page` stops at 100"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.8
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 83,
          "payments": 60,
          "reliability": 78,
          "schema": 65,
          "security": 62,
          "transparency": 72
        },
        "provenanceScore": 63
      },
      "connect": {
        "install": "wp core download \u0026\u0026 wp core install --url=\u003curl\u003e --title=\u003ctitle\u003e --admin_user=\u003cuser\u003e --admin_email=\u003cemail\u003e",
        "http": "curl --user \"USERNAME:PASSWORD\" https://HOSTNAME/wp-json/wp/v2/users?context=edit",
        "config": {
          "mcpServers": {
            "wordpress": {
              "args": [
                "--path=/path/to/your/wordpress/site",
                "mcp-adapter",
                "serve",
                "--server=mcp-adapter-default-server",
                "--user=admin"
              ],
              "command": "wp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/wordpress"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "WordPress, self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "GPL, you pay for your own hosting"
        }
      ],
      "provenance": {
        "legalEntity": "WordPress.org, an open-source project. The WordPress trademark belongs to the WordPress Foundation",
        "domain": "wordpress.org",
        "domainRegistered": "2003-03-28",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "https://wordpress.org/about/privacy/",
        "statusPage": "",
        "changelog": "https://wordpress.org/news/category/releases/",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "No terms of service govern the software. It is licensed under GPL version 2 or later, and no service agreement or API terms were found, so `terms` is left out.",
          "The privacy policy covers the WordPress.org websites and names api.wordpress.org, the service installations call to check for updates. It names no company, and gives dpo@wordpress.org as the contact. It doesn't cover content held on a self-hosted site.",
          "The REST API answers on each owner's own domain.",
          "https://wordpress.org/.well-known/security.txt returned 200 with Contact https://hackerone.com/wordpress and Expires 2027-06-30.",
          "RDAP for wordpress.org gives a registration date of 2003-03-28.",
          "The make.wordpress.org footer says the WordPress trademark is the intellectual property of the WordPress Foundation. `license.txt` gives copyright to the contributors.",
          "No status page applies to self-hosted software."
        ],
        "score": 63
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/wordpress.json",
      "live": {
        "slug": "wordpress",
        "pages": [
          {
            "url": "https://wordpress.org/news/category/releases/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:52.505193763Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cbd71d93d029"
          },
          {
            "url": "https://wordpress.org/about/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:50.079319583Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "61575a1b129f"
          }
        ],
        "updatedAt": "2026-10-08T18:25:52.505193763Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Payload CMS, Inc. (Figma)",
        "b": "WordPress.org (open-source project)",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, stdio",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
        "b": "GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-23",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2024-03-28",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "45k stars, 1.1M npm/wk",
        "b": "21k stars",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "WordPress scores 64.8 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on schema \u0026 documentation.",
        "question": "Which is better for AI agents, Payload or WordPress?"
      },
      {
        "answer": "Both need an API key.",
        "question": "Do Payload and WordPress need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Payload. WordPress runs on your own machine, with no hosted endpoint listed.",
        "question": "Can an agent call Payload and WordPress without installing anything?"
      },
      {
        "answer": "Yes. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). WordPress is open source (GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too).",
        "question": "Are Payload and WordPress open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 70 against 65"
        ],
        "also": null,
        "goodFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "slug": "payload",
        "watchFor": "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026"
      },
      {
        "aheadOn": [
          "Agent ergonomics, 74 against 64",
          "Security \u0026 auth, 62 against 57",
          "Payments \u0026 pricing, 60 against 45",
          "Maintenance \u0026 community, 83 against 78",
          "Transparency \u0026 trust, 68 against 62"
        ],
        "also": [
          "Runs on your own machine"
        ],
        "goodFor": "Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.",
        "slug": "wordpress",
        "watchFor": "Application Passwords have no scopes or expiry. Each one carries every capability of its user"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-payload.json",
        "title": "Contentstack vs Payload",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress.json",
