Visualithic Phyllix

Description

Phyllix reads your website, works out what your business actually does, and then works on your search visibility the way a marketing manager would – by finding what you could realistically rank for, what your existing pages half-cover, and what is missing entirely.

By default, it never publishes anything. Every article it writes is filed as a draft for you to read, edit and approve, and if you want that to stay true forever, it will. Every change it proposes to a page you already have is shown to you in full first, and the original is kept so it can be undone. An explicit Automation section in Settings lets an owner who wants more turn on exactly as much as they choose — anywhere from just sending findings to your Ideas queue automatically, up to approving, writing and publishing articles with no click at all. Every level is off by default, and turning any of it on is a deliberate choice you make.

What it does

  • Reads your published pages and builds a profile of your business from them
  • Maps your existing content and finds the gaps in it
  • Builds a keyword map, cross-checked against Google Search Console where you connect it
  • Researches a topic, then writes a full article and files it as a draft
  • Reviews its own drafts for SEO, readability and accuracy before you see them
  • Improves pages you already have, one at a time, always as a reviewable proposal (or, if you turn automation on, applied automatically with the same safety checks a manual click passes through)
  • Tracks how published articles actually perform in Google over time
  • Checks technical health: image dimensions, heading structure, broken links, redirect chains, mixed content, accidental noindex
  • Adds a call to action to pages that attract visitors but never ask for the business
  • Optional automation: approve, write and publish articles unattended, on a schedule you control, with a full audit trail of what it did and when

How it treats your content

This is the part we care most about. A page you already have is a page that already works for someone, so:

  • Nothing is published automatically unless you explicitly turn that on in Settings — off by default, and every level of automation is its own separate, individually-labelled toggle, not an all-or-nothing switch
  • Every idea, draft and published article keeps a full record of when it was proposed, when and by whom it was approved, when and by whom it was written, and when and by whom it was published — so you can always see what automation did versus what you did yourself
  • A published article is an ordinary WordPress post — you can edit it, unpublish it, or delete it at any time through Phyllix’s own editor or WordPress’s own post editor, exactly as you would with anything you wrote yourself
  • Pages linked in your site’s navigation menu are never touched by any automated action, at any setting — quick fixes, calls to action, page rewrites, none of it. Those always wait for your own explicit review
  • What gets read is an allow-list you control – only Pages and Posts by default, nothing else unless you add it in Settings
  • Private and password-protected content is skipped outright, and any email address found in a page’s text is stripped before that text ever reaches an AI request
  • Page structure is preserved. Block layouts, full-width sections and shortcodes survive an edit, because the layout is never sent to the AI in the first place
  • Pages built with Elementor, Divi or WPBakery are not rewritten at all
  • Every edit to a live page keeps the original, so it can be reversed
  • A newly published article is left alone for four weeks before Phyllix offers to improve it, because Google needs that long before its position means anything

Free plan

The free plan includes 3 AI-written articles, once — a one-time allowance, not a monthly one. Reading your site, the business profile, the content map, the keyword map, the gap analysis, manually-tracked competitors, Google Search Console tracking, and fixing technical SEO problems are always included, for free, forever, with no limit. Once the 3 free articles are used, buy AI credits ($1.25 each, pay only for what you use, no subscription) or move up to a paid plan for an ongoing monthly allowance. Free also reads up to 25 pages of your own site, once, ever.

External services

Phyllix cannot work without connecting to an external service. It does not run AI models on your server, and it does not ask you for API keys. Instead it sends work to the Phyllix service, which runs the AI on your behalf. You should understand exactly what that means before you use it.

The Phyllix service (Visualithic Solutions)

Phyllix connects to https://visualithicsolutions.com, operated by Visualithic Solutions, to license the plugin and to run every AI request.

When it connects:

  • When you first connect the plugin, to create your free licence
  • Every time you ask it to do something that needs AI
  • A licence check roughly every 6 hours while you are using it — more often (down to every few minutes) only while your plan is showing as fully used up, so a credit purchase or upgrade is noticed quickly rather than waiting out the normal cache

What is sent:

  • A randomly generated install identifier, created by the plugin for your site
  • Your site address (home_url())
  • Your licence key, once you have one
  • The text of the pages and drafts Phyllix is working on, including titles and meta descriptions
  • The business profile Phyllix has built from your pages
  • Your Google Search Console figures, if you have connected Search Console
  • Your WordPress administrator email address – only when you activate a paid licence, not when a free licence is created

What is not sent: your database, your users, your customers’ data, your orders, or the content of any page Phyllix has not been asked to work on. Pages you have marked Private or password-protected are skipped outright, whatever content type they are, and any email address found in a page’s text is stripped before that text reaches an AI request.

