xSpeed Cache is officially live! Get 50% OFF during Launch Week — Lifetime starts at just $79Lifetime from $79 — 50% OFF, Launch Week! See Plans →

See Plans →
Features
xSpeed Hub Pricing Docs Blog Scan
Appearance
Get Plugin

Manage every WordPress site at once with Cursor

Managing every WordPress site at once with Cursor means asking the editor agent to run one xSpeed Hub action across your whole workspace, then reading the per-site result without leaving your code.

list_siteslist_workspacespurge_cachetoggle_cacheupdate_settingsstart_preloaderstop_preloaderoptimize_siterun_benchmark

Last updated: October 2026

Example session · Cursor

You: Footer change is merged. Use xSpeed Hub to clear all the caches and warm them up.

list_sites read-only
→ 8 sites in the workspace

Cursor: That will touch all 8 sites: a full purge, then the preloader on each. OK to run?

You: Run it.

purge_cache(site: all, type: all) changes site
→ 8 of 8 purged

start_preloader(site: all) changes site
→ 8 of 8 started

Cursor: All eight sites are purged and warming. Ask me for preloader status per site if you want to watch progress.

01

How Cursor handles this

You are in Cursor because you maintain the themes and plugins that run a whole group of WordPress sites. After you merge a change, you ask the agent to clear and re-warm every site that uses it. It calls purge_cache with site set to "all", then start_preloader, against the xSpeed Hub server in your MCP settings. You get the outcome in the chat panel, next to the diff that caused it.

The Hub runs the sites one after another with a pause of one second between them, and returns a result for each: the site handle, ok or not, and either data or an error. If one site rejects the call, the agent can name that site and the reason while the others carry on. It is a partial success, not a failure. Only seven tools accept "all". For the rest, the agent names a site, so a per-site health pass is a string of single calls.

Since Cursor 3.6 the recommended default Run Mode is Auto-review, where a classifier decides calls that are not on the allowlist, so Cursor does not ask you by default. In Allowlist mode (Settings > Agents > Approvals & Execution) it asks for anything you did not list, and the dialog shows the arguments, so you can see site: "all" before you click. Run Everything asks nothing. For a purge, toggle, settings change or preloader call across every site, the Hub also tells the agent to say "this will touch all N sites" first. That is a request to the model, and it does not name optimize_site. In Allowlist mode the Cursor dialog is one control you can rely on, and the scope on your connection is the other: the connection token with Read-only everywhere on, or a Viewer sign-in, refuses writes.

02

Set up Cursor once

Already connected? Skip to the prompts. Alternatives and troubleshooting are on the Cursor guide.

1Put your sites in xSpeed Hub

Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.

2Add xSpeed Hub to mcp.json

Add the server to ~/.cursor/mcp.json to have it in every project, or to .cursor/mcp.json inside a project to scope it there. The entry is just a name and a url.

~/.cursor/mcp.json
{
  "mcpServers": {
    "xspeedhub": {
      "url": "https://app.xspeedcache.com/xspeed/mcp"
    }
  }
}

3Enable it and sign in

Open Customize in the sidebar, find xspeedhub and make sure it is switched on. When Cursor starts the OAuth sign-in, approve access on the xSpeed Hub page. There is no token to paste. If the server shows an error, open the Output panel with Cmd+Shift+U and pick MCP Logs.

Text
Customize  >  xspeedhub  (on)
1 / 3

Full Cursor setup, sign-in options and FAQ

Before you send a prompt that changes something

Reads change nothing on your sites, though contact_support emails xSpeed support. Writes run once your connection allows them, so your client's approval prompt and a read-only connection (the token's Read-only everywhere switch, or a Viewer sign-in) are the gates that matter. Cursor decides how to treat an MCP tool call by its Run Mode, and you can expand a call to see its arguments. MCP follows the same Run Modes as terminal commands, set under Settings > Agents > Approvals & Execution. The recommended default, Auto-review, runs allowlisted calls at once and sends the rest to a classifier, not to you. Allowlist runs only what you listed, and with an empty list it asks you every time. Run Everything runs every tool call without asking. xSpeed Hub has no confirmation step of its own, so a tool you allowlist, or any call under Run Everything, writes as soon as your connection allows writes. Auto-review is a model, and Cursor says it is not a security boundary.

