LLM SEO Optimization Techniques: (including llms.txt)

Table of Contents

  1. How to Make Your Content Visible in the Age of AI Search
  2. What Are LLMs and Why Should You Care?
  3. The New Way of Searching
  4. SEO vs. GEO vs. AEO vs. LLMO: Are We Just Rebranding SEO?
  5. Key LLM SEO Optimization Techniques
  6. Bonus Strategies for LLM Optimization
  7. The Role of llms.txt: Giving AI Search All the Right Signals
  8. LLM Optimization vs. Traditional SEO
  9. Common Mistakes to Avoid
  10. Tools and Resources to Get Started
  11. Conclusion

How to make your content visible in the age of AI search 

So, what exactly is LLM Optimization? Well, the answer to that question depends on who you ask. For example, if you ask a machine learning engineer, they’ll tell you it’s all about tweaking prompts and token limits to get better performance from a large language model. In fact, Iguazio actually defines LLM optimization as improving the way models respond, which means smarter, faster, and with more contextual recognition.    

If, on the other hand, you are a content strategist or SEO enthusiast, LLM optimization will mean something completely different to you and that is making sure that your content shows up in AI-generated search results. And, that needs to be true no matter whether you’re talking to ChatGPT, searching with Perplexity, or scanning Google’s new AI Mode for answers. Some call this ChatGPT SEO or Generative Engine Optimization. 

So, if you fall into the latter of those two groups, ie: the people who want their content and product pages to be seen and clicked, then this article is for you. And, if you’d like to read on, we’ll show you why LLM optimization in an AI-search landscape isn’t some sort of luxury option; it’s an absolute necessity. 

What are LLMs and why should you care? 

AI engineers train Large Language models on huge amounts of text and data to generate answers, summaries, code, and human-like language. They’ve read everything (not just the Classics) and that includes blogs, news articles and your website.   

The reason that’s important is that LLMs don’t crawl your website in real time like Search Engines do. What they do is read it, learn from it and when someone asks them a question, they try to recall what they saw and rephrase it into an answer. If your site shows up as the answer, “Great” but if not, you’ve got a visibility problem. 

The new way of searching 

Search is not just about Google anymore. Also, it’s not as if just one other thing has come to dominate which means we’re left with a rather messy mix of Perplexity answers, Chat GPT chats, Gemini summaries and voice assistants reading out answers while we try to do two tasks at once. 

In short, people aren’t just searching, they’re conversing and if your content can’t hold its own in this environment then you’re missing out on visibility, traffic, and the ability to build trust.  We’ll walk you through exactly how to fix that.   

Read more: How to optimize content for AI LLM comprehension using Yoast’s tools 

SEO vs. GEO vs. AEO vs. LLMO: Are we just rebranding SEO? 

If you’ve been wondering whether you now need four different strategies for SEO (Search Engine Optimization), GEO (Generative Engine Optimization), AEO (Answer Engine Optimization), and LLMO (Large Language Model Optimization), relax, it’s not as big a deal as you might think. You see, despite all the buzzwords, the core of optimization hasn’t changed much. 

All four terms point to the same central goal: making your content more findable, quotable, and credible in machine-generated output regardless of whether that comes from Google’s AI Overviews, ChatGPT, or an answer box on Bing. 

So, should you overhaul your entire content strategy to ‘do LLMO’? 

Not really. At least, not yet. 

Most of what boosts your presence in LLMs is already what SEO professionals have been doing for years. Structured content, semantic clarity, topical authority, entity association, clean internal linking, it’s all classic SEO.  

Where they slightly diverge: 

SEO (Search Engine Optimization)  Relies on backlinks and site architecture to establish authority 
GEO (Generative Engine Optimization  Puts extra emphasis on unlinked brand mentions and semantic association 
AEO (Answer Engine Optimization)  Focuses on being the single best, most concise, and sourceable response to a specific query 
LLMO (Large Language Model Optimization)  Leans into optimizing content not just for people or search crawlers but for LLMs reading in chunks, skipping JavaScript, and relying on embeddings and grounding datasets  

But the thing is: you don’t need four different playbooks. All you need is one solid SEO foundation. In fact, this point is backed up by Google’s Gary Illyes who confirmed that AI Search does not require specialized optimization, saying that “AI SEO” is not necessary and that standard SEO is all that is needed for both AI Overviews and AI Mode. 

