WP HealthKit is a Model Context Protocol (MCP) server: Security audits for WordPress plugins and themes — 62 verification layers, fix plans and SBOMs. Because it speaks the Model Context Protocol, AI assistants can use WP HealthKit as a set of callable tools instead of you copy-pasting between apps.
You can run WP HealthKit two ways: connect to the hosted endpoint at https://mcp.wphealthkit.com/mcp with no local install, or run it on your own machine via the npm package @wphealthkit/mcp-server. Configuration happens through environment variables — you'll need WPHK_API_KEY. The current release is v0.6.4, published under the MIT license, with source at BuiltByGo/wphealthkit-mcp on GitHub.
On mcp.site, WP HealthKit sits in the Security category. Any MCP client can use it — Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Zed among them — via the install snippets below. If you maintain WP HealthKit for wphealthkit.com, claim this listing to verify ownership, earn the Verified badge, and keep the details current.