Skip to main content Scroll Top

AEO for WordPress: Getting a WordPress Site Fetched, Parsed and Cited by AI Assistants

Updated October 2026 · Written and maintained by the Progression Agency strategy team

AEO for WordPress is answer engine optimization applied to the WordPress stack: the robots.txt rules, firewall and CDN settings, caching, rendering, structured data, sitemaps and page structure that decide whether ChatGPT, Claude, Perplexity, Gemini, Microsoft Copilot and Google AI Overviews can fetch a page, parse it and cite it. It is for businesses, publishers and WooCommerce stores whose site runs on WordPress and who want to be named when a buyer asks an assistant instead of a search box. The output is a site that documented AI crawlers can reach, pages whose answers sit in the HTML, and a monthly record of which prompts name you. Progression Agency is based in New York City and takes on WordPress AEO work for clients across the United States and worldwide.

On this page · 21 sections
  1. What is AEO for WordPress?
  2. How do buyers and WordPress site owners phrase prompts to AI assistants?
  3. Which AI crawlers request a WordPress site, and what does each one control?
  4. robots.txt on WordPress: where does the file actually come from?
  5. Security plugins, host firewalls and CDNs: where do AI crawlers get blocked by accident?
  6. Rendering: is the answer in the HTML that WordPress sends?
  7. Caching and performance: does every crawler get a fast, current page?
  8. Structured data on WordPress: what should the markup say?
  9. llms.txt on WordPress: worth adding, not worth relying on
  10. Sitemaps, feeds and the REST API: how do machines discover WordPress content?
  11. What does a WordPress site have to publish to be cited?
  12. What sources do assistants cite for WordPress questions and WordPress-run businesses?
  13. How is AI retrievability checked on a WordPress site?
  14. How are results measured?
  15. What does a WordPress AEO engagement include?
  16. One service, several names: what do WordPress site owners search for?
  17. How much does AEO for WordPress cost?
  18. How long does AEO take on a WordPress site?
  19. How do you choose an AEO provider for a WordPress site?
  20. WordPress.com, WooCommerce, multisite and headless: where do the rules change?
  21. Related services

The short answerOn WordPress, AI visibility is often lost at the platform layer before content is ever judged. WordPress core blocks no AI crawler: the robots.txt it generates only keeps bots out of /wp-admin/. Blocks come from security plugins, host firewalls, CDN bot settings and old robots rules, and none of them is visible from a browser. The work is to confirm that OAI-SearchBot, Claude-SearchBot, PerplexityBot, Googlebot and Bingbot receive a 200 response with the full text in the HTML, keep one accurate schema graph, list every indexable template in the sitemap, and then run a fixed prompt set every month. We plan access and rendering fixes across the first two to four weeks; citations follow recrawling and are tracked, never guaranteed.

Crawler names, defaults and plugin features on this page were read from each vendor’s own documentation in October 2026 and can change without notice; the links go to the pages we read. Search volumes are Ubersuggest data for the United States, October 2026. Prices are Progression Agency’s published planning ranges; the figure for a given site is set in a written scope. No client, case study or measured outcome is described on this page.

What is AEO for WordPress?

AEO for WordPress is the platform half of answer engine optimization: making sure the software that sits between your content and a crawler (WordPress core, the theme, plugins, the page cache, the host and any CDN) lets AI assistants in and hands them the complete page a person would see. Answer engine optimization as a whole also covers what you write and who corroborates it; this page stays on the part that only applies when the site is built on WordPress.

An assistant can only cite what it can fetch and read. Before any judgment about quality, a request for one of your URLs has to pass a chain of WordPress-specific gates, and each gate is controlled by a different plugin, setting or vendor. Many WordPress sites have never had that chain checked from the outside, because every gate looks open from a logged-in browser.

What a request passes before a WordPress page can be citedWhat a request passes before a WordPress page can be cited
Editorial diagram of the WordPress request path. A failure at any step makes the steps after it irrelevant.

How it differs from WordPress SEO

WordPress SEO configures the site for Google and Bing rankings: the SEO plugin, permalinks, archives, Core Web Vitals and migrations. Our WordPress SEO services page covers that work and this page does not repeat it. The AEO layer adds three questions an SEO plugin does not ask: which AI user agents are being refused by something other than robots.txt, whether the answer text survives without JavaScript, and whether the facts an assistant would quote are stated once, as text, where a parser can find them.

The six control points

Six places on a WordPress site decide whether an assistant can use a page. They are worth naming because each has a different owner in most organizations: marketing owns the SEO plugin, a developer owns the theme, and the host or an IT contact owns the firewall.

robots.txt — Crawl permissions. Virtual file, plugin editor or CDN.
Firewall — Bot rules. Security plugin, host WAF, CDN.
Cache — What bots receive. Fresh, fast and the same HTML.
Rendering — Text in the HTML. Theme, blocks and builder output.
Schema — One graph. Matches the visible page.
Sitemap — Discovery. Every indexable template listed.

How do buyers and WordPress site owners phrase prompts to AI assistants?

Two groups ask assistants questions that a WordPress site has to be ready for. Your customers ask about what you sell, in full sentences with constraints attached. Site owners and their developers ask about the platform itself, usually after noticing that a competitor is named in an answer and they are not.

Prompt types a WordPress site has to answer, and the page that answers them
Who is askingExample promptsWordPress page type that answersWhat has to be true on the platform
A buyer comparing providers“who does commercial roof repair in Tulsa and what does it cost”; “best payroll software for a 12-person company”Service or product pages, one topic per URLThe page returns 200 to AI crawlers; price, area and scope are text in the HTML
A buyer checking you out“is [company] legit”; “what is [company]’s refund policy”; “who founded [company]”About, policy and author pagesOrganization schema agrees with the visible page; policies are pages, not PDFs
A buyer asking how“how do I descale a tankless water heater”; “what documents do I need to form an LLC in New York”Posts and guides with question headingsThe answer sits in the first sentences under the heading, not behind a tab script
A shopper on a WooCommerce store“waterproof hiking boots under $150 in wide sizes”; “does [store] ship to Canada”Product, category and shipping pagesProduct markup and visible price agree; stock and variations are in the HTML
A site owner“why is my WordPress site not showing up in ChatGPT”; “how do I add llms.txt to WordPress”; “does my security plugin block GPTBot”Your documentation, if you sell to WordPress usersExact settings, file paths and version numbers stated plainly
A developer“WordPress robots_txt filter example”; “block AI crawlers on WordPress but allow ChatGPT search”Technical posts and changelogsCode is in the page as text, dated, with the WordPress version named

Measured search demand for the platform questions is small, and it is phrased around tools instead of outcomes. Site owners look for a plugin; what they need is a check of the whole chain.

