=== Evoxup Membership — Membership, Licensing, & Universal Integrations ===
Contributors: evoxupteam
Tags: membership, licensing, woocommerce, webhooks, integrations
Requires at least: 6.5
Requires PHP: 8.3
Tested up to: 7.1
Stable tag: 1.9.5
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html
Donate link: https://evoxup.com/donate/

Professional membership and licensing for WordPress with products, plans, WooCommerce, secure webhooks, entitlements, and integrations.

== Description ==

Evoxup Membership is a WordPress platform for managing memberships, licensing, customers, products, entitlements, commerce fulfillment, and integrations from one administration area.

**This package is the 1.9.5 Professional/Commercial distribution line.** It continues from the 1.8.9 Professional build and is separate from the public WordPress.org 1.8.3 review branch. The plugin slug, data model, existing integrations, Marketplace, Update Manager, WooCommerce bridge, webhook fulfillment and WordPress mail transport remain compatible with the Professional line.

Built-in Membership functionality is not unlocked by a product license check. License/membership entitlement can still protect separately distributed commercial packages and services obtained through the Evoxup Repository/Marketplace.

= What Evoxup Membership manages =

* EVO Products as the canonical product identity used by Evoxup.
* Membership Plans and Product-to-Plan relationships.
* Customers and members, while preserving the native WordPress user ID when a WordPress account is linked.
* Membership lifecycle, status, start and expiration dates.
* EVO licenses, activations, verification rules, domains and entitlement state.
* Product and membership entitlements.
* Normalized order and transaction records.
* Purchase fulfillment from WooCommerce or verified external providers.
* Versioned REST/API integration surfaces for supported integrations.
* Marketplace catalog metadata for separately distributed Evoxup packages.

= Products, plans, members, and entitlements =

An EVO Product is the central commercial object. A Product can be linked to one or more Membership Plans, and a Membership Plan can include one or more Products.

A successful verified purchase can resolve the mapped EVO Product, create or update the Evoxup customer/member record, grant the configured Membership Plan, issue an EVO license when EVO licensing is selected, create entitlements, and record the normalized transaction.

A WordPress account and an EVO member record remain separate identities. When a matching WordPress account already exists, Evoxup can link it to the EVO member record without replacing the native WordPress user ID.

= Licensing =

Evoxup can issue and manage EVO licenses for Products configured to use EVO licensing. License verification can use the Product, license status, activation/site binding, membership entitlement, and configured tier requirements.

If a Product is configured to use another supported licensing provider, Evoxup does not force EVO license issuance and can preserve that provider's ownership of the licensing flow.

Built-in Evoxup Membership functionality is never unlocked by these license checks.

= WooCommerce integration =

WooCommerce is optional.

When WooCommerce is installed, an administrator can map WooCommerce products to EVO Products and define how the purchase should be fulfilled. A successful WooCommerce order can trigger the configured Evoxup membership, entitlement, customer/member, and licensing workflow.

When EVO licensing is selected, Evoxup can issue the corresponding EVO license. When another provider is selected, Evoxup respects that provider instead of generating a duplicate EVO license.

Evoxup uses supported WooCommerce APIs and declares compatibility with WooCommerce HPOS and Cart/Checkout Blocks for the integration paths used by the plugin.

= Verified webhooks and universal integrations =

Evoxup can receive verified commerce events from configured external providers. Webhooks are fulfillment inputs, not a remote administration channel.

A verified provider event can:

* Resolve a provider product to an EVO Product.
* Create or update the Evoxup customer/member record.
* Create or update the normalized order record.
* Grant, update, cancel, or revoke the configured membership or entitlement according to the verified event.
* Issue an EVO license when EVO is the selected licensing provider.
* Process supported refund, cancellation, and revocation events.

Webhook payloads cannot choose privileged WordPress roles, install or remove plugins/themes, change arbitrary WordPress settings, execute PHP or SQL, or perform arbitrary filesystem operations.

In the Professional build, a verified purchase may create or link a WordPress account when the integration is configured to do so. New accounts always use a fixed non-privileged role (`customer` when WooCommerce provides it, otherwise `subscriber`); the webhook payload can never choose a role. The native `wp_users.ID` remains canonical and EVO stores its own separate customer/member identity linked to it.

= Marketplace and external packages =

The bundled Extensions Marketplace is the Professional catalog and entitlement interface for separately distributed Evoxup packages. Signed Local ZIP packages can be installed and updated through the existing Professional Marketplace/Update Manager path, including the existing verification and rollback safeguards.

Public/free external packages do not require a paid entitlement. A license or membership key can verify access to separately distributed commercial packages or services; this does not change the Product/Plan/Member/License data model inside Membership.

= Updates =

The Professional distribution preserves the bundled Marketplace and Update Manager infrastructure from 1.8.8. Existing signed-package verification, installed-package state, update history, restore points and rollback behavior remain available.

Separately distributed packages follow their configured distribution/update channel. Entitlement for a commercial external package remains separate from the authority used for WooCommerce checkout and from the Product-specific License Source.

== External Services ==

Evoxup Membership can be used without a paid Evoxup license. Network communication occurs only for features that require or are configured to use an external service.

= Evoxup Repository / Marketplace =

Provider: Evoxup
Service URL: https://evoxup.com/
Terms of Service: https://evoxup.com/terms-of-service/
Privacy Policy: https://evoxup.com/privacy-policy/

When an administrator opens or refreshes the Marketplace catalog, the plugin may contact the official Evoxup Repository to retrieve package catalog metadata and compatibility information.

When an administrator verifies access to a separately distributed protected package, the request may include the requested package/version identifier, site URL or domain/site identifier, runtime compatibility information, and the configured license or membership key required for that external-package entitlement check.

When an administrator voluntarily submits a Marketplace rating or review, the plugin may send the package identifier, rating/review content, and the site-bound request information required to authenticate and protect that submission.

This service is not used to unlock functionality already included in Evoxup Membership.

= Configured external commerce providers =

Administrators may configure external providers or webhook integrations for purchase fulfillment. The exact provider and data flow depend on the integration selected by the site owner.

Inbound verified events can contain provider order and product identifiers, customer/order information needed for fulfillment, event status, timestamps, and signature or verification metadata.

If a configured provider requires outbound API requests, only the data required by that integration is sent under the administrator's configuration. The site owner should review the terms and privacy policy of each provider before enabling that integration.

= WooCommerce =

WooCommerce integration is local to the WordPress installation unless the site owner separately configures WooCommerce or another service to communicate externally. Evoxup Membership does not require an external Evoxup service merely to process a local WooCommerce order.

== Installation ==

1. Upload the `evoxup-membership` folder to `/wp-content/plugins/`, or install the plugin through the WordPress Plugins screen.
2. Activate **Evoxup Membership — Membership, Licensing, & Universal Integrations**.
3. Open the Evoxup administration menu.
4. Create or review your EVO Products and Membership Plans.
5. Configure licensing rules for Products that use EVO licensing.
6. Optionally map WooCommerce products to EVO Products.
7. Optionally configure verified external providers/webhooks under Integrations.
8. Use Marketplace only when you want to browse separately distributed Evoxup packages.

A Repository key is needed only when a separately distributed protected package/service requires entitlement; it is not a second WordPress user identity or a replacement for Product-specific licensing.

== Frequently Asked Questions ==

= Does the Professional build use a Repository key to unlock its built-in member screens? =

No. Repository entitlement is for separately distributed protected packages/services. Product licensing, memberships, WooCommerce authority and the native member experience are resolved independently.

= Do I need WooCommerce? =

No. WooCommerce is optional. Evoxup Products, Membership Plans, customers/members, memberships, licensing, entitlements, APIs, and supported webhook integrations can be used independently of WooCommerce where applicable.

