=== AI SEO Automation - AYSA ===
Contributors: aysaai
Tags: seo, technical seo, keyword research, on-page seo, rank tracking
Requires at least: 5.9
Requires PHP: 8.0
Tested up to: 7.1
Stable tag: 1.5.0
License: GPLv2 or later
License URI: http://www.gnu.org/licenses/gpl-2.0.html

Guided SEO research, technical review, on-page and off-page planning, and monitoring with explicit approvals for costs and site changes.

== Description ==

AYSA is a service-backed SEO workspace for WordPress. Agent8 guides an administrator from setup and keyword research through technical review, on-page and off-page planning, and recurring monitoring.

AYSA performs read-only discovery and analysis autonomously where it is safe. Provider costs, publication, orders, and material site changes remain behind explicit administrator approval. Opening a review does not by itself start a paid run or modify the site.

= Features =

* **Guided Agent8 journey**: Follow one resumable workflow from activation and business context to research, implementation reviews, and monitoring.
* **Keyword research and mapping**: Discover and review keywords, associate them with validated public pages, and route missing-page opportunities into a separate content plan.
* **Technical SEO review**: Inspect crawl findings, PageSpeed, Schema, redirects, sitemap/robots, internal links, image ALT text, and WebP opportunities before any controlled apply action.
* **On-page review**: Review metadata, content, AEO, internal-linking, image, and execution evidence with separate approvals for generation and writes.
* **Off-page planning**: Review backlink, authority, marketplace, link-exchange, local, and social opportunities without automatic ordering or publishing.
* **Monitoring**: Run approved recurring Search Console and Google position checks, with AI Visibility kept as a separate optional approval.
* **Human control**: Display cost caps before paid work and require explicit approval for provider spend, publication, orders, and material WordPress changes.
* **Romanian and English interface**: Keep the Agent8 shell, progress journey, reviews, and approval boundaries aligned with the selected interface language.
* **AI Visibility (feature flagged)**: Measure how configured answer engines describe, cite, and recommend a confirmed brand, then review evidence-backed recommendations before sending approved proposals to existing AYSA SEO workflows.

= External Services =

This plugin connects to AYSA services because the SEO research, AI-assisted recommendations, activation, billing, credits, worker status, Google integration orchestration, and projection synchronization are provided by AYSA as a Software as a Service platform.

The plugin may send the following data to AYSA services after the plugin is activated and configured: site URL and host, WordPress user ID for the active administrator workflow, AYSA activation/access key, project and website identifiers, selected language, Business Profile setup data entered by the administrator, SEO profile fields, page/post/product/category metadata needed for SEO analysis, keyword and ranking data, audit snapshots, action status, billing/credit usage events, and email notification metadata.

When the feature-flagged AI Visibility module is enabled, the plugin may also send confirmed brand names and aliases, topics, personas, competitors, claims, measurement scenarios, selected answer-engine keys, locale/location, run approvals and action-plan selections to `https://api.aysa.ai`. If the separately feature-flagged Commerce analysis is enabled on a WooCommerce site and an administrator requests the analysis, the plugin also sends a bounded read-only snapshot of published product names, URLs, identifiers, prices, currencies and stock states. If the separately feature-flagged Knowledge Base is enabled and an administrator requests a sync, the plugin sends a bounded read-only snapshot of up to 100 published WordPress pages/posts, including their titles, canonical URLs, modification dates and plain-text content. Knowledge Base content is encrypted server-side, versioned and marked for factual review; it does not automatically confirm marketing claims. AYSA performs provider requests, extraction, aggregation, billing and scheduling server-side. The plugin does not send these requests directly to answer-engine providers, and opening an AI Visibility report does not start a provider request or debit credits. Opening a Commerce, Knowledge Base or source-correlation report is also read-only and non-billable.

The plugin connects to:

* `https://api.aysa.ai` for activation, project binding, SEO research, worker orchestration, Google/OAuth brokered operations, wallet/credit synchronization, projection sync, and AI-assisted SEO actions.
* `https://app.aysa.ai` for account, website, activation key, billing, checkout, and user-facing AYSA application links.
* `https://www.googleapis.com/pagespeedonline/v5/runPagespeed` when an administrator requests or opens the PageSpeed technical review. The plugin sends the public page URL, desktop or mobile strategy, the performance category, and an optional site-configured PageSpeed API key to Google so it can return Lighthouse performance metrics and optimization opportunities. Google PageSpeed API documentation is available at `https://developers.google.com/speed/docs/insights/v5/get-started`; Google API terms and privacy information are available at `https://developers.google.com/terms` and `https://policies.google.com/privacy`.

