{"id":369447,"date":"2026-09-18T14:32:49","date_gmt":"2026-09-18T14:32:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/beplus-site-assistant\/"},"modified":"2026-09-19T05:28:43","modified_gmt":"2026-09-19T05:28:43","slug":"beplus-site-assistant","status":"publish","type":"plugin","link":"https:\/\/cn.wordpress.org\/plugins\/beplus-site-assistant\/","author":23527225,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.12.5","stable_tag":"2.12.5","tested":"7.1.1","requires":"6.1","requires_php":"7.4","requires_plugins":null,"header_name":"Beplus Site Assistant","header_author":"Beplus","header_description":"AI chat assistant that answers questions about your site \u2014 content, plugins, themes, forms, and features. Uses the WordPress AI Client and a custom endpoint for any OpenAI-compatible AI provider.","assets_banners_color":"abadb3","last_updated":"2026-09-19 05:28:43","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/beplus-assistant-doc.beplus-agency.cloud\/","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":115,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.12.1":{"tag":"2.12.1","author":"ducdung2026","date":"2026-09-18 14:32:26","revision":3702140},"2.12.2":{"tag":"2.12.2","author":"ducdung2026","date":"2026-09-18 17:34:42","revision":3702482},"2.12.3":{"tag":"2.12.3","author":"ducdung2026","date":"2026-09-18 17:40:51","revision":3702503},"2.12.4":{"tag":"2.12.4","author":"ducdung2026","date":"2026-09-18 17:51:02","revision":3702512},"2.12.5":{"tag":"2.12.5","author":"ducdung2026","date":"2026-09-19 05:28:43","revision":3702962}},"upgrade_notice":{"2.12.1":"<p>Security and PHP 7.4 compatibility update. Existing conversations remain intact;\nnew visitor sessions use an ownership verifier before they can be ended or timed out.<\/p>","2.12.0":"<p>A compatibility update requested by the WordPress.org review team. Your content,\nsettings and conversations are untouched, and there is nothing to reconfigure.<\/p>","2.11.0":"<p>Groundwork for the WordPress.org release: no settings change, and nothing to\nreconfigure. The assistant behaves exactly as it did in 2.10.0.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.gif":{"filename":"icon-128x128.gif","revision":3702140,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.gif":{"filename":"icon-256x256.gif","revision":3702140,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3702230,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3702230,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.12.1","2.12.2","2.12.3","2.12.4","2.12.5"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3702256,"resolution":"1","location":"assets","locale":"","width":1600,"height":1000},"screenshot-10.png":{"filename":"screenshot-10.png","revision":3702403,"resolution":"10","location":"assets","locale":"","width":1600,"height":1000},"screenshot-11.png":{"filename":"screenshot-11.png","revision":3702403,"resolution":"11","location":"assets","locale":"","width":1600,"height":1000},"screenshot-12.png":{"filename":"screenshot-12.png","revision":3702403,"resolution":"12","location":"assets","locale":"","width":1600,"height":1000},"screenshot-13.png":{"filename":"screenshot-13.png","revision":3702403,"resolution":"13","location":"assets","locale":"","width":1600,"height":1000},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3702270,"resolution":"2","location":"assets","locale":"","width":780,"height":1688},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3702273,"resolution":"3","location":"assets","locale":"","width":1600,"height":1000},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3702403,"resolution":"4","location":"assets","locale":"","width":1600,"height":1000},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3702403,"resolution":"5","location":"assets","locale":"","width":1600,"height":1000},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3702403,"resolution":"6","location":"assets","locale":"","width":1600,"height":1000},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3702403,"resolution":"7","location":"assets","locale":"","width":1600,"height":1000},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3702403,"resolution":"8","location":"assets","locale":"","width":1600,"height":1000},"screenshot-9.png":{"filename":"screenshot-9.png","revision":3702403,"resolution":"9","location":"assets","locale":"","width":1600,"height":1000}},"screenshots":{"1":"Desktop chat widget: a visitor asks a question and receives guided next steps with source links.","2":"Mobile chat widget: full-width replies, quick actions, and a message box designed for a phone screen.","3":"Welcome form: optional name and email capture before a visitor starts a conversation.","4":"AI &amp; Model settings: AI connection, model selection, and content-indexing controls.","5":"Knowledge Base: content sources, custom instructions, and the one-click site scan.","6":"Appearance &amp; FAQs: mascot style, chat colours, placement, and visitor-facing copy.","7":"Leads &amp; Email: lead-capture behaviour, notification recipients, and daily delivery settings.","8":"Security &amp; Limits: rate limits, blocked topics, and information the assistant must refuse.","9":"Embed Script: approved websites and a ready-to-paste snippet for external installation.","10":"Conversations: visitor conversations, contact details, delivery status, and transcripts.","11":"SEO Insights: recurring visitor topics and questions your current site content does not answer.","12":"Storage: retained conversation count, space usage, and cleanup controls.","13":"Export: download conversation records as CSV or JSONL by date range or newest-record count."