{"id":308436,"date":"2026-05-21T12:47:16","date_gmt":"2026-05-21T12:47:16","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/tactical-ai-agent-detection-for-woocommerce\/"},"modified":"2026-09-27T11:37:32","modified_gmt":"2026-09-27T11:37:32","slug":"tactical-agent-detection","status":"publish","type":"plugin","link":"https:\/\/bn-in.wordpress.org\/plugins\/tactical-agent-detection\/","author":23493357,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.0","stable_tag":"1.2.0","tested":"7.1.2","requires":"6.3","requires_php":"7.4","requires_plugins":null,"header_name":"Tactical \u2014 AI Agent Detection for WooCommerce","header_author":"Tactical","header_description":"See which AI agents (ChatGPT, Perplexity, Claude, Google AI) visit your store, what they look at, and what they buy. Free tier \u2014 100 agent sessions\/week.","assets_banners_color":"1a1c20","last_updated":"2026-09-27 11:37:32","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/tactical-app.work","rating":0,"author_block_rating":0,"active_installs":0,"downloads":899,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.2":{"tag":"1.0.2","author":"sourabhnk","date":"2026-05-21 12:46:33","revision":3541972},"1.1.0":{"tag":"1.1.0","author":"sourabhnk","date":"2026-07-06 14:26:02","revision":3597919},"1.2.0":{"tag":"1.2.0","author":"sourabhnk","date":"2026-09-27 11:37:32","revision":3715412}},"upgrade_notice":{"1.1.0":"<p>Adds server-side detection of AI crawlers that don&#039;t run JavaScript \u2014 the majority of AI retrieval traffic. No impact on human visitors. Recommended.<\/p>","1.0.2":"<p>Security fix \u2014 stops rendering the API key into storefront HTML. Recommended upgrade for all installs.<\/p>","1.0.1":"<p>WP.org compliance pass \u2014 script enqueueing is now spec-compliant. No functional changes; safe to upgrade.<\/p>","1.0.0":"<p>First public release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3715128,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3715128,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3715128,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3715412,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3715412,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.2","1.1.0","1.2.0"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Plugin settings page \u2014 paste API key and verify connection.","2":"Tactical dashboard at tactical-app.work showing agent traffic.","3":"Agent type breakdown by day.","4":"Intent funnel \u2014 browse vs. evaluate vs. buy."}},"plugin_section":[],"plugin_tags":[250436,246305,246479,232,286],"plugin_category":[36,45],"plugin_contributors":[263820],"plugin_business_model":[],"class_list":["post-308436","plugin","type-plugin","status-publish","hentry","plugin_tags-agentic-commerce","plugin_tags-ai-agents","plugin_tags-ai-crawlers","plugin_tags-analytics","plugin_tags-woocommerce","plugin_category-analytics","plugin_category-ecommerce","plugin_contributors-sourabhnk","plugin_committers-sourabhnk"],"banners":{"banner":"https:\/\/ps.w.org\/tactical-agent-detection\/assets\/banner-772x250.png?rev=3715412","banner_2x":"https:\/\/ps.w.org\/tactical-agent-detection\/assets\/banner-1544x500.png?rev=3715412","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/tactical-agent-detection\/assets\/icon.svg?rev=3715128","icon":"https:\/\/ps.w.org\/tactical-agent-detection\/assets\/icon.svg?rev=3715128","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>AI assistants are shopping WooCommerce stores. Some send crawlers that never run JavaScript, some drive a browser that behaves like a person, and some send people who then buy. Standard analytics sees little of it: Google Analytics excludes known bots, and you can't turn that off (<a href=\"https:\/\/support.google.com\/analytics\/answer\/9888366\">Google Analytics Help<\/a>); crawlers never fire an analytics tag; and an agent browser is counted as a person.<\/p>\n\n<p>This plugin connects your store to <strong>Tactical<\/strong>, a third-party service at https:\/\/tactical-app.work, which shows you the rest. The plugin installs the storefront script, adds server-side crawler detection and registers the WooCommerce webhooks; the dashboard lives in your Tactical account.<\/p>\n\n<p><strong>What you get:<\/strong><\/p>\n\n<ul>\n<li><strong>AI crawlers, server-side<\/strong> \u2014 when a known AI crawler requests a page, the plugin records it, no JavaScript needed. A hit is marked verified only when its IP matches the operator's published range. Nothing is sent for human visitors.<\/li>\n<li><strong>Agent browsers, by behaviour<\/strong> \u2014 sessions driven by an agent, including ones that never name themselves, are scored on how the session behaves. A score is a probability, not a verdict.