PluginProbe
ThinkRank AI SEO – AI SEO Plugin for WordPress: Schema, XML Sitemaps, Meta Tags, Search Console & Local SEO / 2.10.0
ThinkRank AI SEO – AI SEO Plugin for WordPress: Schema, XML Sitemaps, Meta Tags, Search Console & Local SEO v2.10.0
2.10.0 2.9.0 2.8.0 2.7.0 2.6.0 2.5.0 2.4.0 2.3.0 2.2.0 2.1.1 2.1.0 2.0.2 2.0.1 2.0.0 1.32.0 1.31.0 1.30.0 1.29.0 1.28.0 1.27.0 1.26.0 1.25.0 trunk 1.0.0 1.0.1 All 51 releases
← All changes | includes/core/class-activator.php +230 -10 1.30.0 → 2.10.0 View file →
@@ -48,11 +48,17 @@
48 48 delete_option(self::UNINSTALLED_OPTION);
49 49
50 50 $this->check_requirements();
51 51 $this->create_database_tables();
52 + // Both must precede set_default_options(): they read
53 + // `thinkrank_version`, which that method creates.
54 + $this->retire_sitemap_legacy_fallback();
55 + $this->seed_feed_defaults();
56 + $this->skip_key_features_migration();
52 57 $this->set_default_options();
53 58 $this->setup_indexnow_key();
54 59 $this->schedule_cron_jobs();
60 + $this->restore_webroot_artifacts();
55 61 $this->set_activation_flag();
56 62
57 63 // Grant the admin capabilities here rather than waiting for the `init`
58 64 // hook Role_Manager registers, so the menu is reachable on the very
@@ -114,10 +120,10 @@
114 120 * @throws \Exception If requirements not met
115 121 */
116 122 private function check_requirements(): void {
117 123 // PHP version check
118 - if (version_compare(PHP_VERSION, '8.0', '<')) {
119 - throw new \Exception('ThinkRank requires PHP 8.0 or higher');
124 + if (version_compare(PHP_VERSION, '7.4', '<')) {
125 + throw new \Exception('ThinkRank requires PHP 7.4 or higher');
120 126 }
121 127
122 128 // WordPress version check
123 129 if (version_compare(get_bloginfo('version'), '6.0', '<')) {
@@ -131,15 +137,38 @@
131 137 throw new \Exception(sprintf("Required PHP extension '%s' is not loaded", esc_html($extension)));
132 138 }
133 139 }
134 140
135 - // Check if we can write to WordPress root directory (for robots.txt, llms.txt, sitemaps)
136 - if (!wp_is_writable(ABSPATH)) {
137 - // Log warning but don't block activation — some hosts restrict ABSPATH writes
138 - // and file-writing features will gracefully degrade via WP_Filesystem checks
141 + // Check if we can write to WordPress root directory (for robots.txt, llms.txt,
142 + // the Instant Indexing key file). Never blocks activation — some hosts restrict
143 + // ABSPATH writes by design.
144 + //
145 + // The result is recorded rather than only logged. It used to reach error_log()
146 + // and only under WP_DEBUG, so on a production site nobody was ever told, and the
147 + // features that need it failed later with messages describing the symptom rather
148 + // than the cause (#753). Webroot_Writable_Notice re-evaluates the condition live —
149 + // permissions change without a reactivation — and this value only distinguishes
150 + // "never worked here" from "worked until the host changed something".
151 + $writable = wp_is_writable(ABSPATH);
152 +
153 + update_option(
154 + \ThinkRank\Admin\Webroot_Writable_Notice::OPT_ACTIVATION_STATE,
155 + $writable ? 'writable' : 'not-writable',
156 + false
157 + );
158 +
159 + if (!$writable) {
160 + // A fresh activation on a broken root should warn even if a previous
161 + // install's dismissal is still on record.
162 + delete_option(\ThinkRank\Admin\Webroot_Writable_Notice::OPT_DISMISSED);
163 +
139 164 if ( defined( 'WP_DEBUG' ) && WP_DEBUG ) {
165 + // Not a fixed feature list: robots.txt, llms.txt and the Instant
166 + // Indexing key all have a PHP path, so naming them as broken
167 + // was untrue since #756. Webroot_Writable_Notice works out
168 + // what, if anything, is actually affected.
140 169 // phpcs:ignore WordPress.PHP.DevelopmentFunctions.error_log_error_log
141 - error_log('ThinkRank: WordPress root directory is not writable. Some features (robots.txt, llms.txt, sitemaps) may not work.');
170 + error_log('ThinkRank: WordPress root directory is not writable. Features on Automatic delivery are served from WordPress; any feature explicitly set to write files cannot publish them.');
142 171 }
143 172 }
144 173 }
145 174
@@ -178,8 +207,127 @@
178 207
179 208
180 209
181 210 /**
211 + * On a brand-new install, close the pre-2.1.1 sitemap ownership fallback
212 + * before it can ever open.
