{"id":305777,"date":"2026-07-26T17:14:47","date_gmt":"2026-07-26T17:14:47","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/toutmark-aeo\/"},"modified":"2026-07-26T17:27:12","modified_gmt":"2026-07-26T17:27:12","slug":"toutmark-ai-citation","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/toutmark-ai-citation\/","author":23489545,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.2.2","stable_tag":"2.2.2","tested":"7.0.2","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Toutmark AI Citation","header_author":"Toutmark","header_description":"AI citation tooling for ChatGPT, Claude, Perplexity, Gemini, and Google AI Overviews. Connects your site to your Toutmark account via WordPress Application Passwords. Emits standard schema.org JSON-LD, serves an llms.txt file, and runs daily AI bot reachability checks. All additions are visible to every visitor \u2014 no cloaking, no hidden text. Requires an active Toutmark subscription.","assets_banners_color":"9680b6","last_updated":"2026-07-26 17:27:12","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/toutmark.com\/wordpress","header_author_uri":"https:\/\/toutmark.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":35,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.2.1":{"tag":"2.2.1","author":"toutmarkhq","date":"2026-07-26 17:14:26"},"2.2.2":{"tag":"2.2.2","author":"toutmarkhq","date":"2026-07-26 17:27:12"}},"upgrade_notice":{"2.1.0":"<p>Adds one-click &quot;Connect to Toutmark&quot; + REST API-based draft publishing + \/llms.txt rewrite + daily content cache. Recommended for all customers.<\/p>","2.0.2":"<p>Cleanup and naming-convention compliance. Recommended.<\/p>","2.0.0":"<p><strong>Breaking change.<\/strong> Removes UA-conditional content rewriting to comply with Google&#039;s May 2026 spam-policy update.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3623648,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3623648,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3623648,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3623648,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.2.1","2.2.2"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[2353,1807,226124,1117,186],"plugin_category":[55],"plugin_contributors":[273374],"plugin_business_model":[],"class_list":["post-305777","plugin","type-plugin","status-publish","hentry","plugin_tags-ai","plugin_tags-citation","plugin_tags-llm","plugin_tags-schema","plugin_tags-seo","plugin_category-seo-and-marketing","plugin_contributors-toutmarkhq","plugin_committers-toutmarkhq"],"banners":{"banner":"https:\/\/ps.w.org\/toutmark-ai-citation\/assets\/banner-772x250.png?rev=3623648","banner_2x":"https:\/\/ps.w.org\/toutmark-ai-citation\/assets\/banner-1544x500.png?rev=3623648","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/toutmark-ai-citation\/assets\/icon-128x128.png?rev=3623648","icon_2x":"https:\/\/ps.w.org\/toutmark-ai-citation\/assets\/icon-256x256.png?rev=3623648","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Toutmark is an AI citation platform aligned with Google's May 2026 AI Optimization guidance. This plugin connects your WordPress site to your Toutmark account and adds the technical signals that AI engines reward \u2014 all visible to every visitor, with no user-agent-conditional content delivery and no hidden text.<\/p>\n\n<p><strong>What it does<\/strong><\/p>\n\n<ul>\n<li><strong>Schema injection.<\/strong> Emits standard schema.org JSON-LD on each page via the <code>wp_head<\/code> hook, sourced from your Toutmark account. Visible to humans and bots alike.<\/li>\n<li><strong>\/llms.txt + \/llms-full.txt files.<\/strong> Serves public files at the root of your site (used by ChatGPT and Perplexity): llms.txt is the index, llms-full.txt carries the full text of your published content so AI systems can read everything in one fetch. Both populated from your Toutmark account, both visible to any visitor.<\/li>\n<li><strong>AI bot reachability.<\/strong> Runs a daily ping back to Toutmark; the Toutmark service then verifies that GPTBot, ClaudeBot, PerplexityBot, ChatGPT-User, and Googlebot can reach your site and surfaces results in your dashboard.<\/li>\n<li><strong>One-click connect.<\/strong> A \"Connect to Toutmark\" button on the plugin's settings page generates a WordPress Application Password using core's <code>WP_Application_Passwords<\/code> API and sends it to Toutmark over HTTPS, so Toutmark agents can publish drafts to your approval queue via the standard REST API. You can revoke the password any time from Users \u2192 Profile \u2192 Application Passwords.