{"id":315682,"date":"2026-06-21T11:14:56","date_gmt":"2026-06-21T11:14:56","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/seoforge\/"},"modified":"2026-08-03T15:39:41","modified_gmt":"2026-08-03T15:39:41","slug":"brainwerk-seo-suite","status":"publish","type":"plugin","link":"https:\/\/cs.wordpress.org\/plugins\/brainwerk-seo-suite\/","author":23503111,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.8.1","stable_tag":"1.8.1","tested":"7.0.2","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"Brainwerk SEO Suite","header_author":"Stefan Kogelgruber","header_description":"Privacy-first WordPress SEO suite with built-in visitor analytics, source tracking, on-page analyzer, sitemap, redirects, 404-logger and Schema.org. Multisite-ready and GDPR-compliant.","assets_banners_color":"192245","last_updated":"2026-08-03 15:39:41","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/seoforge.brainwerk.at","header_author_uri":"","rating":5,"author_block_rating":0,"active_installs":0,"downloads":619,"num_ratings":1,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.7.5":{"tag":"0.7.5","author":"brainwerk","date":"2026-06-29 17:01:53"},"0.9.0":{"tag":"0.9.0","author":"brainwerk","date":"2026-06-29 17:26:26"},"1.0.0":{"tag":"1.0.0","author":"brainwerk","date":"2026-06-30 15:50:01"},"1.0.1":{"tag":"1.0.1","author":"brainwerk","date":"2026-07-01 05:57:51"},"1.1.0":{"tag":"1.1.0","author":"brainwerk","date":"2026-07-01 07:09:10"},"1.2.0":{"tag":"1.2.0","author":"brainwerk","date":"2026-07-01 09:50:51"},"1.3.1":{"tag":"1.3.1","author":"brainwerk","date":"2026-07-06 10:45:38"},"1.4.0":{"tag":"1.4.0","author":"brainwerk","date":"2026-07-20 17:49:03"},"1.5.0":{"tag":"1.5.0","author":"brainwerk","date":"2026-07-29 17:18:32"},"1.6.0":{"tag":"1.6.0","author":"brainwerk","date":"2026-07-30 15:58:50"},"1.7.0":{"tag":"1.7.0","author":"brainwerk","date":"2026-07-30 17:53:12"},"1.7.1":{"tag":"1.7.1","author":"brainwerk","date":"2026-08-01 11:45:54"},"1.8.0":{"tag":"1.8.0","author":"brainwerk","date":"2026-08-03 10:20:27"},"1.8.1":{"tag":"1.8.1","author":"brainwerk","date":"2026-08-03 15:39:41"}},"upgrade_notice":{"1.8.0":"<p>Adds a signature-verified peer-benchmark feed and AI-crawler\/bot-traffic visibility to the dashboard, richer (still fully anonymous) aggregate snapshot data, and corrects release notes that wrongly described the SEO benchmark network as off by default \u2014 it has been on by default since 1.4.0. Also fixes self-registration with the benchmark hub, which previously never worked without manually pasting a token. No database changes.<\/p>","1.7.1":"<p>Security fix for Multisite networks: one site&#039;s administrator could read, reconfigure and delete other sites&#039; data. Recommended for all Multisite users. Single-site installations are unaffected but should still update \u2014 this release also makes the analytics beacon respect Do Not Track and repairs Search Console sync (Pro). No database changes.<\/p>","1.7.0":"<p>Fixes visitor-country accuracy behind proxies\/CDNs, adds per-check SEO analyzer explanations, makes Pro features consistently labelled (and closes a region\/city data leak), refreshes the overview without a full reload, improves mobile layout, and completes the German translation. No database changes.<\/p>","1.6.0":"<p>Security &amp; hardening release: Multisite data reset is now correctly scoped per-site, scheduled reports use UTC, webhooks and the analytics beacon are hardened, and report e-mails are polished. No database changes. Recommended for everyone, especially Multisite networks.<\/p>","1.5.0":"<p>Adds a settings\/action audit log (Free: last 5 entries, Pro: full history + CSV export) and makes the weekly digest e-mail opt-in by default on fresh installs. Includes a database upgrade (new audit-log table) that runs automatically on activation.<\/p>","1.4.0":"<p>Adds a periodic review reminder (dismissible) and switches the opt-in SEO network sensor to on-by-default for fresh installs only \u2014 existing installs keep their current setting unchanged.<\/p>","1.2.0":"<p>Your settings now survive an uninstall and are restored automatically on reinstall. Nothing to do \u2014 it&#039;s on by default (toggle under Privacy).<\/p>","1.1.0":"<p>Adds the optional SEO benchmark network \u2014 contribute anonymous aggregate stats and compare against peers. Strictly opt-in, off by default. Nothing is sent unless you enable it.<\/p>","1.0.1":"<p>Fixes connecting to the optional &quot;SEO network&quot; sensor (registration token is now saved correctly). Recommended if you use the SEO network \/ fleet feature.<\/p>","1.0.0":"<p>Version 1.0! Reports are now dependency-free printable HTML (with a visitor-countries block), onboarding gains a GEO\/AEO step, accessibility is improved and schema migrations are hardened. Existing installs upgrade automatically.<\/p>","0.9.0":"<p>Generative Engine Optimization arrives: control AI crawlers, publish llms.txt, add FAQ schema and track AI-answer-engine traffic \u2014 plus free visitor-country analytics. Existing installs upgrade automatically.<\/p>","0.7.6":"<p>Multisite stats are now per-site: a new site selector switches between this site, the whole network, or any single subsite. Single-site installs are unaffected.<\/p>","0.6.0":"<p>Freemius integration is live. Existing Free installs keep working unchanged; Pro features require a license.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3580576,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3580576,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3580576,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3580576,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.7.5","0.9.0","1.0.0","1.0.1","1.1.0","1.2.0","1.3.1","1.4.0","1.5.0","1.6.0","1.7.0","1.7.1","1.8.0","1.8.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3590080,"resolution":"1","location":"assets","locale":"","width":2071,"height":1113},"screenshot-10.png":{"filename":"screenshot-10.png","revision":3590080,"resolution":"10","location":"assets","locale":"","width":1999,"height":871},"screenshot-11.png":{"filename":"screenshot-11.png","revision":3590080,"resolution":"11","location":"assets","locale":"","width":1996,"height":808},"screenshot-12.png":{"filename":"screenshot-12.png","revision":3590080,"resolution":"12","location":"assets","locale":"","width":2053,"height":610},"screenshot-13.png":{"filename":"screenshot-13.png","revision":3590080,"resolution":"13","location":"assets","locale":"","width":1984,"height":544},"screenshot-14.png":{"filename":"screenshot-14.png","revision":3590080,"resolution":"14","location":"assets","locale":"","width":2052,"height":1285},"screenshot-15.png":{"filename":"screenshot-15.png","revision":3590080,"resolution":"15","location":"assets","locale":"","width":2062,"height":1221},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3590080,"resolution":"2","location":"assets","locale":"","width":2005,"height":1240},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3590080,"resolution":"3","location":"assets","locale":"","width":2059,"height":1081},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3590080,"resolution":"4","location":"assets","locale":"","width":2074,"height":868},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3590080,"resolution":"5","location":"assets","locale":"","width":2074,"height":711},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3590080,"resolution":"6","location":"assets","locale":"","width":2079,"height":1276},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3590080,"resolution":"7","location":"assets","locale":"","width":2074,"height":406},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3590080,"resolution":"8","location":"assets","locale":"","width":2062,"height":1270},"screenshot-9.png":{"filename":"screenshot-9.png","revision":3590080,"resolution":"9","location":"assets","locale":"","width":1992,"height":1021}},"screenshots":{"1":"Dashboard \u2014 pageviews, unique visitors, bounce rate and a visits-over-time chart.","2":"Top pages \u2014 hits and unique visitors per URL.","3":"Live recent-visits log \u2014 page, source, device and browser, tracking-cookie-free.","4":"Top pages and top traffic sources side by side.","5":"Traffic by source type \u2014 direct, search, social, referral and more.","6":"Hourly visits plus browser and operating-system breakdowns.","7":"Device split \u2014 mobile, desktop and tablet.","8":"On-page SEO analyzer with per-post focus-keyword scoring.","9":"AI-powered SEO suggestions \u2014 bring your own EU-based Mistral key.","10":"Meta tags, Open Graph, Twitter Cards and Schema.org JSON-LD.","11":"Redirect manager \u2014 301\/302\/307\/308 with exact or wildcard matching.","12":"404 log \u2014 turn any missing URL into a redirect in one click.","13":"Health check \u2014 tables, cron jobs and sitemap status at a glance.","14":"Pre-launch sanity check across every module.","15":"Tools \u2014 test e-mails, CSV import\/export and data cleanup."