=== Frumbik Affiliate Hub – Affiliate Links, Amazon Product Displays, Click Tracking & Geo-Targeting ===
Contributors: mariuszkobak
Donate link: https://frumbik.com/donate/
Tags: affiliate links, amazon products, click tracking, link management, analytics
Requires at least: 6.2
Tested up to: 7.0
Requires PHP: 8.1
Stable tag: 2.5.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Free affiliate link management, Amazon product displays, click tracking, and GA4 integration for WordPress.

== Description ==

Affiliate links are the backbone of your revenue, but managing them shouldn't be a full-time job. **Frumbik Affiliate Hub** turns scattered, ugly affiliate URLs into clean branded links — and gives you the analytics, Amazon integration, and automation tools to earn more from every click.

Stop paying for features that should be free. Frumbik Affiliate Hub is **100% free**, open source, and packed with capabilities that rival — and often exceed — the most popular premium affiliate plugins on the market.

= Link Management & Cloaking =

Transform messy URLs like `https://partner-site.com/ref?id=12345&campaign=xyz` into clean, trustworthy links like `yoursite.com/go/best-hosting`. Organize everything with categories and tags, and insert links from the Gutenberg or Classic editor in seconds. Your visitors see professional links. You see higher click-through rates.

= Destination Rules: Geo-Targeting, Expiration & A/B Testing (NEW) =

Send German visitors to amazon.de and Americans to amazon.com — per link, no code. Schedule links to expire (show a 404, redirect to a fallback URL, or auto-unpublish), and split-test destination URLs with weighted A/B rotation — results appear right in your analytics dashboard, with bot traffic filtered out. Every one of these is a paid add-on in premium competitors; here they are free.

= Amazon Products Integration (NEW) =

Display product boxes, comparison tables, and bestseller lists from Amazon — directly in your content. Supports **22 Amazon marketplaces** with automatic geo-targeting, so visitors always land on their local store. A built-in **TOS Compliance Engine** handles price freshness, affiliate disclaimers, and link transparency automatically. No competitor offers this level of compliance out of the box.

= Price History Charts & Drop Alerts (NEW) =

Show your readers how an Amazon product's price moved over the last 90 days with `[afh_price_history asin="B0..."]` — a clean chart rendered on your own server, no external chart service. Get an e-mail the moment a tracked price drops by more than your chosen percentage, plus an optional weekly summary of clicks, top links and broken links.

= Analytics & Click Tracking =

Know exactly which links perform and where your clicks come from. The **Enhanced Analytics dashboard** shows interactive charts, geographic data on a world map, browser and device breakdowns, and unique visitor tracking. Export everything to CSV for deeper analysis.

= Google Analytics 4 Integration (NEW) =

Send affiliate link click events directly to your **GA4 property** — including link slug, ASIN, marketplace, and page URL. Works with your existing Google Analytics setup. Optionally load gtag.js from the plugin, or use your own. No coding required.

**Core Link Management**

* 🔗 **Link Cloaking** — Clean, branded redirect URLs with 301/302/307 support
* 📁 **Categories & Tags** — Organize hundreds of links effortlessly
* ✏️ **Editor Integration** — Insert links from Gutenberg blocks or TinyMCE toolbar
* 📋 **Shortcodes** — Use `[frumbik_link id="123"]` anywhere in your content
* 🔄 **Import/Export** — Bulk import from CSV/JSON, export for backup or migration
* 🔑 **QR Codes** — Generate downloadable QR codes for any affiliate link
* 🌐 **Query Forwarding** — Pass URL parameters through cloaked links to destination

**Amazon Products Module (NEW)**

* 🛒 **Product Boxes** — 4 layouts that showcase Amazon products and drive clicks
* 📊 **Comparison Tables** — Drag-and-drop builder for side-by-side product comparisons
* 🏆 **Bestseller Lists** — Auto-updating grids from any Amazon category
* ⚡ **Zero-API Mode** — Display manually added products, no API credentials needed
* 🌍 **22 Marketplaces** — Automatic geo-targeting replaces Geniuslink ($5-48/mo)
* ✅ **TOS Compliance Engine** — Automated disclaimers, price checks, and transparency
* 📦 **Bulk ASIN Import** — Add up to 200 products at once
* 🧱 **5 Gutenberg Blocks** — Product Box, Product Link, Comparison Table, Bestseller List, Product Grid
* 📈 **Price History** — Track price trends and time your recommendations
* 🔮 **Creators API Ready** — Future-proofed for Amazon's new API (PA-API 5.0 deprecated April 2026)

**Analytics & Tracking**

* 📊 **Enhanced Analytics** — Interactive dashboard with ApexCharts, filtering, and CSV export
* 🌍 **GeoLocation Tracking** — World map analytics with MaxMind GeoIP2 + 3 fallback APIs
* 👤 **Unique Visitor Detection** — 24-hour fingerprinting with session management
* 📱 **Device Detection** — Browser, OS, and device breakdowns for every click
* 🔍 **Keywords Autolinker** — Automatically convert keywords in your content to affiliate links
* 🔗 **Link Scanner** — Detect broken links with scheduled scans and email alerts

