Agent skill

Maintain Wordpress

by hostinger in hostinger/api-mcp-server

Keep WordPress sites on Hostinger web hosting updated and secure: checks core, plugin and theme versions, known vulnerabilities and install health on one site or every site in the account, reports…

MITAuto-check passed

Install Maintain Wordpress

skills CLI
$ npx skills add hostinger/api-mcp-server --skill maintain-wordpress -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hostinger/api-mcp-server maintain-wordpress --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hostinger/api-mcp-server.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/maintain-wordpress .claude/skills/maintain-wordpress && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
maintain-wordpress
GitHub stars
159
Token cost
~1.4k tokens
SKILL.md length
603 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Keep WordPress sites on Hostinger web hosting updated and secure: checks core, plugin and theme versions, known vulnerabilities and install health on one site or every site in the account, reports…

  • Works in 6 steps: Find the installs → Check (read-only) → Report before changing anything → …
  • SKILL.md covers Calling the operations, 1. Find the installs, 2. Check (read-only) and 3. Report before changing…, plus 4 more sections
  • Calls curl

What it does

Maintain Wordpress is an agent skill from hostinger/api-mcp-server. Keep WordPress sites on Hostinger web hosting updated and secure: checks core, plugin and theme versions, known vulnerabilities and install health on one site or every site in the account, reports what needs doing, applies updates in a safe order, and confirms each site still loads. Also covers cache purges, the Memcached object cache, maintenance mode and one-click wp-admin login links. Triggers: update my WordPress, update plugins, are my WordPress sites secure, WordPress vulnerabilities, outdated plugins or…

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with WordPress. The licence is MIT.

Example prompts

  • “/maintain-wordpress”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Find the installs
  2. Check (read-only)
  3. Report before changing anything
  4. Back up first
  5. Update, one site at a time
  6. Performance and access

What it can do on your machine

Read from SKILL.md and the folder at commit b0e1bc3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Maintain Wordpress loads about 1.4k tokens when it runs. Until then it costs about 152 tokens; SKILL.md has 603 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~152
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hostinger/api-mcp-server at commit b0e1bc3, republished under its MIT licence (© hostinger). 603 words, ~1,385 tokens.

Download SKILL.mdSave it as .claude/skills/maintain-wordpress/SKILL.md (or your agent's skills folder).
name
maintain-wordpress
description
Keep WordPress sites on Hostinger web hosting updated and secure: checks core, plugin and theme versions, known vulnerabilities and install health on one site or every site in the account, reports what needs doing, applies updates in a safe order, and confirms each site still loads. Also covers cache purges, the Memcached object cache, maintenance mode and one-click wp-admin login links. Triggers: update my WordPress, update plugins, are my WordPress sites secure, WordPress vulnerabilities, outdated plugins or themes, WordPress maintenance, speed up WordPress, log me into wp-admin.

Maintain WordPress

Check first, report, then update only what the user approves — one site at a time, proving each still loads before moving to the next.

Calling the operations

  • Read the inputSchema that search returns before the first call of each operation. If a name below is rejected as unknown, search for what the step does (e.g. "wordpress plugins update").
  • Batch reads with multi-execute (up to 20 steps a batch). Batches chain operations from one server only — the Hostinger Connector runs wordpress, hosting and agency-hosting as separate servers.
  • Updates, activations, uninstalls and core changes are queued jobs: a success response means "queued". Poll the matching read operation every 10–20 s until the change shows; never re-send the write.

1. Find the installs

  • One site: wordpress_installations_list with domain (substring match — take the exact entry). Every site: wordpress_installations_list without filters, adding ownership: "all" to include sites the user manages for others.
  • Keep id (the software parameter of every wordpress_* call), username, domain, directory, is_valid and validation_error.
  • Agency Plan WordPress sites come from agency-hosting_websites_list-plan with website_types: ["wordpress"]. When wordpress_installations_list does not include them, only agency-hosting_wordpress_settings and core version changes (agency-hosting_wordpress_list-versions, agency-hosting_wordpress_change-version) are available; plugins and themes are updated from wp-admin.

2. Check (read-only)

Per install:

  • wordpress_installations_show-core-version — core version and the known vulnerabilities that affect it.
  • wordpress_installations_list-core-updates — available core versions.
  • wordpress_plugins_list-installed — status, update (the newer version, when there is one) and vulnerabilities[] with fixed_in.
  • wordpress_themes_list-installed — the same for themes.

