
Royal MCP Security & Risk Analysis
wordpress.org/plugins/royal-mcpWordPress MCP plugin that connects AI platforms like Claude, ChatGPT, and Gemini to your site using Model Context Protocol for secure content access.
Is Royal MCP Safe to Use in 2026?
Generally Safe
Score 100/100Royal MCP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "royal-mcp" v1.2.3 exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding output escaping and avoids dangerous functions, file operations, and bundled libraries. The presence of nonce and capability checks for some entry points is also a good sign. However, a significant concern arises from the attack surface analysis. Three out of five identified entry points, specifically all three REST API routes, lack permission callbacks, leaving them open to unauthorized access and manipulation. Furthermore, the taint analysis reveals two flows with unsanitized paths, indicating a potential for input validation issues that could lead to vulnerabilities if exploited, even though no critical or high severity issues were flagged in this specific analysis. The plugin's clean vulnerability history is a strong positive, suggesting a generally well-maintained codebase and a proactive approach to security by the developers. Despite the clean history, the identified weaknesses in the attack surface and taint analysis warrant caution.
Key Concerns
- REST API routes without permission callbacks
- Flows with unsanitized paths
- AJAX handlers without auth checks
Royal MCP Security Vulnerabilities
Royal MCP Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Royal MCP Attack Surface
AJAX Handlers 2
REST API Routes 3
WordPress Hooks 7
Maintenance & Trust
Royal MCP Maintenance & Trust
Maintenance Signals
Community Trust
Royal MCP Developer Profile
3 plugins · 90 total installs
How We Detect Royal MCP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/royal-mcp/includes/Admin/js/settings-page.js/wp-content/plugins/royal-mcp/includes/Admin/css/settings-page.css/wp-content/plugins/royal-mcp/includes/Admin/js/settings-page.jsHTML / DOM Fingerprints
royal-mcp-settings-pageroyal-mcp-log-tableroyal-mcp-platform-field<!-- Royal MCP Settings Page --><!-- Royal MCP Activity Log -->data-royal-mcp-ajax-urldata-royal-mcp-nonceRoyalMCPConfig/royal-mcp/v1/mcp/royal-mcp/v1/sse/royal-mcp/v1/messages