=== GatewayKit – Simple Payment Form, Donation & Checkout ===
Contributors: pourmirzai
Tags: payment-form, donation, stripe-checkout, crypto-payment, elementor
Requires at least: 6.2
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.5.2
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Accept payments and donations with 9 free gateways (Stripe, PayPal, Crypto). Fast checkout forms with zero platform fees and no WooCommerce bloat.

== Description ==

### Turn any WordPress page into a high-converting payment or donation form in 2 minutes.

If you sell a single product, accept donations, send client invoices, or charge event booking fees, you don't need a heavy online store. You just need a fast, dependable payment form.

**GatewayKit** is the payment form and donation builder for WordPress: create custom checkout forms, accept donations, or connect Elementor forms to secure payment processors. **No WooCommerce, no shopping cart, no 2%–3% platform fees, and no e-commerce bloat.**

Set up in minutes using our visual drag-and-drop form builder, native Gutenberg block, or shortcodes. Every payment is tracked in a centralized WordPress dashboard, and professional PDF receipts and tax invoices are emailed to your customers automatically.

**Who it's for:** Freelancers, consultants, small businesses, nonprofits, course creators, event organizers, and web agencies building client sites.

**Try the live demo:** See GatewayKit in action — [wp-test.pourmirzai.com](https://wp-test.pourmirzai.com/).

**Translations:** Available in English, Spanish, French, German, Brazilian Portuguese, and Arabic.

**Requirements:** WordPress 6.2+, PHP 7.4+. Works with any WordPress theme. Gutenberg and Elementor compatible. No WooCommerce required.

### Why WordPress creators choose GatewayKit

* **All 9 gateways included 100% free** — PayPal, Stripe, Mollie, Razorpay, Paystack, Mercado Pago, CoinGate, Coinify, and NOWPayments. No per-gateway fees and no premium tier just to unlock a processor.
* **0% platform fees** — We never skim 2% or 3% off your sales or donations like competing plugins. What you earn is 100% yours.
* **Works anywhere in WordPress** — Use our standalone visual Form Builder, native Gutenberg block, clean shortcode `[gatewaykit_form id="..."]`, or optional Elementor Free/Pro widget and action.
* **Instant starter templates** — Launch in seconds with pre-built templates for Simple Product Checkout, Tiered Donations, Service Invoicing, and Event Ticket Registration.
* **Dynamic amounts & preset tiers** — Offer fixed pricing, customer-entered donation amounts, or preset tier buttons (e.g. $10, $25, $50, $100) with dynamic price calculation.
* **Automated PDF receipts and tax invoices** — Beautiful, compliant, printable PDF documents generated and emailed automatically upon payment.
* **Payments your customers actually prefer** — Apple Pay, Google Pay, cards, UPI, PIX, mobile money, iDEAL, Bancontact, SOFORT, plus Bitcoin, Ethereum, and 100+ cryptocurrencies.
* **Centralized transaction dashboard** — Search, filter, inspect, and manage every transaction right inside WordPress without jumping across 5 separate merchant portals.
* **Bank-grade security** — API secrets encrypted at rest with AES-256-CBC, auto-redacted log files, nonce protection, rate limiting, and zero telemetry or tracking.

### Popular use cases

* **Digital Products & Downloads** — Sell an ebook, design template, or digital asset directly from a landing page without a cart.
* **Donations & Nonprofits** — Collect charitable contributions with preset tier buttons, custom amounts, and instant tax receipts.
* **Client Invoicing & Retainers** — Let clients pay invoices or project deposits online with automated PDF confirmations.
* **Event Tickets & Registrations** — Take attendee signups and ticket fees with dynamic tiered pricing (Early Bird, VIP).
* **Global & Crypto Checkout** — Accept international payment methods (UPI in India, PIX in Brazil, Paystack in Africa) and cryptocurrencies alongside standard credit cards.

