Repository navigation
Releases: Wordpressistic/seoistic
Release list
SEOistic 1.6.5
Sitemap indexability maintenance release. Expands HTML sitemap coverage to all published viewable content, deduplicates URLs, honors current and legacy noindex directives including noindex,nofollow, preserves existing sitemap query filters, and includes a Windows PowerShell release builder.
SEOistic 1.6.4
Search Console OAuth reliability release: clearer External and Production setup guidance, isolated concurrent OAuth state tokens, refresh-token preservation, granted-scope support, and actionable access-blocked recovery guidance. Google Cloud consent-screen publishing and verification remain required for unrestricted connections.
SEOistic 1.6.3
Fixed the AI Search REST registration fatal that could break the WordPress admin dashboard when Gutenberg preloads REST data. Imports WP_REST_Server correctly inside the namespaced addon. Validated with PHP lint, clean WordPress activation, REST registration, and entitlement smoke tests.
SEOistic 1.6.2
SEOistic 1.6.2 fixes canonical WPistic activation-token integration, safe AI Tools/Search Console error handling, Google OAuth query encoding, and actionable Rank Tracker diagnostics. The ZIP checksum is provided alongside the release asset.
SEOistic 1.5.3 — authoritative licensing
Fixes valid Free licenses incorrectly unlocking Business features. Uses WPistic server-assigned plans, preserves supported legacy aliases and explicit legacy maps, and prevents replacement keys inheriting old paid-plan caches. Existing expiry/revocation and bounded outage handling remain enforced. Before upgrading, check server-assigned customer plans; approved complimentary access belongs in WPistic. Verified: 32 isolated licensing checks, PHP syntax, real WordPress clean install and upgrade from the SHA-verified public 1.5.2 release with SEO metadata/options preserved. Runtime-only ZIP uses the canonical seoistic folder. SHA-256: 97109032dbbdd3655f2d69c47946ac1b290e78a54b6ab1b7b1c06d7790a91a6e. This publication alone does not claim installation on customer sites or registered automatic updates.
Continued WPistic licensing and protected update support.
Changelog
All notable changes to SEOistic are documented here. Format loosely follows
Keep a Changelog.
[1.5.2] - 2026-08-12
Added
- WPistic-backed licensing integration and protected update support.
- WPistic activation/validation adapter and entitlement compatibility layer.
scripts/build-release.sh— deterministic release packaging.
Release
- Bump version to 1.5.2 and prepare production release.
Changed
- Unified licensing architecture to use WPistic platform by default.
- Removed legacy GitHub Releases-based updater for licensed installations.
Security
- Default license API endpoint now points to
https://api.wpistic.com.
Release Notes
[1.5.1]
Stabilisation release. No new marketed features — this fixes surfaces that
reported inaccurate results, did not scale, or claimed capabilities the code
did not have.
Fixed
- SEO score correctness (
src/Core/Scorer.php). Four of the ten checks
could not fail, so the score overstated itself on every page:- The SEO title and meta description passed on being non-empty; the stated
10–60 and 50–160 character targets were shown in the message but never
affected the result. Both now gate on length (filterable via
seoistic/score_title_min|maxandseoistic/score_description_min|max). - The H1 check returned
trueunconditionally, including when no H1
existed. It now fails on duplicate H1s — the state the scorer can actually
prove frompost_content— passes on exactly one, and treats "none in
content" as the theme supplying it unless a site opts into the stricter
rule viaseoistic/score_require_content_h1. - The structured-data check returned
trueunconditionally, including when
schema output was suppressed by another SEO plugin (Core\Compat) or the
post's schema type was set to "none". It now reflects what the page will
actually emit. - "Focus keyword in title" passed when no focus keyword was set, so a page
with no keyword scored a point for having it in the title.
- The SEO title and meta description passed on being non-empty; the stated
- Word counting for non-Latin languages (
src/Core/WordCount.php, new).
str_word_count()is single-byte only and returned 0 for Bengali, Hindi,
Arabic, Greek, Cyrillic and every other non-Latin script, silently failing
the content-length check for entire languages regardless of how much text a
page had. Replaced with a Unicode-aware counter; unspaced scripts (Han,
Kana, Hangul) are counted per character. Unit tested. - Dashboard double-counting (
src/Core/DashboardMetrics.php). The noindex
query matched two meta keys that SEOISTIC deliberately keeps in sync, so a
single noindexed post was counted twice and "Indexable Pages" came out too
low. All postmeta joins now useCOUNT(DISTINCT p.ID), and the average
score is computed one-row-per-post. The metric is also renamed
indexable_pages(the old key remains as an alias) and the card now says
plainly that it counts what robots allow, not what Google has indexed. - Scheduled audit never reached past the first 1,000 posts
(src/Core/ScheduledAudit.php). Each run re-scored the same oldest 1,000
published posts. It now keeps a persistent keyset cursor, continues where
the previous run stopped, and wraps around at the end of the site. - Orphan scan was capped and unbounded at the same time
(src/Core/LinkGraph.php). It loaded the content of the first 5,000
published posts into one synchronous request — wrong results above that cap,
and an expensive admin request below it. Replaced with an incremental,
resumable crawl backed by a new{prefix}seoistic_link_edgestable: each
request indexes a bounded batch from a persisted cursor, and orphans become
a single indexedLEFT JOIN.url_to_postid()results are memoised. Edges
left behind by posts that are no longer published are pruned against the
posts table when a pass completes, so unpublishing or deleting a page makes
the pages it linked to become orphans again. - Redirects were loaded in full on every front-end request
(src/Addon/RedirectsModule.php). Every enabled rule was read from the
database and walked in PHP on each page view. Literal sources now resolve
through a single indexed lookup, and regex rules — the only ones that need
iterating — are cached. Also: invalid regex is rejected at save time instead
of warning on every request, self-referential targets are detected rather
than redirecting forever, and the redirect code is validated before use. - 404 log grew without bound and buried real broken links. Missing assets
and the usual automated probe paths are no longer logged, and the log is
pruned daily to a filterable 30-day retention.
