{"id":332521,"date":"2026-07-15T09:53:16","date_gmt":"2026-07-15T09:53:16","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/neccospeak\/"},"modified":"2026-08-26T08:24:45","modified_gmt":"2026-08-26T08:24:45","slug":"neccospeak","status":"publish","type":"plugin","link":"https:\/\/mlt.wordpress.org\/plugins\/neccospeak\/","author":23521353,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.3.0","stable_tag":"0.3.0","tested":"7.1","requires":"6.4","requires_php":"8.0","requires_plugins":null,"header_name":"NeccoSpeak \u2013 AI Chatbot & Voice Chat","header_author":"neccos","header_description":"Lightweight, self-contained AI chat & voice widget powered by your own OpenAI API key \u2014 no external SaaS server required.","assets_banners_color":"f2fafc","last_updated":"2026-08-26 08:24:45","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/neccos.jp","rating":0,"author_block_rating":0,"active_installs":0,"downloads":194,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.1.0":{"tag":"0.1.0","author":"neccos","date":"2026-07-15 09:52:45"},"0.1.1":{"tag":"0.1.1","author":"neccos","date":"2026-07-30 03:45:01"},"0.3.0":{"tag":"0.3.0","author":"neccos","date":"2026-08-26 08:24:45"}},"upgrade_notice":{"0.3.0":"<p>Major rebuild of both the admin screen and the widget. The settings screen moved to its own top-level &quot;NeccoSpeak&quot; menu, and you must purge your page cache and CDN after updating. Your API key and settings carry over.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":0},"assets_icons":{"icon-128x128.gif":{"filename":"icon-128x128.gif","revision":3627855,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.gif":{"filename":"icon-256x256.gif","revision":3627855,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3652444,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3652444,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.1.0","0.1.1","0.3.0"],"block_files":[],"assets_screenshots":{"screenshot-1-ja.png":{"filename":"screenshot-1-ja.png","revision":3666518,"resolution":"1","location":"assets","locale":"ja","width":1090,"height":1558},"screenshot-1.png":{"filename":"screenshot-1.png","revision":3666518,"resolution":"1","location":"assets","locale":"","width":1002,"height":1618},"screenshot-2-ja.png":{"filename":"screenshot-2-ja.png","revision":3666518,"resolution":"2","location":"assets","locale":"ja","width":2466,"height":1838},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3666518,"resolution":"2","location":"assets","locale":"","width":2472,"height":1830},"screenshot-3-ja.png":{"filename":"screenshot-3-ja.png","revision":3666518,"resolution":"3","location":"assets","locale":"ja","width":2472,"height":2280},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3666518,"resolution":"3","location":"assets","locale":"","width":2468,"height":2266},"screenshot-4-ja.png":{"filename":"screenshot-4-ja.png","revision":3666518,"resolution":"4","location":"assets","locale":"ja","width":2470,"height":1618},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3666518,"resolution":"4","location":"assets","locale":"","width":2460,"height":1642},"screenshot-5-ja.png":{"filename":"screenshot-5-ja.png","revision":3666518,"resolution":"5","location":"assets","locale":"ja","width":2484,"height":2392},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3666518,"resolution":"5","location":"assets","locale":"","width":2452,"height":2390}},"screenshots":{"1":"The AI chatbot widget with its home view and voice chat button \u2014 visitors ask by text, or talk to your site and hear it answer.","2":"The Dashboard tab \u2014 the redesigned admin screen organized into nine tabs.","3":"The AI settings tab \u2014 save your OpenAI API key and define the assistant's role and goals.","4":"The Voice settings tab \u2014 pick the realtime model and voice, and tune how conversations flow.","5":"The Preview tab \u2014 check the widget live inside the admin screen before publishing changes."