
Agentimus is an all-in-one AI SEO plugin for the age of AI agents — AEO (Answer Engine Optimization) and GEO (Generative Engine Optimization) in one place. It does two things.
It makes your site legible and citable. It helps AI assistants like ChatGPT, Claude and Perplexity find your site, read it correctly and cite it in your own words — and shows you which AI bots are visiting. You don’t need to understand AI or web standards: a setup wizard walks you through it in about a minute, then it runs on its own.
And it lets the AI tools you already use operate your site. Turn on the built-in Model Context Protocol (MCP) server and Claude Code, Claude Desktop, Cursor or Codex can read your reports and — behind two more opt-in switches — draft, edit and publish posts. All three are off by default. Prefer wp-admin? A built-in writing assistant drafts and revises posts there.
By default it makes no outbound requests, collects no analytics and logs no IP addresses — everything runs on your own site. Three optional features change that only when you switch them on: Citation checks, Verify bot identities and Store IP addresses, each disclosed in full under External services.
📖 Full documentation — a plain-English manual and developer reference, step-by-step guides for every feature: https://heera.github.io/agentimus/
One screen that says what needs you
- Findings — everything open across your site in one ranked list: pages losing a click they already earn, and anything the setup checks caught — ordered by what each costs you, every row carrying the button that lands on the fix. The nav count only measures work you can act on.
- Your Content — one row per post, page or product: what it is found for, whether it answers that, and anything else it needs. Set aside anything never meant to be quoted and it stays listed, not silently dropped.
With an SEO plugin — or instead of one
- No SEO plugin? You don’t need one. Agentimus covers the search basics: per-page SEO titles, social share cards (Open Graph), canonical links, meta descriptions, and an XML sitemap carrying the last-changed dates core’s own leaves out.
- Already running Yoast, Rank Math, SEOPress, AIOSEO or The SEO Framework? It detects them and steps aside on every overlapping surface — titles, cards, schema, sitemap. No duplicate tags: it adds only the AI layer your SEO plugin doesn’t cover.
Operate your site from your AI agent (MCP) — opt-in
- A Model Context Protocol server on your own site — one switch runs an MCP server at
/wp-json/agentimus/v1/mcp; the library ships with the plugin, nothing extra to install. - Connect by approving, not by pasting keys — an assistant asks you for permission on a consent page on your own site; you choose Read only or Read and write, and each gets its own key and Disconnect. OAuth 2.1 with PKCE, nothing brokered by a third party; a revocable shared token covers clients that can’t ask.
- Read your site’s data — connected agents run the read-only tools — score, AI traffic, request log, bot identification, page previews — and your llms.txt, discovery and agent-card documents are offered as readable resources.
- Draft, edit and publish posts — behind two more switches — turn on Let connected agents write and an agent can create and edit posts and pages fully dressed (categories, tags, featured image, AI topics and descriptions), apply Readiness fixes, and reuse pictures from your media library. A third switch lets it publish; otherwise it leaves drafts for review.
- Safe by construction — every write runs as the signed-in WordPress user, never exceeding their permissions, and is recorded under More Agent Access. Nothing is public, and with the switch off the write tools do not exist.
Write with AI in wp-admin — the built-in assistant (opt-in)
- Idea draft without leaving wp-admin — a spark button opens the writing assistant: describe what you want, shape the outline it proposes, then preview the complete draft — real blocks, AI description, topics, categories, tags. A page is written as a page: no invented sections. Nothing is saved until you click Create draft, and it never publishes.
- Ask AI in the editor — one block, a selection, or the whole post — rewrite or extend the block you’re in, change several with one instruction, or ask about the whole post and get a list of proposed edits, each with its reason, to accept or reject one at a time. Blocks the plan doesn’t name are never touched.
- Images where you write — alt-filled placeholders in drafts, Generate image from the alt text on every image block, a Featured image (AI) panel — or pick from your library. Runs on WordPress’s built-in AI Client (7.0+); Agentimus never sees your key, and every AI button hides until a provider is set up.
Tell your team — and announce what you publish
- Reports where you already look (opt-in) — send Agentimus’s reports to Telegram, Slack, Discord, a Google Sheet or any address of your own. Choose the moments that matter: a new finding, an unfamiliar bot, the weekly digest. Every service stays yours, and nothing is sent until you switch it on.
