{"id":350636,"date":"2026-09-15T08:14:47","date_gmt":"2026-09-15T08:14:47","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/scayla-connect\/"},"modified":"2026-09-25T09:38:18","modified_gmt":"2026-09-25T09:38:18","slug":"scayla-connect","status":"publish","type":"plugin","link":"https:\/\/es-ar.wordpress.org\/plugins\/scayla-connect\/","author":23536244,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.8","stable_tag":"1.0.8","tested":"7.1.2","requires":"6.4","requires_php":"7.4","requires_plugins":null,"header_name":"Scayla Connect","header_author":"Scayla","header_description":"Pairs your WordPress \/ WooCommerce site with the Scayla service: verified SEO meta writes, FAQ structured data, and managed redirects. All plugin functionality is free; content generation runs in the Scayla cloud service (account required).","assets_banners_color":"121016","last_updated":"2026-09-25 09:38:18","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/scayla.co.il\/wordpress","header_author_uri":"https:\/\/scayla.co.il\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":146,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"liorzabari","date":"2026-09-15 08:43:18","revision":3696520},"1.0.1":{"tag":"1.0.1","author":"liorzabari","date":"2026-09-16 11:39:53","revision":3698453},"1.0.8":{"tag":"1.0.8","author":"liorzabari","date":"2026-09-25 09:38:18","revision":3712774}},"upgrade_notice":{"1.0.6":"<p>Adds every remaining Scayla screen to the Scayla menu. Sites that are already connected need to do nothing.<\/p>","1.0.5":"<p>Adds the Deep analysis screen. Sites that are already connected need to do nothing.<\/p>","1.0.4":"<p>Adds the Competitors &amp; AI visibility screen. Sites that are already connected need to do nothing.<\/p>","1.0.3":"<p>Adds the Products screen. Sites that are already connected need to do nothing.<\/p>","1.0.2":"<p>The Scayla screens move inside wp-admin. Sites that are already connected need to do nothing.<\/p>","1.0.1":"<p>Adds a one-click Connect button. Sites that are already connected need to do nothing.<\/p>","1.0.0":"<p>First public release. No upgrade steps.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3696465,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3696465,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3696465,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3696465,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.1","1.0.8"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[2353,726,186,1121,286],"plugin_category":[45,55],"plugin_contributors":[280801],"plugin_business_model":[],"class_list":["post-350636","plugin","type-plugin","status-publish","hentry","plugin_tags-ai","plugin_tags-redirects","plugin_tags-seo","plugin_tags-structured-data","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_category-seo-and-marketing","plugin_contributors-liorzabari","plugin_committers-liorzabari"],"banners":{"banner":"https:\/\/ps.w.org\/scayla-connect\/assets\/banner-772x250.png?rev=3696465","banner_2x":"https:\/\/ps.w.org\/scayla-connect\/assets\/banner-1544x500.png?rev=3696465","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/scayla-connect\/assets\/icon-128x128.png?rev=3696465","icon_2x":"https:\/\/ps.w.org\/scayla-connect\/assets\/icon-256x256.png?rev=3696465","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Scayla Connect is not an SEO plugin. It is the site-side connector for <a href=\"https:\/\/scayla.co.il\/\">Scayla<\/a>, a cloud service that measures whether AI assistants actually name your store when a shopper asks what to buy, and then acts on what it measured.<\/p>\n\n<p>The queries it measures are not generic keywords typed into a box. They are derived from a scan of your own catalogue \u2014 real product titles, product types and categories \u2014 which is why they reach the level of a specific product or category. When a gap is found, the service turns it into a change on your site through this plugin, then measures the same fixed query set again the following week.<\/p>\n\n<p>Every SEO value written is read back from the source your site will actually serve before the write is reported as successful. That is why a separate connector exists. Since Yoast SEO 14, Yoast does not serve SEO meta from post meta; it serves it from its own <code>wp_yoast_indexable<\/code> table. A tool that calls <code>update_post_meta( $id, '_yoast_wpseo_title', ... )<\/code> gets a successful database write, a 200 response, and a front end that keeps serving the old title indefinitely. This plugin writes, reconciles the indexable, re-reads from the serving source, compares, and on any mismatch returns a hard <code>scayla_write_not_verified<\/code> error carrying the expected value, the actual value and which storage layer answered.