### Payment Gateways Included Free

* **PayPal** — Modern hosted PayPal Checkout with sandbox testing and IPN/webhook verification.
* **Stripe** — Stripe Checkout with Apple Pay, Google Pay, cards, Klarna, Afterpay, and embedded checkout.
* **Mollie** — Popular European payment methods including iDEAL, Bancontact, cards, and SOFORT.
* **Razorpay** — UPI, cards, net banking, and wallets for India.
* **Paystack** — Cards, bank transfers, and mobile money for Nigeria, Ghana, South Africa, and Kenya.
* **Mercado Pago** — Cards, PIX, and local payment methods for Latin America.
* **CoinGate** — Bitcoin, Ethereum, and 50+ cryptocurrencies.
* **Coinify** — Bitcoin, Ethereum, and popular cryptocurrencies.
* **NOWPayments** — Bitcoin, Ethereum, and 100+ altcoins.


### GatewayKit Pro (Optional)

Looking for advanced automation and marketing tools? Upgrade to GatewayKit Pro:

* **Discount & Coupon Codes** — Fixed or percentage-based coupons with usage limits and expiration dates.
* **Partial (Deposit) Payments** — Collect an upfront deposit and charge the balance later.
* **One-Click Refunds** — Issue refunds directly from your WordPress dashboard for Stripe and PayPal.
* **Recurring Subscriptions** — Bill weekly, monthly, or annually via Stripe.
* **Analytics & Reports** — Track revenue trends, gateway performance, and top-converting forms.
* **CSV Transaction Export** — Filter and export full financial logs for accounting and CRM import.
* **Outgoing Webhooks** — Trigger real-time automations in Zapier, Make, and n8n with HMAC security.
* **White-Label Branding** — Rebrand the plugin interface for agency client installations.

Visit the [GatewayKit website](https://gatewaykit.pourmirzai.com/) for documentation, guides, and live demos.

== Installation ==

### 1. Install & Activate
Search for **GatewayKit** in your WordPress dashboard under **Plugins → Add New**, click **Install Now**, and **Activate**.

### 2. Quick Setup Wizard
Follow the 2-minute onboarding wizard to select your currency, enable your preferred payment gateways (Stripe, PayPal, etc.), and enter your API keys.

### 3. Create & Embed Your Form
Go to **GatewayKit → Payment Forms** and pick a starter template (Donation, Product, Ticket, or Blank). Embed it anywhere using:
* **Gutenberg:** Add the **Payment Form** block and select your form.
* **Shortcode:** Paste `[gatewaykit_form id="123"]` into any page builder or widget.
* **Elementor:** Use the native GatewayKit widget or add the Payment Gateway action in Elementor Pro Forms.

== Frequently Asked Questions ==

= Does GatewayKit require WooCommerce? =

No. GatewayKit is built specifically to eliminate WooCommerce overhead for single-product sales, service invoices, event tickets, and donations. There is no shopping cart, no shop page, and no database bloat.

= Does GatewayKit require Elementor or Elementor Pro? =

No. GatewayKit includes its own visual drag-and-drop form builder, native Gutenberg block, and universal shortcode `[gatewaykit_form id="..."]`. It works seamlessly on any WordPress theme. If you happen to use Elementor, GatewayKit provides both a dedicated widget for Elementor Free and an "Actions After Submit" integration for Elementor Pro Forms.

= Are all 9 payment gateways really free? Does GatewayKit take a transaction fee? =

Yes, all 9 gateways (PayPal, Stripe, Mollie, Razorpay, Paystack, Mercado Pago, CoinGate, Coinify, NOWPayments) are 100% free in GatewayKit Lite. GatewayKit charges **0% platform fees**. You only pay standard processing fees directly to your payment processor (e.g. Stripe or PayPal).

= Can customers pay custom amounts or donate? =

Yes. GatewayKit supports fixed prices, custom user-entered amounts, and preset donation tier buttons (such as $10, $25, $50, $100). All amounts are validated server-side to prevent client tampering.

= How do automated PDF receipts and invoices work? =

Immediately after a successful payment, GatewayKit generates a professional, printable PDF receipt/tax invoice and emails it to the customer. Customers can also download it from their secure payment confirmation page.

= Is GatewayKit secure? =

Security is our top engineering priority:
1. All secret API keys are encrypted at rest using AES-256-CBC with your site's WordPress security salts (`SECURE_AUTH_KEY`).
2. Log files automatically redact all sensitive credentials, card data, and tokens.
3. Every request is protected by WordPress nonces, strict capability checks, and rate limiting.
4. GatewayKit collects zero tracking data and never calls home.

