Agentic Commerce for WooCommerce

Descriere

AI Traffic & Sales Tracking for WooCommerce — ChatGPT Ads, Product Feed & AI Visibility

Something is already sending you customers, and your analytics can’t see it.

When a shopper asks ChatGPT „find me a cordless drill under $80 that ships in 2 days” and buys from the store it names, that order lands in WooCommerce looking like ordinary direct traffic. Google Analytics shows you nothing. Your reports show you nothing. You cannot tell whether AI assistants are worth your attention, because you cannot see them at all.

This plugin makes the AI channel visible, then makes you the answer it gives — and lets you buy more of it.

Three jobs, in that order:

  1. Measure it. See which AI crawlers reach your store, which pages they read, and which of your real WooCommerce orders came from an AI assistant — broken out by ChatGPT, Claude, Perplexity, Gemini, Copilot and a dozen more, reconciled against your actual orders so you know the number is true.
  2. Win it. Publish your catalog, prices, stock and answers in the formats AI shopping assistants actually read, so you’re the store they recommend.
  3. Buy it. Run ChatGPT Ads — campaigns, budgets, creative and results — from inside WooCommerce, measured against your real orders rather than the ad platform’s own scorecard.

No theme changes. No replatforming. No new payment processor. Your existing gateway and your payout schedule are untouched.

We show you the match rate. Every AI-attributed number in this plugin comes with the percentage of your real orders it accounts for. When tracking misses something, you’ll see that too — because a revenue figure you can’t check isn’t worth having.

🌐 Plugin home: www.xpay.sh/merchants/woocommerce/
🤖 New to this? What agentic commerce actually means for a store owner

See the AI channel

  • AI crawler analytics — which assistants visit (GPTBot, ChatGPT-User, OAI-SearchBot, ClaudeBot, Claude-User, PerplexityBot, Google-Extended and more), what page types they read, whether they reached your catalog, and how that compares against your human traffic. Opt-in, off by default, known AI bots only — never your shoppers.
  • AI-attributed orders — real WooCommerce orders traced back to the assistant that referred the buyer, with revenue split by source. Strictly non-PII: no names, emails, addresses or payment data ever leave your store.
  • Agent-readiness audit — a live score for how well AI shopping assistants can read, understand and recommend your catalog, with a prioritised fix list.
  • Agent delivery speed — AI crawlers give up on slow pages. See how fast your catalog, /llms.txt and product pages answer when requested by the AI crawlers themselves, and what to do when one is too slow. A diagnostic — it won’t fight your caching plugin.

Win the AI channel

  • An agent-readable product feed — your full catalog with live prices and stock, hosted on xpay’s CDN, so assistants reading it never touch your origin. Refreshed within ~30 seconds of any product or stock change, with an hourly safety net.
  • AI-shopping structured dataProduct, Offer, AggregateOffer, BuyAction and ItemList JSON-LD on product pages, shop archive and home page. Detects Yoast, Rank Math and WooCommerce core schema and fills only the gaps — never a duplicate.
  • The real AI shopping standards, on your own domain/llms.txt (llmstxt.org) and an explicit robots.txt allowlist for AI user-agents. If you already publish your own /llms.txt, this appends to it and leaves your content untouched.
  • Cart deep-link — an assistant can hand a shopper a one-click Buy link that pre-fills your existing WooCommerce cart and lands them on your existing checkout.
  • Product FAQs and return policyFAQPage and MerchantReturnPolicy structured data answering the delivery, returns and variant questions AI shoppers ask, for products you approve. Optionally shown to your shoppers too, as a product tab, a summary block, or an [xpay-faq] shortcode — off on new installs.
  • AI storefront assistant (optional) — an on-site shopper chat that answers from your own catalog. Never appears without your explicit say-so.

Run ChatGPT Ads

Not sure what these are? ChatGPT Ads, explained for store owners — what they are, what they cost, and who’s eligible.

  • Campaign management inside WooCommerce — create, edit, budget, activate and pause ChatGPT Ads campaigns and ad groups without switching to another tab. Results land next to the orders they produced.
  • Your numbers, not just theirs — every campaign shows the orders we reconciled against your real WooCommerce data alongside what OpenAI reports. The gap between the two is the most useful number on the screen.
  • A ChatGPT product feed — your catalog serialised to OpenAI’s specification and delivered on a schedule, with a per-product health score so you can see exactly which listings are incomplete and fix them inline.
  • Eligibility, up front — ChatGPT Ads requires a minimum catalog size and is currently limited to the US, Canada, Australia and New Zealand. The plugin tells you where you stand before you invest time, and points you at the organic path if ads aren’t open to you yet.
  • Tracking that works with what you have — already running Pixel Manager, PixelYourSite or a GTM container? This verifies their pixel is firing and reconciles it, instead of asking you to rip it out and install another one.

Works alongside what you already run

Built to cooperate, not compete. If another plugin already does a job, this one stands down rather than duplicating:

  • Yoast SEO / Rank Math / SEOPress — detects existing Product and FAQ schema and fills only what’s missing.
  • AdTribes Product Feed PRO / CTX Feed / Google Listings & Ads — separate feeds for separate channels; nothing conflicts.
  • Pixel Manager / PixelYourSite / GTM / WooCommerce core Order Attribution — attribution here is additive and non-destructive.
  • WP Rocket / LiteSpeed / Autoptimize / SiteGround Optimizer — automatically excluded from JS optimization so nothing breaks.
  • HPOS and Cart/Checkout Blocks — declared compatible.
  • Storefront / Astra / Divi / Elementor and the standard page builders.

What it doesn’t do

  • It doesn’t touch your checkout. Stripe / WooPayments / PayPal / Square / whatever you already use — payment runs through them, unchanged. Your payout schedule is unchanged.
  • It doesn’t see your customers. No buyer names, emails, addresses, IPs, payment cards, order line items, refunds, or PII of any kind passes through xpay. Ever. The plugin is non-custodial.
  • It doesn’t require a new account or contract to start. Free to install and get going — paid plans available as you grow. See pricing.
  • It doesn’t slow down your site. The JSON-LD block is tiny and cached; the catalog feed is served from xpay’s CDN, not your origin.

