=== Forma Core ===
Contributors: formastudio
Tags: portfolio, projects, contact form, enquiries, architecture
Requires at least: 6.6
Tested up to: 7.1
Requires PHP: 8.0
Stable tag: 1.2.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

An independent portfolio workspace with unlimited projects, private enquiries and safe draft starter content.

== Description ==

Forma Core gives a creative studio a focused WordPress workspace. Publish an unlimited portfolio, tell each project's story with native blocks and manage private project enquiries without changing how you own your content.

* Unlimited projects with categories, featured images, excerpts and project facts.
* Native block editing, revision history and WordPress export support.
* A native Forma Projects block with live content, columns, categories, sorting and curated project IDs; the [forma_projects] shortcode remains available.
* A basic, accessible contact form with the [forma_enquiry] shortcode.
* Private enquiries searchable by name, email and message, with sortable columns and New, Reviewed and Replied statuses.
* Configurable form labels, confirmation, message length, honeypot and connection rate limits.
* A dedicated Enquiry Manager role without general settings access.
* Email diagnostics and explicit notification resend, with truthful transport status.
* Reviewed settings JSON export/import with a previous-settings restore action.
* Optional local draft starters that preserve your homepage, menus, branding and existing content.
* WordPress personal data export and erasure support, plus scheduled enquiry retention.
* Optional search and social metadata, switched off by default.

The plugin works independently of Forma Studio and does not require a paid extension, account, license key or external service. Projects remain stored in WordPress if you change themes. Deactivating the plugin hides its content types until it is reactivated; it does not delete content.

= Enquiry privacy =

The form stores the visitor's name, email address, message and consent time in a private WordPress record. Notification email is sent to the recipient chosen by the administrator using WordPress's configured email transport. The site owner is responsible for that provider, a suitable privacy policy and delivery testing.

Failed form values are available for correction for 10 minutes, including compatible extension fields. A random retry token in the return URL is bound to a separate essential, HttpOnly, SameSite browser cookie lasting 30 minutes. Reloading preserves the corrections; the URL alone cannot retrieve them from another browser. Personal form values are not placed in the URL. WordPress scheduled cleanup removes expired records; physical deletion depends on cron execution. Successful submission removes the associated retry record. An hourly anti-spam counter uses a keyed hash of the connection address, not a stored raw IP address. Hosting or email providers may keep separate logs.

By default, completed communication (Replied) becomes eligible for Trash after 90 days without recorded activity. New, Reviewed and held records remain protected. Compatible workflow extensions can protect active work; shared protection markers continue to work when an extension is inactive. Legacy extension stage records without a shared protection marker are retained conservatively. Each daily WordPress cron run scans up to 100 records with a rotating cursor, so protected older records do not block later eligible enquiries. WordPress then applies its configured Trash deletion schedule. Change the period in Forma Studio; 0 disables automatic retention. Cron depends on the site's scheduling setup. Email copies and backups have their own retention. WordPress privacy export and erasure include enquiries in Trash.

Optional extensions may add fields; review their own privacy information. Forma Core itself does not send telemetry or contact a private update service.

= Safe starter content =

Create starter drafts only when you choose to. The importer adds nine clearly labelled local drafts: a homepage, contact page, four projects and three journal entries. It does not download images, publish content or modify the active homepage, menus, theme settings or branding. Running it again skips records already created, including drafts you have edited. Existing Trash records are not silently recreated. Replace the sample text and facts with your own work before publishing.

= Complete guided demo =

With Forma Studio installed, Forma Studio > Guided setup creates six pages, three projects, three journal posts and six locally bundled concept images as drafts. The home page includes a live portfolio block. This English-language demonstration uses fictional studio/project copy and original AI-generated images; review and replace it before launch.

The setup resumes safely after interruption and skips completed demo records. Review the drafts, then explicitly choose publishing, homepage assignment and/or a new navigation menu. Edited drafts are skipped by bulk publishing. Your branding, privacy-policy selection and search visibility are preserved. Undo moves only unchanged demo posts to Trash and restores matching homepage/menu assignments; edited posts, media and the created menu remain available. Missing theme assets produce a recoverable error, not a remote download.

= Optional metadata =

Basic metadata is off by default. Enable it only if another tool does not manage your search metadata. Forma checks for common SEO plugins, including Yoast SEO, Rank Math, All in One SEO, SEOPress and The SEO Framework. Other tools may require you to leave Forma metadata disabled manually. A local Media Library image can provide a social fallback when a page has no featured image. This site-specific attachment ID is deliberately excluded from settings transfer.

== Installation ==

1. Upload the forma-core folder to wp-content/plugins, or upload the installable forma-core ZIP through Plugins > Add New.
2. Activate Forma Core and open Forma Studio in the WordPress administration menu.
3. Add a project, use basic starter drafts, or open Guided setup for the complete optional demo.
4. Add the Forma Projects block, or use [forma_projects] and [forma_enquiry] Shortcode blocks.
5. Choose your notification recipient, publish a privacy policy and submit a real test enquiry before launch.

To update, back up your files and database and test the replacement ZIP on staging first. Install the matching Forma Core, Forma Studio and optional Forma Studio Pro releases when updating the coordinated 1.2.1 set. Your existing content and settings are retained.

== Frequently Asked Questions ==

= Is there a project limit? =

No. Forma Core includes unlimited projects and the full basic enquiry form.

= Do I need the Forma Studio theme? =

No. The content types and shortcodes can be used with other compatible WordPress themes. Appearance depends on your theme and styles.

= Does starter setup overwrite my website? =

No. It only adds local drafts when you request it. Review them before choosing a homepage or publishing.

= Does a successful enquiry mean email arrived? =

No. The enquiry is stored privately first. The record shows whether WordPress's email transport accepted the notification; that is not proof of inbox delivery.

= Can I use another SEO plugin? =

Yes. Leave Forma's optional metadata disabled. Common SEO plugins are also detected automatically.

= Where is my data? =

In your WordPress database and your configured email system. No Forma account or hosted service is required. Export projects with WordPress Tools > Export and handle enquiry privacy requests using WordPress privacy tools.

== Changelog ==

= 1.2.1 =
* Coordinated release with reliable administrator access to Guided setup and Studio controls, and a linked project hero for complete gallery navigation.


= 1.2.0 =
* Complete native-block demo setup with local images, explicit publication and recoverable undo.
* Live project block, curated listings and additional public project facts.
* Site-owned form settings, protected correction sessions and cleanup.
* Enquiry Manager role, notification diagnostics/resend and settings transfer.
* Active-work protection and a rotating retention scan; repeated extension metadata survives inactive privacy export.

= 1.1.0 =
* A focused studio dashboard, unlimited project editing and a private enquiry inbox.
* Accessible form validation and short-lived retries without personal data in URLs.
* Bounded, idempotent local draft imports with missing-file recovery.
* Privacy export, erasure and configurable retention.
* Metadata defaults to off; private updater removed.

= 1.0.0 =
* Initial development version.

== Upgrade Notice ==

= 1.2.1 =
Install the matching theme, Core and optional Pro packages. This release corrects setup-page access and improves project gallery navigation. Existing content and settings remain.


= 1.2.0 =
Back up and test on staging. Update the coordinated theme, Core and optional Pro set together. Existing administrators receive the dedicated enquiry capability. Review retention and form settings; guided demo setup remains optional and never runs on activation.
