# hosting_installWordPressV1

Install WordPress on an existing website. The website must already exist before calling this endpoint. To create a new website first, use POST /api/hosting/v1/websites and poll GET /api/hosting/v1/websites until it appears. Call GET /api/hosting/v1/wordpress/installations filtered by username and domain before proceeding to check whether WordPress is already installed on the target domain/path. If WordPress already exists and overwrite is false (the default), the async job will fail. This operation is asynchronous: a successful response only means the install job has been queued, not that WordPress is ready. Installation typically takes 1-2 minutes. Poll GET /api/hosting/v1/wordpress/installations filtered by username and domain to track progress. When the installation appears in that list, WordPress is ready.

Agent View of the PolicyLayer registry record for `hosting_installWordPressV1`. HTML page: https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-installwordpressv1

## Facts

- Tool: `hosting_installWordPressV1`
- Server: Hostinger Api (`hostinger-api-mcp`) — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp.md
- Install: `npx -y hostinger-api-mcp`
- Homepage: https://github.com/hostinger/api-mcp-server
- Risk category: Execute (High risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 10 (4 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `domain` | string | yes | Domain of the existing website where WordPress will be installed |
| `version` | string | no | WordPress core version to install. If omitted, the latest core version compatible with the account vhost PHP version is selected. |
| `database` | object | no | Optional. If the named database already exists, it will be used for this WordPress install. Otherwise a new database is created with a generated name and random |
| `language` | string | no | WordPress locale. Defaults to en_US when omitted. |
| `username` | string | yes | username parameter |
| `directory` | string | no | Relative directory to install WordPress into. Defaults to the website root when omitted. |
| `overwrite` | boolean | no | When false (default), does not replace an existing installation. If WordPress is already installed on the domain/path, the async install job fails unless true. |
| `site_title` | string | yes | Title of the WordPress site |
| `credentials` | object | yes | WordPress admin credentials |
| `auto_updates` | string | no | WordPress core auto-update policy |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "hosting_installWordPressV1",
    "arguments": {
      "domain": "<domain>",
      "username": "<username>",
      "site_title": "<site_title>",
      "credentials": {}
    }
  }
}
```

## Why hosting_installWordPressV1 is rated High

This tool triggers an external installation operation on a hosting environment. It executes a WordPress installation process on a remote server, which is an external operation with significant side effects (modifying the server environment, potentially overwriting existing data if overwrite=true).

From the tool's own definition: "Install WordPress on an existing website... This operation is asynchronous: a successful response only means the install job has been queued"

Risk signals: Accepts file system path (directory) · Handles credentials or secrets (credentials) · High parameter count (15 properties)

## Use case

AI agents invoke hosting_installWordPressV1 to trigger actions in Hostinger Api. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Hostinger Api:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "hosting_installWordPressV1": {
      "limits": [
        {
          "counter": "hosting_installwordpressv1_rate",
          "window": "minute",
          "max": 10,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Hostinger Api (257)

- `agency-hosting_clearAgencyPlanWebsiteCacheV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-clearagencyplanwebsitecachev1.md
- `agency-hosting_deleteAgencyPlanWebsiteCronJobV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deleteagencyplanwebsitecronjobv1.md
- `agency-hosting_deleteAgencyPlanWebsiteDatabaseUserV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deleteagencyplanwebsitedatabaseuserv1.md
- `agency-hosting_deleteAgencyPlanWebsiteDatabaseV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deleteagencyplanwebsitedatabasev1.md
- `agency-hosting_deleteAgencyPlanWebsiteV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deleteagencyplanwebsitev1.md
- `agencyHosting_deployNodeStaticWebsite` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agencyhosting-deploynodestaticwebsite.md
- `agencyHosting_deployPhpApplication` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agencyhosting-deployphpapplication.md
- `billing_deletePaymentMethodV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/billing-deletepaymentmethodv1.md
- `DNS_deleteDNSRecordsV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/dns-deletednsrecordsv1.md
- `DNS_resetDNSRecordsV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/dns-resetdnsrecordsv1.md
- `domains_deleteDomainForwardingV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/domains-deletedomainforwardingv1.md
- `domains_deleteWHOISProfileV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/domains-deletewhoisprofilev1.md
- `ecommerce_deleteStoreV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/ecommerce-deletestorev1.md
- `hosting_clearWebsiteCacheV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-clearwebsitecachev1.md
- `hosting_deleteAccountCronJobV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deleteaccountcronjobv1.md
- `hosting_deleteAccountDatabaseRemoteConnectionV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deleteaccountdatabaseremoteconnectionv1.md
- `hosting_deleteAccountDatabaseV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deleteaccountdatabasev1.md
- `hosting_deleteWebsiteParkedDomainV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletewebsiteparkeddomainv1.md
- `hosting_deleteWebsiteSubdomainV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletewebsitesubdomainv1.md
- `hosting_deleteWebsiteV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletewebsitev1.md
- `hosting_deleteWordPressInstallationV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletewordpressinstallationv1.md
- `hosting_uninstallWordPressPluginsV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-uninstallwordpresspluginsv1.md
- `hosting_uninstallWordPressThemesV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-uninstallwordpressthemesv1.md
- `mail_deleteMailboxV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/mail-deletemailboxv1.md
- `mail_deleteWebhookV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/mail-deletewebhookv1.md
- `mail_revokeAPITokenV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/mail-revokeapitokenv1.md
- `reach_deleteAContactV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/reach-deleteacontactv1.md
- `VPS_deleteFirewallRuleV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/vps-deletefirewallrulev1.md
- `VPS_deleteFirewallV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/vps-deletefirewallv1.md
- `VPS_deletePostInstallScriptV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/vps-deletepostinstallscriptv1.md
- …and 227 more: https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=io-github-hostinger-hostinger-api-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/io-github-hostinger-hostinger-api-mcp