  • Focus more on entity mentions, not just links 
  • Treat your core site pages (home, pricing, about) and PDFs as important LLM fuel.
  • Remember that AI crawlers don’t render JavaScript, so client-side content might be invisible   
  • Think about how LLMs process structure (chunking, context, citations), not just how humans skim it 

So, if you’ve already been investing in foundational SEO, you’re already doing most of what GEO, AEO, and LLMO ae all about. That’s why not every new acronym needs you to have a whole rethink on your efforts. Sometimes, it’s just like SEO. 

Key LLM SEO optimization techniques 

Now that we know LLMs aren’t crawling our site but are understanding it, we need to think a little differently about how we create and construct content and for more on this, you may find this article extremely insightful. This is not about cramming in keywords or trying to play the algorithm, it’s about clarity, structure and credibility because these are the things LLMs care about when deciding what to quote, summarize or ignore. Below are some techniques that will help your content stay visible now that people are using generative search.   

The bar has been raised on the quality of content  

LLMs love clarity. The more natural and specific your language is, the easier it is for them to understand and reuse your content. That means not using jargon, avoiding ambiguity and instead, focusing on writing like you’re explaining something to a colleague. 

To give an exact example: 

Don’t Say: 

“Our innovative tool revolutionizes the digital landscape for modern businesses.” 

Instead Say: 

“The Yoast SEO plugin for WordPress helps businesses to improve their website’s visibility and appear inn search results 

Use Structure, Chunked Formatting

Chunked formatting means breaking your content into small pieces (chunks) of informatin that are easy to understand and remember. LLMs tend to prioritize the most easily digestible content construction – which means your headings, bullet points, and clearly defined sections must do a lot of heavy lifting. Not only does organizing your content like this help people to skim read, but it also helps machines understand what each section is about.  

Structuring your content like this will help: 

  • Write clear, descriptive H2s and 3s 
  • Use bullet points that can provide standalone value 
  • Include summaries and tables to give quick overviews 

Be Factual, Transparent, and Authoritative 

Just like Google, LLMs need to trust that your content is reliable before they start taking you seriously. This means you need to show your working out, quote sources, reveal authors, and follow the principles of E-E-A-T. Experience, Expertise, Authority, and Trust. 

Follow these E-E-A-T principles 

To do this: 

  • Include an author bio and credentials if possible (include a link to actual author bios and social profiles) 
  • Name your sources when you use claims or statistics 
  • Share real experiences if possible “As a small business owner…” 

The more real, relatable and trustworthy your content looks, the more AI will like it.  

Optimize for Summarization 

LLMs won’t quote your entire blog post; they’ll only use snippets. Your job is to make those snippets irresistible. Start with strong lead sentences so that each paragraph begins with a clear point followed by context. Also, it’s a good idea to front-load your content. Don’t save your best bits for the end.  

As a reminder: 

  • Start each section with what you want the key takeaway to be 
  • Keep paragraphs short and self-contained 
  • Create standalone summary paragraphs as these often get quoted in AI generated answers 

Use Schema 

Behind every great summary is a structured content model. That’s where Schema markup comes in and to help the AI understand your content, you need to speak in a certain way.   

Read more about schema markup 

To make things clear, use: 

  • Article for blog content 
  • FAQPage for questions and answers 
  • HowTo for instructions 
  • Author and Person for writer’s bio
  • WebPage for generic content 

Bonus strategies for LLM optimization

Once you’ve got the basics completed, like clear writing, structure and trust signals, there’s still more you can do to give your content the best shot at visibility. These bonus strategies focus on how to make your site even more AI-friendly by anticipating how LLMs interpret and reuse information. 

Use Explicit Context and Clear language 

Humans have an incredible ability to be able to ‘fill in the blanks’ and still ‘get the message’ even if the information they got was vague or unclear. One of the biggest differences between humans and LLMs? Humans can infer meaning from vague references. LLMs on the other hand… well, let’s just say that it doesn’t come naturally to them. 

In any case, the point is that if your article mentions “this tool” or “our product” without any context, an LLM might miss the connection entirely. The result? You’re left out of the answer, even if you’re the best source. 

