=== AI Visibility ===
Contributors: mishamanko
Tags: ai, robots.txt, chatgpt, crawlers, seo
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 0.1.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Audits and fixes the technical layer AI answer engines read, and tells you honestly what they don't.

== Description ==

AI Visibility checks and fixes the parts of your site that ChatGPT, Claude, Perplexity, Google's AI answers and Copilot actually read. Every check maps to a measured signal from a research network of 50 live sites with 200+ days of bot logs. Every fix is a button. Nothing speculative is sold as a lever.

**How it works**

* **Check, then fix, then prove.** Each card shows what it found, offers a fix, and re-checks so you can see the fix took.
* **One score.** The AI Visibility Score (0-100) weighs each card by how much AI fetchers actually request that surface: feeds about 40%, HTML pages about 25%, sitemaps about 14%, schema about 9%. Each card starts at 100 and loses 40 for a blocking problem, 15 for a warning, 5 for something to check; schema has its own table.
* **Fix everything safe.** One button runs every one-click safe fix; switches stay as you set them. Safe fixes only write this plugin's own settings, and each can be undone on its card. Any fix that sends data elsewhere is a switch you turn on yourself, and the .htaccess edit asks first.
* **Honest about the ceiling.** The plugin cannot see traffic a cache or CDN answers, change Cloudflare or host firewalls, edit other plugins' settings, or guarantee citations. A Limits page says so.

**What it checks and fixes**

* **Bot access.** Finds where each AI bot block comes from: robots.txt and who writes it, "Discourage search engines", noindex on the homepage, .htaccess rules, security plugin throttles, and firewall or CDN blocks tested from outside as each bot. Fixes: allow the AI answer bots in robots.txt; optionally block training bots and keep answer bots; remove .htaccess bot rules with a backup and a preview.
* **Feed repair.** Loads your feed the way a bot does and checks it exists, is full text, lists enough items, carries real dates, is not served stale by a cache, and includes featured images and public post types. Fixes: full posts, 50 items, feed links in the page head, featured images, cache refresh headers, chosen post types, a WebSub hub.
* **HTML cleanliness.** Loads your pages as a browser and as GPTBot and reads the raw HTML: is the article text really there, do bots get the same page, are snippets capped by nosnippet or max-snippet, is there one H1, is the update date visible. Names the lazy-render plugin when the text is missing. Fixes: allow full snippets and large previews; show a "Last updated" line.
* **Sitemap integrity.** Finds who serves the sitemap, checks it loads, that robots.txt points to it, that entries carry honest lastmod dates, that noindex pages are out, and that images and PDFs are listed. Fixes for WordPress's own sitemap: turn it back on, add lastmod dates, add a media sitemap, add the Sitemap line.
* **Schema.** Reads the JSON-LD on your pages: one connected graph or scattered blocks, stable @id values, schema that disagrees with the page, missing logo, author or dates, FAQ questions the page never shows, and types that produce no AI engagement. Fix: one server-rendered graph of the five types that matter, Organization, Person, WebSite, BreadcrumbList and Article, from your real posts and settings. When an SEO plugin prints schema, the plugin audits it and never prints a second graph.
* **Freshness and push.** Publishing cadence, posts that have decayed for six months, dates that do not add up, and IndexNow. Switches: IndexNow pings on publish, update and trash, a "Re-push this URL" link per post with realistic timelines per engine, and a monthly decay email.
* **Internal linking.** Builds a link index on click and reports pages nobody links to, with "link from" suggestions, addresses more than three folders deep, and how much of the site sits within two clicks of the homepage.
* **Media and PDF.** Images without alt text, with an inline field to write it; posts without a featured image; PDFs nobody links to or that sit outside the sitemap.
* **llms.txt.** Marked Optional and never scored: across the research network no AI bot has requested it once. The card checks the file if you have one and can serve a generated one, because it costs nothing.
* **Visitors sent by AI.** Counts people who arrived from ChatGPT, Perplexity, Claude, Gemini, Copilot and others, cached pages included, with a script under 1 KB. It stores the assistant, the page path, the day and a count. Never IPs, cookies, user agents or query strings. A salted hash of the address lives for ten seconds to stop floods.
* **AI bot log.** Which bots reached WordPress, which paths, which status codes, with impostors marked against the published IP ranges. Warns when your server refuses verified bots. Counts are a floor, because caches answer some requests first. No user agents, no humans, no IP addresses, with one exception: a Googlebot or Bingbot address is held until the daily reverse DNS check on hosts that cannot run it right away, then erased.
* **Editor checklist.** Seven yes-or-no checks per post in the block editor sidebar or a Classic Editor box: answer first, buyer phrases present, one topic, no H1 in the body, author bio page, visible update date, FAQ answered on the page.

