=== Easy Invoice – Invoice Generator, PDF Quotes & Payments ===
Contributors: matrixaddons
Tags: invoice, pdf invoice, quotes, billing, payment gateway
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 2.4.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Invoices, quotes, PDFs and payments inside WordPress. Unlimited documents, PayPal, credit notes, statements and a REST API — free.

== Description ==

**Easy Invoice** turns your WordPress site into your invoicing system. Create invoices and quotes, send them as PDFs, take payment on the invoice page and keep every client's history in one place — with no per-document limits, no watermarks and no trial period.

It is built for freelancers, consultants, agencies and small businesses that would rather not pay a monthly fee for a separate invoicing service, and for developers who want invoicing that follows WordPress conventions: custom post types, capabilities, hooks, a REST API and coding standards.

[Live demo](https://try.new/plugins/easy-invoice/) · [Documentation](https://easy-invoice.matrixaddons.com/docs/) · [Product page & Pro pricing](https://matrixaddons.com/plugins/easy-invoice/) · [Support forum](https://wordpress.org/support/plugin/easy-invoice/)

https://www.youtube.com/watch?v=a_0BnBpl0y0

= What the free plugin does =

**Invoices and quotes**

* Unlimited invoices and quotes, with automatic numbering and your own prefix — numbers stay unique even when two people save at the same moment
* Line items with quantities, per-line or global tax, and discounts calculated before or after tax
* Convert an accepted quote into an invoice in one click; clone any document
* Credit notes against issued invoices; client statements with running balances
* Notes, terms, due dates and payment instructions per document; default terms in Settings

**PDF and print**

* PDFs are rendered on the server (real, selectable text) with your logo and business details
* Nine document designs: default, modern, classic, minimal, corporate, professional, elegant, creative and legacy
* Rename any label ("Grand Total", "Net", your language) without touching code
* Download from the admin, from the public invoice page, or through the REST API

**Getting paid**

* PayPal checkout with a Pay Now button on every invoice
* Bank transfer, cheque and cash recorded against the invoice — clients can upload proof of a transfer or cheque for you to approve
* Payment history with partial, paid and overdue states
* A custom Pay Now link for any other provider

**Clients**

* Unlimited client records with billing details and a complete per-client history
* Invoice and quote emails with the PDF attached, from templates you edit
* Every emailed link carries a private access key: a document is shown to you, to the signed-in client it belongs to, or to someone with the emailed link — never to whoever guesses a URL
* Import from Sliced Invoices or Sprout Invoices in one click, or from CSV files with downloadable templates

**Localisation**

* 121 currencies, with symbol, position, decimals and separators set per document
* Dates in the site's timezone; translation-ready (text domain `easy-invoice`)
* Multisite compatible

**For developers**

* REST API for invoices, quotes, clients and PDFs — [API reference](https://easy-invoice.matrixaddons.com/docs/api-reference)
* Migration from Sliced Invoices and Sprout Invoices built in
* Actions and filters at every step; documents are custom post types you can query
* WordPress coding standards, escaped output, prepared SQL, nonce-protected actions
* Tested with 10,000 invoices and 10,000 quotes on one site: every admin screen stays under a second

= Easy Invoice Pro: 26 addons, switch on what you need =

[Easy Invoice Pro](https://matrixaddons.com/plugins/easy-invoice/) is a separate plugin that adds addons on top of the free one. Each addon has its own on/off switch under **Easy Invoice → Addons**; an addon you leave off loads no code and runs no queries. Pro requires Easy Invoice 2.4.0 or newer.