Operational error forwarding is disabled by default. The plugin keeps its existing error-reporting hook for explicitly managed installations, but it contacts no error-ingest server unless the site owner deliberately configures both `AYSA_ERROR_CENTER_INGEST_ENDPOINT` and `AYSA_ERROR_CENTER_INGEST_SECRET`, or their equivalent WordPress options. When enabled, that owner-selected endpoint receives a redacted error code and message, bounded technical context, project ID, site host, run/action/request identifiers, severity, and a deduplication fingerprint. It never reuses the wallet secret for this purpose.

An AYSA account and activation/access key are required for the plugin's service-backed features. Terms and privacy information are available at `https://aysa.ai/terms` and `https://aysa.ai/privacy`.

= Privacy And Data Retention =

The plugin stores activation and project binding data in the WordPress database so the site remains connected to the correct AYSA project. It may store local SEO snapshots, keyword associations, audit history, wallet/credit state, notification state, and generated workflow state.

The plugin exposes projection sync endpoints for AYSA service callbacks. These endpoints require a bearer secret, reject oversized payloads, and are rate limited. They are used to synchronize worker results back into the local WordPress database.

The plugin may send email notifications for AYSA workflows such as audit completion, approval requests, or billing/order events. AYSA branding/signatures are limited to AYSA-generated emails only.

AI Visibility raw provider payloads are retained server-side according to the account's configured entitlement and retention policy. Optional first-party crawler evidence accepts only a separately enabled, privacy-reviewed structured server/CDN import; it strips query strings, IP addresses and raw user-agent strings before persistence, stores only versioned user-agent classifications and bounded aggregates, and applies its configured retention period. The WordPress plugin does not expose a raw-log upload control. Knowledge Base source bodies are kept as encrypted private payloads; normal source lists and exports expose metadata and bounded evidence excerpts, not encryption keys or unrestricted source bodies. Tenant-scoped AI Visibility data export is paginated and excludes server credentials and encrypted-storage identifiers. Erasure uses a separate expiring token, exact confirmation phrase and active-run guard, and keeps a minimal deletion audit record. The plugin receives bounded report and evidence projections rather than provider credentials or unrestricted raw payload archives. Paid measurements and recurring schedules require their documented explicit approvals.

Some technical SEO actions need to update WordPress root files in order to perform the requested operation:

* `.htaccess` may be updated when an administrator explicitly creates, removes, or marks redirect/Gone rules from the AYSA technical optimization tools.
* `robots.txt` may be updated when an administrator explicitly saves the robots editor content or restores the recommended robots.txt content.
* `sitemap_index.xml` may be generated or replaced when an administrator explicitly runs the AYSA sitemap generator.

These file writes are not automatic background writes. They are initiated from administrator tools, require WordPress nonce and capability checks, validate/sanitize the submitted data, check file or directory writability before writing, and return an error if WordPress cannot safely update the target file. They are required for the redirect, Gone URL, robots.txt, and sitemap features to work directly from WordPress.

On uninstall, plugin tables are preserved unless the administrator explicitly enabled deletion of AYSA tables. Plugin options listed by the uninstall script and the current site's authentication binding are removed when the plugin is deleted.

== Installation ==

1. Upload the `aysaaiseo` folder to the `/wp-content/plugins/` directory
2. Activate the plugin through the 'Plugins' menu in WordPress
3. Navigate to 'Aysa.ai' in your WordPress admin menu to access the dashboard

== Frequently Asked Questions ==

= Does this plugin require API credentials? =

Yes. The plugin requires an active AYSA account, authentication, and a valid activation/access key to unlock features.

= Can I use this plugin on multiple sites? =

The plugin code is licensed under GPL v2. Each site must be connected separately to an AYSA project, and service-backed features depend on the account and entitlements associated with that site.

= Does this plugin support WordPress Multisite? =

AYSA AI SEO can be activated separately on an individual site in a WordPress Multisite network. Network-wide activation is not supported because project binding, authentication, billing, schedules, and local workflow tables are scoped to one site. The plugin refuses network-wide activation instead of creating an incomplete shared installation.

= Why does the plugin need to write to .htaccess, robots.txt, or sitemap_index.xml? =

Those writes are only used for administrator-requested technical SEO actions. Redirect and Gone URL tools need `.htaccess` rules on Apache-based sites. The robots editor needs to save `robots.txt`. The sitemap generator needs to write the AYSA sitemap file. The plugin checks permissions and nonces before these actions and reports an error instead of writing if WordPress cannot update the file safely.

== Screenshots ==

1. Agent8 Monitoring in Romanian, showing the completed SEO journey, Google position tracking, and the next scheduled refresh.
2. The same Agent8 Monitoring workspace in English, with Search Console and SERP status plus clear approval boundaries.