}},"plugin_section":[],"plugin_tags":[2353,191735,2364,194533,63792],"plugin_category":[41],"plugin_contributors":[271624],"plugin_business_model":[],"class_list":["post-332521","plugin","type-plugin","status-publish","hentry","plugin_tags-ai","plugin_tags-ai-chatbot","plugin_tags-chatbot","plugin_tags-openai","plugin_tags-voice-chat","plugin_category-communication","plugin_contributors-neccos","plugin_committers-neccos"],"banners":{"banner":"https:\/\/ps.w.org\/neccospeak\/assets\/banner-772x250.png?rev=3652444","banner_2x":"https:\/\/ps.w.org\/neccospeak\/assets\/banner-1544x500.png?rev=3652444","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/neccospeak\/assets\/icon-128x128.gif?rev=3627855","icon_2x":"https:\/\/ps.w.org\/neccospeak\/assets\/icon-256x256.gif?rev=3627855","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/neccospeak\/assets\/screenshot-1.png?rev=3666518","caption":"The AI chatbot widget with its home view and voice chat button \u2014 visitors ask by text, or talk to your site and hear it answer."},{"src":"https:\/\/ps.w.org\/neccospeak\/assets\/screenshot-2.png?rev=3666518","caption":"The Dashboard tab \u2014 the redesigned admin screen organized into nine tabs."},{"src":"https:\/\/ps.w.org\/neccospeak\/assets\/screenshot-3.png?rev=3666518","caption":"The AI settings tab \u2014 save your OpenAI API key and define the assistant's role and goals."},{"src":"https:\/\/ps.w.org\/neccospeak\/assets\/screenshot-4.png?rev=3666518","caption":"The Voice settings tab \u2014 pick the realtime model and voice, and tune how conversations flow."},{"src":"https:\/\/ps.w.org\/neccospeak\/assets\/screenshot-5.png?rev=3666518","caption":"The Preview tab \u2014 check the widget live inside the admin screen before publishing changes."}],"raw_content":"<!--section=description-->\n<p>NeccoSpeak turns your WordPress site into something visitors can simply talk to: an AI agent that answers questions 24\/7 by text or voice, guides people to the right page, and runs entirely on your own OpenAI API key.<\/p>\n\n<p>No SaaS, no extra account, no monthly fee, and no server run by us. It needs nothing but WordPress and your own OpenAI API key. You pay OpenAI directly and stay in control of your costs and your data.<\/p>\n\n<h4>Voice chat: talk, don't type<\/h4>\n\n<p>AI voice chat sets NeccoSpeak apart, and it is on by default. Visitors ask questions hands-free and hear the answer spoken back \u2014 in effect, your website gains a voice assistant \u2014 a natural fit for accessibility, mobile users, and anyone who would rather speak than type. Under the hood, the visitor's browser connects directly to the OpenAI Realtime API over WebRTC using a short-lived token issued by your server; your real API key never reaches the browser. Voice requires HTTPS and browser microphone permission.<\/p>\n\n<h4>What can you use it for?<\/h4>\n\n<ul>\n<li><strong>24\/7 FAQ and support<\/strong> \u2013 answer common questions (opening hours, pricing, services) around the clock.<\/li>\n<li><strong>Online stores<\/strong> \u2013 let shoppers ask about shipping, returns, and store policies on the spot, instead of hunting through pages.<\/li>\n<li><strong>Multilingual visitors<\/strong> \u2013 OpenAI models typically reply in the language the visitor writes in, with no extra configuration.<\/li>\n<li><strong>Blogs and content sites<\/strong> \u2013 give readers a way to ask questions instead of leaving.<\/li>\n<li><strong>Client sites<\/strong> \u2013 agencies and freelancers can deploy it without managing yet another SaaS account; each client brings their own key and owns their own billing and data.<\/li>\n<\/ul>\n\n<p>You decide who the chatbot is: describe your business, opening hours, policies, and tone in the system prompt, and it answers accordingly.<\/p>\n\n<h4>Why NeccoSpeak?<\/h4>\n\n<ul>\n<li><strong>Self-contained<\/strong> \u2013 no third-party SaaS involved; data flows only between your server, the visitor's browser, and OpenAI, unless you reference an external URL in the optional Additional CSS box (see \"External Services\" below).<\/li>\n<li><strong>Secure by design<\/strong> \u2013 your API key is stored encrypted with AES-256-CBC, never sent to the browser, and masked in the admin screen.<\/li>\n<li><strong>Zero footprint until configured<\/strong> \u2013 while disabled or without a key, the widget is not loaded and visitors trigger no external communication at all. (This does not apply if the Additional CSS box references an external image\/font URL \u2014 see \"External Services\".)<\/li>\n<li><strong>Budget protection<\/strong> \u2013 per-IP rate limits plus site-wide caps (hourly and daily for chat, daily for voice) keep bots and abusive visitors from running up your OpenAI bill.<\/li>\n<li><strong>No update needed for new models<\/strong> \u2013 type any model name, or click once to fetch the list of models available to your key. New OpenAI models that support the Chat Completions API work as soon as they are released.