Four steps per install fit five installs in one batch. For an install with is_valid: false, run wordpress_installations_check-if-are-valid with force: true for a fresh reason and leave it out of updates — a broken install is the troubleshoot-website skill's job.

3. Report before changing anything

## example.com (WordPress 6.8.1)
Vulnerable: contact-form-x 5.2 → fixed in 5.3 (update available)
Vulnerable, inactive: old-slider 1.0 — no fix; uninstall recommended
Updates: core 6.8.1 → 6.8.3 (minor), 4 plugins, 1 theme

Vulnerable items come first. A vulnerable plugin without a fix, or an inactive one, is better removed with wordpress_plugins_uninstall than left installed — inactive code on disk can still be reached. Ask which updates to apply.

4. Back up first

The API has no backup operation. Before updating, ask the user to create a backup in hPanel or confirm the latest automatic one is recent enough. Say it plainly; the user may choose to go ahead without one.

Show full SKILL.md (247 more words)Show less

5. Update, one site at a time

  1. Plugins that fix a vulnerability — wordpress_plugins_update with their slugs.
  2. The remaining approved plugins, then themes with wordpress_themes_update.
  3. Core with wordpress_installations_update-core: minor: true for patch releases; a major version only when the user asks for it.

For a busy site the user may want wordpress_maintenance_toggle with enabled: true during the run — and it is always turned off again afterwards, even when something failed.

After each site:

  1. wordpress_litespeed-cache_purge-lite-speed.
  2. curl -s -o /dev/null -w "%{http_code}\n" https://DOMAIN/ and the same for https://DOMAIN/wp-login.php — both should be 200 with no PHP error in the body.
  3. wordpress_installations_check-if-are-valid with force: true.

When a site breaks: stop the run, deactivate the plugin updated last with wordpress_plugins_deactivate, check again, and report which update caused it before touching any other site.

6. Performance and access

  • Page cache: wordpress_litespeed-cache_show-lite-speed-status; purge after design or content changes.
  • Object cache: wordpress_object-cache_show-memcached-status, then wordpress_object-cache_toggle-memcached with enabled: true — the usual quick speed-up.
  • PHP version: hosting_php_get is large (around 25 KB), so read it only when the user asks about PHP. PHP 8.x is markedly faster than 7.x; confirm plugin compatibility before hosting_php_update-version.
  • wp-admin: wordpress_login_create-links returns temporary one-click login links. Give them to the user only; never store or reuse them.
  • Hostinger's own plugins update with wordpress_plugins_update-hostinger (slug).

Many sites

Tell the user how many installs there are before starting. Check in batches, keep one running report, and update site by site so a failure stops the run with the rest untouched.

© hostinger, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/maintain-wordpress of hostinger/api-mcp-server.

Open the folder on GitHubat commit b0e1bc3

Compare with similar skills

Maintain Wordpress next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Maintain Wordpress compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Maintain Wordpress this skillhostinger/api-mcp-server159—~1.4kAutomated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence
Wp Block Developmentgambitph/Stackable3503 repos~1.6kAutomated safety check: PassGPL-3.0
Postizgitroomhq/postiz-agent5052 repos~7.9kAutomated safety check: PassAGPL-3.0
Wp Performance Reviewelvismdev/claude-wordpress-skills2341 repos~4.5kAutomated safety check: PassMIT
Wp Interactivity APIAutomattic/agent-skills2112 repos~1.5kAutomated safety check: PassNone

Similar skills

  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Wp Block Development

    gambitph/Stackable

    A skill your agent uses when developing WordPress (Gutenberg) blocks: block.json metadata, registerblocktype(frommetadata), attributes/serialization, supports, dynamic rendering…

    350 GitHub starsUsed in 3 repos~1.6k tokens
    Auto-check passed
  • Postiz

    gitroomhq/postiz-agent

    Postiz is a tool to schedule social media and chat posts to 28+ channels X, LinkedIn, LinkedIn Page, Reddit, Instagram, Facebook Page, Threads, YouTube, Google My Business, TikTok, Pinterest…

    505 GitHub starsUsed in 2 repos~7.9k tokens
    Writing & ContentAuto-check passed
  • Wp Performance Review

    elvismdev/claude-wordpress-skills

    WordPress performance code review and optimization analysis.