        "title": "Contentstack vs WordPress",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-payload.json",
        "title": "DatoCMS vs Payload",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-wordpress.json",
        "title": "DatoCMS vs WordPress",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-payload.json",
        "title": "Directus vs Payload",
        "url": "https://www.anchorterminal.com/compare/directus-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-wordpress.json",
        "title": "Directus vs WordPress",
        "url": "https://www.anchorterminal.com/compare/directus-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-payload.json",
        "title": "Ghost vs Payload",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-wordpress.json",
        "title": "Ghost vs WordPress",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-sanity.json",
        "title": "Payload vs Sanity",
        "url": "https://www.anchorterminal.com/compare/payload-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-storyblok.json",
        "title": "Payload vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/payload-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-strapi.json",
        "title": "Payload vs Strapi",
        "url": "https://www.anchorterminal.com/compare/payload-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-webflow.json",
        "title": "Payload vs Webflow",
        "url": "https://www.anchorterminal.com/compare/payload-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sanity-vs-wordpress.json",
        "title": "Sanity vs WordPress",
        "url": "https://www.anchorterminal.com/compare/sanity-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/storyblok-vs-wordpress.json",
        "title": "Storyblok vs WordPress",
        "url": "https://www.anchorterminal.com/compare/storyblok-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/strapi-vs-wordpress.json",
        "title": "Strapi vs WordPress",
        "url": "https://www.anchorterminal.com/compare/strapi-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/webflow-vs-wordpress.json",
        "title": "Webflow vs WordPress",
        "url": "https://www.anchorterminal.com/compare/webflow-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 0,
        "edge": "",
        "key": "reliability",
        "name": "Reliability",
        "payload": 78,
        "weight": 16,
        "wordpress": 78
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 5,
        "edge": "payload",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "payload": 70,
        "weight": 13,
        "wordpress": 65
      },
      {
        "by": 10,
        "edge": "wordpress",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "payload": 64,
        "weight": 13,
        "wordpress": 74
      },
      {
        "by": 5,
        "edge": "wordpress",
        "key": "security",
        "name": "Security \u0026 auth",
        "payload": 57,
        "weight": 14,
        "wordpress": 62
      },
      {
        "by": 15,
        "edge": "wordpress",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "payload": 45,
        "weight": 10,
        "wordpress": 60
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 5,
        "edge": "wordpress",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "payload": 78,
        "weight": 7,
        "wordpress": 83
      },
      {
        "by": 6,
        "edge": "wordpress",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "payload": 62,
        "weight": 7,
        "wordpress": 68
      }
    ],
    "summary": "WordPress scores 64.8 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on schema \u0026 documentation. Both do cms content.",
    "verdicts": {
      "payload": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.",
      "wordpress": "The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/payload-vs-wordpress",
    "json": "https://www.anchorterminal.com/compare/payload-vs-wordpress.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/payload-vs-wordpress.md",
    "slim": "https://www.anchorterminal.com/compare/payload-vs-wordpress.min.md"
  },
  "markdown": "WordPress scores 64.8 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on schema \u0026 documentation. Both do cms content.\n\n- Payload: grade C, 55.2/100, rank #516 of 722. Markdown https://www.anchorterminal.com/tools/payload.md · JSON https://www.anchorterminal.com/api/v1/tools/payload.json\n- WordPress: grade B, 64.8/100, rank #272 of 722. Markdown https://www.anchorterminal.com/tools/wordpress.md · JSON https://www.anchorterminal.com/api/v1/tools/wordpress.json\n\n## Which one, for what\n\n### Payload (C)\n\nGood for: Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.\n\nAhead on:\n- Schema \u0026 documentation, 70 against 65\n\nWatch for: 49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026\n\n### WordPress (B)\n\nGood for: Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.