Skip to content

Releases: Wordpressistic/seoistic

SEOistic 1.6.5

Choose a tag to compare

@Shubochandrosarker Shubochandrosarker released this 01 Oct 11:53

Sitemap indexability maintenance release. Expands HTML sitemap coverage to all published viewable content, deduplicates URLs, honors current and legacy noindex directives including noindex,nofollow, preserves existing sitemap query filters, and includes a Windows PowerShell release builder.

SEOistic 1.6.4

Choose a tag to compare

@Shubochandrosarker Shubochandrosarker released this 01 Oct 08:47

Search Console OAuth reliability release: clearer External and Production setup guidance, isolated concurrent OAuth state tokens, refresh-token preservation, granted-scope support, and actionable access-blocked recovery guidance. Google Cloud consent-screen publishing and verification remain required for unrestricted connections.

SEOistic 1.6.3

Choose a tag to compare

@Shubochandrosarker Shubochandrosarker released this 01 Oct 08:19

Fixed the AI Search REST registration fatal that could break the WordPress admin dashboard when Gutenberg preloads REST data. Imports WP_REST_Server correctly inside the namespaced addon. Validated with PHP lint, clean WordPress activation, REST registration, and entitlement smoke tests.

SEOistic 1.6.2

Choose a tag to compare

@Shubochandrosarker Shubochandrosarker released this 01 Oct 07:36

SEOistic 1.6.2 fixes canonical WPistic activation-token integration, safe AI Tools/Search Console error handling, Google OAuth query encoding, and actionable Rank Tracker diagnostics. The ZIP checksum is provided alongside the release asset.

SEOistic 1.5.3 — authoritative licensing

Choose a tag to compare

@Shubochandrosarker Shubochandrosarker released this 07 Sep 13:55
f06ac62

Fixes valid Free licenses incorrectly unlocking Business features. Uses WPistic server-assigned plans, preserves supported legacy aliases and explicit legacy maps, and prevents replacement keys inheriting old paid-plan caches. Existing expiry/revocation and bounded outage handling remain enforced. Before upgrading, check server-assigned customer plans; approved complimentary access belongs in WPistic. Verified: 32 isolated licensing checks, PHP syntax, real WordPress clean install and upgrade from the SHA-verified public 1.5.2 release with SEO metadata/options preserved. Runtime-only ZIP uses the canonical seoistic folder. SHA-256: 97109032dbbdd3655f2d69c47946ac1b290e78a54b6ab1b7b1c06d7790a91a6e. This publication alone does not claim installation on customer sites or registered automatic updates.

Continued WPistic licensing and protected update support.

Choose a tag to compare

@Shubochandrosarker Shubochandrosarker released this 12 Aug 10:59

Changelog

All notable changes to SEOistic are documented here. Format loosely follows
Keep a Changelog.

[1.5.2] - 2026-08-12

Added

  • WPistic-backed licensing integration and protected update support.
  • WPistic activation/validation adapter and entitlement compatibility layer.
  • scripts/build-release.sh — deterministic release packaging.

Release

  • Bump version to 1.5.2 and prepare production release.

Changed

  • Unified licensing architecture to use WPistic platform by default.
  • Removed legacy GitHub Releases-based updater for licensed installations.

Security

  • Default license API endpoint now points to https://api.wpistic.com.

Release Notes

[1.5.1]

Stabilisation release. No new marketed features — this fixes surfaces that
reported inaccurate results, did not scale, or claimed capabilities the code
did not have.

Fixed

  • SEO score correctness (src/Core/Scorer.php). Four of the ten checks
    could not fail, so the score overstated itself on every page:
    • The SEO title and meta description passed on being non-empty; the stated
      10–60 and 50–160 character targets were shown in the message but never
      affected the result. Both now gate on length (filterable via
      seoistic/score_title_min|max and seoistic/score_description_min|max).
    • The H1 check returned true unconditionally, including when no H1
      existed. It now fails on duplicate H1s — the state the scorer can actually
      prove from post_content — passes on exactly one, and treats "none in
      content" as the theme supplying it unless a site opts into the stricter
      rule via seoistic/score_require_content_h1.
    • The structured-data check returned true unconditionally, including when
      schema output was suppressed by another SEO plugin (Core\Compat) or the
      post's schema type was set to "none". It now reflects what the page will
      actually emit.
    • "Focus keyword in title" passed when no focus keyword was set, so a page
      with no keyword scored a point for having it in the title.
  • Word counting for non-Latin languages (src/Core/WordCount.php, new).
    str_word_count() is single-byte only and returned 0 for Bengali, Hindi,
    Arabic, Greek, Cyrillic and every other non-Latin script, silently failing
    the content-length check for entire languages regardless of how much text a
    page had. Replaced with a Unicode-aware counter; unspaced scripts (Han,
    Kana, Hangul) are counted per character. Unit tested.
  • Dashboard double-counting (src/Core/DashboardMetrics.php). The noindex
    query matched two meta keys that SEOISTIC deliberately keeps in sync, so a
    single noindexed post was counted twice and "Indexable Pages" came out too
    low. All postmeta joins now use COUNT(DISTINCT p.ID), and the average
    score is computed one-row-per-post. The metric is also renamed
    indexable_pages (the old key remains as an alias) and the card now says
    plainly that it counts what robots allow, not what Google has indexed.
  • Scheduled audit never reached past the first 1,000 posts
    (src/Core/ScheduledAudit.php). Each run re-scored the same oldest 1,000
    published posts. It now keeps a persistent keyset cursor, continues where
    the previous run stopped, and wraps around at the end of the site.
  • Orphan scan was capped and unbounded at the same time
    (src/Core/LinkGraph.php). It loaded the content of the first 5,000
    published posts into one synchronous request — wrong results above that cap,
    and an expensive admin request below it. Replaced with an incremental,
    resumable crawl backed by a new {prefix}seoistic_link_edges table: each
    request indexes a bounded batch from a persisted cursor, and orphans become
    a single indexed LEFT JOIN. url_to_postid() results are memoised. Edges
    left behind by posts that are no longer published are pruned against the
    posts table when a pass completes, so unpublishing or deleting a page makes
    the pages it linked to become orphans again.
  • Redirects were loaded in full on every front-end request
    (src/Addon/RedirectsModule.php). Every enabled rule was read from the
    database and walked in PHP on each page view. Literal sources now resolve
    through a single indexed lookup, and regex rules — the only ones that need
    iterating — are cached. Also: invalid regex is rejected at save time instead
    of warning on every request, self-referential targets are detected rather
    than redirecting forever, and the redirect code is validated before use.
  • 404 log grew without bound and buried real broken links. Missing assets
    and the usual automated probe paths are no longer logged, and the log is
    pruned daily to a filterable 30-day retention.

Changed

  • External links are no longer blanket-nofollowed
    (src/Addon/LinkManagerModule.php). Every outbound link was marked
    nofollow, which contradicts Google's guidance that ordinary editorial
    links need no qualification and that the qualifiers exist for specific cases
    (sponsored for paid/affiliate, ugc for user-generated). External links
    now get noopener only; sites wanting a qualifier opt in explicitly through
    the seoistic_external_link_rel option or the seoistic/external_link_rel
    filter. A rel an author set by hand is merged into, not overwritten.

  • Google Indexing API submissions are gated to eligible pages
    (src/Indexistic/IndexingEligibility.php, new). Google supports that API
    only for pages carrying JobPosting or BroadcastEvent markup and states that
    submitting other page types can cost a project its access. The UI previously
    said it "works for other page types in practice" and submitted them anyway.
    Ineligible URLs are now skipped and logged with a reason, JobPosting and
    BroadcastEvent are selectable schema types, and sites that emit the markup
    from a template can vouch for a URL via seoistic/google_indexing_eligible.
    Bulk-action counts now report what Google accepted, not what was selected.

  • "Check Google status" renamed to "Check notification status." The
    Indexing API's metadata endpoint reports when Google last received a
    submission for a URL — not whether the page is indexed. The button, the
    method (get_notification_status()) and the surrounding copy now say so and
    point at Search Console's URL Inspection for real index status.

  • Multisite: network activation only ever set up one site
    (src/Install/Activator.php, src/Install/Tables.php, src/Plugin.php).
    WordPress runs the activation hook once for a network-wide activation, in the
    context of whichever site the network admin was on, so Tables::create()
    created tables for that site's prefix alone. Every other site on the network
    was left with no SEOISTIC tables at all, and every front-end page view on
    those sites raised Table 'wp_2_seoistic_redirects' doesn't exist — twice
    per request, indefinitely, since the recovery path was admin-only and a
    subsite can serve traffic for months before anyone opens its dashboard.
    Network activation now sets up each existing site, wp_initialize_site
    covers sites added later, and the version check runs on front-end requests
    too so any site missed on a very large network repairs itself on first
    request (guarded by a short lock so a traffic burst can't stampede
    dbDelta). Pre-existing; not introduced in this release.

  • Translations were loaded before init (src/License/License.php,
    src/Core/ScheduledAudit.php, src/Uptime/UptimeMonitor.php).
    License::register() called wp_schedule_event() at plugin-load time,
    which fires the cron_schedules filter, whose callbacks translated their
    display labels — and WordPress 6.7+ flags any translation before init as
    _doing_it_wrong. Every debug-enabled site on 6.7 or later logged a notice
    on each admin request. Scheduling is deferred to init, and both schedule
    labels fall back to untranslated strings if another plugin triggers the
    filter early. Found by actually booting the plugin on WordPress 7.0.1.

  • The updater checked a private repository (seoistic.php).
    SEOISTIC_GITHUB_REPO defaulted to the development repository, which is
    private — the updater calls the GitHub releases API unauthenticated, so it
    received 404 and every install silently never saw an update. It now defaults
    to the public distribution repository, wordpressistic/seoistic. Sites that
    need a different source can still override the constant in wp-config.php
    or filter seoistic_github_repo.

Security

  • Custom AI knowledge file is restricted to the media library
    (src/AI/KnowledgeBase.php). The setting accepted an absolute filesystem
    path or an HTTP URL and read it with file_get_contents(), then sent the
    contents to a third-party AI provider — an arbitrary-file-read and an SSRF
    primitive against the host's internal network. It now accepts only a
    media-library attachment ID or an uploads-relative path, resolves symlinks
    before checking containment, allowlists text extensions, and caps the read.

Added

  • Database version 1.3.0 → 1.4.0 for the link_edges table. Additive and
    idempotent (dbDelta via Install\Tables); uninstall, cron cleanup and the
    new options are covered.
  • Unit tests for the Unicode word counter and Indexing API eligibility
    detection (16 new tests; suite is now 47).
  • Tested up to: 7.0.1 (was 6.4), from a real test run rather than an
    assumption. WordPress 7.0.1 was booted on PHP 8.4 with the plugin active,
    exercising the scorer, dashboard metrics, the link-graph crawl and its new
    table, the scheduled-audit cursor, redirect matching, indexing eligibility,
    the knowledge-base path guards, and a front-end wp_head render with
    JS...
Read more

Stabilization release.

Choose a tag to compare

@Shubochandrosarker Shubochandrosarker released this 08 Aug 10:32
3298c14

Changelog

All notable changes to SEOistic are documented here. Format loosely follows
Keep a Changelog.

[1.5.1]

Stabilization release. No new marketed features — this fixes surfaces that
reported inaccurate results, did not scale, or claimed capabilities the code
did not have.

