=== Hellion Shortcode Digital Sales ===
Contributors: hellion35
Tags: digital downloads, sell files, stripe, paypal, shortcode
Requires at least: 7.0
Tested up to: 7.0
Requires PHP: 8.0
Stable tag: 0.1.3
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Sell a digital product without a cart: shortcode, Stripe or PayPal, a protected download link.

== Description ==

Hellion Shortcode Digital Sales is a lightweight way to sell a digital product (an ebook, a template, a license file, anything downloadable) without setting up a full store. Add a product, paste a shortcode on any existing page or post, and customers can buy without ever leaving that page or going through a cart.

**Core scenario, no paid add-on required:**

1. Create a product (price, one file, optional custom checkout fields).
2. Add `[hellion_product id="123"]` to any page or post — inline or as a popup.
3. Customer pays with Stripe or PayPal, right there on the page.
4. They land on a protected, time-/count-limited download link and get the same link by email. You get an email too.

= Features =

* Shortcode-based checkout, inline or popup, no page builder or block editor lock-in
* Stripe and PayPal, called directly (no bundled SDK, so it won't clash with other plugins that also bundle payment SDKs)
* Protected file delivery: download links are token-based, not a public URL, with a configurable download-count and expiry limit per order
* Custom checkout fields (text / email / textarea / checkbox / select), configurable globally or per product
* Editable email templates (WYSIWYG) with placeholder tags for customer name, product, download link, order details, and more
* Orders screen with search, status filter, manual status/limit changes, and per-order details
* Sales analytics (revenue, orders, downloads) with day/week/month presets and a custom date range with period-over-period comparison
* Built to be extended: a documented set of actions/filters lets add-ons hook in without touching core files, and third-party add-ons don't need to modify this plugin's code or database tables

= What this plugin does not include =

Coupons, multiple file versions per product, subscriptions/recurring billing, multi-currency, VAT/tax reporting, license-key delivery, abandoned-cart recovery, and additional payment gateways are out of scope for this free plugin — the plugin registers real extension points for these, so they can be added by add-ons without forking core.

== External services ==

This plugin connects to third-party services to process payments and, only if you configure it, verify payment webhooks. No data is sent to these services unless you enable the corresponding gateway in Settings → Payments.

* **Stripe** — when Stripe is enabled and a customer checks out with it, the order amount, currency, and an internal order ID are sent to Stripe's API (`api.stripe.com`) to create a Payment Intent, and the customer's payment details are collected by Stripe's own embedded Payment Element (your site never sees card numbers). Stripe's webhook calls back to this site to confirm payment. See [Stripe's Privacy Policy](https://stripe.com/privacy) and [Terms of Service](https://stripe.com/legal).
* **PayPal** — when PayPal is enabled, the same order data is sent to PayPal's API (`api-m.paypal.com` or the sandbox equivalent) to create and capture an order, and the PayPal JS SDK is loaded from `paypal.com` to render the payment buttons. See [PayPal's Privacy Policy](https://www.paypal.com/privacy) and [Legal Agreements](https://www.paypal.com/legalhub).

Loading Stripe.js and the PayPal SDK from the providers' own domains is a requirement of both providers (self-hosting these scripts is against their terms and unsupported) and is unrelated to any tracking by this plugin itself.

== Third-party libraries ==

* **Chart.js** (used for the Analytics chart) — MIT License. Bundled locally with this plugin (`includes/Admin/assets/vendor/chart.umd.js`); not loaded from a CDN.

== Installation ==

1. Upload the plugin files to `/wp-content/plugins/hellion-shortcode-digital-sales`, or install through the Plugins screen in WordPress directly.
2. Activate the plugin through the "Plugins" screen.
3. Go to **Hellion Shortcode Digital Sales → Settings** and set your currency and at least one payment gateway (Stripe and/or PayPal).
4. Go to **Hellion Shortcode Digital Sales → Products** and add a product with a price and a file.
5. Copy the shortcode shown on the product and paste it into any page or post.

If your server runs Nginx rather than Apache, the plugin's automatic `.htaccess` protection for uploaded product files does not apply — add a rule to your server config to deny direct access to `wp-content/uploads/hellion-shortcode-digital-sales-files/`, for example:

`location /wp-content/uploads/hellion-shortcode-digital-sales-files/ { deny all; }`

== Frequently Asked Questions ==

= Do I need WooCommerce or another e-commerce plugin? =

No. Hellion Shortcode Digital Sales is a standalone checkout for a single product per shortcode — no cart, no separate store pages.

= Can I sell more than one file per product, or offer subscriptions/coupons? =

Not in this version. The plugin is built so these can be added by add-ons without modifying this plugin's core files or database tables.

= Where are uploaded files stored, and are they public? =

Files are stored in `wp-content/uploads/hellion-shortcode-digital-sales-files/` and are blocked from direct access (via `.htaccess` on Apache; see the Installation section for Nginx). Customers only ever get a token-based download link, never the file's real path.

= What happens if a download link expires or reaches its limit? =

The customer sees a clear message explaining why, not a generic error. An admin can manually extend the limit or expiry for a specific order from the Orders screen.

== Screenshots ==

1. Product edit screen with price, file, and checkout field settings.
2. Inline checkout form on a page.
3. Orders screen with an order's details, status, and limit/expiry actions.
4. Sales analytics with a custom date range comparison.
5. Popup checkout form.
6. Sales analytics, 30-day view.
7. Payment gateway settings.

== Changelog ==

= 0.1.3 =
* Fix: browsers could offer to autofill a saved or generated password into the Stripe/PayPal secret key fields, silently overwriting the key you entered.

= 0.1.2 =
* Fix: checkout field labels with non-Latin characters (e.g. Cyrillic) were saved incorrectly.

= 0.1.1 =
* Fix: the product edit screen's file upload never worked — the form was missing the `multipart/form-data` encoding required for file uploads, so the selected file never reached the server. Product files now upload correctly.
* Fix: the shortcode for a product was never actually shown anywhere, despite the Installation instructions telling you to copy it. It now appears on the product edit screen once the product is published.
* If a product file upload does fail (oversized file, server permissions, etc.), an admin notice now explains why instead of failing silently.

= 0.1.0 =
* Initial release.

== Upgrade Notice ==

= 0.1.3 =
Prevents browsers from autofilling your Stripe/PayPal secret key fields with the wrong value.

= 0.1.2 =
Fixes custom checkout fields with non-Latin labels.

= 0.1.1 =
Fixes product file uploads and the missing shortcode display — update is strongly recommended.

= 0.1.0 =
Initial release.
