Model Context Protocol (MCP) server for Strapi CMS - AI-powered content management with natural language. Create, manage, and publish blog
Elementor Mcp Agent is installed from its publisher's own source and answers where it runs, so this marketplace is not in the path of a single call. There is no address here to send one to, and a panel that pretended otherwise would be showing you an answer we made up. Install it and call it from your own client — the Installation tab has the entry for each one.
Open InstallationWhat it does
Agentic MCP server for WordPress Elementor — multi-site management, safe Elementor data editing, template import/export, CSS flush, version tracking. Built for agencies running many client sites.
Quickstart
# 1 — run it from where its publisher ships it
npx -y elementor-mcp-agent
# 2 — ask your agent something
> Agentic MCP server for WordPress Elementor — multi-site management, safe Elementor data editing, template import/export, CSS flush, version
Elementor Mcp Agent is free: there is no plan to choose, no cap to set and nothing that can bill you.
Collected from a public index. Nobody has claimed this account, so nothing here was written by its author — claim it if it is yours.
Where are you running it?
Every route below installs the same thing and ends at the same approval screen. This one runs on your machine: your client starts Elementor Mcp Agent as a process under your own user, with your files and your network, so the tool surface below is what it can do to your computer rather than to a server somewhere else. It is scanned, signed and pinned to the version you choose — read the surface before you approve it.
This is a public server: you run it yourself and this marketplace is not in the path. Claude Code registers it in one command.
claude mcp add elementor-mcp-agent -- npx -y elementor-mcp-agentReconnect, or start a new session, and the tools appear in the model’s tool list.
Nothing is required, but it can take ELEMENTOR_MCP_SITES, ELEMENTOR_MCP_CONFIG_PATH, ELEMENTOR_MCP_DEFAULT_SITE_ID if you want to set them.
One config entry your client uses to start the process locally. A local server runs with your file system and your network, which is why it is priced without metering.
34 tools, with what each one reads, writes and reaches shown before you agree — the same list on every route above. Read the tool surface.
Tool surface
What the model actually sees. Descriptions are diffed on every release — see version history.
List pages built with Elementor (have _elementor_edit_mode =
Takes no parameters.
Fetch a page
Takes no parameters.
Flat list of every widget in a page with id, type, parent path, and an excerpt of the first text setting (for spot-checking before find/replace).
Takes no parameters.
List all global widgets on a site (Elementor library entries of type
Takes no parameters.
Validate a page is safe to edit. Checks: page exists, is Elementor-built, data parses cleanly, references valid global widgets, isn
Takes no parameters.
Find/replace plain text in every widget on one page. TWO-CALL FLOW: dry-run returns match_count + detailed widget hits + confirmation_token. Second call with token applies the change with auto-backup + JSON validation + auto-rollback if validation fails + CSS flush.
Takes no parameters.
List timestamped backups of a page
Takes no parameters.
Restore a page
Takes no parameters.
Duplicate an Elementor page within the same site. Creates a new draft page, copies _elementor_data + _elementor_page_settings + _elementor_edit_mode, flushes CSS.
Takes no parameters.
Fetch a single widget
Takes no parameters.
Shallow-merge a partial settings object into one widget. Backs up the page first, validates the result, auto-flushes CSS, then re-reads the page and verifies the patch persisted (matches_requested in the response). Two-call confirmation.
Takes no parameters.
Remove a widget from a page by id. Two-call confirmation. Backs up before deleting; re-reads to confirm the widget is gone.
Takes no parameters.
Duplicate a widget in place (right after the original). The clone gets a new id. Re-reads to confirm the clone persisted. Two-call confirmation.
Takes no parameters.
Replace a widget
Takes no parameters.
Append a new widget to a parent container (section, column, or container) on a page. Re-reads to confirm the new widget exists under the parent. Two-call confirmation.
Takes no parameters.
Move a widget to a different parent (or different position in the same parent). Re-reads to confirm new parent. Two-call confirmation.
Takes no parameters.
Find/replace plain text in every Elementor page on a single site. TWO-CALL FLOW: dry-run returns per-page match_count + total + confirmation_token. Apply iterates each page (auto-backup + validate + flush per page). Slower than wp_search_replace but works without SSH and gives per-page granularity.
Takes no parameters.
Find/replace plain text across every Elementor page of every site in the pool. Same flow as bulk_find_replace_site but iterates across sites. Returns per-site + grand-total summary. Dry-run first; second call applies. Use sparingly — this is the nuclear option.
Takes no parameters.
Restore a page from a JSON backup file (created by ANY earlier op with backup_to_file=true or by direct fullBackup with to_file). Requires the file_path returned by that backup. Two-call confirmation.
Takes no parameters.
List every WordPress site configured. Best called first in a session.
Takes no parameters.
Verify connectivity + authentication to a WordPress site. Returns user identity + WP/Elementor/Elementor Pro versions if accessible.
Takes no parameters.
Comprehensive site health snapshot: WP/PHP/Elementor versions, disk space (if SSH), plugin count, theme info. Aggregates multiple REST calls into a single overview.
Takes no parameters.
List Elementor library entries on a site: saved sections, pages, popups, headers/footers (Theme Builder Pro), single/archive templates (Theme Builder Pro), and global widgets. Type filter narrows results.
Takes no parameters.
Export an Elementor template (section, page, header, footer, etc.) as a portable JSON object. Output goes into import_elementor_template on another site.
