Model or dataset
use-novamira/novamira avatar
use-novamira/novamira

Novamira: an MCP server that hands AI agents the WordPress runtime

MCP server that gives AI agents full access to WordPress through PHP execution and filesystem operations

675 stars105 forksPHPAGPL-3.0

At a glance

What is it?
Novamira is an AGPL-3.0 WordPress plugin and MCP server that lets AI clients execute PHP, run WP-CLI and edit files on a live installation. It is built for staging sites, and the documentation says so itself.
Who is it for?
Adopt Novamira if you run a WordPress staging or local site and want an agent to test real code against the real runtime instead of guessing from a snippet. Do not adopt it on a production site, and do not adopt it if you need an audit trail of what an agent changed, because the README documents no rollback or change log.
Can I use it commercially?
Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
Is it still maintained?
Yes. The repository last received commits 13 days ago.
What is it written in?
Mainly PHP, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 17, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The gap Novamira fills between an AI client and a running WordPress site

Most AI coding assistants can write WordPress code, but they cannot see the site it will run on. They do not know which plugins are active, which theme is loaded, what the database schema looks like after three years of migrations, or whether a hook fires before or after another plugin's callback. The result is code that reads correctly and fails on contact.

Novamira closes that gap by exposing the WordPress installation itself as a tool surface. According to the README, agents can run PHP and WP-CLI commands, inspect the database, manage files, and read the active plugins and theme. That is a different proposition from generating a snippet for a human to paste in. The agent works against the real site.

The intended audience is narrow and stated plainly. The README carries a warning block: "For dev and staging environments. With backups. Always." Anyone evaluating Novamira should treat that as the project's own scope statement, not as boilerplate. If you are looking for a way to let an agent edit a live storefront, this is the wrong tool and the maintainers say so first.

How the connection works: direct, local, and not proxied

Novamira is a WordPress plugin that also acts as an MCP server. The connection runs directly between your AI client and your WordPress installation. The README states that Novamira is not a hosted proxy and that requests do not pass through Novamira servers. That design choice matters for two reasons: your site content and database queries never leave your infrastructure, and the availability of the connection depends on your own host rather than a third party.

The repository layout reflects a PHP-first project with a JavaScript surface. The top level holds novamira.php, includes/, src/, stubs/, tests/, composer.json and composer.lock, which is the shape of a plugin that ships PHP classes and a Composer dependency tree. The package.json is marked private and defines only two scripts, both built around wp-scripts and a single entry point, src/chat/index.tsx, compiled into includes/assets/chat/index.js. In other words, the chat interface is a thin front end; the substance is server-side PHP.

Authentication is handled through OAuth and WordPress Application Passwords, per the README. The README also lists a recoverable sandbox for new PHP files, which suggests that file creation can be isolated from the rest of the installation, though the README does not describe how the sandbox is scoped or what happens to files that escape it.

Installing Novamira and connecting a first MCP client

The README is explicit that you should not install from GitHub's source archive. The release ZIP is the artifact to use, because the source archive does not include the bundled Composer dependencies the MCP server requires. Download it from the project's download page, then upload it through the WordPress admin.

Inside WordPress, go to Plugins, then Add New, then Upload Plugin. Choose the ZIP and activate it.

bash
# No shell install is documented for the plugin itself.
# Download the release ZIP from https://novamira.ai/download/
# then upload it in wp-admin under Plugins -> Add New -> Upload Plugin.

After activation, open the Novamira configuration screen, enable AI Abilities, and follow the instructions for your client and authentication method.

bash
# In wp-admin: Novamira -> Configuration
# 1. Enable AI Abilities.
# 2. Choose an authentication method (OAuth or WordPress Application Password).
# 3. Follow the client-specific connection instructions shown on that screen.

The README names the compatible clients: Claude, Codex, Cursor, Gemini CLI, Antigravity, VS Code with GitHub Copilot, and other MCP clients. If you work from a terminal, the separate Novamira CLI provides a guided connection for Claude Code, Codex CLI and Gemini CLI. There is also Novamira Visual, described as an experimental browser workspace where you can watch an agent work in WordPress; treat the experimental label as meaningful.

Requirements before you start: WordPress 6.9 or later, PHP 8.0 or later, a WordPress administrator account, and an MCP-compatible client. HTTPS is required for remote connections; local development environments are supported without it. The README points to a quick start guide and a connection troubleshooting page for the full flow, which is where you should go if the client does not appear after configuration.

Where Novamira is the wrong choice

The obvious limitation is the one the project advertises. PHP execution with access to $wpdb, loaded plugins and themes is, by construction, the ability to do anything an administrator can do, including breaking the site. There is no described permission layer that restricts an agent to, say, reading posts but not altering options. The README does not document rollback, change logging, or an approval step before a write. If your workflow requires a review gate on every mutation, Novamira does not provide one out of the box.

