Bridgistic

io.github.Wordpressisticv1.5.2更新於 Oct 5, 2026

Connect Claude to WordPress safely: signed requests, scoped keys, approvals, logs, snapshots.

概覽

AI 產生的概覽

讓 AI 助理透過簽章、限定範圍的請求讀取與編輯 WordPress 網站,並支援審核、日誌與快照。

功能
Bridgistic 透過在使用者電腦本機執行的 MCP 伺服器,把 AI 助理連接到自架的 WordPress 網站。助理可以查詢網站資訊,例如 WordPress 與 PHP 版本、目前佈景主題與外掛清單,並依金鑰所選的權限預設集讀取或修改內容。請求會以金鑰 ID 與密鑰簽章,並記錄在 WordPress 後台日誌中;破壞性寫入可要求人工審核,且會自動建立快照以便一鍵還原。
適用情境
當你希望助理直接操作自己的 WordPress 網站(例如查看設定或管理內容),且希望採用限定權限、稽核日誌與可復原的操作,而非廣泛存取時,適合使用。它鎖定網站擁有者而非開發者,本機連線是 Claude Desktop、Claude Code、Codex CLI 與 Gemini CLI 的建議方式。
執行需求
需要本機執行環境:透過 stdio 執行的 npm 套件 bridgistic-mcp-server,或預先建置的 Claude Desktop 擴充功能。手動設定用戶端需要 Node.js 20+。必須在啟用 HTTPS、固定網址非「單純」的網站上安裝並啟用 Bridgistic WordPress 外掛。必要環境變數:BRIDGISTIC_SITE_URL、BRIDGISTIC_KEY_ID 與 BRIDGISTIC_KEY_SECRET;選用 BRIDGISTIC_CONNECTIONS 與 BRIDGISTIC_LOG_LEVEL。
安裝前請注意
金鑰密鑰(BRIDGISTIC_KEY_SECRET)只在建立時顯示一次,可存取你的網站,請妥善保存,遺失後應輪換。權限預設集決定助理能做什麼,建議從唯讀開始,有需要再放寬。寫入操作可能變更或刪除網站資料,但審核與自動快照可以攔阻並還原。金鑰可隨時撤銷。另有託管雲端連接器,但屬於公開測試版,尚未經過獨立安全審查。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Bridgistic,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

Connecting Bridgistic — the complete guide

[Bridgistic — AI Control for WordPress]

Branding source files and distribution rules are documented in docs/BRANDING.md.

This is the WordPressistic organization repository for the Bridgistic Claude marketplace, OpenAI plugin, Claude Desktop extension, MCP server, and release artifacts. npm publishing is configured through GitHub Actions trusted publishing; see docs/NPM_TRUSTED_PUBLISHER.md.

This is the single walkthrough to go from "I just installed the plugin" to "my AI assistant can safely read and edit my WordPress site." It's written for site owners, not developers — if something below doesn't match what you see, jump to Troubleshooting or run Bridgistic → Health Check first.

Read this if: you want the shortest, least error-prone path to a working connection. Skip to a specific client's page (Claude Desktop, Claude Code, Codex CLI, Gemini CLI, ChatGPT) only if you already know which one you're using and want copy-paste config details.


Before you start: two ways to connect

Bridgistic has two ways to connect an AI assistant to your site.

Local connection (this guide)Cloud connector
StatusLive, fully supported, most-used pathLive, public beta — no independent security review yet
How it worksYour AI app runs a small server on your own computer that talks to your siteA hosted relay (mcp.bridgistic.app) brokers the connection with no local install
Setup effortOne key to create, one app to configurePaste one URL into your AI client, approve in WP Admin
Works withClaude Desktop, Claude Code, Codex CLI, Gemini CLIChatGPT and any other remote-only MCP client (also works with Claude's remote connector)

Use the local connection (below) if you're using Claude Desktop, Claude Code, Codex CLI, or Gemini CLI — it's the most battle-tested path and never sends your credentials anywhere but between your own computer and your own site. Use the cloud connector (WP Admin → Bridgistic → Bridgistic Cloud) only if your client can't run a local server (ChatGPT is the main case) — it's functional but hasn't had an independent security review yet, so avoid it for sites you can't afford to risk, and prefer a Read-only or Content Manager preset over Developer Mode when you do use it. See CLOUD_CONNECTOR.md for its full status.


The five-minute path (recommended for almost everyone)

This is Claude Desktop + the one-click extension — the fewest steps, no terminal, no Node.js install.

Step 1 — Install the WordPress plugin

  1. Download bridgistic-wordpress-plugin.zip from the Releases page.
  2. In WordPress: Plugins → Add New → Upload Plugin, choose the zip, click Install Now, then Activate.
  3. A new Bridgistic menu appears in your left sidebar. That confirms it worked — nothing on your site's content or theme was touched.

Before continuing, make sure:

  • Your site uses HTTPS (a plain http:// address only works for local development sites).
  • Settings → Permalinks is set to anything other than "Plain."

Step 2 — Create a key

  1. Go to Bridgistic → AI / MCP Connections.
  2. Step 1 of the wizard: choose Claude Desktop Extension.
  3. Step 2: choose a permission preset. Start with Read-only — you can widen this later once you trust the connection; it cannot create, change, or delete anything on this preset.
  4. Step 3: click Create key.
  5. A Key ID (wpk_…) and a Secret (wps_…) appear. Copy both somewhere safe right now — the secret is shown exactly once. If you navigate away before copying it, the key still exists but you'll need to click Rotate to get a new secret.

