AlkaPay Payment Gateway with M-Pesa for WooCommerce
Full changelog
==============

readme.txt carries only the two most recent releases, as the WordPress.org guidelines ask.
Every release is recorded here. For the technical detail behind each one, see docs/CHANGELOG.md.

= 1.2.4 =
* Fixed: AlkaPay could crash your site if another M-Pesa plugin was active at the same time. It now runs safely alongside other plugins.

= 1.2.3 =
* Security: The M-Pesa payment page now confirms you own an order before it shows any order details, so order information can no longer be viewed by guessing an order number in the address bar.
* Security: The secret in your M-Pesa callback URL is now generated in a more secure way. Your callback URL does not change, so there is nothing to re-register.
* Changed: AlkaPay's internal names are now unique to AlkaPay, so it will not clash with other plugins. Your settings and saved payments carry over automatically — there is nothing to do.
* Fixed: The "rate AlkaPay" links now open all reviews on WordPress.org rather than a pre-filled star rating.
* Maintenance: Behind-the-scenes code quality improvements.

= 1.2.2 =
* Fixed: On some themes the checkout could show no "Place Order" button, or the order summary and the details on the order-received page could go missing. AlkaPay's payment-page styling was loading on the checkout and thank-you pages, where it did not belong. It now loads only on the M-Pesa payment page.
* Fixed (free version): The gateway was labelled "Test mode" on the WooCommerce Payments screen even on a live store. The free version does not use Sandbox at all — that label applied only to STK Push, which is a Pro feature — so it has been removed.
* Fixed (Pro): A payment confirmation from M-Pesa that arrived without a result code could mark an order as paid. Those are now rejected.
* Improved (Pro): If Pro is installed without an active licence, the checkout now shows manual Paybill/Till payment instead of offering automatic STK Push and then failing. A clear notice explains that a licence is needed, and the customer never sees a licence message.
* Added: When your store is in Sandbox (test) mode, the payment page and settings now warn plainly that manual payments are still real money — only the automatic prompt is simulated.
* Maintenance: All styles and scripts now load through WordPress's own asset system.

= 1.2.1 =
* Changed: The plugin is now listed as "AlkaPay Payment Gateway with M-Pesa for WooCommerce". M-Pesa is a Safaricom trademark and the previous name could read as though AlkaPay came from Safaricom; it does not. Nothing about your settings, your checkout or the payment method name changes.
* Security: The secret in your M-Pesa callback URL is now a random value stored with your settings, instead of being calculated from your site's WordPress security keys. Your callback URL does not change and you do not need to re-register anything with Safaricom.
* Fixed: A payment confirmation from Safaricom that arrived without a result code could mark an order as paid. Those are now rejected.
* Fixed: The log viewer could be tricked into reading a file outside the log folder on a site where the uploads folder could not be located.
* Changed: Installing Pro no longer deactivates and deletes the free copy for you. Remove it yourself from the Plugins screen, as you would any other plugin.
* Changed: The "configuration required" notice now appears only on your Dashboard, Plugins, WooCommerce and AlkaPay screens rather than everywhere in the admin.
* Maintenance: All of the plugin's styles and scripts now load through WordPress's own asset system. No visible change, but it makes AlkaPay a better citizen alongside other plugins.

= 1.2.0 =
* Changed: The free version is now built purely around manual M-Pesa payments. Sandbox STK Push testing has been removed from it — WordPress.org does not allow a plugin to ship code that a licence key unlocks, and the same code served both sandbox and live. To try the automated STK Push checkout, use the demo store at https://demo.alkapay.co.ke.
* Action needed (free version only): if your Payment Mode was set to Sandbox, open AlkaPay → Settings and make sure your Paybill or Till number is filled in. Manual payments are now always on, but they need that number to appear at checkout.
* Added: "Order Status After Manual Payment" is now yours to set in the free version — On Hold, Pending or Processing. It was previously fixed to On Hold.
* Fixed: Admin dates and times now show your store's timezone instead of UTC, so they line up with the M-Pesa SMS. Nairobi stores were reading three hours behind.
* Fixed: The 72-hour window for matching payment callbacks was three hours wider than intended, and the 90-day cleanup slightly narrower.
* Improved: Fewer upgrade prompts. The Free/Pro comparison now lives on one page — AlkaPay → Account — with a single line of text elsewhere.
* Improved: The Help & Rate guide adapts to what you have installed, so the free version no longer walks you through Daraja API keys and callback URLs you do not need.
* Maintenance: Removed several admin pages that no URL could reach, and corrected help text that described features as Pro when they are in fact free.
* Note: Pro is unchanged — live STK Push, automatic verification, analytics and logs all work exactly as before.