<\/li>\n<\/ul>\n\n<h4>Features<\/h4>\n\n<ul>\n<li>Text and voice chat in one widget<\/li>\n<li>Display rules: all pages, only specific URLs, or exclude specific URLs<\/li>\n<li>Customizable title, welcome message, and brand color<\/li>\n<li>Free-form model selection with one-click \"fetch available models\"<\/li>\n<li>Custom system prompt<\/li>\n<li>Per-IP and site-wide rate limits to control cost<\/li>\n<\/ul>\n\n<h4>Cost control<\/h4>\n\n<p>Visitors' chat usage is billed to your own OpenAI account, so NeccoSpeak ships with brakes built in: a per-IP, per-minute limit plus site-wide caps (hourly and daily for text chat, daily for voice sessions). When a cap is hit, further requests are declined with a temporary error until the limit window resets \u2014 so your bill stops growing.\nDefaults: chat 10\/min per IP plus 200\/hour and 1,000\/day site-wide; voice 3\/min per IP plus 200\/day site-wide.<\/p>\n\n<h4>Content sync (optional)<\/h4>\n\n<p>The Content sync card on the AI settings tab lets you choose how much of your own site the assistant can work with.<\/p>\n\n<ul>\n<li><strong>Per-page instructions<\/strong> (on by default) \u2013 adds a \"NeccoSpeak\" box to every post\/page editor where you can set extra instructions, a welcome-message override, and a widget show\/hide switch for that one page.<\/li>\n<li><strong>Read-only tools<\/strong> (on by default) \u2013 let the assistant search this site and look up page details. Each individual tool also has to be enabled with its own checkbox before it runs.<\/li>\n<li><strong>Page directory<\/strong> (optional) \u2013 gives the assistant a list of your published pages so it can point visitors to the right one. Links the assistant produces are checked against your own site, and links to pages that do not exist are removed automatically.<\/li>\n<li><strong>Current date and time<\/strong> \u2013 always supplied to the assistant in your site's own timezone, with no setting needed.<\/li>\n<li><strong>Site content search<\/strong> (optional) \u2013 stores excerpts of your posts and pages in the plugin's own database table so the assistant can quote your content directly. No external service is used for the indexing or the search.<\/li>\n<\/ul>\n\n<p>The two optional features (page directory and site content search) stay off until you turn them on, and none of these features contact any additional external service.<\/p>\n\n<h4>Terms and disclaimer<\/h4>\n\n<ul>\n<li><strong>No warranty<\/strong> \u2013 This plugin is provided free of charge as open source software (GPLv2 or later) on an \"as-is\" basis, without warranty of any kind, express or implied. Because it is distributed free of charge, the developer (neccos) assumes no obligation for support, SLA, or continued availability.<\/li>\n<li><strong>Your OpenAI account<\/strong> \u2013 The plugin runs with your own OpenAI API key, and use of the AI is subject to OpenAI's terms and policies. Usage fees are billed by OpenAI directly to your own account. No developer-operated server or service exists, and the developer is not involved in any contract, billing, or service matters with OpenAI.<\/li>\n<li><strong>Data flow<\/strong> \u2013 Chat text and audio are sent to OpenAI with your key and processed under OpenAI's terms. <strong>They are sent only to OpenAI, and the developer (neccos) never receives this data.<\/strong> Everything the plugin stores within WordPress is administrator-entered settings (the API key is encrypted) plus operational data such as rate-limit counters and the audit log, all removed on uninstall (see \"Data stored on your site\" below for details).<\/li>\n<li><strong>Your responsibilities<\/strong> \u2013 As the site owner, you are responsible for: (1) complying with OpenAI's terms, (2) disclosing to your visitors that their input is sent to OpenAI and obtaining any consent required by applicable law such as GDPR, and (3) maintaining your own privacy policy and related documents. Please also advise users not to enter sensitive information in chat or voice.<\/li>\n<li><strong>AI responses<\/strong> \u2013 The accuracy, legality, and usefulness of AI-generated responses are not guaranteed. Use of this plugin and of AI responses is at the sole risk of the site owner and end users.