Five-minute install flow

  1. Install the plugin from this directory or upload the zip.
  2. Activate. You’ll land on the xpay✦ Commerce dashboard.
  3. Click Connect store. You’re redirected to app.xpay.sh, where you grant a read-only WooCommerce REST API key.
  4. Your catalog goes live on AI surfaces within about 10 minutes. The built-in readiness checklist turns green as each piece confirms, and tells you in plain English what to do about anything that doesn’t.

Stuck on any step? Email merchants@xpay.sh or post in the support forum on this page — we aim to reply within one business day.

Compatibility

  • WooCommerce 7.0+ on WordPress 6.2+ and PHP 7.4+.
  • Declares compatibility with WooCommerce High-Performance Order Storage (HPOS) and Cart/Checkout Blocks.
  • Works alongside Yoast SEO, Rank Math, WooCommerce Blocks, WooPayments, Stripe for WooCommerce, and the standard Storefront / Astra / Divi / Elementor themes.

Privacy and consent

  • Anonymous lifecycle telemetry is off by default. On first activation a single admin notice asks once. Pick „No thanks” and the plugin never contacts our backend for analytics. Pick „Enable” and you can change your mind any time under xpay✦ Commerce Settings Privacy. System-wide opt-out via define( 'XPAY_WC_TELEMETRY', false ); in wp-config.php.
  • Full data disclosure at install.xpay.sh/woocommerce/privacy.html — every byte the plugin sends, when it sends it, how to opt out, how to request deletion.

More from xpay

Source code

The plugin is GPLv2-or-later and ships as readable PHP — the complete source is in wp-content/plugins/agentic-commerce-for-woocommerce/ on your own server the moment you install it. You can read it, fork it, modify it, redistribute it and self-host it without paying anything. Full technical changelog: install.xpay.sh/woocommerce/CHANGELOG.md. Questions or bug reports: merchants@xpay.sh, or the support forum on this page.

External services

This plugin connects to the following xpay-operated services to deliver its core function. Every endpoint and its purpose is documented; full payload disclosure is in the Privacy section.

  1. agent-feed.xpay.sh — Public CDN that hosts your AI-readable catalog feed at https://agent-feed.xpay.sh/catalog/{your-slug}.json. The plugin does not contact this URL directly; the xpay backend writes it from your WooCommerce REST API after you click Connect store.

  2. agent-commerce.xpay.sh — The agent-side API that AI shopping agents call to surface and buy from your products. The plugin contacts this host at the following paths: (a) POST /v1/onboard/woocommerce/wc-auth-callback is the WooCommerce OAuth callback target (WordPress itself calls this on your behalf, server-to-server, after you approve the one-click connect prompt); (b) GET /v1/onboard/woocommerce/status?nonce=… is polled by the xpay onboarding page while the handshake finishes; (c) POST /v1/merchants/{slug}/resync triggers a fresh catalog ingest after a product or stock change; (d) GET /v1/merchants/{slug} is called when xpay✦ Commerce Settings verifies the current connection state; (e) PATCH /v1/merchants/{slug}/products/{sku} pushes a single-product delta when a WooCommerce product/stock webhook fires; (f) DELETE /v1/merchants/{slug} is sent (non-blocking) when you click Disconnect so xpay marks your account as disconnected and archives the cached catalog. The hostname is also the publicly advertised target for POST /mcp/{slug} (the JSON-RPC commerce MCP endpoint AI agents talk to) — the plugin itself does not call this URL but lists it in the /.well-known/ucp manifest.

  3. app.xpay.sh/onboard/woocommerce — The merchant-side onboarding page. When you click Connect store, the plugin redirects your browser here with three query-string parameters: your site URL, your administrator email address, and a one-time random nonce generated locally. No data is sent to xpay before you click the button. You sign in or sign up on xpay and grant the WooCommerce REST API permission there.

  4. agent-commerce.xpay.sh/v1/events — Optional anonymous lifecycle telemetry. Disabled by default; only contacted if you explicitly opt in via the first-activation admin notice or xpay✦ Commerce Settings Privacy. Full payload disclosure in the Privacy section.

  5. agent-commerce.xpay.sh/v1/merchants/{slug}/orders — Agent-attributed order reporting for connected stores (non-PII order summary + attribution source; no customer, payment, or personal data). Off via the xpay_wc_order_events_enabled option. Full payload disclosure in the Privacy section.

  6. agent-commerce.xpay.sh/v1/agent-analytics — Optional anonymous AI-bot crawl analytics. Disabled by default; shares the same opt-in as item 4 (and respects a separate define( 'XPAY_WC_AGENT_ANALYTICS', false ) hard-off). When enabled, the plugin counts requests from known AI bots only (e.g. GPTBot, ChatGPT-User, ClaudeBot, PerplexityBot, Google-Extended) — recording the bot name, a coarse page type (home/product/category/discovery-file/sitemap/other), the HTTP status, and whether we routed the bot to your structured catalog. It also sends an aggregate daily count of human pageviews (a number only — no user-agent, no URLs, no per-visit data) as the AI-vs-human denominator. Since 0.5.3 a bot event also carries a salted, one-way hash of the connecting IP address (a bot’s — behind a proxy or CDN this is the connecting edge address), so two hits from the same crawler can be counted as one visitor. The salt is unique to your store and is regenerated every day, so the hash cannot be linked across days or across stores, and the address itself is never stored or transmitted. This applies to AI bots only — a human visitor’s IP is never read, hashed or sent. Events are buffered locally and sent in the background by WP-Cron, never on a page load. Cart, checkout, account, admin and REST paths are never recorded. No per-visit human data, no customer, order, or personal data.

