[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1usjpZpN-w9WCxvNgKcTqZz5_HXmxHlSIiyB5gD4Q9M":3},{"slug":4,"display_name":5,"profile_url":6,"plugin_count":7,"total_installs":8,"avg_security_score":9,"avg_patch_time_days":10,"trust_score":11,"computed_at":12,"plugins":13},"xpaysh","xpay✦","https:\u002F\u002Fprofiles.wordpress.org\u002Fxpaysh\u002F",3,10,100,30,94,"2026-08-25T05:58:54.628Z",[14,37,53],{"slug":15,"name":16,"version":17,"author":5,"author_profile":6,"description":18,"short_description":19,"active_installs":8,"downloaded":20,"rating":21,"num_ratings":7,"last_updated":22,"tested_up_to":23,"requires_at_least":24,"requires_php":25,"tags":26,"homepage":32,"download_link":33,"security_score":9,"vuln_count":34,"unpatched_count":34,"last_vuln_date":35,"fetched_at":36},"agentic-commerce-for-woocommerce","Agentic Commerce for WooCommerce","0.6.3","\u003Cp>\u003Cstrong>Your next customer is asking ChatGPT, not Google.\u003C\u002Fstrong> They’re shopping by typing “find me a cordless drill under $80 that ships in 2 days” into a chat box — and quietly walking away from any store the AI can’t see. Right now, that’s most WooCommerce stores.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Agentic Commerce for WooCommerce (by xpay) makes your store visible to ChatGPT, Claude, Gemini and Perplexity\u003C\u002Fstrong> in five minutes flat — no theme changes, no replatforming, no new payment processor. Your existing checkout stays exactly as it is; xpay just makes sure you’re the answer the AI gives.\u003C\u002Fp>\n\u003Cp>📘 \u003Cstrong>Full setup guide with screenshots:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fdocs.xpay.sh\u002Fmerchants\u002Fwoocommerce\" rel=\"nofollow ugc\">docs.xpay.sh\u002Fmerchants\u002Fwoocommerce\u003C\u002Fa>\u003Cbr \u002F>\n🌐 \u003Cstrong>Plugin home:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwww.xpay.sh\u002Fmerchants\u002Fwoocommerce\u002F\" rel=\"nofollow ugc\">www.xpay.sh\u002Fmerchants\u002Fwoocommerce\u002F\u003C\u002Fa>\u003Cbr \u002F>\n🔓 \u003Cstrong>Source on GitHub:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fxpaysh\u002Fagentic-commerce-for-woocommerce\" rel=\"nofollow ugc\">github.com\u002Fxpaysh\u002Fagentic-commerce-for-woocommerce\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>What it does\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Publishes a public, agent-readable product feed\u003C\u002Fstrong> — your full catalog with live prices and stock, hosted on xpay’s CDN (no extra load on your origin).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Adds AI-shopping JSON-LD\u003C\u002Fstrong> — \u003Ccode>Product\u003C\u002Fcode>, \u003Ccode>Offer\u003C\u002Fcode>, \u003Ccode>AggregateOffer\u003C\u002Fcode>, \u003Ccode>BuyAction\u003C\u002Fcode> and \u003Ccode>ItemList\u003C\u002Fcode> schemas on product pages, shop archive and home page. Detects existing schema from Yoast \u002F Rank Math \u002F WooCommerce core and only fills the gaps.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Serves the real AI shopping standards on your own domain\u003C\u002Fstrong> — \u003Ccode>\u002Fllms.txt\u003C\u002Fcode> (\u003Ca href=\"https:\u002F\u002Fllmstxt.org\" rel=\"nofollow ugc\">llmstxt.org\u003C\u002Fa>), \u003Ccode>schema.org\u003C\u002Fcode> \u003Ccode>Product\u003C\u002Fcode>\u002F\u003Ccode>Offer\u003C\u002Fcode>\u002F\u003Ccode>BuyAction\u003C\u002Fcode> JSON-LD on every product page, and an explicit \u003Ccode>robots.txt\u003C\u002Fcode> allowlist for AI user-agents. Optional watchlist emitters for \u003Ccode>\u002F.well-known\u002Foauth-protected-resource\u003C\u002Fcode> (RFC 9728, when UCP OAuth identity linking is on) and \u003Ccode>\u002F.well-known\u002Fagent-card.json\u003C\u002Fcode> (A2A 1.0, off by default). The discovery layer is registry-based so new standards plug in cleanly.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Allows the right bots\u003C\u002Fstrong> — GPTBot, ChatGPT-User, OAI-SearchBot, ClaudeBot, Claude-User, Claude-SearchBot, PerplexityBot, Perplexity-User, Google-Extended, Applebot-Extended and CCBot. Never overrides your existing robots.txt rules.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cart deep-link\u003C\u002Fstrong> — AI agents create a one-click “Buy” link that pre-fills your existing WooCommerce cart and lands the buyer on your existing checkout. Orders are tagged with \u003Ccode>_xpay_agent_attribution\u003C\u002Fcode> so you can attribute AI-driven revenue in your existing reporting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Live inventory\u003C\u002Fstrong> — webhook-driven catalog refresh on every product \u002F stock change (debounced 30s), plus an hourly safety-net poll.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Product FAQs and return policy\u003C\u002Fstrong> — for products you approve in your xpay dashboard, the plugin publishes \u003Ccode>FAQPage\u003C\u002Fcode> and \u003Ccode>MerchantReturnPolicy\u003C\u002Fcode> JSON-LD answering the commerce questions AI shoppers ask (delivery, returns, variants). Optionally it can also show those answers to your shoppers as a block on the product page — \u003Cstrong>off on new installs\u003C\u002Fstrong>, enabled for your store from your xpay account on request. Placement is a WooCommerce product tab, the classic product-summary hook, or an \u003Ccode>[xpay-faq]\u003C\u002Fcode> shortcode you place yourself.