213 + *
214 + * {@see thinkrank_webroot_sitemap_is_ours()} keeps one narrow escape hatch:
215 + * a sitemap written before 2.1.1 with `enable_styling` off carries neither
216 + * the marker nor our XSL href, so it can only be recognised by the name the
217 + * stored settings derive. That fallback is gated on this install never
218 + * having written a marked sitemap — but "never written one" describes two
219 + * completely different sites:
220 + *
221 + * - a pre-2.1.1 install that has not regenerated since upgrading, which
222 + * is exactly what the fallback exists to recover; and
223 + * - a fresh install that simply has not generated yet, which cannot have
224 + * a legacy file of ours on disk at all.
225 + *
226 + * On the second, the fallback has nothing to recover and can only delete
227 + * somebody else's sitemap from one of the canonical names — #515 again, in
228 + * a site that never had the problem the fallback addresses. It is not a
229 + * narrow window either: `regenerate_sitemap_from_settings()` returns early
230 + * while the master `enabled` flag is off, so a site with sitemaps disabled
231 + * and styling saved off never records a marked write, and stays exposed for
232 + * as long as it stays in that configuration.
233 + *
234 + * Recording the marker here on a fresh install separates the two cases. An
235 + * upgrade does not reach this code — WordPress does not re-run the
236 + * activation hook on update — so a genuine pre-2.1.1 site keeps the
237 + * fallback until its first marked write, exactly as before.
238 + *
239 + * `thinkrank_version` is the signal: set_default_options() adds it only
240 + * when absent and never updates it, so it is missing on the very first
241 + * activation and present on every one after.
242 + *
243 + * @since 2.1.1
244 + *
245 + * @return void
246 + */
247 + private function retire_sitemap_legacy_fallback(): void {
248 + if (get_option('thinkrank_version') !== false) {
249 + return;
250 + }
251 +
252 + require_once THINKRANK_PLUGIN_DIR . 'includes/cleanup-webroot.php';
253 +
254 + add_option(THINKRANK_SITEMAP_MARKED_WRITE_OPTION, '1', '', false);
255 + }
256 +
257 + /**
258 + * Give a brand-new install the feed posture the competitors ship with.
259 + *
260 + * The feed controls (#635) default to off in
261 + * {@see Site_Identity_Manager::get_default_settings()}, and they have to:
262 + * two of the three change what a site already publishes. Signing every
263 + * entry adds a line to what existing subscribers receive, and noindexing
264 + * feeds withdraws URLs a site may have had indexed for years — on a podcast
265 + * site, whose feed has to stay indexable, silently at that. Neither belongs
266 + * in a plugin update.
267 + *
268 + * A first install has no subscribers and no indexed feed, so there is
269 + * nothing to change and the protective defaults are simply the right
270 + * starting point — which is what The SEO Framework, Yoast and Rank Math all
271 + * ship. Seeding them here rather than in the defaults is what separates the
272 + * two cases.
273 + *
274 + * Excerpt-only is left off even here: it changes what readers get rather
275 + * than what scrapers can take, and that is the site owner's call.
276 + *
277 + * Same signal and same reasoning as {@see self::retire_sitemap_legacy_fallback()}:
278 + * `thinkrank_version` is absent only on the very first activation, and an
279 + * upgrade does not re-run the activation hook at all.
280 + *
281 + * @since 2.7.0
282 + *
283 + * @return void
284 + */
285 + private function seed_feed_defaults(): void {
286 + if (get_option('thinkrank_version') !== false) {
287 + return;
288 + }
289 +
290 + $manager = new \ThinkRank\SEO\Site_Identity_Manager();
291 +
292 + $manager->save_settings(
293 + 'site',
294 + null,
295 + [
296 + 'feed_source_link' => true,
297 + 'feed_noindex' => true,
298 + ]
299 + );
300 + }
301 +
302 + /**
303 + * Mark the llms.txt Key Features migration done on a fresh install.
304 + *
305 + * {@see \ThinkRank\SEO\LLMs_Txt_Manager::maybe_migrate_legacy_key_features()}
306 + * converts a value saved while commas separated features. A brand-new
307 + * install never saved one, so anything it stores later follows the
308 + * one-per-line rule and must not be split on its commas by a migration
309 + * that runs after the user typed it.
310 + *
311 + * Same signal as {@see self::seed_feed_defaults()}: `thinkrank_version` is
312 + * absent only on the very first activation.