  7. audit.xpay.sh — Merchant-facing audit dashboard. The plugin emits a link to audit.xpay.sh/{your-slug} on the Settings page so you can review the live agent-readiness score xpay computed from your catalog; the plugin itself does not fetch from this host. Opening the link from your browser sends standard browser headers to xpay.

  8. auth.xpay.sh — Public OAuth-protected-resource discovery target. The plugin publishes auth.xpay.sh as the authorization_servers[0] entry in /.well-known/oauth-protected-resource (an RFC 9728 metadata document AI agents fetch to learn where to obtain a token). The plugin does not contact this host server-to-server; it is referenced for agent-side discovery only.
  9. install.xpay.sh/woocommerce/{terms,privacy}.html — Static legal documents linked from this readme and from the Settings privacy panel. The plugin itself does not fetch these URLs; clicking the links opens them in your browser.

Terms of use: install.xpay.sh/woocommerce/terms.html
Privacy policy: install.xpay.sh/woocommerce/privacy.html

Privacy

We never see your customers, your orders, or any payment data. The plugin is non-custodial by design.

  • Nothing leaves your site until you click Connect store. Before that, the settings page makes no outbound request of any kind.
  • After you connect we receive: your site URL, your admin email, a one-time nonce, a WooCommerce REST API key so we can read your catalog, and your public product fields (name, description, price, stock, images, categories). No customer data. No order data. No payment data.
  • Anonymous diagnostics are OFF by default. You’re asked once. If you turn them on, we receive plugin lifecycle events and version numbers tagged with your site URL — and, separately, counts of known AI bots only (which bot, what kind of page, the response code) plus a daily total of human pageviews as a number, so you can see your AI-vs-human split. A human visitor’s IP address is never read, hashed or sent, and cart, checkout, account and admin pages are never recorded.
  • Turn it off any time at xpay✦ Commerce Settings Privacy, or hard-disable in wp-config.php with define( 'XPAY_WC_TELEMETRY', false ); (or XPAY_WC_AGENT_ANALYTICS for bot counts alone). The constant overrides any UI choice.
  • Delete your data: email privacy@xpay.sh from your admin address with your store name. Processed within 7 business days.

Every byte, itemised: install.xpay.sh/woocommerce/privacy.html · Terms

Capturi ecran

Blocuri

Acest modul oferă 1 bloc.

  • Xpay Buy In Ai Chat

Instalare

From the WordPress.org plugin directory

  1. In your WordPress admin, go to Plugins Add New.
  2. Search for „Agentic Commerce for WooCommerce”.
  3. Click Install Now, then Activate.
  4. You’ll be redirected to xpay✦ Commerce Settings. Click Connect store.
  5. Approve the WooCommerce REST API permissions on app.xpay.sh, then you’ll be redirected back to your store.

System requirements

  • WordPress 6.2 or higher
  • WooCommerce 7.0 or higher
  • PHP 7.4 or higher
  • SSL (https://) on the store domain — required for the agent discovery files to be honored by AI surfaces

Întrebări frecvente

Will this slow down my store?

No. What we add to your pages is a few lines of invisible data. Your catalog is served from our CDN, so AI shoppers reading it never touch your server at all.

Does xpay see my customers or their payment details?

No — never. Payment runs through your existing gateway exactly as it does today. No buyer names, emails, addresses, cards or order contents ever reach us.

Will it change how my product pages look?

Almost everything we add is invisible to shoppers. The one exception is the product FAQ block, and it is off on new installs — nothing appears on your store until you ask for it.

I already use Yoast or Rank Math. Will this conflict?

No. We check what they’ve already published and add only what’s missing, so you never end up with two of anything.

How much does it cost?

Free to install and use. Paid plans as you grow — see pricing.

What does it send to xpay, and when?

Nothing until you click Connect store. After that: your public product details (name, description, price, stock, images, categories) so we can publish your catalog for AI shoppers. Optional anonymous diagnostics are off by default and you’re asked once. No customer data, no order data, ever. Full disclosure.

How do I remove it?

Plugins Deactivate Delete, and everything the plugin wrote is removed from your database. To also delete your catalog from our CDN, email privacy@xpay.sh from your admin address.

I run several stores. Do I install it on each?

Yes — each store gets its own catalog and its own settings.

Do you support Subscriptions, Bookings or Memberships?

Simple, variable and grouped products today. The others are on the roadmap — email merchants@xpay.sh if one is blocking you and we’ll tell you where it stands.

My host blocks /.well-known/ — does discovery still work?

Yes. There’s an automatic fallback that AI shoppers find on their own. If your host intercepts those paths, nothing breaks.

Is the source code available?

Yes. GPLv2-or-later, shipped as plain readable PHP in wp-content/plugins/agentic-commerce-for-woocommerce/. Nothing minified, obfuscated or loaded from a remote script. Developers: add_filter( 'xpay_wc_faq_visible', '__return_false' ); turns the FAQ block off from code, whatever the dashboard says.

I have a question that isn’t answered here.

Email merchants@xpay.sh, or post in the support forum on this page — we answer both, and we aim to reply within one business day.

Recenzii

3 august 2026
installed this mainly for the visibility audit, but ended up trying quite a few other things as well. The shopping assistant, speed improvements, and image optimisation all worked without any major issues. What stood out most is the visibility audit, it actually showed me how AI was seeing my store. After keeping it on for a while I started noticing better quality traffic, and the percentage of AI visitors has clearly gone up. Feels like a solid plugin overall and I’ll definitely keep using it.
31 iulie 2026
was honestly surprised how quick this started making a difference. After installing the plugin and getting it connected, I noticed ChatGPT and a couple other AIs could finally understand what my store is about and what products I actually sell. Before this a lot of my product pages just got ignored or misunderstood. Now the information comes through much clearer when I test it. Setup was pretty straightforward and didn’t take long. For a WooCommerce store this has been a real improvement so far, and it feels like something that was missing.
21 iulie 2026
We had a really good experience working with the xpay team. The setup was quite simple and they helped us through everything, whenever we had questions they were quick to respond and explain. We also liked that we did not have to change our current checkout or make any changes to the website.. everything’s automated! The plugin works with our existing WooCommerce store and helps make the products more understandable for AI shopping platforms. Overall the whole process was smooth, support was very good and the team made sure everything was working properly. Happy with the experience and would definitely recommend it to other WooCommerce store owners.
20 iunie 2026
I loved the ease of connecting this plugin. I activated, setup the account, it picked my store, showed me a clear audit of what’s gotta be improved, visibility score, readiness score, actions to be done etc. important changes are pushed to GMC automatically, overall a must have for store owners..
Citește toate cele 5 recenzii

Contributori și dezvoltatori

„Agentic Commerce for WooCommerce” este un software open-source. La acest modul au contribuit următoarele persoane.