**Personal — 16 addons, on as soon as Pro is installed (no licence key needed to use them)**

* [Recurring Invoices & Subscriptions](https://easy-invoice.matrixaddons.com/docs/recurring-invoices/) — generate and email invoices on any schedule; optional auto-charge through Stripe or PayPal
* [Partial Payments & Deposits](https://easy-invoice.matrixaddons.com/docs/addons/partial-payments/) — require a deposit, let clients pay the balance in instalments
* [Client Portal](https://easy-invoice.matrixaddons.com/docs/addons/client-portal/) — clients log in to view invoices, download PDFs, see payments and accept or decline quotes
* [PDF Toolkit](https://easy-invoice.matrixaddons.com/docs/addons/pdf-toolkit/) — watermarks (PAID, DRAFT, OVERDUE, VOID or your own), custom headers, footers, colours and fonts
* [Custom Invoice & Quote Templates](https://easy-invoice.matrixaddons.com/docs/addons/custom-templates/) — a visual builder for your own layouts
* [Item Library](https://easy-invoice.matrixaddons.com/docs/addons/item-library/) — saved products and services with price and SKU, inserted in one click
* [Bulk Email & Export](https://easy-invoice.matrixaddons.com/docs/addons/bulk-operations/) — email batches of invoices; export selected rows or everything to CSV, Excel or PDF
* [Additional Tax Lines](https://easy-invoice.matrixaddons.com/docs/addons/additional-tax/) — unlimited named taxes per invoice (VAT + duty, GST + PST, federal + state)
* [Email Enhancements](https://easy-invoice.matrixaddons.com/docs/addons/email-enhancements/) — your own HTML email layout; replies routed by kind
* [Secure Links](https://easy-invoice.matrixaddons.com/docs/addons/secure-links/) — signed, expiring document URLs
* [Payment Links & QR Codes](https://easy-invoice.matrixaddons.com/docs/addons/payment-links/) — a link or QR code for a fixed or open amount, usable anywhere
* [Quote E-Signatures](https://easy-invoice.matrixaddons.com/docs/addons/quote-signatures/) — clients sign when they accept a quote; signature, name, time and connection recorded
* [Quote Request Forms](https://easy-invoice.matrixaddons.com/docs/addons/quote-forms/) — WPForms, Gravity Forms, Contact Form 7 or Fluent Forms submissions become draft quotes
* [WooCommerce Invoicing](https://easy-invoice.matrixaddons.com/docs/addons/woocommerce/) — an invoice for every paid order; refunds become credit notes
* [Reports & Analytics](https://easy-invoice.matrixaddons.com/docs/addons/reports/) — revenue, outstanding balances, per-client performance, month-by-month profit and loss
* [Privacy & GDPR](https://easy-invoice.matrixaddons.com/docs/addons/privacy-tools/) — client documents included in WordPress personal-data export and erasure requests

**Pro payment gateways** (alongside the free PayPal, bank transfer, cheque and cash): Stripe (cards, Apple Pay, Google Pay, Link, 3-D Secure), Square, Authorize.Net, Mollie (SEPA, iDEAL, Bancontact, Klarna), Paystack (cards, bank transfer, USSD, mobile money) and Moneris.

**Professional — 6 more addons, with a Professional licence**

* [Time Tracking & Project Billing](https://easy-invoice.matrixaddons.com/docs/addons/time-tracking/) — start/stop timer, per-project and per-client entries, one click to invoice lines
* [Expense Tracking](https://easy-invoice.matrixaddons.com/docs/addons/expense-tracking/) — billable expenses with receipts and markup, rolled into invoices
* [Smart Reminders & Late Fees](https://easy-invoice.matrixaddons.com/docs/addons/smart-reminders/) — a multi-step reminder cadence, automatic late fees and early-payment discounts
* [E-Invoicing](https://easy-invoice.matrixaddons.com/docs/addons/e-invoicing/) — Factur-X / ZUGFeRD (EN 16931) PDFs and Peppol UBL for public-sector and EU customers
* [Client Language](https://easy-invoice.matrixaddons.com/docs/addons/client-language/) — every document for a client, page, PDF and email, produced in the client's language
* [Retainers & Prepaid Credit](https://easy-invoice.matrixaddons.com/docs/addons/retainers/) — record a block of hours or a prepayment and draw it down invoice by invoice

