Xophz Magic Hookshot
Two-way webhook manager and event dispatcher latching WordPress events onto external APIs and webhooks.
by Hall of the Gods, Inc. · github.com/hallofthegods/xophz-compass-hookshot · website
Install
The author publishes release zips, so WP-CLI can install straight from GitHub:
wp plugin install https://github.com/hallofthegods/xophz-compass-hookshot/releases/download/v26.9.7/xophz-compass-hookshot-26.9.7.zipDeclares an update source (https://github.com/HalloftheGods/xophz-compass-hookshot), so updates arrive through the plugin's own updater.
Readme
🪝 Xophz Magic Hookshot
Enterprise-grade incoming & outgoing webhook engine, payload transformation, signature verification, and automated bridge routing for the Xophz COMPASS ecosystem.
⚡ Overview
Xophz Magic Hookshot is the centralized webhook hub and automation bridge for WordPress and the COMPASS platform. It acts as an intelligent event gateway, allowing COMPASS to seamlessly latch onto external services (GitHub, Slack, Discord, Zapier, Make, custom APIs) and internal ecosystem tools (Questbook CRM, Bomb Bag MA, XP Gamification System).
Hookshot provides robust security guarantees, exponential backoff retries, health tracking, payload mapping, and zero-downtime auto-updates for plugins via GitHub release webhooks.
✨ Key Features
📥 Incoming Webhook Gateway
- Secure REST Endpoints: Dynamic endpoints under
/wp-json/xophz/v1/hookshot/incoming/{secret}. - Verification Challenges: Built-in verification endpoint
/wp-json/xophz/v1/hookshot/verify/{secret}supporting challenge-response handshakes. - Payload Safety: Enforces maximum payload size limits (1MB default) and prevents depth loops (
X-Hookshot-Depth).
📤 Outgoing Webhook Dispatcher
- Action Hook Binding: Automatically trigger webhooks when specific WordPress actions occur.
- Async Dispatching: Non-blocking background dispatches for high-concurrency environments.
- Infinite Loop Safeguard: Tracks call stack depth up to 5 levels to block recursive loops.
🛡️ Security & Authentication System
- HMAC Signature Verification:
- Stripe Format:
t={timestamp},v1={signature}with timestamp tolerance checks against replay attacks. - GitHub Format: Supports standard
sha256=andsha1=signatures. - Custom Headers: Configurable signature header names (defaults to
X-Hookshot-Signature).
- Stripe Format:
- IP Whitelisting: Restrict incoming calls by source IP addresses (
X-Forwarded-Foraware). - Rate Limiting: Custom per-webhook throughput caps backed by transients.
- Multi-Auth Support: Bearer Tokens, Basic Auth (Base64), and custom API Key headers (
X-API-Key).
🌉 Automated Bridge System
Hookshot Bridges automatically turn raw incoming webhooks into executable actions across COMPASS:
| Bridge | Description | Key Capabilities |
|---|---|---|
📦 github_plugin_release |
DevOps Auto-Deployment | Auto-updates plugins on GitHub releases (published / released). Supports Git pulls, automatic backup/rollback, and private repo tokens. |
📇 questbook_contact |
CRM Lead Capture | Auto-creates or updates contacts in Questbook CRM from payload data. |
✉️ bombbag_subscribe |
Marketing Automation | Subscribes incoming leads directly to Bomb Bag mailing lists. |
⭐ xp_grant |
Gamification Engine | Dynamically grants XP to users upon external triggers. |
⚡ wp_action |
Custom Developer Hook | Fires custom WordPress actions with payload parameters. |
🔄 Transformation & Payload Mapping
- JSONPath Mapping: Map incoming/outgoing payload fields using dot-notation (
$.event,$.user.email, or static values). - Presets: Built-in payload mapping presets for Slack, Discord, Zapier, and Make (Integromat).
- Live Preview: Preview payload transformations before persisting rules.
🔁 Resilience & Retry Engine
- Exponential Backoff: Automatic retries scheduled at 2 mins, 15 mins, 1 hr, and 6 hrs.
- Action Scheduler Integration: High-performance background scheduling with fallback to
WP-Cron. - Dead Letter Queue: Failed webhooks exceeding max retry attempts are moved to the Dead Letter Queue for inspection and manual replay.
- Log Retention: Built-in Garbage Collection (
Hookshot_GC) automatically purges logs older than 30 days.
📊 Health Tracking & Monitoring
- Real-time Status: Categorizes webhooks as
Healthy(Green),Degraded(Yellow, ≥10% failure rate), orCritical(Red, ≥50% failure rate). - Degraded Action Trigger: Fires
xophz_hookshot_health_degradedwhen failure rates spike. - REST Dashboard API: Full suite of management endpoints under
/wp-json/xophz-hookshot/v1/.
🚀 REST API Endpoints
Public Webhook Routes (xophz/v1)
POST /wp-json/xophz/v1/hookshot/incoming/{secret}- Incoming webhook ingestion.POST /wp-json/xophz/v1/hookshot/verify/{secret}- Challenge-response endpoint.
