=== PowerSuite Modular Admin Toolkit ===
Contributors: powersuite
Tags: admin, security, performance, modules, toolkit
Requires at least: 6.8
Tested up to: 7.1
Requires PHP: 8.1
Stable tag: 1.1.2
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

90 free modules for WordPress admin, content, media, login, and email. Find tools in one dashboard and enable only what you need.

== Description ==

PowerSuite Modular Admin Toolkit brings everyday site-management tools into one WordPress dashboard. Customize your admin area, manage content and media, configure login options, and connect WordPress email to your chosen provider.

The free plugin includes **90 modules**. Search the Control Center, filter by category, save favorites, and enable the tools that fit your site. You do not need a PowerSuite account or license key to use the included free modules.

= What you can do with the free plugin =

* **Make the dashboard your own:** add an admin logo, adjust dashboard columns, hide unwanted dashboard widgets, and simplify the admin bar.
* **Work with content:** duplicate posts and menus, change post types, publish missed scheduled posts, and configure content expiration.
* **Manage images and media:** sanitize SVG uploads, regenerate thumbnails, set default featured images, and control upload sizes.
* **Adjust login and user workflows:** configure Google Sign-In, block selected usernames, use generic login errors, and display last-login and registration-date columns.
* **Manage site visibility:** edit robots.txt and ads.txt, configure a fallback redirect for 404 pages, and add breadcrumbs, a table of contents, reading time, or post-view counts.
* **Control optional WordPress behavior:** disable features such as emojis, front-end Dashicons, comments, and XML-RPC when your site does not need them.
* **Configure email delivery:** use SMTP or supported email-provider connections, send test emails, and configure fallback delivery and failure alerts.

= A workflow that fits your site =

Use favorites for frequently accessed modules and the Quick Launcher to find tools without returning to the module list. Save configuration presets or import and export settings for repeatable setup. Keep exported configuration files private.

Disabled modules do not run their feature logic; the shared plugin dashboard and core still load as needed. Test changes on staging, especially when another plugin controls the same behavior. This toolkit does not replace site backups or a complete security solution.

External integrations may need a provider account, credentials, and a paid service plan. Review the service and privacy details below before enabling them.

= Optional Pro add-on =

**WP PowerSuite Pro is a separate, paid add-on** for sites that need additional tools. Install it alongside the free plugin to manage its modules in the same Control Center.

Explore features and purchase the separate Pro add-on: [WP Powersuite Premium](https://wppowersuite.com).

Examples of what the Pro add-on provides:

* **Forms and AI assistance:** build forms manually or with AI assistance, manage entries, configure email notifications and webhooks, and generate image alternative text with AI.
* **Login and access controls:** add two-factor authentication, limit failed login attempts, customize the login URL, manage active sessions, and create temporary login links for support.
* **Custom content and site structure:** create custom post types, taxonomies, custom fields, and options pages; reorder posts and terms; and generate pages from CSV templates.
* **Media workflows:** organize media into folders, replace existing attachments, rename media files, define custom image sizes, and choose WebP or AVIF conversion where your server supports it.
* **Maintenance and troubleshooting:** create and restore local file and database backups, clean selected database data, check broken links, review activity logs, and manage redirects using exact, pattern, or regular-expression rules.
* **Email visibility:** review email logs, resend messages, configure scheduled reports, and customize core WordPress email templates.
* **Code and customization:** manage code snippets, header and footer code, custom admin CSS, admin menu organization, and list-table columns.
* **Client branding:** customize the login page and apply white-label names, branding, and support links through the add-on's White Label settings.

These features require the separately installed Pro add-on; their implementations are **not included in this WordPress.org download**. Pro cards in the free Control Center describe the add-on, not locked functionality bundled in the free plugin.

The free plugin works on its own. If you install Pro, keep this free plugin active alongside it. WordPress.org supplies free-plugin updates; Pro updates come from wppowersuite.com.

AI-assisted features require a supported provider connection. Provider accounts, API usage charges, and data policies are separate from the Pro purchase. Manual form building does not require an AI provider. Review the Pro add-on's readme for its requirements and external-service disclosures.

== Privacy ==

The free plugin makes no licensing requests. Enabled integrations, displayed avatars/logos, selected image imports, and explicitly submitted feedback can contact services as detailed below. Disabled modules do not contact these services. Alpine.js is bundled, not CDN-hosted.

