Connect safely
Use the read-only quick start and confirm the resulting connection has only site:read.
Connect safely
Use the read-only quick start and confirm the resulting connection has only site:read.
Operate the plugin
Follow the WordPress operator guide for credentials, permissions, approvals, diagnostics, and revocation.
Understand the boundary
Read the security model and architecture before granting write scopes or approving a change set.
Use a builder
Check the Elementor and Enfold contracts before planning builder-specific work.
Call an operation
Use the MCP API reference for the released operation surface and its risk tiers.
Verify a release
Use current state, release gates, licensing, and third-party notices to verify what is actually shipped.
SitePilot is a guarded bridge between coding agents and WordPress. It does not expose arbitrary PHP, JavaScript, SQL, shell, WP-CLI, secrets, wp-config.php, or filesystem access. WordPress remains the policy-enforcement point for every supported operation.
The marketing and beginner-facing site remains at sitepilot.tools. This documentation origin has its own sitemap and does not add routes to the marketing sitemap.