Security & Sandboxing
Security architecture in More MCP, input sanitization, safe REST handling, and recommendations for dev vs staging vs live sites.
Security Architecture
Giving an AI assistant access to your website requires deliberate guardrails. More MCP is built from the ground up with defensive security defaults.
Key Security Pillars
1. No Third-Party Relays
Unlike cloud-hosted AI bridges, More MCP does not route your credentials, database contents, or prompts through an intermediary SaaS server. Communication is peer-to-peer between your AI client and your WordPress server over TLS.
2. Cryptographic Token Storage
- API keys are hashed with SHA-256 before being stored in the database.
- Even with direct read access to the
wp_optionsorwp_more_mcp_keystable, an attacker cannot retrieve the plaintext API keys. - Revoking a compromised key takes effect instantly without server restarts.
3. Native Data Sanitization
Every parameter passed into a More MCP tool is validated against JSON schema and sanitized using standard WordPress functions:
- HTML text: Filtered through
wp_kses_post()or custom allowed-tag arrays. - Slugs: Sanitized via
sanitize_title(). - Numerical IDs: Cast explicitly using
absint(). - SQL queries: Run via
$wpdb->prepare()with parameterized placeholders.
4. High-Impact Tools are Opt-In
Tools capable of uploading arbitrary zip archives, editing PHP files directly, or activating unvetted plugins are locked behind explicit admin toggles in More MCP -> Settings -> Security. By default, arbitrary code evaluation is disabled.
Recommended Environment Matrix
| Environment | Recommended Configuration |
|---|---|
| Local Dev (LocalWP, Docker, DDEV) | Full tool access enabled. Code execution allowed for rapid prototyping. |
| Staging Site | Standard tool access. Read-only + standard destructive tools. Recommended for AI reviews. |
| Live Production | Read-only tools enabled by default. Require explicit human confirmation for destructive tools. Keep file-editing disabled. |
Disabling More MCP
If you ever need to disable AI access immediately:
- Deactivate the plugin from Plugins -> Installed Plugins.
- Deactivation immediately unregisters all REST routes (
/wp-json/more-mcp/*). - Your database tables and content remain completely intact.