Beschrijving
Install run the setup wizard done. No key, no account, no paid tier: every module and every measurement screen in this plugin is free and fully usable.
Index Harmony maakt je WordPress.site klaar voor AI-assistenten, antwoordmachines en hun crawlers (ChatGPT, Claude, Perplexity, Gemini en andere) zonder je bestanden of content aan te raken — en laat je daarna zien wat er werkelijk is gebeurd. Elke fix is virtueel en omkeerbaar: zet een module uit en hij verdwijnt spoorloos.
Wat het anders maakt: de meeste plugins in deze ruimte stoppen bij het genereren van llms.txt. Index Harmony combineert de outputkant met een first-party meetkant die geen search-console-integratie kan zien: zijn eigen AI-botverkeerslog met echte botverificatie (officiële vendor IP-lijsten plus RFC 9421 Web Bot Auth Ed25519-handtekeningcontroles), dagelijkse tellers per pagina, een bewijs paneel per pagina dat laat zien welke engine welke pagina op aanvraag heeft opgehaald, een crawl versheidsfunnel, een aandacht-afname-radar, herstel voor 404 URL’s die assistants verzinnen, een wijziglog die elke GEO instellingwijziging op je verkeersgrafiek markeert, plus een agentgerichte Site MCP endpoint en WordPress Abilities/WebMCP oppervlakken. llms.txt is een van de 19 modules, niet het product.
Alle 19 vaste modules (gratis, geen sleutel nodig):
- llms.txt + llms-full.txt (virtuele endpoints, dagelijks ververst; kies zelf de uitgelichte pagina’s of bewerk de bestandsinhoud rechtstreeks)
- AI bot manager voor robots.txt (expliciete toestemmingsregels voor 25 AI-bots; je bestaande regels blijven ongewijzigd)
- JSON-LD schema-injector (Organization / WebSite / Article / FAQ / Breadcrumb / Product) — laat Yoast, Rank Math, AIOSEO en SEOPress voorgaan om duplicaten te voorkomen
- Meta-aanvuller (description / Open Graph / Twitter — alleen wanneer geen SEO-plugin het afhandelt)
- Inschakeling van de WordPress core sitemap + robots.txt declaratie
- /.well-known/security.txt
- WooCommerce productfeed + volledigheid van het Product.schema
- hreflang auditor (alleen rapporten — hij schrijft nooit een bestand en geeft nooit een hreflang tag uit)
- /AGENTS.md — een gebruiksgids van de site voor agents (virtueel)
- Markdown negotiation (Accept: text/markdown or ?format=md) — responses carry an X-Markdown-Tokens estimate, the Markdown for Agents convention
- .well-known discovery endpoints (api-catalog RFC 9727; mcp.json en agent-skills alleen wanneer geconfigureerd — geen neppe manifests)
- Agent-discovery Link headers + robots.txt Content-Signal declaration (search / ai-input / ai-train, plus the optional
use=field introduced in 2026) - AI bot traffic log (which bot visited when — visits carrying a Web Bot Auth Signature-Agent header are flagged with the signer’s key-directory host, and while bot verification is enabled their Ed25519 request signatures are cryptographically verified against the signer’s published keys)
- AI policy publishing (ai.txt + TDMRep + Content-Signal header + IETF Content-Usage directive in robots.txt and as an HTTP header)
- RSL content licensing — a virtual RSL 1.0 license.xml derived from your policy axes, plus the robots.txt License pointer (opt-in)
- Security headers — six optional response headers (X-Content-Type-Options, Referrer-Policy, Permissions-Policy, HSTS, CSP-Report-Only, X-Frame-Options); all off by default and picked one by one under Settings Advanced
- IndexNow instant indexering (Bing/Yandex/Seznam/Naver — opt-in)
- WebMCP (agentoppervlak in de browser voor de openbare informatie van je site)
- AI-verkeersaandeel (opt-in dagelijkse kanaaltellers)
Meting en inzichten:
- Botverkeersdashboard — een 30-dagengrafiek en een uitsplitsing per bot van AI-crawlerbezoeken
- Bot verification (opt-in) — once enabled, downloads public bot IP lists and Web Bot Auth signature key directories once a day to flag spoofed bots and cryptographically verify signed agents (works even behind a proxy/CDN, where IP checks must abstain); no visitor data leaves your site
