Linux 软件免费装
Banner图

AVA Pay for WooCommerce

开发者 avalayer
更新时间 2026年9月29日 11:51
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: MIT
版权网址: 版权信息

标签

security coupons ai agents agentic commerce bot verification

下载

0.2.0 0.3.0 0.4.0 0.4.1

详情介绍:

AI agents are already shopping your store. ChatGPT browses product pages, agentic checkouts are rolling out across the ecosystem. AVA Pay tells you which agents to trust, lets you set the rules, and records every verification and attributed order so you can see the traffic when reporting lands. This plugin connects your WooCommerce store to the AVA Pay verification API, which cryptographically verifies agent traffic across protocols (Visa Trusted Agent Protocol, IETF Web Bot Auth, Google AP2) through a single endpoint. What it does Trust model, honestly stated

安装:

  1. Upload the plugin to /wp-content/plugins/ava-pay-for-woocommerce/, or install through the WordPress plugins screen.
  2. Activate the plugin. WooCommerce must be active.
  3. Go to WooCommerce → AVA Pay to review settings. The defaults work out of the box against the hosted AVA Pay API.
  4. Requirements for verification to work: pretty permalinks (Settings → Permalinks, any structure other than "Plain") and an https site address, because agents sign the canonical https://…/wp-json/… URL. The settings page warns you if either is missing.

升级注意事项:

0.4.1 Demo agent visits never create a coupon, and the plugin now tells you when Coming soon mode hides your store from AI agents. 0.4.0 Shows signed AI agent visits to your store. 0.3.0 Sends less data to the verification service: only the headers verification needs, never cookies or credentials. Recommended for all sites.

常见问题:

Does this slow my store down?

Not for human shoppers: a page view without agent signature headers costs one check and nothing else. The verify endpoint is only exercised by agent traffic, and the storefront script loads only on page views that carry agent signature parameters. For a page view that does carry agent signature headers, the check runs after the page has been generated. On PHP-FPM and LiteSpeed hosts (most hosting) the response is finished first, so the agent is not kept waiting. On other server setups, such as Apache with mod_php, the page has been sent but the connection can stay open for up to about 2 seconds while the check completes. Only one check runs at a time for the whole site, checks are capped per agent and per site (see the question below), and you can turn them off in the settings.

What data leaves my site?

Only agent requests are forwarded to the verification API: a request that reached the verify endpoint, and a page view that carried agent signature headers. For each, the plugin sends its method, its URL, its body if it has one (a page view has none), and the headers verification needs (the agent's signature headers, the headers that signature covers, and the protocol headers the verifier reads). Cookies, credentials, and other request headers are not forwarded. No customer, order, or session data is sent. See External services below for the full detail.

My store is behind Cloudflare or a reverse proxy. Does rate limiting still work?

The verify endpoint is rate-limited per client IP (REMOTE_ADDR). If your host does not restore the real client IP, all traffic shares the proxy's IP and one rate-limit bucket. Preferably fix real-IP restoration at the server level (mod_remoteip / ngx_http_realip); alternatively, use the ava_pay_client_ip filter to supply the client IP from a header only your trusted proxy can set (e.g. CF-Connecting-IP when only Cloudflare can reach the origin).

I have enabled full-page caching. Will I see agent visits?

Only for pages that are not served from the cache. A cached page is sent by your host or caching plugin without running WordPress or PHP, so the plugin never sees that visit and it is not shown under Agent visits. A cache that varies on, or bypasses for, the Signature header lets those visits through; most caches do neither by default.

Why don't I see any agent visits?

Check these, in this order:

  1. Coming soon mode. While WooCommerce's Coming soon mode is on, everyone except store managers, AI agents and logged-in customers included, sees a placeholder page instead of your store pages (or your whole site, depending on the setting). You see the store normally because you are a store manager. Agents that visit are still listed under Agent visits, but they see the placeholder, not your products, so they cannot browse on to them. The AVA Pay settings page and the Agent visits screen warn you while it is on. To go live, open WooCommerce, Settings, Site visibility, choose Live and save. AVA Pay never changes this setting for you.
  2. The site must be publicly reachable. An AI agent cannot visit a local development site, or a site behind a password or a maintenance page.
  3. Full-page caching. Visits to cached pages never reach the plugin; see "I have enabled full-page caching. Will I see agent visits?" above.
  4. Most AI crawlers do not sign their requests, so they cannot be verified and are not listed. ChatGPT's agent does sign its requests.
  5. To try it, ask ChatGPT to open one of your product pages by its full address, then reload WooCommerce, Agent visits.

How many agent visits are checked?

Up to 30 a minute and 2,000 a day for each agent, and up to 20 a minute and 2,000 a day for the whole site, one at a time. A visit is also skipped while another check is running, and an agent whose last check could not be completed (the verification service or the agent's key directory did not answer) is skipped for 10 minutes. Skipped visits are not listed; they are counted as "Not checked" under Agent visits, with the reason. Each check waits at most 2 seconds for the verification service. Developers can change the numbers with the ava_pay_page_visit_agent_per_minute, ava_pay_page_visit_agent_per_day, ava_pay_page_visit_site_per_minute, ava_pay_page_visit_site_per_day, ava_pay_page_visit_timeout and ava_pay_page_visit_backoff_seconds filters.

How long are agent visits kept?

90 days. A daily scheduled task deletes older agent visit records (only those; verification and order records used for coupon attribution are not touched). Developers can change the period with the ava_pay_page_visit_retention_days filter. Deactivating or deleting the plugin removes the scheduled task.

Can agents get discounts without my consent?

No. Discounts are capped by your maximum, identity-only agents get 0% unless you explicitly raise the identity-only tier, and platform offers apply only to mandate-backed requests.

更新日志:

0.4.1 0.4.0 0.3.0 0.2.0 0.1.0