Terms: https://visualithicsolutions.com/terms
Privacy: https://visualithicsolutions.com/privacy

AI providers used by that service

The Phyllix service passes your request to one of two AI providers, depending on the task. Your content is sent to them by the Phyllix service, not directly by this plugin.

  • Anthropic – used for writing the final text of an article or page rewrite.
    Terms: https://www.anthropic.com/legal/consumer-terms
    Privacy: https://www.anthropic.com/legal/privacy
  • Google (Gemini) – used for research, analysis, review and classification. When researching, it uses Google Search grounding, which means your topic is searched on the web.
    Terms: https://policies.google.com/terms
    Privacy: https://policies.google.com/privacy

Google Search Console (optional)

If you choose to connect Google Search Console, Phyllix calls
https://oauth2.googleapis.com to exchange the credentials you supply for an
access token, and https://searchconsole.googleapis.com to read which searches
your site appears for. This is entirely optional and nothing is sent to Google
beyond the API request itself.

Terms: https://policies.google.com/terms
Privacy: https://policies.google.com/privacy

Google PageSpeed Insights (optional)

If you run a site health check, Phyllix calls https://www.googleapis.com/pagespeedonline with the public address of the page being checked, to retrieve its performance scores.

Terms: https://policies.google.com/terms
Privacy: https://policies.google.com/privacy

Google grounding redirect (AI Visibility and competitor discovery only)

When checking AI Visibility questions or discovering competitors, Phyllix’s
research sometimes comes back with a citation on vertexaisearch.cloud.google.com
— a Google redirect link, not a real page. For those two features only, Phyllix
makes a HEAD request directly to that link to follow the redirect to the real
address, so it can show or record the actual source rather than a redirect
link. No data about you or your site is sent – the request only asks where
the link redirects to.

Google privacy: https://policies.google.com/privacy

Links on your own pages

When you run a site health check, Phyllix makes a HEAD request to the addresses
your pages link to, in order to find broken links and redirect chains. These are
the sites you have already linked to. No data about you or your site is sent –
the request only asks whether the address still responds.

Connectivity diagnostics

The Diagnostics page in Settings makes one request to https://api.wordpress.org/
as a control check – a destination every WordPress site already trusts. This
confirms your server can reach the internet at all, so a failure to reach the
Phyllix service reads correctly as a problem with that one destination, not
your server’s outbound access in general. No data about you or your site is
sent – the request carries nothing beyond the request itself.

Public DNS resolvers (fallback only)

If your server’s normal DNS lookup for the Phyllix service ever fails, Phyllix
asks Cloudflare (1.1.1.1) and, if that also fails, Google (8.8.8.8) – both
public DNS-over-HTTPS resolvers – to look up the address instead, the same way
a browser’s own DNS-over-HTTPS setting would. This only happens after your
site’s normal outbound connection has already been proven to work. Only the
hostname being looked up is sent, and nothing about your site or its content
is included.

Cloudflare privacy: https://www.cloudflare.com/application-privacy-policy/
Google privacy: https://policies.google.com/privacy

Installation

  1. Install and activate the plugin.
  2. Open Phyllix in the admin menu.
  3. Read what Phyllix will send to its service, and connect. A free licence is created for your site automatically – there is no account to make and no key to paste.
  4. Open Settings -> Instructions for the full walkthrough: what to set up first (including how much automation you want – off by default, and easy to turn on gradually), reading your site, and checking your Business Profile before Phyllix starts writing from it.

FAQ

Does it publish anything by itself?

By default, no — articles are filed as drafts, and changes to existing pages are shown to you as a proposal and only applied when you click to apply them. An explicit Automation section in Settings lets you turn on more — anywhere from just sending findings to your Ideas queue automatically, up to approving, writing and publishing articles with no click at all — but every level is off by default, and turning it on is a deliberate choice you make, not something the plugin does on its own out of the box. A draft still passes the exact same content checks every draft passes before it can be filed at all, whether a human or automation triggered it.

Every idea, draft and published article keeps a full record of when it was proposed, when and by whom it was approved, when and by whom it was written, and when and by whom it was published — visible on every relevant screen, so you can always see what automation did versus what you did yourself.

Nothing automation publishes is permanent. A published article is an ordinary WordPress post — you can edit it, unpublish it, or delete it at any time through Phyllix’s own editor or WordPress’s own post editor, exactly as you would with anything you wrote yourself. Any edit Phyllix makes to a page you already had keeps the original content, so it can be reverted with one click.