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>What it doesn’t do\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>It doesn’t touch your checkout.\u003C\u002Fstrong> Stripe \u002F WooPayments \u002F PayPal \u002F Square \u002F whatever you already use — payment runs through them, unchanged. Your payout schedule is unchanged.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>It doesn’t see your customers.\u003C\u002Fstrong> No buyer names, emails, addresses, IPs, payment cards, order line items, refunds, or PII of any kind passes through xpay. Ever. The plugin is non-custodial.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>It doesn’t require a new account or contract\u003C\u002Fstrong> to start. Free to install and get going — paid plans available as you grow. \u003Ca href=\"https:\u002F\u002Fwww.xpay.sh\u002Fpricing\u002F?tab=agentic-commerce\" rel=\"nofollow ugc\">See pricing\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>It doesn’t slow down your site.\u003C\u002Fstrong> The JSON-LD block is tiny and cached; the catalog feed is served from xpay’s CDN, not your origin.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Five-minute install flow\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Install the plugin from this directory or upload the zip. (\u003Ca href=\"https:\u002F\u002Fdocs.xpay.sh\u002Fmerchants\u002Fwoocommerce\u002Finstalling\" rel=\"nofollow ugc\">detailed walk-through\u003C\u002Fa>)\u003C\u002Fli>\n\u003Cli>Activate. You’ll be taken to \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> xpay\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Connect store\u003C\u002Fstrong>. You’re redirected to app.xpay.sh, where you grant a read-only WooCommerce REST API key. (\u003Ca href=\"https:\u002F\u002Fdocs.xpay.sh\u002Fmerchants\u002Fwoocommerce\u002Frest-api-keys\" rel=\"nofollow ugc\">how to generate one\u003C\u002Fa>)\u003C\u002Fli>\n\u003Cli>Your catalog goes live on AI surfaces within about 10 minutes. The plugin’s built-in audit-readiness checklist (\u003Ca href=\"https:\u002F\u002Fdocs.xpay.sh\u002Fmerchants\u002Fwoocommerce\u002Faudit-readiness\" rel=\"nofollow ugc\">what each row means\u003C\u002Fa>) turns green as each piece confirms.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Stuck on any step? \u003Ca href=\"https:\u002F\u002Fdocs.xpay.sh\u002Fmerchants\u002Fwoocommerce\u002Ftroubleshooting\" rel=\"nofollow ugc\">Troubleshooting guide\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Compatibility\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>WooCommerce 7.0+ on WordPress 6.2+ and PHP 7.4+.\u003C\u002Fli>\n\u003Cli>Declares compatibility with WooCommerce High-Performance Order Storage (HPOS) and Cart\u002FCheckout Blocks.\u003C\u002Fli>\n\u003Cli>Works alongside Yoast SEO, Rank Math, WooCommerce Blocks, WooPayments, Stripe for WooCommerce, and the standard Storefront \u002F Astra \u002F Divi \u002F Elementor themes.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Privacy and consent\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Anonymous lifecycle telemetry is off by default.\u003C\u002Fstrong> On first activation a single admin notice asks once. Pick “No thanks” and the plugin never contacts our backend for analytics. Pick “Enable” and you can change your mind any time under \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> xpay \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Privacy\u003C\u002Fstrong>. System-wide opt-out via \u003Ccode>define( 'XPAY_WC_TELEMETRY', false );\u003C\u002Fcode> in \u003Ccode>wp-config.php\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full data disclosure\u003C\u002Fstrong> at \u003Ca href=\"https:\u002F\u002Finstall.xpay.sh\u002Fwoocommerce\u002Fprivacy.html\" rel=\"nofollow ugc\">install.xpay.sh\u002Fwoocommerce\u002Fprivacy.html\u003C\u002Fa> — every byte the plugin sends, when it sends it, how to opt out, how to request deletion. Plain-English version: \u003Ca href=\"https:\u002F\u002Fdocs.xpay.sh\u002Fmerchants\u002Fwoocommerce\u002Fprivacy-telemetry\" rel=\"nofollow ugc\">docs.xpay.sh\u002Fmerchants\u002Fwoocommerce\u002Fprivacy-telemetry\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Source code and contributing\u003C\u002Fh4>\n\u003Cp>The plugin source is published under GPLv2-or-later. Public repo and issue tracker: \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fxpaysh\u002Fagentic-commerce-for-woocommerce\" rel=\"nofollow ugc\">github.com\u002Fxpaysh\u002Fagentic-commerce-for-woocommerce\u003C\u002Fa>. You can fork, modify, redistribute, and self-host without paying anything.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin connects to the following xpay-operated services to deliver its core function. Every endpoint and its purpose is documented; full payload disclosure is in the \u003Ca href=\"https:\u002F\u002Finstall.xpay.sh\u002Fwoocommerce\u002Fprivacy.html\" rel=\"nofollow ugc\">Privacy\u003C\u002Fa> section.