So, to give your content the clarity it deserves: 

  • Use the full product or brand name, like “Yoast SEO plugin for WordPress,” not just “Yoast” 
  • Define technical or niche terms before using them 
  • Avoid vague language (“this page,” “the above section,” “click here”) 

You don’t need to be repetitive, but you do need to be explicit rather than implicit.  

Leverage FAQs and Conversational Formats 

LLMs love FAQs because they’re direct, predictable, and easy to quote. They closely match real user intent and provide high-value snippets that tools like Perplexity and Gemini can pull from without much guesswork. 

How to use the FAQ block in WordPress 

That said, there’s an important limitation to keep in mind if you’re using the Yoast SEO FAQ block in Gutenberg

You cannot use H2 or H3 heading tags inside the FAQ block. 
The block creates its own question-answer formatting using custom HTML, which is great for structured data (FAQ Page schema), but it doesn’t support native heading tags which limits your ability to optimize AI readability and skimmability. 

So, if your goal is to appear in AI-generated summaries or answer boxes, where headings like “What is LLM SEO?” make it easy for AI to quote your content, you might be better off using manual formatting

Here’s how to get the best of both worlds: 

  • STEP 1: Use H2 or H3 tags for each question (e.g., “What is llms.txt?”) and write a clear, short answer beneath it. This improves LLM visibility but doesn’t generate structured FAQ schema. 
  • Step 2: Use the Yoast FAQ block for schema support but know that it won’t give you a proper heading structure. 

 Ultimately, the more your FAQs resemble natural, searchable questions — and are structured in a way that both humans and AI can easily parse — the more likely they are to be featured in answers. 

Enhance Trust with Freshness Signals  

Just like search engines, some LLMs give preference to newer content, but remember that we need to talk to them in a certain way to get the best out of them. 

Older content can be overlooked. Worse, it can be quoted incorrectly if something has changed since you last hit publish. 

Make sure your pages include: 

  • A clear “last updated” timestamp (can we get a picture of what one would look like for clarification?) 
  • Regular reviews for accuracy 
  • Changelogs or update notes if applicable (especially for software or plugin content) 

It doesn’t have to be complicated, even a simple “Last updated: June 2025” can help both readers and AI systems trust that your content is current.  

How to keep content fresh 

Prioritize Author Visibility and Credibility 

Today, we’re entering a phase where who wrote your content is just as important as what it says. That means you need to highlight author visibility and put effort into signaling real-world experience. 

Here’s how: 

  • Include author bios in WordPress with credentials and links to their professional profiles 
  • Use Person schema to formally associate the content with a specific individual 
  • Weave in relevant experience (“As an SEO consultant who works with SaaS brands…”) 

Remember, LLMs are more likely to trust, quote, and amplify expert-authored content. 

Use Internal Linking Strategically 

Think of internal linking as your site’s nervous system. It helps both humans and LLMs understand what’s important, how topics relate, and where to go next. 

But internal linking isn’t just about SEO hygiene anymore — it’s also a way to establish topic authority and help LLMs build a map of your expertise. 

Do: 

  • Cluster related articles together (e.g., link from “LLM Optimization” to “Schema Markup for SEO”) 
  • Use descriptive anchor text like “read our full guide to Schema markup,” not just “click here” 
  • Ensure every piece of content supports a broader narrative 

Our internal linking feature is available for free with a Yoast SEO Premium plugin. 

The role of llms.txt. Giving AI search all the right signals 

Now let’s talk about one of the most recent developments in LLM visibility; a little file called llms.txt

Think of it as a sibling to robots.txt, but instead of guiding search engines, it tells AI tools how they’re allowed to interact with your content. Note: llms.txt is still an evolving standard, and support across AI tools may vary, but it’s a smart step toward asserting control 

With llms.txt, you can: 

  • Define how your content may be reused or summarized 
  • Set clear expectations around attribution, licensing 

It’s not just about protection, it’s about being proactive as AI usage accelerates. 

Even better: Yoast now offers llms.txt integration right inside the plugin, so you don’t need to mess around with code or server settings. If you want to future-proof your site’s visibility (and your IP), this is where you start. 

The llms.txt feature is available for both free and premium customers.   

LLM Optimization vs Traditional SEO: 

LLM Optimization and SEO are part of the same family, but they serve different functions and require slightly different thinking. 

Let’s compare: 

Traditional SEO  LLM Optimization 
Crawled and ranked by bots  Read, remembered, and reused by AIs 
Emphasizes keywords  Emphasizes context and clarity 
   
Optimizes for SERPs  Optimizes for AI-generated summaries and answers 

The takeaway? You can’t ignore either. One brings traffic; the other boosts brand visibility within AI responses. 

And considering that 42% of users now start their research with an LLM (not Google), you’ll want to be found in both places. 

Common Mistakes to Avoid 

Even well-meaning content creators fall into holes. So, take a look at the tips below to avoid any mishaps that could damage your LLM visibility: 

  • Writing like a robot or allowing a robot to write for you (ironically, not appreciated by robots) 
  • Leaving your content undated and unchanged for years 
  • Publishing posts without any author information or editorial standards 
  • Ignoring internal links or leaving orphaned pages 
  • Using vague headings or anchor text like “read more” or “this article” 

If your content looks generic, outdated, or anonymous, it won’t earn any trust. And, without trust, it won’t get quoted. 

 Tools and Resources to Get Started 

Search used to be about visibility within SERPs. But now, it’s also about being seen in summaries, answers, snippets, and chats. LLMs aren’t just shaping the future of search; they’re shaping how your brand is perceived to both humans and robots alike. 

To stand out: 

  • Write with clarity and context 
  • Structure for humans and machines 
  • Cite your expertise and show your authors 
  • Use tools like Yoast and llms.txt to signal your intent 

Future-proof your visibility with Yoast SEO. From llms.txt integration to schema support, Yoast gives you all the tools you need to speak AI’s language and dominate both generative answers and search engines. Get started with Yoast SEO Premium now and make it easy for AI to say something accurate, useful, and… ideally, about you. 

2025 Core Web Vitals Challenge: WordPress Versus Everyone via @sejournal, @martinibuster

The Core Web Vitals Technology Report shows the top-ranked content management systems by Core Web Vitals (CWV) for the month of June (July’s statistics aren’t out yet). The breakout star this year is an e-commerce platform, which is notable because shopping sites generally have poor performance due to the heavy JavaScript and image loads necessary to provide shopping features.

This comparison also looks at the Interaction to Next Paint (INP) scores because they don’t mirror the CWV scores. INP measures how quickly a website responds visually after a user interacts with it. The phrase “next paint” refers to the moment the browser visually updates the page in response to a user’s interaction.

A poor INP score can mean that users will be frustrated with the site because it’s perceived as unresponsive. A good INP score correlates with a better user experience because of how quickly the website performs.

Core Web Vitals Technology Report

The HTTP Archive Technology Report combines two public datasets:

  1. Chrome UX Report (CrUX)
  2. HTTP Archive

1. Chrome UX Report (CrUX)
CrUX obtains its data from Chrome users who opt into providing usage statistics reporting as they browse over 8 million websites. This data includes performance on Core Web Vitals metrics and is aggregated into monthly datasets.

2. HTTP Archive
HTTP Archive obtains its data from lab tests by tools like WebPageTest and Lighthouse that analyze how pages are built and whether they follow performance best practices. Together, these datasets show how websites perform and what technologies they use.

The CWV Technology Report combines data from HTTP Archive (which tracks websites through lab-based crawling and testing) and CrUX (which collects real-user performance data from Chrome users), and that’s where the Core Web Vitals performance data of content management systems comes from.

#1 Ranked Core Web Vitals (CWV) Performer

The top-performing content management system is Duda. A remarkable 83.63% of websites on the Duda platform received a good CWV score. Duda has consistently ranked #1, and this month continues that trend.

For Interaction to Next Paint scores, Duda ranks in the second position.

#2 Ranked CWV CMS: Shopify

The next position is occupied by Shopify. 75.22% of Shopify websites received a good CWV score.

This is extraordinary because shopping sites are typically burdened with excessive JavaScript to power features like product filters, sliders, image effects, and other tools that shoppers rely on to make their choices. Shopify, however, appears to have largely solved those issues and is outperforming other platforms, like Wix and WordPress.

In terms of INP, Shopify is ranked #3, at the upper end of the rankings.