Pages linked in your site’s navigation menu are never touched by any automated action, at any setting — quick fixes, calls to action, page rewrites, none of it. Those always wait for your own explicit review, with nothing in Settings that overrides it.

Can I use my own OpenAI or Anthropic API key?

No. Phyllix provides the AI as part of the plan, which is why there are no keys to manage and no separate AI bill to reconcile.

Will it break the layout of my pages?

It is built specifically not to. On a block-built page, only the text inside your existing blocks is edited and the block structure is put back exactly as it was, so full-width sections and layout settings survive. If a rewrite would lose block wrappers, alignments or shortcodes, it is refused rather than applied. Pages built with a page builder are not rewritten at all.

Can I undo a change to a live page?

Yes. The original content is stored before any edit, and every applied change can be reverted from within Phyllix.

What happens when I use up my article allowance?

It pauses and tells you, right where you clicked. Nothing is charged automatically and nothing is written that you have not asked for. On a paid plan the allowance resets on the 1st of each month; on the Free plan the 3 articles are a one-time allowance that never resets. Either way, you can buy AI credits ($1.25 each, no subscription, pay only for what you use) to keep going immediately, or move up a plan for ongoing headroom.

How do I get the Google file for Search Console?

Step-by-step instructions in plain English are shown inside the plugin, right above the upload box in Settings. It takes about five minutes, it is free, and you only do it once. In short: create a free Google Cloud project, enable the Search Console API, create a service account and download its JSON key, upload that file here, then add the email address Phyllix shows you as a user on your site in Search Console.

You never need to open the JSON file. Upload it and Phyllix reads the email address out of it for you.

Does it work without Google Search Console?

Yes. Search Console makes the keyword and results work far more accurate, because it replaces guesswork with what Google actually shows for your site, but Phyllix works without it.

What data does it send?

See the “External services” section above, which lists this in full.

Could it read something it shouldn’t – an invoice, a quote, a private page?

No. What Phyllix reads is an allow-list you control in Settings -> Content to read – it starts with just your ordinary Pages and Posts, and nothing else is added unless you tick it, so a separate “Invoices” or “Quotes” post type stays out by default. On top of that, anything you have marked Private or password-protected is skipped outright, whatever its type – and any email address inside a page’s text is stripped in code before that text ever reaches an AI request, everywhere in the plugin, not only on the first read.

What stops it putting something odd on my page?

Every change Phyllix makes to a page is checked before it is saved. If the result contains anything that should not be visible to a visitor – structured data showing as words, HTML tags reading as text, markdown symbols, an unfilled placeholder, mangled characters, or the assistant talking to you – the change is refused and you are told exactly what was found. Nothing Phyllix introduces of that kind can reach a published page.

A step says “This failed” with an old-looking error — I fixed that already, why is it still there?

That message is the stored result of the last time this step actually ran — not a live check. It stays on screen exactly as written, however old, until this specific step runs again. If whatever caused it has since been fixed (a setting corrected, a connection restored, a plugin updated), the message will not know that on its own. Click “Clear error & try again” right there on the step — this clears the stored error and gives it a genuine fresh attempt, which either succeeds (the message disappears) or fails again with an up-to-date reason.

Do I need Yoast or Rank Math?

No, but Phyllix works with both. Where one is installed, the search settings it writes – focus keyphrase, synonyms, SEO title and meta description – go straight into that plugin’s own fields. With neither installed, Phyllix keeps its own copy so the work is not lost if you add one later.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Visualithic Phyllix” is open source software. The following people have contributed to this plugin.

Contributors

Translate “Visualithic Phyllix” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

2.0.24

  • Added: a note on the Licence panel when a site has not yet connected — activating a key was silently refused with no visible message in that state (the request never left the site), which looked exactly like a rejected or broken key. It now says plainly that connecting comes first.
  • Housekeeping: cleared the last few Plugin Check findings ahead of resubmission — two admin-log columns (who fixed a call to action / a Boost rewrite) were plain text with no possible dynamic content but went through the table cell unescaped; both now run through esc_html() at output like everywhere else. One AJAX handler (the automation “run now” poll) was missing the same “nonce already verified above” annotation every other handler in this file already carries, so the scanner flagged its one $_POST read even though check_ajax_referer() already covers it.

