Title: Tactical — AI Agent Analytics for WooCommerce
Author: sourabhnk
Published: <strong>May 21, 2026</strong>
Last modified: September 28, 2026

---

Search plugins

![](https://ps.w.org/tactical-agent-detection/assets/banner-772x250.png?rev=3715412)

![](https://ps.w.org/tactical-agent-detection/assets/icon.svg?rev=3715128)

# Tactical — AI Agent Analytics for WooCommerce

 By [sourabhnk](https://profiles.wordpress.org/sourabhnk/)

[Download](https://downloads.wordpress.org/plugin/tactical-agent-detection.1.4.0.zip)

 * [Details](https://zgh.wordpress.org/plugins/tactical-agent-detection/#description)
 * [Reviews](https://zgh.wordpress.org/plugins/tactical-agent-detection/#reviews)
 *  [Installation](https://zgh.wordpress.org/plugins/tactical-agent-detection/#installation)
 * [Development](https://zgh.wordpress.org/plugins/tactical-agent-detection/#developers)

 [Support](https://wordpress.org/support/plugin/tactical-agent-detection/)

## Description

AI assistants are shopping WooCommerce stores. Some send crawlers that never run
JavaScript, some drive a browser that behaves like a person, and some send people
who then buy. Standard analytics sees little of it: Google Analytics excludes known
bots, and you can’t turn that off ([Google Analytics Help](https://support.google.com/analytics/answer/9888366));
crawlers never fire an analytics tag; and an agent browser is counted as a person.

This plugin connects your store to **Tactical**, a third-party service at https://
tactical-app.work, which shows you the rest. The plugin installs the storefront 
script, adds server-side crawler detection and registers the WooCommerce webhooks;
the dashboard lives in your Tactical account.

**What you get:**

 * **AI crawlers, server-side** — when a known AI crawler requests a page, the plugin
   records it, no JavaScript needed. A hit is marked verified only when its IP matches
   the operator’s published range. Nothing is sent for human visitors.
 * **Agent browsers, by behaviour** — sessions driven by an agent, including ones
   that never name themselves, are scored on how the session behaves. A score is
   a probability, not a verdict.
 * **AI-referred buyers** — people who arrive from ChatGPT, Perplexity, Gemini, 
   Copilot and other assistants.
 * **Agent revenue** — every order is labelled: Agent order, Agent order (session
   match) or AI-referred order, each saying how sure it is, and the two kinds are
   never added together. Agent orders include ones placed in an agent checkout, 
   such as Stripe’s agentic checkout, which no browser pixel sees.
 * **Evidence for every agent order** — a record of the order, how it was attributed,
   the matched session and any Tactical Gate decisions, downloadable as PDF and 
   JSON for disputes and returns. It holds no buyer name, email, address or IP address.
 * **Tactical Gate (beta)** — rules for AI agents by product, cart and checkout,
   starting in Observe mode. It is in a private beta; join the list at https://tactical-
   app.work/waitlist.

**Tactical pricing — managed at tactical-app.work:**

The plugin works on every plan, including the free one. Agent revenue and evidence
are on every plan, with the plan’s history.

 * **Scout — free** — 7-day monitor, top 3 agent types, AI Search report, 100 agent
   sessions/week. No credit card.
 * **Radar — $39/mo** — 90-day history, all agent types, intent signals, product
   interest map (top 50), 10,000 agent sessions/mo.
 * **Command — $129/mo** — everything in Radar, plus marketplace-referral and price-
   check signals, unlimited products, 50,000 agent sessions/mo.

Annual plans save about 25%.

**Multi-platform:**

This plugin is for WooCommerce. The same Tactical account also works on Shopify (
via the Shopify App Store) and on any custom storefront (via a script tag).

### External services

This plugin connects to **Tactical** at https://tactical-app.work — a third-party
AI agent analytics service operated by the plugin author. The plugin requires an
active Tactical account (free Scout tier is sufficient) to function. Without an 
API key configured on the settings page, no requests are made.