<\/li>\n<\/ul>\n\n<h3>External Services<\/h3>\n\n<p>This plugin communicates with the external service <strong>OpenAI API<\/strong> (api.openai.com) to generate AI responses. This is a core feature of the plugin, and communication occurs when the AI chat \/ voice features are used. Voice conversation is a direct connection (WebRTC) to the OpenAI Realtime API, and this plugin does not use a STUN\/TURN server by default (no additional communication to third-party servers occurs).<\/p>\n\n<p>When the optional \"Link check\" setting is on, the plugin also makes a request to <strong>this site's own host<\/strong> \u2014 never to any third party \u2014 solely to confirm that a link the assistant produced actually points to a real page before showing it to a visitor. Every outbound request (to OpenAI or to this site's own host) passes through a single allow-list that rejects private and link-local IP addresses after DNS resolution; a request to this site's own host is exempt from that IP check only, so sites behind Docker, a reverse proxy, or on an intranet keep working. The optional site content search, the optional tools, and the optional Contact Form 7 hand-off contact no external service at all \u2014 they run entirely on your own server and inside the visitor's own browser tab.<\/p>\n\n<h4>OpenAI API<\/h4>\n\n<ul>\n<li>Destination endpoints:\n\n<ul>\n<li>https:\/\/api.openai.com\/v1\/chat\/completions (generating text chat responses; via the PHP proxy)<\/li>\n<li>https:\/\/api.openai.com\/v1\/realtime\/client_secrets (issuing a short-lived token for voice conversation; PHP \u2192 OpenAI)<\/li>\n<li>https:\/\/api.openai.com\/v1\/realtime\/calls (establishing the WebRTC session for voice conversation; sent directly from the browser to OpenAI)<\/li>\n<li>https:\/\/api.openai.com\/v1\/models (retrieving the list of available models; only when an administrator uses \"Fetch available models\" on the settings screen; PHP \u2192 OpenAI)<\/li>\n<\/ul><\/li>\n<li>Data sent (text chat): the message text entered by the visitor in the chat box, the conversation history, the configured system prompt, and the model name in use. These are sent to OpenAI via the PHP proxy at the moment the visitor sends a message.<\/li>\n<li>Data sent (model list retrieval): only when an administrator (manage_options capability) uses \"Fetch available models\" on the settings screen, a request is made from the server side (PHP) to OpenAI using the API key for authentication. Only the authentication credential is sent; no chat text or visitor data is sent. The response (a list of model IDs) is cached temporarily on the server side. This retrieves model metadata and incurs no OpenAI token billing. The API key is never handed to the browser.<\/li>\n<li>Data sent (when voice conversation is enabled): in addition to the short-lived token issuance request (PHP \u2192 OpenAI), the visitor's microphone audio is sent directly from the browser to OpenAI over WebRTC. Audio is sent from the moment the visitor starts a voice conversation.<\/li>\n<li>When data is sent: communication only occurs when a visitor sends a message or starts a voice conversation. When the plugin is not configured (disabled or no key set), no communication occurs at all.<\/li>\n<li>Purpose: to generate and return an AI response (text or voice) to the input.<\/li>\n<\/ul>\n\n<p>Data sent to OpenAI is subject to OpenAI's terms and policies. Please be sure to review them before use.<\/p>\n\n<ul>\n<li>Terms of use: https:\/\/openai.com\/policies\/terms-of-use\/<\/li>\n<li>Privacy policy: https:\/\/openai.com\/policies\/privacy-policy\/<\/li>\n<li>API data usage policies: https:\/\/openai.com\/policies\/api-data-usage-policies\/<\/li>\n<\/ul>\n\n<h4>Additional CSS box (optional)<\/h4>\n\n<p>The Additional CSS box on the Widget settings tab (requires the \"unfiltered_html\" capability to edit) intentionally allows <code>url(https:\/\/\u2026)<\/code> and <code>@font-face { src: url(https:\/\/\u2026) }<\/code> so administrators can reference their own hosted images\/fonts. As a result, if an administrator adds such a rule, every front-end page view may cause the visitor's browser to fetch that resource from the third-party host referenced in the CSS. This is entirely administrator-controlled: the plugin ships with no Additional CSS by default and reaches no third-party host unless an admin explicitly adds one.