

The score and its checks in the editor sidebar, updating as you write.
SolSEO does the SEO work every site needs and gets out of the way. Nothing is held back behind a key, nothing phones home, and there are no notices on screens that have nothing to do with it.
A score you can act on
Every post, page and product is scored out of a hundred from around thirty checks: how the page is aimed at its keyword, titles and links, how the writing reads, and what a shopping result needs. Each check says what to change. The score updates as you type, and the posts list gets a column you can edit in place, so forty titles can be fixed without opening a page.
Titles, meta and sitemaps
Write a title and description per page, or set a template per post type with placeholders in braces, such as {title} {sep} {sitename}. A pixel gauge shows when a title is about to be cut off. XML sitemaps cover posts, pages, products, categories, tags and author archives, list the images on each page, and are added to robots.txt.
Structured data
Organisation or person, the site, breadcrumbs, articles and products. A product with variations gets one offer per variation with its own price, SKU and stock state, which is what sends a buyer to the right size.
The rest
Works with WooCommerce
Product schema, product checks in the score, galleries in the sitemap, and price, SKU and stock placeholders. Twelve checks from Google’s product data specification run against your products here rather than turning up in Merchant Centre three days later. WooCommerce is optional.
SolSEO does not contact anybody else on its own. Every service below is off until you switch it on yourself, and each one stops the moment you switch it off, remove its key or press Disconnect. This is the whole list.
Two things in this plugin ask your own server for your own pages, and neither is one of these. The crawler on the Technical screen reads your published pages when you press the button, and the tag check on the Connections screen reads your home page when you press that button. Both go through the same piece of code, which refuses any address that is not on your own site. Nothing about those pages leaves your server, so there is no third party to name here.
Some screens also carry a link to somebody else’s documentation, and a link is not a service. The robots.txt screen lists the AI crawlers by name and links each one to what its operator publishes about it, at OpenAI, Anthropic, Google, Common Crawl, Perplexity, ByteDance, Apple, Meta and Amazon. The Connections screen links Google’s pages about API keys, the analytics check links each tag vendor’s own installation guide, and the Australian checks link the OAIC, the ACCC and the ATO. Nothing is fetched from any of them: the addresses sit in a href and go nowhere until you click one, at which point your browser goes there and this plugin is not involved. They are here so that what a screen tells you about a crawler or a rule can be checked against the people who set it.
Off until you paste a Google API key on the Connections screen, and used only when you press the button on the Speed screen.
Each check sends one address from your own site, plus your key, and Google sends back how that page performs: a test it runs itself, and, if enough people have visited the page recently, what those visits measured. Nothing else is sent, no check runs on a schedule, and removing the key stops it.
The key is yours, from your own Google Cloud project. Google’s terms and privacy policy cover what they do with the address you send.
Terms: https://developers.google.com/terms
Privacy policy: https://policies.google.com/privacy
Off until you switch it on under SolSEO, Technical, Indexing.
When it is on, publishing or updating a page sends that page’s address, once, so the search engines that take part know to come and look. One submission reaches all of them: Bing, Yandex, Seznam and Naver read the same endpoint. Nothing is sent for a draft, a private page, or a page you have asked to stay out of search results.
Each submission carries your site’s host name, the page addresses, the key described below and the address of the key file. Nothing else. The same screen also has a button that sends up to a thousand of your published addresses in one go, which is useful the first time you switch it on; it only runs when you press it, and only while IndexNow is on.
IndexNow also needs a key file at the root of your site, which this plugin creates and serves for you. It holds a line of letters and numbers and nothing else, and it is how the engines check the submission came from whoever runs the site.
IndexNow is run by its sponsors, Microsoft, Yandex and Seznam.cz.
Terms of use: https://www.indexnow.org/terms
Privacy policy: https://privacy.microsoft.com/privacystatement
How it works: https://www.indexnow.org/documentation
Off until you connect a Google account under SolSEO, Settings, Connections, and you can disconnect on the same screen.
Once connected, the plugin asks Google two things. At the moment you connect, and again if you press the button to refresh the list, it asks which Search Console properties your Google account can see, so it can show you the list and match one to this site. After that, when you open a post or a page in the editor, it asks what that one page did in Google over the last twenty eight days: clicks, impressions, average position, and the search terms people used to reach it. The answer is kept on your own server for six hours so that opening the same page twice does not ask twice.
The permission asked for is read only. It is https://www.googleapis.com/auth/webmasters.readonly, which is the narrowest one Search Console publishes: it cannot add a property, remove one, or submit a sitemap. Nothing is ever written to your Google account.
What is sent is the address of the page you are editing and the address of the property you matched it to. No page content, no customer data and nothing about your visitors.
None of what comes back is sent anywhere. The figures are shown in your own WordPress admin and stored on your own server, and the plugin has no route that sends Search Console data to SolSEO or to anybody else.
Terms: https://policies.google.com/terms
Privacy policy: https://policies.google.com/privacy
Off until you press Connect on that same screen. This is the one place in this plugin that contacts solseo.com.au without a SolSEO account, and it is worth reading before you press it.
Connecting to Google needs an application secret, and a secret that shipped inside a plugin anybody can download is not a secret. So the plugin holds none. When you press Connect, your browser goes to solseo.com.au, which sends you on to Google’s own sign in and permission screen at accounts.google.com. When you say yes, Google sends your browser back to solseo.com.au, which sends it straight back to your site with a one-time code. Your site then asks solseo.com.au to turn that code into a token at oauth2.googleapis.com. Google’s tokens last an hour, so when the plugin next needs Search Console figures and finds the token has run out, it asks solseo.com.au to refresh it the same way, sending the long-lived refresh token Google issued.
What solseo.com.au sees is the one-time code, the refresh token when it is renewing one, the token Google hands back, and the address of your site because your browser came from it. It keeps none of them. There is no account, no row and no log line: the code is exchanged and the answer is passed straight to your site, which is where the token is stored, scrambled, in your own database.
If you would rather we were not in the middle at all, you do not have to be. Under “Use my own Google app” on the same screen you can paste a client id and secret from your own Google Cloud project, and then nothing in this handshake touches solseo.com.au: your site talks to accounts.google.com and oauth2.googleapis.com directly.
Disconnecting deletes the stored token, tells Google to forget the permission, and stops all of it in the same click. Deleting the plugin with “remove my data” ticked under SolSEO, Tools, Data does the same: it tells Google to forget the permission, once, before the stored token is deleted. You can also revoke it from your own Google account at https://myaccount.google.com/permissions.
Google terms: https://policies.google.com/terms
Google privacy policy: https://policies.google.com/privacy
SolSEO terms: https://solseo.com.au/terms
SolSEO privacy policy: https://solseo.com.au/privacy
Off until you paste a pairing code on the Connect screen. This is separate from the Google handshake above, which uses solseo.com.au as a post box and needs no account.
Once paired, the plugin sends twice a day: the site address and time zone, the WordPress, PHP, WooCommerce and plugin versions, the number of published items of each post type SolSEO manages (posts, pages, products and any others you switched on), and the permalink structure. In return it reads back which plan the account is on, a summary of the sites on it, and what the account’s monitoring last measured about this site from outside it, which is what the dashboard widget shows. It only ever talks to solseo.com.au, whatever a reply from there says.
No page content, no customer data, no Search Console figures and nothing about your visitors is sent. Disconnecting on the Connect screen removes the stored key and stops it at once.
Service terms: https://solseo.com.au/terms
Privacy policy: https://solseo.com.au/privacy