Royal MCP

Royal MCP is an open-source, security-first WordPress plugin that connects Claude, ChatGPT, Perplexity, Gemini, and any other MCP agent to your site. It is available as a remote MCP endpoint.

Teams that work with wordpress, elementor and oauth2 and want a hosted endpoint instead of running a local process. The project is written in PHP.

VERIFIED ACTIVE

LAST COMMIT 2026-09-15 · ★ 9 · #147 OF 204 MAINTAINED SECURITY · VERIFIED 2026-09-18

NOASSERTION · PHP · how we verify → /methodology

01 · Install Royal MCP

before you install - you'll need

The README does not document required environment variables for a basic install.

Claude Code

claude mcp add royalplugins-royal-mcp --transport http https://demo.royalplugins.com/wp-json/royal-mcp/v1/mcp

Claude Desktop / Cursor / VS Code - add to config

{
  "mcpServers": {
    "royalplugins-royal-mcp": {
      "url": "https://demo.royalplugins.com/wp-json/royal-mcp/v1/mcp"
    }
  }
}

Same JSON for Cursor. For VS Code, rename the top-level key from `mcpServers` to `servers`.

Using another client? Same JSON, different key

Claude Desktop · mcpServers

Cursor · mcpServers

VS Code · servers

Windsurf · mcpServers

Zed · context_servers

Cline · mcpServers

Roo Code · mcpServers

Continue · mcpServers

LibreChat · mcpServers

Gemini CLI · mcpServers

Codex CLI · mcp_servers

Full setup guides: every client.

02 · Evidence

https://demo.royalplugins.com/wp-json/royal-mcp/v1/mcp

transport: streamable-http

endpoint alive - authentication required · probed 2026-09-17

Security posture

What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.

runs as remote - your agent's requests go to demo.royalplugins.com

endpoint auth requires authentication - rejected our unauthenticated MCP initialize

license no standard license detected - usage rights unclear; check the repo before commercial use

registry vendor namespace com.royalplugins - domain-verified with the official MCP registry

03 · What Royal MCP can do

Prose above is summarized from the project's README and registry record - no invented capabilities.

Latest releases

v1.5.2 · 2026-09-15

Royal MCP 1.5.2.

v1.5.1 · 2026-09-10

Summary · Ships browser-agent support via the W3C WebMCP standard plus machine-readable Agent Readiness discovery documents so external scanners (Cloudflare Agent Readiness, Vercel is-agentic, Chrome Lighthouse Agentic…

v1.5.0 · 2026-09-05

First plugin release supporting the MCP 2026-07-28 spec revision on the initialize handshake. Dual-support: the existing 2025-11-25 wire stays the default for clients that don't ask for anything specific; newer clients…

04 · Who maintains Royal MCP

royal-mcp is maintained by royalplugins. It's the only MCP server we track from this author; the repo dates to Mar 2026.

05 · Facts

category
security - ranked #147 of 204 actively-maintained security servers as of 2026-09-18.
release cadence
7 releases in the last 90 days (latest 2026-09-15)
registry
com.royalplugins/royal-mcp (active, first published 2026-07-10)

06 · Royal MCP FAQ

What is Royal MCP?

Royal MCP is an open-source, security-first WordPress plugin that connects Claude, ChatGPT, Perplexity, Gemini, and any other MCP agent to your site. It is available as a remote MCP endpoint.

Is Royal MCP still maintained?

Yes - as of 2026-09-18, its last commit was 2026-09-15 and it shipped 7 releases in the last 90 days. We re-verify nightly.

How do I install Royal MCP?

Run `claude mcp add royalplugins-royal-mcp --transport http https://demo.royalplugins.com/wp-json/royal-mcp/v1/mcp`. The README does not document required environment variables for a basic install. You can also paste the ready-made client config above.

Does Royal MCP require authentication?

Yes - when we probed the endpoint on 2026-09-17, it rejected an unauthenticated MCP initialize; you'll need credentials to connect.

07 · Alternatives to Royal MCP

More security MCP servers · Hush · Janee · Agent Wormhole · Audit