- Botblokkering en piekwaarschuwingen (opt-in) — kies de bots om te volgen en zet de blokkering aan wanneer je dat besluit, achter een expliciete bevestiging; het paneel raadt eerst een observatievenster van 7 dagen aan en waarschuwt je als je het eerder inschakelt, maar niets is tijdvergrendeld en je kunt de blokkering met één klik stoppen; optionele e-mail bij verkeerspieken
- Pagina-analyse — dagelijkse tellers per pagina (AVG-neutraal: geen IP’s, geen user-agents) voeden een bewijspaneel per pagina dat op verzoek toont welke engine welke pagina heeft opgehaald, een crawlversheidstrechter (welke pagina’s veranderden na de laatste crawl) en een 28-daagse aandachtsvervalradar voor pagina’s waarin de AI interesse verliest
- AI-404 fantoom URL herstel — een rapport van URL’s waarvan assistenten denken dat ze bestaan (404-hits met een AI User-Agent of AI-platformreferrer), de dichtstbijzijnde echte pagina voorgesteld op bewerkingsafstand, en een optionele 301 per rij die ALLEEN wordt toegepast op aanvragen van AI-oorsprong
- GEO change log — every visibility-affecting setting change is marked on the traffic chart with an honest before/after delta (correlation, not causation)
- Botgezondheidsalarmen — een stiltewachter voor vaste crawlers die stil vallen en een spoof-golfbewaking met een expliciet bevestigde één-klik schakelaar “403 alleen voor vervalste”
- Page readiness score + Triage — a per-page content-readiness sub-score with an in-editor meta box and a site-wide triage view
- Wekelijkse (of dagelijkse) samenvattingsmail (opt-in) — een overzicht van botverkeer, vervagende pagina’s en je zwakste pagina’s
Eerlijkheidsprincipes
- Er worden geen bestanden geschreven — alles wordt virtueel geserveerd en schakelt spoorloos uit.
- No cloaking — humans and bots see the same content; only the format may differ when a client asks for it.
- No fake manifests — discovery files are published only when they describe something real.
- Geen upsell-oppervlakken — deze plugin vraagt je nooit om een sleutel en slaat er nooit een op.
Talen
Het beheerpaneel wordt volledig vertaald geleverd in 17 talen: English, Türkçe, Deutsch, Español, Français, Italiano, Nederlands, Polski, Português, Русский, 日本語, 한국어, العربية, فارسی, हिन्दी, Bahasa Indonesia, Tiếng Việt. RTL-lay-outs worden ondersteund voor Arabisch en Perzisch. De vertalingen zitten in de plugin zelf (niet geleverd als WordPress.org-taalpakketten).
Externe diensten
This plugin can connect to the third-party/external services listed below. Nothing is contacted on install or silently: every connection either requires an explicit opt-in toggle (off by default) or happens only when you press a button. With all defaults untouched, the plugin makes no outbound calls and collects no telemetry.
1. Index Harmony scandienst (door ons beheerd op indexharmony.com)
- Wat het is/waarom: de optionele site-readiness scan – een 134-check audit van hoe je site eruitziet voor AI-crawlers. Scoring die vereist dat je pagina’s van buitenaf worden opgehaald, wat niet kan vanuit je eigen WordPress, dus de scan draait op de dienst-s servers.
- Wat wordt verstuurd en wanneer: wanneer je in het dashboard op “Scannen” drukt, opent je browser de scanpagina van de dienst in een nieuw tabblad met het openbare adres van je site in de URL, en de scan draait daar. Het rapport wordt op de eigen pagina van de dienst getoond — het komt niet terug naar je dashboard, en deze plugin doet geen vervolgaanvragen, bewaart geen taak-id en slaat geen scanresultaat op. Er wordt niets verstuurd bij installatie, volgens schema of op de achtergrond.
- Deze plugin bevat geen sleutelinvoerveld, geen ontgrendelstap, geen licentiestatuscontrole en geen supportaanroep, en slaat geen sleutel of token voor deze dienst op.
- Dienstvoorwaarden · Privacybeleid
2. AI-crawler IP lists and signature key directories for bot verification (opt-in, off by default)
When you enable “bot verification”, about once a day the plugin downloads the public, read-only crawler IP-range lists each vendor publishes, so genuine AI crawlers can be told apart from spoofed user-agents. Only a plain HTTP GET is made to the fixed URLs below — none of your site content, settings or visitor data is sent to these vendors.