Fixed

  • SEO score correctness (src/Core/Scorer.php). Four of the ten checks
    could not fail, so the score overstated itself on every page:
    • The SEO title and meta description passed on being non-empty; the stated
      10–60 and 50–160 character targets were shown in the message but never
      affected the result. Both now gate on length (filterable via
      seoistic/score_title_min|max and seoistic/score_description_min|max).
    • The H1 check returned true unconditionally, including when no H1
      existed. It now fails on duplicate H1s — the state the scorer can actually
      prove from post_content — passes on exactly one, and treats "none in
      content" as the theme supplying it unless a site opts into the stricter
      rule via seoistic/score_require_content_h1.
    • The structured-data check returned true unconditionally, including when
      schema output was suppressed by another SEO plugin (Core\Compat) or the
      post's schema type was set to "none". It now reflects what the page will
      actually emit.
    • "Focus keyword in title" passed when no focus keyword was set, so a page
      with no keyword scored a point for having it in the title.
  • Word counting for non-Latin languages (src/Core/WordCount.php, new).
    str_word_count() is single-byte only and returned 0 for Bengali, Hindi,
    Arabic, Greek, Cyrillic and every other non-Latin script, silently failing
    the content-length check for entire languages regardless of how much text a
    page had. Replaced with a Unicode-aware counter; unspaced scripts (Han,
    Kana, Hangul) are counted per character. Unit tested.
  • Dashboard double-counting (src/Core/DashboardMetrics.php). The noindex
    query matched two meta keys that SEOISTIC deliberately keeps in sync, so a
    single noindexed post was counted twice and "Indexable Pages" came out too
    low. All postmeta joins now use COUNT(DISTINCT p.ID), and the average
    score is computed one-row-per-post. The metric is also renamed
    indexable_pages (the old key remains as an alias) and the card now says
    plainly that it counts what robots allow, not what Google has indexed.
  • Scheduled audit never reached past the first 1,000 posts
    (src/Core/ScheduledAudit.php). Each run re-scored the same oldest 1,000
    published posts. It now keeps a persistent keyset cursor, continues where
    the previous run stopped, and wraps around at the end of the site.
  • Orphan scan was capped and unbounded at the same time
    (src/Core/LinkGraph.php). It loaded the content of the first 5,000
    published posts into one synchronous request — wrong results above that cap,
    and an expensive admin request below it. Replaced with an incremental,
    resumable crawl backed by a new {prefix}seoistic_link_edges table: each
    request indexes a bounded batch from a persisted cursor, and orphans become
    a single indexed LEFT JOIN. url_to_postid() results are memoised. Edges
    left behind by posts that are no longer published are pruned against the
    posts table when a pass completes, so unpublishing or deleting a page makes
    the pages it linked to become orphans again.
  • Redirects were loaded in full on every front-end request
    (src/Addon/RedirectsModule.php). Every enabled rule was read from the
    database and walked in PHP on each page view. Literal sources now resolve
    through a single indexed lookup, and regex rules — the only ones that need
    iterating — are cached. Also: invalid regex is rejected at save time instead
    of warning on every request, self-referential targets are detected rather
    than redirecting forever, and the redirect code is validated before use.
  • 404 log grew without bound and buried real broken links. Missing assets
    and the usual automated probe paths are no longer logged, and the log is
    pruned daily to a filterable 30-day retention.

Changed

  • External links are no longer blanket-nofollowed
    (src/Addon/LinkManagerModule.php). Every outbound link was marked
    nofollow, which contradicts Google's guidance that ordinary editorial
    links need no qualification and that the qualifiers exist for specific cases
    (sponsored for paid/affiliate, ugc for user-generated). External links
    now get noopener only; sites wanting a qualifier opt in explicitly through
    the seoistic_external_link_rel option or the seoistic/external_link_rel
    filter. A rel an author set by hand is merged into, not overwritten.

  • Google Indexing API submissions are gated to eligible pages
    (src/Indexistic/IndexingEligibility.php, new). Google supports that API
    only for pages carrying JobPosting or BroadcastEvent markup and states that
    submitting other page types can cost a project its access. The UI previously
    said it "works for other page types in practice" and submitted them anyway.
    Ineligible URLs are now skipped and logged with a reason, JobPosting and
    BroadcastEvent are selectable schema types, and sites that emit the markup
    from a template can vouch for a URL via seoistic/google_indexing_eligible.
    Bulk-action counts now report what Google accepted, not what was selected.

  • "Check Google status" renamed to "Check notification status." The
    Indexing API's metadata endpoint reports when Google last received a
    submission for a URL — not whether the page is indexed. The button, the
    method (get_notification_status()) and the surrounding copy now say so and
    point at Search Console's URL Inspection for real index status.

  • Multisite: network activation only ever set up one site
    (src/Install/Activator.php, src/Install/Tables.php, src/Plugin.php).
    WordPress runs the activation hook once for a network-wide activation, in the
    context of whichever site the network admin was on, so Tables::create()
    created tables for that site's prefix alone. Every other site on the network
    was left with no SEOISTIC tables at all, and every front-end page view on
    those sites raised Table 'wp_2_seoistic_redirects' doesn't exist — twice
    per request, indefinitely, since the recovery path was admin-only and a
    subsite can serve traffic for months before anyone opens its dashboard.
    Network activation now sets up each existing site, wp_initialize_site
    covers sites added later, and the version check runs on front-end requests
    too so any site missed on a very large network repairs itself on first
    request (guarded by a short lock so a traffic burst can't stampede
    dbDelta). Pre-existing; not introduced in this release.

  • Translations were loaded before init (src/License/License.php,
    src/Core/ScheduledAudit.php, src/Uptime/UptimeMonitor.php).
    License::register() called wp_schedule_event() at plugin-load time,
    which fires the cron_schedules filter, whose callbacks translated their
    display labels — and WordPress 6.7+ flags any translation before init as
    _doing_it_wrong. Every debug-enabled site on 6.7 or later logged a notice
    on each admin request. Scheduling is deferred to init, and both schedule
    labels fall back to untranslated strings if another plugin triggers the
    filter early. Found by actually booting the plugin on WordPress 7.0.1.

