{"id":337975,"date":"2026-07-28T18:07:18","date_gmt":"2026-07-28T18:07:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/crossmediabot\/"},"modified":"2026-07-28T18:06:42","modified_gmt":"2026-07-28T18:06:42","slug":"crossmedia-chatbot","status":"publish","type":"plugin","link":"https:\/\/arg.wordpress.org\/plugins\/crossmedia-chatbot\/","author":10535173,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"3.2.0","stable_tag":"3.2.0","tested":"7.0.2","requires":"7.0","requires_php":"8.0","requires_plugins":null,"header_name":"CrossMediaBot","header_author":"Gino Croes","header_description":"AI Business Assistant for WordPress. Answers visitor questions using your knowledge base and site content.","assets_banners_color":"2b3d48","last_updated":"2026-07-28 18:06:42","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/www.crossmedia297.com\/crossmediabot","header_author_uri":"https:\/\/crossmedia297.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":33,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"3.2.0":{"tag":"3.2.0","author":"ginoize","date":"2026-07-28 18:06:42"}},"upgrade_notice":{"3.2.0":"<p>First public release on WordPress.org.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3626341,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3626341,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3626578,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3626578,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["3.2.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3626324,"resolution":"1","location":"assets","locale":"","width":350,"height":508},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3626324,"resolution":"2","location":"assets","locale":"","width":925,"height":1209},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3626324,"resolution":"3","location":"assets","locale":"","width":851,"height":923},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3626324,"resolution":"4","location":"assets","locale":"","width":833,"height":922},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3626324,"resolution":"5","location":"assets","locale":"","width":833,"height":1205}},"screenshots":{"1":"The chat widget on the front end of the site.","2":"General settings: choosing the AI provider and preferred model, the knowledge base, and the welcome message.","3":"The Design tab: widget colours with live preview and automatic theme-colour detection.","4":"The Crawling tab: indexing site content for the bot to reference.","5":"Usage statistics: token counts per provider and model."}},"plugin_section":[],"plugin_tags":[148285,191735,2364,2369,273633],"plugin_category":[],"plugin_contributors":[273634],"plugin_business_model":[],"class_list":["post-337975","plugin","type-plugin","status-publish","hentry","plugin_tags-ai-assistant","plugin_tags-ai-chatbot","plugin_tags-chatbot","plugin_tags-customer-support","plugin_tags-faq-bot","plugin_contributors-ginoize","plugin_committers-ginoize"],"banners":{"banner":"https:\/\/ps.w.org\/crossmedia-chatbot\/assets\/banner-772x250.png?rev=3626578","banner_2x":"https:\/\/ps.w.org\/crossmedia-chatbot\/assets\/banner-1544x500.png?rev=3626578","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/crossmedia-chatbot\/assets\/icon-128x128.png?rev=3626341","icon_2x":"https:\/\/ps.w.org\/crossmedia-chatbot\/assets\/icon-256x256.png?rev=3626341","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/crossmedia-chatbot\/assets\/screenshot-1.png?rev=3626324","caption":"The chat widget on the front end of the site."},{"src":"https:\/\/ps.w.org\/crossmedia-chatbot\/assets\/screenshot-2.png?rev=3626324","caption":"General settings: choosing the AI provider and preferred model, the knowledge base, and the welcome message."},{"src":"https:\/\/ps.w.org\/crossmedia-chatbot\/assets\/screenshot-3.png?rev=3626324","caption":"The Design tab: widget colours with live preview and automatic theme-colour detection."},{"src":"https:\/\/ps.w.org\/crossmedia-chatbot\/assets\/screenshot-4.png?rev=3626324","caption":"The Crawling tab: indexing site content for the bot to reference."},{"src":"https:\/\/ps.w.org\/crossmedia-chatbot\/assets\/screenshot-5.png?rev=3626324","caption":"Usage statistics: token counts per provider and model."}],"raw_content":"<!--section=description-->\n<p>CrossMediaBot turns your knowledge base and website content into a 24\/7 AI assistant. It uses the WordPress AI Client built into WordPress 7.0, so you configure an AI provider once under Settings \u2192 Connectors and the chatbot uses it \u2014 no separate API key handling inside the plugin. You pay your chosen AI provider directly for what you use, typically a few dollars a month for a small business site.