{"id":347452,"date":"2026-08-10T14:29:43","date_gmt":"2026-08-10T14:29:43","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/baseweb-ai-chat-forms-to-max\/"},"modified":"2026-08-10T16:51:47","modified_gmt":"2026-08-10T16:51:47","slug":"baseweb-ai-chat-forms-to-max","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/baseweb-ai-chat-forms-to-max\/","author":23539785,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"3.0.2","stable_tag":"3.0.2","tested":"7.0.3","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"BaseWeb AI Chat & Forms to MAX","header_author":"Oleg Roslyakov","header_description":"AI-\u043a\u043e\u043d\u0441\u0443\u043b\u044c\u0442\u0430\u043d\u0442 \u043d\u0430 \u0431\u0430\u0437\u0435 Yandex AI Studio + \u0438\u043d\u0442\u0435\u0433\u0440\u0430\u0446\u0438\u044f Fluent Forms \u2192 MAX Bot. \u0421\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u0435\u0442 152-\u0424\u0417.","assets_banners_color":"3c80bb","last_updated":"2026-08-10 16:51:47","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/base-web.ru\/","header_plugin_uri":"https:\/\/base-web.ru\/baseweb-ai-chat-forms-to-max-intellektualnyj-sbor-lidov-i-ai-chat-dlya-wordpress\/","header_author_uri":"https:\/\/base-web.ru\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":26,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"3.0.2":{"tag":"3.0.2","author":"olegroslyakov","date":"2026-08-10 16:51:47"}},"upgrade_notice":{"3.0.2":"<p>Recommended update: Bug fixes for session handling, improved frontend compatibility, new lead form trigger system, and enhanced database query security using WordPress 6.2+ %i placeholder.<\/p>","3.0.0":"<p>Major update: PHP 8 strict typing, full localization, and new bacfm_ prefix. Review settings after updating. Fluent Forms plugin required for form capture.<\/p>"},"ratings":[],"assets_icons":{"icon-256x256.png":{"filename":"icon-256x256.png","revision":3640708,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3640708,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3640708,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["3.0.2"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3640918,"resolution":"1","location":"assets","locale":"","width":720,"height":480},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3640918,"resolution":"2","location":"assets","locale":"","width":720,"height":480},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3640918,"resolution":"3","location":"assets","locale":"","width":720,"height":480},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3640918,"resolution":"4","location":"assets","locale":"","width":720,"height":480},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3640918,"resolution":"5","location":"assets","locale":"","width":720,"height":480},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3640918,"resolution":"6","location":"assets","locale":"","width":720,"height":480}},"screenshots":{"1":"The AI chat widget on the frontend, featuring a clear AI disclaimer and a modern, responsive design.","2":"The built-in lead capture form with the mandatory 152-FZ\/GDPR personal data consent checkbox.","3":"The \"Yandex AI Studio\" settings tab, showing API configuration and dynamic brand placeholders.","4":"The \"MAX Bot\" settings tab, including the one-click test message feature and Fluent Forms selection.","5":"The \"Logs &amp; Analytics\" dashboard, displaying request categories, user intents, and paginated log history.","6":"The \"Export\" tab, allowing CSV\/JSON export and secure log cleanup."