Bridgistic
Provides a secure MCP bridge to interact with WordPress sites via signed requests, scoped keys, and approval workflows.
README
<div align="center">
Bridgistic
Connect Claude to WordPress safely.
Signed requests · scoped keys · approvals on destructive ops · audit logs · snapshots · local MCP setup
Also works with Codex CLI, Gemini CLI, and ChatGPT (public beta) — Bridgistic speaks standard MCP, not just Claude's.
Free public version · by WordPressistic
</div>
What is Bridgistic?
Bridgistic is a safe bridge between Claude and your WordPress site. Instead of handing an AI a full-admin Application Password, you mint a scoped key in WordPress and run a local MCP server that signs every request with it. The WordPress plugin verifies the signature, enforces the key's scopes, queues destructive operations for human approval, snapshots before risky writes, and logs everything.
Claude Desktop / Claude Code / Codex CLI / Gemini CLI
│ (MCP, local)
▼
Bridgistic MCP server ── HMAC-signed HTTPS ──▶ WordPress plugin
· scope checks
· approval queue
· snapshots + rollback
· audit log
What this repo includes (free version)
- Claude Code plugin marketplace — install with two slash commands
- Local MCP server (Node 20+, stdio) with 43 WordPress tools
- WordPress plugin with a full admin dashboard: guided Claude Setup, Keys & Scopes, Health Check (16 diagnostics), audit Logs, Snapshots, manual + limited scheduled Playbooks, and an Export Package builder
- HMAC-SHA256 authentication, replay protection, scoped least-privilege keys
- Example configs, install scripts, and step-by-step docs
What it does NOT include
The free version is the complete local bridge, plus a public-beta hosted connector (WP Admin → Bridgistic Cloud) for remote-only clients like ChatGPT. These belong to Bridgistic SaaS (separate, private product): AI skills marketplace (SEO/AIO/Schema audits), multi-site agency dashboard, team permissions, advanced logs & snapshots, usage billing, and white-label. See docs/FREE_VS_PAID.md.
Quick start
New here? Read docs/CONNECT_BRIDGISTIC.md instead — one step-by-step guide covering install → key → connect → verify → troubleshooting, written for non-technical site owners. The steps below are the same flow in short form.
1. Install the WordPress plugin
Download bridgistic-wordpress-plugin.zip from Releases (or build it: npm install && npm run build && npm run package), then upload via WP Admin → Plugins → Add New → Upload and activate. Details: docs/WORDPRESS_SETUP.md.
2. Generate a key
Open WP Admin → Bridgistic → Claude Setup, pick a connection type and a permission preset (start with Read-only), and create a key. The secret is shown once — copy it immediately.
3a. One-click Claude Desktop extension (recommended — no terminal, no Node.js)
Download bridgistic.mcpb, double-click it, and paste your site URL, key ID, and secret when Claude Desktop prompts (the secret is stored securely by the app — no config files, no terminal). Details: docs/CLAUDE_DESKTOP.md.
3b. Or install in Claude Code
/plugin marketplace add Shubochandrosarker/bridgistic-claude-marketplace
/plugin install bridgistic@bridgistic-marketplace
Then set your connection in the shell where you run Claude Code:
export BRIDGISTIC_SITE_URL="https://example.com"
export BRIDGISTIC_KEY_ID="your_key_id"
export BRIDGISTIC_KEY_SECRET="your_key_secret"
Requires Node.js 20+. Details: docs/CLAUDE_CODE.md.
Also available via the MCP Registry as io.github.shubochandrosarker/bridgistic, and on npm:
npx bridgistic-mcp-server
3c. Or set up Claude Desktop manually
Clone this repo and build the server once:
git clone https://github.com/Shubochandrosarker/bridgistic-claude-marketplace.git
cd bridgistic-claude-marketplace
npm install && npm run build
Add this to your Claude Desktop config (macOS: ~/Library/Application Support/Claude/claude_desktop_config.json, Windows: %APPDATA%\Claude\claude_desktop_config.json):
{
"mcpServers": {
"bridgistic": {
"command": "node",
"args": [
"/absolute/path/to/bridgistic-claude-marketplace/mcp-server/dist/index.js"
],
"env": {
"BRIDGISTIC_SITE_URL": "https://example.com",
"BRIDGISTIC_KEY_ID": "your_key_id",
"BRIDGISTIC_KEY_SECRET": "your_key_secret"
}
}
}
}
Restart Claude Desktop. Details: docs/CLAUDE_DESKTOP.md. The Bridgistic → Claude Setup page also generates this config for you, and Bridgistic → Export Package downloads it as a ready-made zip.
