=== Stedica SEO ===
Contributors: stedica
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 8.0
Stable tag: 3.22.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html
Tags: seo, schema, structured data, sitemap, redirects

Audit every page and fix what it finds: meta, schema and social gaps, sitemaps, redirects, hreflang. Works with Yoast, Rank Math, SEOPress, AIOSEO.

== Description ==

Most SEO plugins help you optimise a post while you are writing it. Stedica SEO starts from the other end: it audits the pages you already published, scores every issue by severity, and gives you one screen to work through them.

It is also built to be installed *alongside* whatever SEO plugin you already use. Stedica reads and writes Yoast, Rank Math, SEOPress and All in One SEO metadata, so you can run an audit today without migrating anything or losing what you have.

**What the free edition does**

* **Site audit** — scans every URL on the site and groups every issue by severity: Critical, High, Medium, Low.
* **Titles and meta descriptions** — edit inline, with length guidance, a live Google preview, and templates with dynamic variables such as `#current_year`.
* **Canonical URLs and meta robots** — per-post noindex, nofollow, noarchive and nosnippet, merged correctly into WordPress' own robots output.
* **Open Graph and Twitter Cards** — per-post social metadata with an image picker.
* **Core structured data** — Organization, WebSite, WebPage and BreadcrumbList JSON-LD.
* **Breadcrumbs** — BreadcrumbList schema on singular views.
* **XML sitemap** — paginated, cached and image-aware, with robots.txt integration.
* **robots.txt editor** — override the virtual robots.txt, with your sitemap appended automatically.
* **IndexNow** — submit new and updated URLs to Bing, Yandex, Seznam and Naver.
* **Redirects** — unlimited rules (301, 302, 307, 410) plus a 404 log.
* **Image alt text** — find every image missing alt text and fix it.
* **Readability** — Flesch Reading Ease, shown right in the editor.
* **CSV export** — take the full issue list anywhere.
* **Elementor compatible** — reads content, headings and images from Elementor's own data, which a plain `post_content` read misses.
* **Works with your existing SEO plugin** — reads and writes Yoast, Rank Math, SEOPress and AIOSEO fields.
* **Translation ready** — every string in the interface is translatable, with translations delivered through translate.wordpress.org.
* **Headline analysis** — length, keyword placement and structure scored as you type.
* **HTML sitemap** — `[stedica_html_sitemap]`, nested and cached.
* **Table of contents** — a block, or `[stedica_toc]`, with stable heading anchors.
* **Cornerstone content** — mark your important pages and their problems are scored higher.
* **hreflang** — for multilingual sites, Polylang and WPML aware.
* **llms.txt** — a machine-readable summary of your site for AI crawlers.
* **Orphan and under-linked pages** — every page with no inbound internal links, found during the audit.
* **Keyword cannibalisation** — your own pages competing for the same term.
* **Quick wins** — the pages one or two fixes away from being clean.
* **Fix Mode** — work through issues one at a time, approve suggestions and apply them in bulk.
* **Schema editor** — validate your JSON-LD and edit individual `@graph` nodes by hand.
* **Broken link scan** — check outbound links on demand.
* **Undo** — every write the plugin makes to a post is reversible.
* **SEO permission** — let a contractor do SEO without an administrator account.
* **REST API** — `/wp-json/stedica-seo/v1/` for audits, issues and per-page SEO fields.
* **Health screen** — what is working, and what quietly stopped.
* **Setup wizard** — four questions on first install.

**Stedica SEO Premium**

Premium is a separate plugin that installs alongside this one and both stay active — you will see two rows in your plugins list, the same way Yoast Premium and SEOPress PRO work. Keep this plugin installed; Premium needs it and adds to it. It adds the parts that need automation, an external API, or work across your whole site at once:

* AI meta titles, descriptions, alt text, schema, FAQ blocks and content briefs — using your own API key with OpenAI, Anthropic, Google Gemini, Mistral or Groq, with a screen that tracks tokens and estimated spend.
* Scheduled scans, and scan and weekly digest emails.
* Google Search Console — indexing status, impressions, clicks, average position, and per-URL indexing requests.
* Google Analytics 4 organic sessions.
* Core Web Vitals (LCP, INP, CLS) via PageSpeed Insights.
* Redirect importers for Redirection, Yoast Premium, Rank Math, AIOSEO, SEOPress and Safe Redirect Manager.
* Scheduled broken-link checking on a cron, rather than on demand.
* Internal linking suggestions, with one-click insertion into the donor page.
* AI schema generation, including FAQ and HowTo blocks.
* Multi-location Local SEO — a LocalBusiness entry per branch, with address geocoding.
* Keyword rank tracking — daily positions from Search Console, with biggest movers.
* Content decay — pages whose impressions have fallen away since an earlier audit.
* Multisite support.