#3 Ranked CMS For CWV: Wix

Wix comes in third place, just behind Shopify. 70.76% of Wix websites received a good CWV score. In terms of INP scores, 86.82% of Wix sites received a good INP score. That puts them in fourth place for INP.

#4 Ranked CMS: Squarespace

67.66% of Squarespace sites had a good CWV score, putting them in fourth place for CWV, just a few percentage points behind the No. 3 ranked Wix.

That said, Squarespace ranks No. 1 for INP, with a total of 95.85% of Squarespace sites achieving a good INP score. That’s a big deal because INP is a strong indicator of a good user experience.

#5 Ranked CMS: Drupal

59.07% of sites on the Drupal platform had a good CWV score. That’s more than half of sites, considerably lower than Duda’s 83.63% score but higher than WordPress’s score.

But when it comes to the INP score, Drupal ranks last, with only 85.5% of sites scoring a good INP score.

#6 Ranked CMS: WordPress

Only 43.44% of WordPress sites had a good CWV score. That’s over fifteen percentage points lower than fifth-ranked Drupal. So WordPress isn’t just last in terms of CWV performance; it’s last by a wide margin.

WordPress performance hasn’t been getting better this year either. It started 2025 at 42.58%, then went up a few points in April to 44.93%, then fell back to 43.44%, finishing June at less than one percentage point higher than where it started the year.

WordPress is in fifth place for INP scores, with 85.89% of WordPress sites achieving a good INP score, just 0.39 points above Drupal, which is in last place.

But that’s not the whole story about the WordPress INP scores. WordPress started the year with a score of 86.05% and ended June with a slightly lower score.

INP Rankings By CMS

Here are the rankings for INP, with the percentage of sites exhibiting a good INP score next to the CMS name:

  1. Squarespace 95.85%
  2. Duda 93.35%
  3. Shopify 89.07%
  4. Wix 86.82%
  5. WordPress 85.89%
  6. Drupal 85.5%

As you can see, positions 3–6 are all bunched together in the eighty percent range, with only a 3.57 percentage point difference between the last-placed Drupal and the third-ranked Shopify. So, clearly, all the content management systems deserve a trophy for INP scores. Those are decent scores, especially for Shopify, which earned a second-place ranking for CWV and third place for INP.

Takeaways

  • Duda Is #1
    Duda leads in Core Web Vitals (CWV) performance, with 83.63% of sites scoring well, maintaining its top position.
  • Shopify Is A Strong Performer
    Shopify ranks #2 for CWV, a surprising performance given the complexity of e-commerce platforms, and scores well for INP.
  • Squarespace #1 For User Experience
    Squarespace ranks #1 for INP, with 95.85% of its sites showing good responsiveness, indicating an excellent user experience.
  • WordPress Performance Scores Are Stagnant
    WordPress lags far behind, with only 43.44% of sites passing CWV and no signs of positive momentum.
  • Drupal Also Lags
    Drupal ranks last in INP and fifth in CWV, with over half its sites passing but still underperforming against most competitors.
  • INP Scores Are Generally High Across All CMSs
    Overall INP scores are close among the bottom four platforms, suggesting that INP scores are relatively high across all content management systems.

Find the Looker Studio rankings for here (must be logged into a Google account to view).

Featured Image by Shutterstock/Krakenimages.com

WooCommerce Customer Review Plugin Vulnerability Affects 80,000+ Sites via @sejournal, @martinibuster

An advisory was issued about a vulnerability in the Customer Reviews for WooCommerce plugin, which is installed on over 80,000 websites. The plugin enables unauthenticated attackers to launch a stored cross-site scripting attack.

Customer Reviews for WooCommerce Vulnerability

The Customer Reviews for WooCommerce plugin enables users to send customers an email reminder to leave a review and also offers other features designed to increase customer engagement with a brand.

Wordfence issued an advisory about a flaw in the plugin that makes it possible for attackers to inject scripts into web pages that execute whenever a user visits the affected page.

The exploit is due to a failure to “sanitize” inputs and “escape” outputs. Sanitizing inputs in this context is a basic WordPress security measure that checks if uploaded data conforms to expected types and removes dangerous content like scripts. Output escaping is another security measure that ensures any special characters produced by the plugin aren’t executable.