Contributori

Istoric modificări

The full machine-readable changelog lives at install.xpay.sh/woocommerce/CHANGELOG.md (Keep-a-Changelog format). The summary below is the WP.org-required mirror.

0.6.3

  • The AI Storefront Assistant now loads reliably alongside caching/optimization plugins. When WP Rocket, LiteSpeed Cache, Autoptimize or SiteGround Optimizer minifies, combines, delays or self-hosts JavaScript, it could break the assistant loader so the chat bubble never appeared — while everything looked fine in an incognito/preview window. The loader is now excluded from those optimizers automatically, so you no longer need to add a manual exclusion. (For W3 Total Cache or an edge cache, which have no runtime hook, the plugin still shows a one-line manual-exclusion note.)
  • Fixed: the assistant could show „Array” instead of your store name on multilingual stores. A localized store name is now resolved to your store’s language before it’s displayed.
  • No other storefront changes — reliability fixes only.

0.6.2

  • Your approved product FAQs can no longer be wiped by a partial or interrupted sync. Previously, every FAQ sync replaced the entire stored set with whatever it received — so if a sync ran with an incomplete list (a dropped connection, a catalog still rebuilding), any product left out had its FAQ silently deleted. A sync that would shrink your FAQ set by more than half is now refused unless it explicitly confirms a full replace, so an accidental one fails loudly instead of clearing your pages.
  • A single product’s FAQ can now be updated on its own. Approving one new product, editing one answer, or changing the heading no longer resends every FAQ — the update touches only the products it names and leaves the rest exactly as they were. Only the changed product pages are cleared from your cache.
  • No visible change to your storefront; these are safety improvements to how xpay keeps your FAQs in sync.

0.6.1

  • Enabling the AI Storefront Assistant now works immediately on a cached store. If you run WP Rocket, LiteSpeed, WP Super Cache, W3 Total Cache, WP Fastest Cache, Cache Enabler or SiteGround, your pages were served from the cache before our code ran — so you could switch the assistant on and see nothing change, sometimes for hours, until each page’s cache happened to expire. The page cache is now cleared when you turn the assistant on or off. (Cloudflare APO caches at the edge and can only be purged with your own Cloudflare credentials; those stores still wait for the edge TTL. Developers can hook xpay_wc_purge_site_cache to wire up any other stack.)
  • Fixed: the full-page shopper could stay a 404 after you enabled it. The page is only reconciled when someone loads wp-admin or an hourly job runs, and it refuses to publish until your account is confirmed as entitled — so if you enabled it before that confirmation landed, your own link was dead and nothing retried it. It can now be published on demand.
  • Your shopper page is no longer renamed behind your back. If you retitled it or changed its slug, we were silently restoring our own value every time the page was reconciled — breaking your menu link. Your edits are now left alone.
  • New: open a side-cart drawer from an off-site link. Stores using a side-cart plugin (such as Caddy) often retire the /cart/ page entirely, leaving any link to it a dead end. A link ending in #open-cart now opens the drawer instead. Does nothing on stores without a side cart. Developers can switch it off with add_filter( 'xpay_wc_side_cart_bridge', '__return_false' );.

0.6.0

  • The on-page FAQ block now has an off switch. For products you approve, xpay publishes FAQ schema that AI shoppers and search engines read. Until now it also injected a visible FAQ section into your product pages, with no way to say no — that switch now exists, managed from your xpay account. New installs start with the block off. Stores already displaying it keep displaying it (this release doesn’t strip it off your live pages) and can now have it turned off. Either way the schema is unaffected: approving a FAQ publishes the answers to AI shoppers; showing them to your own shoppers is a separate decision. Developers can force it off from their own code with add_filter( 'xpay_wc_faq_visible', '__return_false' );.
  • The FAQ block works on page-builder themes. It can now render as a WooCommerce product tab, which Elementor and similar builders display — previously it hung off a hook those themes never call, so stores built with them saw nothing at all. There’s also an [xpay-faq] shortcode if you want to place it exactly where you like. Classic themes keep the original placement.
  • FAQ answers show in your own language. The section heading arrives with the FAQ content instead of being hardcoded English, so a French store gets a French heading. It’s now called „Additional questions” rather than „Frequently asked questions” — these answer the commerce facts (delivery, returns, variants) that your own product FAQ usually doesn’t.
  • FAQ changes appear immediately on cached stores. If you run LiteSpeed, WP Rocket, WP Super Cache or W3 Total Cache, the cached copy of a product page was served before our code ran — so an updated FAQ stayed invisible until the cache happened to expire. Product pages are now cleared from the cache whenever their FAQ changes.
  • Non-returnable products no longer advertise a return window. A product marked as non-returnable was still emitting a 14-day return window in its schema, contradicting its own FAQ text. The return category, method and fees you set are now used as given.
  • One FAQPage per page. Where xpay can see that another plugin (Rank Math, a dedicated FAQ plugin) already publishes FAQ schema on a product page, it stands down instead of adding a competing one.

