Sorraia — Forms, Bookings, Shop & AI Chat

Description

If you already build widgets in Sorraia, this plugin saves you from copying script tags around. Connect your site once, then pick a widget from a list — as a block, or a shortcode.

It is a thin wrapper. The widgets themselves are built, styled and served by Sorraia; this plugin only asks Sorraia which widgets exist on your site (and, when you press Verify, to verify the site), and places the same container and loader script the embed code from your Sorraia dashboard would.

You need a Sorraia account. This plugin is a client for that service and does nothing on its own. Sorraia has a free plan; see sorraia.app.

Why use it instead of pasting the snippet yourself?

Two honest reasons, and only two:

  1. Script tags survive. WordPress strips <script> on save from anyone without the unfiltered_html capability — always the case on multisite, and common on single sites where a security plugin has removed it. The block saves cleanly and the script is simply gone. This plugin renders the snippet when the page is displayed, so WordPress never stores it and never strips it.
  2. Site-wide launchers. The AI chat and WhatsApp launchers float in a corner of every page. Doing that by hand means editing your theme footer, which a theme update overwrites. Here it is a checkbox.

If you only need one form on one page and you have unfiltered_html, a Custom HTML block works fine and you do not need this plugin.

Placing a widget

Every widget gets a shortcode you can paste anywhere, and a Sorraia widget block for the block editor. From the settings screen you can also add a widget to several pages at once by ticking them in a list, or draft a new page containing it. Each row tells you which pages already carry that widget, so you are not guessing.

Everything the plugin writes to a page is appended to the end of the content. It never rewrites, reorders or removes anything already there, and it saves a revision first, so the change is undoable from WordPress’s own revision history.

What it does not do

  • It does not create or edit widgets. That happens in Sorraia.
  • It does not read your form submissions, bookings, orders or customer details, and it cannot — the key it uses can only list one site’s widget names and types and check that site’s verification.
  • It does not add tracking, analytics or any third-party asset of its own. What the widgets themselves send and load is listed under External services.

External services

This plugin connects to Sorraia, a hosted widget service operated by Sado Labs, Inc. The plugin cannot work without it: the widgets are built, stored and served by Sorraia, and this plugin is a client for that service.

There are three separate kinds of request, and they are worth telling apart. Two leave your site. One arrives at it.

1. From your server, to list your widgets and to prove you control this site

Your site makes HTTPS requests from PHP to the Sorraia API — https://api.sorraia.app by default. The API address in Settings Sorraia can point at another Sorraia environment if Sorraia support asks you to, but only at a sorraia.app address; the plugin refuses any other host. Three endpoints are called, and no others:

  • GET /v1/site-catalog — the widget list. Requested when you press Connect; when you press Refresh; when the Settings Sorraia screen is loaded and the five-minute cached copy has expired; and when the block editor needs the widget list to populate the block’s picker.
  • GET /v1/site-verification — whether Sorraia considers this site verified. Requested when you press Connect or Refresh, and when you press Verify — before the check, and again after it succeeds.
  • POST /v1/site-verification/attempt — asks Sorraia to run the check now. Requested only when you press Verify.

What is sent: your Sorraia site key, in an x-sorraia-site-key request header; and a User-Agent string identifying the plugin version and this site’s home URL (for example Sorraia-WordPress/1.2.4; https://example.com/). None of the three sends page content, form submissions or anything about your visitors.

What comes back: from the catalog, the connected site’s name and domain, and a list of your widgets — name, type, id, and whether each is paused. From the two verification endpoints, this site’s domain, whether it is verified, which method verified it, when it was checked, and this site’s verification token with the instructions for publishing it — while the site is not verified, and for as long as this plugin is what verified it, because Sorraia’s daily re-check needs the plugin to keep serving it. No submissions, bookings, orders or customer data are returned, and the site key cannot request them.

2. From Sorraia’s servers, to your site — the one that comes inward

When you press Verify, Sorraia’s servers make an HTTPS request to your own site’s URL, from outside, looking for the verification token. They try /?rest_route=/sorraia/v1/verify first and, if that does not answer, /wp-admin/admin-ajax.php?action=sorraia_verify. While the site is verified, Sorraia repeats the same check about once a day. This plugin answers both paths with the verification token and nothing else, and it has nothing to answer with until you have connected a site key.

This is the only request here that your site receives rather than makes, which is why it is called out separately: it comes from a third party’s servers, it happens when you press Verify and in that daily re-check, and it will show up in your access log and in any security plugin that reports unfamiliar visitors.

The verification token is not a credential. It is a random, one-per-site string whose only job is to prove that whoever controls this site also controls the Sorraia account, so it is meant to be published — that is the entire mechanism, and there is nothing about it to keep secret. The site key is the opposite: it is a credential, and it never leaves your server.

3. From your visitors’ browsers, to render a widget

When a page containing one of your widgets is displayed, the visitor’s browser loads that widget’s script from the same Sorraia host (for example https://api.sorraia.app/api/embed/12.js), and the widget then talks to Sorraia to do its job — submit a form, look up booking availability, or start a checkout. This is the same script the embed snippet from your Sorraia dashboard loads; the plugin writes the widget’s container and adds that script through WordPress’s script queue.

