Title: Sorraia — Forms, Bookings, Shop &amp; AI Chat
Author: sorraia
Published: <strong>October 1, 2026</strong>
Last modified: October 1, 2026

---

Search plugins

![](https://ps.w.org/sorraia/assets/banner-772x250.png?rev=3723247)

![](https://ps.w.org/sorraia/assets/icon-256x256.png?rev=3723247)

# Sorraia — Forms, Bookings, Shop & AI Chat

 By [sorraia](https://profiles.wordpress.org/sorraia/)

[Download](https://downloads.wordpress.org/plugin/sorraia.1.2.4.zip)

 * [Details](https://tzm.wordpress.org/plugins/sorraia/#description)
 * [Reviews](https://tzm.wordpress.org/plugins/sorraia/#reviews)
 *  [Installation](https://tzm.wordpress.org/plugins/sorraia/#installation)
 * [Development](https://tzm.wordpress.org/plugins/sorraia/#developers)

 [Support](https://wordpress.org/support/plugin/sorraia/)

## Description

If you already build widgets in Sorraia, this plugin saves you from copying script
tags around. Connect your site once, then pick a widget from a list — as a block,
or a shortcode.

It is a thin wrapper. The widgets themselves are built, styled and served by Sorraia;
this plugin only asks Sorraia which widgets exist on your site (and, when you press
Verify, to verify the site), and places the same container and loader script the
embed code from your Sorraia dashboard would.

**You need a Sorraia account.** This plugin is a client for that service and does
nothing on its own. Sorraia has a free plan; see [sorraia.app](https://sorraia.app/).

**Why use it instead of pasting the snippet yourself?**

Two honest reasons, and only two:

 1. **Script tags survive.** WordPress strips `<script>` on save from anyone without
    the `unfiltered_html` capability — always the case on multisite, and common on 
    single sites where a security plugin has removed it. The block saves cleanly and
    the script is simply gone. This plugin renders the snippet when the page is displayed,
    so WordPress never stores it and never strips it.
 2. **Site-wide launchers.** The AI chat and WhatsApp launchers float in a corner of
    every page. Doing that by hand means editing your theme footer, which a theme update
    overwrites. Here it is a checkbox.

If you only need one form on one page and you have `unfiltered_html`, a Custom HTML
block works fine and you do not need this plugin.

**Placing a widget**

Every widget gets a shortcode you can paste anywhere, and a **Sorraia widget** block
for the block editor. From the settings screen you can also add a widget to several
pages at once by ticking them in a list, or draft a new page containing it. Each
row tells you which pages already carry that widget, so you are not guessing.

Everything the plugin writes to a page is **appended** to the end of the content.
It never rewrites, reorders or removes anything already there, and it saves a revision
first, so the change is undoable from WordPress’s own revision history.

**What it does not do**

 * It does not create or edit widgets. That happens in Sorraia.
 * It does not read your form submissions, bookings, orders or customer details,
   and it cannot — the key it uses can only list one site’s widget names and types
   and check that site’s verification.
 * It does not add tracking, analytics or any third-party asset of its own. What
   the widgets themselves send and load is listed under External services.

### External services

This plugin connects to **Sorraia**, a hosted widget service operated by Sado Labs,
Inc. The plugin cannot work without it: the widgets are built, stored and served
by Sorraia, and this plugin is a client for that service.

There are three separate kinds of request, and they are worth telling apart. Two
leave your site. One arrives at it.

**1. From your server, to list your widgets and to prove you control this site**

Your site makes HTTPS requests from PHP to the Sorraia API — `https://api.sorraia.
app` by default. The API address in Settings  Sorraia can point at another Sorraia
environment if Sorraia support asks you to, but only at a `sorraia.app` address;
the plugin refuses any other host. Three endpoints are called, and no others:

 * `GET /v1/site-catalog` — the widget list. Requested when you press **Connect**;
   when you press **Refresh**; when the **Settings  Sorraia** screen is loaded and
   the five-minute cached copy has expired; and when the block editor needs the 
   widget list to populate the block’s picker.
 * `GET /v1/site-verification` — whether Sorraia considers this site verified. Requested
   when you press **Connect** or **Refresh**, and when you press **Verify** — before
   the check, and again after it succeeds.
 * `POST /v1/site-verification/attempt` — asks Sorraia to run the check now. Requested
   only when you press **Verify**.

_What is sent:_ your Sorraia site key, in an `x-sorraia-site-key` request header;
and a User-Agent string identifying the plugin version and this site’s home URL (
for example `Sorraia-WordPress/1.2.4; https://example.com/`). None of the three 
sends page content, form submissions or anything about your visitors.