<\/li>\n<li><strong>AI-referred buyers<\/strong> \u2014 people who arrive from ChatGPT, Perplexity, Gemini, Copilot and other assistants.<\/li>\n<li><strong>Agent revenue<\/strong> \u2014 every order is labelled: Agent order, Agent order (session match) or AI-referred order, each saying how sure it is, and the two kinds are never added together. Agent orders include ones placed in an agent checkout, such as Stripe's agentic checkout, which no browser pixel sees.<\/li>\n<li><strong>Evidence for every agent order<\/strong> \u2014 a record of the order, how it was attributed, the matched session and any Tactical Gate decisions, downloadable as PDF and JSON for disputes and returns. It holds no buyer name, email, address or IP address.<\/li>\n<li><strong>Tactical Gate (beta)<\/strong> \u2014 rules for AI agents by product, cart and checkout, starting in Observe mode. It is in a private beta; join the list at https:\/\/tactical-app.work\/waitlist.<\/li>\n<\/ul>\n\n<p><strong>Tactical pricing \u2014 managed at tactical-app.work:<\/strong><\/p>\n\n<p>The plugin works on every plan, including the free one. Agent revenue and evidence are on every plan, with the plan's history.<\/p>\n\n<ul>\n<li><strong>Scout \u2014 free<\/strong> \u2014 7-day monitor, top 3 agent types, AI Search report, 100 agent sessions\/week. No credit card.<\/li>\n<li><strong>Radar \u2014 $39\/mo<\/strong> \u2014 90-day history, all agent types, intent signals, product interest map (top 50), 10,000 agent sessions\/mo.<\/li>\n<li><strong>Command \u2014 $129\/mo<\/strong> \u2014 everything in Radar, plus marketplace-referral and price-check signals, unlimited products, 50,000 agent sessions\/mo.<\/li>\n<\/ul>\n\n<p>Annual plans save about 25%.<\/p>\n\n<p><strong>Multi-platform:<\/strong><\/p>\n\n<p>This plugin is for WooCommerce. The same Tactical account also works on Shopify (via the Shopify App Store) and on any custom storefront (via a script tag).<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to <strong>Tactical<\/strong> at https:\/\/tactical-app.work \u2014 a third-party AI agent analytics service operated by the plugin author. The plugin requires an active Tactical account (free Scout tier is sufficient) to function. Without an API key configured on the settings page, no requests are made.<\/p>\n\n<p><strong>Endpoints used:<\/strong><\/p>\n\n<ul>\n<li><strong>Snippet ingest<\/strong> \u2014 <code>https:\/\/tactical-app.work\/api\/ingest<\/code>. The detection script (<code>https:\/\/tactical-app.work\/snippet.js<\/code>) loads on every storefront page view and posts an event payload containing: an anonymised session ID, page URL (path + query string only), referrer domain, user-agent string, scroll\/mouse\/timing heuristics, and your store's API key. No customer PII (no names, emails, IP addresses, payment data, or form contents) is sent.<\/li>\n<li><strong>Connection verification<\/strong> \u2014 <code>https:\/\/tactical-app.work\/api\/verify-connection<\/code>. Triggered only when an admin clicks \"Verify connection\" on the settings page. Sends only your API key (in a request header) so Tactical can confirm the key belongs to this store. No event data.<\/li>\n<li><strong>WooCommerce webhooks<\/strong> \u2014 <code>https:\/\/tactical-app.work\/api\/wc-webhook\/&lt;topic&gt;<\/code>. Once an API key is saved, four webhook subscriptions are registered with WooCommerce (<code>order.created<\/code>, <code>order.updated<\/code>, <code>product.created<\/code>, <code>product.updated<\/code>). WooCommerce delivers these payloads directly to Tactical with WC's standard HMAC signature when matching events occur on your store. Payload contents are WooCommerce's standard webhook bodies (order or product objects).<\/li>\n<\/ul>\n\n<p><strong>Conditions:<\/strong> events are only sent after you paste a valid API key on the settings page. Without a key, the snippet does not load, no requests are made, and no webhooks are registered.<\/p>\n\n<p><strong>Service terms:<\/strong><\/p>\n\n<ul>\n<li>Tactical Privacy Policy: https:\/\/tactical-app.work\/privacy<\/li>\n<li>Tactical Terms of Service: https:\/\/tactical-app.work\/terms<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>tactical-agent-detection<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install via the Plugins \u2192 Add New screen.<\/li>\n<li>Activate the plugin. (WooCommerce must be installed and active first; this plugin declares it as a required dependency.)<\/li>\n<li>Sign up at https:\/\/tactical-app.work and copy your API key from the dashboard.<\/li>\n<li>Go to Settings \u2192 Tactical and paste the API key.<\/li>\n<li>Click \"Verify connection\" \u2014 you should see a green checkmark.