How WordPress site owners search for AI visibility helpHow WordPress site owners search for AI visibility help
US monthly searches and cost per click, Ubersuggest, October 2026. Service phrases such as “aeo for wordpress” have no measured volume yet.

What these prompts have in common

None of them is a keyword. Each describes a situation, and the assistant assembles its reply from several sources at once. A WordPress site earns a place in that reply by stating specific facts (a price range, a service area, a version number, a policy) in a form that can be lifted out as a sentence. Our guide to ranking in ChatGPT explains how answers are assembled; the sections below cover what WordPress has to do so your pages are candidates at all.

Which AI crawlers request a WordPress site, and what does each one control?

Each assistant vendor documents its own user agents, and most run more than one: a crawler that builds a search index, a crawler that collects training data, and a fetcher that runs when a user asks about a specific page. They are separate decisions, and a WordPress site can allow one and refuse another.

AI user agents as described by their operators, October 2026
User agentOperatorWhat the operator says it is forWhat refusing it does
OAI-SearchBotOpenAISurfacing websites in ChatGPT’s search featuresThe site is not shown in ChatGPT search answers, though it can still appear as a navigational link
GPTBotOpenAICrawling content that may be used to train OpenAI’s foundation modelsSignals that content should stay out of training; independent of search
ChatGPT-UserOpenAIVisiting a page when a ChatGPT user or a custom GPT asks for itOpenAI notes robots.txt rules may not apply, because a person started the request
ClaudeBotAnthropicCollecting web content that could contribute to model trainingFuture material is left out of training datasets
Claude-SearchBotAnthropicIndexing content to improve search results for Claude usersLower visibility and accuracy in Claude’s search results
Claude-UserAnthropicFetching a page when a Claude user asks a questionClaude cannot retrieve the page for that user
PerplexityBotPerplexitySurfacing and linking websites in Perplexity results; not used for foundation-model trainingPerplexity recommends allowing it so the site can appear in its results
Perplexity-UserPerplexityVisiting a page to answer a user’s questionPerplexity says this fetcher generally ignores robots.txt
GooglebotGoogleGoogle Search, which includes AI Overviews and AI ModeThe page cannot be indexed, so it cannot be a supporting link
Google-ExtendedGoogleA robots.txt token, not a separate crawler: governs Gemini training and grounding in Gemini apps and Vertex AINo effect on inclusion or ranking in Google Search
BingbotMicrosoftBuilding Bing’s index; Microsoft publishes its crawler listPages leave Bing’s index
Applebot and Applebot-ExtendedAppleApplebot feeds search in Siri, Spotlight and Safari; Applebot-Extended is a token that opts content out of Apple model training and does not crawlRefusing Applebot keeps content out of those search features
DuckAssistBotDuckDuckGoReal-time crawling for AI-assisted answers; not used for trainingNo effect on DuckDuckGo’s organic results
MistralAI-User and MistralAI-IndexMistralUser-requested page visits and search indexing for Mistral’s assistantPages are not fetched or indexed by Mistral

Search, training and user-triggered fetches are three decisions

OpenAI states that its settings are independent: a site can allow OAI-SearchBot so that it appears in ChatGPT search while disallowing GPTBot to keep content out of training. Anthropic and Apple draw the same line with their own tokens. For a business that sells something, the search crawlers are the ones to allow without hesitation; the training crawlers are a rights decision that belongs to whoever owns the content. Our LLM SEO page walks through that decision and the audit around it.

Why the firewall matters as much as robots.txt for these bots

The vendors’ own documentation points at the firewall. OpenAI recommends allowing OAI-SearchBot in robots.txt and also allowing requests from its published IP ranges. Perplexity publishes allow-rule instructions for Cloudflare and AWS firewalls that combine the user agent with its IP list. Anthropic warns that blocking its IP addresses is not a reliable opt-out, because it stops the bots from reading robots.txt in the first place, and says its bots will not try to get past a CAPTCHA. On WordPress, where security plugins and CDN bot settings are common, this is where access is often lost.

OAI-SearchBot — ChatGPT search. Allow to be shown in answers.
GPTBot — OpenAI training. A separate decision.
Claude-SearchBot — Claude search. Indexing for search results.
PerplexityBot — Perplexity. Surfaces and links sites.
Googlebot — AI Overviews and AI Mode. Indexed and snippet-eligible.
Bingbot — Bing index. Listed by Microsoft.

Want to know what AI crawlers receive from your WordPress site?Send the URL, the host and the security and caching plugins you run. You get the status codes the documented AI crawlers receive today and the first three fixes, in writing.

Request the access check

robots.txt on WordPress: where does the file actually come from?

On a default WordPress install there is no robots.txt file on disk. WordPress generates one on request, and at least four other things can change what a crawler finally receives. Knowing which one is in control is the first job, because editing the wrong one changes nothing.

WordPress core answers a request for /robots.txt with the do_robots() function, which outputs one group for all user agents that disallows /wp-admin/ and allows /wp-admin/admin-ajax.php; since version 5.5 the output also points to the core sitemap. That default names no AI crawler and blocks none. Plugins alter the output through the robots_txt filter, and the whole mechanism only runs when WordPress sits in the site root and no physical file exists.

Five places a WordPress robots rule can come from

  • WordPress core. The generated default described above: safe, and silent about AI crawlers.
  • An SEO plugin. Yoast SEO and Rank Math each provide a robots.txt editor in the dashboard; Rank Math’s edits the virtual file and asks you to delete any physical file first.
  • A physical file. A robots.txt uploaded to the web root, often years ago by a previous developer, is served in place of the generated one.
  • The hosting platform. On WordPress.com, the Prevent third-party sharing setting adds known AI bots to the disallow list.
  • The CDN. Cloudflare’s managed robots.txt places its own rules, including disallow groups for named AI crawlers, ahead of whatever the origin serves.

