=== Evo Compliance WP ===
Contributors: evosistemi
Tags: gdpr, cookie banner, privacy, accessibility, cookie
Requires at least: 5.8
Tested up to: 7.0
Requires PHP: 7.4
Stable tag: 2.2.9
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Garante-compliant cookie banner, Privacy/Cookie Policy, WCAG 2.1 AA Accessibility Statement and accessibility widget. All included, with unlimited pageviews.

== Description ==

**Evo Compliance WP** is the all-in-one suite that makes your WordPress site compliant with privacy, cookie and accessibility rules. One free, complete plugin instead of three separate services.

Built in Italy around real regulations: GDPR (EU Reg. 2016/679), the Italian Data Protection Authority (Garante) cookie guidelines of 10 June 2021, Law 4/2004 ("Stanca") and AgID accessibility guidelines, WCAG 2.1 level AA and the European Accessibility Act (EAA).

= Why choose it =

* **UNLIMITED pageviews on every plan** — no traffic limits, no cost that grows with your visits (unlike iubenda, Cookiebot and similar services).
* **Accessibility included** — cookie banner *and* accessibility widget in a single plugin, without paying for a second service.
* **Made for Italy (and the EU)** — texts, banner and statements aligned with the Garante and AgID, ready to use.
* **No locked features** in the free package: what is free is genuinely usable, with no disabled "upgrade to Pro" buttons.

= What the free version does (all included) =

* **Garante-compliant cookie banner (10/06/2021)**: 3 layouts (bar, modal, sidebar) with equal-weight Accept / Reject / Customize buttons and a close (X) that counts as rejection.
* **Prior blocking** of third-party scripts until the user consents (GA4 with IP anonymization, Google Tag Manager, Meta Pixel, Hotjar, Microsoft Clarity, LinkedIn Insight, TikTok Pixel, Google Maps).
* **Native Google Consent Mode v2**.
* **Auto-generated legal pages**: Privacy Policy, Cookie Policy and Accessibility Statement, pre-filled and editable.
* **Accessibility widget** with 10 tools: enlarge text, high contrast, negative contrast, grayscale, underline links, readable font, big cursor, reading guide, reset.
* **Consent log (Proof of Consent)** with a unique UUID per consent, a snapshot of the displayed texts, and IP and user-agent protected with HMAC-SHA256 (never stored in clear text).
* **Policy versioning**: if you change the texts, consent is automatically requested again.
* **Site scanner**: detects cookies and third-party services and assigns a 0-100 Compliance Score.
* **Universal shortcodes** (`[evocwp_privacy]`, `[evocwp_cookie]`, `[evocwp_accessibility]`, `[evocwp_banner_revoke]`), **4 Gutenberg blocks**, an **Elementor** widget and a **WPBakery** element.
* **Placeholders** for YouTube, Vimeo, Google Maps and social embeds until consent is given.
* **Automatic compatibility** with major page builders (Elementor, WPBakery, Divi, Beaver, Oxygen, Bricks, Brizy) and cache plugins (WP Rocket, LiteSpeed, W3TC, Autoptimize, Hummingbird, Perfmatters).
* **Multilingual**: WPML, Polylang, TranslatePress.
* **CSV export** of the consent log and a full **REST API** (`/wp-json/evocwp/v1/`).
* Compatible with **WordPress Multisite**.

= Evo Compliance Pro (optional add-on) =

The free version is complete and enough for the vast majority of sites. Those who manage multiple sites, agencies and projects that need advanced automation can activate **Evo Compliance Pro**, a separate add-on downloaded from our website (not included in this package and not required to use the free plugin).

Pro adds, among other things:

* Automatic scheduled scanning and periodic email reports.
* Extended history and archiving of the consent log.
* Advanced exports and audit-ready proof of compliance.
* **White-label** mode for agencies (branding removal).
* Priority support.

Pro is purchased with an installation-seat license at **https://app.evosistemi.com** — here too, **unlimited pageviews** on every plan. No feature of the free plugin is disabled if you do not activate Pro: the add-on adds, it never removes.

= Transparency about external connections =

The **free plugin works 100% offline** and contacts no external server to operate. The only connections to the Internet happen if **you** decide to activate an Evo Compliance Pro license (see the dedicated FAQ). The scanner queries your own site, not third-party servers.

== Installation ==

1. In your WordPress dashboard go to **Plugins → Add New**, search for "Evo Compliance" and click **Install**; or upload the zip via **Plugins → Add New → Upload Plugin**.
2. Click **Activate**.
3. On first run a 5-step **setup wizard** starts automatically (owner details, DPO, banner, integrations, legal pages).
4. Alternatively go to **Evo Compliance → Owner** and fill in the fields.
5. Recommended: open the **Scanner** tab and run a scan to check the cookies and third-party services active on your site.

