| 开发者 |
skfreelancers
saqibabbasi |
|---|---|
| 更新时间 | 2026年9月19日 01:03 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
[evda_employee_verification] — search employees by ID, Name, or CNIC[evda_document_verification] — verify letters by ID or QR scan
Letter Customization (Settings)
[evda_employee_verification] — Public employee lookup form.
[evda_document_verification] — Public document verification form. Also works via URL: ?id=VERIFICATION_ID
Privacy
This plugin stores employee data entered by the site administrator. No data is sent to external services except for QR code generation (uses a public QR API or falls back to a local generator). No tracking or analytics are included.
employee-verification folder to /wp-content/plugins/, or install via Plugins → Add New → Upload Plugin.[evda_employee_verification][evda_document_verification]No. The plugin works out of the box with no dependencies. Letters are rendered as printer-friendly HTML pages which users can save as PDF using Ctrl+P → Save as PDF.
Yes. Letters are rendered live on every view, so any change to typography, colors, signature, footer message, or other settings is immediately reflected on all existing letters without needing to regenerate them.
Verification IDs are 16-character uppercase hex strings generated using PHP's random_bytes() (cryptographically secure). All inputs are sanitized and validated. All admin actions are protected by WordPress nonces. Database queries use $wpdb->prepare().
Yes. Go to Settings → General → Employee Search Fields and enable the CNIC option (along with Employee ID and/or Full Name).
Deactivating the plugin removes the plugin's database version marker but leaves all employee and document data intact. Data is only removed if you uninstall the plugin.
Yes. Go to Employee Verify → Employees and use the CSV Import section. A downloadable template is provided.
<script> and <style> tags. CSS served via evda_letter_css AJAX endpoint (Content-Type: text/css). JS served via evda_letter_js AJAX endpoint. Print button onclick moved to enqueued JS. All color picker oninput/onchange handlers moved to admin.js using data attributes.current_user_can() + wp_verify_nonce() to page_employees(). Public endpoints (QR image, letter CSS/JS) use HMAC token (wp_hash) with detailed code comments explaining why session nonces cannot be used for public/nopriv endpoints.echo build_letter() with dedicated EVDA_PDF::output_letter() method that sets Content-Type headers and outputs pre-escaped HTML. All dynamic values inside build_letter() are escaped via esc_html(), esc_attr(), esc_url() at point of construction.$wpdb->query("CREATE TABLE...") and ALTER TABLE loops with dbDelta() — the WordPress-standard method for schema management. Added EVDA_Database::validate_table() whitelist validator applied to all table name variables before SQL interpolation across all query files.ev_/EV_ identifiers renamed to evda_/EVDA_ (classes, functions, defines, AJAX actions, options, nonces, shortcodes, form fields).style="" attributes moved to CSS classes in admin.css and public.css. Added evda- prefixed utility classes throughout.saqibabbasi to Contributors in readme.txt.saqibabbasi to Contributors list in readme.txt.<style> block in letter renderer with a PHP variable to satisfy wp_enqueue requirements.paginate_links() output with wp_kses_post() for proper escaping.build_letter() echo explaining why wp_kses_post() cannot be used.ev_/EV_ to evda_/EVDA_ prefix (4+ character unique prefix as required by WordPress.org).esc_sql() to table names, sanitize_key() + esc_sql() to column names, and $wpdb->prepare() to SHOW COLUMNS queries.ev_ prefix to shortcodes ([evda_employee_verification], [evda_document_verification]).<script> and <style> blocks to enqueued admin.js and admin.css files.