This means your visitors’ browsers contact Sorraia, and Sorraia receives whatever the widget is for — for example the contents of a form a visitor submits. Nothing is sent to Sorraia from a page that has no Sorraia widget on it.

Along with what a visitor submits, the widgets tell Sorraia which site they are on. The AI chat (with each message) and the WhatsApp launcher (on each tap) also send the page’s address and any utm_ parameters in it. If the page runs WhatConverts call tracking, the widgets also pass along WhatConverts’ visitor id (its wc_client_current cookie), so a lead is credited to the right campaign. The AI chat keeps a conversation token in the visitor’s browser storage, so reloading the page continues the same chat.

By connecting a site key you agree to Sorraia’s terms and privacy policy:

  • Terms of Service: https://sorraia.app/terms
  • Privacy Policy: https://sorraia.app/privacy
  • Sub-processors: https://sorraia.app/sub-processors

This plugin’s own code contacts no service but Sorraia, and loads no fonts, analytics or assets from anywhere else. The widgets it places are served by Sorraia, and depending on how a widget is set up, a visitor’s browser may also contact:

  • Google Fonts, when a widget’s font is set to one of the Google fonts Sorraia offers (currently Inter, Roboto, Open Sans, Lato and Poppins). The stylesheet comes from fonts.googleapis.com and the font files from fonts.gstatic.com as soon as the widget loads, which gives Google the visitor’s IP address and browser details. Any other font setting loads nothing from Google. Privacy Policy: https://policies.google.com/privacy
  • WhatsApp (Meta), only when a visitor taps the WhatsApp launcher or Continue on WhatsApp in the AI chat. The browser then opens wa.me with your business number and the pre-filled message, which can include the page’s title and a reference code. Privacy Policy: https://www.whatsapp.com/legal/privacy-policy
  • Stripe, only when a visitor buys from a shop widget. They are sent to Stripe Checkout to pay, and Stripe — not Sorraia or this site — takes the card details. Privacy Policy: https://stripe.com/privacy

Blocks

This plugin provides 1 block.

  • Sorraia widget Place a Sorraia form, booking calendar or shop on this page.

Installation

  1. Install and activate the plugin.
  2. In Sorraia, open your site’s card and copy the site key (it starts with sor_site_). On a site you have not verified yet it is under Show verification instructions WordPress plugin; on a verified site it is on the Embed card.
  3. In WordPress, go to Settings Sorraia, paste the key, and press Connect.
  4. Your widgets are listed. Use the shortcode shown next to each one, add the Sorraia widget block to a page, or tick pages in the list and press Add to selected pages.
  5. For AI chat or WhatsApp, tick the launcher under Site-wide launchers and save.

FAQ

Do I need a Sorraia account?

Yes. The plugin lists and embeds widgets that live in a Sorraia account; it cannot create them. There is a free plan.

Where do I find my site key?

On your site’s card in the Sorraia dashboard. It starts with sor_site_.

Which part of the card depends on whether the site is verified yet. If it is not, the key is a step of this verification method: press Show verification instructions on the site’s card and pick WordPress plugin. Once the site is verified, it moves to the Embed card in the expanded site.

Is the site key safe to store here?

It is scoped to one site. It can list that site’s widget names, types and ids, read whether the site is verified, and ask Sorraia to run the verification check — nothing else. It cannot read submissions, bookings, orders or customer data, and it is not an API key. It is stored in your WordPress database and only ever sent from your server to Sorraia, never to a visitor’s browser. If you think it has leaked, regenerate it in Sorraia; the old one stops working immediately.

I regenerated my key and the widget list broke.

In Settings Sorraia, press Disconnect, then paste the new key and press Connect. The old key stops working the moment you regenerate.

My widget does not appear on the page.

Three usual causes. First, the widget is paused in Sorraia — the list on the settings screen labels it. Second, a caching or optimisation plugin deferring, delaying or rewriting the loader script. Third, a Content Security Policy on your site that does not allow scripts from api.sorraia.app.

On the second one: the plugin already asks WP Rocket, Perfmatters and LiteSpeed Cache to leave the loader alone, by registering rocket_exclude_defer_js, rocket_delay_js_exclusions, perfmatters_delay_js_exclusions and litespeed_optm_js_defer_exc and adding both api.sorraia.app/api/embed and /api/embed/ to each list, the second so a custom API host is covered too. Those four filters are the whole of what is automatic. Anything else — Autoptimize, W3 Total Cache, WP Fastest Cache, Cloudflare’s Rocket Loader, an optimiser built into your host, or any setting in those three plugins that the four filters above do not cover — still needs the widget script URL (api.sorraia.app/api/embed) added to its JavaScript exclusion list by hand.

Can I put the same widget on more than one page?

Yes. Tick as many pages as you like and press Add to selected pages. Pages that already have that widget are marked, and you can still pick them — but a second copy of the same widget on one page renders only once, because both copies use the same container id and the loader mounts into the first one. The plugin warns you before doing it.

