=== KillerConversions ===
Contributors: killerconversions
Tags: contact form, form builder, application form, estimate
Requires at least: 6.5
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 0.11.14
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Build enquiries, simple estimates and saved applications. Keep entries, private files and dependable email handling in WordPress.

== Description ==

KillerConversions Free supports three complete workflows without a vendor account: an enquiry with staff and visitor email, a simple service estimate, and a multi-step application with explicit save/resume and eligible private attachments.

* Visual builder with live preview, keyboard field ordering, block and shortcode embeds.
* Private design drafts, explicit publishing, conflicting-save protection and ten-design history. Credentials and operational settings stay outside design history.
* Basic show/hide conditions and multiple steps with Next/Back controls and retained answers.
* Repeatable groups: up to three groups, ten rows per group and six text, email, number, date or select fields per row. Saved drafts, email, CSV and privacy tools retain structured answers. Requires JavaScript; nested groups, uploads, consent, pricing and conditional dependencies inside groups are excluded.
* Quantity × unit-price rows, fixed extras, currency, server-authoritative itemisation, email and print summary. No formula writing needed for simple estimates.
* Private PDF, PNG, JPEG and UTF-8 TXT uploads: three files, one per field, 1/5/10 MiB choices and 15 MiB combined, reduced by hosting capacity.
* Explicit encrypted visitor drafts with 1/3/7-day expiry and private resume links. No automatic capture of incomplete answers.
* Local inbox, search/filter/star, basic assignment, status, submitted-entry counts and wide/long CSV. These counts are not conversion rates.
* Queued staff notifications and separately requested visitor confirmations, validated Reply-To, bounded retries, failure status and guarded resend. Your site controls From.
* Optional basic Brevo and MailerLite subscriber actions with separate visitor subscription consent.
* Retention, deletion/export and storage health for entries, private files and saved drafts.
* Sanitised configuration export/import. Entries, credentials, private destinations and live operational state are excluded by default; review local destinations after import.
* Eight core workflow templates: contact, service enquiry, callback request, feedback, simple estimate, job application, document application and volunteer application. Existing starter identifiers remain supported.

No artificial form count, submission count, time trial, forced attribution or marketing signup is imposed. Hosting resources, safety limits and retention still apply. Free does not download or install the separate Pro companion. Pro adds advanced pricing, nested logic, generated PDFs, routing, integrations and staff operations; its code ships separately.

Administrators can open See what Pro adds for local examples of tiered estimates, HubSpot, Slack and webhook connections, and team review. Examples use fictional details and do not change forms or send data. Links in the editor open separately so unsaved work stays in place. The examples also show what is already included in Free.

Local Free features do not expire and do not require a vendor account or commercial activation. Payments, signatures, AI generation, A/B tests, multisite and a full CRM are outside scope. No conversion-lift, inbox, security or universal accessibility guarantee is claimed.

== Pro workflow examples ==

See what Pro adds includes local Free/Pro comparisons, a fixed interactive pricing illustration and a bundled fictional PDF produced by Pro. The bundled PDF embeds DejaVu Sans; its Bitstream Vera/Arev notices are in assets/pro-estimate-sample-LICENSE.txt. The calculator uses example rates only; it does not add premium pricing to your forms. Opening examples sends no data and changes no form. Contextual hints can be hidden or restored for your administrator account on this site; the examples page stays available. This local preference is retained by default and removed by the documented explicit full uninstall.

== Installation ==

1. Back up your WordPress files and database. Try the release on staging.
2. Upload killerconversions-0.11.14.zip through Plugins > Add New and activate Free.
3. If you need Pro, upload matching killerconversions-pro-0.11.14.zip and keep Free active. For a fresh installation, activate Free before Pro.
4. Open KillerConversions > Forms, choose a template and review its questions, prices, consent, retention and destinations.
5. Use Try form, Save draft and Publish form deliberately. Add the KillerConversions block or `[killerconversions id="123"]` with your actual form ID.
6. Submit a controlled example, inspect the saved entry and verify the intended email/provider receipt separately.

WordPress 6.5+ and PHP 7.4+ are required; Pro requires PHP 8.0+. MySQL or MariaDB with InnoDB tables is required for atomic storage. SQLite, including WordPress Playground, is not supported; use a compatible WordPress site. Text validation works without PHP mbstring; itemised estimates require 64-bit PHP integers. Drafts require PHP Sodium; integrations require PHP cURL, a working CA bundle and public IPv4 HTTPS. Background cleanup and mail retries require working WordPress cron. The plugin does not alter your hosting limits or configure SMTP.

