=== VerifiedReply ===
Contributors: joe08
Tags: reviews, product reviews, review requests, verified reviews, woocommerce
Requires at least: 5.8
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 4.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Send unlimited review requests free. Each reply becomes a WooCommerce review with a verification link any shopper can follow.

== Description ==

Your site asks your customers for a review by email. Their reply becomes a review on the product they bought.

The customer does not make an account, follow a link or load an image to leave a review, they simply hit reply, the way they would to anybody. The reply is tied back to the order it answers. Somebody at your end approves it, and it publishes as an ordinary WooCommerce review.

Every published review carries a link to a verification page. A shopper can follow it and read an independent record of the reply behind the review. When it arrived. Which email provider signed it. Whether the words on the product page still match the reply. Whether the reply came from the person the shop wrote to.

= What it does on its own, free and unlimited =

Everything in this list works the moment you activate the plugin. No account, no key, no sign-up and no trial. There is no limit on how many review requests you send, there never has been, and there is no paid tier of the sending.

* Sends a review request per order, on an order status change and with a delay you configure.
* Lets you write a different request per product category, so a customer is asked about what they actually bought.
* Asks once per order, and once per WooCommerce subscription rather than once per renewal.
* Can catch up on past orders, within a window you set.
* Lets each request send on its schedule, or only when you press Send now.
* Replies come back to the address your shop already sends from, like any other email.

= What an optional VerifiedReply account adds =

* Routes replies to the service instead of your inbox, and pushes them back to your site.
* Holds every reply for a person to approve. Nothing is published automatically.
* Publishes an approved reply as a native WooCommerce review on the product bought.
* Adds a verification link to the review card.
* Never rewords, merges or re-attributes a review. Shortening is marked, disclosed and reversible.
* Adds no schema markup of its own. Your reviews are WooCommerce reviews and your theme marks them up as it already does.

WooCommerce is required. The plugin will not activate without it.

= What it does without an account =

Install it, write a request, and it sends review request emails from your own site on your own schedule. It adds no Reply-To, so replies come back to the address your shop already sends from and land in your inbox like any other email. No account, nothing configured, no data leaves your site.

Used that way it is a complete review request mailer, free and unlimited, for as long as you want to use it. What it does not do is collect those replies, publish them, or add a verification link, because it never sees them.

= What an account adds =

Connect a VerifiedReply account and the request emails carry a Reply-To at verifiedreply.io. Your customer's reply goes to the service instead of your inbox. The service checks it, sends it back to your site for somebody to approve, and hosts the verification page the published review links to.

VerifiedReply is a service operated at https://verifiedreply.io. It has a free tier, and paid plans for shops that want more replies each month. The verification happens there rather than on your site on purpose. The point of the verification page is that a shopper does not have to take the shop's word for anything. So the evidence behind it cannot sit with the shop being checked.

Here is what leaves your site, and when.

**Fifteen minutes after you install the plugin, once per site and never again.** The site address, the plugin version, the WooCommerce version, the WordPress version, and the same self-check figures the plugin's own Settings screen shows you: whether Action Scheduler is draining, how many review requests are published, whether the service addresses are set, whether credentials are present, whether replies are waiting, and the site timezone. **This one is only sent if you have already connected the plugin to a VerifiedReply account.** If you have not, nothing is sent and nothing is recorded. It carries no account name and no key, nothing about your customers, your orders or your reviews, and it is sent once for the lifetime of the site.

**Your customers' replies go to VerifiedReply, not to you.** The review request email your shop sends carries a Reply-To address at verifiedreply.io. When your customer replies, their message is delivered to VerifiedReply rather than to your shop. VerifiedReply keeps that message in full, indefinitely, because the message itself is the evidence behind the verification page. The reply is never published by the service.

**When a review request is sent.** Your account name, the WooCommerce order ID, and the customer's email address, name and company as held on that order.

**When a review is published, edited or taken down.** Your account name, the published review text, the reviewer's first name as it appears on the review, the product name, the address of the review on your site, an order reference, the time of publication, and internal identifiers for the reply and the comment. The star rating is not sent.

**Once a day.** Your account name and the version of this plugin. Nothing about your customers, your orders or your reviews. The service answers with two yes or no flags: whether it is still vouching for your shop, and whether it is holding replies that have not reached you yet.

**When you connect the site.** A one-time enrolment code, your site address, the address of this plugin's inbound route, and a signing secret this site generates for itself.

Everything above goes over HTTPS to verifiedreply.io and nowhere else. Nothing is sent to any other third party, and no third-party script is loaded on your site or your customers'. Every request carrying your account's data is signed with a key held only by your site and the service. The enrolment exchange is not signed, because at that point your site has no key to sign with. The install ping is not signed either, and carries no key and no account name.