According to the official Wordfence advisory:

“The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’ parameter in all versions up to, and including, 5.80.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.”

Users of the plugin are advised to update to version 5.81.0 or newer version.

Featured Image by Shutterstock/Brilliant Eye

WordPress AI Engine Plugin Vulnerability Affects Up To 100,000 Websites via @sejournal, @martinibuster

A security advisory was issued for the AI Engine WordPress plugin, installed on over 100,000 websites, the fourth one this month. Rated 8.8, this vulnerability enables attackers with only subscriber-level authentication to upload malicious files when the REST API is enabled.

AI Engine Plugin: Fifth Vulnerability In 2025

This is the fourth vulnerability discovered in the AI Engine plugin in July, following the first one of the year discovered in June, making a total of five vulnerabilities discovered in the plugin so far in 2025. There were nine vulnerabilities discovered in 2024, one of which was rated 9.8 because it enabled unauthenticated attackers to upload malicious files, plus another rated 9.1 that also enabled arbitrary uploads.

Authenticated (Subscriber+) Arbitrary File Upload

The latest vulnerability enables authenticated file uploads. What makes this exploit more dangerous is that it requires only subscriber-level authentication for an attacker to take advantage of the security weakness. That isn’t as bad as a vulnerability that doesn’t require authentication, but it’s still rated 8.8 on a scale of 1 to 10.

Wordfence describes the vulnerability as being due to missing file type validation in a function related to the REST API in versions 2.9.3 and 2.9.4.

File type validation is a security measure typically used within WordPress to make sure that the content of a file matches the type of file being uploaded to the website.

According to Wordfence:

“This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site’s server when the REST API is enabled, which may make remote code execution possible.”

Users of the AI Engine plugin are recommended updating their plugin to the latest version, 2.9.5, or a newer version.

The plugin changelog for version 2.9.5 shares what was updated:

“Fix: Resolved a security issue related to SSRF by validating URL schemes in audio transcription and sanitizing REST API parameters to prevent API key misuse.

Fix: Corrected a critical security vulnerability that allowed unauthorized file uploads by adding strict file type validation to prevent PHP execution.”

Featured Image by Shutterstock/Jiri Hera

Why Is SureRank WordPress SEO Plugin So Popular? via @sejournal, @martinibuster

A new SEO plugin called SureRank, by Brainstorm Force, makers of the popular Astra theme, is rapidly growing in popularity. In beta for a few months, it was announced in July and has amassed over twenty thousand installations. That’s a pretty good start for an SEO plugin that has only been out of beta for a few weeks.

One possible reason that SureRank is quickly becoming popular is that it’s created by a trusted brand, much loved for its Astra WordPress theme.

SureRank By Brainstorm Force

SureRank is the creation of the publishers of many highly popular plugins and themes installed in many millions of websites, such as Astra theme, Ultimate Addons for Elementor, Spectra Gutenberg Blocks – Website Builder for the Block Editor, and Starter Templates – AI-Powered Templates for Elementor & Gutenberg, to name a few.

Why Another SEO Plugin?

The goal of SureRank is to provide an easy-to-use SEO solution that includes only the necessary features every site needs in order to avoid feature bloat. It positions itself as an SEO assistant that guides the user with an intuitive user interface.

What Does SureRank Do?

SureRank has an onboarding process that walks a user through the initial optimizations and setup. It then performs an analysis and offers suggestions for site-level improvements.

It currently enables users to handle the basics like:

  • Edit titles and meta descriptions
  • Custom write social media titles, descriptions, and featured images,
  • Tweak home page and, archive page meta data
  • Meta robot directives, canonicals, and sitemaps
  • Schema structured data
  • Site and page level SEO analysis
  • Automatic image alt text generation
  • Google Search Console integration
  • WooCommerce integration

SureRank also provides a built-in tool for migrating settings from other popular SEO plugins like Rank Math, Yoast, and AIOSEO.

Check out the SureRank SEO plugin at the official WordPress.org repository:

SureRank – SEO Assistant with Meta Tags, Social Preview, XML Sitemap, and Schema

Featured Image by Shutterstock/Roman Samborskyi

WP Engine’s AI Toolkit Vectorizes WordPress Sites For Smart Search via @sejournal, @martinibuster

WP Engine announced the release of its AI Toolkit, a way to easily integrate advanced AI search and product recommendations into WordPress websites, plus a Managed Vector Database that enables developers to easily integrate AI features directly into websites.

