=== Visualithic Phyllix ===
Contributors: mtairowodza
Tags: seo, ai, content marketing, keyword research, search console
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.3.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

An AI marketing director for your site: learns your business, finds ranking gaps, and drafts articles for your approval.

== Description ==

Phyllix reads your website, works out what your business actually does, and then works on your search visibility the way a marketing manager would - by finding what you could realistically rank for, what your existing pages half-cover, and what is missing entirely.

It never publishes anything. Every article it writes is filed as a **draft** for you to read, edit and approve. Every change it proposes to a page you already have is shown to you in full first, and the original is kept so it can be undone.

**What it does**

* Reads your published pages and builds a profile of your business from them
* Maps your existing content and finds the gaps in it
* Builds a keyword map, cross-checked against Google Search Console where you connect it
* Researches a topic, then writes a full article and files it as a draft
* Reviews its own drafts for SEO, readability and accuracy before you see them
* Improves pages you already have, one at a time, always as a reviewable proposal
* Tracks how published articles actually perform in Google over time
* Checks technical health: image dimensions, heading structure, broken links, redirect chains, mixed content, accidental noindex
* Adds a call to action to pages that attract visitors but never ask for the business

**How it treats your content**

This is the part we care most about. A page you already have is a page that already works for someone, so:

* Nothing is ever published automatically
* What gets read is an allow-list you control - only Pages and Posts by default, nothing else unless you add it in Settings
* Private and password-protected content is skipped outright, and any email address found in a page's text is stripped before that text ever reaches an AI request
* Page structure is preserved. Block layouts, full-width sections and shortcodes survive an edit, because the layout is never sent to the AI in the first place
* Pages built with Elementor, Divi or WPBakery are not rewritten at all
* Every edit to a live page keeps the original, so it can be reversed
* A newly published article is left alone for four weeks before Phyllix offers to improve it, because Google needs that long before its position means anything

**Free plan**

The free plan includes 3 AI-written articles, once — a one-time allowance, not a monthly one. Reading your site, the business profile, the content map, the keyword map, the gap analysis, manually-tracked competitors, Google Search Console tracking, and fixing technical SEO problems are always included, for free, forever, with no limit. Once the 3 free articles are used, buy AI credits ($1.25 each, pay only for what you use, no subscription) or move up to a paid plan for an ongoing monthly allowance. Free also reads up to 25 pages of your own site, once, ever.

== External services ==

**Phyllix cannot work without connecting to an external service.** It does not run AI models on your server, and it does not ask you for API keys. Instead it sends work to the Phyllix service, which runs the AI on your behalf. You should understand exactly what that means before you use it.

= The Phyllix service (Visualithic Solutions) =

Phyllix connects to `https://visualithicsolutions.com`, operated by Visualithic Solutions, to license the plugin and to run every AI request.

**When it connects:**

* When you first connect the plugin, to create your free licence
* Every time you ask it to do something that needs AI
* A licence check roughly every 6 hours while you are using it — more often (down to every few minutes) only while your plan is showing as fully used up, so a credit purchase or upgrade is noticed quickly rather than waiting out the normal cache

**What is sent:**

* A randomly generated install identifier, created by the plugin for your site
* Your site address (`home_url()`)
* Your licence key, once you have one
* The text of the pages and drafts Phyllix is working on, including titles and meta descriptions
* The business profile Phyllix has built from your pages
* Your Google Search Console figures, if you have connected Search Console
* Your WordPress administrator email address - **only when you activate a paid licence**, not when a free licence is created

**What is not sent:** your database, your users, your customers' data, your orders, or the content of any page Phyllix has not been asked to work on. Pages you have marked Private or password-protected are skipped outright, whatever content type they are, and any email address found in a page's text is stripped before that text reaches an AI request.

Terms: https://visualithicsolutions.com/terms
Privacy: https://visualithicsolutions.com/privacy

= AI providers used by that service =

The Phyllix service passes your request to one of two AI providers, depending on the task. Your content is sent to them by the Phyllix service, not directly by this plugin.