Details at [stedica.com](https://stedica.com/).

== External services ==

This plugin can connect to third-party services. All of them are optional and only used when you explicitly enable and configure them in Settings.

**Google Search Console / Google Analytics 4** — When connected, the plugin sends your site URL and individual page URLs to Google in order to retrieve indexing status and traffic metrics. Requires you to authorise access via Google OAuth.
Terms: https://policies.google.com/terms — Privacy: https://policies.google.com/privacy

**Google PageSpeed Insights** — When you request Core Web Vitals for a page, that page's URL is sent to Google.
Terms: https://policies.google.com/terms — Privacy: https://policies.google.com/privacy

**AI providers (OpenAI, Google Gemini, or Anthropic — whichever you configure)** — When you use an AI feature (meta generation, alt text, schema generation, content briefs), the plugin sends the relevant page's title, URL, meta description, focus keyword and an excerpt of its text content to the provider you selected, using the API key you supply. No data is sent unless AI is enabled in Settings and a key is present.
OpenAI: https://openai.com/policies/terms-of-use — https://openai.com/policies/privacy-policy
Google Gemini: https://ai.google.dev/terms — https://policies.google.com/privacy
Anthropic: https://www.anthropic.com/legal/consumer-terms — https://www.anthropic.com/legal/privacy

**IndexNow (Bing, Yandex, Seznam, Naver)** — **Off by default.** If you tick the IndexNow box in Settings, the URL of each post you publish or update is sent to `https://api.indexnow.org/indexnow`, which passes it to those search engines so they can recrawl it. Only the URL is sent — no page content, no personal data, and nothing about your visitors. Nothing is transmitted until you enable it, and unticking the box stops it immediately.
Service: https://www.indexnow.org/
Terms of use: https://www.indexnow.org/terms
Privacy policy: https://privacy.microsoft.com/privacystatement

**OpenStreetMap / Nominatim (Premium — Local SEO only)** — When you click *Find coordinates* on the Local SEO settings, the business address you typed is sent to `https://nominatim.openstreetmap.org/search` to look up its latitude and longitude. It runs only on that click, and the request identifies itself with the plugin name, version and your site URL as Nominatim's usage policy requires.
Terms: https://operations.osmfoundation.org/policies/nominatim/ — Privacy: https://wiki.osmfoundation.org/wiki/Privacy_Policy

**Freemius (licensing, updates and optional usage data)** — Freemius handles Premium licence checks and updates. The free plugin ships with tracking switched off: the SDK runs in anonymous mode, so no site or user data is sent unless you accept its opt-in notice, which you can dismiss or decline and still use every feature.
Terms: https://freemius.com/terms/ — Privacy: https://freemius.com/privacy/

If your site serves visitors in the EU, disclose any AI provider you enable in your own privacy policy, since page content is transmitted to that provider.

Note that in the free edition the AI providers, Search Console, Analytics and PageSpeed integrations are not present in the package at all, so nothing is sent to any of them.

== Licence ==

Stedica SEO is licensed **GPL-2.0-or-later**. A copy of the GPL v2 ships in `LICENSE`.

The plugin bundles the Freemius WordPress SDK (`vendor/freemius/`), which is licensed **GPL-3.0**; its own licence text is in `vendor/freemius/LICENSE.txt`. Because Stedica SEO is offered under GPL v2 *or later*, the two are compatible, and the combined distribution you receive is effectively governed by GPL v3. This is noted here so the presence of two different GPL versions in the package is not mistaken for an oversight.

Third-party components and their licences:

* Freemius WordPress SDK — GPL-3.0 — https://github.com/Freemius/wordpress-sdk
* Chart.js (`assets/js/chart.umd.min.js`) — MIT — https://www.chartjs.org/

Everything else in this package is Copyright © 2026 Stedica LLC.

== Installation ==

1. Upload the `stedica-seo` folder to `/wp-content/plugins/`, or install the ZIP via **Plugins → Add New → Upload Plugin**.
2. Activate the plugin through the **Plugins** menu.
3. Go to **Stedica SEO → Settings** to set your title and description lengths.
4. Go to **Stedica SEO → Audit** and run your first scan.