_What comes back:_ from the catalog, the connected site’s name and domain, and a
list of your widgets — name, type, id, and whether each is paused. From the two 
verification endpoints, this site’s domain, whether it is verified, which method
verified it, when it was checked, and this site’s verification token with the instructions
for publishing it — while the site is not verified, and for as long as this plugin
is what verified it, because Sorraia’s daily re-check needs the plugin to keep serving
it. No submissions, bookings, orders or customer data are returned, and the site
key cannot request them.

**2. From Sorraia’s servers, to your site — the one that comes inward**

When you press **Verify**, Sorraia’s servers make an HTTPS request _to your own 
site’s URL_, from outside, looking for the verification token. They try `/?rest_route
=/sorraia/v1/verify` first and, if that does not answer, `/wp-admin/admin-ajax.php?
action=sorraia_verify`. While the site is verified, Sorraia repeats the same check
about once a day. This plugin answers both paths with the verification token and
nothing else, and it has nothing to answer with until you have connected a site 
key.

This is the only request here that your site receives rather than makes, which is
why it is called out separately: it comes from a third party’s servers, it happens
when you press **Verify** and in that daily re-check, and it will show up in your
access log and in any security plugin that reports unfamiliar visitors.

The verification token is **not** a credential. It is a random, one-per-site string
whose only job is to prove that whoever controls this site also controls the Sorraia
account, so it is meant to be published — that is the entire mechanism, and there
is nothing about it to keep secret. The site key is the opposite: it is a credential,
and it never leaves your server.

**3. From your visitors’ browsers, to render a widget**

When a page containing one of your widgets is displayed, the visitor’s browser loads
that widget’s script from the same Sorraia host (for example `https://api.sorraia.
app/api/embed/12.js`), and the widget then talks to Sorraia to do its job — submit
a form, look up booking availability, or start a checkout. This is the same script
the embed snippet from your Sorraia dashboard loads; the plugin writes the widget’s
container and adds that script through WordPress’s script queue.

This means your visitors’ browsers contact Sorraia, and Sorraia receives whatever
the widget is for — for example the contents of a form a visitor submits. Nothing
is sent to Sorraia from a page that has no Sorraia widget on it.

Along with what a visitor submits, the widgets tell Sorraia which site they are 
on. The AI chat (with each message) and the WhatsApp launcher (on each tap) also
send the page’s address and any `utm_` parameters in it. If the page runs WhatConverts
call tracking, the widgets also pass along WhatConverts’ visitor id (its `wc_client_current`
cookie), so a lead is credited to the right campaign. The AI chat keeps a conversation
token in the visitor’s browser storage, so reloading the page continues the same
chat.

By connecting a site key you agree to Sorraia’s terms and privacy policy:

 * Terms of Service: https://sorraia.app/terms
 * Privacy Policy: https://sorraia.app/privacy
 * Sub-processors: https://sorraia.app/sub-processors

This plugin’s own code contacts no service but Sorraia, and loads no fonts, analytics
or assets from anywhere else. The widgets it places are served by Sorraia, and depending
on how a widget is set up, a visitor’s browser may also contact:

 * **Google Fonts**, when a widget’s font is set to one of the Google fonts Sorraia
   offers (currently Inter, Roboto, Open Sans, Lato and Poppins). The stylesheet
   comes from `fonts.googleapis.com` and the font files from `fonts.gstatic.com`
   as soon as the widget loads, which gives Google the visitor’s IP address and 
   browser details. Any other font setting loads nothing from Google. Privacy Policy:
   https://policies.google.com/privacy
 * **WhatsApp** (Meta), only when a visitor taps the WhatsApp launcher or **Continue
   on WhatsApp** in the AI chat. The browser then opens `wa.me` with your business
   number and the pre-filled message, which can include the page’s title and a reference
   code. Privacy Policy: https://www.whatsapp.com/legal/privacy-policy
 * **Stripe**, only when a visitor buys from a shop widget. They are sent to Stripe
   Checkout to pay, and Stripe — not Sorraia or this site — takes the card details.
   Privacy Policy: https://stripe.com/privacy

## Blocks

This plugin provides 1 block.

 *   Sorraia widget Place a Sorraia form, booking calendar or shop on this page.

## Installation

 1. Install and activate the plugin.
 2. In Sorraia, open your site’s card and copy the site key (it starts with `sor_site_`).
    On a site you have not verified yet it is under **Show verification instructions****
    WordPress plugin**; on a verified site it is on the **Embed** card.
 3. In WordPress, go to **Settings  Sorraia**, paste the key, and press Connect.
 4. Your widgets are listed. Use the shortcode shown next to each one, add the **Sorraia
    widget** block to a page, or tick pages in the list and press **Add to selected
    pages**.
 5. For AI chat or WhatsApp, tick the launcher under **Site-wide launchers** and save.