}},"plugin_section":[],"plugin_tags":[2353,2364,185045,12439,2160],"plugin_category":[55],"plugin_contributors":[275033],"plugin_business_model":[],"class_list":["post-347452","plugin","type-plugin","status-publish","hentry","plugin_tags-ai","plugin_tags-chatbot","plugin_tags-fluent-forms","plugin_tags-max","plugin_tags-yandex","plugin_category-seo-and-marketing","plugin_contributors-olegroslyakov","plugin_committers-olegroslyakov"],"banners":{"banner":"https:\/\/ps.w.org\/baseweb-ai-chat-forms-to-max\/assets\/banner-772x250.png?rev=3640708","banner_2x":"https:\/\/ps.w.org\/baseweb-ai-chat-forms-to-max\/assets\/banner-1544x500.png?rev=3640708","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/baseweb-ai-chat-forms-to-max\/assets\/icon-256x256.png?rev=3640708","icon_2x":"https:\/\/ps.w.org\/baseweb-ai-chat-forms-to-max\/assets\/icon-256x256.png?rev=3640708","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/baseweb-ai-chat-forms-to-max\/assets\/screenshot-1.png?rev=3640918","caption":"The AI chat widget on the frontend, featuring a clear AI disclaimer and a modern, responsive design."},{"src":"https:\/\/ps.w.org\/baseweb-ai-chat-forms-to-max\/assets\/screenshot-2.png?rev=3640918","caption":"The built-in lead capture form with the mandatory 152-FZ\/GDPR personal data consent checkbox."},{"src":"https:\/\/ps.w.org\/baseweb-ai-chat-forms-to-max\/assets\/screenshot-3.png?rev=3640918","caption":"The \"Yandex AI Studio\" settings tab, showing API configuration and dynamic brand placeholders."},{"src":"https:\/\/ps.w.org\/baseweb-ai-chat-forms-to-max\/assets\/screenshot-4.png?rev=3640918","caption":"The \"MAX Bot\" settings tab, including the one-click test message feature and Fluent Forms selection."},{"src":"https:\/\/ps.w.org\/baseweb-ai-chat-forms-to-max\/assets\/screenshot-5.png?rev=3640918","caption":"The \"Logs &amp; Analytics\" dashboard, displaying request categories, user intents, and paginated log history."},{"src":"https:\/\/ps.w.org\/baseweb-ai-chat-forms-to-max\/assets\/screenshot-6.png?rev=3640918","caption":"The \"Export\" tab, allowing CSV\/JSON export and secure log cleanup."}],"raw_content":"<!--section=description-->\n<p><strong>BaseWeb AI Chat &amp; Forms to MAX<\/strong> is a powerful, all-in-one WordPress plugin that combines an intelligent AI consultant with seamless lead generation. It bridges the gap between your website visitors and your MAX messenger, ensuring you never miss a potential client.<\/p>\n\n<p>This plugin acts as a \"combo\" solution:\n1. <strong>AI Chat Consultant<\/strong>: A smart, context-aware chat widget powered by Yandex AI Studio (YandexGPT).\n2. <strong>Fluent Forms Integration<\/strong>: Automatically intercepts form submissions and forwards them to MAX.\n3. <strong>Built-in Lead Capture<\/strong>: An intelligent in-chat form that appears when a user is ready to leave their contact details.<\/p>\n\n<h3>\ud83c\udf1f Key Features<\/h3>\n\n<ul>\n<li><strong>Yandex AI Studio Integration<\/strong>: Uses the modern Responses API with <code>store=true<\/code> and <code>previous_response_id<\/code> for seamless, context-aware conversations.<\/li>\n<li><strong>Fluent Forms Webhook<\/strong>: Native hook (<code>fluentform\/submission_inserted<\/code>) to instantly forward any form submission to your MAX bot.<\/li>\n<li><strong>Smart Lead Generation<\/strong>: The AI can dynamically trigger a built-in contact form directly within the chat interface.<\/li>\n<li><strong>152-FZ \/ GDPR Compliant<\/strong>: Includes a mandatory consent checkbox for personal data processing, automatic PII masking (email, phone, IP) in logs, and automated log cleanup after 30 days.<\/li>\n<li><strong>Enterprise-Grade Security<\/strong>:\n\n<ul>\n<li>Protocol-Lock: API keys are stored securely in <code>wp_options<\/code>, never hardcoded.