If you connect an account, you are then using the VerifiedReply service, which is governed by its own terms and privacy statement. If you never connect one, none of this applies to you:

* Terms of service: https://verifiedreply.io/terms/
* Privacy statement: https://verifiedreply.io/privacy/

= What it costs =

The plugin is free. Sending review requests is free, unlimited, and stays that way.

The service's free tier verifies and publishes two replies a month, with no contract. That is twenty-four verified reviews a year, each one carrying its own verification page a shopper can follow and check. Steady, real proof on your product pages, at no cost, and a lot of small shops never need more than that.

Paid plans raise how many replies reach your shop each month. Nothing is lost if you go over: replies above your allowance are still collected and checked at the service, and they arrive when you move up. Pricing is at https://verifiedreply.io.

== Installation ==

The review request emails work as soon as you install the plugin, free and with no limit on how many you send. An account is only needed for the replies.

1. Install and activate the plugin. WooCommerce must be installed and active first.
2. Go to VerifiedReply, then Emails, and publish a review request. Write it in your own words. Set the order status that starts the clock and how many days after it the email goes.
3. Optionally write a second request per product category, so customers are asked about what they bought.
4. Optionally use Catch Up to ask customers who ordered before you installed the plugin, within a window you choose.

That is enough to start asking. Replies come back to the address your shop already sends from.

To have those replies verified and published as reviews:

5. Go to https://verifiedreply.io, press Get started, and ask for an account. You will be given an enrolment code.
6. Go to VerifiedReply, then Settings, and either paste your enrolment code and press Connect, or press Confirm on an enrolment we have offered your site. Only confirm one you were expecting.

From then on replies arrive on the Replies screen instead of your inbox. Each one waits for somebody to approve it before it is published.

== Frequently Asked Questions ==

= Is the plugin free? =

Yes, and it is not a trial. Everything the plugin does on your own site is free and stays free: writing review requests, scheduling them, a different request per product category, catching up on past orders, and sending as many as you like. None of it is metered, capped or reduced later.

The separate VerifiedReply service is what verifies replies and hosts the verification pages. Its free tier covers two verified replies a month. Paid plans raise that number. You never have to connect it, and the plugin is fully working without it.

= Do I need an account with VerifiedReply? =

No. Sending review requests works on its own, free and unlimited, and the replies come back to your normal inbox. An account is only for the rest: collecting the replies, publishing them as reviews, and the verification page each published review links to. See the description above for the full list of what is sent to it and when. Until you connect an account, nothing is sent.

= Do I have to publish every reply? =

No. Every reply is held until somebody approves it. Choosing what to publish is allowed. Rewording is not, and the plugin provides no way to do it.

= Does the customer have to do anything differently? =

No. They hit reply and write whatever they want to say. There is no link to click, no image to load, no account to make and no app. What ties the reply to the order travels with the message their email programme sends back.

= What is actually being checked? =

Four things. That every word published is a word the customer wrote. That the reply came back on an email about that order. That it came from the person your shop wrote to. That the message left the account it says it left, unaltered.

= Can the plugin decide a review is verified? =

No, and that is deliberate. Your site is the party being checked, so nothing it says about itself is evidence. The plugin records what the service tells it. It can withhold its own mark. It can never grant one.

= Does it work without WooCommerce? =

No. WooCommerce is the only hard dependency and the plugin will not activate without it. There is no second dependency and none is planned.

= What happens if I stop paying? =

You drop to the free tier and carry on. Sending review requests is unaffected, because it is free either way. Reviews already published stay on your site, and their verification pages go on showing what was found. Two verified replies a month keep coming through.

= Will star ratings appear in search results? =

The plugin publishes ordinary WooCommerce reviews and adds no markup of its own, so whatever your theme already marks up is what search engines read. Valid markup makes a page eligible. Search engines decide when to show a rating.

= Does it send anything to my customers without asking? =

It sends one review request per order, on the schedule you set, and nothing else. Every request states plainly that a reply may be published as a review and how to object. That wording is a field on your own request email and you can edit it.

== Screenshots ==

1. The VerifiedReply home screen. How many requests have gone out, how many replies have come back, and how many are waiting for somebody to decide about them.
2. Every reply that has arrived, with the order it answers and what was decided about it. Nothing publishes on its own. Each one waits for a person.
3. Further down the same list. Two published reviews show why the VerifiedReply mark was withheld from them, one for a failed wording check and one for a failed signature check. The plugin can withhold its own mark. It can never grant one.
4. Deciding about a single reply. The customer's words are shown as they were typed, the rating is the one they stated themselves, and the choice is to publish, leave it, or not publish with a reason. There is no rating box to fill in and no way to reword what the customer wrote.
5. Review request emails. Write as many as you like, including a different one per product category so a customer is asked about what they actually bought. Free, and no account is needed.
6. Scheduling a request. The order status that starts the clock, how long to wait, an age limit so old orders are left alone, and the product categories it covers. All of the sending and scheduling is free, unlimited and works out of the box.
7. WooCommerce's own Reviews screen, with a VerifiedReply column showing which reviews carry the mark and which had it withheld.
8. A product page. Two replies carry the VerifiedReply mark and the third does not, because its wording check failed. These are ordinary WooCommerce reviews and your theme styles them as it already does.
9. The verification page a shopper reaches from the mark. It is served by the service rather than by the shop, so the shop being checked is not the one answering for itself.

