TrackSure Cloud – Server-Side Tracking, Meta CAPI & GA4 for WooCommerce
★ What Makes TrackSure Different TrackSure is the only free WordPress plugin that combines server-side conversion tracking (Meta CAPI + GA4 Measurement Protocol) with a complete first-party analytics platform — no GTM required, no external cloud, no monthly fees. Unlike PixelYourSite, TrackSure includes a full analytics dashboard — user journeys, funnels, and attribution — at no extra cost. Unlike GTM-based solutions, it needs no server container, no custom subdomain, and no external hosting. 42% of internet users run ad blockers, and iOS 14+ reduced Meta Pixel reported conversions by 30–40% for most advertisers. TrackSure’s server-side tracking recovers conversions from both, sending events directly from your WordPress server to Meta, GA4, TikTok, Pinterest, and Google Ads — bypassing browser limitations entirely. Setup takes under 3 minutes: paste your Meta Pixel ID and Access Token, and TrackSure handles the browser pixel, Conversion API, event deduplication, and Advanced Matching for maximum Event Match Quality (EMQ). For WooCommerce Store Owners If you run WooCommerce and Meta or Google Ads, TrackSure connects your real purchase data directly to your ad platform — bypassing iOS restrictions, ad blockers, and Safari cookie limits. Higher Event Match Quality (EMQ) means better optimization and lower cost-per-acquisition. For Marketers & Agencies Get user journey tracking, funnel visualization, multi-touch attribution, and traffic source analysis without paying $500/month for Amplitude or Mixpanel. Five attribution models and an assisted conversions report show exactly which channels drive revenue. Manage multiple client sites from the same plugin. For Developers TrackSure exposes a JavaScript API (window.TrackSure.track()), a PHP API, and WordPress hooks (tracksure_filter_event_data, tracksure_conversion_recorded) for custom event tracking with full server-side control — no dependency on browser JavaScript. window.TrackSure.track('button_click', { button_name: 'Download PDF' }); Documentation | Support | GitHub | Get Pro What TrackSure Does Server-Side Conversion Tracking (CAPI) Meta Conversion API — send purchase, view content, add to cart, checkout, and page view events server-to-server Google Analytics 4 Measurement Protocol — server-side GA4 event forwarding TikTok Events API and Pinterest Conversion API (Pro) Automatic browser + server event deduplication — each event gets a unique ID shared between client and server so platforms count it once First-Party Analytics Dashboard All analytics data stored in your WordPress database — you own every byte Automatic traffic source detection — organic search (Google, Bing, DuckDuckGo), social media (Facebook, Instagram, LinkedIn, TikTok), email, referrals, AI chatbots (ChatGPT, Claude, Perplexity), and direct — identified without UTM tags Session-based user journeys with 30-day attribution window (configurable) — complete path from first visit to conversion, including every touchpoint across multiple sessions Five attribution models: first-touch, last-touch, linear, time-decay, position-based Assisted conversion reporting — see which channels helped even without getting final credit Real-time visitors — see who is on your site now and what pages they’re viewing Goals, Funnels & Conversion Tracking Custom conversion goals for form submissions, purchases, downloads, video views, or any event Funnel visualization — see where visitors drop off in your checkout or signup flow Goal completion rates with trend analysis Revenue attribution — connect each sale to its traffic source, campaign, and touchpoint eCommerce Conversion Tracking Auto-tracks the full purchase funnel: product view → add to cart → checkout → purchase Works with WooCommerce and FluentCart (Free), Easy Digital Downloads, SureCart, Cartflow, and MemberPress (Pro) Revenue attribution — connect each sale to its traffic source and campaign Checkout funnel visualization with drop-off rates at each step Privacy & Compliance GDPR and CCPA ready with built-in consent manager support (Cookiebot, CookieYes, OneTrust, and more) Cookieless tracking option (uses localStorage instead of cookies — no consent banner required in some jurisdictions) IP anonymization, Do Not Track (DNT) support, and WordPress privacy tools integration