**Why we don't**

The plugin explains everything it declines to do, with the number behind it: schema everything (six types produce ~97% of AI schema engagement), HowTo (Google retired the rich result in 2024), Speakable (no AI surface uses it), FAQ schema that invents questions the page never shows, llms.txt as a lever (zero requests across the research network), scattered JSON-LD blocks, JavaScript-injected schema, crawler rate limits tuned for humans, and promising citations.

**Coming in later versions**

Citation presence: whether your site is named in the answers to the questions your buyers ask.

== Installation ==

1. Install and activate the plugin. It opens its dashboard for you (AI Visibility in the admin menu).
2. Click "Run check" on each card: Bot access, Feed repair, HTML cleanliness, Sitemap integrity, Schema, Freshness and push, Internal linking, Media and PDF, and llms.txt. The Visitors sent by AI and AI bot log cards start counting on activation; load them any time.
3. For schema, fill in AI Visibility > Schema settings (and each author's bio page on their profile) before you turn the graph on.
4. Apply the fixes you want, or follow the steps shown for the ones only you or your host can change.

== Frequently Asked Questions ==

= Does it change anything on my site by itself? =

Two things start on activation: the AI referral beacon (a small script for logged-out visitors that counts arrivals from AI assistants) and the AI bot log (requests from known AI bots). Both have an off switch on their cards. Nothing else changes until you click a fix. Safe fixes write this plugin's own settings only and work through WordPress hooks, so switching one off puts your feed, sitemap, robots.txt or robots meta tag back as it was. The .htaccess fix asks first, shows the lines it will remove and saves a backup copy.

= Will it add links to my posts? =

No. The internal linking card lists pages nobody links to and suggests related posts to link from, with edit links. You add the link yourself. The only content the plugin writes is the alt text you type into the media card, and only for that image.

= Does it create llms.txt? =

Only if you switch it on. No AI bot has requested llms.txt across the research network, so it will not change your visibility; the card says so. If another plugin or a file already provides llms.txt, the plugin leaves it alone.

= Does it track my visitors? =

No. The AI referral script only acts when a visitor arrives from an AI assistant, and then sends the assistant's name and the page to your own site, where one counter per assistant, page and day goes up. No cookies, no IP address, no user agent, no visitor id, nothing sent anywhere else. Logged-in users are skipped. The AI bot log records bots, never people. Both can be switched off on their cards.

= Does it ping search engines? =

Only if you switch on IndexNow, which is off by default and never switched on by "Fix everything safe". Then each publish, update or trash of a post sends that one address to IndexNow, never more than once per address every 10 minutes, and never from a page view.

= I use Yoast SEO or Rank Math. Will this add a second schema block? =

No. While an SEO or schema plugin prints schema, this plugin prints none. It checks that plugin's output and links to the setting to change.

= Why no HowTo, Speakable or FAQ schema? =

HowTo and Speakable produced no measurable AI engagement across the research network. FAQ schema is read by AI fetchers, but only works when the questions are visible on the page; the plugin does not invent FAQs, and it flags FAQ schema whose questions the page never shows. The "Why we don't" page has the numbers.

= Should I block AI training bots? =

That is your choice, and the toggle is off by default. Blocking training bots keeps your content out of future models' memory, so those models will know less about you. AI search and answer bots stay allowed either way.

= Why does it say "Unclear" for a bot? =

Some firewalls challenge every bot they cannot verify. When the test Googlebot is challenged as well, the block is not aimed at AI bots, and real AI bots crawling from their own IP addresses may still get through. The plugin says so instead of guessing.

= Can it check a local or staging site? =

The WordPress checks work anywhere. The outside checks need a public address. Developers can point the check at a public address with the `aiv_site_url` filter.

== External services ==

This plugin uses the AI Bot Access Checker service at https://aibotaccesschecker.com, run by Misha Manko, to see your site the way AI bots see it from the internet.

* **Only when you click "Run check", "Re-check" or a fix (which re-checks):** the plugin sends your site address (home URL) and a random per-site token (a hash, nothing identifying), which the service echoes on its requests so your AI bot log can tell the probe from a real bot. The service requests your public homepage and robots.txt as a browser, a test Googlebot and several AI bot user agents, and returns the status codes, your robots.txt and your homepage robots tags. Site addresses are not stored; only a daily count of checks is kept.
* Nothing is sent on activation, and the plugin has no tracking.

The feed, HTML, sitemap, schema, freshness, internal linking and llms.txt checks load your own feed, pages, homepage, sitemap, robots.txt, IndexNow key file and llms.txt from your server. Nothing is sent to an outside service. The media check loads nothing.

