Security and permissions
The AI acts as a user
Section titled “The AI acts as a user”Every request runs as the WordPress user who owns the Application Password, with that user’s permissions. RealMCP goes through WordPress’s own REST endpoints, so per-post checks apply: the AI can’t read or edit what that user can’t. Content from users without the unfiltered_html capability is filtered by WordPress as usual.
Use a dedicated user with the role you’re comfortable with. An Editor is enough for every tool.
Safe defaults
Section titled “Safe defaults”- New pages are drafts unless the AI sets another status, and publishing needs the user’s permission to publish.
- Updates are rejected if the page changed since the AI read it.
- Administrators can turn off any tool, for example
save-pagefor read-only access. - Every call is recorded in the activity log.
Revoking access
Section titled “Revoking access”Delete the Application Password in Users → Profile → Application Passwords. The client stops working immediately.
Network
Section titled “Network”- Application Passwords travel only over HTTPS: WordPress requires it, and the bridge refuses plain HTTP to sites that aren’t local.
- The endpoint rejects browser requests from other origins.
- The plugin doesn’t contact any external service; the activity log stays in your database. What your AI client does with the content it reads depends on that client.