<\/li>\n<li><code>sslverify =&gt; true<\/code> enforced for all external API requests.<\/li>\n<li>Strict input sanitization (<code>sanitize_text_field<\/code>, <code>esc_url_raw<\/code>) and nonce verification.<\/li>\n<li>Rate limiting (20 chat requests \/ 5 lead submissions per 5 minutes per IP).<\/li>\n<\/ul><\/li>\n<li><strong>Comprehensive Dashboard<\/strong>: A 4-tab admin interface for Yandex settings, MAX configuration, real-time analytics (categories, intents), and CSV\/JSON log exports.<\/li>\n<li><strong>Universal &amp; Customizable<\/strong>: Dynamic placeholders (<code>{{company_name}}<\/code>, <code>{{manager_name}}<\/code>) allow you to adapt the AI's persona to any brand without touching the code.<\/li>\n<li><strong>Performance Optimized<\/strong>: Asynchronous logging, transient caching for prompts (1 hour), and strict <code>max_output_tokens<\/code> limits to control API costs.<\/li>\n<\/ul>\n\n<h3>\ud83d\udd12 Security &amp; Privacy First<\/h3>\n\n<p>We take data protection seriously. The plugin automatically hashes IP addresses (SHA-256), masks emails and phone numbers in logs, and includes a built-in WordPress Cron job to delete old logs after 30 days, ensuring compliance with data protection regulations like Russia's 152-FZ and the EU's GDPR.<\/p>\n\n<h3>\ud83d\udee0\ufe0f Shortcodes<\/h3>\n\n<ul>\n<li><code>[bacfm_ai_chat]<\/code> \u2013 Embeds the chat widget directly into the page content.<\/li>\n<li><code>[bacfm_ai_button text=\"Ask AI Assistant\"]<\/code> \u2013 Displays a stylish button that opens the chat widget on click.<\/li>\n<\/ul>\n\n<h3>External Services<\/h3>\n\n<p>This plugin connects to external services to provide its core functionality:<\/p>\n\n<ol>\n<li>Yandex AI Studio (Yandex Cloud)<\/li>\n<\/ol>\n\n<p>- Purpose: To process chat messages and generate AI responses.\n- Data sent: User chat messages, session ID, and page URL.\n- Provider: Yandex LLC.\n- Links: <a href=\"https:\/\/yandex.ru\/legal\/cloud_termsofuse\/\">Terms of Service<\/a>, <a href=\"https:\/\/yandex.ru\/legal\/confidential\/\">Privacy Policy<\/a>.<\/p>\n\n<ol>\n<li>MAX Messenger API<\/li>\n<\/ol>\n\n<p>- Purpose: To send lead notifications and form submissions to the site owner's MAX account.\n- Data sent: Form data (name, email, phone, message) and source URL.\n- Provider: MAX.\n- Links: <a href=\"https:\/\/max.ru\/legal\/terms\">Terms of Service<\/a>, <a href=\"https:\/\/max.ru\/legal\/privacy\">Privacy Policy<\/a>.<\/p>\n\n<h3>Support<\/h3>\n\n<p>We are committed to providing high-quality support for BaseWeb AI Chat &amp; Forms to MAX.<\/p>\n\n<p><strong>Official WordPress.org Support Forum:<\/strong>\nFor general questions, bug reports, and community help, please use the official support forum:\n\ud83d\udc49 https:\/\/wordpress.org\/support\/plugin\/baseweb-ai-chat-forms-to-max\/<\/p>\n\n<p><strong>Direct Developer Support:<\/strong>\nFor urgent issues, commercial inquiries, or custom integration requests, you can contact the developer directly:\n\ud83d\udce7 Email: admin@base-web.ru\n\ud83c\udf10 Website: https:\/\/base-web.ru\/<\/p>\n\n<p><em>Please note: We strive to respond to all direct inquiries within 24-48 hours on business days.<\/em><\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>baseweb-ai-chat-forms-to-max<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory.<\/li>\n<li>Activate the plugin through the 'Plugins' menu in WordPress.<\/li>\n<li>Ensure that the <strong>Fluent Forms<\/strong> plugin is installed and activated (required for form interception).<\/li>\n<li>Navigate to <strong>Settings \u2192 BaseWeb AI Chat<\/strong> in your WordPress admin dashboard.