## FAQ

### Do I need a Sorraia account?

Yes. The plugin lists and embeds widgets that live in a Sorraia account; it cannot
create them. There is a free plan.

### Where do I find my site key?

On your site’s card in the Sorraia dashboard. It starts with `sor_site_`.

Which part of the card depends on whether the site is verified yet. If it is not,
the key is a step of this verification method: press **Show verification instructions**
on the site’s card and pick **WordPress plugin**. Once the site is verified, it 
moves to the **Embed** card in the expanded site.

### Is the site key safe to store here?

It is scoped to one site. It can list that site’s widget names, types and ids, read
whether the site is verified, and ask Sorraia to run the verification check — nothing
else. It cannot read submissions, bookings, orders or customer data, and it is not
an API key. It is stored in your WordPress database and only ever sent from your
server to Sorraia, never to a visitor’s browser. If you think it has leaked, regenerate
it in Sorraia; the old one stops working immediately.

### I regenerated my key and the widget list broke.

In Settings  Sorraia, press **Disconnect**, then paste the new key and press **Connect**.
The old key stops working the moment you regenerate.

### My widget does not appear on the page.

Three usual causes. First, the widget is paused in Sorraia — the list on the settings
screen labels it. Second, a caching or optimisation plugin deferring, delaying or
rewriting the loader script. Third, a Content Security Policy on your site that 
does not allow scripts from `api.sorraia.app`.

On the second one: the plugin already asks **WP Rocket**, **Perfmatters** and **
LiteSpeed Cache** to leave the loader alone, by registering `rocket_exclude_defer_js`,`
rocket_delay_js_exclusions`, `perfmatters_delay_js_exclusions` and `litespeed_optm_js_defer_exc`
and adding both `api.sorraia.app/api/embed` and `/api/embed/` to each list, the 
second so a custom API host is covered too. Those four filters are the whole of 
what is automatic. Anything else — Autoptimize, W3 Total Cache, WP Fastest Cache,
Cloudflare’s Rocket Loader, an optimiser built into your host, or any setting in
those three plugins that the four filters above do not cover — still needs the widget
script URL (`api.sorraia.app/api/embed`) added to its JavaScript exclusion list 
by hand.

### Can I put the same widget on more than one page?

Yes. Tick as many pages as you like and press **Add to selected pages**. Pages that
already have that widget are marked, and you can still pick them — but a second 
copy of the same widget on one page renders only once, because both copies use the
same container id and the loader mounts into the first one. The plugin warns you
before doing it.

### How do I know where a widget already is?

Each widget row says so — “On: Contact (draft), About ×2”, with links to edit those
pages, or “Not on any page yet.” Site-wide launchers show whether their switch is
on instead, because they appear on every page rather than on particular ones.

### Does it change my existing page content?

No. Adding a widget appends it to the end of the page and leaves everything already
there untouched, and a revision is saved first, so you can undo it from WordPress’s
revision history.

### Does it work without the block editor?

Yes. Every widget has a shortcode, shown next to it in Settings  Sorraia. The block
is a convenience, not a requirement.

### Does it add a “Powered by” link to my site?

The plugin itself adds none. On Sorraia’s Free plan, the shop widget — which Sorraia
serves — shows a small “Powered by Sorraia” link. Paid plans do not show it, and
no other widget type does.

### What happens if I deactivate the plugin?

Your widgets stop rendering on this site: a Sorraia block shows nothing, and a `[
sorraia]` shortcode shows as plain text until you remove it or reactivate the plugin.
If you verified this site with the plugin, Sorraia’s daily re-check stops finding
the verification token, and the site becomes unverified in Sorraia until you verify
it again: reactivate the plugin, press **Refresh** in Settings  Sorraia, then **
Verify this site** (or add the DNS record instead). Disconnecting has the same effect
on verification. Nothing else in your Sorraia account changes. Uninstalling also
removes the plugin’s stored settings — including the site key — from your database.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Sorraia — Forms, Bookings, Shop & AI Chat” is open source software. The following
people have contributed to this plugin.

