=== پارس کیت (Pars Kit) ===
Contributors: parskit
Tags: jalali, shamsi, woocommerce, webp, performance
Requires at least: 6.2
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 2.0.8
WC requires at least: 8.2
WC tested up to: 11.1
License: GPL-2.0-or-later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

One lightweight plugin for full Jalali dates (including WooCommerce Analytics) and Iranian gateways: Mellat, Saman, Sadad, and more.

== Description ==

**Pars Kit** is a single, lightweight toolkit for Persian WordPress and WooCommerce sites. Install one plugin instead of a pile of Shamsi, gateway, WebP, and SMTP add-ons — the package stays small, every asset ships locally, and the admin UI is Persian. Directory slug: `pars-kit`.

= Complete Jalali (Shamsi) calendar =

The main job is **full display conversion** of dates across WordPress and WooCommerce — storefront, wp-admin, emails, and especially **WooCommerce Analytics**. Database values stay Gregorian, so REST, feeds, and SEO dates stay valid.

* Official WordPress [`wp_date`](https://developer.wordpress.org/reference/hooks/wp_date/) filter (WP 5.3+)
* `date_i18n()`, WooCommerce `WC_DateTime::date_i18n()`, classic admin, emails, and Analytics labels
* Optional Persian digits in dates
* REST, feeds, and machine formats (`U`, `c`, `r`, ISO) stay Gregorian

= Iranian bank payment gateways =

Seven widely used Iranian PSPs register as WooCommerce gateways. Each one is **off by default**. Enable a gateway with one click in Pars Kit, then enter the merchant terminal in **WooCommerce → Settings → Payments**. Classic checkout, Cart/Checkout Blocks, and HPOS are supported.

* **Behpardakht Mellat** — Bank Mellat IPG
* **Saman Electronic Payment (SEP)** — Saman / SEP IPG
* **Asan Pardakht (AP)** — Asan Pardakht IPG
* **Iran Kish** — Iran Kish IPG
* **Sadad (Bank Melli)** — Bank Melli / Sadad IPG
* **Pardakht Novin** — Pardakht Novin Arian IPG
* **Pasargad Electronic Payment** — Pasargad / PEP IPG

= Speed: WebP and outbound blocker =

* **WebP** — new JPG/PNG uploads convert automatically so images load faster (off by default; Imagick or the WordPress image editor; no shell/`cwebp`)
* **External connection blocker** — stop unused third-party requests that slow Iranian sites on the storefront and in wp-admin (off by default; review the domain whitelist first)

= Tools =

* Jalali date-range filter on WooCommerce orders, so you can find orders in a Shamsi interval
* Optional Persian-script first and last name on checkout (classic checkout and Checkout Block)
* Vazirmatn admin font (on by default; no CDN)
* Optional WordPress admin (wp-admin) optimization

= Admin activity log =

Turn it on to record what site managers do, then filter and inspect each event with full detail (off by default).

= Email / SMTP =

Send WordPress mail through an SMTP host you already use, then confirm the connection with a test email so orders and password resets actually arrive.

= Important notes =

* The external traffic blocker is **off by default**. Enable under **Pars Kit → Speed** only after reviewing the domain whitelist.
* Do not run another Shamsi plugin (e.g. Parsi Date) at the same time — double conversion.
* Do not run a standalone Mellat / Saman / Asan Pardakht / Iran Kish / Bank Melli / Pardakht Novin / Pasargad plugin for the same bank while those modules are enabled.
* All plugin CSS/JS/fonts ship inside the plugin folder — no remote CDNs.

= Compatibility =

* WordPress 6.2+, PHP 7.4+
* WooCommerce 8.2+ (soft dependency): HPOS and Cart/Checkout Blocks when WooCommerce is active
* Broad theme compatibility (including builders such as Elementor): display-only conversion, no storefront asset spam

== Installation ==

1. Install from the WordPress.org Plugin Directory, **or** upload the ZIP so the plugin lives at `wp-content/plugins/pars-kit/pars-kit.php` (ZIP must contain a single top-level folder named `pars-kit`).
2. Activate **Pars Kit**.
3. Open **Pars Kit** in the admin menu and configure modules.
4. For Mellat, Saman, Asan Pardakht, Iran Kish, Bank Melli, Pardakht Novin, or Pasargad: enable under **Payment gateways**, then set terminal credentials in **WooCommerce → Settings → Payments**.

