Turn your WordPress content into answers visitors can trust.
Achla AI Search gives visitors a concise answer drawn from your public pages
and links every answer to its sources. They can ask naturally, in their own
language, and get an answer instead of digging through a list of search
results.
Achla is managed end to end. You do not need an OpenAI, Gemini, or other model
API key. There is no separate model-provider account to fund, no prepaid model
credits to monitor, and no embeddings database or search backend
to maintain. Achla handles crawling, indexing, model calls, signed widget
releases, and usage controls.
Start free with 30 searches per month and up to 30 indexed pages — no card
required. Paid plans include a fixed number of searches, so you budget in
searches rather than LLM tokens.
Connection actions require a WordPress administrator and use short-lived,
server-generated proof. Credentials remain server-side. Widget releases are
signed and verified before they run in the browser; if verification fails,
the widget stays off. A cloned site or a move to another subdomain requires
ownership verification again.
Visual styling is managed in the Achla dashboard. This plugin controls whether
the widget is active and where it is placed. HTTP sites show a persistent
reduced-security warning.
This plugin requires the third-party Achla AI Search service at
https://achlaai.com. The service crawls permitted public content, builds and
maintains the index, generates cited answers, provides widget configuration,
and manages service billing.
Ownership connection. When an administrator clicks Connect, Resume, or
Reconnect, the plugin sends the site origin, WordPress callback URL, and a
short-lived ownership challenge to Achla. The secret verifier is sent only
after WordPress validates Achla’s signed callback. WordPress then stores the
site binding, project identifier, public widget key, and a server-side
management credential.
Lifecycle status and health. While connected, WordPress makes paced,
authenticated requests to read project and index status. Diagnostics can
contain only the classified states ATTACH_TARGET_MISSING and
RELEASE_UNAVAILABLE, software versions, status classifications, and
timestamps. They do not contain page content, visitor questions, email
addresses, IP addresses, cookies, secrets, arbitrary URLs, or stack traces.
Disconnect. An administrator disconnect, or uninstall best effort,
revokes the installation binding and management credential. It does not
cancel an Achla subscription.
Signed widget release. WordPress periodically requests a signed control
and manifest from Achla. The connector checks its signature, expiry,
compatibility, rollback state, immutable asset URL, and Subresource
Integrity value. The browser loads only a verified release.
Widget use. The verified widget uses Achla’s widget configuration and
search APIs. When a visitor asks a question, Achla receives the question,
the site’s public widget key, the page origin, and the visitor’s IP address
carried by the HTTPS request. These data are used for site binding, abuse
controls, and returning an answer from the indexed public content.
The plugin’s three public WordPress REST routes are limited to a signed
ownership callback, a no-store release decision, and nonce-protected,
same-origin runtime diagnostics. All management routes require an
administrator capability and WordPress REST nonce.
The local bridge does not use cookies, browser storage, advertising
identifiers, iframes, or page-content telemetry. Review the service terms
before enabling the widget: