{"id":349395,"date":"2026-08-10T20:22:49","date_gmt":"2026-08-10T20:22:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/botmetria\/"},"modified":"2026-08-10T20:22:27","modified_gmt":"2026-08-10T20:22:27","slug":"botmetria","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/botmetria\/","author":23532086,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.9.1","stable_tag":"1.9.1","tested":"7.0.3","requires":"6.4","requires_php":"8.1","requires_plugins":null,"header_name":"Botmetria","header_author":"Botmetria","header_description":"AI-bot analytics for WooCommerce: see which AI crawlers and assistants visit your store, attribute visits and orders coming from ChatGPT\/Perplexity, control bot access, and serve machine-readable data (JSON-LD, llms.txt).","assets_banners_color":"384145","last_updated":"2026-08-10 20:22:27","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/botmetria.com\/help\/","header_author_uri":"https:\/\/botmetria.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":41,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.9.1":{"tag":"1.9.1","author":"botmetria","date":"2026-08-10 20:22:27"}},"upgrade_notice":{"1.7.0":"<p>Events the cloud refuses no longer block delivery of everything else; retries back off politely, and a broken API key is called out in the admin instead of failing silently.<\/p>","1.4.0":"<p>Shows what share of the pages your server renders is served to traffic that never runs JavaScript \u2014 the visitors nothing else could see.<\/p>","1.3.0":"<p>Automatically keeps AI bots out of WP Rocket&#039;s cache and flags other caches on the Status page, so bot visits are no longer lost to caching.<\/p>","1.2.0":"<p>Adds the agentic product feed + UCP catalog so AI shopping agents can discover and read your catalog.<\/p>","1.1.0":"<p>Adds a user-managed blocklist (custom bots + IP networks) controlled from the dashboard.<\/p>","1.0.0":"<p>First public release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3641091,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3641091,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3641091,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3641091,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3641091,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.9.1"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Status page \u2014 detected AI visits, buffer state, last delivery.","2":"AI Traffic page \u2014 firewall modes, vendor allowlist, per-bot matrix, 7-day counters.","3":"Settings \u2014 cloud connection and feature toggles.","4":"Weekly e-mail report."}},"plugin_section":[],"plugin_tags":[2353,232,4866,244604,286],"plugin_category":[36,45],"plugin_contributors":[275074],"plugin_business_model":[],"class_list":["post-349395","plugin","type-plugin","status-publish","hentry","plugin_tags-ai","plugin_tags-analytics","plugin_tags-bots","plugin_tags-llms-txt","plugin_tags-woocommerce","plugin_category-analytics","plugin_category-ecommerce","plugin_contributors-botmetria","plugin_committers-botmetria"],"banners":{"banner":"https:\/\/ps.w.org\/botmetria\/assets\/banner-772x250.png?rev=3641091","banner_2x":"https:\/\/ps.w.org\/botmetria\/assets\/banner-1544x500.png?rev=3641091","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/botmetria\/assets\/icon.svg?rev=3641091","icon":"https:\/\/ps.w.org\/botmetria\/assets\/icon.svg?rev=3641091","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Shoppers increasingly ask ChatGPT, Perplexity and other AI assistants what to buy \u2014 and classic analytics records those visitors as \"direct\", so store owners never see them. Botmetria makes this traffic visible and controllable:<\/p>\n\n<ul>\n<li><strong>AI bot analytics<\/strong> \u2014 every visit by a known AI crawler or assistant agent (GPTBot, ChatGPT-User, ClaudeBot, PerplexityBot and more) is detected and counted, with the page, product and response time.<\/li>\n<li><strong>Impostor detection<\/strong> \u2014 a User-Agent string is trusted only after the visitor IP is verified against the bot vendor's published IP ranges. Scrapers pretending to be GPTBot show up as impostors, not as AI traffic.<\/li>\n<li><strong>AI referral attribution<\/strong> \u2014 human visitors arriving from AI assistants (chatgpt.com, perplexity.ai, \u2026) are tracked to first-touch source, including WooCommerce orders and revenue.<\/li>\n<li><strong>AI firewall<\/strong> \u2014 decide who gets in: Showcase (welcome all known AI bots), Allowlist (block everything except chosen vendors), Server relief (temporary 503 + Retry-After for all AI bots), or a per-bot Custom matrix. Classic search engines (Googlebot, Bingbot, \u2026) are never blocked \u2014 a code-level safety.