The only version that counts is the one a crawler receives at your public /robots.txt address. Fetch it from outside the site, not from a dashboard preview, and read it top to bottom. The format is standardized as RFC 9309: a crawler obeys the group that names it and falls back to the wildcard group only when none does, so a short allow group for one bot is not cancelled by a broad rule elsewhere in the file.

A pattern that separates search from training

A WordPress site that wants to be cited but does not want its content used for model training can say so in a few lines. The choice is a business decision; the syntax is simple.

  • Name OAI-SearchBot, Claude-SearchBot and PerplexityBot in their own groups with Allow: /.
  • Name GPTBot and ClaudeBot with Disallow: / if training use is not wanted, and treat Google-Extended and Applebot-Extended the same way.
  • Keep the wildcard group for all other agents, including the /wp-admin/ rule and the admin-ajax exception that themes and plugins rely on.
  • Keep the Sitemap line, and make sure it points to the sitemap index the site really serves.
  • Repeat the file on every subdomain; Anthropic’s documentation notes that an opt-out has to be made per subdomain.
  • Allow time: OpenAI says its search systems can take about 24 hours to adjust after a robots.txt change.

The “Discourage search engines” checkbox

Settings, Reading contains one box that can undo everything else. According to the WordPress documentation for the Reading screen, since version 5.3 it adds a noindex, nofollow robots meta tag to every page instead of a robots.txt rule; the robots API introduced in 5.7 keeps that behavior. Leaving the box ticked after a staging site goes live is a common launch-day mistake. A noindexed page leaves Google’s index, and Google states that a page must be indexed and eligible for a snippet before it can be a supporting link in AI Overviews or AI Mode.

Security plugins, host firewalls and CDNs: where do AI crawlers get blocked by accident?

A robots.txt rule is a request; a firewall rule is a locked door. On WordPress the door is typically locked by a security plugin, a managed host’s bot protection or a CDN setting that someone enabled to stop scrapers, and the lock applies to the AI search crawlers you want as well.

Where an AI crawler can be refused on a WordPress stack
LayerTypical componentHow it refuses an AI crawlerHow to check
CDNCloudflare or a CDN bundled by the hostAI bot blocking, bot-fight features, managed challengesRead the bot settings; request a page with the bot’s user agent from outside
HostManaged WordPress host firewallBlocks or rate-limits unfamiliar user agents and data-center IP rangesAsk the host which bot rules apply; read access logs for 403 and 429 responses
Security pluginFirewall and rate-limiting pluginsThrottles fast crawlers; blocks by user agent, country or IP reputationReview the plugin’s blocked-request log for AI user agents
Web serverApache or Nginx rules, .htaccessOld deny rules for “bad bots” copied from a tutorialSearch the configuration for user-agent conditions
WordPressMaintenance-mode, coming-soon and membership pluginsReturns 503 or a login page to any visitor without a sessionOpen the URL in a private window
robots.txtAny of the five sources aboveDisallow rules, which the documented search and training crawlers honorFetch the public file

Cloudflare’s AI bot settings

Cloudflare sorts AI traffic into three behaviors: Search, Agent and Training. Each can be allowed, blocked everywhere or blocked only on pages that show ads. Its documentation states that from September 15, 2026 new domains default to blocking Training and Agent bots on pages that display ads while Search stays allowed, and that crawlers used for both search and training are caught by every option that blocks training. If your WordPress site moved onto Cloudflare recently, or someone once switched on the older “Block AI bots” option, check which crawlers are affected. AI Crawl Control shows which AI services are requesting the site and lets you set a rule per crawler.

Bot challenges

Cloudflare’s Bot Fight Mode issues computationally expensive challenges to traffic it identifies as automated and, according to its documentation, cannot be adjusted with custom firewall rules. A challenge page is not your content. To a crawler it reads as an empty or irrelevant document, and Anthropic’s documentation is explicit that its bots do not attempt to pass CAPTCHAs.

Rate limits

Security plugins and hosts throttle clients that request many pages quickly, and a crawler that keeps receiving 429 or 503 responses gets little of the site. Anthropic’s bots support the Crawl-delay directive, which is a gentler tool than a block when server load is the real worry, and a page cache in front of WordPress removes most of the load problem at its source.

What a blocked crawler looks like from outside

Everything works in a browser. The home page loads, the SEO plugin shows green lights, and robots.txt looks permissive. The only evidence is in the logs: requests from an AI user agent answered with 403, 429, 503 or a challenge page. A test request that copies a bot’s user agent string is a useful first pass, but it does not come from the vendor’s IP ranges, so a pass is not proof. The access log is. Our free AI crawler access checker runs the first pass, and our technical SEO team reads the logs.

Rendering: is the answer in the HTML that WordPress sends?

WordPress builds pages on the server in PHP, which is good news: by default the text is in the HTML response. The exceptions are the parts of a page that a plugin or builder loads with JavaScript after the page arrives, and those are often the parts that hold the answer.

Googlebot renders JavaScript in a second pass, as its JavaScript SEO documentation describes. The crawler documentation from OpenAI, Anthropic and Perplexity explains what each bot is for and how to control it, and none of it promises to run a page’s scripts. Apple says Applebot may render pages and still advises that a site degrade gracefully when resources are unavailable. The safe working assumption is that the HTML response is all an assistant gets.

Blocks: static and dynamic

In the block editor, a static block saves its HTML into the database and a dynamic block is rendered by PHP on each request. Both arrive as HTML. Core’s Interactivity API, part of WordPress since 6.5 and used by the Search, Query, Navigation and File blocks, adds behavior on top of server-rendered markup instead of replacing it. A site built with core blocks and a block theme is, in rendering terms, about as safe as WordPress gets.

Page builders and bloat

Elementor, Divi, WPBakery and similar builders also output server-rendered HTML, so text placed in a standard text or heading widget is present in the response. The cost is weight: deep wrapper nesting and large stylesheets and scripts on every page, which slow the response a crawler is waiting for. The risk sits in particular widgets: tabs and accordions that fetch their panels on click, post grids with a “load more” button, sliders that hold the only copy of a headline, and reviews pulled in by a third-party script.