**Agency — 4 more addons, with an Agency licence**

* [White-Label & Brand Override](https://easy-invoice.matrixaddons.com/docs/addons/white-label/) — your name, menu, icon, PDF footer and email signature; every upgrade prompt hidden
* [Team Members & Audit Log](https://easy-invoice.matrixaddons.com/docs/addons/team-roles/) — Manager, Accountant, Sales and Viewer roles, and a searchable log of every action
* [Accounting Sync](https://easy-invoice.matrixaddons.com/docs/addons/accounting-sync/) — QuickBooks Online, Xero and FreshBooks: invoices push out, payment status comes back
* [Webhooks & Zapier](https://easy-invoice.matrixaddons.com/docs/addons/webhooks/) — invoice events to any URL, HMAC-signed with retries; drops into Zapier, Make or n8n

[See plans and pricing](https://matrixaddons.com/plugins/easy-invoice/#pricing) — every Pro plan has a 14-day money-back guarantee. Upgrading keeps every invoice, quote, client and payment the free plugin created.

= Who uses Easy Invoice =

* **Freelancers** — quote, invoice and collect payment from one screen
* **Agencies and studios** — per-client history, statements, deposits and a client portal
* **Shops and B2B sellers** — proper invoices for WooCommerce orders and everything the cart can't bill
* **Consultants and service firms** — billed hours, expenses, retainers and e-invoices for larger customers

= Privacy =

Easy Invoice stores everything in your own WordPress database and sends nothing to us. The plugin contacts outside services only when you use them: the payment gateway you configure (PayPal in the free plugin), and the WordPress.org update check that every plugin performs. Card details never touch your site — they are handled by the gateway. With the Pro Privacy & GDPR addon, a client's invoices, quotes and payments are included in WordPress's personal-data export and erasure requests.

= Translations =

Easy Invoice is translation-ready (text domain `easy-invoice`, `.pot` in `/languages`). Translate it with Loco Translate, Poedit or on [translate.wordpress.org](https://translate.wordpress.org/projects/wp-plugins/easy-invoice/).

== Installation ==

1. In your WordPress admin go to **Plugins → Add New**, search for "Easy Invoice", click **Install Now**, then **Activate**. (Or upload the zip under **Plugins → Add New → Upload Plugin**.)
2. Open **Easy Invoice → Settings** and enter your business name, address, logo, currency and default terms.
3. Under **Settings → Payments**, connect PayPal and/or enable bank transfer, cheque and cash.
4. Go to **Easy Invoice → Clients** and add a client, then **Easy Invoice → Invoices → Add New** to create your first invoice. Send it from the invoice screen; the client receives an email with the PDF and a private link.

**Requirements:** WordPress 6.0 or newer, PHP 7.4 or newer. Any properly coded theme or page builder.

**Easy Invoice Pro:** install the Pro plugin from your purchase email next to the free one, then switch on the addons you want under **Easy Invoice → Addons**. Pro needs Easy Invoice 2.4.0 or newer.

== Frequently Asked Questions ==

= Is the free plugin limited in any way? =

No. Unlimited invoices, quotes, clients and PDFs, with no watermark and no time limit. Pro adds optional addons; it does not unlock things the free plugin holds back.

= Which payment methods can clients use? =

Free: PayPal, plus bank transfer, cheque and cash recorded against the invoice (clients can upload proof for you to approve). Pro adds Stripe, Square, Authorize.Net, Mollie, Paystack and Moneris. You can also put any provider's payment link on the invoice.

= Are there transaction fees? =

None from Easy Invoice. Your payment gateway charges its own fees.

= Can clients pay in instalments, or pay a deposit first? =

Yes, with the Partial Payments & Deposits addon (Pro, Personal tier).

= Can I set up recurring invoices? =

Yes, with the Recurring Invoices & Subscriptions addon (Pro, Personal tier): invoices are generated and emailed on the schedule you set, with optional automatic charging through Stripe or PayPal.

= Can I customise the invoice design? =

The free plugin ships nine designs and lets you add your logo, business details, colours and renamed labels. The Pro PDF Toolkit adds watermarks, headers and footers; the Custom Templates addon adds a visual layout builder.