<\/p>\n\n<p>Yoast SEO and Rank Math \u2014 the two SEO plugins this connector writes through \u2014 both ship AI-visibility tracking of their own, and track it well, at brand level. Scayla is the other shape of the same problem: catalogue-derived queries, a write path back into the exact product or category that caused the gap, and verification on every write. Scayla is not the only vendor that both measures and writes back, and this plugin does not claim to be.<\/p>\n\n<p><strong>Hebrew and RTL.<\/strong> Redirect paths never pass through <code>sanitize_text_field()<\/code>, which strips every percent-encoded octet and would silently turn an encoded Hebrew slug into a live 301 to the wrong page; the plugin uses its own percent-safe sanitiser. FAQ content renders as a native <code>&lt;details&gt;<\/code> \/ <code>&lt;summary&gt;<\/code> accordion with no JavaScript and no stylesheet, so it inherits your theme's RTL direction. Hebrew content analysis is not claimed as a differentiator \u2014 Yoast and Rank Math both support Hebrew already.<\/p>\n\n<p><strong>What the plugin does on your site<\/strong><\/p>\n\n<ul>\n<li>Pairs with your Scayla account through WordPress's own Application Password approval screen (or a manually created Application Password), used once, then operates through a dedicated <code>scayla-connector<\/code> service user with a narrow, revocable token.<\/li>\n<li>Bridges SEO title and meta description writes to Yoast SEO or Rank Math, with mandatory read-back verification on every write. With no SEO plugin active it stores and renders those values itself.<\/li>\n<li>Renders FAQ structured data as a single FAQPage node merged into Yoast's schema graph, or into Rank Math's JSON-LD, or as its own script tag when neither is present. The three paths are mutually exclusive, so an FAQPage is never rendered twice.<\/li>\n<li>Writes category and tag descriptions through a dedicated endpoint, because WordPress core registers <code>wp_filter_kses<\/code> on <code>pre_term_description<\/code> unconditionally and silently strips <code>div<\/code>, <code>h2<\/code>, <code>p<\/code>, <code>details<\/code> and <code>summary<\/code> while returning a 200. The plugin does not detach core's filter; it runs its own allowlist and outranks core, so nothing else on the site loses kses protection.<\/li>\n<li>Manages a redirects table for dead URLs, with guards against self-redirects, two-step loops, cross-host targets, and the protected prefixes <code>\/wp-admin<\/code>, <code>\/wp-json<\/code>, <code>\/wp-login.php<\/code>, <code>\/wp-content<\/code> and the site root.<\/li>\n<li>Adds a <strong>Scayla<\/strong> admin menu. Before connecting it holds the Connect page. Once connected it holds the Scayla screens (Home, Competitors &amp; AI visibility, Deep analysis, Content, Keywords, Products, Collections, Fixes, Rankings, Links, Strategy, Weekly report and Settings), shown inside wp-admin the way an app sits inside a store's admin, and a native <strong>Connection<\/strong> page with the connection status, detected SEO plugin, redirect and FAQ counts, and a Disconnect button.<\/li>\n<\/ul>\n\n<p><strong>How it is built.<\/strong> Plain, readable PHP: seven classes plus the main file and <code>uninstall.php<\/code>, and one short, unminified admin script (<code>admin\/js\/scayla-app.js<\/code>) that runs only on the Scayla screens. No build step and no minified or obfuscated code. The plugin loads no script, stylesheet, font or image from a remote server into your WordPress pages: the Scayla screens are a page served by the Scayla service and displayed in a frame, where they run in their own origin and cannot read the admin page around them. Nothing is compiled, so what you read in the plugin folder is exactly what runs.<\/p>\n\n<p><strong>Nothing in the plugin is gated.<\/strong> No premium tier inside this code, no license check, no feature flag, no nag, no upsell that unlocks a function. Every capability above works in full without paying anything. Paid limits exist only in the Scayla cloud service, and they limit how much work the service does, not what the plugin may do.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin is a connector for Scayla, a third-party cloud service operated by Scayla (https:\/\/scayla.co.il\/). <strong>A Scayla account is required.