<\/li>\n<li><strong>Machine readability<\/strong> \u2014 valid JSON-LD Product markup, an <code>llms.txt<\/code> summary of your store, and a robots.txt helper, so AI agents can actually read your prices, availability and delivery terms.<\/li>\n<li><strong>Weekly e-mail report<\/strong> \u2014 AI visits, verified vs. impostor bots, top products by bot attention, AI-sourced orders, and plain-language recommendations.<\/li>\n<\/ul>\n\n<p>The hot path is a single User-Agent substring scan per request (a few milliseconds, no DB writes, no HTTP calls); events are buffered locally and shipped in batches in the background. If the cloud is unreachable, your store is never slowed down or blocked \u2014 the plugin fails open.<\/p>\n\n<h4>External service (required reading)<\/h4>\n\n<p>This plugin is a connector for <strong>Botmetria<\/strong>, an analytics service. Once you connect your store (by entering the Cloud URL, API key and HMAC secret from your Botmetria account), the plugin communicates with the Botmetria cloud \u2014 by default <code>https:\/\/api.botmetria.com<\/code>, or a server you configure:<\/p>\n\n<ul>\n<li><strong>Sent<\/strong>: AI-bot visit events (bot name, bot user-agent, bot IP address, requested URL path, page type, product ID, HTTP status, response time), AI-referral events (source such as \"chatgpt\", landing URL, an anonymized session hash, and for conversions the WooCommerce order ID, order total and currency; orders with no AI interaction are reported the same way with source \"none\" \u2014 the baseline needed to compute the AI share of revenue \u2014 and a refund, cancellation or failed payment sends a negative amount correcting the revenue previously reported for that order), results of one-click fix actions you triggered from your dashboard (action id, status and a short message), aggregate page-serve counters (how many pages the server served per time window \u2014 numbers only), and a product-feed quality summary after each feed rebuild (how many products lack a price, image or GTIN\/SKU, with up to 10 SKU identifiers per gap as examples). Events are signed with your HMAC secret.<\/li>\n<li><strong>Received<\/strong>: the up-to-date AI bot detect list, official bot vendor IP ranges for impostor detection, your plugin configuration (including firewall settings if you manage them from the Botmetria dashboard), one-click fix commands you approved in your dashboard (the plugin only executes actions from the fixed list built into its code \u2014 the cloud cannot send code or arbitrary instructions), and question\/answer pairs you approved for FAQPage markup.<\/li>\n<li><strong>Not sent<\/strong>: no shopper names, e-mails, addresses or payment data; no admin credentials. The session hash cannot be reversed into a person. Bot IP addresses (not human visitors' IPs) are transmitted for verification purposes.<\/li>\n<\/ul>\n\n<p>Nothing is transmitted until you enter your API credentials. Terms of use: <a href=\"https:\/\/botmetria.com\/terms.html\">https:\/\/botmetria.com\/terms.html<\/a>. Privacy policy: <a href=\"https:\/\/botmetria.com\/privacy.html\">https:\/\/botmetria.com\/privacy.html<\/a>. The service is operated by Botmetria (<a href=\"https:\/\/botmetria.com\">https:\/\/botmetria.com<\/a>).<\/p>\n\n<p>The AI firewall, JSON-LD and llms.txt features also work <strong>without<\/strong> a cloud account, using the detect list and IP ranges bundled with the plugin.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin ZIP via <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong>, then activate it.<\/li>\n<li>Create a site in your Botmetria account.<\/li>\n<li>Open <strong>Settings \u2192 Botmetria<\/strong>, paste the Cloud URL, API key and HMAC secret, and press <strong>Test connection<\/strong>.<\/li>\n<li>(Recommended) Disable WP-Cron and add a real cron job so buffered events ship on time, and exclude AI bots from your page cache \u2014 see the Status page hints.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20it%20slow%20my%20store%20down%3F\"><h3>Does it slow my store down?<\/h3><\/dt>\n<dd><p>No. The per-request work is one substring scan over a cached bot list (a few milliseconds). Events are written to a local buffer table and shipped in the background on shutdown and via cron.<\/p><\/dd>\n<dt id=\"does%20it%20work%20without%20woocommerce%3F\"><h3>Does it work without WooCommerce?<\/h3><\/dt>\n<dd><p>The analytics, firewall and llms.txt work on any WordPress site. Product JSON-LD and order\/revenue attribution require WooCommerce.<\/p><\/dd>\n<dt id=\"will%20it%20block%20google%3F\"><h3>Will it block Google?