{"id":280720,"date":"2026-03-11T08:59:55","date_gmt":"2026-03-11T08:59:55","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/eonsr-aeo-agent\/"},"modified":"2026-08-21T11:16:42","modified_gmt":"2026-08-21T11:16:42","slug":"eonsr-aeo-agent","status":"closed","type":"plugin","link":"https:\/\/km.wordpress.org\/plugins\/eonsr-aeo-agent\/","author":23434917,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"3.9.2","stable_tag":"3.9.2","tested":"7.1","requires":"6.8","requires_php":"7.4","requires_plugins":null,"header_name":"EONSR AEO Agent","header_author":"Eonsr Team","header_description":"Generate long-form SEO, AEO articles with a 2-pane UI using Google Gemini API. Integrates a highly detailed, structured prompt for superior quality.","assets_banners_color":"373549","last_updated":"2026-08-21 11:16:42","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/eonsr.com\/en\/","rating":5,"author_block_rating":0,"active_installs":0,"downloads":575,"num_ratings":3,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"3.7.9":{"tag":"3.7.9","author":"smitheonsr","date":"2026-05-05 04:21:27"},"3.9.0":{"tag":"3.9.0","author":"smitheonsr","date":"2026-08-21 10:13:33"},"3.9.1":{"tag":"3.9.1","author":"smitheonsr","date":"2026-08-21 10:16:59"},"3.9.2":{"tag":"3.9.2","author":"smitheonsr","date":"2026-08-21 11:16:42"}},"upgrade_notice":{"3.8.0":"<p>Security update. This release fixes unauthenticated stored cross-site scripting and unauthorized post-creation risks in inbound REST API processing. Update immediately.<\/p>","3.7.7":"<p>Major update with security improvements and code standardization. Please update to ensure API compatibility.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":3},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3479843,"resolution":"128x128","location":"assets","locale":"","width":534,"height":534},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3479843,"resolution":"256x256","location":"assets","locale":"","width":1067,"height":1067}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3479843,"resolution":"1544x500","location":"assets","locale":"","width":6434,"height":2084},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3479843,"resolution":"772x250","location":"assets","locale":"","width":3217,"height":1042}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["3.7.9","3.9.0","3.9.1","3.9.2"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"<strong>Main Dashboard:<\/strong> The 2-pane interface for generating and reviewing content with AI.","2":"<strong>Bulk Generator:<\/strong> Interface for uploading Excel files for mass generation.","3":"<strong>Image Results:<\/strong> AI-generated images with automatic logo and text insertion.","4":"<strong>License Activation:<\/strong> Simple activation screen for connecting to EONSR Cloud."}},"plugin_section":[],"plugin_tags":[244526,2353,13175,186,207607],"plugin_category":[55],"plugin_contributors":[257512],"plugin_business_model":[],"class_list":["post-280720","plugin","type-plugin","status-closed","hentry","plugin_tags-aeo","plugin_tags-ai","plugin_tags-content-generator","plugin_tags-seo","plugin_tags-writing-assistant","plugin_category-seo-and-marketing","plugin_contributors-smitheonsr","plugin_committers-smitheonsr"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/eonsr-aeo-agent_373549.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>EONSR AEO Agent is a powerful content generation tool designed to help website owners automate the creation of SEO and AEO (Answer Engine Optimization) friendly articles.<\/p>\n\n<p>Unlike generic AI writers, this plugin utilizes a specialized 2-pane UI workflow and structured prompt engineering to produce in-depth, formatted, and media-rich content directly within your WordPress dashboard.<\/p>\n\n<p><strong>How it works (SaaS Service)<\/strong><\/p>\n\n<p>This plugin operates as a connector (client) to the EONSR Cloud Platform. It sends your input (keywords, topics, settings) to our external Node.js processing servers to generate content using advanced AI models (Google Gemini API). This architecture ensures your WordPress site remains fast and is not burdened by heavy AI processing tasks.