=== AlpineConsent ===
Contributors: alpineconsent
Tags: cookie consent, gdpr, privacy, consent management, cookie banner
Requires at least: 6.0
Tested up to: 6.6
Requires PHP: 8.0
Stable tag: 0.6.7
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Lean, EU-native cookie consent and compliance widget for WordPress.

== Description ==

AlpineConsent is a lightweight cookie consent management platform (CMP), built and hosted in Austria/Germany. It helps WordPress sites comply with the GDPR, the Austrian TKG 2021, and the German TDDDG, without the weight of typical enterprise consent plugins.

The plugin enqueues the real AlpineConsent banner — granular consent categories (necessary/preferences/statistics/marketing), prior-blocking of scripts and iframes, Google Consent Mode v2 — and holds any script you assign a category to under its own AlpineConsent menu until a visitor grants it. A script left unassigned loads normally, so activating the plugin never breaks a site by default.

Scripts are found for you automatically — no need to dig through theme or plugin code for a WordPress "handle." As visitors load your pages (or immediately, via the "Scan homepage now" button), every tracked script is listed with a suggested category already filled in, matched against a real, curated database of thousands of known cookies and providers. You just confirm or change it. That same scan also reads the cookies your homepage actually sets, showing each one's real description, retention period, and data controller on a separate Cookies tab.

The banner's layout (bar top/bottom, floating, or modal), title/description text, and button set are all configurable on the Banner tab — buttons can be shown as buttons or plain links, reordered, and you can add your own Privacy Policy/Cookie Policy/Imprint links (with a one-click autofill for WordPress's own Privacy Policy page). A small "Powered by AlpineConsent" badge shows on the free plan.

The banner's language auto-detects: if you run WPML or Polylang, it follows that visitor's own detected language dynamically — whatever languages your site is actually configured for, not a fixed list — otherwise it follows your site's own WordPress language setting. You can also set a fixed default (German, English, or Italian) on the Banner tab, overriding both. A detected language without a full translation yet falls back to English rather than showing anything broken.

Not yet implemented: automatic theme-matching with your site's own colors/fonts, consent logging, and languages beyond German/English.

== Installation ==

1. Upload the `wordpress-plugin` directory to `/wp-content/plugins/alpineconsent`, or install via the WordPress plugin screen once packaged.
2. Activate the plugin through the 'Plugins' screen in WordPress.
3. Go to the AlpineConsent menu item — assign a category to any discovered script you want held until consent.

== Changelog ==

= 0.6.7 =
* Fixed the new Settings tab's own section headings ("AlpineConsent account", "Behavior") rendering in a near-invisible dark color against the dark card background — found live, right after 0.6.6 shipped.
* Fixed a real testing gap in the Connect flow: connecting a local WordPress test site (e.g. wp-env/Local/Valet, all plain http) always failed with a confusing "returnUrl must be https" error, even though local testing was always meant to work — localhost/127.0.0.1 is now correctly exempted, and the error message for a real non-local, non-https site is now a clear, specific explanation instead of a bare technical string.

= 0.6.6 =
* New "Connect to AlpineConsent" button on a new Settings tab — links this site to your AlpineConsent account (sign in on alpineconsent.com, confirm, and you're brought straight back) so the plugin knows your real plan, without ever copy-pasting a key by hand. A site you never connect keeps working exactly as before, fully standalone.
* New Settings tab also adds two toggles — show/hide the banner and turn script-blocking on/off — plus company details (used for automatic legal-text generation in a future release).

= 0.6.5 =
* Fixed "Scan homepage now" only ever adding brand-new scripts/cookies to the Suggested column — an already-discovered script or cookie kept its very first suggestion forever, even after later plugin updates taught the classifier to recognize it correctly. Rescanning now refreshes the suggestion for already-known entries too, without ever touching a category you've already assigned yourself.