- Announce a new post (opt-in) — Agentimus offers the words for X and LinkedIn; you approve them or edit them first. Each connection is an app you own, so the post comes from you, not from us. A ledger shows what went out, what is queued and what failed, with the reason.
Control — who may use your content
- robots.txt content-signals + AI-training blocklist — declare your content-usage policy and block model-training crawlers (GPTBot, CCBot, ClaudeBot, Google-Extended, Bytespider, …) by name, while leaving read/cite bots free.
- Block scanners & scrapers (opt-in hard block) — robots rules are a polite request; this enforces them, returning 403 to the user-agents on your denylist. Your always-allowed list is never blocked: pre-trust well-known assistants with one click, search engines are recognised automatically, and SSL renewals stay reachable.
- Exposure controls (opt-in, all OFF by default) — switches that close what stock WordPress reveals to anonymous crawlers: username enumeration, author archives, the WordPress version, the auto-generated
<head>discovery links, and XML-RPC. Signed-in admins and the block editor are never affected. Exposure hygiene, not a firewall.
Visibility — who is reading you
- Report — what AI did on your site between any two dates: reads, visits from AI answers, and where you stand. Today, a week, or dates you pick; every block says how fresh its numbers are.
- Agent activity log — which AI crawlers and agents actually fetch your content and endpoints (GPTBot, Claude, Perplexity, Googlebot, …), recorded first-party, with no IP logging by default.
- Activity to review — a nav-bar queue surfaces clients worth a second look, with one-click Block or Allow. Nothing is blocked unless you say so.
- Request Log — every recorded request, one row each. Filter by client, endpoint, network, user-agent and date to see what a single bot fetched.
- Agent Access — who authenticates and acts: assistants approved, keys created or revoked, abilities run, requests refused. A record, not a guard — it names the key, never the person.
- Traffic from AI — the real visitors an AI assistant sent you, day by day, by assistant and landing page — aggregate counts only, never a row for one person, no IP. An opt-in CDN mode keeps counts accurate behind a cache.
- Edge traffic (Cloudflare, opt-in) — what Cloudflare answered or blocked before your server saw the request: cache hits and edge blocks no server-side log can see. It warns when the edge disagrees with your policy.
- You decide how long it’s kept — retention, nightly auto-delete and a hard size cap, so the log never outgrows your host.
- Citation checks (opt-in) — track each brand, product or person you choose across ChatGPT, Perplexity, Gemini and Claude: whether it is mentioned, linked, and how it ranks against rivals. Off by default; bring your own API key (the one feature that makes an outbound request — see External services).
Classic search, measured — Bing & Google (opt-in)
- Search Performance & Opportunities — connect Bing Webmaster Tools and/or Google Search Console (a key held on your own server, no third-party proxy) and see what people searched, how often you appeared, and which pages sit one improvement from page one. Every number is the engine’s own, never estimated; probe traffic is named, not blended in.
- In the index — Google’s and Bing’s — whether the indexes behind AI Overviews, Gemini, ChatGPT search and Copilot hold your pages: the whole site in rotation, every verdict in the engine’s own words, problems grouped with deep links to the fix, any page re-checked live — plus week-on-week trend, Google Discover, and your registered sitemap’s health.
Content — clean, machine-readable output
- Markdown delivery — request any page as clean markdown by appending
.mdto its URL. AnAccept: text/markdownmode also exists. - /llms.txt & /llms-full.txt — an llmstxt.org index of your pages, topics and recent posts, plus a full-text edition an agent ingests in one request.
- JSON-LD — WebSite + Person/Organization, plus BlogPosting and BreadcrumbList on posts. Defers to Yoast, Rank Math, SEOPress, AIOSEO and The SEO Framework, so never duplicate schema.
- Topics for AI — say what each post is about in plain words; they become the JSON-LD
keywordsand a line in the page’s.md. Type your own or fill them from tags and categories. Nothing shows on the page. - AI description — a one-line summary per post; it becomes the JSON-LD
description, the lead of its.md, and its<meta name="description">unless an SEO plugin owns it. Blank uses the excerpt; a sub-switch keeps it out of your<head>. - XML sitemap — with no SEO plugin, Agentimus serves your sitemap at
/wp-sitemap.xmland advertises it in robots.txt and llms.txt; with one, it links theirs. - Change feed —
/agentimus-changes.jsonlists added, updated and removed pages (with?since=), so an assistant re-checks only what changed.
Identity & contact
- Author / site identity — a profile sentence, expertise topics and linked profiles (
