Linux 软件免费装
Banner图

Wynko for Laposta

开发者 roydg
flexbordercoltd
更新时间 2026年9月18日 17:45
PHP版本: 8.0 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

newsletter email marketing signup form campaigns laposta

下载

1.2.2 1.3.0

详情介绍:

Wynko connects your WordPress site to your Laposta account, then gets out of the way. Once you've entered your API key, you get two things you can drop anywhere on your site: a signup form that adds people straight to one of your Laposta lists, and a campaigns list that shows the newsletters you've most recently sent. No embed codes. No iframes. Just your own site, with your own styling. Full documentation for every screen, plus the hooks and filters for developers, lives at https://getwynko.com/docs/. Signup forms that can't get out of sync Pick a Laposta list, and Wynko builds the form from that list's own fields. If Laposta says a field is required, it's required here too. If a dropdown has five options in Laposta, it has those same five options on your site. You can't accidentally build a form that Laposta will reject, because the form is always built from what Laposta actually accepts. Wynko ships only the bare structural CSS. Colours, fonts and spacing come from your theme, and you can adjust them with CSS custom properties if you want to fine-tune. Subscribe from forms you already have Wynko also bridges other form plugins to Laposta. Bundled integrations for Contact Form 7 and HTML Forms — off until you switch one on under Wynko → Integrations — let an existing form subscribe people to a list by adding a single checkbox. Any plugin or theme can register its own integration the same way, so the list isn't limited to those two. Campaigns block Add the Wynko: Campaigns block to any post or page and it shows a simple list of links to your most recently sent campaigns. Choose how many to show, which list they come from, the order, and what each line says. There's no front-end CSS at all here — your theme styles it completely. Your API key, handled carefully Your Laposta API key is the key to your whole mailing list, so Wynko treats it carefully. Prefer environment variables? Every Wynko setting, not just the key, can come from an environment variable or a wp-config.php constant — see the FAQ for the full list. That means staging and production can each have their own configuration, deployed with your code, instead of someone remembering to click through the settings screen on every site. Built-in spam and abuse protection Signup forms are public by nature, so every submission is checked and metered before anything reaches Laposta: Keeping an eye on things Source code and contributing Full documentation is at https://getwynko.com/docs/. Development happens at https://github.com/FlexBorder/wynko — issues and pull requests are welcome. Laposta is a trademark of its respective owner. This plugin is developed independently by FlexBorder Co., Ltd with Laposta's permission and is not an official Laposta product.

安装:

  1. Install Wynko from Plugins → Add New, or upload the ZIP under Plugins → Add New → Upload Plugin.
  2. Activate the plugin.
  3. Go to Wynko → Settings and paste in your Laposta API key. Wynko checks it with Laposta before saving anything, so you'll know immediately if it's wrong.
  4. Add the Wynko: Campaigns block to a post or page, or build a form under Wynko → Signup forms and place it with the form block or the [wynko_form id="N"] shortcode.
Extra credit: instead of pasting your key into the settings screen, put it in wp-config.php (see the FAQ below). It's a little more effort once, and your key stays out of your database for good.

屏幕截图:

  • Adding the Wynko: Campaigns block to a post or page from the block editor.
  • The Campaigns block on the front end, listing the site's most recently sent newsletters.
  • Building a signup form under Wynko → Signup forms — fields come straight from the chosen Laposta list.
  • A signup form rendered on the Astra theme, styled entirely by the theme.
  • The same signup form rendered on the Kadence theme.

升级注意事项:

1.0.0 First public release.

常见问题:

Where do I find my Laposta API key?

Laposta explains it here: https://docs.laposta.org/article/947-how-do-i-get-an-api-key Paste the key into Wynko → Settings. Wynko makes a live check with Laposta before saving, so an invalid key is caught straight away.

What's the safest way to store my API key?

Put it in your wp-config.php file rather than in the settings screen: define( 'WYNKO_API_KEY', 'your-laposta-api-key' ); Why this is better: your database gets backed up, exported, copied to staging sites, and is the first thing an attacker goes looking for. A key in wp-config.php isn't in any of that. It also means the key travels with your deployment rather than being re-entered by hand on every environment. Two things to know:

  • A key defined this way always takes priority, and Wynko won't save a database value that would shadow it.
  • Because it isn't in the database, uninstalling Wynko won't remove it. Delete the line from wp-config.php yourself when you're done.
On multisite, add the blog ID to give one site its own key — for example WYNKO_API_KEY_3.

How is my API key encrypted when it's stored in the database?

When your server allows it: if the sodium PHP extension is available (bundled with PHP since 7.2, so almost every host has it) and your site has real SECURE_AUTH_KEY/SECURE_AUTH_SALT values in wp-config.php — the ones WordPress itself generates, and the same ones you'd rotate as part of an incident response — Wynko seals the key with authenticated encryption (libsodium's secretbox) before writing it to the database. A raw database export, a SQL-injection leak, or an administrator browsing the options table doesn't hand over a usable key. What this protects against: exposure of the database on its own — a leaked backup, a stray export, a SQL-injection read. What it doesn't protect against: anyone who can also read wp-config.php. Your security salts live there, right alongside your database credentials, so someone with filesystem access already has everything needed to open the key. For that level of protection, keep the key out of the database entirely with the WYNKO_API_KEY constant or environment variable described above. If you rotate SECURE_AUTH_KEY — standard practice after a suspected leak — every previously sealed key becomes unreadable on purpose. Wynko treats that exactly like no key being configured (it will never send garbage to Laposta), and the settings screen tells you plainly what happened so you can re-enter it. If your server has no sodium extension, or your site is still running WordPress's placeholder salts, the key is stored as plain text and the settings screen says so.