Contributors

 *   [ sorraia ](https://profiles.wordpress.org/sorraia/)

[Translate “Sorraia — Forms, Bookings, Shop & AI Chat” into your language.](https://translate.wordpress.org/projects/wp-plugins/sorraia)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/sorraia/), check out
the [SVN repository](https://plugins.svn.wordpress.org/sorraia/), or subscribe to
the [development log](https://plugins.trac.wordpress.org/log/sorraia/) by [RSS](https://plugins.trac.wordpress.org/log/sorraia/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.2.4

 * Verified sites keep serving the verification token so Sorraia’s daily re-check
   can succeed; previously a verified site was un-verified the next day.
 * The token is removed only when you disconnect, connect a different site key, 
   or uninstall the plugin.
 * Settings  Sorraia now warns when a site this plugin verified has no token to 
   serve, and asks you to press Refresh when Sorraia has not reported the site’s
   verification status yet, instead of showing nothing.
 * The FAQ now says that deactivating or disconnecting the plugin un-verifies a 
   site it verified, and that a regenerated key is entered by disconnecting first.

#### 1.2.3

 * “Used on” no longer caches page titles or edit links: each user sees only the
   pages they can edit, and the notices shown after Connect, Refresh and Verify 
   are kept per user.

#### 1.2.2

 * Widget loader scripts now load through WordPress’s script queue (`wp_enqueue_script`)
   at the end of the page, instead of being printed straight after each widget. 
   The script addresses are unchanged, and a widget placed twice on one page now
   loads its script once.
 * The Sorraia block declares block API version 3, for the iframed block editor 
   in WordPress 7.0 and later.
 * The API address in Settings  Sorraia now accepts only `sorraia.app` addresses.
 * Fixes from WordPress’s Plugin Check: translations are left to WordPress’s own
   language packs, form input is sanitised as it arrives, and uninstall no longer
   leaves unprefixed variables behind. The Plugins screen now lists the plugin simply
   as “Sorraia”.
 * Corrected the settings screen’s note on the “Powered by Sorraia” link: only shop
   widgets on the Free plan show it.
 * The readme now says what the site key can do (list this site’s widgets and check
   its verification), when the verification status is requested, that Sorraia re-
   checks a verified site about once a day, and what the widgets themselves load
   from third parties — Google Fonts, WhatsApp and Stripe.

#### 1.2.1

 * Corrected where this plugin says to find your site key. It said “Site  Embed”,
   which was only true for a site you had already verified — and 1.2.0’s whole point
   is verifying a site you have not. Sorraia now shows the key inside the WordPress
   verification method itself, and this plugin’s settings screen, installation steps
   and FAQ say so.
 * Text only — apart from the version number, nothing but wording changed. The plugin
   behaves exactly as 1.2.0 did.

#### 1.2.0

 * Site verification from the settings screen. Sorraia can now confirm you control
   this site by fetching a token the plugin serves, so there is no DNS record to
   add and no meta tag to paste into your theme.
 * The plugin answers that check at two public paths — `/?rest_route=/sorraia/v1/
   verify` and `/wp-admin/admin-ajax.php?action=sorraia_verify` — returning the 
   verification token and nothing else.
 * Corrected the “my widget does not appear” answer. It said the plugin adds no 
   optimiser exclusions of its own; it has registered exclusions for WP Rocket, 
   Perfmatters and LiteSpeed Cache since 1.0.0. The FAQ now names the four filters
   it registers, and says plainly which optimisers are still yours to configure.
 * External services now documents the verification traffic in both directions —
   the two calls this site makes, and the inbound request Sorraia’s servers make
   to your site when you press Verify.

#### 1.1.0

 * “Used on” — each widget row now says which pages it is already on, counting repeats(“
   About ×2”), with edit links. Site-wide launchers show their switch state instead.
 * Add to several pages at once: the single page dropdown is now a checklist with
   one “Add to selected pages” button. Pages that already carry the widget are marked
   and stay selectable.
 * A warning before adding a widget to a page that already has it, explaining that
   a second copy is saved but renders once per page.
 * Buttons on the settings screen now use the plugin’s own styling instead of borrowing
   WordPress’s default blue.
 * Uninstall now also removes the placement-cache settings introduced in this version.

#### 1.0.0

 * First release. Site key connection, widget list, shortcode, block, and site-wide
   launchers for AI chat and WhatsApp.

## Meta

 *  Version **1.2.4**
 *  Last updated **20 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.8 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/sorraia/)
 * Tags
 * [booking](https://tzm.wordpress.org/plugins/tags/booking/)[calendar](https://tzm.wordpress.org/plugins/tags/calendar/)
   [chat](https://tzm.wordpress.org/plugins/tags/chat/)[ecommerce](https://tzm.wordpress.org/plugins/tags/ecommerce/)
   [forms](https://tzm.wordpress.org/plugins/tags/forms/)
 *  [Advanced View](https://tzm.wordpress.org/plugins/sorraia/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/sorraia/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/sorraia/reviews/)

## Contributors

 *   [ sorraia ](https://profiles.wordpress.org/sorraia/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/sorraia/)