Smart Search AI

WP Engine’s AI Toolkit helps WordPress site owners improve search and content visibility without requiring a steep technical learning curve. Smart Search AI is easily enabled in just a few clicks. Once activated, it syncs with WordPress content, including:

  • Posts
  • Pages
  • Tags
  • Metadata
  • Custom fields

Smart Search AI converts a website’s content into a vector format to deliver faster, more useful search results. The system combines natural-language and keyword search to help contextualize queries and guide visitors to what they need, which may help reduce bounce rates and support higher conversions.

AI-Powered Recommendations

The AI-powered recommendations feature uses past and current user session data to suggest products or content that is relevant to the user. This helps increase shopping sales and keeps readers engaged with content. The system runs efficiently without slowing down the website and uses flat-rate pricing with no overage fees. It’s suited for eCommerce, media, and any site focused on driving sales and engagement through personalized experiences.

Managed Vector Database

WP Engine’s Managed Vector Database is a service that simplifies building AI features directly into WordPress websites. Designed for developers, agencies, and site owners, it removes the need to manage tasks like data extraction, embedding creation, and content updates. Developers can start building content-based AI apps and functionalities immediately, because the system automatically processes and trains on their WordPress content without additional setup.

Integrated with WordPress, the database keeps AI outputs aligned with current site content without extra work. It enables developers to connect WordPress data directly to chatbot frameworks or APIs, and it also makes AI features accessible to non-technical creators or site owners. This enables creators to focus on building meaningful experiences without getting bogged down in technical setup.

Read more about WP Engine’s AI Toolkit:

WP Engine Launches AI Toolkit Empowering Website Owners to Drive Engagement and Growth

Featured Image by Shutterstock/Ground Picture

WordPress Malware Scanner Plugin Contains Vulnerability via @sejournal, @martinibuster

Wordfence published an advisory on the WordPress Malcure Malware Scanner plugin, which was discovered to have a vulnerability rated at a severity level of 8.1. At the time of publishing, there is no patch to fix the problem.

Screenshot Showing 8.1 Severity Rating

Malcure Malware Scanner Vulnerability

The Malcure Malware Scanner plugin, installed on over 10,000 WordPress websites, is vulnerable to “Arbitrary File Deletion due to a missing capability check on the wpmr_delete_file() function” by authenticated attackers. The fact that an attacker needs authentication as a user makes it a little less likely for it to be exploited, however not by much because it only requires subscriber level authentication, which is the lowest level of authentication. The “subscriber” role is the default level of registration on a WordPress website (if registration is allowed).

According to Wordfence:

“This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files making remote code execution possible. This is only exploitable when advanced mode is enabled on the site.”

There is no known patch available for the plugin and users are cautioned to take necessary actions such as uninstalling the plugin to mitigate risk.

The plugin is currently unavailable for download with a notice showing that it is under review.

Screenshot Of Malcure Plugin At WordPress Repository

Read More WordPress News

WordPress Update 6.8.2 – Ends Security Support For 0.9% of Sites

Featured Image by Shutterstock/Kues

WordPress Update 6.8.2 – Ends Security Support For 0.9% of Sites via @sejournal, @martinibuster

WordPress released a maintenance update that contains twenty changes to the core and fixes fifteen issues in the Gutenberg block editor. WordPress also announced that it is dropping security support for WordPress versions 4.1 to 4.6.

Short-Cycle Maintenance Release

This is a maintenance release that incrementally makes WordPress a smoother experience.

Some of the fixes that are representative of what’s in this release:

Dropping Security Support

WordPress announced that it is dropping support for versions 4.1 through 4.6. According to the official WordPress stats, only 0.9% of websites are using those versions of WordPress.

Statement on release page:

“Dropping security updates for WordPress versions 4.1 through 4.6
This is not directly related to the 6.8.2 maintenance release, but branches 4.1 to 4.6 had their final release today. These branches won’t receive any security update anymore.”