Takes no parameters.
Import a portable template JSON (output of export_elementor_template) into a target site as a new library entry. Useful for cross-site template sync.
Takes no parameters.
Copy the _elementor_data + _elementor_page_settings of a SOURCE template (or page) onto a TARGET page on the same site. Backs up the target first. Use to apply a section/page template to an existing draft.
Takes no parameters.
Fleet-wide Elementor version audit. For every site, fetches installed Elementor/Pro versions and compares against wordpress.org latest. Flags outdated installs.
Takes no parameters.
Capture a PNG screenshot of a page
Takes no parameters.
Compare two screenshot files via SHA-256 hash equality and size delta. Quick way to spot whether a page changed visually after an edit. For pixel diffs, use a dedicated tool externally.
Takes no parameters.
Execute an arbitrary wp-cli command on a site via SSH. The
Takes no parameters.
Run
Takes no parameters.
Flush Elementor
Takes no parameters.
List installed plugins on a site with name, version, status (active/inactive), and update_version (if outdated). Uses WP-CLI for accurate version data including update_version.
Takes no parameters.
Update one or more plugins on a site to their latest version. Requires confirmation token (uses wp-cli).
Takes no parameters.
- Every tool, no call limit
- No card, no account needed
- Source published under a licence you can read
- Runs on your machine — nothing of it reaches our gateway
- Nothing to cap, because nothing bills
What counts against your monthly calls
| Tool | Unit | Calls used | Out of the allowance |
|---|
Nothing here is billable. Elementor Mcp Agent costs nothing to install and nothing to call, at any volume.
Two independent axes, because powerful and malicious are different questions. The grade is threat only. The capability level is blast radius, and it is never a penalty on the grade — it is priced as one subtract-only term in the score, where you can see it.
| Term | Level | What it prices | Points |
|---|---|---|---|
| −1.2 | |||
| capability-exposure | high | capability blast radius (high) — client exposure if the model is manipulated | −6 |
| verification-discount | repo | publisher verification (public source) — no provenance, but the source is public and inspectable | −1 |
| coverage-honesty | source | inspection depth (source) — how much of the target the scan could see | −0 |
What the scan could actually read
A grade is only as meaningful as its coverage, so the scanner publishes its own depth before it publishes its result.
Tools were statically extracted from the published source (34 recovered), not enumerated from a running server. Tool-poisoning, Unicode-smuggling, capability and toxic-flow analysis ran on this inferred surface, but a mis-parsed registration could be missed or mis-attributed, so tool-derived findings are capped below “confirmed”. To grade the real runtime surface, scan the running server: --command "npx -y <package>".
Capability — what it could do if the model were manipulated
Tags derived from each tool’s schema and the implementation, not from what the tool calls itself. high is the level these add up to.
| Tool | Capability tags | Why the tag was assigned |
|---|---|---|
| list_sites | no tags | |
| ping_site | no tags | |
| site_health | no tags | |
| list_elementor_pages | no tags | |
| read_page_elementor | untrusted-input | |
| list_widgets_in_page | no tags | |
| list_global_widgets | no tags | |
| preflight_check | no tags | |
| elementor_find_replace | no tags | |
| list_elementor_backups | no tags | |
| restore_elementor_backup | no tags | |
| duplicate_elementor_page | no tags | |
| list_elementor_templates | no tags | |
| export_elementor_template | no tags | |
| import_elementor_template | no tags | |
| apply_template_to_page | untrusted-input | |
| wp_cli_run | no tags | |
| wp_search_replace | no tags | |
| wp_elementor_flush_css | no tags | |
| wp_plugin_list | no tags | |
| wp_plugin_update | no tags | |
| screenshot_page | no tags | |
| compare_screenshots | no tags | |
| check_elementor_versions | no tags | |
| read_widget | untrusted-input | |
| update_widget_settings | no tags | |
| delete_widget | no tags | |
| duplicate_widget | no tags | |
| swap_widget_type | no tags | |
| add_widget | no tags | |
| move_widget | no tags | |
| bulk_find_replace_site | no tags | |
| fleet_find_replace | no tags | |
| restore_from_file | no tags |
Toxic-flow graph
The lethal trifecta, checked as a graph rather than as a checklist: untrusted input, a sensitive source and an external sink have to meet before there is a path worth worrying about.
The public result for this release does not print the flow graph, so there is nothing to show here. That is not the same as "no paths were found": what the scan did read is above, under coverage.
Supply chain and provenance
This is the first scan of this surface here, so there is nothing yet to compare it against.
Every result on this tab comes from one deterministic pass over the published package — offline, rule by rule, and auditable line by line above. Same methodology version, same bytes, same score.
Release history
Pinned to 1.3.0 — the install command below asks for that release. A pin is part of an install, so it is kept for this visit and written down when you install.
No release note was published with this version.
Only accounts with at least 50 real tool calls against this server in the last 90 days can post. Ratings are weighted by how much the reviewer actually uses it, and publishers can reply once per review.
Writing one takes an account with at least 50 real tool calls against Elementor Mcp Agent in the last 90 days. That is the whole gate — there is no other way to post, which is why the counts beside each review are worth reading.
Nobody has reviewed this listing. The rating on the card is the mean of the reviews written here and nothing else, so there is no rating until somebody writes the first — which takes an account with 50 real tool calls against it.