== External services ==

= Email Delivery =

Email Delivery uses configured PHP mail, SMTP, or an email provider. WordPress mail and Test email send subject, body, sender, recipients, reply-to, attachments, and authentication information through that connection.

Test connection uses configured credentials. SMTP connects/authenticates without sending mail. API checks request account, permission, domain, or sender information. Emailit and Bird request a recent message record; SendLayer requests a recent delivery-event record. Responses can expose existing account mail information. Netcore and turboSMTP POST synthetic send requests with intentionally invalid sender/recipient addresses and subject/body `connection-test` to check authentication, without customer messages or attachments. Maileroo only checks locally for a sending key; Test email verifies delivery.

For provider SMTP delivery, an empty host uses the default relay below; an entered host overrides it. The relay receives mail content and SMTP credentials. API User-Agent headers include plugin name/version. Servers receive connection information, including your server's IP.

Connecting Gmail/Microsoft sends authorization code, application credentials, and callback URL to the provider's token endpoint; later sends may refresh tokens there. Configured SES event webhooks fetch SNS signing certificates and verified subscription-confirmation URLs containing subscription tokens. Sender-domain health checks query your DNS resolver for domain records.

Delivery webhooks authenticate using provider signatures or configured secrets. Mailgun requires its HTTP Webhook Signing Key and HTTPS.

* Other SMTP host you enter: the email content goes to that host. Use that host's own Terms and Privacy Policy.
* Amazon SES: regional `email.*.amazonaws.com` API hosts, `email-smtp.*.amazonaws.com` SMTP hosts, plus `sns.amazonaws.com` / `sns.*.amazonaws.com` certificate and subscription URLs when delivery-event webhooks are enabled. [Terms](https://aws.amazon.com/service-terms/) and [Privacy](https://aws.amazon.com/privacy/).
* SendGrid (Twilio): API `api.sendgrid.com` or `api.eu.sendgrid.com`; SMTP `smtp.sendgrid.net`. [Terms](https://www.twilio.com/en-us/legal/tos) and [Privacy](https://www.twilio.com/en-us/legal/privacy).
* Mailgun: API `api.mailgun.net` or `api.eu.mailgun.net`; SMTP `smtp.mailgun.org` or `smtp.eu.mailgun.org`. [Terms](https://www.mailgun.com/legal/terms/) and [Privacy](https://www.mailgun.com/legal/privacy-policy/).
* Brevo: API `api.brevo.com`; SMTP `smtp-relay.brevo.com`. [Terms](https://www.brevo.com/legal/termsofuse/) and [Privacy](https://www.brevo.com/legal/privacypolicy/).
* Google Gmail API: `accounts.google.com`, `oauth2.googleapis.com`, `gmail.googleapis.com`, and `www.googleapis.com`. [Terms](https://policies.google.com/terms) and [Privacy](https://policies.google.com/privacy).
* Microsoft Graph: `login.microsoftonline.com` and `graph.microsoft.com`. [Terms](https://www.microsoft.com/servicesagreement) and [Privacy](https://privacy.microsoft.com/privacystatement).
* Postmark: API `api.postmarkapp.com`; SMTP `smtp.postmarkapp.com`. [Terms](https://postmarkapp.com/terms-of-service) and [Privacy](https://postmarkapp.com/privacy-policy).
* Mailjet: API `api.mailjet.com`; SMTP `in-v3.mailjet.com`. [Terms](https://www.mailjet.com/legal/terms/) and [Privacy](https://www.mailjet.com/legal/privacy-policy/).
* MailerSend: API `api.mailersend.com`; SMTP `smtp.mailersend.com`. [Terms](https://www.mailersend.com/legal/terms-of-use) and [Privacy](https://www.mailersend.com/legal/privacy-policy).
* SMTP2GO: API `api.smtp2go.com`, `us-api.smtp2go.com`, `eu-api.smtp2go.com`, or `au-api.smtp2go.com`; SMTP `mail.smtp2go.com`. [Terms](https://www.smtp2go.com/terms/) and [Privacy](https://www.smtp2go.com/privacy/).
* Resend: API `api.resend.com`; SMTP `smtp.resend.com`. [Terms](https://resend.com/legal/terms-of-service) and [Privacy](https://resend.com/legal/privacy-policy).
* Mandrill (Mailchimp): API `mandrillapp.com`; SMTP `smtp.mandrillapp.com`. [Terms](https://mailchimp.com/legal/terms/) and [Privacy](https://www.intuit.com/privacy/statement/).
* SparkPost / Bird Email: classic SparkPost API keys use `https://api.sparkpost.com` or `https://api.eu.sparkpost.com`; Bird platform API keys use `https://us1.platform.bird.com` or `https://eu1.platform.bird.com`. SMTP defaults are `smtp.sparkpostmail.com` or `smtp.eu.sparkpostmail.com`. [Terms](https://bird.com/en-us/legal/terms) and [Privacy](https://bird.com/en-us/legal/privacy).
* Elastic Email: API `api.elasticemail.com`; SMTP `smtp.elasticemail.com`. [Terms](https://elasticemail.com/resources/usage-policies/terms-of-use) and [Privacy](https://elasticemail.com/resources/usage-policies/privacy-policy).
* SendLayer: API `console.sendlayer.com`; SMTP `smtp.sendlayer.com`. [Terms](https://sendlayer.com/terms-of-service/) and [Privacy](https://sendlayer.com/privacy-policy/).
* SMTP.com: API `api.smtp.com`; SMTP `send.smtp.com`. [Terms](https://www.smtp.com/policies/terms-and-conditions/) and [Privacy](https://www.smtp.com/policies/privacy-policy/).
* Netcore (formerly Pepipost): `https://emailapi.netcorecloud.net` or `https://apieu.netcorecloud.net`. [Terms](https://netcorecloud.com/email-api-terms-and-policies/) and [Privacy](https://netcore.ai/privacy-policy/).
* turboSMTP: API `api.turbo-smtp.com` or `api.eu.turbo-smtp.com`; SMTP `pro.turbo-smtp.com` or `pro.eu.turbo-smtp.com`. [Terms](https://serversmtp.com/terms-and-conditions/) and [Privacy](https://serversmtp.com/privacypolicy-eu-regulation-2016-79-gdpr/).
* Maileroo: `smtp.maileroo.com` for both the HTTPS email API and SMTP relay. [Terms](https://maileroo.com/legal/terms-conditions) and [Privacy](https://maileroo.com/legal/privacy-policy).
* Emailit: API `api.emailit.com`; SMTP `smtp.emailit.com`. [Terms](https://emailit.com/terms-of-service/) and [Privacy](https://emailit.com/privacy-policy/).
* Mail.baby (InterServer): API `https://api.mailbaby.net`; SMTP `relay.mailbaby.net`. [Terms](https://www.interserver.net/terms-of-service.html) and [Privacy](https://www.interserver.net/privacy-policy.html).