**Google Analytics 4 (NEW)**

* 📈 **GA4 Event Tracking** — Send click events with link slug, ASIN, marketplace, and page URL
* 🏷️ **Custom Events** — Track affiliate clicks alongside your other GA4 data
* ⚙️ **Flexible Setup** — Load gtag.js from the plugin or use your existing tag

**Advanced Modules**

* ⚡ **Performance Monitor** — System optimization and caching insights
* 🏥 **Health Monitor** — Diagnostic tools and error logging
* 🧩 **Modular Architecture** — Enable only what you need; disable the rest
* 🌐 **Multilingual** — English, Polish, German, and Spanish out of the box
* 📱 **Mobile Responsive** — Admin interface works on any device

= Why Choose Frumbik Affiliate Hub? =

**It's free.** Not "free with limits" or "free trial" — genuinely free and open source under GPLv2. No upsells, no premium tier, no nag screens.

Most affiliate plugins charge annual subscriptions for features like link cloaking, auto-linking, click analytics, Amazon product displays, or geo-targeting — and you often need **multiple paid plugins** to cover everything. With Frumbik Affiliate Hub, you get all of these capabilities **in one plugin, completely free**. No annual fees, no feature gates, no "upgrade to unlock" prompts. Just install and use everything from day one — including features you won't find anywhere else, like the TOS Compliance Engine and built-in GA4 event tracking.

Approved and distributed through **WordPress.org**. Follows WordPress Coding Standards. All SQL queries use prepared statements. All output is escaped. Nonce verification on every form.

= Perfect For =

* **Bloggers** who monetize with affiliate links and want clean URLs
* **Amazon affiliates** who need product boxes, comparison tables, and geo-targeting
* **Content creators** who want to track which links actually earn money
* **Niche site builders** running multiple affiliate programs at once
* **Marketing agencies** managing affiliate links across client sites

The full shortcode reference (all attributes with worked examples) is in the FAQ: "What shortcodes are available?"

== Installation ==

= Automatic Installation =

1. Log in to your WordPress dashboard
2. Navigate to Plugins > Add New
3. Search for "Frumbik Affiliate Hub"
4. Click "Install Now" and then "Activate"

= Manual Installation =

1. Download the plugin zip file
2. Upload it via Plugins > Add New > Upload Plugin
3. Activate the plugin through the 'Plugins' menu in WordPress

= After Activation =

1. Go to Affiliate Hub in your WordPress admin menu
2. Configure your settings under Settings tab
3. Enable desired modules in the Modules tab
4. Start creating your first affiliate links!

= System Requirements =

* WordPress 6.2 or higher
* PHP 8.1 or higher
* MySQL 5.6 or higher / MariaDB 10.0 or higher
* Minimum 64MB PHP memory limit (128MB+ recommended)
* cURL support for link validation
* MaxMind GeoIP2 database for geographical analytics (optional)

== Frequently Asked Questions ==

= How do I create my first affiliate link? =

1. Go to AffiliateHub → Add New
2. Enter your affiliate URL and a descriptive title
3. Optionally customize the slug and settings
4. Click Publish to create your clean link

= Can I track clicks and conversions? =

Yes! The Enhanced Analytics module provides comprehensive tracking including:
- Real-time click analytics
- Geographic data with world map visualization
- Browser and device detection
- Unique visitor identification
- Export capabilities for further analysis

= How does the Keywords Autolinker work? =

The Keywords Autolinker automatically converts specified keywords in your content into affiliate links:
1. Enable the module in Settings → Modules
2. Configure keywords in Settings → Keywords Autolinker
3. Set up keyword-to-link mappings
4. The plugin automatically converts keywords in posts and pages

= Is the plugin GDPR compliant? =

Frumbik Affiliate Hub is designed with privacy in mind:
- Click tracking and geolocation are **disabled by default** — you must explicitly enable them
- IP address anonymization option available (enabled by default)
- When geolocation is enabled, visitor IPs are sent to third-party APIs (ipapi.co, ip-api.com, or ipinfo.io) to resolve country/city — see each service's privacy policy
- The plugin registers its data collection practices with WordPress Privacy Tools (Tools → Privacy Policy)
- You are responsible for updating your site's privacy policy to reflect any tracking you enable

= Can I monitor link health? =

Absolutely! The Link Scanner module provides:
- Automated broken link detection
- Regular monitoring of all affiliate links
- Email notifications for issues
- Bulk health checks
- Detailed reports on link status

= How do I customize the link structure? =

1. Go to Settings → General
2. Set your preferred link prefix (default: "go")
3. Choose link behavior (301/302 redirects)
4. Configure SEO options
5. Your links will use the format: yoursite.com/go/your-slug

