[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDZZ2SY07ZOkQ28S0m-L_Ubb80z04f3V9QjLt2-c4aF8":3},{"slug":4,"display_name":5,"profile_url":6,"plugin_count":7,"total_installs":8,"avg_security_score":9,"avg_patch_time_days":10,"trust_score":11,"computed_at":12,"plugins":13},"thiagoqvaz","Global AI","https:\u002F\u002Fprofiles.wordpress.org\u002Fthiagoqvaz\u002F",2,0,100,30,94,"2026-08-29T05:17:20.840Z",[14,35],{"slug":15,"name":16,"version":17,"author":5,"author_profile":6,"description":18,"short_description":19,"active_installs":8,"downloaded":20,"rating":8,"num_ratings":8,"last_updated":21,"tested_up_to":22,"requires_at_least":23,"requires_php":24,"tags":25,"homepage":31,"download_link":32,"security_score":9,"vuln_count":8,"unpatched_count":8,"last_vuln_date":33,"fetched_at":34},"global-ai-chat","Global AI Chat","3.6.17","\u003Cp>\u003Cstrong>Global AI Chat puts a helpful AI assistant on your website that talks to your visitors 24\u002F7.\u003C\u002Fstrong> It welcomes people, answers their questions in plain language, points them to the right page, and quietly turns those conversations into leads — so you capture interest even while you sleep.\u003C\u002Fp>\n\u003Cp>It runs on OpenAI’s models using \u003Cem>your own\u003C\u002Fem> OpenAI key, so you stay in control and OpenAI bills you directly for what you use. No middle-man, no monthly plugin fee.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Everything here is free and fully functional\u003C\u002Fstrong> — no trials, no locked buttons, no time limits, no “upgrade to continue”.\u003C\u002Fp>\n\u003Ch4>Why you’ll like it\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Up and running in minutes\u003C\u002Fstrong> — paste your OpenAI key, pick a personality (Support, Sales\u002FSDR or FAQ), and you’re live.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Looks like part of your brand\u003C\u002Fstrong> — customise colours, icon, position and the welcome message.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Turns chats into leads\u003C\u002Fstrong> — the assistant naturally collects name, email, phone, company and any custom field you want, and saves them for you.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Works everywhere you build\u003C\u002Fstrong> — a floating widget, the \u003Ccode>[growthai_chat]\u003C\u002Fcode> shortcode, plus blocks for Gutenberg, Elementor, Divi, Beaver Builder and WPBakery.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Speaks your visitor’s language\u003C\u002Fstrong> — automatically replies in the visitor’s browser language.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Knows your content\u003C\u002Fstrong> — upload documents so the assistant answers from your own material, not guesses.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy-friendly\u003C\u002Fstrong> — optional cookie-consent banner and a one-click “delete all my data on uninstall” switch. Your conversations stay in your own database.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Go further with Global AI Chat Pro\u003C\u002Fh4>\n\u003Cp>When you’re ready to scale, the optional \u003Cstrong>Global AI Chat Pro\u003C\u002Fstrong> add-on builds right on top of this free plugin. It’s a separate download — learn more at https:\u002F\u002Fglobalai.software\u002Fplugin-global-ai-chat. Install it and everything you already set up keeps working; remove it and the free plugin carries on exactly as before. Nothing to migrate, nothing to lose.\u003C\u002Fp>\n\u003Cp>Pro unlocks the features businesses ask for most:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Live human takeover\u003C\u002Fstrong> — jump into any conversation from the \u003Cstrong>iOS & Android app\u003C\u002Fstrong> and reply as a real person, with push notifications the moment a visitor needs you.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One app for all your sites\u003C\u002Fstrong> — the mobile app manages \u003Cstrong>multiple WordPress sites from a single login\u003C\u002Fstrong>, so agencies and multi-brand teams handle every conversation in one place.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Voice calls\u003C\u002Fstrong> — let a visitor start a \u003Cstrong>voice call\u003C\u002Fstrong> with your team straight from the chat, answered live in the app.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Unlimited agents\u003C\u002Fstrong> — run separate assistants for sales, support, FAQ and more, each with its own prompt, look and knowledge.