{"id":227396,"date":"2025-07-07T02:56:57","date_gmt":"2025-07-07T02:56:57","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/inpipe-by-seresa\/"},"modified":"2026-07-24T06:36:44","modified_gmt":"2026-07-24T06:36:44","slug":"inpipe-by-seresa","status":"publish","type":"plugin","link":"https:\/\/fi.wordpress.org\/plugins\/inpipe-by-seresa\/","author":23226096,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.0.3","stable_tag":"2.0.3","tested":"7.0.2","requires":"6.4","requires_php":"8.3","requires_plugins":null,"header_name":"inPIPE by Seresa","header_author":"Seresa.io","header_description":"Captures, stores, and decodes UTM parameters for enhanced results in Google Analytics, Facebook Ads, and other platforms. Integrates with the dataLayer and supports standard and encoded UTM codes.","assets_banners_color":"","last_updated":"2026-07-24 06:36:44","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/seresa.io\/wordpress-plugin","header_author_uri":"https:\/\/seresa.io","rating":5,"author_block_rating":0,"active_installs":0,"downloads":1177,"num_ratings":1,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"seresa8","date":"2025-07-07 02:56:24"},"1.0.1":{"tag":"1.0.1","author":"seresa8","date":"2025-07-21 09:35:40"},"1.0.2":{"tag":"1.0.2","author":"seresa8","date":"2025-11-21 07:29:37"},"1.0.3":{"tag":"1.0.3","author":"seresa8","date":"2025-12-03 05:09:15"},"1.0.4":{"tag":"1.0.4","author":"seresa8","date":"2026-01-05 08:29:17"},"1.0.5":{"tag":"1.0.5","author":"seresa8","date":"2026-01-07 08:42:49"},"1.0.6":{"tag":"1.0.6","author":"seresa8","date":"2026-01-09 06:40:38"},"1.0.7":{"tag":"1.0.7","author":"seresa8","date":"2026-01-14 06:43:12"},"1.0.8":{"tag":"1.0.8","author":"seresa8","date":"2026-01-15 03:43:41"},"1.0.9":{"tag":"1.0.9","author":"seresa8","date":"2026-01-20 09:00:54"},"1.1.0":{"tag":"1.1.0","author":"seresa8","date":"2026-01-30 02:50:29"},"1.1.1":{"tag":"1.1.1","author":"seresa8","date":"2026-03-12 06:04:51"},"2.0.0":{"tag":"2.0.0","author":"seresa8","date":"2026-07-10 08:42:42"},"2.0.1":{"tag":"2.0.1","author":"seresa8","date":"2026-07-15 10:31:38"},"2.0.2":{"tag":"2.0.2","author":"seresa8","date":"2026-07-21 02:52:19"},"2.0.3":{"tag":"2.0.3","author":"seresa8","date":"2026-07-24 06:36:44"}},"upgrade_notice":[],"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3323178,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.1.0","1.1.1","2.0.0","2.0.1","2.0.2","2.0.3"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[244594,43896,219244,244593,25969],"plugin_category":[],"plugin_contributors":[244595],"plugin_business_model":[],"class_list":["post-227396","plugin","type-plugin","status-publish","hentry","plugin_tags-ad-blocker-bypass","plugin_tags-datalayer","plugin_tags-server-side-tracking","plugin_tags-utm-encoding","plugin_tags-utm-tracking","plugin_contributors-seresa8","plugin_committers-seresa8"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/inpipe-by-seresa\/assets\/icon-128x128.png?rev=3323178","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>inPIPE by Seresa allows you to generate, store, and manage UTM parameters\u2014both plain and coded. The plugin automatically decodes coded UTM query strings when visitors land on your website, pushing the full UTM data to the dataLayer. This helps bypass ad blockers and improves tracking in Google Analytics, Facebook Ads, and other platforms.<\/p>\n\n<ul>\n<li>Generate &amp; manage UTM query strings with ease  <\/li>\n<li>Supports both <strong>plain and coded UTM parameters<\/strong>  <\/li>\n<li>Decodes coded UTM links on-site and sends data to the dataLayer  <\/li>\n<li>Reduces tracking disruptions caused by ad blockers<\/li>\n<li>Works with GA4, GTM, Facebook Ads &amp; more<\/li>\n<li><strong>NEW \u2014 UTM API Access:<\/strong> connect external tools, scripts, and AI automations to your saved UTM links through a secure, key-protected REST API<\/li>\n<\/ul>\n\n<p><strong>Use WP inPIPE for more reliable UTM tracking and better data collection!<\/strong><\/p>\n\n<h3>Features<\/h3>\n\n<ul>\n<li>Generate and store UTM query string URLs based on user input  <\/li>\n<li>Encode UTM parameters to enhance tracking accuracy  <\/li>\n<li>Decode UTM query strings on site visits and push the original UTM data to the dataLayer<\/li>\n<li>Potentially bypass ad blockers to ensure accurate data collection<\/li>\n<\/ul>\n\n<h3>UTM API Access \u2014 External REST API (new)<\/h3>\n\n<p>Connect external tools, scripts, and AI automations directly to your UTM links through a secure, key-protected REST API. Enable it from the <strong>UTM API Access<\/strong> panel (shown when UTM Processing is on), provision your scoped keys, and call four server-to-server endpoints under <code>\/wp-json\/inpipe\/v1\/ext\/<\/code>:<\/p>\n\n<ul>\n<li><code>POST \/inpipe\/v1\/ext\/utm-generate<\/code> \u2014 create a new UTM-tagged link, or update an existing one by its short code<\/li>\n<li><code>GET \/inpipe\/v1\/ext\/utm-list<\/code> \u2014 retrieve your saved UTM records, with filtering and pagination<\/li>\n<li><code>DELETE \/inpipe\/v1\/ext\/utm-delete<\/code> \u2014 permanently delete a record by its short code<\/li>\n<li><code>GET \/inpipe\/v1\/ext\/status<\/code> \u2014 check the API toggle states and your current rate-limit budgets<\/li>\n<\/ul>\n\n<p>Secured with HTTPS-only transport, two scoped API keys (read-only and read-write, encrypted at rest), per-operation rate limiting, per-site IP throttling, a same-site domain guard, and an admin-configurable storage cap.<\/p>\n\n<p>Example \u2014 create a UTM-tagged link (<code>POST \/inpipe\/v1\/ext\/utm-generate<\/code>):<\/p>\n\n<pre><code>curl -X POST https:\/\/your-site.com\/wp-json\/inpipe\/v1\/ext\/utm-generate \\\n  -H \"X-InPipe-Key: YOUR_READ_WRITE_KEY\" \\\n  -H \"Content-Type: application\/json\" \\\n  -d '{\n    \"base_url\": \"https:\/\/your-site.com\/landing\",\n    \"utm_source\": \"newsletter\",\n    \"utm_medium\": \"email\",\n    \"utm_campaign\": \"summer_sale\",\n    \"custom_params\": [ { \"key\": \"partner\", \"value\": \"acme\" } ]\n  }'\n<\/code><\/pre>\n\n<p>Example response:<\/p>\n\n<pre><code>{\n  \"success\": true,\n  \"error\": null,\n  \"data\": {\n    \"code\": \"u4gf2\",\n    \"coded_url\": \"https:\/\/your-site.com\/landing?u4gf2=84729301\",\n    \"full_url\": \"https:\/\/your-site.com\/landing?utm_source=newsletter&amp;utm_medium=email&amp;utm_campaign=summer_sale\",\n    \"utm_source\": \"newsletter\",\n    \"utm_medium\": \"email\",\n    \"utm_campaign\": \"summer_sale\",\n    \"custom_params\": [ { \"key\": \"partner\", \"value\": \"acme\" } ],\n    \"created_at\": \"2026-06-19T10:24:00Z\",\n    \"updated_at\": \"2026-06-19T10:24:00Z\"\n  }\n}\n<\/code><\/pre>\n\n<p><strong>Full documentation, authentication details, and more code examples:<\/strong> <a href=\"https:\/\/support.seresa.io\/docs\/inpipe-utm-api-documentation\">inPIPE UTM API Documentation<\/a><\/p>\n\n<h3>Configuration<\/h3>\n\n<ul>\n<li>Navigate to <strong>Admin Dashboard &gt; inPIPE<\/strong> to manage plugin settings.<\/li>\n<li>Enable automatic UTM processing in the settings panel.<\/li>\n<li>Use the <strong>UTM Coder<\/strong> to create, edit, or delete UTM query strings.<\/li>\n<\/ul>\n\n<h3>External Services<\/h3>\n\n<p>This plugin connects to external services hosted by Seresa.io for the following purposes:<\/p>\n\n<p><strong>Subscription Verification &amp; Premium Package Downloads<\/strong>\n   - <strong>Service:<\/strong> The plugin uses the API at [https:\/\/sub.seresa.app] to verify premium subscriptions and to download premium packages or updates.\n   - <strong>When:<\/strong>\n     - Subscription verification occurs when you attempt to access premium features or validate your license.\n     - Package downloads occur when you install or update premium components from within the plugin.\n   - <strong>Data Sent:<\/strong>\n     - The plugin sends your license key, site URL, and (if applicable) the requested package identifier to the API.\n   - <strong>Purpose:<\/strong>\n     - To verify your entitlement to premium features and to deliver premium package files securely.\n   - <strong>Terms of Service:<\/strong> [https:\/\/seresa.io\/terms]\n   - <strong>Privacy Policy:<\/strong> [https:\/\/seresa.io\/privacy]<\/p>\n\n<p><strong>Other Hosted Services<\/strong>\n   - See below for additional premium features that may rely on external event processing (e.g., Transmute Engine).