{"id":369553,"date":"2026-10-09T22:59:48","date_gmt":"2026-10-09T22:59:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/keystone-seo\/"},"modified":"2026-10-09T22:59:35","modified_gmt":"2026-10-09T22:59:35","slug":"lumioh-seo","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/lumioh-seo\/","author":23562809,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.22.1","stable_tag":"1.22.1","tested":"7.1.3","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Lumioh SEO","header_author":"John O'Connor","header_description":"Technical SEO operating system for WordPress: sitewide audit, redirect and migration tooling, internal-link intelligence. Local-first, no telemetry.","assets_banners_color":"01498b","last_updated":"2026-10-09 22:59:35","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/github.com\/sponsors\/web-lifter","header_plugin_uri":"","header_author_uri":"https:\/\/johnoconnor.xyz","rating":0,"author_block_rating":0,"active_installs":0,"downloads":65,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.22.1":{"tag":"1.22.1","author":"johnoconnor0","date":"2026-10-09 22:59:35","revision":3737410}},"upgrade_notice":{"1.22.1":"<p>Maintenance release: shared CSV and file-reading helpers, and SQL written so coding-standard checks can read it. No change to features, settings or stored data. A bundle restore started before 1.22 must be read again.<\/p>","1.22.0":"<p>Security release. Running audits, changing findings and viewing configuration now need manager capabilities, and every form has its own nonce, so reload any admin page you left open before updating. Disabled features no longer act in the background.<\/p>","1.20.0":"<p>Lumioh SEO fields have moved off the core REST routes to\n\/wp-json\/lumioh\/v1\/seo\/\/, where each is named after its\nmeta key without the <em>useo<\/em> prefix. This affects you only if you turned on\nREST Writes and built against \/wp\/v2. The admin is unaffected.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3737410,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3737410,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3737410,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3737410,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.22.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3737410,"resolution":"1","location":"assets","locale":"","width":1280,"height":900},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3737410,"resolution":"2","location":"assets","locale":"","width":1000,"height":790},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3737410,"resolution":"3","location":"assets","locale":"","width":1280,"height":900},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3737410,"resolution":"4","location":"assets","locale":"","width":1280,"height":900},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3737410,"resolution":"5","location":"assets","locale":"","width":1280,"height":900},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3737410,"resolution":"6","location":"assets","locale":"","width":1280,"height":900}},"screenshots":{"1":"Dashboard evidence states, findings and setup progress.","2":"Post editor meta box with search, social, JSON-LD and analysis tabs.","3":"Search Appearance templates and variable picker.","4":"Redirect Manager rules, 404 log, activity and import\/export.","5":"Sitemap settings and public URL status.","6":"Site audit findings with evidence, ownership and resolution state."}},"plugin_section":[],"plugin_tags":[6681,726,186,20034,167235],"plugin_category":[55],"plugin_contributors":[285452],"plugin_business_model":[],"class_list":["post-369553","plugin","type-plugin","status-publish","hentry","plugin_tags-internal-links","plugin_tags-redirects","plugin_tags-seo","plugin_tags-site-audit","plugin_tags-technical-seo","plugin_category-seo-and-marketing","plugin_contributors-johnoconnor0","plugin_committers-johnoconnor0"],"banners":{"banner":"https:\/\/ps.w.org\/lumioh-seo\/assets\/banner-772x250.png?rev=3737410","banner_2x":"https:\/\/ps.w.org\/lumioh-seo\/assets\/banner-1544x500.png?rev=3737410","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/lumioh-seo\/assets\/icon-128x128.png?rev=3737410","icon_2x":"https:\/\/ps.w.org\/lumioh-seo\/assets\/icon-256x256.png?rev=3737410","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/lumioh-seo\/assets\/screenshot-1.png?rev=3737410","caption":"Dashboard evidence states, findings and setup progress."},{"src":"https:\/\/ps.w.org\/lumioh-seo\/assets\/screenshot-2.png?rev=3737410","caption":"Post editor meta box with search, social, JSON-LD and analysis tabs."},{"src":"https:\/\/ps.w.org\/lumioh-seo\/assets\/screenshot-3.png?rev=3737410","caption":"Search Appearance templates and variable picker."},{"src":"https:\/\/ps.w.org\/lumioh-seo\/assets\/screenshot-4.png?rev=3737410","caption":"Redirect Manager rules, 404 log, activity and import\/export."},{"src":"https:\/\/ps.w.org\/lumioh-seo\/assets\/screenshot-5.png?rev=3737410","caption":"Sitemap settings and public URL status."},{"src":"https:\/\/ps.w.org\/lumioh-seo\/assets\/screenshot-6.png?rev=3737410","caption":"Site audit findings with evidence, ownership and resolution state."}],"raw_content":"<!--section=description-->\n<p>Lumioh SEO is a local-first technical SEO plugin for WordPress. It audits\nwhat a site emits, records evidence for each finding, and provides controlled\ntools to fix redirects, metadata, links, migrations and search appearance.