<\/p>\n\n<p>All plugin features are fully functional. The plugin itself contains no locked or restricted functionality. API usage limits are managed entirely server-side by the EONSR Cloud service.<\/p>\n\n<p><strong>Key Features<\/strong><\/p>\n\n<ul>\n<li><strong>AI Article Generation:<\/strong> Create comprehensive articles from a single keyword using advanced prompting.<\/li>\n<li><strong>Dual-Pane Interface:<\/strong> Edit content and prompts side-by-side before publishing.<\/li>\n<li><strong>Image Generation:<\/strong> Automatically create Featured Images and In-Content images with text overlays.<\/li>\n<li><strong>Bulk Generation:<\/strong> Upload an Excel (.xlsx) file to schedule and generate hundreds of posts automatically in the background.<\/li>\n<li><strong>Smart Auto-Translation:<\/strong> Generate content in one language and automatically translate\/localize it into multiple languages.<\/li>\n<li><strong>SEO Optimization:<\/strong> Automatically fills Rank Math \/ Yoast SEO meta descriptions and focus keywords.<\/li>\n<li><strong>YouTube Embedding:<\/strong> Automatically finds and embeds relevant videos to increase time-on-site.<\/li>\n<\/ul>\n\n<h3>External Services<\/h3>\n\n<p>This plugin connects to the following external services. By using this plugin, you agree to the terms of each service listed below.<\/p>\n\n<h4>1. EONSR Cloud API<\/h4>\n\n<p>This plugin requires the EONSR Cloud API to function. All content generation, image creation, and translation features are processed on EONSR's external servers \u2014 no AI processing is done locally on your WordPress site.<\/p>\n\n<ul>\n<li><strong>What it is:<\/strong> A managed Node.js API platform that processes AI content generation requests using Google Gemini models.<\/li>\n<li><strong>API Endpoint:<\/strong> <code>https:\/\/commercial-api.congtyeon.com<\/code><\/li>\n<li><strong>What data is sent:<\/strong> When an authorized WordPress user triggers a generation action, the plugin sends the requested keywords, language, country, writing style, generation settings, site URL, license information, and any selected source content required to complete the request. The plugin does not send WordPress user passwords.<\/li>\n<li><strong>When data is sent:<\/strong> Data is sent when an authorized user starts article generation, image generation, translation, bulk processing, license activation or synchronization, or a supported payment flow.<\/li>\n<li><strong>How the connection is secured:<\/strong> Outbound requests use HTTPS. Inbound callbacks from EONSR Cloud use signed HMAC authentication with a per-site secret, timestamp, nonce, request-body hash, and replay protection.<\/li>\n<li><strong>Outbound endpoints used:<\/strong> Every feature of this plugin is a thin client for the EONSR Cloud service. No article text, image, or translation is produced on the WordPress server itself.\n\n<ul>\n<li><code>POST \/api\/v1\/article\/generate<\/code> \u2014 Generates article text.<\/li>\n<li><code>POST \/api\/v1\/article\/generate-images<\/code> \u2014 Generates illustration images.<\/li>\n<li><code>POST \/api\/v1\/article\/bulk\/upload-scheduled<\/code> \u2014 Uploads an XLSX job list for bulk generation. The spreadsheet is parsed and every article in it is written on EONSR's servers.<\/li>\n<li><code>GET \/api\/v1\/article\/bulk\/status-scheduled<\/code> \u2014 Polls the progress of a bulk job.<\/li>\n<li><code>GET \/api\/v1\/apiConfig\/config\/get<\/code> \u2014 Retrieves the generation configuration for the active plan.<\/li>\n<li><code>POST \/api\/v1\/license\/create<\/code>, <code>\/activate<\/code>, <code>\/validate<\/code>, <code>\/trial<\/code>, <code>GET \/api\/v1\/license\/details\/<\/code>, <code>POST \/api\/v1\/license\/cancel\/<\/code> \u2014 License lifecycle.<\/li>\n<li><code>GET \/api\/v1\/product<\/code>, <code>POST \/api\/v1\/paypal\/capture-order\/<\/code> \u2014 Plan catalogue and payment confirmation.