Requirements: WordPress 5.8+ and PHP 7.4+.

== Frequently Asked Questions ==

= Does the plugin make calls to external servers? =
The **free version contacts no external server** to work: banner, script blocking, scanner and legal pages run entirely on your own site. The only exception is **optional and under your control**: if you activate an **Evo Compliance Pro** license, the plugin communicates with our license server **https://app.evosistemi.com** to validate the key. In that case it sends only the minimum data needed for verification: the entered key, the site URL and a site hash, whether the environment is staging, and the plugin, WordPress and PHP versions. It does **not** send any visitor data, site content or consent logs. If you do not activate Pro, this communication never happens.

= Is it really free or a demo with locked features? =
It is genuinely free and complete. There are no disabled buttons or "showcase" features that require payment: everything you see in the free plugin is usable. Pro is a separate add-on that *adds* features, it does not unlock hidden ones.

= Are there pageview or traffic limits? =
No. No view limits, neither in the free version nor in Pro. The cost does not grow with your site's traffic.

= Is the banner compliant with the Italian Garante? =
Yes. The banner follows the Garante guidelines of 10 June 2021: equal-weight Accept/Reject buttons, close (X) treated as rejection, prior blocking of scripts before consent, revocation, and a consent log with proof.

= Does it cover accessibility (Stanca Law / WCAG / EAA)? =
The plugin generates an **Accessibility Statement** in line with Law 4/2004 and the AgID guidelines, and includes an **accessibility widget** with WCAG 2.1 AA tools. Note: no plugin makes a site automatically "compliant"; the widget and the statement are tools that help you reach and document compliance, but accessible content and themes are also required.

= Is it compatible with Elementor, WPBakery and Gutenberg? =
Yes. It registers 4 Gutenberg blocks, an Elementor widget and WPBakery elements, and automatically disables asset loading inside the editor to avoid conflicts.

= Can I use it together with other cookie plugins (Complianz, CookieYes, iubenda...)? =
No. Use a single cookie management system at a time. The plugin detects and reports the presence of other GDPR plugins: remove them before configuring Evo Compliance.

= Does it work on WordPress Multisite? =
Yes. Each site in the network has its own configuration and its own consent log.

= How do you protect the data in the consent log? =
IP and user-agent are never stored in clear text: they are hashed with HMAC-SHA256 using an automatically generated salt. Each consent has a UUID and a snapshot of the displayed texts (Proof of Consent).

== Screenshots ==

1. Evo Compliance dashboard with consent statistics and Compliance Score.
2. Garante-compliant cookie banner with equal-weight buttons (bar layout).
3. Banner customization panel (layout, colors, texts).
4. Accessibility widget with the 10 WCAG 2.1 AA tools.
5. Site scanner: detected cookies and third-party services.
6. Integrations tab with prior blocking of GA4, GTM, Meta Pixel and others.
7. First-run setup wizard.
8. Accessibility Statement and auto-generated legal pages.

== Changelog ==

= 2.2.9 =
* FIX: more robust banner rendering with dual-hook (wp_footer + shutdown fallback).
* FIX: updated compatibility with recent WP Rocket and LiteSpeed Cache.
* FIX: minor stability improvements to the scanner and integrations.
* Updated declared compatibility up to WordPress 7.0.

= 2.2.0 =
* NEW: automatic site scanner with a 0-100 Compliance Score.
* NEW: universal shortcodes, 4 Gutenberg blocks, Elementor widget, WPBakery elements.
* NEW: 5-step setup wizard on first install.
* NEW: Proof of Consent with a unique UUID and a snapshot of the texts.
* NEW: automatic policy versioning with re-consent.
* NEW: placeholders for video, Maps and social embeds.
* NEW: full REST API and CSV export of the consent log.
* NEW: Microsoft Clarity, LinkedIn Insight, TikTok Pixel integrations.
* NEW: WPML/Polylang/TranslatePress multilingual support.
* FIX: the negative-contrast CSS filter no longer breaks the banner's position:fixed.
* FIX: editor compatibility with Divi/Beaver/Oxygen/Bricks/Brizy.
* FIX: banner skipped for bots (Googlebot, Bingbot, etc.).

= 2.0.0 =
* First public release.

== Upgrade Notice ==

= 2.2.9 =
Stability and compatibility update (WordPress 7.0, recent WP Rocket/LiteSpeed). No action required: the update is transparent.

= 2.2.0 =
Major update: site scanner, page-builder compatibility and Proof of Consent. No reconfiguration needed.