**Endpoints used:**

 * **Snippet ingest** — `https://tactical-app.work/api/ingest`. The detection script(`
   https://tactical-app.work/snippet.js`) loads on every storefront page view and
   posts an event payload containing: an anonymised session ID, page URL (path +
   query string only), referrer domain, user-agent string, scroll/mouse/timing heuristics,
   and your store’s API key. No customer PII (no names, emails, IP addresses, payment
   data, or form contents) is sent.
 * **Connection verification** — `https://tactical-app.work/api/verify-connection`.
   Triggered only when an admin clicks “Verify connection” on the settings page.
   Sends only your API key (in a request header) so Tactical can confirm the key
   belongs to this store. No event data.
 * **WooCommerce webhooks** — `https://tactical-app.work/api/wc-webhook/<topic>`.
   Once an API key is saved, four webhook subscriptions are registered with WooCommerce(`
   order.created`, `order.updated`, `product.created`, `product.updated`). WooCommerce
   delivers these payloads directly to Tactical with WC’s standard HMAC signature
   when matching events occur on your store. Payload contents are WooCommerce’s 
   standard webhook bodies (order or product objects).
 * **Agent key directories (Tactical Gate, 1.4.0)** — when a request to your store
   carries a Web Bot Auth signature (the `Signature`, `Signature-Input` and `Signature-
   Agent` headers) naming a signer in Tactical’s agent registry, the plugin fetches
   that signer’s public key directory to check the signature: `https://chatgpt.com/.
   well-known/http-message-signatures-directory` (OpenAI, ChatGPT agent) or `https://
   agent.bot.goog/.well-known/http-message-signatures-directory` (Google, Google-
   Agent). It is a plain GET with no cookies and nothing about your store or its
   visitors, made at most once per five minutes to an hour per signer (the answer
   is cached in a transient), and only while the Gate has a policy. Unsigned requests,
   the usual case, fetch nothing. OpenAI: https://openai.com/policies/terms-of-use
   and https://openai.com/policies/privacy-policy. Google: https://policies.google.
   com/terms and https://policies.google.com/privacy.

**Conditions:** events are only sent after you paste a valid API key on the settings
page. Without a key, the snippet does not load, no requests are made, and no webhooks
are registered.

**Service terms:**

 * Tactical Privacy Policy: https://tactical-app.work/privacy
 * Tactical Terms of Service: https://tactical-app.work/terms

## Installation

 1. Upload the `tactical-agent-detection` folder to `/wp-content/plugins/`, or install
    via the Plugins  Add New screen.
 2. Activate the plugin. (WooCommerce must be installed and active first; this plugin
    declares it as a required dependency.)
 3. Sign up at https://tactical-app.work and copy your API key from the dashboard.
 4. Go to Settings  Tactical and paste the API key.
 5. Click “Verify connection” — you should see a green checkmark.
 6. Open your storefront — Tactical starts classifying agent traffic immediately.

The plugin auto-registers WooCommerce webhooks for `order.created`, `order.updated`,`
product.created`, and `product.updated` so order and catalog activity is correlated
with agent sessions.

## FAQ

### Do I need a Tactical account to use this plugin?

Yes — sign up free at tactical-app.work. The free Scout tier is 100 agent sessions
per week with no credit card.

### What data does the plugin collect?

The storefront script sends anonymised session metadata only: user-agent, page URL,
referrer, scroll/mouse heuristics, and product context, with no names, emails, IP
addresses or payment data. The order webhooks deliver WooCommerce’s standard order
body, which includes the customer’s details; Tactical keeps only the order ID, total,
currency, line items and how the order was attributed, uses the buyer’s IP address
and user-agent once to match the order to a session, and discards the rest.

### How is agent traffic detected?

Named crawlers and fetchers are matched against Tactical’s registry of AI operators
by user agent, and verified against the operator’s published IP ranges where there
are any. Browser sessions are scored on behaviour and environment (page-timing regularity,
interaction signals, a datacenter network, automation flags); the IP itself is not
stored. The dashboard updates in 15-minute batches.

