{"id":350870,"date":"2026-08-19T01:38:48","date_gmt":"2026-08-19T01:38:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/ai-crawler-tracker-by-citlyze\/"},"modified":"2026-09-27T04:15:21","modified_gmt":"2026-09-27T04:15:21","slug":"citlyze-ai-crawler-tracker","status":"publish","type":"plugin","link":"https:\/\/ja.wordpress.org\/plugins\/citlyze-ai-crawler-tracker\/","author":23543573,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.3.0","stable_tag":"2.3.0","tested":"7.1.2","requires":"6.0","requires_php":"7.2","requires_plugins":null,"header_name":"AI Crawler Tracker by Citlyze","header_author":"Citlyze","header_description":"Track verified AI crawler visits and referrals from AI answer engines in Citlyze.","assets_banners_color":"0b1a30","last_updated":"2026-09-27 04:15:21","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/citlyze.com\/integrations","header_author_uri":"https:\/\/citlyze.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":695,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.1.0":{"tag":"2.1.0","author":"citlyze","date":"2026-08-19 02:24:26","revision":3653735},"2.2.0":{"tag":"2.2.0","author":"citlyze","date":"2026-08-27 03:35:30","revision":3668021},"2.3.0":{"tag":"2.3.0","author":"citlyze","date":"2026-09-27 04:15:21","revision":3714957}},"upgrade_notice":{"2.3.0":"<p>Exact status codes, redirect tracking, queued delivery with retries, and correct visitor IPs behind proxies. Update to keep reporting: Citlyze now expects this version&#039;s event format.<\/p>","2.0.0":"<p>Encrypted signing-secret storage, enforced HTTPS endpoints, and a stricter signed request format. Re-paste your signing secret after upgrading.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3653705,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3653705,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3653705,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3653705,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.1.0","2.2.0","2.3.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3653705,"resolution":"1","location":"assets","locale":"","width":2560,"height":1580},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3653705,"resolution":"2","location":"assets","locale":"","width":2560,"height":1580},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3653705,"resolution":"3","location":"assets","locale":"","width":2560,"height":1580}},"screenshots":{"1":"Connection settings, the write-only signing-secret field, and the signed connection test.","2":"Verified AI crawler visits in the Citlyze dashboard: totals, top crawler, trend, and visits over time.","3":"User-triggered agents and verification diagnostics: verified totals kept separate from unverified user-agent claims."}},"plugin_section":[],"plugin_tags":[244526,2353,232,2591,186],"plugin_category":[36,55],"plugin_contributors":[276381],"plugin_business_model":[],"class_list":["post-350870","plugin","type-plugin","status-publish","hentry","plugin_tags-aeo","plugin_tags-ai","plugin_tags-analytics","plugin_tags-geo","plugin_tags-seo","plugin_category-analytics","plugin_category-seo-and-marketing","plugin_contributors-citlyze","plugin_committers-citlyze"],"banners":{"banner":"https:\/\/ps.w.org\/citlyze-ai-crawler-tracker\/assets\/banner-772x250.png?rev=3653705","banner_2x":"https:\/\/ps.w.org\/citlyze-ai-crawler-tracker\/assets\/banner-1544x500.png?rev=3653705","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/citlyze-ai-crawler-tracker\/assets\/icon-128x128.png?rev=3653705","icon_2x":"https:\/\/ps.w.org\/citlyze-ai-crawler-tracker\/assets\/icon-256x256.png?rev=3653705","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/citlyze-ai-crawler-tracker\/assets\/screenshot-1.png?rev=3653705","caption":"Connection settings, the write-only signing-secret field, and the signed connection test."},{"src":"https:\/\/ps.w.org\/citlyze-ai-crawler-tracker\/assets\/screenshot-2.png?rev=3653705","caption":"Verified AI crawler visits in the Citlyze dashboard: totals, top crawler, trend, and visits over time."},{"src":"https:\/\/ps.w.org\/citlyze-ai-crawler-tracker\/assets\/screenshot-3.png?rev=3653705","caption":"User-triggered agents and verification diagnostics: verified totals kept separate from unverified user-agent claims."}],"raw_content":"<!