}},"plugin_section":[],"plugin_tags":[2353,1320,5707,2364,14090],"plugin_category":[41],"plugin_contributors":[256392,270267],"plugin_business_model":[],"class_list":["post-369447","plugin","type-plugin","status-publish","hentry","plugin_tags-ai","plugin_tags-assistant","plugin_tags-chat","plugin_tags-chatbot","plugin_tags-knowledge-base","plugin_category-communication","plugin_contributors-bearsthemes","plugin_contributors-ducdung2026","plugin_committers-ducdung2026"],"banners":{"banner":"https:\/\/ps.w.org\/beplus-site-assistant\/assets\/banner-772x250.png?rev=3702230","banner_2x":"https:\/\/ps.w.org\/beplus-site-assistant\/assets\/banner-1544x500.png?rev=3702230","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/beplus-site-assistant\/assets\/icon-128x128.gif?rev=3702140","icon_2x":"https:\/\/ps.w.org\/beplus-site-assistant\/assets\/icon-256x256.gif?rev=3702140","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/beplus-site-assistant\/assets\/screenshot-1.png?rev=3702256","caption":"Desktop chat widget: a visitor asks a question and receives guided next steps with source links."},{"src":"https:\/\/ps.w.org\/beplus-site-assistant\/assets\/screenshot-2.png?rev=3702270","caption":"Mobile chat widget: full-width replies, quick actions, and a message box designed for a phone screen."},{"src":"https:\/\/ps.w.org\/beplus-site-assistant\/assets\/screenshot-3.png?rev=3702273","caption":"Welcome form: optional name and email capture before a visitor starts a conversation."},{"src":"https:\/\/ps.w.org\/beplus-site-assistant\/assets\/screenshot-4.png?rev=3702403","caption":"AI &amp; Model settings: AI connection, model selection, and content-indexing controls."},{"src":"https:\/\/ps.w.org\/beplus-site-assistant\/assets\/screenshot-5.png?rev=3702403","caption":"Knowledge Base: content sources, custom instructions, and the one-click site scan."},{"src":"https:\/\/ps.w.org\/beplus-site-assistant\/assets\/screenshot-6.png?rev=3702403","caption":"Appearance &amp; FAQs: mascot style, chat colours, placement, and visitor-facing copy."},{"src":"https:\/\/ps.w.org\/beplus-site-assistant\/assets\/screenshot-7.png?rev=3702403","caption":"Leads &amp; Email: lead-capture behaviour, notification recipients, and daily delivery settings."},{"src":"https:\/\/ps.w.org\/beplus-site-assistant\/assets\/screenshot-8.png?rev=3702403","caption":"Security &amp; Limits: rate limits, blocked topics, and information the assistant must refuse."},{"src":"https:\/\/ps.w.org\/beplus-site-assistant\/assets\/screenshot-9.png?rev=3702403","caption":"Embed Script: approved websites and a ready-to-paste snippet for external installation."},{"src":"https:\/\/ps.w.org\/beplus-site-assistant\/assets\/screenshot-10.png?rev=3702403","caption":"Conversations: visitor conversations, contact details, delivery status, and transcripts."},{"src":"https:\/\/ps.w.org\/beplus-site-assistant\/assets\/screenshot-11.png?rev=3702403","caption":"SEO Insights: recurring visitor topics and questions your current site content does not answer."},{"src":"https:\/\/ps.w.org\/beplus-site-assistant\/assets\/screenshot-12.png?rev=3702403","caption":"Storage: retained conversation count, space usage, and cleanup controls."},{"src":"https:\/\/ps.w.org\/beplus-site-assistant\/assets\/screenshot-13.png?rev=3702403","caption":"Export: download conversation records as CSV or JSONL by date range or newest-record count."}],"raw_content":"<!--section=description-->\n<p>Beplus Site Assistant adds an AI chat box to your WordPress site. Visitors can ask questions in natural language and get accurate answers based on your actual site content and structure: not generic guesses.<\/p>\n\n<p><strong>What it knows:<\/strong><\/p>\n\n<ul>\n<li>Pages, posts and products (indexed content)<\/li>\n<li>Active plugins and themes (names only)<\/li>\n<li>Navigation menus and their links<\/li>\n<li>Post types, forms, search, comments, login\/registration<\/li>\n<li>WooCommerce presence (cart, checkout)<\/li>\n<\/ul>\n\n<p><strong>Key features:<\/strong><\/p>\n\n<ul>\n<li>Floating chat widget for visitors<\/li>\n<li><strong>WordPress AI Client integration<\/strong>: reads your API key from <em>Settings \u2192 Connectors<\/em><\/li>\n<li><strong>Custom endpoint mode<\/strong>: works with any OpenAI-compatible endpoint (OpenAI, OpenRouter, Anthropic via gateway, DeepSeek, Ollama, or your own server)<\/li>\n<li>Automatic daily re-scan of your content (cron)<\/li>\n<li>Manual re-scan button in settings<\/li>\n<li>Security guardrails: describes features, never reveals code, keys or internal implementation<\/li>\n<li>Sources included with answers so visitors can verify<\/li>\n<\/ul>\n\n<p><strong>Privacy:<\/strong> the plugin never exposes your API key. Content is stored in your own database. You choose which provider receives your content.