=== MarketXY ===
Contributors: dilmohankumar
Tags: whois, domain lookup, company intelligence, security, seo
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Instant company, domain, security and trust intelligence — as a WordPress admin tool and a public [marketxy_lookup] shortcode.

== Description ==

MarketXY brings the MarketXY domain-intelligence report into WordPress:

* A dedicated **MarketXY → Lookup** admin page for looking up any domain
* A `[marketxy_lookup]` shortcode so site visitors can run their own lookups
* Domain Score, Contact Information, Technical Profile, and Website Analysis
  (categories, competitor/scam/phishing/lookalike domains, connected
  companies), all in one report
* Server-side caching (WordPress Transients) so repeat lookups of the same
  domain are instant and don't re-call the API

= Connecting the MarketXY API =

The plugin needs a MarketXY API base URL to return real report data:

1. Go to **MarketXY → Settings**
2. Enter your **API base URL**
3. Save Changes

That's it — no other configuration needed. Until an API base URL is set,
looking up a domain shows a "MarketXY API is not configured yet" message
instead of a report.

== Installation ==

1. Upload the `marketxy-lookup` folder to `/wp-content/plugins/`
   (or install the zip via **Plugins → Add New → Upload Plugin**)
2. Activate the plugin through the **Plugins** menu in WordPress
3. Go to **MarketXY → Settings** and enter your API base URL
4. Go to **MarketXY → Lookup** to try it, or add `[marketxy_lookup]` to any
   page or post

== Frequently Asked Questions ==

= Do I need an API base URL to use this? =

Yes. Every lookup calls the MarketXY API using the base URL configured
under MarketXY → Settings; until one is set, lookups return a
"not configured yet" message instead of a report.

= Is the API base URL or its response data ever exposed to site visitors? =

The API base URL itself is a server-side setting never sent to the
browser. Lookups go through a WordPress REST API endpoint that runs
server-side and calls the MarketXY API on the server's behalf; the
resulting report data is then returned to whoever performed that lookup
(the same visibility any public [marketxy_lookup] shortcode search
already has).

== External services ==

This plugin connects to the following third-party services:

1. **MarketXY API** — used to retrieve the domain, company, security and
trust intelligence shown in the lookup report. Once a site owner has
entered an API base URL under MarketXY → Settings, the domain name being
looked up is sent to that API at the time each lookup is performed, and
the report data is returned for display. This service is provided by
MarketXY: [Terms of Service](https://marketxy.com/terms-of-use/), [Privacy Policy](https://marketxy.com/privacy-policy/).

2. **Clearbit Logo API** — used to show the looked-up domain's own
company logo next to its report, and next to each related/competitor
domain listed in the report. Each time a report is rendered, the browser
requests that domain's logo directly from Clearbit
(https://logo.clearbit.com), which receives the requesting site visitor's
IP address and the domain name being looked up. This service is provided
by Clearbit: [Terms of Service](https://clearbit.com/terms), [Privacy Policy](https://clearbit.com/privacy-policy).

3. **Google (favicons)** — used as a fallback to show a domain's site
icon when Clearbit has no logo for it. Each time this fallback is needed,
the browser requests that domain's favicon directly from Google's public
favicon service (https://www.google.com/s2/favicons), which receives the
requesting site visitor's IP address and the domain name being looked
up. This service is provided by Google: [Terms of Service](https://policies.google.com/terms), [Privacy Policy](https://policies.google.com/privacy).

== Changelog ==

= 1.0.1 =
* Fixed "Refresh Live Data" to call a genuinely live backend endpoint
  instead of re-serving cached data.
* Fixed the domain score (and the Overall/Risk score tiles, which depend on
  it) occasionally showing blank on the first lookup due to one endpoint's
  higher failure rate inside a 10-way concurrent batch — added a retry.
* Various security, accessibility, performance, and code-quality fixes.

= 1.0.0 =
* Initial release: admin dashboard, public shortcode, server-side caching,
  Settings page.
 