
Royal MCP Security & Risk Analysis
wordpress.org/plugins/royal-mcpThe security-first MCP server for WordPress. Connect Claude, ChatGPT, and Gemini with API key auth, rate limiting, and activity logging.
Is Royal MCP Safe to Use in 2026?
Generally Safe
Score 99/100Royal MCP has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "royal-mcp" v1.2.3 exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding output escaping and avoids dangerous functions, file operations, and bundled libraries. The presence of nonce and capability checks for some entry points is also a good sign. However, a significant concern arises from the attack surface analysis. Three out of five identified entry points, specifically all three REST API routes, lack permission callbacks, leaving them open to unauthorized access and manipulation. Furthermore, the taint analysis reveals two flows with unsanitized paths, indicating a potential for input validation issues that could lead to vulnerabilities if exploited, even though no critical or high severity issues were flagged in this specific analysis. The plugin's clean vulnerability history is a strong positive, suggesting a generally well-maintained codebase and a proactive approach to security by the developers. Despite the clean history, the identified weaknesses in the attack surface and taint analysis warrant caution.
Key Concerns
- REST API routes without permission callbacks
- Flows with unsanitized paths
- AJAX handlers without auth checks
Royal MCP Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini <= 1.4.2 - Missing Authorization
Royal MCP Release Timeline
Royal MCP Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Royal MCP Attack Surface
AJAX Handlers 2
REST API Routes 3
WordPress Hooks 7
Maintenance & Trust
Royal MCP Maintenance & Trust
Maintenance Signals
Community Trust
Royal MCP Alternatives
StifLi Flex MCP – AI Copilot, Chat Agent and MCP Server
stifli-flex-mcp
AI Copilot for the WordPress editor, AI Chat Agent for full site management & MCP server for external AI clients. OpenAI, Claude & Gemini.
AIKO – AI Developer Lite
aiko-developer-lite
A plugin that makes other plugins.
Notification for Telegram
notification-for-telegram
Sends notifications to Telegram users or groups, when some events occur in WordPress.
BotWriter – AI Writer & Content Generator
botwriter
AI Writer & content generator for WordPress & WooCommerce. Auto blogging, AI writing plugin, product descriptions and SEO content.
AI
ai
AI features, experiments and capabilities for WordPress.
Royal MCP Developer Profile
4 plugins · 500 total installs
How We Detect Royal MCP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/royal-mcp/includes/Admin/js/settings-page.js/wp-content/plugins/royal-mcp/includes/Admin/css/settings-page.css/wp-content/plugins/royal-mcp/includes/Admin/js/settings-page.jsHTML / DOM Fingerprints
royal-mcp-settings-pageroyal-mcp-log-tableroyal-mcp-platform-field<!-- Royal MCP Settings Page --><!-- Royal MCP Activity Log -->data-royal-mcp-ajax-urldata-royal-mcp-nonceRoyalMCPConfig/royal-mcp/v1/mcp/royal-mcp/v1/sse/royal-mcp/v1/messages