Version 3.26.0
Added
- WordPress.org distribution:
build.shnow produces two packages from one tree../build.shbuilds the GitHub release exactly as before;./build.sh --wporgbuilds the directory package, which omits the self-update subsystem because directory guideline 8 forbids a hosted plugin from serving its own updates. The extra exclusions live in.wporgignore. Choice_Universal_Form_Tracker::has_updater()reports whether the update subsystem is bundled. Loading, the Force Update tab, its assets, and the custom update notice all check it, so the directory build degrades to core-managed updates instead of failing.build.shfails the build on a version mismatch across the three version sources, on hidden files, on em-dashes in shipped files, and (for--wporg) on any self-update file or third-party CDN reference reaching the package.readme.txtgained an== External services ==section itemising every third-party endpoint the plugin can contact, what is transmitted, when, and under which terms and privacy policy.
Changed
- SHA-256 now ships with the plugin. CryptoJS was loaded from
cdnjs.cloudflare.com, which guideline 8 prohibits and which introduced a race: a slow CDN response leftlead_idoff the event entirely. The bundled implementation is synchronous, solead_idis always available when the payload is built. Digests are unchanged and still match PHPhash('sha256'). - Declared PHP 7.4 consistently. The plugin header had no
Requires PHPat all,readme.txtclaimed 7.4, and the runtime notice named 7.0. - Added
Plugin URI,Requires at least,Requires PHP, andLicense URIto the plugin header. - Text domain corrected to
choice-universal-form-trackerin 275 places that usedchoice-uft, which did not match the declaredText Domainheader and left those strings untranslatable. readme.txttags reduced from 12 to the 5 WordPress.org permits, and the six that were other companies' trademarks removed. Framework compatibility is described in the Description body instead.
Fixed
- GitHub updates were silently switched off on every settings save. The checkbox that
save_settings()read was removed in Feature 008, so the value was always false and got written back over the stored option. save_settings()now verifies the settings nonce itself rather than relying on its caller, and unslashes$_POSTvalues before sanitising them.- Escaped previously unescaped output across the admin screens, the GTM injector, and the testing dashboard.
- Replaced
date()withgmdate(),rand()withwp_rand(), andparse_url()withwp_parse_url(). /llms.txt,/ai.txt, and/llms-full.txtnow sendX-Content-Type-Options: nosniff.
Installation
Automatic Update
If you already have the plugin installed, it should automatically detect this update. Go to Plugins in your WordPress admin and click Update Now.
Manual Installation
- Download the
choice-uft-v3.26.0.zipfile from the assets below - In WordPress admin, go to Plugins → Add New → Upload Plugin
- Choose the downloaded zip file and click Install Now
- Activate the plugin after installation
Requirements
- WordPress 5.0 or higher
- PHP 7.4 or higher
Support
For issues or questions, please visit: https://github.com/ChoiceOMG/choice-uft/issues