=== Freexya – Site Administration Modules ===
Contributors: nexyadev, freemius
Tags: admin, security, seo, redirects, cookies
Requires at least: 6.2
Tested up to: 7.1
Requires PHP: 8.2
Stable tag: 1.2.18
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

WordPress modules, one panel. Switch a module on, switch a module off — and nothing of it runs on the site while it is off.

== Description ==

nexya.dev gathers the everyday jobs under a single admin panel. Each one is a module you turn on or off from the hub, and a module that is off registers nothing: none of its hooks run on the site.

* **Dashboard** — a readable admin home and a tidied toolbar.
* **Shortcuts** — duplicate content, reorder it by hand, add entries in one click.
* **Roles & capabilities** — capabilities sorted under the post type that creates them, and the site seen through a role's eyes without leaving your own account.
* **Activity log** — who changed what, with the before and the after.
* **Cookies** — a consent banner, third-party scripts held back until consent, and a scan that finds them.
* **SEO** — titles and descriptions with a suggestion drawn from the page's text, sitemap, schema, llms.txt.
* **Mail** — SMTP or an API provider, a delivery log, a test message, an invisible captcha for the site's forms.
* **Redirects** — exact redirects and a 404 log with the hit count.
* **Media** — regenerate thumbnails in the background, in batches.
* **Security** — security headers, a content policy, and a check of the installed plugins against known vulnerabilities.
* **Maintenance** — a holding page, database clean-up, a database export.
* **Custom fields** — field groups with repeaters, flexible content and relations, kept in their own tables.
* **Element** — sixteen Elementor widgets for custom fields, NCF’s or ACF’s: repeaters as cards, tabs or tables, galleries and sliders, key figures, teams, timelines, taxonomies, maps.
* **Translate** — your site in several languages: each page linked to its translations, a translation editor beside the original (blocks, Elementor, ACF and NCF fields), addresses in /en/, a menu per language, a language switcher, hreflang, and every text of the site translated from the admin. A site coming from WPML or Polylang moves over in one click.

= Free and Pro =

Everything above is free, on as many sites as you like. nexya Pro, sold on nexya.dev, adds two modules — Mailya for newsletters and a page cache — and the parts that do the repetitive work for you: suggested redirects and pattern rules, CSV import, a daily vulnerability pass and a file fingerprint with rollback, undo from the activity log, a second sending server and failure alerts for mail, a branded login screen and admin skin, banner appearance and consent service by service, scheduled database clean-up, orphan image sizes, folders in the media library, and longer log retention. The free version contains none of that code; nexya Pro is delivered by Freemius after purchase, and takes over from this plugin with the same settings.

= Privacy =

The plugin sends nothing to a third party by default. The features that reach the network, and what they send, are listed under External services below.

= Multisite =

Multisite networks are not supported. On a network the plugin stays switched off and says so.

== Installation ==

1. Upload the folder to `wp-content/plugins/`, or install the zip from the Plugins screen.
2. Activate it.
3. Open **nexya** in the admin menu and switch on the modules you want.

== Frequently Asked Questions ==

= Does a module I turned off still cost anything? =

Almost nothing. The registry declares them all, but only boots the modules that are on: the others register no hooks, load no assets and run no queries.

= Where are SMTP passwords stored? =

Encrypted with AES-256-GCM in a single option, under a key derived from your WordPress salts. If you rotate those salts the stored secrets can no longer be read, and the panel tells you to enter them again.

= And the licence? =

The licence is handled by Freemius: the key, its activation and the checkout live in the Freemius screens under the nexya menu. The plugin stores nothing about it.

= What happens when I uninstall? =

You choose, when you deactivate the plugin (or in Settings › If the plugin is deleted):

* Keep my settings — its scheduled tasks are cleared and the server rules it wrote are taken out; everything else stays, for a reinstall or a move to nexya Pro.
* Erase everything — roles go back to the capabilities they had before the plugin touched them, the plugin's tables and options are dropped, its scheduled tasks are cleared and the private folder is removed. A copy of the settings only (no logs, no page data) stays for 30 days as a WordPress transient, which WordPress deletes on its own once it expires; if the plugin comes back within that time, it offers to import it.