<\/h3><\/dt>\n<dd><p>Never. Classic search engine crawlers (Googlebot, Bingbot, YandexBot, DuckDuckBot and others) are exempt from every firewall mode at code level.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20the%20botmetria%20cloud%20is%20down%3F\"><h3>What happens if the Botmetria cloud is down?<\/h3><\/dt>\n<dd><p>Your store keeps working normally. Events stay in the local buffer and are retried later; firewall decisions use locally cached lists. The plugin never blocks the page render on a network call.<\/p><\/dd>\n<dt id=\"where%20does%20the%20ai%20bot%20list%20come%20from%3F\"><h3>Where does the AI bot list come from?<\/h3><\/dt>\n<dd><p>A versioned detect list bundled with the plugin, refreshed twice a day from the Botmetria cloud once connected.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.9.1<\/h4>\n\n<ul>\n<li>Question and answer markup. Q&amp;A pairs you have reviewed and approved in your Botmetria dashboard are published as FAQPage structured data on the matching product page. The plugin writes nothing on its own \u2014 only pairs a human approved \u2014 and removing them is one click away.<\/li>\n<\/ul>\n\n<h4>1.9.0<\/h4>\n\n<ul>\n<li>One-click fixes. Recommendations from your Botmetria audit can now be applied from the dashboard: the plugin picks the request up on its regular settings check and reports back what it did. The list of things the plugin will do is fixed in its own code \u2014 the cloud can only pick from that list, never send instructions of its own \u2014 and every action can be undone.<\/li>\n<\/ul>\n\n<h4>1.8.1<\/h4>\n\n<ul>\n<li>Agent endpoint errors are now reported honestly. Until this release every request from an AI agent to the product or checkout endpoint was logged as a success, even when the shop answered with a rate limit or a server error \u2014 so the dashboard could never warn you that agents were unable to place orders. It can now.<\/li>\n<\/ul>\n\n<h4>1.8.0<\/h4>\n\n<ul>\n<li>Quick connect: paste one connection string from your Botmetria dashboard instead of copying the Cloud URL, API key and HMAC secret one by one. The plugin fills the fields and tests the connection in the same step; a truncated paste is rejected on the spot instead of failing later as an authorization error.<\/li>\n<li>Honest revenue: refunds, cancellations and failed payments now correct the AI-attributed revenue that was reported when the order was created. Partial refunds send only the difference, so repeated refunds cannot double-count.<\/li>\n<li>Orders without an AI click are reported too, as the baseline the dashboard needs to answer \"what share of revenue did AI influence\" \u2014 no extra data about the shopper is sent.<\/li>\n<li>Orders that started as an agent checkout session carry that session id, so the dashboard can show the whole chain from crawl to order.<\/li>\n<li>Russian and Romanian admin translations are available again. On WordPress.org they are delivered through translate.wordpress.org; a community language pack always wins when one exists.<\/li>\n<\/ul>\n\n<h4>1.7.0<\/h4>\n\n<ul>\n<li>Reliable delivery: an event the cloud cannot accept no longer blocks every event behind it. Such events are set aside with the reason shown on the Status page, while the rest keep flowing.<\/li>\n<li>Smarter retries: temporary problems (network, server hiccups, rate limits) now back off gradually instead of retrying every 5 minutes forever.<\/li>\n<li>If the API key stops working, delivery pauses and a notice in the admin tells you exactly what to fix \u2014 no more silently growing queue.<\/li>\n<li>The Status page shows undeliverable events and why they were refused.<\/li>\n<li>All AI Traffic controls are now available locally: custom blocked bots, blocked IP networks, unknown-automation and impostor policies got their own settings on the AI Traffic page, and cloud management became an explicit opt-in you can switch off at any time.<\/li>\n<li>AI referral attribution now also recognises URL markers (for example ChatGPT's utm_source tag) when the browser sends no Referer \u2014 visits from native AI apps and in-app browsers were previously uncounted.<\/li>\n<li>Translations moved to translate.wordpress.org (community language packs); bundled translation files were removed.<\/li>\n<\/ul>\n\n<h4>1.6.2<\/h4>\n\n<ul>\n<li>Hardening: the machine-readable endpoints (llms.txt, Markdown, product feed, UCP catalog and manifest) now send X-Content-Type-Options: nosniff, so a browser cannot MIME-sniff their responses into something executable. Defense-in-depth; no behavior change.