Overview
AI Site Bridge is a secure capability layer between WordPress and your AI-assisted development workflow. Your AI tools never talk to WordPress directly: they call explicit capabilities with a scoped credential, every response is redacted and limited, and every request is recorded in the audit log.
| Settings and credentials | Tools → AI Site Bridge |
|---|---|
| REST namespace | /wp-json/ai-site-bridge/v1/ |
| Requirements | WordPress |
| Editions | Lite: free on WordPress.org · Pro: from €59 / year |
Quick start
Install and activate Lite
Install AI Site Bridge from WordPress.org and activate it. Open Tools → AI Site Bridge.
Create a credential
Click “+ Create credential”, give it a name (for example “AI · staging”) and choose the read scopes it needs. Use one credential per connection.
Copy the key
The key is shown once. It is stored as a hash, never in plain text. Store it in your AI workflow’s secret storage.
Connect your AI workflow
Send the key as a bearer token with every request: Authorization: Bearer aisb_live_…
Request context
Call a read capability, for example GET /wp-json/ai-site-bridge/v1/site. The response is redacted, rate-limited and size-limited.
Check the audit log
Every request is recorded with credential, capability, detail and result. Use the Context preview to see exactly what a credential can read.
Capability reference
Each credential gets one or more scopes. A credential can only call the capabilities of the scopes it was granted.
| Scope | Returns | Edition |
|---|---|---|
site.read | WordPress and PHP versions, multisite flag, environment type and other safe environment metadata. Secrets are redacted. | Lite |
theme.read | Active theme, version, parent theme, block-theme flag and registered post types and taxonomies. | Lite |
plugins.read | Plugin names, versions and status (active, inactive, update available). | Lite |
logs.read | Controlled access to logs. | PRO |
files.read | Read files only where explicitly permitted, with path validation and traversal protection. | PRO |
files.write | Off by default. Enabled by an administrator only, for allowlisted files, with diff review, backup-before-write and rollback. | PRO |
REST endpoints
All requests need a bearer token. Responses are JSON, redacted, rate-limited and size-limited.
curl https://yourstore.com/wp-json/ai-site-bridge/v1/site \
-H "Authorization: Bearer aisb_live_…"
| Method | Endpoint | Scope | Description |
|---|---|---|---|
GET | /wp-json/ai-site-bridge/v1/site | site.read | Safe environment metadata. |
GET | /wp-json/ai-site-bridge/v1/theme | theme.read | Theme metadata and the content model. |
GET | /wp-json/ai-site-bridge/v1/plugins | plugins.read | Installed plugins with version and status. |
Error codes
| Status | Meaning |
|---|---|
401 | The credential is missing, invalid or revoked. |
403 | The credential doesn’t have the scope, or the path is outside the allowlist. |
413 | The request is larger than the request-size limit. |
429 | Rate limit reached. Wait and retry. |
Security model
Scoped capabilities
Each credential can only call the capabilities it was granted. Nothing is allowed unless it is explicitly granted.
Separate credentials
High-entropy keys, separate from WordPress user passwords. Name, rotate and revoke them at any time.
Secret redaction
wp-config secrets, WordPress salts and passwords are never exposed. Sensitive values are removed from every response.
Limits and audit
Rate and request-size limits protect the site. Every request is recorded in the audit log.
No execute endpoint
There is no endpoint to run commands, PHP or SQL, in Lite or Pro.
Write boundaries (Pro)
Write mode is off by default and only an administrator can enable it. Changes are limited to allowlisted files, reviewed as a diff, backed up first, applied atomically and can be rolled back. The emergency kill switch disables every connection at once.
Never exposed, in Lite or Pro
- Unrestricted shell access
- Arbitrary PHP execution or eval
- Unrestricted SQL
- Unrestricted filesystem access
- wp-config secrets and WordPress salts
- User passwords
- Unrestricted remote code execution
Upgrading to Pro
- Choose a licence on the pricing section of AI Site Bridge, or take the Pro Bundle.
- Download AI Site Bridge Pro from your account.
- Upload it under Plugins → Add New → Upload Plugin and activate it.
- Enter your licence key in the plugin settings to receive updates and support.
Pro builds on Lite, so your existing settings and data stay in place.
FAQ
Can an AI tool change my site with Lite?
No. Lite is strictly read-only. It has no write capabilities, no filesystem access and no code execution.
Is there an endpoint to run commands, PHP or SQL?
No. There is no generic execute endpoint in Lite or Pro. The plugin does not provide shell access, arbitrary PHP execution, eval or unrestricted SQL.
Which data is never exposed?
wp-config secrets, WordPress salts and passwords are never exposed. Secret redaction removes sensitive values from responses.
How do connection credentials work?
Each connection gets its own high-entropy credential, separate from WordPress user accounts. You can name, scope, rotate and revoke credentials at any time.
How does write access work in Pro?
Write mode is off by default and must be explicitly enabled by an administrator. Changes are limited to allowlisted files, paths are validated, a backup is made first, you review the diff, and changes can be rolled back.
Can Pro read any file on my server?
No. files.read only works where it has been explicitly permitted, with path validation and protection against path traversal.
What if I need to cut off access immediately?
Revoke a single credential, or use the emergency kill switch in Pro to disable all connections at once.
Is every request logged?
Lite records basic audit events. Pro adds advanced audit logging with credential, capability, detail and result.
What happens when my Pro licence expires?
The plugin keeps working. You stop receiving commercial updates and support until you renew.
Troubleshooting
- I lost my key
- Keys are shown once and stored as a hash. Rotate the credential to get a new key; the old key stops working.
- A request returns 403
- Check the credential’s scopes in Tools → AI Site Bridge. For files.read and files.write, check the allowlist.