=== ambera Theme Builder ===
Contributors: amberagmbh
Tags: theme builder, page builder, site editor, templates, seo
Requires at least: 6.5
Tested up to: 7.1
Requires PHP: 8.1
Stable tag: 0.3.4
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Build the whole website in one editor: header, footer, pages and templates, with ready demos, statistics, forms and a media manager.

== Description ==

https://youtu.be/JKGi2dDtqTY

ambera Theme Builder replaces the theme. Install it, and one editor covers everything a visitor sees: the header, the footer, every page and every template. You do not need a separate theme, a page builder and a handful of add-ons — the pieces live in one plugin and share one design.

**What is in the box**

* **One editor for everything.** Drag blocks onto a canvas, style them with a design panel, and see the result at once. Header and footer are edited the same way as pages.
* **Design tokens.** Colours, fonts, spacing and text styles are set once and used everywhere; change a token and the whole site follows.
* **Twenty-five demos.** Complete websites — a bakery, a coaching practice, a locksmith, a portfolio, a moving company — that install with one click and can be taken apart and reused. Sixty-eight more come with Pro.
* **Header and footer.** Built in the same editor as the pages, with menus, mega menus and a mobile menu; blog index, single posts, archives, search and 404 use the built-in layouts. Pro adds editable templates for those.
* **Forms.** Contact, booking and registration forms with mail delivery, a mail log and spam protection, without a form plugin.
* **Media manager.** Your own library with folders, image editing, and a search across free stock photos (Pixabay, with your own API key).
* **Statistics.** Page views, referrers and countries, counted on your own server, without cookies and without a third party.
* **SEO and speed.** Titles, descriptions, social images, a sitemap, and a critical-CSS pipeline that ships only the rules a page uses.
* **Ten languages.** The editor and the dashboard speak English, German, French, Italian, Spanish, Portuguese, Dutch, Polish, Japanese and Turkish.

**Your client never sees WordPress**

The client area at `/themebuilder/admin/` is the whole back end for the people who run the site: pages, blog, messages, media, forms, statistics, users — in plain words, with the site's own logo. No wp-admin, no plugin list, no update nags. You keep the WordPress admin for yourself.

= 🔥 ambera Theme Builder Pro =

The free version is complete on its own. [Pro](https://amberathemebuilder.com/) adds what a business site needs on top:

* **Shop** — products, cart, checkout, orders, invoices, Stripe and PayPal, a currency switch.
* **Newsletter** — write it in the same editor, send it from your own site, see who opened it.
* **Multilingual** — the whole site in several languages, translated by machine and corrected by you, with a language switch in the header.
* **AI** — write and rewrite text, describe a section and have it built, generate pictures, write alt texts. With your own API key.
* **Custom fields** — field sets for pages, posts and products, shown with the field block.
* **Firewall and country blocking** — before WordPress even loads.
* **More blocks** — table, slider, tabs, accordion, pricing table, price switch, countdown, timeline, popup, map, hotspots, video playlist, HTML.
* **Templates** — blog index, single post, archives, search, 404, and any custom post type, edited like a page.
* **Tasks and backups** — a to-do list on the dashboard, backups of files and database.
* **Updates from your own dashboard**, a year of updates and support, and a licence for one or many sites.

Pro is a separate plugin. Nothing in this free plugin is locked or waits for a key: what is listed above is simply not in it.

== Installation ==

1. Upload the plugin to `/wp-content/plugins/` or install it from the plugin directory.
2. Activate it under Plugins.
3. Open **ambera** in the admin menu. The dashboard walks you through the first steps: pick a demo or start blank, set your colours and fonts, edit the header and footer.

The plugin brings its own theme layer. If you keep another theme active, ambera renders the pages you assign to it and leaves the rest to the theme.

== Frequently Asked Questions ==

= Do I still need a theme? =

No. ambera renders header, footer and every template itself. A block theme can stay installed; WordPress needs one to be active, and ambera works with any.

= Does it work with the block editor (Gutenberg)? =

Yes. Posts written in the block editor are shown inside the templates you build. Pages can be built with either editor; ambera's editor is used for the layout of the site itself.

= Where do the demos come from? =

From a catalogue on amberathemebuilder.com. The list is loaded when you open the demo screen, the demo itself only when you install it. See "External services" below.

= Does the plugin send anything home? =

Nothing without your action. There is no tracking and no licence check — this plugin has no key, no account and no licence server; updates come from wordpress.org through WordPress' own update check, and the Help screen shows what WordPress found. The demo catalogue, Google Fonts and the stock-photo search are loaded only when you open those screens or press those buttons; see "External services".

