Description
At a glance
Looking for Alesta v1.9.0? It is available here as a free GPL download for WordPress — 10+ active installs · updated September 28, 2026 · requires WordPress 6.0+ & PHP 7.4+.
Alesta is a minimalist WordPress toolkit focused on SEO and technical performance. Every module does one thing and does it well.
Modules shipped in this version (16 free modules):
- Title & Meta AI + SEO Audit — Generates SEO titles and meta descriptions for your posts, pages (and products) with your AI provider (Anthropic Claude or OpenAI), one by one or in batch, then applies them to your site (or mirrors them into Yoast SEO, Rank Math or All in One SEO when one of them is active). Includes an SEO audit tab with a score per page (title, description, headings, images, links). Also adds an editable SEO meta box (title, description, Open Graph, Twitter Card, robots, canonical) on every post and page, whose AI button (“Générer avec Claude”) is available to editors and administrators by default. Password-protected content is never sent to the AI. Requires your own Anthropic or OpenAI API key (see “External services” below).
- FAQ Schema — Generates FAQ questions and answers from the content of a page with the AI provider you chose, lets you edit them, and outputs the FAQPage JSON-LD structured data eligible for Google rich results. Requires your own Anthropic or OpenAI API key.
- Brute-force protection — Limits failed login attempts per IP (configurable attempts, time window and lockout duration), blocks the login form and XML-RPC for banned IPs, IP whitelist, lockout history, manual unban and optional e-mail notification. Off by default: you turn it on from its page after checking the IP it detects. If your site sits behind an undeclared proxy or CDN, lockouts are suspended with a warning instead of blocking every visitor (see the FAQ). No external service.
- XML Sitemap — Generates a sitemap.xml (with image and video entries), can regenerate it automatically when content changes, lets you exclude post types or individual posts and disable the native WordPress sitemaps. It checks that the file is publicly reachable and links to Google Search Console and Bing Webmaster Tools so you can submit it there.
- Gzip, Cache, HTTPS optimization — Clean, safe manipulation of the .htaccess file: enable Gzip compression, browser cache headers for static assets, and HTTP to HTTPS redirection. One-click backup and restore included.
- Robots.txt editor — Edit, backup, restore and check the accessibility of your robots.txt directly from the WordPress admin.
- Broken links scanner (4xx / 5xx) — On-demand scan of the links found in your published posts, pages and products (Elementor content included) to detect 404, 500 and other HTTP errors, with a sortable results table and a single-URL tester.
- Scheduled database cleaner — Removes revisions, auto-drafts, orphan meta, expired transients, spam and trash comments on a WP Cron schedule. One-click manual cleanup and detailed report.
- Google Fonts GDPR self-hosting — Detects Google Fonts loaded by your theme/plugins, downloads them locally, and rewrites the URLs so no requests hit Google servers (GDPR compliance).
- Maintenance mode — One-click maintenance / coming-soon page with configurable logo, headline, message, background, countdown and whitelist for admins. Sends a 503 status to search engines.
- GDPR cookies banner — Customizable consent banner (Accept / Refuse / Configure) rendered site-wide, with per-category storage of the visitor’s choice.
- Talk to Me — floating contact widget — Multi-channel contact button (WhatsApp, Messenger, phone, email, SMS, Telegram, Instagram DM, custom link) with configurable opening hours per day. No AI, no external API. The “Powered by Alesta” credit link is optional and off by default.
- Minify HTML/CSS — Minifies the CSS files enqueued by WordPress and the HTML output, with an automatic bypass for the major page builders (Elementor, Divi, Beaver, Bricks, Oxygen, WPBakery, Brizy, Thrive) and the Customizer preview. Cache stored in
wp-content/cache/alesta-minify/. An optional “Preload CSS” section adds<link rel="preload" as="style">hints to the page head for the enqueued stylesheets (all of them, or only the handles you list, with exclusions). Every option is off by default. JavaScript minification is still in development and currently unavailable. - Health Check — Site health dashboard: PHP version, SSL, disk usage, active plugins count, MySQL version, uploads folder size, key file/permission checks.
- Debug Manager — One-click toggle for WP_DEBUG (writes the WP_DEBUG constants to wp-config.php after checking that the result is valid PHP, and keeps a restorable copy of the previous file), live viewer for debug.log with size/rotation info, one-click clear and optional AI analysis of the log.
- Budget tracker — Monthly / daily token consumption and estimated cost of the AI modules, with an optional monthly limit, alert threshold and e-mail notification.
The modules come with a Configuration page where you choose your AI provider (Anthropic Claude or OpenAI), store its API key (encrypted with your site’s AUTH_KEY salt) and pick the model used by the AI modules. Both keys can be stored side by side so you can switch provider without retyping them. Test and delete a key at any time.
Alesta is built in the same product family as the Alesta AI suite. The AI modules are “bring your own key”: you create an API key in your own Anthropic or OpenAI account, you are billed by that provider for what you use, and the plugin never proxies your requests through a third-party server.
External services
The Title & Meta AI + SEO Audit and FAQ Schema modules, the AI button of the SEO meta box and the optional debug.log analysis use one third-party AI API, the one you select in Alesta AI Configuration: either the Anthropic Claude API (operated by Anthropic PBC) or the OpenAI API (operated by OpenAI, L.L.C.). No AI request is ever sent to the provider you did not select, and no request at all is sent until you enter a key.