\u003C\u002Fp>\n\u003Col>\n\u003Cli>\n\u003Cp>\u003Cstrong>agent-feed.xpay.sh\u003C\u002Fstrong> — Public CDN that hosts your AI-readable catalog feed at \u003Ccode>https:\u002F\u002Fagent-feed.xpay.sh\u002Fcatalog\u002F{your-slug}.json\u003C\u002Fcode>. The plugin does not contact this URL directly; the xpay backend writes it from your WooCommerce REST API after you click \u003Cstrong>Connect store\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>agent-commerce.xpay.sh\u003C\u002Fstrong> — The agent-side API that AI shopping agents call to surface and buy from your products. The plugin contacts this host at the following paths: (a) \u003Ccode>POST \u002Fv1\u002Fonboard\u002Fwoocommerce\u002Fwc-auth-callback\u003C\u002Fcode> is the WooCommerce OAuth callback target (WordPress itself calls this on your behalf, server-to-server, after you approve the one-click connect prompt); (b) \u003Ccode>GET \u002Fv1\u002Fonboard\u002Fwoocommerce\u002Fstatus?nonce=…\u003C\u002Fcode> is polled by the xpay onboarding page while the handshake finishes; (c) \u003Ccode>POST \u002Fv1\u002Fmerchants\u002F{slug}\u002Fresync\u003C\u002Fcode> triggers a fresh catalog ingest after a product or stock change; (d) \u003Ccode>GET \u002Fv1\u002Fmerchants\u002F{slug}\u003C\u002Fcode> is called when \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> xpay\u003C\u002Fstrong> verifies the current connection state; (e) \u003Ccode>PATCH \u002Fv1\u002Fmerchants\u002F{slug}\u002Fproducts\u002F{sku}\u003C\u002Fcode> pushes a single-product delta when a WooCommerce product\u002Fstock webhook fires; (f) \u003Ccode>DELETE \u002Fv1\u002Fmerchants\u002F{slug}\u003C\u002Fcode> is sent (non-blocking) when you click \u003Cstrong>Disconnect\u003C\u002Fstrong> so xpay marks your account as disconnected and archives the cached catalog. The hostname is also the publicly advertised target for \u003Ccode>POST \u002Fmcp\u002F{slug}\u003C\u002Fcode> (the JSON-RPC commerce MCP endpoint AI agents talk to) — the plugin itself does not call this URL but lists it in the \u003Ccode>\u002F.well-known\u002Fucp\u003C\u002Fcode> manifest.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>app.xpay.sh\u002Fonboard\u002Fwoocommerce\u003C\u002Fstrong> — The merchant-side onboarding page. When you click \u003Cstrong>Connect store\u003C\u002Fstrong>, the plugin redirects your browser here with three query-string parameters: your site URL, your administrator email address, and a one-time random nonce generated locally. No data is sent to xpay before you click the button. You sign in or sign up on xpay and grant the WooCommerce REST API permission there.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>agent-commerce.xpay.sh\u002Fv1\u002Fevents\u003C\u002Fstrong> — Optional anonymous lifecycle telemetry. Disabled by default; only contacted if you explicitly opt in via the first-activation admin notice or \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> xpay \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Privacy\u003C\u002Fstrong>. Full payload disclosure in the Privacy section.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>agent-commerce.xpay.sh\u002Fv1\u002Fmerchants\u002F{slug}\u002Forders\u003C\u002Fstrong> — Agent-attributed order reporting for connected stores (non-PII order summary + attribution source; no customer, payment, or personal data). Off via the \u003Ccode>xpay_wc_order_events_enabled\u003C\u002Fcode> option. Full payload disclosure in the Privacy section.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>agent-commerce.xpay.sh\u002Fv1\u002Fagent-analytics\u003C\u002Fstrong> — Optional anonymous AI-bot crawl analytics. Disabled by default; shares the same opt-in as item 4 (and respects a separate \u003Ccode>define( 'XPAY_WC_AGENT_ANALYTICS', false )\u003C\u002Fcode> hard-off). When enabled, the plugin counts requests from \u003Cem>known AI bots only\u003C\u002Fem> (e.g. GPTBot, ChatGPT-User, ClaudeBot, PerplexityBot, Google-Extended) — recording the bot name, a coarse page type (home\u002Fproduct\u002Fcategory\u002Fdiscovery-file\u002Fsitemap\u002Fother), the HTTP status, and whether we routed the bot to your structured catalog. It also sends an aggregate daily count of human pageviews (a number only — no user-agent, no URLs, no per-visit data) as the AI-vs-human denominator. Since 0.5.3 a bot event also carries a salted, one-way hash of the connecting IP address (a bot’s — behind a proxy or CDN this is the connecting edge address), so two hits from the same crawler can be counted as one visitor. The salt is unique to your store and is regenerated every day, so the hash cannot be linked across days or across stores, and the address itself is never stored or transmitted. This applies to AI bots only — a human visitor’s IP is never read, hashed or sent. Events are buffered locally and sent in the background by WP-Cron, never on a page load. Cart, checkout, account, admin and REST paths are never recorded. No per-visit human data, no customer, order, or personal data.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>audit.xpay.sh\u003C\u002Fstrong> — Merchant-facing audit dashboard. The plugin emits a link to \u003Ccode>audit.xpay.sh\u002F{your-slug}\u003C\u002Fcode> on the Settings page so you can review the live agent-readiness score xpay computed from your catalog; the plugin itself does not fetch from this host. Opening the link from your browser sends standard browser headers to xpay.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>auth.xpay.sh\u003C\u002Fstrong> — Public OAuth-protected-resource discovery target. The plugin publishes \u003Ccode>auth.xpay.sh\u003C\u002Fcode> as the \u003Ccode>authorization_servers[0]\u003C\u002Fcode> entry in \u003Ccode>\u002F.well-known\u002Foauth-protected-resource\u003C\u002Fcode> (an RFC 9728 metadata document AI agents fetch to learn where to obtain a token). The plugin does not contact this host server-to-server; it is referenced for agent-side discovery only.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>install.xpay.sh\u002Fwoocommerce\u002F{terms,privacy}.html\u003C\u002Fstrong> — Static legal documents linked from this readme and from the Settings privacy panel. The plugin itself does not fetch these URLs; clicking the links opens them in your browser.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Terms of use: \u003Ca href=\"https:\u002F\u002Finstall.xpay.sh\u002Fwoocommerce\u002Fterms.html\" rel=\"nofollow ugc\">install.xpay.sh\u002Fwoocommerce\u002Fterms.html\u003C\u002Fa>\u003Cbr \u002F>\nPrivacy policy: \u003Ca href=\"https:\u002F\u002Finstall.xpay.sh\u002Fwoocommerce\u002Fprivacy.html\" rel=\"nofollow ugc\">install.xpay.sh\u002Fwoocommerce\u002Fprivacy.html\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>xpay is built non-custodially: we never see your customers, your orders, or any payment data. Concretely:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Nothing leaves your site before you click Connect store.\u003C\u002Fstrong> The Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> xpay page is pure markup — no outbound HTTP, no analytics ping, no nonce pre-registration.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Sent only after you click Connect store\u003C\u002Fstrong> (required for the plugin to work): your site URL, your administrator email address, a one-time random nonce, your WooCommerce REST API consumer key\u002Fsecret (so xpay can read the product catalog), and your public product fields (name, description, price, stock, image URLs, categories). No customer data. No order data. No payment data.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Optionally sent if you opt in to anonymous telemetry\u003C\u002Fstrong> (default OFF): lifecycle event names tagged with your site URL, plugin version, WP version, WC version, PHP version, locale. No customer data, no order data, no customer PII.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Optionally sent if you opt in (default OFF), as part of the same telemetry consent — AI-bot crawl analytics\u003C\u002Fstrong>: for requests from \u003Cem>known AI bots only\u003C\u002Fem>, the bot name, a coarse page type (home\u002Fproduct\u002Fcategory\u002Fdiscovery-file\u002Fsitemap\u002Fother), the HTTP status, and whether the bot was routed to your structured catalog — tagged with your site URL. Also sent: an aggregate daily count of human pageviews (a number only — the AI-vs-human denominator). Also sent for \u003Cem>AI-bot\u003C\u002Fem> hits only: a salted one-way hash of the bot’s IP (per-store salt, rotated daily — not the address, and not linkable across days or stores). Never recorded: per-visit human data, human IP addresses, query strings, cart\u002Fcheckout\u002Faccount\u002Fadmin\u002FREST paths, or any customer, order, or personal data. Hard-disable just this (while keeping lifecycle telemetry) with \u003Ccode>define( 'XPAY_WC_AGENT_ANALYTICS', false );\u003C\u002Fcode>.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Opt out of anonymous telemetry\u003C\u002Fstrong>: \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> xpay \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Privacy \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Turn off\u003C\u002Fstrong>. Or define \u003Ccode>XPAY_WC_TELEMETRY\u003C\u002Fcode> to \u003Ccode>false\u003C\u002Fcode> in \u003Ccode>wp-config.php\u003C\u002Fcode> for a system-wide hard disable that overrides any UI choice.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Request data deletion\u003C\u002Fstrong>: email privacy@xpay.sh from your admin email with your merchant slug. We process within 7 business days.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Full data-handling disclosure: \u003Ca href=\"https:\u002F\u002Finstall.xpay.sh\u002Fwoocommerce\u002Fprivacy.html\" rel=\"nofollow ugc\">install.xpay.sh\u002Fwoocommerce\u002Fprivacy.html\u003C\u002Fa>.