Changed
-
External links are no longer blanket-nofollowed
(src/Addon/LinkManagerModule.php). Every outbound link was marked
nofollow, which contradicts Google's guidance that ordinary editorial
links need no qualification and that the qualifiers exist for specific cases
(sponsoredfor paid/affiliate,ugcfor user-generated). External links
now getnoopeneronly; sites wanting a qualifier opt in explicitly through
theseoistic_external_link_reloption or theseoistic/external_link_rel
filter. Arelan author set by hand is merged into, not overwritten. -
Google Indexing API submissions are gated to eligible pages
(src/Indexistic/IndexingEligibility.php, new). Google supports that API
only for pages carrying JobPosting or BroadcastEvent markup and states that
submitting other page types can cost a project its access. The UI previously
said it "works for other page types in practice" and submitted them anyway.
Ineligible URLs are now skipped and logged with a reason,JobPostingand
BroadcastEventare selectable schema types, and sites that emit the markup
from a template can vouch for a URL viaseoistic/google_indexing_eligible.
Bulk-action counts now report what Google accepted, not what was selected. -
"Check Google status" renamed to "Check notification status." The
Indexing API's metadata endpoint reports when Google last received a
submission for a URL — not whether the page is indexed. The button, the
method (get_notification_status()) and the surrounding copy now say so and
point at Search Console's URL Inspection for real index status. -
Multisite: network activation only ever set up one site
(src/Install/Activator.php,src/Install/Tables.php,src/Plugin.php).
WordPress runs the activation hook once for a network-wide activation, in the
context of whichever site the network admin was on, soTables::create()
created tables for that site's prefix alone. Every other site on the network
was left with no SEOISTIC tables at all, and every front-end page view on
those sites raisedTable 'wp_2_seoistic_redirects' doesn't exist— twice
per request, indefinitely, since the recovery path was admin-only and a
subsite can serve traffic for months before anyone opens its dashboard.
Network activation now sets up each existing site,wp_initialize_site
covers sites added later, and the version check runs on front-end requests
too so any site missed on a very large network repairs itself on first
request (guarded by a short lock so a traffic burst can't stampede
dbDelta). Pre-existing; not introduced in this release. -
Translations were loaded before
init(src/License/License.php,
src/Core/ScheduledAudit.php,src/Uptime/UptimeMonitor.php).
License::register()calledwp_schedule_event()at plugin-load time,
which fires thecron_schedulesfilter, whose callbacks translated their
display labels — and WordPress 6.7+ flags any translation beforeinitas
_doing_it_wrong. Every debug-enabled site on 6.7 or later logged a notice
on each admin request. Scheduling is deferred toinit, and both schedule
labels fall back to untranslated strings if another plugin triggers the
filter early. Found by actually booting the plugin on WordPress 7.0.1. -
The updater checked a private repository (
seoistic.php).
SEOISTIC_GITHUB_REPOdefaulted to the development repository, which is
private — the updater calls the GitHub releases API unauthenticated, so it
received 404 and every install silently never saw an update. It now defaults
to the public distribution repository,wordpressistic/seoistic. Sites that
need a different source can still override the constant inwp-config.php
or filterseoistic_github_repo.
Security
- Custom AI knowledge file is restricted to the media library
(src/AI/KnowledgeBase.php). The setting accepted an absolute filesystem
path or an HTTP URL and read it withfile_get_contents(), then sent the
contents to a third-party AI provider — an arbitrary-file-read and an SSRF
primitive against the host's internal network. It now accepts only a
media-library attachment ID or an uploads-relative path, resolves symlinks
before checking containment, allowlists text extensions, and caps the read.
Added
- Database version 1.3.0 → 1.4.0 for the
link_edgestable. Additive and
idempotent (dbDeltaviaInstall\Tables); uninstall, cron cleanup and the
new options are covered. - Unit tests for the Unicode word counter and Indexing API eligibility
detection (16 new tests; suite is now 47). Tested up to: 7.0.1(was 6.4), from a real test run rather than an
assumption. WordPress 7.0.1 was booted on PHP 8.4 with the plugin active,
exercising the scorer, dashboard metrics, the link-graph crawl and its new
table, the scheduled-audit cursor, redirect matching, indexing eligibility,
the knowledge-base path guards, and a front-endwp_headrender with
JS...
Stabilization release.
Changelog
All notable changes to SEOistic are documented here. Format loosely follows
Keep a Changelog.
[1.5.1]
Stabilization release. No new marketed features — this fixes surfaces that
reported inaccurate results, did not scale, or claimed capabilities the code
did not have.
Fixed
- SEO score correctness (
src/Core/Scorer.php). Four of the ten checks
could not fail, so the score overstated itself on every page:- The SEO title and meta description passed on being non-empty; the stated
10–60 and 50–160 character targets were shown in the message but never
affected the result. Both now gate on length (filterable via
seoistic/score_title_min|maxandseoistic/score_description_min|max). - The H1 check returned
trueunconditionally, including when no H1
existed. It now fails on duplicate H1s — the state the scorer can actually
prove frompost_content— passes on exactly one, and treats "none in
content" as the theme supplying it unless a site opts into the stricter
rule viaseoistic/score_require_content_h1. - The structured-data check returned
trueunconditionally, including when
schema output was suppressed by another SEO plugin (Core\Compat) or the
post's schema type was set to "none". It now reflects what the page will
actually emit. - "Focus keyword in title" passed when no focus keyword was set, so a page
with no keyword scored a point for having it in the title.