}},"plugin_section":[262246],"plugin_tags":[232,131785,727,186,1557],"plugin_category":[36,55],"plugin_contributors":[268198],"plugin_business_model":[],"class_list":["post-315682","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-analytics","plugin_tags-gdpr","plugin_tags-redirect","plugin_tags-seo","plugin_tags-sitemap","plugin_category-analytics","plugin_category-seo-and-marketing","plugin_contributors-brainwerk","plugin_committers-brainwerk"],"banners":{"banner":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/banner-772x250.png?rev=3580576","banner_2x":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/banner-1544x500.png?rev=3580576","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/icon-128x128.png?rev=3580576","icon_2x":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/icon-256x256.png?rev=3580576","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/screenshot-1.png?rev=3590080","caption":"Dashboard \u2014 pageviews, unique visitors, bounce rate and a visits-over-time chart."},{"src":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/screenshot-2.png?rev=3590080","caption":"Top pages \u2014 hits and unique visitors per URL."},{"src":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/screenshot-3.png?rev=3590080","caption":"Live recent-visits log \u2014 page, source, device and browser, tracking-cookie-free."},{"src":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/screenshot-4.png?rev=3590080","caption":"Top pages and top traffic sources side by side."},{"src":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/screenshot-5.png?rev=3590080","caption":"Traffic by source type \u2014 direct, search, social, referral and more."},{"src":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/screenshot-6.png?rev=3590080","caption":"Hourly visits plus browser and operating-system breakdowns."},{"src":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/screenshot-7.png?rev=3590080","caption":"Device split \u2014 mobile, desktop and tablet."},{"src":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/screenshot-8.png?rev=3590080","caption":"On-page SEO analyzer with per-post focus-keyword scoring."},{"src":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/screenshot-9.png?rev=3590080","caption":"AI-powered SEO suggestions \u2014 bring your own EU-based Mistral key."},{"src":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/screenshot-10.png?rev=3590080","caption":"Meta tags, Open Graph, Twitter Cards and Schema.org JSON-LD."},{"src":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/screenshot-11.png?rev=3590080","caption":"Redirect manager \u2014 301\/302\/307\/308 with exact or wildcard matching."},{"src":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/screenshot-12.png?rev=3590080","caption":"404 log \u2014 turn any missing URL into a redirect in one click."},{"src":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/screenshot-13.png?rev=3590080","caption":"Health check \u2014 tables, cron jobs and sitemap status at a glance."},{"src":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/screenshot-14.png?rev=3590080","caption":"Pre-launch sanity check across every module."},{"src":"https:\/\/ps.w.org\/brainwerk-seo-suite\/assets\/screenshot-15.png?rev=3590080","caption":"Tools \u2014 test e-mails, CSV import\/export and data cleanup."}],"raw_content":"<!--section=description-->\n<p><strong>SEO and visitor analytics that never sell you \u2014 or your visitors \u2014 out.<\/strong><\/p>\n\n<p>Brainwerk SEO Suite is the all-in-one SEO and analytics toolkit for WordPress that keeps <strong>100 % of your data on your own server<\/strong>. No third-party or tracking cookies. No external analytics services. No ad-tech tracking pixels. No \"anonymous\" data brokering. Just clear, honest insight into how people find and use your site \u2014 plus everything you need to rank in search <em>and<\/em> in AI answer engines.<\/p>\n\n<h4>\ud83c\uddea\ud83c\uddfa Made in Europe. Made for Europe.<\/h4>\n\n<p><strong>Brainwerk SEO Suite is the European answer for privacy-first SEO and analytics \u2014 the solution built in the EU, for the EU.<\/strong><\/p>\n\n<p>Engineered in the EU, to EU standards, with <strong>privacy-by-design built into every query<\/strong> \u2014 never bolted on afterwards. Your analytics never leave your infrastructure, so you stay in control of your data and your visitors' trust.<\/p>\n\n<ul>\n<li><strong>Privacy-focused by default<\/strong> \u2014 IP anonymisation, daily-rotating visitor hashes, DNT-aware, configurable retention and one-click erasure. These are technical data-minimisation measures; whether a cookie\/consent banner is required depends on your configuration and jurisdiction and should be legally reviewed.<\/li>\n<li><strong>Built for NIS2-era governance<\/strong> \u2014 everything self-hosted, auditable and under your control, to support your GDPR and NIS2 data-governance obligations.<\/li>\n<li><strong>EU-based AI, optional<\/strong> \u2014 AI suggestions run on <strong>Mistral AI \ud83c\uddea\ud83c\uddfa<\/strong> with your own key, so even your AI workflow stays in Europe.<\/li>\n<li><strong>High-tech under the hood<\/strong> \u2014 pre-aggregated daily tables for sub-millisecond dashboards even past 100k+ visits\/month, hardened <code>%i<\/code> SQL, cached sitemap &amp; meta output, a REST API and full WP-CLI control.<\/li>\n<\/ul>\n\n<h4>Get found by search engines *and* AI<\/h4>\n\n<p>Search is changing. Brainwerk SEO Suite covers classic SEO <strong>and<\/strong> the new world of AI answer engines:<\/p>\n\n<ul>\n<li><strong>Generative Engine Optimization (GEO\/AEO)<\/strong> \u2014 control which AI crawlers may use your content (GPTBot, Google-Extended, ClaudeBot, PerplexityBot and more) straight from robots.txt, publish an <code>llms.txt<\/code> content manifest, add per-post FAQ schema (FAQPage + speakable), and see traffic arriving from ChatGPT, Gemini, Copilot, Perplexity &amp; Claude as its own source.<\/li>\n<li><strong>Meta engine<\/strong> \u2014 title, meta description, Open Graph, Twitter Cards, canonical, per-post overrides.<\/li>\n<li><strong>Schema.org JSON-LD<\/strong> \u2014 Article, Organization, BreadcrumbList, WebSite, FAQPage.<\/li>\n<li><strong>XML sitemap<\/strong> \u2014 chunked URL sets + custom robots.txt.<\/li>\n<li><strong>On-page SEO analyzer<\/strong> \u2014 score 0\u2013100 across 9 checks (focus keyword, alt text, internal links, readability).<\/li>\n<\/ul>\n\n<h4>Privacy-first analytics, built in<\/h4>\n\n<ul>\n<li><strong>Local visitor analytics<\/strong> \u2014 server-side pageviews, no third-party or tracking cookies, no external analytics services, no ad-tech tracking pixels.<\/li>\n<li><strong>Source attribution<\/strong> \u2014 search, social, referrers, UTM, direct, and AI answer engines.<\/li>\n<li><strong>Visitor countries<\/strong> \u2014 offline IP\u2192country lookup from a bundled database, no external calls (works on locked-down servers).<\/li>\n<li><strong>Top pages, entry\/exit pages, device + browser + OS breakdown.<\/strong><\/li>\n<li><strong>Redirect manager<\/strong> \u2014 301 \/ 302 \/ 307 \/ 308 with exact &amp; prefix matching, plus a <strong>404 log<\/strong> with one-click \"create redirect\".<\/li>\n<li><strong>AI suggestions<\/strong> \u2014 bring your own Mistral key for titles, meta descriptions and focus keywords.