=== Acez SEO AI ===
Contributors: acezworld
Tags: seo, schema, structured-data, json-ld, ai
Requires at least: 6.4
Tested up to: 7.1
Requires PHP: 8.1
Stable tag: 0.9.9.36
License: GPL-2.0-or-later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Schema.org, meta tags & AI-powered SEO for WordPress — your own AI key, no lock-in.

== Description ==

Acez SEO AI generates the meta tags and Schema.org (JSON-LD) structured data search
engines and AI assistants need to understand your site — titles, descriptions,
Open Graph, Twitter Cards, canonical URLs, and a growing library of Schema.org
types — all fully configurable, with sensible automatic defaults.

= Structured data, out of the box =

* Article, WebSite, Organization, BreadcrumbList, Person, FAQPage (auto-detected
  from native `core/details` blocks), HowTo, Product (with WooCommerce data when
  active), and LocalBusiness
* A full JSON graph override and a custom-node repeater for anything the built-in
  types don't cover, with a local schema validator against Google's Rich Results
  requirements
* Location Rules (AND/OR condition groups) to control exactly which templates,
  post types, or pages get which schema and meta output

= AI generation on your own key =

Connect your own Anthropic, OpenAI, Google Gemini, or OpenRouter account and
generate SEO titles, meta descriptions, image alt text, FAQ/HowTo schema
nodes, and product descriptions with one click, directly in the block editor
or Classic Editor.
Every result lands in an editable field for review — nothing is ever saved
automatically. Because it runs on your own API key, there are no extra credits
or subscriptions to buy for AI features.

= Feeding both search engines and AI crawlers =

* A graphical robots.txt editor with one-click blocking for known search and AI
  bots (GPTBot, Google-Extended, ClaudeBot, and more)
* A dedicated llms.txt generator (the llmstxt.org standard) — a concise guide to
  your site's most important content, built for language models
* A site-wide noai/noimageai opt-out signal for AI training

= Multilingual sites =

Works alongside WPML, Polylang, and TranslatePress: per-post `inLanguage` in the
JSON-LD graph, and no duplicate hreflang output when your multilingual plugin
already generates it.

= Migrate in minutes =

A dry-run importer reads existing SEO data from Slim SEO, Yoast SEO, and All in
One SEO — titles, descriptions, canonical URLs, robots settings, and Open Graph
images — so switching plugins doesn't mean starting from zero.

= Plays well with others =

Acez SEO AI automatically detects other active SEO plugins (Yoast, Rank Math,
All in One SEO, SEOPress, Slim SEO) and steps aside for anything they already
handle, to avoid duplicate meta tags or conflicting signals.

= Also included =

Advanced Custom Fields integration (a `%acf:field%` template variable and an ACF
image field as an Open Graph fallback), site ownership verification for Google,
Bing, Yandex, Pinterest, Baidu and Meta, Google Tag Manager/Analytics/Hotjar
integration fields, per-post-type feature toggles, and full Polish and English
localization.

= Pro add-on =

An optional, separately distributed Pro add-on extends Acez SEO AI with a
redirect manager and 404 monitor, in-editor content analysis with Polish-aware
readability scoring, bulk AI generation, Google Search Console dashboards with
OAuth, premium schema types (Recipe, Event, JobPosting, Course, VideoObject),
AI-assisted internal linking, per-language Organization overrides, and AI
translation of meta fields. The free plugin above is fully functional on its
own — the Pro add-on only adds capabilities, it never takes any away.

== Installation ==

1. Upload the plugin files to `/wp-content/plugins/acez-seo`, or install it
   directly through the Plugins screen in WordPress.
2. Activate the plugin through the "Plugins" screen.
3. Open "Acez SEO AI" in the admin menu to configure your Organization details,
   review the per-post-type meta/schema settings, and (optionally) connect an
   AI provider.

== Frequently Asked Questions ==

= Do I need an AI provider account to use this plugin? =

No. Every AI feature is optional and off by default until you connect an
Anthropic, OpenAI, Google Gemini, or OpenRouter account with your own API key.
All core SEO features (meta tags, schema, robots.txt, llms.txt, importers, ACF
integration) work fully without any AI provider configured.