3d. Or connect Codex, Gemini CLI, or ChatGPT
The same Bridgistic → Claude Setup wizard (despite the name) also generates ready-to-paste configs for OpenAI Codex CLI and Gemini CLI — pick them as the connection type on step 1. See docs/CODEX_SETUP.md and docs/GEMINI_SETUP.md. ChatGPT only supports remote connectors and needs Bridgistic's hosted cloud connector — free, public beta, linked at Bridgistic → Bridgistic Cloud — see docs/CHATGPT_SETUP.md. Managing more than one WordPress site from the same client (any of them)? See docs/CONNECT_OTHER_AI.md.
4. Test the connection
- In WP Admin: Bridgistic → Claude Setup → Step 5 → Run test, or open Bridgistic → Health Check for 16 diagnostics with fixes.
- In Claude: ask it to run
bridgistic_get_site_info(read-only). Then check Bridgistic → Logs — the request should be there.
Troubleshooting
Run Bridgistic → Health Check first — it detects blocked REST APIs, WAF interference, clock drift, permalink problems, and more, each with a fix. Full guide: plugins/bridgistic/package/TROUBLESHOOTING.md.
Security model
- HMAC-SHA256 signed requests — the secret never travels on the wire; a timestamp window (±300s) plus single-use nonces block replays.
- Scoped keys — each key carries an explicit permission set (
posts:read,db:write, …) enforced server-side on every call. Presets: Read-only, Content Manager, Safe Admin, Developer Mode. - Approvals — keys can require human sign-off; destructive operations pause in a queue you decide on in WP Admin.
- Snapshots — automatic reversible captures before destructive writes; one-call rollback.
- Secrets at rest — encrypted (libsodium / AES-256-GCM), shown exactly once at creation, never logged. Rotate any time.
- Dangerous tools (
bridgistic_execute_php,bridgistic_db_query, filesystem writes) require developer scopes and pass through dry-run/approval/snapshot guards. Use Developer Mode only on sites you control.
Full details: docs/SECURITY.md. Found a vulnerability? Please report it privately to support@wordpressistic.com — do not open a public issue.
Repo layout
.claude-plugin/marketplace.json Claude Code marketplace manifest
plugins/bridgistic/ Claude Code plugin (manifest, mcp.json, pre-built server, setup package)
mcp-server/ MCP server source (TypeScript)
wordpress-plugin/bridgistic/ WordPress plugin
docs/ Setup, security, free-vs-paid, roadmap
scripts/ validate / package / desktop-package tooling
Commands
npm install # once
npm run build # install + compile mcp-server, regenerate plugin server bundle
npm run validate # manifest + structure + secret-scan checks
npm run package # dist/bridgistic-claude-package.zip + dist/bridgistic-wordpress-plugin.zip
npm run desktop:package # dist/bridgistic-desktop-package.zip (.mcpb-ready layout)
npm test # MCP server contract + integration tests
Contributing
Issues and PRs are welcome for the free version: bug fixes, docs, health checks, translations, and setup UX. Ground rules:
- Never commit secrets —
npm run validatescans for them. - Don't weaken the security path (HMAC, scopes, approvals, snapshots) — hardening PRs are very welcome.
- WordPress code follows WordPress coding standards (nonces, capability checks, sanitize/escape everything, prefixed names).
- Paid/SaaS features are out of scope for this repo.
Free vs paid direction
Free = the local secure bridge, plus a public-beta hosted connector (this repo, complete and maintained). Paid = Bridgistic SaaS: skills, agencies, automation. Read docs/FREE_VS_PAID.md and docs/ROADMAP.md.
License
GPL-2.0-or-later. © WordPressistic / Shuvo Sarker.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。