=== 6Arshid Social Community ===
Contributors: 6arshid, hassantafreshi, aminkhadivar
Tags: social network, wordpress social network, buddypress, community, messaging
Requires at least: 6.5
Tested up to: 7.1
Stable tag: 1.8.3
Requires PHP: 8.1
License: MIT
License URI: https://opensource.org/licenses/MIT

Build a fast, secure WordPress social network with member profiles, activity feeds, groups, messaging, notifications, polls, moderation, and more.

== Description ==

6Arshid Social Community is a complete **WordPress social network plugin** for building member communities, private networks, creator communities, discussion spaces, and social platforms directly inside WordPress.

It provides member profiles, activity feeds, groups, friends and followers, private messaging, notifications, polls, hashtags, bookmarks, moderation, social embeds, creator monetization, REST API support, and more — without requiring BuddyPress.

If you are looking for a **WordPress social network**, a flexible **WP social network** solution, or a standalone alternative to a traditional BuddyPress-based setup, 6Arshid Social Community gives you the core community features in one modular plugin.

= Build a Social Network with WordPress =

Turn WordPress into a modern social community where members can create profiles, publish activity posts, follow people, become friends, join groups, send private messages, react to content, vote in polls, save posts, and receive notifications.

The plugin is designed for:

* Private or public online communities
* Membership websites
* Creator and fan communities
* Company or organization networks
* Niche social networks
* Discussion and interest-based communities
* Local communities
* Educational and professional networks

Each major feature can be enabled or disabled independently, so you can build a lightweight community or a more complete social network experience.

= Member Profiles =

Members can create rich profiles with avatars, cover photos, extended profile fields, social links, privacy controls, profile completion indicators, and verification badges.

Profile features include:

* Custom profile fields and field groups
* Public, friends-only, and private field visibility
* Avatar and cover image uploads
* Profile completion progress
* Verified member badges
* User settings and privacy preferences
* GDPR export and erasure integration

= Activity Feed =

The activity stream is the center of the community. Members can publish posts, images, GIFs, polls, links, mentions, hashtags, and attachments.

Activity features include:

* Public, friends-only, and private posts
* Image, GIF, emoji, and link support
* Comments and threaded replies
* Reactions and comment reactions
* @mentions and member autocomplete
* Hashtags and hashtag archives
* Sticky posts
* Bookmarks and collections
* Post sharing
* Reporting and moderation
* Infinite scroll or standard pagination

Members can also edit or delete their own posts and interact with content through reactions, comments, shares, and saved collections.

= Groups =

Create public, private, or hidden groups with their own members, activity feeds, avatars, cover photos, invitations, and moderation roles.

Group features include:

* Admin, moderator, and member roles
* Join requests and invitations
* Group activity feeds
* Member directories
* Parent and child groups
* Group search
* Public, private, and hidden visibility

= Friends, Followers, and Blocking =

6Arshid Social Community supports both mutual friendships and one-way following.

Members can:

* Send, accept, reject, and remove friend requests
* Follow or unfollow other members
* Receive follower notifications
* Block and unblock users
* Discover suggested friends based on mutual connections

= Private Messaging =

Members can communicate through one-to-one or group conversations without leaving the WordPress site.

Messaging includes:

* Private conversation threads
* Group conversations
* Image and document attachments
* Read receipts
* Unread message counters
* WordPress Heartbeat-powered updates
* Message deletion
* Spam and abuse reporting

= Notifications =

The built-in notification center keeps members informed about community activity.

Notifications can be generated for:

* Friend requests
* Accepted friendships
* Reactions
* Comments
* Mentions
* Private messages
* Group invitations
* New followers

Users can control notification preferences, while email digest support can send daily or weekly summaries.

= Polls, Hashtags, and Engagement =

Create interactive polls directly from the activity composer. Polls support multiple options, expiration dates, live result distribution, quiz mode, reusable templates, and participation history.

Hashtags are automatically detected and linked. Members can browse hashtag archive pages, follow hashtags, use autocomplete, and discover trending topics.