\u003C\u002Fp>\n","Put your WooCommerce catalog inside ChatGPT, Claude, Gemini and Perplexity — buyers complete checkout on your existing WooCommerce gateway.",877,74,"2026-07-15T12:59:00.000Z","7.0.2","6.2","7.4",[27,28,29,30,31],"agentic-commerce","ai","chatgpt","llms","woocommerce","https:\u002F\u002Fwww.xpay.sh\u002Fmerchants\u002Fwoocommerce\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fagentic-commerce-for-woocommerce.0.6.3.zip",0,null,"2026-07-22T17:31:50.256Z",{"slug":38,"name":39,"version":40,"author":5,"author_profile":6,"description":41,"short_description":42,"active_installs":34,"downloaded":43,"rating":34,"num_ratings":34,"last_updated":44,"tested_up_to":23,"requires_at_least":45,"requires_php":25,"tags":46,"homepage":51,"download_link":52,"security_score":9,"vuln_count":34,"unpatched_count":34,"last_vuln_date":35,"fetched_at":36},"agentic-commerce-product-images","Agentic Commerce – Product Images for WooCommerce","1.0.0","\u003Cp>\u003Cstrong>Your next customer might be an AI. Is your catalog ready for it?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Shoppers now ask ChatGPT, Perplexity, Google AI Mode and Amazon Rufus to find and compare products for them. Before a human ever sees your store, an AI reads your product images, and it is far pickier than any web browser. Wrong format, too small, no alt text, and your product is quietly skipped.\u003C\u002Fp>\n\u003Cp>This plugin is built for that shift to agentic commerce. It fixes what AI shoppers need, adds AI editing (background removal, lifestyle scenes, upscaling), and keeps your store fast for humans too.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>⚡ Start free: run the AI Shopper Image Audit. 30 seconds, no signup, no account.\u003C\u002Fstrong> It scores every product for ChatGPT, Google AI Mode, Pinterest and Amazon Rufus, and tells you exactly what to fix.\u003C\u002Fp>\n\u003Ch4>🆓 Six tools that work the second you activate (no account, no API key, no network calls)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>🔍 AI Shopper Image Audit\u003C\u002Fstrong>: a per-product score with specific fixes: “fails ChatGPT carousel (WebP), passes Google AI (1500×1500), outside Pinterest ratio.” Right on the Edit Product screen.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>🚀 Format-aware delivery\u003C\u002Fstrong>: serves AVIF\u002FWebP to browsers for speed, and JPEG\u002FPNG to AI shopper crawlers (ChatGPT-User, PerplexityBot, GPTBot and more), exactly as the Agentic Commerce Protocol requires.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>✅ Upload-time compliance\u003C\u002Fstrong>: upload a WebP or AVIF and the plugin auto-creates an AI-shopper-ready JPEG sibling, then tells you what it did.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>🔁 Variation hover-swap\u003C\u002Fstrong>: hover a product card and the image flips to a variation or gallery shot. Block-theme friendly.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>🎬 Shoppable video block\u003C\u002Fstrong>: a Gutenberg block with product pins and an add-to-cart overlay.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>🧹 Image dedupe\u003C\u002Fstrong>: perceptual-hash detection of duplicate product images you re-uploaded.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🤖 Five AI tools (100 free AI edits a month, per site)\u003C\u002Fh4>\n\u003Cp>Connect once and unlock studio-grade editing, run on our managed AI so there is no separate provider account or key to babysit:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>✂️ Background Remover\u003C\u002Fstrong>: detect the product and cut a clean, precise cutout. One photo or a bulk catalog pass.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>🏝️ Scene Generator\u003C\u002Fstrong>: drop the cutout into an AI-generated lifestyle scene, the editorial imagery Perplexity and Pinterest surface first.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>🔬 Image Enhancer\u003C\u002Fstrong>: upscale low-res photos 2x or 4x, denoise and sharpen, so every listing clears the Google AI Mode minimum.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>📝 AI Alt Text\u003C\u002Fstrong>: generate accurate, descriptive alt text for SEO and AI shoppers, and bulk-fix an entire catalog in one pass.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>📐 Marketplace Auto-crop\u003C\u002Fstrong>: subject-aware crop to 1:1 (Google + Agentic Commerce), 4:5 (Pinterest) and 16:9 (video), without lopping off the product.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>📈 Why this is suddenly urgent\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>OpenAI’s Agentic Commerce Protocol (Jan 2026)\u003C\u002Fstrong> requires product \u003Ccode>image_url\u003C\u002Fcode> to be \u003Cstrong>JPEG or PNG only\u003C\u002Fstrong>. Most WordPress image plugins default to WebP\u002FAVIF, which breaks ChatGPT Shopping carousels.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google AI Mode\u003C\u002Fstrong> enforces a 500×500 minimum from June 2026.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Perplexity\u003C\u002Fstrong> favours lifestyle, in-context imagery.