If you switch on IndexNow (off by default), each time a post or page is published, updated or moved to the trash, the plugin sends that page's address, your site's host name, the IndexNow key and the key file's address to https://api.indexnow.org/indexnow, which shares them with the search engines that take part in IndexNow (Microsoft Bing, Yandex, Seznam, Naver and others). The same happens when you click "Re-push this URL". The search engines then load the key file from your site to verify it. Nothing else is sent. IndexNow.org is run by Microsoft, Yandex and Seznam.cz. Terms and privacy: https://www.indexnow.org/terms, documentation: https://www.indexnow.org/documentation

Google's sitemap ping endpoint (google.com/ping) is not used: Google retired it in 2023.

While the AI bot log is on (the default; switch it off on its card), a daily task downloads the IP ranges these services publish, to tell real AI bots from impostors. Nothing about your site or visitors is sent.

* OpenAI: https://openai.com/gptbot.json, https://openai.com/searchbot.json, https://openai.com/chatgpt-user.json (terms: https://openai.com/policies/terms-of-use, privacy: https://openai.com/policies/privacy-policy)
* Perplexity: https://www.perplexity.com/perplexitybot.json, https://www.perplexity.com/perplexity-user.json (terms: https://www.perplexity.ai/hub/legal/terms-of-service, privacy: https://www.perplexity.ai/hub/legal/privacy-notice)
* Anthropic: https://claude.com/crawling/bots.json (terms: https://www.anthropic.com/legal/consumer-terms, privacy: https://www.anthropic.com/legal/privacy)
* Cloudflare, to trust the visitor address it passes on: https://www.cloudflare.com/ips-v4, https://www.cloudflare.com/ips-v6 (terms: https://www.cloudflare.com/website-terms/, privacy: https://www.cloudflare.com/privacypolicy/)

The AI referral script reports only to your own site (/wp-json/aiv/v1/ref).

If you switch on "Announce a WebSub hub" (off by default), your feeds name Google's public WebSub hub at https://pubsubhubbub.appspot.com/, and each time you publish a post the plugin sends that hub the addresses of your RSS and Atom feeds, so subscribers fetch the new post. Nothing else is sent. Terms: https://policies.google.com/terms, privacy: https://policies.google.com/privacy

Privacy policy and terms: https://aibotaccesschecker.com/privacy

== Changelog ==

= 0.1.0 =
* Dashboard with the AI Visibility Score and the module card pattern.
* Bot access module with fixes for robots.txt and .htaccess. Bytespider added to the training bots.
* Feed repair module: full content, item count, feed links, featured images, custom post types, WebSub and cache headers.
* Sitemap integrity module: lastmod dates, a media sitemap, the robots.txt Sitemap line, and turning WordPress's sitemap back on.
* Schema module: emitter detection, a four-page JSON-LD audit, the five-type graph, folding WooCommerce product schema, the Schema settings page and author profile fields.
* HTML cleanliness module: article text in the raw HTML, the page bots get, snippet limits and noindex, headings, a visible update date, collapsed text; fixes for snippet rules and a "Last updated" line.
* Freshness and push module: cadence, content decay, IndexNow and odd post dates; IndexNow with "Re-push this URL", and a monthly decay email.
* One score rule for every module: 100 minus 40 per blocking problem, 15 per warning and 5 per check. "Fix everything safe" shows no count while a result is missing or over an hour old.
* "Fix everything safe" re-checks every module first and applies only the fixes the fresh results call for.
* Internal linking module: link index (content, menus, homepage), orphans with "link from" suggestions, deep addresses, homepage reach, important pages with few links.
* Media and PDF module: alt text with an inline editor, missing featured images, unlinked PDFs and PDFs outside the sitemap, featured images without dimensions.
* llms.txt module (Optional, never scored): checks an existing file and its links; optional /llms.txt and /llms-full.txt, rebuilt on publish.
* Freshness: sites with fewer than five posts get a note instead of a cadence problem.
* "Why we don't" and Limits pages.
* AI referral traffic (Optional, never scored): a beacon under 1 KB counts visitors sent by ChatGPT, Perplexity, Claude, Gemini, Copilot, You.com, Meta AI and Grok per page and day, with no personal data; 12-week chart, sources, landing pages.
* AI bot log (Optional, never scored): AI bot requests that reach WordPress, IP-verified against published ranges and reverse DNS; status codes, paths, endpoint split; a warning when servers refuse verified bots; the llms.txt card shows how often a bot asked for llms.txt.
* Editor checklist: a block editor sidebar and a Classic Editor box with seven yes-or-no checks per post and a phrases field.
* "Fix everything safe" re-checks every card after applying fixes, so cards that read another card's setting are current.
* Content decay ranks by inbound links from the link index when it is less than a day old.