== Frequently Asked Questions ==

= Does this change dates in the database? =

No. Only display is converted. Stored dates stay Gregorian.

= Does the plugin load scripts or fonts from a CDN? =

No. Assets ship inside the plugin. Optional admin bridges may use WordPress/WooCommerce core script handles already on your site.

= What external services does Pars Kit connect to? =

Pars Kit does not phone home or track visitors. See **External services** below for Mellat, Saman, Asan Pardakht, Iran Kish, Bank Melli, Pardakht Novin, Pasargad, and optional SMTP.

= Does WebP use shell commands (exec / cwebp)? =

No. Conversion uses Imagick when available, otherwise the WordPress image editor.

= Does WebP convert existing media? =

No. Only new JPG/PNG uploads when the module is enabled. The original file is removed after a successful conversion.

= Can I use it with Parsi Date or Persian WooCommerce? =

Not recommended at the same time — double conversion. Disable one of them.

= Where do I configure Mellat, Saman, Asan Pardakht, Iran Kish, Bank Melli, Pardakht Novin, or Pasargad credentials? =

**WooCommerce → Settings → Payments**, after enabling the gateway in Pars Kit.

= How do I send email through SMTP? =

Open **Pars Kit → Email**, choose SMTP, fill host/username/password/from address (auto-save), then use **Send test**. Host mode leaves WordPress default mail unchanged.

= Can shop managers deactivate the plugin? =

Anyone who can manage plugins can deactivate or delete it. Pars Kit does not hide or block those links.

== External services ==

Pars Kit does **not** phone home, does **not** send telemetry, and does **not** require an account with the plugin author. Optional modules that you enable may connect to third-party services that **you** already use.

Licensed Iranian card payments run on the national Shaparak network (Central Bank of Iran). Each bank PSP is hosted on its own shaparak.ir subdomain. These modules stay **off by default**. They are used only when you turn them on and enter a merchant terminal in WooCommerce. Pars Kit is not a payment intermediary and never collects card numbers, CVV, or expiry.

= Behpardakht Mellat (optional WooCommerce gateway) =

This plugin connects to Behpardakht Mellat (Bank Mellat’s licensed PSP) so WooCommerce can start, verify, settle, or reverse a card payment on the official Shaparak payment page. It is needed only when the store owner enables the Mellat module and the customer chooses Mellat at checkout.

It sends the merchant terminal id, username, password, order id, amount in Rials, callback URL, and optionally the customer mobile number from the order. This happens when checkout creates a payment request and again when the site verifies the bank callback. Card data is entered only on the bank page.

Endpoints used:
https://bpm.shaparak.ir/pgwchannel/services/pgw?wsdl
https://bpm.shaparak.ir/pgwchannel/startpay.mellat

This service is provided by "Behpardakht Mellat": [terms of use](https://www.behpardakht.com/), [privacy policy](https://www.shaparak.ir/).
Provider site: https://www.behpardakht.com/
Network / regulator (Shaparak): https://www.shaparak.ir/

= Saman Electronic Payment — SEP (optional WooCommerce gateway) =

This plugin connects to Saman Electronic Payment (SEP) so WooCommerce can request a payment token, send the customer to the official Shaparak payment page, then verify or reverse the transaction. It is needed only when the store owner enables the Saman module and the customer chooses Saman at checkout.

It sends the merchant terminal id, amount in Rials, merchant reference (ResNum), redirect/callback URL, and optionally the customer mobile number (CellNumber) from the order. This happens when checkout requests a token and again on verify / reverse after the bank returns the customer.