= Email failure alerts: Slack and Discord =

Enabled failure alerts send site name, provider name, and redacted error to your configured chat webhook after final delivery failure, at most once per 15 minutes. Errors may retain message-specific information; chat alerts exclude email bodies/attachments. Email alerts also use your selected mail connection and configured recipient, falling back to the admin email.

Slack uses hooks.slack.com: [Terms](https://slack.com/main-services-agreement) and [Privacy](https://slack.com/trust/privacy/privacy-policy).

Discord uses discord.com or discordapp.com: [Terms](https://discord.com/terms) and [Privacy](https://discord.com/privacy).

A developer can explicitly allow another HTTPS webhook host. Review that recipient's Terms and Privacy Policy before configuring it.

= Customizer image imports =

Importing Customizer settings with image downloads requests URLs from the import and creates Media Library attachments. Each host receives the URL, server IP, and HTTP request information. Hosts are arbitrary; review their Terms and Privacy Policy before importing.

= Admin Logo images from configured hosts =

Admin Logo displays configured admin-bar/menu image URLs. External hosts receive direct browser requests on settings previews and pages displaying the logo, including front-end admin bars: image URL, viewer IP, browser information, and policy-permitted referrer. Images are not copied into the Media Library. Hosts are arbitrary; review their Terms and Privacy Policy before configuring them.

= Gravatar avatar images =

Automattic's Gravatar supplies default WordPress avatars. Enabled Local User Avatar prepares a profile-editor fallback; Remove Admin Bar Items requests avatars when replacing the account greeting. Unless another avatar filter overrides them, browsers request `https://secure.gravatar.com/avatar/`, sending the profile email's hash, size/default/rating options, and initials if selected. Gravatar receives viewer IP, browser information, and policy-permitted referrer. The profile-editor fallback can render even with Show Avatars off, a local upload, or a hidden preview. [Terms](https://wordpress.com/tos/) and [Privacy](https://automattic.com/privacy/).