sameAs) feed llms.txt and JSON-LD — the highest-signal lines for agent retrieval. - security.txt — optionally publish an RFC 9116 disclosure contact at
/.well-known/security.txt.
Readiness report
- A one-screen score of how machine-readable your site is, with a plain-English checklist of what’s enabled and what’s still missing.
- Agent preview — see the exact JSON-LD and Markdown an AI agent receives for the whole site or any page, then copy it. It shows what would ship even when the feature is off, and a matching preview sits in the post editor.
- Readability tips — as you write, a panel flags what makes a page hard to read, section and quote: thin content, missing headings, no opening summary, a nav-heavy page, images without alt text. Most of those serve search engines and screen readers just as much, and the panel says so. Editor-only — nothing shows to visitors.
Machine discovery (forward-looking)
Everything above is read by search engines and AI tools today. This part is forward-looking — the conventions the agent ecosystem is converging on, putting identity, capabilities and APIs in one predictable place:
- /.well-known/discovery.json — an owner-curated document describing the site’s identity, capabilities, APIs and agent cards. Other plugins declare themselves through one hook.
- /.well-known/agent-card.json and /.well-known/mcp.json — an A2A agent card and an MCP manifest, generated for you.
- Standards-aligned
.well-knownendpoints — an RFC 9727api-catalog, plus — only when the capability exists — an MCP server card and an Agent Skills index. Response signing (RFC 9421 / Web Bot Auth) uses an Ed25519 key that never leaves your server. - WordPress Abilities API — the same read-only tools are registered as abilities, each gated by the capability of its screen, so WordPress’s built-in AI can read them. An off-by-default switch adds the write abilities.
- The plugins you run, described — a WooCommerce store says it sells products; FluentCart, FluentCommunity and Fluent Support say what they hold. Plugins that keep everything behind a login are named as such. Switch off anything you would rather not announce.
- Zero-config auto-discovery — reads your REST namespaces, public post types and the Abilities API, so a site is described even when no plugin declares itself. The Discovery Hub shows what an agent sees.
Why it’s useful
Most tools cover one slice — an llms.txt file, a bot blocker, or structured data. Agentimus brings the whole job together in one lightweight package — and tells you what’s still missing.
External services
Agentimus makes no outbound requests by default: no remote scripts, fonts or analytics, and the agent-activity log stays in your own database with no IP addresses. (IP storage is optional, off by default — see the FAQ.)
Every outbound feature is opt-in and off by default.
Data sources & IndexNow: connecting Cloudflare, Google Search Console or Bing Webmaster Tools polls that service with your own key. The optional IndexNow switch announces published and removed URLs to search engines via api.indexnow.org (https://www.indexnow.org/) — only the changed URL list is sent.
Verify bot identities makes DNS lookups and, once a day, downloads the IP-range files bot operators publish to verify their crawlers (Google, Microsoft, DuckDuckGo, Apple, OpenAI, Perplexity — or a URL you add yourself). Only those files are fetched; nothing about your site is sent.
The same setting verifies Web Bot Auth signatures — the standard where an AI agent signs its request cryptographically. To check one, Agentimus fetches (and caches) the signing operator’s public key directory at /.well-known/http-message-signatures-directory, only when a signed request arrives, and sends nothing about your site with it. Operators publishing one today:
- OpenAI — https://chatgpt.com/.well-known/http-message-signatures-directory · https://openai.com/policies/terms-of-use · https://openai.com/policies/privacy-policy
- Google — https://agent.bot.goog/.well-known/http-message-signatures-directory · https://policies.google.com/terms · https://policies.google.com/privacy
Citation checks: when you enable them and add your own API key for a provider, Agentimus sends the prompts you configured to that provider to check whether it mentions and cites your site — only for the engines you turn on, and only when a check runs. Your keys are stored on your own site and used solely for these calls. The providers, with their terms and privacy policies:
- OpenAI (ChatGPT) — https://openai.com/policies/terms-of-use · https://openai.com/policies/privacy-policy
- Perplexity — https://www.perplexity.ai/hub/legal/terms-of-service · https://www.perplexity.ai/hub/legal/privacy-policy
- Google (Gemini) — https://ai.google.dev/gemini-api/terms · https://policies.google.com/privacy
- Anthropic (Claude) — https://www.anthropic.com/legal/consumer-terms · https://www.anthropic.com/legal/privacy
URL-like strings in the plugin’s output are labels, not requests — the discovery documents’ $schema value names the format (never fetched), and the example.com URLs in examples/ are documentation placeholders.
Screenshots