= The activation link in my opt-in email returns a 403 error. What should I do? =

This is an occasional security firewall false-positive documented in [Freemius License Activation Issues](https://freemius.com/help/documentation/wordpress-sdk/license-activation-issues/). The activation URL contains random cryptographic characters that some WAFs (ModSecurity, Cloudflare, Wordfence) flag. Temporarily pause your security firewall rule during initial email activation, then re-enable it immediately.

== Screenshots ==

1. Visual drag-and-drop payment form builder with live settings.
2. Native Gutenberg block for embedding payment and donation forms with live preview.
3. Clean frontend donation form with preset amount buttons and custom amount option.
4. Centralized transaction dashboard with search, filters, and transaction details.
5. Automated professional PDF receipt sent to customers after payment.
6. Multi-gateway settings with encrypted credential storage (Stripe, PayPal, Crypto, etc.).
7. Optional Elementor form integration with Actions After Submit.
8. Pro features: Discount coupon management, analytics overview, and CSV export.

== Changelog ==

= 1.5.1 =

**Security & Attribution**

* Server-side amount validation now requires the submitted amount to exactly match the price of the selected priced option (dropdown/radio tiers) — a lower-tier price can no longer be submitted together with a higher-tier selection.
* Free forms now display a small "Powered by GatewayKit" footer badge (automatically hidden with an active GatewayKit Pro license).

= 1.5.0 =

**Gutenberg Block, Setup Wizard & Tiered Pricing**

* Native Gutenberg Block — add and configure payment forms directly in the WordPress Block Editor with live preview and custom styling.
* 3-Step Setup Wizard — onboard new installations in under two minutes with currency setup, gateway activation, and instant starter forms.
* Labeled Pricing Presets — define named pricing tiers (e.g. `Early Bird: 25, General Admission: 50, VIP Pass: 100`) for tickets, registrations, and campaigns.
* Dynamic Option-Based Pricing — attach prices to dropdown and radio choice options (`VIP Pass | 100`) with live frontend calculation.
* Event Registration & Tickets Starter Template — pre-built ticket checkout template with tier options and attendee fields.
* Modern Clean & Elevated Card Presets — hardened style isolation preventing theme button style leakage.
* Style presets split by edition: theme inherit and Modern stay free; Elevated Card, custom CSS, and the new branded GatewayKit style are part of GatewayKit Pro.
* Form Builder Polish — added customizable Section/Tier label and optimized layout.

= 1.4.2 =

**Form UX Polish, Style Presets & Spam Protection**

* Cancelled payments now redirect back gracefully (form page or receipt page with a friendly notice) instead of showing a blank error page.
* New "Amount section position" option — show the price/donation block before or after the form fields (after fields is the new default).
* Style presets per form: inherit your theme's styling or use the built-in Modern design (Elevated Card and custom CSS presets available with GatewayKit Pro).
* New Discount Code field for the payment form builder (GatewayKit Pro) with live validation and atomic usage tracking.
* Built-in honeypot spam protection on all standalone payment forms.

= 1.4.1 =

**Major Update: Drag & Drop Form Builder**

* New drag-and-drop form builder on the Payment Forms screen — add, reorder, duplicate, and configure fields visually (keyboard-friendly move buttons included).
* 13 field types: text, email, phone, number, textarea, dropdown, radio buttons, single checkbox, checkbox group, date, hidden field, section heading, and divider.
* Per-field settings: label, placeholder, required toggle, help text, half/full width, options editor, and default value. Email stays required so PDF receipts keep working.
* Starter templates — Blank, Donation, Product/Service, and Invoice — plus one-click Duplicate on the forms list.
* Fixed a fatal error (`get_title() on string`) on the form editor screen and in frontend form rendering when payment gateways are registered.
* Existing 1.4.0 forms are automatically migrated to the new field structure — no action needed.

