{"id":11874,"date":"2026-09-20T16:06:10","date_gmt":"2026-09-20T08:06:10","guid":{"rendered":"https:\/\/aeosub.com\/twt-chat\/"},"modified":"2026-09-20T16:06:10","modified_gmt":"2026-09-20T08:06:10","slug":"twt-chat","status":"publish","type":"post","link":"https:\/\/aeosub.com\/zh\/twt-chat\/","title":{"rendered":"TWT Chat"},"content":{"rendered":"<div class=\"post-img\" style=\"margin-bottom: 25px\"><img decoding=\"async\" src=\"https:\/\/ps.w.org\/twt-chat\/assets\/banner-1544x500.png?rev=3703963\" alt=\"TWT Chat\" loading=\"lazy\" style=\"width: 100%;height: auto;border-radius: 12px\"><\/div>\n<div class=\"plugin-expert-review\" style=\"border: 1px solid #e2e8f0;border-left: 4px solid #4a3bca;border-radius: 10px;padding: 20px;margin-bottom: 25px;background: #fff;font-family: -apple-system, system-ui, sans-serif\">\n<div style=\"font-weight: bold;font-size: 1.1em;color: #4a3bca;margin-bottom: 10px\">LethaldiranMX Insight<\/div>\n<div style=\"color: #4a5568;font-size: 14px;line-height: 1.6\">\n<div>\n<p>The TWT Chat plugin offers a highly streamlined, lightweight integration path for site owners looking to deploy the TWT Chat external SaaS without bloating their WordPress database or codebase. By offloading the heavy lifting\u2014such as the chat interface, WebSocket connections, and visitor state persistence\u2014entirely to the external TWT infrastructure, it maintains an exceptionally low footprint on the host server. This architecture is ideal for digital operations teams who prioritize front-end performance and secure, handshake-based authentication over manual, error-prone configuration.<\/p>\n<p><strong>Best Fit &amp; Operational Role:<\/strong> This integration is best suited for enterprise or mid-market WordPress sites already utilizing or onboarding the TWT Chat SaaS platform. It fits cleanly into modern digital operations workflows by replacing manual script injections with a structured, admin-only OAuth binding flow. This eliminates the need for non-technical administrators to handle raw API keys or embed codes, solving the operational challenge of maintaining secure, standardized third-party integrations across multiple web properties.<\/p>\n<p><strong>Potential Limitations &amp; Pitfalls:<\/strong> From an operational standpoint, the strict reliance on a one-time external callback means troubleshooting connection issues requires access to both the WordPress admin and the TWT console, with no fallback for manual App ID configuration. Additionally, because the plugin dynamically loads the external core.js payload on the front-end, organizations must ensure their Content Security Policies (CSP) and privacy policies are updated to permit connections to visitorchat.twt.com, as the runtime handles visitor sessions and cookies externally.<\/p>\n<\/div>\n<\/div><\/div>\n<div class=\"plugin-info-card\" style=\"border: 1px solid #e2e8f0;border-radius: 10px;overflow: hidden;margin-bottom: 30px;font-family: -apple-system, system-ui, sans-serif;background: #fff\">\n<div style=\"padding: 20px;border-bottom: 1px solid #edf2f7;background: #fafafa;display: flex;align-items: flex-start\">\n                <img decoding=\"async\" src=\"https:\/\/ps.w.org\/twt-chat\/assets\/icon-256x256.png?rev=3703963\" alt=\"TWT Chat icon\" loading=\"lazy\" style=\"width: 45px;height: 45px;border-radius: 8px;margin-right: 15px\"> <\/p>\n<div style=\"flex: 1;line-height: 1.2\">\n<div style=\"font-weight: bold;font-size: 1.1em;color: #1a202c\">Plugin Specification<\/div>\n<p>                    <small style=\"color: #718096\">WordPress.org Official Data<\/small>\n                <\/div>\n<\/p><\/div>\n<table style=\"width: 100%;border-collapse: collapse;font-size: 14px\">\n<tr style=\"border-bottom: 1px solid #edf2f7\">\n<th style=\"padding: 12px 20px;text-align: left;width: 35%;color: #4a5568;background: #fcfcfc\">Developer<\/th>\n<td style=\"padding: 12px 20px;font-weight: 500\"><a href=\"https:\/\/profiles.wordpress.org\/twtchat\/\" target=\"_blank\" rel=\"noopener\">twtchat<\/a><\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #edf2f7\">\n<th style=\"padding: 12px 20px;text-align: left;color: #4a5568;background: #fcfcfc\">Version<\/th>\n<td style=\"padding: 12px 20px\">v1.0.1<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #edf2f7\">\n<th style=\"padding: 12px 20px;text-align: left;color: #4a5568;background: #fcfcfc\">Active