= Can I issue a credit note or a statement? =

Yes, both are in the free plugin: credit notes are issued against a paid or partly paid invoice from the invoice screen, and a client statement (with running balance) is available from the client record.

= Are invoice links safe to email? =

Yes. Since 2.4.0 every invoice and quote link carries a per-document access key. A document is shown only to you, to the signed-in client it belongs to, or to someone opening the emailed link — never to anyone who guesses a URL. Links sent before 2.4.0 show a page that offers to email a fresh link to the address the document was issued to.

= I see "Page not found" when opening an invoice. =

Go to **Settings → Permalinks** and click **Save Changes** once — this refreshes WordPress's URL rules. If you use a caching plugin, clear its cache.

= Can I import data from another invoicing plugin or a spreadsheet? =

Yes. **Easy Invoice → Import** migrates directly from Sliced Invoices and Sprout Invoices (with a dry-run count first), and accepts CSV files of clients and invoices — download the CSV templates from the same screen. Exporting to CSV, Excel or PDF is part of the Pro Bulk Email & Export addon.

= Does it work with WooCommerce? =

The free plugin runs alongside WooCommerce without conflict. The Pro WooCommerce Invoicing addon creates an Easy Invoice invoice for every paid order and turns refunds into credit notes.

= Does it work on multisite? =

Yes. Each site keeps its own invoices, clients and settings.

= Is there a REST API? =

Yes — invoices, quotes, clients and PDFs, authenticated with WordPress application passwords. See the [API reference](https://easy-invoice.matrixaddons.com/docs/api-reference).

= How does the Pro addon system work? =

Pro is one plugin containing 26 addons. Under **Easy Invoice → Addons** you switch each one on or off. The 16 Personal addons work as soon as Pro is installed; Professional and Agency addons need a licence of that tier. An addon you leave off loads no code.

= What if I update Pro before the free plugin? =

Pro 2.3.0 needs Easy Invoice 2.4.0. If Pro is updated first it stays inactive with a notice until the free plugin is updated, and the secure links your clients already hold keep working meanwhile.

= What happens to my data if I stop paying for Pro? =

Nothing is deleted. Personal addons keep working; Professional and Agency addons pause until the licence is renewed. Every document stays in your database and the free plugin continues to work with it.

= How do I report a security issue? =

Please do not open a public forum thread. Report it through the [Patchstack Vulnerability Disclosure Program](https://patchstack.com/database/vdp/8b8da081-d07d-4239-b795-0f0895d186dd), which validates reports and coordinates the fix with us, or use the [contact form](https://matrixaddons.com/contact/).

= Where do I get help? =

The [documentation](https://easy-invoice.matrixaddons.com/docs/) covers setup and every addon. Free users: the [WordPress.org support forum](https://wordpress.org/support/plugin/easy-invoice/). Pro customers: priority support from the [account area](https://store.mantrabrain.com/).

== Screenshots ==

1. Dashboard — outstanding, paid and overdue at a glance, monthly revenue and recent invoices
2. Invoices — filters by status, search, bulk actions and pagination that stays fast with thousands of documents
3. Invoice builder — client, line items, taxes and discounts with a live preview of the chosen design
4. Public invoice page — what the client sees from the emailed link, with the Pay Now button
5. Quotes — status filters, conversion to invoice, expiry tracking
6. Quote builder — the same editor, with expiry date and acceptance flow
7. Payments — every payment with method, status and the invoice it settles
8. Clients — records with contact details, document counts and balances
9. Settings — business details, logo, currency, taxes, email templates and payment methods

== Changelog ==
= 2.4.1 - September 15, 2026 =
* Fix: on phones the public invoice and quote pages clipped the line-item table's Total column and, in the Modern, Creative and Professional designs, the totals box; every design now fits a 360px screen (narrower screens scroll the table sideways).
* Performance: the payment script (and the jQuery it needs) loaded on every front-end page of the site; it now loads on the public invoice page only. Filter `easy_invoice_load_payment_assets` to add pages.
* Housekeeping: the changelog in this file now summarises each release; the complete, itemised history lives in changelog.txt inside the plugin folder and on GitHub.