Step 3 — Install the extension in Claude Desktop

  1. Download bridgistic.mcpb (there's also a direct download button on the wizard's Step 4).
  2. Double-click the downloaded file. Claude Desktop opens and asks to install the extension.
  3. Claude Desktop then prompts for three values — paste in what you copied in Step 2:
    • WordPress Site URL — exactly as it appears in WP Admin → Settings → General (e.g. https://example.com, no trailing slash)
    • Bridgistic Key ID
    • Bridgistic Key Secret
  4. Click Enable. The secret is stored securely by Claude Desktop itself — it is never written to a plain text file.

Step 4 — Verify it's working

  1. In Claude Desktop, start a new chat and ask:

    Run bridgistic_get_site_info

  2. Claude should reply with your WordPress version, PHP version, active theme, and plugin list.
  3. Back in WordPress, open Bridgistic → Logs — you should see that request recorded. The Bridgistic → Dashboard connection badge also flips from "Waiting for first request" to "Connected."

That's it — done. If step 4 didn't work, go to Troubleshooting.


Using a different AI client

The plugin's setup wizard (Bridgistic → AI / MCP Connections) generates ready-to-paste configuration for each of these — pick your client on Step 1 of the wizard, then follow its guide for the one-time setup around it (installing the CLI/app itself, where its config file lives, restarting it):

ClientRuns locally?Guide
Claude Desktop (manual config, no extension)YesCLAUDE_DESKTOP.md
Claude CodeYesCLAUDE_CODE.md
OpenAI Codex CLIYesCODEX_SETUP.md
Gemini CLIYesGEMINI_SETUP.md
ChatGPTNo — remote onlyCHATGPT_SETUP.md (uses the cloud connector, a free public beta)
Anything else that speaks MCPDependsUse the wizard's "Manual MCP JSON" option

All of the "runs locally" options follow the same shape as the extension path above, with one extra manual step: you paste a JSON snippet into that client's own config file, and you need Node.js 20+ installed (node --version to check) unless you're using the pre-built extension. The wizard's Step 4 generates the exact JSON for you, and Bridgistic → Export Package downloads it as a ready-made zip with install scripts.

Important — what "Test connection" in the wizard actually checks: Step 5's "Run test" button only confirms your WordPress site and key are configured correctly on the server side. It does not confirm your AI client is set up right — that's what Step 4 above (asking Claude to run a tool) is for. Don't stop at a green "Run test" result and assume you're fully connected; always do the "ask Claude to run bridgistic_get_site_info" check too.

Managing more than one WordPress site? See CONNECT_OTHER_AI.md for the multi-site connections.json registry — one key per site, one shared config file.


Understanding what you just gave access to

  • Scoped, not all-powerful. The key you created only allows what its permission preset says (Read-only / Content Manager / Safe Admin / Developer Mode). Check Bridgistic → Keys & Scopes any time to see or change this.
  • Every request is logged. Bridgistic → Logs shows exactly what was requested, when, and by which key.
  • Destructive actions can require your approval. If your preset includes approvals, risky operations pause in Bridgistic → Approvals until you personally allow them.
  • Changes can be undone. Before any destructive write, Bridgistic automatically snapshots the affected data — Bridgistic → Snapshots lets you restore with one click.
  • You can revoke access instantly. Bridgistic → Keys & Scopes → Revoke disables a key immediately; nothing further can be done with it.

Troubleshooting

Run Bridgistic → Health Check first — it runs 16 diagnostics and tells you exactly what's wrong and how to fix it. The most common issues:

SymptomLikely causeFix
"Run test" fails in the wizardREST API blocked, permalinks set to "Plain," or clock drift between server and your computerHealth Check names the exact failing check and its fix
Claude says the tool doesn't exist / times outThe extension/config wasn't restarted after setup, or the site URL has a typoFully quit and reopen your AI client; double-check the site URL has no trailing slash and matches Settings → General exactly
"Invalid signature" or "Unauthorized" errorsThe secret was mistyped, or the key was rotated/revoked since you configured itRecreate or rotate the key in Keys & Scopes, and re-paste the new secret into your AI client
Nothing appears in Logs after asking Claude to run a toolYour AI client isn't actually using this key — check its own MCP server list/settingsRe-check the config was pasted into the right file and the client was restarted
A hosting firewall (WAF) is blocking requestsSome managed WordPress hosts block unfamiliar REST API trafficHealth Check's "REST API reachable" and "WAF interference" checks flag this with host-specific guidance

Full diagnostic reference: plugins/bridgistic/package/TROUBLESHOOTING.md. Still stuck? Open a GitHub issue or copy the no-secrets debug report from Bridgistic → Health Check into it.


FAQ

Do I need to know how to code? No. The five-minute path above involves no terminal and no file editing.

Is my API key/password shared with Claude, WordPress.com, or Anthropic? No. The key lives only between your AI client (running on your own computer) and your own WordPress site. Bridgistic never sends it anywhere else.

What if I lose the secret? You can't view it again, but nothing is broken — go to Keys & Scopes and click Rotate to generate a fresh secret, then re-paste it into your AI client.

Can I use this on more than one site? Yes — WP Admin → Bridgistic → Multi-Site is a guided builder for the config file this needs. See CONNECT_OTHER_AI.md for details.

Can I just paste one cloud URL like some other tools? Yes — that's WP Admin → Bridgistic → Bridgistic Cloud. It's live and free, but hasn't had an independent security review yet, so the local connection above is still the recommended default for most people. See CLOUD_CONNECTOR.md for its current state.

來源:README.md,提交 d87c5d4

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.5.2最新Oct 5, 2026