  • The updater checked a private repository (seoistic.php).
    SEOISTIC_GITHUB_REPO defaulted to the development repository, which is
    private — the updater calls the GitHub releases API unauthenticated, so it
    received 404 and every install silently never saw an update. It now defaults
    to the public distribution repository, wordpressistic/seoistic. Sites that
    need a different source can still override the constant in wp-config.php
    or filter seoistic_github_repo.

Security

  • Custom AI knowledge file is restricted to the media library
    (src/AI/KnowledgeBase.php). The setting accepted an absolute filesystem
    path or an HTTP URL and read it with file_get_contents(), then sent the
    contents to a third-party AI provider — an arbitrary-file-read and an SSRF
    primitive against the host's internal network. It now accepts only a
    media-library attachment ID or an uploads-relative path, resolves symlinks
    before checking containment, allowlists text extensions, and caps the read.

Added

  • Database version 1.3.0 → 1.4.0 for the link_edges table. Additive and
    idempotent (dbDelta via Install\Tables); uninstall, cron cleanup and the
    new options are covered.
  • Unit tests for the Unicode word counter and Indexing API eligibility
    detection (16 new tests; suite is now 47).
  • Tested up to: 7.0.1 (was 6.4), from a real test run rather than an
    assumption. WordPress 7.0.1 was booted on PHP 8.4 with the plugin active,
    exercising the scorer, dashboard metrics, the link-graph crawl and its new
    table, the scheduled-audit cursor, redirect matching, indexing eligibility,
    the knowledge-base path guards, and a front-end wp_head render with
    JSON-LD output — with no deprecations, warnings or notices from plugin
    code. Requires at least stays 6.4. Multisite, WooCommerce and
    MySQL-backed runs remain untested and are not claimed; the verification run
    used the SQLite database drop-in, so the custom-table DDL was not exercised
    against MySQL/MariaDB.

[1.5.0]

Added

  • Domain & Uptime Monitor (src/Uptime/, src/Addon/UptimeMonitorModule.php,
    src/Admin/UptimeMonitorPage.php, assets/js/uptime-monitor.js): a free,
    self-contained monitor for site/domain uptime, response time and SSL-expiry.
    • `UptimeM...
Read more

SEOistic v1.5.0 — Smarter WordPress SEO, Clearer Workflows, Greater Control

Choose a tag to compare

@Shubochandrosarker Shubochandrosarker released this 24 Jul 19:20
3298c14

SEOistic v1.5.0 — Smarter WordPress SEO, Clearer Workflows, Greater Control

Release status: Draft for final package verification
Product: SEOistic by WordPressistic
Release tag: v1.5.0
License: GPL-2.0-or-later

Public GitHub Release Copy

SEOistic v1.5.0 brings technical SEO, content optimization, search-engine indexing, structured data, and privacy-conscious AI assistance into one focused WordPress workflow.

This release is designed for site owners, content teams, WooCommerce stores, developers, and agencies that need practical SEO controls without spreading everyday work across multiple disconnected plugins.

Release Highlights

  • A unified SEO command center with site-health scoring, issue prioritization, quick actions, and content-level drill-downs.
  • Live on-page SEO analysis with a deterministic 0–100 score and prioritized recommendations.
  • Google desktop, Google mobile, and social-sharing previews while editing content.
  • Technical SEO controls for metadata, canonical URLs, robots directives, XML sitemaps, breadcrumbs, and llms.txt.
  • Schema.org JSON-LD support for site-wide and page-level structured data.
  • Redirect management, 404 monitoring, and CSV import/export.
  • Indexistic fast-indexing tools for Google Indexing API and IndexNow.
  • Content Health tools for identifying orphaned and potentially decaying content.
  • AI-assisted SEO suggestions using OpenRouter, Groq, or a self-hosted Ollama endpoint.
  • Import tools for Yoast SEO, Rank Math, and AIOSEO metadata.
  • Improved licensing reliability, encrypted secret storage, and clearer premium entitlement handling.

What’s Included

SEO Dashboard and Content Workflow

The SEOistic dashboard provides a clearer operational view of site-wide SEO health.

  • Review the current SEO health score and scan history.
  • See issues grouped by priority and severity.
  • Open affected content directly from the optimization roadmap.
  • Run site-wide audits in batches to reduce timeout risk on larger websites.
  • Filter content by score range, detected issue, focus keyword, and index state.
  • Search content or navigate plugin screens through the Ctrl/Cmd + K command palette.

SEOistic uses real on-page checks for scoring. It does not invent traffic, ranking, or impact estimates.

Live On-Page SEO Analysis

The post-editor SEO workspace provides immediate feedback while content is being prepared.

  • SEO title and meta-description controls.
  • Focus-keyword analysis and placement checks.
  • Heading-structure review.
  • Content-length guidance.
  • Internal-link checks.
  • Image-alt-text checks.
  • Open Graph image validation.
  • Canonical URL and robots controls.
  • Page-level schema selection.
  • Breadcrumb-title overrides.
  • Prioritized failed checks and a separate passed-checks view.

Unsaved field values can be analyzed without silently publishing or changing the post.

Search and Social Appearance

  • Google desktop preview.
  • Google mobile preview.
  • Social-sharing preview.
  • Open Graph title, description, and image controls.
  • Live preview refresh while metadata is edited.

These tools make it easier to review how content may appear before it is published or updated.

Technical SEO Foundation

SEOistic includes the technical foundations required by most WordPress websites:

  • XML sitemaps.
  • Canonical URLs.
  • Robots meta directives.
  • Editable robots rules.
  • Breadcrumbs.
  • llms.txt support.
  • Organization and WebSite schema.
  • Page-level JSON-LD structured data.
  • Schema validation against required and recommended properties.
  • WooCommerce-aware SEO fields when WooCommerce is active.
  • Local-business SEO support.