= Does this conflict with Yoast SEO / Rank Math / other SEO plugins? =

Acez SEO AI detects other active SEO plugins and automatically stops printing
its own meta tags, canonical URLs, and sitemap/llms.txt entries where they would
duplicate what the other plugin already outputs, so you can safely run it
alongside another plugin during a migration.

= Is the free version limited or a trial? =

No. The free version is fully functional and not time-limited or feature-capped.
The optional Pro add-on adds extra tools (redirects, bulk AI, Search Console
dashboards, premium schema types, AI linking) — it never removes anything from
the free version.

= What data does the plugin send to third parties? =

Only what you explicitly configure — see "External services" below for the
full list. There is no telemetry and no data collection beyond that.

== External services ==

This plugin can connect to the following third-party services, but only when
you explicitly configure and use the corresponding feature. No data is sent to
any of these services unless you take the described action.

* **AI content generation (Anthropic / OpenAI / Google Gemini / OpenRouter)** —
  when you connect a provider with your own API key and click a "Generate with
  AI" button, the relevant field's context (e.g. post title and excerpt) is
  sent to that provider's API to generate the requested text. This only
  happens when you click the button; nothing is sent automatically.
  Anthropic: https://www.anthropic.com/legal/consumer-terms | https://www.anthropic.com/legal/privacy
  OpenAI: https://openai.com/policies/terms-of-use | https://openai.com/policies/privacy-policy
  Google Gemini: https://ai.google.dev/gemini-api/terms | https://policies.google.com/privacy
  OpenRouter: https://openrouter.ai/terms | https://openrouter.ai/privacy
* **Google Tag Manager / Google Analytics (GA4)** — only loaded on your site's
  front end once you enter a Container ID or Measurement ID in the Integrations
  tab. Loads a script from googletagmanager.com.
  Terms: https://marketingplatform.google.com/about/analytics/terms/us/ | Privacy: https://policies.google.com/privacy
* **Hotjar** — only loaded once you enter a Site ID in the Integrations tab.
  Loads a script from static.hotjar.com. Hotjar is now part of Contentsquare,
  which publishes the governing terms and privacy policy.
  Terms: https://contentsquare.com/legal/terms-conditions/ | Privacy: https://contentsquare.com/privacy-center/services-privacy-policy/

== Screenshots ==

1. Dashboard — per-post-type overview and feature toggles.
2. Schema.org settings — Organization, LocalBusiness, and structured data.
3. Block editor sidebar — SEO title/description, SERP preview, and AI generation.
4. AI Providers — connect your own Anthropic/OpenAI/Gemini key.
5. Graphical robots.txt editor with known-bot blocking.

== Changelog ==

= 0.9.9.36 =
* Every settings screen now verifies the form nonce in its own save handler,
  instead of relying only on the shared dispatcher that calls it.
* Table names in the AIOSEO import and conflict detection are passed through
  $wpdb->prepare()'s %i identifier placeholder rather than being interpolated
  into the query string.
* Structured data is printed through WordPress's own inline script tag API
  (wp_print_inline_script_tag). The JSON-LD output itself is unchanged.

= 0.9.9.35 =
* Form input is now sanitized with core WordPress functions at the point it is
  read, before the plugin's own template sanitizers run. Percent signs in
  %variable% tokens and percent-encoded URLs are still kept intact.
* Custom schema JSON is sanitized after decoding: HTML tags are removed from
  every value and property name.
* Fixed: sitemap URL exclusions did not work for percent-encoded (non-Latin)
  slugs. Exclusion rules now match regardless of letter case in the encoding
  and also accept the plain, decoded characters.
* Fixed: uninstalling the plugin now also removes the sitemap, onboarding, AI
  bot and AI usage/log settings, and the dismissed-notice state.

= 0.9.9.34 =
* Added "Generate with AI" buttons to the llms.txt tab (title, description,
  introduction and footer).