- Who triggers a request: only a logged-in user who clicks a generate / analyze / test / refresh button in the WordPress admin. The Title & Meta, FAQ Schema, Debug Manager and Configuration screens are reserved to administrators. The AI button of the SEO meta box is available to editors and administrators by default (
alesta_meta_ai_capabilityfilter) and limited to 30 generations per user per hour (alesta_meta_ai_rate_limitfilter). - What is sent and when: at that moment, the plugin sends the text content of the selected post(s) or page(s) (title, excerpt, body text, post type, site language) — or, for the Debug Manager, the last 100 lines of your debug.log — together with your API key to the selected provider over HTTPS. Password-protected content is never sent. Nothing is sent automatically, on a schedule, or when visitors browse your site. The “Test the key” button sends a short fixed prompt, and “Refresh the model list” only asks the provider which models your key can use.
- Endpoints used:
https://api.anthropic.com/v1/messagesandhttps://api.anthropic.com/v1/modelswhen the Anthropic provider is selected;https://api.openai.com/v1/chat/completionsandhttps://api.openai.com/v1/modelswhen the OpenAI provider is selected. - Why: to obtain the generated SEO title, meta description, FAQ questions and answers, or log analysis from the model you selected, and to list the models available to your key.
- Requirement: an API key that you create in your own account with the chosen provider and enter in Alesta AI Configuration. Without a key the AI features are simply disabled; every other module works without any external service.
- Anthropic terms of service: https://www.anthropic.com/legal/consumer-terms
- Anthropic privacy policy: https://www.anthropic.com/legal/privacy
- OpenAI terms of use: https://openai.com/policies/row-terms-of-use
- OpenAI privacy policy: https://openai.com/policies/row-privacy-policy
Some optional modules contact the following additional services, always as a result of an action in the WordPress admin and never because a visitor browses your site:
- Google Fonts (Google LLC): the “Google Fonts GDPR” module downloads font stylesheets and font files from
https://fonts.googleapis.comandhttps://fonts.gstatic.comso they can be served from your own server. It runs only when an administrator scans the site or localises a font, and sends only the font request — no visitor data. Terms: https://policies.google.com/terms — Privacy: https://policies.google.com/privacy - Vimeo oEmbed (Vimeo.com, Inc.): when the XML sitemap module builds a video sitemap, it queries
https://vimeo.com/api/oembed.jsonfor the public metadata (thumbnail) of the Vimeo videos embedded in your content. Triggered only when the sitemap is generated: by an administrator, or after a content change if you enabled automatic regeneration. Terms: https://vimeo.com/terms — Privacy: https://vimeo.com/privacy - Link checker: the SEO Audit and the broken-links scanner send an HTTP HEAD request to the URLs found in your own published content, to verify they still resolve (User-Agent
Alesta-LinkCheckerorAlesta-Scanner). Internal and private network addresses are refused. Triggered only when an administrator runs the audit or the scan; the destinations are the sites you yourself linked to.
Privacy and GDPR
Apart from the external services described above — each triggered from the WordPress admin, never by visitor traffic — Alesta does not send any data outside your site. It does not ping search engines: you submit your sitemap yourself in Google Search Console or Bing Webmaster Tools. No tracking, no telemetry, and no link to our site is added to your pages unless you enable the optional Talk to Me credit.
Compatibility
- Works with any theme
- Compatible with the Classic Editor and the Block Editor (Gutenberg)
- Compatible with WooCommerce (products are included in the sitemap if the CPT is public)
- Does not duplicate the meta description, Open Graph or Twitter tags of Yoast SEO, Rank Math, All in One SEO, SEOPress, The SEO Framework, Slim SEO, Squirrly SEO, SmartCrawl or Jetpack (see the FAQ)
Pro version
A separate Alesta AI Pro extension provides additional modules (AI, security, reporting, chatbot, and more). It is distributed outside the WordPress.org repository at alesta-ai.com and is fully independent and optional. When it is active, it can take over the modules both plugins share (Configuration, Title & Meta, SEO Audit, SEO meta box, FAQ Schema, brute-force protection) with its own pages and defaults; settings, keys, generated meta and lockouts are shared. From version 2.0.8, its SEO meta box follows the same rules as this plugin (AI button for editors and administrators by default, same filters, same hourly limit), and its SEO meta box, Title & Meta generation and FAQ Schema never send password-protected content to the AI.
Frequently asked questions
What do I get when I download Alesta?
Alesta 1.9.0 is the latest version. It is a WordPress plugin you can download here free of charge under the GPL license, with the complete feature set included and no trial limitations.
Does Alesta cost anything?
No. Alesta 1.9.0 is 100% free — the full GPL version, not a trial or demo. There are no download limits, no accounts to create, and no upsells during the download.
How do I install Alesta 1.9.0?
Download the ZIP file from this page, then in your WordPress dashboard go to Plugins → Add New → Upload Plugin, choose the file, click Install Now, then Activate. The plugin works immediately after activation — no license key or extra setup is required for the core features.
What are the requirements for Alesta?
Alesta 1.9.0 requires WordPress 6.0 or higher and PHP 7.4 or higher. Most modern WordPress hosts already meet these versions. Running older versions may cause features to break, so update WordPress and PHP first if your site is behind.
When was Alesta last updated?
Version 1.9.0 was last updated on September 28, 2026. This page is refreshed automatically, so the download here always matches the newest version we have verified.
Is the Alesta download safe?
The file is sourced directly from the official WordPress.org repository — the same file the developer published. It is served unmodified, so what you install here is byte-identical to the official release.
Technical details
| Version | 1.9.0 |
|---|---|
| Last updated | September 28, 2026 |
| Active installs | 10+ |
| Requires WordPress | 6.0 or higher |
| Requires PHP | 7.4 or higher |
| Author | alestaplugin |
| Tags | brute-force, faq-schema, meta-description, seo, sitemap |
Download Alesta
Download Alesta WP PluginNote: if the download does not start, disable your ad blocker and try again.