Server data from the Official MCP Registry
Read-only MCP server for WordPress + WooCommerce products, orders, sales, and posts.
About
Read-only MCP server for WordPress + WooCommerce products, orders, sales, and posts.
Security Report
A well-architected read-only MCP server for WooCommerce with proper authentication, input validation, and secure credential handling. The codebase demonstrates good security practices: credentials are loaded at call time (not import time), API errors are surfaced safely without echoing secrets, and all operations are read-only by design. Minor code quality observations do not materially impact security. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.
4 files analyzed · 8 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: WP_URL
Environment variable: WC_CONSUMER_KEY
Environment variable: WC_CONSUMER_SECRET
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-wppoland-woocommerce-mcp": {
"env": {
"WP_URL": "your-wp-url-here",
"WC_CONSUMER_KEY": "your-wc-consumer-key-here",
"WC_CONSUMER_SECRET": "your-wc-consumer-secret-here"
},
"args": [
"-y",
"@wppoland/woocommerce-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
woocommerce-mcp
A small, read-only Model Context Protocol server for WordPress + WooCommerce. It lets Claude (or any MCP client) answer questions about a live store — products, orders, sales, and blog posts — over the official REST APIs. No writes, no plugins to install on the store: it talks to the existing WordPress/WooCommerce REST endpoints.
Built and maintained by WPPoland, a senior WordPress developer working with WordPress since 2006. If you need this wired into a real store stack, we build WooCommerce ERP and API integrations and enterprise e-commerce architecture (headless, integrations, AI-ready data).
Tools
| Tool | What it does | Needs WooCommerce keys |
|---|---|---|
list_products | List / search products (name, sku, price, stock, permalink) | yes |
get_product | Full details for one product by id | yes |
list_orders | Recent orders, newest first, optional status filter | yes |
sales_report | Sales totals for a period (week / month / last_month / year) | yes |
search_posts | Search published blog posts (public WP REST API) | no |
Everything is read-only. The server never creates, edits, or deletes anything in the store.
Install & build
From npm (package name is scoped - the unscoped woocommerce-mcp name is locked on the registry):
npm install -g @wppoland/woocommerce-mcp
# or: npx @wppoland/woocommerce-mcp
From source:
git clone https://github.com/wppoland/woocommerce-mcp.git
cd woocommerce-mcp
npm install
npm run build
Configure
Set three environment variables:
| Var | Required | Example |
|---|---|---|
WP_URL | yes | https://shop.example.com |
WC_CONSUMER_KEY | for wc_* tools | ck_xxx |
WC_CONSUMER_SECRET | for wc_* tools | cs_xxx |
Create the WooCommerce keys in WooCommerce → Settings → Advanced → REST API → Add key with Read permission. search_posts works without keys against any public WordPress site.
The keys are sent to your own store over HTTPS as REST query auth. Use HTTPS, and give the key Read access only.
Use with Claude Desktop / Claude Code
Add to your MCP client config (e.g. claude_desktop_config.json):
{
"mcpServers": {
"woocommerce": {
"command": "node",
"args": ["/absolute/path/to/woocommerce-mcp/dist/index.js"],
"env": {
"WP_URL": "https://shop.example.com",
"WC_CONSUMER_KEY": "ck_xxx",
"WC_CONSUMER_SECRET": "cs_xxx"
}
}
}
}
Then ask things like "What were last month's WooCommerce sales?" or "List the 5 most recent orders that are on hold."
Docs on wppoland.com
- WooCommerce MCP open source (read-only): release and ops guide - npm scope, registry, Glama, and how we ship updates without write tools
Articles (off-site)
Field notes published on DEV (not duplicates of wppoland.com pages):
- A read-only MCP server for WooCommerce: what AI agents actually need from a store
- Syncing a wholesaler's API into WooCommerce without overselling or melting the server
- Twelve months after migrating wppoland.com from WordPress to Astro on Cloudflare Pages
Show HN: discussion
Verify
npm run check # builds, then asserts all five tools register (no network/credentials needed)
Notes
- Node 18+ (uses the built-in
fetch). - Logs go to stderr so they never corrupt the stdio MCP protocol on stdout.
- API errors are surfaced with the store's message; credentials are never echoed.
License
MIT © WPPoland
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
