{"id":244923,"date":"2025-09-13T19:27:26","date_gmt":"2025-09-13T19:27:26","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/ultimo-bots\/"},"modified":"2026-08-01T15:11:42","modified_gmt":"2026-08-01T15:11:42","slug":"ultimo-bots","status":"publish","type":"plugin","link":"https:\/\/br.wordpress.org\/plugins\/ultimo-bots\/","author":23340252,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.0","stable_tag":"1.2.0","tested":"7.0.2","requires":"5.4","requires_php":"7.4","requires_plugins":null,"header_name":"AI Chatbot & Support Agent - Ultimo Bots","header_author":"Ultimo Bots","header_description":"First-time onboarding, snippet injection, and a simple settings screen (bot_id input + \"Modify chatbot\" button) inside WP-Admin.","assets_banners_color":"361387","last_updated":"2026-08-01 15:11:42","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/ultimo-bots.com\/","header_author_uri":"","rating":5,"author_block_rating":0,"active_installs":30,"downloads":855,"num_ratings":3,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.6":{"tag":"1.0.6","author":"ultimobots","date":"2025-09-13 19:30:15"},"1.0.7":{"tag":"1.0.7","author":"ultimobots","date":"2025-09-13 19:43:42"},"1.0.8":{"tag":"1.0.8","author":"ultimobots","date":"2025-09-14 16:32:58"},"1.0.9":{"tag":"1.0.9","author":"ultimobots","date":"2025-09-14 16:44:55"},"1.1.0":{"tag":"1.1.0","author":"ultimobots","date":"2025-09-14 17:00:40"},"1.1.1":{"tag":"1.1.1","author":"ultimobots","date":"2025-09-16 14:21:55"},"1.1.2":{"tag":"1.1.2","author":"ultimobots","date":"2025-10-21 16:05:08"},"1.2.0":{"tag":"1.2.0","author":"ultimobots","date":"2026-08-01 15:11:42"}},"upgrade_notice":{"1.2.0":"<p>More private onboarding (one-time codes instead of personal data in URLs) and more reliable assistant activation. Safe to update; existing setups keep working unchanged.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":3},"assets_icons":{"icon-128x128.gif":{"filename":"icon-128x128.gif","revision":3631070,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.gif":{"filename":"icon-256x256.gif","revision":3631070,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3631045,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3631045,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.6","1.0.7","1.0.8","1.0.9","1.1.0","1.1.1","1.1.2","1.2.0"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Ultimo Bots admin settings page (connection status, Connect button, Bot ID)","2":"Seamless onboarding flow after activation","3":"AI assistant widget visible on a public page"}},"plugin_section":[],"plugin_tags":[232494,2364,2369,337,2379],"plugin_category":[41],"plugin_contributors":[247807],"plugin_business_model":[],"class_list":["post-244923","plugin","type-plugin","status-publish","hentry","plugin_tags-ai-agent","plugin_tags-chatbot","plugin_tags-customer-support","plugin_tags-lead-generation","plugin_tags-live-chat","plugin_category-communication","plugin_contributors-ultimobots","plugin_committers-ultimobots"],"banners":{"banner":"https:\/\/ps.w.org\/ultimo-bots\/assets\/banner-772x250.png?rev=3631045","banner_2x":"https:\/\/ps.w.org\/ultimo-bots\/assets\/banner-1544x500.png?rev=3631045","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/ultimo-bots\/assets\/icon-128x128.gif?rev=3631070","icon_2x":"https:\/\/ps.w.org\/ultimo-bots\/assets\/icon-256x256.gif?rev=3631070","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>You already know the old kind. A visitor asks a real question, the bot replies with a link to your FAQ page, and the visitor leaves.<\/p>\n\n<p>This is the other kind.<\/p>\n\n<p>Ultimo Bots puts a real AI support agent on your WordPress site. It answers from your own content, and then it does the actual work: books the meeting, looks up the order, saves the lead, and pulls you into the conversation when it matters.<\/p>\n\n<h4>You describe it. It builds itself.<\/h4>\n\n<p>There is no canvas to drag boxes around on. You open the builder and type what should happen, in your own words:<\/p>\n\n<p><em>\"When someone asks about pricing, explain the plans and offer a demo call. If they want one, book it in my Cal.com and send the lead to HubSpot.