= 0.6.4 =
* Category suggestions synced against the public scanner's own classifier, closing a real gap between the two: recognizes jQuery and other WordPress-core-bundled libraries, WordPress core's own @wordpress/* packages, plugins that serve their tracker from /wp-content/uploads/ (Burst Statistics and others), must-use plugins (/wp-content/mu-plugins/ and VIP's /wp-content/client-mu-plugins/), and Cloudflare's own /cdn-cgi/ path (email obfuscation and similar built-in features, recognized on any Cloudflare-proxied site). Also adds around two dozen real hosts and several WordPress plugin slugs found scanning live sites this session (Osano, DataDome, NoBid, Optimizely, Sailthru, Complianz, and others). A handful of already-recognized plugins/themes (Divi, Elementor, Contact Form 7, and others) now get a real category suggestion instead of none at all.

= 0.6.3 =
* Fixed "Check Again" (Dashboard -> Updates) not actually re-checking for a new version — this plugin's own update cache wasn't being cleared alongside WordPress's own, so a manual check could still show stale results.
* Fixed the dropdown arrow rendering oversized and overlapping option text; the custom-links table now actually reserves the URL column its own width instead of squeezing it back down.
* Category suggestions now also recognize well-known plugins (WooCommerce and similar) from their /wp-content/plugins/ URL path, for scripts served from the site's own domain where the host alone gives no clue.

= 0.6.2 =
* Fixed the branded admin theme: buttons and dropdowns could become unreadable on hover/focus (text same color as background), the masthead now shows the real site logo, and the custom-links table is no longer capped to a fixed width.
* Category suggestions now also check the script's WordPress handle name (e.g. "csrf", "analytics", "pixel") when its source URL alone doesn't match a known provider.

= 0.6.1 =
* The settings page is now visually branded to match alpineconsent.com — navy background, Consent Green accent, card-based sections — instead of bare, unstyled Settings API chrome.

= 0.6.0 =
* Settings moved out from under Settings into their own top-level AlpineConsent menu item, reorganized into Banner / Scripts & Categories tabs, with a Save button at both top and bottom and "Scan homepage now" moved directly above the scripts table.
* Category labels updated to Functional (Essential) / Preferences / Statistics / Analytics / Marketing / Tracking; auto-suggestion matching extended to a few more well-known providers.
* The banner description now preserves line breaks instead of collapsing multi-line text to one line; the "Manage preferences" panel's Save button now sits directly with the checkboxes it saves.
* The plugin now checks for and can install updates the normal WordPress way (Plugins list "Update now"), without needing WordPress.org.

= 0.5.0 =
* Automatic banner language detection: follows WPML or Polylang's own per-visitor language when either is active, otherwise your site's WordPress language setting. A new "Language" dropdown under Settings -> AlpineConsent lets you fix it to German or English instead, overriding both.

= 0.4.0 =
* Banner customization: layout (modal, bar top/bottom, floating), title/description text, and a configurable button set (show/hide, reorder, button-or-link style) for Accept/Reject/Manage, plus custom link buttons (e.g. Privacy Policy, Cookie Policy, Imprint) with a one-click autofill from WordPress's own Privacy Policy page.
* The banner's language now follows the site's own WordPress language setting (German or English).
* A "Powered by AlpineConsent" badge is now shown on the banner (free plan).

= 0.3.0 =
* Automatic script discovery: every tracked script is found as visitors load your pages (or on demand via a "Scan homepage now" button), with a suggested category pre-filled for well-known trackers. Replaces the old manual-handle-entry textareas with a single table.

= 0.2.0 =
* Real prior-blocking: a `script_loader_tag` filter holds any script assigned a category (via the new Settings -> AlpineConsent page) until a visitor consents to that category.
* The loader now enqueues the real AlpineConsent widget (granular categories, blocking engine, Consent Mode v2) instead of a placeholder stub.

= 0.1.0 =
* Initial development skeleton: plugin bootstrap and stub loader enqueue.