= Is the statistics module GDPR-friendly? =

It counts on your server, sets no cookie and stores no IP address. The visitor's country comes from your CDN's header if there is one; the optional lookup at an external service is off by default.

== External services ==

The plugin talks to the services below. Each one is called only in the situation described, never in the background.

**Demo catalogue (amberathemebuilder.com)**
When you open the demo screen, the plugin fetches the list of demos from `https://amberathemebuilder.com/katalog/demos.json`. When you install a demo, it downloads that demo's zip file from the same host. The request carries no personal data and no site information beyond what any HTTP request carries (the server's IP address). The service is run by the plugin author, ambera GmbH; [terms](https://amberathemebuilder.com/agb/), [privacy policy](https://wordpress-theme-builder.com/privacy/).

**Google Fonts (fonts.googleapis.com, fonts.gstatic.com)**
When you type a font name under Settings → Fonts and press "Fetch and store it", your server downloads the font files once from Google and stores them in your uploads folder. From then on the font is served from your own site; visitors' browsers never contact Google. The request is made by your server, not by visitors, and sends the font name only. [Terms](https://developers.google.com/fonts/terms), [privacy policy](https://policies.google.com/privacy).

**Pixabay (pixabay.com)**
The media manager can search free stock photos on Pixabay. This works only after you enter your own Pixabay API key under Settings; without a key nothing is sent. When you search, the search words and your key are sent to `https://pixabay.com/api/`; when you pick a photo, the image file is downloaded from Pixabay to your media library. [Terms](https://pixabay.com/service/terms/), [privacy policy](https://pixabay.com/service/privacy/).

**Country lookup (api.country.is)**
The statistics module can look up a visitor's country. By default it reads the country from a header your CDN sets (Cloudflare and others) and asks nothing outside. If you switch on the country lookup under Settings → Statistics, the visitor's IP address is sent to `https://api.country.is/` and only the two-letter country code is stored. This is off by default. [Privacy policy](https://country.is/).

**Video embeds (YouTube, Vimeo)**
The video block shows a poster image and loads the player from `youtube-nocookie.com` or `player.vimeo.com` only after the visitor clicks. [YouTube terms](https://www.youtube.com/t/terms), [Vimeo privacy](https://vimeo.com/privacy).

**Support portal (portal.amberathemebuilder.com)**
"Support ticket" and "Feature request" on the Help screen are links that open the plugin author's support portal in a new tab. The link carries your site's host name and a short technical summary (plugin, WordPress and PHP version, site language) so the form there is prefilled; nothing is sent unless you click the link, and nothing is submitted until you send the form on the portal. The plugin itself never calls the portal. Run by ambera GmbH; [terms](https://amberathemebuilder.com/agb/), [privacy policy](https://wordpress-theme-builder.com/privacy/).

**Help videos (YouTube)**
The Help screen can show short tutorial films. A tile shows only the title; the player from `youtube-nocookie.com` is loaded when you press play, and only then. [YouTube terms](https://www.youtube.com/t/terms), [Google privacy policy](https://policies.google.com/privacy).

**PayPal button (paypal.com)**
The PayPal block renders a plain form that leads to `https://www.paypal.com/cgi-bin/webscr` when a visitor clicks the button. Only then, and only what you entered in the block, is sent: your PayPal e-mail address, the item name, amount and currency, and the return address. The plugin itself never calls PayPal. [User agreement](https://www.paypal.com/legalhub/useragreement-full), [privacy statement](https://www.paypal.com/legalhub/privacy-full).

**Share links (Facebook, X, LinkedIn, WhatsApp, Telegram, Pinterest)**
The share block is a row of ordinary links to the share pages of these networks. A link opens the network with the address and title of the page when a visitor clicks it; no script from any network is loaded and nothing is sent before the click. [Meta privacy](https://www.facebook.com/privacy/policy/), [X privacy](https://x.com/privacy), [LinkedIn privacy](https://www.linkedin.com/legal/privacy-policy), [WhatsApp privacy](https://www.whatsapp.com/legal/privacy-policy), [Telegram privacy](https://telegram.org/privacy), [Pinterest privacy](https://policy.pinterest.com/privacy-policy).

**Interpol (interpol.int)**
When the firewall is set to "harsh" and an address on the block list keeps coming back, the blocked request is answered with a redirect to Interpol's public cybercrime page instead of an error page. This is a plain redirect of the blocked visitor; nothing is sent to Interpol by the plugin.

**Images in imported HTML**
When you paste HTML into the editor's import, images that point to another server are copied into your media library so the page does not load from there on every visit. Your server fetches only the image addresses in the HTML you pasted.