No data leaves your server unless you enable an ad platform destination — with the single exception of the optional IP geolocation lookup, which can be switched off in Settings → Privacy Who Is TrackSure For? WooCommerce & FluentCart store owners running paid ads who need more accurate conversion data for Meta, Google Ads, and other platforms Bloggers & content creators who want to see which posts bring the most traffic, engagement, and conversions Small business owners who need simple, privacy-friendly analytics without Google Analytics complexity Digital marketers managing ad campaigns who want user journey tracking, funnel visualization, and multi-touch attribution Agencies & freelancers who need analytics and conversion tracking across client sites (Pro includes white label) Privacy-focused site owners who want GDPR-compliant analytics without sending data to external services Developers who need JavaScript and PHP APIs for custom event tracking with WordPress hooks Free vs Pro Free includes everything you need for analytics and conversion tracking: First-party analytics dashboard with user journeys, funnels, goals, and attribution Real-time visitor tracking Meta Pixel + Conversion API (CAPI) server-side tracking Google Analytics 4 + Measurement Protocol server-side tracking WooCommerce and FluentCart automatic ecommerce tracking All form plugins (Contact Form 7, Gravity Forms, WPForms, Fluent Forms, Elementor Forms) All page builders (Elementor, Divi, Beaver Builder, Gutenberg, WPBakery, Oxygen, Bricks) Five attribution models with assisted conversion reports Consent management integration Unlimited events and sessions Pro adds advanced ad platforms and ecommerce integrations: 14+ ad platform destinations: TikTok, Pinterest, LinkedIn, Snapchat, Reddit, Google Ads, Microsoft Ads, Twitter/X, Taboola, Outbrain, and more Advanced ecommerce: Easy Digital Downloads, SureCart, Cartflow, MemberPress, LearnDash, Amelia, WooCommerce Bookings, GiveWP Cart abandonment emails, session recording, heatmaps, cohort analysis, predictive analytics Email marketing sync (Mailchimp, ActiveCampaign, Klaviyo) White label for agencies Priority support with 24-hour response time Compare Plans Integrations eCommerce: WooCommerce, FluentCart, Easy Digital Downloads (Pro), SureCart (Pro), Cartflow (Pro), MemberPress (Pro) Forms: Contact Form 7, Gravity Forms, WPForms, Fluent Forms, Elementor Forms Builders: Elementor, Divi, Beaver Builder, Gutenberg, WPBakery, Oxygen, Bricks Ad Platforms: Meta (Facebook/Instagram), Google Analytics 4, Google Ads (Pro), TikTok (Pro), Pinterest (Pro), LinkedIn (Pro), Snapchat (Pro), Microsoft Ads (Pro), Reddit (Pro), Twitter/X (Pro), Taboola (Pro), Outbrain (Pro) Consent: Cookiebot, CookieYes, OneTrust, and custom consent filters Getting Started Install and activate TrackSure Cloud from the WordPress plugin directory Visit TrackSure → Settings to review tracking and privacy options (Optional) Add your Meta Pixel ID + Access Token or GA4 Measurement ID for server-side conversion tracking Go to TrackSure → Overview — analytics data starts appearing after 1 hour External services This plugin connects to external third-party services to provide its functionality. Below is a complete list of all external services used, when they are called, what data is transmitted, and links to their terms of service and privacy policies. When You Enable Meta Pixel / Conversion API: Service: Meta (Facebook) Graph API Purpose: Send conversion events (purchases, add-to-cart, page views) to Facebook for ad optimization What data is sent: Event name, timestamp, hashed user email/phone (if available), product SKU, revenue, IP address, user agent, pixel ID When it’s sent: Automatically when a tracked event occurs (product view, purchase, etc.) and Meta destination is enabled in settings Service provider: Meta Platforms, Inc. Terms of Service: https://www.facebook.com/legal/terms Privacy Policy: https://www.facebook.com/privacy/policy Data Processing Agreement: https://www.facebook.com/legal/terms/dataprocessing When You Enable Google Analytics 4: Service: Google Analytics 4 Measurement Protocol Purpose: Send analytics events to Google Analytics for website traffic analysis What data is sent: Event name, page URL, referrer, session ID, client ID, IP address, user agent, device information When it’s sent: Automatically when page views or custom events occur and GA4 destination is enabled in settings Service provider: Google LLC Terms of Service: https://marketingplatform.google.com/about/analytics/terms/us/ Privacy Policy: https://policies.google.com/privacy When Loading Google Tag Manager Script (If Enabled): Service: Google Tag Manager CDN Purpose: Load gtag.js library for browser-side Google Analytics tracking What data is sent: Standard HTTP request data (IP address, user agent, referrer) when loading the script When it’s sent: On every page load when GA4 browser tracking is enabled Service provider: Google LLC Script URL: https://www.googletagmanager.com/gtag/js Terms of Service: https://marketingplatform.google.com/about/analytics/terms/us/ Privacy Policy: https://policies.google.com/privacy When Loading Facebook Pixel Script (If Enabled): Service: Facebook Connect CDN Purpose: Load fbevents.js library for browser-side Facebook Pixel tracking What data is sent: Standard HTTP request data (IP address, user agent, referrer) when loading the script When it’s sent: On every page load when Meta Pixel browser tracking is enabled Service provider: Meta Platforms, Inc. Script URL: https://connect.facebook.net/en_US/fbevents.js Terms of Service: https://www.facebook.com/legal/terms Privacy Policy: https://www.facebook.com/privacy/policy Cloudflare IP Detection (Always Active): Service: Cloudflare IP Ranges API Purpose: Fetch current list of Cloudflare proxy IP addresses to accurately detect real visitor IPs behind Cloudflare CDN. A bundled static list is included as fallback. What data is sent: Standard HTTP request headers only (no user data transmitted) When it’s sent: Once per day (cached for 24 hours) to refresh the Cloudflare IP list. The plugin includes a bundled fallback list and works without this request. Service provider: Cloudflare, Inc. API URLs: https://www.cloudflare.com/ips-v4 and https://www.cloudflare.com/ips-v6 Terms of Service: https://www.cloudflare.com/website-terms/ Privacy Policy: https://www.cloudflare.com/privacypolicy/ IP Geolocation (When Tracking Is Enabled): Service: ipapi.co (primary), ip-api.com (secondary fallback), WordPress.com Geo API (tertiary fallback) Purpose: Determine the country, region, and city of visitors based on their IP address for geographic analytics reporting What data is sent: The visitor’s IP address is sent to one of the geolocation providers. No other user data is transmitted. When it’s sent: When a new visitor session is recorded and the IP has not been looked up recently. Results are cached for 24 hours per IP. Service providers and policies: ipapi.co (primary) – https://ipapi.co/privacy/ and https://ipapi.co/terms/ ip-api.com (fallback) – https://ip-api.com/docs/legal WordPress.com Geo API (fallback) – https://automattic.com/privacy/ and https://wordpress.com/tos/ Local sources are tried first: if your site is behind Cloudflare, has the PHP GeoIP extension, or has a local MaxMind database, the country is read from those and no address leaves your server. Transport: ipapi.co and the WordPress.com Geo API are contacted over HTTPS. ip-api.com does not offer HTTPS on its free tier, so that fallback is contacted over plain HTTP — it is only reached if ipapi.co has already failed. Turning it off: Settings → Privacy → “Look up visitor location remotely”. Turning it off keeps the local sources above and stops any address being sent to a third party. Developers can also decide per request with the tracksure_remote_geolocation_enabled filter. Important Notes: Destinations are opt-in: TrackSure does not send anything to an advertising or analytics platform — Meta, Google Analytics, or any other destination — unless you enable and configure it in TrackSure Settings → Destinations. IP geolocation, described above, is the one exception: it runs while tracking is enabled and is not tied to any destination. Consent-aware: If you use a cookie consent plugin (Cookiebot, CookieYes, etc.), TrackSure will respect user consent choices and only fire pixels after consent is granted. First-party analytics: TrackSure’s core analytics features store all data in your WordPress database. Nothing is sent to an analytics platform unless you enable Google Analytics 4 or another destination. The one external call made without a destination being enabled is the IP geolocation