- The SEO title and meta description passed on being non-empty; the stated
- Word counting for non-Latin languages (
src/Core/WordCount.php, new).
str_word_count()is single-byte only and returned 0 for Bengali, Hindi,
Arabic, Greek, Cyrillic and every other non-Latin script, silently failing
the content-length check for entire languages regardless of how much text a
page had. Replaced with a Unicode-aware counter; unspaced scripts (Han,
Kana, Hangul) are counted per character. Unit tested. - Dashboard double-counting (
src/Core/DashboardMetrics.php). The noindex
query matched two meta keys that SEOISTIC deliberately keeps in sync, so a
single noindexed post was counted twice and "Indexable Pages" came out too
low. All postmeta joins now useCOUNT(DISTINCT p.ID), and the average
score is computed one-row-per-post. The metric is also renamed
indexable_pages(the old key remains as an alias) and the card now says
plainly that it counts what robots allow, not what Google has indexed. - Scheduled audit never reached past the first 1,000 posts
(src/Core/ScheduledAudit.php). Each run re-scored the same oldest 1,000
published posts. It now keeps a persistent keyset cursor, continues where
the previous run stopped, and wraps around at the end of the site. - Orphan scan was capped and unbounded at the same time
(src/Core/LinkGraph.php). It loaded the content of the first 5,000
published posts into one synchronous request — wrong results above that cap,
and an expensive admin request below it. Replaced with an incremental,
resumable crawl backed by a new{prefix}seoistic_link_edgestable: each
request indexes a bounded batch from a persisted cursor, and orphans become
a single indexedLEFT JOIN.url_to_postid()results are memoised. Edges
left behind by posts that are no longer published are pruned against the
posts table when a pass completes, so unpublishing or deleting a page makes
the pages it linked to become orphans again. - Redirects were loaded in full on every front-end request
(src/Addon/RedirectsModule.php). Every enabled rule was read from the
database and walked in PHP on each page view. Literal sources now resolve
through a single indexed lookup, and regex rules — the only ones that need
iterating — are cached. Also: invalid regex is rejected at save time instead
of warning on every request, self-referential targets are detected rather
than redirecting forever, and the redirect code is validated before use. - 404 log grew without bound and buried real broken links. Missing assets
and the usual automated probe paths are no longer logged, and the log is
pruned daily to a filterable 30-day retention.
Changed
-
External links are no longer blanket-nofollowed
(src/Addon/LinkManagerModule.php). Every outbound link was marked
nofollow, which contradicts Google's guidance that ordinary editorial
links need no qualification and that the qualifiers exist for specific cases
(sponsoredfor paid/affiliate,ugcfor user-generated). External links
now getnoopeneronly; sites wanting a qualifier opt in explicitly through
theseoistic_external_link_reloption or theseoistic/external_link_rel
filter. Arelan author set by hand is merged into, not overwritten. -
Google Indexing API submissions are gated to eligible pages
(src/Indexistic/IndexingEligibility.php, new). Google supports that API
only for pages carrying JobPosting or BroadcastEvent markup and states that
submitting other page types can cost a project its access. The UI previously
said it "works for other page types in practice" and submitted them anyway.
Ineligible URLs are now skipped and logged with a reason,JobPostingand
BroadcastEventare selectable schema types, and sites that emit the markup
from a template can vouch for a URL viaseoistic/google_indexing_eligible.
Bulk-action counts now report what Google accepted, not what was selected. -
"Check Google status" renamed to "Check notification status." The
Indexing API's metadata endpoint reports when Google last received a
submission for a URL — not whether the page is indexed. The button, the
method (get_notification_status()) and the surrounding copy now say so and
point at Search Console's URL Inspection for real index status. -
Multisite: network activation only ever set up one site
(src/Install/Activator.php,src/Install/Tables.php,src/Plugin.php).
WordPress runs the activation hook once for a network-wide activation, in the
context of whichever site the network admin was on, soTables::create()
created tables for that site's prefix alone. Every other site on the network
was left with no SEOISTIC tables at all, and every front-end page view on
those sites raisedTable 'wp_2_seoistic_redirects' doesn't exist— twice
per request, indefinitely, since the recovery path was admin-only and a
subsite can serve traffic for months before anyone opens its dashboard.
Network activation now sets up each existing site,wp_initialize_site
covers sites added later, and the version check runs on front-end requests
too so any site missed on a very large network repairs itself on first
request (guarded by a short lock so a traffic burst can't stampede
dbDelta). Pre-existing; not introduced in this release. -
Translations were loaded before
init(src/License/License.php,
src/Core/ScheduledAudit.php,src/Uptime/UptimeMonitor.php).
License::register()calledwp_schedule_event()at plugin-load time,
which fires thecron_schedulesfilter, whose callbacks translated their
display labels — and WordPress 6.7+ flags any translation beforeinitas
_doing_it_wrong. Every debug-enabled site on 6.7 or later logged a notice
on each admin request. Scheduling is deferred toinit, and both schedule
labels fall back to untranslated strings if another plugin triggers the
filter early. Found by actually booting the plugin on WordPress 7.0.1. -
The updater checked a private repository (
seoistic.php).