<\/strong> Without one the plugin has nothing to talk to: it will pair with nothing, receive no writes, and do nothing useful.<\/p>\n\n<p><strong>The plugin makes no outbound requests.<\/strong> It contains no <code>wp_remote_*<\/code>, <code>curl_*<\/code>, <code>file_get_contents<\/code> or <code>fsockopen<\/code> call anywhere in its code. It never contacts Scayla, on any schedule or on any event, including deactivation. The <strong>Connect to Scayla<\/strong> button is an ordinary link, and the Scayla screens are a frame: in both cases it is your browser that talks to Scayla, and the plugin sends nothing. Scayla's servers call your site's REST API and authenticate with the paired token, and data leaves your site only inside the response to one of those authenticated requests, or inside the short-lived ticket described below.<\/p>\n\n<p><strong>What leaves your site, and when:<\/strong><\/p>\n\n<ul>\n<li><strong>When you pair.<\/strong> Clicking <strong>Connect to Scayla<\/strong> takes your browser to Scayla (<code>https:\/\/wp-api.scayla.co.il\/connect\/start<\/code>) with your site address and admin language in the link. Scayla reads your site's public REST index (<code>GET \/wp-json\/<\/code>) to confirm this plugin is active and to find your approval screen, then sends your browser to that screen on your own site (<code>\/wp-admin\/authorize-application.php<\/code>). If you approve, WordPress creates an Application Password named Scayla and sends your browser to Scayla with it (<code>\/connect\/authorized<\/code>). Scayla uses it for one authenticated <code>POST \/wp-json\/scayla\/v1\/pair<\/code>, then deletes it: <code>GET \/wp-json\/wp\/v2\/users\/me\/application-passwords\/introspect<\/code> identifies that one password and <code>DELETE \/wp-json\/wp\/v2\/users\/me\/application-passwords\/{uuid}<\/code> removes it, leaving any other Application Passwords untouched. Your browser is then sent back to the Scayla menu in your admin. If you decline, WordPress sends you straight back to that menu and nothing is created. (Connecting manually instead, you paste an Application Password into the portal and revoke it yourself afterwards.) The pairing response carries your site address and REST API address, your WordPress and WooCommerce version numbers, your permalink structure, which SEO plugin was detected, the login name of the service user just created, and \u2014 once only, in this one response \u2014 the API token your site mints for Scayla to authenticate with from then on. Your site keeps only a SHA-256 hash of that token.<\/li>\n<li><strong>While the service operates<\/strong> (each time Scayla's servers call your site with the paired token): the content being worked on \u2014 product, post, page and category titles and descriptions, SEO titles and meta descriptions, image alt text, FAQ questions and answers, and redirect paths. Scayla reads these to know the current state, and writes new values back the same way.<\/li>\n<li><strong>When you open a Scayla screen<\/strong> (any page under the Scayla menu except Connection): your browser loads the screen from <code>https:\/\/wp-api.scayla.co.il\/app<\/code>, with your admin's host name, the admin language and the screen name in the address, and sends your admin's origin (the scheme and host, never the page's path) as the referrer. The admin page then hands the screen a signed ticket, by <code>postMessage<\/code> and never in an address, so Scayla can tell which site is asking. The ticket contains your site's host name, the time it was issued, a random value, and an HMAC signature made with a key derived from the stored token hash; it is valid for five minutes and contains no user name, email address, password or token. When a screen stays open longer than that, it asks for a fresh ticket through the <code>scayla_app_ticket<\/code> admin-ajax action, which answers administrators only (<code>manage_options<\/code> and a nonce). What the screens then show is read from Scayla's own records about your site.<\/li>\n<li><strong>When Scayla checks the connection<\/strong> (<code>GET \/wp-json\/scayla\/v1\/health<\/code>, authenticated): plugin version, WordPress and WooCommerce versions, detected SEO plugin, permalink structure, site and home URL, locale, time zone, and the first 8 characters of the stored token hash as a connection fingerprint. The token itself is never returned.