= 1.4.0 =

**Major Release: Standalone Payment Forms & Elementor Free Support**

* Added standalone Payment Forms builder (`gatewaykit_form`) with support for fixed pricing, customer-entered amounts, and donation preset buttons.
* Added native Elementor widget for Elementor Free — embed and style payment forms without Elementor Pro.
* Added universal shortcode `[gatewaykit_form id="..."]` to embed payment forms in Gutenberg, block editor, or any page builder.
* Automatic onboarding: automatically generates a Payment Receipt page and pre-configured sample forms on activation.
* Removed hard dependency on Elementor Pro — GatewayKit can now run standalone or with Elementor Free.
* Enhanced server-side validation for currencies and enabled gateways per form.
* Updated security architecture with isolated nonce faucets and cookie-bind verification across mixed-form environments.

= 1.3.4 =

**Critical fix**

* Fixed a PHP 7.4 compatibility issue that could prevent the plugin from loading on some sites

**Compatibility**

* Verified with WordPress 7.1 — "Tested up to" updated to 7.1

= 1.3.3 =

**Critical fixes**

* White Label magic link no longer breaks after saving settings — the secret is no longer wiped by options.php
* Fixed analytics charts showing "No data" on the Analytics page
* Top Forms now shows page/form names instead of raw IDs
* Fixed analytics filter styling to match standard WordPress admin UI
* Redesigned dashboard to a cleaner two-column layout

**Polish**

* Applied White Label branding to all admin page titles
* Removed redundant White Label submenu from the dashboard menu
* Improved subscriptions page filter styling and spacing

= 1.3.2 =

**New**

* Subscriptions overview page (Pro) — track active, past-due, cancelled, and paused subscriptions in one place
* Analytics, Discounts, and Subscriptions now appear in the GatewayKit menu for everyone — Pro users get the full feature, free users get a clear upgrade path

**Polish**

* Minor admin styling and translation improvements

= 1.3.1 =

**Critical fixes**

* Bulk Export on the Transactions page now downloads the selected rows instead of failing silently
* Webhooks for Razorpay, Paystack, Mercado Pago, and NOWPayments now correctly process pending payments
* White-label magic link unlocks the settings page again

**Security hardening**

* Payment redirect pages are now safe to reload — duplicate receipts and redundant notifications are prevented
* PayPal and Coinify webhooks require signing secrets to be configured; unverified requests are rejected
* Removed the request scanner that was blocking legitimate form fields; SQL safety is still enforced at the database layer
* Duplicate rate-limit implementations consolidated into one consistent system
* Encrypted gateway secrets now refuse to operate when WordPress security keys are absent, with a clear admin notice

**Reliability**

* Outgoing webhooks are now delivered asynchronously — a slow downstream service no longer stalls the buyer's success page
* Proxy-spoofed IP headers can no longer bypass per-IP rate limits (unless you explicitly configure trusted proxy ranges)
* Payment endpoint now validates redirect URLs and can't be replayed across clients

= 1.3.0 =

**New gateways and payment methods**

* Added Razorpay — UPI, cards, net banking, and wallets for Indian merchants
* Added Paystack — cards, bank transfers, and mobile money for African markets
* Added Mercado Pago — cards, PIX, and local methods for Latin American markets
* Added Apple Pay and Google Pay support via Stripe Checkout
* Added Klarna and Afterpay / Clearpay (Buy Now Pay Later) via Stripe Checkout
* Added Stripe Embedded Checkout — keep customers on your site with no redirect
* Added Payment Links — generate shareable Stripe checkout links without a form

= 1.2.1 =
* Fixed discount codes not being applied at checkout — discounted total is now correctly sent to all payment gateways

= 1.2.0 =
* Added PDF invoice attachment to customer receipt emails
* Added refund processing from dashboard (Stripe + PayPal)
* Added advanced analytics dashboard with revenue charts (PRO)
* Added invoice PDF download from receipt page
* Added Stripe subscription lifecycle management (PRO)
* Added outgoing webhooks with HMAC-SHA256 verification (PRO)
* Added white-label mode for agencies (PRO)
* Added Payment Summary form field for Elementor (PRO)
* Added optional (donation-style) payment forms (PRO)
* Fixed Payment Summary and Discount Code field rendering in Elementor editor (PRO)

= 1.1.0 =
* Stronger PayPal webhook security with optional signature verification
* Safer payment confirmation for PayPal orders
* Faster payments — PayPal tokens are now cached
* More accurate zero-decimal currency list
* Pro features: CSV export and date-range filter on Transactions page

= 1.0.0 =
* First public release
* PayPal payments through Elementor Pro Forms
* Optional GatewayKit Pro add-on with Stripe, Mollie, and CoinGate gateways

== Upgrade Notice ==

= 1.3.4 =
Fixes a PHP 7.4 compatibility issue that could prevent the plugin from loading, and is verified with WordPress 7.1.