The plugin also includes photo tagging, friend tagging, post sharing, sticky posts, saved bookmarks, and bookmark collections.

= Moderation and Community Safety =

Community administrators can manage reports, suspended users, banned words, spam, and abusive content from WordPress.

Moderation features include:

* Reporting for posts, comments, profiles, messages, and groups
* Admin moderation queue
* Resolve and dismiss workflows
* Configurable automatic suspension
* Banned-word filtering
* Suspension audit logs
* Akismet integration
* Upload validation and access controls

= Social Embeds and Link Previews =

Members can share links from popular social and media platforms. Depending on the provider and configuration, the plugin can display oEmbed content, sandboxed iframes, or Open Graph preview cards.

Supported platforms include YouTube, Vimeo, X / Twitter, Instagram, Facebook, TikTok, Spotify, SoundCloud, Pinterest, Reddit, Twitch, Dailymotion, Apple Music, Apple Podcasts, LinkedIn, Telegram, Threads, Bluesky, and Aparat.

A privacy-focused click-to-play mode can prevent third-party requests until a visitor chooses to load embedded content.

= Search =

Unified search helps users discover content across the community from a single interface.

Search can include:

* Activity posts
* Members
* Groups
* Marketplace listings

Results respect content visibility and privacy settings.

= Creator Monetization =

Optional monetization tools allow creators to offer paid content, monthly subscriptions, and pay-per-view posts.

Stripe Connect support allows creators to connect their own Stripe accounts, while site administrators can configure platform fees and supported currencies.

Monetization can be disabled entirely when it is not needed.

= Developer Friendly =

6Arshid Social Community is built as a modular WordPress plugin with REST API endpoints, AJAX actions, hooks, filters, Gutenberg blocks, shortcodes, and template overrides.

Developer features include:

* REST API under `/wp-json/arshid6social/v1/`
* Action and filter hooks
* Component-based architecture
* Theme template overrides
* Gutenberg blocks
* Shortcodes for activity, members, groups, messages, notifications, profiles, bookmarks, hashtags, stories, verification, and blocking
* WordPress core XML sitemap integration

= Multilingual and RTL Ready =

The plugin includes internationalization support and ships with Persian (`fa_IR`) and Danish (`da_DK`) translation files.

It also includes:

* RTL support for Persian and Arabic
* Dedicated RTL stylesheet
* Jalali (Shamsi) calendar option
* Compatibility with WPML, Polylang, and TranslatePress

= Security and Performance =

The plugin uses WordPress security best practices throughout its forms, AJAX actions, REST endpoints, database operations, and file uploads.

Security and performance features include:

* Nonce and capability checks
* Input sanitization and output escaping
* Prepared database queries
* Upload MIME and extension validation
* Image re-encoding and EXIF stripping
* Rate limiting
* Honeypot and optional reCAPTCHA / Cloudflare Turnstile
* Conditional CSS and JavaScript loading
* Object cache and transient caching
* Database indexes
* Deferred scripts
* No jQuery dependency in front-end JavaScript

= BuddyPress Alternative =

6Arshid Social Community is **not a BuddyPress add-on and does not require BuddyPress**.

It is a standalone WordPress community and social network plugin. Sites currently using BuddyPress can use the included migration tool to help move supported data into 6Arshid Social Community.

This makes it suitable for site owners searching for a BuddyPress alternative while still wanting familiar features such as member profiles, activity streams, groups, friendships, messaging, and notifications.

= Accessibility and Privacy =

The interface includes keyboard navigation, ARIA labels, touch-friendly controls, dark mode support, and WCAG-oriented accessibility features.

WordPress privacy tools are supported for member data export and erasure, and users can control email notification preferences.

Third-party integrations such as GIF providers, social embeds, Gravatar, Stripe, and Akismet are documented below in the **External services** section.