== Privacy, storage and external services ==

Local core use makes no publisher telemetry, licence or marketing requests. Assets are bundled locally except the explicitly enabled Turnstile service below. Completed entries, files and provider credentials are private database data, not encrypted at rest by the plugin. Protect database access and backups.

Saved visitor drafts are encrypted using Sodium and WordPress salt-derived keys; changing or losing those salts can make existing drafts unreadable. The plugin reports decryption failure without exposing answers or tokens. Resume tokens are hashed in storage and live in the private link fragment. Anyone holding a valid link can access that draft. Expiry runs from first save; consent/permission choices need a fresh visitor decision. Quota failure preserves an existing saved application. Site backups have their own retention.

Entry retention defaults to 90 days and can be set to 1–3650 days for new entries. Daily cleanup depends on WordPress cron. Saved draft storage is capped at 64 MiB per form and 256 MiB per site; hosting capacity can reduce limits. Completed-entry/file storage has a baseline site budget and a health display. Deleting an entry removes linked files and jobs. Privacy exports/erasure locate entries by submitted email fields; records without one need administrator review. Email/provider copies are outside local erasure.

Optional editor recovery stores a design in that administrator's browser for up to 24 hours, excluding credentials, recipients and nonces. Ten-design history is local. Explicitly remembered workflow links are local per-administrator references with seven-day expiry. These actions make no external request.

New entries retain original field definitions. Same-page browser retries use a random attempt ID held in memory; the database retains its hash and committed entry reference until erasure/expiry. This does not cover a fresh page load, legacy clients or the no-JavaScript fallback. Abuse protection uses short-lived salted rate hashes, not stored raw IPs. Submitted-entry counts require no visitor tracking.

= Transactional email =

When configured, the queue passes the selected staff notification or separately requested visitor confirmation to WordPress wp_mail() and your site's mail provider. A submitted email can become validated Reply-To; it does not replace From. Estimates include their saved breakdown. Confirmation consent, marketing subscription and saved-link purposes remain separate. The plugin provides no SMTP service, bounce tracking or receipt guarantee. Disable a destination to stop future jobs; delivered copies need separate removal.

= Brevo (optional) =

An administrator explicitly enables and acknowledges this connection. With a separately checked optional visitor marketing-consent question, the plugin sends the mapped email, optional FIRSTNAME/LASTNAME and selected list ID to https://api.brevo.com/v3/contacts to create/update a subscriber contact. It does not send unrelated answers or files, force unsubscribe flags, perform double opt-in or send a campaign. Your Brevo list automations may run. Disable the connection to stop future requests; remove its saved credential to forget it locally. Provider copies require separate removal. Terms: https://www.brevo.com/legal/termsofuse/ ; privacy: https://www.brevo.com/legal/privacypolicy/ .

= MailerLite (optional) =

After administrator enablement/acknowledgement and separate optional visitor subscription consent, the plugin sends mapped email, optional name and selected group ID to https://connect.mailerlite.com/api/subscribers to create/update a subscriber. It does not send files or unrelated answers, request forced resubscription, or send a campaign. Group automations may run under your provider settings. Disable and remove credentials to stop future local requests; provider data needs separate removal. Terms: https://www.mailerlite.com/legal/terms-of-service ; privacy: https://www.mailerlite.com/legal/privacy-policy .

Changing a destination, mapping or consent meaning cancels old pending work instead of reinterpreting it. Reviewed resend preserves recorded consent. Copied-site protection pauses outgoing work after a recorded address/environment change; identical-identity copies and pre-baseline copies need operator review.

= Cloudflare Turnstile (optional) =

Turnstile defaults off and needs widget keys plus service acknowledgement. Enabled forms load https://challenges.cloudflare.com/turnstile/v0/api.js; Cloudflare processes browser/network signals. The server sends only the configured secret and challenge token to https://challenges.cloudflare.com/turnstile/v0/siteverify. Form answers are not included. Protected forms require JavaScript; editor preview never loads it. Disable protection to stop requests and remove the saved secret to forget it. Privacy: https://www.cloudflare.com/turnstile-privacy-policy/ ; terms: https://www.cloudflare.com/website-terms/ .

== Frequently Asked Questions ==

= Are my entries lost if email fails? =

No. A committed entry stays saved when transport or post-save extensions fail. Queue-storage failure rejects the submission before commit so the visitor can retry.

= What happens when Pro is deactivated? =

Basic workflows continue with Free alone. Premium-dependent forms and jobs retain their data and pause with an explanation; they do not calculate a different price or silently choose a fallback recipient. Existing scoped staff restrictions remain enforced. Finish both updates before editing during a mixed-version upgrade.

