Field-by-field comparison

Compare the evidence before choosing an MCP.

Each signal stays separate, missing facts remain visible, and the column order follows your selection.

MCPs in this comparison

Uncheck an MCP to remove it. Comparing two or three keeps each signal in its own row.

Open canonical comparison link

Comparable alternatives

Shown only when capability or industry context overlaps.

Side-by-side MCP evidence comparison
Evidence fieldWordPress Remote MCPWatchlist candidateHubSpot MCPMCP100 Selected
Task fit
Best for
  • WordPress developers/operators who need a remote MCP proxy to a WordPress site using the site's existing user/capability model.
  • Querying CRM records, activities, marketing content, and organizational context
  • Creating or updating supported CRM records and activities with confirmation
  • Building managed AI workflows around HubSpot account data
Not ideal for
  • Users who want a zero-configuration hosted WordPress service or who cannot safely grant the AI client the underlying WordPress account's capabilities.
  • Clients that do not support OAuth 2.1 with PKCE
  • Vector or semantic CRM search, which the documented backend does not provide
Avoid when
  • Avoid using a highly privileged WordPress administrator account when lower-privilege credentials can satisfy the workflow.
  • Existing HubSpot user permissions are broader than the intended agent workflow
  • CRM or communication records cannot be shared with the chosen AI client
  • Record creation, email logging, or meeting actions cannot require human approval
Provenance
Provenance details

Ecosystem official

github:automattic · Publisher source ↗

First-party MCP

HubSpot · Publisher source ↗

Maintenance
Maintenance details

Stale

Repo: Not documented

Package: Not documented

Repo: Not documented

Package: Not documented

Popularity evidence
Client coverage
Client coverage detailsNot documented
Claude CodeStreamable HTTP
Claude DesktopStreamable HTTP
CodexStreamable HTTP
VS CodeStreamable HTTP
CursorStreamable HTTP
OpenCodeStreamable HTTP
Client coverage noteLocal stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server.
Access and data
AuthenticationOAuth 2.1 with PKCE is the preferred path; reviewed alternatives include JWT and WordPress Application Passwords.OAuth 2.1 with PKCE is required. A HubSpot MCP auth app supplies client ID, client secret, and registered redirect URL; the user selects an account and grants available permissions.
CostOpen-source proxy; WordPress hosting/plugins/services and AI/model costs can still apply.HubSpot documents the remote MCP server as generally available to all HubSpot accounts without a separate MCP fee. HubSpot subscription features, API limits, integration hosting, and AI-client costs still apply.
PermissionsEffective permissions follow the authenticated WordPress user and the abilities exposed by the backend MCP Adapter.Read access includes CRM records, activities, marketing content, campaigns, and organizational context. Write access includes supported contacts, companies, deals, tickets, line items, products, calls, emails, meetings, notes, and tasks. Every action respects the authenticated HubSpot user's permissions.
Data handlingWordPress content, metadata and action results can transit the proxy and connected AI client/provider. OAuth tokens are stored locally by the proxy and must be protected.HubSpot's hosted MCP service relays authorized CRM and activity data to the MCP client. Sensitive Data accounts block activity objects through MCP. Client credentials, OAuth tokens, retrieved records, and tool results must be protected by the integrating application.
Limitations
Tradeoffs
  • Official WordPress MCP adapter is promising and ecosystem-significant, but self-hosted/plugin-dependent maturity and ability scoping need more evidence.
  • The GA hosted service removes local server maintenance but requires creation and management of an MCP auth app.
  • Available scopes follow current server tools and user-granted permissions; newly added scopes can require reauthorization.
  • HubSpot blocks activity objects through MCP when Sensitive Data is enabled, reducing exposure but also capability.
Risk contextA high-privilege WordPress user can expose broad content/site administration authority to the AI client.CRM and activity tools can expose personal and commercially sensitive data or create consequential customer records and communications. Use a dedicated auth app, narrow user permissions, secure PKCE and token storage, re-review scope changes, and confirm mutations. No MCP100 execution testing is claimed.
Evidence date
Editorial review2026-09-13T00:00:00Z2026-07-24
Candidate evidence2026-09-13T00:00:00Z2026-07-29T20:58:26.000Z

Popularity, maintenance, fit, permissions, and client support are independent evidence fields.

Read the evidence method →