<\/li>\n<li><strong>Migration wizard<\/strong> \u2014 import metadata + redirects from Yoast, RankMath, AIOSEO.<\/li>\n<li><strong>Multisite-aware<\/strong> \u2014 network activation, network-wide settings, per-site overrides.<\/li>\n<\/ul>\n\n<h4>Plays nicely with Yoast, RankMath &amp; co.<\/h4>\n\n<p>Already running another SEO plugin? Brainwerk SEO Suite auto-detects it and stands down its meta, schema and sitemap modules \u2014 so you keep <strong>analytics, the 404 log, redirects and the analyzer<\/strong> as a clean add-on, with no duplicate output. One toggle forces full takeover whenever you're ready to switch.<\/p>\n\n<h4>Go Pro<\/h4>\n\n<p>The Pro tier (via Freemius license) adds:<\/p>\n\n<ul>\n<li>Google Search Console &amp; Bing Webmaster sync<\/li>\n<li>Region &amp; city geolocation drill-down (Free already covers countries)<\/li>\n<li>Slack \/ Discord \/ MS-Teams webhook alerts<\/li>\n<li>Traffic anomaly detection (Z-score baseline, 3\u03c3 alerts)<\/li>\n<li>Multisite-aggregate dashboard, white-label branding, priority support<\/li>\n<\/ul>\n\n<h4>\ud83c\uddea\ud83c\uddfa Auf Deutsch \u2014 kurz &amp; knapp<\/h4>\n\n<p><strong>Die europ\u00e4ische Antwort f\u00fcr datenschutzfreundliches SEO &amp; Analytics \u2014 die L\u00f6sung aus der EU f\u00fcr die EU.<\/strong><\/p>\n\n<p>Brainwerk SEO Suite ist das All-in-one-SEO- und Analytics-Tool f\u00fcr WordPress, das <strong>100 % deiner Daten auf deinem eigenen Server<\/strong> beh\u00e4lt. Keine Tracking-Cookies, keine externen Analytics-Dienste, keine Ad-Tech-Tracking-Pixel, kein Datenhandel \u2014 nur ehrliche Insights und alles, was du brauchst, um in Suchmaschinen <strong>und<\/strong> in KI-Antwortmaschinen gefunden zu werden.<\/p>\n\n<ul>\n<li><strong>Made in Europe, made for Europe<\/strong> \u2014 in der EU nach EU-Standards entwickelt, Privacy-by-Design in jeder Abfrage<\/li>\n<li><strong>Datenschutzfreundlich ab Werk<\/strong> \u2014 IP-Anonymisierung, t\u00e4glich rotierende Besucher-Hashes, DNT-treu, konfigurierbare Aufbewahrung und Ein-Klick-L\u00f6schung. Ob ein Cookie-\/Consent-Banner n\u00f6tig ist, h\u00e4ngt von Ihrer Nutzung ab und ist rechtlich zu pr\u00fcfen.<\/li>\n<li><strong>F\u00fcr die NIS2-\u00c4ra gebaut<\/strong> \u2014 alles selbst gehostet, auditierbar und unter deiner Kontrolle<\/li>\n<li><strong>EU-KI<\/strong> \u2014 AI-Vorschl\u00e4ge laufen optional \u00fcber <strong>Mistral AI \ud83c\uddea\ud83c\uddfa<\/strong> mit deinem eigenen Key<\/li>\n<li><strong>GEO\/AEO<\/strong> \u2014 KI-Crawler steuern (GPTBot, Google-Extended, ClaudeBot \u2026), <code>llms.txt<\/code>, FAQ-Schema, KI-Traffic-Tracking (ChatGPT, Gemini, Perplexity, Claude)<\/li>\n<li><strong>Echte Anonymit\u00e4t im Benchmark-Netzwerk<\/strong> \u2014 unter 50 Seitenaufrufen\/Tag, unter 10 Core-Web-Vitals-Messungen oder unter 5 analysierten Beitr\u00e4gen wird der jeweilige Wert gar nicht erst gesendet; Werte wie KI-Crawler-Traffic werden nur geb\u00e4ndert (nie als exakte Zahl) \u00fcbertragen \u2014 deshalb ist <strong>kein AV-Vertrag<\/strong> f\u00fcr diese Funktion n\u00f6tig<\/li>\n<li><strong>Neu ab 1.8.0 \u2014 signaturgepr\u00fcfte Branchenvergleiche<\/strong> \u2014 das Benchmark-Netzwerk holt jetzt zus\u00e4tzlich einen Ed25519-signierten Feed vom Hub zur\u00fcck, damit du Absprungrate, Sitzungsdauer und Analyzer-Checks mit anonymisierten Branchen-Peers vergleichen kannst; ungepr\u00fcfte oder veraltete Feeds werden grunds\u00e4tzlich verworfen. Das Netzwerk ist <strong>standardm\u00e4\u00dfig aktiv<\/strong> und l\u00e4sst sich jederzeit mit einem Klick abschalten \u2014 fr\u00fchere Formulierungen, die \"standardm\u00e4\u00dfig deaktiviert\" behaupteten, waren falsch und wurden korrigiert.<\/li>\n<li><strong>Neu ab 1.8.1 \u2014 Report-Dateien mit unr\u00e4tbarem Dateinamen<\/strong> \u2014 erzeugte SEO-Reports (w\u00f6chentlich\/monatlich\/individuell) trugen bisher einen vorhersehbaren Dateinamen, der auf manchen Serverkonfigurationen direkt \u00fcber die Adresse erreichbar war. Reportdateien bekommen jetzt zus\u00e4tzlich ein langes Zufalls-Token im Namen, bestehende Reports werden beim Update automatisch umbenannt \u2014 kein Handlungsbedarf, einfach aktualisieren.<\/li>\n<li><strong>High-Tech im Maschinenraum<\/strong> \u2014 Sub-Millisekunden-Dashboards, geh\u00e4rtetes SQL, REST-API &amp; WP-CLI<\/li>\n<li><strong>Alles aus einer Hand<\/strong> \u2014 Analytics, Meta, Schema.org, Sitemap, Redirects, 404-Log, Analyzer<\/li>\n<\/ul>\n\n<p>Bereits Yoast oder RankMath im Einsatz? Brainwerk erkennt das automatisch und schaltet seine Meta-\/Schema-\/Sitemap-Module ab \u2014 du beh\u00e4ltst <strong>Analytics, 404-Log, Redirects und Analyzer<\/strong> als sauberes Add-on, ohne Doppelausgabe.<\/p>\n\n<h3>External services<\/h3>\n\n<p>The optional AI features connect to <strong>one external AI provider, Mistral AI (EU-based)<\/strong>. They are <strong>opt-in<\/strong> and only used when you explicitly enter your own API key.<\/p>\n\n<p><strong>Mistral AI API \u2014 <code>https:\/\/api.mistral.ai<\/code><\/strong> (EU-based)<\/p>\n\n<ul>\n<li><strong>What it is used for:<\/strong> Generating AI suggestions for SEO titles, meta descriptions, focus keywords and internal-link recommendations when you click the \"\u2728 Suggest with AI\" buttons in the on-page meta box or the AI tab.<\/li>\n<li><strong>When data is sent:<\/strong> Only when an editor clicks one of the AI-suggestion buttons in the WordPress admin. No data is sent on the front-end, during normal page views, or in cron jobs.<\/li>\n<li><strong>What data is sent:<\/strong> Your own Mistral API key (you supply it; the plugin does not bundle one), the post title and the post body content of the post you are editing, plus a short instruction prompt. Nothing else \u2014 no user identifiers, no site-wide content, no analytics.<\/li>\n<li><strong>How to disable:<\/strong> Leave the API key field empty in <em>Brainwerk SEO Suite \u2192 AI<\/em> settings, or toggle the AI feature off. With no key, the plugin never contacts any AI provider.<\/li>\n<li><strong>Provider:<\/strong> Mistral AI (France\/EU) \u2014 <a href=\"https:\/\/mistral.ai\/terms\/\">Terms of Service<\/a> \u2014 <a href=\"https:\/\/mistral.ai\/terms\/#privacy-policy\">Privacy Policy<\/a><\/li>\n<li><strong>API documentation:<\/strong> <a href=\"https:\/\/docs.mistral.ai\/\">https:\/\/docs.mistral.ai\/<\/a><\/li>\n<\/ul>\n\n<p><strong>SEO benchmark network \u2014 <code>https:\/\/shieldforge-intel.brainwerk.at<\/code><\/strong> (EU-based) \u2014 <strong>on by default, disclosed during onboarding<\/strong><\/p>\n\n<ul>\n<li><strong>What it is used for:<\/strong> The plugin sends one aggregate snapshot per day so you can compare your site against anonymised peers in your industry, and (Multisite) pulls back a signature-verified peer-benchmark feed. Enabled from install so the benchmark data is populated from day one; you can turn it off at any time.<\/li>\n<li><strong>When data is sent:<\/strong> Only after the site has completed a lightweight registration step with the hub (shown during onboarding, or under <em>Brainwerk SEO Suite \u2192 Tools \u2192 SEO network<\/em>). Nothing is transmitted before registration completes, and you can disconnect any time.<\/li>\n<li><strong>What data is sent:<\/strong> Aggregate figures only, all counts and percentages over the whole site for one UTC day \u2014 visit\/session totals, traffic-source\/device\/bot-share percentages, p75 Core Web Vitals, on-page-analyzer score distribution and per-check pass\/fail rates, an hour-of-day\/day-of-week traffic profile, AI-crawler visibility (which recognised crawler families visited, banded \u2014 never the exact count \u2014 plus your robots.txt\/llms.txt configuration), a declared\/suspect\/cloaked bot mix, coarse comparability bands (PHP major version, WordPress minor version, site-size and traffic bands, whether a page cache is active) and an optional self-declared industry label. On a Multisite network, the subsite's hostname is included so snapshots can be told apart (not shared publicly). <strong>Below 50 pageviews in a day, or below 10 Core Web Vitals samples, or below 5 analysed posts, the corresponding figures are suppressed entirely rather than sent<\/strong> \u2014 at that volume a percentage would describe one visitor, not a population. <strong>Never<\/strong> an individual visitor, IP address, URL or any personal data.