<\/p>\n\n<p>The bot only answers using content you control: text you write in the knowledge base, and pages indexed by the built-in site crawler. It does not browse the internet and will not fabricate information about your business.<\/p>\n\n<p><strong>Features<\/strong><\/p>\n\n<ul>\n<li><strong>Knowledge base<\/strong> \u2014 write a description of your business, services, prices, hours, and FAQs in plain text. The bot uses this as its primary source of truth.<\/li>\n<li><strong>Site crawler<\/strong> \u2014 crawl up to 200 pages of your WordPress site and index their content automatically. Combined with the knowledge base, the bot can answer questions about any page on your site.<\/li>\n<li><strong>Conversation memory<\/strong> \u2014 multi-turn history is sent to the AI on every message, so visitors can ask follow-up questions naturally without repeating themselves.<\/li>\n<li><strong>Welcome message<\/strong> \u2014 configure a greeting that appears as the bot's first message when the chat opens.<\/li>\n<li><strong>WhatsApp escalation<\/strong> \u2014 hand a conversation over to a human on WhatsApp, with the transcript pre-filled.<\/li>\n<li><strong>Full color theming<\/strong> \u2014 8 independently configurable colors (header background, header text, user bubble, bot bubble, send button, text, links, and background) with a live preview panel, plus automatic theme-color detection.<\/li>\n<li><strong>Testing mode<\/strong> \u2014 the chat widget is hidden from all visitors and visible only to logged-in administrators, so you can test privately before going live.<\/li>\n<li><strong>Provider and model selection<\/strong> \u2014 choose which configured AI provider and which preferred model the bot should use.<\/li>\n<li><strong>Usage statistics<\/strong> \u2014 input, output, and thinking token counts with a per-provider\/model breakdown, and the number of conversations logged. Costs are billed directly by your AI provider according to their pricing.<\/li>\n<li><strong>Security<\/strong> \u2014 per-IP rate limiting, message length caps, output sanitization, and whitelisted internal links only.<\/li>\n<\/ul>\n\n<p>Additional features are offered in a separate plugin, CrossMediaBot Pro, available from <a href=\"https:\/\/www.crossmedia297.com\/crossmediabot\">crossmedia297.com<\/a>.<\/p>\n\n<h3>Usage<\/h3>\n\n<p>The chat widget is injected automatically via <code>wp_footer<\/code> on every front-end page. No shortcode or page template change is required.<\/p>\n\n<p>On the <strong>General<\/strong> tab you can optionally select a specific AI provider and preferred model, or leave both on automatic to let WordPress choose from your configured providers.<\/p>\n\n<h3>Security<\/h3>\n\n<p>Security was a design priority throughout development.<\/p>\n\n<ul>\n<li><strong>Nonces on every form and AJAX action<\/strong> \u2014 all admin forms and AJAX handlers verify a WordPress nonce before executing. This provides CSRF protection for every privileged operation.<\/li>\n<li><strong>Capability checks<\/strong> \u2014 every AJAX handler verifies <code>current_user_can( 'manage_options' )<\/code> before running. The public chat endpoint is intentionally unauthenticated but rate-limited.<\/li>\n<li><strong>Rate limiting<\/strong> \u2014 the public chat endpoint allows a maximum of 15 requests per 60 seconds per real client IP, using a TOCTOU-safe transient lock. Shared proxy headers (<code>X-Forwarded-For<\/code>, <code>CF-Connecting-IP<\/code>) are read only when the real <code>REMOTE_ADDR<\/code> is a known private range.<\/li>\n<li><strong>Input validation and sanitisation<\/strong> \u2014 the visitor's message is capped at 500 characters and sanitised via <code>sanitize_text_field<\/code>. Conversation history is validated to a maximum of 12 turns with alternating user\/model roles, a 32 KB raw JSON cap before decoding, and each turn capped to 1,000 characters.<\/li>\n<li><strong>Model ID allowlist<\/strong> \u2014 the model name passes through a strict regex before being used in the API URL, preventing path traversal via a crafted model string.<\/li>\n<li><strong>Output escaping<\/strong> \u2014 all PHP output uses <code>esc_html()<\/code>, <code>esc_attr()<\/code>, <code>esc_url()<\/code>, or <code>wp_kses_post()<\/code>. Bot reply links are whitelisted against the indexed URL set. The chat widget renders user messages via jQuery <code>.text()<\/code>, not <code>.html()<\/code>, so user-supplied content can never inject markup.