= Does it work with caching plugins? =

Yes! Frumbik Affiliate Hub is compatible with major caching plugins and includes:
- Performance optimization features
- Caching-friendly code structure
- Cache-busting for analytics when needed
- Integration with popular caching solutions

= Can I import existing affiliate links? =

Yes! Use the Import/Export feature to:
- Import links from CSV or JSON files
- Bulk upload affiliate URLs
- Export existing data for backup
- Migrate from other link management tools

= How do I enable modules? =

1. Go to AffiliateHub → Settings → Modules
2. Toggle the modules you want to enable
3. Configure each module in its respective settings tab
4. Some modules may have dependencies that need to be enabled first

= How do I display an Amazon product box? =

1. Enable the Amazon Products module: AffiliateHub → Settings → Amazon → "Enable Amazon Products" (or via the Modules tab)
2. In the same Amazon tab, enter your Amazon Associates Partner Tag and pick your default marketplace
3. Add the shortcode to any post or page: `[afh_product asin="B08N5WRWNW"]` — you can also paste a full Amazon product URL instead of the ASIN
4. Or use the "Amazon Product Box" Gutenberg block and pick the product visually

No Amazon API credentials? Zero-API mode still works: add products manually under AffiliateHub → Amazon Products (title, price, image), and the plugin renders the box and builds your tagged affiliate link from the ASIN automatically. See "What shortcodes are available?" below for all attributes and more examples.

= What shortcodes are available? =

**Affiliate link** — insert a cloaked affiliate link anywhere in your content:

`[frumbik_link id="123"]`
`[frumbik_link slug="my-link" text="Check it out"]`

Attributes: `id`, `slug` or `title` (pick one to select the link), `text` (anchor text), `class`, `target`, `rel`.

**Amazon Product Box** — display a full product box for any Amazon product (requires the Amazon Products module — see the FAQ entry above):

`[afh_product asin="B08N5WRWNW"]`
`[afh_product url="https://www.amazon.com/dp/B08N5WRWNW"]`
`[afh_product asin="B08N5WRWNW" layout="vertical" show_rating="1" show_prime="1" cta_text="Check Price on Amazon" cta_color="#FF9900"]`

Attributes: `asin` (10-character ASIN — or simply paste a full Amazon product URL), `url` (Amazon product URL, takes priority over `asin`), `marketplace` (e.g. US, DE, UK — defaults to your setting), `layout` (`horizontal`, `vertical`, `compact`, `mini`, `cards`), `show_rating` (0/1), `show_prime` (0/1), `cta_text` (button label), `cta_color` (hex color).

**Inline Amazon product link** — a tagged text link inside a sentence:

`[afh_product_link asin="B08N5WRWNW"]this speaker[/afh_product_link]`
`[afh_product_link asin="B08N5WRWNW" text="this speaker"]`

Attributes: `asin`, `url`, `text` (anchor text if not used as an enclosing tag), `marketplace`, `show_tooltip` (0/1).

**Amazon comparison table:**

`[afh_comparison asins="B08N5WRWNW,B09B8V1LZ3,B07XJ8C8F5" highlight="B08N5WRWNW"]`
`[afh_comparison id="42"]`

Attributes: `asins` (comma-separated), `id` or `slug` (a saved comparison from the Comparison Builder), `fields` (default `price,rating,prime`), `highlight` (ASIN to emphasize), `layout` (`table`, `cards`), `title`, `marketplace`, `max` (default 5).

**Amazon bestseller list:**

`[afh_bestsellers keyword="wireless headphones" limit="5" layout="grid" columns="3"]`

Attributes: `keyword` or `node` (browse node ID — one of the two is required), `marketplace`, `limit` (default 5), `layout` (`grid`, `list`), `columns` (default 3), `show_rank` (0/1), `show_price` (0/1), `show_rating` (0/1), `title`.

**Amazon price history chart:**

`[afh_price_history asin="B08N5WRWNW"]`
`[afh_price_history url="https://www.amazon.com/dp/B08N5WRWNW" title="Deal tracker"]`

Attributes: `asin`, `url` (takes priority over `asin`), `marketplace`, `title` (heading override).

Shows the product's recorded price changes over the last 90 days as a chart, followed by the current price and the required Amazon disclaimer. History is collected by the background refresh cron, so the chart appears once the price has actually moved at least once — a brand-new product shows a "no price changes recorded yet" note instead. The chart is drawn as plain SVG on your server: no JavaScript library and no external chart service. To restyle it, copy `price-history.php` from the plugin's `Rendering/Templates/` folder into `your-theme/affiliate-hub/amazon/`.

Every Amazon shortcode except the price history chart also has a matching Gutenberg block (Product Box, Product Link, Comparison Table, Bestseller List, Product Grid) — search for "Amazon" in the block inserter if you prefer blocks over shortcodes.