<\/li>\n<li><strong>Also exposed:<\/strong> a read-only <em>inbound-pull<\/em> REST route (<code>GET \/wp-json\/seoforge\/v1\/relay\/snapshot<\/code>) for sites whose server cannot make outbound requests \u2014 the hub fetches the same daily snapshot instead, authenticated with a secret you (or the hub operator) configure; disabled unless a relay secret is set. A companion <em>inbound feed<\/em> endpoint (the hub's <code>GET \/v1\/seo\/intel<\/code>) lets this site pull back an Ed25519-signature-verified peer-benchmark\/bot-reputation feed once a day \u2014 the fetch carries no visitor data, only the site's existing HMAC identity.<\/li>\n<li><strong>How to disable:<\/strong> Turn it off, or click <em>Disconnect<\/em>, under <em>Tools \u2192 SEO network<\/em>. When off, the plugin never contacts the hub and the inbound-pull route returns 404.<\/li>\n<li><strong>Provider:<\/strong> Brainwerk (Austria\/EU) \u2014 <a href=\"https:\/\/brainwerk.at\/datenschutz\/\">Privacy Policy<\/a><\/li>\n<\/ul>\n\n<p>Licensing for the optional Pro tier is handled by Freemius (Merchant of Record). License-validation traffic \u2014 only performed when you activate a Pro license on the <em>License<\/em> tab \u2014 goes to <code>https:\/\/api.freemius.com<\/code>. See the <a href=\"https:\/\/freemius.com\/terms\/\">Freemius Terms of Service<\/a> and <a href=\"https:\/\/freemius.com\/privacy\/\">Privacy Policy<\/a>. With no Pro license entered, the plugin never contacts Freemius.<\/p>\n\n<p><strong>Visitor-country lookup is offline.<\/strong> The Free country-level geolocation uses a compact IP\u2192country database <strong>bundled inside the plugin<\/strong> and resolved locally \u2014 it makes <strong>no external requests<\/strong>. The bundled data is derived from the <strong>DB-IP IP-to-Country Lite<\/strong> database by DB-IP, licensed under <a href=\"https:\/\/creativecommons.org\/licenses\/by\/4.0\/\">Creative Commons Attribution 4.0 International (CC BY 4.0)<\/a>. IP Geolocation by <a href=\"https:\/\/db-ip.com\">DB-IP<\/a>. The Pro region\/city drill-down uses MaxMind's GeoLite2 City database (downloaded once to your server when you enable it); this product includes GeoLite2 data created by MaxMind, available from <a href=\"https:\/\/www.maxmind.com\">https:\/\/www.maxmind.com<\/a>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>seoforge<\/code> folder to <code>\/wp-content\/plugins\/<\/code> (or install via the WordPress Plugin Directory).<\/li>\n<li><strong>Activate<\/strong> the plugin on the Plugins page, or <strong>Network Activate<\/strong> on Multisite.<\/li>\n<li>Open <em>Brainwerk SEO Suite<\/em> in the admin menu and complete the 3-step setup wizard.<\/li>\n<li>(Optional) On the <em>License<\/em> tab, activate a Pro license to unlock Pro modules.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20brainwerk%20seo%20suite%20work%20with%20yoast%20%2F%20rankmath%20%2F%20aioseo%20already%20installed%3F\"><h3>Does Brainwerk SEO Suite work with Yoast \/ RankMath \/ AIOSEO already installed?<\/h3><\/dt>\n<dd><p>Yes. Brainwerk SEO Suite auto-detects the active SEO plugin and stands down its meta, schema, sitemap and robots modules so there's no duplicate output. Analytics, the 404 log, redirects and the on-page analyzer keep working side by side. A single toggle on the <em>Privacy \/ GDPR<\/em> tab forces takeover whenever you want.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20add%20tracking%20cookies%3F\"><h3>Does this plugin add tracking cookies?<\/h3><\/dt>\n<dd><p>Brainwerk SEO Suite uses no third-party or cross-site tracking cookies (only a first-party session cookie), anonymizes IPs and respects DNT by default. Whether your site needs a consent banner overall depends on all services you run and your jurisdiction \u2014 please assess this yourself, if needed with legal advice. The bundled privacy snippet documents exactly what is stored so you can paste it into your own privacy policy.<\/p><\/dd>\n<dt id=\"is%20the%20analytics%20data%20accurate%20without%20javascript%3F\"><h3>Is the analytics data accurate without JavaScript?<\/h3><\/dt>\n<dd><p>The server-side mode catches all real requests, including users who block JavaScript or use strict tracking-protection. It does count fewer \"bot-like\" visits than JS-based analytics because we filter known crawler user agents. A JS beacon mode for time-on-page and scroll depth is included if you want the extra signal.<\/p><\/dd>\n<dt id=\"will%20brainwerk%20seo%20suite%20slow%20down%20my%20site%3F\"><h3>Will Brainwerk SEO Suite slow down my site?<\/h3><\/dt>\n<dd><p>The tracker only inserts one row per pageview (no joins, no remote calls). All dashboards read from a pre-aggregated daily table, so the admin pages are sub-millisecond even at 100k+ visits per month. The sitemap and meta output are cached.<\/p><\/dd>\n<dt id=\"is%20there%20a%20wp-cli%20command%3F\"><h3>Is there a wp-cli command?<\/h3><\/dt>\n<dd><p>Yes \u2014 <code>wp brainwerk-seo-suite stats<\/code>, <code>wp brainwerk-seo-suite purge<\/code>, <code>wp brainwerk-seo-suite cleanup<\/code>, <code>wp brainwerk-seo-suite aggregate<\/code>, <code>wp brainwerk-seo-suite export<\/code>, <code>wp brainwerk-seo-suite import-redirects<\/code>, <code>wp brainwerk-seo-suite seed-demo<\/code> and <code>wp brainwerk-seo-suite license<\/code> (<code>wp seoforge seed-demo<\/code> and <code>wp seoforge import-redirects<\/code> also work as short aliases).<\/p><\/dd>\n<dt id=\"where%20is%20data%20stored%3F\"><h3>Where is data stored?<\/h3><\/dt>\n<dd><p>Six tables under the network prefix (<code>wp_seoforge_visits<\/code>, <code>_sessions<\/code>, <code>_redirects<\/code>, <code>_404<\/code>, <code>_meta<\/code>, <code>_daily<\/code>) and a settings option. Nothing leaves the server (Pro modules use opt-in external APIs).<\/p><\/dd>\n<dt id=\"where%20is%20the%20license%20server%3F\"><h3>Where is the license server?<\/h3><\/dt>\n<dd><p>Licensing is handled by Freemius (Merchant of Record). All license traffic goes to <code>api.freemius.com<\/code>. There is no Brainwerk SEO Suite-operated license server.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.8.1 \u2014 2026-08-03<\/h4>\n\n<ul>\n<li><strong>Security \u2014 report files now use unguessable filenames<\/strong>: generated SEO reports (weekly\/monthly\/custom) were previously saved under a predictable filename that could be reached directly by guessing the address on some server configurations. Report filenames now carry a long random token, and any existing report files are renamed to the new scheme automatically the next time an admin visits wp-admin after updating \u2014 no action needed. Users are recommended to update.<\/li>\n<\/ul>\n\n<h4>1.8.0 \u2014 2026-08-01<\/h4>\n\n<ul>\n<li><strong>New \u2014 signature-verified peer benchmarks<\/strong>: the SEO benchmark network now pulls back an Ed25519-signed feed from the hub as well as sending your own snapshot, so the dashboard can show how your bounce rate, session length and on-page-analyzer checks compare with anonymised peers in your industry. The feed is verified against pinned public keys before anything is trusted; it fails closed (silently ignored, never accepted unverified) if it can't be verified, is out of date, or looks like a replay of an older feed. A new \"Pull feed now\" button sits next to the existing push controls under <em>Tools \u2192 SEO network<\/em>.<\/li>\n<li><strong>New \u2014 AI-crawler and bot-traffic visibility<\/strong>: the dashboard gains a \"Bot &amp; AI-crawler traffic\" card showing your declared\/suspect\/cloaked bot mix and crawl-to-referral ratio, plus (once the peer feed is available) a read-time reputation note when traffic claims to be a known AI crawler but doesn't behave like one. Nothing here is inferred until the peer feed actually supplies it.