<\/p>\n\n<p><strong>Documentation:<\/strong> setup guides, screenshots and troubleshooting for every screen are published at <a href=\"https:\/\/beplus-assistant-doc.beplus-agency.cloud\/\">beplus-assistant-doc.beplus-agency.cloud<\/a>.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin answers questions with the help of an AI service. It sends data out,\nand it only works because it does: so here is exactly what leaves your site and\nwhere it goes. Nothing is sent until you connect a provider and enable the\nassistant.<\/p>\n\n<p><strong>Who receives it<\/strong><\/p>\n\n<p>The service <em>you<\/em> choose. There is no fixed destination and no account of ours\nin the middle:<\/p>\n\n<ul>\n<li>the AI provider plugin you connect under <em>Settings \u2192 Connectors<\/em> (for example OpenAI, Anthropic or Google); or<\/li>\n<li>the OpenAI-compatible endpoint you type into <strong>Custom endpoint<\/strong> mode: your own gateway, or a locally hosted model such as Ollama on your own server.<\/li>\n<\/ul>\n\n<p>In Custom endpoint mode the plugin sends your content only to the address you\nentered.<\/p>\n\n<p><strong>What is sent<\/strong><\/p>\n\n<ul>\n<li>The visitor's question, as typed.<\/li>\n<li>The excerpts from your own site content the plugin judged relevant to that question, so the answer can be grounded in your pages rather than invented.<\/li>\n<li>The site's structure summary: post types, menu names and active plugin or theme names: so the assistant can describe what the site offers.<\/li>\n<\/ul>\n\n<p><strong>What is never sent<\/strong><\/p>\n\n<ul>\n<li>Your API key, which stays in your database and is used only by your server to authenticate the request.<\/li>\n<li>The visitor's IP address, name or email address. The lead form stores those in your own database; they are not part of the AI request.<\/li>\n<li>Other visitors' conversations, or any transcript from an earlier session.<\/li>\n<\/ul>\n\n<p><strong>What is stored, and where<\/strong><\/p>\n\n<p>Everything the plugin records: the content index, the conversations, the leads\nand the analysis results: is stored in your own WordPress database. The plugin\nhas no server of its own and collects nothing.<\/p>\n\n<p><strong>Your provider's own terms<\/strong><\/p>\n\n<p>Every AI provider has its own retention and training policy for the requests it\nreceives. Which policy applies to you depends on the provider you pick, so please\nread theirs before enabling the assistant:<\/p>\n\n<ul>\n<li>OpenAI: https:\/\/openai.com\/policies\/privacy-policy<\/li>\n<li>Anthropic: https:\/\/www.anthropic.com\/legal\/privacy<\/li>\n<li>Google: https:\/\/policies.google.com\/privacy<\/li>\n<li>OpenRouter: https:\/\/openrouter.ai\/privacy<\/li>\n<\/ul>\n\n<p>If you would rather nothing left your site at all, host a model yourself and\npoint Custom endpoint mode at it.<\/p>\n\n<h4>About BePlus<\/h4>\n\n<p>This plugin is developed and maintained by BePlus, a WordPress and Shopify development studio with 10+ years of experience building themes and plugins for nonprofits and eCommerce brands.<\/p>\n\n<p>Learn more at <a href=\"https:\/\/beplusthemes.com\/\">beplusthemes.com<\/a>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>beplus-site-assistant<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install the ZIP via <em>Plugins \u2192 Add New \u2192 Upload Plugin<\/em>.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Go to <strong>Site Assistant<\/strong> in the admin menu.<\/li>\n<li><strong>Recommended:<\/strong> install an AI provider plugin (e.g. OpenAI, Anthropic, Google) and add your API key under <strong>Settings \u2192 Connectors<\/strong>. Beplus Site Assistant uses it automatically.<\/li>\n<li><em>Alternatively<\/em>, switch to <strong>Custom endpoint<\/strong> mode and enter your own OpenAI-compatible endpoint URL, API key and model.<\/li>\n<li>Click <strong>Re-scan site<\/strong> to index your content, then open the chat widget to answer questions.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"which%20ai%20providers%20are%20supported%3F\"><h3>Which AI providers are supported?<\/h3><\/dt>\n<dd><p>Two modes: <strong>(1)<\/strong> any provider plugin you install under <em>Settings \u2192 Connectors<\/em> (OpenAI, Anthropic, Google and more); <strong>(2)<\/strong> Custom endpoint mode: any provider that implements the OpenAI chat completions format (OpenAI, OpenRouter, Groq, DeepSeek, Ollama, or your own gateway), just paste the endpoint URL and API key.<\/p><\/dd>\n<dt id=\"can%20i%20choose%20the%20ai%20model%3F\"><h3>Can I choose the AI model?<\/h3><\/dt>\n<dd><p>Yes. The <strong>AI model<\/strong> field in Site Assistant settings lets you pick any model the provider exposes: for example <code>gemini-3.7-flash<\/code> to avoid high-demand 503 errors, or leave it empty to use the provider's default. It works in both Connectors and Custom endpoint modes.<\/p><\/dd>\n<dt id=\"does%20it%20reveal%20my%20code%20or%20api%20keys%3F\"><h3>Does it reveal my code or API keys?<\/h3><\/dt>\n<dd><p>No. Security guardrails instruct the assistant to describe features at a high level and refuse requests for source code, credentials or internal implementation. Your API key is stored in site options and never sent to the browser.