=== Aurora Membership Manager ===
Contributors: autoranoor
Tags: membership, membership-management, member-management, associations, clubs
Requires at least: 6.2
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.3.2
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Manage members, renewals, expiries, imports, privacy and a secure member portal for associations and clubs directly in WordPress.

== Description ==

Aurora Membership Manager is a free, self-contained membership management plugin built for associations, clubs, nonprofit organizations and other membership-based groups that want to manage members directly inside WordPress.

The Core plugin works without an Aurora account, license key or external service. Member data stays in the site's WordPress database, and Core updates are delivered only through WordPress.org.

= What Core includes =

* Member records with contact details, status, reference numbers and expiry dates.
* Configurable rolling or annual membership validity, including a selectable next-membership-year sales cutover for annual expiries.
* Renewal overview for active, expiring and expired members.
* Member search and a mobile-friendly staff workspace.
* Secure Aurora Admin API with one-time device pairing and revocable credentials.
* CSV import and export with spreadsheet-formula protection.
* Secure member portal with opaque, expiring email access links.
* Member profile and privacy-consent management.
* WordPress personal-data exporter and eraser integration.
* Backup, restore, reconciliation, diagnostics and audit tools owned by Core.
* Stable hooks and APIs for separately installed extensions.

= Built for organizations that want to keep control =

Aurora runs inside WordPress rather than moving your membership database to a separate closed platform. Core can be used on its own and does not require WooCommerce, a digital-card provider or a commercial Aurora license.

= Optional extensions =

Core remains fully usable without paid extensions. Separate add-on plugins are available when an organization needs additional workflows:

* **Membership Manager Pro** — communications, campaigns, events, member benefits and advanced operational tools.
* **Membership Manager Commerce** — WooCommerce membership products, order-to-member workflows and renewals.
* **Membership Manager Digital Cards** — Passcreator-based digital membership cards and wallet delivery workflows.

Aurora can also support **organization-specific extensions** for workflows that do not belong in Core or in a standard add-on. These separately installed extensions can combine reusable Aurora capabilities with rules, labels, mappings, templates or integrations tailored to one organization.

For example, an organization may need different digital-card templates according to age, membership type or role, or may have its own membership categories and operational workflow. Aurora keeps reusable capabilities generic while organization-specific behavior remains isolated in a separate extension rather than creating a fork of Core.

During the 2026 launch period, eligible associations and membership organizations can request no-cost access to the standard separately distributed add-ons until **31 December 2026**. [Early Adopter 2026 programme details](https://www.aurora-noor.com/early-adopter-2026/)

[Explore optional extensions and regular pricing](https://www.aurora-noor.com/pricing/) or [contact Aurora about an organization-specific extension](https://www.aurora-noor.com/support/).

Standard and organization-specific extensions are separate plugins with their own code, configuration, licensing, external-service disclosures and update channels. They are not included in or unlocked by this WordPress.org package.

= Documentation and support =

* [Aurora documentation](https://www.aurora-noor.com/documentation/)
* For Core support, use the support forum available from this plugin's WordPress.org page.

== Installation ==

1. Install and activate Aurora Membership Manager from WordPress.org.
2. Open **Membership Manager > Initial configuration**.
3. Enter the organization name and choose the membership validity rule.
4. Add members manually or import a CSV file.
5. Optionally create a member portal page from **Membership Manager > Settings > Member portal**.

No license key is required for the Core plugin.

== Screenshots ==

1. Membership overview with total, active, expiring and expired member counts, renewal shortcuts and Core management tools.
2. Searchable member list with membership status, expiry dates and CSV export.
3. Renewal dashboard for tracking upcoming expiries, expired memberships and renewal segments.
4. Member profile with contact details, membership status, expiry information and privacy preferences.
5. Secure member self-service portal with membership status, profile details and privacy controls.
6. Core administration tools for imports, exports, backups, privacy, system checks and security.

== Frequently Asked Questions ==

= Is Aurora Membership Manager really free? =

Yes. Core is free and fully usable without a trial period, Aurora account or license key. Optional extensions are separate plugins.

= Does Core require WooCommerce? =

No. Core works independently. WooCommerce is only needed if you separately install an extension that integrates WooCommerce workflows.