SEOISTIC_GITHUB_REPOdefaulted to the development repository, which is
private — the updater calls the GitHub releases API unauthenticated, so it
received 404 and every install silently never saw an update. It now defaults
to the public distribution repository,wordpressistic/seoistic. Sites that
need a different source can still override the constant inwp-config.php
or filterseoistic_github_repo.
Security
- Custom AI knowledge file is restricted to the media library
(src/AI/KnowledgeBase.php). The setting accepted an absolute filesystem
path or an HTTP URL and read it withfile_get_contents(), then sent the
contents to a third-party AI provider — an arbitrary-file-read and an SSRF
primitive against the host's internal network. It now accepts only a
media-library attachment ID or an uploads-relative path, resolves symlinks
before checking containment, allowlists text extensions, and caps the read.
Added
- Database version 1.3.0 → 1.4.0 for the
link_edgestable. Additive and
idempotent (dbDeltaviaInstall\Tables); uninstall, cron cleanup and the
new options are covered. - Unit tests for the Unicode word counter and Indexing API eligibility
detection (16 new tests; suite is now 47). Tested up to: 7.0.1(was 6.4), from a real test run rather than an
assumption. WordPress 7.0.1 was booted on PHP 8.4 with the plugin active,
exercising the scorer, dashboard metrics, the link-graph crawl and its new
table, the scheduled-audit cursor, redirect matching, indexing eligibility,
the knowledge-base path guards, and a front-endwp_headrender with
JSON-LD output — with no deprecations, warnings or notices from plugin
code.Requires at leaststays 6.4. Multisite, WooCommerce and
MySQL-backed runs remain untested and are not claimed; the verification run
used the SQLite database drop-in, so the custom-table DDL was not exercised
against MySQL/MariaDB.
[1.5.0]
Added
- Domain & Uptime Monitor (
src/Uptime/,src/Addon/UptimeMonitorModule.php,
src/Admin/UptimeMonitorPage.php,assets/js/uptime-monitor.js): a free,
self-contained monitor for site/domain uptime, response time and SSL-expiry.- `UptimeM...
SEOistic v1.5.0 — Smarter WordPress SEO, Clearer Workflows, Greater Control
SEOistic v1.5.0 — Smarter WordPress SEO, Clearer Workflows, Greater Control
Release status: Draft for final package verification
Product: SEOistic by WordPressistic
Release tag:v1.5.0
License: GPL-2.0-or-later
Public GitHub Release Copy
SEOistic v1.5.0 brings technical SEO, content optimization, search-engine indexing, structured data, and privacy-conscious AI assistance into one focused WordPress workflow.
This release is designed for site owners, content teams, WooCommerce stores, developers, and agencies that need practical SEO controls without spreading everyday work across multiple disconnected plugins.
Release Highlights
- A unified SEO command center with site-health scoring, issue prioritization, quick actions, and content-level drill-downs.
- Live on-page SEO analysis with a deterministic 0–100 score and prioritized recommendations.
- Google desktop, Google mobile, and social-sharing previews while editing content.
- Technical SEO controls for metadata, canonical URLs, robots directives, XML sitemaps, breadcrumbs, and
llms.txt. - Schema.org JSON-LD support for site-wide and page-level structured data.
- Redirect management, 404 monitoring, and CSV import/export.
- Indexistic fast-indexing tools for Google Indexing API and IndexNow.
- Content Health tools for identifying orphaned and potentially decaying content.
- AI-assisted SEO suggestions using OpenRouter, Groq, or a self-hosted Ollama endpoint.
- Import tools for Yoast SEO, Rank Math, and AIOSEO metadata.
- Improved licensing reliability, encrypted secret storage, and clearer premium entitlement handling.
What’s Included
SEO Dashboard and Content Workflow
The SEOistic dashboard provides a clearer operational view of site-wide SEO health.
- Review the current SEO health score and scan history.
- See issues grouped by priority and severity.
- Open affected content directly from the optimization roadmap.
- Run site-wide audits in batches to reduce timeout risk on larger websites.
- Filter content by score range, detected issue, focus keyword, and index state.
- Search content or navigate plugin screens through the
Ctrl/Cmd + Kcommand palette.
SEOistic uses real on-page checks for scoring. It does not invent traffic, ranking, or impact estimates.
Live On-Page SEO Analysis
The post-editor SEO workspace provides immediate feedback while content is being prepared.
- SEO title and meta-description controls.
- Focus-keyword analysis and placement checks.
- Heading-structure review.
- Content-length guidance.
- Internal-link checks.
- Image-alt-text checks.
- Open Graph image validation.
- Canonical URL and robots controls.
- Page-level schema selection.
- Breadcrumb-title overrides.
- Prioritized failed checks and a separate passed-checks view.
Unsaved field values can be analyzed without silently publishing or changing the post.
Search and Social Appearance
- Google desktop preview.
- Google mobile preview.
- Social-sharing preview.
- Open Graph title, description, and image controls.
- Live preview refresh while metadata is edited.
These tools make it easier to review how content may appear before it is published or updated.
Technical SEO Foundation
SEOistic includes the technical foundations required by most WordPress websites:
- XML sitemaps.
- Canonical URLs.
- Robots meta directives.
- Editable robots rules.
- Breadcrumbs.
llms.txtsupport.- Organization and WebSite schema.
- Page-level JSON-LD structured data.
- Schema validation against required and recommended properties.
- WooCommerce-aware SEO fields when WooCommerce is active.
- Local-business SEO support.
Redirects and 404 Monitoring
- Create and manage redirects from WordPress.
- Monitor unresolved 404 requests.
