=== Evo Compliance Suite ===
Contributors: evosistemi
Tags: gdpr, cookie banner, privacy, accessibility, cookie
Requires at least: 5.8
Tested up to: 7.0
Requires PHP: 7.4
Stable tag: 2.3.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Cookie banner (Italian Garante guidelines), Privacy/Cookie Policy, WCAG 2.1 AA Accessibility Statement and accessibility widget, consent log.

== Description ==

**Evo Compliance Suite** helps you make your WordPress site compliant with privacy, cookie and accessibility rules:

* GDPR (EU Reg. 2016/679)
* The Italian Data Protection Authority (Garante) cookie guidelines of 10 June 2021
* Law 4/2004 ("Stanca") and AgID accessibility guidelines
* WCAG 2.1 level AA and the European Accessibility Act (EAA)

= Features =

* **Cookie banner** following the Garante guidelines of 10 June 2021: 3 layouts (bar, modal, sidebar) with equal-weight Accept / Reject / Customize buttons and a close (X) that counts as rejection.
* **Prior blocking** of third-party scripts until the user consents (GA4 with IP anonymization, Google Tag Manager, Meta Pixel, Hotjar, Microsoft Clarity, LinkedIn Insight, TikTok Pixel, Google Maps). Scripts are loaded only if you configure the corresponding IDs and only after the visitor's consent.
* **Google Consent Mode v2** support.
* **Auto-generated legal pages**: Privacy Policy, Cookie Policy and Accessibility Statement, pre-filled and editable.
* **Accessibility widget** with 10 tools: enlarge text, high contrast, negative contrast, grayscale, underline links, readable font, big cursor, reading guide, reset.
* **Consent log (Proof of Consent)** with a unique UUID per consent, a snapshot of the displayed texts, and IP and user-agent protected with HMAC-SHA256 (never stored in clear text). **CSV export** included.
* **Policy versioning**: if you change the texts, consent is automatically requested again.
* **Site scanner**: detects cookies and third-party services on your own pages and assigns a 0-100 Compliance Score. Manual scan and optional weekly scheduled scan with email alerts.
* **Universal shortcodes** (`[evocwp_privacy]`, `[evocwp_cookie]`, `[evocwp_accessibility]`, `[evocwp_banner_revoke]`), **4 Gutenberg blocks**, an **Elementor** widget and a **WPBakery** element.
* **Placeholders** for YouTube, Vimeo, Google Maps and social embeds until consent is given.
* **Automatic compatibility** with major page builders (Elementor, WPBakery, Divi, Beaver, Oxygen, Bricks, Brizy) and cache plugins (WP Rocket, LiteSpeed, W3TC, Autoptimize, Hummingbird, Perfmatters).
* **Multilingual**: WPML, Polylang, TranslatePress.
* Full **REST API** (`/wp-json/evocwp/v1/`).
* Compatible with **WordPress Multisite**.

All features included in this plugin are fully functional: nothing is locked, limited or subject to a license key.

= Source code =

All JavaScript and CSS files in this plugin ship in readable, unminified form; there is no build step. The third-party tracking bootstraps in `assets/js/banner.js` (Google, Meta, Hotjar, Clarity, LinkedIn, TikTok) are the standard public loader snippets documented by each vendor, included in readable form; they only run after the visitor's consent.

The plugin also contains a local, static dataset of well-known third-party services and their cookies (`includes/scanner/class-scanner-cookies-db.php`). It is reference data used by the scanner to classify what it finds on your own pages: the plugin does not connect to any of the domains listed there.

= Optional Pro add-on =

A separate add-on with additional features (scheduled reporting, extended log archiving, white-label mode) is distributed independently on the developer's website. It is **not included** in this package and is **not required**: no feature of this plugin depends on it.

== Installation ==

1. In your WordPress dashboard go to **Plugins → Add New**, search for "Evo Compliance Suite" and click **Install**; or upload the zip via **Plugins → Add New → Upload Plugin**.
2. Click **Activate**.
3. On first run a 5-step **setup wizard** starts automatically (owner details, cookie categories, integrations).
4. Alternatively go to **Evo Compliance → Owner** and fill in the fields.
5. Recommended: open the **Scanner** page and run a scan to check the cookies and third-party services active on your site.

Requirements: WordPress 5.8+ and PHP 7.4+.

== External services ==

The plugin itself does not contact any external server: banner, script blocking, consent log, legal pages and scanner run entirely on your own site (the scanner requests your own site's pages).

However, its purpose is consent-gated loading of third-party services **that you, the site administrator, choose to enable** by entering the corresponding IDs in the settings. When (and only when) an ID is configured **and** the visitor has given consent, the visitor's browser loads the service's script directly from the vendor. In that case the vendor receives the data its script normally collects (such as the visitor's IP address, user agent and page URL). The services supported are:

* **Google Analytics 4 / Google Tag Manager** (loaded from googletagmanager.com) — audience measurement and tag management. [Terms of Service](https://marketingplatform.google.com/about/analytics/terms/us/), [Privacy Policy](https://policies.google.com/privacy)
* **Google Maps JavaScript API** (loaded from maps.googleapis.com) — displays a map for the `[evocwp_map]` shortcode. [Terms of Service](https://cloud.google.com/maps-platform/terms), [Privacy Policy](https://policies.google.com/privacy)
* **Meta (Facebook) Pixel** (loaded from connect.facebook.net) — advertising measurement. [Terms of Service](https://www.facebook.com/legal/technology_terms), [Privacy Policy](https://www.facebook.com/privacy/policy/)
* **Hotjar** (loaded from static.hotjar.com) — behavior analytics. [Terms of Service](https://www.hotjar.com/legal/policies/terms-of-service/), [Privacy Policy](https://www.hotjar.com/legal/policies/privacy/)
* **Microsoft Clarity** (loaded from clarity.ms) — behavior analytics. [Terms of Use](https://clarity.microsoft.com/terms), [Privacy Statement](https://privacy.microsoft.com/privacystatement)
* **LinkedIn Insight Tag** (loaded from snap.licdn.com) — advertising measurement. [Terms](https://www.linkedin.com/legal/l/li-corp-agreement), [Privacy Policy](https://www.linkedin.com/legal/privacy-policy)
* **TikTok Pixel** (loaded from analytics.tiktok.com) — advertising measurement. [Terms of Service](https://www.tiktok.com/legal/tiktok-commercial-terms-of-service), [Privacy Policy](https://www.tiktok.com/legal/privacy-policy)

If you configure none of these IDs, no external request is ever made.

== Frequently Asked Questions ==

= Does the plugin make calls to external servers? =
No. The plugin contacts no external server to work: banner, script blocking, scanner and legal pages run entirely on your own site. Third-party scripts (GA4, Meta Pixel, etc.) are loaded by the visitor's browser only if you configure them and only after consent — see the "External services" section.

= Is the banner compliant with the Italian Garante? =
The banner follows the Garante guidelines of 10 June 2021: equal-weight Accept/Reject buttons, close (X) treated as rejection, prior blocking of scripts before consent, revocation, and a consent log with proof. Final compliance also depends on how you configure the plugin and your site.

= Does it cover accessibility (Stanca Law / WCAG / EAA)? =
The plugin generates an **Accessibility Statement** in line with Law 4/2004 and the AgID guidelines, and includes an **accessibility widget** with WCAG 2.1 AA tools. Note: no plugin makes a site automatically "compliant"; the widget and the statement are tools that help you reach and document compliance, but accessible content and themes are also required.

= Is it compatible with Elementor, WPBakery and Gutenberg? =
Yes. It registers 4 Gutenberg blocks, an Elementor widget and WPBakery elements, and automatically disables asset loading inside the editor to avoid conflicts.

= Can I use it together with other cookie plugins? =
No. Use a single cookie management system at a time. The plugin detects and reports the presence of other GDPR plugins: remove them before configuring Evo Compliance Suite.

= Does it work on WordPress Multisite? =
Yes. Each site in the network has its own configuration and its own consent log.

= How do you protect the data in the consent log? =
IP and user-agent are never stored in clear text: they are hashed with HMAC-SHA256 using an automatically generated salt. Each consent has a UUID and a snapshot of the displayed texts (Proof of Consent).

== Screenshots ==

1. Evo Compliance dashboard with consent statistics and Compliance Score.
2. Cookie banner with equal-weight buttons (bar layout).
3. Banner customization panel (layout, colors, texts).
4. Accessibility widget with the 10 WCAG 2.1 AA tools.
5. Site scanner: detected cookies and third-party services.
6. Integrations tab with prior blocking of GA4, GTM, Meta Pixel and others.
7. First-run setup wizard.
8. Accessibility Statement and auto-generated legal pages.

== Changelog ==

= 2.3.0 =
* Plugin renamed to "Evo Compliance Suite".
* All features are now available with no restrictions: modal and sidebar banner layouts, CSV export of the consent log, weekly scheduled scanning with email alerts, and all marketing integrations (Meta Pixel, Hotjar, Clarity, LinkedIn, TikTok).
* Removed all license-related code: the plugin makes no external calls.
* All inline styles and scripts are now added through the WordPress enqueue APIs (wp_add_inline_style / wp_add_inline_script).
* Rewrote the TikTok Pixel bootstrap in readable, documented form.
* Documented all supported external services with links to their terms and privacy policies.

= 2.2.9 =
* FIX: more robust banner rendering with dual-hook (wp_footer + shutdown fallback).
* FIX: updated compatibility with recent WP Rocket and LiteSpeed Cache.
* FIX: minor stability improvements to the scanner and integrations.
* Updated declared compatibility up to WordPress 7.0.

= 2.2.0 =
* NEW: automatic site scanner with a 0-100 Compliance Score.
* NEW: universal shortcodes, 4 Gutenberg blocks, Elementor widget, WPBakery elements.
* NEW: 5-step setup wizard on first install.
* NEW: Proof of Consent with a unique UUID and a snapshot of the texts.
* NEW: automatic policy versioning with re-consent.
* NEW: placeholders for video, Maps and social embeds.
* NEW: full REST API and CSV export of the consent log.
* NEW: Microsoft Clarity, LinkedIn Insight, TikTok Pixel integrations.
* NEW: WPML/Polylang/TranslatePress multilingual support.
* FIX: the negative-contrast CSS filter no longer breaks the banner's position:fixed.
* FIX: editor compatibility with Divi/Beaver/Oxygen/Bricks/Brizy.
* FIX: banner skipped for bots (Googlebot, Bingbot, etc.).

= 2.0.0 =
* First public release.

== Upgrade Notice ==

= 2.3.0 =
The plugin is now "Evo Compliance Suite": every feature is available with no restrictions and no license. No reconfiguration needed.