<\/p>\n\n<p>It works against your own WordPress database and server. There is no account,\nlicence key, usage quota or telemetry. It does not score pages or promise\nrankings.<\/p>\n\n<h4>Features<\/h4>\n\n<ul>\n<li><strong>Site audit:<\/strong> resumable checks for titles, descriptions, canonicals,\nrobots directives, sitemaps, redirects, links and other technical signals.\nFindings include severity, the affected object and supporting evidence. An\naudit can be scheduled locally to run daily or weekly.<\/li>\n<li><strong>Redirects and migration:<\/strong> exact or regular-expression rules, supported\nstatus codes, scheduling, priorities, cycle detection, chain flattening,\nCSV\/JSON imports, dry-run migration, backups and rollback.<\/li>\n<li><strong>Internal-link intelligence:<\/strong> link graph, orphan and weak-page reports,\nanchor analysis, link-equity opportunities and topic clusters.<\/li>\n<li><strong>Metadata and search appearance:<\/strong> per-object and inherited title,\ndescription, canonical and robots templates with a resolved preview.<\/li>\n<li><strong>Social and structured data:<\/strong> Open Graph, X\/Twitter and validated JSON-LD.\nLumioh stands down when WooCommerce already owns Product schema.<\/li>\n<li><strong>Sitemaps and robots:<\/strong> source-aware XML sitemaps, optional HTML sitemap,\nguided robots.txt rules, effective previews and optional llms.txt.<\/li>\n<li><strong>Internationalisation:<\/strong> page and term hreflang support for native entries\nand supported translation plugins, without emitting duplicate sets.<\/li>\n<li><strong>Import\/export:<\/strong> detection-first imports from supported SEO and redirect\nplugins, dry runs, change history, rollback, JSON\/CSV export and WP-CLI.<\/li>\n<li><strong>Administration:<\/strong> bulk editing, granular capabilities, Site Health\nintegration, audit reports and a local change\/event history.<\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>Lumioh SEO has no telemetry, licence checks, tracking pixels, remote scripts,\nstyles or fonts. Analysis and output checks run on your server. Administrators\ncan enable these network features:<\/p>\n\n<ul>\n<li>Rendered-page analysis requests one published permalink on the same site.<\/li>\n<li>Output checks request the site's own home page, robots.txt, sitemap, llms.txt\nor IndexNow key file.<\/li>\n<li>A manually started redirect check sends one HEAD request to the destination\nentered for that rule; redirects off the site's host are not followed.<\/li>\n<li>IndexNow is disabled by default. When enabled, it sends changed public URLs,\nthe site's hostname and its IndexNow key to the configured endpoint\n(default: https:\/\/api.indexnow.org\/indexnow). It sends no post content,\npersonal data or visitor information. See https:\/\/www.indexnow.org\/ and the\nMicrosoft Privacy Statement at https:\/\/privacy.microsoft.com\/privacystatement.<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload or install <strong>Lumioh SEO<\/strong> from <strong>Plugins \u2192 Add New<\/strong>, then activate it.<\/li>\n<li>Open <strong>Lumioh SEO<\/strong> in the admin menu and review the setup checklist.<\/li>\n<li>Configure templates under <strong>Search Appearance<\/strong>, then review <strong>Sitemap<\/strong> and\n<strong>robots.txt<\/strong> before relying on them.<\/li>\n<li>Export existing data before a migration or destructive uninstall.<\/li>\n<\/ol>\n\n<p>Lumioh detects supported SEO plugins and stands down from output they own. It\nnever deactivates or modifies another plugin.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20it%20work%20with%20woocommerce%3F\"><h3>Does it work with WooCommerce?<\/h3><\/dt>\n<dd><p>Yes. Lumioh does not emit duplicate Product schema when WooCommerce already\nprovides it. Shop archives and product taxonomies can be configured.<\/p><\/dd>\n<dt id=\"can%20i%20use%20it%20with%20another%20seo%20plugin%3F\"><h3>Can I use it with another SEO plugin?<\/h3><\/dt>\n<dd><p>Lumioh can coexist with supported SEO plugins. It stops emitting metadata,\ncanonical, social and schema output owned by the other plugin, while its\nredirect, sitemap, robots, IndexNow and reporting tools remain available.\nImporters help you migrate before switching.<\/p><\/dd>\n<dt id=\"can%20non-administrators%20use%20it%3F\"><h3>Can non-administrators use it?<\/h3><\/dt>\n<dd><p>Yes. Lumioh defines separate capabilities for settings, metadata, redirects,\nschema, analysis and reports. Administrators can assign only the parts a user\nneeds.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20delete%20the%20plugin%3F\"><h3>What happens when I delete the plugin?<\/h3><\/dt>\n<dd><p>Deactivation keeps settings and metadata. Deleting the plugin removes Lumioh\noptions, metadata and tables for redirects, links, audits, history, activity\nand the IndexNow queue. On multisite this runs for each site. The <strong>Keep Lumioh\nSEO data on this site<\/strong> setting preserves that data during uninstall; it is off\nby default. Export anything required before deleting.<\/p><\/dd>\n<dt id=\"will%20it%20make%20my%20site%20rank%20higher%3F\"><h3>Will it make my site rank higher?<\/h3><\/dt>\n<dd><p>No plugin can promise rankings. Lumioh reports verifiable technical signals\nand advisory editorial guidance; search engines decide how to use them.<\/p><\/dd>\n<dt id=\"where%20do%20i%20get%20support%3F\"><h3>Where do I get support?<\/h3><\/dt>\n<dd><p>Use the WordPress.org support forum. Report security issues privately to\njohn@weblifter.com.au.