The same daily job also fetches Web Bot Auth signature key directories: when a bot visit carries an RFC 9421 Signature-Agent header, the plugin downloads that signer’s public Ed25519 keys from the fixed, standardised path /.well-known/http-message-signatures-directory on the key-directory host the signed request itself declares (for example Google’s agent identity or OpenAI’s signing hosts), so later signed requests can be verified locally. This is a plain GET of a public key file — nothing about your site or visitors is sent; hosts are strictly validated, capped at 16, and requests go through WordPress’s safe-URL transport (private and loopback addresses are refused).
- OpenAI — openai.com/gptbot.json, /searchbot.json, /chatgpt-user.json · Voorwaarden · Privacy
- Anthropic — claude.com/crawling/bots.json · Voorwaarden · Privacy
- Perplexity — perplexity.com/perplexitybot.json, /perplexity-user.json · Voorwaarden · Privacy
- Amazon — developer.amazon.com/amazonbot/ip-addresses/ · Gebruiksvoorwaarden · Privacyverklaring
- Mistral — mistral.ai/mistralai-user-ips.json · Voorwaarden · Privacy
- Google — developers.google.com/static/crawling/ipranges/user-triggered-agents.json (Google-Agent) · Terms · Privacy
- Microsoft Bing — geen HTTP-aanvraag; bingbot wordt geverifieerd met een standaard reverse-DNS-lookup (PTR moet eindigen op search.msn.com) via de resolver van je server · Microsoft-servicesovereenkomst · Privacyverklaring
3. IndexNow (opt-in module, standaard uit)
- What it is / why: instant-indexing protocol operated by Microsoft Bing and used by participating engines (Bing, Yandex, Seznam, Naver) to hear about new/updated content immediately.
- What is sent and when: when you publish or update a public post, its URL, your site host and your site’s IndexNow key are POSTed to api.indexnow.org. Nothing else is transmitted.
- IndexNow gebruiksvoorwaarden · Microsoft privacyverklaring
Ontwikkelaar
agrc_bot_visit_post_id
Koppelt een gelogd botbezoek aan de WordPress inhoud die het opgevraagde pad vertegenwoordigt.
Sites that serve pages through a custom router (a rewrite or template_include handler running after template_redirect priority 0) have no queried object at the moment the visit is recorded, so the visit is stored with no entry attached. Those pages then drop out of the entry-based surfaces — readiness correlation, blind spots, content freshness and the crawl funnel — and blind spots may even report them as “not visited by any bot yet”.
Alleen de router weet welke inhoud een pad vertegenwoordigt, dus de beslissing wordt aan hem gedelegeerd. Het filter is opt-in: zonder gekoppelde callback blijft het gedrag ongewijzigd.
add_filter( 'agrc_bot_visit_post_id', function ( $post_id, $bot_id, $path ) {
if ( 0 === $post_id && 0 === strpos( $path, '/catalog/' ) ) {
return my_router_resolve_post_id( $path ); // int, or 0 when unknown
}
return $post_id;
}, 10, 3 );
Parameters:
int $post_id— door WordPress opgeloste vermelding ID; 0 wanneer de aanvraag geen losse vermelding is (archieven, het blogoverzicht, 404’s en echt virtuele pagina’s).string $bot_id— registeridentifier van de herkende crawler, bijv.gptbot.string $path— request path with the query string removed and truncated to 255 characters; byte-for-byte what is stored in the visit row.
Geef een geheel getal terug. Niet-numerieke waarden worden genegeerd en negatieve waarden worden op 0 gezet. Het filter draait één keer per botbezoek en nooit bij menselijk verkeer.
Genuinely virtual pages (those with no WordPress entry at all) cannot be scored, because readiness scores live in post meta. Such paths are listed in a separate section of the “Bot interest x readiness” card so the report stays honest instead of silently dropping them.
Schermafbeeldingen





FAQ
Does it modify my files or content?
No. Nothing is written to your files and your post content is never changed. All endpoints (llms.txt, AGENTS.md, the product feed…) are served virtually. Disable a module and it is gone without a trace.
Heb ik een sleutel of een account nodig?
Nee. Er is nergens in deze plugin een sleutelveld, niets te activeren en niets te kopen. Alle 19 modules en elk meetscherm werken zodra je ze aanzet.
