If you already build widgets in Sorraia, this plugin saves you from copying script tags around. Connect your site once, then pick a widget from a list — as a block, or a shortcode.
It is a thin wrapper. The widgets themselves are built, styled and served by Sorraia; this plugin only asks Sorraia which widgets exist on your site (and, when you press Verify, to verify the site), and places the same container and loader script the embed code from your Sorraia dashboard would.
You need a Sorraia account. This plugin is a client for that service and does nothing on its own. Sorraia has a free plan; see sorraia.app.
Why use it instead of pasting the snippet yourself?
Two honest reasons, and only two:
<script> on save from anyone without the unfiltered_html capability — always the case on multisite, and common on single sites where a security plugin has removed it. The block saves cleanly and the script is simply gone. This plugin renders the snippet when the page is displayed, so WordPress never stores it and never strips it.If you only need one form on one page and you have unfiltered_html, a Custom HTML block works fine and you do not need this plugin.
Placing a widget
Every widget gets a shortcode you can paste anywhere, and a Sorraia widget block for the block editor. From the settings screen you can also add a widget to several pages at once by ticking them in a list, or draft a new page containing it. Each row tells you which pages already carry that widget, so you are not guessing.
Everything the plugin writes to a page is appended to the end of the content. It never rewrites, reorders or removes anything already there, and it saves a revision first, so the change is undoable from WordPress’s own revision history.
What it does not do
This plugin connects to Sorraia, a hosted widget service operated by Sado Labs, Inc. The plugin cannot work without it: the widgets are built, stored and served by Sorraia, and this plugin is a client for that service.
There are three separate kinds of request, and they are worth telling apart. Two leave your site. One arrives at it.
1. From your server, to list your widgets and to prove you control this site
Your site makes HTTPS requests from PHP to the Sorraia API — https://api.sorraia.app by default. The API address in Settings Sorraia can point at another Sorraia environment if Sorraia support asks you to, but only at a sorraia.app address; the plugin refuses any other host. Three endpoints are called, and no others:
GET /v1/site-catalog — the widget list. Requested when you press Connect; when you press Refresh; when the Settings Sorraia screen is loaded and the five-minute cached copy has expired; and when the block editor needs the widget list to populate the block’s picker.GET /v1/site-verification — whether Sorraia considers this site verified. Requested when you press Connect or Refresh, and when you press Verify — before the check, and again after it succeeds.POST /v1/site-verification/attempt — asks Sorraia to run the check now. Requested only when you press Verify.What is sent: your Sorraia site key, in an x-sorraia-site-key request header; and a User-Agent string identifying the plugin version and this site’s home URL (for example Sorraia-WordPress/1.2.4; https://example.com/). None of the three sends page content, form submissions or anything about your visitors.
What comes back: from the catalog, the connected site’s name and domain, and a list of your widgets — name, type, id, and whether each is paused. From the two verification endpoints, this site’s domain, whether it is verified, which method verified it, when it was checked, and this site’s verification token with the instructions for publishing it — while the site is not verified, and for as long as this plugin is what verified it, because Sorraia’s daily re-check needs the plugin to keep serving it. No submissions, bookings, orders or customer data are returned, and the site key cannot request them.
2. From Sorraia’s servers, to your site — the one that comes inward
When you press Verify, Sorraia’s servers make an HTTPS request to your own site’s URL, from outside, looking for the verification token. They try /?rest_route=/sorraia/v1/verify first and, if that does not answer, /wp-admin/admin-ajax.php?action=sorraia_verify. While the site is verified, Sorraia repeats the same check about once a day. This plugin answers both paths with the verification token and nothing else, and it has nothing to answer with until you have connected a site key.
This is the only request here that your site receives rather than makes, which is why it is called out separately: it comes from a third party’s servers, it happens when you press Verify and in that daily re-check, and it will show up in your access log and in any security plugin that reports unfamiliar visitors.
The verification token is not a credential. It is a random, one-per-site string whose only job is to prove that whoever controls this site also controls the Sorraia account, so it is meant to be published — that is the entire mechanism, and there is nothing about it to keep secret. The site key is the opposite: it is a credential, and it never leaves your server.
3. From your visitors’ browsers, to render a widget
When a page containing one of your widgets is displayed, the visitor’s browser loads that widget’s script from the same Sorraia host (for example https://api.sorraia.app/api/embed/12.js), and the widget then talks to Sorraia to do its job — submit a form, look up booking availability, or start a checkout. This is the same script the embed snippet from your Sorraia dashboard loads; the plugin writes the widget’s container and adds that script through WordPress’s script queue.
This means your visitors’ browsers contact Sorraia, and Sorraia receives whatever the widget is for — for example the contents of a form a visitor submits. Nothing is sent to Sorraia from a page that has no Sorraia widget on it.
Along with what a visitor submits, the widgets tell Sorraia which site they are on. The AI chat (with each message) and the WhatsApp launcher (on each tap) also send the page’s address and any utm_ parameters in it. If the page runs WhatConverts call tracking, the widgets also pass along WhatConverts’ visitor id (its wc_client_current cookie), so a lead is credited to the right campaign. The AI chat keeps a conversation token in the visitor’s browser storage, so reloading the page continues the same chat.
By connecting a site key you agree to Sorraia’s terms and privacy policy:
This plugin’s own code contacts no service but Sorraia, and loads no fonts, analytics or assets from anywhere else. The widgets it places are served by Sorraia, and depending on how a widget is set up, a visitor’s browser may also contact:
fonts.googleapis.com and the font files from fonts.gstatic.com as soon as the widget loads, which gives Google the visitor’s IP address and browser details. Any other font setting loads nothing from Google. Privacy Policy: https://policies.google.com/privacywa.me with your business number and the pre-filled message, which can include the page’s title and a reference code. Privacy Policy: https://www.whatsapp.com/legal/privacy-policy