Where WordPress content goes missing

  • Prices or specifications held in an image, a PDF or a slider.
  • FAQ answers loaded by an accordion script, when the native Details block would keep the text in the HTML.
  • Reviews and testimonials injected by a widget hosted on another domain.
  • Product filters and post grids that swap their content through AJAX.
  • Text inside an embedded iframe: maps, booking tools, forms and catalogs.
  • Content shown only after a cookie banner or location prompt is answered.
  • Pages behind a membership or login plugin.
  • A headless front end that renders in the browser; our headless WordPress guide covers that case.

How to test a template

Request the URL without a browser, or open the page source instead of the inspector, and search for one sentence from each important section. Test one URL per template, not one page: a post, a page, a service or other custom post type, a category archive, a product and the home page. If the sentence is in the source, the template passes. If it only appears in the inspector, a script put it there.

Already have an SEO plugin and a retainer?Ask for a second opinion on the AI side. We test crawler access, rendering and schema and tell you what your current setup already covers.

Get a second opinion

Caching and performance: does every crawler get a fast, current page?

A page cache is the most useful performance layer on WordPress, and it changes what crawlers receive: a stored copy in place of a freshly built page. That is fine when the copy is current and complete, and a problem when it is not.

The WordPress caching documentation describes how plugins such as W3 Total Cache, WP Super Cache and Cache Enabler store posts and pages as static files so the server does far less work per request. Speed matters for AI retrieval because a fetch made while a person waits for an answer has little patience for a slow origin.

Stale copies

A cached page that still shows last season’s price, a closed location or an expired offer will be quoted as though it were current. Purge rules need to cover every page that depends on a changed fact: the service page when a price changes, category archives when a post is published, the home page when opening hours change.

Script-delay features

Optimization plugins can postpone JavaScript until a visitor scrolls or taps. A crawler does neither, so anything those scripts would have added (a pricing table, reviews, a tabbed specification) never exists for it. The fix is to move that content into the HTML, not to switch the optimization off.

Different pages for different visitors

Caches vary their output by cookie, device and sometimes user agent. Confirm that a crawler receives the same content as a first-time human visitor, and that a mobile variant does not drop sections the desktop page keeps.

Uncached pages deserve a look too: internal search results, filtered archives and cart pages are built fresh each time and are often slow. Keep crawlers out of them with robots rules and keep the cache warm on the pages that matter. Website speed optimization and a sound WordPress hosting setup do most of this work; website maintenance keeps it from drifting.

Structured data on WordPress: what should the markup say?

Structured data helps a machine confirm what a page is about and who published it; it does not replace the visible text. Google’s guide to optimizing for generative AI features says structured data is not required for generative AI search and that no special markup exists for it, while still recommending it as normal practice and asking that it match what the page shows.

On WordPress the markup usually comes from the SEO plugin. Yoast documents its schema output as one connected graph that other plugins can extend, and WooCommerce outputs product structured data automatically as JSON-LD on single product pages. Trouble starts when a theme, a review plugin and an SEO plugin each describe the same page differently. The WordPress SEO page covers removing duplicate graphs; the table below covers what the surviving graph should carry for assistants.

Facts the schema graph should carry, by WordPress page type
Page typeschema.org typeFacts worth statingWhere WordPress holds them
Home and AboutOrganization or a LocalBusiness subtypeLegal name, logo, address, phone, sameAs profiles, founding dateSEO plugin site settings
Posts and guidesArticleHeadline, author with a profile page, published and modified datesPost fields and the author’s user profile
Service pagesServiceService name, area served, provider, price range where one is publishedSEO plugin schema tab or a custom field
WooCommerce productsProduct with OfferName, price, currency, availability, SKU, brand, ratingProduct data panel and attributes
Question sectionsFAQPageEach question with its full answer, identical to the visible textThe SEO plugin’s FAQ block, or a custom block
Every pageBreadcrumbList and WebPagePosition in the site and the page’s primary topicGenerated by the SEO plugin

FAQ markup after Google retired the FAQ rich result

Google’s Search documentation changelog records that the FAQ rich result stopped appearing in Google Search on May 7, 2026 and that its documentation was removed the following month. FAQPage remains valid schema.org vocabulary, and a clearly marked question with its answer is still easy for any parser to lift. Add it because the page contains real questions, not in expectation of a search feature.

Check the markup against the page

Run important templates through the Schema.org validator and compare every value with the visible copy. Prices, opening hours, ratings and dates are where WordPress sites drift, because the visible figure is edited in the page and the marked-up one lives in a plugin setting. Our schema and copy validator automates that comparison, and the FAQ schema generator writes clean markup for hand-built sections.

llms.txt on WordPress: worth adding, not worth relying on

llms.txt is a proposed convention: a Markdown file at /llms.txt that gives language models a short description of a site and links to its most useful pages, ideally to clean Markdown versions of them. WordPress plugins can generate it with one switch. It is cheap to add and should not be mistaken for the work.

Which WordPress plugins generate it

Yoast SEO generates an llms.txt file as a free feature that selects key content automatically or lets you choose it. Rank Math has an LLMS Txt module that lists chosen post types with titles, URLs and short descriptions, and its own documentation notes that llms.txt is a proposal with limited adoption so far. To write the file by hand, our llms.txt generator produces one to upload.

What to list in a WordPress llms.txt

  • The pages that define what the business does: services, products and pricing.
  • The policies an assistant gets asked about: returns, shipping, warranties, service areas.
  • The strongest guides and documentation, not every post in the archive.
  • About and contact pages, so the business is described in your own words.
  • Nothing that is noindexed, gated or thin.

What Google says about it

Google’s generative AI guide lists llms.txt among the things site owners can ignore for Google Search: the file neither helps nor harms visibility there, and Google adds that it is fine to maintain one for other systems that read it. That is the right weight to give it. Switch it on, keep it accurate, and spend the effort on access, rendering and content.

Sitemaps, feeds and the REST API: how do machines discover WordPress content?

Discovery is the quiet half of retrieval: a crawler has to learn that a URL exists before it can fetch it. WordPress ships three machine-readable routes to its content, and each deserves a short review.