Endpoints used:
https://sep.shaparak.ir/OnlinePG/OnlinePG
https://sep.shaparak.ir/verifyTxnRandomSessionkey/ipg/VerifyTransaction
https://sep.shaparak.ir/verifyTxnRandomSessionkey/ipg/VerifyTranscation
https://sep.shaparak.ir/verifyTxnRandomSessionkey/ipg/ReverseTransaction
https://sep.shaparak.ir/verifyTxnRandomSessionkey/ipg/ReverseTranscation

This service is provided by "Saman Electronic Payment (SEP)": [terms of use](https://www.sep.ir/), [privacy policy](https://www.shaparak.ir/).
Provider site: https://www.sep.ir/
Network / regulator (Shaparak): https://www.shaparak.ir/

= Asan Pardakht (optional WooCommerce gateway) =

This plugin connects to Asan Pardakht Persian (IPG REST 1.9.3) so WooCommerce can request a payment token, send the customer to the official Shaparak payment page, then look up, verify, settle, reverse, or cancel the transaction. It is needed only when the store owner enables the Asan Pardakht module and the customer chooses Asan Pardakht at checkout.

It sends the merchant configuration id, username, password (HTTP headers `usr` / `pwd`), unique local invoice id, amount in Rials, Gregorian local date, callback URL (including the invoice id), and optionally the customer mobile number (`mobileNumber`) from the order. This happens when checkout requests a token and again on TranResult / Verify / Settlement (or Reverse / Cancel) after the bank returns the customer.

Endpoints used:
https://ipgrest.asanpardakht.ir/v1/Token
https://ipgrest.asanpardakht.ir/v1/TranResult
https://ipgrest.asanpardakht.ir/v1/Verify
https://ipgrest.asanpardakht.ir/v1/Settlement
https://ipgrest.asanpardakht.ir/v1/Reverse
https://ipgrest.asanpardakht.ir/v1/Cancel
https://asan.shaparak.ir

This service is provided by "Asan Pardakht Persian": [terms of use](https://asanpardakht.ir/), [privacy policy](https://www.shaparak.ir/).
Provider site: https://asanpardakht.ir/
Merchant portal: https://asanpardakht.ir/portals/
Network / regulator (Shaparak): https://www.shaparak.ir/

= Iran Kish (optional WooCommerce gateway) =

This plugin connects to Iran Kish IPG REST (technical guide V11) so WooCommerce can request a payment token, send the customer to the official Shaparak payment page, then confirm or reverse the transaction. It is needed only when the store owner enables the Iran Kish module and the customer chooses Iran Kish at checkout.

It sends the merchant terminal id, acceptor id, unique request id, amount in Rials, callback URL (including the request id), a DigitalEnvelope (AES-128-CBC + SHA-256 + RSA of the terminal password), and optionally the customer mobile number (`cmsPreservationId`) from the order. This happens when checkout requests a token and again on confirmation/purchase (or reversePurchase) after the bank returns the customer.

Endpoints used:
https://ikc.shaparak.ir/api/v3/tokenization/make
https://ikc.shaparak.ir/api/v3/confirmation/purchase
https://ikc.shaparak.ir/api/v3/confirmation/reversePurchase
https://ikc.shaparak.ir/iuiv3/IPG/Index/

This service is provided by "Iran Kish": [terms of use](https://www.irankish.com/), [privacy policy](https://www.shaparak.ir/).
Provider site: https://www.irankish.com/
Network / regulator (Shaparak): https://www.shaparak.ir/

= Bank Melli — Sadad (optional WooCommerce gateway) =

This plugin connects to Sadad Electronic Payment (Bank Melli’s licensed PSP, purchase guide 1.10) so WooCommerce can request a payment token, send the customer to the official Shaparak payment page, then verify the transaction. It is needed only when the store owner enables the Bank Melli module and the customer chooses Bank Melli at checkout.

It sends the merchant id, terminal id, amount in Rials, unique order id, Gregorian local date/time, callback URL, and a Triple DES signature (`SignData`). This happens when checkout requests a token and again on Verify after the bank returns the customer. Card data is entered only on the bank page. Calling Verify is the final confirmation; if it is not called, the amount is returned automatically after 15 minutes.

Endpoints used:
https://sadad.shaparak.ir/api/v0/Request/PaymentRequest
https://sadad.shaparak.ir/api/v0/Advice/Verify
https://sadad.shaparak.ir/Purchase

This service is provided by "Sadad Electronic Payment": [terms of use](https://sadadpsp.ir/), [privacy policy](https://www.shaparak.ir/).
Provider site: https://sadadpsp.ir/
Network / regulator (Shaparak): https://www.shaparak.ir/

= Pardakht Novin Arian (optional WooCommerce gateway) =

This plugin connects to Pardakht Novin Arian IPG REST (purchase guide I.P.IT.012.00) so WooCommerce can request a payment token, send the customer to the official Shaparak payment page, then confirm or reverse the transaction. It is needed only when the store owner enables the Pardakht Novin module and the customer chooses Pardakht Novin at checkout.