Waar verschijnt het scanresultaat?
Op de eigen pagina van de dienst, in het browsertabblad dat opent wanneer je op “Scannen” drukt. De plugin haalt het rapport niet terug naar wp-admin en slaat het niet op.
Verzend de plugin uit zichzelf ergens gegevens naartoe?
With everything at its defaults, no: there is no telemetry and no outbound call happens on its own. If you enable an opt-in module, it makes only the calls described in the “External services” section — IndexNow submits a URL when you publish or update a post, and bot verification downloads public crawler IP lists and signer key directories about once a day. The plugin never phones home.
Botst het met mijn SEO-plugin?
Nee. Wanneer Yoast SEO, Rank Math, AIOSEO of SEOPress wordt gedetecteerd, laat Index Harmony de overlappende schema-/meta-uitvoer aan hen over en meldt dat in het paneel.
Is dit cloaking?
No. Visitors and bots always receive the same content. Markdown negotiation only changes the format when a client explicitly asks for it.
Beoordelingen
Er zijn geen beoordelingen voor deze plugin.
Bijdragers & ontwikkelaars
“Index Harmony” is open source software. De volgende personen hebben bijgedragen aan deze plugin.
Bijdragers“Index Harmony” is vertaald in 3 localen. Dank voor de vertalers voor hun bijdragen.
Vertaal “Index Harmony” in je eigen taal.
Interesse in ontwikkeling?
Bekijk de code, haal de SVN repository op, of abonneer je op het ontwikkellog via RSS.
Changelog
0.9.43
- Fixed: after deactivating and re-activating the plugin, its virtual endpoints (llms.txt, ai.txt, AGENTS.md, the .well-known files, license.xml, security.txt, the product feed) answered 404 until any module was toggled — the hook that runs when the plugin is switched on flushed the rewrite rules before the modules had registered theirs. The flush is now deferred to the next page load, where the rules are present (the path plugin updates already used).
- Audit round: static analysis (PHPStan level 8 with WordPress stubs) over every shipped file, an AJAX/REST authorization sweep, cron teardown parity, i18n key and placeholder coverage, and a live end-to-end run on WordPress 7.1 (setup wizard, the Content-Signal
use=field, Markdown negotiation, every admin screen) found no further defects; two stale docblocks and one null-safe cast were tidied.
0.9.42
- New: Content Signals
use=field — the Content-Signal declaration (Settings General) gains the optional fourth field Cloudflare added to the Content Signals format in 2026:use=immediate(interact only, store nothing),use=reference(index, excerpt and link back) oruse=full(summarise and reproduce). When set it is appended to the robots.txt Content-Signal line, the Content-Signal response header and the ai.txt mirror; left undeclared, nothing changes. RSL, TDMRep and IETF Content-Usage have no equivalent term and are deliberately not touched, and the setup wizard’s policy presets keep the field intact. - New: Markdown negotiation responses now send an
X-Markdown-Tokensheader with the estimated token count of the Markdown body — the convention established by Markdown for Agents (February 2026) — so agents can plan context windows and chunking before reading. - Compatibility: reviewed against WordPress 7.1 (iframed editors, list-table markup, Abilities API lifecycle filters); no changes were needed.
0.9.41
- Hardening (audit round): the
expirestimestamp of a Web Bot Auth signature is now a hard cutoff — an expired signature can no longer earn the verified badge through the clock-skew allowance (the skew tolerance now applies only tocreated, so signers with a slightly fast clock still verify). - Fixed: signer hosts whose key directory could never be fetched used to stay in the cache indefinitely and were re-tried every day forever; failed directories are now dropped after 7 consecutive failed fetches (a signer that comes back simply re-enters through its next signed request), and the cache-size cap now evicts never-successful entries first.
- Docs: the privacy descriptions now also disclose the stored 0/1 signature-verification flag and the signer key-directory downloads, and two stale internal counts (2425 known bots, 1112 verifiable bots) were corrected.
