
Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini Security & Risk Analysis
wordpress.org/plugins/royal-mcpSecurity-first MCP server. Connect Claude, ChatGPT & Gemini to WordPress with API key auth, rate limiting, audit logs, and Elementor tools.
Is Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini Safe to Use in 2026?
Generally Safe
Score 98/100Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "royal-mcp" v1.2.3 exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding output escaping and avoids dangerous functions, file operations, and bundled libraries. The presence of nonce and capability checks for some entry points is also a good sign. However, a significant concern arises from the attack surface analysis. Three out of five identified entry points, specifically all three REST API routes, lack permission callbacks, leaving them open to unauthorized access and manipulation. Furthermore, the taint analysis reveals two flows with unsanitized paths, indicating a potential for input validation issues that could lead to vulnerabilities if exploited, even though no critical or high severity issues were flagged in this specific analysis. The plugin's clean vulnerability history is a strong positive, suggesting a generally well-maintained codebase and a proactive approach to security by the developers. Despite the clean history, the identified weaknesses in the attack surface and taint analysis warrant caution.
Key Concerns
- REST API routes without permission callbacks
- Flows with unsanitized paths
- AJAX handlers without auth checks
Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini <= 1.4.25 - Missing Authorization
Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini <= 1.4.2 - Missing Authorization
Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini Release Timeline
Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini Attack Surface
AJAX Handlers 2
REST API Routes 3
WordPress Hooks 7
Maintenance & Trust
Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini Maintenance & Trust
Maintenance Signals
Community Trust
Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini Alternatives
WPVibe – MCP Server for WordPress. Connect Claude, ChatGPT, Gemini & Cursor
vibe-ai
Secure MCP server for WordPress. Connect Claude, ChatGPT, Gemini, Cursor & any AI agent to manage content, edit themes & automate your site.
StifLi Flex MCP – MCP Server with undo for ChatGPT, Claude & Gemini
stifli-flex-mcp
The most secure MCP Server for WordPress with Undo, plus AI Copilot & Chat Agent. ChatGPT, Claude, Gemini, OpenRouter & Mistral.
MCP Content Manager Lite
mcp-content-manager-lite
Manage WordPress from Claude, ChatGPT, Copilot or any MCP client. 60+ abilities, OAuth 2.1, allowlists, activity log, multilingual and SEO read.
MountDev AI MCP Connector for WordPress
mountdev-ai-mcp-connector
Transform your WordPress site into an AI-powered Model Context Protocol (MCP) server. Exposes WordPress functionality for AI agents.
AI Connector – MCP for Claude, ChatGPT, Gemini & More
bcs-mcp-manager
Connect Claude, ChatGPT, Gemini, Cursor, and other AI assistants to your WordPress site using the Model Context Protocol (MCP). 150+ tools, OAuth 2.
Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini Developer Profile
4 plugins · 8K total installs
How We Detect Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/royal-mcp/includes/Admin/js/settings-page.js/wp-content/plugins/royal-mcp/includes/Admin/css/settings-page.css/wp-content/plugins/royal-mcp/includes/Admin/js/settings-page.jsHTML / DOM Fingerprints
royal-mcp-settings-pageroyal-mcp-log-tableroyal-mcp-platform-field<!-- Royal MCP Settings Page --><!-- Royal MCP Activity Log -->data-royal-mcp-ajax-urldata-royal-mcp-nonceRoyalMCPConfig/royal-mcp/v1/mcp/royal-mcp/v1/sse/royal-mcp/v1/messages