<\/li>\n<li>Open your storefront \u2014 Tactical starts classifying agent traffic immediately.<\/li>\n<\/ol>\n\n<p>The plugin auto-registers WooCommerce webhooks for <code>order.created<\/code>, <code>order.updated<\/code>, <code>product.created<\/code>, and <code>product.updated<\/code> so order and catalog activity is correlated with agent sessions.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20a%20tactical%20account%20to%20use%20this%20plugin%3F\"><h3>Do I need a Tactical account to use this plugin?<\/h3><\/dt>\n<dd><p>Yes \u2014 sign up free at tactical-app.work. The free Scout tier is 100 agent sessions per week with no credit card.<\/p><\/dd>\n<dt id=\"what%20data%20does%20the%20plugin%20collect%3F\"><h3>What data does the plugin collect?<\/h3><\/dt>\n<dd><p>The storefront script sends anonymised session metadata only: user-agent, page URL, referrer, scroll\/mouse heuristics, and product context, with no names, emails, IP addresses or payment data. The order webhooks deliver WooCommerce's standard order body, which includes the customer's details; Tactical keeps only the order ID, total, currency, line items and how the order was attributed, uses the buyer's IP address and user-agent once to match the order to a session, and discards the rest.<\/p><\/dd>\n<dt id=\"how%20is%20agent%20traffic%20detected%3F\"><h3>How is agent traffic detected?<\/h3><\/dt>\n<dd><p>Named crawlers and fetchers are matched against Tactical's registry of AI operators by user agent, and verified against the operator's published IP ranges where there are any. Browser sessions are scored on behaviour and environment (page-timing regularity, interaction signals, a datacenter network, automation flags); the IP itself is not stored. The dashboard updates in 15-minute batches.<\/p><\/dd>\n<dt id=\"what%20about%20agents%20that%20don%27t%20identify%20themselves%2C%20like%20meta%27s%20muse%3F\"><h3>What about agents that don't identify themselves, like Meta's Muse?<\/h3><\/dt>\n<dd><p>A named crawler (GPTBot, PerplexityBot, ClaudeBot) says who it is in its user-agent, so server-side detection catches it outright. An agent browser \u2014 Meta's Muse, OpenAI's Operator \u2014 drives a real browser on a shopper's behalf, and it visits your store whether or not you're a commerce partner of theirs. No request-layer fingerprint for Muse has been published by anyone yet, so a user-agent list can't see it. Tactical's behavioural layer scores the session itself (page-timing regularity, interaction signals, browser environment). In a September 2026 test, an AI-driven browser scored as an agent and a person in Chrome on the same laptop scored as human; a real Muse session has not yet been confirmed. Tactical's agent registry tracks Muse as fingerprint research, and a confirmed signature goes live without waiting for a plugin release.<\/p><\/dd>\n<dt id=\"will%20this%20slow%20down%20my%20site%3F\"><h3>Will this slow down my site?<\/h3><\/dt>\n<dd><p>The storefront script loads with the <code>defer<\/code> attribute (about 8 KB gzipped), and classification happens on Tactical's servers, not yours. Server-side crawler detection does nothing for human visitors: it sends a small, non-blocking request only when a request's user agent matches a known AI crawler.<\/p><\/dd>\n<dt id=\"how%20do%20i%20cancel%3F\"><h3>How do I cancel?<\/h3><\/dt>\n<dd><p>Cancel from the Tactical dashboard's billing page at tactical-app.work. The plugin keeps working on the free Scout tier after cancellation.<\/p><\/dd>\n<dt id=\"where%27s%20my%20data%20stored%3F\"><h3>Where's my data stored?<\/h3><\/dt>\n<dd><p>In Tactical's Postgres database. Sessions, product views and Gate decisions are deleted after 90 days and AI crawler visits after 180 days; order records and their evidence are kept while your store is connected. Details: https:\/\/tactical-app.work\/privacy<\/p><\/dd>\n<dt id=\"is%20this%20gdpr-compliant%3F\"><h3>Is this GDPR-compliant?<\/h3><\/dt>\n<dd><p>Tactical processes data under the legitimate-interest legal basis. It stores no names or contact details of visitors or buyers, and merchants can request deletion at any time by emailing support@tactical-app.work. A Data Processing Addendum is available on request.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.0<\/h4>\n\n<ul>\n<li><strong>New: Tactical Gate.<\/strong> Enforce the agent policy you set on tactical-app.work in the request path: throttle, require identification, challenge, redirect or block AI agents by identity, category, confidence and scope (paths, products, collections, cart, checkout, schedule). Fetches the compiled policy every five minutes with an ETag, applies it on page requests, add-to-cart and checkout, and reports decisions in batches.