=== WPPowerSuite Lite ===
Contributors: wppowersuite
Tags: admin, security, performance, modules, toolkit
Requires at least: 6.8
Tested up to: 7.1
Requires PHP: 8.1
Stable tag: 1.0.9
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

A modular WordPress toolkit. Enable only the modules you need. Disabled modules do not load.

== Description ==

WPPowerSuite Lite is a modular admin toolkit. Turn on the tools you want from one Control Center. Modules you leave off do not run, so unused features do not add front-end cost.

This is the **free** plugin from [wordpress.org](https://wordpress.org/plugins/wppowersuite-lite/). It includes the core suite and the free modules.

Premium modules ship in a separate add-on, **WPPowerSuite Pro**, sold from [wppowersuite.com](https://wppowersuite.com/). Install Pro beside this plugin. Do not replace or delete the free plugin.

= What you get in the free plugin =

* A module hub to enable, disable, favorite, and search tools
* Free modules for admin cleanup, login hardening, media, SEO helpers, and site tools
* Import/export of your enabled-module configuration

= WPPowerSuite Pro (separate plugin) =

Pro is not included in this zip. After you install the add-on from wppowersuite.com:

* Premium modules appear in the same hub
* Agency White Label branding (your name, logo, and client-ready plugin rows)
* Header & Footer Code, Custom Admin CSS, and Code Snippet for site-specific markup and scripts
* License activation and commercial updates apply to the Pro plugin only
* This free plugin keeps updating from wordpress.org

= Privacy =

The free plugin does not phone home for licensing. See **External services** for what optional modules can send, when, and each provider's Terms and Privacy Policy.

== External services ==

This plugin contacts third-party services only when you enable the related module and enter your own credentials (API keys, OAuth client IDs, or SMTP details). Disabled modules do not reach those services. Alpine.js is bundled in the plugin and is not loaded from a CDN.

= Email Delivery =

Email Delivery sends WordPress mail through the connection you configure (PHP mail, SMTP, or an ESP HTTP API). It is used so site mail (form notices, password resets, and your test emails) can leave through your provider instead of the default server mailer.

When WordPress sends mail, or when you click Test connection / Test email, the plugin sends the message subject, body, sender, recipients, reply-to, attachments, and your API key, SMTP password, or OAuth token to the host you chose. No mail is sent until you save a connection and WordPress (or a test) actually sends.

* Other SMTP host you enter: the email content goes to that host. Use that host's own Terms and Privacy Policy.
* Amazon SES: [Terms](https://aws.amazon.com/service-terms/) and [Privacy](https://aws.amazon.com/privacy/).
* SendGrid (Twilio): [Terms](https://www.twilio.com/en-us/legal/tos) and [Privacy](https://www.twilio.com/en-us/legal/privacy).
* Mailgun: [Terms](https://www.mailgun.com/legal/terms/) and [Privacy](https://www.mailgun.com/legal/privacy-policy/).
* Brevo: [Terms](https://www.brevo.com/legal/termsofuse/) and [Privacy](https://www.brevo.com/legal/privacypolicy/).
* Google Gmail API: [Terms](https://policies.google.com/terms) and [Privacy](https://policies.google.com/privacy).
* Microsoft Graph: [Terms](https://www.microsoft.com/servicesagreement) and [Privacy](https://privacy.microsoft.com/privacystatement).
* Postmark: [Terms](https://postmarkapp.com/terms-of-service) and [Privacy](https://postmarkapp.com/privacy-policy).
* Mailjet: [Terms](https://www.mailjet.com/legal/terms-conditions/) and [Privacy](https://www.mailjet.com/legal/privacy-policy/).
* MailerSend: [Terms](https://www.mailersend.com/legal/terms-of-service) and [Privacy](https://www.mailersend.com/legal/privacy-policy).
* SMTP2GO: [Terms](https://www.smtp2go.com/terms/) and [Privacy](https://www.smtp2go.com/privacy/).
* Resend: [Terms](https://resend.com/legal/terms-of-service) and [Privacy](https://resend.com/legal/privacy-policy).
* Mandrill (Mailchimp): [Terms](https://mailchimp.com/legal/terms/) and [Privacy](https://www.intuit.com/privacy/statement/).
* SparkPost (Bird): [Terms](https://bird.com/en-us/legal/terms-previous-sparkpost) and [Privacy](https://bird.com/en-us/legal/sparkpost-privacy-policy-v1).
* Elastic Email: [Terms](https://elasticemail.com/resources/usage-policies/terms-of-use) and [Privacy](https://elasticemail.com/resources/usage-policies/privacy-policy).
* SendLayer: [Terms](https://sendlayer.com/terms-of-service/) and [Privacy](https://sendlayer.com/privacy-policy/).
* SMTP.com: [Terms](https://www.smtp.com/policies/terms-and-conditions/) and [Privacy](https://www.smtp.com/policies/privacy-policy/).
* Netcore (formerly Pepipost): [Terms](https://netcorecloud.com/email-api-terms-and-policies/) and [Privacy](https://netcorecloud.com/privacy-policy/).
* turboSMTP: [Terms](https://serversmtp.com/terms-and-conditions/) and [Privacy](https://serversmtp.com/regulation-eu-2016-679-gdpr/).
* Maileroo: [Terms](https://maileroo.com/terms-conditions) and [Privacy](https://maileroo.com/privacy-policy).
* Emailit: [Terms](https://emailit.com/terms-of-service/) and [Privacy](https://emailit.com/privacy-policy/).
* Mail.baby (InterServer): [Terms](https://www.interserver.net/terms-of-service.html) and [Privacy](https://www.interserver.net/privacy-policy.html).

