Hedomi Tarot
Hedomi Tarot
Description
Hedomi Tarot is a free, fully functional tarot-reading plugin for WordPress. The WordPress.org build includes its local reading and optional AI functionality without feature locking or trial restrictions. WooCommerce payment and reading-credit functionality is a separate Pro feature and its functional code is not included in this Free build.
Features include:
- Deck taxonomy and tarot card post type.
- Upright and reversed meanings.
- Keywords and optional Yes/No classification.
- Spread builder with unlimited positions.
- Visual drag-and-drop position preview.
- Manual and automatic card selection.
- Optional reversed cards and configurable probability.
- Secure AJAX validation with nonce and deck verification.
- Responsive frontend and card-reveal animations.
- Reading cards or tabbed interpretations.
- Shortcode: [hedomi_tarot id=”123″]
- Optional OpenAI personalized interpretations using the visitor question and the administrator’s card meanings.
- Required visitor consent for AI personalization, configurable local AI abuse protection, connection test, and traditional-reading fallback.
- One-click creation of the standard 78-card Tarot structure as editable drafts.
The plugin does not include copyrighted card artwork or interpretations. Site owners must provide content they have the right to use.
OpenAI is an optional external service. Traditional readings work without OpenAI and without an API key.
External services
Hedomi Tarot can optionally connect to the OpenAI API to generate personalized tarot interpretations. OpenAI performs the interpretation on its external servers. This service is not required for traditional readings.
The connection occurs only when the site owner configures an OpenAI API key, enables AI, and an AI reading is requested. The visitor must explicitly confirm consent before the question and spread data are sent to OpenAI.
For an AI reading, the plugin may send the visitor question (if provided), spread title, selected card names, card orientation, spread position names and context, card keywords, Yes/No metadata, site locale, card meanings entered by the site administrator, and any additional AI instructions entered by the administrator. The OpenAI API key is sent in the server-to-server Authorization header. It is not exposed in frontend JavaScript. Requests set the OpenAI store parameter to false; OpenAI’s processing and retention practices remain governed by its own policies. WordPress authentication cookies, authentication keys, salts, and session identifiers are not sent to OpenAI.
When the administrator enables the optional per-visitor AI abuse-protection limit, anonymous requests use a SHA-256 hash of the visitor IP address as a temporary local rate-limit key. The raw IP address is not stored by this feature, the hash is not sent to OpenAI, and the transient expires within one hour. This rate protection affects only optional AI personalization and never blocks traditional readings.
OpenAI Terms of Use: https://openai.com/policies/terms-of-use/
OpenAI Privacy Policy: https://openai.com/policies/privacy-policy/
Installation
- Upload the plugin ZIP in Plugins > Add New > Upload Plugin.
- Activate Hedomi Tarot.
- Open Hedomi Tarot > Decks and create a deck.
- Open Hedomi Tarot > Create 78 cards to generate a standard deck, or add cards manually. Set each card’s Featured Image and meanings.
- Open Hedomi Tarot > Spreads and create a spread.
- Select the deck, add positions and arrange them in the visual preview.
- Publish the spread and paste its shortcode into a page.
Faq
No. Card artwork and interpretations must be added by the site owner, using material they have the right to use.
Yes. Its local tarot-reading functionality is available without feature locking or trial restrictions. OpenAI personalization is optional and requires the site owner’s own API configuration.
Yes. The server checks the nonce, card count, duplicate IDs and whether every card belongs to the selected deck.
No. OpenAI is optional. Traditional readings use the card meanings saved by the site owner and work without an API key. When a site owner supplies an OpenAI API key and enables AI, the plugin can request personalized interpretations from OpenAI.
No. The plugin does not send WordPress authentication cookies, keys, salts, or session identifiers to OpenAI.
Reviews
Changelog
0.4.7
- Added a secure admin tool that creates all 78 standard Tarot cards as editable drafts.
- Existing cards in the selected deck are detected and skipped to prevent duplicates.
0.4.6
- Added a non-functional Pro preview for WooCommerce payment and reading-credit settings inside the spread editor.
- Premium controls are visibly marked PRO and disabled; premium WooCommerce and credit code remains excluded from the Free build.
- Added a restrained link to the separate Hedomi Tarot Pro edition.
0.4.5
- Removed legacy access restrictions from the WordPress.org build so local reading functionality remains fully available.
- Removed use of WordPress authentication salts from AI identifiers and removed the external safety identifier from OpenAI requests.
- Moved the AI settings JavaScript to an enqueued script.
- Removed the unnecessary load_plugin_textdomain() call for WordPress.org-hosted translations.
- Kept nonce and capability checks on administrative AJAX actions and nonce validation on frontend reading requests.
- Made visitor consent mandatory before sending reading data to OpenAI.
- Simplified WordPress.org-facing documentation and removed promotional admin UI.
0.4.4
- Corrected the WordPress.org contributor username to elenadom so the plugin is linked to the submitting account.
0.4.3
- Updated WordPress compatibility metadata.
- Removed production-root setup Markdown files flagged by the WordPress.org automated scanner.
- Removed the Domain Path header because this build does not bundle a local languages directory.
0.4.0
- Made AI an optional enhancement instead of a dependency of the reading flow.
- API failures, missing consent, and AI limits fall back to traditional meanings instead of blocking the reading.
- Added a visible result badge showing AI personalized vs traditional reading mode.
0.2.3
- Added a real OpenAI Responses API connection test and sanitized diagnostics.
0.2.0
- Added optional OpenAI personalized interpretations and per-spread AI controls.
0.1.0
- Initial functional foundation.