<\/p>\n\n<ol>\n<li><p>Subscription Verification<\/p>\n\n<ul>\n<li>What: The plugin connects to https:\/\/sub.seresa.app\/premium-downloader\/v1\/verify-subscription to validate subscription codes<\/li>\n<li>When: This occurs only when a user enters a subscription code in the admin panel to activate premium features<\/li>\n<li>Data sent: Subscription code entered by the user, site URL, and WordPress version<\/li>\n<li>Purpose: To verify the validity of subscription purchases and enable premium features<\/li>\n<li>Provider: Seresa.io - <a href=\"https:\/\/seresa.io\/terms\">Terms of Service<\/a> and <a href=\"https:\/\/seresa.io\/privacy\">Privacy Policy<\/a><\/li>\n<\/ul><\/li>\n<li><p>Package Installation<\/p>\n\n<ul>\n<li>What: The plugin connects to https:\/\/sub.seresa.app\/premium-downloader\/v1\/download to download premium components<\/li>\n<li>When: This occurs only after subscription verification when the user initiates the installation of premium features<\/li>\n<li>Data sent: Verified subscription code, site URL, WordPress version, and PHP version<\/li>\n<li>Purpose: To securely download and install authorized premium components<\/li>\n<li>Provider: Seresa.io - <a href=\"https:\/\/seresa.io\/terms\">Terms of Service<\/a> and <a href=\"https:\/\/seresa.io\/privacy\">Privacy Policy<\/a><\/li>\n<\/ul><\/li>\n<li><p>Transmute Engine (Premium Feature)<\/p>\n\n<ul>\n<li>What: Premium users' event data is processed through Transmute Engine, a server-side event processing service<\/li>\n<li>When: When events are triggered on your website (page views, clicks, form submissions, etc.)<\/li>\n<li>Data sent: Event data, UTM parameters, and tracking information<\/li>\n<li>Purpose: To process and route event data to your configured third-party services<\/li>\n<li>How it works: Transmute Engine acts as a first-party server to your website, temporarily processing data without permanent storage, and forwarding it to your specified endpoints<\/li>\n<li>Provider: Seresa.io - <a href=\"https:\/\/seresa.io\/terms\">Terms of Service<\/a> and <a href=\"https:\/\/seresa.io\/privacy\">Privacy Policy<\/a><\/li>\n<\/ul><\/li>\n<\/ol>\n\n<p>No data is shared with third parties beyond Seresa.io, and all connections use secure HTTPS encryption. Users can choose not to use premium features, in which case no external connections will be made.<\/p>\n\n<h3>Third-Party Libraries<\/h3>\n\n<p>This plugin uses the following third-party libraries:<\/p>\n\n<ol>\n<li><p>Vue.js<\/p>\n\n<ul>\n<li>What: A progressive JavaScript framework for building user interfaces<\/li>\n<li>Website: https:\/\/vuejs.org\/<\/li>\n<li>License: MIT License - https:\/\/github.com\/vuejs\/vue\/blob\/main\/LICENSE<\/li>\n<\/ul><\/li>\n<li><p>Vue Toastification<\/p>\n\n<ul>\n<li>What: Toast notification library for Vue.js<\/li>\n<li>Website: https:\/\/github.com\/Maronato\/vue-toastification<\/li>\n<li>License: MIT License<\/li>\n<\/ul><\/li>\n<li><p>Lucide Icons<\/p>\n\n<ul>\n<li>What: Beautiful &amp; consistent icon toolkit for Vue.js<\/li>\n<li>Website: https:\/\/lucide.dev\/<\/li>\n<li>License: ISC License - https:\/\/github.com\/lucide-icons\/lucide\/blob\/main\/LICENSE<\/li>\n<\/ul><\/li>\n<li><p>Axios<\/p>\n\n<ul>\n<li>What: Promise-based HTTP client for JavaScript<\/li>\n<li>Website: https:\/\/axios-http.com\/<\/li>\n<li>License: MIT License<\/li>\n<\/ul><\/li>\n<li><p>Pinia<\/p>\n\n<ul>\n<li>What: State management library for Vue.js<\/li>\n<li>Website: https:\/\/pinia.vuejs.org\/<\/li>\n<li>License: MIT License<\/li>\n<\/ul><\/li>\n<li><p>Vue I18n<\/p>\n\n<ul>\n<li>What: Internationalization plugin for Vue.js<\/li>\n<li>Website: https:\/\/vue-i18n.intlify.dev\/<\/li>\n<li>License: MIT License<\/li>\n<\/ul><\/li>\n<li><p>Tailwind CSS<\/p>\n\n<ul>\n<li>What: Utility-first CSS framework<\/li>\n<li>Website: https:\/\/tailwindcss.com\/<\/li>\n<li>License: MIT License<\/li>\n<\/ul><\/li>\n<li><p>WordPress JavaScript Libraries<\/p>\n\n<ul>\n<li>What: Official WordPress JavaScript libraries (@wordpress\/api-fetch, @wordpress\/components, @wordpress\/element, @wordpress\/i18n)<\/li>\n<li>Website: https:\/\/developer.wordpress.org\/block-editor\/reference-guides\/packages\/<\/li>\n<li>License: GPL-2.0+ License<\/li>\n<\/ul><\/li>\n<\/ol>\n\n<p>All third-party libraries used are compatible with the GPL-2.0+ license of this plugin.<\/p>\n\n<h3>Build Tools and Source Code Access<\/h3>\n\n<p>This plugin uses modern frontend tools (Vue.js, Vite, Axios) to build its admin interface. The full, human-readable source code is included directly within the plugin package under the \/src directory.<\/p>\n\n<p>Included source code:\n    \u2022   \/src\/ contains all original Vue 3 components, Pinia store, and JavaScript modules\n    \u2022   \/dist\/ contains the compiled production build\n    \u2022   \/src\/README.md contains full build instructions and configuration references<\/p>\n\n<p>Build Toolchain:\n    \u2022   Vue.js 3\n    \u2022   Vite\n    \u2022   Tailwind CSS\n    \u2022   PostCSS\n    \u2022   Vitest\n    \u2022   Grunt<\/p>\n\n<p>To rebuild the admin interface from source:\n    1.  Navigate to the \/src directory\n    2.  Run npm install\n    3.  Run npm run build:free or npm run build:premium to compile assets to \/dist<\/p>\n\n<p>This ensures full compliance with WordPress.org\u2019s guidelines requiring human-readable source code for all minified or bundled assets.<\/p>\n\n<p>For detailed developer instructions, see \/src\/README.md.<\/p>\n\n<h3>License<\/h3>\n\n<p>This plugin is licensed under the GNU General Public License v2.0 or later.<br \/>\nFor more details, visit: https:\/\/www.gnu.org\/licenses\/gpl-2.0.html<\/p>\n\n<h3>Support<\/h3>\n\n<p>For <strong>free users<\/strong>: Report issues on our GitHub page:<br \/>\n\ud83d\udd17 <a href=\"https:\/\/github.com\/seresa8\/inPIPE-by-Seresa-issues\/issues\">GitHub Issues<\/a><\/p>\n\n<p>For <strong>general inquiries<\/strong>, contact us at <a href=\"mailto:support@seresa.io\">support@seresa.io<\/a>.<\/p>\n\n<p>For <strong>premium users<\/strong>: Get priority support at \ud83d\udd17 <a href=\"https:\/\/seresa.io\/support\">seresa.io\/support<\/a>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to your WordPress plugin directory (<code>wp-content\/plugins\/<\/code>).  <\/li>\n<li>Activate the plugin through the <strong>Plugins &gt; Installed Plugins<\/strong> menu in WordPress.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"can%20i%20use%20this%20plugin%20just%20to%20generate%20utm%20parameter%20query%20strings%3F\"><h3>Can I use this plugin just to generate UTM parameter query strings?<\/h3><\/dt>\n<dd><p>Yes! The plugin allows you to easily generate <strong>UTM parameter query strings<\/strong> for your marketing campaigns. You can create both <strong>plain and coded UTM query strings<\/strong> with simple click options. If you only need to generate and use UTM parameters without decoding, you can do so without enabling the decoding feature.<\/p><\/dd>\n<dt id=\"can%20i%20use%20plain%20utm%20parameters%20instead%20of%20coded%20ones%3F\"><h3>Can I use plain UTM parameters instead of coded ones?<\/h3><\/dt>\n<dd><p>Yes! The plugin supports both <strong>plain and coded UTM parameters<\/strong>. If you don\u2019t enable decoding, your standard UTM parameters will work as usual. If you want extra protection against ad blockers, you can enable decoding in the plugin settings.<\/p><\/dd>\n<dt id=\"how%20do%20i%20enable%20coded%20utm%20decoding%3F\"><h3>How do I enable coded UTM decoding?<\/h3><\/dt>\n<dd><p>Go to <strong>Settings &gt; WP inPIPE<\/strong> and turn on the option for <strong>Coded UTM Processing<\/strong>. When enabled, the plugin will detect and decode coded UTM query strings, replacing them with the full UTM parameters in the URL bar and pushing them to the dataLayer.<\/p><\/dd>\n<dt id=\"how%20does%20this%20help%20with%20google%20tag%20manager%20%28gtm%29%3F\"><h3>How does this help with Google Tag Manager (GTM)?<\/h3><\/dt>\n<dd><p>By pushing <strong>decoded UTM parameters<\/strong> directly into the <strong>dataLayer<\/strong>, Web GTM can receive the data without requiring extra configurations to extract and manage UTM values. This simplifies tracking setup and ensures cleaner data in your analytics.<\/p><\/dd>\n<dt id=\"what%20is%20utm%20api%20access%3F\"><h3>What is UTM API Access?