= Google Sign-In =

Google Sign-In lets visitors sign in with a Google account when you enable the module and add your own OAuth Client ID and Client Secret.

When a visitor clicks Sign in with Google, the browser is sent to Google's authorization page. After they approve, this site posts the authorization code, client ID, and client secret to Google's token endpoint, then requests the OpenID profile (email and display name) from Google userinfo. That happens only on that sign-in (or account-link) click, not on every page load.

This service is provided by Google: [Terms](https://policies.google.com/terms) and [Privacy](https://policies.google.com/privacy).

= Google Analytics 4 =

Analytics Integration loads Google's gtag library so you can record pageviews when you enable the module and enter a GA4 Measurement ID.

On each front-end page view (unless you exclude that visitor), the visitor's browser requests `https://www.googletagmanager.com/gtag/js` and sends the Measurement ID, page URL, and standard GA4 event data to Google.

This service is provided by Google: [Terms](https://policies.google.com/terms) and [Privacy](https://policies.google.com/privacy).

= Google reCAPTCHA =

The admin script can load Google reCAPTCHA when a reCAPTCHA module is enabled and you click Test connection. Front-end forms that use reCAPTCHA send a token from the visitor's browser to Google. The site then posts that token and your secret key to Google siteverify to check the result.

This service is provided by Google: [Terms](https://policies.google.com/terms) and [Privacy](https://policies.google.com/privacy).

= Cloudflare Turnstile =

The admin script can load Cloudflare Turnstile when a Turnstile module is enabled and you click Test connection. Front-end forms that use Turnstile send a token from the visitor's browser to Cloudflare. The site then posts that token and your secret key to Cloudflare siteverify.

This service is provided by Cloudflare: [Terms](https://www.cloudflare.com/website-terms/) and [Privacy](https://www.cloudflare.com/privacypolicy/).

== Installation ==

1. Install WPPowerSuite Lite from Plugins → Add New, or upload this zip.
2. Activate the plugin.
3. Open **WPPowerSuite** in the admin menu and enable the modules you need.

To add premium modules, buy WPPowerSuite Pro from wppowersuite.com and install it as a second plugin. Keep this free plugin active.

== Frequently Asked Questions ==

= Do I delete this plugin if I buy Pro? =

No. Keep WPPowerSuite Lite installed. WPPowerSuite Pro is an add-on that requires this plugin.

= Why do I see Pro modules I cannot enable? =

Those cards are a catalog. The PHP for those modules is not in the free zip. Install WPPowerSuite Pro to add them.

= Is White Label included in the free plugin? =

No. The free plugin shows what White Label can do. The branding form and apply logic are in WPPowerSuite Pro. Get the add-on from wppowersuite.com and keep this free plugin installed.

= Can I add custom CSS, JavaScript, or PHP in the free plugin? =

No. Header & Footer Code, Custom Admin CSS, Code Snippet, and Alpine initialization scripts are part of WPPowerSuite Pro. Alpine.js Enqueue in the free plugin only loads the bundled Alpine.js file. It does not offer a JavaScript textarea and does not save or run pasted CSS, JavaScript, or PHP. Install the Pro add-on from wppowersuite.com to add those tools.

= Will wordpress.org updates overwrite Pro? =

No. wordpress.org updates this free plugin only. Pro updates from wppowersuite.com.

= What happens to my settings if I install Pro later? =

Enabled free modules and their settings stay. Pro modules appear in the same hub after you activate the add-on and your license.

== Changelog ==

= 1.0.9 =
* Plugin name is WPPowerSuite Lite. The wordpress.org slug and text domain are wppowersuite-lite.
* Safer Temporary Login when using Login as User, plus tighter 2FA and wp-config checks.
* Media Rename updates real attachment URL pairs instead of rewriting by basename.
* AI Form Builder can combine field and design edits, preview before apply, and use OpenRouter free models.
* Alpine.js is bundled only. Plugin Check offloading warnings for service hosts are cleared.
* wordpress.org Guideline 5: the free zip ships only fully working modules. Pro tools stay in the separate add-on.
* White Label in the free plugin is a catalog for WP PowerSuite Pro, not a license-locked toggle.
* Header & Footer Code, Custom Admin CSS, and Code Snippet stay in WP PowerSuite Pro so the free zip has no arbitrary CSS/JS/PHP editors.
* Alpine.js Enqueue in the free zip only loads bundled Alpine.js. Pasted initialization scripts stay in WP PowerSuite Pro.
* Lite translation catalog drops leftover license-lock strings from Pro modules.
* readme External services section names each optional provider, what is sent, when, and Terms/Privacy links.

= 1.0.8 =
* Safer Temporary Login vendor access. Vendor sessions cannot manage invites or the license.
* Tighter admin checks across 2FA, CAPTCHA, Coming Soon, Custom Fields, and related tools.
* Pro modules stay locked in the hub until WP PowerSuite Pro is installed.
* Activity Log and other Pro screens load correctly.

= 1.0.7 =
* WP-CLI commands, Change Login URL and Code Snippet hardening, license update version fix.

== Upgrade Notice ==

= 1.0.9 =
Safer Temporary Login with Login as User, more reliable Media Rename, and a clearer AI Form Builder.

= 1.0.8 =
Safer Temporary Login, related admin checks, and Pro screen load fixes.
