Skip to content

Module 7 — Frontend-Facing AI Features

Goal: AI features your site's visitors actually use — not just wp-admin.

Everything in Module 6 lived inside the block editor, features for whoever’s writing the post, always logged in, always with real capabilities. This module moves to the other side of the site, features your actual visitors interact with, some of whom aren’t logged in at all.

What’s in this module

  1. A Public AI-Powered FAQ / Search Widget. A frontend widget that answers visitor questions using your site’s own content. The first chapter in this book whose REST endpoint has to work for someone who isn’t logged in at all.
  2. Smart Comment Reply Suggestions. A button on the comment form suggesting a reply draft, logged-in only this time, but still a frontend feature, not an admin one.
  3. A Multi-Turn Chatbot Widget on the Frontend. A real floating chat widget with actual conversation memory, combining Chapter 16’s with_history() with the REST pattern from Chapter 20, built all the way out this time into something a visitor could actually use.

One real shift this module makes

Every permission_callback so far in this book has checked current_user_can(), because every REST endpoint so far assumed someone logged in was calling it. Chapter 25 breaks that assumption.

A logged-out visitor has no capabilities to check. “Who’s allowed to use this” stops being a capability question and becomes a different one: how do you stop a public endpoint from being abused, rate limiting, nonces, and scoping exactly what it’s allowed to do, without ever checking who the caller is.

On to Chapter 25.

This book is created with Chapterwright