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Amazon Rufus\u003C\u002Fstrong> reads the text inside a product image as a ranking signal.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Your images may be perfectly optimised for humans and still invisible to the assistant doing the shopping. This plugin closes that gap.\u003C\u002Fp>\n\u003Ch4>🤝 Works alongside your image-optimization plugins\u003C\u002Fh4>\n\u003Cp>Image-optimization and CDN plugins compress and serve your images. This plugin adds AI editing and AI-shopper-aware delivery on top, detects an existing image CDN, and stays out of its way.\u003C\u002Fp>\n\u003Ch4>💰 Simple pricing\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Free forever:\u003C\u002Fstrong> the six always-on tools above are fully local.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI tools:\u003C\u002Fstrong> 100 free AI edits every month, per site. Then $5 for a 500-edit pack, one time, credits never expire.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🔓 Open source\u003C\u002Fh4>\n\u003Cp>Read the code, open an issue, or send a pull request: \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fxpaysh\u002Fproduct-images-for-woocommerce\" rel=\"nofollow ugc\">https:\u002F\u002Fgithub.com\u002Fxpaysh\u002Fproduct-images-for-woocommerce\u003C\u002Fa>. Built by xpay✦ Commerce.\u003C\u002Fp>\n\u003Cp>The illustrative product photos bundled with the plugin (in \u003Ccode>public\u002Fimg\u002F\u003C\u002Fcode>) were generated with FLUX.1 [schnell] and Recraft; their outputs are freely usable and GPL-compatible.\u003C\u002Fp>\n\u003Ch3>Third-party services\u003C\u002Fh3>\n\u003Cp>This plugin makes \u003Cstrong>no autonomous or background calls\u003C\u002Fstrong>. The six always-on tools run entirely on your site. The plugin contacts our servers only after you connect (sign in), and only when you take an explicit action.\u003C\u002Fp>\n\u003Cp>When you sign in, your site URL, WordPress \u002F WooCommerce \u002F plugin versions and email are sent to the xpay✦ Commerce API (product-images.xpay.sh) to link this site to your account.\u003C\u002Fp>\n\u003Cp>When you use an AI tool, the image URL you select is sent to the xpay✦ Commerce API (product-images.xpay.sh), which runs the model on Replicate (models such as cjwbw\u002Frembg, black-forest-labs\u002Fflux-schnell, nightmareai\u002Freal-esrgan and lucataco\u002Fmoondream) and meters your quota. No AI-provider API key is stored on your site. Bundle-pack purchases are completed through Stripe Checkout.\u003C\u002Fp>\n\u003Cp>When you click “See how AI shoppers read your store” (or a product’s “Why?”) on the AI Shopper Image Audit screen, the plugin sends that screen’s aggregate audit numbers (your site URL, WordPress \u002F WooCommerce \u002F plugin versions, product count, overall score, and how many products fail each check) to the xpay✦ Commerce API (product-images.xpay.sh) to generate a plain-language explanation. No image files and no order or customer data are sent. This only happens when you click.\u003C\u002Fp>\n\u003Cp>You can disconnect at any time from Settings, Privacy, which removes the stored sign-in token from your site.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>xpay✦ Commerce API: \u003Ca href=\"https:\u002F\u002Fproduct-images.xpay.sh\" rel=\"nofollow ugc\">https:\u002F\u002Fproduct-images.xpay.sh\u003C\u002Fa> (\u003Ca href=\"https:\u002F\u002Fwww.xpay.sh\u002Flegal\u002Fterms\u002F\" rel=\"nofollow ugc\">terms\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fwww.xpay.sh\u002Flegal\u002Fprivacy-policy\u002F\" rel=\"nofollow ugc\">privacy\u003C\u002Fa>)\u003C\u002Fli>\n\u003Cli>Replicate: \u003Ca href=\"https:\u002F\u002Freplicate.com\" rel=\"nofollow ugc\">https:\u002F\u002Freplicate.com\u003C\u002Fa> (\u003Ca href=\"https:\u002F\u002Freplicate.com\u002Fterms\" rel=\"nofollow ugc\">terms\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Freplicate.com\u002Fprivacy\" rel=\"nofollow ugc\">privacy\u003C\u002Fa>)\u003C\u002Fli>\n\u003Cli>Stripe: \u003Ca href=\"https:\u002F\u002Fstripe.com\" rel=\"nofollow ugc\">https:\u002F\u002Fstripe.com\u003C\u002Fa> (\u003Ca href=\"https:\u002F\u002Fstripe.com\u002Flegal\" rel=\"nofollow ugc\">terms\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fstripe.com\u002Fprivacy\" rel=\"nofollow ugc\">privacy\u003C\u002Fa>)\u003C\u002Fli>\n\u003C\u002Ful>\n","AI background removal, scene generation, upscaling and alt text, plus AI-shopper delivery so WooCommerce products render in ChatGPT and Google AI.",73,"2026-07-10T11:58:00.000Z","6.5",[47,48,49,50,31],"ai-alt-text","background-remover","image-seo","product-images","https:\u002F\u002Fwww.xpay.sh\u002Fagentic-commerce\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fagentic-commerce-product-images.1.0.0.zip",{"slug":54,"name":55,"version":56,"author":5,"author_profile":6,"description":57,"short_description":58,"active_installs":34,"downloaded":59,"rating":34,"num_ratings":34,"last_updated":60,"tested_up_to":23,"requires_at_least":24,"requires_php":25,"tags":61,"homepage":65,"download_link":66,"security_score":9,"vuln_count":34,"unpatched_count":34,"last_vuln_date":35,"fetched_at":36},"xpay-agentic-commerce-for-publishers","xpay✦ Agentic Commerce for Publishers","0.4.3","\u003Cp>\u003Cstrong>Plugin landing page:\u003C\u002Fstrong> https:\u002F\u002Fwww.xpay.sh\u002Fpublishers\u002Fwordpress-plugin\u002F · \u003Cstrong>Documentation:\u003C\u002Fstrong> https:\u002F\u002Fdocs.xpay.sh\u002Fen\u002Fpublishers\u002Fwordpress-plugin · \u003Cstrong>Source code:\u003C\u002Fstrong> https:\u002F\u002Fgithub.com\u002Fxpaysh\u002Fxpay-agentic-commerce-for-publishers\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Your readers are increasingly arriving from ChatGPT, Claude, Gemini and Perplexity.