= What is an EVO Product? =

An EVO Product is Evoxup's canonical product identity. It can be mapped to WooCommerce or another configured provider without creating a separate duplicate product model for every integration.

= Can one Product belong to more than one Membership Plan? =

Yes. Evoxup supports Product-to-Plan relationships that allow a Product to participate in one or more plans, and plans can include multiple Products.

= Does a webhook create WordPress administrator accounts? =

No. Verified webhook fulfillment cannot choose privileged WordPress roles and does not create WordPress users. It creates or updates Evoxup customer/member data and may link an already-existing WordPress account through the supported identity flow.

= Does Marketplace entitlement change WooCommerce or Product license ownership? =

No. Marketplace entitlement applies to separately distributed packages/services. Commerce authority and each EVO Product License Source are separate decisions in the 1.9.0 Control Plane.

= Does the WordPress.org plugin install external executable packages? =

No. The WordPress.org build does not install, update, roll back, or remove executable third-party add-on code through Marketplace.

= Does Core require an Evoxup key to update? =

No. Evoxup Membership Core updates through WordPress.org and does not require an Evoxup license or membership key.

== Screenshots ==

1. **Evoxup Dashboard** — Overview of membership, licensing, customers, products, and integration activity.
2. **Products** — EVO Product management and licensing/provider configuration.
3. **Membership Plans** — Build plans and connect Products to the memberships that grant them.
4. **Members and Licenses** — Manage member/customer records, memberships, licenses, activations, and entitlement status.
5. **WooCommerce Integration** — Map WooCommerce products to EVO Products and select the fulfillment/licensing behavior.
6. **Universal Integrations** — Configure external providers, verified webhooks, API credentials, and integration diagnostics.
7. **Extensions Marketplace** — Browse separately distributed Evoxup packages and review external-package entitlement status.
8. **Member Center / Access Experience** — Example of the user-facing membership and access information provided by Evoxup.

For the WordPress.org listing, upload the corresponding images as `screenshot-1.png` through `screenshot-8.png` in the plugin directory's WordPress.org `assets` area.


== Support Evoxup ==

Evoxup Membership is free software. If the plugin is useful to you and you would like to support continued development, you can make an optional one-time contribution.

Donate: https://evoxup.com/donate/

Donations are optional and do not unlock features, licenses, memberships, updates, support tiers, or any functionality included in the WordPress.org plugin.

== Changelog ==

= 1.9.5 =
* Updated bundled Update Manager to 3.5.0 with Cloud Native access/grant transport, signed Cloud invocation support and FREE Cloud Agent installation while preserving Local ZIP/Core update and recovery behavior.
* Updated bundled Marketplace to 2.4.0 with a dedicated Cloud Services tab, Agent install/connect state, entitlement-aware Activate/Deactivate actions and no Local ZIP installation for Cloud services.
* Simplified the Integration Editor so known providers use compact provider-specific setup while advanced API/webhook controls remain available without removing capabilities.
* Reorganized the Integration Editor into General, Provider API Verification, Webhook/IPN Security and Endpoints so outbound provider credentials cannot be confused with inbound webhook credentials.
* Added provider-neutral outbound transaction verification policies: Disabled (preserve current behavior), Advisory, and Required. Existing integrations remain unchanged until explicitly enabled.
* Added encrypted Provider API credentials, configurable adapter/auth/transaction endpoint, and read-only API connection testing without changing the database schema.
* Added a built-in Gumroad sales verifier using the configured Access Token and the provider sale lookup, while keeping Gumroad inside the generic provider-verification architecture.
* Test and live transactions continue through the same fulfillment pipeline after the selected verification policy passes; TEST remains an audit/environment marker rather than a fulfillment bypass.
* Preserved the 1.9.4 webhook compatibility repair, duplicate transaction protection, Marketplace live entitlement checks, Update Manager, licensing, membership and WooCommerce behavior.