* **Anthropic** - used for writing the final text of an article or page rewrite.
  Terms: https://www.anthropic.com/legal/consumer-terms
  Privacy: https://www.anthropic.com/legal/privacy
* **Google (Gemini)** - used for research, analysis, review and classification. When researching, it uses Google Search grounding, which means your topic is searched on the web.
  Terms: https://policies.google.com/terms
  Privacy: https://policies.google.com/privacy

= Google Search Console (optional) =

If you choose to connect Google Search Console, Phyllix calls
`https://oauth2.googleapis.com` to exchange the credentials you supply for an
access token, and `https://searchconsole.googleapis.com` to read which searches
your site appears for. This is entirely optional and nothing is sent to Google
beyond the API request itself.

Terms: https://policies.google.com/terms
Privacy: https://policies.google.com/privacy

= Google PageSpeed Insights (optional) =

If you run a site health check, Phyllix calls `https://www.googleapis.com/pagespeedonline` with the public address of the page being checked, to retrieve its performance scores.

Terms: https://policies.google.com/terms
Privacy: https://policies.google.com/privacy

= Links on your own pages =

When you run a site health check, Phyllix makes a HEAD request to the addresses
your pages link to, in order to find broken links and redirect chains. These are
the sites you have already linked to. No data about you or your site is sent -
the request only asks whether the address still responds.

== Installation ==

1. Install and activate the plugin.
2. Open **Phyllix** in the admin menu.
3. Read what Phyllix will send to its service, and connect. A free licence is created for your site automatically - there is no account to make and no key to paste.
4. Run **Read the website** so Phyllix can learn your business from your own pages.

== Frequently Asked Questions ==

= Does it publish anything by itself? =

No. Articles are filed as drafts. Changes to existing pages are shown to you as a proposal and are only applied when you click to apply them. There is no code path in the plugin that publishes a post or changes the status of a published one.

= Can I use my own OpenAI or Anthropic API key? =

No. Phyllix provides the AI as part of the plan, which is why there are no keys to manage and no separate AI bill to reconcile.

= Will it break the layout of my pages? =

It is built specifically not to. On a block-built page, only the text inside your existing blocks is edited and the block structure is put back exactly as it was, so full-width sections and layout settings survive. If a rewrite would lose block wrappers, alignments or shortcodes, it is refused rather than applied. Pages built with a page builder are not rewritten at all.

= Can I undo a change to a live page? =

Yes. The original content is stored before any edit, and every applied change can be reverted from within Phyllix.

= What happens when I use up my article allowance? =

It pauses and tells you, right where you clicked. Nothing is charged automatically and nothing is written that you have not asked for. On a paid plan the allowance resets on the 1st of each month; on the Free plan the 3 articles are a one-time allowance that never resets. Either way, you can buy AI credits ($1.25 each, no subscription, pay only for what you use) to keep going immediately, or move up a plan for ongoing headroom.

= How do I get the Google file for Search Console? =

Step-by-step instructions in plain English are shown inside the plugin, right above the upload box in Settings. It takes about five minutes, it is free, and you only do it once. In short: create a free Google Cloud project, enable the Search Console API, create a service account and download its JSON key, upload that file here, then add the email address Phyllix shows you as a user on your site in Search Console.

You never need to open the JSON file. Upload it and Phyllix reads the email address out of it for you.

= Does it work without Google Search Console? =

Yes. Search Console makes the keyword and results work far more accurate, because it replaces guesswork with what Google actually shows for your site, but Phyllix works without it.

= What data does it send? =

See the "External services" section above, which lists this in full.

= Could it read something it shouldn't - an invoice, a quote, a private page? =

No. What Phyllix reads is an allow-list you control in Settings -> Content to read - it starts with just your ordinary Pages and Posts, and nothing else is added unless you tick it, so a separate "Invoices" or "Quotes" post type stays out by default. On top of that, anything you have marked Private or password-protected is skipped outright, whatever its type - and any email address inside a page's text is stripped in code before that text ever reaches an AI request, everywhere in the plugin, not only on the first read.