<\/p><\/dd>\n<dt id=\"how%20often%20is%20content%20updated%3F\"><h3>How often is content updated?<\/h3><\/dt>\n<dd><p>The site is re-scanned daily via WordPress cron. You can also click <em>Re-scan site now<\/em> in settings any time.<\/p><\/dd>\n<dt id=\"what%20data%20leaves%20my%20site%3F\"><h3>What data leaves my site?<\/h3><\/dt>\n<dd><p>Only what the AI request needs: the visitor's question, the excerpts from your content that answer it, and a short summary of your site's structure. It goes to the one provider you configured: no one else. Your API key, your visitors' IP addresses and their contact details are never part of that request. See <em>External services<\/em> above for the full list.<\/p><\/dd>\n<dt id=\"does%20one%20visitor%20see%20another%20visitor%27s%20conversation%3F\"><h3>Does one visitor see another visitor's conversation?<\/h3><\/dt>\n<dd><p>No. Each conversation is separate, and the AI request contains only the current visitor's question and your own site content.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.12.5<\/h4>\n\n<ul>\n<li>Refined readme copy for a more natural writing style.<\/li>\n<\/ul>\n\n<h4>2.12.4<\/h4>\n\n<ul>\n<li>Moved About BePlus section below \"Your provider's own terms\" right above Screenshots.<\/li>\n<\/ul>\n\n<h4>2.12.3<\/h4>\n\n<ul>\n<li>Reordered sections so About BePlus displays correctly above the screenshot gallery on the WordPress.org Details tab.<\/li>\n<\/ul>\n\n<h4>2.12.2<\/h4>\n\n<ul>\n<li>Refreshed WordPress.org screenshots with selective-blur documentation captures.<\/li>\n<li>Added the About BePlus section immediately before the screenshot gallery.<\/li>\n<\/ul>\n\n<h4>2.12.1<\/h4>\n\n<ul>\n<li><strong>Protected anonymous chat sessions.<\/strong> A browser receives a high-entropy session secret only when it starts a new conversation. WordPress stores only its hash, and a missing, wrong, or cross-session secret cannot end or time out another visitor's conversation.<\/li>\n<li><strong>PHP 7.4 compatibility restored.<\/strong> Removed a PHP 8-only union return type while retaining the same documented return value.<\/li>\n<li><strong>No unimplemented shortcode claim.<\/strong> The listing now accurately describes the floating widget that the plugin ships.<\/li>\n<li><strong>Preset FAQ answers stay in the browser.<\/strong> The server only stores answers it generated itself, so a visitor cannot submit an arbitrary answer into conversation history or AI memory.<\/li>\n<li><strong>Internal worker HTTPS is verified.<\/strong> The timeout worker no longer disables certificate verification.<\/li>\n<\/ul>\n\n<h4>2.12.0<\/h4>\n\n<ul>\n<li><strong>No promotional wording in anything a visitor sees.<\/strong> The starter questions\nthat used to appear on the chat welcome screen described this company's own\nservices, before the site owner had chosen to add them. That list now ships\nempty, and the examples in the settings screen are neutral prompts about\n<em>your<\/em> site. Nothing is displayed to a visitor unless you write it yourself.<\/li>\n<li><strong>One consistent prefix across the code.<\/strong> Every function, setting, AJAX\naction and browser variable now uses the <code>beplsa_<\/code> \/ <code>beplsa<\/code> prefix instead\nof the three-letter <code>bsa<\/code>. This is what the directory requires so that two\nplugins can never collide. Nothing you configured changes.<\/li>\n<li><strong>The copy-paste embed snippet is generated by WordPress itself<\/strong> rather than\nassembled from a text template, so it always follows the platform's own\nescaping rules.<\/li>\n<li><strong>Default assistant name is now \"Site Assistant\"<\/strong>: a neutral starting point\nyou can rename to anything.<\/li>\n<\/ul>\n\n<h4>2.11.0<\/h4>\n\n<ul>\n<li><strong>Groundwork for the WordPress.org plugin directory.<\/strong> No functional change:\nyour settings, your indexed content and your conversations are untouched.<\/li>\n<li><strong>Admin pages load only what they need.<\/strong> The stylesheet and script now load\non the Site Assistant screens alone, instead of across the whole dashboard.<\/li>\n<li><strong>Admin assets are loaded the WordPress way<\/strong>, so they no longer risk loading\ntwice or clashing with another plugin on the same screen.<\/li>\n<li><strong>More of the privacy story, in plainer words.<\/strong> The readme now spells out\nwhich provider receives what, and what is never sent. See <em>External services<\/em>.<\/li>\n<\/ul>\n\n<h4>2.10.0<\/h4>\n\n<ul>\n<li><strong>New report: questions the assistant could not answer.<\/strong> Under the topic\ntable, SEO Insights now lists the subjects visitors asked about that your site\nhas no page for: \"Do you ship to Japan?\", \"What are your support hours?\".\nEach row is a page worth writing. It comes from the same one-click analysis as\nthe topics, so it costs no extra AI calls.<\/li>\n<li><strong>Honest gap detection.<\/strong> Only genuine content gaps are listed. Questions the\nassistant answered, greetings and small talk, and questions it was configured\nto refuse are all left out: a refusal is a setting, not a missing page.\nWorks for questions asked in any language.<\/li>\n<li><strong>\"Questions, word for word\" has been removed.