WordPress core facts that matter for AI retrievalWordPress core facts that matter for AI retrieval
Sources: make.wordpress.org core notes for 5.5 and 5.7; developer.wordpress.org and make.wordpress.org/ai for the Interactivity API and Abilities API.

XML sitemaps

Since version 5.5, WordPress core has published a sitemap index at /wp-sitemap.xml covering public post types, taxonomies, author archives and the home page, with up to 2,000 URLs per sitemap by default, and has referenced it from the generated robots.txt. SEO plugins such as Yoast SEO and Rank Math supply their own sitemaps instead. Whichever is active should list every indexable template and nothing that is noindexed, redirected or thin. The format is defined by the sitemaps.org protocol.

IndexNow

IndexNow lets a site notify participating search engines the moment a URL changes. The IndexNow plugin for WordPress, built by the Bing Webmaster team, submits new, updated and deleted URLs automatically and respects noindex settings. For assistants that answer from a search index, faster indexing shortens the gap between an edit and a correct answer.

Feeds and the REST API

WordPress exposes posts through RSS feeds and through the REST API, which serves public content as JSON and keeps private content behind authentication. Neither is a visibility lever in itself. They matter for two reasons: a security plugin that disables them can break legitimate integrations, and an API left at its defaults can list details you never meant to publish. Review both on purpose instead of by accident.

What does a WordPress site have to publish to be cited?

Once crawlers can reach and read the site, citations go to pages that state specific facts plainly. WordPress gives you good tools for that, and a few habits that work against it.

Answer box — First two sentences. Under every question heading.
Table block — Comparisons. An HTML table, never an image.
Details block — FAQs. Text stays in the HTML.
Author page — Who wrote it. Credentials and profile links.
Service page — One topic per URL. Price, area and process.
Updated line — Dated facts. Changes with real edits only.
  • One topic per URL: a page for each service, product line or location, built as Pages or a custom post type instead of sections of one long page.
  • Question headings with the answer in the first two sentences beneath them.
  • Prices, ranges, turnaround times and service areas as text, with the date they were last checked.
  • Comparisons in the Table block, which outputs an HTML table; never a screenshot of a spreadsheet.
  • FAQs in the Details block or under plain headings, so the text is in the response.
  • An author page for each named writer, with credentials and links to profiles elsewhere.
  • A real About page: who owns the business, where it operates and how to reach it.
  • Policies as pages: returns, guarantees, cancellations and privacy.
  • Links to primary sources for every figure you did not measure yourself.
  • An honest “last updated” line that changes only when the content does.

The writing rules themselves are the same on any platform, and AEO content writing sets them out. What is particular to WordPress is where structure leaks away: tag and date archives that duplicate posts, builder sections that bury a heading inside a slider, and reusable blocks that paste the same paragraph onto thirty pages.

Prefer numbers before a call?AEO planning ranges are published on this site. Ask for the band that fits your template count and we will scope against it.

See AEO pricing

What sources do assistants cite for WordPress questions and WordPress-run businesses?

Assistants rarely answer from one page. For questions about WordPress itself they lean on official documentation and long-standing community sources; for questions about a business that happens to run on WordPress they combine the site with third-party profiles that confirm it. The table lists where to be present and accurate. It describes tendencies, not measured shares.

Source types assistants draw on, and what to do about each
Source typeExamplesWhat a WordPress site owner should do
Official documentationWordPress.org documentation, developer.wordpress.org, make.wordpress.org release notesCite it in your own technical content; match its terminology and version numbers
Plugin and theme listingsWordPress.org plugin directory pages, their reviews and support threads; vendor knowledge basesIf you publish a plugin or theme, keep the readme, changelog and FAQ complete and current
Developer communitiesWordPress Stack Exchange, GitHub issues, r/WordPress, the WordPress.org support forumsAnswer questions in your field under a consistent name; link to documentation, not sales pages
Search engine documentationGoogle Search Central, Bing Webmaster guidelinesFollow it, and link to it when you explain a technical choice
Business profilesGoogle Business Profile, Bing Places, industry directories, the Better Business BureauKeep name, address, phone, hours and services identical to the site
Review platformsGoogle reviews, Trustpilot, G2 or Clutch for B2B firms, category-specific sitesRun a steady, honest review request process and reply to what is written
PublishersTrade press, local news, WordPress news sitesEarn coverage with data or expertise; a quoted expert is a corroborated entity
Your own siteService, pricing, policy, author and guide pagesMake them reachable, complete and specific, as described above

Corroboration is slower than configuration and no plugin automates it. Local AEO covers the profile side for businesses with a service area, and AEO for small business covers what an owner can do before spending anything.

How is AI retrievability checked on a WordPress site?

With requests, logs and source code, not with a plugin score. The checks below take about a working day on a typical business site and produce evidence a developer can act on.

  1. Fetch the public /robots.txt and identify which of the five sources produced it.
  2. Request the home page and one URL per template with each documented AI user agent; record the status code and response size.
  3. Pull 30 to 90 days of access logs from the host and filter for the AI user agents: which arrived, what they requested and what they were served.
  4. Compare the IP addresses of those requests with the ranges OpenAI, Anthropic and Perplexity publish, to separate real crawlers from imitators.
  5. Review CDN and security plugin settings for AI bot blocking, bot challenges and rate limits.
  6. Open the source of each template and search for the sentences that carry the answer.
  7. Load the same URLs as a first-time visitor and as a crawler, and compare the cached output.
  8. Validate the structured data on each template and compare it with the visible copy.
  9. Open the sitemap index and compare its URLs with the pages that should be indexed.
  10. If /llms.txt exists, confirm it is current and that every link in it resolves.
  11. Confirm indexing of the same templates in Google Search Console and Bing Webmaster Tools.
Retrievability on a WordPress site: states to aim for and to avoidRetrievability on a WordPress site: states to aim for and to avoid
Editorial scorecard: target states and failure states, not a measurement of any particular site.

We run this as a fixed-scope AEO audit; the AI visibility audit adds the prompt-set baseline, and a full SEO audit covers the ranking side of the same site.

How are results measured?

