=== LoginDash ===
Contributors: spinxdigitaldev
Tags: custom login, login customizer, login page, login logo, recaptcha
Requires at least: 6.2
Tested up to: 7.1
Requires PHP: 8.0
Stable tag: 1.0.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Design a branded WordPress login page in a live, side-by-side customizer: logo, backgrounds, video, fonts, reCAPTCHA and more. No code needed.

== Description ==

=== 🎨 A Visual Login Page Customizer For WordPress ===

**LoginDash** replaces the plain, generic `wp-login.php` screen with a fully branded sign-in experience — your logo, colours, backgrounds, fonts and messaging — all from a live, side-by-side editor that requires **no code**.

Adjust a control on the left and watch the real login page update instantly on the right. Everything is rendered with native WordPress markup, loads **only on the login page**, and leaves WordPress authentication working exactly as WordPress intends.

It's built for agencies, freelancers and site owners who want a professional, on-brand login screen for clients, members and staff — in minutes, not hours.

=== ✨ Why Choose LoginDash? ===

* **True Live Preview** — Most changes repaint instantly through CSS variables. No page reloads, no guesswork.
* **No Code Required** — Every colour, size, border and position has a visual control, each with its own per-field reset arrow.
* **Lightweight by Design** — Styles, fonts and scripts load only on the login page, never on your front end or admin. Generated CSS is cached and rebuilt only when you save.
* **Safe to Experiment** — Nothing goes live until you click **Save Changes**, and form submission is disabled inside the preview.
* **Non-Destructive Themes** — Applying a starter theme overwrites only the settings it defines. Your other customizations survive.
* **Core-Compatible** — Native WordPress markup and hooks. Translation-ready, multisite-aware and PHP 8+ ready.

=== 🖼️ Features at a Glance ===

* **Starter Themes** — Three one-click starting designs: **Clean WordPress Style** (the default), **Minimal Light** and **Minimal Dark**. Apply one, then fine-tune every value.

* **Logo & Page Identity** — Upload a custom logo (recommended 320×80), set its width, height and spacing, link URL and alt title, change the browser page `<title>`, and add a custom favicon. Or hide the logo entirely.

* **Backgrounds** — Choose a solid colour, separate desktop and mobile background images with repeat / position / size controls, a **random image gallery** that picks a new image on every page load, or a **background video** (Media Library MP4 with optional start/end times, or YouTube) with an overlay tint for readability.

* **Form Position** — Place the login form anywhere on screen: Top / Center / Bottom and Left / Center / Right, plus four-side offsets for fine-tuning. The forgot-password form has its own independent position.

* **Login Form Styling** — Width (200–800 px), minimum height, corner radius, shadow size and opacity, four-side padding, border, background colour or image, and a transparency toggle.

* **Input Fields & Labels** — Field background and focus background, text colour, default and focus borders, radius, password-eye icon colour, remember-me checkbox colour, and label colours and sizes.

* **Button Styling** — Button colour and hover colour, borders, text colours, radius, padding and text size. Choose **Default** (inline beside Remember Me) or **Full** width mode with its own width and alignment.

* **Forgot Password Form** — Its own background image and colour, its own input radius, and its own position.

* **Typography (Google Fonts)** — A curated list including Inter, Roboto, Open Sans, Lato, Montserrat, Poppins, Nunito, Raleway and Playfair Display, with weights from 300 to 800. Choosing "System Default" loads no external font.

* **Footer Links & Copyright Bar** — Toggle the Lost-password, Back-to-site and Privacy-policy links, set custom text and URLs, style them together, and add a copyright bar that supports a `$YEAR$` token.

* **Welcome & Error Messages** — Custom welcome messages for the Login, Lost-password, Registration and Logout screens (limited HTML allowed), custom text for eleven validation errors, and separate styling for welcome and error notices.

* **Custom CSS / JS** — Syntax-highlighted CSS and JavaScript editors for anything the controls don't cover. Code is sanitised on save and loaded only on the login page.

* **Google reCAPTCHA v2 & v3** — Protect the login, registration and lost-password forms from bots.

* **Safe SVG Logos** — SVG uploads are sanitized automatically, stripping scripts, event handlers and `javascript:` URIs.

=== 🖥️ How the Customizer Works ===

1. Open **LoginDash → Customizer**.
2. Optionally pick a starting design on the **Themes** tab.
3. Open any panel and adjust the controls. The preview updates as you go.
4. Check your design with the **Desktop / Tablet / Mobile** buttons, and switch the preview between the login and forgot-password forms.
5. Click **Save Changes** to publish, or **Reset** to return everything to defaults.

Controls are grouped into tabs: Themes, Logo, Background, Form Position, Login Form, Forgot Password Form, Button Beauty, Input Labels, Google Fonts, Error Messages, Welcome Messages, Form Footer, reCAPTCHA and Custom CSS / JS.

The **Settings** screen is your control hub. It shows the live status of each feature with a link to where it's configured, plus maintenance tools such as clearing the compiled-CSS cache.