= 1.9.4 =
* Marketplace now re-verifies the stored license/membership key live on every Marketplace page load and after catalog refresh, so stopped, frozen, expired, disabled or restored keys are reflected immediately.
* One live key verification is shared across the current Marketplace request to avoid duplicate authority calls from the Access box and package cards.
* Removed Repository endpoint/path editing from Marketplace; Marketplace now exposes catalog status and refresh only.
* Existing Update Manager, Repository trust, signed package verification, maintenance/recovery, FREE package behavior and Marketplace key-status colors are preserved.


= 1.9.3 =
* Unified professional Control Plane with dynamic extension discovery and operational shortcuts.
* Update Manager 3.4.1 adds built-in recovery readiness source and safer recovery diagnostics.
* Repaired Update Manager filesystem initialization and WordPress-managed staging for install, update, rollback, uninstall, self-update and recovery operations without changing the 1.9.3 release number.
* Fixed the Update Manager uninstall fatal caused by a missing filesystem initializer and preserved activation state when deletion cannot start.
* Marketplace 2.3.0 improves recovery-related update handling.
* Fixed the current Plugin Check translator-comment, nonce-sniff annotation, escaped role-badge output, catalog URL sanitization and short-description findings.


= 1.9.2 =
* Added Marketplace compatibility for the separately distributed Evoxup Member Administration extension, providing one unified member workspace for identity, memberships, licenses, activations, orders, entitlements and activity.
* Added private administrative notes to the existing EVO event timeline without creating a parallel notes/member database.
* Added granular Member Administration capabilities and Member Manager / Member Support access presets through the shared Access Extension Registry.
* Added safe EVO customer profile editing with optional synchronization to the already-linked WordPress/WooCommerce account; roles and capabilities are never overwritten by profile synchronization.
* Preserved Marketplace, Update Manager, WooCommerce Administration, Admin Editor and existing extension contracts; no database schema migration was introduced.

= 1.9.0 =
* Fix: EVO-owned products now receive generated canonical public product URLs through Membership Center; no manual Purchase URL is required for a public product page.
* Added the mandatory bundled Evoxup Admin Editor module as the owner of professional editing surfaces.
* Products and Membership Plans open in dedicated editors; Product and Plan descriptions use the native WordPress rich editor.
* Integrations now use a clean registry → Add/Edit workflow with separate Platform, Product Routing, REST API and Control Plane areas.
* Customers, Licenses, Access and Settings administration are routed through the Admin Editor module while Core remains the data/service authority.
* Restored the Professional Update Manager execution interface with updates, bulk updates, rollback, recovery and Repository security controls.
* Fixed the Update Manager package-card layout regression and synchronized mandatory bundled component versions.
* No destructive database migration; existing WooCommerce, webhook, mail, licensing, Marketplace and membership behavior remains in place.

= 1.8.9 =
* Unified Products, Plans, Members, Licenses, Integrations and fulfillment around a shared Control Plane without removing existing 1.8.8 Professional integrations.
* Added reversible Commerce Authority modes: Hybrid/provider-led or Full WooCommerce. Full WooCommerce owns price, checkout, payment and Woo order lifecycle while Product license ownership remains independent.
* Added provider-neutral WordPress user synchronization so WordPress, WooCommerce and compatible membership/community plugins converge on the same EVO customer instead of creating parallel identities.
* Added native frontend member login, registration, profile, active-member directory, plan-aware content restriction and payment/order history shortcodes.
* Added Gutenberg blocks for login, registration, profile, member directory and payment history while retaining all existing EVO blocks and shortcodes.
* Preserved the WordPress-native asynchronous mail path from 1.8.8; SMTP/mail plugins remain responsible for actual transport through `wp_mail()`.
* Preserved Marketplace, Update Manager, signed Local ZIP handling, webhooks, REST routing, licenses and existing database schema; no destructive migration is introduced.

= 1.8.8 =
* Fixed Marketplace install preflight to resolve the effective pinned Ed25519 trust anchor instead of incorrectly requiring a manually entered public key.
* Official Repository installs now reuse the verified/pinned key established by RepositoryClient.
* Bundled Update Manager 3.3.6.