<\/li>\n<li><strong>Yandex AI Studio Tab<\/strong>: Enter your API Key (format: <code>AQVN...<\/code>) and Folder ID (format: <code>b1g...<\/code> from the classic Yandex Cloud console).<\/li>\n<li><strong>MAX Bot Tab<\/strong>: Enter your MAX Bot Token and User ID to enable lead forwarding.<\/li>\n<li>Configure your company name and manager name to personalize the AI's responses.<\/li>\n<li>Add the shortcode <code>[bacfm_ai_button]<\/code> to your desired pages or posts.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"where%20do%20i%20get%20the%20yandex%20ai%20studio%20api%20key%3F\"><h3>Where do I get the Yandex AI Studio API Key?<\/h3><\/dt>\n<dd><p>Go to <a href=\"https:\/\/aistudio.yandex.ru\/\">Yandex AI Studio<\/a>, create a service account with the <code>ai.editor<\/code> role, and generate an API key in the settings.<\/p><\/dd>\n<dt id=\"where%20do%20i%20find%20the%20folder%20id%3F\"><h3>Where do I find the Folder ID?<\/h3><\/dt>\n<dd><p>You must use the <strong>classic Yandex Cloud console<\/strong> (<a href=\"https:\/\/console.yandex.cloud\/folders\/\">console.yandex.cloud\/folders\/<\/a>). Copy the Folder ID that starts with <code>b1g...<\/code>. <em>Note: IDs starting with <code>bpf...<\/code> from the new Yandex Cloud Center are not compatible with the Responses API.<\/em><\/p><\/dd>\n<dt id=\"how%20do%20i%20configure%20the%20max%20bot%3F\"><h3>How do I configure the MAX Bot?<\/h3><\/dt>\n<dd><ol>\n<li>Create or use an existing bot at <a href=\"https:\/\/business.max.ru\/\">business.max.ru<\/a>.<\/li>\n<li>Copy the bot's authorization token.<\/li>\n<li>Obtain your User ID (you can use a simple script or check your MAX bot logs).<\/li>\n<li>Enter both values in the \"MAX Bot\" tab of the plugin settings.<\/li>\n<\/ol><\/dd>\n<dt id=\"is%20this%20plugin%20compliant%20with%20gdpr%20and%20152-fz%3F\"><h3>Is this plugin compliant with GDPR and 152-FZ?<\/h3><\/dt>\n<dd><p>Yes. The plugin includes a mandatory consent checkbox in the lead form, automatically masks Personally Identifiable Information (PII) like emails, phones, and IPs in the logs, and features an automated 30-day log cleanup via WordPress Cron.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20work%20without%20fluent%20forms%3F\"><h3>Does the plugin work without Fluent Forms?<\/h3><\/dt>\n<dd><p>Yes. The AI chat widget and its built-in lead capture form work perfectly on their own. The Fluent Forms integration is an additional module that activates only if the plugin is present.<\/p><\/dd>\n<dt id=\"how%20do%20i%20control%20api%20costs%3F\"><h3>How do I control API costs?<\/h3><\/dt>\n<dd><p>The plugin enforces a strict <code>max_output_tokens<\/code> limit (default 500) and includes rate limiting to prevent spam. We also recommend setting up a monthly budget and alerts in your Yandex Cloud billing dashboard.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>3.0.2<\/h4>\n\n<ul>\n<li><strong>Hotfix<\/strong>: Used %i placeholder in $wpdb-&gt;prepare() for secure table name substitution (requires WordPress 6.2+).<\/li>\n<li><strong>Hotfix<\/strong>: Improved session ID validation to support UUID format with hyphens.<\/li>\n<li><strong>Hotfix<\/strong>: Added compatibility aliases in API response for frontend JavaScript.<\/li>\n<li><strong>Hotfix<\/strong>: Updated system prompt with [SHOW_LEAD_FORM] marker instructions for automatic lead form display.<\/li>\n<li><strong>Hotfix<\/strong>: Added support for Fluent Forms selection in admin settings.<\/li>\n<li><strong>Requirement<\/strong>: Minimum WordPress version raised to 6.2 for %i placeholder support.<\/li>\n<\/ul>\n\n<h4>3.0.0<\/h4>\n\n<ul>\n<li><strong>Release<\/strong>: Public version prepared for WordPress.org repository.