= Optional deactivation feedback =

"Submit & Deactivate" stores feedback and a diagnostic snapshot locally (up to 50 records), including site/admin details, plugins/theme, enabled modules, browser/environment, and recent errors.

It sends WP PowerSuite your reason/comments, site URL/hash, administrator/submitting-user emails, plugin/WordPress/PHP/database versions, theme, installed/active plugins, enabled modules, license status (not key), browser/OS, language, user role, hosting/server, memory, cache/CDN, HTTPS, and cron information at `https://wppowersuite.com/wp-json/licensor/deactivation-feedback` to investigate issues and improve the plugin. Automatic diagnostics exclude raw errors, log excerpts, local user IDs, passwords, API keys, and license keys. The recipient receives server IP and normal HTTP information. [Terms](https://wppowersuite.com/terms-of-service/) and [Privacy](https://wppowersuite.com/privacy-policy/).

Sharing is optional. "Skip & Deactivate" collects/sends nothing; opening/closing the dialog sends nothing. Developers can override/disable the recipient via constants/filters and must disclose replacement recipients and their Terms/Privacy before collecting feedback.

The separate "You may contact me by email about this feedback" checkbox defaults checked. Submissions include this yes/no preference; uncheck to decline follow-up. It neither sends email nor subscribes you to marketing. Skip sends no contact permission.

= Google Sign-In =

Enabled Google Sign-In requires your OAuth Client ID/Secret. Clicking sign-in opens `https://accounts.google.com`; after approval, your site sends authorization code, client ID/secret, and callback URL to `https://oauth2.googleapis.com/token`, then uses the access token at `https://openidconnect.googleapis.com/v1/userinfo` for email, display name, and profile-image URL to sign in/create a local account.

Social sign-in and its CAPTCHA gate use separate first-party HttpOnly browser-binding cookies, expiring after ten minutes and cleared on matching verification. They are not sent to providers or used for tracking. Use HTTPS in production.

Google avatar URL storage defaults enabled. While sign-in is enabled/configured, later avatar views can load saved images directly from their host, including for viewers not signing in; local uploads can override them. Hosts receive image URL, viewer IP, browser information, and policy-permitted referrer. Images are not copied into the Media Library. Disabling new URL storage does not remove saved URLs.

This service is provided by Google: [Terms](https://policies.google.com/terms) and [Privacy](https://policies.google.com/privacy).

= Facebook and GitHub Sign-In =

This plugin ships a shared OAuth HTTP helper that can request access tokens and user profiles from Facebook Graph and GitHub. Google Sign-In in this free plugin uses that helper. Facebook and GitHub sign-in modules ship in the separate Pro add-on; the helper that performs the token and profile requests is part of this plugin.

Requests require the matching module installed, enabled, and configured with your OAuth application. Choosing sign-in opens provider authorization with application ID, callback URL, permissions, and security state. After approval, your site exchanges authorization code/application credentials for an access token, then retrieves account ID, name, permitted email, and profile image to sign in/create a WordPress account. No WordPress password is sent. GitHub may request `GET /user/emails` with that token and `user:email` permission; see [API documentation](https://docs.github.com/en/rest/users/emails#list-email-addresses-for-the-authenticated-user).

Facebook uses `https://www.facebook.com` for authorization and `https://graph.facebook.com` for token and profile requests: [Terms](https://www.facebook.com/legal/terms) and [Privacy](https://www.facebook.com/privacy/policy/).

GitHub uses `https://github.com` for authorization and tokens, and `https://api.github.com` for profile and email requests: [Terms](https://docs.github.com/en/site-policy/github-terms/github-terms-of-service) and [Privacy](https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement).

= Google Analytics 4 =

Enabled Analytics Integration requires a GA4 Measurement ID. Default Consent Mode waits for a CMP's analytics-storage consent or the `wppsmodule_allow_analytics` filter (default false) before requesting scripts/sending pageviews. Disabling Consent Mode allows immediate tracking unless that filter blocks it.

On each included front-end page view, the visitor's browser requests `https://www.googletagmanager.com/gtag/js` and then sends the Measurement ID, page URL, and standard GA4 event data to Google Analytics (`https://www.google-analytics.com` / `https://analytics.google.com`).