<\/li>\n<\/ul><\/li>\n<li><strong>Service Provider:<\/strong> Cong Ty EON (EONSR)<\/li>\n<li><strong>Terms of Service:<\/strong> https:\/\/aeo.eonsr.com\/terms\/<\/li>\n<li><strong>Privacy Policy:<\/strong> https:\/\/aeo.eonsr.com\/privacy-policy\/<\/li>\n<\/ul>\n\n<h4>2. YouTube Data API v3 (Google)<\/h4>\n\n<p>This plugin optionally uses the YouTube Data API v3 to search for and embed relevant videos inside generated articles.<\/p>\n\n<ul>\n<li><strong>What it is:<\/strong> Google's public API for searching YouTube video content.<\/li>\n<li><strong>API Endpoint:<\/strong> <code>https:\/\/www.googleapis.com\/youtube\/v3\/search<\/code><\/li>\n<li><strong>What data is sent:<\/strong> The article keyword\/topic is sent to YouTube's API to find a relevant video. No personal user data is transmitted.<\/li>\n<li><strong>When data is sent:<\/strong> Only when the YouTube embedding feature is enabled and a generation action is triggered.<\/li>\n<li><strong>Service Provider:<\/strong> Google LLC<\/li>\n<li><strong>Terms of Service:<\/strong> https:\/\/developers.google.com\/youtube\/terms\/api-services-terms-of-service<\/li>\n<li><strong>Privacy Policy:<\/strong> https:\/\/policies.google.com\/privacy<\/li>\n<\/ul>\n\n<h4>REST API Endpoints (Inbound Webhooks)<\/h4>\n\n<p>This plugin registers REST API endpoints on the connected WordPress site so that the EONSR Cloud service can return generated content and retrieve the limited site information required for article generation.<\/p>\n\n<p>The protected endpoints require an HMAC-signed request generated with a unique per-site secret. Every signed request includes a timestamp, a random nonce, and a SHA-256 hash of the raw request body. Expired, modified, incorrectly signed, or replayed requests are rejected.<\/p>\n\n<ul>\n<li><code>POST \/wp-json\/eonsr-aeo-agent\/v1\/scheduled-post\/create<\/code> \u2014 Receives completed article data from EONSR Cloud and creates or schedules a WordPress post. Requires HMAC authentication. Incoming HTML is sanitized before it is stored.<\/li>\n<li><code>POST \/wp-json\/eonsr-aeo-agent\/v1\/sync-license<\/code> \u2014 Receives a license synchronization request. Requires HMAC authentication and verifies that the supplied domain matches the current WordPress site.<\/li>\n<li><code>GET \/wp-json\/eonsr-aeo-agent\/v1\/languages<\/code> \u2014 Returns the active language configuration needed for translation routing. Requires HMAC authentication.<\/li>\n<li><code>GET \/wp-json\/eonsr-aeo-agent\/v1\/posts<\/code> \u2014 Returns a limited list of published post information used for internal-link suggestions and duplicate-content prevention. Requires HMAC authentication and enforces a maximum result limit.<\/li>\n<li><code>GET \/wp-json\/eonsr-aeo-agent\/v1\/keyphrases<\/code> \u2014 Returns a limited list of existing SEO focus keyphrases used to reduce keyword cannibalization. Requires HMAC authentication, validates the search query, excludes deleted and auto-draft posts, and limits the response size.<\/li>\n<\/ul>\n\n<p>The inbound endpoints do not return WordPress passwords, authentication cookies, private user credentials, payment credentials, or unrestricted post metadata.<\/p>\n\n<h3>Third-Party Libraries<\/h3>\n\n<p>This plugin bundles the following third-party library. It is served locally so that no request is made to an external CDN.<\/p>\n\n<ul>\n<li><strong>SweetAlert2<\/strong> v11.26.17 \u2014 used for the plugin's dialog boxes.\n\n<ul>\n<li>File: <code>assets\/js\/sweetalert2.all.min.js<\/code><\/li>\n<li>License: MIT<\/li>\n<li>Source: https:\/\/github.com\/sweetalert2\/sweetalert2<\/li>\n<li>Unminified source for this exact version: https:\/\/github.com\/sweetalert2\/sweetalert2\/releases\/tag\/v11.26.17<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Log in to your WordPress Administration Panels.<\/li>\n<li>Go to <strong>Plugins -&gt; Add New<\/strong>.<\/li>\n<li>Search for <strong>EONSR AEO Agent<\/strong>.