= Does Core require a digital-card provider? =

No. Digital-card providers are optional and are implemented by separate extensions.

= Can Aurora be adapted to our organization? =

Yes. Aurora exposes stable hooks and APIs so separately installed extensions can add organization-specific rules, mappings, integrations or workflows without modifying Core. Tailored extensions are separate from the free WordPress.org package and are evaluated according to the requested scope.

= Does Aurora Admin need my WordPress password? =

No. Core can generate a short-lived, one-time pairing challenge for a compatible Aurora Admin client. The resulting device credential is revocable and limited to Aurora's own mobile REST namespace and to the permissions of the WordPress user who paired it.

= Does the plugin contact Aurora automatically? =

No. The WordPress.org Core build does not contact Aurora, perform license checks or download executable code from external servers.

= Where is member data stored? =

Member records, profile metadata and Core audit records are stored in tables in the local WordPress database. Core settings are stored as WordPress options.

= Can members access their own information? =

Yes. Core includes an optional member portal that can send expiring access links through the site's configured WordPress mail system. Site administrators control whether and how the portal is used.

= What happens when I uninstall the plugin? =

By default, membership data is preserved. Mobile device credentials are security state and are removed when Core is uninstalled. If **Delete Core data when Core is uninstalled** is enabled first, the uninstaller also removes Core-owned tables, options, files and roles. Data owned by separate extensions is never deleted by Core.

== Privacy ==

Aurora Membership Manager can store member names, email addresses, membership status, expiry dates, profile details, consent choices and administrator audit events in the local WordPress database.

The public member portal can send an access email through the site's configured WordPress mail system. Access links use opaque, expiring tokens. The plugin integrates with WordPress personal-data export and erasure tools.

When an administrator pairs a compatible Aurora Admin client, Core can store device identification metadata, granted scopes and usage timestamps. The bearer-token secret itself is not stored in plaintext; Core stores a cryptographic hash used to validate the presented credential. Device credentials can be revoked from WordPress.

Site administrators are responsible for choosing an appropriate legal basis, retention period and privacy notice for their organization. Installing this plugin does not by itself make a site compliant with any privacy law.

== External services ==

Aurora Membership Manager does not require or automatically contact an external service.

Separately installed extensions may use their own external services. Those extensions must disclose their behavior, transmitted data, terms and privacy policy in their own documentation.

== Changelog ==

= 1.3.2 =
* Exposes the existing fixed-annual-expiry rollover policy in Initial configuration so an organization can choose the month from which new memberships and renewals use the next membership year.
* Keeps the Core expiry engine as the single source of truth; no WooCommerce-specific expiry calculation or database schema change is introduced.
* Preserves existing installations and defaults: annual memberships continue to roll to the next year from the configured threshold, with October as the historical default when the option has never been explicitly changed.

= 1.3.1 =
* Fixes an early-load mobile bearer-authentication route check that could call WordPress REST URL helpers before rewrite initialization and fatally interrupt unrelated REST requests.
* Keeps Aurora Admin bearer authentication restricted to the `aurora-mobile/v1` namespace while allowing unrelated REST endpoints to operate normally during early WordPress bootstrap.
* Restores compatibility for sites that run Core alongside independent REST services such as the Aurora License Server; no database schema or Core add-on API contract change.

= 1.3.0 =
* Adds the native Aurora Admin REST API to Core for secure direct administration from compatible mobile clients.
* Adds short-lived, one-time pairing challenges and revocable device credentials without storing WordPress passwords or plaintext bearer-token secrets.
* Restricts device authentication to Aurora's own mobile REST namespace and rechecks the paired WordPress user's capabilities for every request.
* Adds mobile member list, search and detail endpoints plus controlled member updates through the canonical Core repository, including supported profile and consent fields.
* Protects integration-owned member identity fields from mobile editing and keeps existing Core validation, expiry and consent rules authoritative.
* Adds paired-device management to the existing Core Admin App workspace.
* Adds a controlled extension surface so separately installed add-ons can expose their own Aurora Admin capabilities and protected routes without being bundled into Core.
* Corrects a translation-context annotation in the CSV import error path identified by Plugin Check.
* No database schema change; the existing Core add-on API contract remains 2.0.0.