== Installation ==

1. Upload the `6arshid-social-community` folder to `/wp-content/plugins/`
2. Activate the plugin through the **Plugins** menu in WordPress
3. Follow the setup wizard that appears after activation
4. Activation and setup create/configure plugin pages only. The plugin does not change `show_on_front`, `page_on_front`, or assign itself as the site homepage automatically.
5. Configure components and settings at **6arshid Social Community → Settings**

== Frequently Asked Questions ==


= Is this a WordPress social network plugin? =
Yes. 6Arshid Social Community is a standalone WordPress social network plugin that adds member profiles, activity feeds, groups, friends, followers, private messaging, notifications, polls, hashtags, moderation, and other community features.

= Is this a BuddyPress plugin or BuddyPress add-on? =
No. It does not require BuddyPress. It is an independent social network plugin for WordPress and includes a BuddyPress migration tool for supported data.

= Can I disable specific features? =
Yes. Go to **6arshid Social Community → Settings → Components** and toggle each feature on or off.

= How do I override a template? =
Copy the template file from `6arshid-social-community/templates/` into your theme at `{your-theme}/social-network/` with the same relative path.

= Is it compatible with BuddyPress? =
6Arshid Social Community is an independent plugin and does not require BuddyPress. A data migration tool from BuddyPress is included in the admin Tools page.

= Does it work in RTL? =
Yes. Persian and Arabic are fully supported with a dedicated `rtl.css` and Jalali calendar date formatting.

= How do I add custom profile fields? =
Developers can use the `arshid6social_xprofile_groups` and `arshid6social_xprofile_fields` tables directly or via the provided PHP API. An admin UI for field management is planned for a future release.

= Can I extend it with my own components? =
Yes. Hook into `arshid6social_loaded` to register custom components, and use `arshid6social_settings_tabs` to add your own settings tab.

= What shortcodes are available? =
`[arshid6social_activity]`, `[arshid6social_members]`, `[arshid6social_groups]`, `[arshid6social_messages]`, `[arshid6social_notifications]`, `[arshid6social_profile]`, `[arshid6social_bookmarks]`, `[arshid6social_trending_hashtags]`, `[arshid6social_stories_tray]`, `[arshid6social_verification_request]`, `[arshid6social_block_list]`

= Is the REST API available to external apps? =
Yes. The REST API at `/wp-json/arshid6social/v1/` covers activity, members, friends, groups, messages, notifications, bookmarks, hashtags, polls, tags, sharing, sticky posts, and attachments.

== Screenshots ==

1. Member directory with search and filters
2. User profile with cover photo, avatar, and activity feed
3. Activity composer with emoji, GIF, poll, and attachment support
4. Comment section with threaded replies, reactions, and GIF support
5. Group directory and single group view
6. Private messages inbox with real-time updates
7. On-site notification centre
8. Bookmarks with collections
9. Trending hashtags feed
10. Admin settings panel (tabbed)
11. Admin moderation queue

== External services ==

This plugin can contact the following third-party services. Calls are feature-gated and happen only when the matching feature is enabled, configured, or triggered by a user or administrator action.

= Gravatar =
Member profile photos fall back to Gravatar when no custom avatar has been uploaded. The request sends the MD5 hash of the user's email address to Gravatar when an avatar is displayed.
* Service: https://gravatar.com
* Privacy Policy: https://automattic.com/privacy/
* Terms of Service: https://wordpress.com/tos/

= GIF search APIs: GIPHY and Tenor =
When GIF comments are enabled and an API key is configured, the GIF picker requests trending GIFs or search results from the selected provider. Search requests send the user's search term, the configured API key, and normal HTTP request metadata such as IP address and user agent.
* GIPHY API: https://api.giphy.com/v1/gifs/
  * Privacy Policy: https://support.giphy.com/hc/en-us/articles/360032872931-GIPHY-Privacy-Policy
  * Terms of Service: https://support.giphy.com/hc/en-us/articles/360020027752-GIPHY-User-Terms-of-Service
* Tenor API: https://tenor.googleapis.com/v2/
  * Privacy Policy: https://policies.google.com/privacy
  * Terms of Service: https://policies.google.com/terms