== Screenshots ==

1. The editor: canvas in the middle, blocks on the left, design panel on the right.
2. The dashboard with the first steps, statistics and the mail log.
3. The demo screen with complete websites to start from.
4. The design panel: colours, fonts and text styles, set once for the whole site.
5. Forms with the mail log.
6. The media manager with folders and the stock-photo search.
7. Statistics: views, referrers and countries, counted on your own server.

== Changelog ==

= 0.3.4 =
* The early firewall (loader in the site root) is a Pro file; the free plugin writes nothing outside the uploads folder.
* The residual stylesheet of an HTML import is kept only with its checker, which is Pro; the free plugin drops it.
* The block library's preview document uses a data-address stylesheet link instead of a style tag where no file can be written.
* External services: PayPal button, share links and the Interpol redirect are documented.

= 0.3.3 =
* Login hiding is off on a fresh installation; switch it on under Security.
* The finished page goes through wp_kses with an allow-list of what the blocks output before it is printed; shortcodes run afterwards, as WordPress does.
* JSON-LD of the breadcrumbs and reviews blocks is printed in the footer through wp_print_inline_script_tag.
* Icons, the mark, the template sketches and the QR code are escaped where they are printed; inline stylesheets go through wp_strip_all_tags.
* Demo files are checked before unpacking: only JSON, images, fonts, media, PDF and text, nothing outside the folder.
* The Snippets module is not in the free plugin at all any more.
* Inputs of the template conditions, the client bar and the mail password are sanitised or validated on arrival.
* Fresh installation with WP_DEBUG: statistics table created on activation, no early translation, no unknown style dependency.
* Backups: a percent sign survives a restore.

= 0.3.2 =
* Sign-in guard: whoever keeps trying while locked out, or comes back for a third round, goes on the firewall's block list for good.
* Twenty-five short help films, one per screen, linked from the Help.
* Nothing locked: the Pro blocks, modules, template kinds and the license section are not in this plugin any more, instead of standing there locked. Pro is a separate plugin.
* Every external service is listed under "External services" with terms and privacy links.
* Early scripts and styles go through wp_print_inline_script_tag and wp_add_inline_style; JSON-LD keeps slashes escaped; the page cache closes its buffer itself; translations load on init.

= 0.3.1 =
* Text size and contrast for the client area ("Aa" in the top bar), per user.
* New versions show in the client area (dashboard stripe, Help) and lead to the WordPress updates page — not only in wp-admin.
* Support tickets and feature requests open the support portal, prefilled; no mail server needed.
* Statistics: addresses that are never counted (Settings → Speed → Statistics).
* Menus in the section library: five built menus to put in — a row with a dropdown, a mega menu across the whole width, a dark one, one centred under the name, one down a side column. A full-width mega menu now begins at the lower edge of the header.

= 0.3.0 =
* Access: per role and area, what a role sees and where it may only look — hidden, see only, or see and change; give an editor the newsletter, the shop or the users without making them an administrator.
* Menu builder: the Menu block built on the spot — entries with icons, badges and a line below; a list or a built panel (mega menu) under every entry; in a row or one under the other. Menu templates (Pro) shared by several headers.
* Backups (Pro): the whole site in one file, made now or on a plan, incremental or full, checked after every run, restored with one click; download and upload.
* Navigation folds from the first paint on phones; pictures carry their aspect ratio — no layout jump.

= 0.2.10 =
* Site fonts are preloaded: no layout jump when the font arrives.
* Accessibility styles sit in the head instead of a render-blocking file.

= 0.2.9 =
* Dragging a block wider works even against a max-width class from a demo.
* The structure panel has its own close button.

= 0.2.8 =
* A demo brings its AVIF pictures with it; the import no longer spends minutes on them.
* AVIF files are really smaller now.

= 0.2.7 =
* First release on wordpress.org: the plugin slug is ambera-theme-builder, the readme names every external service, and the free version never calls home.
* A demo imports in the free version again.

= 0.2.6 =
* Ninety-three demos in the catalogue, every one with its own skeleton and a photo up front.
* The demo list counts itself.
* An update from the dashboard stripe leaves the plugin switched on.

= 0.2.5 =
* The carousel loops for real, a slide lays out its content.
* A demo imports in a window over the page and can be cancelled.
* The plugin list says Pro or Light.

= 0.2.4 =
* Fourteen new blocks: slider, popup, off canvas, loop carousel, flip box, reviews, share buttons, video playlist, image hotspots, portfolio, sitemap and more.
* The block library opens at once.

= 0.2.3 =
* A library of 270 ready-made sections at the plus of every section — five of them menus, with a mega menu.
* Your own picture in the profile; an editor bar with room to breathe.

== Upgrade Notice ==

= 0.2.9 =
First release on wordpress.org. Existing users of the Pro version keep updating from the portal.