0.5.3

  • AI referrals are now detected even when your pages are cached. If your store runs a page cache, the cached HTML is served before our code runs — so a shopper arriving from ChatGPT looked identical to someone typing your address in. Detection now also happens in the browser and reports back to a page that is never cached, which is how WooCommerce’s own order-source tracking works. Referrals from AI assistants stop silently disappearing.
  • Works with WP Rocket out of the box. Our referral tag no longer gets swallowed by WP Rocket’s cache, and it does not create a second cached copy of the page.
  • A „likely AI (unconfirmed)” signal, kept honest. Some AI apps (ChatGPT’s iOS app, the Atlas browser) send no clue at all — Atlas even identifies itself as ordinary Chrome, so no rule can ever spot it for certain. Where an order arrives with no referrer straight onto a deep product page, we now flag it as possible AI influence and show it separately. It is never counted as confirmed AI revenue.
  • Fixed: Google crawls could have been mislabelled as AI traffic. Gemini’s fetcher identifies itself as exactly „Google”, which is also the start of „Googlebot” — we now require an exact match, so your ordinary Google search crawling is never misreported as an AI referral.
  • Better AI-crawler reporting. Repeat visits from the same crawler can now be grouped into sessions, using a salted daily hash of the bot’s address (never a person’s, and never the address itself). Added lmarena.ai and komo.ai; removed a rule that could never match anything.

0.5.2

  • See the orders AI agents actually place. WooCommerce’s built-in Agentic Checkout records a session ID on every order an AI agent completes through it. We now read that ID, so those orders show up in your dashboard as confirmed agent orders instead of being lumped in with everything else. This applies to new orders from now on — it can’t reach back and re-label past ones.
  • Attribution that survives page caching. If your store runs a page cache (WP Rocket, LiteSpeed and friends), the cached HTML is served before our code gets a chance to look at where the shopper came from — so referrals from ChatGPT and other assistants were being missed. We now also read WooCommerce’s own order-source data, which is recorded in the shopper’s browser and isn’t affected by caching.
  • Orders paid by bank transfer, cheque or cash on delivery are no longer skipped. Previously only orders that reached „Processing” or „Completed” were reported. Stores using offline payments, or shipping plugins with their own custom statuses (La Poste, for example), were missing roughly a fifth of their orders.
  • Order reporting no longer depends on a visitor arriving. Order events were queued for WordPress’s scheduler, which only runs when someone next loads a page — so on a quiet store an order could sit unsent for hours, or never send. Orders now dispatch straight after checkout, and a daily catch-up re-sends anything that slipped through the past week. Only runs on stores connected to xpay.

0.5.1

  • Help search engines find your articles. Your blog’s sitemap is now reachable on your own domain (yourstore.com/blog/sitemap.xml), and its address is added to your robots.txt automatically — so Google and other search engines discover and index your xpay articles faster. Only active when the blog feature is turned on, and it adds to your robots.txt without changing anything already there.

0.5.0

  • Publish your xpay articles on your own domain. Your Content Agent articles can now appear at yourstore.com/blog — on your own domain instead of a separate subdomain — so the pages build your site’s authority and are more likely to be cited by AI answer engines. Off until you turn it on; only the articles xpay created for you; your own content always wins if you already have a page at that address.

0.4.4

  • GDPR-aware attribution defaults. EU/UK stores (30-country list: all EU + EEA IS/LI/NO + UK) ship with the 30-day _xpay_ref persistence cookie OFF by default; the WC session still carries attribution through the active shopping journey (~48h). New xpay_wc_attribution_cookie_enabled option and xpay_wc_attribution_should_set_cookie filter for CMP integrations (Cookiebot, Iubenda, Complianz, etc.).
  • Asynchronous agentic-order attribution. Order summaries dispatch in the background via a wp_schedule_single_event cron job that fires immediately through WP-Cron loopback, keeping the shopper’s thank-you page on the critical path. An in-flight sentinel collapses concurrent completion hooks into a single dispatched job.
  • Resilient storefront-widget consent gate. Only successful entitlement responses are cached for an hour; transient backend failures use a 60-second breaker so a brief blip clears within a minute instead of locking the widget out for the full hour.
  • GTIN schema validation. Numeric identifiers continue to emit as length-keyed gtin8/gtin12/gtin13/gtin14; alphanumeric values now route to the bare gtin slot per schema.org so Google Search Console accepts the markup on every PDP.

0.4.3

  • AI-referred orders are now attributed and reported. When a shopper completes checkout after being referred by an AI assistant — through one of our links (sidecar, MCP, chat widget) or via a Referer / utm_source from ChatGPT, Perplexity, Claude, Gemini, Copilot, Meta AI, You.com, DeepSeek, Grok, Phind, Poe, Mistral, HuggingChat, Kagi or DuckDuckGo AI — the order surfaces in your xpay dashboard’s attributed-orders feed with revenue split by source. First-touch attribution carried in a first-party cookie (30 days, no third-party tracking).
  • Strict no-PII contract. Only order_id, placed_at, status, amount_total, amount_discount, currency, line_count, ordered SKUs and the attribution source leave your store. Never customer email, address, phone or IP. The server-side ingest enforces an allow-list on top-level keys as defence in depth.

As of 0.5.2 an attributed order may also carry: the WooCommerce Agentic Checkout session and provider ID (present only on orders an AI agent completed through WooCommerce’s own agentic checkout), and WooCommerce’s own order-source context — the channel type (utm/organic/referral/typein/admin), the device type, and the path of the page the shopper first landed on. The landing value is the path only: the host, query string and fragment are stripped before it leaves your store, so no tokens or personal data can ride along. Still never sent: customer email, address, phone, or IP.
* No re-authorization needed. Uses existing plugin permissions only — no new WooCommerce REST scope, no new merchant grant. WordPress will not surface a „permission change” prompt on auto-update.
* Includes everything from 0.4.2 (consent-gated AI Storefront Assistant, GTIN in product schema, defensive out-of-stock guard at the cart deeplink, variable-product carts, faster dashboard propagation).