<\/li>\n<li><strong>New \u2014 richer, still-anonymous benchmark snapshot<\/strong>: the daily aggregate snapshot now also includes on-page-analyzer score distribution and per-check failure rates, an hour-of-day\/day-of-week traffic profile, AI-crawler visibility (banded, never an exact count) with crawl-to-referral, your declared-bot mix, and coarse comparability bands (PHP\/WordPress version, site size, traffic volume). All of it is counts, percentages and bands \u2014 never a single visitor, IP, URL or raw crawler string.<\/li>\n<li><strong>Improved \u2014 stronger anonymity guarantees<\/strong>: days under 50 pageviews (or under 10 Core Web Vitals samples, or under 5 analysed posts for the analyzer figures) now send no metrics for that figure at all, rather than a low-confidence number. Small-sample countries are dropped from the country breakdown. Versions, site size and traffic are only ever sent as coarse bands, never exact values.<\/li>\n<li><strong>Corrected \u2014 consent wording<\/strong>: earlier release notes and onboarding copy described the SEO benchmark network as \"off by default.\" That was wrong \u2014 it has been <strong>on by default since 1.4.0<\/strong>, with a one-click switch-off in onboarding and under <em>Tools \u2192 SEO network<\/em>. The copy now says this plainly; nothing about the actual default has changed, only the description of it.<\/li>\n<li><strong>Clarified \u2014 external-service disclosures<\/strong>: the <em>External services<\/em> section below now documents the new inbound feed pull and the Multisite inbound-pull relay route, alongside the existing outbound snapshot.<\/li>\n<li><strong>Fix \u2014 the benchmark network now actually works for everyone, not just our own sites.<\/strong> Self-registration with the hub silently failed for every install that never pasted a token by hand, because no default registration token shipped with the plugin \u2014 the opt-in looked \"on\" but never connected. A rate-limited, publicly-scoped registration token (isolated to the SEO benchmark channel, no access beyond that) now ships with the plugin, and a failed registration is now shown in the admin card instead of failing silently.<\/li>\n<li>Adds automated regression tests covering all of the above (152 tests total). No database changes.<\/li>\n<\/ul>\n\n<h4>1.7.1 \u2014 2026-08-01<\/h4>\n\n<ul>\n<li><strong>Security \u2014 Multisite: sites can no longer see or affect each other.<\/strong> On a Multisite network, an administrator of one site could previously view another site's analytics via the site selector, change settings for the whole network by saving on their own site, and delete other sites' records with the \"Clean up now\" tool. All three are now correctly limited to the site the administrator actually manages; the network-wide view and network-wide settings remain available to Super Admins as before. <strong>Single-site installations were never affected by any of these.<\/strong><\/li>\n<li><strong>Privacy \u2014 the analytics beacon now honours \"Do Not Track\".<\/strong> The server-side tracker already respected the browser's Do-Not-Track signal; the JavaScript beacon (time on page, scroll depth, Core Web Vitals, outbound clicks) did not. Both now use the same rule, so a visitor sending DNT is not recorded at all.<\/li>\n<li><strong>Fix \u2014 Search Console sync (Pro) works again.<\/strong> The sync silently did nothing because the license key was never passed through; it now runs, and any failure is reported in the admin instead of failing quietly.<\/li>\n<li>Adds automated regression tests covering all of the above (78 tests total). No database changes.<\/li>\n<\/ul>\n\n<h4>1.7.0 \u2014 2026-07-30<\/h4>\n\n<ul>\n<li><strong>Fix \u2014 accurate visitor countries behind a proxy or CDN<\/strong>: sites served through a reverse proxy (e.g. nginx) or a CDN like Cloudflare were attributing most or all visits to a single wrong country (the proxy\/edge location). The plugin now detects the real client IP from the standard forwarded headers when the request comes through a trusted local proxy, so country stats are correct again. Manual override via <code>SEOFORGE_TRUSTED_PROXIES<\/code> still works.<\/li>\n<li><strong>New \u2014 the on-page SEO analyzer now explains every check<\/strong>: alongside the score, each check shows what was measured, whether it passed, and a concrete tip to improve it \u2014 in the post editor and as an expandable breakdown in the SEO list.<\/li>\n<li><strong>New \u2014 consistent, clear Pro labelling<\/strong>: every Pro-only feature now carries the same \"Pro\" badge and a proper upsell card (region &amp; city geolocation, Search Console &amp; Bing sync, traffic-spike alerts, the network-aggregate dashboard and the full audit log), so it's always obvious what's included in your plan.<\/li>\n<li><strong>Fix \u2014 region &amp; city drill-down is now correctly Pro-gated<\/strong>: the country \u2192 region\/city detail was being returned to Free installs; it is now enforced server-side as the Pro feature it is.<\/li>\n<li><strong>Change \u2014 the overview refreshes in place<\/strong>: switching the date range or site scope now updates just the dashboard widgets instead of reloading the whole page (with a graceful fallback if JavaScript is unavailable).<\/li>\n<li><strong>New \u2014 traffic-source tooltips<\/strong>: Direct, Internal, Search, Referral, Social, Campaign and AI answer engines each have a one-line explanation, so it's clear what every source means.<\/li>\n<li><strong>Improved \u2014 clearer AI answer engines section<\/strong>: a better explanation of AEO\/GEO traffic (visits arriving from ChatGPT, Gemini, Copilot, Perplexity, Claude and others).<\/li>\n<li><strong>Fix \u2014 mobile layout<\/strong>: wide tables and stat grids no longer overflow the screen on phones; tables scroll and grids reflow.<\/li>\n<li><strong>Improved \u2014 German translations completed<\/strong>: 113 previously-English admin strings are now translated for German (de_DE) and Austrian German (de_AT).<\/li>\n<li>Assorted i18n and licensing-consistency hardening. No database changes.<\/li>\n<\/ul>\n\n<h4>1.6.0 \u2014 2026-07-30<\/h4>\n\n<ul>\n<li><strong>Security \u2014 Multisite data reset is now per-site<\/strong>: the <em>Tools<\/em> reset actions (visitor stats and 404 log) now clear only the current site's rows instead of the shared network-wide tables, so a single-site admin can no longer wipe another site's analytics on a Multisite network.<\/li>\n<li><strong>Fix \u2014 scheduled reports use the correct time window<\/strong>: the automatic weekly\/monthly report crons now compute their date range in UTC (matching how visits are stored), so reports on non-UTC servers no longer drift. The monthly report e-mail is now correctly labelled (was mislabelled \"weekly\"), and report e-mail subjects are unified under the Brainwerk SEO Suite name.<\/li>\n<li><strong>Hardening \u2014 outbound webhooks &amp; settings import<\/strong>: Pro webhook alerts and imported settings now refuse URLs that resolve to internal\/loopback\/link-local addresses, closing a server-side request forgery (SSRF) vector.<\/li>\n<li><strong>Hardening \u2014 analytics beacon<\/strong>: the public beacon endpoint now also requires a rotating, site-signed token, on top of the existing origin check and per-IP rate limit.<\/li>\n<li><strong>Fix \u2014 race-free 404 logging<\/strong>: concurrent first hits to the same missing URL are now recorded with a single atomic upsert, so no hit is lost.<\/li>\n<li><strong>Fix \u2014 uninstall respects a per-site \"keep data\" choice<\/strong>: on Multisite, the shared data is kept if any site opted to keep it.<\/li>\n<li><strong>Polished report e-mails<\/strong>: dark-mode-aware colour scheme, hidden preview (preheader) text, accessible logo alt text, a document language attribute, and a \"Manage e-mail reports\" footer link.<\/li>\n<li><strong>European positioning<\/strong>: refreshed EU messaging (\"the European answer \u2014 from the EU, for the EU\") and removed third-party product comparisons from the marketing copy.<\/li>\n<li>Assorted i18n and defense-in-depth cleanups. No database changes.