<\/li>\n<li><strong>When Scayla checks what changed<\/strong> (<code>GET \/wp-json\/scayla\/v1\/changes<\/code> and <code>GET \/wp-json\/scayla\/v1\/terms\/stamps<\/code>, authenticated, every few minutes while your site is connected to a Scayla workspace): whether products or product categories changed since Scayla last asked, the ids of any that were deleted, and when each category was last edited. The plugin notes these in one option (<code>scayla_changes<\/code>) and in category meta (<code>_scayla_updated_at<\/code>) on your own site; it still sends nothing by itself.<\/li>\n<li><strong>When you choose who Scayla's articles are published as<\/strong> (<code>GET \/wp-json\/scayla\/v1\/authors<\/code>, authenticated): for each user who may publish posts, at most 100, their user ID, display name and role. Never their login name, email address or any other profile field, and never anyone who cannot publish posts (subscribers, shop customers).<\/li>\n<\/ul>\n\n<p><strong>What never leaves your site:<\/strong> no visitor data, no IP addresses, no analytics, no tracking beacons, no order or customer data, no email addresses or login names, no user accounts other than the display name and role of the users who may publish posts (above), and no data of any kind sent to any host other than the Scayla service that authenticated the request.<\/p>\n\n<p>By pairing your site you agree to Scayla's terms and privacy policy:<\/p>\n\n<ul>\n<li>Terms of service: https:\/\/scayla.co.il\/terms<\/li>\n<li>Privacy policy: https:\/\/scayla.co.il\/privacy<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin files to <code>\/wp-content\/plugins\/scayla-connect<\/code>, or install it through the WordPress Plugins screen.<\/li>\n<li>Activate the plugin. Activation creates the redirects table and nothing else \u2014 no user account is created and no token exists yet.<\/li>\n<li>Open the <strong>Scayla<\/strong> admin menu and read the external-service disclosure shown there before you continue.<\/li>\n<li>Click <strong>Connect to Scayla<\/strong> and approve the request on the WordPress screen that follows. Scayla uses the Application Password WordPress creates once, to pair, deletes it, and brings you back to the <strong>Scayla<\/strong> menu, where the Scayla screens now live.<\/li>\n<li>Prefer to do it by hand? Under <strong>Connect manually instead<\/strong>: create an Application Password for your administrator account (Users \u2192 Profile \u2192 Application Passwords), paste it into the Scayla portal, and revoke it once pairing succeeds.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20exactly%20can%20the%20service%20do%20on%20my%20site%3F\"><h3>What exactly can the service do on my site?<\/h3><\/dt>\n<dd><p>Pairing creates one user, <code>scayla-connector<\/code>, holding a custom role with exactly 13 capabilities: <code>read<\/code>, <code>edit_posts<\/code>, <code>edit_others_posts<\/code>, <code>publish_posts<\/code>, <code>edit_published_posts<\/code>, <code>delete_posts<\/code>, <code>delete_others_posts<\/code>, <code>delete_published_posts<\/code>, <code>edit_pages<\/code>, <code>edit_others_pages<\/code>, <code>edit_published_pages<\/code>, <code>upload_files<\/code>, <code>manage_categories<\/code>. With WooCommerce active, 9 product capabilities are added, including <code>read_private_products<\/code> (WooCommerce maps a product collection read to it) and <code>manage_product_terms<\/code>.<\/p>\n\n<p>It does not get <code>manage_options<\/code>, <code>install_plugins<\/code>, <code>install_themes<\/code>, <code>switch_themes<\/code>, <code>edit_theme_options<\/code>, <code>edit_users<\/code>, <code>unfiltered_html<\/code>, <code>publish_pages<\/code> or <code>delete_pages<\/code>. Pages are editable but not publishable or deletable, because the service only writes SEO onto pages that already exist. The role is re-asserted on every load and any capability not on the list is stripped, so another plugin cannot quietly widen it.<\/p><\/dd>\n<dt id=\"is%20any%20code%20downloaded%20or%20executed%20from%20the%20remote%20service%3F\"><h3>Is any code downloaded or executed from the remote service?<\/h3><\/dt>\n<dd><p>No. The plugin never fetches, stores or evaluates remote code \u2014 no <code>eval<\/code>, no dynamic include, no remote file download. What arrives from Scayla is text: titles, descriptions, FAQ questions and answers, and paths. Each passes an explicit filter before storage: FAQ questions have all tags stripped and answers pass <code>wp_kses_post<\/code>; category and tag descriptions pass a post-context <code>wp_kses<\/code> allowlist extended only with <code>details<\/code>, <code>summary<\/code> and a small set of <code>class<\/code>\/<code>id<\/code>\/<code>data-<\/code> attributes, so <code>script<\/code>, <code>iframe<\/code> and <code>on*<\/code> handlers cannot be stored even if the token were stolen. Redirect paths pointing at another host are rejected outright.