= 1.1.6 =
* Fixed: Plugin updates now apply database changes properly. Until now an update could leave your payment records table on an older structure, because the upgrade step was quietly skipped.
* Fixed: A brand-new install could greet you with "your plugin has been updated from 1.1.4 to 1.1.5" when nothing had been updated.
* Fixed: Feedback and notes containing an apostrophe were saved with a stray backslash, so "doesn't work" became "doesn\'t work".
* Fixed: The Analytics page no longer asks for a file that isn't part of the free version.
* Changed: Settings backups are now kept in your uploads folder, where they survive plugin updates. Backups made by earlier versions still work.
* Changed: The plugin is now listed as "AlkaPay - M-Pesa Payment Gateway for WooCommerce" in your Plugins screen. The payment method at checkout is unchanged.
* Changed: Removed the "Powered by AlkaPay" footer from the customer payment page. WordPress.org does not allow plugins to place links to their own site on pages your shoppers see.
* Improved: The update notice is shorter, and the Changelog page now shows what a release contains before you install it.
* Improved: Text that could never be translated before — including the payment settings help and the underpayment emails sent to customers — can now be translated.
* Maintenance: A full pass against the WordPress.org coding standards, covering security, output escaping and translations. Payment behaviour is unchanged.
* Note: AlkaPay now requires WordPress 6.0 or newer, and is tested up to WordPress 7.0.

= 1.1.5 =
* Fixed: Diagnostics could wrongly say SSL was enabled on a site without a certificate.
* Fixed: Partial payments no longer lose their payment details on sites where email isn't set up. (Pro)
* Fixed: Order details now show the callback status instead of always reading "N/A". (Pro)
* Improved: The "Payer Phone" line is hidden for manual payments, where Safaricom doesn't share a usable number. (Pro)
* Improved: Settings → System now has one Save button, and the callback URL has a Copy button.
* Improved: Updated the callback setup guide to match Safaricom's current Daraja portal.
* Improved: Cleaner admin notices.

= 1.1.4 =
* Fixed: A critical error in 1.1.3 that could crash stores using the block checkout. Update straight away if you are on 1.1.3.
* Fixed: The payment form could appear twice on the payment page.
* Fixed: Manual payments could fail on the first try, or be labelled as STK Push by mistake, on sites without email set up.
* Fixed: Manual payments now work in Sandbox mode. (Pro)
* Fixed: Your browser no longer autofills your WordPress login into the API credential fields.
* Fixed: A dashboard layout glitch that left a blank gap under the orders table.
* Added: The dashboard now counts orders from when AlkaPay was installed, so older orders don't skew your stats. Adjustable under Settings → System.
* Improved: Clearer first-time setup prompt, and manual payments no longer require switching to Production first.

= 1.1.3 =
* Added: Support for the WooCommerce block checkout — M-PESA now appears there, not just the classic checkout.
* Fixed: The AlkaPay logo now displays on the payment page.
* Fixed: Manual payments could show "Order submission failed" on the first click.
* Fixed: The "Update Now" button in the update notice now actually updates.

= 1.1.2 =
* Maintenance: Updated the bundled licensing library for better PHP 8 compatibility. No change to payment behaviour.

= 1.1.1 =
* Fixed: License deactivation now reports accurately instead of showing a false success.
* Fixed: Removed a duplicate licensing notice on the account screens.
* Improved: Added a "Reactivate License" action to the Account page.
* Improved: Manual payment setup is now documented for both Free and Pro.
* Improved: Larger analytics preview on the free dashboard.

= 1.1.0 =
First public release of AlkaPay — M-Pesa payments for WooCommerce.

* Free: Accept M-Pesa through your Paybill or Buy Goods (Till). Customers confirm by entering their M-Pesa code.
* Free: Sandbox testing, an admin dashboard, guided setup, and automatic updates.
* Pro: Live STK Push — the payment prompt goes straight to the customer's phone and the order completes on its own.
* Pro: Automatic payment verification, analytics, transaction logs, and configurable order statuses.
* Security: Encrypted API credentials, a secret per-site callback URL, and protection against spoofed callbacks.
* Requires WordPress 5.0+, WooCommerce 6.0+, and PHP 7.4+.