<\/li>\n<li>Click <strong>Install Now<\/strong>, then click <strong>Activate<\/strong>.<\/li>\n<li>Go to the <strong>AEO Agent<\/strong> menu in your dashboard.<\/li>\n<li>Optionally, enter your License Key to connect your own third-party API quota (YouTube, Google Search). You can also proceed without a key using EONSR's shared default quota.<\/li>\n<li>Start generating content!<\/li>\n<\/ol>\n\n<p>Alternatively, you can upload the plugin zip file via the <strong>Plugins -&gt; Add New -&gt; Upload Plugin<\/strong> screen.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20to%20pay%20to%20use%20this%20plugin%3F\"><h3>Do I need to pay to use this plugin?<\/h3><\/dt>\n<dd><p>The plugin itself is free to download and all features are fully accessible without a license key. The plugin connects to the EONSR Cloud service for AI processing, which is available to all users using EONSR's default shared quota. A License Key is available for purchase at https:\/\/aeo.eonsr.com and grants you a dedicated, higher-volume quota for third-party integrations such as the YouTube Data API and Google Search API \u2014 resources that EONSR provisions and manages on your behalf.<\/p><\/dd>\n<dt id=\"where%20is%20my%20data%20sent%3F\"><h3>Where is my data sent?<\/h3><\/dt>\n<dd><p>Depending on the feature you use, the plugin may send keywords, article settings, selected source content, image prompts, language and country settings, site URL, license information, and payment product identifiers to <code>https:\/\/commercial-api.congtyeon.com<\/code>. WordPress account passwords and authentication cookies are not sent to the service. Please review the Terms of Service and Privacy Policy listed in the External Services section for retention and processing details.<\/p><\/dd>\n<dt id=\"why%20does%20it%20use%20an%20external%20server%3F\"><h3>Why does it use an external server?<\/h3><\/dt>\n<dd><p>AI content generation, especially image creation and long-form text processing, requires significant computational power. Running this directly on your WordPress hosting would likely cause timeout errors. Our Node.js cloud infrastructure handles the heavy lifting to ensure stability.<\/p><\/dd>\n<dt id=\"can%20i%20use%20my%20own%20google%20gemini%20api%20key%3F\"><h3>Can I use my own Google Gemini API Key?<\/h3><\/dt>\n<dd><p>No. To ensure quality consistency, structured prompt engineering security, and advanced features (like text-on-image generation), the system uses our managed API infrastructure.<\/p><\/dd>\n<dt id=\"what%20are%20the%20rest%20api%20endpoints%20registered%20by%20this%20plugin%3F\"><h3>What are the REST API endpoints registered by this plugin?<\/h3><\/dt>\n<dd><p>The plugin registers protected inbound endpoints used to receive generated articles and retrieve the limited site information required for translation, internal linking, license synchronization, and duplicate-content prevention. All listed inbound endpoints require signed HMAC authentication. See the \"External Services\" section for the endpoint list and data-flow details.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>3.9.2<\/h4>\n\n<ul>\n<li>Security: removed  from the article HTML allowlist. Generated posts can no longer carry inline JavaScript. YouTube embeds are unaffected (they use <\/li>\n<\/ul>\n\n<p>&lt;<\/p>\n\n<p>iframe&gt; plus a separately enqueued script).\n*   Security:<\/p>\n\n<p>&lt;<\/p>\n\n<p>iframe&gt; embeds are now restricted to YouTube hosts; any other iframe src is stripped when a post is saved.\n*   Hardens the scheduled-post, languages and sync-license REST routes, which already require HMAC authentication, against stored cross-site scripting in the article body.<\/p>\n\n<h4>3.9.0<\/h4>\n\n<ul>\n<li>Rebuilt the plugin on an object-oriented architecture: 91 global functions and 31 anonymous hook callbacks are now 37 autoloaded classes under the EONSR\\AEO_Agent namespace.<\/li>\n<li>Page markup moved out of PHP into dedicated view files under views\/.