<\/strong> It counted the same question\ntwice whenever the wording differed slightly, which the topic report already\nhandles properly by meaning.<\/li>\n<li><strong>Live Conversations is easier to work with.<\/strong> The heading sits on one line\nwith the Refresh and Export buttons at the right edge, and each conversation\nhas a checkbox.<\/li>\n<li><strong>Act on many conversations at once.<\/strong> Select any number and delete them in\none go, or end them and send the summary email: a confirmed report says\nexactly what succeeded and what did not.<\/li>\n<li><strong>Pagination.<\/strong> Choose 10, 20, 30 or 40 conversations per page, with \"Showing\n21\u201340 of 152\" underneath so the total is never a guess.<\/li>\n<li><strong>Export by count, not just by date.<\/strong> The Export dialog now offers \"Last N\nconversations\" alongside the date range, for when you want the most recent\nhundred rather than everything since Tuesday.<\/li>\n<li><strong>The export size estimate is now accurate.<\/strong> It was understating the real\nfile size by more than five times, which made a large export look harmless\nbefore it started.<\/li>\n<li><strong>The release package now ships the embed loader.<\/strong> Every earlier ZIP was\nbuilt without <code>assets\/embed.js<\/code>, so a site installed from a ZIP: rather than\nfrom the plugin folder: served a 404 for the script that puts the assistant\non a non-WordPress website. The packaging step now includes it.<\/li>\n<\/ul>\n\n<h4>2.9.1<\/h4>\n\n<ul>\n<li><strong>Questions are now grouped by meaning, not wording.<\/strong> A new report at the\ntop of SEO Insights lists the subjects visitors actually ask about. \"How do I\ninstall it?\" and \"steps to set it up\" count as one topic instead of two\nseparate one-off rows, so the report stays readable however much traffic the\nsite gets.<\/li>\n<li><strong>Analysis runs on demand, from a button.<\/strong> Nothing is analysed behind the\nscenes: one press reads the conversations and groups them, with a progress\nbar showing how far along it is. Analysis costs AI calls, so it happens when\nan administrator asks for it rather than continuously in the background.<\/li>\n<li><strong>A conversation is only ever analysed once.<\/strong> Finished conversations are\nmarked, and the next press looks at new conversations only, so pressing the\nbutton repeatedly costs nothing extra. Closing the page part-way through is\nsafe too: the next press continues from where it stopped instead of starting\nover.<\/li>\n<li><strong>The report is bounded.<\/strong> Topics are stored as a small permanent tally, and\nthe table keeps the most-asked 300 so a long-running site cannot accumulate\nthousands of one-off subjects.<\/li>\n<li><strong>Word-for-word questions and top pages are still listed<\/strong>, counted directly\nfrom the log without the AI, so both keep working even when the AI is\nunavailable.<\/li>\n<li><strong>Rebuild from scratch<\/strong> re-reads every conversation and throws the tally\naway, for when an earlier run's results are not trustworthy.<\/li>\n<\/ul>\n\n<h4>2.8.0<\/h4>\n\n<ul>\n<li><strong>One conversation, one record.<\/strong> The separate per-turn chat log is gone.\nEverything it held: the whole exchange and the page the visitor was on :\nnow lives on the conversation itself, so there is a single place to look and\na single place to delete from.<\/li>\n<li><strong>Deleting a conversation now deletes all of it.<\/strong> Previously the delete\nbutton removed the conversation but left its turns behind, and the SEO report\nkept showing chats that had already been deleted. Deleting now clears the\nconversation, its transcript and what the assistant remembered about that\nvisitor, together.<\/li>\n<li><strong>The SEO report sees every conversation.<\/strong> It used to read the per-turn log,\nwhich only recent chats reached: on a site with 14 conversations it reported\non 2. Top pages and top questions are now counted from the conversations\nthemselves.<\/li>\n<li><strong>Export is one row per conversation<\/strong> instead of one row per message. The\nfull back-and-forth sits in a single <code>transcript<\/code> column, so one row reads as\none conversation.<\/li>\n<li>The admin screen drops the separate Chat Log tab: <strong>Live Sessions<\/strong>, <strong>SEO\nInsights<\/strong> and <strong>Storage<\/strong> cover everything. The menu entry is renamed\n<strong>Conversations<\/strong> and the table gains a <strong>Page<\/strong> column showing where each\nvisitor was when they started chatting.<\/li>\n<\/ul>\n\n<h4>2.7.0<\/h4>\n\n<ul>\n<li><strong>Every conversation is now kept permanently.<\/strong> A new chat log records each\nvisitor question and each answer with the page URL it came from, so you can\nfinally answer \"which pages make people ask us things, and what do they ask?\"\nThat page-level record is what turns traffic into content decisions: the\nquestions that repeat are the pages and FAQs you are missing.<\/li>\n<li>The new <strong>Chat Log<\/strong> screen replaces Live Chats and has four tabs: Live\nSessions, Chat Log (searchable, paginated, with full transcripts), SEO\nInsights (top pages and top questions over any date range) and Storage (table\nsize, growth and free disk).