Description
Cognitcxt AI Chat Assistant for WooCommerce adds an AI customer support assistant to your store. It answers the questions that fill your support inbox — “Where is my order?”, “Can I return this?”, “Do you have this in blue?” — instantly and around the clock, using live data from your WooCommerce store instead of canned replies.
What your customers can ask:
- Order tracking and order history
- Refund and return requests, and order cancellations
- Product questions and catalog search
- Shipping, payment and store-policy questions
- Account questions, complaints and feedback
Why store owners use it:
- Fewer support tickets — routine order and refund questions are resolved without a human.
- Always accurate — every answer is built from your live orders, products and policies.
- Live in minutes — install the plugin, paste your license key, and the widget appears on your store.
- More than web chat — from your Cognitcxt dashboard the same assistant can also answer customers on WhatsApp, voice calls and email.
Try it first in the live demo store. Plans start at $20 per store per month — see pricing.
Plugin features:
- Floating chat bubble that auto-injects into your site footer — no shortcode required
- Shortcode
[cognitcxt_chat]for manual placement with position, width, and height options - License key authentication — only activated sites can use the widget
- Supports multiple license keys per site (e.g. multi-store setups)
- Display control — show the widget on all pages or select specific pages/posts
- Demo mode — let unauthenticated visitors preview the chat on a marketing page
- Works with WooCommerce 5.x and above for product and order look-ups
- Integrates with the MCP (Model Context Protocol) standard for AI tool use
- Compatible with WooCommerce 9.x shared MCP adapter — no conflicts
Requirements:
- WordPress 5.8 or later
- PHP 7.4 or later
- WooCommerce (for product and order features)
- HTTPS / SSL enabled on your site
- A valid Cognitcxt license key (available at cognitcxt.com)
- Visitors must be logged in to use the chat widget (the widget identifies users by their WordPress user ID to look up orders and account data)
External Services
This plugin connects to the Cognitcxt service hosted at https://cognitcxt.com to validate and activate license keys. This connection is initiated only by a site administrator from the plugin settings page — it is never triggered automatically in the background without admin action.
What data is sent and when:
-
License activation / validation (POST request to the Cognitcxt license activation endpoint at cognitcxt.com)
Triggered when an admin clicks Activate License or Add & Validate in the plugin settings.
Data sent:- License key entered by the admin
- Site URL (
home_url()) - A randomly generated API secret (auto-created on plugin activation, stored in
wp_options) - WordPress username and a WordPress Application Password (used by the Cognitcxt backend to authenticate REST API requests from the AI to your site)
- Platform identifier (
WOOCOMMERCE)
-
License re-validation (POST request to the Cognitcxt license validation endpoint at cognitcxt.com)
Triggered when an admin switches the active license in the Activated Licenses tab.
Data sent:- License key
- Site URL
No data is sent to external servers on the front end or during normal page loads. The chat widget itself is loaded in an iframe from the URL configured in the plugin settings (default: https://cognitcxt.com/widget/). The iframe receives the license key, a WordPress user ID, and the site URL as URL parameters so the chat UI can authenticate requests.
Cognitcxt service links:
- Service home: https://cognitcxt.com
- Privacy Policy: https://cognitcxt.com/privacy
- Terms of Service: https://cognitcxt.com/terms
Security and Vulnerability Disclosure
To report a security vulnerability in this plugin, please email contact@connexion-technologies.com with a description of the issue, steps to reproduce, and any relevant proof-of-concept. We aim to acknowledge reports within 48 hours and to release a patch within 14 days for critical vulnerabilities.
Please do not disclose vulnerabilities publicly until we have had a reasonable opportunity to investigate and remediate. We do not currently operate a bug bounty programme, but we are committed to crediting reporters in release notes where disclosure is consented to.
This policy is maintained in compliance with the EU Cyber Resilience Act, which requires commercial WordPress plugin developers distributing software to EU users to have a formal vulnerability disclosure process in place by September 2026.
Installation
- In your WordPress admin go to Plugins Add New, search for Cognitcxt, then click Install Now and Activate.
- Go to Cognitcxt Chat in the WordPress admin menu.
- Follow the Getting Started tab:
- Make sure your site uses HTTPS and WooCommerce is active.
- Paste your license key (get one at cognitcxt.com) and click Activate License.
- The chat widget will automatically appear on your site once the license is active.
Manual installation
- Download the plugin zip from this page.
- In your WordPress admin go to Plugins Add New Upload Plugin, choose the zip, and click Install Now.
- Alternatively, unzip and upload the
cognitcxt-chat-widgetfolder to/wp-content/plugins/via FTP/SFTP. - Activate the plugin through the Plugins screen, then follow steps 2–4 above.
FAQ
-
Do visitors need to be logged in?
-
Yes. The chat widget requires visitors to be logged in to a WordPress account. It identifies users by their WordPress user ID in order to retrieve their orders and account information from WooCommerce. Logged-out visitors are shown a “Please log in” prompt instead of the chat window. Use Demo Mode if you want unauthenticated visitors to preview the chat using a test account.
-
Do I need WooCommerce?
-
WooCommerce is required for product and order look-up features inside the chat. The widget itself will load without WooCommerce, but AI responses about orders and products will not be available.
-
Does this plugin work without HTTPS?
-
No. HTTPS is required to safely transmit the license key and WordPress Application Password to the Cognitcxt backend. The plugin will refuse to activate a license over plain HTTP.
-
Where do I get a license key?
-
Log in to your account at cognitcxt.com, choose a plan, and copy the license key shown in your dashboard.
-
What is the API Secret?
