Current product state
Status date: 4 September 2026
Repository plugin version: 0.4.10
Published npm adapter version: 0.1.6
This is the canonical present-state summary for the sitepilot-mcp product repository. It covers the WordPress plugin, npm adapter, published contracts, product documentation, packaging, signing, and product CI. It does not describe the deployed cloud control plane. Feature guides describe supported contracts, while release-gates.md records verification and release gates.
Supported product surfaces
Section titled “Supported product surfaces”- Direct WordPress MCP: self-hosted MCP and OAuth at
/wp-json/sitepilot-mcp/v2/mcp; WordPress remains the policy-enforcement point for every operation. - Local MCP adapter:
sitepilot-mcp@0.1.6provides exact-version stdio profiles for Claude Code, Codex, Cursor, Antigravity CLI, Windsurf, Antigravity IDE, and Claude Desktop. Supported remote clients can connect directly through OAuth discovery. - Operation bridge: trusted orchestration callers use
/wp-json/sitepilot-mcp/v1/ops/{ability}. The former/gateway/{ability}route remains a compatibility alias; approval is deliberately absent from/ops. - Builders: Gutenberg, Elementor 3 and bounded mixed Elementor 4 documents, calibrated Enfold ALB workflows, and WooCommerce operations use the guarded change-set model.
- Contracts:
@instantbuild-sitepilot/contracts@1.0.0is the published Apache-2.0 schema and risk-policy boundary. This repository is its source of record. - Public reader surfaces:
sitepilot.toolsprovides the English-first product site with Greek under/el/;docs.sitepilot.toolspublishes the technical guides with a separate sitemap.
Security and release state
Section titled “Security and release state”- Plugin
0.4.10and npm adapter0.1.6are the current shipped artifacts. Their current versions and published artifact state are summarized on this page. Detailed provenance and parity evidence is maintained in the private product repository. - Claimed Application Password authority comes from an immutable credential grant; a re-claim cannot widen scopes.
- Approval requires the dedicated
sitepilot_approvecapability and approval-channel guard. Ordinary OAuth credentials cannot approve. - OAuth Dynamic Client Registration persists a client scope ceiling. An omitted scope defaults to
site:read, and broader authorization requests are reduced before consent and token issue. - Every mutation remains subject to WordPress capabilities, credential scopes, risk classification, immutable change-set approval, optimistic version checks, audit logging, and rollback data.
Verification state
Section titled “Verification state”- Product CI covers JavaScript, contracts, PHP 8.2–8.5, WordPress 6.9/7.0/nightly, Elementor and WooCommerce compatibility, packaging, runtime licensing, dependency audit, npm artifact parity, MCP conformance, and the clean lifecycle rehearsal.
- The repository-history Gitleaks scan and deliberate synthetic-secret rejection run in every CI execution.
- Published npm
0.1.6has SLSA provenance and passed authoritative source-to-registry parity. The signed plugin0.4.10ZIP is byte-identical by packaged file content to its accepted CI artifact. - A successful CI run counts only for its exact head SHA.
Product limitations
Section titled “Product limitations”- Elementor 4 atomic documents: mixed pages inspect per region and existing atomic elements accept known typed-setting updates only. Atomic element construction, structural edits, and Global Classes or Variables writes are unsupported.
- Enfold nested globals: SitePilot reads and writes only inspected scalar colour and typography keys. Uncalibrated nested Enfold 7.x structures in
avia_options_enfoldremain unsupported and must be changed by an administrator in Enfold. - Cloud-only evidence: visual regression baselines and whole-site durable builds require the optional SitePilot cloud control plane. The self-hosted plugin and npm adapter do not claim those capabilities.
- Compiler verification: HTML/CSS-to-builder compilation is bounded and best effort. It does not provide a pixel-similarity guarantee; inspect the staged artifact before approval.
Open product and launch gates
Section titled “Open product and launch gates”- Broader live Enfold corpus acceptance and a representative WooCommerce pilot remain external evidence items; neither is implied by unit or wp-env coverage.
- Antigravity CLI remote acceptance remains carried and non-gating. Its primary-matrix pass used the local stdio profile path.
- S5 licensing counsel review, three-person reader testing, final bilingual website claims audit, a public HTTPS destination for repository technical guides, and final launch authorization remain open. The public product hostname exists, but the technical-documentation URL gate is not closed by the marketing site.
Planned post-split improvements
Section titled “Planned post-split improvements”- Make agent-led client setup simpler and faster with a reviewed setup script or command and ready-to-use agent instruction files. Validate that final onboarding path with people unfamiliar with SitePilot as improvement evidence, not as a phase or launch gate. This work must preserve least privilege, secret exclusion, configuration backup, and a bounded connection check. It is intentionally deferred until the split-phase plan is complete and is not a current release gate.
Public normalization derived from product commit 00c30de825b68dc14535f6455e82c927ad256b47, file docs/current-state.md. See source-manifest.json for the source digest and declared normalization classes.