guides•Last updated: 2026-09-02

Permissions & Destructive Actions

How More MCP enforces WordPress capability checks and implements confirmation safety gates for destructive operations.

Two-Tier Security Model

When an AI agent executes a tool through More MCP, the request passes through two distinct enforcement gates:

  1. WordPress Core Capabilities (current_user_can): Verifies that the authenticated user actually has rights to perform the requested action.
  2. Destructive Tool Confirmation: Forces confirmation prompts before high-risk changes take effect.

1. WordPress Capability Checks

More MCP never bypasses WordPress permission controls. Every tool call sets up the authenticated user session and runs native capability checks:

Tool Category Required WordPress Capability
wp_posts_* (publish) publish_posts or publish_pages
wp_users_* (edit) edit_users
wp_options_update manage_options
wc_products_* manage_woocommerce
def_scan / wf_scan manage_options

If an API key is tied to an Editor account, an AI request attempting to call wp_options_update or wp_plugins_activate will fail immediately with 403 Forbidden: Insufficient permissions.

2. Destructive Operations Flagging

Of the 107 baseline tools, exactly 26 are designated Destructive. Examples include:

  • wp_delete_post
  • wp_delete_user
  • wp_drop_table
  • wp_update_option
  • wc_delete_order

How Clients Handle Destructive Tools

In the MCP protocol, tool definitions publish metadata about whether they are state-altering. Modern clients like Claude Desktop and Claude Code use this metadata to pause execution and prompt the human operator:

Claude wants to call: wp_delete_post
Parameters: { "id": 1420, "force": true }
Allow this action? [Yes / No]

This prevents accidental deletion loops or unintended bulk edits.

Audit Logs

Every tool execution, whether read-only or destructive, is recorded in your local WordPress database table (wp_more_mcp_audit_log):

  • Timestamp: Exact execution time
  • Tool Name: For example, wp_posts_update
  • User ID: The authenticated user or key ID
  • Execution Status: Success, Failed, or Blocked
  • Parameters: Sanitized input parameters

You can review recent activity anytime under More MCP -> Audit Log.