= What stops it putting something odd on my page? =

Every change Phyllix makes to a page is checked before it is saved. If the result contains anything that should not be visible to a visitor - structured data showing as words, HTML tags reading as text, markdown symbols, an unfilled placeholder, mangled characters, or the assistant talking to you - the change is refused and you are told exactly what was found. Nothing Phyllix introduces of that kind can reach a published page.

= Do I need Yoast or Rank Math? =

No, but Phyllix works with both. Where one is installed, the search settings it writes - focus keyphrase, synonyms, SEO title and meta description - go straight into that plugin's own fields. With neither installed, Phyllix keeps its own copy so the work is not lost if you add one later.

== Screenshots ==

1. The cockpit - what Phyllix is working on and what needs your decision
2. Ideas, scored and waiting for your approval
3. A draft article with its SEO and readability review
4. Improve pages - the plan for a page, shown before anything is written
5. Results - how your published articles are actually doing in Google
6. Site health - technical problems found on your pages, with fixes

== Changelog ==

= 1.3.0 =
* An already-paying licence's "Upgrade to X" now actually upgrades in place instead of sending you to a subscription-management page with no way to change plan on it — it lands on a short confirmation showing the exact charge (based on articles you haven't used yet this cycle, not calendar days) before anything is charged. Tiers below your current one now offer a plain "Move to X" downgrade — no charge now, takes effect at your next renewal, current plan stays active until then.

= 1.2.0 =
* Upgrade buttons on the plan comparison table now link straight to checkout for the tier you clicked, or to your subscription-management portal if you're already on a paid plan — no need to find the right tier on a separate pricing page yourself.

= 1.1.0 =
* Fixed a mix-up where one "geography" field was being asked to do two different jobs at once — the single, big-picture market AI Visibility builds its questions around, versus the actual list of specific areas Service Areas and local-content ideas need. These are now two separate fields, so listing several towns no longer makes AI Visibility fixate every question on whichever one happened to be listed first.

= 1.0.6 =
* When the business profile comes back from a read with a required section still blank, Phyllix now derives a starting answer from a closely related section that was filled in (for example, "services" from "what we do") instead of leaving Ideas, Competitors, Research and Keywords stalled until the gap is noticed and filled in by hand. Always marked as a low-confidence starting point, and never overwrites a section you've already edited yourself.

= 1.0.5 =
* Setting up "Win enquiries" destinations now checks whether your own contact or quote page already publishes a phone number, email, or WhatsApp link, and pre-fills the form with what it finds — still fully editable, and nothing is saved until you press Save.

= 1.0.4 =
* Competitor discovery now runs in the background instead of blocking the request on up to 8 web searches, avoiding the "kept getting killed mid-run" failure some hosts hit on this step — the same background pattern already used for writing articles and improving pages.

= 1.0.3 =
* Every "business profile is incomplete" message — on the cockpit, and wherever Ideas, Competitors, Research, Keywords, local content or Service Areas refuse to run without it — now names exactly which section is still empty, instead of a generic "it's incomplete" that sent owners hunting through the whole profile page to find the gap themselves.

= 1.0.2 =
* Plugin Check round 2: fixed a missed unescaped post ID in the Search pages table's Edit button, and restructured the "Win enquiries" call-to-action card to echo directly instead of being built as a returned string — the returned-string pattern (safe internally, but flagged regardless since the card also has to render the site owner's own live page content through wp_kses_post(), which a fixed admin-chrome allowlist would have stripped) was the plugin's last remaining OutputNotEscaped error.

= 1.0.1 =
* Plugin Check hardening: fixed 4 leftover text-domain mismatches, added explicit versions to two registered stylesheets, and re-verified every internally-built HTML fragment (score cards, result rows, sparkline charts, search snippets) with wp_kses() at the point it is output, plus inline int-casts on numeric values, so escaping is checked at the actual output call rather than relied on from where a value was first computed.

= 1.0.0 =
* Initial release.

