=== SiteTella AI ===
Contributors: sitetella
Tags: ai, chat, chatbot, elementor, gutenberg
Requires at least: 6.6
Tested up to: 7.0
Requires PHP: 8.2
Stable tag: 0.4.2
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Add configurable, site-aware AI chat agents to WordPress with Gutenberg and Elementor support.

== Description ==

SiteTella AI provides a free WordPress extension that connects a verified site tenant to the SiteTella service hosted on Cloudflare Workers. An administrator grants consent with one Connect action; the plugin then registers the site automatically, receives its assigned site ID, verifies ownership, and queues selected content. A packaged public extension requires no endpoint or SiteTella service key setup. It includes:

* A dynamic Gutenberg block, shortcode, optional site-wide launcher, and an Elementor widget with comprehensive Content and Style controls.
* Multiple agents with separate instructions, visibility, models, WordPress abilities, and optional remote MCP servers.
* Managed model access or bring-your-own-key providers.
* Asynchronous indexing of published WordPress content.
* Usage reporting and configurable conversation retention.
* Visitor approval before approval-only abilities and every write ability run.
* English and Spanish interfaces, with per-widget language and visibility controls for headers, greetings, availability, and sources.

The plugin does not place provider credentials or the site installation secret in browser markup. Chat sessions are minted by WordPress and expire automatically.

== External service ==

This plugin connects to the SiteTella API at https://api.sitetella.com, or to the development-only `SITETELLA_API_URL` override. The service receives site registration metadata, normalized content selected for indexing, chat messages, and session data. The plugin sets one random first-party cookie (`sitetella_visitor`) so a visitor can continue their own conversations; only a keyed hash of it leaves WordPress. For signed-in visitors, WordPress user ID and role names are included in short-lived chat session claims so authenticated agents can enforce access and one conversation history follows the account across devices. While processing those requests, the service records measured usage. For configured site abilities, the service sends signed requests to WordPress and receives the results. A provider API key is sent only when an administrator explicitly selects bring-your-own-key mode.

SiteTella routes managed AI requests through Cloudflare Workers AI and Cloudflare AI Gateway, using `@cf/zai-org/glm-5.2` by default. Content selected for indexing, search queries, chat messages, tool context, and generated responses can be processed by Cloudflare and the selected model provider. When bring-your-own-key mode is selected, the same request data is routed through Cloudflare AI Gateway to the configured OpenAI, Anthropic, Google, or Mistral service. Gateway payload logging and caching are disabled by SiteTella.

When an administrator configures a remote MCP server, the SiteTella service can connect to that administrator-supplied public HTTPS endpoint. No connection is made until at least one tool name is explicitly allowlisted. Tool inputs and outputs are processed by that third-party MCP service under its own terms and permissions. SiteTella does not accept MCP credentials in WordPress settings.

On SiteTella's own WordPress administration pages only, the plugin sends pseudonymous product-usage events, JavaScript errors, and privacy-masked session recordings to PostHog through https://e.sitetella.com. All form inputs are masked; provider credentials, MCP settings, notices, and conversation content are blocked or masked. The telemetry identifies a WordPress administrator with a one-way, installation-scoped hash and does not send their email address. PostHog telemetry is not loaded on visitor-facing pages.

This plugin connects automatically to `https://api.sitetella.com`. Packaged releases do not require endpoint settings or service credentials. `SITETELLA_API_URL` is reserved for development overrides.

== Installation ==

1. Upload and activate the plugin.
2. Open Settings > SiteTella AI and select Connect this site. That one consent-gated action automatically registers the site, assigns its site ID, and verifies ownership; no endpoint or SiteTella service key setup is required in a packaged public build.
3. Select Link to a SiteTella account to create a short-lived one-time code, then finish the claim in the SiteTella account dashboard.
4. Configure agents, provider, knowledge, appearance, and retention.
5. Add the SiteTella AI block, use `[sitetella agent="default"]`, add the Elementor widget, or enable the global launcher.