It sends the merchant corporation pin, amount in Rials, unique order id, callback URL, and optionally the customer mobile number (`Originator`, `09xxxxxxxxx`) from the order. This happens when checkout requests a token and again on Confirm (or Reverse) after the bank returns the customer. Card data is entered only on the bank page. Calling Confirm is required for next-day settlement; if it is not called, the amount is returned automatically after 15 minutes. Reverse is valid only after a successful Confirm and only within 15 minutes.

Endpoints used:
https://pna.shaparak.ir/mhipg/api/Payment/NormalSale
https://pna.shaparak.ir/mhipg/api/Payment/confirm
https://pna.shaparak.ir/mhipg/api/Payment/Reverse
https://pna.shaparak.ir/mhipg/api/Inquiry/TransactionInfoByToken
https://pna.shaparak.ir/mhui/home/index/

This service is provided by "Pardakht Novin Arian": [terms of use](https://pna.co.ir/), [privacy policy](https://www.shaparak.ir/).
Provider site: https://pna.co.ir/
Network / regulator (Shaparak): https://www.shaparak.ir/

= Pasargad Electronic Payment (optional WooCommerce gateway) =

This plugin connects to Pasargad Electronic Payment IPG REST (Parsa IPG 25.0) so WooCommerce can request a JWT, start a purchase, send the customer to the official Shaparak payment page, then inquire, verify, or reverse the transaction. It is needed only when the store owner enables the Pasargad module and the customer chooses Pasargad at checkout.

It sends the merchant username and password (token), terminal number, unique invoice id, invoice date, amount in Rials, callback URL, Referer (the store domain), and optionally the customer mobile number, email, and name from the order. This happens when checkout requests a purchase URL and again on payment-inquiry / verify-payment (or reverse-transactions) after the bank returns the customer. Card data is entered only on the bank page. Calling verify-payment is required so the amount settles; if it is not called, the amount is returned automatically after the terminal window (guide default 25 minutes). Reverse is valid only after a successful verify and only within that same window.

Endpoints used (cluster prefix `dorsa1`, `dorsa2`, or `nvcservice` as configured for the terminal):
https://pep.shaparak.ir/dorsa1/token/getToken
https://pep.shaparak.ir/dorsa1/api/payment/purchase
https://pep.shaparak.ir/dorsa1/api/payment/payment-inquiry
https://pep.shaparak.ir/dorsa1/api/payment/verify-payment
https://pep.shaparak.ir/dorsa1/api/payment/reverse-transactions
https://pep.shaparak.ir/dorsa2/token/getToken
https://pep.shaparak.ir/nvcservice/token/getToken

This service is provided by "Pasargad Electronic Payment": [terms of use](https://www.pep.co.ir/), [privacy policy](https://www.shaparak.ir/).
Provider site: https://www.pep.co.ir/
Network / regulator (Shaparak): https://www.shaparak.ir/

= SMTP email (optional) =

This plugin can send WordPress mail through an SMTP host **you** configure (your hosting provider, Google, and similar). It is needed only if you switch Email from host mail to SMTP.

It sends the outgoing message plus your SMTP username and password to that host when WordPress sends mail (orders, password resets, or the in-plugin test).

This service is provided by the SMTP host you enter. That host’s own terms of use and privacy policy apply. Pars Kit does not operate a mail service.

== Privacy ==

This plugin does not phone home or send data to Pars Kit servers.

When optional modules are enabled:

* **Admin activity log** (off by default): stores manager actions in a custom table on your site (user ID, timestamp, event summary, client IP from `REMOTE_ADDR`, field diffs). WooCommerce order edits may include billing/shipping fields in diffs. Retention is configurable; data is removed on uninstall.
* **SMTP**: host, username, password, and from-address are saved in `parskit-settings` on your server and used only with your SMTP provider.
* **Payment gateways**: checkout/verify traffic goes between your site and the bank; Pars Kit is not a payment intermediary.
* **External traffic blocker**: blocks outbound HTTP to non-whitelisted domains locally; nothing is sent externally about blocked requests.