### What about agents that don’t identify themselves, like Meta’s Muse?

A named crawler (GPTBot, PerplexityBot, ClaudeBot) says who it is in its user-agent,
so server-side detection catches it outright. An agent browser — Meta’s Muse, OpenAI’s
Operator — drives a real browser on a shopper’s behalf, and it visits your store
whether or not you’re a commerce partner of theirs. No request-layer fingerprint
for Muse has been published by anyone yet, so a user-agent list can’t see it. Tactical’s
behavioural layer scores the session itself (page-timing regularity, interaction
signals, browser environment). In a September 2026 test, an AI-driven browser scored
as an agent and a person in Chrome on the same laptop scored as human; a real Muse
session has not yet been confirmed. Tactical’s agent registry tracks Muse as fingerprint
research, and a confirmed signature goes live without waiting for a plugin release.

### Will this slow down my site?

The storefront script loads with the `defer` attribute (about 8 KB gzipped), and
classification happens on Tactical’s servers, not yours. Server-side crawler detection
does nothing for human visitors: it sends a small, non-blocking request only when
a request’s user agent matches a known AI crawler.

### How do I cancel?

Cancel from the Tactical dashboard’s billing page at tactical-app.work. The plugin
keeps working on the free Scout tier after cancellation.

### Where’s my data stored?

In Tactical’s Postgres database. Sessions, product views and Gate decisions are 
deleted after 90 days and AI crawler visits after 180 days; order records and their
evidence are kept while your store is connected. Details: https://tactical-app.work/
privacy

### Is this GDPR-compliant?

Tactical processes data under the legitimate-interest legal basis. It stores no 
names or contact details of visitors or buyers, and merchants can request deletion
at any time by emailing support@tactical-app.work. A Data Processing Addendum is
available on request.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Tactical — AI Agent Analytics for WooCommerce” is open source software. The following
people have contributed to this plugin.

Contributors

 *   [ sourabhnk ](https://profiles.wordpress.org/sourabhnk/)

[Translate “Tactical — AI Agent Analytics for WooCommerce” into your language.](https://translate.wordpress.org/projects/wp-plugins/tactical-agent-detection)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/tactical-agent-detection/),
check out the [SVN repository](https://plugins.svn.wordpress.org/tactical-agent-detection/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/tactical-agent-detection/)
by [RSS](https://plugins.trac.wordpress.org/log/tactical-agent-detection/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.4.0

 * **Tactical Gate verifies signed agents.** An agent that signs its requests with
   Web Bot Auth (HTTP Message Signatures) is checked against its operator’s published
   keys: today ChatGPT agent and Google-Agent (on some of its requests). A valid
   signature makes the visitor that agent at the “verified” tier, even when its 
   user agent looks like ordinary Chrome, so “Declared and verified agents are welcome”
   in _Assistant etiquette_ and _Drop protection_ now applies, and a verified agent
   is no longer asked to identify at checkout.
 * An invalid signature (tampered, expired, or for another site) never counts as
   verified; the visitor is treated as before and the decision log says why. Nothing
   is blocked because of a signature.
 * Only signed requests are checked. The signer’s key directory is fetched with 
   a one-second timeout, never follows a redirect, and is cached for five minutes
   to an hour; if it can’t be fetched the Gate decides as if there were no signature.
   Ed25519 signatures only, the algorithm every signer uses today.
 * The agent registry adds Google-Agent.

#### 1.3.0

 * **Tactical Gate sees agents that don’t name themselves.** At add-to-cart and 
   checkout, for a visitor that names no agent, the plugin asks Tactical whether
   that visitor’s session was classified as an agent browser in the last 30 minutes,
   and how sure it was, and the rules use the answer. This is what lets _Drop protection_
   and _Assistant etiquette_ (formerly Amazon-style) reach an agent that never identifies
   itself. Only the Gate’s one-way hash of IP and user agent is sent, never the 
   IP; the lookup times out after half a second and is cached for 30 seconds; slow
   or failed means the Gate decides as before. Page views are never looked up.
 * A visitor Tactical reads as a person, or isn’t sure about, is still never restricted,
   and blocking still needs high confidence. Tactical can misread a person as an
   agent, who could then be asked to identify at checkout in Enforce mode; every
   policy starts in Observe mode.

