=== SEOvault AI ===
Contributors: seovaultai
Tags: seo, schema, sitemap, open graph, ai
Requires at least: 5.9
Tested up to: 7.1
Stable tag: 1.1.2
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Fully automated WordPress SEO with metadata, schema, e-commerce, Local SEO, sitemaps, social previews, llms.txt, AI visibility, and app integration.

== Description ==

SEOvault AI is a next-generation, lightweight WordPress SEO plugin built for automated SEO, manual control, AI visibility, and modern content workflows.

It helps WordPress site owners manage essential SEO output including SEO titles, meta descriptions, focus keywords, canonical URLs, robots directives, Open Graph tags, Twitter/X Cards, JSON-LD schema, and noindex-aware sitemap behavior.

SEOvault AI is designed to work automatically for most websites while still giving advanced users full manual control when needed. Use automatic mode to let the plugin generate and manage SEO output, switch to manual mode for direct control, or disable specific features when you want another tool or custom workflow to handle them.

Unlike traditional SEO plugins that focus only on search snippets and static checklists, SEOvault AI is built for the current discovery landscape: search engines, AI crawlers, answer engines, AI Overviews, ChatGPT, Gemini, Perplexity, Claude, and external AI-assisted content workflows.

The plugin combines classic WordPress SEO fundamentals with AI visibility tools such as llms.txt publishing, robots.txt policy controls, crawler logging, structured data support, and secure SEOvault web app integration.

= Key Features =

* Fully **automated SEO** mode with optional **manual** and **disabled** modes
* Automatic **SEO title** and **meta description** generation
* Automatic and manual **focus keyword** management
* **Canonical URL** and **robots directive** controls
* **Open Graph** metadata for social sharing
* **Twitter/X Card** metadata
* **JSON-LD schema** — Architecture V2: foundational graph plus blocks, guided instances, templates, integrations, and optional custom JSON-LD (not a global “enable every type” checkbox grid)
* **Sitemap** integration with noindex-aware behavior
* **llms.txt** publishing for AI visibility workflows
* **robots.txt** policy controls
* **AI crawler logging**
* **WooCommerce** product schema and store SEO when WooCommerce is active
* **Secure REST API** connection for the SEOvault web app
* **Site key authentication** for external app communication
* SEO data **importer** for popular SEO plugins
* Compatibility detection for common SEO plugin conflicts
* **404 monitoring**, **redirect management**, **404 fallback behavior**, and an optional **404 recovery page**
* **Local SEO** settings for business information
* **WordPress Core Sitemap:** Noindex-aware sitemap integration

= Automated SEO with Manual Control =

SEOvault AI is built around a simple idea: SEO should work automatically when possible, but users should never lose control.

Automatic mode allows the plugin to generate and manage important SEO output without requiring constant manual editing. This is useful for site owners who want solid SEO foundations without configuring every field by hand.

Manual mode gives editors, SEOs, agencies, and advanced users direct control over the SEO fields that matter.

Disabled mode lets you turn off SEO features when you want another plugin, custom code, or an external workflow to handle that part of the site.

This flexible approach helps SEOvault AI stay simple for beginners while remaining useful for professional WordPress SEO workflows.

= Built for Search Engines and AI Discovery =

Modern SEO is no longer only about traditional search result snippets. Content may now be discovered, parsed, summarized, cited, or evaluated by search engines, AI crawlers, answer engines, and AI-assisted research tools.

SEOvault AI helps prepare WordPress content for this broader discovery layer by combining classic SEO features with AI visibility tools.

The plugin supports structured data, llms.txt publishing, robots policy controls, crawler logging, and secure external workflows through the SEOvault web app.

= Why SEOvault AI is Different =

SEOvault AI is designed to balance automation with flexibility. Many SEO tasks work best when handled automatically, while advanced users still need precise control when it matters. The plugin provides comprehensive SEO tools without requiring every feature to be configured before your site can benefit.

SEOvault AI focuses on a cleaner workflow: automate what can be automated, but still have and allow manual control where it matters, and keep WordPress responsible for the SEO output that belongs inside WordPress.

The plugin is built to manage traditional SEO, structured data, social metadata, sitemap behavior, and AI visibility without turning your dashboard into a bloated control center.

SEOvault AI is especially useful for site owners, bloggers, content teams, agencies, and AI-assisted publishers who want a modern SEO plugin that can work automatically but still provide serious control.

= SEO Data Import =

SEOvault AI includes importer support for moving existing SEO data from popular WordPress SEO plugins.

You can import SEO metadata from supported plugins and continue managing your SEO output inside SEOvault AI.

Supported import targets include:

* Yoast SEO
* Rank Math
* All in One SEO
* Slim SEO
* The SEO Framework

If your site already uses another SEO plugin, SEOvault AI can also detect common compatibility conflicts and warn you about duplicate or competing SEO output.

= SEOvault Web App Integration =

SEOvault AI can connect securely to the SEOvault web app using REST API endpoints and site key authentication.

The web app integration supports external SEO workflows such as site verification, reading and updating SEO fields, managing AI visibility settings, publishing llms.txt content, applying robots.txt policies, injecting schema, importing SEO data, and supporting AI-assisted content workflows.

Developer-facing endpoints are available under:

`/wp-json/seovaultai/v1/`

Protected endpoints require the `X-Site-Key` header.

= Lightweight WordPress-First Architecture =

SEOvault AI is designed to keep your WordPress installation focused and maintainable.

The plugin handles SEO output, structured data, sitemap behavior, compatibility checks, and secure app communication inside WordPress. More advanced AI-assisted workflows can be handled through the SEOvault web app.

This architecture helps reduce plugin bloat while keeping important SEO controls close to your WordPress content.

All functionality included in this plugin package is available without payment, a license key, a trial period, or a usage quota. Connecting to the separate SEOvault AI web service is optional. The service performs additional cloud-based processing and workflows on external servers; it does not unlock locally included plugin code.

== Installation ==

1. Upload the plugin files to `/wp-content/plugins/seovault-ai/`
2. Activate the plugin through the 'Plugins' menu in WordPress
3. Go to "SEOvault AI" in the admin sidebar to configure settings
4. Choose automatic, manual, or disabled modes depending on your workflow
5. Connect to the SEOvault web app if you want to use external AI-assisted SEO workflows

== Frequently Asked Questions ==

= Is SEOvault AI a full SEO plugin? =

Yes. SEOvault AI manages core WordPress SEO output including titles, meta descriptions, canonical URLs, robots directives, Open Graph metadata, Twitter/X Cards, schema, and sitemap behavior.

= Does SEOvault AI work automatically? =

Yes. SEOvault AI includes automatic SEO modes designed to generate and manage important SEO output without requiring users to manually edit every field.

= Can I manually edit SEO fields? =

Yes. SEOvault AI supports manual control for users who want to edit SEO titles, meta descriptions, focus keywords, canonical URLs, robots directives, and other SEO settings directly.

= Can I disable specific SEO features? =

Yes. SEOvault AI supports disabled modes for workflows where you want another tool, custom code, or a different system to handle a specific SEO feature.

= Does SEOvault AI work without the SEOvault web app? =

Yes. The plugin can manage essential SEO features inside WordPress. The SEOvault web app adds external AI-assisted workflows, bulk management, and advanced content optimization features.

= Can I use SEOvault AI with Yoast, Rank Math, AIOSEO, or another SEO plugin? =

SEOvault AI can detect common SEO plugin conflicts and show warnings. For best results, use only one primary SEO plugin to avoid duplicate metadata, duplicate schema, or conflicting sitemap output.

= Can SEOvault AI import existing SEO data? =

Yes. SEOvault AI includes importer support for popular SEO plugins including Yoast SEO, Rank Math, All in One SEO, Slim SEO, and The SEO Framework.

= Does the plugin support AI visibility? =

Yes. SEOvault AI includes AI visibility tools such as llms.txt publishing, robots.txt policy controls, crawler logging, and structured data support.

= Does SEOvault AI create XML sitemaps? =

SEOvault AI integrates with the WordPress core sitemap system and adjusts sitemap behavior based on SEO settings such as noindex rules.

= Is SEOvault AI lightweight? =

Yes. SEOvault AI is designed to keep the WordPress plugin focused on SEO output, compatibility, automation, and secure app integration rather than unnecessary bloat.

= Who is SEOvault AI for? =

SEOvault AI is built for WordPress site owners, bloggers, content publishers, agencies, AI-assisted writers, and SEO teams that want automated SEO foundations with manual control when needed.

= How do unmatched 404s work? =

Under General Settings → 404 Monitor you can choose Fallback Behavior: keep the theme 404, redirect to the homepage, or redirect to a custom page/URL. Redirect Manager rules always win when they match.