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No OpenAI key needed\u003C\u002Fstrong> — switch to managed AI billed by simple token packs, with access to top models — perfect if you’d rather not manage an OpenAI account.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto-sync your whole site\u003C\u002Fstrong> — pages, posts and WooCommerce products are indexed automatically so the assistant always answers with up-to-date info.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI Prompt Generator\u003C\u002Fstrong> — a guided wizard writes a high-quality agent prompt for you in a couple of minutes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Booking built in\u003C\u002Fstrong> — connect Google Calendar and let the assistant schedule meetings.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Send leads anywhere\u003C\u002Fstrong> — outbound webhooks push every captured lead to your CRM or automation tool.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Never miss a lead\u003C\u002Fstrong> — instant email + mobile push the moment someone becomes a lead.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>White-label\u003C\u002Fstrong> — remove the “Powered by” badge and make the widget fully your own.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One-click auto-updates\u003C\u002Fstrong> and \u003Cstrong>conversation analytics\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>See the screenshots below for a look at both the free widget and the Pro features.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin relies on \u003Cstrong>one\u003C\u002Fstrong> third-party service: the OpenAI API. No other external endpoint is contacted by the free plugin.\u003C\u002Fp>\n\u003Ch4>OpenAI API (required)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>What it is:\u003C\u002Fstrong> OpenAI provides the language model that generates chat replies and, when you upload knowledge-base documents, runs the file search against them.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>What is sent:\u003C\u002Fstrong> Every chat message the visitor submits, plus the system prompt your agent is configured with, is sent to \u003Ccode>https:\u002F\u002Fapi.openai.com\u002Fv1\u002Fresponses\u003C\u002Fcode> using your own API key. When you upload training documents, the file bytes are sent to \u003Ccode>https:\u002F\u002Fapi.openai.com\u002Fv1\u002Ffiles\u003C\u002Fcode> and registered with \u003Ccode>https:\u002F\u002Fapi.openai.com\u002Fv1\u002Fvector_stores\u003C\u002Fcode> so the agent can search them.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> On every user message (chat completion) and only when an admin manually uploads\u002Fdeletes a knowledge-base document (vector store).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of service:\u003C\u002Fstrong> https:\u002F\u002Fopenai.com\u002Fpolicies\u002Fterms-of-use\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy policy:\u003C\u002Fstrong> https:\u002F\u002Fopenai.com\u002Fpolicies\u002Fprivacy-policy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Not contacted by this free plugin\u003C\u002Fh4>\n\u003Cp>The companion Pro addon (separate download, not on wp.org) introduces additional endpoints under \u003Ccode>https:\u002F\u002Fsaas.globalai.software\u002F\u003C\u002Fcode> for license verification, managed token billing, mobile-app push notifications, plugin auto-updates, Google Calendar OAuth, outbound webhooks, page\u002Fpost auto-sync, and the AI prompt generator. None of those endpoints are reached from this free plugin’s code — they are documented here only so admins know what changes if they later install the Pro addon.\u003C\u002Fp>\n\u003Ch3>Security\u003C\u002Fh3>\n\u003Ch4>Visitor session token (`session_id`)\u003C\u002Fh4>\n\u003Cp>Every chat conversation is bound to a \u003Ccode>session_id\u003C\u002Fcode> token generated \u003Cstrong>client-side, in the visitor’s browser\u003C\u002Fstrong>, using \u003Ccode>window.crypto.getRandomValues\u003C\u002Fcode> (a 128-bit cryptographically random value rendered as 32 hex characters with the prefix \u003Ccode>gai_\u003C\u002Fcode>). The token is stored in \u003Ccode>localStorage\u003C\u002Fcode> after the visitor accepts the cookie consent banner; without consent, an in-memory ephemeral token is used and discarded when the tab closes.