This service is provided by Google: [Terms](https://policies.google.com/terms) and [Privacy](https://policies.google.com/privacy).

= Google reCAPTCHA =

This integration requires the separate Pro add-on. The free plugin's admin script still contains the Test connection loader. Enabled reCAPTCHA loads `https://www.google.com/recaptcha/api.js` and related `https://www.gstatic.com` assets when you click Test connection. Protected front-end forms exchange browser tokens with Google; your site posts the token and secret key to `https://www.google.com/recaptcha/api/siteverify` for anti-spam verification.

This service is provided by Google: [Terms](https://policies.google.com/terms) and [Privacy](https://policies.google.com/privacy).

= Cloudflare Turnstile =

This integration requires the separate Pro add-on. The free plugin's admin script still contains the Test connection loader. Enabled Turnstile loads `https://challenges.cloudflare.com/turnstile/v0/api.js` when you click Test connection. Protected front-end forms exchange browser tokens with Cloudflare; your site posts the token and secret key to `https://challenges.cloudflare.com/turnstile/v0/siteverify` for anti-spam verification.

This service is provided by Cloudflare: [Terms](https://www.cloudflare.com/website-terms/) and [Privacy](https://www.cloudflare.com/privacypolicy/).

== Bundled libraries and source code ==

Alpine.js 3.17.2 is bundled as minified production JavaScript from the official npm package. Source code, license, and build instructions are available at https://github.com/alpinejs/alpine.

SVG Upload includes svg-sanitize 1.0.0 (GPLv2 or later), with a prefixed PHP namespace to avoid plugin conflicts. Its source and license are available at https://github.com/darylldoyle/svg-sanitizer and in modules/svg-upload/includes/svg-sanitize. Sanitization runs locally. External resources, unsafe CSS and active content are removed; SVG files with ambiguous IDs, excessive complexity or invalid reference graphs are rejected.

== Installation ==

1. Check that your site runs WordPress 6.8 or later and PHP 8.1 or later. Back up your site before making changes.
2. In Plugins > Add New, search for PowerSuite Modular Admin Toolkit and install it. Alternatively, upload the free plugin ZIP using Upload Plugin.
3. Activate the plugin and open PowerSuite > Modules.
4. Search or filter the module list, enable one tool at a time, and open its settings where available.
5. Review the affected site pages or workflow after each change. Avoid enabling overlapping functionality in multiple plugins.
6. For email or social sign-in integrations, configure your provider credentials and test the connection or sign-in flow before relying on it.

== Frequently Asked Questions ==

= Is the free plugin fully functional? =

Yes. The 90 included modules work without a PowerSuite license key. Some integrations require a third-party account or credentials, and that provider may charge for its service. Pro is a separate, optional add-on.

= Do I need to enable every module? =

No. Enable only what your site needs. Disabled modules do not run their feature logic, though the shared plugin core still loads. There is no guaranteed speed improvement from installing the toolkit; results depend on the modules you use and your site.

= Can I use it alongside other plugins? =

Check for overlapping features before enabling a module. For example, use one system to route WordPress email or manage a particular redirect. Test changes on staging; compatibility with every plugin and theme cannot be guaranteed.

= Why do I see Pro modules in the Control Center? =

The list can show cards describing modules available in the separate Pro add-on. Those cards are informational; their premium implementation is not bundled with this free plugin. Use the tier filter to focus on free modules.

= Does the plugin send data to external services? =

The free plugin makes no licensing requests. Configured integrations, displayed remote images, selected imports, and feedback you choose to submit can contact external services. The Privacy and External services sections explain when requests happen, what data is sent, and the providers' policies.

= Where can I get help? =

Use the Support tab on this plugin's WordPress.org page for free-plugin questions. Include your WordPress, PHP, and plugin versions, the affected module, and steps to reproduce the issue. Do not post passwords, API keys, license keys, exported configuration, or private site data.

= How do command-line exports work? =

WP-CLI exports print to standard output. To create a local file, use shell redirection: `wp powersuite settings export > settings.json` or `wp powersuite redirects export > redirects.csv`. The former file argument and `--file` option are no longer supported. Store exported site configuration privately.

Settings, module, cache, status and cron commands are included in Lite. Backup, database cleanup, broken-link and redirect-manager commands require the separate Pro add-on, where their implementation is shipped.