== Frequently Asked Questions ==

= Do I have to remove Yoast / Rank Math / SEOPress / AIOSEO? =

No. Stedica detects the active SEO plugin and reads and writes its metadata fields, so both stay in sync.

= Does it work with Elementor? =

Yes. Content, H1 detection, word count, readability and image alt scanning all read Elementor's stored page data, which a normal `post_content` read would miss.

= Is AI required? =

No. Every AI feature is optional and off until you add your own API key. Without it the plugin still audits, scores, and lets you edit everything manually.

= Who pays for the AI calls? =

You do, directly to whichever provider you configure, using your own API key. The **AI Costs** page tracks token usage and estimated spend.

= What languages is Stedica available in? =

The interface is written in English and is fully translatable — every string, including the screens drawn in the browser by JavaScript. Translations are hosted on translate.wordpress.org and WordPress installs them for you when you set your site language, so nothing ships inside the plugin.

= Can I translate Stedica into another language? =

Yes, and the best place to do it is <https://translate.wordpress.org/projects/wp-plugins/stedica-seo/>. Translating there means your work is reviewed by the WordPress polyglots community, shipped to every site through the normal translation updates, and never lost on a plugin update. A `languages/stedica-seo.pot` template also ships with the plugin; its header explains which strings must be left in English (product names, Schema.org types, and values the plugin stores internally) and how the `%s`/`%d` placeholders work.

If you would rather work offline first, copy the template to `stedica-seo-{your_locale}.po` and translate it in a tool like Poedit, then import the result at translate.wordpress.org. Always validate with `msgfmt --check` before importing — it catches the placeholder mistakes that would otherwise break the plugin in your language only.

A translation you keep locally belongs in `wp-content/languages/plugins/`, which survives plugin updates; WordPress prefers a translation found there.

= Will it slow down my site? =

Front-end work is minimal: the plugin outputs meta tags on singular pages and does one indexed lookup for redirects. Scanning and AI calls happen in the admin area or on a schedule, never during a visitor's page load.

= How do I upgrade to Premium? =

From **Stedica SEO → Upgrade** inside your dashboard. There is a 7-day trial and it does not ask for a card. Stedica SEO Premium installs alongside this plugin rather than replacing it — keep this one active — and nothing in your data changes.

= Is Premium a separate plugin, or does it replace this one? =

Separate. Stedica SEO Premium installs alongside Stedica SEO and both stay active — two rows in your plugins list. Premium contains only the paid features and uses this plugin's code, so it cannot run without it. WordPress enforces that for you: it will not activate Premium without Stedica SEO, and will not let you deactivate Stedica SEO while Premium is active.

= Do I have to reconfigure anything after upgrading? =

No. Your settings, scans, redirects and every meta description you have written stay exactly as they are — Premium reads the same data this plugin already wrote. If you later cancel, deactivating Premium leaves all of it untouched; only the paid features stop.

= What is the difference between the free version and Premium? =

The free edition is complete. It audits every URL on your site, stores as many redirects as you need, and everything it does it does fully — nothing is capped, watermarked or half-written. Stedica SEO Premium is a separate add-on that adds capability this plugin does not contain: AI writing, Google Search Console and Analytics, Core Web Vitals, keyword rank tracking, content decay detection, scheduled auditing, the redirect importers and the broken link checker.

= What happens to my redirects if my licence lapses? =

Nothing. Redirects are part of this free plugin and there is no limit on them, so every rule you created keeps working and you can still add, edit, disable and delete them exactly as before. A lapsed licence only stops the separate Premium add-on from updating.

== Screenshots ==

1. Issues — quick wins first: the pages closest to clean, plus a severity-scored history of every scan.
2. The dashboard after a scan: pages scanned, issues by severity, and connected services. Search Console, Analytics 4 and the AI providers shown here are Premium features.
3. Audit — choose the post types, then scan the pages you already published. Results export to CSV.
4. The post editor: a live search preview with length-checked title and description, and tabs for social, schema and robots. The badge top right names the metadata source, so the same box edits Yoast, Rank Math, SEOPress or All in One SEO fields when one of those is active.
5. Redirects — import existing rules from Redirection, Rank Math or All in One SEO, add exact or regex 301s, and promote a logged 404 to a redirect in one click.
6. Settings — breadcrumb schema, the redirect engine, XML sitemaps and the rest, each opt-in. "Move in from another SEO plugin" copies metadata across without modifying or removing the other plugin.

== Changelog ==

The full history is in `changelog.txt`, which ships with the plugin.

