All plugins
Sign in Get the bundle
AI Site Bridge
By WP Plugin Premium
Lite · Free · read-only Pro · Premium

Connect AI-assisted development workflows to WordPress through a secure capability layer.

AI Site Bridge is a secure capability layer between WordPress and your AI-assisted development workflow. Every request uses a scoped credential, every response is redacted, and every call is audited.

✓ No execute endpoint✓ Secret redaction✓ Revocable credentials
CLIENT
AI development workflow
HTTPS · scoped credential
AI SITE BRIDGE
Secure Capability Layer
DEFAULT: READ ONLY
✓Credential authentication
✓Scope check
✓Rate and size limits
✓Secret redaction
✓Audit event
CAPABILITIES
site.readtheme.readplugins.read logs.read · Profiles.read · Pro · allowlistfiles.write · Pro · off by default
YOUR SITE
WordPress
core · theme · plugins · WooCommerce
Architecture

Everything passes through the capability layer.

Your AI tools never talk to WordPress directly. They can only call explicit capabilities that a credential has been granted, and every response is redacted, limited and logged.

NEVER EXPOSED, IN LITE OR PRO
Unrestricted shell access
Arbitrary PHP execution or eval
Unrestricted SQL
Unrestricted filesystem access
wp-config secrets and WordPress salts
User passwords
Unrestricted remote code execution
WordPress context

The context your AI assistant needs to help you.

Safe environment metadata, theme and plugin details, and registered post types and taxonomies. Enough to reason about your site, nothing that could compromise it.

Context preview
Exactly what a credential with these scopes can read.
site.readtheme.readplugins.read
ENVIRONMENT · site.read
WordPress6.8.2
PHP8.2.18
Multisitefalse
Environmentstaging
DB_PASSWORD[redacted]
AUTH_KEY[redacted]
THEME · theme.read
ActiveStorefront Child
Version2.1.0
ParentStorefront 4.6.1
Block themeNo
CONTENT MODEL
postpageproductproduct_catproduct_tag
PLUGINS · plugins.read24 active
WooCommerce9.9.1Active
Returns Portal for WooCommerce2.3.0Active
Yoast SEO25.4Active
WP Mail SMTP4.5.0Active
Query Monitor3.18.0Inactive
Legacy Slider1.2.4Update
Credentials and scopes

One credential per connection. Only the scopes it needs.

Connection credentials are separate from WordPress user passwords. Create, name, rotate and revoke them at any time.

Connection credentials+ Create credential
NAMESCOPESLAST USEDACTIONS
AI · staging
aisb_…3f9a
site.readtheme.readplugins.read
2 min ago Rotate · Revoke
AI · production
aisb_…a71c
site.readplugins.read
1 h ago Rotate · Revoke
CI pipeline
aisb_…0d42
plugins.read
Yesterday Rotate · Revoke
Old laptop
aisb_…9be5
site.read
12 Aug Revoked
New credential created · “AI · staging”
aisb_live_7Hq2vN9xKc4pR8tLm3Wz6yB1fD5sJ0aECopy
Shown once. Stored as a hash, never in plain text.
Scopes · AI · staging
Grant only what this connection needs.
site.read
WordPress/PHP versions and safe environment metadata
theme.read
Theme metadata and registered post types/taxonomies
plugins.read
Plugin names, versions and status
logs.readPRO
Controlled access to logs
files.readPRO
Only where explicitly permitted
files.writePRO
Off by default · admin enablement · allowlist only
files.write is off by default and can only be enabled by an administrator, for allowlisted files only.
AI Site Bridge · Lite · Free

A safe, read-only connection.

Lite is deliberately read-only. It gives your AI tools the site context it needs, and it does not provide filesystem access or code execution.