<\/li>\n<li><strong>Storage is small and predictable<\/strong>: each turn costs roughly 326 bytes, so a\nmillion turns is about 650 MB. Nothing is ever deleted automatically: the log\nis yours to keep.<\/li>\n<li><strong>Assistant memory is now 7 days<\/strong> (previously 30) and is purely short-term\ncontext for follow-up questions. The permanent record lives in the chat log,\nso shortening it no longer loses anything.<\/li>\n<li>Live-chat sessions are no longer deleted after 24 hours, and the session list\nis paginated: it previously selected every row with no limit.<\/li>\n<li><strong>The stored API key is no longer sent to the browser.<\/strong> The settings screen\nnow only reports whether a key is saved; it can be replaced but never read\nback. The admin JavaScript no longer keeps a copy either.<\/li>\n<li><strong>Security fix:<\/strong> the typing-time check was skipped whenever the widget's\nelapsed field was 0 or absent, so a scripted client could bypass it by simply\nomitting the value. A missing value is now treated as instant, which is what a\nbot looks like.<\/li>\n<li><strong>Upgrade fix:<\/strong> the chat log table was gated behind a plugin-version check\nthat returns early on any install already past 2.2.0, so a site updating from\n2.5.x would never create it and the feature would silently record nothing. The\nschema now has its own version gate and is also applied on admin load.<\/li>\n<li>Export now reads the chat log when present and includes the page URL column,\nso an exported file is directly usable for SEO analysis.<\/li>\n<li>Table indexes declare a 191-character prefix on the URL column. This is not\ndefensive: on MariaDB 10.5 a plain index on a 255-character utf8mb4 column is\nrejected outright (error 1709, \"maximum column size is 767 bytes\"), and a\nschema that fails to create leaves the log table missing on that host. The\nprefix keeps the key at 764 bytes, inside the limit.<\/li>\n<li><strong>Every entry point now records.<\/strong> Three separate paths answer a visitor :\non-site chat, a widget embedded on another website, and the Quick FAQ button :\nand two of them were not writing to the permanent log at all. Conversations on\nembedded sites and quick-FAQ replies were therefore invisible in SEO Insights.\nAll three now write the same record.<\/li>\n<li><strong>Visitor details are now kept for embedded sites.<\/strong> The lead form lives in\nthe widget, so a visitor on another website types their name and email there.\nThose two fields were never read on the way in, so every embedded conversation\nwas stored without them and appeared as \"Guest\" in Live Conversations with no\nway to follow up. They are now validated and stored alongside the transcript\nand in the permanent log.<\/li>\n<li>Fixed: the version shown in the header was hardcoded and had been wrong since\n2.1.2; it now reports the running version.<\/li>\n<li>Fixed: \"Load older turns\" stacked a second table below the first instead of\nextending one log, leaving two scroll positions and two headers.<\/li>\n<\/ul>\n\n<h4>2.6.0<\/h4>\n\n<ul>\n<li>Add an Export button to the Live Chats screen. One click produces a single\nflat file: CSV for spreadsheets or JSONL for AI analysis: containing every\nconversation turn on the site, including questions the assistant refused to\nanswer. A date range is offered, and the dialog states how many rows and how\nmuch data the download will contain before it starts.<\/li>\n<li>The export is read-only and streams out one row at a time, so peak memory\nstays flat no matter how much history a site has: measured at 64 MB for a\n250,000-row export, the same as for 500 rows. Nothing in the chat tables is\nwritten, altered or deleted.<\/li>\n<li>Exports over a hard ceiling are refused up front with a message asking for a\nnarrower date range, so a mistaken click cannot fill the disk.<\/li>\n<li>Conversations the assistant declined to answer are included with their\nrefusal reason, so the most interesting rows for improving a site are not\nthe ones missing from the file.<\/li>\n<\/ul>\n\n<h4>2.5.2<\/h4>\n\n<ul>\n<li>Say on the Embed Script screen that example.com and www.example.com are two\ndifferent sites. A mismatch is refused silently, so a correct-looking setup\ncan produce no chat at all with nothing to point at.<\/li>\n<\/ul>\n\n<h4>2.5.1<\/h4>\n\n<ul>\n<li>Warn in Embed Script when the WordPress address is plain HTTP. The script is\nthen refused by every HTTPS site (\"mixed content\") and the visitor sees no\nchat at all, with nothing logged anywhere. The notice names the address and\nsays what to do.<\/li>\n<li>Document the HTTPS requirement and the reverse-proxy setup.<\/li>\n<\/ul>\n\n<h4>2.5.0<\/h4>\n\n<ul>\n<li>Improvement: one place for everything external: <strong>Site Assistant -&gt; Embed Script<\/strong>. Each connected website shows its own Connect\/Pause switch, its own script and its own status. Keys are minted and retired automatically.<\/li>\n<li>Improvement: pausing a website (or every embed) is refused on every transport, including signed server requests. Reconnecting needs no new script.<\/li>\n<li>Improvement: the duplicate External Embed controls in Settings are gone; the website list there could silently override this screen.