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.22.1<\/h4>\n\n<ul>\n<li>Maintenance release: no change to features, settings or stored data, with one exception for a restore started before 1.22 (below).<\/li>\n<li>CSV imports (bulk edit, redirects, metadata) are read by one shared reader and the audit CSV is written by one shared formatter. The bytes written and the rows read are the same as in 1.22.0. The reader holds the file in memory only; it no longer uses a temporary stream that can spill to disk.<\/li>\n<li>The sitemap stylesheet, the inclusive-language word list, the audit report style and import files are read through WordPress's own filesystem class, with a size limit checked before and after the read.<\/li>\n<li>A bundle restore that a release before 1.22 left half finished can no longer be resumed: it stops and asks you to read the bundle again. Its old scratch file is still deleted and is never read.<\/li>\n<li>The bulk CSV export reads 100 posts at a time instead of 200 and still stops at the same number of posts.<\/li>\n<li>Database statements name their tables as <code>{$wpdb-&gt;prefix}useo_...<\/code>, so WordPress coding-standard checks can read them. The SQL itself is unchanged.<\/li>\n<li>Coding-standard clean-up: fewer inline suppression comments, translators comments on strings that take placeholders, and renamed parameters that shadowed reserved words.<\/li>\n<\/ul>\n\n<h4>1.22.0<\/h4>\n\n<ul>\n<li>Fixed stored cross-site scripting in the page title: custom-field values used by the <code>%%cf_&lt;key&gt;%%<\/code> token are treated as plain text and the title handed to WordPress is escaped.<\/li>\n<li>Fixed the audit CSV export so a value can no longer start a spreadsheet formula.<\/li>\n<li>Tightened permissions: running audits, changing finding status and refreshing the dashboard need the manager capability; redirect data over REST, abilities and activity export needs the redirect capability; configuration cards on the dashboard are shown to site managers only.<\/li>\n<li>Every admin form and Ajax action now has its own nonce and all request data is read through one verified gateway. A form left open while updating must be reloaded once.<\/li>\n<li>Redirects: destinations WordPress would refuse are rejected when you save them, a source typed the way browsers send it (for example <code>\/caf%C3%A9\/<\/code>) now matches because the encoded characters are no longer deleted from the request, and the host is checked again when a visitor is redirected.<\/li>\n<li>Screens no longer write data, create folders or make loopback requests while they render; checks run when you press the button.<\/li>\n<li>Redirect imports and audit snapshots scale with the data instead of the square of it, wildcard rules in robots and content sources no longer use regular expressions, and a bulk CSV import stops at 50,000 rows (filter <code>useo_bulk_import_max_rows<\/code>).<\/li>\n<li>Disabled features have no public, REST, IndexNow or scheduled effect.<\/li>\n<li>llms.txt is cached for five minutes for anonymous visitors. A <code>$<\/code> inside a robots.txt tester rule is matched literally, as RFC 9309 defines; only a trailing <code>$<\/code> anchors the end.<\/li>\n<li>A large redirect import holds the redirect write lock while it runs; another redirect save waits up to three seconds and then asks you to try again.<\/li>\n<li>Editor and admin scripts build DOM nodes instead of HTML strings.<\/li>\n<\/ul>\n\n<h4>1.21.1<\/h4>\n\n<ul>\n<li>Hardened request handling with field-specific sanitization, validation,\ncontextual output escaping and capability\/nonces on state-changing actions.<\/li>\n<li>Kept bundle-restore payloads in the database instead of writing protection\ndirectives into uploads, and retained safe cleanup for legacy restore files.<\/li>\n<li>Fixed WordPress upload MIME validation for JSON imports and strengthened the\nexact-ZIP security and release audit gates.<\/li>\n<\/ul>\n\n<h4>1.21.0<\/h4>\n\n<ul>\n<li>Activity report imports now recognize custom WordPress admin, content, core,\nREST and uploads paths when filtering asset requests.<\/li>\n<\/ul>\n\n<h4>1.20.0<\/h4>\n\n<ul>\n<li>Moved Lumioh field access from core <code>wp\/v2<\/code> routes to <code>lumioh\/v1<\/code>; see the\nupgrade notice for sites using REST Writes.<\/li>\n<li>Added REST access for post, term and user fields, content analysis and\ntemplate previews against unsaved edits.<\/li>\n<li>Fixed template-variable display, keyword-field controls and admin list layout.<\/li>\n<\/ul>\n\n<p>Earlier release history is included in <code>CHANGELOG.md<\/code> in the plugin files.<\/p>","raw_excerpt":"Technical SEO operating system for WordPress: audits, redirects, migrations, internal links and evidence-backed history. Local-first, no telemetry.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/369553","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=369553"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/johnoconnor0"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=369553"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=369553"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=369553"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=369553"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=369553"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=369553"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}