Dashboard — it opens with today: what AI crawlers read, who arrived from an AI answer, and what connected assistants did, each against yesterday, and one sentence naming who did it. Then your AEO/GEO score across five plain rungs (Findable, Readable, Trusted, Optimized, Cited) with the one next step worth taking, and what your site runs: every system's standing in four panels — how AI assistants reach you, what your site tells the engines, what search shows, what your writing holds — each led by one number that links to its full screen. Beneath them, the two audiences counted apart — the people who came to read, and the machines that fetched — then a first-party log of which AI agents and crawlers reached each endpoint, who reads you most, and the real visitors AI assistants sent. Every day bar opens that day's full report.

Visibility → In the index — whether the engines' indexes actually hold your pages, Bing's and Google's on one screen. Bing is the index ChatGPT search and Copilot read today: how much of your site it holds, how cleanly its crawler gets in, and a live question you can ask about any single page. Google's is walked in rotation and re-checked daily — healthy pages stay a count, while anything that needs a look earns a row in Google's own words, each with a link straight to that URL in Search Console.

Visibility → Search — what people searched, how often you appeared, how often those results were clicked, and the pages that earned them; every number the engine's own. Connect both Google and Bing and a switch appears, because the two count different searchers and are never merged. Directly beneath it, Search Opportunities turns those same numbers into a worklist: pages sitting just off page one, and pages on page one being scrolled past, each wired to the exact field that fixes it. It also names the searches several of your pages are splitting between them — the clicks divide, so each ranks lower than one page would — with the page that earns the click stated, and one decision on every other.

Readiness report — a plain-English pass/warn/fail checklist of what's enabled and what's still missing, grouped by rung, each row carrying its own fix in the site's own words. Buttons at the top preview your site the way an agent sees it, re-run every check live, and scan for files that shouldn't be public. Beneath the checklist your content is summarised rather than listed: how many pieces are graded, how many carry something worth fixing, and which issue is the most common — with a way in page by page, a way in by issue, and the set-aside list of everything you have deliberately left out of the score.

Crawler policy & bot identity — declare your content-usage signals, block scanners and scrapers by name, turn away spoofed traffic, and verify bots against what each operator publishes: reverse DNS for the search engines, published IP ranges for GPTBot and PerplexityBot. The verified-bots registry is yours to edit.

Request Log — every visit a machine made to your site, in one filterable table: which crawler or AI assistant it was, what it fetched — your own pages included, not just the AI files — and whether it was served or turned away. Narrow by client, address, verification verdict, signature, User-Agent or date. A Status column carries one honest mark per request — verified, signed, spoofed, forged, refused or unchecked. Your readers are never logged here.