= Do existing shortcodes still work? =

Legacy breadcrumbs, post views, table of contents, and social sign-in shortcodes in normal post and widget content are translated while rendering, unless another plugin owns that shortcode. Saved content is not changed. For new content and direct PHP `do_shortcode()` calls, use `[wppsmodule_breadcrumbs]`, `[wppsmodule_post_views]`, `[wppsmodule_toc]`, `[wppsmodule_social_login]`, or the provider-specific `[wppsmodule_google_sign_in]`, `[wppsmodule_facebook_sign_in]`, and `[wppsmodule_github_sign_in]` tags. Each requires its corresponding module; Facebook and GitHub require the separate add-on.

= Where are configuration backups stored? =

The configuration editor and debug tools in the separate Pro add-on use encrypted, non-autoloaded database backups rather than raw PHP files in uploads. Up to 50 backups per tool are retained. Existing recognized backups are migrated and verified before their old files are removed. An administrator is notified if migration cannot complete. Changing the site's authentication keys can make older encrypted backups unreadable; keep independent site backups.

= Should I delete this plugin after installing Pro? =

No. Pro is an add-on. Keep this free plugin active.

= Is white-label branding included in the free plugin? =

No. The free plugin can show the white-label feature, but the branding form and apply logic are part of Pro.

= Can the free plugin run custom CSS, JavaScript, or PHP snippets? =

No. Header and footer code, custom admin CSS, code snippets, and Alpine initialization scripts are Pro features. The free Alpine.js module only loads the bundled Alpine.js library.

= Will WordPress.org updates overwrite Pro? =

No. WordPress.org updates this free plugin only. Pro updates come from wppowersuite.com.

== Screenshots ==

1. The Control Center with module search, category filters, favorites, and individual enable controls. Pro cards describe the separate add-on.
2. General settings for the Quick Launcher, interface appearance, and module cache.

== Changelog ==

= 1.1.2 =
* Hardened social sign-in state, CAPTCHA tokens, and nonce handling.
* Preserved encoded redirect-loop cookie values and validated feedback fields individually.
* Expanded external-service documentation, including email connection tests and remote images.

= 1.1.1 =
* Bound social sign-in attempts to their initiating browser and preserved configured second-factor verification.
* Corrected author-slug metadata cache invalidation and new-site initialization on multisite.
* Added the wppsmodule internal prefix with upgrade handling for existing settings, content, schedules, and credentials.
* Prepared complete cleanup queries at the database call site.
* CLI exports print to STDOUT; wp-config backups stay in the database, not as PHP files under uploads.
* Documented Facebook Graph, GitHub, SparkPost, Netcore, and Mail.baby API hosts with Terms and Privacy links.
* Module search also matches tags, so tools are easier to find.
* Replaced site-wide featured-image and expiration metadata joins with post-ID batch scans.
* Improved Pro package separation, file-write boundaries and optional feedback consent.
* Updated Lite package naming for WordPress.org review.
* Bundled Alpine.js source attribution added to the readme.
* Fixed content expiration across site timezones and legacy expiration dates.
* Improved AJAX compatibility and preserved existing breadcrumb shortcodes.
* Fixed cached avatar assignments, view counts, and passwords containing backslashes.
* Limited data cleanup to literal plugin-owned prefixes.

= 1.1.0 =
* Improved module admin screen asset loading.
* Social account creation uses Subscriber role and respects site registration settings.
* Debug log and snippet files stay under the WordPress uploads directory.

= 1.0.9 =
* Free package ships only working free modules. Premium module PHP remains in the separate Pro add-on.
* Safer Temporary Login behavior and tighter checks around 2FA, CAPTCHA, and configuration tools.
* Media Rename updates real attachment URL pairs instead of rewriting by basename.
* External services documentation expanded for optional providers.

= 1.0.8 =
* Improved Temporary Login vendor access controls.
* Improved admin checks across security and CAPTCHA modules.
* Pro module screens load correctly when Pro is installed.

= 1.0.7 =
* Added WP-CLI commands and hardening for login URL and code tools.

== Upgrade Notice ==

= 1.1.2 =
Back up your site before updating. Update Lite and Pro together if you use the Pro add-on, then clear cached assets. Includes security hardening and improved request validation.

= 1.1.1 =
Back up your database and plugins first. Pro users must install matching Lite and Pro packages together during maintenance. This build migrates internal identifiers; custom PHP integrations need updating. Clear page/CDN caches after updating.
