=== AdPriva ===
Contributors: adprivadevops
Tags: traffic verification, bot detection, traffic quality, privacy, analytics
Requires at least: 6.0
Tested up to: 7.0
Requires PHP: 7.4
Stable tag: 1.0.2
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Privacy-first traffic verification. Connect your site to AdPriva, load the tag, and see human vs. bot traffic in your WordPress dashboard.

== Description ==

AdPriva verifies your traffic with cryptographic proofs so you can tell real, human visits from
abusive bots. Install the plugin, click **Connect with AdPriva** (a secure OAuth sign-in — no API keys
to copy), and the plugin will:

* Register and verify your site with AdPriva automatically.
* Provision a site placement and load the AdPriva verification tag on your site from the AdPriva CDN.
* Show a traffic & validity summary right on your WordPress dashboard, with a link to your full
  AdPriva console.

The plugin is self-sufficient inside wp-admin:

* **Settings page** — control where the tag loads (post types, exclude logged-in users,
  administrators, or specific URLs), choose how it cooperates with consent plugins, toggle the
  dashboard widget, and (advanced) override the AdPriva endpoints.
* **In-admin dashboard** — KPI cards, a human vs. bot verdict breakdown, and a trend chart over the
  last 7, 30, or 90 days, all without leaving WordPress.

No personal data about your visitors is collected by this plugin. Verification happens server-side at
AdPriva using privacy-preserving signals.

= Connecting =

After activating, open the **AdPriva** menu in wp-admin and click **Connect with AdPriva**. You will be
sent to AdPriva to approve the connection for your organization, then returned to your site — connected.

== External services ==

This plugin connects to AdPriva, a third-party service, to verify your traffic. This is required for
the plugin to function.

**1. AdPriva API — `https://api.adpriva.com`**
Used to: complete the "Connect with AdPriva" sign-in (OAuth 2.0 authorization-code with PKCE), register
and verify your site's domain, provision a site placement, and fetch your traffic summary and per-day
trend for the dashboard widget and the in-admin dashboard.
Data sent: your site's domain, the OAuth authorization parameters, and the access token issued to this
install. No visitor personal data is sent by the plugin.
Terms: https://adpriva.com/terms — Privacy Policy: https://adpriva.com/privacy

**2. AdPriva verification tag (CDN) — `https://cdn.adpriva-ads.com/tag.js`**
Used to: load the lightweight verification tag on your site's front end (with your provisioned
placement ID) so AdPriva can verify traffic. The script is served from AdPriva's CDN.
Terms: https://adpriva.com/terms — Privacy Policy: https://adpriva.com/privacy

== Privacy ==

* The plugin stores a single option in your database holding the AdPriva connection: access/refresh
  tokens (encrypted at rest using your site's WordPress salts), your placement ID, and your domain.
* The plugin does not set cookies and does not collect or store your visitors' personal data.
* You can disconnect at any time from the **AdPriva** settings page; this revokes the access token and
  deletes the stored connection. Uninstalling the plugin removes all stored data.
* Respecting consent: the tag only loads when connected and when your Settings → Tag targeting rules
  allow it, and a consent/privacy plugin can always suppress it via the `adpriva_should_load_tag`
  filter (the filter is the final override).
* Settings are stored in a separate `adpriva_settings` option; they contain no visitor data.

== Installation ==

1. Upload the plugin to `/wp-content/plugins/adpriva`, or install it from the Plugins screen.
2. Activate it.
3. Open the **AdPriva** menu and click **Connect with AdPriva**.

== Frequently Asked Questions ==

= Do I need an AdPriva account? =
Yes. The Connect button signs you in to AdPriva; you approve the connection for your organization.

= Does this collect my visitors' personal data? =
No. The plugin sends your site's domain and the connection token to AdPriva. Traffic verification is
performed by AdPriva using privacy-preserving signals.

= How do I stop loading the tag? =
Disconnect from the AdPriva settings page, or use the `adpriva_should_load_tag` filter to control it.

== Screenshots ==

1. The AdPriva dashboard — KPI cards, verdict breakdown, and a trend chart, inside wp-admin.
2. The AdPriva Settings page — tag targeting, consent, dashboard, and advanced endpoint controls.
3. The AdPriva dashboard widget — verified events with a human vs. abusive-bot breakdown.

== Changelog ==

= 1.0.2 =
* Fixed: the default AdPriva console address now points at console.adpriva.com. The "Open console" links in the dashboard, settings page, and widget previously went to the wrong AdPriva app unless you had set an endpoint override.

= 1.0.1 =
* Compliance: the Contributors field now lists the plugin owner's WordPress.org account, as required for the directory listing.
* Removed the unused Plugin URI header and hardened WordPress Plugin Check (strict mode) for a clean review. No functional changes.

= 1.0.0 =
* First stable release, submitted to the WordPress.org plugin directory.
* Connect with AdPriva via OAuth 2.0 authorization-code with PKCE — no API keys to copy.
* Loads the AdPriva verification tag from the CDN with your provisioned placement ID.
* Settings page: tag targeting (post types, exclude logged-in users / administrators / URLs), consent integration mode, dashboard preferences, and advanced endpoint overrides.
* In-admin dashboard and dashboard widget: KPI cards, human vs. bot verdict breakdown, and a 7/30/90-day trend chart.

= 0.2.0 =
* New: in-admin dashboard with KPI cards, verdict breakdown, and a 7/30/90-day trend chart (no console trip needed).
* New: Settings page — tag targeting (post types, exclude logged-in users / administrators / URLs), consent integration mode, dashboard preferences, and advanced endpoint overrides.
* New: the dashboard widget can be toggled from Settings, and now links to the in-admin dashboard.
* Endpoint URLs resolve as: a wp-config constant wins, then a Settings override, then the built-in default.

= 0.1.0 =
* Initial release: Connect with AdPriva (OAuth + PKCE), CDN tag injection, and a dashboard traffic widget.

== Upgrade Notice ==

= 1.0.1 =
Metadata and directory-compliance fixes only; no functional changes.

= 1.0.0 =
First stable release of AdPriva for WordPress.

= 0.2.0 =
Adds an in-admin dashboard and a full Settings page. No action required; your existing connection is preserved.

= 0.1.0 =
First public release of AdPriva for WordPress.