= 2.4.0 - September 11, 2026 =
A large release; read the upgrade notice before updating. The full, itemised list (about 190 entries) is in changelog.txt.

**Security**
* Invoices and quotes were readable, and enumerable, by anyone with the URL, including drafts. Every document now needs a per-document access key (`?ik=` / `?qk=`) carried by emailed links, a signed-in client, or an admin. Links emailed before keys existed show a page offering to email a fresh keyed link to the address the document was issued to; nothing is shown and drafts are never offered.
* Payment endpoints, PDF-download nonces, the payment callback, proof-of-payment file names and the migration "skip" link all authorise properly; Pro card gateways no longer bypass the authorisation check. Stored XSS through a client's profile into the builders fixed. Every output is escaped at the point it is printed; all redirects go through `wp_safe_redirect`.

**New**
* Server-side PDF rendering (dompdf, now bundled): real, text-based PDFs in every design, A4 / Letter / Legal, optional PDF attachment on invoice emails, page numbers on multi-page documents.
* Credit notes against issued invoices, statements of account per client, and issued invoices can no longer be deleted permanently (trash still works).
* REST API at `easy-invoice/v1` (invoices, quotes, clients, PDF download), authenticated and capability-checked; responses never expose access keys.
* Cross-border tax: reverse charge and export handling, VAT identifiers for both parties with VIES checking, EN 16931 tax categories.
* Import from Sliced Invoices, Sprout Invoices and CSV. Attachments from the media library on invoices and quotes. Client-view tracking (first and latest view, count). Convert-to-invoice on each quote row. Clients search box. Uninstall routine that keeps your data unless told otherwise.
* New hooks and filters for addons: `easy_invoice_quote_total`, `easy_invoice_presented_access_token`, `easy_invoice_reports_after_summary`, `easy_invoice_email_headers`, `easy_invoice_client_view_after_details`, `easy_invoice_credit_note_actions`, `easy_invoice_text_setting` and others.

**Documents and designs**
* Every invoice and quote design reset and tidied; the public page is a real WordPress page laid out as an A4 sheet, themeable from `{theme}/easy-invoice/`. "Total Due" in every header; Credit note / Paid / Balance due rows once anything is paid; the "To" block names the contact, phone and VAT number; totals rows read in calculation order; the Legacy design prints Terms & Conditions; Minimal quote markup fixed.
* Stock emails rewritten as plain business correspondence; receipts and payment notices correct for partial payments; "Test Template" works; emails sign off with the business name.

**Fixes (selection)**
* Correctness: duplicate invoice, quote and credit-note numbers under concurrent use; negative totals from oversized discounts; line amounts that did not add up to the subtotal; dates defaulting to UTC instead of the site's timezone; taxable state of new lines; "Apply Tax" that could not be switched off; quotes that never expired; acceptance and decline details never saved; quote conversion producing empty lines; customer details dropped on save; attachments that could not be removed.
* Payments: overdue and part-paid invoices could not be paid from their page; a part-paid or credited invoice asked for the full amount again; PayPal IPN left invoices unpaid; bank transfer, cheque and cash from emailed links were refused; "Add New Payment" could not record a payment; trashing or restoring payments left the invoice status untouched; failed or refunded payments put issued invoices back to Draft.
* Admin: team members could not open any screen; the admin was unusable on phones; Dashboard Edit/View links, the invoice list status filter, Reports totals and date ranges, the "Delete client only" option (it deleted the documents), settings image fields, colours that never rendered, sideways-scrolling lists, keyboard and touch access to row actions, about 140 untranslatable strings.
* Performance: invoice totals are stored (dashboard, lists, reports and statements no longer rebuild every model); admin screens that took 30–40 s on a few thousand invoices open in under a second; the Overdue filter, Add Payment picker and payments totals answered from single queries (10,000-invoice stores: 19 s → 3 s); rewrite rules no longer flushed on every request; the admin loads 47 KB of CSS instead of 2.8 MB.
* Packaging: all CDN assets (jsPDF, html2canvas, Chart.js, Select2) bundled; Composer dependencies resolved for PHP 7.4; dead classes, duplicate AJAX registrations and an endpoint that fataled removed; addon descriptions corrected to what is actually implemented.