== Changelog ==

= 4.0.0 =
* Every reply a customer sends is now emailed to you as it arrives. This is on once you install, and you did not have to ask for it.
* Until now a reply sat on the Replies screen until somebody went and looked at it. If that is once a week, a customer who took the trouble to write waits a week for their review to appear. So does anybody asking you to stop emailing them, and every request you send promises them they can ask.
* The email arrives looking like the customer's own message. Same subject, their words, and the reply address set to theirs, so pressing Reply in your mail program answers the customer directly. It is sent from your shop's own address with the customer's name on it, because mail leaving your server cannot claim to come from their address without being treated as spam.
* Under a line at the bottom there is a link that opens that reply on your site, ready to publish. The email publishes nothing and there is no way to publish from it. Publishing still happens on your site and nothing about that has changed.
* If somebody is asking not to be emailed, that is said at the top in plain words. Nothing acts on it by itself. It is put in front of you because it is the one thing here that should not look like ordinary correspondence.
* The setting is under VerifiedReply, then Settings, under Collection. "Email each reply as it arrives" turns it off. Underneath it, "Email those replies to" takes one or more addresses separated by commas. Leave that empty and the emails go to your site's admin email, so it is worth checking that address is one somebody reads.
* A very long reply is cut short in the email, with the whole of it still on the screen. Each reply is emailed once, however many times it is delivered to your site.
* This is the first release on WordPress.org. The plugin now updates through WordPress like any other plugin in the directory.

= 3.14.0 =
* The plugin's own screens now look like VerifiedReply. Home, Send requests, Catch-up and Settings take the same design as the VerifiedReply website. Nothing your customers see has changed, and nothing about how requests are sent, how replies are collected or how reviews are published has changed either.
* You can now choose a light or a dark screen, at the foot of Settings under Appearance. The choice belongs to you rather than to the shop, so two people administering the same shop each get their own. Leave it alone and the plugin follows whatever your computer is set to.
* Settings is grouped into boxes rather than one long list, with the mark's ink and your light or dark choice together under Appearance.
* Replies and Emails are WordPress's own list screens and are unchanged.
* The download is larger, roughly 220KB against 150KB, because the plugin now carries the design and its typeface. None of it loads on your shop's front end.

= 3.13.1 =
* If your shop runs PHP 7.4 you have not been offered an update in some time. The plugin has always run on PHP 7.4, the same version WooCommerce asks for and the one its own header declares, but the file telling WordPress which shops may update said 8.0. Any shop on 7.4 was passed over silently.
* It now says 7.4. If several versions have gone by without your seeing them, this update brings you up to date in one go.
* Nothing in the plugin itself has changed since 3.13.0.

= 3.13.0 =
* The plugin's own help text now reads the same on every shop. A lot of the wording on the Replies, Home, Send requests, Catch-up and email screens was only reaching shops with their site language set to English (UK). Every other shop got a longer, more technical version of the same sentence.
* The Send requests screen can no longer be stopped by a malformed submission. It would have ended the page with an error rather than refusing the send and saying why.
* The two small blocks of styling on the plugin's admin screens now load through the WordPress style queue.
* The plugin's four built-in sentences are now written where translators can read them.
* The plugin no longer carries its own translation files. WordPress.org builds those from the source.
* The two REST routes the service uses now name what protects them, which was already true and simply was not written down.
* No change to how replies are collected or published.

= 3.12.1 =
* Corrects the plugin header, which named the same address as both the plugin URI and the author URI. The plugin URI has been dropped and the author URI kept. Nothing about how the plugin works has changed.