\"<\/em><\/p>\n\n<p>That is the entire build step. The agent is configured from that sentence. No code, no flowcharts, no developer, no agency.<\/p>\n\n<p>Changed your mind? Tell it. That is the edit step too.<\/p>\n\n<h4>It doesn't just answer. It acts.<\/h4>\n\n<p>Connect the tools you already run, and the agent uses them mid-conversation:<\/p>\n\n<ul>\n<li><strong>Books appointments<\/strong> in Cal.com, including reschedule and cancel, or hands over your Calendly link<\/li>\n<li><strong>Takes payments and manages subscriptions<\/strong> through Stripe links. It can list, change, or cancel a subscription. Card details never enter the chat<\/li>\n<li><strong>Saves and finds contacts<\/strong> in HubSpot, and subscribes visitors to Mailchimp with proper double opt-in<\/li>\n<li><strong>Answers from your product catalog<\/strong>, with prices and stock, so \"do you have this in blue\" gets a real answer<\/li>\n<li><strong>Calls your own API<\/strong> with your own credentials when you need something nobody else offers<\/li>\n<li><strong>Captures leads<\/strong> inside the conversation and emails them to you the second they land<\/li>\n<\/ul>\n\n<p>Before the agent touches anything private, it emails the visitor a six-digit code and waits for it. Verified first, every time.<\/p>\n\n<h4>One agent. Every channel.<\/h4>\n\n<p>The same agent runs on your WordPress site, on a shareable chat link, in Facebook Messenger, Instagram DMs, Telegram, and Slack. You train it once and it shows up everywhere. Nothing to duplicate, nothing to keep in sync.<\/p>\n\n<h4>It knows your business, and it will not invent<\/h4>\n\n<p>Point it at your WordPress site and it reads it. Add PDFs, Word files, spreadsheets, Google Drive, OneDrive, Notion. Every answer is built from your material, and one click re-scans your site whenever it changes.<\/p>\n\n<p>When it does not know something, it says so and offers you instead. That one habit is why people trust it on a live site.<\/p>\n\n<p>It detects the language your visitor is writing in and answers in it. You configure nothing.<\/p>\n\n<h4>You stay in control<\/h4>\n\n<p>Write your rules in plain words and the agent holds them, even when a visitor pushes back. Watch conversations as they happen and jump in yourself with one click. The agent goes quiet the moment you start typing and picks up again when you leave. Get pinged in Slack, Telegram, Teams, or email whenever someone wants a human.<\/p>\n\n<h4>Everything is included<\/h4>\n\n<p>Every capability above is on every plan. Plans differ in volume, not in what your agent can do. No per-seat pricing, no per-resolution fees, no \"contact sales\". Start with a free trial, then from $19 a month.<\/p>\n\n<h4>Live in about two minutes<\/h4>\n\n<p>Activate the plugin, answer a few questions, and your agent is on your site. That is the whole setup.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to external services operated by Ultimo Bots to function. The integration is required to register your site securely and render your AI assistant. Below are the services, what they are used for, and what data is transmitted. Policies for all of them: Terms of Service: https:\/\/www.ultimo-bots.com\/terms - Privacy Policy: https:\/\/www.ultimo-bots.com\/privacy<\/p>\n\n<h4>1) Ultimo Bots Portal API - site registration<\/h4>\n\n<ul>\n<li>What: https:\/\/portal.ultimo-bots.com\/api\/auth\/wordpress\/save_secret<\/li>\n<li>When: On plugin activation (and retried if the first attempt failed).<\/li>\n<li>Purpose: Register your WordPress site and exchange a site-specific identifier used for secure operations.<\/li>\n<li>Data sent: site_id (random UUID generated in your WordPress site), site_url (your WordPress home URL), site_secret (random secret generated in your WordPress site), and the admin user's email, first_name, last_name (used only to prefill the onboarding form; transferred server-side, never placed in a URL).<\/li>\n<li>Data received: wordpress_secret_id (an internal identifier) and a one-time connect code (valid 15 minutes, single use).<\/li>\n<\/ul>\n\n<h4>2) Ultimo Bots Portal API - connect code<\/h4>\n\n<ul>\n<li>What: https:\/\/portal.ultimo-bots.com\/api\/auth\/wordpress\/connect_code<\/li>\n<li>When: When you click \"Connect to Ultimo Bots\" in the plugin settings, and right before the one-time onboarding redirect.