<\/p>\n\n<h4>Data stored on your site (no external service)<\/h4>\n\n<p>When \"Restore conversation\" is enabled, the conversation is temporarily saved in the visitor's own browser (sessionStorage) so it survives a page navigation within the same tab; it is cleared when the tab is closed. When the \"First-open modal\" disclaimer is enabled, only a true\/false \"acknowledged\" flag is saved (in localStorage or sessionStorage, depending on the setting). Neither of these is sent to any server, and neither stores any information that identifies the visitor.<\/p>\n\n<p><strong>In your own WordPress database.<\/strong> The plugin can also keep operational records in four of its own database tables on your server. Nothing here is ever transmitted anywhere \u2014 not to the developer, not to OpenAI, not to any third party \u2014 and every table is dropped when you uninstall the plugin.<\/p>\n\n<ul>\n<li><strong>Settings audit log<\/strong> (on by default): which setting an administrator changed, when, and by whom. API keys and Additional CSS are recorded as redacted placeholders, never as their real values. Kept for 90 days by default.<\/li>\n<li><strong>Settings version history<\/strong> (always on): up to the 30 most recent snapshots of your settings so you can compare and roll back \u2014 the API key is never included in a snapshot, and rollback is one click from the Change history tab.<\/li>\n<li><strong>Token usage totals<\/strong> (on by default): per day, per model \u2014 request counts and token counts recorded from the API responses. It contains no visitor data of any kind.<\/li>\n<li><strong>Anonymous usage events<\/strong> (<strong>off by default<\/strong>): counts of widget opens, messages, voice starts, and CTA clicks.<\/li>\n<li><strong>Site content index<\/strong> (<strong>off by default<\/strong>): when the optional site content search is turned on, excerpts of your own published posts and pages are split and stored in the plugin's own database table so the assistant can quote them. Nothing here is ever sent anywhere except, when actually quoted in an answer, to OpenAI as part of that answer's prompt \u2014 the same way any other part of the prompt is sent.<\/li>\n<\/ul>\n\n<p><strong>No IP addresses, no cookies, no visitor identifiers are ever stored<\/strong> in any of these tables. Usage events are grouped by a random value that lives only in the visitor's own tab (sessionStorage) and disappears when that tab is closed \u2014 it cannot be used to recognise the same person again, on a later visit or in another tab.<\/p>\n\n<p><strong>Per-page settings<\/strong>: the optional per-page instructions, welcome-message override, widget show\/hide choice, and content-search exclusion flag are stored as WordPress post meta on the page itself \u2014 editing them requires a publishing-level role, not just the ability to edit that page.<\/p>\n\n<p><strong>Contact Form 7 hand-off<\/strong> (on by default; nothing is loaded on sites where Contact Form 7 is not installed, or until you add a \"Contact Form 7 (prefill)\" CTA button): clicking that CTA stores the name\/email\/message prefill values entirely inside the visitor's own browser tab (sessionStorage) \u2014 never on your server. It expires automatically after five minutes and is deleted as soon as the form page reads it.<\/p>\n\n<h3>Third-party resources<\/h3>\n\n<p>From 0.3.0, the widget frame document (the same-origin <code>?neccospeak_frame=1<\/code> page the front-end launcher opens inside an iframe) bundles the following third-party asset. It is served entirely from your own site \u2014 nothing here is fetched from a CDN or any other external host.<\/p>\n\n<h4>Bootstrap Icons<\/h4>\n\n<ul>\n<li>Name: Bootstrap Icons<\/li>\n<li>Version: 1.13.1<\/li>\n<li>License: MIT<\/li>\n<li>Source: https:\/\/icons.getbootstrap.com\/ (https:\/\/github.com\/twbs\/icons)<\/li>\n<li>Bundled files: <code>assets\/widget-frame\/vendor\/bootstrap-icons\/bootstrap-icons.css<\/code> (the complete upstream stylesheet; the only changes are the <code>@font-face<\/code> rule reduced to the bundled woff2 file and an added explanatory comment \u2014 no selector or property value is modified), <code>assets\/widget-frame\/vendor\/bootstrap-icons\/fonts\/bootstrap-icons.woff2<\/code> (the upstream v1.13.1 icon font, unmodified), <code>assets\/widget-frame\/vendor\/bootstrap-icons\/LICENSE<\/code> (the upstream MIT license text, unmodified).<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Install the plugin from \"Add New\" in the admin Plugins screen (or upload it), then activate it.<\/li>\n<li>Open the top-level <strong>NeccoSpeak<\/strong> menu in the admin sidebar and paste your own <strong>OpenAI API key<\/strong>. It is stored encrypted and masked thereafter.