<\/li>\n<\/ul>\n\n<h4>1.5.0 \u2014 2026-07-29<\/h4>\n\n<ul>\n<li><strong>New \u2014 settings &amp; action audit log<\/strong>: a new <em>Audit Log<\/em> tab records who changed what and when (settings saved, redirects created\/deleted, license\/tier changes, the uninstall data-deletion choice, manual data resets, SEO-network opt-in\/opt-out) \u2014 a short human-readable summary only, never a raw diff of your data, so the privacy footprint stays small. The free build shows your last 5 entries with a Pro upsell; <strong>Pro<\/strong> gets full pagination and CSV export. A new <em>Privacy \u2192 Audit log retention<\/em> setting (default 180 days) keeps it tidy automatically.<\/li>\n<li><strong>Changed \u2014 weekly digest e-mail is now consent-first<\/strong>: on a fresh install, the weekly digest no longer looks \"on\" while silently sending nothing \u2014 it now defaults to off, matching the daily digest, until you explicitly enable e-mail reports (in onboarding or under <em>Tools \u2192 E-mail reports<\/em>). Existing installs are unaffected.<\/li>\n<li><strong>Changed \u2014 network admins can manage Reports<\/strong>: a network admin without their own admin rights on the active site can now open and use the Reports tab, matching how every other admin screen already behaves on Multisite.<\/li>\n<li><strong>Fix \u2014 Reports tab is now fully translatable<\/strong>: the last hardcoded UI strings on the Reports screen now go through the plugin's translation files, so nothing falls back to English on a translated site (source strings added to all 5 language catalogs).<\/li>\n<li>Assorted internal hardening and documentation cleanup; see <code>CHANGELOG.md<\/code> for the full list.<\/li>\n<\/ul>\n\n<h4>1.4.0 \u2014 2026-07-20<\/h4>\n\n<ul>\n<li><strong>New \u2014 periodic review reminder<\/strong>: a friendly, dismissible admin notice invites you to rate the plugin, starting 14 days after activation. Snooze it for another 14 days, or dismiss it for good \u2014 your choice is remembered.<\/li>\n<li><strong>Changed \u2014 SEO network sensor is on by default on fresh installs<\/strong>: the opt-in benchmark sensor (see <em>External services<\/em> below) now defaults to enabled for new installs, so benchmark data starts building from day one. It still transmits nothing until the site completes registration, and can be turned off any time under <em>Tools \u2192 SEO network<\/em>. Existing installs keep whatever they already had configured.<\/li>\n<\/ul>\n\n<h4>1.3.1 \u2014 2026-07-06<\/h4>\n\n<p>This is the first wp.org release since 1.2.0; it delivers everything from 1.3.0 to the public build plus one fix.\n* <strong>New \u2014 true PDF export for reports (Pro)<\/strong>: on Pro, both the standard report and the Executive (CEO\/CTO) report download as real, server-generated PDF files through a bundled PDF engine \u2014 no more relying on the browser's \"Save as PDF\". The free build is unchanged: it keeps the printable HTML report you save as PDF from your browser.\n* <strong>Fix \u2014 bundled translations now load<\/strong>: the plugin again registers its own <code>\/languages<\/code> folder (via <code>load_plugin_textdomain()<\/code> on <code>init<\/code>), so the shipped German, Spanish and French catalogs are actually used. Previously the admin stayed in English even on a translated site: wp.org's slug-based auto-loader only scans the global <code>wp-content\/languages\/plugins\/<\/code> folder, never the plugin's own bundled <code>\/languages<\/code> directory \u2014 so the catalogs shipped in the plugin were never picked up. Re-registering the folder is the wp.org-supported way to load bundled translations.\n* <strong>New \u2014 Austrian German (de_AT)<\/strong>: adds a <code>de_AT<\/code> catalog so Austrian-German sites are no longer shown in English (they previously got no German at all, because WordPress does not fall back from <code>de_AT<\/code> to <code>de_DE<\/code>).\n* <strong>Fix \u2014 Reports tab is reachable again<\/strong>: the Reports screen and its handlers existed but the tab was never registered in the admin tab list, so its menu entry had no link and <code>?tab=reports<\/code> silently fell back to the Dashboard. The tab is now wired into the <em>System<\/em> group.<\/p>\n\n<h4>1.3.0 \u2014 2026-07-04<\/h4>\n\n<ul>\n<li><strong>New \u2014 true PDF export for reports (Pro)<\/strong>: on Pro, both the standard report and the Executive (CEO\/CTO) report now download as real, server-generated PDF files through a bundled PDF engine \u2014 no more relying on the browser's \"Save as PDF\". The Executive report gains a one-click <em>Download as PDF<\/em> button. The free build is unchanged: it keeps the printable HTML report you save as PDF from your browser.<\/li>\n<li><strong>Fix \u2014 bundled translations now load<\/strong>: the plugin again registers its own <code>\/languages<\/code> folder, so the shipped German, Spanish and French catalogs are actually used. Previously the admin stayed in English even on a translated site because WordPress' just-in-time loader only scans the global translations folder. Adds an <strong>Austrian German (de_AT)<\/strong> catalog so <code>de_AT<\/code> sites are no longer shown in English.<\/li>\n<\/ul>\n\n<h4>1.2.0 \u2014 2026-07-01<\/h4>\n\n<ul>\n<li><strong>New \u2014 settings survive uninstall &amp; reinstall<\/strong>: your configuration is now kept in a private database backup, so if you delete and later reinstall the plugin, all your settings are restored automatically \u2014 no reconfiguring. The backup holds only your settings (never visitor data) and is never placed in a public folder. It even survives the \"delete all data on uninstall\" option. A new <em>Privacy \u2192 Remember settings for reinstall<\/em> toggle (on by default) lets you turn it off for a complete wipe.<\/li>\n<\/ul>\n\n<h4>1.1.0 \u2014 2026-07-01<\/h4>\n\n<ul>\n<li><strong>New \u2014 SEO benchmark network (opt-in)<\/strong>: contribute one aggregate snapshot per day (counts, percentages and p75 Core Web Vitals only \u2014 never a single visitor, IP or URL) and see how your site compares to anonymised peers in your industry. Strictly opt-in and off by default: a clear consent step in onboarding, plus a one-time invitation on the plugin's own screens. Available on every tier. Manage or disconnect any time under <em>Tools \u2192 SEO network<\/em>. Fully documented under <em>External services<\/em>.<\/li>\n<li><strong>New \u2014 pull transport for locked-down servers<\/strong>: sites whose PHP cannot make outbound HTTPS can still take part \u2014 the hub fetches the daily snapshot from an authenticated, read-only endpoint instead (the site makes no outbound connections).<\/li>\n<\/ul>\n\n<h4>1.0.1 \u2014 2026-07-01<\/h4>\n\n<ul>\n<li><strong>Fix<\/strong>: connecting to the optional \"SEO network\" sensor could fail with \"missing_register_token\" \u2014 the registration token, industry and enable toggle were silently dropped when saving settings. These are now persisted correctly, so connecting works.<\/li>\n<\/ul>\n\n<h4>1.0.0 \u2014 2026-06-30<\/h4>\n\n<ul>\n<li><strong>Printable reports, no PDF software required<\/strong>: the report generator now produces a self-contained, branded HTML report that any browser saves as PDF. This removes an external PDF library dependency, so reports work on every install \u2014 including locked-down servers.<\/li>\n<li><strong>Reports now include visitor countries<\/strong>: the report gained a \"Top countries\" block (flags + share bars) alongside the KPI grid, trend, sources and devices.<\/li>\n<li><strong>Onboarding<\/strong>: a new \"AI search readiness (GEO\/AEO)\" step lets you switch on the llms.txt manifest and FAQ schema right from the setup wizard.<\/li>\n<li><strong>Accessibility<\/strong>: clearer screen-reader labels on the redirect, 404 and visitor-country controls; decorative icons are now correctly hidden from assistive tech.<\/li>\n<li><strong>Hardening<\/strong>: database schema migrations now run only in the admin context (never triggered by a public front-end request), with a lock against concurrent runs.<\/li>\n<li><strong>Pro<\/strong>: opt-in \"SEO network\" sensor pushes one aggregate snapshot per day to power an agency fleet overview and anonymous peer benchmarks (counts and percentages only \u2014 never per-visitor data). Search Console performance (clicks, impressions, position, top queries) now has its own card.