<\/li>\n<li>Every policy starts in Observe mode, where rules only tag. People are never restricted, whatever the policy says, and a search engine only when the policy names it and confirms the SEO impact. No policy, a failed fetch or any error means the request passes untouched.<\/li>\n<li>New settings toggle \"Tactical Gate\" (on by default; a no-op until a policy exists) with policy version, mode and last-fetch status.<\/li>\n<li>The settings page now recreates any missing Tactical webhooks (for example after WooCommerce was activated after this plugin), instead of asking you to reactivate.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li><strong>New: server-side AI crawler detection.<\/strong> Detects AI crawlers that don't run JavaScript (most retrieval crawlers) by matching the request user-agent against a maintained registry of AI operators (OpenAI, Anthropic, Perplexity, Google, Meta, Apple, Amazon, ByteDance, Mistral, DuckDuckGo, and more). Fires only on a matched AI user-agent; human visitors trigger nothing.<\/li>\n<li>Non-blocking delivery (<code>wp_remote_post<\/code> with <code>blocking =&gt; false<\/code>, 1s timeout) and a 60-second per-(agent, URL) dedup guard against crawler bursts.<\/li>\n<li>New settings toggle \"Server-side AI crawler detection\" (on by default) with a \"last event sent\" status line.<\/li>\n<li>Optional <code>tactical_trust_proxy_headers<\/code> filter to read the crawler's real IP from CDN\/proxy headers when the store is behind Cloudflare or similar.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Security: removed the <code>data-key<\/code> attribute from the storefront <code>&lt;script&gt;<\/code> tag. The Tactical API key is a server-side secret used to sign WooCommerce webhook deliveries and authenticate plugin-to-server API calls \u2014 it must not appear in browser-rendered HTML. The snippet identifies the tenant by <code>data-shop<\/code> plus the request Origin, so no key is required client-side. Recommended upgrade for all installs.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Compliance: storefront snippet now loads via <code>wp_enqueue_script<\/code> with the <code>defer<\/code> strategy, decorated via the <code>script_loader_tag<\/code> filter. No more inline <code>&lt;script&gt;<\/code> injection.<\/li>\n<li>Compliance: settings-page admin JS extracted to <code>assets\/admin-settings.js<\/code>, enqueued via <code>wp_enqueue_script<\/code> + <code>wp_localize_script<\/code>. No more inline <code>&lt;script&gt;<\/code> in the admin page.<\/li>\n<li>Compliance: declared <code>Requires Plugins: woocommerce<\/code> so WP correctly blocks activation without WooCommerce.<\/li>\n<li>Readme: added the \"External services\" disclosure, clarified Scout\/Tactical naming in the pricing section, updated Contributors.<\/li>\n<li>Bumped <code>Requires at least<\/code> to WP 6.3 (needed for <code>wp_enqueue_script<\/code> defer\/async strategy).<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>Snippet injection on the storefront when an API key is configured.<\/li>\n<li>Settings page with API key, store domain, and \"Verify connection\" button.<\/li>\n<li>Auto-registration of WooCommerce webhooks for order and product topics.<\/li>\n<li>Uninstall removes options + Tactical-managed webhooks.<\/li>\n<\/ul>","raw_excerpt":"See the AI crawlers, agent browsers and AI-referred buyers on your WooCommerce store, and which orders AI agents placed.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/bn-in.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/308436","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bn-in.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/bn-in.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/bn-in.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=308436"}],"author":[{"embeddable":true,"href":"https:\/\/bn-in.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/sourabhnk"}],"wp:attachment":[{"href":"https:\/\/bn-in.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=308436"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/bn-in.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=308436"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/bn-in.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=308436"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/bn-in.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=308436"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/bn-in.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=308436"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/bn-in.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=308436"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}