=== 🛡️ Built-in reCAPTCHA Protection ===

* **reCAPTCHA v2** shows the familiar "I'm not a robot" checkbox.
* **reCAPTCHA v3** runs invisibly and scores each request against Google's recommended 0.5 threshold.
* Verification runs server-side. If it fails, the sign-in, registration or password reset is blocked and your custom error message is shown.
* If Google is temporarily unreachable, LoginDash lets the request through instead of locking everyone out.
* Your Secret Key is stored in a masked field and is only ever sent to Google's verification endpoint, never exposed in the page.

=== 💡 Best For ===

* Agencies delivering white-labelled, client-branded login screens.
* Membership, e-learning and WooCommerce sites that want the login page to match the storefront.
* Corporate intranets and staff portals that need a consistent brand at sign-in.
* Any site owner who wants a professional login page without touching code.

=== ⭐ Do More With LoginDash Pro ===

The free plugin is a complete login-page customizer on its own. **[LoginDash Pro](https://apps.spinxdigital.com)** is an optional add-on that installs alongside it and adds a premium template library plus login, security and workflow features:

**Design**

* **9 Pre-built Designed Templates** — Agency Style, Corporate Blue, Developer Console, Elegant Blur, Gradient Pro, Modern Glassmorphism, Neon Dark, SaaS Style and Split Screen, added to the same Themes grid as the free starters.

**Security**

* **Limit Login Attempts** — Lock out an IP after a configurable number of failed sign-ins, show a "remaining attempts" message, and keep an audit log that records password length only, never the password itself.
* **IP Whitelist / Blacklist** — Exempt trusted IPs from lockouts and block known-bad IPs immediately (IPv4 and IPv6).
* **XML-RPC Protection** — Block `/xmlrpc.php`, pingbacks and remote-publishing requests.
* **CAPTCHA Escalation** — Show reCAPTCHA only after an IP starts failing, so legitimate users sign in without friction.
* **Hide Login** — Move `wp-login.php` to a secret custom URL and redirect, 404 or reroute logged-out visits to the old endpoints.

**Workflow**

* **Auto Login** — Generate secure, passwordless login links: one-time, time-limited or never-expiring, stored as SHA-256 hashes, with an activity log.
* **Login Redirects** — Send users to different destinations after login and logout, by individual user or by role.
* **Social Login** — Sign in or register with Google, Facebook, X (Twitter) or GitHub. Administrator accounts can never be auto-linked.
* **Import / Export** — Back up, restore and migrate your full configuration (including uploaded media) between sites, with a 7-day roll back.

Learn more about LoginDash Pro: [https://apps.spinxdigital.com](https://apps.spinxdigital.com)

== Installation ==

= From your WordPress dashboard =
1. Go to `Plugins > Add New`.
2. Search for `LoginDash`.
3. Click `Install Now`, then `Activate`.
4. Open `LoginDash → Customizer` from the admin menu.

= Manual upload =
1. Upload the `logindash` folder to the `/wp-content/plugins/` directory.
2. Activate **LoginDash** through the `Plugins` screen.
3. Open `LoginDash → Customizer` from the admin menu.

= After activation =
1. Pick a starter theme on the **Themes** tab (optional).
2. Upload your logo, then set your background, form and button colours.
3. Optionally enable reCAPTCHA and paste in your Google keys.
4. Click **Save Changes** and open your login page in a private window to see it live.

== Frequently Asked Questions ==

= Do I need to know CSS or code? =

No. Every setting has a visual control and the preview updates as you edit. The Custom CSS / JS panel is there only for edge cases the controls don't cover.

= Will visitors see my changes while I'm still editing? =

No. The preview shows your unsaved edits, but nothing changes on the live login page until you click **Save Changes**.

= Does applying a theme erase my customizations? =

No. A theme overwrites only the settings it defines and keeps your other customizations. Every value stays editable after you apply it.

= Will LoginDash slow down my site? =

No. LoginDash's styles, scripts and Google Fonts load only on the login page, never on your front end or in the admin. Generated CSS is cached and rebuilt only when settings change.

= Does LoginDash change how WordPress logs users in? =

No. It changes how the login page looks and what it says. Authentication is still handled entirely by WordPress core.

= Which reCAPTCHA version should I use? =

Use v2 if you want a visible "I'm not a robot" checkbox, or v3 for an invisible check with no extra click. Register your site in the Google reCAPTCHA admin console with the same version you select in LoginDash, otherwise the keys won't work.

= What happens if Google reCAPTCHA is unreachable? =

LoginDash lets the request through rather than blocking every sign-in, so a Google outage can never lock you out of your own site.

= Can I use a video as the login background? =

Yes. Use an MP4 from your Media Library (with optional start and end times) or a YouTube video. Videos are always muted so browsers allow autoplay, and an overlay tint keeps the form readable.

= Can I upload SVG logos? =

Yes. LoginDash sanitizes SVGs on upload, stripping `<script>`, event handlers and `javascript:` URIs.