<\/li>\n<li>Replaced the bundled Tahoma font with the SIL Open Font License Noto fonts. Chinese, Japanese and Korean image watermarks now render correctly instead of showing empty boxes.<\/li>\n<li>Fixed bulk XLSX upload, which rejected every file.<\/li>\n<li>Fixed saved language, country and writing-style selections not appearing in the editor.<\/li>\n<li>The keyphrase REST route now requires the same HMAC authentication as every other webhook, and no longer reports keyphrases from trashed posts.<\/li>\n<li>Diagnostic logging is silent unless WP_DEBUG is enabled.<\/li>\n<\/ul>\n\n<h4>3.8.0<\/h4>\n\n<ul>\n<li>Fixed an unauthenticated stored cross-site scripting vulnerability in inbound article creation.<\/li>\n<li>Added HMAC authentication to all inbound REST API endpoints used for article creation, license synchronization, language retrieval, post retrieval, and keyphrase lookup.<\/li>\n<li>Added timestamp validation, nonce validation, SHA-256 request-body hashing, constant-time signature comparison, and replay protection.<\/li>\n<li>Restored WordPress KSES filtering for generated article HTML and removed unsafe KSES bypasses.<\/li>\n<li>Added validation and sanitization for generated HTML, CSS, metadata, tags, summaries, image prompts, license data, payment data, uploads, and remote API responses.<\/li>\n<li>Removed the fallback that attributed webhook-created posts to WordPress user ID 1.<\/li>\n<li>Added per-post capability checks for article editing, image generation, translation, scheduling, and category updates.<\/li>\n<li>Added ownership checks and capability validation for job and bulk cancellation actions.<\/li>\n<li>Strengthened XLSX and PNG upload validation, including MIME type, file size, and image dimension checks.<\/li>\n<li>Added authorization and nonce protection to license synchronization actions.<\/li>\n<li>Hardened PayPal and ZaloPay flows with trusted redirect-domain checks, PayPal order ownership validation, duplicate-capture protection, and safer license activation handling.<\/li>\n<li>Added query validation, result limits, and deleted-post filtering to the protected keyphrase lookup endpoint.<\/li>\n<li>Updated compatibility information for WordPress 7.0.<\/li>\n<\/ul>\n\n<h4>3.7.7<\/h4>\n\n<ul>\n<li>Refactored codebase for better performance and security (Prefix Standardization).<\/li>\n<li>Implemented WordPress Nonce verification for all AJAX actions.<\/li>\n<li>Enhanced Bulk Processor with background processing logic.<\/li>\n<li>Added DOMDocument handling for better image injection in translated posts.<\/li>\n<li>Updated API endpoints to v1 structure.<\/li>\n<li>Extracted all inline CSS and JavaScript into separate enqueued files per WordPress guidelines.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Generate high-quality, SEO\/AEO optimized long-form articles, images, and translations using Google Gemini AI via EONSR Cloud.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/km.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/280720","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/km.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/km.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/km.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=280720"}],"author":[{"embeddable":true,"href":"https:\/\/km.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/smitheonsr"}],"wp:attachment":[{"href":"https:\/\/km.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=280720"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/km.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=280720"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/km.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=280720"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/km.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=280720"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/km.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=280720"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/km.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=280720"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}