= Does it work without JavaScript? =

Published forms have a standard server submission fallback. All relevant server validation still applies; enhanced multi-step navigation, save/resume, live estimates and the visual editor require JavaScript. Without it, fields remain readable together. Turnstile-protected forms require JavaScript.

= Where can I get help? =

Use https://killerconversions.com/docs/ and the public support form at https://killerconversions.com/help/ . Public support has no guaranteed response time. No subscription or sister-plugin installation is required for local features.

= How do I recover an upgrade? =

Keep a pre-upgrade database/files backup. Reinstalling an old ZIP does not reverse migrations. Do not overwrite newer submissions with an old database. Follow the matched update and recovery guide and test restoration on a separate copy.

== Data on uninstall ==

Deactivation and normal uninstall preserve forms and entries. Deliberate permanent removal requires `define( 'KCONV_DELETE_DATA_ON_UNINSTALL', true );` in wp-config.php before uninstalling Free. Back up needed data first. This removes plugin-owned data for the current site; it does not retract email/provider copies or release a remote licence seat. Multisite network removal is unsupported.

== Changelog ==

= 0.11.14 =
* Use the WordPress HTTP API for integration delivery while retaining bounded, pinned HTTPS requests.
* Make request-handler nonce and permission checks explicit and preserve public form submission.
* Restrict delivery history to entries within the current operator's access and retention period.


= 0.11.13 =
* Restrict form records to administrators across WordPress APIs while retaining published-form embedding for editors.
* Validate text and display Inbox initials when PHP mbstring is unavailable.
* Clarify public release, hosting and optional Pro PDF requirements.


= 0.11.12 =
* Keep unused estimate settings behind Add pricing; reveal active prices and pending pricing removals for review.
* Keep the editor’s Quick actions keyboard shortcut from also opening WordPress’s command menu.
* Preserve pricing controls, draft edits and keyboard focus through disclosure, restore and guided setup actions.
* Refresh the bundled fictional PDF with readable pricing labels from the matching Pro renderer.


= 0.11.11 =
* Consistent Edit form, Try form, Save draft and Publish controls; practice runs do not create entries or send notifications.
* After publishing, optional guidance explains embedding on a page, making a real test submission and checking Inbox.
* Clearer Pro workflow examples name HubSpot, Slack and webhooks and show plan availability.
* Updated fictional PDF example generated by the matching Pro renderer.


= 0.11.10 =
* Use a unique five-letter prefix for plugin declarations, stored data and registered identifiers.
* Sanitize nonce values after validating their type and preserve structured form input.
* Restrict plugin assets and operational notices to relevant administration screens.
* Correct the saved-application duration wording.
* Preserve shared Free storage during Pro removal and complete explicit Free review-data cleanup.


= 0.11.9 =
* Mobile editor brings the form forward with compact, accessible tools.
* Inbox entries become labelled cards on phones while desktop keeps its table.
* Workflow examples show the real sample output earlier with more concise copy.


= 0.11.8 =
* Prevent a PHP deprecation when a single-page list has no pagination links.
* Compact Forms and Inbox layouts bring forms and entries into view sooner.
* Clearer working text and sidebar branding improve navigation.
* Visual workflow examples show the sample PDF, CRM handoff and team review alongside edition comparisons.


= 0.11.7 =
* Clearer workflow comparisons, local pricing examples and a real sample estimate PDF.
* Context-aware Pro setup, private sample PDF previews and per-admin suggestion preferences.
* Keep Free functionality, saved work and the signed Pro updater.


= 0.11.6 =
* Add a local Pro comparison with illustrative tiered estimates, CRM handoffs and team review examples.
* Link relevant Free tools to examples while preserving unsaved work and all Free features.

= 0.11.5 =
* Use the Plugins.shop publisher website for the author link and the KillerConversions website for the plugin link.

= 0.11.4 =
* Explain the MySQL/MariaDB requirement clearly on SQLite and pause plugin features before database setup.
* Show accurate setup guidance without an unrelated site-address warning or delivery authorization prompt.
* Preserve existing data and the delivery review required after a genuine site-address change.


= 0.11.3 =
* Hardened request handling and clarified prepared database identifiers.
* Added translator context and refreshed packaged documentation.


= 0.11.2 =
* Keep new unsaved Pro forms on validated default settings without a false stored-settings warning. Existing malformed saved settings still fail closed.
* Matched Free and Pro evaluation pair; local feature and commercial boundaries unchanged.

= 0.11.1 =
* Matched Free/Pro packaging; installed Free functionality remains independent of entitlement.
* Matched packaging and current service disclosures; checkout remains closed pending qualification.