== Support ==

For support, please visit our [help center](https://aysa.ai/help/).

== Changelog ==

= 1.5.0 =
* Add the feature-flagged AI Visibility and Recommendation Engine with tenant-scoped evidence, explicit paid-run approval, bounded failure retry, review-only extraction reprocessing, canonical action-plan handoff, verified impact readback, configurable entitlements, and default-off scheduling.
* Add the guided Agent8 SEO journey with explicit cost, publication, order, and material-write approval boundaries.
* Improve responsive and keyboard access for Technical, On Page, Off Page, and Monitoring workspaces.
* Align the Romanian and English progress journey and release-facing descriptions with the verified product behavior.

= 1.4.0 =
* Controlled beta release for manual Agent8 v1.4 testing.
* Public download package and runtime labels aligned to the controlled beta channel.

= 1.3.131-beta.7 =
* Split featured and inline article image generation into separate requests to avoid API timeouts.

= 1.3.131-beta.6 =
* Generate distinct featured and inline article images for Content Strategy posts.

= 1.3.131-beta.5 =
* Publish controlled beta update after Agent8 content calendar cadence fixes.

= 1.3.131-beta.4 =
* Disable Agent 8 QA and reset controls by default for controlled beta builds.

= 1.3.131-beta.3 =
* Route post-activation apprentice redirects to the registered Agent 8 beta page.

= 1.3.131-beta.2 =
* Allow the Activation Key async conversation request through the pre-activation AJAX gate.

= 1.3.131-beta.1 =
* Gate the beta admin root behind Activation Key until a valid access key exists.
* Hide Agent8 QA/debug/full reset controls in controlled beta unless QA is explicitly enabled.

= 1.2.18 =
* Publish important conversational events to AYSA Notification Center.
* Send keyword refresh completion/failure and approval-required events through the app notification pipeline.
* Keep plugin chat notifications aligned with app notifications and conversational email delivery.

= 1.2.17 =
* Moved keyword suggestion refresh to a background worker flow in chat and Keyword Discovery.
* Added live completion/failure notifications for background keyword refresh jobs.
* Improved async intent contract for keyword refresh in the conversational agent.

= 1.2.1 =
- Fix duplicate "Connect Google" setup button and add inline Google CTA inside the setup chat.

= 1.2.0 =
* Introduced AYSA Apprentice as the main novice-first experience
* Unified setup and execution into a single visible agent flow
* Reduced visible navigation so users can work through the agent without module hopping
* Improved action-first guidance with approval before sensitive SEO changes

= 1.1.0 =
* Fixed credit display issues in settings page - now loads credits from dashboard component
* Implemented proper credit analytics loading with current balance, total used, monthly usage, and daily average
* Fixed transaction history balance calculations - now correctly shows running balance from current credits
* Enhanced credit data loading with proper error handling and fallback mechanisms
* Improved transaction formatting with proper date display and transaction type badges
* Added comprehensive credit summary statistics and transaction history rendering
* Fixed "Balance After" calculations to show correct historical balances
* Enhanced credit component integration across all settings page sections

= 1.0.9 =
* Converted settings page from jQuery to plain JavaScript for better compatibility
* Fixed "Unexpected end of input" syntax error by properly closing all functions
* Replaced jQuery AJAX calls with native fetch API
* Improved tab switching functionality using vanilla JavaScript
* Enhanced error handling and null checks throughout the settings page
* Added proper function closures and modular code structure
* Fixed authentication status display and API controls
* Improved range input functionality and advanced settings
* Made utility functions globally available for onclick handlers

= 1.0.7 =
* Fixed settings page display issues - added missing HTML content structure
* Resolved JavaScript errors preventing settings page from loading
* Added proper null checks for DOM elements to prevent errors
* Fixed authentication status display and chart rendering issues
* Enhanced settings page with complete tab navigation and content areas
* Improved error handling for missing DOM elements

= 1.0.6 =
* Added calculable "Balance After" field in credit transaction history
* Improved credit analytics display with proper balance tracking
* Enhanced transaction history with running balance calculations
* Fixed horizontal tab navigation in settings page
* Added proper date formatting for transaction history

= 1.0.5 =
* Enhanced dashboard with call-to-action buttons
* Improved user experience with better navigation

= 1.0.0 =
* Initial release

== Upgrade Notice ==

= 1.5.0 =
This release aligns the public WordPress.org package with AYSA 1.5.0, preserves existing site/project/authentication data, removes the private updater from the public distribution, and keeps paid or write-capable workflows behind their existing approval and feature gates.