The second limitation is environmental. WordPress 6.9 and PHP 8.0 are the floors. Sites on older PHP, which is common on shared hosting, cannot run it at all. Remote connections require HTTPS, so a site without a valid certificate is limited to local use.

The third is the install path itself. Because the GitHub source archive lacks bundled Composer dependencies, anyone who clones the repository and zips it will get a plugin that does not work, and the failure may not be obvious until the MCP server refuses to start. That is a real friction point for developers who prefer git-based deployment over uploading ZIP files.

Finally, the README does not document what happens to the sandbox when a file is created outside it, nor how the recoverable sandbox is bounded. If sandboxing is the reason you are considering Novamira over hand-written PHP snippets, that gap is worth resolving in the documentation before you rely on it.

Novamira compared with a hosted WordPress MCP proxy

The alternative most people will weigh is a hosted MCP service for WordPress, where a third-party server brokers the connection between your AI client and your site. The architectural difference is where the request travels. A hosted proxy terminates the MCP session on infrastructure you do not control, then reaches into your site through an API or a companion plugin. Novamira runs the MCP server inside the plugin, so the session terminates on your own installation.

That changes the failure modes. A hosted proxy can go down independently of your site, and its operator can see the traffic. Novamira cannot go down separately from your WordPress install, and the README states your requests do not pass through Novamira servers. The trade is operational: with Novamira you own the upgrade path, the PHP version, the certificate and the backup discipline. With a hosted service you own less and can see less.

A second alternative is simply not using an MCP server. Write the PHP yourself, test it on staging, deploy it. That is slower and requires a developer, but it produces code a human reviewed line by line. Novamira's value is speed of iteration against a real runtime; if your team does not have that bottleneck, the added attack surface buys you little.

Maintenance, licensing and what AGPL-3.0 means here

The repository is not archived, and the last push was on 2026-09-10, with v1.12.3 released on 2026-09-09, v1.12.2 on 2026-09-02 and v1.12.1 on 2026-09-01. That is a tight release cadence across the first ten days of September, and it means you should expect to update the plugin more often than a typical WordPress extension. Budget for that: each update is a ZIP upload through the admin, and the README does not describe an automatic update channel.

The licence is AGPL-3.0-or-later, and the repository carries a LICENSES/ directory alongside the main LICENSE file, which usually signals bundled third-party components under their own terms. AGPL-3.0 is a strong copyleft licence with a network clause: if you modify Novamira and let users interact with it over a network, the licence's obligations extend to those users. Running the plugin unmodified on your own site is the ordinary case and does not raise that question. Modifying it for a client and exposing it publicly does. That is a description of the licence text, not legal advice; if you plan to redistribute a modified build, read the licence or ask a lawyer.

One practical note on cost: the README documents no paid tier and no feature gating. Everything it lists, from PHP execution to Novamira CLI, is described as part of the open-source plugin. The homepage is novamira.ai, and the README links to a download page, documentation, a CLI page and videos there.

Editorial conclusion

Adopt Novamira if you run a WordPress staging or local site and want an agent to test real code against the real runtime instead of guessing from a snippet. Do not adopt it on a production site, and do not adopt it if you need an audit trail of what an agent changed, because the README documents no rollback or change log. Before connecting a client, confirm your WordPress is 6.9 or later, your PHP is 8.0 or later, and that the ZIP you uploaded is the release build rather than the GitHub source archive, which the README says lacks the bundled Composer dependencies the MCP server needs.

Frequently asked questions

Is Novamira free to use?

The project is published under AGPL-3.0-or-later and the README describes no paid tier or gated feature; the plugin, the MCP server and Novamira CLI are all presented as part of the open-source distribution. If you modify and redistribute it, the licence's copyleft terms apply.

How do I install Novamira?

Download the release ZIP rather than GitHub's source archive, then in WordPress go to Plugins, Add New, Upload Plugin and activate it. After activation, open Novamira, then Configuration, enable AI Abilities and follow the client-specific connection instructions. The README notes the source archive omits the bundled Composer dependencies the MCP server needs.

What is Novamira?

It is an open-source WordPress plugin that also acts as an MCP server, letting AI agents run PHP and WP-CLI commands, inspect the database, manage files and read the active plugins and theme. The connection is direct between your AI client and your WordPress installation, not routed through Novamira servers.

Is Novamira safe to run on my site?

The README itself warns that it is for dev and staging environments, with backups, always, because PHP execution gives an agent the same reach as an administrator. Authentication uses OAuth or WordPress Application Passwords, and HTTPS is required for remote connections. The README does not document rollback or change logging, so a staging copy is the safe target.

Does Novamira work with Divi?

The README does not mention Divi or any page builder specifically. It states that agents can read the active plugins and theme and work against WordPress APIs, which would include whatever builder is active, but no builder-specific integration is documented.

Official sources

  1. License: AGPL-3.0
  2. Project website
  3. README
  4. Releases
  5. use-novamira/novamira on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/use-novamira-novamira.svg)](https://hysenlabs.com/projects/use-novamira-novamira)