Can I use environment variables instead?

Yes. Every setting below can come from an environment variable (your .env file, web server config, or container definition) or a wp-config.php constant. An environment variable always outranks a constant, and a constant always outranks whatever is saved on the settings screen. On multisite, suffix the blog ID to override one site only — for example WYNKO_API_KEY_3 or WYNKO_THROTTLE_WINDOW_3 — otherwise the value applies network-wide.

  • WYNKO_API_KEY — the Laposta API key (see above).
  • WYNKO_CACHE_MINUTES — how long campaign data is cached before Laposta is asked again. Default: 60.
  • WYNKO_LOG_LEVEL — the lowest severity recorded in the activity log: error, warning, or info. Default: info.
  • WYNKO_THROTTLE_WINDOW — the signup rate-limit window, in minutes. Default: 10.
  • WYNKO_THROTTLE_IP_MAX — signups one visitor may submit per window, across all your forms. Default: 15.
  • WYNKO_THROTTLE_FORM_MAX — signups one form may take per window, from every visitor combined. Default: 400.
  • WYNKO_NOTIFY_ENABLED — whether critical-error email alerts are on. Default: off.
  • WYNKO_NOTIFY_EMAILS — comma-separated addresses that receive those alerts.
Wherever a setting is supplied this way, its tab on the settings screen shows it as read-only and names the variable or constant in charge, so it's never ambiguous where a value came from.

How does Wynko stop spam and abuse on signup forms?

A few layers, all before anything reaches Laposta:

  • A hidden honeypot field — a bot that fills it in is shown the normal success message, but nothing is actually sent to Laposta.
  • Rate limiting per visitor and per form, over a rolling window (see the next question for the defaults and how to tune them).
  • Full server-side validation against the list's real fields in Laposta, regardless of what a script sends — required fields, allowed choices, value ranges, text length and patterns.
  • A security token scoped to each individual form, checked before anything else in the submission is read.
  • Identical responses to a forged token, an unknown form, and a rate-limited request, so a script probing the endpoint can't learn which check it failed.
  • "Already subscribed" answered the same as a new signup by default, so the form can't be used to check whether a given address is on your list.

What are the default signup rate limits, and should I change them?

By default, one visitor can submit up to 15 signups, and one form can accept up to 400 signups in total, within any rolling 10-minute window. All three numbers live on the Security tab and can be changed — the per-visitor and per-form caps go up to 1000 and 100,000 respectively, and the window up to 24 hours. Raise the per-visitor cap if a shared office, school, or NAT gateway sends real visitors from a single address — that's the most common reason a legitimate visitor gets turned away. Treat the per-form cap as a backstop rather than a first line of defense: keep it well above your form's real traffic, because a form that reaches it turns away every visitor, real or not, until the window passes. If a limit ever locks out real visitors before you've had a chance to raise it, use "Reset signup limits" on the same tab to clear the counters immediately.

Does it work on multisite?

Yes. Every site keeps its own settings, connects to its own Laposta account, keeps its own log, and sends its own alerts on its own hourly limit.

What does Wynko store about my visitors?

Nothing beyond what it passes to Laposta. Signups aren't saved on your site. The activity log notes that a form was submitted and whether it worked, and names the form — but never the email address or anything else the visitor typed.

How many signup forms can I have?

As many as you need. Each is bound to its own Laposta list and has its own fields, messages and settings.

Can I subscribe people from a form built in another plugin?

Yes. Wynko bundles integrations for Contact Form 7 and HTML Forms, switched off until you enable one under Wynko → Integrations. Add a checkbox to your existing form and accepted submissions are subscribed to the Laposta list you choose. The system is open, so any plugin or theme can add support for another form plugin. Integrations you didn't get from Wynko are supported by whoever wrote them.

Will it slow my site down?

No. Campaign data is cached for 60 minutes by default (you can change this), so a page with the campaigns block on it isn't calling Laposta every time someone visits.

Can I style the forms to match my theme?

Yes. Wynko only ships the minimum layout CSS and leaves colours, fonts and spacing to your theme. CSS custom properties are there if you want more control. The campaigns block ships no front-end CSS at all.

Can I show recent campaigns with a shortcode?

Yes. [wynko_campaigns] renders the same list as the Wynko: Campaigns block, for places a block won't reach — a classic-editor post, a widget, a template. Every block setting has a matching attribute: count, list, order_by, order, and label, all optional. For example [wynko_campaigns count="5" list="abc123" order="asc" label="name_date"].

I can't find the answer to my question here — where else can I look?

The full documentation, covering every screen plus hooks and filters for developers, is at https://getwynko.com/docs/.

更新日志:

1.3.0 1.2.2 1.2.1 1.2.0 1.1.0 1.0.0