READ ONLY
site.readtheme.readplugins.read
Get Lite Free
  1. 1
    Create a credential
    Name it and choose read scopes.
    aisb_live_…3f9a
  2. 2
    Connect your AI workflow
    Use the credential for every request.
    Bearer token
  3. 3
    Request context
    Call an explicit read capability.
    GET /v1/site
  4. 4
    Receive a safe response
    Redacted, rate-limited and size-limited.
    200 · redacted
  5. 5
    Audit event recorded
    You can see what was requested and when.
    site.read · allowed
  • Secure connection authentication
  • Separate high-entropy connection credentials
  • Create connection credential
  • Name credential
  • Revoke credential
  • Rotate credential
  • Capability-based REST API
  • site.read
  • theme.read
  • plugins.read
  • Safe WordPress environment metadata
  • WordPress/PHP version information
  • Theme metadata
  • Plugin metadata
  • Registered post types/taxonomies
  • Safe development information
  • Secret redaction
  • Rate limiting
  • Request-size limits
  • Authentication protection
  • Basic audit events
  • Strictly read-only architecture
AI Site Bridge Pro · Premium

A controlled development workflow, with explicit boundaries.

Pro adds scoped access to logs and permitted files, and optional file changes that are off by default, limited to an allowlist, reviewed as a diff, backed up and reversible.

Get Pro
  1. 01
    Admin enables write mode
    Off by default. Only an administrator can switch it on.
  2. 02
    Define file allowlist
    Paths are validated; traversal is blocked.
  3. 03
    The AI proposes a change
    Within allowlisted files only.
  4. 04
    Diff review
    You see exactly what changes.
  5. 05
    Backup, then write
    A backup is made before an atomic change.
  6. 06
    Rollback if needed
    Restore the previous version.
  7. 07
    Advanced audit log
    Every step is recorded.
Review change
wp-content/themes/storefront-child/functions.php
✓ In allowlist
41add_action( 'woocommerce_before_cart', 'stride_cart_notice' );
42-function stride_cart_notice() { echo 'Free shipping over 50'; }
42+function stride_cart_notice() {
43+ echo esc_html__( 'Free shipping over €75', 'stride' );
44+}
Backup created before write · atomic apply · rollback availableRejectApprove and apply
Write mode
StatusOFF by default
Enabled byAdministrator only
File allowlist
themes/storefront-child/*.phpthemes/storefront-child/assets/*.css
Emergency kill switch
Disable every connection at once.
Disconnect all
  • Expanded secure development capabilities
  • Advanced scoped access
  • Controlled logs.read capabilities
  • Controlled files.read where explicitly permitted
  • Optional controlled files.write workflows
  • Write mode OFF by default
  • Explicit administrator enablement
  • File allowlists
  • Path validation
  • Protection against path traversal
  • Backup-before-write
  • Diff review workflows
  • Atomic controlled changes
  • Rollback support
  • Advanced WooCommerce inspection
  • Advanced audit logging
  • Advanced credential/scoping controls
  • Emergency kill switch
  • Extended developer diagnostics
  • Commercial updates and support
Security architecture

Secure by design, not by configuration.

The safe defaults are built into the architecture. There is nothing to forget to switch off.

scopes

Scoped capabilities

Each credential can only call the capabilities it was granted.
credentials

Separate connection credentials

High-entropy keys, separate from WordPress user passwords.
redaction

Secret redaction

Sensitive values are removed from every response.
revoke

Credential revocation

Revoke or rotate a credential instantly.
limits

Rate limiting

Rate and request-size limits protect the site.
audit

Audit trail

Every request is recorded with credential and result.
explicit

Explicit permissions

Nothing is allowed unless it is explicitly granted.
no /execute

No generic execute endpoint

There is no endpoint to run commands, PHP or SQL.
write: off

Write disabled by default

In Pro, write access stays off until an admin enables it.
allowlist

Controlled file boundaries

Allowlists, path validation and traversal protection.
Audit trail

Every request, on the record.

See which credential called which capability, when, and with what result. Lite records basic audit events; Pro adds advanced audit logging.