Redirects and 404 Monitoring

  • Create and manage redirects from WordPress.
  • Monitor unresolved 404 requests.
  • Import and export redirect data using CSV.
  • Review redirect activity without editing server files manually.

After updating, test business-critical redirects and checkout/account routes before deploying to production.

Indexistic Fast Indexing

Indexistic helps notify supported search engines when important URLs are published or updated.

  • Google Indexing API integration.
  • IndexNow support for participating search engines.
  • Optional automatic submission when content is published or updated.
  • Bulk URL-submission console.
  • Submission-history tracking.
  • Sitemap-ping tools where supported.

All external indexing connections are opt-in and require the relevant credentials or feature configuration.

Content Health

Content Health helps surface pages that may need editorial attention.

  • Orphan-page detection.
  • Content-decay flagging.
  • Direct links from each finding to the WordPress editor.
  • Clear recommendations without automatically rewriting or publishing content.

AI-Assisted SEO

Premium AI tools support bring-your-own-provider workflows:

  • OpenRouter.
  • Groq.
  • Self-hosted Ollama.

Available AI-assisted actions can include:

  • Generate or improve SEO titles.
  • Generate or improve meta descriptions.
  • Suggest focus keywords.
  • Recommend a schema type.
  • Suggest image alt text.
  • Recommend internal links.
  • Prepare broader page-optimization suggestions.

AI output is presented as a before-and-after preview. Applying a suggestion requires an explicit user action; SEOistic does not silently write or publish AI-generated content.

SEO Plugin Migration

SEOistic includes metadata importers for:

  • Yoast SEO.
  • Rank Math.
  • All in One SEO.

Before importing on a production website, create a current backup and test the migration on staging. Avoid running two plugins that output the same metadata or schema at the same time.

Licensing and Premium Access

  • Simplified license activation workflow.
  • Masked license-key display after activation.
  • Automatic background revalidation for active licenses.
  • Clearer handling of temporary license-server outages.
  • Premium access is not immediately removed because of a single timeout or transient network failure.
  • Account, subscription, billing, and license management links point to the WPistic account dashboard.

Security and Privacy

  • License keys are encrypted at rest.
  • Connected API secrets and integration tokens follow protected-storage workflows.
  • Admin forms use WordPress nonce and capability checks.
  • REST routes require permission callbacks and post-level authorization where applicable.
  • Input is sanitized and output is escaped.
  • No analytics or visitor-tracking beacon is enabled by default.
  • AI, Google, IndexNow, Search Console, licensing, and automation services are contacted only when their related feature is activated or explicitly used.

Free and Premium Capabilities

Free

  • On-page SEO analysis and scoring.
  • Search and social previews.
  • Metadata and canonical controls.
  • XML sitemaps.
  • Robots controls.
  • Breadcrumbs and llms.txt.
  • Core structured data.
  • Redirects and 404 monitoring.
  • Image SEO.
  • WooCommerce SEO fields.
  • Local SEO fields.
  • Indexistic fast-indexing tools.
  • Content Health.
  • Yoast, Rank Math, and AIOSEO importers.

Premium

  • AI-assisted generation with a connected provider.
  • Advanced/custom schema builder.
  • Core Web Vitals monitoring.
  • AI search-visibility and AEO reporting.
  • Keyword-rank tracking.
  • Read-only Google Search Console reporting.
  • WPistic Business Automator integration.

Plan availability may vary. Review the current pricing page for the capabilities included with each license.

Upgrade Guidance

  1. Create a full database and files backup.
  2. Test the update on a staging copy first, especially on WooCommerce, membership, multilingual, or heavily cached websites.
  3. Deactivate any other SEO plugin that outputs overlapping titles, canonical tags, schema, or sitemaps.
  4. Upload and activate seoistic-1.5.0.zip.
  5. Clear WordPress, page-cache, object-cache, CDN, and browser caches.
  6. Open SEOistic → Dashboard and run a fresh site audit.
  7. Verify the XML sitemap, robots rules, canonical URLs, schema output, redirects, and public metadata.
  8. Confirm license status and reconnect optional Google, AI, or automation integrations if required.
  9. Test several representative pages while logged out, including the homepage, a post, a page, an archive, and a WooCommerce product if applicable.

Compatibility and Requirements

  • WordPress 6.4 or newer.
  • PHP 8.1 or newer.
  • MySQL or MariaDB through the standard WordPress database connection.
  • Compatible with the Block Editor and Classic Editor.
  • WooCommerce-aware but does not require WooCommerce.
  • No Composer install or frontend build step is required for the packaged release.

Important Usage Notes

  • AI features require a supported provider, credentials, and an eligible license.
  • Google Indexing API and Search Console features require separately configured Google credentials.
  • IndexNow and other submission tools notify search engines but cannot guarantee crawling, indexing, ranking, or a specific processing time.
  • Do not keep two SEO plugins actively generating duplicate metadata, schema, redirects, or sitemaps.
  • Review AI suggestions before applying them and verify important factual or regulated content manually.

Download and Verification

Release asset:

  • seoistic-1.5.0.zip

Recommended companion asset:

  • seoistic-1.5.0.zip.sha256

After the final package is built, add the verified SHA-256 value here:

SHA-256: [ADD VERIFIED CHECKSUM]

Links

Sugges...

Read more

seoistic-1.4.0

Choose a tag to compare

@Shubochandrosarker Shubochandrosarker released this 20 Jul 15:29
3298c14

Changelog

All notable changes to SEOistic are documented here. Format loosely follows
Keep a Changelog.

