Description
Kitsuly Commerce is a commerce-native WordPress ecommerce platform with native store building, catalogue, checkout, shipping, tax, accounting, fulfilment and Stripe Connect payments.
Kitsuly platform fees are controlled by the private T1K1 controller. Merchant plugin code never receives T1K1 Stripe secret keys.
Privacy and local analytics
Kitsuly’s built-in Site SEO analytics is disabled by default. It begins collecting local visit/engagement statistics only after a site administrator deliberately enables that feature in Kitsuly settings. The built-in analytics records are stored in the site’s own WordPress database and are not sent to Kitsuly, T1K1 or another analytics provider by that feature. Administrators can configure retention and exclude administrators.
Features that contact external providers are separately disclosed below and are used only when the merchant connects, enables or invokes the relevant integration.
External Services
Kitsuly Commerce connects to external services only when the merchant enables or uses the relevant feature. Credentials are stored in WordPress and sensitive integration values are encrypted where supported. External setup/help links opened from Kitsuly launch in a new browser tab.
Kitsuly Support requests
If a site administrator deliberately submits the Kitsuly Support form, WordPress sends the administrator-provided name, email address, support area, subject, message and any optional screenshot to support@kitsuly.com using the site’s configured WordPress mail transport. The message also includes the site’s URL plus the installed Kitsuly Commerce, WordPress and PHP versions so the reported installation can be identified and diagnosed. This data is sent only when the administrator presses the support-form submit button.
Kitsuly terms: https://kitsuly.com/terms/
Kitsuly privacy: https://kitsuly.com/privacy/
Kitsuly Platform Controller and Stripe
Kitsuly uses the private Kitsuly Platform Controller hosted at https://t1k1.com for controller-backed payment and merchant social-integration features. When a controller-backed feature first needs registration, the plugin sends a generated installation identifier, site URL, Kitsuly admin return URL, signed-callback URL, Kitsuly edition and plugin version so that installation can be registered and authenticated.
For payments and invoice payments, the controller receives the authenticated installation context plus the amount, currency, checkout/order/invoice reference, requested payment methods and Stripe payment identifiers required to connect the merchant account, create or retrieve payment intents, reconcile payments, process refunds and record transaction costs. Stripe.js is loaded from https://js.stripe.com/v3/. Card and wallet credentials are entered into Stripe-hosted Elements and are not stored by Kitsuly Commerce. Stripe webhook handling is controller-managed: individual merchant WordPress installations do not require or store a Stripe webhook signing secret (whsec_...), and the controller sends signed Kitsuly callbacks to the registered store for payment/refund reconciliation.
For supported brokered social connections (Facebook, Instagram, Pinterest, X, LinkedIn and TikTok), the controller can receive the selected provider, return URL, site URL, store name and administrator email when the merchant deliberately starts a connection. When the merchant deliberately publishes through a brokered provider, it can also receive the selected provider plus the post title/text, public link, public media URL and provider-specific publishing choices required for that post. Provider app secrets and controller-held social refresh tokens are not stored in the merchant WordPress installation.
Kitsuly Platform Controller: https://t1k1.com/
Kitsuly terms: https://kitsuly.com/terms/
Kitsuly privacy: https://kitsuly.com/privacy/
Stripe terms: https://stripe.com/legal
Stripe privacy: https://stripe.com/privacy
Kitsuly Licensing API
When a merchant activates, validates or requests a domain change for an official Kitsuly Pro or Business licence, the plugin communicates with the Kitsuly Licensing API hosted at https://api.kitsuly.com. The service receives the licence key, normalised production domain, installation identifier and site URL required to verify the entitlement and enforce the approved one-domain licence. On the private Kitsuly owner store, authorised licence-management requests may also include customer email, company, plan and expiry details. Payment card credentials are not sent to the licensing API.
Kitsuly Licensing API: https://api.kitsuly.com/
Kitsuly terms: https://kitsuly.com/terms/
Kitsuly privacy: https://kitsuly.com/privacy/
Kitsuly Signature Theme Catalogue
When the merchant opens the Signature Edition theme catalogue, Kitsuly may request up to four promoted theme-pack records from Kitsuly/T1K1 endpoints. The catalogue request sends normal HTTP request metadata plus the Kitsuly plugin version in the User-Agent so compatible theme metadata can be returned. If the merchant deliberately chooses Install, Kitsuly downloads only that selected Kitsuly-native theme pack from the same validated HTTPS host and imports its layout/JSON/media assets into the local store. These are Kitsuly theme packs, not WordPress themes, and the plugin does not activate a WordPress theme.
Kitsuly: https://kitsuly.com/
T1K1: https://t1k1.com/
Kitsuly terms: https://kitsuly.com/terms/
Kitsuly privacy: https://kitsuly.com/privacy/
Google services
If Google Analytics or Google Search Console integrations are configured, Kitsuly sends the merchant-configured credentials, property/site identifiers and report/query parameters to the applicable Google APIs so aggregate analytics or search-performance information can be retrieved. Google OAuth endpoints are contacted only when the merchant explicitly connects or refreshes a Google integration.
When a merchant explicitly runs the Site SEO performance analyser, Kitsuly sends the tested public page URL and selected mobile/desktop strategy to Google’s PageSpeed Insights API so Google can return performance diagnostics.
Google privacy: https://policies.google.com/privacy
Google API terms: https://developers.google.com/terms
Google PageSpeed Insights documentation: https://developers.google.com/speed/docs/insights/v5/get-started
AI providers
Kitsuly can optionally connect to OpenAI, Google Gemini and Anthropic Claude for merchant-invoked content generation, marketing automation and the Kit dashboard assistant. For ordinary content/marketing actions, the selected provider receives the merchant’s API credential plus the prompt and relevant source copy or product/content context required for that request. When Kit AI is connected, Kit sends only the merchant’s question, the current Kitsuly screen, the installed Kitsuly version and the most relevant built-in Kitsuly help snippets needed to answer the question. Kit’s local navigation/component help works without sending a request to an external AI provider.
OpenAI privacy: https://openai.com/policies/privacy-policy/
OpenAI terms: https://openai.com/policies/terms-of-use/
Google privacy: https://policies.google.com/privacy
Gemini API terms: https://ai.google.dev/gemini-api/terms
Anthropic privacy: https://www.anthropic.com/legal/privacy
Anthropic commercial terms: https://www.anthropic.com/legal/commercial-terms
Shopify
When Shopify transfer tools are enabled, Kitsuly sends the configured Shopify store domain and Admin API token together with catalogue/import query data to Shopify’s Admin API so merchant-authorised store content can be read for transfer.
Shopify privacy: https://www.shopify.com/legal/privacy
Shopify API terms: https://www.shopify.com/legal/api-terms
Australia Post
When Australia Post live shipping is enabled, Kitsuly sends the configured API/account credentials and the origin/destination and parcel data required for the selected quote request, such as postcode, weight and dimensions, to Australia Post.
Australia Post developer information: https://auspost.com.au/developers/
Australia Post terms: https://auspost.com.au/terms-conditions
Australia Post privacy: https://auspost.com.au/privacy
DHL Express
When DHL Express live shipping is enabled, Kitsuly sends the merchant’s DHL API credentials plus the origin, destination and parcel details needed to request shipping rates from the DHL MyDHL API. This occurs only when a customer or merchant requests a live shipping quote.
DHL developer information: https://developer.dhl.com/
DHL terms: https://www.dhl.com/global-en/home/footer/terms-of-use.html
DHL privacy: https://www.dhl.com/global-en/home/footer/privacy-notice.html
Sendle
When Sendle live shipping is enabled, Kitsuly sends the merchant’s Sendle credentials and the origin, destination and parcel details required for a shipping quote to the Sendle API. This occurs only when a live Sendle quote is requested.
Sendle developer information: https://developers.sendle.com/
Sendle terms: https://support.sendle.com/hc/en-au/articles/205800148-Terms-and-Conditions
Sendle privacy: https://support.sendle.com/hc/en-au/articles/206525557-Privacy-Policy
FedEx
When FedEx live shipping is enabled, Kitsuly sends the merchant’s FedEx OAuth credentials/account number and the origin, destination and parcel details required to authenticate and request shipping rates from FedEx. This occurs only when a live FedEx quote is requested.
FedEx developer information: https://developer.fedex.com/
FedEx terms: https://www.fedex.com/en-us/terms-of-use.html
FedEx privacy: https://www.fedex.com/en-us/trust-center/privacy.html
UPS
When UPS live shipping is enabled, Kitsuly sends the merchant’s UPS OAuth credentials and the origin, destination and parcel details required to authenticate and request shipping rates from UPS. This occurs only when a live UPS quote is requested.
UPS developer information: https://developer.ups.com/
UPS terms: https://www.ups.com/us/en/support/shipping-support/legal-terms-conditions.page
UPS privacy: https://www.ups.com/us/en/support/shipping-support/legal-terms-conditions/privacy-notice.page
BigCommerce
When the optional BigCommerce transfer connection is configured, Kitsuly stores the merchant-provided store hash, client ID and access token so the merchant can stage a migration of catalogue, customer and order information. When transfer requests are performed, the credential and the requested resource/query information are sent to the merchant’s BigCommerce store API. The connection is not used unless the merchant configures and starts the transfer feature.