Another WordPress page provides more information:

“As of July 2025, the WordPress Security Team will no longer provide security updates for WordPress versions 4.1 through 4.6.

These versions were first released nine or more years ago and over 99% of WordPress installations run a more recent version. The chances this will affect your site, or sites, is very small.”

Read the official WordPress 6.8.2 announcement:

WordPress 6.8.2 Maintenance Release

Read More WordPress News

Malware Discovered In Gravity Forms WordPress Plugin

Featured Image by Shutterstock/Praew stock

Malware Discovered In Gravity Forms WordPress Plugin via @sejournal, @martinibuster

WordPress security company Patchstack published an advisory about a serious vulnerability in Gravity Forms caused by a supply chain attack. Gravity Forms responded immediately and released an update to fix the issue.

Supply Chain Attack

Patchstack has been monitoring an attack on a WordPress plugin in which the attackers uploaded an infected version of the plugin directly to the publisher’s repository and fetched other files from a domain name similar to the official domain. This, in turn, led to a serious compromise of websites that used that plugin.

A similar attack was observed in Gravity Forms and was immediately addressed by the publisher. Malicious code had been injected into Gravity Forms (specifically in gravityforms/common.php) by the attackers. The code caused the plugin, when installed, to make HTTP POST requests to the rogue domain gravityapi.org, which was registered just days before the attack and controlled by the attacker.

The compromised plugin sent detailed site and server information to the attacker’s server and enabled remote code execution on the infected sites. In the context of a WordPress plugin, a remote code execution (RCE) vulnerability occurs when an attacker can run malicious code on a targeted website from a remote location.

Patchstack explained the extent of the vulnerability:

“…it can perform multiple processes:

  • Upload an arbitrary file to the server.
  • List all of the user accounts on the WordPress site (ID, username, email, display name).
  • Delete any user accounts on the WordPress site.
  • Perform arbitrary file and directory listings on the WordPress server.”

That last one means that the attacker can view any file, regardless of permissions, which would include the wp-config.php file which contains database credentials.

Gravity Forms Responds

RocketGenius, the publishers of Gravity Forms, took immediate action and uploaded a fixed version of the plugin right away, on the very same day. The domain name registrar, Namecheap, suspended the rogue typosquatted domain which effectively blocked any compromised websites from contacting the attackers.

Gravity Forms has released an update to the plugin, version 2.9.13. Users may want to consider updating to the very latest version.

Read more at Patchstack:

Malware Found in Official Gravity Forms Plugin Indicating Supply Chain Breach

Featured Image by Shutterstock/Warm_Tail

Payment Processor Startup Finix Announces WooCommerce Plugin via @sejournal, @martinibuster

Finix, a payment processing company, has launched a new WooCommerce plugin that enables WordPress merchants to integrate embedded payments directly into their stores. The new plugin enables WooCommerce merchants to accept all major credit cards, as well as Apple Pay and bank transfers. Setting up via the WooCommerce plugin is easy and is said to take only ten minutes to set up and start accepting payments.

Features available through the plugin:

  • “Flexible Payment Methods: Accept major credit and debit cards, Apple Pay, and bank transfers. Offer flexibility customers expect and reduce checkout friction.
  • Transparent Pricing: Finix uses interchange-plus pricing for clear, detailed fee breakdowns, ideal for high-volume merchants.
  • Apple Pay Integration: Enable Apple Pay on supported browsers like Safari and Chrome, with customizable button styles and types that blend seamlessly into your storefront.
  • Customizable Checkout Display: Match your brand’s voice by tailoring the look and language of each payment method for a more intuitive customer experience.
  • WooCommerce Blocks Checkout Compatible Fully supports WooCommerce’s new block-based checkout and the classic flow, keeping your store aligned with the latest updates.
  • Automated Dispute & Bank Return Handling Reduce operational overhead with automatic order status updates triggered by webhook events.”

Finix is a payment processor that was founded in San Francisco in 2015. It has received funding from major Silicon Valley venture capitalists and is regarded as a rising competitor to companies like Stripe.

Finix claims that merchants report faster payouts using its systems and that it offers a streamlined checkout flow.

Read more about the Finix announcement:

Enhance Your WooCommerce Checkout with the Power of Finix Payment Gateway

Featured Image by Shutterstock/Tapati Rinchumrus