0.9.40
- New: Web Bot Auth cryptographic verification — while bot verification is enabled, bot visits that carry an RFC 9421 Signature-Agent header are now actually verified: the plugin fetches the signer’s public Ed25519 keys from its standardised
/.well-known/http-message-signatures-directory(daily, cached, capped) and checks each signed request’s signature locally (tagweb-bot-auth, JWK-thumbprint key ids, created/expires freshness). Verified visits get a distinct “Signed ✓” badge and asig_verifiedCSV column; unverified ones keep the neutral presence badge — a failed or unavailable check never accuses anyone. Follows draft-meunier-webbotauth-httpsig-protocol-02 (August 2026), including the current dictionary Signature-Agent form with the legacy string form still accepted. Unlike IP-list checks, signature verification also works when your site sits behind a proxy or CDN. - Improved: the bot-verification toggle description and the External services documentation now spell out the signer key-directory downloads, and the traffic-log signature badge distinguishes “carried a signature” from “signature verified”.
- Fixed: the FAQ still said “all 18 modules” — the module count has been 19 since RSL licensing shipped.
0.9.39
- New: RSL content licensing (opt-in module) — publishes a machine-readable RSL 1.0 licensing document at /license.xml, derived from your existing Content-Signal policy axes, and adds the matching License pointer line to robots.txt (rslstandard.org — the open standard backed by Reddit, Yahoo and Medium).
- New: IETF Content-Usage — the AI policy module now emits the draft-ietf-aipref-attach preference expression (train-ai / search) alongside Content-Signal, both as a robots.txt directive and as an HTTP response header, and mirrors it in ai.txt.
- New: Web Bot Auth signature flagging — bot visits that carry an RFC 9421 Signature-Agent header (OpenAI and Google’s agent.bot.goog identity already sign) are flagged in the traffic log and CSV export with the signer’s key-directory host. Presence detection only; this version does not claim cryptographic verification.
- New bot: Google-Agent — Google’s user-triggered AI agent fetcher (Gemini agent features and Project Mariner; added to Google’s official crawler list in March 2026) joins the robots.txt manager (25 bots total), the traffic log with Gemini engine attribution, and opt-in IP-list verification via Google’s published ranges.
- Docs: the External services list now includes Google’s IP-range list, and the privacy description documents the new signature-host column in the visit log.
0.9.38
- First release on WordPress.org: 18 fix modules, setup wizard, tabbed settings, 17-language admin panel, virtual & traceless fix architecture — no key, no account, no paid tier anywhere in the plugin.
- Meting en inzichten: botverkeersdashboard, opt-in botverificatie, botblokkering en piekwaarschuwingen, paginagereedheidsscore + Triage, en een opt-in wekelijkse/dagelijkse samenvatting.
- Pagina-analysesuite: AVG/GDPR neutrale dagelijkse tellers per pagina die een AI-bewijspaneel per pagina voeden, een crawlversheidstrechter, een 28-daagse aandachtsvervalradar, AI-404 fantoom URL-herstel met optionele alleen AI-301’s, een GEO-wijzigingslog met voor/na-impact, en botgezondheidsalarmen (stiltewachter + spoof-golfbewaking met expliciet bevestigde 403 alleen voor vervalste).
- Content scope & curation: opt other plugins’ public content types into your llms.txt, AGENTS.md and page scoring, hand-pick which pages your llms.txt highlights with a live search picker, or edit the published llms.txt body directly.
- Security headers now have a selection screen (Settings Advanced): six optional response headers, each off by default and switched on one at a time.
- Richtlijnen- en hardeningronde: deze build bevat helemaal geen licentie-, ontgrendel- of updatecontrolecode, en niets erin is beperkt door tijd, door gebruik of door iets waarvoor je zou kunnen betalen — botblokkering in het bijzonder is nooit tijdvergrendeld, hij beveelt alleen een observatievenster aan en waarschuwt je als je hem vroeg inschakelt. Hij delegeert ook sitemaps en Product-schema correct aan je SEO-plugin en WooCommerce, voegt cache-invalidatie toe voor llms.txt en de productfeed, haalt audits weg van bezoekersaanvragen en registreert een exporteur/wisser van persoonsgegevens voor auteursprofielvelden.
- Polijstronde: werkende Amazonbot-IP-verificatie, getal-/datumnotatie in de paneeltaal op de meetschermen, een eerlijke waarschuwing (plus ingehouden promotie) voor .well-known-endpoints op submap-installaties (RFC 8615), en openbare identifiers met Index Harmony-branding (REST index-harmony/v1, blok index-harmony/nap, index_harmony_*-shortcodes).