\u003C\u002Fp>\n\u003Cp>The \u003Ccode>session_id\u003C\u002Fcode> is the access key for the chat REST endpoints (\u003Ccode>\u002Fwp-json\u002Fgrowthai\u002Fv1\u002Fchat\u003C\u002Fcode>, \u003Ccode>\u002Fwp-json\u002Fgrowthai\u002Fv1\u002Flive-chat\u002Fpoll\u003C\u002Fcode>). These endpoints are intentionally public (\u003Ccode>permission_callback => __return_true\u003C\u002Fcode>) so that anonymous site visitors can chat without needing a WordPress account — knowing the token is what authorises the request, the same security model used by mainstream chat \u002F support widgets (Crisp, Tawk, Intercom).\u003C\u002Fp>\n\u003Cp>Implications:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>The token is \u003Cstrong>not\u003C\u002Fstrong> derived from the IP, User-Agent, cookies the server sets, or any sequential \u002F predictable scheme. A third party cannot guess another visitor’s token.\u003C\u002Fli>\n\u003Cli>The plugin never logs full \u003Ccode>session_id\u003C\u002Fcode> values in plaintext outside the database row that owns the conversation.\u003C\u002Fli>\n\u003Cli>If the visitor clears their browser storage, the next page load gets a fresh token and a fresh conversation.\u003C\u002Fli>\n\u003Cli>Old browsers without the Web Crypto API fall back to \u003Ccode>Math.random()\u003C\u002Fcode> — a worse entropy source. We surface this in the JS for transparency; if your audience relies on legacy browsers, factor that into your threat model.\u003C\u002Fli>\n\u003C\u002Ful>\n","Add a friendly AI chat assistant to WordPress. It greets visitors, answers questions and captures leads — free, using your own OpenAI key.",273,"2026-06-14T14:47:00.000Z","7.0.2","6.0","7.4",[26,27,28,29,30],"ai","assistant","chat","chatbot","openai","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fglobal-ai-chat.3.6.17.zip",null,"2026-07-22T17:31:50.256Z",{"slug":36,"name":37,"version":38,"author":5,"author_profile":6,"description":39,"short_description":40,"active_installs":8,"downloaded":41,"rating":8,"num_ratings":8,"last_updated":42,"tested_up_to":22,"requires_at_least":43,"requires_php":24,"tags":44,"homepage":50,"download_link":51,"security_score":9,"vuln_count":8,"unpatched_count":8,"last_vuln_date":33,"fetched_at":34},"global-ai-gallery","Global AI Gallery","1.3.6","\u003Cp>Global AI Gallery creates clean, functional galleries on any WordPress site:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Dedicated Custom Post Types\u003C\u002Fstrong> for Galleries and Albums\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Responsive Grid layout\u003C\u002Fstrong> (1–6 configurable columns)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PhotoSwipe 5 lightbox\u003C\u002Fstrong> with keyboard, arrow and touch swipe navigation\u003C\u002Fli>\n\u003Cli>\u003Cstrong>YouTube support\u003C\u002Fstrong> — paste a URL and the plugin handles the thumbnail and playback\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Native Elementor widget\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Schema.org ImageGallery\u003C\u002Fstrong> markup for SEO\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Accessible\u003C\u002Fstrong> — ARIA, focus trap, screen-reader friendly\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-language ready\u003C\u002Fstrong> — Polylang\u002FWPML compatible, .pot file included\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No external dependencies\u003C\u002Fstrong> — everything is vendored, no CDN calls\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Pro Version\u003C\u002Fh4>\n\u003Cp>The Pro add-on (sold separately) adds Masonry, Justified and Carousel layouts, Vimeo and self-hosted videos, premium lightbox with zoom\u002Fshare\u002Fdownload, animated filters, interactive albums, and premium templates. Learn more at https:\u002F\u002Fglobalai.software\u002Fplugin-global-ai-gallery\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin connects to YouTube to display video content that the site administrator has chosen to add to a gallery or album. No data is sent unless an admin explicitly adds a YouTube URL to a gallery item.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>YouTube thumbnail lookup (i.ytimg.com)\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen a gallery item is a YouTube video, the plugin requests the thumbnail URL from \u003Ccode>https:\u002F\u002Fi.ytimg.com\u002Fvi\u002F\u003Cvideo-id>\u002Fmaxresdefault.jpg\u003C\u002Fcode> (with a fallback to \u003Ccode>hqdefault.jpg\u003C\u002Fcode>) using \u003Ccode>wp_remote_head()\u003C\u002Fcode>. Only the video ID is sent in the URL. The result (a URL string) is cached locally for 24 hours via WordPress transients to avoid repeat requests.