<\/li>\n<li>Purpose: Mint a fresh one-time connect code so the onboarding can be opened without any personal data in the URL.<\/li>\n<li>Data sent: site_id, site_secret, and the admin user's email, first_name, last_name (prefill, server-side only).<\/li>\n<li>Data received: a one-time connect code.<\/li>\n<\/ul>\n\n<h4>3) Ultimo Bots Portal API - assistant lookup<\/h4>\n\n<ul>\n<li>What: https:\/\/portal.ultimo-bots.com\/api\/wordpress\/my_bot<\/li>\n<li>When: On WP-Admin page loads (throttled to once per 5 minutes), on the plugin settings page, and once daily via WP-Cron.<\/li>\n<li>Purpose: Fetch the ID of the assistant connected to this site, so the assistant activates automatically after onboarding.<\/li>\n<li>Data sent: site_id, site_secret.<\/li>\n<li>Data received: bot_id and its creation status.<\/li>\n<\/ul>\n\n<h4>4) Ultimo Bots Widget Configuration API<\/h4>\n\n<ul>\n<li>What: https:\/\/portal.ultimo-bots.com\/api\/widget_configuration\/{bot_id}<\/li>\n<li>When: On public page views where the assistant is displayed, and on activation to check whether an existing Bot ID is active.<\/li>\n<li>Purpose: Retrieve the widget configuration for your Bot ID (colors, sizes, welcome messages).<\/li>\n<li>Data sent: bot_id (path parameter); optionally host_url when provided by the widget for basic operational analytics.<\/li>\n<li>Data received: widget configuration JSON.<\/li>\n<\/ul>\n\n<h4>5) Ultimo Bots Widget Script Host - static asset<\/h4>\n\n<ul>\n<li>What: https:\/\/robert-kloepsch.github.io\/ultimo-bots-widget\/dist\/bundle.js<\/li>\n<li>When: On public page views where the assistant is displayed.<\/li>\n<li>Purpose: Load the widget client code.<\/li>\n<li>Data sent: standard CDN\/HTTP request metadata (IP, user agent) as with any static asset request.<\/li>\n<\/ul>\n\n<p>Important: This plugin does not accept or store arbitrary HTML\/JS\/CSS from users. It only stores a Bot ID and generates safe markup internally. The widget script is properly enqueued via WordPress functions.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>This plugin communicates with Ultimo Bots services as described in External services. Please review:\n- Terms of Service: https:\/\/www.ultimo-bots.com\/terms\n- Privacy Policy: https:\/\/www.ultimo-bots.com\/privacy<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>ultimo-bots<\/code> folder to <code>\/wp-content\/plugins\/<\/code> (or install from the plugin directory)<\/li>\n<li>Activate the plugin via Plugins -&gt; Installed Plugins<\/li>\n<li>On activation, the plugin generates site credentials and securely registers your site with Ultimo Bots<\/li>\n<li>If there is no active assistant on your site yet, you are guided to the Ultimo Bots onboarding, which lets you create an account, create your assistant, and put it live within 2 minutes<\/li>\n<\/ol>\n\n<p>Ongoing: In Settings -&gt; Ultimo Bots you can check the connection status, reconnect, manage the Bot ID, and open the Ultimo Bots Portal.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20it%20make%20things%20up%3F\"><h3>Will it make things up?<\/h3><\/dt>\n<dd><p>No. It answers from the material you give it, and it is built to say when something is not covered rather than guess its way through. At that point it offers to fetch you instead, which is usually what the visitor wanted anyway.<\/p><\/dd>\n<dt id=\"how%20does%20it%20learn%20about%20my%20business%3F\"><h3>How does it learn about my business?<\/h3><\/dt>\n<dd><p>During setup it reads your WordPress site. After that you can add PDFs, Word files, spreadsheets, and connect Google Drive, OneDrive, or Notion. One click re-scans your site whenever your content changes, and the Boost and Ultimo plans re-scan on a schedule for you.<\/p><\/dd>\n<dt id=\"do%20i%20really%20not%20need%20to%20write%20code%20or%20build%20a%20flowchart%3F\"><h3>Do I really not need to write code or build a flowchart?<\/h3><\/dt>\n<dd><p>No. You describe how your support should work in plain language, and the agent is configured from that. Changing it later works the same way: you tell it what to do differently.