WordPress Installation Guide
Last researched 2026-08-26
This is the canonical Virent installation guide for WordPress sites.
Research Notes#
- WordPress front-end scripts should be registered through
wp_enqueue_scripts. - Custom script attributes can be added through
script_loader_tag. - The
shutdownhook runs late enough to read the final WordPress response status. wp_remote_postperforms server-side POST requests.
Primary references:
- https://developer.wordpress.org/reference/functions/wp_enqueue_script/
- https://developer.wordpress.org/reference/hooks/shutdown/
- https://developer.wordpress.org/reference/functions/wp_remote_post/
Human Analytics#
Prefer a small plugin or mu-plugin so tracking survives theme changes.
TXT
<?php/** * Plugin Name: Virent Human Analytics */add_action('wp_enqueue_scripts', function () { wp_enqueue_script( 'virent-human-analytics', 'https://app.virent.app/js/script.js', array(), null, false );});add_filter('script_loader_tag', function ($tag, $handle) { if ($handle !== 'virent-human-analytics') { return $tag; } return str_replace( '<script ', '<script defer data-write-key="vha_pk_..." ', $tag );}, 10, 2);Best practices:
- Use
wp_enqueue_scriptsrather than editing WordPress core. - Prefer a plugin, mu-plugin, or child theme over direct theme edits.
- Keep the server secret out of rendered HTML.
- Purge page caches and CDN caches after installation.
Verification:
- Activate the plugin.
- View source on a public page and confirm the Virent script exists.
- Check Network for
/js/script.jsand pageview requests. - Refresh Human Analytics status.
Troubleshooting:
- If the script is absent, confirm the plugin is active and the hook runs on the front end.
- If page caching hides the change, purge cache and CDN.
- If a security plugin blocks the script, allow the Virent origin.
AI Analytics#
Keep server values in wp-config.php or environment-specific configuration.
TXT
define('VIRENT_SITE_ID', 'site_...');define('VIRENT_INGEST_SECRET', 'vha_sk_...');define('VIRENT_INGEST_ENDPOINT', 'https://app.virent.app/v1/ingest/bot');Install a plugin or mu-plugin:
TXT
<?php/** * Plugin Name: Virent AI Analytics */add_action('shutdown', function () { if (is_admin() || wp_doing_ajax() || wp_doing_cron()) { return; } $user_agent = $_SERVER['HTTP_USER_AGENT'] ?? ''; $path = parse_url($_SERVER['REQUEST_URI'] ?? '/', PHP_URL_PATH) ?: '/'; if ( preg_match('/\.(?:png|jpg|jpeg|gif|svg|ico|webp|css|js|map|txt|xml)$/i', $path) || ! preg_match('/GPTBot|OAI-SearchBot|ChatGPT-User|ClaudeBot|claudebot|Claude-Web|Claude-User|Claude-SearchBot|PerplexityBot|PerplexityBot\/|Perplexity-User|Perplexity-User\/|Google-CloudVertexBot|DeepSeekBot|DeepSeekSpider|CCBot|Applebot|Bytespider|meta-externalagent|meta-webindexer|meta-externalfetcher|Amazonbot|DuckAssistBot|PetalBot|YouBot/i', $user_agent) ) { return; } wp_remote_post(VIRENT_INGEST_ENDPOINT, array( 'headers' => array( 'Content-Type' => 'application/json', 'x-api-key' => VIRENT_INGEST_SECRET, ), 'body' => wp_json_encode(array( 'siteId' => VIRENT_SITE_ID, 'url' => home_url(add_query_arg(array(), $_SERVER['REQUEST_URI'] ?? '/')), 'host' => $_SERVER['HTTP_HOST'] ?? wp_parse_url(home_url(), PHP_URL_HOST), 'path' => $path, 'method' => $_SERVER['REQUEST_METHOD'] ?? 'GET', 'referer' => $_SERVER['HTTP_REFERER'] ?? null, 'userAgent' => $user_agent, 'statusCode' => http_response_code() ?: 200, 'requestId' => wp_generate_uuid4(), 'timestamp' => gmdate('c'), )), 'timeout' => 2, 'blocking' => false, ));});Best practices:
- Use a plugin or mu-plugin rather than editing core.
- Skip
wp-admin, AJAX, cron, login, REST API, and static asset requests unless intentionally tracking them. - Store
VIRENT_INGEST_SECREToutside rendered HTML. - Confirm the host allows outbound HTTP requests to Virent.
Verification:
SH
curl -A "GPTBot" https://your-domain.com/- Confirm the plugin is active.
- Confirm Virent receives crawler events.
- Refresh AI Analytics status.
Troubleshooting:
- If no events arrive, confirm outbound HTTP is allowed by the host or security plugin.
- If admin requests are tracked, keep admin and login exclusions.
- If the secret appears in page source, move it to server config and rotate it.