== Third-party resources ==

* **Vazirmatn** (v33.003) — SIL Open Font License 1.1. Source: [rastikerdar/vazirmatn](https://github.com/rastikerdar/vazirmatn). License file shipped at `assets/admin/fonts/vazirmatn/OFL.txt`.
* **Payment method logos** (Behpardakht Mellat, SEP/Saman, Asan Pardakht, Iran Kish, Sadad/Bank Melli, Pardakht Novin, Pasargad) — trademarks of the respective licensed PSPs. Bundled only to identify the optional WooCommerce gateway on checkout.

== Screenshots ==

1. Dashboard — Jalali date conversion toggles
2. Speed — WebP and external traffic blocker
3. Payment gateways — Mellat, Saman, Asan Pardakht, Iran Kish, Bank Melli, Pardakht Novin, and Pasargad registration
4. Tools — Vazirmatn font, dashboard optimization, orders filter
5. Email — SMTP test send, then optional debug
6. Admin activity log

Screenshots for the WordPress.org plugin page are shipped in the directory SVN `assets/` folder (not inside the plugin ZIP).

== Changelog ==

= 2.0.8 =
* Blocker: blocked remote images keep a local blank src and stay hidden (no browser broken-image icon)
* Admin activity: description and retention stay visible; the log table appears when the module is on
* Directory tags (max 5): jalali, shamsi, woocommerce, webp, performance

= 2.0.7 =
* Admin menu PK icon uses WordPress core SVG handling (20px + svg-painter); removed extra admin-menu.css that could hide the icon until the item was current
* Blocker: keep WordPress admin-menu SVG data URIs (add_menu_page); do not replace with url("")
* Plugin header Description: WordPress + WooCommerce Jalali, Analytics, WebP, orders date filter, speed, outbound blocker, activity log, and one-click Iranian gateways
* Iranian IPG pack: Mellat, Saman, Asan Pardakht, Iran Kish, Sadad/Melli, Pardakht Novin, Pasargad (each off by default)

= 2.0.6 =
* Display name in Plugins list and directory: پارس کیت (slug remains pars-kit)
* WordPress admin menu uses the bundled PK logo; the plugin settings sidebar stays text-only
* Directory review: Analytics Jalali calendar CSS via wp_enqueue_style (no runtime style tags)
* Edit Order: native date field no longer uses off-screen offsets; leftover jQuery UI datepicker is parked
* Blocker: sanitize rest_route with WordPress helpers; keep core/WooCommerce admin layout CSS as files
* Tools: optional Persian-script checkout first/last name (off by default; classic + Checkout Block; accepts legacy-keyboard ي/ك)
* Compatibility header: WC tested up to 11.1
* Asan Pardakht IPG REST gateway (off by default; credentials in WooCommerce → Payments)
* Iran Kish IPG REST V11 gateway (off by default; credentials in WooCommerce → Payments)
* Bank Melli / Sadad IPG REST gateway (off by default; credentials in WooCommerce → Payments)
* Pardakht Novin Arian IPG REST gateway (off by default; credentials in WooCommerce → Payments)
* Pasargad Electronic Payment IPG REST gateway (off by default; credentials in WooCommerce → Payments)
* WooCommerce-only Tools/gateway toggles stay locked when WooCommerce is inactive (including after AJAX save)
* Directory review: no site-wide WebP/font admin nags (inline notices on the plugin screen only)
* Deactivate/Delete stay standard WordPress links
* Directory review: plugin header Description kept under 140 characters
* Directory review: bundled Vazirmatn OFL and PSP logos documented in the header and readme
* Sanitize remaining REST route / REQUEST_URI reads the same way as the blocker
* Directory review: "Tested up to" lives only in readme.txt (Plugin Check 1.8)
* Directory review: English Description (Plugin Check 1.8); search-focused copy for Jalali dates and named Iranian gateways
* Email tab: test send sits above SMTP debug

= 2.0.5 =
* Directory review: CSS/JS only via wp_enqueue / wp_add_inline_* (no raw style/script markup)
* Paths via plugin_dir_path/url, plugins_url, wp_upload_dir, theme-root helpers; wp-includes/wp-admin from ABSPATH