= Social embeds and link previews =
When Social Embeds are enabled and a user pastes a supported URL into social content, the plugin fetches oEmbed data, iframe metadata, or Open Graph metadata for that URL. The requested URL, site server request metadata, and any administrator-configured provider token are sent to the matched provider. Rendered embeds or iframes may also cause the visitor's browser to contact the provider when the embedded content is displayed. Each provider can be disabled in Settings > Engagement.
* YouTube / Google: https://www.youtube.com/oembed
  * Privacy Policy: https://policies.google.com/privacy
  * Terms of Service: https://policies.google.com/terms
* Vimeo: https://vimeo.com/api/oembed.json
  * Privacy Policy: https://vimeo.com/privacy
  * Terms of Service: https://vimeo.com/terms
* X / Twitter: https://publish.twitter.com/oembed
  * Privacy Policy: https://x.com/en/privacy
  * Terms of Service: https://x.com/en/tos
* Instagram / Meta: https://graph.facebook.com/v18.0/instagram_oembed
  * Privacy Policy: https://privacycenter.instagram.com/policy/
  * Terms of Service: https://help.instagram.com/581066165581870
* Facebook / Meta: https://graph.facebook.com/v18.0/oembed_post
  * Privacy Policy: https://www.facebook.com/privacy/policy/
  * Terms of Service: https://www.facebook.com/terms.php
* TikTok: https://www.tiktok.com/oembed
  * Privacy Policy: https://www.tiktok.com/legal/page/us/privacy-policy/en
  * Terms of Service: https://www.tiktok.com/legal/page/us/terms-of-service/en
* Spotify: https://open.spotify.com/oembed
  * Privacy Policy: https://www.spotify.com/legal/privacy-policy/
  * Terms of Service: https://www.spotify.com/legal/end-user-agreement/
* SoundCloud: https://soundcloud.com/oembed
  * Privacy Policy: https://soundcloud.com/pages/privacy
  * Terms of Service: https://soundcloud.com/terms-of-use
* Pinterest: https://www.pinterest.com/oembed.json
  * Privacy Policy: https://policy.pinterest.com/en/privacy-policy
  * Terms of Service: https://policy.pinterest.com/en/terms-of-service
* Reddit: https://www.reddit.com/oembed
  * Privacy Policy: https://www.reddit.com/policies/privacy-policy
  * Terms of Service: https://redditinc.com/policies/user-agreement
* Twitch: https://clips.twitch.tv/embed and https://player.twitch.tv/
  * Privacy Policy: https://legal.twitch.com/en/legal/privacy-notice/
  * Terms of Service: https://legal.twitch.com/en/legal/terms-of-service/
* Dailymotion: https://www.dailymotion.com/services/oembed
  * Privacy Policy: https://legal.dailymotion.com/en/privacy-policy/
  * Terms of Service: https://legal.dailymotion.com/en/terms-of-use/
* Apple Music / Podcasts: https://music.apple.com and https://podcasts.apple.com
  * Privacy Policy: https://www.apple.com/legal/privacy/
  * Terms of Service: https://www.apple.com/legal/internet-services/itunes/
* LinkedIn: https://www.linkedin.com
  * Privacy Policy: https://www.linkedin.com/legal/privacy-policy
  * Terms of Service: https://www.linkedin.com/legal/user-agreement
* Telegram: https://t.me/
  * Privacy Policy: https://telegram.org/privacy
  * Terms of Service: https://telegram.org/tos
* Threads / Meta: https://www.threads.net/oembed/
  * Privacy Policy: https://help.instagram.com/515230437301944/
  * Terms of Service: https://help.instagram.com/769983657850450
* Bluesky: https://bsky.app
  * Privacy Policy: https://bsky.social/about/support/privacy-policy
  * Terms of Service: https://bsky.social/about/support/tos
* Aparat: https://www.aparat.com/oembed.json
  * Privacy Policy: https://www.aparat.com/privacy
  * Terms of Service: https://www.aparat.com/terms
* Generic Open Graph previews: when no named provider matches and generic previews are enabled, the plugin fetches the user-submitted target URL to read metadata. The external service is the target site chosen by the user; that site's own privacy policy and terms apply.

