WordPress Plugin

Verify your domain and serve your AI visibility files from your WordPress site with a free plugin — no DNS changes, no server access, live in about two minutes.

The Indexora AI Files plugin does two jobs. It verifies that you control your domain — which Indexora requires before it will host files for you — and, once you have a subscription, it serves those files directly at your domain: yourdomain.com/llms.txt, yourdomain.com/robots.txt, and the rest. Because WordPress itself answers those URLs, there are no DNS records to add and nothing to configure at your host.

The two halves are independent. Verification is free and needs no subscription — if you are here only to verify a domain before buying, do Step 1 and stop.

Requirements

  • WordPress 5.9 or newer, PHP 7.4 or newer
  • Permission to install plugins on your site (Administrator role)
  • Plugin version 1.3.0 or later for domain verification
  • An active Hosted Files subscription — for serving files only, not for verification

Step 1 — Download the plugin

Get the latest version from indexora.app/deploy → select WordPress PluginDownload plugin, or download it directly: indexora.app/api/wp-plugin/download.

Step 2 — Install and activate

In your WordPress admin:

Plugins → Add New Plugin → Upload Plugin
→ choose indexora-ai-files.zip → Install Now → Activate

Step 3 — Verify your domain

Get your verification code from indexora.app/verify, then in WordPress:

Settings → Indexora AI Files → Step 1 · Verification Code
→ paste code → Save & Verify

Saving checks with Indexora immediately, so the page usually reads Domain verified straight away. You only need to do this once per domain, and it is what unlocks checkout for Hosted Files. Full detail on this and the three non-WordPress alternatives is in Verifying Your Domain.

The plugin publishes your code two ways — at a REST endpoint and as a meta tag in your <head> — so verification still works on sites where the WordPress REST API has been disabled by a host or security plugin.

Step 4 — Nothing, if you verified here

A site that verified through this plugin (v1.4.0 or later) sets itself up. When you buy Hosted Files, your site collects its own Hosting Token and starts serving your files — usually within seconds. There is no token to copy and no second visit to wp-admin.

If your site happened to be offline, in maintenance mode, or behind a firewall at that moment, its daily background check collects the token within a day. To fetch it right away, open Settings → Indexora AI Files and press Check for my token.

Setting up by hand instead? If you verified some other way, or you are configuring a different site, get your Hosting Token from indexora.app/deploy while signed in, then:

Settings → Indexora AI Files → paste token → Save Token

Either route ends the same way: the settings page shows a status panel with your connected domain, plan tier, and a table of every file path with its current state.

How the automatic setup is secured

Worth knowing, because it explains why this is safe to leave switched on:

  • Indexora never writes to your site. There is no endpoint in this plugin that accepts an authenticated command from us. Your site does the asking, so nothing outside your server can change what it serves.
  • Your site's secret never leaves it in usable form. The plugin generates a 48-character secret on activation and publishes only its SHA-256 fingerprint. Indexora stores only a hash of it — so neither reading the plugin's source nor a breach of our database yields anything that can be presented as your site.
  • It is rotated on every use, which caps how long a leaked secret could matter.
  • The token is checked against your own domain before the plugin keeps it, so a site can never be pointed at another customer's files.
  • The worst case is small. A Hosting Token is not a login — it fetches the AI files for one domain, which are public documents served at that domain anyway. It cannot reach your account, your billing, or any other domain.

What gets served

The plugin answers up to 12 paths at your domain, depending on what your scans have generated:

/llms.txt          /robots.txt        /sitemap.xml
/ai-index.json     /crawl-hints.txt   /security.txt
/faq-schema.json   /faq-display.html  /about-us.txt
/meta-tags.html    /agents.md         /schema.json

Paths marked Not generated yet in the settings table simply haven't been produced for your domain — run a scan at indexora.app/generate and refresh. WordPress installs in a subdirectory (e.g. example.com/blog) are supported; files are served relative to your WordPress address.

Keeping files current

Files refresh three ways — you don't need to do anything for the first two:

  • Automatically after every rescan — Indexora pings your site the moment new files are generated.
  • Daily background refresh — a scheduled task pulls the latest files once a day, which covers sites Indexora can't reach directly (password-protected staging, strict firewalls).
  • Manually — the Refresh Files Now button on the settings page.

Plugin updates

The plugin updates itself like any wordpress.org plugin (v1.2.0 and later): it checks indexora.app for new versions automatically, and when one is available it appears in Dashboard → Updates and on the Plugins screen with the usual update now link — one click and you're on the latest version. Your Hosting Token, fetched files and settings are stored in your WordPress database and are never touched by an update, so everything continues exactly as you set it up — no reconnection, no re-entering the token.

Reinstalling or moving hosts? Update in place rather than removing the plugin: download the latest zip, then in wp-admin go to Plugins → Add New → Upload Plugin, choose the zip and click Replace current with uploaded. Your token and settings are preserved (do not delete the plugin first — deleting erases its saved data).

About robots.txt

While the plugin is active, Indexora's robots.txt replaces the one WordPress generates. It includes everything WordPress would normally output, plus AI crawler directives. Deactivating the plugin instantly reverts to WordPress's own robots.txt and sitemap.xml; the other AI file paths return 404 until reactivated.

Troubleshooting

  • "Refresh failed" after saving the token — check the token was copied exactly, your subscription is active, and you've run at least one scan for the domain at indexora.app/generate. The settings page shows the exact API error under Last error.
  • Files show old content — a caching plugin or host-level page cache may be caching the file URLs. Exclude the AI file paths from caching, or purge the cache after a refresh. The plugin itself serves with a 1-hour cache header.
  • /robots.txt ignores the plugin — if a physical robots.txt file exists in your site's web root, the server serves it before WordPress loads. Delete or rename the physical file so requests reach WordPress.
  • "We couldn't read the code back from your site" — verification needs your site to be publicly reachable. Maintenance mode, a staging password, an IP allow-list or Cloudflare "Under Attack" mode will all block it. If Save & Verify times out on very constrained hosting, press Check verification on indexora.app/verify instead — it takes a different route and generally succeeds where the in-dashboard button does not.
  • Uninstalling — deleting the plugin removes all of its data (token, verification code, cached files, scheduled tasks) automatically. Note that removing the plugin also removes the proof your domain was verified with; if you re-verify later, paste the code again.
  • Still stuck — email [email protected] with your domain and a screenshot of the plugin settings page.

Prefer not to use a plugin?

The CNAME setup serves the same files from Indexora's edge network with one DNS record — a good fit if you keep WordPress lean or your host restricts plugins.

Stripe TEST mode — payments are simulated and no card is charged. Use card 4242 4242 4242 4242.