= 1.3.3 =
Critical White Label fix: magic links no longer break on save. If you are locked out, use `?gatewaykit_wl=GatewayKit_WL_emergency_key` after updating.

= 1.3.2 =
Manage your Stripe subscriptions from a dedicated overview page in the admin.

= 1.3.0 =
Three new regional gateways (Razorpay, Paystack, Mercado Pago), Apple Pay, Google Pay, Klarna, Afterpay, embedded checkout, and shareable Payment Links.

= 1.2.0 =
Crypto payments via NOWPayments, date filters, customer email receipts, and transaction notes.

= 1.1.0 =
Security and performance release. PayPal webhooks are now verified via PayPal's official signature endpoint — open PayPal settings and paste your Webhook ID to enable full protection. PayPal access tokens are now cached across requests.

= 1.0.0 =
First release. Accept PayPal payments through Elementor Pro Forms. Upgrade to GatewayKit Pro for Stripe, Mollie, and CoinGate.

== External Services ==

This plugin connects to payment provider APIs to process payments.

= What is sent and when =

When a user submits a payment form, the plugin sends the payment amount, currency, and a transaction reference to the configured payment provider's servers for authorization and capture. No personal user data beyond what the provider requires for payment processing is transmitted.

= PayPal =

* API Endpoint (Live): https://api-m.paypal.com
* API Endpoint (Sandbox): https://api-m.sandbox.paypal.com
* Terms of Service: https://www.paypal.com/us/legalhub/useragreement-full
* Privacy Policy: https://www.paypal.com/us/legalhub/privacy-full

= Stripe =

* API Endpoint (Live): https://api.stripe.com
* API Endpoint (Test): https://api.stripe.com
* Terms of Service: https://stripe.com/legal
* Privacy Policy: https://stripe.com/privacy

= Mollie =

* API Endpoint (Live): https://api.mollie.com
* API Endpoint (Test): https://api.mollie.com
* Terms of Service: https://www.mollie.com/terms
* Privacy Policy: https://www.mollie.com/privacy

= CoinGate =

* API Endpoint (Live): https://api.coingate.com
* API Endpoint (Test): https://api-sandbox.coingate.com
* Terms of Service: https://coingate.com/terms-of-service
* Privacy Policy: https://coingate.com/privacy-policy

= Coinify =

* API Endpoint (Live): https://api.coinify.com
* API Endpoint (Test): https://api.coinify.com
* Terms of Service: https://coinify.com/terms
* Privacy Policy: https://coinify.com/privacy-policy

= NOWPayments =

* API Endpoint (Live): https://api.nowpayments.io
* API Endpoint (Test): https://api-sandbox.nowpayments.io
* Terms of Service: https://nowpayments.io/terms
* Privacy Policy: https://nowpayments.io/privacy

= Razorpay =

* API Endpoint (Live): https://api.razorpay.com
* API Endpoint (Test): https://api.razorpay.com (test keys)
* Terms of Service: https://razorpay.com/terms-of-service/
* Privacy Policy: https://razorpay.com/privacy-policy/

= Paystack =

* API Endpoint (Live): https://api.paystack.co
* API Endpoint (Test): https://api.paystack.co (test keys)
* Terms of Service: https://paystack.com/terms
* Privacy Policy: https://paystack.com/privacy-policy

= Mercado Pago =

* API Endpoint (Live): https://api.mercadopago.com
* API Endpoint (Test): https://api.mercadopago.com (sandbox tokens)
* Terms of Service: https://www.mercadopago.com/terms-and-conditions
* Privacy Policy: https://www.mercadopago.com/privacy-experience