03

What do I ask?

Three prompts written for Cursor. More for this job are below.

Prompt for Cursor
I just changed the shared footer. Use xSpeed Hub to purge every site, then start the preloader on all of them.
Prompt for Cursor
Ask xSpeed Hub to run the benchmark on all sites and tell me which three have the worst uncached response time.
Prompt for Cursor
With xSpeed Hub, show me every site where caching is off, then ask me before turning it on.
04

What happens, step by step

If you run many WordPress sites, repeating one action on each is the slow part. Through xSpeed Hub, seven tools accept every site in a workspace, or a list of handles, in a single call. The Hub runs the sites one after another and returns a result for each, so a site that fails is named instead of hidden. Everything else in the Hub works on one site per call.

01

See what you can reach

list_sites returns each site's handle, URL, status and scopes. When you have more than one workspace, list_workspaces returns each one's handle, id, your role, its site count, which one is the default, and whether this connection can reach it.

02

Choose the scope of the call

The agent passes site: "all" for every site in one workspace, or an array of handles for exactly those sites. For a workspace other than the default it also passes the workspace argument. Omit workspace and the call acts on the default workspace.

03

Confirm once

Before a purge, toggle, settings change or preloader call that touches every site, the Hub tells the agent to say "this will touch all N sites" and wait for you, then make one call. That instruction does not name optimize_site, so for it your client's prompt is the gate. It is guidance to the agent, not a lock. It is one tool call, so one approval in your client covers every site in it.

04

Run it as one call

The Hub runs the sites one after another with a one-second pause between live calls, so a fleet purge is not a burst of traffic at your servers. Revoked sites are skipped from "all". Each site's action lands in the activity log as its own row.

05

Read the result per site

The reply is a summary of targets, succeeded and failed, plus one row per site with ok and either its data or its error. Some sites failing is a partial success. Only a run where every site failed comes back as an error.

06

Follow up on the failures

The agent reports which sites failed and why, then retries just those handles with an array. Tools that read one site, such as get_cache_status and get_health, do not fan out, so a fleet-wide check means one call per site.

05

Reference

Fan-out toolspurge_cache, toggle_cache, update_settings, start_preloader, stop_preloader, optimize_site, run_benchmark
Selectorsite: "all", or an array of handles
What all coversEvery site this connection can see in one workspace, minus revoked ones
PacingOne after another, with a 1 second pause between live calls
Resultsummary (targets, succeeded, failed) and a row per site: ok, then data or error
Partial failureReported per site; the call counts as an error only when every site failed
Workspace argumentOptional. Omit it for the default workspace; name one by its handle or id from list_workspaces
ReachFixed when you approve the connection; list_workspaces shows reachable: false for the rest
Not fan-outget_health, get_cache_status and every other tool take one site per call
Slow toolsoptimize_site takes up to 2 minutes per site; a target_score run is capped at 12 rounds per call
Read-onlyThe connection token with Read-only everywhere on, or a Viewer sign-in, refuses every fan-out write; run_benchmark works. An OAuth sign-in gets the scopes the client asks for
Hub daily passRe-verifies sites, snapshots cache status and hit ratio, reads stored reports, alerts by Slack webhook or email
06

Rules worth keeping

  • Confirm once, then call once. The Hub has no confirmation step of its own, so your client's approval prompt and a read-only connection (the connection token with Read-only everywhere on, or a Viewer sign-in) are the gates that matter. The Hub's "this will touch all N sites" is an instruction to the agent for purge, toggle, settings and preloader calls, and it does not name optimize_site.
  • "all" is one workspace, never every workspace. To act in another workspace, name it. A write to a non-default workspace must name it, and an array of handles is looked up only in the workspace the call names.
  • Read every result per site. Treat some sites failing as a partial result, and never accept a blanket "done" from the agent.
  • Try a behaviour change on one site before you send it to the fleet. toggle_cache and update_settings on every site are one call, and each site checks values against its own settings, so a Pro setting can fail on a Free site.
  • optimize_site on many sites is slow, because each site can take up to two minutes inside one call. Use dry_run first, or name a short list of handles.
  • The Hub has no scheduler for agent prompts. Its own daily pass and alerts run without an agent, and an agent can only act when you send a prompt or your AI client runs one on a timer.