[1.4.0]

Added

  • Setup wizard (src/Admin/OnboardingPage.php): a versioned, resumable
    first-activation flow — Welcome, Site identity, Search appearance, Import
    detection (reuses Addon\MigrationModule::detected_sources()), optional
    IndexNow/AI integrations, and Finish (with an opt-in "run a real site
    audit" hand-off to the existing dashboard button). Redirects exactly once,
    only from a genuine single-site activation (Install\Activator sets a
    short-lived transient; never on network-wide/bulk activation, never on an
    upgrade), gated on manage_options and never on AJAX/REST/CLI. Skipped
    sites get a dismissible resume notice, not another forced redirect. Every
    write is nonce- and capability-checked and sanitized per field, and every
    option it writes is the same one the normal Settings screen owns — no
    second source of truth.
  • Duplicate-tag protection (src/Core/Compat.php): detects active Yoast /
    Rank Math / AIOSEO and, in the default auto mode, suppresses SEOistic's
    own output per surface (title, meta, robots.txt, sitemap, schema) so two
    SEO plugins don't emit duplicate tags. Configurable in Settings →
    Compatibility, with per-surface "force on" overrides; never deactivates the
    other plugin.
  • Self-hosted update checker (src/Core/Updater.php): hooks
    pre_set_site_transient_update_plugins and plugins_api to offer one-click
    updates from the curated seoistic-{version}.zip GitHub release asset —
    never the zipball_url source archive. Uses the WordPress HTTP API,
    validates the tag/version/asset, caches success and failure, and fails safe
    (no asset → treated as "no update").
  • Release automation (.github/workflows/release.yml): builds and
    verifies the ZIP via bin/build-release.sh on a version tag, attaches the
    ZIP + SHA-256 to a draft release with notes from this changelog, and
    never publishes. CI (.github/workflows/php.yml) now runs a PHP 8.1/8.2/8.3
    matrix with php -l, node --check, and PHPUnit.
  • First automated tests: tests/Unit/PlansTest.php and
    tests/Unit/CompatTest.php (13 tests) with a WordPress-free
    tests/bootstrap.php.
  • Module\Entitlement::has_unmapped_product() plus License-screen diagnostics
    for an unconfigured SEOISTIC_LICENSE_PRODUCT_ID and for a valid-but-unmapped
    license product, and a License-screen privacy disclosure of the exact
    activation payload.

Changed

  • WooCommerce Product schema (src/Addon/WooCommerceModule.php) now emits
    image, description, stable @id/url, and (via the
    seoistic_woocommerce_product_brand filter) brand; uses a bounded
    AggregateOffer price range for variable products instead of a single wrong
    price; handles grouped/external/backorder correctly; and removes
    WooCommerce core's own duplicate Product JSON-LD on product pages.
  • Pricing model: added the scale plan rank; removed the lifetime-deal
    cards and Plans::lifetime(); the upgrade screen no longer hardcodes annual
    prices (owned by the marketing site); GSC, rank tracking, and AI visibility
    are now Pro-eligible; replaced internal marketing copy.
  • A valid license whose product id isn't mapped to a known plan now resolves
    to Free (fail-closed) instead of defaulting to Business.
  • Editor SEO workspace tabs and the Business Automator page tabs now implement
    the full WAI-ARIA tabs pattern (role=tab/tabpanel, aria-selected,
    aria-controls, roving tabindex, arrow/Home/End keyboard navigation).
  • Breadcrumb shortcode registration now honors the seoistic_breadcrumbs
    option; that option and a compatibility panel are now editable in Settings.

Fixed

  • Uninstall (uninstall.php) now inventories and (only on the documented
    seoistic_delete_data opt-in) removes every plugin option — including the
    dynamically-suffixed per-provider AI key options — plus all transients, all
    three cron events, all custom tables, and all _seoistic_* post meta, across
    both single-site and multisite. Default behavior still preserves customer
    data.
  • Deactivation now also clears the seoistic_run_automations cron event.
  • Password-protected posts no longer leak their content/excerpt into the public
    meta description or JSON-LD (Core\Meta).
  • Business Automator's test-connection REST endpoint now validates the target
    URL scheme/host (blocks non-HTTP(S) and the cloud metadata address) to reduce
    SSRF surface; competitor-noindex import uses
    unserialize(..., ['allowed_classes' => false]).
  • src/autoload.php returns instead of exit-ing when loaded outside
    WordPress, so tooling (Composer, PHPUnit) can require plugin classes.

Migration

  • No database schema change (SEOISTIC_DB_VERSION unchanged at 1.2.0). All
    existing options, post meta, encrypted secrets, license state, and REST
    contracts are preserved. New options (seoistic_onboarding,
    seoistic_compat_mode, seoistic_compat_force_on) are additive with safe
    defaults. Rolling back to 1.3.0 leaves those options harmlessly unread.

[1.3.0] — First public release

Added

  • Premium application shell: grouped sidebar navigation, a topbar with
    breadcrumbs, and a Ctrl/Cmd+K command palette that navigates screens and
    searches content by title/score in real time.
  • Dashboard rebuilt as a command center: an animated SEO health score with a
    real "vs. previous scan" delta (tracked scan history), quick actions, and
    an optimization roadmap grouped by severity with real per-issue counts
    and drill-down links — never invented traffic/impact numbers.
  • New Content screen: a server-paginated inventory of every post/page
    with its score, focus keyword, and index state, filterable by issue and
    score band.
  • Post-editor SEO workspace redesign: a live score header, debounced live
    re-analysis of unsaved field values (new POST /analyze REST route —
    deterministic, versioned, never persists), and a priority-fixes /
    passed-checks list that updates as you type.
  • AI suggestions now render as an explicit before/after preview card with
    Apply / Dismiss / Undo, instead of writing directly into a field.
  • GET /analyze route's sibling, GET /search, powers the command
    palette's content search, permission-filtered per result.
  • Core\Links — a single source of truth for the pricing
    (https://seoistic.wpistic.com/#pricing) and account
    (https://app.wpistic.com/) URLs, overridable via the
    SEOISTIC_PRICING_URL / SEOISTIC_ACCOUNT_URL constants or the
    seoistic_pricing_url / seoistic_account_url filters.
  • A lightweight plan-summary block on the Upgrade screen (current plan,
    license status, one primary "View Plans and Pricing" CTA, "Manage
    Account" link) above the existing detailed plan-comparison cards.
  • docs/release-audit.md, docs/distribution-model.md,
    docs/ui-audit.md, docs/ui-architecture.md, docs/design-system.md,
    docs/rest-api-contracts.md, docs/implementation-plan.md,
    docs/test-plan.md, docs/migration-notes.md, docs/feature-status.md.
  • bin/build-release.sh — a reproducible, allowlist-based release build
    that produces build/packages/seoistic-{version}.zip and a matching
    .sha256 checksum.
  • readme.txt (WordPress.org-format, including a full "External Services"
    disclosure) and this changelog.