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20a%20visitor%20wants%20a%20real%20person%3F\"><h3>What happens when a visitor wants a real person?<\/h3><\/dt>\n<dd><p>The agent hands the conversation over and stops replying. You get a notification in Slack, Telegram, Teams, or email, you open the conversation and type. When you leave, the agent picks up again. The visitor never leaves the chat or repeats themselves.<\/p><\/dd>\n<dt id=\"can%20i%20control%20what%20it%20says%2C%20and%20what%20it%20refuses%20to%20say%3F\"><h3>Can I control what it says, and what it refuses to say?<\/h3><\/dt>\n<dd><p>Yes. You write your rules in plain words: which topics to stay away from, which disclaimer to always attach, when to insist on a human. The agent holds those rules even when a visitor pushes back on them.<\/p><\/dd>\n<dt id=\"can%20i%20make%20it%20match%20my%20brand%3F\"><h3>Can I make it match my brand?<\/h3><\/dt>\n<dd><p>Yes. Colours, fonts, your logo, the launcher icon and its shape, size, position, the welcome message, and up to three starter questions your visitors can click. On Boost and Ultimo you can also remove the \"Powered by\" line.<\/p><\/dd>\n<dt id=\"which%20languages%20does%20it%20speak%3F\"><h3>Which languages does it speak?<\/h3><\/dt>\n<dd><p>It detects the language your visitor is writing in and answers in that language, with nothing to configure. If you take a conversation over yourself, you get translation help so you can reply across a language barrier.<\/p><\/dd>\n<dt id=\"which%20tools%20can%20it%20actually%20connect%20to%3F\"><h3>Which tools can it actually connect to?<\/h3><\/dt>\n<dd><p>Cal.com, Calendly, Stripe, HubSpot, and Mailchimp today. It can also call your own API with credentials you supply, which covers plenty that a fixed connector list never will. The portal always shows what is connectable right now.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20woocommerce%3F\"><h3>Does it work with WooCommerce?<\/h3><\/dt>\n<dd><p>Yes. It reads your shop the way it reads the rest of your site, so it handles questions about products, shipping, returns, and your policies. Upload your catalog as CSV or JSON and it answers on price, stock, and variants exactly rather than approximately. Looking up one specific customer's order is available for Wix and Shopify stores today, not for WooCommerce.<\/p><\/dd>\n<dt id=\"can%20i%20see%20what%20visitors%20are%20actually%20asking%3F\"><h3>Can I see what visitors are actually asking?<\/h3><\/dt>\n<dd><p>Yes, and it tends to be the part people did not expect to value. You get every conversation, the questions that come up most, where visitors are from, the leads they left, and a full export. Daily or weekly summaries can land in your inbox.<\/p><\/dd>\n<dt id=\"what%20does%20it%20cost%3F\"><h3>What does it cost?<\/h3><\/dt>\n<dd><p>There is a free trial, and paid plans start at $19 a month on annual billing ($29 billed monthly). Every feature is included on every plan. Plans differ in volume, meaning AI responses, knowledge sources, and number of skills. No per-seat pricing, and no charge per resolved conversation.<\/p><\/dd>\n<dt id=\"do%20i%20need%20a%20separate%20ultimo%20bots%20account%3F\"><h3>Do I need a separate Ultimo Bots account?<\/h3><\/dt>\n<dd><p>Yes. Your agents live in the Ultimo Bots portal. The onboarding that opens right after activation creates the account in the same flow, so it is not a separate errand.<\/p><\/dd>\n<dt id=\"will%20it%20slow%20down%20my%20site%2C%20and%20does%20it%20work%20with%20my%20theme%3F\"><h3>Will it slow down my site, and does it work with my theme?<\/h3><\/dt>\n<dd><p>The widget is lightweight and enqueued in the footer, so it does not block your page or touch your layout. It works with any theme and with Elementor, Divi, Gutenberg, and the rest. Real-world performance always depends on your theme and your other plugins, but the script is built to stay out of the way.<\/p><\/dd>\n<dt id=\"what%20exactly%20does%20the%20plugin%20send%20to%20the%20service%3F\"><h3>What exactly does the plugin send to the service?