
CiteCue AI Auto-Fix is the WordPress end of CiteCue, an answer engine optimization (AEO) platform. It decides, per request, which version of a page WordPress returns — the optimized one to a recognised AI crawler, your normal page to everyone else — and it can do that only from inside WordPress, before the theme renders.
- Per-request delivery to AI crawlers — when GPTBot, ClaudeBot, PerplexityBot, ChatGPT-User or any other agent in the crawler registry requests a page, the plugin returns the CiteCue-optimized version of that URL. Human visitors always see your normal site, and optimized responses are never cached for regular traffic. Any miss, timeout or outage passes straight through to the normal page.
- Gap-filling page metadata — adds CiteCue’s title, meta description, OpenGraph, canonical and structured-data tags to your live pages, so search engines and AI answer engines see them on the page a human sees. It fills gaps only: it reads what your theme, WordPress and your SEO plugin actually printed into
<head>and adds only what none of them emitted, so there is never a second title or canonical. - Page enhancements — where you have approved one in CiteCue, adds a short facts-and-FAQ section to the end of a page you already have, built from your own answered facts and grounded FAQ entries rather than generated. It is placed only if the page does not already carry one, and it is the only thing this plugin adds that your visitors can see.
- Recognises 18 AI crawlers, and learns new ones on its own — GPTBot, ChatGPT-User, ClaudeBot, PerplexityBot, GoogleOther, Amazonbot, Bytespider, CCBot, meta-externalagent, MistralAI-User, DuckAssistBot and more. The registry refreshes daily from CiteCue, so an agent that launched last week is recognised without updating the plugin.
- Never makes a visitor wait — the path that renders a page for a person reads cache only; nothing on it calls out to the network. A URL with nothing cached yet renders untouched and the fetch is queued for afterwards, so the first visitor to a cold page pays one un-enriched view rather than one slow one. Requests from AI crawlers are the deliberate exception — only a bot is waiting there — and even those are bounded by a three-second timeout, a per-minute lookup budget and a circuit breaker that stops the plugin trying at all while CiteCue is unreachable.
- Content from CiteCue — a signed endpoint through which CiteCue can push new brand-building content (content briefs, FAQ packs, gap-filling pages) into WordPress as drafts for your review.
- WooCommerce-aware — cart, checkout, account pages and cart-modifying links are never intercepted, while product and shop pages are served optimized. Pushed content can also create or enrich WooCommerce products (draft by default, matched by SKU with explicit consent).
This plugin requires a CiteCue account — citecue.com — and does nothing until you connect one. See “External services” below for exactly what is sent where.
What the plugin actually does
Everything above happens on a live request, and that is where the design decisions are:
- It serves a different representation per requester, safely. Crawler matching runs against a registry that refreshes daily, so an agent launched last week is recognised without a plugin update. A logged-in user, a cart URL, a WooCommerce endpoint or a cart-modifying link is never intercepted. A circuit breaker, a per-minute lookup budget, negative caching and a stale-while-revalidate cache mean an outage at CiteCue costs a passthrough, never a broken page or a slow one.
- It composes with your SEO plugin rather than replacing it. The metadata layer detects what was actually printed into
<head>rather than looking for particular plugins, so it behaves correctly beside Yoast, Rank Math, a plugin nobody has heard of, or none at all. Every tag it adds carries adata-citecueattribute, so View Source tells you exactly which ones came from CiteCue. - Nothing from the API is trusted as markup. Every returned tag is parsed, matched against an allowlist of shapes and rebuilt from escaped values, with structured data re-encoded so it cannot escape its own script element.
- It never makes a visitor wait on a third party. The render path reads cache only; a URL with nothing cached yet renders untouched and the fetch is queued to WP-Cron.
- Content flows back in. The signed
citecue/v1endpoint is how CiteCue delivers new content into WordPress — as drafts, with replayed signatures rejected — so the loop from “this page is missing” to “this page exists” closes without anyone copying and pasting.
The service behind all of it is at citecue.com.
External services
This plugin is the WordPress end of CiteCue, a hosted service at citecue.com that generates AI-optimized versions of your pages. The optimized pages, your llms.txt and the pushed draft content are all produced by that service, so the plugin cannot work without it. Nothing below happens until an administrator connects the site.
Terms of Service: citecue.com/terms
Privacy Policy: citecue.com/privacy
The service is reached at https://app.citecue.com (or the origin you pin with the CITECUE_API_BASE constant, for self-hosted CiteCue deployments).
Connecting the site — once, when an administrator clicks “Connect to CiteCue”. Your browser is sent to app.citecue.com/connect/wordpress with this site’s address so CiteCue can show you which project you are pairing. WordPress then posts to /api/delivery/v2/connect/claim: the one-time code from that redirect, this site’s address, its REST API address, this site’s content-push secret, the plugin version, whether WooCommerce is active, and whether enriched page metadata is switched on. CiteCue returns the API key it issued for this site. The API-key fallback instead sends the key you paste to /api/delivery/v2/config, which returns your organization’s projects.
Serving a page to an AI crawler — on each request from a matched AI crawler, and never for a human visitor or a logged-in user. The plugin sends the requested URL, the matched crawler’s User-Agent token and the site’s project key to /api/delivery/v2/page. No visitor data — no IP address, no cookies, no personal data — is sent. CiteCue records the crawler hit so it can report it back to you. Responses are cached, misses are remembered for a minute, and a per-minute budget caps the total.
Enriching a page’s metadata — in the background, on WP-Cron, for a URL a visitor has requested while enriched metadata is switched on. The requested URL and the site’s project key are sent to /api/delivery/v2/seo-head. No visitor data — no IP address, no cookies, no personal data — is sent, and this never happens while a visitor is waiting: a page with no cached block yet is rendered untouched and the fetch is queued for afterwards.
Before a URL is cached, queued or sent, every query argument WordPress does not recognise as a query variable is removed from it, so tokens, order keys and nonces that happen to be in the address are never included. WooCommerce cart, checkout, account and order pages are skipped entirely. Responses are cached, empty answers are remembered for a minute, the same per-minute budget caps outbound calls, and a second per-minute cap limits how many refreshes a burst of traffic can queue.
Serving llms.txt — when /llms.txt is requested and the feature is on. The site’s project key is sent to /api/delivery/v2/llms.txt. The response is cached.
Refreshing the AI-crawler list — once a day, on WP-Cron, for a connected site only. An unauthenticated request to /api/delivery/v1/crawlers fetches the current list of AI crawler User-Agent tokens, so newly launched crawlers are recognised without a plugin update.
Verifying the installation — when you connect, and whenever you click “Verify installation”. The plugin requests your own site’s /llms.txt over HTTP, identifying itself as an AI crawler, to confirm the plugin answers rather than a cache or CDN. This request goes to your site, not to CiteCue.
Every outbound request identifies itself with a CiteCue-WordPress/<version> (+<your site URL>) User-Agent.
In the other direction: when content pushes are enabled, CiteCue sends new content to this site’s citecue/v1 REST route. Each request is signed with the shared secret exchanged during connection, replayed signatures are rejected, and the content is created as a draft unless you raise that limit yourself.