-
The API secret is a randomly generated token (created automatically on plugin activation) that the Cognitcxt backend uses to authenticate its requests to your site’s REST API. You can rotate it at any time from the Settings tab.
-
Can I use the shortcode instead of the auto-injected widget?
-
Yes. Add
[cognitcxt_chat]to any page or post. Optional parameters:position—bottom-right(default),bottom-left,top-right,top-leftwidth— widget width, e.g.400px(default:350px)height— widget height, e.g.700px(default:600px)
-
Can I show the widget on specific pages only?
-
Yes. Uncheck Show on all pages in the Settings tab and select the pages/posts where the widget should appear.
-
What is Demo Mode?
-
Demo mode lets unauthenticated visitors see the chat widget on pages with
?cgx_demo=1in the URL, using a designated WordPress user’s store data. Useful for marketing or live demo pages. -
How do I remove all plugin data?
-
Deleting the plugin via the WordPress admin triggers the uninstall routine, which removes all
cognitcxt_*options from the database and revokes the WordPress Application Password created by the plugin.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Cognitcxt AI Chat Assistant for WooCommerce” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Cognitcxt AI Chat Assistant for WooCommerce” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
2.3.3
- Security: Re-activating a license on a different domain now requires the activation token issued at the original activation, instead of trusting client-supplied origin headers. A leaked license key can no longer be activated on an unauthorized domain, which would repoint the assistant at a store the attacker controls.
- Security: A “License domain changed” email is now sent to the account email address whenever a license moves to a new domain, so an unauthorized re-bind is visible to the store owner.
- Fix: Every activation call (automatic re-activation, the Activate button, adding a key, and regenerating the API secret) now sends the stored activation token, so a store that migrates to a new domain re-activates on its own rather than failing with a re-bind error.
- Fix: When re-activation is refused because the domain does not match the bound one, the error now explains how to resolve it: set the new domain on the license in the Cognitcxt dashboard, then activate again.
2.3.2
- Naming: Renamed the plugin to “Cognitcxt AI Chat Assistant for WooCommerce” to resolve a WordPress.org Plugin Directory trademark naming violation (display name no longer leads with the WooCommerce trademark).
2.3.1
- Fix: WooCommerce cart session double-serialization bug that caused guest/customer carts to report as empty in MCP tool calls.
- Fix: Product sync cap to enforce a maximum of 100 products per request.
2.3.0
- Security: Domain binding for license activation now uses a signed, server-issued token instead of the client-controlled Origin/Referer headers, preventing license replay from unauthorized domains.
- Security: Chat widget now authenticates using short-lived, domain-bound widget tokens minted per page render instead of embedding the license key in the browser, closing key-scraping from page source.
- Security: /validate now requires the activation token, preventing apiKey exfiltration by key-only callers.
- Fix: WordPress application password is now reused across activations instead of being revoked and recreated each time, so concurrent activations can no longer leave the chat assistant with a revoked credential.
- Security: Anonymous sessions (chat visitors, Call Assist, WhatsApp, CMS) now get a unique per-session guest token instead of a shared hardcoded token that previously resolved every anonymous session to the site admin — guests can no longer impersonate a registered user or the store administrator.
2.2.5
- Fix: Prevent session timeouts and connection drops in ElevenLabs integration by ensuring active socket connections during long WooCommerce database queries.
2.2.4
- Fix: Build customer session data for MCP cart abilities from the persisted session record and live cart keys instead of accessing WC_Session’s protected properties, ensuring correct data is returned for the requested user without relying on internal implementation details.
2.2.3
- Security: Removed user-impersonation (wp_set_current_user) from the WooCommerce cart bootstrap and MCP CLI command to prevent identity-switch side effects and session data leakage.
- Security: Tightened REST ability permission checks so individual ability schemas respect each ability’s own permission callback, not just a baseline ‘read’ capability.
2.2.2
- Fix: Removed str_starts_with() usage that was incompatible with the plugin’s declared minimum WordPress version (5.8).
2.2.1
- Refactor: Renamed the internal CogniTcxt PHP namespace to Cognitcxt for consistent naming.
- Refactor: Renamed internal PHP classes and constants to use the Cognitcxt naming convention consistently.
2.2.0
- Security: Customer-specific MCP abilities (get-cart, update-cart-item, apply-coupon, order-history, manage-account, request-refund) now require a short-lived session_token instead of a caller-supplied user_id, preventing IDOR access to other customers’ data.
- Naming: Renamed all internal mcp_adapter_ filter/action hook names to cognitcxt_mcp_ to avoid potential conflicts with other plugins.
2.1.1
- Update security vulnerability disclosure contact email
2.1.0
- Security: cognitcxt_mcp_permission_check() now requires manage_woocommerce instead of only is_user_logged_in()
- Security: cancel-order, log-feedback, and search-products abilities upgraded to admin-level permission check (manage_woocommerce)
- Security: MCP HTTP transport endpoint now requires manage_woocommerce via mcp_adapter_default_transport_permission_user_capability filter
- Security: internal mcp-adapter abilities (discover-abilities, get-ability-info, execute-ability) now require manage_woocommerce instead of read
2.0.0
- Complete rewrite with license key authentication
- Multi-license support (manage multiple store keys from one WordPress install)
- Bundled MCP Adapter for AI tool-use integration with WooCommerce
- Bundled Abilities API for registering WordPress actions as AI-callable tools
- WooCommerce 9.x compatibility — reuses WooCommerce’s shared MCP adapter when available
- Demo mode for unauthenticated preview links
- HTTPS enforcement for all credential transmissions
- Automatic WordPress Application Password creation and rotation
- Per-page display control
1.0.0
- Initial release