\u003C\u002Fstrong> They are also still arriving the usual way. xpay✦ Agentic Commerce helps you serve both at once.\u003C\u002Fp>\n\u003Cp>For human readers, the plugin loads a lightweight recommendation widget (a floating button + a footer drawer) on your connected site — install once, works on every page, no shortcode required. You can narrow the widget to a subset of paths or disable site-wide loading entirely in the settings. For inline placement inside a specific post, use the \u003Ccode>[xpay_recs]\u003C\u002Fcode> shortcode or the Recommendations Gutenberg block. The plugin never modifies your post content directly — recommendations live in a sandboxed iframe hosted at \u003Ccode>widget.xpay.sh\u003C\u002Fcode>, sets no third-party cookies, and uses no behavioural targeting.\u003C\u002Fp>\n\u003Cp>For AI assistants and agents, the plugin publishes a single endpoint at \u003Ccode>\u002F.well-known\u002Fagent-storefront.json\u003C\u002Fcode> that lists products contextually relevant to your site. Agents that fetch it can discover and (where the underlying merchants support it) transact, with the resulting referral attributed back to your site.\u003C\u002Fp>\n\u003Ch4>What it does\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Site-wide widget (floating button + footer drawer)\u003C\u002Fstrong> — loads on every page of your connected site by default. Disable site-wide loading entirely, or narrow it to matching paths only, from Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> xpay Agentic Commerce \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> “Where the widget loads”. URL patterns support \u003Ccode>*\u003C\u002Fcode> wildcards (PostHog-style).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Inline placement\u003C\u002Fstrong> — shortcode \u003Ccode>[xpay_recs]\u003C\u002Fcode> and a Gutenberg block for placing a product-card grid inside a specific post. Independent of the site-wide widget. The plugin never modifies post content via \u003Ccode>the_content\u003C\u002Fcode> — placement is always explicit.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy-first\u003C\u002Fstrong> — the plugin sets no third-party cookies and emits no tracking pixels. The decision API receives only the public URL, post title, public categories and tags. Personalization is off unless you turn it on and a Consent API plugin reports positive consent.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Agent storefront endpoint\u003C\u002Fstrong> — publishes \u003Ccode>\u002F.well-known\u002Fagent-storefront.json\u003C\u002Fcode> so AI assistants can list products contextually relevant to the page they are reading. Detects existing \u003Ccode>.well-known\u003C\u002Fcode> files and refuses to overwrite them.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Optional \u003Ccode>llms.txt\u003C\u002Fcode> augmentation\u003C\u002Fstrong> — append a clearly-delimited block to your \u003Ccode>llms.txt\u003C\u002Fcode>, only if you have opted in. Never replaces an existing \u003Ccode>llms.txt\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brand-safety controls\u003C\u002Fstrong> — exclude product categories and merchant domains directly from the native settings screen.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Amazon Associates\u003C\u002Fstrong> — set your Amazon Associates tag. Any Amazon link the widget surfaces gets \u003Ccode>?tag=\u003Cyours>\u003C\u002Fcode> appended. Amazon pays you directly.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Native WordPress settings screen\u003C\u002Fstrong> — all configuration happens inside a standard wp-admin settings page (Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> xpay Agentic Commerce). No remote UI, no embedded admin iframe.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>What it does not do\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>It does not modify your post content.\u003C\u002Fstrong> The plugin never hooks \u003Ccode>the_content\u003C\u002Fcode> or rewrites your post bodies. The site-wide widget lives in page chrome (floating button + drawer); inline placement requires an explicit shortcode or block.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>It does not collect visitor identifiers.\u003C\u002Fstrong> The plugin sets no cookies on your site and emits no tracking pixels.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>It does not change your existing themes, posts or templates.