In two layers that move at different speeds. Technical measures (crawler requests, status codes, render completeness) change within days of a fix and are certain. Visibility measures (whether an assistant names or links you) change over weeks and are probabilistic, because answers vary from one run to the next.

Measures for a WordPress AEO program
MeasureWhere it comes fromWhat it showsCaveat
AI crawler requestsHost access logs or the CDN’s AI crawler reportWhich documented bots reached which URLs, and the response each receivedCounts crawling, not citation
Template pass rateSource-code tests per templateShare of key templates whose answer text is in the HTMLRe-test after every theme or plugin update
Prompt-set mentionsA fixed list of buyer prompts run monthly in ChatGPT, Claude, Perplexity, Gemini and CopilotHow often the business is named, and who is named insteadAnswers vary by run; record several runs and the date
CitationsThe same prompt setHow often an answer links one of your URLs, and which oneA mention without a link still counts as visibility
Google AI featuresSearch Console, including the Generative AI performance report that Google’s guide describesAppearances in AI Overviews and AI ModeGoogle reports on Google surfaces only
Assistant referralsAnalytics sessions whose referrer is an assistant’s domainVisits that arrived from a cited linkUnder-counts, since many answers are read without a click
InquiriesForm plugin entries, call tracking, the CRMLeads that say an assistant sent themAdd “How did you hear about us?” to the form

Be wary of any WordPress plugin or dashboard that reports a single “AI visibility score”. Google’s guide points out that no third-party tool has access to its internal systems, and the same is true of every other assistant. Our free AI visibility checker runs a first prompt test, the prompt builder helps write the set, and our comparison of AI visibility trackers covers the paid tools.

What does a WordPress AEO engagement include?

An audit that proves what crawlers receive, fixes made inside the WordPress installation you already have, content and schema work on the pages most likely to be cited, and monthly measurement. The scope is written down before work starts.

The audit

  • Crawler access report: status codes per AI user agent, per template, with log evidence.
  • Render report: what each template contains without JavaScript.
  • Schema reconciliation: every marked-up value compared with the visible page.
  • Discovery review: sitemap, robots.txt source, llms.txt, indexing status.
  • Prompt-set baseline: the buyer prompts, who is named today and which sources are cited.

Fixes inside WordPress

  • robots.txt rewritten at its real source, with search and training crawlers handled separately.
  • Firewall, CDN and security plugin rules adjusted so documented AI search crawlers are allowed.
  • Cache purge rules and script-delay exclusions set for pages that carry changing facts.
  • Script-loaded content rebuilt with blocks or server-side templates.
  • One schema graph, with duplicates from themes and add-on plugins switched off.

Content and corroboration

  • Priority service, product and policy pages restructured so each section answers its heading first.
  • New pages where a prompt has no page to cite: pricing, comparisons, service areas.
  • Author, About and contact pages completed.
  • Business profiles and directory listings corrected to match the site.

Monitoring

The prompt set is repeated every month, crawler logs are re-read, and templates are re-tested after theme and plugin updates, since an update can quietly undo a fix. Where development work is larger than a fix, our WordPress development team takes it on, and a WordPress maintenance plan keeps the stack patched in between.

Want to know what AI crawlers get from your WordPress site?

Send the URL, the host and the security and caching plugins you run. We reply with what the documented AI crawlers receive today and the first fixes we would make.

Request the access check

One service, several names: what do WordPress site owners search for?

The work on this page is sold as AEO, GEO, AI SEO, LLM SEO and half a dozen other labels, and they overlap almost entirely. If you arrived by searching one of the phrases below, this is the page for it.

Names for the same service, as WordPress site owners search for them
LabelAs searchedWhat the label stresses
AEO, answer engine optimizationAEO for WordPress; answer engine optimization for WordPressBecoming the source an assistant quotes when it answers
GEO, generative engine optimizationGEO for WordPress; generative engine optimization for WordPressThe same work, named after the generative models behind the assistants
AI SEOAI SEO for WordPressAI answers treated as an extension of search, which is how Google describes them
AI search optimizationAI search optimization for WordPress; AI search for WordPressGoogle’s AI Overviews and AI Mode alongside the chat assistants
LLM SEO, LLM optimizationLLM SEO for WordPress; LLM optimization for WordPressThe technical side: crawler access, rendering and extraction
AI visibilityAI visibility for WordPress; WordPress AI visibilityThe measurement: how often you are named and linked
ChatGPT optimization, ChatGPT SEOChatGPT optimization for WordPress; ChatGPT SEO for WordPress; WordPress ChatGPT visibility; get found in ChatGPT, WordPress editionOne assistant, usually the first one a client checks
AI Overviews and Perplexity optimizationAI Overviews optimization for WordPress; Perplexity optimization for WordPressRequests aimed at a single answer surface
Conversational search optimizationConversational search optimization for WordPressThe older voice-search name for the same retrievability work

AEO vs GEO vs LLM SEO explains where the terms differ; our generative engine optimization page and our AI SEO agency page describe the same team from those angles.

Want to know what AI crawlers receive from your WordPress site?Send the URL, the host and the security and caching plugins you run. You get the status codes the documented AI crawlers receive today and the first three fixes, in writing.

Request the access check

How much does AEO for WordPress cost?

Most WordPress AEO work is priced as a one-off audit followed by a short fix project or a monthly retainer. The figures below are the planning ranges Progression Agency publishes; a quote follows a written scope, and the number moves with template count, how much is rendered by scripts, and how many plugins touch the same output.

Planning ranges for AEO on a WordPress site, in US dollars
EngagementPlanning rangeWhat it covers on a WordPress site
AEO audit$1,000–$4,000 one-offCrawler access, rendering, schema and sitemap checks across templates, with a prioritized fix list; about a working week
AEO strategy$1,500–$6,000 one-offPrompt set, page plan and corroboration plan built from the audit
Schema implementation$400–$1,200 one-offOrganization, Service, FAQ and Breadcrumb markup reconciled across templates
Small-business AEO retainer$1,500–$5,000 per monthFixes, 5 to 15 pages restructured or written, basic monitoring
Mid-market AEO retainer$5,000–$10,000 per monthTracking across assistants, wider restructuring, strategy sessions every two weeks
Enterprise AEO retainer$10,000–$20,000+ per monthFull-site work across many templates or a multisite network, custom reporting
Rendering and restructure project$25,000–$100,000For sites whose templates must be rebuilt so that content is server-rendered
WordPress maintenance alongside$100–$500 per month for most business sites; $500–$2,000 for stores and high-traffic sitesUpdates, backups and monitoring that stop fixes from regressing

Tracking tools are a separate and smaller line: the AI visibility trackers we have verified list at $20 to $295 a month. AEO pricing breaks the bands down, and the marketing agency pricing guide sets them beside other services.