313 + *
314 + * @since 2.10.0
315 + *
316 + * @return void
317 + */
318 + private function skip_key_features_migration(): void {
319 + if (get_option('thinkrank_version') !== false) {
320 + return;
321 + }
322 +
323 + add_option(
324 + \ThinkRank\SEO\LLMs_Txt_Manager::KEY_FEATURES_MIGRATION_OPTION,
325 + \ThinkRank\SEO\LLMs_Txt_Manager::KEY_FEATURES_MIGRATION_VERSION
326 + );
327 + }
328 +
329 + /**
182 330 * Set default plugin options
183 331 *
184 332 * @return void
185 333 */
@@ -186,11 +334,11 @@
186 334 private function set_default_options(): void {
187 335 $default_options = [
188 336 'thinkrank_version' => THINKRANK_VERSION,
189 337
190 - 'thinkrank_ai_provider' => 'openai',
338 + 'thinkrank_ai_provider' => \ThinkRank\Core\Settings::AI_PROVIDER_NONE,
191 339 'thinkrank_cache_duration' => 3600, // 1 hour
192 - 'thinkrank_max_requests_per_minute' => 10,
340 + 'thinkrank_max_requests_per_minute' => 0,
193 341 'thinkrank_enable_logging' => true,
194 342 'thinkrank_auto_optimize' => false,
195 343 'thinkrank_seo_score_threshold' => 70,
196 344 ];
@@ -203,10 +351,82 @@
203 351 }
204 352
205 353
206 354 /**
355 + * Republish the web-root artifacts deactivation took away.
356 + *
357 + * Deactivation removes the published sitemap, robots.txt and llms.txt so an
358 + * inactive ThinkRank stops shadowing whatever the user switched to (#510).
359 + * That is only safe if switching the plugin back on puts them back, which is
360 + * what this does.
361 + *
362 + * Restores strictly what {@see Deactivator::REPUBLISH_OPTION} recorded as
363 + * having been removed — never "everything the settings would allow", which
364 + * on a fresh install would publish files the site never had.
365 + *
366 + * The sitemap goes through schedule_regeneration() rather than being built
367 + * inline: a full rebuild on a large site is far too slow to sit inside an
368 + * activation request, and the debounced hook already respects the master
369 + * `enabled` flag. robots.txt and llms.txt are single small writes, so they
370 + * happen here.
371 + *
372 + * @since 2.1.0
373 + *
374 + * @return void
375 + */
376 + private function restore_webroot_artifacts(): void {
377 + $republish = get_option(Deactivator::REPUBLISH_OPTION, null);
378 +
379 + if ($republish === null) {
380 + // No recorded deactivation — a first install, or an activation that
381 + // already consumed the record.
382 + return;
383 + }
384 +
385 + // Consume it first. A restore that fatals must not re-run on every
386 + // subsequent activation, and each entry below is independently guarded.
387 + delete_option(Deactivator::REPUBLISH_OPTION);
388 +
389 + if (!is_array($republish)) {
390 + return;
391 + }
392 +
393 + try {
394 + if (in_array('sitemap', $republish, true) && class_exists('ThinkRank\\SEO\\Sitemap_Generator')) {
395 + // Read-only instance: the hook-registering one would bind a
396 + // second set of content-change listeners to this request.
397 + (new \ThinkRank\SEO\Sitemap_Generator(false))->schedule_regeneration();
398 + }
399 +
400 + if (in_array('robots', $republish, true) && class_exists('ThinkRank\\SEO\\Site_Identity_Manager')) {
401 + (new \ThinkRank\SEO\Site_Identity_Manager())->sync_robots_txt_file();
402 + }
403 +
404 + if (in_array('llms', $republish, true) && class_exists('ThinkRank\\SEO\\LLMs_Txt_Manager')) {
405 + $llms = new \ThinkRank\SEO\LLMs_Txt_Manager();
406 + $content = $llms->get_published_content();
407 +
408 + // write_llms_txt_to_file() enforces the enabled toggle and the
409 + // delivery mode itself, so an empty document is the only case
410 + // worth short-circuiting here.
411 + if ($content !== '') {
412 + $llms->write_llms_txt_to_file($content);
413 + }
414 + }
415 + } catch (\Throwable $e) {
416 + // A failed republish must not block activation — the user would be
417 + // left unable to switch the plugin on at all. The artifacts rebuild
418 + // on the next content or settings save.
419 + if (defined('WP_DEBUG') && WP_DEBUG) {
420 + // phpcs:ignore WordPress.PHP.DevelopmentFunctions.error_log_error_log
421 + error_log('ThinkRank: failed to restore web-root artifacts: ' . $e->getMessage());
422 + }
423 + }
424 + }
425 +
426 + /**
207 427 * Schedule cron jobs
208 - *
428 + *
209 429 * @return void
210 430 */
211 431 private function schedule_cron_jobs(): void {
212 432