= 0.9.9.33 =
* Removed the Custom Code tab (header/body/footer snippet injection), following
  the WordPress.org plugin review — arbitrary code insertion is not allowed in
  plugins hosted in the directory.
* Added site ownership verification fields for Google Search Console, Bing
  Webmaster Tools, Yandex, Pinterest, Baidu and Meta/Facebook to the
  Integrations tab. These cover the legitimate reason most people reached for
  header snippets: pasting a verification meta tag. Each field is validated and
  sanitized, and outputs a single `<meta>` tag.
* Verification codes entered in the admin are now sanitized at the point the
  form is read, not only when they are stored.

= 0.9.9.32 =
Collective entry covering the main changes since 0.9.5, most of them made in
response to the WordPress.org plugin review.

* No feature in the free plugin is gated behind a licence any more. Per-language
  Organization overrides, schema property overrides for a forced node, the
  form-based node builder, and AI translation of meta fields moved to the Pro
  add-on; the llms.txt footer, publication dates and caching, plus AI alt text
  from image analysis, are now permanently free.
* Source strings are English. Polish and Spanish translations are served from
  translate.wordpress.org instead of being bundled with the plugin.
* Removed the `anthropic-ai/sdk` Composer dependency — all four AI providers now
  talk to their APIs through the WordPress HTTP API. The plugin ships with no
  production dependencies at all.
* Security: AI provider API keys are encrypted with a key derived from
  `wp_salt('auth')`, unique per install; the older key derivation and its
  hard-coded fallback have been removed.
* Security: JSON-LD output is escaped with `JSON_HEX_TAG` against `</script>`
  breakout, and user-authored schema nodes now pass through a recursive
  sanitizer after decoding.
* Google Tag Manager and Hotjar snippets are emitted through the WordPress
  script enqueue API instead of raw `<script>` tags.
* Manual override of the main schema node type per post, AI generation of full
  article content, automatic connection test for the active AI provider, and a
  declared search intent used as AI context.
* Fixed the Hotjar terms and privacy links under "External services" (Hotjar is
  now part of Contentsquare).

= 0.9.5 =
* Internal: added a generic `AiGenerationService::generate_for_filtered_field()`
  entry point for AI fields whose context isn't a post (used by the Pro
  addon's new AI redirect-target suggestions) — no user-facing change in
  the free plugin.

= 0.9.4 =
* Added "Generuj przez AI" for the focus keyword field ("Fraza kluczowa"),
  in both the Classic meta box and the Gutenberg sidebar — free feature,
  same as the existing title/description generation.

= 0.9.3 =
* AI Providers: fixed a bug where a configured-and-tested provider that
  wasn't (yet) set as the "Aktywny dostawca" disappeared from the tab on
  the next visit, looking like the save had silently failed — a provider
  card now stays visible whenever it has a saved API key, not only when
  it's the active one.
* Fixed two related markup bugs: a duplicate id="model" shared by all three
  provider cards, and a duplicate class="" attribute on the provider "Zapisz"
  button that silently dropped its custom class.

= 0.9.2 =
* AI Providers: after a successful "Testuj połączenie" test, the provider
  card now shows up to 10 of the provider's most recent models to pick from
  — selecting one fills the "Model" field, so both the API key and the
  chosen model are saved together on "Zapisz".

= 0.9.1 =
* AI Providers: added a "Rozłącz i usuń klucz API" (Disconnect & delete API key)
  button per provider card, so a connected provider's key, model and tested
  status can be fully erased from the database, with a confirmation prompt.

= 0.8.7 =
* Current feature set as of this release: Schema.org/meta engine, Location
  Rules, AI generation on your own key, robots.txt/llms.txt editors,
  multilingual support, SEO-data importers, ACF integration, and the optional
  Pro add-on.

== Upgrade Notice ==

= 0.9.9.32 =
Formerly licence-gated features now live in the Pro add-on (per-language
Organization overrides, forced-node property overrides, the node builder, AI
meta translation); stored data is kept. Any AI provider API key saved before
the encryption fix must be entered again.