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20a%20write%20does%20not%20land%3F\"><h3>What happens if a write does not land?<\/h3><\/dt>\n<dd><p>It fails loudly. After every SEO write the plugin reconciles the provider's storage, re-reads the value from the source your front end will actually serve, and compares. If they differ it returns HTTP 500 with <code>scayla_write_not_verified<\/code> and a body containing the expected value, the actual value, which storage layer answered (<code>indexable<\/code>, <code>postmeta<\/code>, <code>option<\/code> or <code>scayla<\/code>) and a hint distinguishing \"Yoast's indexable did not reconcile\" from \"another plugin may be overriding SEO meta\". For Yoast terms the read-back deliberately reads the indexable rather than the option just written, because a verification that reads back its own write proves nothing.<\/p><\/dd>\n<dt id=\"does%20it%20work%20without%20woocommerce%2C%20or%20without%20an%20seo%20plugin%3F\"><h3>Does it work without WooCommerce, or without an SEO plugin?<\/h3><\/dt>\n<dd><p>Both are optional. Without WooCommerce it works on posts, pages, categories and tags; with it, products and product categories are covered too. Without Yoast or Rank Math it stores values in its own <code>_scayla_seo_title<\/code> and <code>_scayla_seo_description<\/code> meta and renders them through <code>pre_get_document_title<\/code> and a <code>wp_head<\/code> meta description. Those standalone renderers refuse to run unless the detected provider is exactly \"none\", so there is never a duplicate title alongside Yoast or Rank Math.<\/p><\/dd>\n<dt id=\"does%20it%20slow%20down%20my%20site%3F\"><h3>Does it slow down my site?<\/h3><\/dt>\n<dd><p>The redirect matcher runs at <code>template_redirect<\/code> and costs zero database queries when a request does not match: the map lives in one autoloaded option WordPress has already fetched, an empty map returns before the request URI is parsed, and only a hit touches the database. If the map would exceed 100 KB it is dropped in favour of a single prepared query, so a large table never bloats every admin and cron request. Paths are stored in <code>utf8mb4_bin<\/code> columns so matching is byte-exact, which stops a case-normalising rule such as <code>\/Page<\/code> to <code>\/page<\/code> from matching its own destination and looping forever. The plugin registers no cron jobs.<\/p><\/dd>\n<dt id=\"can%20the%20service%20user%20log%20in%3F\"><h3>Can the service user log in?<\/h3><\/dt>\n<dd><p>No. It is created with a 64-character random password that is never transmitted, displayed, stored in plaintext or logged \u2014 but the guarantee does not rest on that. An <code>authenticate<\/code> filter rejects any interactive login resolving to the service user, and an <code>allow_password_reset<\/code> filter refuses password resets for it, closing the otherwise real path of requesting a reset to <code>connector@yourdomain<\/code> on a catch-all mail domain. The token maps to the service user only on REST requests, anchored to the first path segment via <code>rest_get_url_prefix()<\/code>, so a front-end permalink merely containing <code>wp-json<\/code> cannot borrow the identity.<\/p><\/dd>\n<dt id=\"are%20any%20of%20the%20rest%20routes%20public%3F\"><h3>Are any of the REST routes public?<\/h3><\/dt>\n<dd><p>No. Every route has a real permission callback, including <code>GET \/health<\/code>; there is no <code>__return_true<\/code> anywhere in the code. Write routes additionally check the specific object: <code>current_user_can( 'edit_post', $id )<\/code> for that post, or term existence plus a taxonomy allowlist plus <code>manage_categories<\/code> for that term. The bulk read endpoint enforces authorisation per ID rather than once per batch, and anything the service user may not touch is returned in a <code>skipped<\/code> list instead of being read. Failed token attempts are rate-limited per IP, bucketed on <code>REMOTE_ADDR<\/code> rather than on spoofable proxy headers.<\/p><\/dd>\n<dt id=\"how%20do%20i%20disconnect%2C%20and%20what%20is%20removed%20if%20i%20delete%20the%20plugin%3F\"><h3>How do I disconnect, and what is removed if I delete the plugin?