Our take, with sources
Articles
Opinion pieces, grounded in the primary spec text — not summaries of summaries. Every claim links back to the source so you can check it yourself.
What WebMCP’s Security Model Actually Covers — And Where It’s Still a TODO
The spec names real risks — tool poisoning, output injection, over-parameterization — but says up front it can’t define precise mitigations. Here’s what that means in practice.
How WordPress Sites Should Handle WebMCP’s Security Gaps
The spec documents the risks and leaves the policy to implementers. A concrete approach for what a WordPress site actually needs to gate, annotate, and refuse.
Check your own site next
Free, instant, and it works whether or not you run WordPress — though that's where the fixes are one click away.
Scan your site