<\/li>\n<li>Optionally set the model, system prompt, welcome message, brand color, display rules, and rate limits.<\/li>\n<li>That's it \u2014 once enabled with a key set, the chat widget is live on the pages your display rules match. Voice conversation is on by default (requires HTTPS; HTTPS is strongly recommended for text chat as well) \u2014 turn it off in Voice settings if you don't want it.<\/li>\n<\/ol>\n\n<p>While the configuration is incomplete, the widget is not loaded and no external communication is triggered.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20an%20account%20with%20you%2C%20or%20your%20server%3F\"><h3>Do I need an account with you, or your server?<\/h3><\/dt>\n<dd><p>No. NeccoSpeak is self-contained: it needs only WordPress and your own OpenAI API key.<\/p><\/dd>\n<dt id=\"is%20it%20really%20free%3F\"><h3>Is it really free?<\/h3><\/dt>\n<dd><p>The plugin: yes \u2014 free and open source (GPL). The AI usage: billed by OpenAI to your own account (your own key), at OpenAI's rates. Check OpenAI's official pricing for details.<\/p><\/dd>\n<dt id=\"does%20the%20chatbot%20know%20my%20site%20content%3F\"><h3>Does the chatbot know my site content?<\/h3><\/dt>\n<dd><p>By default it answers from the AI model plus the system prompt you write \u2014 put your key business facts (hours, prices, policies) in the system prompt and it will use them. If you turn on the optional site content search and page directory (both off by default, on the AI settings tab's Content sync card), it can also quote excerpts from your own published posts and pages and point visitors to the right one.<\/p><\/dd>\n<dt id=\"is%20the%20api%20key%20handled%20securely%3F\"><h3>Is the API key handled securely?<\/h3><\/dt>\n<dd><p>The key is stored encrypted in the database with AES-256-CBC. It is never output to the front end (browser) and is masked in the admin screen.<\/p><\/dd>\n<dt id=\"can%20visitors%20run%20up%20my%20openai%20bill%3F\"><h3>Can visitors run up my OpenAI bill?<\/h3><\/dt>\n<dd><p>The chat endpoint has per-IP, per-minute rate limiting plus site-wide hourly and daily caps; voice token issuance has per-IP and site-wide daily caps. When a cap is exceeded, responses are temporarily limited (503). Beyond that, display rules let you reduce exposure to abuse by limiting which pages show the widget. The chat API also refuses requests that do not come from a page on your own site (a same-origin check), but since origins can be forged, the rate limits remain the real line of defense.<\/p><\/dd>\n<dt id=\"what%20do%20i%20need%20for%20voice%20chat%3F\"><h3>What do I need for voice chat?<\/h3><\/dt>\n<dd><p>Voice chat is on by default (the \"Enable voice conversation\" toggle in Voice settings) \u2014 just serve your site over <strong>HTTPS (SSL)<\/strong>. Browser microphone permission is requested when it is used. Audio goes from the browser directly to OpenAI over WebRTC using a short-lived token \u2014 your API key is never handed to the browser.<\/p><\/dd>\n<dt id=\"will%20it%20slow%20down%20my%20site%3F\"><h3>Will it slow down my site?<\/h3><\/dt>\n<dd><p>While the plugin is unconfigured (disabled or no key), nothing is loaded on the front end at all. Once active, it loads a small widget only on the pages your display rules match.<\/p><\/dd>\n<dt id=\"do%20i%20need%20to%20update%20the%20plugin%20when%20a%20new%20model%20is%20released%3F\"><h3>Do I need to update the plugin when a new model is released?<\/h3><\/dt>\n<dd><p>No. The model name is free-form, and \"Fetch available models\" retrieves the list of models currently available to your API key so you can pick one (metadata only \u2014 no token billing).<\/p><\/dd>\n<dt id=\"are%20responses%20displayed%20as%20a%20stream%3F\"><h3>Are responses displayed as a stream?<\/h3><\/dt>\n<dd><p>Yes. Replies appear progressively, typewriter-style, instead of all at once. The reply your browser has already received is revealed a bit at a time, so nothing extra is needed from your server. The effect also respects the operating system's \"reduce motion\" setting.<\/p><\/dd>\n<dt id=\"does%20the%20content%20search%20send%20my%20pages%20to%20openai%3F\"><h3>Does the content search send my pages to OpenAI?<\/h3><\/dt>\n<dd><p>No \u2014 the search itself runs entirely on your own server, against your own database. Only the excerpts actually selected as relevant to a visitor's question are sent to OpenAI, the same way any other part of the prompt is.