<\/li>\n<\/ul>\n\n<h4>0.9.0 \u2014 2026-06-29<\/h4>\n\n<ul>\n<li><strong>Generative Engine Optimization (GEO\/AEO)<\/strong> \u2014 a new toolkit to get your content surfaced and cited by AI answer engines:\n\n<ul>\n<li><strong>AI-crawler controls<\/strong>: one-click allow\/block for GPTBot, OAI-SearchBot, ChatGPT-User, ClaudeBot, Claude-User, PerplexityBot, Google-Extended, Applebot-Extended, Bytespider, CCBot and more \u2014 written straight into robots.txt.<\/li>\n<li><strong>llms.txt manifest<\/strong>: optionally publish <code>\/llms.txt<\/code> (+ <code>\/llms-full.txt<\/code>), a Markdown map of your key pages and posts for AI crawlers \u2014 generated automatically and cached.<\/li>\n<li><strong>FAQ schema<\/strong>: add question\/answer pairs per post\/page in the editor; output as FAQPage JSON-LD (plus <code>speakable<\/code> on articles) for rich results and AI answers.<\/li>\n<li><strong>AI-engine traffic<\/strong>: visits arriving from ChatGPT, Gemini, Copilot, Perplexity, Claude and other assistants are now classified as their own \"AI answer engines\" source, with a dedicated breakdown on the Sources tab.<\/li>\n<\/ul><\/li>\n<li><strong>Fix<\/strong>: saving settings on the Meta\/Schema tab silently did nothing after a slug rename (the form data was read under the wrong key). Settings now save correctly again.<\/li>\n<\/ul>\n\n<h4>0.8.0 \u2014 2026-06-29<\/h4>\n\n<ul>\n<li><strong>Visitor geolocation, now in Free<\/strong>: the Visitors tab gets a \"Visitor countries\" breakdown with flags and share-of-traffic bars, and recent visits show a country column. Country resolution runs entirely <strong>offline<\/strong> from a compact IP\u2192country database bundled inside the plugin (built from DB-IP Lite, CC BY 4.0) \u2014 no external requests, so it works on locked-down\/firewalled servers too. Covers both IPv4 and IPv6.<\/li>\n<li><strong>Pro \u2014 region &amp; city drill-down<\/strong>: with a Pro license, click any country to expand its top regions and cities, powered by MaxMind's GeoLite2 City database (read with a bundled, dependency-free reader). Country-level data stays available on Free.<\/li>\n<li><strong>Schema<\/strong>: visits and sessions gain <code>region<\/code> + <code>city<\/code> columns (DB upgrade to v4, applied automatically).<\/li>\n<li><strong>Demo data<\/strong>: the demo seeder now emits internally-consistent country\/region\/city so the new geolocation views look populated out of the box.<\/li>\n<\/ul>\n\n<h4>0.7.7 \u2014 2026-06-24<\/h4>\n\n<ul>\n<li><strong>Every e-mail now shares the same polished design<\/strong>: the traffic-spike alert, the scheduled report cover e-mails (auto weekly\/monthly and re-sends) and the \"send test\" e-mail were plain text or a bare one-liner \u2014 they now use the same branded HTML shell as the digests (navy gradient header with logo, status-coloured hero band, clean facts table, call-to-action button and the made-in-EU footer). Consistent look across every notification the plugin sends.<\/li>\n<li><strong>Richer traffic-spike alert<\/strong>: the anomaly alert now leads with a colour-coded hero (amber for a spike, red for an extreme spike) and a tidy breakdown \u2014 hour, human pageviews, z-score, rolling baseline and your alert threshold \u2014 plus a one-click button into the live dashboard. Slack\/Discord\/Teams webhook payloads are unchanged.<\/li>\n<li><strong>Fix \u2014 <code>\/favicon.ico<\/code> no longer counted as a page<\/strong>: favicon requests (and any other static asset that gets routed through WordPress) were recorded as visits and could top the \"Top pages\" report. They are now excluded from tracking (via <code>is_favicon()<\/code> plus a static-file-extension guard), so the report only shows real pages.<\/li>\n<li><strong>Fix \u2014 broken in-app links (\"Sorry, you are not allowed to access this page\")<\/strong>: links that pointed to the old <code>admin.php?page=seoforge<\/code> slug \u2014 the onboarding \"Start setup\" button, Site Health fixes, the dashboard widget, report\/e-mail buttons and others \u2014 led to a permission error because the admin page slug is <code>brainwerk-seo-suite<\/code>. All ~40 links now use the correct slug.<\/li>\n<\/ul>\n\n<h4>0.7.6 \u2014 2026-06-21<\/h4>\n\n<ul>\n<li><strong>E-mail reports \u2014 graphical daily &amp; weekly digests<\/strong>: the report e-mails are now beautifully designed HTML (brand header, KPI tiles with period-over-period trend arrows, traffic-source bars, top pages, Core Web Vitals ratings, human-vs-bot split) \u2014 everything at a glance. New <strong>daily<\/strong> digest in addition to the weekly one; configure recipient + cadence and send a test from <em>Tools \u2192 E-mail reports<\/em>.<\/li>\n<li><strong>Fix \u2014 Core Web Vitals, engagement &amp; new-visitor tracking now actually work<\/strong>: these metrics queried database columns that were never created or populated (they silently returned 0 and logged \"unknown column\" errors). The schema now includes <code>lcp_ms<\/code>\/<code>cls_x1000<\/code>\/<code>inp_ms<\/code>\/<code>is_engaged<\/code>\/<code>is_new_visitor<\/code> (DB upgrade to v3, applied automatically), new-visitor detection runs server-side, engagement + Core Web Vitals (LCP\/INP\/CLS, real field data) are captured via the front-end beacon (beacon\/hybrid tracking mode). Verified on a staging install.<\/li>\n<li><strong>Hardening &amp; cleanup<\/strong> (from an internal audit): Multisite isolation fix so a subsite admin can no longer delete\/toggle another site's redirect by id; removed a dead \"link check\" cron that fired into the void; report crons are now cleared on deactivation; minor robustness fixes.<\/li>\n<li><strong>AI \u2014 Mistral AI support (EU-based) + provider choice<\/strong>: AI suggestions can now run on Mistral AI \u2014 an EU-based provider, so your content stays in the EU \u2014 in addition to Anthropic (Claude). Choose your provider and model in the AI tab; Mistral is the new default for fresh installs. Still bring-your-own-key, encrypted at rest, fully opt-in.<\/li>\n<li><strong>Pro \u2014 Executive report (CEO \/ CTO)<\/strong>: a one-click, print-ready branded report for leadership. Pick an Executive (CEO), Technical (CTO) or Full\/Board preset, choose a period, and present it or save it as PDF from the browser. Includes period-over-period deltas, human-vs-bot split, traffic mix, geographic reach, top\/entry\/exit pages, Core Web Vitals ratings (overall and by device), new-vs-returning audience and a privacy\/compliance summary \u2014 rendered entirely from your own first-party data, no external service. The Free build shows a preview\/upsell.<\/li>\n<li><strong>Multisite<\/strong>: the analytics tabs (Dashboard, Visitors, Sources, Pages) and the at-a-glance dashboard widget now scope visitor stats per site. A new site selector lets you switch between <strong>this site<\/strong>, the <strong>entire network<\/strong> (aggregated), or any <strong>single subsite<\/strong>; the choice is remembered per user. Previously every subsite admin saw network-wide totals.<\/li>\n<li><strong>Multisite<\/strong>: the network Dashboard adds a per-site breakdown table (pageviews \/ unique visitors \/ sessions per subsite) with a one-click drill-down into each site.<\/li>\n<li><strong>Fix<\/strong>: <code>SEOFORGE_VERSION<\/code> was still reporting <code>0.7.4<\/code>; it is now back in sync with the plugin header.<\/li>\n<\/ul>\n\n<h4>0.7.5 \u2014 2026-06-19<\/h4>\n\n<ul>\n<li><strong>Security\/SQL<\/strong>: every plugin-owned table name that was previously interpolated into a query string is now passed through the <code>$wpdb-&gt;prepare()<\/code> <code>%i<\/code> identifier placeholder (WordPress 6.2+) instead of string interpolation. Conditional <code>WHERE<\/code> builders and the breakdown\/percentile switches were restructured so each <code>$wpdb-&gt;prepare()<\/code> call receives a string literal with placeholders only \u2014 no SQL string is built in a variable. The only remaining interpolation is the dynamic <code>post_type IN (...)<\/code> list, which uses generated <code>%s<\/code> placeholders bound through <code>prepare()<\/code> (an <code>IN()<\/code> list cannot use <code>%i<\/code>). Requires at least WordPress 6.2.