How long does AEO take on a WordPress site?

Access and rendering fixes are quick; citations are not instant. We plan the technical work across the first month and judge visibility at about ninety days, against a baseline taken before anything changes.

A WordPress AEO engagement, first ninety daysA WordPress AEO engagement, first ninety days
Planning sequence for a typical business site on WordPress.

Some of the waiting is set by the vendors. OpenAI says its search systems can take roughly a day to act on a robots.txt change. Google’s AI features documentation says recrawling can take anywhere from several days to several months, depending on the page. Nothing shortens those waits except starting them early, which is why crawler access is fixed before any content is rewritten. How long AEO takes goes through the stages in more detail.

How do you choose an AEO provider for a WordPress site?

Ask for evidence, WordPress-specific answers and a written scope. A provider who cannot say where your robots.txt comes from has not looked at your site.

Requirements for a WordPress AEO provider, and how to check each
RequirementHow to check it
They test crawler access from outsideAsk for status codes per AI user agent on your own URLs, with dates
They read server logsAsk which log source they will use on your host and what they will filter for
They know the WordPress stackAsk where your robots.txt is generated, which plugin outputs your schema and what your cache serves to bots
They test templates, not single pagesAsk for the list of templates and the source-code result for each
They separate search crawlers from training crawlersAsk which user agents they would allow and which they would leave to you
They do not sell a plugin as the answerAsk what they would do if no new plugin could be installed
They measure with a fixed prompt setAsk to see the prompts before work starts, and keep a copy
They make no ranking or citation guaranteesRead the proposal for promises about specific assistants
They leave you in controlConfirm that accounts, content and configuration stay yours and that every change is documented

WordPress.com, WooCommerce, multisite and headless: where do the rules change?

The checks above assume a self-hosted WordPress site with a conventional theme. Four common setups move the gates to a different owner.

WordPress.com

On WordPress.com the hosting, caching and firewall belong to the platform. The setting to know is Prevent third-party sharing: WordPress.com says ticking it removes the site from its network of content partners and adds known AI bots to the robots.txt disallow list. A business that wants to be cited should understand that this box asks AI crawlers to stay away.

WooCommerce stores

WooCommerce prints product markup on single product pages by default, and its documentation is clear that marked-up data should already be visible on the page. For AI shopping answers the product record matters as much as the page: complete attributes, variation data, stock status and identifiers. Google’s generative AI guide points merchants to Merchant Center feeds for product visibility in AI responses. Shopify vs WooCommerce compares the two platforms, WooCommerce hosting covers performance, and AEO for ecommerce covers product data in depth.

Multisite and subdomains

Each site in a network, and each subdomain, answers for its own robots.txt, sitemap and schema. Rules set on the main site do not cover blog.example.com or shop.example.com, and a network-activated security plugin can block crawlers everywhere at once.

Headless WordPress

When WordPress only supplies content through its API and a JavaScript framework builds the pages, rendering stops being WordPress’s job. The front end has to render on the server, and it has to produce its own robots.txt, sitemap and structured data.

AI agents inside WordPress

A separate development is worth knowing about. WordPress 6.9 introduced the Abilities API, a registry of what a site can do, and the WordPress AI team’s MCP Adapter exposes selected abilities to assistants such as Claude and ChatGPT as tools. That concerns assistants operating a site with permission, not being cited by one, and it does not change the retrieval work on this page. It does show that WordPress is being prepared for agents as well as crawlers.

Pages that sit beside this one, starting with its SEO twin.