- Import and export redirect data using CSV.
- Review redirect activity without editing server files manually.
After updating, test business-critical redirects and checkout/account routes before deploying to production.
Indexistic Fast Indexing
Indexistic helps notify supported search engines when important URLs are published or updated.
- Google Indexing API integration.
- IndexNow support for participating search engines.
- Optional automatic submission when content is published or updated.
- Bulk URL-submission console.
- Submission-history tracking.
- Sitemap-ping tools where supported.
All external indexing connections are opt-in and require the relevant credentials or feature configuration.
Content Health
Content Health helps surface pages that may need editorial attention.
- Orphan-page detection.
- Content-decay flagging.
- Direct links from each finding to the WordPress editor.
- Clear recommendations without automatically rewriting or publishing content.
AI-Assisted SEO
Premium AI tools support bring-your-own-provider workflows:
- OpenRouter.
- Groq.
- Self-hosted Ollama.
Available AI-assisted actions can include:
- Generate or improve SEO titles.
- Generate or improve meta descriptions.
- Suggest focus keywords.
- Recommend a schema type.
- Suggest image alt text.
- Recommend internal links.
- Prepare broader page-optimization suggestions.
AI output is presented as a before-and-after preview. Applying a suggestion requires an explicit user action; SEOistic does not silently write or publish AI-generated content.
SEO Plugin Migration
SEOistic includes metadata importers for:
- Yoast SEO.
- Rank Math.
- All in One SEO.
Before importing on a production website, create a current backup and test the migration on staging. Avoid running two plugins that output the same metadata or schema at the same time.
Licensing and Premium Access
- Simplified license activation workflow.
- Masked license-key display after activation.
- Automatic background revalidation for active licenses.
- Clearer handling of temporary license-server outages.
- Premium access is not immediately removed because of a single timeout or transient network failure.
- Account, subscription, billing, and license management links point to the WPistic account dashboard.
Security and Privacy
- License keys are encrypted at rest.
- Connected API secrets and integration tokens follow protected-storage workflows.
- Admin forms use WordPress nonce and capability checks.
- REST routes require permission callbacks and post-level authorization where applicable.
- Input is sanitized and output is escaped.
- No analytics or visitor-tracking beacon is enabled by default.
- AI, Google, IndexNow, Search Console, licensing, and automation services are contacted only when their related feature is activated or explicitly used.
Free and Premium Capabilities
Free
- On-page SEO analysis and scoring.
- Search and social previews.
- Metadata and canonical controls.
- XML sitemaps.
- Robots controls.
- Breadcrumbs and
llms.txt. - Core structured data.
- Redirects and 404 monitoring.
- Image SEO.
- WooCommerce SEO fields.
- Local SEO fields.
- Indexistic fast-indexing tools.
- Content Health.
- Yoast, Rank Math, and AIOSEO importers.
Premium
- AI-assisted generation with a connected provider.
- Advanced/custom schema builder.
- Core Web Vitals monitoring.
- AI search-visibility and AEO reporting.
- Keyword-rank tracking.
- Read-only Google Search Console reporting.
- WPistic Business Automator integration.
Plan availability may vary. Review the current pricing page for the capabilities included with each license.
Upgrade Guidance
- Create a full database and files backup.
- Test the update on a staging copy first, especially on WooCommerce, membership, multilingual, or heavily cached websites.
- Deactivate any other SEO plugin that outputs overlapping titles, canonical tags, schema, or sitemaps.
- Upload and activate
seoistic-1.5.0.zip. - Clear WordPress, page-cache, object-cache, CDN, and browser caches.
- Open SEOistic → Dashboard and run a fresh site audit.
- Verify the XML sitemap, robots rules, canonical URLs, schema output, redirects, and public metadata.
- Confirm license status and reconnect optional Google, AI, or automation integrations if required.
- Test several representative pages while logged out, including the homepage, a post, a page, an archive, and a WooCommerce product if applicable.
Compatibility and Requirements
- WordPress 6.4 or newer.
- PHP 8.1 or newer.
- MySQL or MariaDB through the standard WordPress database connection.
- Compatible with the Block Editor and Classic Editor.
- WooCommerce-aware but does not require WooCommerce.
- No Composer install or frontend build step is required for the packaged release.
Important Usage Notes
- AI features require a supported provider, credentials, and an eligible license.
- Google Indexing API and Search Console features require separately configured Google credentials.
- IndexNow and other submission tools notify search engines but cannot guarantee crawling, indexing, ranking, or a specific processing time.
- Do not keep two SEO plugins actively generating duplicate metadata, schema, redirects, or sitemaps.
- Review AI suggestions before applying them and verify important factual or regulated content manually.
Download and Verification
Release asset:
seoistic-1.5.0.zip
Recommended companion asset:
seoistic-1.5.0.zip.sha256
After the final package is built, add the verified SHA-256 value here:
SHA-256: [ADD VERIFIED CHECKSUM]
Links
- Repository: https://github.com/Wordpressistic/seoistic
- Product website: https://seoistic.wpistic.com/
- Pricing: https://seoistic.wpistic.com/#pricing
- Account and license management: https://app.wpistic.com/
- WordPressistic: https://wordpressistic.com/
Sugges...
seoistic-1.4.0
Changelog
All notable changes to SEOistic are documented here. Format loosely follows
Keep a Changelog.