Installs<\/th>\n<td style=\"padding: 12px 20px\">0 +<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #edf2f7\">\n<th style=\"padding: 12px 20px;text-align: left;color: #4a5568;background: #fcfcfc\">Requires \/ Tested<\/th>\n<td style=\"padding: 12px 20px\">6.0 \/ 7.1.1<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #edf2f7\">\n<th style=\"padding: 12px 20px;text-align: left;color: #4a5568;background: #fcfcfc\">Last Updated<\/th>\n<td style=\"padding: 12px 20px\">2026-09-20 7:57am GMT<\/td>\n<\/tr>\n<tr>\n<th style=\"padding: 12px 20px;text-align: left;color: #4a5568;background: #fcfcfc\">Official Link<\/th>\n<td style=\"padding: 12px 20px\"><a href=\"https:\/\/wordpress.org\/plugins\/twt-chat\/\" target=\"_blank\" rel=\"noopener noreferrer\" style=\"text-decoration: none;color: #4a3bca;font-weight: bold\">View Details -&gt;<\/a><\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"plugin-short-desc\" style=\"margin: 20px 0;padding: 12px 15px;background: #f9fafb;border-left: 4px solid #4a3bca;border-radius: 6px;font-style: italic;color: #4a5568\">Connect an authorized project to add the TWT Chat floating launcher to your WordPress site.<\/div>\n<p>TWT Chat is a small WordPress integration for the TWT Chat external SaaS. The plugin is disabled after activation. An administrator with the <code>manage_options<\/code> capability clicks the <strong>TWT Chat<\/strong> menu and is sent directly to the Accounts address baked into the installed package to sign in. The external Chat Console recognizes the WordPress source, shows the restricted project-list view, and returns the selected <code>app_id<\/code>, normalized <code>address<\/code>, and per-binding <code>sign_key<\/code> through a one-time callback.<\/p>\n<p>The plugin does not contain the chat interface, iframe runtime, HTTP API, WebSocket implementation, or browser persistence. It loads the visitor-next loader for the installed build environment only when the setting is enabled and the appid passes the strict ASCII validation contract.<\/p>\n<h3>Settings<\/h3>\n<p>The plugin stores one site-wide appid, normalized site address, per-binding sign_key, and an enabled flag in the <code>twt_chat_options<\/code> WordPress option. Valid appids contain only ASCII letters, numbers, underscores, and hyphens and are 1 to 128 characters long. There is no editable App ID field and no legacy migration path. A successful binding writes <code>enabled=true<\/code>; <strong>Disconnect your account<\/strong> first calls the same-environment <code>\/console\/site\/wordpress_unbind<\/code> endpoint with a signed request, then clears all local binding fields only after <code>code=1<\/code>, without deleting the TWT project.<\/p>\n<p>The successful project binding authorizes this site to load the external TWT Chat service. It does not replace any visitor consent that the site or a completed TWT Chat privacy assessment may require.<\/p>\n<h3>External Services<\/h3>\n<p>When a project has been successfully bound and enabled on a front-end page, the plugin loads this fixed HTTPS visitor-next loader:<\/p>\n<ul>\n<li><code>https:\/\/visitorchat.twt.com\/install\/core.js?version=v1.2<\/code><\/li>\n<\/ul>\n<p>The loader can create the default launcher and panel and may connect the browser to TWT Chat runtime services. The plugin provides the bound <code>appid<\/code>; the runtime may also process the current page URL and title, visitor session data, chat messages, and cookies, Local Storage, or other browser storage needed to keep chat state. The processing purpose is to provide the requested chat experience and maintain its session.<\/p>\n<p>For the production package, the widget frame is served from <code>https:\/\/visitorchat.twt.com\/widget-frame\/<\/code> and its HTTPS API base is <code>https:\/\/visitorchat.twt.com\/api\/<\/code>. Verified runtime requests include <code>GET \/api\/fk\/user\/get_domain_bmd<\/code> during widget bootstrap, <code>POST \/api\/fk\/user\/login<\/code> when visitor authentication starts, and <code>\/api\/fk\/chat\/*<\/code>, <code>\/api\/fk\/msg\/*<\/code>, or <code>\/api\/fk\/common\/*<\/code> requests only when the visitor uses the corresponding chat features. After visitor authentication and session initialization, the runtime opens <code>wss:\/\/apichat.twt.com\/ws<\/code>. No widget iframe, API, or WebSocket request is made while the plugin is unbound or disabled.