= 1.8.7 =
* Updated the pinned official Evoxup Repository Ed25519 trust anchor to the current production key fingerprint.
* Verified the public key returned by the official Repository hashes to the pinned fingerprint before trust is established.
* Bundled Update Manager 3.3.5.

= 1.8.6 =
* Fixed same-host Repository detection: local REST dispatch now falls back to the canonical HTTPS endpoint when the Repository is on another WordPress context on the same domain.
* Prevents false Not connected Marketplace state caused by local rest_no_route/404 responses.

= 1.8.5 =
* PRO packages use a gold trophy badge and STAR packages use a gold crown badge in Marketplace.
* Paid Install actions remain visible in red while access is missing and switch to the normal WordPress action style after entitlement is granted.
* Professional Local ZIP extensions install and update under wp-content/evoxup-extensions after SHA-256 and Ed25519 verification.
* Same-domain Repository requests use internal WordPress REST dispatch while remote sites continue through the WordPress HTTP API.
* Bundled Marketplace 2.2.9 and Update Manager 3.3.3.

= 1.8.4 =
* Restored Marketplace install, update, and uninstall for signed Local ZIP packages in the Evoxup site build.
* Added same-domain Repository REST dispatch to avoid HTTP loopback failures when Marketplace and Repository share one WordPress site.
* Paid package actions are red while access is missing and return to the normal action color after entitlement is granted.
* Package access labels are normalized to FREE, PRO, and STAR for a clearer Marketplace.


= 1.8.3 =
* Restored a visible optional Support / Donate link inside Evoxup administration pages and in the WordPress.org readme.
* Donations remain completely optional and do not unlock or restrict any plugin functionality.

= 1.8.2 =
* Restored the bundled Marketplace visual interface using WordPress enqueue APIs after the WordPress.org compliance refactor.
* Kept Marketplace as a catalog/entitlement interface for separately distributed packages without restoring runtime executable-package installation.
* Updated the public product identity to **Evoxup Membership — Membership, Licensing, & Universal Integrations** and refreshed WordPress.org-facing documentation.

= 1.8.1 =
* Completed the main WordPress.org compliance pass for remote fulfillment, executable-package handling, script loading, audit sanitization, and external-service disclosure.
* Verified webhooks continue to create/update EVO member, membership, entitlement, order, and license records but no longer create WordPress users remotely.
* Removed Core-managed runtime install/update/rollback/uninstall of executable third-party add-ons and legacy custom executable storage paths.

= 1.8.0 =
* Clarified that every built-in Evoxup Membership function is free and that Core updates use the normal WordPress.org updater.
* Defined the boundary between free built-in functionality and separately distributed commercial packages/services.
* Clarified WooCommerce fulfillment, verified webhook integration, and free/external package access policy.

= 1.7.9 =
* Fixed managed update filesystem initialization and moved temporary update/rollback staging into WordPress-managed upgrade storage.
* Preserved signed download verification, post-update identity/version checks, restore points, and automatic rollback behavior for the pre-compliance update architecture.

= 1.7.8 =
* Resolved the remaining Plugin Check input-sanitization findings in Marketplace and Update Manager administration requests.
* No membership, entitlement, Repository, or product-model behavior changed in this maintenance release.

= 1.7.7 =
* Completed a broad WordPress.org remediation pass covering escaping, sanitization, nonce handling, translator comments, filesystem helpers, and rollback-storage location.
* Removed obsolete Remote Runtime/generated Cloud Proxy customer execution paths while preserving the membership/licensing model and Repository entitlement behavior.

== Upgrade Notice ==

= 1.9.2 =
Supports the separately distributed Evoxup Member Administration Marketplace extension on top of the existing Access Extension Registry without changing the database schema or replacing existing extensions.

= 1.9.0 =
Adds the mandatory Admin Editor module and restores the Professional Update Manager while preserving the existing Professional data schema, WooCommerce, webhook, licensing and asynchronous mail integrations.