Audit log
Credential: All ▾Result: All ▾Export CSV
TIMECREDENTIALCAPABILITYDETAILRESULT
14:02:11 AI · staging site.read GET /v1/site · 2.1 KB · 38 ms Allowed
14:02:12 AI · staging plugins.read GET /v1/plugins · 24 items Allowed
14:03:40 AI · staging files.read wp-config.php · outside allowlist Denied
14:05:02 AI · staging files.write functions.php · diff approved by admin · backup #118 Applied
14:09:17 CI pipeline plugins.read 61 requests in 60 s Rate limited
14:12:55 Old laptop site.read Credential revoked on 12 Aug Denied
14:20:03 [email protected] credentials Rotated “AI · production” Admin
14:31:48 [email protected] kill switch Test: all connections disabled for 30 s Admin
Lite vs Pro

Read-only with Lite. Controlled development with Pro.

Lite vs Pro feature comparison for AI Site Bridge
FeatureLiteFreeProFrom €59 / year
Secure connection authentication✓✓
Separate high-entropy credentials: create, name, revoke, rotate✓✓
Capability-based REST API✓✓
site.read, theme.read, plugins.read✓✓
WordPress/PHP, theme, plugin, post type and taxonomy metadata✓✓
Secret redaction✓✓
Rate limiting and request-size limits✓✓
Authentication protection✓✓
Audit loggingBasic eventsAdvanced
Access modelStrictly read-onlyScoped + controlled write
Controlled logs.read—✓
Controlled files.read where explicitly permitted—✓
Controlled files.write workflows—Optional · off by default
File allowlists, path validation, traversal protection—✓
Backup-before-write, diff review, atomic changes, rollback—✓
Advanced WooCommerce inspection—✓
Advanced credential/scoping controls—✓
Emergency kill switch—✓
Extended developer diagnostics—✓
Commercial updates and support—✓
Not available in any edition
Unrestricted shell accessNeverNever
Arbitrary PHP execution or evalNeverNever
Unrestricted SQLNeverNever
Unrestricted filesystem accessNeverNever
wp-config secrets and WordPress saltsNeverNever
User passwordsNeverNever
Unrestricted remote code executionNeverNever
Get Lite FreeGet Pro
Pricing

AI Site Bridge Pro

Yearly licence with all Pro capabilities, commercial updates and support.

Lite

Read-only connection
Free
Get Lite Free
  • site, theme, plugins.read
  • Credential management
  • Redaction and rate limits
  • Basic audit events

Pro · Single site

For one site
€59/ year
Get Pro
  • 1 website
  • All Pro capabilities
  • Updates and support

Pro · Agency

For client websites
€249/ year
Get Pro
  • Unlimited websites
  • All Pro capabilities
  • Priority support

Need more plugins? The Pro Bundle includes all six Pro plugins for €149 / year.

Developer FAQ

More detail in the documentation and the security model.

Can an AI tool change my site with Lite?

No. Lite is strictly read-only. It has no write capabilities, no filesystem access and no code execution.

Is there an endpoint to run commands, PHP or SQL?

No. There is no generic execute endpoint in Lite or Pro. The plugin does not provide shell access, arbitrary PHP execution, eval or unrestricted SQL.

Which data is never exposed?

wp-config secrets, WordPress salts and passwords are never exposed. Secret redaction removes sensitive values from responses.

How do connection credentials work?

Each connection gets its own high-entropy credential, separate from WordPress user accounts. You can name, scope, rotate and revoke credentials at any time.

How does write access work in Pro?

Write mode is off by default and must be explicitly enabled by an administrator. Changes are limited to allowlisted files, paths are validated, a backup is made first, you review the diff, and changes can be rolled back.

Can Pro read any file on my server?

No. files.read only works where it has been explicitly permitted, with path validation and protection against path traversal.

What if I need to cut off access immediately?

Revoke a single credential, or use the emergency kill switch in Pro to disable all connections at once.

Is every request logged?

Lite records basic audit events. Pro adds advanced audit logging with credential, capability, detail and result.

What happens when my Pro licence expires?

The plugin keeps working. You stop receiving commercial updates and support until you renew.

Useful context for AI. Full control for you.

Start with a free, read-only connection. Move to Pro when you need a controlled development workflow with explicit boundaries.