= 2.0.4 =
* Directory review: list every Mellat/Saman Shaparak URL; add terms of use and privacy policy links
* Blocker: resolve local CSS via site_url() / home_url() / content/plugins/uploads maps (no ABSPATH path join)

= 2.0.3 =
* Directory review: document Mellat / Saman / SMTP under External services (Shaparak hosts + official PSP sites)
* Receipt pages: bank auto-submit uses `wp_enqueue_script` / `wp_add_inline_script` (no raw `<script>` tags)
* Blocker: pair `ob_start` with `shutdown` `ob_end_flush`; rewritten CSS printed via `wp_register_style` / `wp_add_inline_style`

= 2.0.2 =
* Plugin Check: Latin Plugin Name **Pars Kit** (admin UI stays Persian); AJAX nonce verified in-scope; Mellat SOAP timeout via stream context (no `ini_set`)
* Code identity: `parskit` / `PARSKIT_*` internally; wordpress.org slug `pars-kit`
* Activity log: safer table name `{prefix}parskit_activity_log`, cron cleared on deactivate, product trash/delete logging, logout/user/search fixes
* Hardening: SMTP password save, IP from `REMOTE_ADDR`, ABSPATH guards, uninstall cleanup, Blocks registration, blocker scope radios
* Packaging: flattened nested folder so ZIP root contains `pars-kit.php`

= 2.0.1 =
* Directory identity and Plugin Check cleanup for wordpress.org submission
* Activity log SQL prepare pattern fixed for Plugin Check

= 2.0.0 =
* WordPress.org release packaging; Persian admin UI throughout; contributor `parskit`

= 1.9.0 =
* Admin activity log (default off) and Saman (SEP) gateway

= 1.8.x =
* Dashboard optimization, orders Jalali date filter, email/SMTP tab, WebP/UI polish

= 1.7.x =
* Multi-tab admin (Dashboard / Speed / Gateways / Tools / Email) with AJAX auto-save

= 1.6.x =
* Behpardakht Mellat gateway integration

= 1.5.x =
* External traffic blocker (domain whitelist)

= 1.4.0 =
* Local Vazirmatn admin font (no CDN)

= 1.3.x =
* WebP on upload (Imagick / WP image editor)

= 1.2.x – 1.0.0 =
* Shamsi core via `wp_date`; WooCommerce Analytics and orders date UI

== Upgrade Notice ==

= 2.0.8 =
Blocked remote admin images stay hidden. Activity log help stays visible when the module is off. Directory tags updated.

= 2.0.7 =
Admin menu icon uses core WordPress SVG coloring (no extra CSS). Description wording update. Iranian gateways remain off until enabled in Pars Kit.

= 2.0.6 =
Directory review: Analytics calendar CSS, Edit Order layout, WC 11.1 tested-up-to, optional Persian checkout names (off; legacy-keyboard ي/ك), Asan Pardakht, Iran Kish, Bank Melli, Pardakht Novin, and Pasargad gateways (off).

= 2.0.5 =
Directory review: enqueue APIs for blocker CSS and ABSPATH-based core path mapping. No settings or schema changes.

= 2.0.4 =
External-service links and CSS path resolution for subdirectory / custom content installs. No settings or schema changes.

= 2.0.3 =
WordPress.org review fixes: external-service documentation, enqueued gateway receipt script, explicit blocker output-buffer close. No settings or schema changes.

= 2.0.2 =
Plugin Check readiness (Latin name **Pars Kit**). Activity log table rename for MySQL safety; SMTP/Jalali/autoload fixes. Slug remains `pars-kit`.

= 2.0.1 =
Directory slug is `pars-kit`. No breaking changes to stored settings or schema.

= 2.0.0 =
Major release aligned with WordPress.org directory submit. No breaking settings/schema changes.

= 1.9.0 =
Optional admin activity log — enable under **Admin activity** (default off). Uninstall removes the log table.

= 1.5.0 =
Optional outbound traffic blocker — review the domain whitelist after enabling.

= 1.3.0 =
Optional WebP conversion on upload — enable under **Pars Kit** settings.