Changed

  • License screen simplified. The inactive form is now exactly two
    controls: a license key field and an Activate button. License-server and
    product-ID configuration moved from editable settings fields to
    deployment constants (SEOISTIC_LICENSE_API_URL,
    SEOISTIC_LICENSE_PRODUCT_ID) with filter overrides — never a visible
    wp-admin setting. The active state shows a masked key, plan, expiry, and
    last-validated time, plus Deactivate and Manage Account actions.
  • License validation now distinguishes an unreachable server from an
    actual revoke/expiry.
    A transient failure (network error, timeout,
    malformed response) backs off with capped exponential delay and never
    overwrites the last known-good status; a real rejection from the server
    still applies immediately. A confirmed-active license stays trusted for
    up to 30 days without a fresh confirmation, so a single outage can't
    silently downgrade a paying site to Free.
  • Module\Entitlement's validity check now delegates to
    LicenseClient::is_valid() instead of duplicating (and having drifted
    out of sync with) its own simpler logic.
  • Every plan/LTD "Upgrade" and "Get the deal" button now defaults to the
    real marketing pricing URL instead of a dead # link (the
    seoistic_upgrade_url filter is preserved for backward compatibility —
    only its default changed).
  • Sidebar navigation switched from a dark-navy theme to light mode: white
    surface, navy/slate text, pale-blue hover/selected states, and a blue
    selection indicator.
  • Plugin header: Plugin URI updated, License URI added, Update URI: false added (this plugin is not distributed via WordPress.org), and the
    description shortened to an accurate, current summary.
  • README.md restructured to lead with user-facing setup/usage/privacy
    documentation, with the existing architecture notes kept as a
    "For developers" section further down.

Fixed

  • Button text contrast. A CSS specificity bug made some primary/AI
    button text render in the same color family as its own background
    (blue-on-blue, purple-on-purple) — root cause was a single overly broad
    link-color rule; fixed with a zero-specificity :where() selector so it
    can never outrank a component's own color.
  • Disabled buttons now get a real neutral disabled treatment (backgrou...
Read more

SEOistic v1.3.0 — First Public Release

Choose a tag to compare

@Shubochandrosarker Shubochandrosarker released this 20 Jul 04:18
6c2093f

SEOistic v1.3.0 — First Public Release

SEOistic v1.3.0 is the first public release of WordPressistic's modern SEO suite for WordPress. It combines deterministic on-page SEO analysis, structured data, XML sitemaps, redirects, image SEO, content health, fast indexing, and optional AI-assisted optimization in one modular plugin.

This release also introduces a redesigned light-mode admin experience, safer license handling, stronger secret storage, and a GitHub-based update channel.

Release type: First public release
Version: 1.3.0
Recommended tag: v1.3.0
Minimum WordPress: 6.4
Minimum PHP: 8.1
License: GPL-2.0-or-later

Highlights

  • A premium light-mode WordPress admin interface with grouped navigation, breadcrumbs, and a global command palette.
  • Deterministic 0–100 SEO scoring based on real page-level checks.
  • Live post-editor analysis that responds to unsaved SEO field changes.
  • A full content inventory with filtering by SEO score, issue, keyword, and index state.
  • Search appearance previews for Google desktop, Google mobile, and social sharing.
  • Schema, XML sitemaps, robots controls, canonical URLs, breadcrumbs, and llms.txt support.
  • Redirect management, 404 monitoring, and CSV import/export.
  • Indexistic fast indexing through Google Indexing API and IndexNow.
  • AI-assisted SEO suggestions with before/after preview, Apply, Dismiss, and Undo controls.
  • Encrypted license and integration secrets, resilient license validation, and improved activation security.

New admin experience

SEOistic now behaves like a focused SEO application inside WordPress instead of a collection of disconnected settings pages.

Application shell

  • Grouped sidebar navigation for faster access to SEO tools.
  • Topbar breadcrumbs to make the current location clear.
  • Ctrl+K on Windows/Linux or Cmd+K on macOS opens the global command palette.
  • The command palette can navigate SEOistic screens and search WordPress content by title or SEO score.

SEO dashboard

  • Animated overall site-health score.
  • Real comparison with the previous completed scan.
  • Quick actions for common SEO workflows.
  • Optimization roadmap grouped by severity.
  • Real issue counts with drill-down links to affected content.
  • No invented traffic estimates or artificial impact numbers.

Content inventory

The new SEOistic → Content screen provides a server-paginated view of posts and pages with:

  • SEO score.
  • Focus keyword.
  • Index state.
  • Score-band filtering.
  • Issue-type filtering.
  • Direct access to the relevant editor.

Post-editor SEO workspace

  • Live score header.
  • Debounced analysis of unsaved SEO field values.
  • Priority fixes and passed checks update while editing.
  • Google desktop/mobile and social previews update as metadata changes.
  • Analysis remains deterministic and does not silently save or publish content.