--section=description-->\n<p>AI Crawler Tracker by Citlyze shows you which AI crawlers visit your WordPress site and which AI answer engines send you human visitors. It is built for AI SEO: generative engine optimization (GEO), answer engine optimization (AEO), and LLM visibility measurement.<\/p>\n\n<p>AI search engines and LLM chatbots such as ChatGPT, Claude, Perplexity, Gemini, and Copilot discover your content by crawling it, and most AI bots never execute JavaScript, so JavaScript analytics tools cannot see them. This plugin runs server-side inside WordPress, so it observes the AI bot traffic that reaches PHP and reports it to your Citlyze workspace.<\/p>\n\n<h4>Features<\/h4>\n\n<ul>\n<li>Server-side AI bot detection that JavaScript analytics misses: GPTBot, ChatGPT-User, OAI-SearchBot, ClaudeBot, PerplexityBot, Bingbot, Amazonbot, Applebot, Google and Meta AI crawlers, and many more.<\/li>\n<li>Verified AI crawler analytics: Citlyze independently confirms that a request genuinely came from the bot it claims to be, so spoofed user agents never inflate your numbers.<\/li>\n<li>AI referral tracking: see when ChatGPT, Perplexity, Gemini, Copilot, Claude, Meta AI, Grok, DeepSeek, or Mistral send real visitors to your pages.<\/li>\n<li>Web Bot Auth support: cryptographically signed AI agents are recognised and passed to Citlyze for verification.<\/li>\n<li>No impact on page speed: a matching request is noted in the site's own database, and delivery happens after the response is finished or on a one-minute schedule. Nothing loads in visitors' browsers, and the plugin sets no cookies.<\/li>\n<li>Exact status codes and redirects: counts show the real response (200, 301, 404, 410, 500), including requests another plugin redirects before WordPress renders a page, and where each redirect pointed.<\/li>\n<li>Reliable delivery: events are sent in signed batches and retried if Citlyze is briefly unreachable, so a short outage does not lose them.<\/li>\n<li>Security-first settings: the signing secret is write-only and stored encrypted, with optional wp-config.php constants so it never touches the database.<\/li>\n<li>Clean uninstall: the plugin removes its settings, its delivery queue, and its scheduled tasks when you delete it.<\/li>\n<\/ul>\n\n<p>A Citlyze account and a site key generated in Citlyze are required. Tracking stays inactive until an administrator enters valid settings. The plugin sends signed events only for matching crawler, signed-agent, or AI-referral requests. Citlyze independently verifies supported crawler sources before adding them to verified totals; other claims remain separate diagnostics.<\/p>\n\n<h4>Why track AI crawlers?<\/h4>\n\n<p>AI search is becoming a real discovery channel. Whether ChatGPT, Perplexity, or Gemini can cite your site starts with whether their crawlers can reach it. Tracking AI crawler visits tells you which bots read your content, how often they come back, and which pages they fetch, and tracking AI referrals tells you when that visibility turns into visitors. That measurement is the foundation of any GEO or AEO strategy.<\/p>\n\n<h4>External services<\/h4>\n\n<p>This plugin connects to the Citlyze endpoint entered by the site administrator. It requires a Citlyze account and cannot provide tracking without that service.<\/p>\n\n<p>For a request from a known AI crawler or signed agent, the plugin sends the visitor IP address, user agent, requested path, query string, HTTP status code, HTTP method, the request host, and for redirects the redirect destination (a same-site path, or only the domain for an external destination) and the name of the plugin that issued it. When Web Bot Auth is present, it also sends bounded Signature, Signature-Input, Signature-Agent, and safe original-request metadata so Citlyze can independently verify the signature. When a human visitor arrives from a supported AI answer engine, the plugin sends the referrer URL without its query string. The site key ID, a timestamp, a request signature, and a one-time nonce authenticate each batch. Once a day the plugin also downloads Citlyze's current list of known crawlers, signed with your site key, so newly launched crawlers are recognised without a plugin update.