<\/li>\n<li><strong>Prompt injection mitigation<\/strong> \u2014 the knowledge base is wrapped in delimiters inside the AI <code>systemInstruction<\/code> field, making it harder for a visitor to override system behavior through message content.<\/li>\n<li><strong>Credential handling<\/strong> \u2014 the plugin does not store or transmit AI provider API keys. All provider credentials are managed by WordPress core's Connectors infrastructure, not by this plugin.<\/li>\n<li><strong>Database<\/strong> \u2014 all direct database queries use <code>$wpdb-&gt;prepare()<\/code>. All output is escaped at the point of rendering.<\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>This plugin generates chatbot replies through the WordPress AI Client that is built into WordPress 7.0. The plugin itself does not connect to any third-party API directly and does not store or transmit AI provider API keys. Instead, it hands the prompt to WordPress core, which sends it to whichever AI provider you have configured under Settings \u2192 Connectors (for example Google, Anthropic, or OpenAI). The specific external service that receives the data is therefore the provider you choose; the plugin has no built-in or default provider of its own.<\/p>\n\n<p><strong>What data is sent, and when:<\/strong> each time a visitor sends a message to the chatbot, the plugin passes the visitor's message, the recent conversation history for that session, and your configured knowledge base text (and, if site crawling is enabled, text extracted from your selected pages) to WordPress core's AI Client, which forwards it to your configured AI provider so a relevant reply can be generated. No data is sent until a visitor actually interacts with the chatbot, and no data is sent to Crossmedia297.<\/p>\n\n<p><strong>Where it goes:<\/strong> to the AI provider you configured under Settings \u2192 Connectors. That provider's own terms of service and privacy policy govern how it handles the data, so please review them before enabling the chatbot. The providers most commonly used with the WordPress AI Client are:<\/p>\n\n<ul>\n<li>Google (Gemini API) \u2014 Terms: https:\/\/ai.google.dev\/gemini-api\/terms \u2014 Privacy: https:\/\/policies.google.com\/privacy<\/li>\n<li>Anthropic (Claude) \u2014 Terms: https:\/\/www.anthropic.com\/legal\/commercial-terms \u2014 Privacy: https:\/\/www.anthropic.com\/legal\/privacy<\/li>\n<li>OpenAI \u2014 Terms: https:\/\/openai.com\/policies\/terms-of-use \u2014 Privacy: https:\/\/openai.com\/policies\/privacy-policy<\/li>\n<\/ul>\n\n<p>If you configure a provider other than these, consult that provider's own terms and privacy policy. This plugin has no default provider and sends nothing anywhere until you configure one.<\/p>\n\n<p>This plugin also makes requests to your own website (same domain) when you use the site crawler to index your pages, and, if your theme's own files do not provide enough colour information, when the \"Detect theme colors\" tool reads your homepage. These are requests to your own server, not to a third-party service.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>crossmedia-chatbot<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install the ZIP via <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong>.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> menu in WordPress.<\/li>\n<li>Go to <strong>CrossMediaBot<\/strong> in the admin sidebar.<\/li>\n<li>Set up an AI provider under <strong>Settings \u2192 Connectors<\/strong> (WordPress 7.0). Install one of the official provider plugins (Google, Anthropic, or OpenAI) and enter its credentials there. The chatbot uses whatever provider you configure.<\/li>\n<li>Fill in the <strong>Knowledge Base<\/strong> field with a description of your business \u2014 services, prices, hours, FAQs, and any other information visitors are likely to ask about.<\/li>\n<li>Optionally go to the <strong>Crawling<\/strong> tab and click <strong>Start Full Crawl<\/strong> to index up to 200 pages of your site.<\/li>\n<li>Use <strong>Testing Mode<\/strong> on the General tab to test the widget privately \u2014 it is visible only to logged-in administrators until you disable it.<\/li>\n<li>Disable Testing Mode when you are ready to go live. The chat widget appears in the bottom-right corner of every page on your site.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20to%20configure%20an%20ai%20provider%3F\"><h3>Do I need to configure an AI provider?