<\/h3><\/dt>\n<dd><p>Click <strong>Disconnect<\/strong> on the <strong>Scayla \u2192 Connection<\/strong> page. The token hash is deleted immediately and every subsequent request from Scayla is rejected; your content, SEO values, FAQ data and redirects stay exactly as they are. Deactivating changes nothing else, so you can deactivate to troubleshoot and reactivate without re-pairing.<\/p>\n\n<p>Deleting the plugin removes the role from the service user, deletes the role, drops the redirects table, deletes <code>_scayla_faq<\/code>, <code>_scayla_seo_title<\/code> and <code>_scayla_seo_description<\/code> from every post and term, and sweeps every <code>scayla_*<\/code> option and transient \u2014 on every site of a multisite network. Two things are kept on purpose: the <code>scayla-connector<\/code> account, so content it authored keeps its author attribution (it has no role, zero capabilities and cannot be logged into; delete it manually if you prefer), and SEO values already written into Yoast or Rank Math, because at that point they are your site's meta, not the plugin's.<\/p><\/dd>\n<dt id=\"does%20it%20support%20multisite%3F\"><h3>Does it support multisite?<\/h3><\/dt>\n<dd><p>Yes. Network activation provisions every existing site, sites created afterwards are provisioned automatically, and uninstall walks every site so no orphan table or role is left behind.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.8<\/h4>\n\n<ul>\n<li>Elementor blog posts: when this site is connected to a Scayla workspace, runs Elementor with the Atomic Editor turned on, and the site owner turns the feature on in Scayla, Scayla can write NEW blog posts designed in your site's Elementor style, save them as drafts, and publish one only after a person approved it in Scayla. Scayla only ever changes posts it created itself. It never builds pages, never edits a post or page you made, and never touches your header, footer, templates, global colors, fonts or classes.<\/li>\n<\/ul>\n\n<h4>1.0.7<\/h4>\n\n<ul>\n<li>When your site is connected to a Scayla workspace, Scayla now sees your product and category edits within minutes, and reads only what changed instead of your whole catalogue. The plugin notes that something changed; Scayla's server asks for that note.<\/li>\n<li>Product answers to Scayla carry each image's small rendition on WooCommerce versions that do not include it already.<\/li>\n<li>When this site is connected to a Scayla workspace, Scayla can list the users who may publish posts (their display name and role only, never an e-mail or login), so you choose who Scayla's articles are published as.<\/li>\n<li>Scayla's own development store can point at Scayla's development service with a <code>wp-config.php<\/code> constant. Nothing changes for any other site.<\/li>\n<\/ul>\n\n<h4>1.0.6<\/h4>\n\n<ul>\n<li>The Scayla menu now holds every Scayla screen, in the same order as Scayla's app in other store admins: <strong>Home<\/strong>, <strong>Competitors &amp; AI visibility<\/strong>, <strong>Deep analysis<\/strong>, <strong>Content<\/strong>, <strong>Keywords<\/strong>, <strong>Products<\/strong>, <strong>Collections<\/strong>, <strong>Fixes<\/strong>, <strong>Rankings<\/strong>, <strong>Links<\/strong>, <strong>Strategy<\/strong>, <strong>Weekly report<\/strong> and <strong>Settings<\/strong>.<\/li>\n<li><strong>Home<\/strong> replaces the Overview: what Scayla did this week, what waits for you, and the next best step.<\/li>\n<li><strong>Content<\/strong> shows each article as it will look on your site, with approve, reject, schedule and rewrite-with-a-note.<\/li>\n<li><strong>Keywords<\/strong>, <strong>Strategy<\/strong> and <strong>Weekly report<\/strong> show the research, the plan and the week's results the Deep analysis builds.<\/li>\n<li><strong>Collections<\/strong> writes SEO titles, descriptions, intro paragraphs and FAQ for your product categories, each on your approval and reversible.<\/li>\n<li><strong>Fixes<\/strong> checks what AI crawlers may read and suggests 301 redirects for pages that return 404, applied only on your approval.<\/li>\n<li>A Scayla redirect now acts only when WordPress answers the address with a 404, so it can never cover a page that exists.<\/li>\n<li><strong>Settings<\/strong> holds your plan and billing, your content preferences and what Scayla learned from you. The old Plan address opens it.<\/li>\n<li>The screens' frame may start a download (the keyword research file) and copy the weekly report to the clipboard.<\/li>\n<\/ul>\n\n<h4>1.0.5<\/h4>\n\n<ul>\n<li>New <strong>Deep analysis<\/strong> screen under the Scayla menu: Scayla reads your store and researches your competitors, market, buyer searches and content opportunities, then shows what it found and a strategy built from it. You follow each stage live while it runs.