<\/li>\n<li><strong>Architecture<\/strong>: Full migration to strict PHP 8 typing (<code>declare(strict_types=1)<\/code>).<\/li>\n<li><strong>Localization<\/strong>: 100% i18n compliance. All UI strings wrapped in <code>__()<\/code> with text domain <code>baseweb-ai-chat-forms-to-max<\/code>.<\/li>\n<li><strong>Prefix Update<\/strong>: All options, transients, and hooks migrated from <code>baseweb_uac_<\/code> to <code>bacfm_<\/code> to prevent conflicts.<\/li>\n<li><strong>Security<\/strong>: Enhanced nonce verification, strict input sanitization, and enforced <code>sslverify =&gt; true<\/code> across all endpoints.<\/li>\n<li><strong>New Feature<\/strong>: Added <code>uninstall.php<\/code> for clean database removal upon plugin deletion.<\/li>\n<li><strong>Compatibility<\/strong>: Added explicit <code>Requires Plugins: fluentform<\/code> header.<\/li>\n<\/ul>\n\n<h4>2.1.0<\/h4>\n\n<ul>\n<li><strong>Universality<\/strong>: Removed hardcoded brand references. Added dynamic <code>{{company_name}}<\/code> and <code>{{manager_name}}<\/code> placeholders.<\/li>\n<li><strong>Prompt Caching<\/strong>: Added 1-hour transient caching for system prompts to reduce database load.<\/li>\n<li><strong>Compliance<\/strong>: Added mandatory consent checkbox for lead forms (152-FZ\/GDPR) and automated 30-day log cleanup via WP-Cron.<\/li>\n<li><strong>MAX Integration<\/strong>: Added 60-second transient duplicate locking to prevent double lead submissions.<\/li>\n<li><strong>UX<\/strong>: Added native WordPress spinner for MAX test button and improved error handling in JS.<\/li>\n<\/ul>\n\n<h4>2.0.3<\/h4>\n\n<ul>\n<li><strong>Bugfix<\/strong>: Corrected parameter order in the <code>fluentform\/submission_inserted<\/code> hook.<\/li>\n<li><strong>Bugfix<\/strong>: Added strict length validation (max 4000 chars) for MAX API payloads.<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li><strong>Major Architecture Overhaul<\/strong>: Combined AI Chat and Fluent Forms \u2192 MAX modules into a single unified plugin.<\/li>\n<li><strong>New Classes<\/strong>: Introduced <code>class-max-handler.php<\/code> (with retry logic), <code>class-logger.php<\/code> (structured PII-masking logs), and <code>class-fluent-forms.php<\/code>.<\/li>\n<li><strong>Dashboard<\/strong>: Upgraded to a 4-tab settings interface (Yandex, MAX, Logs, Export).<\/li>\n<li><strong>Security<\/strong>: Enforced <code>sslverify =&gt; true<\/code>, removed all hardcoded tokens, and implemented strict session ID validation.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added <code>session_id<\/code> validation and guest generation.<\/li>\n<li>Enforced <code>sslverify =&gt; true<\/code> and <code>max_tokens =&gt; 500<\/code> for all API calls.<\/li>\n<li>Improved JavaScript error handling and fallback UI messages.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release of the BaseWeb AI Chat plugin.<\/li>\n<\/ul>","raw_excerpt":"AI chatbot powered by Yandex AI Studio. Captures leads from chat and Fluent Forms, sending them to MAX. Fully 152-FZ\/GDPR compliant.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/347452","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=347452"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/olegroslyakov"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=347452"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=347452"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=347452"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=347452"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=347452"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=347452"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}