= 3.22.1 =
* Adds a single request for a WordPress.org review, shown after your third completed audit and only on Stedica SEO's own screens. Dismissing it is permanent, it is never shown to anyone who has already answered it, and it offers nothing in exchange — a review you were paid for is not worth having. Site owners who want it gone entirely can add `add_filter( 'stedica_seo_show_review_prompt', '__return_false' );`.

= 3.22.0 =
* **New: Reports (Premium).** A report written for the person who has to explain SEO to someone who does not do SEO. It opens with a plain-language summary, charts issue counts over time, and lists what is worth fixing next — then answers the question the summary raises: what did the work actually earn?
* **What changed, and what happened next.** Stedica records the moment a fix lands on a page, and stores that page's Search Console figures at every audit. The report compares the pages you changed against the pages you did not, over the same period, so seasonal movement is visible rather than claimed as a result. It states plainly that this is evidence rather than proof.
* **Six to twelve months of history.** A new per-page snapshot table keeps a narrow row per page per capture, well past the point where a full audit is recycled. Existing audits are used to seed it on first run, and periods are offered only once that much history exists.
* Reports print, download as PDF, and arrive by email to the site administrator each month. A test-send button is included, because a monthly schedule is a slow way to find out that mail is not working.

= 3.21.0 =
* **The free plugin is now fully functional, with nothing held back.** The WordPress.org review team found audits capped at 100 URLs and redirects at 25, with a licence lifting both. They were right: limiting a built-in, working feature purely to sell the removal of the limit is not allowed. Both caps are gone, and so is every other licence check — the advanced schema editor, bulk fixing, the broken-link scan, quick wins and content decay all had working code sitting behind one. Premium is a separate add-on that adds code this plugin does not contain; it no longer unlocks anything that was already here.
* The free plugin no longer shows controls for features that live in the add-on. Google connection, AI meta generation, scheduled scanning, the weekly digest, Core Web Vitals and the broken-link checker were rendering settings that stored values nothing could read, and "Run Scan Now" reported a scan that never ran. Anything configured while Premium is active is left untouched.
* Fixed a cross-site scripting hole: product data reached a JSON-LD block without escaping `<` and `>`, so a `</script>` in a product title could break out of it. The same fix was applied to the multi-location schema.
* Hardened authorisation on five handlers that wrote to a post without checking the caller could edit that particular post — schema apply and clear, single alt-text save, focus-keyword save and alt-text generation.
* All inline `<script>` and `<style>` blocks now go through the WordPress enqueue API, and the old welcome pop-up has been removed — the setup wizard added in 3.12.0 made it redundant.
* Chart.js updated to 4.5.1, and it now actually reaches browsers: the file was updated but still enqueued under the old version, so the cached copy was never replaced.
* Translations are left to translate.wordpress.org rather than bundled. IndexNow is opt-in everywhere, its terms and privacy policy are linked, and the terms link no longer points at a Bing page that has been removed.
* Fixed four settings stored empty that ignored their own defaults, which also produced a "Using null as an array offset" notice on PHP 8.1+.

== Upgrade Notice ==

= 3.22.1 =
Adds one dismissible request for a WordPress.org review after your third audit.

= 3.22.0 =
New: Reports for Premium — a monthly report that shows what changed and what it earned, with six to twelve months of history.

= 3.21.0 =
Free is now fully functional — every cap and licence gate removed. Also fixes an XSS in product schema.

= 3.20.0 =
A table of contents block and shortcode, with stable heading anchors.

= 3.19.0 =
Headline analysis as you type, with the reasons shown — and honest about which parts are only rules of thumb.

= 3.18.0 =
An HTML sitemap for visitors, via [stedica_html_sitemap], with the same exclusions as the XML one.

= 3.17.1 =
Cornerstone pages are flagged when too few pages link to them, not only when none do.

= 3.17.0 =
Mark your most important pages as cornerstone and the audit prioritises their problems accordingly.

= 3.16.0 =
Fill missing image alt text from captions, titles and filenames — free, no AI required.

= 3.15.0 =
A Health screen: nine checks covering what is working, what stopped, and where to fix it.

= 3.14.0 =
An MCP server so AI assistants can read and improve your SEO, plus a per-page issues endpoint.

= 3.13.0 =
A REST API at /wp-json/stedica-seo/v1/ for audits, issues and per-page SEO fields.

= 3.12.0 =
A setup wizard for new installs, including one-click import of your existing SEO data.

= 3.11.0 =
SEO work no longer requires an admin account: grant it per role, with Settings and AI Costs still admin-only.

