Description
Tengence injects two growth engines into your WordPress site, helping more people discover your website:
- SEO Optimization — Meta tags, social cards, JSON-LD structured data, sitemap, robots.txt, llms.txt and IndexNow. All configurable from a single settings page, no technical barrier.
- GEO (Generative Engine Optimization) — Structure your content so ChatGPT, Claude, Perplexity and other leading AI can directly cite it, capturing next-generation search traffic.
The on-site SEO/GEO features work out of the box — no registration or API key required.
Cloud Sync (optional): Create a free account at Tengence and configure your API Key to sync posts to the Tengence platform. Once enabled, publishing, updating or deleting a post automatically pushes it to Tengence servers, including title, rendered content, excerpt, author, dates, permalink, featured image and categories. Failed syncs are retried automatically via a database-backed queue, with real-time status monitoring.
External Services Disclosure
This plugin connects to third-party services. Nothing is transmitted unless you explicitly enable and configure the corresponding feature. Full details are listed in the “External services” section below.
Key Features
- Automatic Sync — Posts are synced on publish, update, and delete — no manual effort required.
- Full Push — One-click bulk sync of all published posts, or trigger it automatically when you change your API Key.
- Queue & Batch Processing — Database-backed queue with configurable batch sizes (1–200) processed via WP-Cron.
- Retry Mechanism — Failed syncs are retried automatically (configurable, up to 10 attempts).
- Status Dashboard — Real-time monitoring of pending, processing, completed, and failed tasks with auto-refresh.
- Post-level GEO/SEO Meta Box — Edit per-post fields (AI summary, FAQ schema, citations, key points, SEO title/description, canonical, noindex, OG settings and more) right in the editor.
- Site-level Branding & SEO Settings — Brand info, verification codes, custom head code, robots.txt / llms.txt content, IndexNow key hosting.
- Secure Storage — API keys are encrypted with AES-256-CBC before being stored in the database.
- Clean Uninstall — Removing the plugin deletes all tables, options, and cron jobs — no leftover data.
External services
This plugin relies on the following third-party / external services. No data is sent to any of them unless you explicitly enable and configure the related feature.
- Tengence Cloud Sync (api.tengence.com) — used to sync your posts to the Tengence platform. When Cloud Sync is enabled with your API Key, post data (title, rendered content, excerpt, author name and email, publish/update dates, permalink, featured image and categories) is sent when a post is published, updated or deleted, and when a full push runs. This service is provided by Tengence: terms of use — https://www.tengence.com/user-agreement, privacy policy — https://www.tengence.com/privacy-policy
- Tengence Client Registration (console.tengence.com) — used to register the site and obtain client credentials. Sends the site ID, the site URL and the webhook secret when registration runs. This service is provided by Tengence: terms of use — https://www.tengence.com/user-agreement, privacy policy — https://www.tengence.com/privacy-policy
- Tengence Search Token (api.tengence.com) — when a Search API Key is configured, the public
access-tokenendpoint sends that key to the Tengence search API on behalf of your visitors to obtain a short-lived, read-only search token for the on-site search widget. No visitor data is sent. This service is provided by Tengence: terms of use — https://www.tengence.com/user-agreement, privacy policy — https://www.tengence.com/privacy-policy - IndexNow (api.indexnow.org) — used to notify participating search engines (Bing, Yandex, Naver, Seznam) about new or updated URLs. When the IndexNow module is enabled, the changed URL, your site host and your IndexNow key are sent when a post is published. This service is provided by IndexNow: terms of use — https://www.indexnow.org/terms, privacy policy — https://www.indexnow.org/privacy
REST API
The plugin also exposes REST API endpoints:
POST /wp-json/tengence/v1/access-token— intentionally public (__return_trueequivalent). It is the endpoint your site visitors’ browser calls to obtain a short-lived, read-only search token, so the on-site search widget can query the Tengence search API. It never returns your Search API Key, only the short-lived token issued by the Tengence search API. To limit abuse, non-administrator requests are rate limited per IP (60 requests/hour; HTTP 429 when exceeded).
Other endpoints (/articles, /articles/batch, /webhook, and the data module endpoints) require the appropriate capabilities, a WordPress REST nonce, or a valid HMAC signature.
Screenshots




/sitemap_index.xml.Installation
- In WordPress admin, go to Plugins Add New Upload Plugin, choose the downloaded zip, and activate.
- Or upload the
tengencefolder to/wp-content/plugins/and activate through the Plugins menu. - Navigate to Tengence in the admin sidebar.