#### 1.2.0

 * **New: Tactical Gate.** Enforce the agent policy you set on tactical-app.work
   in the request path: throttle, require identification, challenge, redirect or
   block AI agents by identity, category, confidence and scope (paths, products,
   collections, cart, checkout, schedule). Fetches the compiled policy every five
   minutes with an ETag, applies it on page requests, add-to-cart and checkout, 
   and reports decisions in batches.
 * Every policy starts in Observe mode, where rules only tag. People are never restricted,
   whatever the policy says, and a search engine only when the policy names it and
   confirms the SEO impact. No policy, a failed fetch or any error means the request
   passes untouched.
 * New settings toggle “Tactical Gate” (on by default; a no-op until a policy exists)
   with policy version, mode and last-fetch status.
 * The settings page now recreates any missing Tactical webhooks (for example after
   WooCommerce was activated after this plugin), instead of asking you to reactivate.

#### 1.1.0

 * **New: server-side AI crawler detection.** Detects AI crawlers that don’t run
   JavaScript (most retrieval crawlers) by matching the request user-agent against
   a maintained registry of AI operators (OpenAI, Anthropic, Perplexity, Google,
   Meta, Apple, Amazon, ByteDance, Mistral, DuckDuckGo, and more). Fires only on
   a matched AI user-agent; human visitors trigger nothing.
 * Non-blocking delivery (`wp_remote_post` with `blocking => false`, 1s timeout)
   and a 60-second per-(agent, URL) dedup guard against crawler bursts.
 * New settings toggle “Server-side AI crawler detection” (on by default) with a“
   last event sent” status line.
 * Optional `tactical_trust_proxy_headers` filter to read the crawler’s real IP 
   from CDN/proxy headers when the store is behind Cloudflare or similar.

#### 1.0.2

 * Security: removed the `data-key` attribute from the storefront `<script>` tag.
   The Tactical API key is a server-side secret used to sign WooCommerce webhook
   deliveries and authenticate plugin-to-server API calls — it must not appear in
   browser-rendered HTML. The snippet identifies the tenant by `data-shop` plus 
   the request Origin, so no key is required client-side. Recommended upgrade for
   all installs.

#### 1.0.1

 * Compliance: storefront snippet now loads via `wp_enqueue_script` with the `defer`
   strategy, decorated via the `script_loader_tag` filter. No more inline `<script
   >` injection.
 * Compliance: settings-page admin JS extracted to `assets/admin-settings.js`, enqueued
   via `wp_enqueue_script` + `wp_localize_script`. No more inline `<script>` in 
   the admin page.
 * Compliance: declared `Requires Plugins: woocommerce` so WP correctly blocks activation
   without WooCommerce.
 * Readme: added the “External services” disclosure, clarified Scout/Tactical naming
   in the pricing section, updated Contributors.
 * Bumped `Requires at least` to WP 6.3 (needed for `wp_enqueue_script` defer/async
   strategy).

#### 1.0.0

 * Initial release.
 * Snippet injection on the storefront when an API key is configured.
 * Settings page with API key, store domain, and “Verify connection” button.
 * Auto-registration of WooCommerce webhooks for order and product topics.
 * Uninstall removes options + Tactical-managed webhooks.

## Meta

 *  Version **1.4.0**
 *  Last updated **6 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.3 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/tactical-agent-detection/)
 * Tags
 * [agentic-commerce](https://zgh.wordpress.org/plugins/tags/agentic-commerce/)[ai agents](https://zgh.wordpress.org/plugins/tags/ai-agents/)
   [AI Crawlers](https://zgh.wordpress.org/plugins/tags/ai-crawlers/)[analytics](https://zgh.wordpress.org/plugins/tags/analytics/)
   [woocommerce](https://zgh.wordpress.org/plugins/tags/woocommerce/)
 *  [Advanced View](https://zgh.wordpress.org/plugins/tactical-agent-detection/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/tactical-agent-detection/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/tactical-agent-detection/reviews/)

## Contributors

 *   [ sourabhnk ](https://profiles.wordpress.org/sourabhnk/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/tactical-agent-detection/)