0.4.2

  • AI Storefront Assistant is consent-gated. The chat bubble surfaces on your storefront only after you explicitly turn it on — either from the Storefront Assistant page in the xpay dashboard or from the WooCommerce settings toggle. A backend subscription or design-partner grant alone never renders the widget; you stay in control of what shows on your site.
  • GTIN in product schema. When your products carry a global_unique_id (WC 8.6+) or a legacy GTIN/EAN/UPC value, it’s emitted in the Product JSON-LD as gtin8/gtin12/gtin13/gtin14 so Google Shopping, Bing and AI shopping agents can match each PDP to the corresponding offer in your feed.
  • Defensive out-of-stock guard at the cart deeplink. The cart-deeplink handler refuses lines whose target product or variation is out of stock — a guard against stale agent responses or manual deeplinks arriving after a stock-out. If every line is rejected, you still get the existing „items unavailable” response.
  • Variable-product carts. Agent-minted carts pass the variation attribute map through to WC()->cart->add_to_cart() so variable-product lines flow into checkout correctly. Variation SKUs supplied without a separate variation id are resolved automatically.
  • Faster propagation. Toggle and appearance changes from the xpay dashboard take effect on your storefront within seconds.

0.4.1

  • New: Content Engine pages. When your store is subscribed to the Content Engine add-on, xpay can publish answer-first comparison, buying-guide and listicle pages — tuned to the questions AI assistants ask — as real Pages on your own domain (indexable, in your sitemap, human-visible, and discoverable by AI agents). Pages stay in sync automatically: published while subscribed, reverted to draft if you unsubscribe, and we only ever touch pages we created — your own content is never modified. Off by default; nothing publishes unless the add-on is active for your store.

0.3.7

  • Maintenance and reliability polish.
  • Optional agency/referral attribution: a store set up by a partner can carry that partner’s referral code — captured automatically from a referral link, entered on the Connect screen, or pinned by the installer. Counts only — no product, customer or order data is shared.

0.3.5

  • New: /agents.md agent skill. A dedicated, machine-readable skill served at yourstore.com/agents.md that tells AI shopping agents (and skill-using assistants) exactly how to connect to your store: browse the live catalog over MCP or REST, look products up, and build a cart that hands the shopper off to your existing checkout. Purpose-written connect-and-transact instructions — not a copy of /llms.txt. Served once your store is connected; like our other discovery files it steps aside quietly if you already publish your own /agents.md.
  • Hardened /llms.txt merge. When appending to an existing /llms.txt, the plugin ignores non-text responses. Hybrid/headless storefronts and single-page themes that answer every URL with an HTML page have that page rejected instead of pulled in above our agent-shopping sections.
  • Branded catalog link. The /llms.txt catalog link now points at your store’s own agent-commerce surface instead of the shared feed host (same data, your brand).
  • Optional AI shopping-bot routing. Realtime AI shopping assistants can be transparently routed to your structured catalog surface for cleaner, faster product data, while search/indexing crawlers stay on your store for citations. Centrally controlled and off by default — nothing changes for your site until xpay enables it for your store; never affects humans, logged-in users, your cart, or checkout.

0.3.4

  • Outcome-first Connect screen. The pre-connect panel leads with what you get — your products discoverable to ChatGPT, Claude, Gemini and Perplexity, with no code and no payment change — and demotes the protocol acronyms (llms.txt, schema.org, ACP/UCP/AP2/MCP) to a small footnote for technical reviewers.
  • Upfront safety promise. The Connect screen now states plainly what this update verified end-to-end: the plugin writes zero files to your site, doesn’t touch your theme or payments, appends to any existing /llms.txt rather than replacing it, and fully reverts the moment you deactivate.
  • New transparency panel. Once connected, the General tab lists every external service the plugin contacts (agent-feed.xpay.sh, agent-commerce.xpay.sh, app.xpay.sh) and what each receives, alongside the Terms and Privacy links.
  • Value-first telemetry opt-in. The anonymous-diagnostics prompt explains the benefit to you — we can flag a silently broken AI connection (failed sync, blocked endpoint) before your products drop out of ChatGPT, Claude and Perplexity. Still off by default, still no customer or order data, still changeable any time.

0.3.3

  • New: Run site diagnostics (Tools tab). One click loopback-checks the three layers that gate connection at the web server before WordPress runs: the WordPress REST API (Pretty Permalinks), the plugin’s own REST routes, and the /.well-known/ discovery files. Each row shows pass/fail with the HTTP status, and any failure renders the exact next step — switch Permalinks off „Plain”, or (on Apache/ACME hosts that reserve /.well-known/) the query-arg fallback URL that agents can still use.
  • No behaviour change to the connect flow itself. Diagnostics are network-only on the explicit button click; the Settings page still makes zero outbound calls on render.

0.3.2

  • Good neighbour with other AI/SEO plugins. If your site already publishes its own llms.txt (e.g. via Yoast SEO AI, RankMath AI, AIOSEO, or your own setup), the plugin appends our agent-shopping sections at the end of your file. Everything you wrote is preserved exactly as you wrote it; /.well-known/* JSON emitters defer to existing handlers cleanly.
  • Automatic detection. A daily WP-Cron probe (and a 6-hour transient cache) detects when another tool is publishing one of the same discovery files we do. When it sees one, we step aside or append cleanly — no merchant action needed.
  • Smoother connect experience. A handful of polish items in the Connect flow so the handshake is quicker and an idempotent retry resolves silently.
  • Backend-callable admin/refresh endpoint. Once you’re connected, xpay can flush local discovery caches and fine-tune small parts of your discovery setup without a plugin update. Constant-time site-token auth, local-only actions (no outbound HTTP triggered by the endpoint), forward-compatible action vocabulary.

