=== Gatekeepr – Password Protect for Post Types ===
Contributors: mbilalkk
Tags: password protect, restrict content, content protection, access control, custom post type
Requires at least: 6.0
Tested up to: 7.0
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Password protect the single/detail pages of any post type behind a shared or per-post-type password, with a clean, modern unlock screen.

== Description ==

Gatekeepr lets you require a password before visitors can view the single/detail page of any post type — Posts, Pages, or any custom post type registered by your theme or another plugin.

Unlike WordPress's built-in per-post password protection, this plugin protects an entire post type at once from a single settings screen — with either one shared password for everything, or an individual password per post type.

= Features =

* Choose exactly which post types are protected — every public post type is listed with a toggle, including custom post types.
* Two password modes: one shared password for everything, or an individual password per protected post type.
* Visitors who enter the correct password stay unlocked for a configurable number of days (cookie-based), instead of being asked every visit.
* Changing a password immediately invalidates every visitor's existing unlock for it — no manual cleanup needed.
* Logged-in users who can edit a given post always see it directly, so editing and previewing is never blocked.
* Clean, standalone unlock screen that doesn't depend on your active theme, so it renders consistently even on page-builder sites.
* Customize the unlock screen: background color, accent color, an uploaded logo, and an optional secondary button (e.g. "Contact us") linking anywhere you choose.
* Built-in brute-force throttling on the password form.
* The REST API and RSS/Atom feeds are gated too, so protected content isn't readable through either while locked.
* Protected post types are automatically excluded from XML sitemaps (core WordPress sitemaps, Yoast SEO, and Rank Math), so they aren't advertised to search engines.
* A small "Protected" indicator appears in the post list table for any post type that's currently gated, so editors can see it at a glance.
* Compatible with full-page caching plugins — protected pages are automatically excluded from the page cache so one visitor's session is never served to another.
* No external requests, no tracking, no bundled third-party services.

Development happens in the open on GitHub: https://github.com/bilalkk9/post-type-password-protect

= A note on the "current password" display =

The Gatekeepr settings screen can show you the current password (hidden by default, behind a "Show" toggle) so you don't need to reset it if you've forgotten it. To make this possible, the password is stored in an encrypted, recoverable form rather than only as a one-way hash. If your workflow requires a password that can never be viewed after saving, simply treat the field as write-only and don't use the "Show" toggle — the underlying visitor-facing verification always uses a one-way hash regardless.

== Installation ==

1. Upload the plugin files to the `/wp-content/plugins/gatekeepr` directory, or install the plugin directly through the WordPress "Plugins → Add New" screen.
2. Activate the plugin through the "Plugins" screen in WordPress.
3. Go to Settings → Password Protect.
4. Check the post types you want to protect, set a password, and click "Update Password".

== Frequently Asked Questions ==

= Does this replace WordPress's built-in post password feature? =

No. WordPress's native feature protects one post at a time with a password you set per-post. This plugin instead protects every single/detail page of a chosen post type at once, from a single settings screen — with a shared password across all protected types, or a separate password for each one.

= Will search engines index my protected pages? =

No. While a page is locked, the unlock screen is served with a `noindex` directive instead of the real content.

= What happens if I change the password? =

Every visitor who was previously unlocked will be asked for the password again on their next visit. This happens automatically — there is nothing to clear manually.

= Does this work with page builders like Elementor? =

Yes. The gate runs before the page is rendered, so it works regardless of how the page itself was built.

= Does this affect the REST API or RSS feeds? =

Protected, locked posts have their content and excerpt redacted in both the REST API and RSS/Atom feed output, so the underlying content isn't exposed through those either.

== Screenshots ==

1. Choose which post types are protected, with a clear toggle for each.
2. Appearance settings — background color, accent color, logo, and secondary button.
3. Individual password mode — give each protected post type its own password.
4. The front-end unlock screen shown to visitors.
5. The Gatekeepr settings screen — password mode, password field, and unlock duration.
6. A "Protected" indicator column on the Posts list, showing which posts are gated.

== Changelog ==

= 1.0.0 =
* Initial release.