= What languages are supported? =

Frumbik Affiliate Hub supports multiple languages:
- English (default)
- Polish (Polski)
- German (Deutsch) 
- Spanish (Español)
- Community translations welcome!

== Screenshots ==

1. Main affiliate links management dashboard
2. Enhanced Analytics dashboard with interactive charts and world map
3. Link creation interface with advanced options
4. Advanced analytics with geographic data and filtering
5. Link management with categories, tags and bulk operations
6. Keywords Autolinker configuration and keyword management
7. Link Scanner reports and health monitoring
8. Module management with dependency visualization
9. Settings and configuration options across multiple tabs
10. TinyMCE editor integration with link insertion

== Changelog ==

= 2.5.1 =
* Fix: The "Include bot traffic" checkbox had no effect on the Recent Activity table — crawler visits were always listed there, no matter how the filter was set, while the summary cards and charts above it filtered correctly. The table (and its pagination counter) now follows the checkbox like everything else on the dashboard
* Fix: CSV export ignored both "Include bot traffic" and "Unique clicks only". Worse, exports from sites with more than 5,000 clicks used a different code path that filtered correctly — so the same settings produced different files depending on how much data you had. Both paths now agree
* Improved: Ticking "Include bot traffic" refreshes the dashboard immediately, the same as "Unique clicks only" — previously it did nothing until you also pressed "Apply Filters"

= 2.5.0 =
* NEW: Price history chart for Amazon products — the new `[afh_price_history asin="B0..."]` shortcode shows how a product's price moved over the last 90 days, drawn as plain SVG on your own server (no JavaScript library, no external chart service), with the current price and the required Amazon disclaimer. The template is theme-overridable
* NEW: Price drop alerts — get an e-mail when a tracked product's price falls by more than your chosen percentage (Amazon settings). Only real drops trigger it, and at most one alert per product per day
* NEW: Weekly e-mail report — an opt-in Monday-morning (or any day/hour you pick) summary: clicks this week versus last week, top 10 links, bot traffic share and broken links from the latest scan (Analytics settings)
* NEW: Unknown ASINs used in inline product links, comparison tables and price history charts now create stub products automatically, so every ASIN in your content shows up in the Amazon Products list ready for enrichment (previously only the product box shortcode did this)
* Fix: The Link Scanner report e-mail counted broken links differently than it listed them — links you had marked as ignored inflated the headline count and produced a phantom "…and N more" line, while forbidden/SSL failures were missing from the count entirely. Both now use the same set
* Fix: Price history dates in the product editor were shown in UTC instead of your site's timezone, and the editor's chart could freeze on a product's oldest records once it had more than 90 price changes
* Fix: A failing mail server could leave other plugins' e-mails formatted as HTML and sent under this plugin's name for the rest of the request; all plugin e-mails now share one template that always cleans up after itself
* Developers: New `frumbik_amazon_price_changed` action fires whenever a price change is recorded, and the price history chart template can be overridden from your theme

= 2.4.0 =
* NEW: Geo rules per link — send visitors from chosen countries to alternative destination URLs (country dropdown in the new "Destination Rules" box on the link edit screen); everyone else gets the default URL. Uses the local MaxMind database — no external API calls during redirects
* NEW: Link expiration — set an expiry date per link and choose what happens after: show a 404, redirect to a fallback URL, or unpublish the link automatically (hourly background task). New sortable "Expires" column on the links list. Expiry dates imported from BetterLinks are picked up automatically
* NEW: A/B testing — rotate between destination URLs with weighted variants (labeled A, B, C…); every click records which variant it got, and a new "A/B Test Variants" card in the Analytics dashboard shows clicks and share per variant with bot traffic excluded
* NEW: Broken-link actions in the Link Scanner — select multiple links and replace their destination URL or disable them (draft) in one step; optionally auto-disable a link after N consecutive failed scheduled scans, with an admin notice and one-click Restore. Safety guard: when the whole scan batch fails (host DNS/network outage), nothing is disabled
* NEW: Links with geo or A/B rules always redirect with 302 — a cached 301 would pin the first-seen destination in the visitor's browser
* Fix: Query-parameter forwarding now also works when Fast Redirect is disabled (the fallback redirect path silently skipped it)
* Fix: Changing a link's slug or prefix now takes effect immediately on sites with a persistent object cache (the redirect cache was never invalidated — old slugs kept redirecting for up to 5 minutes and brand-new prefixes could 404 for up to a day)
* Fix: Click tracking on the fallback redirect path was permanently disabled on servers with unlimited PHP memory (memory_limit = -1)
* Maintenance: removed the unused legacy click-tracking AJAX endpoint (frumbik_fast_track); geo lookups on the redirect path never download the MaxMind database inline and never queue background jobs (both could stall or bloat high-traffic sites)