[1.4.0]
Added
- Setup wizard (
src/Admin/OnboardingPage.php): a versioned, resumable
first-activation flow — Welcome, Site identity, Search appearance, Import
detection (reusesAddon\MigrationModule::detected_sources()), optional
IndexNow/AI integrations, and Finish (with an opt-in "run a real site
audit" hand-off to the existing dashboard button). Redirects exactly once,
only from a genuine single-site activation (Install\Activatorsets a
short-lived transient; never on network-wide/bulk activation, never on an
upgrade), gated onmanage_optionsand never on AJAX/REST/CLI. Skipped
sites get a dismissible resume notice, not another forced redirect. Every
write is nonce- and capability-checked and sanitized per field, and every
option it writes is the same one the normal Settings screen owns — no
second source of truth. - Duplicate-tag protection (
src/Core/Compat.php): detects active Yoast /
Rank Math / AIOSEO and, in the defaultautomode, suppresses SEOistic's
own output per surface (title, meta, robots.txt, sitemap, schema) so two
SEO plugins don't emit duplicate tags. Configurable in Settings →
Compatibility, with per-surface "force on" overrides; never deactivates the
other plugin. - Self-hosted update checker (
src/Core/Updater.php): hooks
pre_set_site_transient_update_pluginsandplugins_apito offer one-click
updates from the curatedseoistic-{version}.zipGitHub release asset —
never thezipball_urlsource archive. Uses the WordPress HTTP API,
validates the tag/version/asset, caches success and failure, and fails safe
(no asset → treated as "no update"). - Release automation (
.github/workflows/release.yml): builds and
verifies the ZIP viabin/build-release.shon a version tag, attaches the
ZIP + SHA-256 to a draft release with notes from this changelog, and
never publishes. CI (.github/workflows/php.yml) now runs a PHP 8.1/8.2/8.3
matrix withphp -l,node --check, and PHPUnit. - First automated tests:
tests/Unit/PlansTest.phpand
tests/Unit/CompatTest.php(13 tests) with a WordPress-free
tests/bootstrap.php. Module\Entitlement::has_unmapped_product()plus License-screen diagnostics
for an unconfiguredSEOISTIC_LICENSE_PRODUCT_IDand for a valid-but-unmapped
license product, and a License-screen privacy disclosure of the exact
activation payload.
Changed
- WooCommerce Product schema (
src/Addon/WooCommerceModule.php) now emits
image,description, stable@id/url, and (via the
seoistic_woocommerce_product_brandfilter)brand; uses a bounded
AggregateOfferprice range for variable products instead of a single wrong
price; handles grouped/external/backorder correctly; and removes
WooCommerce core's own duplicate Product JSON-LD on product pages. - Pricing model: added the
scaleplan rank; removed the lifetime-deal
cards andPlans::lifetime(); the upgrade screen no longer hardcodes annual
prices (owned by the marketing site); GSC, rank tracking, and AI visibility
are now Pro-eligible; replaced internal marketing copy. - A valid license whose product id isn't mapped to a known plan now resolves
to Free (fail-closed) instead of defaulting to Business. - Editor SEO workspace tabs and the Business Automator page tabs now implement
the full WAI-ARIA tabs pattern (role=tab/tabpanel,aria-selected,
aria-controls, rovingtabindex, arrow/Home/End keyboard navigation). - Breadcrumb shortcode registration now honors the
seoistic_breadcrumbs
option; that option and a compatibility panel are now editable in Settings.
Fixed
- Uninstall (
uninstall.php) now inventories and (only on the documented
seoistic_delete_dataopt-in) removes every plugin option — including the
dynamically-suffixed per-provider AI key options — plus all transients, all
three cron events, all custom tables, and all_seoistic_*post meta, across
both single-site and multisite. Default behavior still preserves customer
data. - Deactivation now also clears the
seoistic_run_automationscron event. - Password-protected posts no longer leak their content/excerpt into the public
meta description or JSON-LD (Core\Meta). - Business Automator's
test-connectionREST endpoint now validates the target
URL scheme/host (blocks non-HTTP(S) and the cloud metadata address) to reduce
SSRF surface; competitor-noindex import uses
unserialize(..., ['allowed_classes' => false]). src/autoload.phpreturns instead ofexit-ing when loaded outside
WordPress, so tooling (Composer, PHPUnit) can require plugin classes.
Migration
- No database schema change (
SEOISTIC_DB_VERSIONunchanged at1.2.0). All
existing options, post meta, encrypted secrets, license state, and REST
contracts are preserved. New options (seoistic_onboarding,
seoistic_compat_mode,seoistic_compat_force_on) are additive with safe
defaults. Rolling back to 1.3.0 leaves those options harmlessly unread.
[1.3.0] — First public release
Added
- Premium application shell: grouped sidebar navigation, a topbar with
breadcrumbs, and a Ctrl/Cmd+K command palette that navigates screens and
searches content by title/score in real time. - Dashboard rebuilt as a command center: an animated SEO health score with a
real "vs. previous scan" delta (tracked scan history), quick actions, and
an optimization roadmap grouped by severity with real per-issue counts
and drill-down links — never invented traffic/impact numbers. - New Content screen: a server-paginated inventory of every post/page
with its score, focus keyword, and index state, filterable by issue and
score band. - Post-editor SEO workspace redesign: a live score header, debounced live
re-analysis of unsaved field values (newPOST /analyzeREST route —
deterministic, versioned, never persists), and a priority-fixes /
passed-checks list that updates as you type. - AI suggestions now render as an explicit before/after preview card with
Apply / Dismiss / Undo, instead of writing directly into a field. GET /analyzeroute's sibling,GET /search, powers the command
palette's content search, permission-filtered per result.Core\Links— a single source of truth for the pricing
(https://seoistic.wpistic.com/#pricing) and account
(https://app.wpistic.com/) URLs, overridable via the
SEOISTIC_PRICING_URL/SEOISTIC_ACCOUNT_URLconstants or the
seoistic_pricing_url/seoistic_account_urlfilters.- A lightweight plan-summary block on the Upgrade screen (current plan,
license status, one primary "View Plans and Pricing" CTA, "Manage
Account" link) above the existing detailed plan-comparison cards. docs/release-audit.md,docs/distribution-model.md,
docs/ui-audit.md,docs/ui-architecture.md,docs/design-system.md,
docs/rest-api-contracts.md,docs/implementation-plan.md,
docs/test-plan.md,docs/migration-notes.md,docs/feature-status.md.bin/build-release.sh— a reproducible, allowlist-based release build
that producesbuild/packages/seoistic-{version}.zipand a matching
.sha256checksum.readme.txt(WordPress.org-format, including a full "External Services"
disclosure) and this changelog.