How do I know where a widget already is?

Each widget row says so — “On: Contact (draft), About ×2”, with links to edit those pages, or “Not on any page yet.” Site-wide launchers show whether their switch is on instead, because they appear on every page rather than on particular ones.

Does it change my existing page content?

No. Adding a widget appends it to the end of the page and leaves everything already there untouched, and a revision is saved first, so you can undo it from WordPress’s revision history.

Does it work without the block editor?

Yes. Every widget has a shortcode, shown next to it in Settings Sorraia. The block is a convenience, not a requirement.

Does it add a “Powered by” link to my site?

The plugin itself adds none. On Sorraia’s Free plan, the shop widget — which Sorraia serves — shows a small “Powered by Sorraia” link. Paid plans do not show it, and no other widget type does.

What happens if I deactivate the plugin?

Your widgets stop rendering on this site: a Sorraia block shows nothing, and a [sorraia] shortcode shows as plain text until you remove it or reactivate the plugin. If you verified this site with the plugin, Sorraia’s daily re-check stops finding the verification token, and the site becomes unverified in Sorraia until you verify it again: reactivate the plugin, press Refresh in Settings Sorraia, then Verify this site (or add the DNS record instead). Disconnecting has the same effect on verification. Nothing else in your Sorraia account changes. Uninstalling also removes the plugin’s stored settings — including the site key — from your database.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Sorraia — Forms, Bookings, Shop & AI Chat” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.2.4

  • Verified sites keep serving the verification token so Sorraia’s daily re-check can succeed; previously a verified site was un-verified the next day.
  • The token is removed only when you disconnect, connect a different site key, or uninstall the plugin.
  • Settings Sorraia now warns when a site this plugin verified has no token to serve, and asks you to press Refresh when Sorraia has not reported the site’s verification status yet, instead of showing nothing.
  • The FAQ now says that deactivating or disconnecting the plugin un-verifies a site it verified, and that a regenerated key is entered by disconnecting first.

1.2.3

  • “Used on” no longer caches page titles or edit links: each user sees only the pages they can edit, and the notices shown after Connect, Refresh and Verify are kept per user.

1.2.2

  • Widget loader scripts now load through WordPress’s script queue (wp_enqueue_script) at the end of the page, instead of being printed straight after each widget. The script addresses are unchanged, and a widget placed twice on one page now loads its script once.
  • The Sorraia block declares block API version 3, for the iframed block editor in WordPress 7.0 and later.
  • The API address in Settings Sorraia now accepts only sorraia.app addresses.
  • Fixes from WordPress’s Plugin Check: translations are left to WordPress’s own language packs, form input is sanitised as it arrives, and uninstall no longer leaves unprefixed variables behind. The Plugins screen now lists the plugin simply as “Sorraia”.
  • Corrected the settings screen’s note on the “Powered by Sorraia” link: only shop widgets on the Free plan show it.
  • The readme now says what the site key can do (list this site’s widgets and check its verification), when the verification status is requested, that Sorraia re-checks a verified site about once a day, and what the widgets themselves load from third parties — Google Fonts, WhatsApp and Stripe.

1.2.1

  • Corrected where this plugin says to find your site key. It said “Site Embed”, which was only true for a site you had already verified — and 1.2.0’s whole point is verifying a site you have not. Sorraia now shows the key inside the WordPress verification method itself, and this plugin’s settings screen, installation steps and FAQ say so.
  • Text only — apart from the version number, nothing but wording changed. The plugin behaves exactly as 1.2.0 did.

1.2.0

  • Site verification from the settings screen. Sorraia can now confirm you control this site by fetching a token the plugin serves, so there is no DNS record to add and no meta tag to paste into your theme.
  • The plugin answers that check at two public paths — /?rest_route=/sorraia/v1/verify and /wp-admin/admin-ajax.php?action=sorraia_verify — returning the verification token and nothing else.
  • Corrected the “my widget does not appear” answer. It said the plugin adds no optimiser exclusions of its own; it has registered exclusions for WP Rocket, Perfmatters and LiteSpeed Cache since 1.0.0. The FAQ now names the four filters it registers, and says plainly which optimisers are still yours to configure.
  • External services now documents the verification traffic in both directions — the two calls this site makes, and the inbound request Sorraia’s servers make to your site when you press Verify.

1.1.0

  • “Used on” — each widget row now says which pages it is already on, counting repeats (“About ×2”), with edit links. Site-wide launchers show their switch state instead.
  • Add to several pages at once: the single page dropdown is now a checklist with one “Add to selected pages” button. Pages that already carry the widget are marked and stay selectable.
  • A warning before adding a widget to a page that already has it, explaining that a second copy is saved but renders once per page.
  • Buttons on the settings screen now use the plugin’s own styling instead of borrowing WordPress’s default blue.
  • Uninstall now also removes the placement-cache settings introduced in this version.

1.0.0

  • First release. Site key connection, widget list, shortcode, block, and site-wide launchers for AI chat and WhatsApp.