<\/h3><\/dt>\n<dd><p>Yes. This plugin uses the WordPress AI Client, so a site administrator sets up an AI provider once under Settings \u2192 Connectors (for example Google, Anthropic, or OpenAI, each available as an official provider plugin). WordPress manages the provider credentials; the plugin never handles them. Provider free tiers typically cover testing and low-volume use, and production usage is billed by the provider directly.<\/p><\/dd>\n<dt id=\"how%20much%20does%20it%20cost%20to%20run%3F\"><h3>How much does it cost to run?<\/h3><\/dt>\n<dd><p>Costs depend on the AI provider you configure and their pricing, and are billed to you directly by that provider. The plugin's General and About tabs show token usage per provider and model so you can monitor consumption.<\/p><\/dd>\n<dt id=\"what%20does%20the%20bot%20actually%20know%3F\"><h3>What does the bot actually know?<\/h3><\/dt>\n<dd><p>Only what you put in the knowledge base and what it finds by crawling your site. The bot does not browse the internet or answer questions about topics outside your content. This means no hallucinations about your business \u2014 if you have not told it something, it will say so.<\/p><\/dd>\n<dt id=\"does%20crossmediabot%20see%20my%20conversations%3F\"><h3>Does CrossMediaBot see my conversations?<\/h3><\/dt>\n<dd><p>No. Messages are sent from your WordPress server to your configured AI provider through the WordPress AI Client. Crossmedia297 never receives your conversations, your provider credentials, your knowledge base content, or any visitor data.<\/p><\/dd>\n<dt id=\"how%20does%20the%20plugin%20connect%20to%20an%20ai%20provider%3F\"><h3>How does the plugin connect to an AI provider?<\/h3><\/dt>\n<dd><p>This plugin uses the WordPress AI Client built into WordPress 7.0. The site administrator configures an AI provider (such as Google, Anthropic, or OpenAI) once under Settings \u2192 Connectors, and WordPress manages the provider connection and API key. The plugin never stores or handles API keys itself. You can optionally choose a specific provider and preferred model on the plugin's General settings tab.<\/p><\/dd>\n<dt id=\"are%20there%20other%20versions%20of%20this%20plugin%3F\"><h3>Are there other versions of this plugin?<\/h3><\/dt>\n<dd><p>Additional features are offered in a separate plugin, CrossMediaBot Pro, available from https:\/\/www.crossmedia297.com\/crossmediabot. This plugin is complete and fully functional on its own.<\/p><\/dd>\n<dt id=\"does%20the%20widget%20work%20with%20any%20wordpress%20theme%3F\"><h3>Does the widget work with any WordPress theme?<\/h3><\/dt>\n<dd><p>Yes. The widget is injected via <code>wp_footer<\/code> and is self-contained with its own CSS. The Design tab includes a <strong>Detect Theme Colors<\/strong> button that extracts your theme's primary colors and maps them to the widget automatically.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20multisite%3F\"><h3>Does it work on multisite?<\/h3><\/dt>\n<dd><p>The plugin has not been tested on multisite networks. Single-site installs are fully supported.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>3.2.0<\/h4>\n\n<ul>\n<li>First public release on WordPress.org.<\/li>\n<\/ul>","raw_excerpt":"AI Business Assistant for WordPress. Answers visitor questions using your knowledge base and site content, powered by the AI provider of your choice.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/arg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/337975","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/arg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/arg.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/arg.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=337975"}],"author":[{"embeddable":true,"href":"https:\/\/arg.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/ginoize"}],"wp:attachment":[{"href":"https:\/\/arg.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=337975"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/arg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=337975"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/arg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=337975"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/arg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=337975"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/arg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=337975"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/arg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=337975"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}