<\/h3><\/dt>\n<dd><p>On activation: site_id, site_url, a random site_secret, and the admin's email, first_name, and last_name (to prefill the onboarding; transferred server-side, never in a URL). Ongoing: the site_id\/site_secret pair to look up the assistant connected to this site. On page load: your bot_id is used to fetch widget configuration, and the static widget script is loaded from the widget host.<\/p><\/dd>\n<dt id=\"is%20the%20integration%20secure%3F\"><h3>Is the integration secure?<\/h3><\/dt>\n<dd><p>Yes. A unique secret is generated during activation and is required for protected operations. Onboarding handoffs use one-time codes valid for 15 minutes. All service calls are over HTTPS. The plugin never evaluates arbitrary code from options.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20inject%20custom%20code%3F\"><h3>Does this plugin inject custom code?<\/h3><\/dt>\n<dd><p>Yes. It injects a safe container<\/p>\n\n<p>&lt;<\/p>\n\n<p>div&gt; and enqueues the Ultimo Bots widget script. This is required for the assistant to appear on your site. Users cannot add arbitrary CSS\/JS\/PHP; only the Bot ID is stored, and the markup is generated automatically.<\/p><\/dd>\n<dt id=\"can%20i%20remove%20all%20data%20if%20i%20uninstall%3F\"><h3>Can I remove all data if I uninstall?<\/h3><\/dt>\n<dd><p>Yes. Uninstalling the plugin removes the plugin's options (including credentials and the snippet container) from your WordPress database. It does not delete any data in your Ultimo Bots account.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Privacy: the onboarding redirect no longer contains your email or name - it uses an anonymous one-time connect code instead<\/li>\n<li>Reliability: the assistant now activates via a secure pull from the Ultimo Bots service, so setups behind security plugins, firewalls, or basic auth work too (the instant push path is kept as an accelerator)<\/li>\n<li>New settings screen: connection status, a Connect button that (re)opens the onboarding, and the manual Bot ID field as fallback<\/li>\n<li>The one-time onboarding redirect no longer gets lost to background requests (heartbeat\/AJAX)<\/li>\n<li>Daily background sync keeps the assistant binding fresh<\/li>\n<li>Fixed a potential error when the REST inject endpoint was called before credentials existed<\/li>\n<li>Refreshed listing: description, FAQ, and banner<\/li>\n<li>Tested up to WordPress 7.0<\/li>\n<\/ul>\n\n<h4>1.0.7<\/h4>\n\n<ul>\n<li>Updated plugin description and branding<\/li>\n<\/ul>\n\n<h4>1.0.6<\/h4>\n\n<ul>\n<li>Removed powered by link in the snippet<\/li>\n<\/ul>\n\n<h4>1.0.5<\/h4>\n\n<ul>\n<li>Compliance update: Documented external services and data flow<\/li>\n<li>REST endpoint now accepts bot_id only (no arbitrary HTML); plugin rebuilds safe markup internally<\/li>\n<li>Front-end assets are properly enqueued (wp_enqueue_script)<\/li>\n<li>Added thorough escaping in admin output<\/li>\n<li>Production HTTPS endpoints set for service calls<\/li>\n<\/ul>\n\n<h4>0.9.3<\/h4>\n\n<ul>\n<li>Compliance refinements and code tidy-up<\/li>\n<li>Unified option keys under ultibo_ prefix; added one-time migration from legacy keys<\/li>\n<li>Uninstall routine removes both new and legacy keys<\/li>\n<\/ul>\n\n<h4>0.9.2<\/h4>\n\n<ul>\n<li>Initial public release: onboarding, secure registration, REST integration, auto-injection, and portal access<\/li>\n<\/ul>","raw_excerpt":"An AI support agent that answers from your content, books, captures leads, and hands off to you. You build it by describing it.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/244923","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=244923"}],"author":[{"embeddable":true,"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/ultimobots"}],"wp:attachment":[{"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=244923"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=244923"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=244923"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=244923"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=244923"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/br.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=244923"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}