Optionally enable the 404 Recovery Page (Theme 404 mode only) to show a simple branded recovery layout. The response stays HTTP 404 and is still logged by the 404 Monitor. SEOvault AI does not auto-create WordPress pages for this feature.

Prefer status **302** (default) for global homepage or custom redirects. A **301** permanent fallback can look like a soft 404 to search engines when many unrelated missing URLs land on the same destination.

= Does SEOvault AI collect or send data off my site? =

Core SEO features run on your WordPress site. Optional features may store data locally (for example SEO metadata, 404 logs, or hashed API audit logs) or contact external services only when you enable them — such as IndexNow, Google Analytics output, Google Maps shortcodes, or connecting the SEOvault web app with a site key. The Free plugin does not include hidden telemetry or license phone-homes. If you install the separate SEOvault AI Pro plugin and activate a license, Pro may contact SEOvault licensing and update endpoints to verify entitlements and deliver updates; Free SEO output still works without Pro. Full details: https://seovaultai.com/privacy/

= How does the connector API stay secure? =

The SEOvault web app connects through a site key over the WordPress REST API (`seovaultai/v1`). Treat the main site key as a high-privilege secret — anyone with it can read and change content through the connector. Regenerate it from SEOvault AI → General → Security if it may have leaked.

The plugin also includes:

* Rate limiting and temporary lockouts after repeated failed authentication
* An API activity audit log (IPs are hashed and never shown in admin)
* A CORS allowlist for browser origins (production SEOvault domains, your site URL, and localhost only when `WP_DEBUG` is on)
* Optional read-only and write-scoped API keys for limited integrations (the web app continues to use the full site key by default)

Developers can customize limits and CORS with WordPress filters:

* `seovaultai_api_rate_limits` — override rate-limit / lockout thresholds
* `seovaultai_cors_allowed_origins` — extend or replace the CORS allowlist

== External services ==

This plugin works as a local WordPress SEO plugin without connecting to SEOvault AI or enabling any of the services below. External requests occur only when an administrator connects, enables, configures, or explicitly uses the related feature.

= SEOvault AI web service =

The optional SEOvault AI web service provides cloud-based AI processing, bulk site management, advanced reports, and content workflows. When an administrator connects the site with a site key, authorized requests from the service can read or update WordPress content, SEO metadata, media, schema, redirects, robots.txt and llms.txt settings, and other plugin settings needed for the action the administrator requests. The plugin does not upload posts to SEOvault AI automatically in the background.

When an authorized content action from the service includes a public image URL, such as an AI-generated featured image, the plugin sends a standard HTTP GET request from the WordPress server to the host named in that URL and downloads the image into the WordPress Media Library. This occurs only for the requested content action and only when the image is not already available locally. The request reveals the site's server IP address and normal HTTP request headers to the image host; it does not send WordPress post content to that host. The image host's operator, terms, and privacy practices depend on the URL supplied by the service. The plugin accepts only public HTTP/HTTPS URLs and rejects private or reserved network addresses before downloading.

Service provider: SEOvault AI
Terms of Service: https://seovaultai.com/terms/
Privacy Policy: https://seovaultai.com/privacy/

= SEOvault AI Pro licensing (separate plugin) =

SEOvault AI Pro is a separate plugin (not bundled here). When Pro is installed and an administrator activates a license, Pro may contact SEOvault licensing and plugin-update endpoints to verify entitlements, refresh activation status, and download authorized updates. Those requests are initiated by Pro, not by this Free plugin. Without Pro, this Free plugin does not perform license checks. A paid plan / license key is required for Pro features; Free SEO features do not require an account.

= IndexNow =

When IndexNow is enabled, the plugin submits public URLs that are published, updated, or manually submitted, together with the site host and IndexNow verification key, to the IndexNow API. This notifies participating search engines that the URLs changed. No submission occurs while IndexNow is disabled.

Service provider: IndexNow
Terms and privacy information: https://www.indexnow.org/terms

= Google Analytics =

When an administrator enables Google Analytics and supplies a Measurement ID, eligible public pages load Google tag code from googletagmanager.com. The visitor's browser then sends page, device, network, and interaction data to Google according to the site's Google Analytics configuration. The plugin does not enable Google Analytics by default. Site owners are responsible for providing any notices or consent required for their visitors.

