=== QTech Cloudflare Turnstile Integration ===
Contributors: QTech
Tags: cloudflare, turnstile, captcha, security, spam protection, woocommerce, contact form 7
Requires at least: 5.8
Tested up to: 6.9
Requires PHP: 7.4
Stable tag: 1.2.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Add Cloudflare Turnstile protection to supported WordPress, WooCommerce and Contact Form 7 forms.

== Description ==

QTech Cloudflare Turnstile Integration helps protect WordPress forms from spam and automated submissions using Cloudflare Turnstile.

The plugin provides a central settings page where the site administrator can enter the Cloudflare Turnstile Site Key and Secret Key, choose supported forms, and configure widget appearance.

No Cloudflare credentials are hardcoded into the plugin.

= Supported Forms =

* WordPress Login
* WordPress Registration
* WordPress Lost Password
* WordPress Comments (always protected for blog-post spam prevention)
* Contact Form 7
* WooCommerce Checkout
* WooCommerce Login
* WooCommerce Registration
* WooCommerce Lost Password

= Features =

* Cloudflare Turnstile integration
* Central Site Key and Secret Key settings
* Enable or disable protection for supported forms
* WordPress form protection
* WooCommerce form protection
* Contact Form 7 integration with automatic placement and optional `[qtech_turnstile]` form tag for manual placement
* Server-side Turnstile verification
* Configurable widget theme
* Normal and compact widget sizes
* Custom security verification error message
* Frontend and admin assets
* Support for dynamically updated forms
* Lightweight and reusable QTech plugin structure

== Installation ==

1. Upload the `qtech-cloudflare-turnstile-integration` folder to the `/wp-content/plugins/` directory.
2. Activate the plugin through the WordPress Plugins screen.
3. Go to the QTech Cloudflare Turnstile settings page.
4. Enter your Cloudflare Turnstile Site Key.
5. Enter your Cloudflare Turnstile Secret Key.
6. Select the forms you want to protect.
7. Configure the widget appearance if required.
8. Save your settings.

== Cloudflare Turnstile Setup ==

Before using this plugin, create a Turnstile widget in your Cloudflare account.

You will need:

* Site Key
* Secret Key

Enter these credentials from the plugin settings page.

For more information about Cloudflare Turnstile, visit:

https://developers.cloudflare.com/turnstile/

== Frequently Asked Questions ==

= Does this plugin include a Cloudflare Turnstile Site Key? =

No. The website administrator must enter their own Site Key from the plugin settings page.

= Does this plugin include a Cloudflare Turnstile Secret Key? =

No. The Secret Key must be entered by the website administrator and is used for server-side verification.

= Can I enable Turnstile only on selected forms? =

Yes. The plugin is designed to allow supported forms to be selected individually from the settings page.

= Does this plugin work with WooCommerce? =

Yes. The plugin includes integration for WooCommerce checkout, login, registration and lost password forms.

= Does this plugin work with Contact Form 7? =

Yes. Contact Form 7 integration is included when the Contact Form 7 plugin is active.

= What happens if Turnstile verification fails? =

The form submission is blocked and the configured security verification error message is displayed.

== Changelog ==

= 1.2.1 =

* Added Contact Form 7 setup instructions directly to the plugin settings page.
* Added optional `[qtech_turnstile]` tag for precise widget placement in Contact Form 7 forms.
* Existing Contact Form 7 forms continue to receive the widget automatically when the tag is not used.
* WordPress comments are now always protected by Turnstile to help prevent blog comment spam.
* Updated the WordPress Comments label and settings UI to show that comment protection is always on.

= 1.2.0 =

* Simplified Custom Page Integrations to page selection with automatic form detection.

= 1.2.1 =

* Added always-on blog comment protection and improved Contact Form 7 setup guidance.

= 1.1.0 =

* Added Custom Page Integrations for hardcoded forms.
* Select a WordPress page from a dropdown.
* Add a CSS form selector and submission type.
* AJAX forms can be protected by entering their WordPress AJAX action.
* Multiple custom forms can be configured from plugin settings.

= 1.0.1 =

* Initial release.
* Added Cloudflare Turnstile integration.
* Added WordPress Login protection.
* Added WordPress Registration protection.
* Added WordPress Lost Password protection.
* Added WordPress Comments protection.
* Added Contact Form 7 integration.
* Added WooCommerce Checkout protection.
* Added WooCommerce Login protection.
* Added WooCommerce Registration protection.
* Added WooCommerce Lost Password protection.
* Added server-side token verification.
* Added configurable widget appearance.
* Added plugin settings and supported form controls.

== Upgrade Notice ==

= 1.2.1 =

* Added always-on blog comment protection and improved Contact Form 7 setup guidance.

= 1.1.0 =

* Added Custom Page Integrations for hardcoded forms.
* Select a WordPress page from a dropdown.
* Add a CSS form selector and submission type.
* AJAX forms can be protected by entering their WordPress AJAX action.
* Multiple custom forms can be configured from plugin settings.

= 1.0.1 =

Initial release of QTech Cloudflare Turnstile Integration.

== Credits ==

Developed by Midul Islam Shakil Q

Website: https://qtech.top/