<\/h3><\/dt>\n<dd><p>UTM API Access is a secure, key-protected REST API that lets external tools, scripts, and AI automations create, list, update, and delete your UTM links without using the dashboard. It exposes four server-to-server endpoints under <code>\/wp-json\/inpipe\/v1\/ext\/<\/code> \u2014 <code>utm-generate<\/code>, <code>utm-list<\/code>, <code>utm-delete<\/code>, and <code>status<\/code>. Full details, authentication, and code examples are in the <a href=\"https:\/\/support.seresa.io\/docs\/inpipe-utm-api-documentation\">inPIPE UTM API Documentation<\/a>.<\/p><\/dd>\n<dt id=\"how%20do%20i%20enable%20the%20utm%20api%20and%20get%20my%20api%20keys%3F\"><h3>How do I enable the UTM API and get my API keys?<\/h3><\/dt>\n<dd><p>First make sure <strong>UTM Processing<\/strong> is enabled, then open the <strong>UTM API Access<\/strong> panel in the inPIPE settings. Turn on the master toggle to provision your two scoped keys \u2014 a <strong>read-only<\/strong> key (for <code>utm-list<\/code> and <code>status<\/code>) and a <strong>read-write<\/strong> key (also required for <code>utm-generate<\/code> and <code>utm-delete<\/code>). You can copy or regenerate the keys at any time from the panel.<\/p><\/dd>\n<dt id=\"is%20the%20utm%20api%20secure%3F\"><h3>Is the UTM API secure?<\/h3><\/dt>\n<dd><p>Yes. Every request is served over HTTPS only and must carry a valid API key. The two keys are scoped (read-only vs. read-write) and stored <strong>encrypted at rest<\/strong> using libsodium, with the encryption key derived from your wp-config salts and never written to the database. The layer also applies per-operation rate limiting, per-site IP throttling, a same-site domain guard, and a storage cap. The endpoints are server-to-server only (browser CORS is suppressed).<\/p><\/dd>\n<dt id=\"where%20can%20i%20find%20full%20utm%20api%20documentation%3F\"><h3>Where can I find full UTM API documentation?<\/h3><\/dt>\n<dd><p>Complete documentation \u2014 endpoint reference, request\/response formats, authentication, rate limits, and examples \u2014 is available here: <a href=\"https:\/\/support.seresa.io\/docs\/inpipe-utm-api-documentation\">inPIPE UTM API Documentation<\/a><\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.0.3 - 2026-07-24<\/h4>\n\n<p><strong>Bug fix: broken admin styles after upgrading to Premium (stale cached CSS)<\/strong><\/p>\n\n<h4>BUG FIXES<\/h4>\n\n<ul>\n<li><strong>Admin UI no longer loads stale CSS after a Premium upgrade<\/strong>: The settings screen now pulls the real stylesheet directly, so the new styles appear immediately instead of requiring a manual browser\/CDN cache clear\n\n<ul>\n<li>The admin styles were enqueued through a build-generated redirect stub (<code>inPipeAdmin.css<\/code>) that only did <code>@import '.\/inPipeMain.css';<\/code>. WordPress applied the cache-busting version to the stub, but the imported <code>inPipeMain.css<\/code> \u2014 which actually contains the styles \u2014 was requested with no version query, so browsers and CDNs kept serving the old cached bundle after the upgrade<\/li>\n<li>The admin stylesheet now enqueues <code>inPipeMain.css<\/code> directly, so the <code>inpipe_assets_version<\/code> cache-buster applies to the file that holds the CSS<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>TECHNICAL<\/h4>\n\n<ul>\n<li><code>enqueue_admin_assets()<\/code> in <code>class-inpipe-vue-admin.php<\/code> now registers <code>dist\/css\/inPipeMain.css<\/code> instead of the <code>dist\/css\/inPipeAdmin.css<\/code> redirect stub, keyed to <code>inpipe_assets_version<\/code><\/li>\n<li>No change to what styles are shipped \u2014 only which file WordPress requests, so the version query busts the actual bundle<\/li>\n<\/ul>\n\n<h4>2.0.2 - 2026-07-20<\/h4>\n\n<p><strong>Database schema support for the premium Harvest Lite trial<\/strong><\/p>\n\n<h4>TECHNICAL<\/h4>\n\n<ul>\n<li>Added a <code>data_access_key<\/code> column to the <code>wp_inpipe_pluginsettings<\/code> table to store the read-only data key issued to premium Harvest Lite trial sites<\/li>\n<li>Bumped the internal database schema version so existing installs add the new column automatically on update (via dbDelta), rather than only on a fresh activation<\/li>\n<li>No changes to free-plugin behavior, UTM tracking, the admin UI, or any stored data<\/li>\n<\/ul>\n\n<h4>2.0.1 - 2026-07-15<\/h4>\n\n<p><strong>Bug fixes: stale dropdown values and reappearing custom parameters when editing a stored UTM URL<\/strong><\/p>\n\n<h4>BUG FIXES<\/h4>\n\n<ul>\n<li><strong>UTM Coder \u2014 Edit no longer offers deleted dropdown values<\/strong>: Opening a stored UTM URL for editing now refreshes the parameter dropdown options from the server first, so a value that was deleted in another browser tab or an earlier session is never offered again\n\n<ul>\n<li>Previously the dropdown options were loaded only once when the page opened, so a second open browser could keep showing an option that had already been removed<\/li>\n<li>The edit form now re-fetches the current options before populating, keeping the dropdowns in sync with the saved list<\/li>\n<li>No change to validation, sanitization, or what gets saved \u2014 only which options are shown<\/li>\n<\/ul><\/li>\n<li><strong>UTM Coder \u2014 Removed custom parameters no longer reappear on the next edit<\/strong>: Editing a stored UTM URL, removing a custom parameter, and saving now clears it for good\n\n<ul>\n<li>Previously the parameter was correctly dropped from the saved URL, but re-opening the record for editing brought it back into the input fields<\/li>\n<li>The removed parameter was left behind in the database and rebuilt when the record was re-opened; saving now clears the vacated custom-parameter slots so the input fields always match the saved URL<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>TECHNICAL<\/h4>\n\n<ul>\n<li><code>handleEdit()<\/code> in <code>inPipeUTMCoderComponent.vue<\/code> now awaits <code>fetchUtmOptions()<\/code> before populating the form<\/li>\n<li>Added <code>nocache_headers()<\/code> to the <code>inpipe-utm-options-fetch<\/code> REST handler \u2014 the GET endpoint previously sent no cache directives, so on servers without a FastCGI\/CDN bypass rule the options list could be served stale<\/li>\n<li><code>save_utm_url()<\/code> in <code>class-inpipe-utm-decoder.php<\/code> now blanks unused <code>utm_customN_*<\/code> column pairs on update \u2014 <code>$wpdb-&gt;update()<\/code> only touched the columns it was handed, so a reduced\/removed custom param previously left stale pairs that the fetch endpoint rebuilt into the edit form<\/li>\n<li>Removed the now-redundant external-API workaround for this (<code>set_custom_params()<\/code> in <code>class-inpipe-external-record-store.php<\/code> and its call in the write adapter) \u2014 the fix at the save layer covers every write path<\/li>\n<li>Added unit coverage for refetch-on-edit and fetch-before-populate ordering (<code>tests\/unit\/UTMCoderComponent.test.ts<\/code>)<\/li>\n<\/ul>\n\n<h4>DOCS<\/h4>\n\n<ul>\n<li>Rewrote the plugin short description to lead with agentic\/REST API UTM tracking (\"Agentic-ready UTM tracking via REST API. Mask, store, and decode UTM parameters for Google Analytics, Facebook Ads, and more.