# WordPress (slim) > WordPress is an open-source content management system that its owner hosts. Agents create, revise and publish posts, pages and media through the built-in REST API, WP-CLI or the official MCP Adapter plugin. - Full: https://www.anchorterminal.com/tools/wordpress.md (~7,700 tokens) · this version ~2,130 tokens · JSON https://www.anchorterminal.com/tools/wordpress.json · canonical https://www.anchorterminal.com/tools/wordpress - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 64.8/100 · rank #272 of 722 · #7 in CMS & website publishing · not agent-ready · confidence medium** Assessment: The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026. ## Facts - Kind: HTTP API · vendor: WordPress.org (open-source project) · category: CMS & website publishing · legal entity: WordPress.org, an open-source project. The WordPress trademark belongs to the WordPress Foundation · provenance 63/100 - Local only (HTTP, stdio) - Auth: API key · pricing: Free · x402: no · licence: GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too - Probe metrics: not measured yet (probes haven't run) - Graded surface: Self-hosted WordPress 7.1.3 through the core REST API at /wp-json/wp/v2, authenticated with an Application Password. WP-CLI and the MCP Adapter plugin are described but not the basis of the grade. WordPress.com, Automattic's hosted service, is a separate product and isn't graded here - REST API: In core since 4.7. Posts, pages, media, revisions, autosaves, comments, categories, tags, users, settings, templates, menus, plugins, themes and custom post types registered with `show_in_rest`. Each site lists its routes and their JSON Schema arguments at /wp-json and on OPTIONS requests - Credentials: Application Passwords (core since 5.6), one per application, revocable one at a time, with last used time and last IP recorded. No scopes and no expiry. Sent as Basic auth, and available only over HTTPS or in a `local` environment. An application can request one through `wp-admin/authorize-application.php`, which the user approves in a browser - Roles: Access follows the user's role. Core checks capabilities such as `publish_posts` and `edit_others_posts` on every write, so a Contributor account can draft but not publish - Draft and publish: `status` is one of the site's registered statuses, such as draft, pending, private, publish and future. A create without `status` is saved as a draft. A user without `publish_posts` can't set publish - Assets: POST /wp/v2/media with the file as the request body or as multipart form data. Further routes for post-process, edit, sideload and `finalize` on an attachment - Version history: Each update to a post type that supports revisions stores one. GET /wp/v2/posts//revisions and /revisions/, DELETE with `force=true`. No restore route. Autosaves have their own routes - Response controls: `_fields` with nested properties, `_embed` with a list of relations, `context` of view, embed or edit, `page`, `per_page` (1 to 100, default 10), `offset`, and X-WP-Total and X-WP-TotalPages headers - Deletes: DELETE moves a post to the Trash unless `force=true`. Revisions and media can't be trashed and need `force=true` - Abilities and MCP: Abilities API in core since 6.9, with `readonly`, `destructive` and `idempotent` annotations. Core registers three read-only abilities. The MCP Adapter plugin (v0.7.0, needs WordPress 6.9 and PHP 7.4) maps abilities to MCP tools, resources and prompts for MCP revisions 2025-11-25 and 2026-07-28. Abilities are private unless marked `meta.public` - WP-CLI: `wp post create`, `wp post update`, `wp media import`, `wp core install` and `wp user application-password create` among its commands. The newest tag on GitHub is v2.12.0 of 7 May 2025, with commits to 8 October 2026 - Rate limits: None in core. No 429 handling or Retry-After was found in the REST server source or the handbook - Runtime: PHP 7.4 or later and MySQL 5.5.5 or later as the minimum. PHP 8.3, MySQL 8.0 or MariaDB 10.11 and HTTPS are recommended - Releases: 7.1 on 19 August 2026, then 7.1.1 (17 September), 7.1.2 (22 September) and 7.1.3 (6 October). 7.2 is planned for December 2026. Version numbers aren't semver, and the project states that it aims never to break backward compatibility - Security: security.txt valid until 30 June 2027, reports through HackerOne, security fixes backported as a courtesy to 4.7, and only the latest version actively supported - Data sent to WordPress.org: Core, plugin and theme update checks to api.wordpress.org. The core check sends versions, locale, user and site counts and PHP extensions. `WP_HTTP_BLOCK_EXTERNAL` and the `core_version_check_query_args` filter change or stop it. There is no setting in the admin screens - Prices: WordPress, self-hosted free per month (plan) - Scores: Reliability 78, Performance pending, Schema & documentation 65, Agent ergonomics 74, Security & auth 62, Payments & pricing 60, Task success pending, Maintenance & community 83, Transparency & trust 68 · negative events -5 · total over the 7 assessed categories - Why: Reliability, Read with the local-software lines, since each site runs on its owner's host and WordPress.org runs no hosted API. · Schema & documentation, No published OpenAPI file. · Agent ergonomics, `_fields` trims a response down to nested properties, `context` picks view, embed or edit, and the MCP Adapter's default server lists three… · Security & auth, Application Passwords are per application, revocable one at a time, sent only in the Authorization header and refused on plain HTTP outside… · Payments & pricing, Scored with the self-hosted rule. · Maintenance & community, 7.1.3 was released on 6 October 2026, two days before this check (30). · Transparency & trust, GPL version 2 or later, with the source public (30). - Sources: 21, open questions: 9, both in the full twin - Capabilities: cms.content, cms.publish, cms.assets - JSON: https://www.anchorterminal.com/api/v1/tools/wordpress.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/wordpress.svg` or a link to https://www.anchorterminal.com/tools/wordpress from a page on wordpress.org or one of its subdomains, or the README of github.com/WordPress/wordpress-develop, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Ask the owner for a dedicated user with the lowest role that fits. A Contributor can draft and edit its own posts but can't publish them 2. Send the Application Password as Basic auth over HTTPS only. Core disables Application Passwords on plain HTTP outside a local environment 3. Upload a file with POST `/wp-json/wp/v2/media` first, then set `featured_media` or reference the returned URL in the post content 4. To roll back, GET `/wp/v2/posts//revisions/?context=edit` and POST its title and content to the post. There's no restore route 5. Pass `_fields=id,status,link,modified` on lists and read X-WP-TotalPages. `per_page` stops at 100 ## Connect ```bash wp core download && wp core install --url= --title= --admin_user=<user> --admin_email=<email> ``` ```bash curl --user "USERNAME:PASSWORD" https://HOSTNAME/wp-json/wp/v2/users?context=edit ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/wordpress ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | DatoCMS | BB | 74.4 | cms.content, cms.publish, cms.assets | https://www.anchorterminal.com/tools/datocms.min.md | | Sanity | BB | 73.7 | cms.content, cms.publish, cms.assets | https://www.anchorterminal.com/tools/sanity.min.md | | Webflow | B | 69.4 | cms.content, cms.publish, cms.assets | https://www.anchorterminal.com/tools/webflow.min.md | | Storyblok | B | 67.7 | cms.content, cms.publish, cms.assets | https://www.anchorterminal.com/tools/storyblok.min.md | | Directus | B | 67.1 | cms.content, cms.assets, cms.publish | https://www.anchorterminal.com/tools/directus.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)