= 2.3.1 =
* Fix: Clicking the top-level "Affiliate Hub" menu entry caused a 500 error on some hosts — it now opens the affiliate links list
* Fix: Safe Mode and a false "low memory" warning were triggered on servers configured with unlimited PHP memory (memory_limit = -1)
* Fix: An hourly integrity check recreated all database tables every hour because it looked for a table under an old name
* Fix: Uninstall now removes everything it promised — Amazon product tables are dropped, all affiliate links are deleted including auto-drafts (previously roughly half could remain), analytics/metrics tables are dropped under their real names, and cleanup also runs when uninstalling via WP-CLI (a permission check silently skipped it before)
* Fix: Fresh installs (2.3.0) did not flag bot clicks until the first wp-admin visit — sites installed or activated via WP-CLI never flagged them at all; bot detection is now armed immediately on activation
* Fix: Amazon geo-targeting in the Product Grid block crashed with a fatal error when a visitor's marketplace was resolved
* Fix: Saving the Amazon settings tab cleared the affiliate URL of every product even when the Partner Tag had not changed
* Fix: The Amazon compliance audit only ever checked the first 50 products — it now audits the whole catalog in batches; the disclaimer check also respects the "automatic disclaimer" setting
* Fix: The analytics API no longer returns three sample rows on fresh installs — an empty site now shows an empty list
* Fix: Content scan controls (pause / resume / cancel) did not work, the post-type checkboxes were ignored, and the "force finish" button for stuck scans did nothing — all wired up
* Fix: Changing the link prefix now flushes rewrite rules and the redirect cache automatically — no more 404s on existing links until visiting Permalinks
* Fix: Keywords Autolinker now matches words with accented characters (ą, é, ü, …) correctly, accepts them in the keyword form, and no longer links keywords of draft/unpublished affiliate links
* Fix: Scheduled health checks and data cleanup could be silently skipped on cached page loads
* Fix: The PA-API deprecation notice now also appears when API Mode is set to "Auto" but PA-API is effectively in use
* Fix: The classic editor (TinyMCE) "Insert Affiliate Link" button was broken — the toolbar button never registered and the link picker errored out; both repaired
* Improved: The GeoLocation status now tells the truth about which reader is active — native GeoIP2 library vs the bundled PHP reader (both read the local database; neither calls external APIs)
* Maintenance: Removed ~5,400 lines of dead legacy code (an unused experimental click-storage layer, an unreachable optimization dashboard, duplicate analytics prototypes and an orphaned import/export screen) — smaller plugin, identical behavior

= 2.3.0 =
* NEW: Bot detection with names — crawler clicks (Googlebot, Bingbot, SeznamBot, SemrushBot, AI bots and 30+ more) are now flagged and shown by name in Recent Activity instead of "Unknown", and are excluded from click totals, unique counts and charts by default (new "Include bot traffic" filter toggle brings them back)
* NEW: Optional background bot IP verification — confirms that a claimed crawler really comes from the crawler's published IP ranges (static ranges always on; reverse-DNS check opt-in)
* Fix: Real user clicks were counted twice (once by the redirect, once by the JavaScript beacon) — the beacon now enriches the redirect record instead of inserting a duplicate
* Fix: Clicks no longer store the configured fallback location (e.g. "Warsaw, Poland") as if it were the visitor's real location; unresolved locations show as "Pending…"/"Unknown" and are repaired in the background (a one-time repair also fixes historical rows and the world map country grouping)
* Fix: Safari version detection (reversed pattern), Opera detected as Chrome, and the impossible "Windows 11" UA pattern — Windows now shows the honest "Windows 10/11" label, upgraded to the exact version via User-Agent Client Hints where available
* NEW: The JavaScript beacon now delivers the source page URL and its UTM parameters (UTM tracking finally works for on-page clicks) plus Client Hints (real browser version despite the frozen User-Agent)
* NEW: Internal clicks in Recent Activity show the source page instead of a bare "Internal"; external referrers show "Label (domain)" with the full URL on hover
* NEW: Unified, trusted-proxy-aware client IP resolution (Cloudflare supported) shared by all tracking paths — consistent unique-visitor fingerprints and no header spoofing
* NEW: Optional masking of visitor IPs in the Recent Activity table (frumbik_anonymize_ip_display option)
* NEW: GA4 server-side events via the Measurement Protocol (new API secret setting) — clicks that enter your /go/ links directly (e-mail, social media, QR codes) never load a page of your site and could not fire a JavaScript event before; they are now sent from the server, with session attribution taken from the visitor's GA cookies
* Fix: GA4 events on sites using Google Tag Manager never fired (no global gtag function) — the tracker now falls back to a dataLayer push you can wire to a GA4 tag
* Fix: GA4 events are now routed to the Measurement ID configured in the plugin (send_to) instead of whatever property the page's own gtag config points at
* Fix: affiliate click detection moved to a capture-phase listener (immune to other scripts calling stopPropagation) and the obsolete Universal Analytics transport_type parameter was removed
* NEW: configuration warnings when GA4 is enabled without a Measurement ID or with the Click Tracking module disabled
* Maintenance: database schema 2.6.0 (is_bot/bot_name columns) with automatic backfill of existing click data and per-link counter recalculation