2.0.23

  • Fixed: the “Write the approved ones” step on Home could show “Running” / “Writing N articles” forever, with no way to clear it — even a hard refresh or an incognito window made no difference. The cause: once an article’s own record is updated to reflect that its page actually went live, that status was never added to the list of “this one is finished, stop counting it” statuses used in three places, so a genuinely finished, published article kept being counted as still being written, indefinitely. Fixed at the source with one shared list instead of three separate copies, so it can’t happen again.
  • Fixed a related, more serious risk this same gap caused: the “Stop everything currently being written” button did not recognise an already-published article as something it must never touch, unlike an already-drafted one. It’s now refused the same way, so a stuck-looking step can never be “stopped” into silently marking a live, published article as failed and sending its idea back to be written all over again.

2.0.22

  • Changed: Quick fixes and Win enquiries now also get applied on the regular 5-minute check, not only on the weekly run — so a fix that recovers (for example, a call to action that failed only because no destination was configured yet) doesn’t have to wait up to a week for its next chance. This never applies more than your weekly settings already allow; it only means less waiting when something becomes fixable between scheduled runs.

2.0.21

  • Fixed: the floating “automation is running” progress banner could end up unreadable — white text with no visible background, only its border showing — when something else on the page (a WordPress core notice, the active theme, another plugin) won a styling conflict against it. Its colour and stacking are now locked down against that regardless of what else is on the page.

2.0.20

  • Fixed: a call to action that failed to auto-apply because no destination was configured at the time stayed stuck in that state forever — every automated run kept retrying the exact same broken, empty-button proposal from when it was first composed, failing the same way every time, even long after real destinations were added in Settings. It’s now reset for a fresh attempt when this specific failure happens, so it genuinely recovers on the next run instead of being permanently stuck.

2.0.19

  • Changed: each group under Published’s “Other automated actions” (Competitor gaps, AI Visibility, Win enquiries, and the rest) is now its own collapsible section, closed by default — a much shorter page at a glance, with the full detail still one click away.

2.0.18

  • Added: Published’s “Pages Boost has improved” list now shows where each improvement was originally found — Results, Improve pages, or Keywords — next to who fixed it and when. Covers both automation’s own picks and your own manual clicks from those three screens.

2.0.17

  • Fixed: Quick Fixes’ “link an orphaned page in” almost always failed with “Nothing could be linked safely,” even across pages that clearly had a natural place to link from. The step choosing which phrase to turn into a link was only ever shown a short, paraphrased summary of each candidate page — never its real text — so it was effectively guessing at wording it had never actually read, then presenting that guess with the confidence of an exact quote. It now reads the real text of a handful of the most topically relevant candidates (narrowed first, for free, using topic data already captured when each page was crawled) before choosing a phrase, so what it picks is a genuine quote rather than a coincidence.
  • Fixed: a phrase could pass verification and still fail to apply, because the two steps checked different things — verification used a loose substring search that said “found” for a phrase sitting inside a heading, while applying it used a stricter rule that correctly refuses to turn a heading into a random inline link. Both now share the exact same rule, so a fix is never marked as findable and then silently fail later.

2.0.16

  • Fixed: automated page improvements (Boost, drawing on Results, Improve pages and Keywords) always stopped after diagnosing a plan and sat waiting for approval forever, even with automation turned on and even on a page with nothing stopping it — the setting’s own description already promised full automatic prepare-and-apply, but nothing ever actually carried an automated diagnosis through to the rewrite. It now does, under the exact same conditions the setting already describes (never on a page in your navigation menu).
  • Fixed: a call to action’s automatic destination was picked by whichever contact link happened to be listed first, regardless of type — a page with several WhatsApp numbers and one quote page could end up offering two WhatsApp numbers instead of a quote page and a WhatsApp number. Automation now picks by destination type (a page on your site, then email, then WhatsApp, then phone, then text message), one of each of the top two types present, however many links you’ve added or however they’re ordered.
  • Added: Published now shows every call to action and every page improvement that has actually gone live, whether you added it yourself or automation did — collapsed by default, with who did it, when, a link to view it live, and an “Edit here” that lets you change the wording or destination and update the live page, or undo it back to how it was before.
  • Fixed: undoing an applied page improvement didn’t update its own record, so it could still show as “applied” after being reverted. Undoing a call to action or a page improvement now correctly puts it back to waiting for review either way.