0.3.1

  • REST endpoints constructed via rest_url(). The fallback UCP manifest now calls rest_url('xpay/ucp/v1') / rest_url('xpay/mcp') instead of hardcoding home_url('/wp-json/...'), so the plugin respects sites that customize the REST prefix. Per the WP.org Determining Locations guideline.
  • Tested against WordPress 7.0 + WooCommerce 10.8.1 on a clean sandbox with WP_DEBUG=true.

0.3.0

  • Privacy: no outbound calls on Settings page load. The Connect panel no longer pre-registers a nonce with the xpay backend when the page renders. The nonce is generated, the attempt is stamped, and the merchant is redirected to the xpay onboarding flow only after the Connect store button is clicked. Matches WordPress.org’s no-phoning-home guideline.
  • Requires Plugins: woocommerce header. Declares the WooCommerce dependency via the WP 6.5 plugin-dependencies mechanism so the plugin won’t activate without WooCommerce present. Existing manual activation check remains as defence-in-depth for pre-6.5 sites.
  • Inline admin script removed. The Connect button no longer emits an inline <script> tag; click-time telemetry is recorded server-side in the redirect handler instead.

0.2.4

  • Tabbed Settings xpay UI. Five tabs replace the single-screen layout: General (status + slug + last sync + disconnect + telemetry opt-in), Capabilities (per-UCP-capability toggles), Payments (map enabled WC gateways to UCP payment_handlers[]), Links (auto-detect privacy/TOS/about/contact/shipping with per-row override), Tools (view UCP profile, view full audit, test connection, refresh catalog now, telemetry debug log toggle). URL is bookmarkable via ?tab=.
  • Capability toggles wired into /.well-known/ucp. Switching off any of checkout / fulfillment / discount / order removes the entry from the emitted UCP manifest. Default (no option set) = all enabled, so existing installs don’t regress on upgrade.
  • payment_handlers[] now populated from the Payments tab. Each enabled gateway emits as {id, label, type:"merchant_gateway"} so UCP-aware agents can negotiate payment surfaces against the methods you actually accept.
  • ucp.links array. Privacy, TOS, About, Contact, Shipping URLs are auto-detected (WordPress privacy_policy_url + common page slugs) and overridable on the Links tab; emitted in the manifest as {rel, href} pairs.

0.2.3

  • MCP transport advertised in /.well-known/ucp. Native MCP-speaking agents (Claude, ChatGPT Operator, Shopify AI Toolkit) discover the endpoint at agent-commerce.xpay.sh/mcp/{slug} without further configuration. Three tools available: search_catalog (BM25-ranked over title + description), get_product (lookup by SKU or numeric product ID), create_cart (returns a signed deeplink that pre-populates checkout on your store).
  • One-click connect via WooCommerce’s /wc-auth/v1/authorize OAuth. When you click Connect store, the xpay onboarding page opens WooCommerce’s built-in approval popup. You approve there once and WordPress hands xpay read-only API credentials directly — no Settings Advanced REST API trip, no copy-paste. The manual paste flow remains available as a fallback.
  • Disconnect notifies the backend. Clicking Disconnect now fires a non-blocking DELETE /v1/merchants/{slug} so your account is marked disconnected and the cached agent-feed catalog is archived. Local cleanup happens regardless of whether the backend acks.
  • UCP manifest aligned with the 2026-04-08 spec. extends emitted as an array (["dev.ucp.shopping.checkout"]); capability spec URLs uniformly date-prefixed; payment_handlers: [] placeholder added for parity with the rest of the ecosystem.
  • Recovery guidance on incomplete Connect attempts. If you start a Connect flow but the handshake doesn’t complete, the Settings xpay page surfaces a clear „click Connect again” CTA and our ops team is notified automatically so we can assist.

0.2.2

  • Idempotent onboarding handshake. Plugin-side rest_finalize is idempotent on (slug, api_key) replay, so a re-click of Connect store is always safe within the nonce TTL. Initial catalog resync moved to wp_schedule_single_event + non-blocking wp_remote_post so the REST response returns in under a second on hosts whose outbound HTTPS to xpay is slow. Paired with a backend change that delivers credentials before consuming the nonce and surfaces a clear actionable error if the WP site is unreachable.

0.2.1

  • /llms.txt ## Commerce protocols section is now gated on the xpay_wc_protocol_endpoints wp_option (backend-pushed during Connect). Agents that follow a URL from /llms.txt reach a working service or a structured 501 — never a bare 404.
  • Companion: backend stubs at agent-commerce.xpay.sh/{ucp,acp,ap2,mcp}/... now return a 501 Not Implemented envelope with protocol, spec, merchant_slug, status, retry_after_seconds, and a docs link.
  • Filter xpay_wc_protocol_endpoints lets a mu-plugin override.

0.2.0

  • Aligned with the open commerce standards. Per-protocol surfaces (ACP, UCP, AP2, MCP) are now advertised in /llms.txt and hosted on xpay infrastructure. The plugin keeps the merchant’s domain to what genuinely belongs there: discovery files, JSON-LD, robots.txt allowlist.
  • NEW: /.well-known/ucp (UCP business profile, spec 2026-04-08). This is the file Google, Shopify, Etsy, Wayfair, Target and Walmart fetch to negotiate capabilities with your store. The plugin generates a sensible default profile pointing at xpay-hosted UCP service endpoints; commercial-tier merchants can override the body + inject JWK signing keys via the xpay_wc_ucp_profile and xpay_wc_ucp_signing_keys options.
  • Discovery layer is an extensible emitter registry. Each standard (/llms.txt, /.well-known/ucp, RFC 9728 OAuth metadata, A2A agent-card) is a registered emitter with a default-on/default-off flag and per-merchant override. Adding a new standard means adding a new emitter — no changes elsewhere in the plugin.
  • Added watchlist emitters (off by default):
    • /.well-known/oauth-protected-resource (RFC 9728) — turns on automatically when UCP OAuth Identity Linking is enabled for the merchant on the xpay side.
    • /.well-known/agent-card.json (A2A 1.0, IANA-registered 2025-08-01) — opt-in via the xpay_wc_emit_agent_card option once A2A adoption matures in commerce.
  • /llms.txt content refresh. Now links the agent-readable catalog, the per-protocol endpoints (ACP / UCP / AP2 / MCP), the cart-deeplink template, and top product categories. Markdown structure follows the llmstxt.org convention.
  • Admin readiness checklist updated to reflect the standards-based architecture — the „AI assistants know where to send a buyer” row now points at the per-protocol endpoints listed in /llms.txt, not at a single discovery file.
  • No breaking changes for merchants. Cart deeplink, catalog feed, JSON-LD injection, robots.txt allowlist, telemetry pipe and the WC REST onboarding flow are unchanged. The audit-readiness pills continue to all turn green after Connect.

