# hosting_installWordPressThemeV1

Install a theme on an existing WordPress installation. Provide the WordPress installation (software) identifier in the path. It can be obtained from GET /api/hosting/v1/wordpress/installations (the id field). When the theme is one of the Hostinger themes (hostinger-blog, hostinger-affiliate-theme, hostinger-ai-theme), the optional palette, layout, and font fields are forwarded to the custom installer (defaults: palette1, layout1, default). For any other theme they are ignored. This operation is asynchronous: a successful response only means the install job has been queued, not that the theme is ready.

Agent View of the PolicyLayer registry record for `hosting_installWordPressThemeV1`. HTML page: https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-installwordpressthemev1

## Facts

- Tool: `hosting_installWordPressThemeV1`
- Server: Hostinger Api (`hostinger-api-mcp`) — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp.md
- Install: `npx -y hostinger-api-mcp`
- Homepage: https://github.com/hostinger/api-mcp-server
- Risk category: Execute (High risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 6 (3 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `font` | string | no | Font identifier. Only applied when the theme is a Hostinger theme; the default is used when omitted. |
| `theme` | string | yes | Slug of the theme to install. Hostinger theme slugs (hostinger-blog, hostinger-affiliate-theme, hostinger-ai-theme) trigger the custom installer and forward the |
| `layout` | string | no | Layout identifier. Only applied when the theme is a Hostinger theme; the default is used when omitted. |
| `palette` | string | no | Palette identifier. Only applied when the theme is a Hostinger theme; the default is used when omitted. |
| `software` | string | yes | WordPress installation (software) identifier |
| `username` | string | yes | username parameter |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "hosting_installWordPressThemeV1",
    "arguments": {
      "theme": "<theme>",
      "software": "<software>",
      "username": "<username>"
    }
  }
}
```

## Why hosting_installWordPressThemeV1 is rated High

This tool triggers an external operation (installing a WordPress theme) on a live hosting environment. It is not simply writing data but executing an installation process on a remote server. Misuse could install malicious or unwanted themes on production WordPress sites, making severity high.

From the tool's own definition: "Install a theme on an existing WordPress installation... This operation is asynchronous: a successful response only means the install job has been queued"

## Use case

AI agents invoke hosting_installWordPressThemeV1 to trigger actions in Hostinger Api. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Hostinger Api:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "hosting_installWordPressThemeV1": {
      "limits": [
        {
          "counter": "hosting_installwordpressthemev1_rate",
          "window": "minute",
          "max": 10,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Hostinger Api (257)

- `agency-hosting_clearAgencyPlanWebsiteCacheV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-clearagencyplanwebsitecachev1.md
- `agency-hosting_deleteAgencyPlanWebsiteCronJobV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deleteagencyplanwebsitecronjobv1.md
- `agency-hosting_deleteAgencyPlanWebsiteDatabaseUserV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deleteagencyplanwebsitedatabaseuserv1.md
- `agency-hosting_deleteAgencyPlanWebsiteDatabaseV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deleteagencyplanwebsitedatabasev1.md
- `agency-hosting_deleteAgencyPlanWebsiteV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deleteagencyplanwebsitev1.md
- `agencyHosting_deployNodeStaticWebsite` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agencyhosting-deploynodestaticwebsite.md
- `agencyHosting_deployPhpApplication` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agencyhosting-deployphpapplication.md
- `billing_deletePaymentMethodV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/billing-deletepaymentmethodv1.md
- `DNS_deleteDNSRecordsV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/dns-deletednsrecordsv1.md
- `DNS_resetDNSRecordsV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/dns-resetdnsrecordsv1.md
- `domains_deleteDomainForwardingV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/domains-deletedomainforwardingv1.md
- `domains_deleteWHOISProfileV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/domains-deletewhoisprofilev1.md
- `ecommerce_deleteStoreV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/ecommerce-deletestorev1.md
- `hosting_clearWebsiteCacheV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-clearwebsitecachev1.md
- `hosting_deleteAccountCronJobV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deleteaccountcronjobv1.md
- `hosting_deleteAccountDatabaseRemoteConnectionV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deleteaccountdatabaseremoteconnectionv1.md
- `hosting_deleteAccountDatabaseV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deleteaccountdatabasev1.md
- `hosting_deleteWebsiteParkedDomainV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletewebsiteparkeddomainv1.md
- `hosting_deleteWebsiteSubdomainV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletewebsitesubdomainv1.md
- `hosting_deleteWebsiteV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletewebsitev1.md
- `hosting_deleteWordPressInstallationV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletewordpressinstallationv1.md
- `hosting_uninstallWordPressPluginsV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-uninstallwordpresspluginsv1.md
- `hosting_uninstallWordPressThemesV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-uninstallwordpressthemesv1.md
- `mail_deleteMailboxV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/mail-deletemailboxv1.md
- `mail_deleteWebhookV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/mail-deletewebhookv1.md
- `mail_revokeAPITokenV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/mail-revokeapitokenv1.md
- `reach_deleteAContactV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/reach-deleteacontactv1.md
- `VPS_deleteFirewallRuleV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/vps-deletefirewallrulev1.md
- `VPS_deleteFirewallV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/vps-deletefirewallv1.md
- `VPS_deletePostInstallScriptV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/vps-deletepostinstallscriptv1.md
- …and 227 more: https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=io-github-hostinger-hostinger-api-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/io-github-hostinger-hostinger-api-mcp