= 2.2.4 =
* Fix: [afh_product] shortcodes for ASINs the plugin doesn't know yet now create stub products automatically — the Amazon Products list shows every ASIN used in your content, ready for enrichment once API credentials are added (previously nothing was saved and the list stayed at zero)
* NEW: Dismissible setup notice on plugin admin pages when Amazon Products is enabled but no product has data yet — links both setup paths (connect the Amazon API, or add product data manually / via Bulk Import)
* Docs: Clarified that Zero-API mode displays manually added products (it does not fetch product data by itself)

= 2.2.0 - 2.2.3 =
* NEW: Bundled the MaxMind GeoIP2 reader library — fast local geolocation works out of the box, no Composer required
* Fix: MaxMind database download failures (false success reports, a fatal error on the download button, orphaned temp files, unreliable extraction) and native GeoIP2 not activating even when the database and reader were present
* Fix: PHP deprecation notice during redirects when the request URI has no path component, and the same pattern in the Link Scanner, minification and category import
* Docs: Shortcodes reference with worked examples, plus the corrected affiliate link shortcode name (`[frumbik_link]`)

= 2.1.6 - 2.1.9 =
* Fix: Link Scanner scheduled scans now honour the preferred day/time and the WordPress timezone
* Fix: Browsers no longer cache 301 redirects, so every click reaches the server and is tracked
* Fix: "Unique clicks only (24h)" now works during pagination and sorting in Recent Activity
* Remove: Conversions and Heatmaps placeholders — UI-only with no backend implementation

= 2.1.1 - 2.1.4 =
* NEW: Migration Tool — 4-step import wizard with adapters for ThirstyAffiliates, Pretty Links, BetterLinks and generic CSV; dry-run preview, conflict resolution and one-click rollback
* NEW: Exclude Scanner Tracking setting — Link Scanner no longer inflates click statistics (with cleanup of historical phantom clicks)
* Fix: instant redirects (tracking moved after the redirect header), imported-link slugs/prefixes/click counts, FastRedirect query order, and a batch of Migration Tool polish

= 2.0.0 - 2.0.1 =
* NEW: Amazon Products module — product boxes, comparison tables, bestseller lists, inline links; 5 Gutenberg blocks and 4 shortcodes; Zero-API mode, Bulk ASIN Import, TOS Compliance Engine, geo-targeting across 22 marketplaces, price history tracking, background price refresh, Creators API support
* NEW: Google Analytics 4 module — send affiliate click events (slug, ASIN, marketplace, page URL) to GA4, with optional gtag.js loading

= 1.0.9 - 1.1.6 =
* Automatic recurring link scans with HTML email reports (incl. compatibility with WPS Hide Login), security hardening (XSS fixes, capability checks, ABSPATH guards), performance passes (query caching, autoload cleanup, N+1 fixes), ~1,300 lines of dead code removed, and assorted scanner/settings fixes

= 1.0.1 - 1.0.8 =
* Link Scanner stabilization: chart rendering, ignored-links filters, boolean parsing, CSV export, and responsive layout fixes

= 1.0.0 =
* Initial stable release: link cloaking with 301/302/307 redirects, Enhanced Analytics dashboard, click tracking with unique-visitor detection and IP anonymization, MaxMind GeoLite2 geolocation with API fallbacks, Keywords Autolinker, Link Scanner, Setup Wizard, QR codes, import/export, query-parameter forwarding, TinyMCE + Gutenberg integration, GDPR features, and full WordPress Coding Standards compliance

== Privacy & Security ==

= GDPR Compliance =
- **Data Minimization**: Only essential data is collected
- **User Consent**: All tracking and geolocation are disabled by default — must be explicitly enabled
- **Data Export**: Built-in tools for data export/deletion requests
- **Anonymization**: IP address anonymization options
- **Transparency**: Clear data usage policies in settings

= Security Features =
- **Nonce Protection**: All forms use WordPress nonces
- **Capability Checks**: Role-based access control
- **SQL Injection Prevention**: Prepared statements only
- **XSS Protection**: All output properly sanitized
- **Regular Updates**: Active maintenance and security patches

== External Services ==

This plugin connects to several third-party services to provide enhanced functionality. All external connections are optional and can be disabled.