The site and callback URLs must be publicly reachable over HTTPS for automatic ownership verification and site abilities.

The shortcode accepts `mode` (`inline`, `floating`, or `search`), `position`, `language`, `header`, `presence`, `show_greeting`, and `sources`. Visibility values may be `default`, `true`, or `false`. Text can be overridden with `assistant_title`, `greeting`, `placeholder`, `presence_label`, and `launcher_label`. The `search` mode renders a search-box trigger that opens the chat in a centered overlay. Pre-defined questions are offered with `questions`, separated by `|` (for example `questions="What do you sell?|How do I get support?"`); visitors send one by selecting it.

== Frequently Asked Questions ==

= Are API keys stored in WordPress? =

No. The settings form forwards a key to the tenant backend over HTTPS and does not persist it in WordPress.

= What content is indexed? =

Only published, publicly viewable content from the post types selected in Knowledge. Content is normalized without executing arbitrary `the_content` filters.

= Can an agent edit WordPress? =

Only when the agent has an explicit local grant, a configured WordPress actor with the required capability, and the visitor approves the action. Write grants cannot be configured as automatic. Read grants can also require visitor approval.

The configured actor is used only for approved write abilities. Read abilities run as the signed-in visitor; anonymous visitors can read only public content.

= Can an agent use a remote MCP server? =

Yes. Configure up to eight trusted public HTTPS servers on the agent. No connection is made until you explicitly allowlist a tool name. Listing a tool preapproves agent calls without the WordPress visitor-approval flow, so list only tools you have verified are read-only or otherwise safe for visitors to invoke. Credentials, private-network URLs, wildcard tool access, and duplicate tool namespaces are rejected.

= What happens when the plugin is uninstalled? =

Uninstall always revokes only this WordPress connector. The account-owned tenant, indexed content, conversations, usage, and billing records are never deleted by plugin uninstall. When local-data deletion is enabled, local tables and credentials are removed after successful revocation; if revocation fails, they are preserved so reinstalling SiteTella can retry safely. When local-data deletion is disabled, the remaining local preferences and tables are preserved.

== Privacy ==

The plugin adds suggested privacy-policy text under Settings > Privacy. Chat messages and selected site content leave WordPress for processing by the configured SiteTella service. SiteTella administration pages also use privacy-masked PostHog telemetry. Configure retention and content selection to match your policy.

== Changelog ==

= 0.4.2 =
* Added privacy-masked PostHog telemetry for the API and WordPress administration pages.
* Added GitHub Actions deployment for the auth, dashboard, and CDN Workers.

= 0.4.1 =
* Restored scheduled exchange-rate refreshes and public callbacks on Cloudflare's public-only outbound network path.

= 0.4.0 =
* Rebuilt the service runtime on Cloudflare Workers, Durable Objects, Workflows, D1, and Vectorize.
* Routed managed AI and embedding usage through Cloudflare AI Gateway Unified Billing with payload logging and caching disabled.
* Added production Wompi billing and a verified, atomic release deployment.

= 0.3.0 =
* One conversation across every widget surface: the floating launcher, inline blocks, search overlay, and other browser tabs stay in step.
* One conversation history per person: signed-in visitors keep their history across devices and networks, and anonymous visitors are recognized by a first-party cookie instead of their network address.
* Faster first message: site configuration is cached and the session is warmed on hover, so opening the chat no longer waits on a connection.
* Past conversations from earlier versions are not carried over.


= 0.2.0 =
* New dashboard: top-level SiteTella menu with Home overview and grouped sections.
* Site manager integrations: WooCommerce products and orders plus SEO metadata from Yoast, Rank Math, or AIOSEO, with approval-gated writes.
* Billing shown in USD with usage as a percentage of the plan.


= 0.1.0 =

* Initial tenant-aware chat, indexing, agent, provider, usage, Gutenberg, and Elementor implementation.