\")<\/li>\n<\/ul>\n\n<h4>2.0.0 - 2026-06-24<\/h4>\n\n<p><strong>UTM API Access, Stored UTM Attribution, Premium Update Reminder, In-Place Updates, Plugin List Enhancements, UTM Decoding Reliability &amp; Performance<\/strong><\/p>\n\n<h4>NEW FEATURES<\/h4>\n\n<ul>\n<li><strong>Stored UTM URLs \u2014 Creator &amp; Editor Attribution<\/strong>: Each stored UTM URL now records and displays who created it and who last edited it, alongside the existing \"Created\" date\n\n<ul>\n<li>URLs saved from the dashboard are attributed to the logged-in WordPress user (shown by display name)<\/li>\n<li>URLs created or updated through the External UTM API are attributed to \"API\"<\/li>\n<li>The \"Last Edited\" date and editor only appear once a record has actually been changed (unedited records show just \"Created\")<\/li>\n<li>Records created before this release show no attribution (graceful fallback \u2014 no raw values shown)<\/li>\n<li>External UTM API list\/read responses include privacy-safe <code>created_by<\/code> \/ <code>updated_by<\/code> fields \u2014 collapsed to <code>\"user\"<\/code> or <code>\"API\"<\/code> so internal WordPress user IDs are never exposed to third-party integrations<\/li>\n<li>New <code>created_by<\/code> \/ <code>updated_by<\/code> columns on the <code>inpipe_utm_codes<\/code> table; existing sites migrate automatically on upgrade with no data loss<\/li>\n<\/ul><\/li>\n<li><strong>UTM API Access \u2014 External REST API<\/strong>: Securely connect external tools and automations to your UTM links with a key-protected REST API (new \"UTM API Access\" panel, shown when UTM Processing is enabled)\n\n<ul>\n<li>Four server-to-server routes under <code>\/wp-json\/inpipe\/v1\/ext\/<\/code>: <code>utm-generate<\/code> (create\/update), <code>utm-list<\/code>, <code>utm-delete<\/code>, and <code>status<\/code><\/li>\n<li>Two scoped API keys \u2014 read-only and read-write \u2014 provisioned per site and regenerable from the dashboard<\/li>\n<li>Keys are stored <strong>encrypted at rest<\/strong> via libsodium (<code>InPipe_Encryption<\/code>), with the encryption key derived from the wp-config auth salts (never written to the database); only a masked display string is shown after first reveal<\/li>\n<li>Per-operation, three-tier rate limiting \u2014 per-second \/ per-minute \/ per-hour windows (read 10\/300\/10000, write 10\/300\/5000, delete 5\/30\/1000), fixed shared-hosting-safe ceilings (not admin-editable) \u2014 plus a site-wide request ceiling and per-site salted-IP throttling with escalating bans; over-limit responses carry a <code>Retry-After<\/code> header<\/li>\n<li>Domain guard fails closed \u2014 <code>base_url<\/code> must resolve to this site's own host before a write is accepted<\/li>\n<li>Admin-configurable storage cap gates new creates (HTTP 507); existing inventory stays fully readable (grandfathered)<\/li>\n<li>CORS is suppressed on the namespace (server-to-server only \u2014 no browser caller), and the layer ships its own request logger for diagnostics<\/li>\n<li>Documentation links surfaced throughout the UI: the Settings \"Enable UTM Processing with API\" label links to the API docs, and the UTM Coder shows an \"API\" button (linking to the docs) whenever UTM API Access is disabled, hidden once it is enabled<\/li>\n<\/ul><\/li>\n<li><strong>UTM Coder \u2014 Rename &amp; Smarter Validation<\/strong>: Saved dropdown options can now be renamed in place, and per-field validation is more permissive where it should be\n\n<ul>\n<li>New \"rename option\" action on UTM parameter dropdowns<\/li>\n<li><code>content<\/code> and <code>term<\/code> fields now accept spaces; apostrophes are normalized rather than rejected<\/li>\n<li>Other fields still reject spaces and invalid characters with a clear toast message<\/li>\n<\/ul><\/li>\n<li><strong>Visitor IP REST Endpoint<\/strong>: New public <code>\/wp-json\/inpipe\/v1\/visitor-ip<\/code> endpoint resolves the visitor IP from server headers (Cloudflare \/ X-Forwarded-For \/ X-Real-IP \/ REMOTE_ADDR)\n\n<ul>\n<li>Fallback for cached pages where <code>inPipeConfig.visitorIp<\/code> from <code>wp_localize_script<\/code> is stale<\/li>\n<li>Honors the <code>inpipe_anonymize_ip<\/code> setting via <code>wp_privacy_anonymize_ip()<\/code><\/li>\n<\/ul><\/li>\n<li><p><strong>Premium Update Reminder<\/strong>: Display-only \"update available\" notice for the premium plugin via the Seresa API<\/p>\n\n<ul>\n<li>Polls the Seresa update-check API on a throttled, jittered schedule from the admin screens (avoids thundering herd; each site checks at its own consistent offset)<\/li>\n<li>Shows an \"Update now\" reminder row under the plugin on the Plugins page, linking to the inPIPE settings page where the premium installer applies the update<\/li>\n<li>Display-only by design \u2014 does not modify WordPress's plugin-update system, keeping the free plugin fully WordPress.org-compliant and unable to interfere with its own .org-delivered updates<\/li>\n<li>Manual force-check available from the Vue dashboard<\/li>\n<li>Cache cleared automatically when subscription changes<\/li>\n<\/ul><\/li>\n<li><p><strong>In-Place Premium Updates<\/strong>: Premium users can now update without re-downloading the full package<\/p>\n\n<ul>\n<li>New <code>update<\/code> parameter on premium install API endpoint allows re-installation when already active<\/li>\n<li>Requests <code>unified-premium<\/code> package type for updates vs <code>plugin<\/code> for first-time upgrades<\/li>\n<li>Routes update through <code>InPipe_Premium_Updater<\/code> (premium class) for full plugin replacement<\/li>\n<li>Falls back to standard integrator for first-time upgrade flow<\/li>\n<\/ul><\/li>\n<li><p><strong>Plugin List Enhancements<\/strong>: Richer plugin row in WordPress Plugins page<\/p>\n\n<ul>\n<li>\"Update Available\" action link (red, bold) when premium update detected \u2014 links to settings<\/li>\n<li>\"Docs &amp; Support\" meta link pointing to support.seresa.io<\/li>\n<li>\"API\" meta link (between \"Docs &amp; Support\" and \"Go Premium\") pointing to the UTM API documentation<\/li>\n<li>\"Go Premium\" meta link (red, bold) for free users pointing to seresa.io\/pricing<\/li>\n<li>Plugin name, description, and version dynamically change when premium is active<\/li>\n<\/ul><\/li>\n<li><p><strong>Gorilla Food Cookie \u2014 Rolling Renewal<\/strong>: The <code>gorilla_food<\/code> visitor cookie now uses a sliding 400-day expiry instead of a fixed expiry from first visit<\/p>\n\n<ul>\n<li>Returning visitors have their cookie refreshed on every page load via the <code>\/wp-json\/inpipe\/v1\/gorilla-food<\/code> REST endpoint<\/li>\n<li>Identity persists indefinitely as long as the visitor returns within the browser's cookie ceiling (RFC 6265bis)<\/li>\n<li>Renewal runs in a REST context only \u2014 Set-Cookie headers cannot be captured by page caches (WP Super Cache, W3TC, LiteSpeed, Cloudflare)<\/li>\n<li>Cookie value is never rotated \u2014 only the expiry slides forward, preserving attribution continuity<\/li>\n<li>Malformed incoming cookies are rejected before re-emission, blocking session-fixation attempts<\/li>\n<\/ul><\/li>\n<li><p><strong>Gorilla Food \u2014 Public Hooks for Consumer Plugins<\/strong>: New WordPress hooks expose the visitor UID to other inPIPE\u2122 ecosystem plugins<\/p>\n\n<ul>\n<li><code>inpipe_get_gorilla_food()<\/code> \u2014 function returning the current visitor UID (or null)<\/li>\n<li><code>inpipe_gorilla_food<\/code> \u2014 filter for overriding\/extending the UID before it reaches consumers<\/li>\n<li><code>inpipe_user_identified<\/code> \u2014 action fired on <code>init<\/code> (priority 5) when a UID is present, primary integration point for consumer plugins<\/li>\n<li>Consumer plugins should use these hooks rather than reading the cookie directly<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>IMPROVEMENTS<\/h4>\n\n<ul>\n<li><strong>Stored UTM URLs \u2014 Search &amp; Pagination<\/strong>: The saved-UTM list in the dashboard now has a search box (filter by URL\/params) and paginated results, so large inventories stay manageable<\/li>\n<li><strong>UTM Decode Caching<\/strong>: Decoded UTM keys are cached in a 6-hour transient \u2014 repeat requests for the same key return instantly and bypass rate limiting entirely (same key always decodes to the same params)<\/li>\n<li><strong>Higher UTM Rate Limit<\/strong>: Uncached UTM decode requests raised from 50 to 200 per hour per IP<\/li>\n<li><strong>Reliable UTM Handoff Across Navigation<\/strong>: Original coded URL data and decoded events are written to <code>sessionStorage<\/code> synchronously before navigation, so the destination page can emit <code>utm_decoded<\/code> \/ <code>inPIPE_utm_decoded<\/code> reliably (previously <code>beforeunload<\/code> fetches were cancelled by the browser on hard navigations)<\/li>\n<li><strong>UTM Decoder Retry<\/strong>: The decode request now retries once (after 300ms) on transient <code>502\/503\/504<\/code> responses caused by PHP-FPM overload or brief restarts<\/li>\n<li><strong>Faster DB Version Check<\/strong>: <code>inpipe_maybe_upgrade_db()<\/code> bails early when <code>inpipe_db_version<\/code> already matches, avoiding a DB query on every request<\/li>\n<li><strong>Subscription Data Enrichment<\/strong>: Upgrade process now saves additional fields from the verification API