Core SEO features

On-page analysis

SEOistic calculates a versioned 0–100 score using checks such as:

  • SEO title quality.
  • Meta description quality.
  • Focus-keyword placement.
  • Heading structure.
  • Content length.
  • Internal linking.
  • Image alternative text.
  • Open Graph image availability.

Technical SEO

  • XML sitemaps.
  • Robots controls and robots.txt support.
  • Canonical URL management.
  • Breadcrumbs.
  • llms.txt support.
  • Organization, WebSite, and per-page JSON-LD schema.
  • Schema validation against required and recommended properties.

Redirects and 404 monitoring

  • Redirect rule management.
  • 404 request monitoring.
  • CSV import and export for redirects.

Indexistic fast indexing

  • Google Indexing API integration.
  • IndexNow support for participating search engines.
  • Optional automatic submission when content is published or updated.
  • Bulk URL-submission console.
  • Submission history for operational visibility.

Content Health

  • Orphan-page detection.
  • Content-decay flagging.
  • Direct links to affected content for manual review.
  • No automatic content changes.

Metadata migration

Import existing SEO metadata from:

  • Yoast SEO.
  • Rank Math.
  • All in One SEO.

AI-assisted optimization

Premium AI tools support OpenRouter, Groq, and a self-hosted Ollama endpoint using credentials supplied by the site owner.

AI can assist with:

  • SEO titles.
  • Meta descriptions.
  • Focus keywords.
  • Schema selection.
  • Image alternative text.
  • Internal-link opportunities.
  • Full-page optimization suggestions.

Every suggestion is displayed as a before/after preview. Applying a suggestion always requires an explicit user action; SEOistic does not silently write or publish AI-generated content.

Licensing and account experience

The inactive license screen has been simplified to the essentials:

  • License-key field.
  • Activate License button.

After activation, SEOistic displays the current plan, expiry, last validation time, and a masked license key. The full key is not shown again.

License validation now separates a temporary connection failure from a confirmed expiration or revocation. A transient service outage uses retry backoff and preserves the last known-good status for a bounded period instead of immediately disabling paid features.

WPistic links

Security improvements

  • License keys are encrypted at rest.
  • Existing plaintext license keys are migrated transparently on first read.
  • Business Automator API tokens are encrypted at rest and are no longer returned to settings fields in plaintext.
  • License activation is rate-limited to five attempts per ten minutes.
  • Every REST route uses an explicit permission callback.
  • Post-specific REST operations verify the current user's post-edit capability.
  • License-validation cron events are removed when the plugin is deactivated.

Fixes

  • Fixed primary and AI button text contrast caused by an overly broad CSS selector.
  • Added clear disabled, hover, and pressed states across button variants.
  • Fixed spacing around the featured pricing-plan label.
  • Fixed missing SEO score-ring styles on WordPress post-list screens.
  • Fixed a PHP 8+ fatal error on the Business Automator settings screen caused by an undefined constant.
  • Removed calls to Google's retired sitemap-ping endpoint.
  • Centralized account and pricing URLs so deployments can override them with documented constants or filters.
  • Improved entitlement checks so all premium modules use the same license-validity source.

Free and premium availability

Included without a premium license

  • On-page analysis and scoring.
  • Search appearance previews.
  • Core schema and structured data.
  • XML sitemaps, robots controls, canonicals, breadcrumbs, and llms.txt.
  • Redirects and 404 monitoring.
  • Image SEO.
  • WooCommerce SEO fields when WooCommerce is active.
  • Local SEO fields.
  • Indexistic fast-indexing tools.
  • Content Health.
  • Yoast SEO, Rank Math, and All in One SEO importers.

Premium license features

  • AI-assisted optimization using the site owner's provider credentials.
  • Schema Pro custom schema builder.
  • Core Web Vitals monitoring.
  • AI search visibility and AEO reporting.
  • Keyword rank tracking.
  • Read-only Google Search Console dashboard.
  • WPistic Business Automator integration.

See More SEOistic or WPistic pricing for current availability and plan details.

Privacy and external services

SEOistic does not send analytics or telemetry by default. External connections occur only when the related feature is configured or explicitly used.

  • WPistic licensing: license activation, deactivation, and periodic validation after a license is activated.
  • Google APIs: only after the site owner configures Google Indexing or Search Console.
  • IndexNow/Bing: only when the relevant indexing or sitemap feature is enabled or manually triggered.
  • OpenRouter/Groq: only when the site owner configures a provider and starts an AI action.
  • Self-hosted Ollama: requests are sent to the endpoint configured by the site owner.
  • Business Automator: only after an instance and API token are configured.

Compatibility and requirements

  • WordPress 6.4 or newer.
  • PHP 8.1 or newer.
  • Standard WordPress MySQL/MariaDB database connection.
  • Block Editor (Gutenberg).
  • Classic Editor.
  • WooCommerce-aware, but WooCommerce is not required.

Installation

  1. Download the installable seoistic-1.3.0.zip asset attached to this release.
  2. In WordPress, open Plugins → Add New → Upload Plugin.
  3. Select the ZIP and click Install Now.
  4. Activate SEOistic.
  5. Open SEOistic → Dashboard and run the first site audit.

Do not upload the source-code archive generated automatically by GitHub if a dedicated installable plugin ZIP is attached. Use seoistic-1.3.0.zip so WordPress receives the correct plugin directory and release contents.

Upgrade notes

This is the first versioned public release. For sites running a pre-release build:

  • Back up the WordPress database and files before updating.
  • Existing SEO metadata remains supported through the plugin's compatibility layer.
  • Existing plaintext license keys are migrated to encrypted storage automatically.
  • No database migration is listed for this release.
  • Clear page and object caches after activation if the old admin styling remains visible.

Support and reporting

Read more