<\/p>\n<p>The plugin does not store a TWT token. It generates a 32-byte random state for each start request, stores only the SHA-256 state digest in a 1-hour (3600-second) transient, and deletes that transient on callback success or failure. The callback accepts <code>state<\/code>, a strictly validated public <code>app_id<\/code>, a normalized HTTP(S) <code>address<\/code>, and a non-empty opaque <code>sign_key<\/code>. The key is not displayed and is used only to sign the later disconnect request.<\/p>\n<p>The confirmed policy links are:<\/p>\n<ul>\n<li>Terms of Service: <a href=\"https:\/\/www.twt.chat\/a\/agreement\" rel=\"nofollow ugc noopener\" target=\"_blank\">https:\/\/www.twt.chat\/a\/agreement<\/a><\/li>\n<li>Privacy Policy and deletion requests: <a href=\"https:\/\/www.twt.chat\/a\/privacy\" rel=\"nofollow ugc noopener\" target=\"_blank\">https:\/\/www.twt.chat\/a\/privacy<\/a><\/li>\n<\/ul>\n<p>The production service endpoints, request timing, data-processing terms, consent responsibilities, and loader release controls have been verified for this version. Responsibility for visitor consent remains with the site owner. Administrator enablement authorizes the external service load but is not itself visitor consent. Sites that require opt-in must delay enablement until their consent mechanism allows the service. TWT Chat&#8217;s current service documentation and Privacy Policy govern retention, deletion requests, controller\/processor roles, subprocessors, and cross-border processing. The <code>v1.2<\/code> loader is immutable for this release, version-pinned in the package, and managed through reviewed compatibility, release, audit, and rollback controls.<\/p>\n<p>Uninstalling this plugin retains the local <code>twt_chat_options<\/code> binding data and sets its enabled flag to false. Reactivating a complete retained binding on the same site origin enables the integration without another authorization flow. <strong>Uninstalling the plugin does not delete TWT Chat server-side history<\/strong>. Use the TWT Chat Privacy Policy and its deletion-request route for service-side data requests.<\/p>\n<h3>Privacy<\/h3>\n<p>The plugin registers suggested text with the WordPress Privacy Policy guide. Site owners must review that text, their own consent tooling, and the current TWT Chat Privacy Policy before enabling the service for visitors.<\/p>\n<h3>Support<\/h3>\n<p>Support and documentation are available at <a href=\"https:\/\/www.twt.com\/\" rel=\"nofollow ugc noopener\" target=\"_blank\">https:\/\/www.twt.com\/<\/a>.<\/p>\n<h3>Release readiness<\/h3>\n<p>The WordPress.org author, contributor, Plugin URI, Author URI, support channel, and directory assets have been verified and completed for this release. The directory icon, banner, and screenshots are licensed for use with TWT Chat and are supplied through the WordPress.org directory asset channel.<\/p>\n<div class=\"plugin-editorial-note\" style=\"margin-top: 25px;padding: 12px 15px;background: #f8fafc;border-radius: 6px;color: #64748b;font-size: 13px;line-height: 1.5\">Editorial note: This overview combines WordPress.org official plugin metadata with an AI-assisted LethaldiranMX editorial review. Plugin data should be verified on the official WordPress.org listing before installation.<\/div>","protected":false},"excerpt":{"rendered":"<p>Connect an authorized project to add the TWT Chat floating launcher to your WordPress site.<\/p>","protected":false},"author":1,"featured_media":11875,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[252],"tags":[556,617,618,555],"class_list":["post-11874","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trends","tag-chat","tag-customer-support","tag-live-chat","tag-wordpress-plugin"],"_links":{"self":[{"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/posts\/11874","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/comments?post=11874"}],"version-history":[{"count":0,"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/posts\/11874\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/media\/11875"}],"wp:attachment":[{"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/media?parent=11874"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/categories?post=11874"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/tags?post=11874"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}