0.1.12

  • Plugin renamed to „Agentic Commerce for WooCommerce” (slug agentic-commerce-for-woocommerce).
    • Why: the previous name „xpay for WooCommerce” was rejected at WordPress.org submission as too similar to Nexi XPay (an established Italian payment-gateway plugin for WC by Nexi Payments, ~6,000 installs since 2017). WordPress.org’s similarity check matches on the brand string regardless of category, and Nexi has prior art.
    • What changed: Plugin Name header, Text Domain (agentic-commerce-for-woocommerce), main file name (agentic-commerce-for-woocommerce.php), /languages/agentic-commerce-for-woocommerce.pot, admin page slug, plugin folder name inside the zip. User-Agent header for outbound HTTP. Settings page H1.
    • What didn’t change: the product, the architecture, the xpay brand identity (still the author + still in admin nav as „xpay”), backend services (agent-feed.xpay.sh, agent-commerce.xpay.sh, etc.), or anything else functional.

0.1.11

  • Cleared 4 PCP PrefixAllGlobals warnings:
    • uninstall.php now runs in an anonymous-closure IIFE — no top-level $option_keys / $key globals.
    • class-xpay-schema.php :: render_product() uses a local $xpay_product and skips the global $product declaration entirely. Direct wc_get_product(get_the_ID()) works on PDPs without WC’s template-loop side effect.
    • class-xpay-plugin.php :: woocommerce_active() uses raw get_option('active_plugins') + multisite merge + class_exists('WooCommerce') instead of filtering WP core’s active_plugins hook. Same behavior, no false-positive.

0.1.10

  • Tested up to WordPress 6.9 (PCP flagged 6.7 as below current). No code changes — verified compatibility on a real WC 9.x install.
  • Short description trimmed to 141 chars (PCP cap is 150).
  • Removed load_plugin_textdomain() call. Discouraged since WP 4.6 — WordPress.org-hosted plugins get translations loaded automatically by core via the plugin slug.
  • Excluded non-canonical markdown files (INSTAWP_TEST_WALKTHROUGH.md, README.md) from the release zip. The plugin zip should only contain files needed at runtime; READMEs and walkthroughs are repo-only.

0.1.9

  • Documentation URLs migrated docs.xpay.sh/products/woocommerce/* docs.xpay.sh/merchants/woocommerce/*. Merchants is the bucket; WooCommerce is one (of many future) integrations inside it. Future Shopify / BigCommerce docs will live as siblings.
  • No plugin functionality changed — readme + admin-UI links updated.

0.1.8

  • Punchier Description hero — leads with the buyer-side framing („Your next customer is asking ChatGPT, not Google”) instead of an abstract claim.
  • Pricing link updated everywhere to https://www.xpay.sh/pricing/?tab=agentic-commerce.
  • New documentation site at docs.xpay.sh/merchants/woocommerce — multi-page walkthrough covering install, WC REST API key generation, connect flow, privacy & telemetry, audit readiness checklist, and a troubleshooting guide. readme backlinks the docs at the right moments.
  • GitHub backlinks throughout the readme + FAQ (issue tracker, source browse).

0.1.7

  • xpaysh/xpay-for-woocommerce GitHub repo flipped public. Restored repo link references in readme.txt FAQ and „Source code” section so reviewers and merchants can browse the unminified source directly. GPLv2-or-later unchanged.

0.1.6

  • Removed GitHub repo link references from readme.txt to avoid a broken-link impression for reviewers (the source repo was private). Plugin is still GPLv2-or-later — the zip is the canonical, unminified source.

0.1.5

  • Query-arg fallback for the discovery file: hosts that intercept /.well-known/ (some shared hosts, CDN edges, ACME setups) can now serve the discovery file at /?xpay_route=acp. Discoverable via the Link header on the home page.
  • Post-activation redirect to Settings xpay now fires on any activation when the store hasn’t connected yet, not only on the very first activation. Skipped on bulk-activate.

0.1.4

  • WC HPOS + Cart/Checkout Blocks compatibility declared.
  • First-activation redirect to Settings xpay.
  • Privacy + Terms pages at install.xpay.sh/woocommerce/{privacy,terms}.html.
  • Plugin URI: xpay.sh/sellers/woocommerce www.xpay.sh/merchants/woocommerce/.

0.1.3

  • PHPCS WordPress-standard clean: 0 errors / 1 cosmetic warning.
  • phpcs.xml.dist ruleset added.
  • languages/xpay-for-woocommerce.pot generated.
  • WP.org listing assets (banner / icon / 5 screenshots).

0.1.2

  • Slug renamed xpay-woocommerce xpay-for-woocommerce (Guideline 17).
  • Telemetry now opt-in via first-activation admin notice; default OFF (Guideline 7).
  • Settings xpay Privacy toggle.
  • readme.txt External services and Privacy sections added.

0.1.1

  • Fire-and-forget lifecycle telemetry pipe (was always-opt-out; reworked to opt-in in 0.1.2).

0.1.0

  • Initial release. WP plugin scaffold; /llms.txt and /.well-known/agentic-commerce.json; JSON-LD on PDP / shop / home; robots.txt allowlist; cart-deeplink handler; webhook-driven resync; admin page with connect flow and audit-readiness checklist.