= 1.2.8 =
* Documents organization-specific extensions as a supported way to add tailored rules and workflows without forking Core.
* Adds one contextual extension-discovery panel to the **Extensions** screen with links to optional extensions and tailored-extension support.
* Keeps commercial discovery limited to the Extensions screen: no global promotional notices, dashboard advertising, remote promotional assets, tracking or locked Core controls.
* No database schema or public API contract changes.

= 1.2.7 =
* Fix checkbox and radio sizing in the member editor.
* Improve WordPress.org discovery tags and screenshot captions.
* Confirm compatibility with WordPress 7.1 after final-release testing.
* Clarifies that a saved renewal fee and currency are manual dashboard assumptions, while installed extensions may supply both values only when the fee is left blank.
* Fix final CSV import button remaining disabled when valid rows are ready.
* Prevent immediate import and backup-restore lock refreshes from being misreported as lost when their expiry value is unchanged within the same second.
* Keep a retained CSV preview visible and renew its retry window when a recoverable final-import error occurs.
* Keep member-bound portal tokens restricted to their original member identities.
* Preserve extension-defined consent keys when Core consent fields are updated.
* Report partial CSV write failures instead of treating them as skipped successful completion.
* Fix the renewal onboarding completion condition.
* Clean up Core schema/lock state completely when data deletion is requested on uninstall.

= 1.2.6 =
* Refreshes the WordPress.org presentation, documentation and screenshot captions, and adds one public link to information about optional extensions. No runtime, API or database schema changes.

= 1.2.5 =
* Removes promotional/storefront content from the WordPress administration while preserving the operational extension inventory and existing add-on hooks; no API or database schema changes.

= 1.2.4 =
* Completes the WordPress.org review hardening by fixing translator annotations for backup/restore notices; no functional API or database schema changes.

= 1.2.3 =
* Hardened Plugin Check handling for read-only backup/restore status notices; no functional API or schema changes.

= 1.2.2 =
* Hardened request/upload handling for WordPress.org review while preserving Core/add-on contracts.
* Normalized admin notice inputs and documented read-only request parameters for static analysis.

= 1.2.1 =
* Aligns the WordPress.org text domain with the approved aurora-membership-manager slug.
* Hardens Basic Setup upload hand-off so extension callbacks receive only explicitly registered and validated upload metadata, never the raw PHP upload superglobal.
* Completes the review audit for request nonces, permissions and early input sanitization while preserving the Core 2.0.0 API contract.
* Keeps Core free of commercial licensing and external update delivery; commercial add-ons remain separate plugins.

= 1.2.0 =
* Introduces collision-resistant `Aurora_MMC` and `aurora_mmc` prefixes across Core APIs, hooks, options, capabilities, routes and interface identifiers.
* Adds a conservative one-time migration for legacy Core tables, options and role capabilities while preserving existing add-on data.
* Uses identifier placeholders for dynamic database table names on supported WordPress versions.
* Removes inline administration JavaScript and strengthens direct output escaping.
* Preserves legacy public shortcodes as compatibility aliases.
* Publishes Core API contract 2.0.0 for the coordinated add-on releases.

== Upgrade Notice ==

= 1.3.2 =
Adds a configurable month for switching fixed annual memberships to the next membership year, using the existing Core expiry engine and without a database schema or public API contract change.

= 1.3.1 =
Prevents an early mobile-auth REST route check from interrupting unrelated REST services during WordPress bootstrap. No database schema or public API contract change.

= 1.3.0 =
Adds the native secure Aurora Admin mobile API, revocable device pairing, member read/write operations through Core rules and a controlled mobile extension surface. No database schema change.

= 1.2.8 =
Documents organization-specific extensions and adds a restrained, contextual discovery panel to the Extensions screen. No database schema or public API contract changes.

= 1.2.7 =
Fixes CSV import completion, lock handling, portal-token authorization, consent preservation, member-editor checkbox sizing and related reliability issues, and refreshes WordPress.org presentation. No database schema or public API contract change.

= 1.2.6 =
Documentation and WordPress.org presentation update only. No database or API changes.