response\n\n<ul>\n<li><code>subscription_creation<\/code> extracted from <code>current_subscription_start<\/code> (fixes \"Activated On: Unknown\" in subscription panel)<\/li>\n<li><code>subscription_name<\/code> extracted from <code>plan_brand_name<\/code> (e.g., \"Cerise\")<\/li>\n<li><code>events_allowance<\/code> seeded into usage data immediately on upgrade (no longer waits for first webhook)<\/li>\n<\/ul><\/li>\n<li><strong>Subscription Plan Validation<\/strong>: Updated valid plans \u2014 added <code>harvest<\/code> and <code>entry<\/code>, removed <code>business<\/code><\/li>\n<li><strong>Premium Version Source<\/strong>: <code>inpipe_get_premium_version()<\/code> now prefers <code>INPIPE_PREMIUM_VERSION<\/code> constant (set at load time) over database option for accuracy<\/li>\n<li><strong>Frontend Premium Version<\/strong>: <code>premiumVersion<\/code> now exposed to Vue admin settings for dashboard display<\/li>\n<li><strong>Package Installer Return Values<\/strong>: Fixed three code paths that returned <code>void<\/code> instead of <code>WP_Error<\/code> \u2014 callers can now properly detect and handle failures<\/li>\n<li><strong>Premium Version Sync<\/strong>: After install\/upgrade, calls the update-check API to set the correct <code>inpipe_premium_version<\/code> in the database \u2014 fixes version staying at default <code>1.0.0<\/code> or <code>2.0.0<\/code><\/li>\n<li><strong>Subscription Vue Data Enrichment<\/strong>: <code>get_subscription_data()<\/code> now exposes additional fields to the Vue admin dashboard\n\n<ul>\n<li><code>planBrandName<\/code> and <code>billingPeriod<\/code> merged from <code>inpipe_subscription<\/code> option (set by Seresa webhook)<\/li>\n<li><code>outpipesLimit<\/code>, <code>outpipesAddonCount<\/code>, <code>outpipesAddonLimit<\/code>, <code>outpipesAddonAvailable<\/code> from <code>inpipe_outpipe_data<\/code> option<\/li>\n<li><code>outpipesActive<\/code> \u2014 live count of active outPIPEs via <code>InPipe_Premium_Connections_Manager<\/code> (premium only)<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>BUG FIXES<\/h4>\n\n<ul>\n<li><strong>Rate Limit on Premium Upgrade<\/strong>: Subscription verification now correctly handles HTTP <code>429<\/code> responses with a clear \"too many attempts\" message instead of falling through to a generic error\n\n<ul>\n<li>Simplified the Vue-side 429 detection (removed brittle string matching on the error message)<\/li>\n<\/ul><\/li>\n<li><strong>UTM Coder \u2014 Landing page path is now editable after it's locked<\/strong>: Clicking the Landing Page field once UTM parameters have been added (or after the path was confirmed) now re-opens it for editing instead of showing a \"Reset All to edit\" notice\n\n<ul>\n<li>Previously the path could only be changed by clearing the entire form, because the field was replaced by the live UTM query preview \/ a read-only value once any parameter existed<\/li>\n<li>Editing runs the same five-layer path validation as the original confirm step, then re-locks the field \u2014 no security or sanitization change<\/li>\n<li>The confirm (\u2713) button and Enter\/blur all confirm an inline edit; the regenerated full and coded URLs update automatically, and the coded URL keeps its original id so shared links don't break<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>NEW FILES<\/h4>\n\n<ul>\n<li><code>includes\/core\/api\/external\/<\/code> \u2014 UTM API Access layer (24 files): external endpoints (<code>class-inpipe-api-endpoints-external.php<\/code>), admin controller, settings, request logger, plus <code>adapter\/<\/code>, <code>storage\/<\/code>, <code>ratelimit\/<\/code>, <code>handlers\/<\/code>, <code>validation\/<\/code>, and <code>flow\/<\/code> subsystems<\/li>\n<li><code>includes\/core\/class-inpipe-encryption.php<\/code> \u2014 libsodium encryption util promoted to core (from premium) for API-key storage at rest<\/li>\n<li><code>src\/shared\/ExternalApiPanel.vue<\/code> \u2014 \"UTM API Access\" settings panel<\/li>\n<li><code>includes\/free\/premium-upgrade\/class-inpipe-premium-update-checker.php<\/code> \u2014 Premium update checker with jitter-based caching<\/li>\n<\/ul>\n\n<h4>TECHNICAL<\/h4>\n\n<ul>\n<li>Registered the four <code>\/inpipe\/v1\/ext\/*<\/code> external routes plus admin routes (<code>\/inpipe-ext-settings<\/code>, <code>\/inpipe-ext-regenerate-key<\/code>) gated by <code>manage_options<\/code> + nonce<\/li>\n<li>Added <code>generate_unique_code()<\/code> public wrapper on <code>InPipe_UTM_Decoder<\/code> so the external write adapter can mint collision-checked short codes without a browser<\/li>\n<li>Added <code>inpipe_setting_updated<\/code>-driven external config refresh and <code>ExternalApiPanel.vue<\/code> injection via the new settings <code>after-header<\/code> slot<\/li>\n<li>External UTM API endpoints exposed in <code>src\/utils\/inPipeApiEndpoints.js<\/code><\/li>\n<li>Added <code>handle_visitor_ip()<\/code> and registered the <code>\/visitor-ip<\/code> route in <code>InPipe_API_Endpoints_Free<\/code><\/li>\n<li>Added transient caching (<code>inpipe_utm_decoded_{key}<\/code>) in the UTM decode handler and a cache short-circuit in <code>validate_public_utm_request()<\/code><\/li>\n<li>Added <code>case 429<\/code> handling to <code>InPipe_Subscription_Manager<\/code> verification response mapping<\/li>\n<li>Added <code>inpipe_setting_updated<\/code> action hook (fired after a setting is saved) in <code>InPipe_Settings_Manager<\/code><\/li>\n<li>Added an <code>after-header<\/code> slot to <code>inPipeSettingsComponent.vue<\/code> for premium content injection<\/li>\n<li>Added <code>fetchWithRetry()<\/code> and synchronous <code>sessionStorage<\/code> writes in <code>inPipeUtmDecoder.js<\/code><\/li>\n<li>Added <code>handleRenameOption()<\/code> and per-field space\/apostrophe handling in <code>inPipeUTMCoderComponent.vue<\/code><\/li>\n<li>Added <code>isEditingPath<\/code> state and <code>confirmPathEdit()<\/code> to <code>inPipeUTMCoderComponent.vue<\/code> so a locked landing-page path can be re-opened for editing (click-to-unlock); <code>.landing-path-input<\/code> cursor reflects clickable\/editable states<\/li>\n<li>Added <code>$is_update<\/code> property and parameter to <code>InPipe_Package_Installer::install_premium_package()<\/code><\/li>\n<li>Added <code>update<\/code> parameter handling in <code>handle_premium_install()<\/code> API endpoint<\/li>\n<li>Added <code>add_row_meta()<\/code> and <code>modify_plugin_description()<\/code> methods to <code>InPipe_Plugin<\/code><\/li>\n<li>Registered <code>InPipe_Premium_Update_Checker<\/code> in plugin bootstrap (only when premium is active)<\/li>\n<li>Added <code>InPipe_Premium_Update_Checker::cleanup()<\/code> to uninstall routine<\/li>\n<li>Fixed <code>install_premium_package()<\/code> to return <code>true<\/code> on success, <code>WP_Error<\/code> on failure (was void)<\/li>\n<li>Added <code>sync_premium_version()<\/code> to <code>InPipe_Package_Installer<\/code> \u2014 queries update-check API post-install to set correct premium version<\/li>\n<li>Added <code>InPipe_Gorilla_Food_Manager::renew_cookie()<\/code> \u2014 re-emits existing cookie with fresh expiry; validates input, no-ops for bots \/ sent headers \/ missing or invalid cookie<\/li>\n<li>Added <code>InPipe_Gorilla_Food_Integration::renew_cookie()<\/code> static facade \u2014 lazily instantiates manager when called from REST context<\/li>\n<li>Added <code>InPipe_Gorilla_Food_Integration::broadcast_user_identified()<\/code> \u2014 fires <code>inpipe_user_identified<\/code> action on <code>init<\/code> priority 5 when a UID is present<\/li>\n<li>Added <code>inpipe_get_gorilla_food()<\/code> function with <code>inpipe_gorilla_food<\/code> filter in <code>inpipe-gorilla-food-functions.php<\/code><\/li>\n<li>Updated <code>handle_gorilla_food()<\/code> REST handler to call <code>renew_cookie()<\/code> for returning visitors (rolling renewal)<\/li>\n<li>Replaced misleading <code>httponly<\/code> inline comment in <code>InPipe_Gorilla_Food_Manager::set_cookie()<\/code> \u2014 JS reads value via REST endpoint, not the cookie<\/li>\n<\/ul>\n\n\n\n<h4>1.1.1 - 2026-02-12<\/h4>\n\n<p><strong>UTM Import, Dropdown Options Management, Edit UX Overhaul, Validation &amp; Security Enhancements<\/strong><\/p>\n\n<h4>NEW FEATURES<\/h4>\n\n<ul>\n<li><p><strong>Quick Import UTM<\/strong>: Paste