<\/li>\n<\/ul>\n\n<h4>0.7.4 \u2014 2026-06-14<\/h4>\n\n<ul>\n<li><strong>Security<\/strong>: removed the last two cases of a column identifier being interpolated into SQL. The breakdown query (<code>Seoforge_Stats::group_count()<\/code>) and the Core Web Vitals percentile query (<code>Seoforge_Reports::percentile()<\/code>) now select a separate, fully literal query string per allowed column \u2014 the SQL identifier is never taken from a variable. All values continue to be bound through <code>$wpdb-&gt;prepare()<\/code>.<\/li>\n<\/ul>\n\n<h4>0.7.3 \u2014 2026-06-13<\/h4>\n\n<ul>\n<li><strong>Enqueue<\/strong>: the Reports tab no longer outputs an inline <code>&lt;script&gt;<\/code>; its quick-range helper moved into the enqueued <code>assets\/js\/admin.js<\/code>.<\/li>\n<li><strong>i18n<\/strong>: the last <code>seoforge<\/code> text-domain string now uses <code>brainwerk-seo-suite<\/code>, matching the plugin slug.<\/li>\n<li><strong>Security<\/strong>: report admin-post handlers sanitize the nonce with <code>sanitize_text_field( wp_unslash() )<\/code> and unslash\/sanitize all request values; the post meta box sanitizes its submitted array at input.<\/li>\n<\/ul>\n\n<h4>0.7.2 \u2014 2026-06-10<\/h4>\n\n<ul>\n<li><strong>Security<\/strong>: table names passed to the internal table-resolver are now validated against the fixed whitelist of plugin tables before being used in SQL.<\/li>\n<li><strong>Security<\/strong>: the migration coordinator builds its post-type <code>IN (...)<\/code> list from dynamically generated <code>%s<\/code> placeholders via <code>$wpdb-&gt;prepare()<\/code> instead of escaping + interpolation.<\/li>\n<li><strong>Security<\/strong>: internal report\/stats helpers validate metric and group-by column names against fixed whitelists before using them as SQL identifiers.<\/li>\n<\/ul>\n\n<h4>0.7.1 \u2014 2026-06-03<\/h4>\n\n<ul>\n<li><strong>Security<\/strong>: Schema.org JSON-LD is now emitted with slash-escaping (no <code>JSON_UNESCAPED_SLASHES<\/code>), so a value containing <code>&lt;\/script&gt;<\/code> can no longer break out of the inline <code>application\/ld+json<\/code> block. <code>\\\/<\/code> and <code>\\uXXXX<\/code> remain valid JSON-LD.<\/li>\n<\/ul>\n\n<h4>0.7.0 \u2014 2026-05-21<\/h4>\n\n<ul>\n<li><strong>Rebranded<\/strong> to Brainwerk SEO Suite (was: SEOForge). Display name + text-domain + plugin filename updated.<\/li>\n<li><strong>Security<\/strong>: nonce verification in the post meta box now goes through <code>sanitize_text_field( wp_unslash() )<\/code> (pluggable-function hardening).<\/li>\n<li><strong>Security<\/strong>: <code>$_COOKIE<\/code> reads in the tracker now go through <code>sanitize_text_field( wp_unslash() )<\/code> in addition to the existing hex-filter.<\/li>\n<li><strong>Security<\/strong>: SVG sparkline attributes in the dashboard widget now use <code>esc_attr()<\/code> for chart coordinates.<\/li>\n<li><strong>Security<\/strong>: WP-CLI <code>export --out=&lt;path&gt;<\/code> is now restricted to a <code>wp-content\/uploads\/seoforge\/<\/code> subdirectory (and writes only the basename) so it cannot clobber arbitrary paths.<\/li>\n<li><strong>wp.org compliance<\/strong>: removed the Pro-only bearer-key path from the REST <code>permission_callback<\/code>. The Free REST API is admin-cookie\/nonce only. Pro external dashboards stay in the separate Premium build.<\/li>\n<li><strong>wp.org compliance<\/strong>: removed <code>load_plugin_textdomain()<\/code> \u2014 WordPress 4.6+ auto-loads translations for plugins hosted on wp.org by slug.<\/li>\n<li><strong>wp.org compliance<\/strong>: weekly digest now uses <code>admin_url()<\/code> instead of a hard-coded <code>\/wp-admin\/<\/code> path.<\/li>\n<li><strong>Docs<\/strong>: readme now documents the optional Anthropic (Claude) API integration as an <code>== External services ==<\/code> section, with what is sent, when, how to disable, and links to Anthropic's Terms \/ Privacy.<\/li>\n<\/ul>\n\n<h4>0.6.0 \u2014 2026-05-19<\/h4>\n\n<ul>\n<li>Freemius integration live-wired end-to-end (real product IDs, SDK in <code>freemius\/<\/code>, <code>is_live=true<\/code>).<\/li>\n<li>Paid plans Starter (\u20ac59\/yr, 1 site) and Agency (\u20ac199\/yr, 25 sites) with auto-generated pricing table.<\/li>\n<li>New sanity row in the Tools tab reports SDK \/ opt-in \/ license state.<\/li>\n<li>Premium build script (<code>bin\/build-premium.sh<\/code>) for Freemius Deploy.<\/li>\n<li>Fix: <code>Seoforge_License::is_pro()<\/code> now uses <code>is_paying()<\/code> so Pro modules load in both Free and Premium builds with a valid license.<\/li>\n<li><code>uninstall.php<\/code> logic migrated to Freemius <code>after_uninstall<\/code> hook (per Freemius Deploy guideline).<\/li>\n<\/ul>\n\n<h4>0.5.0 \u2014 2026-05-10<\/h4>\n\n<ul>\n<li>CI alignment with the ShieldForge UX (Hero banner, tab groups, action items, iOS toggles, tooltips, dark mode, mobile, sanity card).<\/li>\n<li><code>bin\/bump-version.{sh,ps1}<\/code> + <code>bin\/build-free.{sh,ps1}<\/code> + <code>.distignore<\/code>.<\/li>\n<li>Pre-launch sanity check (17 checks across versioning, cron, DB, privacy, tracking, sitemap, coexistence, file hygiene, readme, translations).<\/li>\n<li>i18n: POT + de_DE PO\/MO shipped.<\/li>\n<li>PHPUnit tests for <code>Seoforge_Crypto<\/code> + <code>Seoforge_Analyzer<\/code>.<\/li>\n<\/ul>\n\n<h4>0.4.0 \u2014 2026-05-07<\/h4>\n\n<ul>\n<li>Migration wizard for Yoast \/ RankMath \/ AIOSEO (metadata + redirects).<\/li>\n<li>JS-beacon tracking mode with scroll depth + outbound clicks.<\/li>\n<li><code>Seoforge_Health<\/code> setup-health score on the Dashboard.<\/li>\n<li>UX polish for non-technical site owners.<\/li>\n<\/ul>\n\n<h4>0.3.0 \u2014 2026-05-07<\/h4>\n\n<ul>\n<li>Pre-aggregated daily table for O(1) dashboard queries.<\/li>\n<li>Transient caches with auto-flush on mutations.<\/li>\n<li>License-key encryption at rest (AES-256-CBC).<\/li>\n<li>Streamed CSV exports (visits, sessions, 404, redirects).<\/li>\n<li>Bulk redirect import from CSV.<\/li>\n<li>WP-CLI commands (<code>wp brainwerk-seo-suite ...<\/code>).<\/li>\n<li>Demo seeder + live-visitors widget.<\/li>\n<li>REST API (<code>\/wp-json\/seoforge\/v1\/...<\/code>).<\/li>\n<\/ul>\n\n<h4>0.2.0 \u2014 2026-05-07<\/h4>\n\n<ul>\n<li>Coexistence layer detects Yoast \/ RankMath \/ AIOSEO \/ The SEO Framework \/ SEOPress and stands down passively.<\/li>\n<li>License + Pro module foundation.<\/li>\n<li>Pro stubs: Geo-Lookup, webhooks, anomaly detection, Search Console.<\/li>\n<li>Marketing landing page (<code>landing\/index.html<\/code>).<\/li>\n<\/ul>\n\n<h4>0.1.0 \u2014 2026-05-07<\/h4>\n\n<ul>\n<li>Initial release: tracker, sessions, stats, meta, schema, sitemap, robots, redirects, 404 log, on-page analyzer, weekly digest, onboarding wizard, tools tab.<\/li>\n<\/ul>","raw_excerpt":"The European answer for privacy-first SEO &amp; cookie-free analytics \u2014 plus AI-search (GEO\/AEO). From the EU, for the EU.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/cs.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/315682","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cs.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/cs.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/cs.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=315682"}],"author":[{"embeddable":true,"href":"https:\/\/cs.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/brainwerk"}],"wp:attachment":[{"href":"https:\/\/cs.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=315682"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/cs.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=315682"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/cs.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=315682"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/cs.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=315682"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/cs.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=315682"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/cs.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=315682"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}