Service provider: Google
Google Terms of Service: https://policies.google.com/terms
Google Privacy Policy: https://policies.google.com/privacy

= Google Maps =

When an administrator supplies a Google Maps API key and places a Local SEO map shortcode on a page, that page loads the Google Maps JavaScript API from maps.googleapis.com. The visitor's browser sends the API key, IP address, browser information, and map requests, including configured location coordinates, to Google. Pages without the map shortcode do not load the service.

Service provider: Google
Google Maps Platform Terms: https://cloud.google.com/maps-platform/terms
Google Privacy Policy: https://policies.google.com/privacy

= Administrator-requested URL retrieval =

The schema import and live schema validation tools can retrieve a URL entered or selected by an administrator. The request is sent directly from the WordPress site to that URL only when the administrator uses the relevant tool. The remote site's operator, terms, and privacy practices depend on the URL selected by the administrator.

= SEO Analyzer and sitemap self-checks =

When an administrator runs the SEO Analyzer, the plugin sends standard server-side HTTP GET requests to the website's own public homepage, sitemap.xml, robots.txt, RSS feed, and HTTP/HTTPS or www/non-www URL variants. These requests test sitemap, robots and feed availability, redirects and canonical host behavior, response time, and homepage headings. The authorized sitemap connector can also request the website's own public sitemap when retrieving sitemap data.

These requests contain only the normal server IP address and HTTP request headers and are sent to the analyzed website itself, not to an independent third-party service. If the website uses a hosting provider, CDN, proxy, or security service to serve those public URLs, that provider may process the requests under the site owner's existing terms and privacy arrangements.

== Development ==

Human-readable source for every compiled editor block is included in the distributed plugin:

* `blocks/faq/src/` builds `build/blocks/faq/`
* `blocks/howto/src/` builds `build/blocks/howto/`
* `blocks/quick-answer/src/` builds `build/blocks/quick-answer/`

The included `package.json` and `package-lock.json` define the build tools and exact dependency versions. From the plugin directory, rebuild all three production bundles with:

    npm ci
    npm run build

No external source repository is required: the readable block source, build manifest, locked dependencies, and build instructions are all included in the distributed plugin.

New public PHP symbols, hooks, options, and AJAX actions use the `seovaultseo_` prefix. WordPress shortcode tags and asset handles use the plugin-specific `seovault_` or `seovault-` prefix. Existing public names remain for backward compatibility; new unprefixed symbols must not be introduced. The competing `wpseo_breadcrumb` and `aioseo_breadcrumbs` shortcode aliases are disabled by default; developers who need legacy migration compatibility can explicitly enable the `seovaultseo_register_legacy_breadcrumb_shortcodes` filter. SEOvault AI never replaces an alias already registered by another plugin.

== Screenshots ==

1. Output Mode overview with Auto mode enabled
2. e-commerce tab overview
3. Local SEO tab overview
4. Schema tab overview
5. 404 Monitor tab overview
6. IndexNow page overview
7. Sitemap settings page overview

== Changelog ==

= 1.1.2 =

* Removed arbitrary JavaScript insertion from the Free Analytics settings. Free tracking is generated programmatically from a GA4 Measurement ID (gtag.js) only; separately distributed SEOvault AI Pro may add its own custom tracking mode when installed.
* Free no longer intercepts PHP errors, reads error logs, runs runtime health diagnostics, or reports those errors externally.
* Closed every output buffer opened during schema template AJAX rendering with an explicit paired `ob_get_clean()` within the same function scope.
* Removed the advanced early-fatal MU-plugin collector from the WordPress.org package; the Free plugin no longer installs or manages executable files in `wp-content/mu-plugins/`.
* Added reviewer-requested nonce and capability boundaries to administrative actions and request routing.
* Kept standard WordPress Site Health checks and the connector API contract available to compatible extensions.

= 1.1.1 =

* Included human-readable block source code, package.json, and package-lock.json in the plugin package per WordPress.org guideline #4.
* Documented all on-site SEO Analyzer URL requests (sitemap, robots, feed, www/non-www variants) in the readme.
* Documented Schema Parser admin-requested URL retrieval in the readme.
* Added build instructions and source-to-build mappings for Gutenberg blocks.

= 1.1.0 =

* Added media, featured-image, onboarding, API, and third-party block-conversion improvements.
* Updated asset loading, request handling, output encoding, and external-service disclosures for WordPress.org compatibility.
* Stopped claiming third-party breadcrumb shortcode names by default and prefixed the Google Maps script handle.

= 1.0.0 =

* Initial release