lookup described above, which can be switched off in Settings → Privacy. You control the data: You choose which platforms to enable, what events to track, and what user data to include (emails, phones, etc.). For more information about data privacy and compliance, see the Privacy & GDPR Compliance section below. Source Code & Build Instructions The admin interface is built with React 18 and TypeScript, compiled with Webpack 5. The compiled files in admin/dist/ are generated from the source code in admin/src/. Full source code is available on GitHub: https://github.com/tracksure-cloud/tracksure To build from source: Navigate to the admin/ directory Run npm install to install dependencies Run npm run build for a production build, or npm run dev for development mode with watch Build tools used: Node.js (v18+) npm Webpack 5 (config: admin/webpack.config.js) TypeScript 5 (config: admin/tsconfig.json) ts-loader for TypeScript compilation Key source directories: admin/src/ — React/TypeScript source code (pages, components, contexts, hooks) admin/dist/ — Compiled production JavaScript (generated by Webpack) assets/js/ — Frontend tracking scripts (non-compiled, human-readable) includes/ — PHP backend (non-compiled, human-readable) Privacy Policy TrackSure stores the following data in your WordPress database: Tracking Data (90-day retention): – Page URLs visited – Referrer URLs – UTM campaign parameters – Device type (desktop/mobile/tablet) – Browser and OS information (user agent) – IP address (can be anonymized) – Session duration and engagement metrics For E-commerce (if using WooCommerce/FluentCart/EDD/SureCart): – Product views – Cart actions – Order completion (order ID, total, items) – Customer email and phone (hashed when sent to Meta/GA4) External Data Sharing (Optional): TrackSure stores all analytics data locally in your WordPress database. No data is sent to an ad platform or analytics service unless you enable that integration. The one exception is the IP geolocation lookup used for geographic reporting, described under “External services” above — it is not tied to any integration, and it can be switched off in Settings → Privacy. Privacy Controls: – IP Anonymization: Available in Settings → Privacy. Default is off for accurate geo reporting; enable it for GDPR compliance. – Cookieless Mode: Uses localStorage instead of cookies to avoid cookie consent requirements. – Consent Integration: Respects Cookiebot, CookieYes, OneTrust, and custom consent filters. Supported Third-Party Services: TrackSure connects to the following services only when you enable them and provide API credentials. 1. Meta (Facebook/Instagram) – Available in Free & Pro – Method: Server-to-Server via Meta Graph API (CAPI) – Data Sent: Event data (PageView, ViewContent, AddToCart, Checkout, Purchase), Hashed user data (email, phone, IP, User Agent) – Purpose: Ad optimization and attribution 2. Google Analytics 4 (GA4) – Available in Free & Pro – Method: Server-to-Server via Measurement Protocol – Data Sent: Event parameters, Client ID, User Agent, IP – Purpose: Analytics reporting 3. Pro-Only Integrations (Add-ons) – Google Ads: Sends offline conversion adjustments via Google Ads API. – TikTok: Sends web events via TikTok Events API. – Pinterest: Sends conversion events via Pinterest API. – Snapchat: Sends conversion events via Snapchat Conversions API. – Microsoft Ads: Sends offline conversions via Microsoft Ads API. – LinkedIn: Sends conversion events via LinkedIn CAPI. You must obtain user consent before enabling these destinations (GDPR/CCPA requirement). Your Responsibilities: Disclose TrackSure’s tracking in your privacy policy Obtain consent before tracking (if required by law) Configure data retention periods appropriately Enable IP anonymization if required Data Deletion: Users can request data deletion via WordPress Privacy Tools or TrackSure Settings → Privacy. Support Free Support: Documentation [Community …
Top keywords
- data35×1.45%
- analytics33×1.36%
- tracking28×1.16%
- google27×1.11%
- privacy27×1.11%
- tracksure27×1.11%
- com24×0.99%
- conversion23×0.95%
- https23×0.95%
- ip23×0.95%
- pro22×0.91%
- api21×0.87%
VigIA – AI Visibility, Analytics & Control