= MaxMind GeoLite2 Database Service =

**What it is**: MaxMind provides geolocation data through their GeoLite2 database
**What it's used for**: Converting visitor IP addresses to geographical locations (country, city, coordinates) for analytics
**What data is sent**: Only IP addresses of visitors who click affiliate links. IP data is processed locally using the downloaded database — no visitor data is sent to MaxMind servers in real-time.
**When it's sent**: Only when the GeoLocation module is enabled and a visitor clicks an affiliate link
**Database updates**: When a license key is configured, the plugin automatically re-downloads the GeoLite2 database weekly via WordPress Cron (no visitor data is sent — only a download request using the administrator's license key)
**Service provider**: MaxMind, Inc.
**Terms of service**: https://www.maxmind.com/en/terms-of-use
**Privacy policy**: https://www.maxmind.com/en/privacy-policy
**Database download**: https://download.maxmind.com/ (requires free license key)

= IP Geolocation API Services =

**What they are**: Fallback geolocation services, used only when the local MaxMind database is unavailable and GeoLocation tracking is enabled
**What data is sent**: The visitor's IP address only (anonymized when IP anonymization is on), one request per click. IP-API.com is also used for admin-initiated benchmark tests, which send public test IPs such as 8.8.8.8 — never visitor data.

**IP-API.com** — Terms & privacy: https://ip-api.com/docs/legal (45 requests/minute free tier)
**IPApi.co** — Privacy: https://ipapi.co/privacy/ | Terms: https://ipapi.co/terms/ (15,000 requests/month free tier)
**IPInfo.io** — Privacy: https://ipinfo.io/privacy-policy | Terms: https://ipinfo.io/terms-of-service (50,000 requests/month free tier)

= GitHub API Service =

**What it is**: GitHub's REST API and archive downloads, used to fetch the open-source MaxMind GeoIP2 PHP libraries
**What data is sent**: No visitor or site data — only standard HTTP headers (server IP, plugin User-Agent "AffiliateHub-WordPress-Plugin")
**When it's used**: Only when an administrator manually clicks "Install Native GeoIP2 Library" in the plugin settings — never automatically
**Domains contacted**: https://api.github.com/ (release metadata for maxmind/GeoIP2-php and maxmind/MaxMind-DB-Reader-php), https://github.com/ and https://codeload.github.com/ (ZIP archive downloads)
**Service provider**: GitHub, Inc. (Microsoft)
**Privacy policy**: https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement
**Terms of service**: https://docs.github.com/en/site-policy/github-terms/github-terms-of-service

= Link Scanner =

The Link Scanner module checks your affiliate link destination URLs to verify they are still active and responding.

* It sends HTTP HEAD/GET requests to the destination URLs stored in your affiliate links
* These are URLs you have entered yourself — no visitor data is sent
* Requests are only triggered manually by an administrator from the Link Scanner settings page
* No third-party service is involved — requests go directly to the destination URLs

= Google Analytics 4 (optional) =

**What it is**: Google Analytics 4 tracking via Google Tag Manager
**What it's used for**: Sending affiliate link click events to GA4 for analytics
**What data is sent**: Click event data (event name, link slug, ASIN, marketplace, page URL) — sent from visitor's browser to Google
**When it's sent**: Only when the Google Analytics 4 module is enabled in plugin settings
**Optional script loading**: When "Load gtag.js" is enabled, the plugin loads a JavaScript tracking library from Google's CDN. This is optional and disabled by default.
**Server-side events (Measurement Protocol, optional)**: When the site owner additionally provides a GA4 Measurement Protocol API secret, the plugin sends click events for visitors who enter affiliate redirect links directly (from e-mails, social media, QR codes) from the WordPress server to Google. Data sent: the Google Analytics client/session identifier read from the visitor's existing GA cookies, the clicked link's ID/slug/destination/title and the traffic source name. The visitor's IP address is NOT sent (the request originates from the server). No events are sent for visitors without a Google Analytics cookie.
**Domains contacted**:
- https://www.googletagmanager.com/ (gtag.js library download)
- https://www.google-analytics.com/ (event data collection; also the Measurement Protocol endpoint when an API secret is configured)
**Service provider**: Google LLC
**Terms of service**: https://marketingplatform.google.com/about/analytics/terms/us/
**Privacy policy**: https://policies.google.com/privacy

= User Control and Privacy =

- **All external services are optional and off by default** — the plugin works without any external connections, and disabling GeoLocation stops all IP-based tracking and API calls
- **No CDN dependencies** — all JavaScript and CSS assets are bundled locally
- **Local processing preferred** — the MaxMind database (user-supplied license key) processes IPs locally; APIs are only a fallback

== Source Code ==

This plugin includes third-party JavaScript libraries in both minified and human-readable form. All plugin-authored JavaScript files (admin.js, analytics-dashboard-production.js, affiliate-hub-block.js, affiliate-hub-qrcode.js, etc.) are unminified. No build tools are required.

Full plugin source code is included in the plugin package. All plugin-authored files are unminified and human-readable.