MCP server — one switch runs a Model Context Protocol server on your own site. Your server address leads: give it to an assistant and it asks you for approval — no keys to paste — and every approved assistant is listed with its scope, its last call and its own Disconnect. Above it, the trust ladder: a second switch lets agents write, a third decides whether they may publish or only leave drafts.

Data sources — the outside services Agentimus reads from, all optional, each with one key held on your own server and no third-party proxy: Cloudflare for what the edge answered or blocked before your server saw it (and, with an optional extra permission, clearing its cache when you publish), Google Search Console for classic search and index coverage — with Analytics alongside it, on that same key, if you want visitor numbers too — and Bing Webmaster Tools, which can also announce every change you publish through IndexNow. Numbers land in your own database, so your history outlives each service's own reporting window.

Visibility → Citations, set up — the opt-in check that asks ChatGPT, Perplexity, Gemini and Claude whether they mention and link each brand, product or person you track. Name the thing, say what kind of thing it is, name the rivals it competes with, and write the questions a real person would type — or have them suggested. Then switch on the assistants that should answer them: each runs on your own API key, kept on your own server and used for nothing but your checks, because a citation check is graded on the sources an assistant actually cited and WordPress's shared connector hands back the answer text without them. Choose how often the checks run and how long the history is kept. Results land on the tab beside this one: seen-in-answers and linked-your-site rates, rank against each item's own rivals, and question-by-question answers with the sources each engine cited.

Discovery — everything your site offers AI assistants, in one place and in plain words: the things assistants can read, the things they can do, and what each of those rows actually allows. Beneath them the MCP connection, and every well-known document your site serves with its live status and one line saying what it is for — so none of it is a filename you have to go and look up. Any registration problem is listed with a plain-English fix.

The writing assistant — a spark button on every Agentimus screen opens the drawer: choose what you are writing (a post, a page, or one of your own content types — a page gets no invented sections and no tags), describe it in your own words, then draft it straight away or shape the outline first. Preview the fully dressed draft, create it as a draft and land straight in the editor. Nothing is saved until you say so, and it never publishes.

In the post editor — the "Agentimus" box, Readability tab: a per-page pass/warn check of what makes the page hard to read, section and quote — for AI assistants, for search engines and for people alike — enough substance, an opening summary, specifics and cited sources, section headings and their order, quotable passages, reading ease, prose vs links, image alt text, video and audio, the featured image and whether it is described, and freshness. The rows an AI can draft a fix for — a thin page, a missing opening summary, an over-long block — carry a "Fix with AI" button once you have set a provider up in WordPress. Two more tabs sit alongside it: JSON-LD and Share.

Findings — one front door for everything open across your site, ranked by what each one costs: pages losing a click they already earn, and anything the setup checks caught. Every row says what to do and carries the button that lands on the fix. Beneath it, your content one row at a time — what each page is found for, whether it answers that, and anything else it needs. It covers every kind of content you publish, and the line above the list says which kinds are being checked.

Integrations → Services — where Agentimus sends its reports. A new finding, a caught impostor, the weekly digest and three more moments can go to Telegram, Slack, Discord, a Google Sheet, or any address of your own as signed JSON. Each service is one you own — your bot, your channel, your sheet — and every connection is tested before it is saved, so a card never claims to be connected when nothing would arrive. All of it is off until you switch it on.

Integrations → Plugins — what your other plugins tell AI assistants about your site, on your behalf. A WooCommerce store says it sells products; FluentCart says it has store and checkout pages; FluentCommunity says it holds community spaces. Plugins that keep everything behind a login are listed too, saying exactly that — a plugin with nothing public has nothing to pass on, and naming it is more use than leaving it out. Any plugin can describe itself the same way through one hook, with no dependency on Agentimus.

Report — what AI did on your site between any two dates. How many AI crawlers read you and which ones, how many people arrived from an AI answer and from where, what assistants did here, where you stand in search, your score, and the one thing worth doing. Today, yesterday, seven days, thirty, or two dates from a calendar. Every block says how fresh it can be: your own log answers any window to the minute, while Google and Bing publish days behind and name the newest day they have rather than printing a zero that would read as "nobody searched". Your dashboard opens with the same reading for today.