<\/p><\/dd>\n<dt id=\"are%20the%20optional%20tools%20able%20to%20change%20anything%20on%20my%20site%3F\"><h3>Are the optional tools able to change anything on my site?<\/h3><\/dt>\n<dd><p>No. Both tools (site search, page lookup) are read-only \u2014 the assistant can look things up but can never create, edit, or delete anything. The current date and time is supplied automatically and is not a tool at all, so it cannot change anything either.<\/p><\/dd>\n<dt id=\"why%20does%20voice%20not%20connect%20on%20my%20network%3F\"><h3>Why does voice not connect on my network?<\/h3><\/dt>\n<dd><p>Voice connects the browser directly to OpenAI (WebRTC). Because OpenAI's Realtime API does not require STUN\/TURN, this plugin does not use a STUN\/TURN server by default. On a few highly restrictive networks (UDP blocked, symmetric NAT, etc.), voice may fail to connect; please use text chat there. Advanced users can set their own STUN\/TURN servers via window.NECCOSPEAK_RTC_ICE_SERVERS (in that case, that destination becomes something you must disclose).<\/p><\/dd>\n<dt id=\"why%20can%20i%20not%20turn%20the%20voice%20volume%20all%20the%20way%20down%20on%20android%3F\"><h3>Why can I not turn the voice volume all the way down on Android?<\/h3><\/dt>\n<dd><p>This is a Chrome-for-Android behavior, not something this plugin controls: while a voice call is active, the call's audio is tied to the device's in-call volume control, and Android will not let that be lowered all the way to silent. To fully silence the assistant's voice during a call, use the widget's own speaker-mute button in the voice control bar instead of the device volume buttons \u2014 that mutes the assistant completely, on any device.<\/p><\/dd>\n<dt id=\"i%20updated%20the%20plugin%20but%20the%20widget%20still%20looks%2Fbehaves%20like%20the%20old%20version\"><h3>I updated the plugin but the widget still looks\/behaves like the old version<\/h3><\/dt>\n<dd><p>After updating, purge any caching plugin (page cache and, if it has one, a separate \"minify\/combine JS\" cache) and any CDN sitting in front of your site, then hard-reload the page. The widget's front-end JavaScript is loaded from several nested files that browsers and CDNs are free to cache independently of the main plugin file's version number, so a stale copy of just one of those files can outlive the update. If the browser's developer console shows a \"Version mismatch\" warning, that confirms this is exactly what happened.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.3.0<\/h4>\n\n<ul>\n<li><strong>Admin screen<\/strong>: rebuilt around a 9-tab layout (Dashboard, Widget settings, AI settings, Conversation flow, Voice settings, Model &amp; advanced settings, Security, Preview, Change history) with a draft\/publish workflow \u2014 edit freely, review a sticky summary of what changed, then publish when you are ready.<\/li>\n<li>Settings version history now keeps up to 30 generations with one-click rollback, backed by a full audit log of who changed what and when.<\/li>\n<li>The Preview tab renders the widget live inside a sandboxed iframe, so what you see while editing matches the real front end.<\/li>\n<li>Added an icon picker, a call-to-action (CTA) editor, and one-click fetching of the voice models available to your API key.<\/li>\n<li><strong>Chat widget<\/strong>: rebuilt as a same-origin document (<code>?neccospeak_frame=1<\/code>) that the launcher opens inside an iframe, with its own dedicated Content-Security-Policy \u2014 script execution is restricted to same-origin plus a per-request nonce, and network access is restricted to this site and <code>api.openai.com<\/code> only.<\/li>\n<li>Home view with quick actions and CTA buttons, Markdown-formatted replies, session restore across page navigations, and full theme\/launcher customization.<\/li>\n<li>Bootstrap Icons 1.13.1 is now bundled locally for the widget (see \"Third-party resources\" above) \u2014 no CDN request.<\/li>\n<li><strong>Voice chat<\/strong>: the voice session now survives switching between UI views instead of reconnecting from scratch; visitors can switch microphone devices mid-call; voice now follows the visitor's own language; and voice conversation is now blocked while its browser tab is inactive.<\/li>\n<li>Voice fixes: a duplicate greeting on reconnect, a conversation-history ordering bug, the microphone button occasionally failing to reappear, and a crash when the status indicator is turned off.