<\/li>\n<\/ul>\n\n<p><strong>What it does NOT do<\/strong><\/p>\n\n<ul>\n<li>Does not deliver different content to bots than to humans. Google's spam policy treats user-agent-conditional content delivery as a manual-action risk. Toutmark refuses to do it on principle.<\/li>\n<li>Does not inject hidden text, white-on-white text, off-screen text, zero-size text, or <code>display:none<\/code> content blocks. Every character is visible to humans at full opacity, in normal document flow.<\/li>\n<li>Does not modify your post content. Schema and llms.txt content are added via standard WordPress hooks (<code>wp_head<\/code>, rewrite rules); your existing posts and pages are untouched.<\/li>\n<li>Does not publish anything without your approval. Toutmark agents publish drafts to your WordPress site; you approve in your Toutmark dashboard before anything goes live.<\/li>\n<li>Does not work without an active Toutmark subscription \u2014 the plugin no-ops if unreachable or inactive.<\/li>\n<\/ul>\n\n<p><strong>Compliance with Google's May 2026 spam policy<\/strong><\/p>\n\n<p>Google's updated spam policy targets user-agent-conditional content (cloaking), hidden or invisible text, \"AI-only\" content blocks visible only to LLM bots, and inauthentic mentions. Toutmark does none of these. Every signal we add is plainly visible to anyone who visits your site.<\/p>\n\n<p><strong>Requirements<\/strong><\/p>\n\n<ul>\n<li>An active Toutmark subscription \u2014 sign up at <a href=\"https:\/\/toutmark.com\">toutmark.com<\/a>.<\/li>\n<li>WordPress 6.0+, PHP 7.4+.<\/li>\n<li>Application Passwords enabled (default in WordPress 5.6+; some security plugins disable them).<\/li>\n<li>Outbound HTTPS access from your server to <code>toutmark.com<\/code>.<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Install the plugin from the WordPress.org directory (or upload the ZIP via WordPress admin \u2192 Plugins \u2192 Add New \u2192 Upload Plugin).<\/li>\n<li>Activate the plugin. You'll be redirected automatically to the settings page at Settings \u2192 Toutmark AI Citation.<\/li>\n<li>Your Customer ID is pre-filled if you came from your Toutmark dashboard's install link. Otherwise paste it from your Toutmark dashboard.<\/li>\n<li>Check \"Enable plugin\" and save.<\/li>\n<li>Click \"Connect to Toutmark.\" The plugin generates a WordPress Application Password and sends it to Toutmark in one click. Success notice appears.<\/li>\n<\/ol>\n\n<p>That's it. Toutmark agents can now publish drafts to your approval queue, and the plugin emits schema + serves <code>\/llms.txt<\/code> from the daily content bundle.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20affect%20my%20google%20rankings%3F\"><h3>Will this affect my Google rankings?<\/h3><\/dt>\n<dd><p>This plugin is designed to be Google-compliant. Schema injection follows Google's own guidance. There is no cloaking or hidden text. llms.txt is a standard file at a standard URL, similar to robots.txt or sitemap.xml.<\/p><\/dd>\n<dt id=\"how%20does%20the%20%22connect%20to%20toutmark%22%20button%20work%3F\"><h3>How does the \"Connect to Toutmark\" button work?<\/h3><\/dt>\n<dd><p>It generates a WordPress Application Password under the current user's account, scoped to \"Toutmark AI Citation,\" and sends it to Toutmark over HTTPS. Toutmark stores it encrypted and uses it for Basic Auth on standard WordPress REST API calls (<code>wp\/v2\/posts<\/code>, <code>wp\/v2\/pages<\/code>). You can revoke the password any time from Users \u2192 Profile \u2192 Application Passwords; the plugin will gracefully no-op until you re-connect.<\/p><\/dd>\n<dt id=\"what%20does%20toutmark%20publish%20to%20my%20site%3F\"><h3>What does Toutmark publish to my site?<\/h3><\/dt>\n<dd><p>Toutmark agents publish drafts \u2014 blog posts, FAQ entries, brand summary pages, at-a-glance pages \u2014 to your WordPress install via the standard REST API. Nothing is auto-published. Every draft sits in your WordPress drafts AND your Toutmark approval queue until you approve it. Approval flips the WordPress post status from draft to publish via another REST API call.<\/p><\/dd>\n<dt id=\"what%20if%20toutmark%20is%20down%3F\"><h3>What if Toutmark is down?<\/h3><\/dt>\n<dd><p>The plugin fails open. If the Toutmark API is unreachable, slow, or returns an error, the plugin no-ops. Your site is never broken.