Good to know with Cursor

An allowlisted tool runs whatever site it is given, including "all", so switch Run Mode to Allowlist, list the reads and leave the six fan-out tools that write off the list. Under the default Auto-review, unlisted calls go to a classifier. Run Everything removes the Cursor dialog for every call, including the all-sites ones, and Auto-review is a classifier that Cursor says is not a security boundary. In both cases the Hub's confirm-once instruction to the agent is close to the only check, and it is not a lock. Cursor also says Cloud Agents never ask for approval, so give a Cloud Agent only a Hub connection token with Read-only everywhere on. The bigger risk is a habit: once the dialog is gone for xSpeed, a casual request that mentions every site can run as a write before you have read it.

07

More prompts for this job

They work in any client connected to xSpeed Hub.

Prompt
Use xSpeed Hub to list every site I can reach, and every workspace, and say which workspace you act in by default.
Prompt
With xSpeed Hub, purge the cache on every site in my workspace and tell me which ones failed.
Prompt
Use xSpeed Hub to run a benchmark on all my sites and rank them by cached response time.
Prompt
Use xSpeed Hub to start the preloader on blog, shop and docs only.
Prompt
With xSpeed Hub, turn page caching on for every site where it is off. Check each site first.
Prompt
Use xSpeed Hub to stop the preloader everywhere. The servers are busy.
Prompt
Ask xSpeed Hub to preview a safe optimize_site pass on every site with dry_run and summarize what it would change.
Prompt
Use xSpeed Hub to purge every site in the client-acme workspace, not my default one.
08

Frequently asked questions

Yes, when it prompts. The approval dialog lists the tool and its arguments, so a fleet-wide call shows site set to all. If the tool is allowlisted, or you run in Run Everything, there is no dialog and you only see the result afterwards.

Allowlist is the most predictable. List the read tools you trust, such as list_sites and run_benchmark, and leave the fan-out tools that write off the list, so each one asks and shows site set to all. Auto-review hands the decision to a classifier that Cursor says is not a security boundary, and Run Everything asks nothing.

Every site the connection can see in one workspace. It never crosses workspaces, and revoked sites are skipped. If your connection is limited to some sites, "all" quietly means the sites you are allowed, with no error naming the rest. To act in another workspace, the agent names it with the workspace argument.

The other sites still run. The reply has a summary and a row for each site with ok and its data or its error, so a site that was unreachable is named. A run counts as an error only when every site failed. Ask the agent to retry just the failed handles.

No. get_health and get_cache_status take one site per call, so the agent loops. The tools that fan out are purge_cache, toggle_cache, update_settings, start_preloader, stop_preloader, optimize_site and run_benchmark. The Hub dashboard has a fleet overview for health.

Yes, on its own. A daily pass re-verifies each site, retrying a failed probe once, snapshots cache status and hit ratio, and reads the PageSpeed and GTmetrix reports your sites already stored. It can alert you by Slack webhook or email when a site becomes unreachable, caching is switched off, the hit ratio falls below a floor you set, or a score regresses. Each alert fires once per incident, not every day.

The Hub has no confirmation step. Its instructions tell the agent to confirm once with you, saying how many sites a call will touch, but that is guidance and not a lock. Your AI client's approval prompt and a read-only connection (the connection token with Read-only everywhere on, or a Viewer sign-in) are what stop a write. The instruction covers purge, toggle, settings and preloader calls, not optimize_site. The dashboard's own Purge all button does confirm before it runs.

No. It cannot add, remove or rename sites, change members, roles or billing, mint or rotate tokens, or widen the workspaces this connection reaches. Those stay in the Hub dashboard.

09

Keep going

Manage every site at once with other agents

More with Cursor

Documentation

From the blog

Manage every site at once, from Cursor.

xSpeed Hub is free and has no site cap. Connect your sites once and ask from the agent you already use.