You already have the data. Search Console shows what people search for. Analytics shows what visitors do. An SEO plugin grades each post. Somewhere, an AI answer engine is describing your business to a buyer, and nothing on your site records it. Each tool is right about its own column. None of them is the page.
RankSage joins every signal that decides whether a page gets found, on one row, the page: search demand, what AI answers say about you, content quality, competitors, technical health and visitor behaviour. Out comes one ranked list of what to change, with the evidence behind each item, and a check afterwards on whether the change worked.
RankSage Connect is the WordPress side of that join. Connect once and your site contributes the signals no browser script can collect, and receives the fixes and index pings RankSage sends back.
Every score RankSage shows is derived from stored evidence you can open. When a check cannot run, it says so. If a page cache or CDN is hiding part of your crawler traffic, the settings screen tells you which one and gives the exclusion steps for it, so you read a count you can trust rather than one that quietly undercounts.
Founders, marketers and agencies who run WordPress sites and want to know what to fix next without stitching exports together. You do not need to be technical. Connect, then read the list.
The plugin sends nothing anywhere until you click Connect. Disconnect from the same screen and everything stops at once.
AI crawlers never run JavaScript, so the only place their visit exists is on your server, before any page cache answers. The plugin takes that record on the request itself, buffers it locally and sends it to RankSage on a schedule. A normal page view costs one user-agent check.
Full-page caches serve pages without running PHP, and no plugin can see those requests. RankSage Connect recognises WP Rocket, LiteSpeed Cache, W3 Total Cache, WP Super Cache, SiteGround Optimizer, WP Engine, Kinsta and WordPress VIP and gives you the exclusion steps for each. Edge caches such as Cloudflare cannot be seen from PHP at all. For complete coverage behind an edge, RankSage offers a Cloudflare Worker snippet that runs at the edge itself.
We would rather over-explain than surprise you. The plugin contacts no server until you connect. After you connect it talks only to RankSage, the crawler feature never records a human visitor, and no RankSage secret is stored on your site. The complete disclosure of every request, what it contains and when it happens follows. It is long on purpose.
This plugin connects your site to RankSage, an external SaaS product operated by RankSage. It needs a RankSage account to do anything.
Nothing below happens until you click “Connect to RankSage” and finish signing in. Before that the plugin contacts no server and adds nothing to your pages. Disconnecting (Settings RankSage Disconnect) stops every item below immediately.
https://app.ranksage.com/wp-connect in your browser.All of these requests go from your web server to https://api.ranksage.com, never from your visitors’ browsers.
/api/v1/wordpress/wp-connect/exchange): once, when you connect. Sends the single-use code RankSage gave you, your site URL, the plugin version and the name of any detected page-cache plugin. RankSage answers with a signed configuration containing your public tracking key, a site token and your IndexNow key./api/v1/wordpress/plugin-config): about once a day while connected. Sends the plugin version and your site URL (in the user-agent header) and the site token. The response (the AI-crawler user-agent list, batch sizes, a kill switch, your IndexNow key) is verified with an Ed25519 signature before use and can never change which server the plugin talks to./api/v1/tracking/bot-hits): only while “AI-crawler capture” is on. For each request whose user-agent matches a known AI crawler, the plugin stores the crawler’s user-agent string, the requested path (query string removed) and a timestamp in a local table, and sends them in one batched request roughly every five minutes, identified by your public tracking key. No visitor personal data, no IP addresses, no query strings, no post content. Ordinary human traffic is never recorded by this feature.Only while “Tracking tag” is on. The plugin adds https://www.ranksage.com/rs.js to your front-end pages, with your public tracking key. Each visitor’s browser downloads the script from www.ranksage.com and sends its events to https://api.ranksage.com/e. Events are encrypted in the browser before they are sent.
What the script collects about each visit:
name attribute) was focused and for how long, and whether the form was submitted or abandoned. Field values are never read or sent.DNT: 1), which switches the script to an aggregate-only mode with no fingerprint, no click and no form data.What the script stores in the visitor’s browser: one localStorage entry, rs_consent, written only when a visitor opts out, so the opt-out persists. The script sets no cookies. A site owner or consent manager can stop tracking for a visitor by setting window.__RS_OPT_OUT__ = true before the script loads, or by calling window.RanksageTracker.optOut().
You are the data controller for your visitors’ data. If your visitors are in a jurisdiction that requires consent for analytics or device fingerprinting (for example the EU/UK under GDPR and ePrivacy), load the tag only after consent, or turn “Tracking tag” off and keep AI-crawler capture only — that feature never touches human visitors.
The plugin makes no IndexNow request itself. It answers GET /<your-key>.txt on your own site with your IndexNow key so that IndexNow-participating search engines (Bing, Yandex, Naver, Seznam and others) can confirm that RankSage is allowed to notify them — from RankSage’s servers, via https://api.indexnow.org — when your pages change. The key is public by design. See https://www.indexnow.org/terms for the IndexNow terms.
Your RankSage public tracking key (the same key visible in your page source), the site token, your IndexNow key, your two toggle preferences, the local AI-crawler buffer table, and, per administrator, whether they dismissed the page-cache notice. No RankSage secret or password is ever written to your site. Deleting the plugin removes all of it.
wp-config.php (the RANKSAGE_CONNECT_API_BASE, RANKSAGE_CONNECT_APP_BASE and RANKSAGE_CONNECT_SCRIPT_SRC constants) or with the ranksage_connect_app_base filter. The plugin never downloads, evaluates, includes or writes executable code.