<\/li>\n<li>Security: the bridge secret is never printed in full and no longer returned by the settings API. Use Copy on the Embed Script screen.<\/li>\n<li>Security: removed the \"Require signed server requests\" switch, which did not gate any request and could make an admin believe unsigned traffic was blocked.<\/li>\n<li>Compatibility: websites previously approved in the old Settings allowlist are moved into the website list automatically, so nothing stops working.<\/li>\n<\/ul>\n\n<h4>2.4.0<\/h4>\n\n<ul>\n<li>Feature: new <strong>Embed Script<\/strong> screen. Enter the address of the site you want the assistant on, get a ready-to-copy script, paste it into that site's footer. No proxy, no secret, no code editing.<\/li>\n<li>Feature: each approved site gets its own public site key, bound to that exact address. Removing a site disables its script immediately.<\/li>\n<li>Feature: the widget now loads from the same host the browser used, so embeds work on HTTPS, behind a tunnel or any reverse proxy.<\/li>\n<li>Security: external chat requests are rate limited against the real visitor IP; a direct embed can never spoof it.<\/li>\n<\/ul>\n\n<h4>2.3.0<\/h4>\n\n<ul>\n<li>Security: External embeds can require signed server-to-server requests using HMAC, a 60-second validity window, one-time nonces, and replay rejection.<\/li>\n<li>Security: External chat requests use a verified client IP for rate limiting; unsigned browser-supplied IP headers are never trusted.<\/li>\n<li>Security: Added exact-origin controls and safe bridge configuration guidance. No bridge or AI secret is sent to the widget\/browser.<\/li>\n<\/ul>\n\n<h4>2.1.0<\/h4>\n\n<ul>\n<li>Feature: Pre-chat Lead Capture gate (Visitor Name + Email) with seamless continuous chat persistence.<\/li>\n<li>Feature: Live Conversations Admin Dashboard (<code>Site Assistant -&gt; Live Chats<\/code>) with real-time countdown timer, live chat viewer modal, and instant force-send.<\/li>\n<li>Feature: Zero database bloat architecture: transient sessions automatically emailed upon inactivity timeout or chat clear, then permanently purged.<\/li>\n<li>Improvement: Removed old Activity Log in favor of the new Live Chats dashboard.<\/li>\n<li>Improvement: Added configurable inactivity timeout and recipient email options.<\/li>\n<\/ul>\n\n<h4>2.0.8<\/h4>\n\n<ul>\n<li>Fix: chat history was saved from only the first text node of a reply, so after clicking a link (popup reopen) the bot's message lost most of its content. History now keeps the full reply including markdown links\/formatting.<\/li>\n<li>Fix: bot bubble text color is now fixed and no longer inherits the host theme\/current homepage template color.<\/li>\n<\/ul>\n\n<h4>2.0.7<\/h4>\n\n<ul>\n<li>The cached-answer indicator (\"\u26a1 cached answer\") is no longer shown to visitors: the answer cache still works (faster replies), it is just silent now.<\/li>\n<\/ul>\n\n<h4>2.0.6<\/h4>\n\n<ul>\n<li>Removed all remaining embedding \/ semantic-search mentions from the admin UI. The assistant runs in clean keyword-search mode; no embedding data is stored. Backend support stays intact and is ready for a later release if an embedding provider is added.<\/li>\n<\/ul>\n\n<h4>2.0.5<\/h4>\n\n<ul>\n<li>Embedding \/ semantic search section removed from the admin UI for now (backend support remains; the assistant keeps using fast keyword search and stores no embedding data). It can be re-enabled later when an embedding provider is available.<\/li>\n<li>New \"Scan mode\" option: Auto (batched, best for large sites: processes content in batches so memory stays bounded even with 10,000+ items) or Full (one pass, slightly faster on small sites).<\/li>\n<\/ul>\n\n<h4>2.0.4<\/h4>\n\n<ul>\n<li>New: \"Clear index\" button in the admin: wipes the entire AI knowledge base (all indexed chunks + site fingerprint) in one click, so you can re-scan from a clean slate. Chat history and cached answers are kept. Protected by a confirmation dialog.<\/li>\n<\/ul>\n\n<h4>2.0.3<\/h4>\n\n<ul>\n<li>Fix: upgrading from v1 to v2 (and re-scanning) left stale v1 chunks behind, so the same post could end up with both an old single chunk and fresh smart chunks: polluting retrieval with outdated\/duplicated content. Re-scan now removes legacy v1 (position=0) chunks before indexing, so the knowledge base stays clean after upgrade.<\/li>\n<\/ul>\n\n<h4>2.0.2<\/h4>\n\n<ul>\n<li>Mobile chat: full-screen panel on phones (correctly handles the address-bar viewport height), safe-area insets for notched devices, 16px input font so iOS doesn't zoom on focus, and 48px+ touch targets for the send button \/ input \/ FAB.<\/li>\n<li>Send button is now a clean paper-plane icon (easier to reach with a thumb) instead of a cramped text button.<\/li>\n<\/ul>\n\n<h4>2.0.1<\/h4>\n\n<ul>\n<li>Fix: duplicate RELATED LINKS when several chunks of the same page are used: links are now deduplicated by URL.<\/li>\n<li>Fix: inline markdown rendering reordered text (bold\/italic text appearing glued to surrounding text): the parser now walks tokens left-to-right in source order.<\/li>\n<li>Fix: sporadic \"Unexpected AI response format\": the SSE fallback now also handles gateways that put content under message.content instead of delta.content, and skips empty data: lines.<\/li>\n<li>Embedding settings are now grouped behind an \"Enable semantic search\" toggle: the embedding model, top-k and minimum-similarity fields only appear when enabled. When disabled, the plugin runs keyword search exactly as before.<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Smart, semantic chunking: content is split on paragraph\/sentence boundaries (not fixed length) with overlap, and tagged with position metadata: so chunked instructions (e.g. step-by-step guides) stay intact and can be merged back into the full source.<\/li>\n<li>Retrieval mode auto-detection: if your AI endpoint offers an embedding model, the assistant uses <strong>semantic (vector) search<\/strong>: it matches by meaning, not just exact words, and pulls in the whole parent document for full context. If no embedding model is configured, it automatically falls back to <strong>keyword search<\/strong> so the plugin always works.<\/li>\n<li>New \"Embedding model (optional)\" setting + a Retrieval mode indicator in the admin panel (shows whether semantic or keyword search is active).<\/li>\n<li>Multi-chunk storage: a post's content now spans multiple indexed rows (one per chunk), so long posts\/guides are fully searchable instead of truncated to a single entry.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Conversation memory: the widget sends a stable per-browser <code>client_id<\/code>; the server stores every turn (visitor + assistant) and injects the last 8 messages plus keyword-matched older context into the prompt: follow-ups like \"what name did you pick?\" or A\/B \"which is better?\" now work.<\/li>\n<li>Language lock: each message's language (vi\/en) is detected on the widget and pinned in the prompt, so conversations no longer drift from English to Vietnamese (or vice versa) mid-chat.<\/li>\n<li>Markdown rendering in chat bubbles (bold, italic, code, lists, links, code blocks) built safely with DOM APIs: AI output can never inject HTML\/scripts.<\/li>\n<\/ul>\n\n<h4>1.2.4<\/h4>\n\n<ul>\n<li>Fix chat history lost when navigating between pages: history is always restored from localStorage (no welcome re-show), with a restore guard preventing overwrite.<\/li>\n<\/ul>\n\n<h4>1.2.3<\/h4>\n\n<ul>\n<li>Fix welcome bubble re-shown on every widget reopen; crisp SVG clear-chat icon.<\/li>\n<\/ul>\n\n<h4>1.2.2<\/h4>\n\n<ul>\n<li>Redesigned chat widget (teal theme, trash + close on the right edge of the header).<\/li>\n<li>Current-page context: the AI knows which page the visitor is on and can answer \"what's on this page?\".<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Added a full Security &amp; Limits panel: honeypot, min-typing-time, per-IP rate limits (minute + hour), daily question budget with 80% email warning.<\/li>\n<li>Response caching: repeated identical questions are answered from cache (no AI call, saves tokens).<\/li>\n<li>Prompt-injection protection: hardened system prompt + keyword filter that refuses malicious prompts before the AI runs.<\/li>\n<li>Chat activity log + manual\/automatic IP ban\/unban (banned IPs shown in the admin panel).<\/li>\n<li>Friendly blocked notices in the chat widget: each refusal explains the reason and what to do next.<\/li>\n<\/ul>\n\n<h4>1.1.4<\/h4>\n\n<ul>\n<li>E-commerce permission applies only to the native WooCommerce <code>product<\/code> post type; other custom post types stay under Site content.<\/li>\n<\/ul>\n\n<h4>1.1.3<\/h4>\n\n<ul>\n<li>Indexes every public post type (auto-detected custom post types), not just posts\/pages\/products.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Permissions simplified to Site content + E-commerce (removed plugins\/themes\/menus\/forms).<\/li>\n<li>Site content covers posts\/pages\/CPTs only; product data requires the E-commerce permission.<\/li>\n<li>Shows exactly what is indexed (per-group counts + item titles).<\/li>\n<li>Extra info now supports three sources: free text, an external web link, and an uploaded .md file.<\/li>\n<li>Grouped settings: \"Answer &amp; Site Status\" card with its own save + re-scan buttons.<\/li>\n<li>MySQL FULLTEXT search for fast retrieval on large sites.<\/li>\n<li>Removed the separate \"Enable frontend chat widget\" toggle (Enable assistant drives it).<\/li>\n<li>Endpoint now accepts a base URL (\u2026\/v1) and auto-appends \/chat\/completions.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"AI chat assistant that knows your site content, plugins, themes, forms and features.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/369447","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=369447"}],"author":[{"embeddable":true,"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/ducdung2026"}],"wp:attachment":[{"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=369447"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=369447"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=369447"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=369447"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=369447"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=369447"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}