2.0.15

  • The real fix for the daily automated cycle stalling after reading the site and pulling Search Console data, then going quiet on some hosting — every AI call outside the article-writing pipeline (reading a page, building the knowledge base, mapping content, finding SEO/keyword gaps, checking AI Visibility, checking competitors, proposing ideas, scoring findings, composing a Win-enquiries call to action, writing the service-areas page, learning from a published edit) was still holding its own WordPress request open for the length of the call — exactly the exposure the article pipeline’s own async rework already closed. On a host whose CDN/edge layer or PHP-FPM kills a long-held connection, that call just vanished mid-run with no error, which is what read as automation reliably completing the early, cheap steps and then stopping. All of it now starts the call and returns immediately, resuming once the result actually lands, the same pattern the writer already used.
  • Found and fixed two real, already-live bugs while doing this: competitor discovery’s own docblock said it fired asynchronously, but the actual call passed extra arguments to the synchronous method instead — PHP silently drops arguments a function doesn’t declare, so this ran fully blocking for months and its result was thrown away every time, meaning discovered competitors were never actually added. Separately, the three automated “is this worth an idea” sweeps (competitor gaps, keyword gaps, AI Visibility losses) scored every finding with a blocking AI call inside a loop, one call per finding, back to back, in a single request — now each finding is queued as its own async job instead.
  • A synchronous helper only ever used inside an already-async job (competitor-name extraction inside the AI Visibility check) also moved onto the same async pattern, plus a couple of confirmed-dead synchronous functions removed where an async twin had already fully replaced them.

2.0.14

  • Fixed: the real bug behind two remaining translator-comment warnings — the comment sat above the variable assignment, not directly above the translated string two lines below it (a multi-line ternary). Moved to the correct line, above each branch.
  • Fixed every remaining “output not escaped” warning on the admin screens, root and branch. A phpcs:ignore/phpcs:disable comment does not reliably suppress this check, however correct the reasoning underneath it, so every instance of two patterns was rebuilt to need no suppression at all: (1) a card-building method that returned a pre-built HTML string for another method to echorender_pipeline(), render_idea(), render_knowledge_card(), rules_list_html(), render_prep_state(), render_conversion(), render_seo_check() and step_bar() now print their own output directly, and the few places that still need the HTML as a string (an AJAX response) capture it locally instead; (2) a value already cast to a number earlier in the method, then printed several lines later — every such value is now cast again at the exact point it is printed, which is what the check is actually able to verify.

2.0.11

  • Fixed: three untranslated placeholders in automated keyword/competitor-gap proposals were missing their “translators:” comments — added.
  • Fixed: the review panel’s status line had its translator comments sitting above the wrong line for the sniff that checks for them — moved directly above each translated string.
  • Fixed: Tested up to used a patch version (7.1.1); wp.org only accepts major.minor — trimmed to 7.1.
  • Fixed: the short description was cut off at wp.org’s 150-character limit — shortened to fit.

2.0.10

  • Major release: optional automation. Off by default — Phyllix keeps working exactly as before (drafts only, every page edit shown as a proposal first) until you deliberately turn something on in Settings Automation.
  • Granular, opt-in levels: automatically send findings to your Ideas queue, approve ideas, write drafts, publish articles, and apply quick fixes/calls to action/page improvements — each its own toggle, so you can automate one stage and keep the rest manual. A configurable pace and a budget split between new articles and improving existing pages.
  • Full audit trail: every idea, draft and published article records when it was proposed, approved, written and published, and by whom — visible everywhere that matters, distinguishing your own actions from automation’s.
  • Navigation-menu pages are never touched by any automated action, at any setting, with no override — including automatic internal linking, a gap closed in this release.
  • Automatic publishing now checks for finished drafts every few minutes rather than once a week, and works through a backlog oldest-first rather than newest-first, so nothing genuinely finished is ever left stuck waiting behind newer work.
  • Published pages: “Edit here” now opens everything in one place — the SEO fields, the article body, then Update/Unpublish/Trash/View/Cancel, with the full review (score, what was fixed automatically, what is still open) underneath. Unpublish and Trash reach a published article for the first time; “Mark ready to publish” does the same for your own drafts. “Reconnect Phyllix” in Settings covers a stuck connection, and “Clear error & try again” fixes a failed step showing a stale error.
  • AI Visibility question generation rebuilt on genuine AI reasoning instead of a template. Win-enquiries calls to action can compose and apply themselves automatically when you turn that on. A “possible duplicate” flag on drafts that weakly overlap an existing page.
  • A number of correctness and billing-accuracy fixes found in an internal audit ahead of this release: several real-money AI calls that were running untagged (never double-charged to you, but invisible to our own cost tracking), a queue retry-counting bug, a budget-reservation race between overlapping automation runs, and one AI-research destination missing from External Services — added.
  • Every automation feature above is entirely optional. If you do nothing in Settings Automation, Phyllix behaves exactly as it always has.

Versions before 2.0.0

Full version-by-version history available in the plugin’s own repository. Every version before 2.0.0 predates the automation feature entirely — each one describes Phyllix’s manual-only, draft-and-propose behaviour, which remains the default today.