= How do I move to nexya Pro without losing my settings? =

Install and activate nexya Pro while this plugin is still in place: both read the same settings, and Pro switches this version off. Then delete this version.

== External services ==

Nothing below runs unless you switch the matching module or option on. No data leaves the site by default, and the plugin sends no usage data anywhere.

**WPVulnerability (Security module, vulnerability watch).** When you start a check from the Security screen, the plugin asks the public WPVulnerability API whether the installed plugins have known vulnerabilities. For each installed plugin, its slug is sent to www.wpvulnerability.net; nothing else about the site is sent. Nothing is sent until you start a check. Terms and privacy (legal notice of its publisher): https://www.robotstxt.es/legal/

**Patchstack (Security module, optional).** Only if you enter your own Patchstack API key, the same check also asks api.patchstack.com, sending each installed plugin's slug and your key. Terms: https://patchstack.com/terms-and-conditions/ — Privacy: https://patchstack.com/privacy-policy/

**E-mail delivery (E-mails module).** When you pick an API provider instead of SMTP, the messages your site sends are handed to that provider's API: sender, recipients, subject, body and attachments, at the moment the message is sent. You choose the provider and enter its API key. The providers offered are Brevo (https://www.brevo.com/legal/termsofuse/ — https://www.brevo.com/legal/privacypolicy/), SendGrid (https://www.twilio.com/en-us/legal/tos — https://www.twilio.com/en-us/legal/privacy), Postmark (https://postmarkapp.com/terms-of-service — https://postmarkapp.com/privacy-policy), Resend (https://resend.com/legal/terms-of-service — https://resend.com/legal/privacy-policy), SMTP2GO (https://www.smtp2go.com/terms/ — https://www.smtp2go.com/privacy/), MailerSend (https://www.mailersend.com/legal/terms-of-service — https://www.mailersend.com/legal/privacy-policy), SendLayer (https://sendlayer.com/terms-of-service/ — https://sendlayer.com/privacy-policy/), Mandrill (https://mailchimp.com/legal/terms/ — https://mailchimp.com/legal/privacy/), Mailgun (https://www.mailgun.com/legal/terms/ — https://www.mailgun.com/legal/privacy-policy/), Elastic Email (https://elasticemail.com/resources/usage-policies/terms-of-use — https://elasticemail.com/resources/usage-policies/privacy-policy) and SparkPost (https://www.sparkpost.com/policies/tou/ — https://www.sparkpost.com/policies/privacy/).

**Audience measurement tags (SEO module).** If, and only if, you enter an ID or an address for one of them, the module prints that service's tag on the front end; the visitor's browser then loads the script from the service and sends it what that tag collects.
* Google Tag Manager and Google Analytics 4, from www.googletagmanager.com. Terms: https://marketingplatform.google.com/about/analytics/terms/us/ — Privacy: https://policies.google.com/privacy
* Plausible, from plausible.io or the address you enter. Terms: https://plausible.io/terms — Privacy: https://plausible.io/privacy
* Umami, from the address of your own Umami instance or Umami Cloud. Terms: https://umami.is/terms — Privacy: https://umami.is/privacy
* Matomo, from the address of your own Matomo instance or Matomo Cloud. Terms: https://matomo.org/matomo-cloud-terms-of-service/ — Privacy: https://matomo.org/privacy-policy/

**Freemius (trial and purchase of nexya Pro).** The Freemius SDK ships with the plugin in anonymous mode: on its own it sends nothing and shows no opt-in. Only when an administrator starts the Pro trial or buys nexya Pro from the plugin's screens are the site address, the WordPress, PHP and plugin versions and the administrator's name and e-mail address sent to Freemius, which handles the checkout and the licence. Terms: https://freemius.com/terms/ — Privacy: https://freemius.com/privacy/

**Lists of known hosts (Cookies and Security modules).** These are not remote files and nothing is loaded from them. The cookie module carries a list of third-party hostnames (Google Fonts, Font Awesome, public CDNs, YouTube, Google Maps and so on) as plain data: a script or frame already on your page whose address matches one of them is held back until the visitor consents. The Security module carries a similar list of well-known origins, offered as ready-made lines when you write your site's content security policy, the header that tells browsers which origins your pages may load from. Both lists are plain data files, modules/Cookie/data/hosts.json and modules/Security/data/origins.json. The plugin itself never contacts any of these hosts.