\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>It does not require a merchant relationship.\u003C\u002Fstrong> Publishers can install and connect with no e-commerce site of their own.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>External services\u003C\u002Fh4>\n\u003Cp>This plugin contacts services operated by xpay (xpay.sh).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>1. \u003Ccode>publisher-api.xpay.sh\u003C\u002Fcode>\u003C\u002Fstrong> — backend API.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>POST \u002Fstorefront\u002Fdecide\u003C\u002Fcode> — recommendation decision API. The widget iframe (front-end) calls this when it renders. Data sent: page URL, title, categories, tags, \u003Ccode>site_id\u003C\u002Fcode>. No visitor identifier.\u003C\u002Fli>\n\u003Cli>\u003Ccode>POST \u002Fstorefront\u002Fbeacon\u003C\u002Fcode> — load\u002Fclick event endpoint. The widget iframe fires this anonymously when it mounts (load) and when a reader clicks a product card (click). Data sent: \u003Ccode>site_id\u003C\u002Fcode>, hostname, post URL, merchant domain (on click), user-agent string. No visitor identifier.\u003C\u002Fli>\n\u003Cli>\u003Ccode>POST \u002Fstorefront\u002Fregister\u003C\u002Fcode> — registration endpoint. Called once from the \u003Ccode>app.xpay.sh\u003C\u002Fcode> onboard page during one-click connect to mint a \u003Ccode>site_id\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Ccode>GET \u002Fstorefront\u002Fagent-card\u002F{site_id}\u003C\u002Fcode> — server-to-server call from your WordPress install to build the \u003Ccode>\u002F.well-known\u002Fagent-storefront.json\u003C\u002Fcode> response.\u003C\u002Fli>\n\u003Cli>\u003Ccode>GET \u002Fstorefront\u002Fsites\u003C\u002Fcode> — used by the publisher dashboard at \u003Ccode>app.xpay.sh\u003C\u002Fcode>, not by this plugin.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>2. \u003Ccode>widget.xpay.sh\u003C\u002Fcode>\u003C\u002Fstrong> — sandboxed iframe host for the front-end widget. Loaded only on posts where you place the \u003Ccode>[xpay_recs]\u003C\u002Fcode> shortcode or the Recommendations block, and only when consent allows. Data passed via URL parameters: \u003Ccode>site_id\u003C\u002Fcode>, post URL, title, public categories, public tags. No visitor identifier.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>3. \u003Ccode>app.xpay.sh\u003C\u002Fcode>\u003C\u002Fstrong> — publisher dashboard. Opened in a new tab from the settings page (a button labelled “Open xpay dashboard”). Never embedded.\u003C\u002Fp>\n\u003Cp>The xpay terms of use and privacy policy: https:\u002F\u002Fwww.xpay.sh\u002Flegal\u002Fterms-of-use\u002F and https:\u002F\u002Fwww.xpay.sh\u002Flegal\u002Fprivacy-policy\u002F.\u003C\u002Fp>\n\u003Ch4>Privacy\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>No third-party cookies, no tracking pixels.\u003C\u002Fstrong> The plugin sets no cookies and emits no tracking pixels on your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Page-context only, no visitor identifiers.\u003C\u002Fstrong> The decision API and beacons receive only the public URL of the page, its public title, and its public categories and tags — the same data already in your HTML for search engines.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Iframe sandbox isolation.\u003C\u002Fstrong> The front-end widget renders inside a sandboxed iframe loaded from \u003Ccode>widget.xpay.sh\u003C\u002Fcode>. The host page and the iframe are separate browsing contexts that cannot read each other.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WP Consent API integration.\u003C\u002Fstrong> When the WP Consent API plugin is installed and reports a hard “no” for marketing consent, the widget iframe does not render.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>All settings stored locally.\u003C\u002Fstrong> Your Amazon Associates tag, excluded categories, excluded domains and toggles are stored in WordPress \u003Ccode>wp_options\u003C\u002Fcode>. They are not copied to xpay’s backend.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cleanup on uninstall.\u003C\u002Fstrong> Deleting the plugin removes every \u003Ccode>wp_options\u003C\u002Fcode> row it created and disables the agent storefront endpoint.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Where the recommended products come from\u003C\u002Fh4>\n\u003Cp>The recommendation engine uses a curated catalog of merchants from xpay’s own merchant network, with affiliate-network fallbacks. The agent storefront endpoint only lists products from agent-ready merchants, since those are the only ones an AI assistant can transact with.\u003C\u002Fp>\n","Add contextual product recommendations to your WordPress posts and publish an agent-readable product feed for AI shopping assistants.",89,"2026-06-14T13:07:00.000Z",[62,63,28,30,64],"affiliate","agentic","recommendations","https:\u002F\u002Fwww.xpay.sh\u002Fpublishers\u002Fwordpress-plugin\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fxpay-agentic-commerce-for-publishers.0.4.3.zip"]