- (Optional) Enter your Tengence API Key and adjust sync settings, then click Test Connection.
- Configure SEO/GEO settings and per-post fields as needed.
FAQ
-
Does the plugin send my data anywhere?
-
No data is sent unless you enable it. The on-site SEO/GEO features are fully local. Only when you configure a Tengence API Key does the plugin push post data to Tengence servers (api.tengence.com) for content sync. If you enable the IndexNow module, it submits your URLs to api.indexnow.org.
-
What happens when I delete a post?
-
The plugin sends a delete request to Tengence so the content is removed from the platform as well. Moving a post to the trash also triggers removal.
-
Can I change the batch size?
-
Yes. Go to Tengence Settings and adjust the Batch Size field (1–200, default 50). This controls how many posts are processed per WP-Cron cycle.
-
What if a sync fails?
-
Failed items are retried automatically based on your Max Retries setting (1–10, default 3). You can also manually retry failed items from the status dashboard.
-
Is my API key stored securely?
-
Yes. API keys are encrypted with AES-256-CBC using a key derived from your WordPress
SECURE_AUTH_KEYconstant. -
Does the plugin leave data after uninstall?
-
No. Uninstalling the plugin removes all database tables, WordPress options, and scheduled cron jobs.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Tengence” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Tengence” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
2.0.4
- Security: the article create and batch REST endpoints now require the
manage_categoriescapability whenever categories or tags are supplied, so a user with onlyedit_postscan no longer create taxonomy terms through the API - Security: when
author_idis omitted on the batch endpoint, the post is now attributed to the current user instead of a hardcoded user ID 1 — previously the permission check validated “current user” while the post was actually assigned to ID 1 - Fix: replaced
wp_create_category()withwp_insert_term()when creating missing categories — the former is only defined in wp-admin and caused a fatal error in REST requests
2.0.3
- Fix: the article create and batch REST endpoints now require the
read_private_postscapability when the requested post status isprivate, closing the private-status authorization gap flagged by the review - Fix: encryption degrades gracefully when the PHP OpenSSL extension is unavailable — the webhook secret is stored in a plainly-wrapped, reversible form instead of calling
openssl_encrypt(), so activation no longer fatals on PHP builds without OpenSSL
2.0.2
- Fix: the optimization (SEO/GEO) module now boots by default, so the out-of-the-box SEO and GEO features described in the readme are active on a clean install
- Fix: article create/update REST endpoints now verify
edit_postcapability on any existing post matched by slug, preventing a lower-privileged user from overwriting another author’s post - Fix:
uninstall.phpnow removes all plugin options, transients, per-post meta (tengence_*), custom tables, and every scheduled cron hook (tengence_process_queue,tengence_data_process,tengence_sync_article) — no leftover data after uninstall
2.0.1
- Security: tightened REST permissions —
access-tokennow requiresmanage_options; article endpoints honourpublish_posts/edit_others_postsand a status allow-list; webhook signature check moved intopermission_callback - Security: sanitized all request inputs and escaped all outputs (custom head code is filtered through a tag allow-list, JSON-LD is encoded with
JSON_HEX_*) - Fix: all admin JavaScript is now loaded through
wp_enqueue_script/wp_localize_scriptinstead of inline<script>tags - Fix: llms.txt default content is generated from the site’s own posts and pages instead of preset content
- Fix: no longer writes translation files into the plugin directory at runtime
- Docs: added a full “External services” section (Tengence Cloud Sync, Client Registration, IndexNow, Search Token)
- Removed: “millisecond intelligent search” and “smart content recommendations” claims — those features are not included in this plugin
- Hardening: replaced
parse_url()/date()withwp_parse_url()/gmdate(), sanitized request-path handling, and cleared every escaping / sanitization / prepared-SQL item reported by Plugin Check
2.0.0
- Added SEO module: meta tags, social cards, JSON-LD, sitemap, robots.txt, llms.txt, IndexNow
- Added GEO module with post-level meta box (21 fields)
- Added site-level branding, verification and custom head settings
- Enhanced REST API and config API
- UI overhaul: settings page grouped into tabs
1.1.0
- Added REST API endpoint for issuing access tokens
- Added Search API Key configuration field
- Added CORS header support for API endpoints
1.0.0
- Initial release
- Automatic post sync on publish, update, and delete
- Full push for bulk content synchronization
- Database-backed queue with batch processing
- Configurable retry mechanism
- Real-time status dashboard
- AES-256-CBC encrypted API key storage
- Connection test functionality
- Clean uninstall