<\/li>\n<li><strong>Content and tools<\/strong>: per-page instructions, an optional page directory, optional read-only tools (site search, page lookup), an optional site content index for on-site search, Contact Form 7 hand-off, and the current date and time now always supplied to both text chat and voice conversation.<\/li>\n<li><strong>Changes you should know about before updating:<\/strong>\n\n<ol>\n<li>The settings screen has moved from \"Settings \u2192 NeccoSpeak\" to its own top-level \"NeccoSpeak\" menu in the admin sidebar \u2014 update any bookmarks.<\/li>\n<li><strong>Purge your page cache and any CDN after updating.<\/strong> Old cached HTML that still references the previous <code>assets\/widget.js<\/code> \/ <code>assets\/widget.css<\/code> front end will 404 until the cache is cleared.<\/li>\n<li>Server-side storage of the conversation log has been removed entirely, and its database table is dropped automatically on update. 0.1.1 never shipped this feature, so no existing data is lost.<\/li>\n<li>The visitor feedback rating, the first-visit privacy notice, and the \"current date\/time\" tool setting have all been removed. The date and time are now supplied automatically at all times instead \u2014 a strict improvement, not a loss of capability.<\/li>\n<li>The previous widget front end has been replaced by the iframe + CSP approach described above.<\/li>\n<li>Voice conversation is now blocked while its browser tab is inactive (new behavior, see \"Voice chat\" above).<\/li>\n<li>Voice chat, quick actions\/CTAs, the read-only tools, per-page instructions, and the Contact Form 7 hand-off are now on by default \u2014 turn any of them off in the relevant settings tab if you don't want them.<\/li>\n<li><strong>Your API key, display rules, appearance settings, and rate limits all carry over unchanged.<\/strong><\/li>\n<\/ol><\/li>\n<\/ul>\n\n<h4>0.1.1<\/h4>\n\n<ul>\n<li>Internationalization: all user-facing strings, including the admin settings screen, now use English as the source language, so the plugin is fully translatable.<\/li>\n<li>Added a bundled Japanese (ja) translation \u2014 sites running in Japanese keep a fully localized admin screen and widget.<\/li>\n<li>Replaced emoji glyphs (launcher, close, microphone) with crisp inline SVG icons that follow the widget's brand color and button states.<\/li>\n<li>No functional changes to chat, voice, security, or data handling.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>Self-contained, BYO-key lightweight AI chat widget.<\/li>\n<li>Text chat (relayed to OpenAI via a thin PHP proxy, full response returned).<\/li>\n<li>Optional voice conversation (off by default; short-lived token + WebRTC connecting the browser directly to OpenAI; HTTPS required).<\/li>\n<li>API key stored encrypted with AES-256-CBC, never sent to the front end, masked in the admin screen.<\/li>\n<li>Per-IP rate limiting, display rules (all pages \/ specific URLs only \/ exclude), appearance customization.<\/li>\n<li>Zero loading and zero external communication when not configured.<\/li>\n<\/ul>","raw_excerpt":"Let visitors talk to your website \u2014 an AI agent with text chat and real-time voice, on your own OpenAI key. No SaaS, no extra account, no monthly fee.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/mlt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/332521","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mlt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/mlt.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/mlt.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=332521"}],"author":[{"embeddable":true,"href":"https:\/\/mlt.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/neccos"}],"wp:attachment":[{"href":"https:\/\/mlt.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=332521"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/mlt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=332521"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/mlt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=332521"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/mlt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=332521"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/mlt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=332521"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/mlt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=332521"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}