Changed
- License screen simplified. The inactive form is now exactly two
controls: a license key field and an Activate button. License-server and
product-ID configuration moved from editable settings fields to
deployment constants (SEOISTIC_LICENSE_API_URL,
SEOISTIC_LICENSE_PRODUCT_ID) with filter overrides — never a visible
wp-admin setting. The active state shows a masked key, plan, expiry, and
last-validated time, plus Deactivate and Manage Account actions. - License validation now distinguishes an unreachable server from an
actual revoke/expiry. A transient failure (network error, timeout,
malformed response) backs off with capped exponential delay and never
overwrites the last known-good status; a real rejection from the server
still applies immediately. A confirmed-active license stays trusted for
up to 30 days without a fresh confirmation, so a single outage can't
silently downgrade a paying site to Free. Module\Entitlement's validity check now delegates to
LicenseClient::is_valid()instead of duplicating (and having drifted
out of sync with) its own simpler logic.- Every plan/LTD "Upgrade" and "Get the deal" button now defaults to the
real marketing pricing URL instead of a dead#link (the
seoistic_upgrade_urlfilter is preserved for backward compatibility —
only its default changed). - Sidebar navigation switched from a dark-navy theme to light mode: white
surface, navy/slate text, pale-blue hover/selected states, and a blue
selection indicator. - Plugin header:
Plugin URIupdated,License URIadded,Update URI: falseadded (this plugin is not distributed via WordPress.org), and the
description shortened to an accurate, current summary. - README.md restructured to lead with user-facing setup/usage/privacy
documentation, with the existing architecture notes kept as a
"For developers" section further down.
Fixed
- Button text contrast. A CSS specificity bug made some primary/AI
button text render in the same color family as its own background
(blue-on-blue, purple-on-purple) — root cause was a single overly broad
link-color rule; fixed with a zero-specificity:where()selector so it
can never outrank a component's own color. - Disabled buttons now get a real neutral disabled treatment (backgrou...
SEOistic v1.3.0 — First Public Release
SEOistic v1.3.0 — First Public Release
SEOistic v1.3.0 is the first public release of WordPressistic's modern SEO suite for WordPress. It combines deterministic on-page SEO analysis, structured data, XML sitemaps, redirects, image SEO, content health, fast indexing, and optional AI-assisted optimization in one modular plugin.
This release also introduces a redesigned light-mode admin experience, safer license handling, stronger secret storage, and a GitHub-based update channel.
Release type: First public release
Version: 1.3.0
Recommended tag:v1.3.0
Minimum WordPress: 6.4
Minimum PHP: 8.1
License: GPL-2.0-or-later
Highlights
- A premium light-mode WordPress admin interface with grouped navigation, breadcrumbs, and a global command palette.
- Deterministic 0–100 SEO scoring based on real page-level checks.
- Live post-editor analysis that responds to unsaved SEO field changes.
- A full content inventory with filtering by SEO score, issue, keyword, and index state.
- Search appearance previews for Google desktop, Google mobile, and social sharing.
- Schema, XML sitemaps, robots controls, canonical URLs, breadcrumbs, and
llms.txtsupport. - Redirect management, 404 monitoring, and CSV import/export.
- Indexistic fast indexing through Google Indexing API and IndexNow.
- AI-assisted SEO suggestions with before/after preview, Apply, Dismiss, and Undo controls.
- Encrypted license and integration secrets, resilient license validation, and improved activation security.
New admin experience
SEOistic now behaves like a focused SEO application inside WordPress instead of a collection of disconnected settings pages.
Application shell
- Grouped sidebar navigation for faster access to SEO tools.
- Topbar breadcrumbs to make the current location clear.
Ctrl+Kon Windows/Linux orCmd+Kon macOS opens the global command palette.- The command palette can navigate SEOistic screens and search WordPress content by title or SEO score.
SEO dashboard
- Animated overall site-health score.
- Real comparison with the previous completed scan.
- Quick actions for common SEO workflows.
- Optimization roadmap grouped by severity.
- Real issue counts with drill-down links to affected content.
- No invented traffic estimates or artificial impact numbers.
Content inventory
The new SEOistic → Content screen provides a server-paginated view of posts and pages with:
- SEO score.
- Focus keyword.
- Index state.
- Score-band filtering.
- Issue-type filtering.
- Direct access to the relevant editor.
Post-editor SEO workspace
- Live score header.
- Debounced analysis of unsaved SEO field values.
- Priority fixes and passed checks update while editing.
- Google desktop/mobile and social previews update as metadata changes.
- Analysis remains deterministic and does not silently save or publish content.
Core SEO features
On-page analysis
SEOistic calculates a versioned 0–100 score using checks such as:
- SEO title quality.