any URL containing UTM parameters and auto-fill the form<\/p>\n\n<ul>\n<li>Supports full URLs, query-only strings, bare parameters, and URLs without protocol<\/li>\n<li>Six-step validation chain: empty check, 512-char length cap, multiple URL detection, dangerous protocol blocking, URL parsing with fallbacks, and UTM parameter extraction<\/li>\n<li>Extracts standard UTM parameters (source, medium, campaign, term, content, id)<\/li>\n<li>Now also picks up all non-standard query parameters as custom parameters (up to 3), not just <code>utm_*<\/code> prefixed ones<\/li>\n<li>Domain validation: rejects URLs that don't match the site domain<\/li>\n<li>Warning toast when custom parameters exceed the limit, showing how many were skipped<\/li>\n<li>Landing path extracted from URL and auto-confirmed<\/li>\n<li>Import UTM button in card header next to Reset All<\/li>\n<\/ul><\/li>\n<li><p><strong>UTM Dropdown Options Management<\/strong>: Custom dropdown values for all six UTM parameter fields<\/p>\n\n<ul>\n<li>New <code>inpipe_utm_options<\/code> database table with seeded defaults and user-added values<\/li>\n<li>Add custom values inline via dropdown input (auto-saved to server immediately)<\/li>\n<li>Delete any option (including defaults) via delete icon in dropdown<\/li>\n<li>Options loaded from server on mount via <code>InPipe_UTM_Options_Manager<\/code> with 24-hour object caching<\/li>\n<li>Toast feedback on add (\"{value} added\") and delete (\"{value} removed\")<\/li>\n<\/ul><\/li>\n<li><p><strong>Landing Page Path Confirmation<\/strong>: Confirm-before-edit workflow for the landing page path<\/p>\n\n<ul>\n<li>Three-state field: editable input with checkmark \u2192 confirmed display \u2192 live query preview<\/li>\n<li>Five-layer path validation: query characters (<code>?#&amp;=<\/code>), UTM parameter patterns, character allowlist, path traversal\/dot abuse, consecutive slashes<\/li>\n<li>UTM params lock overlay when path is typed but not confirmed (prevents editing UTM fields until path is confirmed)<\/li>\n<li>Users can skip the path entirely and go straight to UTM params<\/li>\n<\/ul><\/li>\n<li><p><strong>Live UTM Query Preview<\/strong>: Real-time preview of the URL being built inside the landing page field<\/p>\n\n<ul>\n<li>Shows <code>page\/subpage?utm_source=google&amp;utm_medium=cpc&amp;custom_key=value<\/code> as params are selected<\/li>\n<li>Replaces the editable input once any UTM parameter has a value<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>UTM EDIT UX OVERHAUL<\/h4>\n\n<ul>\n<li><strong>Editing State Indicator<\/strong>: Blue banner below card header when editing a stored UTM\n\n<ul>\n<li>Shows pencil icon, \"Editing UTM:\" label, and the UTM ID in a monospace badge<\/li>\n<li>Cancel button to exit edit mode and clear the form<\/li>\n<\/ul><\/li>\n<li><strong>Save Button Context<\/strong>: Button changes from \"Save UTM\" to \"Update UTM\" with pencil icon when editing<\/li>\n<li><strong>Active UTM Highlight<\/strong>: Stored UTM item being edited gets a blue border and tint<\/li>\n<li><strong>Saved UTM Highlight<\/strong>: Newly saved or updated UTM gets a primary-color highlight with 3-second fade-out animation, auto-scrolls into view<\/li>\n<li><strong>Auto-Copy on Save<\/strong>: Coded URL is automatically copied to clipboard after saving\n\n<ul>\n<li>Toast message: \"UTM saved \u2014 coded URL copied to clipboard!\"<\/li>\n<li>Graceful fallback if clipboard access is denied<\/li>\n<\/ul><\/li>\n<li><strong>Param Value Indicators<\/strong>: UTM parameter cards show primary-color border when they have a value<\/li>\n<li><strong>Scroll Behavior<\/strong>: Edit and import scroll to the top of the UTM Parameters card; save scrolls to the highlighted stored UTM<\/li>\n<\/ul>\n\n<h4>EDIT BUG FIXES<\/h4>\n\n<ul>\n<li><strong>Fixed hasUnsavedChanges<\/strong>: Now compares against a snapshot of the loaded UTM values instead of static empty defaults<\/li>\n<li><strong>Fixed Coded URL Regeneration<\/strong>: Editing a UTM no longer generates a new random coded URL value on every keystroke \u2014 preserves the original coded URL so shared links aren't broken<\/li>\n<li><strong>Fixed Watcher During Edit Load<\/strong>: Added <code>isLoadingEdit<\/code> guard to prevent the deep watcher from firing multiple times while populating the form during edit<\/li>\n<li><strong>Fixed Custom Params Shallow Copy<\/strong>: Edit now deep-copies custom parameters to prevent mutation of stored UTM data<\/li>\n<\/ul>\n\n<h4>SECURITY ENHANCEMENTS<\/h4>\n\n<ul>\n<li><p><strong>Allowlist-Based Sanitization<\/strong>: Replaced blocklist <code>sanitizeUtmValue()<\/code> with normalize-and-allowlist approach<\/p>\n\n<ul>\n<li>NFKC normalization collapses fullwidth characters (e.g., <code>\uff47\uff4f\uff4f\uff47\uff4c\uff45<\/code> \u2192 <code>google<\/code>)<\/li>\n<li>Strips zero-width characters, directional overrides, and BOM marks<\/li>\n<li>Allowlist filter: only <code>a-z<\/code>, <code>0-9<\/code>, <code>_<\/code>, <code>-<\/code>, <code>.<\/code>, space survive<\/li>\n<li>Blocks emoji, non-standard whitespace, control characters, and all non-Latin input<\/li>\n<\/ul><\/li>\n<li><p><strong>Strict Custom Key Sanitization<\/strong>: New <code>sanitizeCustomKey()<\/code> function for custom parameter keys<\/p>\n\n<ul>\n<li>Only <code>a-z<\/code>, <code>0-9<\/code>, <code>_<\/code>, <code>-<\/code> allowed (no spaces or periods)<\/li>\n<\/ul><\/li>\n<li><p><strong>Custom Parameter Input Validation<\/strong>: Blur-based validation for custom parameter keys and values<\/p>\n\n<ul>\n<li>Key validation: rejects invalid characters, standard UTM name collisions, <code>utm_<\/code> prefix, and duplicate keys<\/li>\n<li>Value validation: rejects query-breaking and injection characters<\/li>\n<li>Immediate feedback via warning toasts \u2014 invalid input is rejected and field is cleared on blur<\/li>\n<li>Uppercase input silently normalized to lowercase on blur (e.g., <code>TEST<\/code> \u2192 <code>test<\/code>)<\/li>\n<li>Save-time sanitization via <code>sanitizeCustomKey()<\/code> \/ <code>sanitizeUtmValue()<\/code> as final safety net<\/li>\n<\/ul><\/li>\n<li><p><strong>Dropdown Value Sanitization<\/strong>: <code>handleAddFromDropdown()<\/code> sanitizes via allowlist before setting v-model<\/p>\n\n<ul>\n<li>Strict equality check rejects any input altered by sanitization (e.g., <code>&lt;script&gt;alert(1)&lt;\/script&gt;<\/code> \u2192 rejected)<\/li>\n<li>Dirty value guard in watcher silently clears pre-existing dirty options on selection<\/li>\n<\/ul><\/li>\n<li><p><strong>Landing Page Path Hardening<\/strong>: Five-layer validation for the landing page path<\/p>\n\n<ul>\n<li>Layer 3: Character allowlist \u2014 only <code>a-z<\/code>, <code>0-9<\/code>, <code>-<\/code>, <code>_<\/code>, <code>.<\/code>, <code>\/<\/code> allowed (rejects commas, spaces, special chars)<\/li>\n<li>Layer 4: Path traversal protection \u2014 blocks <code>..\/<\/code>, <code>.\/<\/code>, leading\/trailing dots, <code>\/.<\/code> patterns<\/li>\n<li>Layer 5: Malformed path detection \u2014 blocks consecutive slashes (<code>\/\/<\/code>)<\/li>\n<\/ul><\/li>\n<li><p><strong>Import Domain Validation<\/strong>: Imported URLs are validated against the site domain \u2014 mismatched domains are rejected with a clear error message<\/p><\/li>\n<\/ul>\n\n<h4>IMPROVEMENTS<\/h4>\n\n<ul>\n<li><p><strong>inPipeBaseSelect Component<\/strong>: Complete rebuild with custom dropdown mode<\/p>\n\n<ul>\n<li>Custom dropdown with deletable options, inline custom value input, keyboard navigation<\/li>\n<li>ARIA combobox\/listbox roles for accessibility<\/li>\n<li>Click-outside close, escape key handling, arrow key navigation with highlighted index<\/li>\n<li>Falls back to native <code>&lt;select&gt;<\/code> when <code>deletableOptions<\/code> is not provided<\/li>\n<\/ul><\/li>\n<li><p><strong>Coded URL Landing Path<\/strong>: Both full URL and coded URL now include the landing page path<\/p><\/li>\n<li><strong>Placeholder Update<\/strong>: Landing page placeholder changed to <code>page\/subpage<\/code><\/li>\n<li><strong>Emoji to Lucide Icons<\/strong>: Replaced all emoji icons in UTM Coder with Lucide icon components (Download, RefreshCcw, Pencil, Trash2, Save, Copy, Check, Loader, Plus, Zap, CircleAlert, Rocket)<\/li>\n<li><strong>Stored UTMs Spacing Fix<\/strong>: Fixed <code>space-y<\/code> (Tailwind-only utility) not working in plain CSS \u2014 replaced with flexbox gap for proper spacing between stored UTM items and URL rows<\/li>\n<\/ul>\n\n<h4>NEW FILES<\/h4>\n\n<ul>\n<li><code>includes\/core\/class-inpipe-utm-options-manager.php<\/code> \u2014 UTM dropdown options CRUD with WordPress object caching<\/li>\n<\/ul>\n\n<h4>TECHNICAL<\/h4>\n\n<ul>\n<li>Bumped <code>INPIPE_DB_VERSION<\/code> from <code>1.0.0<\/code> to <code>1.1.0<\/code> to trigger database upgrade for users updating from v1.1.0 \u2014 ensures <code>inpipe_utm_options<\/code> table is created via <code>dbDelta<\/code><\/li>\n<li>Added <code>inpipe_utm_options<\/code> table: <code>id<\/code>, <code>field_name<\/code>, <code>option_value<\/code>, <code>is_default<\/code>, <code>created_at<\/code>, <code>updated_at<\/code> with unique index on <code>(field_name, option_value)<\/code><\/li>\n<li>Added <code>inpipe_seed_utm_options()<\/code> function in <code>install.php<\/code> with INSERT IGNORE for idempotent re-activation<\/li>\n<li>Added 3 new REST API endpoints: <code>inpipe-utm-options-fetch<\/code>, <code>inpipe-utm-options-save<\/code>, <code>inpipe-utm-options-delete<\/code><\/li>\n<li>Added <code>handle_utm_options_fetch()<\/code>, <code>handle_utm_options_save()<\/code>, <code>handle_utm_options_delete()<\/code> to <code>InPipe_API_Endpoints_Free<\/code><\/li>\n<li>Added <code>UTM_OPTIONS_FETCH<\/code>, <code>UTM_OPTIONS_SAVE<\/code>, <code>UTM_OPTIONS_DELETE<\/code> to frontend <code>API_ENDPOINTS<\/code><\/li>\n<li>Removed Gorilla tracking script from free build in <code>vite.config.js<\/code> (premium-only)<\/li>\n<li>Table added to <code>inpipe_cleanup_tables()<\/code> for proper uninstall cleanup<\/li>\n<li>Added <code>editSnapshot<\/code>, <code>editingCodedValue<\/code>, <code>isLoadingEdit<\/code>, <code>highlightedUtmId<\/code>, <code>utmParamsCard<\/code> reactive refs to UTM Coder component<\/li>\n<\/ul>\n\n\n\n<h4>1.1.0 - 2026-01-29<\/h4>\n\n<p><strong>Gorilla Food REST API Endpoint, Cache-Busting &amp; Hourly Usage Sync<\/strong><\/p>\n\n<h4>NEW FEATURES<\/h4>\n\n<ul>\n<li><strong>Hourly Usage Data Sync<\/strong>: <code>inpipe_sync_subscription_data<\/code> now fetches fresh usage data from Subscriber App API\n\n<ul>\n<li>Automatically updates <code>inpipe_usage_data<\/code> option with events_used_this_month, allowance, etc.<\/li>\n<li>Updates <code>inpipe_last_webhook<\/code> timestamp so \"Synced at\" reflects actual sync time<\/li>\n<li>No longer relies solely on Stripe webhook push - now actively pulls data hourly<\/li>\n<\/ul><\/li>\n<li><strong>Gorilla Food REST API Endpoint<\/strong>: Added <code>\/wp-json\/inpipe\/v1\/gorilla-food<\/code> endpoint for Safari ITP bypass on cached pages\n\n<ul>\n<li>Called by JavaScript when no <code>gorilla_food<\/code> cookie exists<\/li>\n<li>Sets server-side cookie via PHP (bypasses Safari 7-day ITP limitation)<\/li>\n<li>REST API endpoints bypass FastCGI page cache, ensuring PHP always executes<\/li>\n<li>Returns <code>gorilla_food<\/code> visitor ID and <code>is_new_user<\/code> boolean<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>IMPROVEMENTS<\/h4>\n\n<ul>\n<li><p><strong>Gorilla Food Cookie Optimization<\/strong>: Cookie now only set for new users<\/p>\n\n<ul>\n<li>Prevents polluting page cache with Set-Cookie headers<\/li>\n<li>Returning users already have the cookie - no need to re-set<\/li>\n<li>Improves cache efficiency on high-traffic sites<\/li>\n<\/ul><\/li>\n<li><p><strong>Cache-Busting Page Reload<\/strong>: Improved page refresh after premium installation<\/p>\n\n<ul>\n<li>Replaced <code>window.location.reload()<\/code> with cache-busting URL approach<\/li>\n<li>Adds <code>_inpipe_refresh<\/code> timestamp parameter to force fresh HTML<\/li>\n<li>Ensures premium CSS\/JS loads correctly without manual hard refresh<\/li>\n<li>Applied to both successful installation and timeout recovery flows<\/li>\n<\/ul><\/li>\n<li><p><strong>Renamed Frontend Tracking Script<\/strong>: Renamed tracking script to \"Gorilla\" for consistency<\/p>\n\n<ul>\n<li>Script handle changed from <code>inpipe-tracking<\/code> to <code>inpipe-gorilla<\/code><\/li>\n<li>Script file renamed from <code>tracking.js<\/code> to <code>gorilla.js<\/code><\/li>\n<li>Backwards-compatible: <code>window.initInPipeTracker<\/code> aliased to <code>window.initGorilla<\/code><\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>TECHNICAL<\/h4>\n\n<ul>\n<li>Added <code>handle_gorilla_food()<\/code> method to <code>InPipe_API_Endpoints_Free<\/code> class<\/li>\n<li>Registered new public REST route <code>\/inpipe\/v1\/gorilla-food<\/code> with <code>__return_true<\/code> permission<\/li>\n<li>Updated <code>set_cookie()<\/code> in <code>InPipe_Gorilla_Food_Manager<\/code> to skip returning users<\/li>\n<li>Simplified cookie path to <code>\/<\/code> for broader compatibility<\/li>\n<li>Changed error logging to use <code>inpipe_debug_log()<\/code> helper<\/li>\n<li>Removed redundant <code>log_error()<\/code> private method from Gorilla Food Manager<\/li>\n<li>Updated <code>inPipeSubscriptionComponent.vue<\/code> reload logic with URL cache-busting<\/li>\n<li>Renamed <code>wp_enqueue_script<\/code> handle from <code>inpipe-tracking<\/code> to <code>inpipe-gorilla<\/code><\/li>\n<li>Updated <code>wp_localize_script<\/code> to use new <code>inpipe-gorilla<\/code> handle<\/li>\n<\/ul>\n\n\n\n<h4>1.0.9 - 2026-01-20<\/h4>\n\n<p><strong>Server-Side Cookie for Safari ITP Bypass (gorilla_food)<\/strong><\/p>\n\n<h4>FIXES<\/h4>\n\n<ul>\n<li>Fixed duplicate error message display on subscription activation page\n\n<ul>\n<li>Removed redundant error display from <code>inPipeBaseInput<\/code> <code>:error<\/code> prop<\/li>\n<li>Error now only shows once in the styled red-bordered box<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>NEW FEATURES<\/h4>\n\n<ul>\n<li><p><strong>Gorilla Food Cookie System<\/strong>: Implemented server-side cookie system to bypass Safari ITP 7-day JavaScript cookie limitation<\/p>\n\n<ul>\n<li>Server-side PHP <code>setcookie()<\/code> creates HTTP cookie that Safari treats as first-party<\/li>\n<li>400-day cookie expiration (maximum browser-allowed duration)<\/li>\n<li>Unique 35-character visitor ID format: <code>XXXXXXXX-XXXXXXXX-XXXXXXXX-XXXXXXXX<\/code><\/li>\n<li>Uses 58-character set excluding confusing characters (O, o, l, 0)<\/li>\n<\/ul><\/li>\n<li><p><strong>Visitor Identification<\/strong>: New <code>gorilla_food<\/code> cookie provides persistent visitor identification<\/p>\n\n<ul>\n<li>Survives Safari ITP cookie restrictions that limit JavaScript cookies to 7 days<\/li>\n<li>Cookie refreshed on every page load to maintain freshness<\/li>\n<li>Bot detection to skip cookie setting for crawlers<\/li>\n<\/ul><\/li>\n<li><p><strong>dataLayer Integration<\/strong>: Gorilla food value automatically pushed to dataLayer<\/p>\n\n<ul>\n<li><code>gorilla_food<\/code> - The unique visitor identifier<\/li>\n<li><code>is_new_user<\/code> - Boolean indicating if this is a new visitor (cookie just created)<\/li>\n<li>Available at priority 1 in <code>wp_head<\/code> for all tracking scripts<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>NEW FILES<\/h4>\n\n<ul>\n<li><code>includes\/core\/cookie\/index.php<\/code> - Directory protection<\/li>\n<li><code>includes\/core\/cookie\/inpipe-gorilla-food-functions.php<\/code> - Core generation functions and constants<\/li>\n<li><code>includes\/core\/cookie\/class-inpipe-gorilla-food-manager.php<\/code> - Cookie management class<\/li>\n<li><code>includes\/core\/cookie\/class-inpipe-gorilla-food-integration.php<\/code> - WordPress hooks and dataLayer output<\/li>\n<\/ul>\n\n<h4>TECHNICAL<\/h4>\n\n<ul>\n<li>Added <code>INPIPE_COOKIE_NAME<\/code> constant (<code>gorilla_food<\/code>)<\/li>\n<li>Added <code>INPIPE_COOKIE_EXPIRY<\/code> constant (400 days)<\/li>\n<li>Added <code>INPIPE_COOKIE_ID_LENGTH<\/code> constant (35 characters)<\/li>\n<li>Added <code>inpipe_generate_gorilla_food()<\/code> function<\/li>\n<li>Added <code>inpipe_generate_random_string()<\/code> function<\/li>\n<li>Added <code>inpipe_validate_gorilla_food()<\/code> function<\/li>\n<li>Added <code>InPipe_Gorilla_Food_Manager<\/code> class<\/li>\n<li>Added <code>InPipe_Gorilla_Food_Integration<\/code> class with static access methods<\/li>\n<li>Bootstrap runs at <code>plugins_loaded<\/code> priority 5<\/li>\n<li>Cookie set at <code>init<\/code> priority 1 (before headers sent)<\/li>\n<li>dataLayer output at <code>wp_head<\/code> priority 1<\/li>\n<\/ul>\n\n<h4>PREMIUM INTEGRATION<\/h4>\n\n<ul>\n<li>Premium plugin's tracking.js now reads <code>gorilla_food<\/code> from dataLayer<\/li>\n<li>All events include <code>gorilla_food<\/code> and <code>is_new_user<\/code> fields<\/li>\n<li>PHP-collected events also include gorilla_food via <code>InPipe_Gorilla_Food_Integration::get_gorilla_food()<\/code><\/li>\n<li>Added <code>inpipe_premium_build_event()<\/code> helper function for building events with gorilla_food<\/li>\n<\/ul>\n\n\n\n<h4>1.0.8 - 2026-01-15<\/h4>\n\n<p><strong>Redis Stale Cache Recovery<\/strong><\/p>\n\n<h4>NEW FEATURES<\/h4>\n\n<ul>\n<li>Added <code>refresh_settings()<\/code> method to Settings Manager for Redis stale cache recovery\n\n<ul>\n<li>Force-reloads settings from database bypassing object cache<\/li>\n<li>Used by Connections Manager when <code>client_id<\/code> appears empty due to stale Redis cache<\/li>\n<li>Used by Usage Webhook Sender when <code>subscription_key<\/code>\/<code>subscription_status<\/code> appear empty<\/li>\n<li>Prevents \"Valid client ID not found\" error on Redis-enabled servers (e.g., Cloudways)<\/li>\n<li>Ensures usage webhooks are scheduled and sent correctly even with stale cache<\/li>\n<\/ul><\/li>\n<\/ul>\n\n\n\n<h4>1.0.7 - 2026-01-13<\/h4>\n\n<p><strong>Auto-Disable Event Tracking for Expired Subscriptions<\/strong><\/p>\n\n<h4>NEW FEATURES<\/h4>\n\n<ul>\n<li><strong>Automatic Event Tracking Disable<\/strong>: Event tracking is now automatically disabled when subscription is not active\n\n<ul>\n<li>Catches cases where subscription expired while site was offline<\/li>\n<li>Runs on plugin initialization and when subscription status changes<\/li>\n<li>Only <code>active<\/code> and <code>trialing<\/code> subscriptions can have event tracking enabled<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>IMPROVEMENTS<\/h4>\n\n<ul>\n<li><strong>Subscription Data Always Available<\/strong>: Subscription data is now always included in admin settings, not just for active premium users\n\n<ul>\n<li>Enables proper display of expired\/cancelled subscription status in UI<\/li>\n<li>Allows users to see their subscription status even after it expires<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>UI ENHANCEMENTS<\/h4>\n\n<ul>\n<li><strong>Toggle Component Disabled State<\/strong>: Added disabled prop support to base toggle component\n\n<ul>\n<li>Visual feedback with reduced opacity and grayscale filter<\/li>\n<li>Prevents interaction when disabled<\/li>\n<li>Proper ARIA accessibility attributes<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>BUG FIXES<\/h4>\n\n<ul>\n<li><strong>Fixed Auto-Refresh After Premium Upgrade<\/strong>: Page now correctly auto-refreshes after successful premium installation\n\n<ul>\n<li>Backend was missing <code>safe_to_refresh<\/code> and <code>require_refresh<\/code> flags in API response<\/li>\n<li>Frontend condition was always false, preventing the reload from triggering<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>CODE CLEANUP<\/h4>\n\n<ul>\n<li>Removed dead code from Settings Manager:\n\n<ul>\n<li>Removed unused <code>$is_premium<\/code> property<\/li>\n<li>Removed unused <code>validate_license()<\/code> method (~75 lines)<\/li>\n<li>Premium status now fully handled by <code>InPipe_Status_Manager<\/code><\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>TECHNICAL<\/h4>\n\n<ul>\n<li>Added <code>maybe_disable_event_tracking()<\/code> method to <code>InPipe_Status_Manager<\/code><\/li>\n<li>Updated <code>on_subscription_changed()<\/code> to auto-disable tracking when subscription becomes inactive<\/li>\n<li>Modified <code>get_vue_admin_settings()<\/code> to always include subscription data<\/li>\n<li>Enhanced <code>inPipeBaseToggle.vue<\/code> with disabled state styling and handling<\/li>\n<li>Fixed <code>handle_premium_install()<\/code> response to include refresh flags<\/li>\n<li>Updated <code>class-inpipe-settings-manager.php<\/code> - Removed stale-cache check, dead code cleanup<\/li>\n<\/ul>\n\n\n\n<h4>1.0.6 - 2026-01-08<\/h4>\n\n<p><strong>Redis Object Cache Compatibility Fix<\/strong><\/p>\n\n<h4>BUG FIXES<\/h4>\n\n<ul>\n<li><strong>Fixed WordPress Hooks Not Registering on Redis Cache Hit<\/strong>: Hooks were incorrectly placed inside cache check blocks, causing them to not register when object cache returned a hit\n\n<ul>\n<li>WordPress hooks are request-specific and must be registered on every request<\/li>\n<li>Cache was preventing <code>add_action()<\/code> and <code>add_filter()<\/code> calls from executing on cached requests<\/li>\n<li>Fixes cron jobs not firing, REST API endpoints not registering, and event tracking not working on Redis\/Memcached hosting<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>AFFECTED FILES<\/h4>\n\n<ul>\n<li><code>class-inpipe-utm-decoder.php<\/code> - Fixed <code>init_hooks()<\/code> method<\/li>\n<li><code>class-inpipe-premium-event-collector.php<\/code> - Fixed <code>register_wordpress_hooks()<\/code>, <code>register_pattern_based_hooks()<\/code>, and <code>initialize_form_protection()<\/code> methods<\/li>\n<\/ul>\n\n<h4>TECHNICAL<\/h4>\n\n<ul>\n<li>Moved all <code>add_action()<\/code> and <code>add_filter()<\/code> calls outside of cache check if-blocks<\/li>\n<li>Cache is now only used for debug logging purposes (first-init detection)<\/li>\n<li>WordPress automatically deduplicates identical hook registrations, making this pattern safe<\/li>\n<li>Compatible with all object cache backends: Redis, Memcached, APCu, and default (no cache)<\/li>\n<\/ul>\n\n\n\n<h4>1.0.5 - 2026-01-06<\/h4>\n\n<p><strong>Trial Subscription Support &amp; REST API Fix<\/strong><\/p>\n\n<h4>NEW FEATURES<\/h4>\n\n<ul>\n<li><strong>Trial Subscription Status Support<\/strong>: Added full support for <code>trialing<\/code> subscription status from Stripe\n\n<ul>\n<li>Trial users now properly recognized as premium users with access to all features<\/li>\n<li>Premium UI components display correctly during trial period<\/li>\n<li>Event tracking enabled for trial subscriptions<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>UI ENHANCEMENTS<\/h4>\n\n<ul>\n<li><strong>Trial Status Display<\/strong>: Added \"Trial Active\" status display in subscription management\n\n<ul>\n<li>New blue badge styling for trial status (<code>.badge-trialing<\/code>)<\/li>\n<li>Status indicator shows \"Trial Active\" instead of \"Unknown\"<\/li>\n<li>Consistent visual styling across all subscription status displays<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>BUG FIXES<\/h4>\n\n<ul>\n<li><strong>Fixed REST API 404 Errors on Cached Servers<\/strong>: Removed incorrect route caching that caused 404 errors on servers with persistent object cache (Redis\/Memcached)\n\n<ul>\n<li>Routes must be registered on every <code>rest_api_init<\/code> call; caching was preventing registration<\/li>\n<li>Fixes <code>\/wp-json\/inpipe\/v1\/*<\/code> endpoints returning 404 on cached hosting environments<\/li>\n<\/ul><\/li>\n<li><strong>Fixed Premium Detection for Trials<\/strong>: Trial subscriptions now correctly detected as valid premium subscriptions\n\n<ul>\n<li>Updated <code>isValid()<\/code> method to accept <code>trialing<\/code> status<\/li>\n<li>Updated <code>inpipe_has_premium_subscription()<\/code> SQL query to include <code>trialing<\/code><\/li>\n<li>Fixed <code>is_active<\/code>  &hellip;<\/li>\n<\/ul><\/li>\n<\/ul>","raw_excerpt":"Agentic-ready UTM tracking via REST API. Mask, store, and decode UTM parameters for Google Analytics, Facebook Ads, and more.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/227396","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=227396"}],"author":[{"embeddable":true,"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/seresa8"}],"wp:attachment":[{"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=227396"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=227396"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=227396"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=227396"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=227396"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=227396"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}