= Social sharing links =
The social sharing feature builds share links in the browser. No request is sent to these services until the user explicitly clicks a share button or opens a local share handler. The shared page URL and title are passed to the selected service or app.
* Facebook / Meta: https://www.facebook.com/sharer/sharer.php
  * Privacy Policy: https://www.facebook.com/privacy/policy/
  * Terms of Service: https://www.facebook.com/terms.php
* X / Twitter: https://twitter.com/intent/tweet
  * Privacy Policy: https://x.com/en/privacy
  * Terms of Service: https://x.com/en/tos
* WhatsApp: https://api.whatsapp.com/send
  * Privacy Policy: https://www.whatsapp.com/legal/privacy-policy
  * Terms of Service: https://www.whatsapp.com/legal/terms-of-service
* Telegram: https://t.me/share/url
  * Privacy Policy: https://telegram.org/privacy
  * Terms of Service: https://telegram.org/tos
* LinkedIn: https://www.linkedin.com/sharing/share-offsite/
  * Privacy Policy: https://www.linkedin.com/legal/privacy-policy
  * Terms of Service: https://www.linkedin.com/legal/user-agreement
* Reddit: https://reddit.com/submit
  * Privacy Policy: https://www.reddit.com/policies/privacy-policy
  * Terms of Service: https://redditinc.com/policies/user-agreement
* Threads / Meta: https://www.threads.net/intent/post
  * Privacy Policy: https://help.instagram.com/515230437301944/
  * Terms of Service: https://help.instagram.com/769983657850450
* Bluesky: https://bsky.app/intent/compose
  * Privacy Policy: https://bsky.social/about/support/privacy-policy
  * Terms of Service: https://bsky.social/about/support/tos
* Pinterest: https://pinterest.com/pin/create/button/
  * Privacy Policy: https://policy.pinterest.com/en/privacy-policy
  * Terms of Service: https://policy.pinterest.com/en/terms-of-service
* LINE: https://social-plugins.line.me/lineit/share
  * Privacy Policy: https://www.lycorp.co.jp/en/company/privacypolicy/
  * Terms of Service: https://terms.line.me/line_terms
* Gmail / Google: https://mail.google.com/mail/
  * Privacy Policy: https://policies.google.com/privacy
  * Terms of Service: https://policies.google.com/terms
* Yahoo Mail and AOL Mail: https://compose.mail.yahoo.com/ and https://mail.aol.com/
  * Privacy Policy: https://legal.yahoo.com/us/en/yahoo/privacy/index.html
  * Terms of Service: https://legal.yahoo.com/us/en/yahoo/terms/otos/index.html
* Outlook.com / Microsoft: https://outlook.live.com/owa/
  * Privacy Policy: https://privacy.microsoft.com/privacystatement
  * Terms of Service: https://www.microsoft.com/servicesagreement
* Viber local app handler: viber://forward
  * Privacy Policy: https://www.viber.com/en/terms/viber-privacy-policy/
  * Terms of Service: https://www.viber.com/en/terms/viber-terms-use/
* Email, SMS, copy-link, and send-as-message actions are local browser/site actions. The plugin does not make a third-party HTTP request for those actions.

= Stripe =
When the Monetization module is enabled and Stripe keys are configured, the checkout UI loads Stripe.js from Stripe and server-side monetization requests call the Stripe API to create or retrieve payment intents and process webhook events. Data sent can include amount, currency, payment intent identifiers, Stripe keys, purchaser and creator user IDs, activity IDs, and Stripe metadata required to complete the payment. The plugin does not store raw card or bank details.
* Stripe.js: https://js.stripe.com/v3/
* Stripe API: https://api.stripe.com/v1/
* Privacy Policy: https://stripe.com/privacy
* Terms of Service: https://stripe.com/legal

= Akismet =
When Akismet spam checking is enabled and the separate Akismet plugin is installed and active, activity content is sent to Akismet's spam-checking API before publication. Data sent includes the submitted content, author information, IP address, user agent, referrer, permalink, and site URL.
* Service: https://akismet.com
* Privacy Policy: https://automattic.com/privacy/
* Terms of Service: https://akismet.com/tos/