<\/li>\n<li>The analysis then prepares every other screen: product and category SEO suggestions, the questions measured on the AI visibility screen, and a first article for your approval queue.<\/li>\n<li>Five short questions switch Scayla on. The Overview leads there until they are answered.<\/li>\n<\/ul>\n\n<h4>1.0.4<\/h4>\n\n<ul>\n<li>New <strong>Competitors &amp; AI visibility<\/strong> screen under the Scayla menu: Scayla asks AI assistants the questions your buyers ask and shows how often your store appears in their answers, next to the competitors you track. Read each answer as the assistant wrote it, add competitors by their website and questions of your own, and turn a question you are missing from into an article for your approval queue.<\/li>\n<li>Measuring runs in the background, so you can leave the page while it works.<\/li>\n<\/ul>\n\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>New <strong>Products<\/strong> screen under the Scayla menu: Scayla scans your catalogue for the weakest SEO titles, meta descriptions and image alt texts, and shows each suggestion next to the value it would replace. Apply one, apply all within your monthly allowance, or dismiss with a reason Scayla learns from. Every applied change can be rolled back.<\/li>\n<li>The scan runs in the background, so you can leave the page while it works.<\/li>\n<li>A short notice after each action and a progress indicator while it runs.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>The Scayla screens now live inside wp-admin: <strong>Overview<\/strong>, <strong>Content<\/strong> (the approval queue, where every article can be read, approved, sent back with a note, or rejected) and <strong>Plan<\/strong>, under the Scayla menu.<\/li>\n<li>Connecting brings you back to that menu, whether you approve, decline, or something goes wrong, with a notice saying which.<\/li>\n<li>A new <strong>Connection<\/strong> page keeps the connection status and the Disconnect button, and works even when Scayla cannot be reached.<\/li>\n<li>Returning from a payment brings you back to the Plan screen.<\/li>\n<li>Hebrew translation for the plugin's own screens.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>One-click connect: a <strong>Connect to Scayla<\/strong> button takes you through WordPress's own Application Password approval screen, so nothing has to be copied or pasted. Scayla uses that password once to pair and then deletes it.<\/li>\n<li>The manual flow (create an Application Password, paste it into the portal) is still available under <strong>Connect manually instead<\/strong>.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First public release.<\/li>\n<li>Pairing through a one-time admin Application Password; day-to-day access through a scoped, revocable token stored only as a SHA-256 hash.<\/li>\n<li>Dedicated service user and role with a fixed capability list that cannot be logged into or password-reset.<\/li>\n<li>SEO title and meta description bridge for Yoast SEO and Rank Math, plus a standalone mode, with read-back verification on every write.<\/li>\n<li>FAQPage JSON-LD merged into Yoast's schema graph or Rank Math's JSON-LD, with a self-contained fallback.<\/li>\n<li>Category and tag description endpoint that preserves structural HTML through an allowlist without detaching core's kses filter, and verifies the stored result.<\/li>\n<li>Redirects table with byte-exact matching, loop, self-redirect, cross-host and protected-path guards, and a zero-query front-end match on a miss.<\/li>\n<li>Multisite provisioning and multisite-aware uninstall.<\/li>\n<\/ul>","raw_excerpt":"Connector for Scayla: measures whether AI assistants name your store, then writes SEO, FAQ schema and redirects, verified by read-back.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/350636","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=350636"}],"author":[{"embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/liorzabari"}],"wp:attachment":[{"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=350636"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=350636"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=350636"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=350636"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=350636"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/es-ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=350636"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}