= 2.3.8 - August 21, 2026 =
* Compatibility - **Tested and confirmed compatible with WordPress 7.1.** "Tested up to" bumped from 7.0. The release was audited against the 7.1 codebase rather than smoke-tested: every WordPress function the plugin calls was resolved against the 7.1 symbol table (no removed or renamed API is used), the plugin's global function, class and constant names were diffed against the 92 functions and 5 classes 7.1 introduces (no redeclaration collisions), and the full plugin tree was scanned with PHPCompatibility for PHP 7.4 through 8.4 (zero issues).
* Compatibility - **jQuery UI 1.14.2** ships in WordPress 7.1 (up from 1.13.3). The payment-gateway drag-to-reorder list on Settings -> Payment uses `.sortable()` and `.disableSelection()`; both remain available because core enables `jQuery.uiBackCompat` and still bundles the disable-selection module. The four APIs 1.14 removed (`$.fn._form`, `$.ui.ie`, `$.ui.safeActiveElement`, `$.ui.safeBlur`) are not used anywhere in the plugin.
* Compatibility - **The enforced iframed post editor in 7.1 does not affect Easy Invoice.** Invoices and quotes are edited through the plugin's own admin screens; their post types register with `show_ui => false` and the one UI-visible post type does not declare `editor` support, so no plugin JavaScript or CSS reaches across the editor document boundary.
* Compatibility - Admin styling verified against 7.1 markup: the `#adminmenu`, `#adminmenuwrap`, `#adminmenuback`, `#wpcontent`, `#wpbody-content` and `#wpfooter` containers the plugin restyles are all still emitted by `wp-admin/admin-header.php` and `menu-header.php` in 7.1, and the persistent admin toolbar change touches `#wpadminbar`, which the plugin does not style.
* Compatibility - The REST and media changes in 7.1 (image dimension validation on the sideload endpoint, size-aware encoding quality in attachment responses) are not applicable: the plugin's REST routes are its own (no media, sideload or attachment endpoints) and it calls no attachment or sideload APIs.
* Fixed - **Payment-gateway drag-to-reorder relied on incidental script ordering.** The `easy-invoice-settings` script handle is registered in two different places, and WordPress keeps whichever registration runs first while silently discarding the other's dependency array. The registration that wins did not list `jquery-ui-sortable`, so `settings.js` was printed ahead of jQuery UI Sortable and only worked because its code runs inside a DOM-ready callback. The jQuery UI handles are now declared explicitly on that registration, so `wp_scripts` resolves the load order instead of it falling out of enqueue sequence - worth tightening now that 7.1 ships a new jQuery UI build.

= 2.3.7 - June 29, 2026 =
* Fixed - **Invoice and Quote listing "Download PDF" button** could leave the user stranded on a blank `admin-ajax.php?action=easy_invoice_generate_pdf...` page instead of downloading the PDF. Root causes on affected sites included page-cache layers (WP Rocket, LiteSpeed, Cloudflare) replaying stale responses of the intermediate admin-ajax URL, security plugins / WAFs stripping the redirect body, and cross-tab session-cookie behaviour (Safari ITP, `SameSite=Strict`) dropping the WP session between the click and the new tab. Two coordinated changes address this:
  1. **The button no longer routes through admin-ajax.** The anchor's native href already points directly at `<invoice-permalink>?auto_download_pdf=1`, and the single-page JS renders the PDF from there. Removing the click interceptor collapses three server round-trips into one and sidesteps every intermediate-hop failure mode. No security posture change — the destination is the same public permalink the hop was going to anyway.
  2. **The server-side download handlers are hardened for any external caller.** `generateInvoicePdf` and `generateQuotePdf` now accept an admin session or a valid per-document access key (`?ik=` / `?qk=`) as alternate authorisation paths when the per-request nonce fails, emit explicit `Cache-Control: no-store` headers to defeat intermediate caching, and fall back to a client-side redirect (`<meta refresh>` + `window.location.replace`) when the server-side redirect can't fire because upstream output already flushed the response headers. Email download links, dashboard widgets, and any other integration calling these endpoints directly benefit from the same hardening.

