InstaWP
example.instawp.siteComments+ New
InstaMCP Settings
General
Capabilities
Skills
API Tokens
Endpoints
These are powerful tools that are OFF by default. They stay listed over MCP even when off — so connecting agents discover that they exist and learn how to enable them — but they do nothing until you turn them on here. Their write operations are additionally gated by Safe Mode (see the General tab).
Execute PHP
Enable the execute_php tool (lets the AI run arbitrary PHP)
Warning: This grants the AI agent root-equivalent control over WordPress. Use only on staging/development sites or when you fully trust the connecting client. Restricted to the mcp:admin scope.
Database Query
Off
Off
Read-only
Read & write
The db_query tool. Off by default. Read-only is safe inspection; read & write runs arbitrary write SQL. mcp:admin scope.
Site Files
Off
Off
Read-only
Read & write
The site_files tool (wp-config, .htaccess, mu-plugins, drop-ins, uploads). Off by default. Writes are Safe-Mode-gated and backed up.
Save Settings
3
raw tools, off by default
4 scopes
mapped to WordPress roles
readwritedeleteadmin