<\/p>\n\n<p>Data is sent only when the request carries a recognised crawler user agent, contains bounded Web Bot Auth headers, comes from a supported AI-referrer host, or when an administrator explicitly sends a connection test. Requests are never sent for ordinary human page views, and a human visitor's query string is never sent. Matching requests wait in a table in your WordPress database until delivery, at most one day. Citlyze uses the IP address and signature metadata transiently for verification and does not store them. Referrer URLs are not stored. Citlyze persists aggregate counters, and on plans that include the crawl log it also keeps a per-request record of verified crawler and signed agent visits (time, path, sanitized query string, status code, and redirect destination; never an IP address or user agent) for up to 30 days. Sanitized user-agent samples may be retained in bounded diagnostics for unrecognized bots.<\/p>\n\n<p>Service terms: https:\/\/citlyze.com\/terms-of-service<\/p>\n\n<p>Privacy policy: https:\/\/citlyze.com\/privacy-policy<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin ZIP in WordPress under Plugins &gt; Add New &gt; Upload Plugin.<\/li>\n<li>Activate \"AI Crawler Tracker by Citlyze\".<\/li>\n<li>In Citlyze, open AI Crawlers &gt; Install tracking and generate a site key.<\/li>\n<li>In WordPress, open Settings &gt; AI Crawler Tracker and enter the tracker URL, key ID, and signing secret.<\/li>\n<li>Save the settings, then use \"Send test event\" to verify the connection.<\/li>\n<\/ol>\n\n<p>For security-conscious hosts, define <code>CITLYZE_CRAWLER_SIGNING_KEY<\/code> in <code>wp-config.php<\/code>. The plugin hashes it in memory and does not store it in the WordPress database. <code>CITLYZE_CRAWLER_ENDPOINT<\/code> and <code>CITLYZE_CRAWLER_KEY_ID<\/code> may be defined there as well.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20work%20with%20full-page%20caching%20or%20a%20cdn%3F\"><h3>Does this work with full-page caching or a CDN?<\/h3><\/dt>\n<dd><p>Only when the request reaches WordPress. A full-page cache or CDN can respond without running PHP, so those crawler visits are not visible to this plugin. The settings page tells you when it detects a page cache. Use the Citlyze Cloudflare Worker, or upload your server logs in Citlyze, for sites where most traffic is served from a cache or the edge.<\/p><\/dd>\n<dt id=\"what%20can%20the%20plugin%20not%20see%3F\"><h3>What can the plugin not see?<\/h3><\/dt>\n<dd><p>Anything that never reaches WordPress: redirects done by your web server or CDN (for example rules in .htaccess or nginx, or a host-level redirect to https or www), requests a firewall blocks before WordPress loads, and pages served from a full-page cache. The Citlyze Cloudflare Worker or a log upload covers those.<\/p><\/dd>\n<dt id=\"my%20site%20is%20behind%20a%20proxy%20or%20load%20balancer.%20does%20verification%20still%20work%3F\"><h3>My site is behind a proxy or load balancer. Does verification still work?<\/h3><\/dt>\n<dd><p>Citlyze confirms a crawler by its IP address, so the plugin needs the real visitor address. Behind Cloudflare this works automatically: the plugin trusts Cloudflare's visitor header only for requests that come from Cloudflare's own network. Behind another proxy, choose the header it sets and list its addresses under Settings &gt; AI Crawler Tracker &gt; Visitor IP behind a proxy.<\/p><\/dd>\n<dt id=\"which%20crawlers%20are%20counted%3F\"><h3>Which crawlers are counted?<\/h3><\/dt>\n<dd><p>The plugin recognises crawlers that issue live page requests, including GPTBot, ChatGPT-User, OAI-SearchBot, ClaudeBot, PerplexityBot, Googlebot, Google Gemini Notebook, Google-Agent, Atlassian Rovo, Amazonbot, Applebot, Bingbot, Meta crawlers, and others. The list is updated with each release.<\/p>\n\n<p>Citlyze independently confirms that a request genuinely came from the crawler it claims to be before counting it as verified. A user-agent string on its own is only a claim, so unconfirmed requests are reported separately as diagnostics and never inflate verified crawler totals.<\/p><\/dd>\n<dt id=\"does%20this%20help%20with%20ai%20seo%2C%20geo%2C%20or%20aeo%3F\"><h3>Does this help with AI SEO, GEO, or AEO?<\/h3><\/dt>\n<dd><p>Tracking is the measurement side of generative engine optimization. The plugin shows whether AI crawlers actually reach your pages and whether AI answer engines send you visitors, so you can tell if your optimization work is having an effect. It does not modify your content or your robots.txt.<\/p><\/dd>\n<dt id=\"where%20does%20the%20data%20go%3F\"><h3>Where does the data go?<\/h3><\/dt>\n<dd><p>Events go to the Citlyze endpoint configured in Settings. See the External services section for the exact fields, timing, retention summary, and policy links.