= Will my changes survive a plugin or theme update? =

Yes. Settings live in a single dedicated option (`sdld_settings`) and are never touched by updates.

= Does it work on multisite? =

Yes. Settings are per-site. For network-wide branding, activate the plugin on each subsite and configure it there.

= Why doesn't a specific error message change? =

WordPress sometimes returns a single combined error string. LoginDash matches the most common cases. If a message you care about isn't replaced, please open a support request with the exact wording.

= Where are the Customizer controls? =

In the dashboard sidebar under **LoginDash → Customizer**, or via the **Customize** link on the plugin's row in the Plugins screen.

= Is there a Pro version? =

Yes. LoginDash Pro is an optional add-on that adds nine designed templates, Limit Login Attempts with IP whitelist / blacklist, XML-RPC protection and CAPTCHA escalation, Hide Login, Auto Login links, user- and role-based Login Redirects, Social Login (Google, Facebook, X, GitHub) and Import / Export. The free plugin works fully without it. Details: [https://apps.spinxdigital.com](https://apps.spinxdigital.com)

= How do I get support? =

Please open a thread in the plugin's support forum and include:

* WordPress version
* PHP version
* Active theme and any other login or security plugins
* Steps to reproduce the issue

== External Services ==

LoginDash optionally connects to the following external services. All connections are triggered only by explicit administrator configuration — nothing is sent by default on a fresh install.

= Google reCAPTCHA =

When the reCAPTCHA feature is enabled in the plugin settings, LoginDash loads the Google reCAPTCHA JavaScript library from Google's servers and sends a server-side verification request to Google on each login, lost-password, or registration form submission.

* **What is sent:** The reCAPTCHA response token generated in the user's browser, the site's reCAPTCHA secret key, and the submitting user's IP address.
* **What is received:** A pass/fail verdict (and a bot-likelihood score for v3).
* **When it applies:** Only when an administrator enables reCAPTCHA and configures a Google site key and secret key.
* **Why it is required:** Bot detection cannot be performed locally; the verification depends on Google's infrastructure.
* **Google reCAPTCHA Privacy Policy:** https://policies.google.com/privacy
* **Google reCAPTCHA Terms of Service:** https://policies.google.com/terms

= Google Fonts =

When an administrator selects a Google Font in the Typography settings, LoginDash loads that font's CSS stylesheet from Google Fonts on the login page.

* **What is sent:** The selected font family name and weight, as URL parameters.
* **What is received:** A CSS stylesheet pointing to the font files hosted by Google.
* **When it applies:** Only when an administrator selects a Google Font. If no font is selected, no request is made.
* **Why it is required:** Google Fonts are hosted on Google's CDN; local self-hosting would require bundling hundreds of font files.
* **Google Fonts Privacy Policy:** https://policies.google.com/privacy

= YouTube (background video) =

When an administrator enables a YouTube video as the login page background, LoginDash embeds the video in an `<iframe>` pointing to `youtube-nocookie.com`.

* **What is sent:** The YouTube video ID, as part of the URL.
* **What is received:** The video player and stream.
* **When it applies:** Only when an administrator enables the background video feature and provides a YouTube URL.
* **Why it is required:** Video streaming must originate from YouTube's CDN; the video file is not downloaded or bundled locally.
* **Note:** LoginDash uses the `youtube-nocookie.com` domain, which is YouTube's privacy-enhanced mode and does not set cookies until the user plays the video.
* **YouTube Privacy Policy:** https://policies.google.com/privacy
* **YouTube Terms of Service:** https://www.youtube.com/t/terms

== Screenshots ==

1. Themes – pick a starter theme and see it applied instantly in the live preview.
2. Logo – replace the WordPress logo with your own and set its size, spacing, link URL and title.
3. Background – choose a background style and colour for the login page.
4. Form Position – align the form vertically and horizontally, with fine-tune offsets.
5. Login Form – style the form background, width, minimum height, corner radius and shadow.
6. Forgot Password Form – style the lost-password form and its input fields.
7. reCAPTCHA – protect the login, registration and lost-password forms with Google reCAPTCHA.
8. Buttons – set button colours, borders and text colours, including hover states.
9. Error Messages – rewrite the messages shown when login validation fails.
10. Welcome Messages – add messages above the form on the login, lost-password, registration and logout screens.
11. Form Footer – show, hide or reword the "Lost your password?" and "Back to site" links.
12. Google Fonts – apply a Google Font and weight across the entire login screen.
13. Settings – plugin overview with feature shortcuts, security status and branding options.
14. Help – quick start guide, feature documentation, troubleshooting and developer hooks.

== Changelog ==

= 1.0.1 =
* Hardened input validation for the background position and Google Font settings.
* Minor security and code-quality improvements.

= 1.0.0 =
* Initial release.

== Upgrade Notice ==

= 1.0.1 =
WordPress.org review-feedback release. Recommended for everyone.

= 1.0.0 =
First public release.