VigIA (Spanish for “lookout” or “watchman”, incorporating “IA” – Spanish for “AI”) is a complete AI visibility toolkit for WordPress. Monitor 60+ AI crawlers, control access to your content, and optimize how AI systems discover and understand your site. What does VigIA do? Scores your AI visibility with a 100-point analyzer covering 20 checks across 5 categories Tracks AI crawlers visiting your site (GPTBot, ClaudeBot, PerplexityBot, and 60+ others) Provides detailed analytics with advanced filters, server-side pagination, and exportable reports with metadata banner Blocks unwanted crawlers via PHP (403 response) Manages robots.txt rules for AI crawlers with compliance monitoring Sends email alerts about crawler activity (daily, weekly, or monthly) Generates llms.txt files to help AI systems understand your site Serves markdown endpoints for posts, pages, taxonomy archives (categories, tags, WooCommerce product categories, custom taxonomies) and WooCommerce products with schema-like data Generates JSON-LD structured data with Site Identity and AI Discovery signals Exposes abilities for AI agents and automation tools (WordPress 6.9+) Key Features AI Visibility Analyzer * 100-point scoring system with letter grades (A+ to F) * 20 individual checks across 5 categories * Access & AI Discovery (37 pts): robots.txt, AI bot directives, Content Signals, llms.txt, sitemap, RSS feed * Structured Data & Semantic Context (25 pts): JSON-LD schemas, Open Graph, Twitter Cards, meta description, canonical URL * Content Structure & Readability (20 pts): heading hierarchy, semantic HTML5, image alt text, content/HTML ratio * AI Interaction & Distribution (8 pts): markdown delivery, AI share buttons * Access Performance (10 pts): TTFB measurement * Smart recommendations with direct links to VigIA features and plugin suggestions * Analyze any page on your site with URL autocomplete selector * Results cached for 24 hours with manual re-analyze option Analytics Dashboard * Total visits, unique crawlers, and pages crawled statistics * Timeline chart with daily breakdown * Category distribution (AI Training, AI Search, AI Assistant, Data Scraper) * Top crawlers and most crawled pages tables with paginated navigation * Share Buttons & AI-powered Summaries integration: see share button clicks per page * Recent activity log with content type and HTTP status columns (color coded by status family) * Advanced filters: multi-select crawler picker, content type, HTTP status code, and configurable date range * Server-side pagination with four-button pager (first, previous, next, last) — operates over the full database, not just the latest 500 rows * Period comparison functionality * CSV export with a metadata banner (site name, site URL, export type, date range, export timestamp, applied filters) * “Export filtered CSV” button that downloads exactly what the active filters return, with vigia-filtered-YYYY-MM-DD.csv filename * Content type detection distinguishes Home, Post, Page, Product, custom CPTs, Category archive, Tag archive, Date/Author archive, Feed, Sitemap, REST API, File, Admin / login attempts (/wp-admin, /wp-login.php), WordPress system (admin-ajax, xmlrpc, wp-cron, wp-comments-post), 404 Not found, and Other Crawler Blocking * Block crawlers via PHP with 403 Forbidden response * Quick block dropdown in analytics dashboard * Manage blocks from Extras page * Works on any server (Apache, Nginx, LiteSpeed, etc.) Robots.txt Management * Add Disallow rules for AI crawlers * Visual preview of your robots.txt * Compliance monitoring: see which crawlers ignore your rules * One-click blocking for non-compliant crawlers * Works with both physical and virtual robots.txt Email Alerts * Daily, weekly, or monthly reports * Three detail levels: Minimal, Normal, Complete * Non-compliant crawler warnings * Activity comparison with previous period Markdown for Agents * Serve posts, pages and any public post type as optimized markdown for AI agents * Serve taxonomy archive pages (categories, tags, WooCommerce product categories, custom taxonomies) as markdown — disabled by default, opt in per taxonomy * Dedicated .md URL endpoints (e.g., /your-post.md, /category/news.md, /product-category/electronics.md) * Accept: text/markdown content negotiation on posts and taxonomy archive pages * Discoverability via Link HTTP headers and HTML tags * YAML frontmatter for posts: title, date, modified, author, image, categories, tags, post type, lang * YAML frontmatter for taxonomy terms: title, description, url, type, taxonomy, parent, count, image (term meta), lang * WooCommerce product frontmatter adds schema-like fields: sku, product_type, price, regular_price, sale_price, currency, availability, stock_quantity, rating, rating_count, review_count * Taxonomy term body includes the term description (rendered through the_content), the list of direct child terms in hierarchical taxonomies, and an excerpt of the latest posts/products assigned to the term * Product listings inside product_cat archives include an inline summary with formatted price, “was X” on sale items, star rating and out-of-stock flag * Respects blocking rules (blocked crawlers get 403) and LLMs.txt exclusion filters * Per-term noindex detection from Yoast SEO, Rank Math, All in One SEO and SEOPress * Analytics integration: tracks markdown requests per crawler * X-Markdown-Tokens response header * Filters: vigia_markdown_post_eligible, vigia_markdown_term_eligible, vigia_markdown_term_posts_limit * Follows the Cloudflare Markdown for Agents standard LLMs.txt Generator * Select content by post type with one click * Filter by taxonomies (categories, tags, custom) * Manual include/exclude with AJAX search * Exclude by URL patterns (wildcards supported) * SEO plugin integration (auto-exclude noindex content) * Auto-regeneration (daily, weekly, monthly) * Robots.txt integration (add llms.txt and llms-full.txt references) * Generate llms.txt and llms-full.txt files * Full content or excerpt mode * Compatible with Yoast SEO, Rank Math, All in One SEO, SEOPress, The SEO Framework, and Native SEO NoIndexer JSON-LD Structured Data * Generate WebSite and Organization/Person schema for site identity * AI Discovery: ReadAction pointers to llms.txt, llms-full.txt, and Markdown for Agents endpoints * Social profiles and sameAs links for brand identity across the web * SearchAction for Google sitelinks search box * Media library integration for logo selection * SEO plugin conflict detection (Yoast, Rank Math, AIOSEO, SEOPress, The SEO Framework) * Choose output page (front page or any published page) * Live JSON-LD preview with real-time updates * Smart integration with LLMs.txt and Markdown for Agents features Supported AI Crawlers VigIA monitors 60+ AI crawlers including: OpenAI: GPTBot, OAI-SearchBot, OAI-AdsBot, ChatGPT-User Anthropic: ClaudeBot, Claude-SearchBot, Claude-User, Claude-Code Google: Google-Extended, GoogleOther, Gemini-Deep-Research, Google-NotebookLM Perplexity: PerplexityBot, Perplexity-User Meta: Meta-ExternalAgent, FacebookBot, Meta-WebIndexer Amazon: Amazonbot, Amzn-SearchBot, bedrockbot Mistral: MistralAI-User, MistralAI-Index Microsoft: BingBot ByteDance: Bytespider Apple: Applebot-Extended And many more… Privacy Focused VigIA stores visitor data locally in your WordPress database. No data is sent to external servers. Abilities API VigIA is one of the first WordPress plugins to implement the Abilities API introduced in WordPress 6.9. This API allows AI agents, automation tools, and external systems to discover and interact with VigIA’s functionality in a standardized, secure way. What are Abilities? Abilities are self-contained units of functionality that VigIA exposes through WordPress’s central registry. Each ability has defined inputs, outputs, and permissions, making it easy for automation tools to understand and use them. Available Abilities VigIA registers the following abilities: Analytics vigia/get-crawler-stats – Get statistics about AI crawler visits (total visits, unique crawlers, pages crawled) vigia/get-top-crawlers – Get a ranked list of most active AI crawlers vigia/get-top-pages – Get the most crawled pages on your site Blocking vigia/get-blocked-items – List all blocked crawlers and IP addresses vigia/block-crawler – Block a crawler by User-Agent pattern vigia/unblock-crawler – Remove an existing block Robots.txt vigia/get-robots-rules – Get current AI crawler rules in robots.txt vigia/add-robots-disallow – Add a Disallow directive for a crawler vigia/remove-robots-rule – Remove a robots.txt rule Use Cases Automated monitoring: AI agents can query crawler statistics and alert you to anomalies Reactive blocking: Automation tools can block crawlers that repeatedly ignore robots.txt External dashboards: Aggregate data from multiple WordPress sites with VigIA installed WP-CLI integration: Future command-line access through the Abilities API n8n / Make workflows: Build custom automation flows using VigIA’s abilities Requirements The Abilities API ships with WordPress 6.9 and later. On older WordPress versions, VigIA works normally but abilities and MCP are not available. MCP Server (Model Context Protocol) VigIA exposes its 9 abilities as native MCP tools to any MCP-compatible client (Claude Code, Cursor, Claude Desktop, Codex CLI, Antigravity, Continue, Cline, Zed and similar) using the official WordPress MCP Adapter. The adapter ships bundled with the plugin, so the MCP endpoint is active right after installation — no Composer step or terminal access required. Requirements WordPress 6.9 or later (provides the Abilities API) Quick connect (recommended) Open VigIA > Extras > MCP and click “Generate password and connection commands”. The plugin creates a dedicated Application Password named VigIA MCP and renders ready-to-paste commands for Claude Code, Cursor, Claude Desktop and a generic block (URL + Authorization header) for any other MCP client. The plain password is shown only once. If you lose it, revoke the entry from the same panel and generate a new one. Endpoint https://your-site.example/wp-json/vigia/v1/mcp The endpoint uses HTTP Basic auth with the WordPress Application Password. The user must have the manage_options capability. Connecting Claude Code Quick Connect builds the full command for you. The shape is: claude mcp add --transport http vigia https://your-site.example/wp-json/vigia/v1/mcp --header "Authorization: Basic BASE64_OF_USER_AND_APP_PASSWORD" Claude Code merges the new entry into its config file automatically — no risk of breaking other servers. Connecting Cursor Save the JSON block from Quick Connect as ~/.cursor/mcp.json. You can also reach this file from inside Cursor at Settings → Cursor Settings → MCP. If the file already exists with other content, see the FAQ. Claude Desktop and other clients Claude Desktop does not speak HTTP MCP, so it needs a small bridge and a config file of its own. Any other client (Codex CLI, Continue, Cline, Antigravity, Zed, or your own) takes the two raw values Quick Connect exposes: the server URL and the Authorization header. Both cases are covered in the FAQ, together with how to merge VigIA into a config file that already exists without losing what is in it. Read-only mode If you only want your AI to consult VigIA (not change anything), enable “Read-only mode” in the MCP tab. While on, write actions (block, unblock, robots changes) return a permission denied error. Read actions (statistics, top crawlers, blocked items, robots rules) keep working. The toggle stores a vigia_mcp_read_only option that hooks into the vigia_can_write_via_abilities filter. Developers can still force read-only from a mu-plugin: add_filter( 'vigia_can_write_via_abilities', '__return_false' ); The mu-plugin filter at the default priority takes precedence over the toggle. Who can reach the endpoint The endpoint requires the capability to manage options, the same one every tool behind it already asked for. The vigia_mcp_transport_capability filter can lower that bar; each tool keeps its own permission check. After connecting Restart your MCP client after adding the server so it picks up the new tools. Then try a few prompts to confirm everything is wired up: “Show me VigIA crawler stats for the last 7 days.” “List the top 5 most crawled pages on this site.” “Add a robots.txt Disallow rule for TestBot and then list the current AI crawler rules.” The third example exercises a read + write + read round-trip, which is the most complete sanity check. Support Need private support or custom development? Do you need one-on-one help, priority troubleshooting, or a custom feature, integration, or tweak built specifically for your site? I offer private support and custom development. Just contact me and tell me what you need. Need help or have suggestions? Official website WordPress support forum YouTube channel Documentation and tutorials Love the plugin? Please leave us a 5-star review and help spread the word! About AyudaWP We are specialists in WordPress security, SEO, AI and performance optimization plugins. We create tools that solve real problems for WordPress site owners while maintaining the highest coding standards and accessibility requirements.