Dashboard REST API (xophz-hookshot/v1)
GET /wp-json/xophz-hookshot/v1/webhooks- List all configured webhooks.GET|POST /wp-json/xophz-hookshot/v1/webhooks/{id}- Retrieve or update a webhook configuration.POST /wp-json/xophz-hookshot/v1/webhooks/{id}/test- Send a test payload.GET /wp-json/xophz-hookshot/v1/webhooks/{id}/logs- Fetch execution logs for a webhook.GET /wp-json/xophz-hookshot/v1/webhooks/{id}/health- Get health stats for a webhook.GET /wp-json/xophz-hookshot/v1/dead-letters- View dead letter queue.POST /wp-json/xophz-hookshot/v1/dead-letters/{id}/retry- Manually retry a dead letter event.GET /wp-json/xophz-hookshot/v1/stats- Aggregate system health stats.GET /wp-json/xophz-hookshot/v1/bridges- Available bridge configurations.GET /wp-json/xophz-hookshot/v1/presets- Transformation presets.
🛠️ Installation & Setup
- Clone or extract
xophz-compass-hookshotinto your WordPress plugins directory:wp-content/plugins/xophz-compass-hookshot - Ensure core COMPASS plugin (
xophz-compass) is activated first. - Activate Xophz Magic Hookshot in WordPress Admin (
Plugins > Installed Plugins). - Access the Webhook Management interface via COMPASS ITSM Dashboard or REST API.
🧪 Developer Hooks & Actions
Hookshot provides developer actions and filters for custom integrations:
// Listen for incoming webhook dispatches
add_action( 'xophz_hookshot_incoming', function( $payload, $webhook_id ) {
// Custom handling for incoming payload
}, 10, 2 );
// Modify outgoing payload before transmission
add_filter( 'xophz_hookshot_outgoing_payload', function( $payload, $webhook_id, $event ) {
$payload['custom_meta'] = 'COMPASS-System';
return $payload;
}, 10, 3 );
// Register custom bridges
add_action( 'xophz_hookshot_register_bridges', function() {
Hookshot_Bridges::register( 'my_custom_bridge', [
'name' => 'Custom Automation',
'description' => 'Triggers internal service on incoming webhook.',
'icon' => 'fad fa-cogs',
'category' => 'Custom',
'fields' => [ 'endpoint', 'token' ],
'handler' => 'my_custom_bridge_handler_callback',
] );
} );
📄 License & Attribution
Developed with ❤️ by Hall of the Gods, Inc.
Licensed under the GNU General Public License v2.0 or later.
Read the full README on GitHub →
Releases
| Tag | Published | Asset | Downloads |
|---|---|---|---|
| v26.9.7 | Sep 8, 2026 | xophz-compass-hookshot-26.9.7.zip | 1 |
| v26.9.8 | Sep 8, 2026 | xophz-compass-hookshot-26.9.8.zip | 1 |
| v26.9.4 | Sep 5, 2026 | xophz-compass-hookshot-26.9.4.zip | 2 |
| v26.9.5 | Sep 5, 2026 | xophz-compass-hookshot-26.9.5.zip | 2 |
| v26.9.1 | Sep 2, 2026 | xophz-compass-hookshot-26.9.1.zip | 1 |
| v26.9.2 | Sep 2, 2026 | xophz-compass-hookshot-26.9.2.zip | 1 |
| v26.8.30 | Aug 31, 2026 | xophz-compass-hookshot-26.8.30.zip | 1 |
| v26.8.31 | Aug 31, 2026 | xophz-compass-hookshot-26.8.31.zip | 1 |
| v26.8.11 | Aug 11, 2026 | xophz-compass-hookshot-26.8.11.zip | 1 |
| v26.8.10 | Aug 10, 2026 | xophz-compass-hookshot-26.8.10.zip | 1 |
| v26.8.8 | Aug 9, 2026 | xophz-compass-hookshot-26.8.8.zip | 1 |
| v26.8.9 | Aug 9, 2026 | xophz-compass-hookshot-26.8.9.zip | 1 |
| v26.8.7 | Aug 7, 2026 | xophz-compass-hookshot-26.8.7.zip | 1 |
| v26.8.5 | Aug 6, 2026 | xophz-compass-hookshot-26.8.5.zip | 0 |
| v26.8.6 | Aug 6, 2026 | xophz-compass-hookshot-26.8.6.zip | 0 |
| v26.7.30 | Jul 30, 2026 | xophz-compass-hookshot-26.7.30.zip | 1 |
| v26.7.26 | Jul 26, 2026 | xophz-compass-hookshot-26.7.26.zip | 1 |
| v26.7.24 | Jul 25, 2026 | xophz-compass-hookshot-26.7.24.zip | 0 |
| v26.7.25 | Jul 25, 2026 | xophz-compass-hookshot-26.7.25.zip | 0 |
| v26.7.21 | Jul 22, 2026 | xophz-compass-hookshot-26.7.21.zip | 0 |
| v26.7.22 | Jul 22, 2026 | xophz-compass-hookshot-26.7.22.zip | 0 |