- Meta description quality.
- Focus-keyword placement.
- Heading structure.
- Content length.
- Internal linking.
- Image alternative text.
- Open Graph image availability.
Technical SEO
- XML sitemaps.
- Robots controls and
robots.txtsupport. - Canonical URL management.
- Breadcrumbs.
llms.txtsupport.- Organization, WebSite, and per-page JSON-LD schema.
- Schema validation against required and recommended properties.
Redirects and 404 monitoring
- Redirect rule management.
- 404 request monitoring.
- CSV import and export for redirects.
Indexistic fast indexing
- Google Indexing API integration.
- IndexNow support for participating search engines.
- Optional automatic submission when content is published or updated.
- Bulk URL-submission console.
- Submission history for operational visibility.
Content Health
- Orphan-page detection.
- Content-decay flagging.
- Direct links to affected content for manual review.
- No automatic content changes.
Metadata migration
Import existing SEO metadata from:
- Yoast SEO.
- Rank Math.
- All in One SEO.
AI-assisted optimization
Premium AI tools support OpenRouter, Groq, and a self-hosted Ollama endpoint using credentials supplied by the site owner.
AI can assist with:
- SEO titles.
- Meta descriptions.
- Focus keywords.
- Schema selection.
- Image alternative text.
- Internal-link opportunities.
- Full-page optimization suggestions.
Every suggestion is displayed as a before/after preview. Applying a suggestion always requires an explicit user action; SEOistic does not silently write or publish AI-generated content.
Licensing and account experience
The inactive license screen has been simplified to the essentials:
- License-key field.
- Activate License button.
After activation, SEOistic displays the current plan, expiry, last validation time, and a masked license key. The full key is not shown again.
License validation now separates a temporary connection failure from a confirmed expiration or revocation. A transient service outage uses retry backoff and preserves the last known-good status for a bounded period instead of immediately disabling paid features.
WPistic links
- SEOistic product and feature details
- Create a WPistic account
- Log in to WPistic
- View WPistic pricing
Security improvements
- License keys are encrypted at rest.
- Existing plaintext license keys are migrated transparently on first read.
- Business Automator API tokens are encrypted at rest and are no longer returned to settings fields in plaintext.
- License activation is rate-limited to five attempts per ten minutes.
- Every REST route uses an explicit permission callback.
- Post-specific REST operations verify the current user's post-edit capability.
- License-validation cron events are removed when the plugin is deactivated.
Fixes
- Fixed primary and AI button text contrast caused by an overly broad CSS selector.
- Added clear disabled, hover, and pressed states across button variants.
- Fixed spacing around the featured pricing-plan label.
- Fixed missing SEO score-ring styles on WordPress post-list screens.
- Fixed a PHP 8+ fatal error on the Business Automator settings screen caused by an undefined constant.
- Removed calls to Google's retired sitemap-ping endpoint.
- Centralized account and pricing URLs so deployments can override them with documented constants or filters.
- Improved entitlement checks so all premium modules use the same license-validity source.
Free and premium availability
Included without a premium license
- On-page analysis and scoring.
- Search appearance previews.
- Core schema and structured data.
- XML sitemaps, robots controls, canonicals, breadcrumbs, and
llms.txt. - Redirects and 404 monitoring.
- Image SEO.
- WooCommerce SEO fields when WooCommerce is active.
- Local SEO fields.
- Indexistic fast-indexing tools.
- Content Health.
- Yoast SEO, Rank Math, and All in One SEO importers.
Premium license features
- AI-assisted optimization using the site owner's provider credentials.
- Schema Pro custom schema builder.
- Core Web Vitals monitoring.
- AI search visibility and AEO reporting.
- Keyword rank tracking.
- Read-only Google Search Console dashboard.
- WPistic Business Automator integration.
See More SEOistic or WPistic pricing for current availability and plan details.
Privacy and external services
SEOistic does not send analytics or telemetry by default. External connections occur only when the related feature is configured or explicitly used.
- WPistic licensing: license activation, deactivation, and periodic validation after a license is activated.
- Google APIs: only after the site owner configures Google Indexing or Search Console.
- IndexNow/Bing: only when the relevant indexing or sitemap feature is enabled or manually triggered.
- OpenRouter/Groq: only when the site owner configures a provider and starts an AI action.
- Self-hosted Ollama: requests are sent to the endpoint configured by the site owner.
- Business Automator: only after an instance and API token are configured.
Compatibility and requirements
- WordPress 6.4 or newer.
- PHP 8.1 or newer.
- Standard WordPress MySQL/MariaDB database connection.
- Block Editor (Gutenberg).
- Classic Editor.
- WooCommerce-aware, but WooCommerce is not required.
Installation
- Download the installable
seoistic-1.3.0.zipasset attached to this release. - In WordPress, open Plugins → Add New → Upload Plugin.
- Select the ZIP and click Install Now.
- Activate SEOistic.
- Open SEOistic → Dashboard and run the first site audit.
Do not upload the source-code archive generated automatically by GitHub if a dedicated installable plugin ZIP is attached. Use seoistic-1.3.0.zip so WordPress receives the correct plugin directory and release contents.
Upgrade notes
This is the first versioned public release. For sites running a pre-release build:
- Back up the WordPress database and files before updating.
- Existing SEO metadata remains supported through the plugin's compatibility layer.
- Existing plaintext license keys are migrated to encrypted storage automatically.
- No database migration is listed for this release.
- Clear page and object caches after activation if the old admin styling remains visible.
Support and reporting
- SEOistic product site
- [GitHub issues](https://github.com/...