<\/p><\/dd>\n<dt id=\"does%20this%20slow%20my%20site%20down%3F\"><h3>Does this slow my site down?<\/h3><\/dt>\n<dd><p>No. Schema is emitted from a locally-cached daily bundle (one fetch per day via wp-cron, then served from a WordPress option). llms.txt is served from the same cache. There are no per-pageview calls to Toutmark.<\/p><\/dd>\n<dt id=\"how%20do%20i%20disconnect%3F\"><h3>How do I disconnect?<\/h3><\/dt>\n<dd><p>Two options. (1) Deactivate the plugin \u2014 it immediately stops emitting schema and serving llms.txt. (2) Revoke the Application Password under Users \u2192 Profile \u2192 Application Passwords \u2014 Toutmark can no longer publish to your site, but cached schema and llms.txt remain until you deactivate the plugin or uninstall it.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.2.2<\/h4>\n\n<ul>\n<li>New: serves \/llms-full.txt at your site root - the full-content companion to llms.txt, from the same cached daily bundle. No new inputs, no new API calls, visible to every visitor like everything else.<\/li>\n<li>Rewrite rules now flush automatically once after each plugin update, so the new route works without re-saving permalinks.<\/li>\n<\/ul>\n\n<h4>2.2.1<\/h4>\n\n<ul>\n<li>Internationalization: text domain now matches the plugin slug (toutmark-ai-citation) per WordPress.org review.<\/li>\n<li>Plugin folder and main file renamed to match the slug; legacy toutmark-aeo copies are deactivated automatically on upgrade (settings are preserved).<\/li>\n<\/ul>\n\n<h4>2.2.0<\/h4>\n\n<ul>\n<li>Security hardening per WordPress.org plugin review: every form handler now checks capability first, then verifies its nonce via check_admin_referer(), before reading any input or changing any state.<\/li>\n<li>The dashboard install link's Customer ID parameter is now display-only pre-fill \u2014 it is never persisted from the URL; saving goes through the nonce-protected Settings API form.<\/li>\n<li>\"Test connection\" handling moved out of the page renderer into a dedicated admin_init handler with its own capability + nonce gate.<\/li>\n<li>Added uninstall.php: removes all plugin options, transients, and cron events on uninstall.<\/li>\n<li>Deactivation now uses wp_clear_scheduled_hook() to clear all scheduled cron occurrences.<\/li>\n<li>Confirmed compatible with WordPress 7.0.<\/li>\n<\/ul>\n\n<h4>2.1.0<\/h4>\n\n<ul>\n<li>New: One-click \"Connect to Toutmark\" button generates a WordPress Application Password via core API and sends it to Toutmark for REST API-based draft publishing.<\/li>\n<li>New: Daily content-bundle cron pulls schema + llms.txt + at-a-glance HTML from Toutmark; served from local cache (no per-pageview API calls).<\/li>\n<li>New: <code>\/llms.txt<\/code> rewrite rule serves the file from cache.<\/li>\n<li>New: Activation redirect to settings page.<\/li>\n<li>New: Customer ID pre-fill via <code>?toutmark_customer_id=<\/code> URL parameter.<\/li>\n<li>Compatibility: class names now prefixed with <code>Toutmark_Aeo_<\/code> per WordPress.NamingConventions.PrefixAllGlobals.<\/li>\n<\/ul>\n\n<h4>2.0.2<\/h4>\n\n<ul>\n<li>Cleanup: removed dead user-agent detection code paths.<\/li>\n<li>Cleanup: completed truncated source files.<\/li>\n<li>Compliance: all global class\/constant names properly prefixed.<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Breaking change. Removed UA-conditional content rewriting to comply with Google's May 2026 spam-policy update.<\/li>\n<li>Schema injection retained \u2014 visible to humans and bots equally.<\/li>\n<li>llms.txt support retained.<\/li>\n<\/ul>\n\n<h4>1.0.5<\/h4>\n\n<ul>\n<li>Final pre-rebrand release of the prior architecture.<\/li>\n<\/ul>","raw_excerpt":"AI citation for ChatGPT, Claude, Perplexity, Gemini, and Google AI Overviews \u2014 schema, llms.txt, bot reachability. No cloaking, no hidden text.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/305777","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=305777"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/toutmarkhq"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=305777"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=305777"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=305777"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=305777"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=305777"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=305777"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}