= WordPress.org theme downloads =
The setup wizard can download a WordPress.org theme ZIP when an administrator explicitly chooses to install a theme from the wizard. The requested theme slug and normal server request metadata are sent to WordPress.org.
* Service: https://downloads.wordpress.org/theme/
* Privacy Policy: https://wordpress.org/about/privacy/
* Project License and Policies: https://wordpress.org/about/license/

= Developer build helper =
The development-only Bootstrap Icons download helper in the build directory downloads the Bootstrap Icons release ZIP from GitHub only when a maintainer runs that script manually. This is not executed during normal plugin runtime.
* GitHub: https://github.com/twbs/icons/
  * Privacy Policy: https://docs.github.com/site-policy/privacy-policies/github-privacy-statement
  * Terms of Service: https://docs.github.com/site-policy/github-terms/github-terms-of-service

== Changelog ==

= 1.8.3 =
* WordPress.org review fix: plugin activation and setup no longer assign a static front page or modify the site's homepage settings.
* Security hardening: sticky activity REST/AJAX permissions now validate the activity owner, profile scope owner, group destination, and moderator capabilities before pinning or unpinning.
* Compliance hardening: removed runtime error-suppression operators from local asset version and icon metadata reads.
* Security hardening: tightened REST permission callbacks, social media file serving, story visibility checks, friend-request acceptance, monetization setting sanitization, and remote GIF API requests.
* External services documentation: rebuilt the section to match the currently supported services and removed obsolete sharing-provider disclosures.

= 1.8.2 =
* Plugin Check: resolved the remaining `PluginCheck.Security.DirectDB.UnescapedDBParameter` notices by annotating the safe dynamic table-name/whitelist identifiers (all query values are bound via `$wpdb->prepare()` placeholders — never raw user input) and cleared the last `PreparedSQLPlaceholders` notices.
* Hardened the dev-only CLI migration test harness with a direct-access guard; it remains excluded from the distributed package.
* Trimmed the readme tag list to five.

= 1.8.1 =
* Hardening: unslashed and type-correctly sanitized all remaining superglobal reads (passwords are unslashed but never sanitize_text_field'd; arrays sanitized per field type; uploads validated by the media handler).
* Added explicit nonce-context annotations to the Ads admin screen's read-only view routing (form processing was already nonce-verified).
* Corrected all `$wpdb->prepare()` placeholder usages flagged by Plugin Check (dynamic `IN()`/`WHERE` clauses build their placeholders at runtime and bind values via prepare()).
* Annotated safe dynamic table-name interpolations (built from `$wpdb->prefix` and in-code whitelists, never user input) and the intentional third-party cache-plugin integration hooks.

= 1.8.0 =
* Consistency: migrated all custom database tables from the legacy `sn_` secondary prefix to the plugin's standard `arshid6social_` prefix. Existing sites are upgraded automatically and losslessly via an idempotent `RENAME TABLE` migration on update; fresh installs create the new table names directly.
* Consistency: renamed the remaining client-side `sn_*` form-field names (GIF and attachment staging fields) to the `arshid6social_*` prefix. No stored data or request payloads are affected.
* Fixed broken third-party Terms/Privacy links in the External Services documentation.
* Packaging: the development-only `build/` tooling is excluded from the distributed plugin via `.distignore` / `.gitattributes`.

= 1.7.0 =
* Renamed plugin to 6Arshid Social Community with a consistent `6arshid-social-community` slug/text domain and `arshid6social` code prefix throughout.
* Fixed remaining WordPress.org plugin review items: removed the last raw inline `<script>` output, removed the remaining remote Google Fonts dependency, corrected short/inconsistent prefixes in the Monetization module and a handful of shortcodes, and documented Akismet under External Services.

= 1.0.0 =
* Initial release

== Upgrade Notice ==

= 1.7.0 =
Internal prefix and slug consistency fixes; no action required for existing installs.

= 1.0.0 =
Initial release. No upgrade path required.