Frequently asked questions

What does AEO for WordPress involve?
It involves checking and fixing the WordPress layers that decide whether AI assistants can use your pages: robots.txt, firewall and CDN bot rules, caching, server-side rendering, structured data and sitemaps. Key pages are then restructured so answers are stated plainly, and a fixed set of buyer prompts is measured each month. The same service is sold as GEO, AI SEO or LLM SEO for WordPress.
Does WordPress block AI crawlers such as GPTBot by default?
No. The robots.txt that WordPress core generates has one group for all user agents, which disallows /wp-admin/ and allows admin-ajax.php. It neither names nor blocks any AI crawler. Blocks come from other layers: a security plugin, a host firewall, a CDN bot setting, an old physical robots.txt file, or the Prevent third-party sharing option on WordPress.com.
How do I let ChatGPT search read my WordPress site without allowing model training?
Allow OAI-SearchBot and disallow GPTBot in robots.txt. OpenAI documents the two as independent: OAI-SearchBot decides whether a site can be shown in ChatGPT search answers, and GPTBot covers training. Edit the file through your SEO plugin or replace the physical file, confirm the public version changed, check that no firewall blocks OpenAI’s published IP ranges, and allow about 24 hours.
Where is the robots.txt file on a WordPress site?
Usually nowhere on disk. WordPress generates it on request through the do_robots() function unless a physical robots.txt exists in the web root, in which case the server sends that file. SEO plugins such as Yoast SEO and Rank Math edit the generated version from the dashboard, and a CDN such as Cloudflare can place its own rules ahead of it.
Should a WordPress site add an llms.txt file?
Yes, if it takes five minutes, and no, if it is the whole plan. Yoast SEO and Rank Math can both generate one. The file is a proposal that some AI systems read, and Google states that its Search features ignore it, so it neither helps nor harms there. Crawler access, rendering and clear content decide far more.
Can AI assistants read pages built with Elementor, Divi or WPBakery?
Generally yes, because those builders output server-rendered HTML and text in standard widgets is present in the response. Problems come from specific widgets that load content with JavaScript after the page arrives, such as some tabs, load-more grids and third-party review embeds, and from page weight that slows the response. Test each template’s source for the sentences that matter.
Do caching plugins change what AI crawlers see on WordPress?
They can. A page cache serves crawlers a stored copy, so an outdated copy gets quoted as current, and features that delay JavaScript until a visitor interacts leave script-added content out for bots entirely. Set purge rules for pages whose facts change, move essential content into the HTML, and confirm that bots and first-time visitors receive the same page.
Does the Discourage search engines setting in WordPress affect AI answers?
Yes. Since WordPress 5.3 the setting adds a noindex, nofollow robots meta tag to every page. A noindexed page leaves Google’s index, and Google requires a page to be indexed and eligible for a snippet before it can appear as a supporting link in AI Overviews or AI Mode. The box is often left ticked after a launch, so check it first.
Is FAQ schema still worth adding on WordPress now that Google has removed FAQ rich results?
It is worth keeping where a page has real questions and answers, but not for a Google feature: Google’s changelog records that the FAQ rich result stopped appearing on May 7, 2026. FAQPage is still valid schema.org vocabulary, and clearly marked question and answer pairs are easy for any parser to extract. The markup has to match the visible text.
Does Cloudflare block AI bots on a WordPress site?
Only if its AI bot settings say so, and they may without your knowledge. Cloudflare sorts AI traffic into Search, Agent and Training and lets you allow or block each. Its documentation says new domains from September 15, 2026 default to blocking Training and Agent bots on pages with ads while Search stays allowed. Review those settings and Bot Fight Mode.
How can I tell whether ClaudeBot or PerplexityBot has visited my WordPress site?
Read the server access logs from your host and filter for the user agent names. Each request shows the URL and the status code returned. To rule out imitators, compare the request IP addresses with the ranges Anthropic and Perplexity publish. If the site is on Cloudflare, AI Crawl Control reports the same activity without log access.
Does a WooCommerce store need different AEO work from a brochure site?
The access and rendering checks are the same; the content is different. A store’s answers come from product data, so attributes, variations, stock, identifiers and policies have to be complete and visible, the product markup WooCommerce outputs has to match the page, and a Merchant Center feed is worth maintaining because Google points merchants to it for AI responses.
Is GEO for WordPress a different service from AEO for WordPress?
No. Generative engine optimization and answer engine optimization describe the same work on a WordPress site: letting documented AI crawlers in, making sure answers are in the HTML, keeping schema accurate and measuring which prompts name you. Agencies and tool vendors chose different labels. Google’s own guidance treats all of it as part of search optimization.
What is the price range for AEO work on a WordPress site?
As planning ranges, an AEO audit costs $1,000 to $4,000, schema implementation $400 to $1,200, and a monthly retainer $1,500 to $5,000 for a small business, $5,000 to $10,000 for a mid-market site and $10,000 to $20,000 or more at enterprise scale. A template rebuild for rendering is a separate project. Quotes follow a written scope.
How long does AEO take to show results on a WordPress site?
Access and rendering fixes usually ship within the first month, and their effect on crawler logs is visible within days. Being named in answers takes longer, because it depends on recrawling and on how each assistant assembles its answers. We take a prompt-set baseline first and judge change at about ninety days, without promising a specific citation.
Will changing my WordPress theme affect AI visibility?
It can, in either direction. A theme controls heading structure, how much content is rendered by scripts, page weight and sometimes its own schema output. Before switching, test the new templates’ source for your key sentences, validate the structured data and keep URLs unchanged. After launch, re-run the crawler access and template checks, since theme updates can undo earlier fixes.
Does a headless WordPress site need different AEO work?
Yes. In a headless build WordPress supplies content through its API and a separate front end builds the pages, so rendering, robots.txt, sitemaps and structured data become the front end’s responsibility. Pages must be rendered on the server so the text is in the HTML response. The checks are the same; the place where they are fixed moves.
Can a WordPress.com site control which AI crawlers visit?
Partly. WordPress.com offers a Prevent third-party sharing option in its privacy settings. According to its support documentation, enabling it excludes the site from WordPress.com’s content partners and adds known AI bots to the robots.txt disallow list. A business that wants AI citations should know that this box asks those crawlers to stay away.
What is the WordPress Abilities API, and does it matter for AEO?
The Abilities API, introduced in WordPress 6.9, is a registry that describes what a site can do so that tools and AI agents can discover those functions; an MCP Adapter exposes chosen abilities to assistants such as Claude and ChatGPT. It concerns agents operating a site with permission. It does not affect whether your pages are crawled or cited.
Do AI assistants use a WordPress XML sitemap?
Sitemaps are read by crawlers that build search indexes, including Googlebot and Bingbot, and assistants that answer from those indexes benefit indirectly. The AI vendors’ crawler documentation does not describe sitemap use in detail. Keep the sitemap accurate anyway: every indexable template listed, nothing noindexed or redirected, and the right index referenced in robots.txt.
How is WordPress AI visibility measured month to month?
With a fixed set of buyer prompts run in the main assistants using identical wording, recording who is named and which URLs are linked. Alongside it we track AI crawler requests in the logs, template pass rates after updates, Google’s reporting on generative AI features in Search Console, and inquiries that mention an assistant. The prompt list is shared with you.
What access does a WordPress AEO audit need?
Read access is enough to start: the public site, the hosting or CDN logs and a list of active plugins. To make fixes we need an administrator account or a developer on your side, plus access to the CDN and security plugin settings. Changes are made on staging where one exists, documented and reversible, and accounts and content remain yours.
Can a New York agency handle AEO for a WordPress site based elsewhere?
Yes. Progression Agency is based in New York City and takes WordPress AEO engagements from clients across the United States and worldwide. The work is done through the dashboard, the host and the CDN, none of which depend on location, and prompt sets are written for the markets and cities you actually serve.

Want to know what AI crawlers receive from your WordPress site?Send the URL, the host and the security and caching plugins you run. You get the status codes the documented AI crawlers receive today and the first three fixes, in writing.

Request the access check

Get a free marketing proposal

Tell us what you are trying to grow and we will come back with a plan, not a pitch deck. Same-day reply on weekdays.

Privacy Preferences
When you visit our website, it may store information through your browser from specific services, usually in form of cookies. Here you can change your privacy preferences. Please note that blocking some types of cookies may impact your experience on our website and the services we offer.
Contact Us