guides•Last updated: 2026-09-02

Security & Sandboxing

Security architecture in More MCP, input sanitization, safe REST handling, and recommendations for dev vs staging vs live sites.

Security Architecture

Giving an AI assistant access to your website requires deliberate guardrails. More MCP is built from the ground up with defensive security defaults.

Key Security Pillars

1. No Third-Party Relays

Unlike cloud-hosted AI bridges, More MCP does not route your credentials, database contents, or prompts through an intermediary SaaS server. Communication is peer-to-peer between your AI client and your WordPress server over TLS.

2. Cryptographic Token Storage

  • API keys are hashed with SHA-256 before being stored in the database.
  • Even with direct read access to the wp_options or wp_more_mcp_keys table, an attacker cannot retrieve the plaintext API keys.
  • Revoking a compromised key takes effect instantly without server restarts.

3. Native Data Sanitization

Every parameter passed into a More MCP tool is validated against JSON schema and sanitized using standard WordPress functions:

  • HTML text: Filtered through wp_kses_post() or custom allowed-tag arrays.
  • Slugs: Sanitized via sanitize_title().
  • Numerical IDs: Cast explicitly using absint().
  • SQL queries: Run via $wpdb->prepare() with parameterized placeholders.

4. High-Impact Tools are Opt-In

Tools capable of uploading arbitrary zip archives, editing PHP files directly, or activating unvetted plugins are locked behind explicit admin toggles in More MCP -> Settings -> Security. By default, arbitrary code evaluation is disabled.

Environment Recommended Configuration
Local Dev (LocalWP, Docker, DDEV) Full tool access enabled. Code execution allowed for rapid prototyping.
Staging Site Standard tool access. Read-only + standard destructive tools. Recommended for AI reviews.
Live Production Read-only tools enabled by default. Require explicit human confirmation for destructive tools. Keep file-editing disabled.

Disabling More MCP

If you ever need to disable AI access immediately:

  1. Deactivate the plugin from Plugins -> Installed Plugins.
  2. Deactivation immediately unregisters all REST routes (/wp-json/more-mcp/*).
  3. Your database tables and content remain completely intact.