= assets/js/jsvectormap.min.js =

Minified distribution of jsVectorMap v1.7.0, an interactive map library.
The unminified human-readable source is included in the plugin as assets/js/jsvectormap.js (2301 lines).
Upstream source: https://github.com/themustafaomar/jsvectormap/releases/tag/v1.7.0

= assets/js/jsvectormap-world.js =

This file (1661 lines) contains auto-generated SVG path data defining country boundaries for every country in the world. It is distributed as part of the jsVectorMap package. The path strings consist of SVG drawing commands (M=moveto, l=lineto, Z=closepath) followed by x,y geographic coordinates — they are NOT minified or obfuscated JavaScript code. The upstream dist/maps/world.js ships this data fully minified on a single line; this version is reformatted for readability with each country in its own commented block, properties on separate lines, and long multi-territory paths split at sub-path (Z) boundaries. Maximum line length is under 250 characters.
Upstream source: https://github.com/themustafaomar/jsvectormap/releases/tag/v1.7.0

= assets/js/qrcode-generator.js / qrcode-generator.min.js =

QR code generation library (qrcodejs v1.0.0). The human-readable source is included as assets/js/qrcode-generator.js (fully formatted with proper indentation). The minified version (qrcode-generator.min.js) is used at runtime.
Upstream source: https://github.com/davidshimjs/qrcodejs

= assets/js/apexcharts.min.js =

Minified distribution of ApexCharts v5.3.3, a JavaScript charting library.
The unminified source (dist/apexcharts.js) is available in the upstream release archive.
Upstream source: https://github.com/apexcharts/apexcharts.js/releases/tag/v5.3.3

== Third-Party Libraries ==

This plugin bundles the following open-source JavaScript and CSS libraries. All libraries are served locally from the plugin package — no external network requests are made to load them.

= ApexCharts =

* Library: ApexCharts
* Version: 5.3.3
* Bundled file: assets/js/apexcharts.min.js
* Purpose: Interactive charts in the Enhanced Analytics and Link Scanner dashboards
* License: MIT License
* Source: https://github.com/apexcharts/apexcharts.js/releases/tag/v5.3.3
* Copyright: (c) 2018-2025 ApexCharts

= jsVectorMap =

* Library: jsVectorMap
* Version: 1.7.0
* Bundled files: assets/js/jsvectormap.js (unminified source, 2301 lines), assets/js/jsvectormap.min.js, assets/js/jsvectormap-world.js (1661 lines), assets/css/jsvectormap.min.css
* Purpose: Interactive world map in the GeoLocation analytics view
* Note: jsvectormap-world.js contains auto-generated SVG geographic coordinate data (not minified JS). Reformatted from upstream single-line format to one commented block per country with paths split at sub-path boundaries. Max line length under 250 chars.
* License: MIT License
* Source: https://github.com/themustafaomar/jsvectormap/releases/tag/v1.7.0
* Copyright: (c) Mustafa Omar

= QRCode (qrcodejs) =

* Library: qrcodejs
* Version: 1.0.0
* Bundled files: assets/js/qrcode-generator.js (human-readable formatted source, 1425 lines), assets/js/qrcode-generator.min.js
* Purpose: QR code generation for affiliate links
* License: MIT License
* Source: https://github.com/davidshimjs/qrcodejs
* Copyright: (c) 2012 davidshimjs

== Support & Development ==

= Getting Help =
- **Documentation**: Visit our [Knowledge Base](https://frumbik.com/affiliatehub/)
- **Community Forum**: WordPress.org support forums
- **Feature Requests**: Submit via WordPress.org or GitHub
- **Bug Reports**: Please include WordPress/PHP versions and error logs

= Contributing =
- **Translations**: Help translate AffiliateHub in your language
- **Code Contributions**: Submit pull requests via GitHub
- **Testing**: Beta testing program available
- **Feedback**: Your suggestions shape our roadmap

= Roadmap =
- **Advanced Targeting**: Device, browser, time-based rules
- **A/B Testing**: Split testing for affiliate links
- **API Integration**: REST API for external tools
- **White Label**: Custom branding options
- **Multi-Site Support**: Network-wide management

== License ==

This plugin is licensed under the GPLv2 or later — see https://www.gnu.org/licenses/gpl-2.0.html for the full license text. It is distributed WITHOUT ANY WARRANTY, without even the implied warranty of merchantability or fitness for a particular purpose.

== Upgrade Notice ==

= 2.5.1 =
Fixes the "Include bot traffic" filter, which was ignored by the Recent Activity table and by CSV export. If you rely on those numbers, upgrade — bot visits were being counted in both.

= 2.5.0 =
Adds Amazon price history charts, price drop alerts and an optional weekly e-mail report. Also fixes the Link Scanner report e-mail miscounting broken links, and price history dates showing in UTC instead of your site timezone.

= 1.0.0 =
Initial release of Frumbik Affiliate Hub. Professional affiliate link management for WordPress with advanced analytics, GeoLocation tracking, Keywords Autolinker, Link Scanner, and comprehensive module system.