<\/li>\n<\/ul>\n\n<h4>1.6.1<\/h4>\n\n<ul>\n<li>Security: password-protected products (WooCommerce Visibility \u2192 Password) are no longer exposed to AI agents. Their JSON-LD, agentic feed, UCP catalog and UCP checkout now skip them \u2014 matching the markdown twin \u2014 so an anonymous request can no longer read a product the owner hid behind a password.<\/li>\n<\/ul>\n\n<h4>1.6.0<\/h4>\n\n<ul>\n<li>Feed performance for large catalogs (up to 50,000 products): the agentic feed and products.xml are now generated as files in a streamed, batched pass (flat memory use) and served from disk. Product edits no longer rebuild the feed immediately \u2014 one deferred rebuild is scheduled while the current feed keeps serving.<\/li>\n<li>Faster UCP catalog list: variations are no longer expanded on the list endpoint (agents drill into a single product for offers), and normalized product data is cached (self-invalidating on product edit).<\/li>\n<li>Honest sliding-window rate limiting (120 requests\/minute per IP) on UCP endpoints, replacing the per-second counter.<\/li>\n<li>Internal refactor: JSON-LD and the markdown twin now read product data through the same catalog serializer as the feed and UCP (one reader, consistent stock semantics via the short-TTL stock cache).<\/li>\n<\/ul>\n\n<h4>1.5.0<\/h4>\n\n<ul>\n<li>Agentic commerce (phase 2): UCP checkout sessions. AI agents can now build a cart via POST\/PATCH \/ucp\/v1\/checkout-sessions and receive a signed hand-off URL; opening it pre-fills the native WooCommerce cart and redirects the shopper to the store's own checkout. Payments stay entirely with the store \u2014 the plugin never sees card data.<\/li>\n<li>Orders born from an agent session are attributed: order meta marks the source (chatgpt\/perplexity\/gemini\/copilot\/claude, or \"ai_agent\" when the agent is unknown) and known agents are counted as AI conversions in the dashboard.<\/li>\n<li>The \/.well-known\/ucp manifest now advertises checkout capability (payment: false).<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>Traffic-without-JS measurement: the plugin now reports how many pages the server actually served, so the dashboard can show what share of them never ran the pixel \u2014 traffic that claims no bot user-agent and executes no JavaScript was previously counted nowhere at all. Counters only, no personal data.<\/li>\n<li>Not measured behind a page cache, on purpose: a full-page cache serves visitors HTML without running PHP, so the count would be wrong. The dashboard hides the tile instead of showing a plausible but false number.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Page-cache integration: AI bots are automatically excluded from WP Rocket's page cache (so their visits reach the plugin and get counted), and the Status page now detects other active caches (LiteSpeed, W3 Total Cache, WP Super Cache, WP Fastest Cache, Cloudflare) and shows the exact user-agents to exclude from them.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Agentic commerce (phase 1): ACP product feed (\/feed\/agentic.json + \/products.xml) with a data-quality validator, and read-only UCP endpoints (\/.well-known\/ucp manifest + \/ucp\/v1\/products catalog) built over one internal catalog format. New \"Agentic feed\" \/ \"UCP\" toggles in Settings.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>User-managed blocklist: custom unwanted bots (block by User-Agent substring) and blocked IP networks (CIDR), managed from the Botmetria dashboard and applied in any mode. Classic search engines are never blocked.<\/li>\n<li>Cloud-controlled unknown-automation policy. robots.txt lists custom-blocked bots.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release: AI bot detection with impostor verification, AI referral and order attribution, AI firewall (Showcase \/ Allowlist \/ Server relief \/ Custom), JSON-LD and llms.txt layer, weekly e-mail reports, cloud-managed firewall via the Botmetria dashboard.<\/li>\n<\/ul>","raw_excerpt":"See which AI bots read your store, attribute visits and orders coming from AI assistants, and control which AI crawlers get access.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/349395","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=349395"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/botmetria"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=349395"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=349395"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=349395"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=349395"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=349395"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=349395"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}