= 2.3.6 - June 26, 2026 =
* Security - Tightened the capability check on the AJAX payment-update endpoint so only users with the dedicated payment-management permission can change payment records or invoice status. **All sites should update.**
* Security - The `[easy_invoice_url]` and `[easy_quote_url]` shortcodes no longer generate per-document access keys for arbitrary visitors. Keys are now produced only when an invoice or quote email is sent; the shortcodes attach an existing key only when the current viewer is the site admin, the bound client, or already holds the key in the page URL.
* Fixed - The bound-client authorisation path on quote Accept / Decline and invoice manual-payment submission silently never succeeded for logged-in customers. The guard relied on PHP's `method_exists()` which returns false for `__call`-resolved methods, and both the Invoice and Quote models resolve `getClientId()` that way. Logged-in clients whose email matches the document's bound client are now correctly recognised. (Admin and emailed-link paths were unaffected.)
* Note - Emailed `{{invoice_url}}` and `{{quote_url}}` links continue to work unchanged for the legitimate recipient. The shortcode change is invisible for admin embeds on admin-context pages; on public pages the shortcode now renders a plain permalink for visitors who don't already hold a valid key (they can still view the document — only the Accept / Decline / submit-manual-payment paths require the key).

= 2.3.5 - June 26, 2026 =
* Security - Hardened authorisation on the manual-payment submission flow. **All sites should update.**
* Improved - Invoice share links emailed to clients (`{{invoice_url}}` in email templates, `[easy_invoice_url]` shortcode) now carry a per-invoice access key. Recipients of these links can submit "I paid by bank transfer / cheque" entries as before — no extra steps for the customer.
* Note - Invoice links generated **before** this update will still load and display the invoice and accept online gateway payments (Stripe / PayPal / etc.). The manual-payment submission form appears only after the admin resends the invoice (which produces a new link) or after the client logs in to the WordPress account whose email matches the invoice's bound client. Admins are unaffected — the form is always available from the admin UI.
* Fixed - Race condition under high concurrency where two simultaneous invoice (or quote) creates could be assigned the same number. The counter read-check-write is now serialised via a MySQL named lock; the lock auto-releases on connection close so it cannot leak across requests.
* Added - License recognition for the new Professional Lifetime and Agency Lifetime SKUs so customers on those plans are correctly placed in their tier and see the matching variant label on the License page.

Older releases (2.3.4 back to 1.0) are listed in changelog.txt inside the plugin folder and at https://github.com/matrixaddons/easy-invoice/blob/master/changelog.txt.

== Upgrade Notice ==

= 2.4.1 =
Small follow-up to 2.4.0: public documents fit phone screens in every design, and the payment script no longer loads on every front-end page. If you are coming from 2.3.x, read the 2.4.0 notice below and back up first.

= 2.4.0 =
Large release: invoice and quote links now need a per-document access key (old links get a page offering a fresh one); issued invoices can only be trashed; PDFs render on the server; public pages are real WordPress pages (theme overrides: {theme}/easy-invoice/). Update Pro to 2.3.0. Back up first.

= 2.3.9 =
Security release: invoices and quotes were readable and enumerable by anyone with a URL; access is now checked before anything is rendered. Update as soon as possible.

= 2.3.8 =
WordPress 7.1 compatibility release. Verified against the 7.1 codebase and PHP 7.4-8.4, plus a fix for payment-gateway drag-to-reorder script ordering on the Settings screen.

= 2.1.9 =
Important update fixing vendor dependencies. Recommended for all users.

= 2.0.0 =
Major version update with significant improvements. If upgrading from 1.x, please backup your site and run the migration tool when prompted.