= 3.12.0 =
* A review request can now be set to send only when you ask for it. Each email has a new Send automatically box, and it is on. Turn it off and the email stays published and stays on the VerifiedReply box on every order, where Send now still sends it.
* Your existing emails are unchanged and still send automatically. The new box is ticked on all of them.
* Turning an email off still stops it entirely, Send now included. That is why the new box exists: switching off was the only way to take an email out of the automatic sending, and it took the button with it.
* The order box now says why an email did not go out, rather than offering a button that could never have worked.
* The install ping now waits until the plugin is connected to an account. It used to send the site address and a diagnostic profile fifteen minutes after install on every site, connected or not.
* Nothing re-arms that ping yet, so a shop that connects more than fifteen minutes after installing sends nothing.
* Direct-access guards on every file, escaped admin output, and three global functions renamed to carry the plugin's prefix.
* Your shop's pages do less work on every visit. Two database queries were running on every page a customer loaded, and a third on any product page showing a verified reply. All three are gone.
* A product page carrying several verified replies is a lot smaller. The mark now draws once per page rather than once per reply, around 80% less markup on a page showing twenty. Nothing looks different.
* The plugin's own screens have a new look. Home, Send requests, Catch-up and Settings take their colours, panels and form styling from the VerifiedReply site. Nothing has moved or been renamed, and no other screen is affected.
* No change to how replies are collected or published.

= 3.11.2 =
* A shop on a plan is now told in three places when the service is holding replies it has not received yet. There is still no count, because the service sends a yes or no and the plugin has nothing to count.

= 3.11.1 =
* The VerifiedReply home screen shows a new shop a setup checklist rather than a red warning panel.
* Settings no longer lists checks it has not measured.

= 3.11.0 =
* A review containing an angle bracket reads as a match again on the verification page. Both halves now normalise those characters before comparing. Records already written keep the verdict they have.

= 3.10.0 =
* Fixed: a customer's reply could put working markup on your product page. A review is now stored so that it always reads as text. Nothing is deleted and the customer's words stay as they were typed.
* Fixed: an account able to write posts could reach the review request editor and publish a template of its own. Review requests are now restricted to people who can manage WooCommerce.
* Fixed: an enrolment offered to a site was accepted automatically. It now waits for somebody who can manage WooCommerce to press Confirm.
* The "verified owner" badge now appears only where the reply could be tied back to an order.
* The site now checks in with the service once a day, sending its account name and plugin version.

= 3.9.0 =
* The verification page now names the review it is about: the reviewer, the product, and a link back to the review on your own site.
* A change to the name on a review now reaches the verification page. Taking a review down clears the name and the link.

= 3.8.0 =
* The mark on your review cards is now always drawn in the brand colours, with a Light option for dark review cards.
* The Collection screen is now called Settings. Its address has not changed.

= 3.7.1 =
* Corrected the wording of the "What if we stop paying?" answer in the help panel.

= 3.7.0 =
* Connecting a site no longer means copying a secret by hand. A one-time enrolment code does it.
* The two service addresses fill themselves in when they were blank. A box saved empty is still read as a decision.

= 3.6.0 =
* Fixed: the header logo sat under the admin bar on the Replies and Emails screens below 600px.

= 3.5.0 =
* The "View version details" window now has Description, Installation and FAQ tabs.
* A Settings link on the Plugins screen.

= 3.4.1 =
* The plugin shows its own icon on the Updates screen, served from your own site rather than from verifiedreply.io.

= 3.4.0 =
* The privacy and consent line in a review request can be reworded without a plugin release.
* Fixed: an admin whose profile language differed from the site's saw the wrong one.

= 3.3.0 =
* The plugin can update itself using WordPress's own update mechanism. No licence key. The check sends nothing identifying your site. Every download is checked against a published fingerprint. Automatic updates are off deliberately.

= 3.2.1 =
* Fixed: a review left without a star rating could be given one star the next time it was edited.

= 3.2.0 =
* The plugin's own wording moved into one catalogue, so a correction no longer waits on a release. Your request emails are not part of this and stay in your own site.

= 3.1.0 =
* Shortening a review is recognised more accurately, so a trim that keeps the customer's words is not treated as a rewrite.
* Verification links moved onto verifiedreply.io. The old address still redirects.

= 3.0.0 =
* Checking who a reply came from moved to the service, and the plugin records the answer rather than working it out. A check a site runs on itself is not evidence.
* The mark is withheld when the sender check or the email signature check fails. The review still publishes.

Older entries are in CHANGELOG.md in the plugin's repository.

== Upgrade Notice ==

= 4.0.0 =
Every reply a customer sends is now emailed to you as it arrives, so a review is not waiting on somebody opening the Replies screen. Turn it off in Settings, under Collection. No change to how requests are sent or how reviews are published.

= 3.11.2 =
A shop on a plan is now told when the service is holding replies it has not received yet. No change to collecting, sending or publishing.

= 3.11.0 =
A review containing an angle bracket reads as a match again on the verification page. Records already written are unchanged.

= 3.10.0 =
Update for this one. A customer's reply could put working markup on your product page, an account able to write posts could publish a review request template, and an offered enrolment was accepted with nobody at your end involved. All three are fixed.

= 3.2.1 =
Fixes a review with no star rating being given one star when it was next edited.