= 0.11.0 =
* Add bounded repeatable groups of ordinary fields for staging evaluation.
* Preserve the existing enquiry, estimate and saved-application workflows.


= 0.10.0 =
* Move private uploads, visitor save/resume, queued mail, basic subscriber actions and clean portability into Free with verified ownership migration.
* Add simple itemised estimates, multi-step forms, eight core workflow templates and storage health.
* Preserve old drafts, file references, settings and delivery provenance; guard mixed-version updates and premium-dependent configurations.
* Extend copied-site delivery protection to Free and retain historical estimate results with submissions.

= 0.9.0 =
* Save draft changes separately from a live form; publish explicitly. Conflicting editors and incomplete saves preserve the previous complete configuration.
* Keep the last 10 saved designs and restore a design into the editor for review. Delivery, credentials and privacy settings are excluded from restoration.
* Recognize retries of the same browser attempt, contain post-save extension/mail failures, and reject changed-form submissions from new browser pages.
* Preserve submitted field labels, prepare complete bounded CSV files before downloading, show site-local or UTC times, and inspect retention cleanup health.
* Configure text lengths, number/date/time limits and autofill hints; use linked submission errors and initialize fresh dynamically inserted form markup.
* Matched Pro 0.9.0 required when Pro is installed. Existing settings, entries and visitor drafts are retained.

= 0.8.0 =
* Matched compatibility for the Pro guided workflows, email, integration and upload improvements.
* Bounded privacy exports preserve access to larger private files and saved applications with Pro inactive.
* Six Free templates remain included; eight complete Pro starters belong to the separate add-on.


= 0.7.2 =

* Contextual Pro workflow explanations with useful Free alternatives, persistent local dismissal and administrator-scoped task continuation.
* Explicit save-before-leaving guidance and basic published-form checklist; no automatic upgrade, publishing or telemetry.
* Separate compound-condition runtime ownership in Pro; protect incomplete matched-pair updates.
* Existing Free entry access, exports, assignment, basic conditions and privacy controls stay available.

= 0.7.1 =

* More spacious mobile form controls and faithful calculated-summary preview with Pro.
* Preserve explicit consent field definitions and safely prepare compatible visitor draft edits.
* Privacy export and erasure cover encrypted draft attachments even when Pro is inactive.
* Correct the spam FAQ to describe optional Turnstile.

= 0.7.0 =

* Basic per-field conditional logic, live published preview, whole-editor history and recovery.
* Optional per-form Cloudflare Turnstile with guarded settings and authoritative server verification.
* Shared support for Pro calculated estimates and encrypted visitor drafts; draft expiry and privacy tools remain available with Pro inactive.

= 0.6.0 =

* Shared whole-editor support for applying and undoing Pro reusable designs while retaining operational settings.
* Direct access to Pro starters when the separate add-on is active.
* Matched release supporting the Pro setup review and more compact workspace.

= 0.5.0 =

* Mobile field properties drawer with Done, Save, keyboard focus handling and direct access to invalid settings.
* Clearer workspace text and navigation across forms, entries, delivery and insights.
* More branding controls: typography, width, corners, custom accent color, public heading and introduction, plus responsive half-width fields.
* Isolated Preview uses the published form renderer with unsaved changes and a 360px mobile view; entered test answers remain unsent.

= 0.4.0 =

* Focused workspace with Design/Test modes, selectable canvas, drag ordering, field search, quick actions, keyboard save, and separate logic/delivery/style/settings views.
* Classic, Studio and Minimal form styles, three accent colors, and comfortable/compact spacing, with live previews and preserved original defaults.
* Redesigned form library and lead inbox with real counts, quick views, selection controls and protected lead actions.


= 0.3.0 =
* Whole-editor undo, optional local draft recovery and searchable block selector.
* Date/time, checkbox groups and server-defined hidden values.
* Searchable entry inbox, workflow/bulk actions, wide CSV and delegated Lead manager role.
* Whole-form draft duplication and paginated form management.

= 0.2.0 =
* Compact editor, six templates, interactive desktop/mobile preview, duplication, keyboard reorder and undo/redo.
* Pro settings validate against unsaved fields before any form changes are written.
* InnoDB transaction keeps accepted entries, privacy indexes and optional Pro delivery jobs together.
* Entry deletion removes related Pro data even when the add-on is inactive.

= 0.1.0 =
* Initial beta with visual field editing, published form rendering, local entries, CSV, notifications, abuse controls, retention and privacy tools.


== Developer notes ==

All executable source ships in readable form. No compilation is needed. The optional remote services are disclosed above. No WordPress.org submission or endorsement is implied by preparing this package.