\u003Cbr \u002F>\n– Data sent: the YouTube video ID that the administrator added.\u003Cbr \u002F>\n– When: the first time a gallery containing that video is rendered, and every 24 hours after the cache expires.\u003Cbr \u002F>\n– Service provider: Google LLC.\u003Cbr \u002F>\n– Terms of service: https:\u002F\u002Fwww.youtube.com\u002Ft\u002Fterms\u003Cbr \u002F>\n– Privacy policy: https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fp>\n\u003Cp>\u003Cstrong>YouTube embed iframe (youtube.com or youtube-nocookie.com)\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen a visitor opens a YouTube video in the lightbox, the browser loads the embed from \u003Ccode>https:\u002F\u002Fwww.youtube.com\u002Fembed\u002F\u003Cvideo-id>\u003C\u002Fcode> — or, if the “Use youtube-nocookie.com” setting is enabled (Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Global AI Gallery), from \u003Ccode>https:\u002F\u002Fwww.youtube-nocookie.com\u002Fembed\u002F\u003Cvideo-id>\u003C\u002Fcode>. This is a standard browser iframe; the plugin does not perform any server-side request.\u003Cbr \u002F>\n– Data sent: the YouTube video ID, plus whatever YouTube itself collects from the visitor’s browser (User-Agent, Referer, cookies — unless the cookieless host is used).\u003Cbr \u002F>\n– When: only when a visitor actually plays a YouTube video on the page.\u003Cbr \u002F>\n– Service provider: Google LLC.\u003Cbr \u002F>\n– Terms and privacy: same links as above.\u003C\u002Fp>\n\u003Cp>The plugin does not contact any other external service. No telemetry, analytics, license servers, or auto-update endpoints are called by this Free version.\u003C\u002Fp>\n\u003Ch3>Security\u003C\u002Fh3>\n\u003Cp>This plugin exposes one public REST endpoint to support deferred rendering of galleries from the frontend without requiring a logged-in user:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>GET \u002Fwp-json\u002Fglobal-ai-gallery\u002Fv1\u002Frender\u002F\u003Cid> — returns the HTML for a single published gallery. The endpoint declares `permission_callback => __return_true` (public) because a published gallery is public content by definition, exactly like the post that embeds it. The handler then enforces a real read-permission check before rendering anything:\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>1. \u003Ccode>\u003Cid>\u003C\u002Fcode> is sanitised with \u003Ccode>absint()\u003C\u002Fcode> and validated to be a positive integer before reaching the handler.\u003Cbr \u002F>\n2. The post must exist and be of the \u003Ccode>gawpg_gallery\u003C\u002Fcode> custom post type; otherwise a 404 \u003Ccode>WP_Error\u003C\u002Fcode> is returned.\u003Cbr \u002F>\n3. Read access is checked the same way WordPress core checks it (\u003Ccode>WP_REST_Posts_Controller::check_read_permission()\u003C\u002Fcode>): a \u003Ccode>publish\u003C\u002Fcode> gallery is readable by anyone, but any non-public status (draft, pending, private, future, trash) only renders when the current user actually has read access to that specific post (\u003Ccode>current_user_can( 'read_post', $id )\u003C\u002Fcode>) — otherwise 404.\u003Cbr \u002F>\n4. Password-protected galleries are never rendered without the password. \u003Ccode>post_password_required()\u003C\u002Fcode> is honoured (respecting the \u003Ccode>wp-postpass\u003C\u002Fcode> cookie), returning a 401\u002F403 \u003Ccode>WP_Error\u003C\u002Fcode> when the password has not been entered.\u003Cbr \u002F>\n5. The endpoint only returns rendered HTML; it never reads or writes user data, options, transients, or any other server state.\u003C\u002Fp>\n\u003Cp>This is the same content the visitor can already see by visiting the gallery’s public page or any post that embeds it via the shortcode, so making the endpoint authenticated would add no privacy or security benefit.\u003C\u002Fp>\n","Image and video gallery with premium PhotoSwipe lightbox and a native Elementor widget. Accessible, SEO-ready, YouTube support.",208,"2026-07-17T10:14:00.000Z","6.2",[45,46,47,48,49],"album","elementor","gallery","lightbox","photoswipe","https:\u002F\u002Fglobalai.software\u002Fplugin-global-ai-gallery","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fglobal-ai-gallery.1.3.6.zip"]