    234 GitHub starsUsed in 1 repo~4.5k tokens
    Business, Finance & HRAuto-check passed
  • Wp Interactivity API

    Automattic/agent-skills

    A skill your agent uses when building or debugging WordPress Interactivity API features (data-wp- directives, @wordpress/interactivity store/state/actions, block viewScriptModule integration…

    211 GitHub starsUsed in 2 repos~1.5k tokens
    DevelopmentAuto-check passed
  • Wp Env

    WordPress/agent-skills

    A skill your agent uses when setting up, configuring, or troubleshooting local WordPress development environments with @wordpress/env (wp-env).

    2.2k GitHub stars~2.2k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from hostinger/api-mcp-server

All 8 skills in this repo
  • Audit Hosting

    hostinger/api-mcp-server

    Audit a Hostinger web hosting account (Shared, Cloud and Agency plans) and report what needs attention: every plan and website, SSL problems, broken or vulnerable WordPress installs, failed Node.js…

    159 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Connect Domain

    hostinger/api-mcp-server

    Connect a custom domain to a website on Hostinger web hosting (Shared, Cloud or Agency plans) end to end: attach the domain to the site, point DNS at Hostinger without breaking existing email or…

    159 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Deploy To Hosting

    hostinger/api-mcp-server

    Deploy an existing project to a website on Hostinger web hosting (Shared, Cloud or Agency plans) and keep it deployed: picks the right deploy for static sites, Node.js apps (Next.js, Nuxt, Express…

    159 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check: notes
  • Hostinger Headless Entry

    hostinger/api-mcp-server

    Build a complete website on Hostinger from a single prompt — hosting, domain, and (optionally) a store with real checkout or a blog/CMS the owner edits in WordPress.

    159 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Migrate To Hosting

    hostinger/api-mcp-server

    Move an existing website from another host to Hostinger web hosting (Shared, Cloud or Agency plans) without downtime: WordPress sites from a files archive and SQL dump, static and PHP sites from an…

    159 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Troubleshoot Website

    hostinger/api-mcp-server

    Diagnose and fix a website on Hostinger web hosting (Shared, Cloud or Agency plans) that is down, slow, erroring, insecure or failing to build.

    159 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Maintain Wordpress

What does Maintain Wordpress do?

Keep WordPress sites on Hostinger web hosting updated and secure: checks core, plugin and theme versions, known vulnerabilities and install health on one site or every site in the account, reports…. Maintain Wordpress is an agent skill from hostinger/api-mcp-server. Keep WordPress sites on Hostinger web hosting updated and secure: checks core, plugin and theme versions, known vulnerabilities and install health on one site or every site in the account, reports what needs doing, applies updates in a safe order, and confirms each site still loads.

How do I install Maintain Wordpress in Claude Code?

Run `npx skills add hostinger/api-mcp-server --skill maintain-wordpress -a claude-code`. Or copy the skill folder (skills/maintain-wordpress in hostinger/api-mcp-server) into .claude/skills/maintain-wordpress in your project. Claude Code loads it when a task matches its description.

How do I install Maintain Wordpress in Codex?

Run `npx skills add hostinger/api-mcp-server --skill maintain-wordpress -a codex`. Or copy the skill folder (skills/maintain-wordpress in hostinger/api-mcp-server) into .agents/skills/maintain-wordpress in your project. Codex loads it when a task matches its description.

Can I use Maintain Wordpress in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hostinger/api-mcp-server --skill maintain-wordpress -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/maintain-wordpress, .gemini/skills/maintain-wordpress, .github/skills/maintain-wordpress and .opencode/skills/maintain-wordpress in your project.

What does Maintain Wordpress need to run?

Going by SKILL.md and its folder, Maintain Wordpress needs the command-line tools its instructions call (curl).

Does Maintain Wordpress access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Maintain Wordpress safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Maintain Wordpress use?

Maintain Wordpress is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Maintain Wordpress use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Maintain Wordpress?

Skills that share tags, products or a category with Maintain Wordpress: WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Wp Block Development (gambitph/Stackable, 350 stars), Postiz (gitroomhq/postiz-agent, 505 stars) and Wp Performance Review (elvismdev/claude-wordpress-skills, 234 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Maintain Wordpress?

hostinger (a GitHub organization) maintains it in hostinger/api-mcp-server, which has 159 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 6, 2026.

Source: hostinger/api-mcp-server on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.