= 3.10.1 =
Audit results are now recycled rather than growing forever. Trend history is unaffected.

= 3.10.0 =
Multi-location Local SEO: a row per branch, each giving its own page a Local Business entry.

= 3.9.1 =
Premium: cleared 18 Plugin Check errors and 4 warnings. No behaviour change.

= 3.9.0 =
Internal linking suggestions are now one-click: Stedica writes the link into the other page for you.

= 3.8.6 =
Housekeeping only: the full version history moved to changelog.txt so WordPress.org stops truncating it.

= 3.8.5 =
Stedica now warns you when the Google connection breaks, rather than quietly pausing Search Console features.

= 3.8.4 =
An expired Google connection now says so and self-heals where it can, instead of surfacing as a 401.

= 3.8.3 =
Rank tracking now says why a snapshot failed instead of blaming your traffic, and finds the most recent settled day.

= 3.8.2 =
Rank Tracking screen, plus an important fix: twenty Settings checkboxes could not be switched off.

= 3.8.1 =
Premium: daily keyword rank tracking from Search Console, with history and movement.

= 3.8.0 =
Premium: content decay detection — find the pages that used to earn search traffic and no longer do.

= 3.7.3 =
Plugin description updated.

= 3.7.2 =
Fixes applied by Stedica can now be undone in one click, including what was written into Yoast, Rank Math, SEOPress or AIOSEO.

= 3.7.1 =
Author pages get their own SEO settings, and author credentials are now published as structured data.

= 3.7.0 =
Divi, Bricks, Oxygen, Beaver Builder and WPBakery pages are now read correctly. Issue counts will change on sites using them.

= 3.6.11 =
Interface consistency: every button, card, panel and field now shares the same 6px corner.

= 3.6.10 =
Premium scheduled scans, the weekly digest and broken-link checking now stop when a licence lapses.

= 3.6.9 =
Your sitemap address can no longer be claimed by another SEO plugin, and Stedica's sitemap now takes precedence over any other.

= 3.6.8 =
Fixes an XML sitemap that can quietly start returning "not found" after another plugin is installed.

= 3.6.7 =
Audit accuracy: duplicates now appear in your issue list, missing descriptions are reported, and false keyword warnings are gone. Issue counts will change after the next scan.

= 3.6.6 =
Fixes hreflang narrowing your language targeting, and imports that invented metadata you never wrote.

= 3.6.5 =
Pages without a meta description now fall back to your excerpt; social previews fall back to the page text.

= 3.6.4 =
Important fix for new installations: redirects could not be saved at all.

= 3.6.3 =
Important sitemap fix: robots.txt was pointing search engines at WordPress's sitemap instead of Stedica's.

= 3.6.2 =
Fixes duplicate og:type on WooCommerce product pages, which could drop the price from shared links.

= 3.6.1 =
Important fix for WooCommerce stores using Elementor, Divi, Bricks or Oxygen: product rich results were missing entirely.

= 3.6.0 =
WooCommerce product rich results, product Open Graph, and better product descriptions.

= 3.5.0 =
hreflang support for WPML and Polylang, including x-default.

= 3.4.0 =
One-click import from Yoast, Rank Math, SEOPress and All in One SEO, plus a portable settings file.

= 3.3.0 =
Regex redirects and automatic 404 rescue.

= 3.2.0 =
Adds /llms.txt so AI assistants and AI search can understand your site.

= 3.1.1 =
Archives now get proper SEO output, and taxonomy terms get their own SEO fields.

= 3.1.0 =
The XML sitemap now covers taxonomy, author and date archives.

= 3.0.21 =
Plugin header fix required by WordPress.org. No functional change.

= 3.0.20 =
IndexNow now ships switched off and asks for consent first. Sites that already enabled it are unaffected.

= 3.0.19 =
Housekeeping in the Premium add-on. Nothing in the free plugin changed.

= 3.0.18 =
Documentation only. No functional change.

= 3.0.17 =
Fixes apostrophes being saved escaped, and completes the WordPress.org standards pass.

= 3.0.16 =
Compliance pass for the WordPress.org directory. No change to how the plugin behaves.

= 3.0.15 =
The Premium Version link now opens the plans page directly.

= 3.0.14 =
Fixes the Premium Version link introduced in 3.0.13.

= 3.0.13 =
Fixes the blank Premium Version page.

= 3.0.12 =
Stedica SEO is now free, with an optional Stedica SEO Premium upgrade installed alongside it. Existing licences keep every feature. Install or update the free plugin first, then Premium.