<\/p><\/dd>\n<dt id=\"how%20is%20the%20signing%20secret%20stored%3F\"><h3>How is the signing secret stored?<\/h3><\/dt>\n<dd><p>The secret you paste is never stored. It is reduced to a derived signing key immediately, and that key is encrypted using your site's own WordPress salts before it is written to the database. The field is write-only: once saved, the value cannot be read back through the admin screen.<\/p>\n\n<p>You can avoid database storage entirely by defining CITLYZE_CRAWLER_SIGNING_KEY in wp-config.php instead.<\/p>\n\n<p>If a database backup leaks, rotate the site key in Citlyze under AI Crawlers &gt; Install tracking. Rotation invalidates the old key immediately.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.3.0<\/h4>\n\n<ul>\n<li>Reports the exact HTTP status code (301, 302, 404, 410, 500 and others) instead of only 404.<\/li>\n<li>Counts requests that are redirected before WordPress renders a page, such as redirects from the Redirection plugin, canonical redirects, and REST API requests, and records where each redirect pointed.<\/li>\n<li>Delivery is now queued in the site database and sent in signed batches after the response is finished, with retries, so a short outage no longer loses events and crawlers never wait for it.<\/li>\n<li>Recognises the real visitor IP behind Cloudflare automatically, and behind other proxies through a new trusted-proxy setting, so crawlers can be verified.<\/li>\n<li>Downloads Citlyze's signed list of known crawlers daily, so new crawlers are recognised without waiting for a plugin release.<\/li>\n<li>Detects full-page caches and explains what the plugin cannot see.<\/li>\n<li>Requires the Citlyze beacon format introduced with this release.<\/li>\n<\/ul>\n\n<h4>2.2.0<\/h4>\n\n<ul>\n<li>Hits reported by the plugin are now labeled with their own source in the Citlyze dashboard, so plugin-collected traffic can be told apart from other collectors.<\/li>\n<\/ul>\n\n<h4>2.1.0<\/h4>\n\n<ul>\n<li>Expanded the AI answer-engine referrer list (Copilot, Duck.ai, Poe, Phind, HuggingChat and more).<\/li>\n<li>AI referrals are now also detected from utm_source values that AI engines append when no referrer is sent (for example ChatGPT's utm_source=chatgpt.com).<\/li>\n<li>Reports the matched utm_source with referral events for stripped-referrer attribution.<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Renamed the plugin to AI Crawler Tracker by Citlyze.<\/li>\n<li>Added encrypted, write-only signing-secret storage and wp-config overrides.<\/li>\n<li>Enforced HTTPS endpoints and improved request-input sanitization.<\/li>\n<li>Added a signed, no-count connection test.<\/li>\n<li>Added privacy disclosures, translatable admin text, and cleanup on uninstall.<\/li>\n<li>Moved delivery to a stricter, signed request format.<\/li>\n<li>Added bounded Web Bot Auth signature metadata forwarding.<\/li>\n<li>Expanded crawler coverage while separating unconfirmed claims from verified totals.<\/li>\n<\/ul>","raw_excerpt":"Track GPTBot, ClaudeBot, PerplexityBot and other verified AI crawlers, plus referrals from ChatGPT, Perplexity and other AI answer engines.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ja.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/350870","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ja.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ja.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ja.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=350870"}],"author":[{"embeddable":true,"href":"https:\/\/ja.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/citlyze"}],"wp:attachment":[{"href":"https:\/\/ja.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=350870"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ja.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=350870"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ja.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=350870"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ja.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=350870"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ja.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=350870"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ja.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=350870"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}