**Requests to your own site.** The cookie scan, the sharing-image finder of the SEO module and a few background jobs fetch pages of your own site from your own server. Nothing leaves it.

== Changelog ==

= 1.2.18 =
* Security: the field group editor only opens a group from the plugin’s own links, and the forms of Custom fields and Popup are cleaned value by value as they are read.

= 1.2.17 =
* Aris: a “Referring sites” list shows the sites that send you visitors, by domain — referral spam and visits that leave at once left out.

= 1.2.16 =
* nexya Pro: the licence screen shown after installing Pro is in the panel’s colours and speaks of nexya Pro, with a reminder that the settings are already there.

= 1.2.15 =
* Hub: “Discover nexya Pro” and “Choose a plan” lead straight to the pricing page.

= 1.2.14 =
* Popup is no longer in beta.
* Popup (Pro): while the shop is closed, the checkout buttons are hidden, no payment method is offered and the checkout page leads back to the cart; paying an existing order still works.
* Translate, Popup and Custom fields: every submitted text and every list built in the editor is cleaned as soon as it is read.

= 1.2.13 =
* Mailya (Pro): the AI writes a newsletter from the posts published since the last sending — titles, marketing paragraphs, posts, images and a button, in Mailya’s own sections — added under what the message already holds, without touching it.
* Media (Pro): a folder shows the folders it holds after its own files, as tiles the size of the images, each with its count of files — no more “No media found” on a folder that only holds folders.
* Mailya (Pro) and Cache (Pro) are no longer in beta.
* Mailya (Pro): the campaign name, subject and preview text line up at the top of the editor, at the same height.

= 1.2.12 =
* Translate: a translation editor — the original beside its translation, row by row: title, blocks, Elementor widgets, ACF and NCF fields (repeaters and flexible content included) and SEO texts. Free by hand; with nexya Pro, one row or the whole page translated by AI, and every text of the Texts tab too.
* nexya element: a language switcher widget — side by side or in a menu, code, name or flag — and, with nexya Pro, a newsletter widget showing Mailya’s form in the page or in a window that opens on its own, with its text above or beside the form and an image.
* Deactivating the plugin asks what becomes of the settings if it is deleted: kept for a reinstall or a move to nexya Pro, or erased with a copy kept for 30 days that the plugin offers to import when it comes back. nexya Pro activated next to the free version takes over its settings and switches it off.
* Mailya (Pro): a message has its phone version — sizes, widths, alignment and spacing of its own, set in the phone preview; left alone, a phone gets every block at full width and slightly smaller type. The phone preview shows where the screen ends.
* Mailya (Pro): a newsletter’s posts take their text from a text area or an editor field of the post type, as they already could their image.
* Media (Pro): folders can be renamed, a “Select all” sits beside “Bulk select” in every view of the library, and a folder with sub-folders shows the count of all their files.
* Hub: switching a module on or off saves at once.
* Media (Pro): a file dragged into a folder no longer takes along files picked earlier: once moved, the bulk selection ends.
* Translate: the “From WPML” and “From Polylang” tabs only show while that plugin is installed.
* Mailya (Pro): a sign-up whose address’s domain cannot receive e-mail is refused.
* Mailya (Pro): the sign-up form goes through the captcha of the E-mails module, and an address gets one confirmation e-mail an hour at most.
* Security: the last answer of the vulnerability sources and its warning line up with the field above them.

= 1.2.11 =
* Translate (beta), a new module: your site in several languages — each page linked to its translations, addresses in /en/, a menu per language, a language switcher (menu link or [nexya_lang_switcher] shortcode), hreflang, and the site title, terms, menus, forms and theme strings translated from the admin. Everything translated by hand is free.
* Translate: a site coming from WPML or Polylang moves over in one click — languages, versions of the contents, terms, menus and translated texts are taken over, the addresses stay the same, and nothing is deleted before the clean-up. A Help tab explains the move and every way to add a switcher.
* SEO: on a site in several languages, each language’s home page now gives its own address as canonical, no longer the default language’s.
* Aris: the Heatmap tab keeps its name in every language.

= 1.2.10 =
* Custom fields: an options page opened to editors can now be saved by them; it only takes the fields placed on it.