\n\nAhead on:\n- Agent ergonomics, 74 against 64\n- Security \u0026 auth, 62 against 57\n- Payments \u0026 pricing, 60 against 45\n- Maintenance \u0026 community, 83 against 78\n- Transparency \u0026 trust, 68 against 62\n\nAlso in its favour:\n- Runs on your own machine\n\nWatch for: Application Passwords have no scopes or expiry. Each one carries every capability of its user\n\n\n## Score by category\n\n| Category | Weight | Payload | WordPress | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 78 | 78 | even |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 70 | 65 | Payload +5 |\n| Agent ergonomics | 13% (16.2 this run) | 64 | 74 | WordPress +10 |\n| Security \u0026 auth | 14% (17.5 this run) | 57 | 62 | WordPress +5 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 45 | 60 | WordPress +15 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 78 | 83 | WordPress +5 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 62 | 68 | WordPress +6 |\n| Negative events | ≤15 | -10 | -5 | |\n| **Total** | | **55.2 · C** | **64.8 · B** | |\n\n## Facts side by side\n\n| Fact | Payload | WordPress |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Payload CMS, Inc. (Figma) | WordPress.org (open-source project) |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP, stdio |\n| Auth | API key | API key |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales | GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-23 | 2026-10-06 |\n| Terms last updated | no document linked | no document linked |\n| Privacy policy last updated | 2024-03-28 | no date given |\n| Customer content may train models |  |  |\n| Terms restrict automated access |  |  |\n| Terms restrict benchmarking |  |  |\n| Terms or service can change without notice |  |  |\n| Arbitration or class-action waiver |  |  |\n| Popularity | 45k stars, 1.1M npm/wk | 21k stars |\n\n## Verdicts\n\n**Payload.** Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.\n\n**WordPress.** The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026.\n\n## Before you call either\n\n### Payload\n\n1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing\n2. Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate\n3. To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written\n4. Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented\n5. Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them\n\n### WordPress\n\n1. Ask the owner for a dedicated user with the lowest role that fits. A Contributor can draft and edit its own posts but can't publish them\n2. Send the Application Password as Basic auth over HTTPS only. Core disables Application Passwords on plain HTTP outside a local environment\n3. Upload a file with POST `/wp-json/wp/v2/media` first, then set `featured_media` or reference the returned URL in the post content\n4. To roll back, GET `/wp/v2/posts/\u003cid\u003e/revisions/\u003crev\u003e?context=edit` and POST its title and content to the post. There's no restore route\n5. Pass `_fields=id,status,link,modified` on lists and read X-WP-TotalPages. `per_page` stops at 100\n\n## Questions\n\n### Which is better for AI agents, Payload or WordPress?\n\nWordPress scores 64.8 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on schema \u0026 documentation.\n\n### Do Payload and WordPress need an API key?\n\nBoth need an API key.\n\n### Can an agent call Payload and WordPress without installing anything?\n\nNo hosted endpoint is listed for Payload. WordPress runs on your own machine, with no hosted endpoint listed.\n\n### Are Payload and WordPress open source?\n\nYes. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). WordPress is open source (GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/payload-vs-wordpress.json, and with the fewest tokens: https://www.anchorterminal.com/compare/payload-vs-wordpress.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"payload\", \"b\": \"wordpress\"}`. From a terminal: `anchor compare payload wordpress`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/payload.json and https://www.anchorterminal.com/api/v1/tools/wordpress.json\n\n## Other comparisons with Payload or WordPress\n\n- [Contentstack vs Payload](https://www.anchorterminal.com/compare/contentstack-vs-payload.md)\n- [Contentstack vs WordPress](https://www.anchorterminal.com/compare/contentstack-vs-wordpress.md)\n- [DatoCMS vs Payload](https://www.anchorterminal.com/compare/datocms-vs-payload.md)\n- [DatoCMS vs WordPress](https://www.anchorterminal.com/compare/datocms-vs-wordpress.md)\n- [Directus vs Payload](https://www.anchorterminal.com/compare/directus-vs-payload.md)\n- [Directus vs WordPress](https://www.anchorterminal.com/compare/directus-vs-wordpress.md)\n- [Ghost vs Payload](https://www.anchorterminal.com/compare/ghost-vs-payload.md)\n- [Ghost vs WordPress](https://www.anchorterminal.com/compare/ghost-vs-wordpress.md)\n- [Payload vs Sanity](https://www.anchorterminal.com/compare/payload-vs-sanity.md)\n- [Payload vs Storyblok](https://www.anchorterminal.com/compare/payload-vs-storyblok.md)\n- [Payload vs Strapi](https://www.anchorterminal.com/compare/payload-vs-strapi.md)\n- [Payload vs Webflow](https://www.anchorterminal.com/compare/payload-vs-webflow.md)\n- [Sanity vs WordPress](https://www.anchorterminal.com/compare/sanity-vs-wordpress.md)\n- [Storyblok vs WordPress](https://www.anchorterminal.com/compare/storyblok-vs-wordpress.md)\n- [Strapi vs WordPress](https://www.anchorterminal.com/compare/strapi-vs-wordpress.md)\n- [Webflow vs WordPress](https://www.anchorterminal.com/compare/webflow-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Payload vs WordPress",
        "url": ""
      }
    ],
    "description": "WordPress scores 64.8 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on schema \u0026 documentation. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Payload C 55.2",
      "WordPress B 64.8",
      "scores"
    ],
    "h1": "Payload vs WordPress",
    "image": "https://www.anchorterminal.com/assets/og/compare-payload-vs-wordpress.png",
    "path": "/compare/payload-vs-wordpress",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Payload vs WordPress for AI agents, C 55.2 vs B 64.8 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/payload-vs-wordpress"
  },
  "tokens": {
    "markdown": 2200,
    "slim": 580
  },
  "version": 1
}