BigCommerce developer information: https://developer.bigcommerce.com/docs/start/authentication/api-accounts
BigCommerce terms: https://www.bigcommerce.com/terms/
BigCommerce privacy: https://www.bigcommerce.com/privacy/
Social publishing services
When a merchant connects a supported social account and deliberately publishes from Kitsuly Marketing, the applicable provider receives the account identifiers/authorisation held for that connection plus the post content required by the selected network, such as title or message text, public destination link, public media URL and network-specific publishing choices. Facebook, Instagram, Pinterest, X, LinkedIn and TikTok can use the Kitsuly Platform Controller broker described above where the connected merchant account and provider permissions allow it. GitHub publishing uses the merchant-provided GitHub access token and repository directly from the WordPress installation. Dribbble and DeviantArt currently use connection/setup or manual-handoff states when their required publishing/upload flow is unavailable rather than reporting an external post as successful.
Meta privacy: https://www.facebook.com/privacy/policy/
Meta Platform terms: https://developers.facebook.com/terms/
Pinterest privacy: https://policy.pinterest.com/privacy-policy
Pinterest developer terms: https://developers.pinterest.com/terms/
X privacy: https://x.com/en/privacy
X developer agreement: https://developer.x.com/en/developer-terms/agreement-and-policy
LinkedIn privacy: https://www.linkedin.com/legal/privacy-policy
LinkedIn API terms: https://www.linkedin.com/legal/l/api-terms-of-use
TikTok privacy: https://www.tiktok.com/legal/page/row/privacy-policy/en
TikTok developer terms: https://www.tiktok.com/legal/page/global/tik-tok-developer-terms-of-service/en
GitHub privacy: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
GitHub terms for developer features: https://docs.github.com/en/site-policy/github-terms/github-terms-for-additional-products-and-features
Merchant-configured remote digital files
For a digital product, a merchant can optionally configure a remote source URL instead of storing the downloadable file in the local WordPress uploads directory. When an authorised customer uses a valid Kitsuly download token, the WordPress server requests that merchant-configured URL, temporarily streams the returned file through the store and then removes the temporary copy. Kitsuly does not choose or operate that remote host; the merchant is responsible for the terms, privacy policy and permission to use whichever remote storage/provider URL they configure.
Optional media, map and font resources
Kitsuly Builder can render merchant-selected YouTube or Vimeo video embeds and Google Maps embeds. When a merchant places one of these elements on a public page, the visitor’s browser connects to the selected provider to load that media or map; the provider may receive normal web-request information such as the visitor’s IP address, browser headers and the requested embed URL. Kitsuly uses YouTube’s privacy-enhanced youtube-nocookie.com embed domain where supported. Kitsuly can also load Google Fonts selected by the merchant, which causes the visitor’s browser to request the chosen font resources from Google.
YouTube terms: https://www.youtube.com/static?template=terms
Google privacy: https://policies.google.com/privacy
Google Maps terms: https://maps.google.com/help/terms_maps/
Vimeo terms: https://vimeo.com/terms
Vimeo privacy: https://vimeo.com/privacy
Google Fonts information: https://developers.google.com/fonts/faq/privacy
QR discount tickets
The merchant-only QR discount ticket maker requests a QR-code PNG from QRServer (api.qrserver.com) when a store administrator opens or generates a coupon ticket. The request contains the public store promotion URL and selected coupon code so the QR image can be created. No customer, order, payment or account data is sent by this feature. If the QR service is unavailable, the ticket image cannot be generated until it becomes available again.
QRServer / goQR.me API information: https://goqr.me/api/
QRServer API privacy statement: https://goqr.me/de/rechtliches/datenschutz-api.html
QRServer API terms of service: https://goqr.me/legal/tos-api.html
Kitsuly.com owner-site documentation compatibility
When the plugin is running on kitsuly.com itself, it can render Kitsuly’s own documentation library from cover images and PDF files already stored in that site’s local WordPress uploads folders. This compatibility component is disabled on third-party/customer sites and does not contact kitsuly.com from those installations.
Source Code
This plugin ZIP is the source distribution. The PHP under src/ and includes/, the JavaScript under assets/js/ and assets/seo/, and the CSS under assets/css/ and assets/seo/ are the human-readable maintained source files loaded by WordPress.
Kitsuly Commerce does not use npm, webpack, Rollup, Vite, Babel, Sass or another compilation/minification pipeline for the distributed first-party assets. There is no separate unpublished source tree or build command needed to recreate the JavaScript/CSS included in this ZIP. The distributed files are intentionally readable and are edited directly.
A concise source-layout note is also included as SOURCE-CODE.txt. Third-party components and their licences are documented in THIRD-PARTY-LICENSES.txt.
Screenshots















Reviews
There are no reviews for this plugin.
Contributors & Developers
“Kitsuly Commerce” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Kitsuly Commerce” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.44.11
- Fixed account/checkout/page live-content ordering by replacing the responsive template carrier with a single hidden payload that is moved into the active Builder slot before footer layout.
- Explicitly preserved Kitsuly semantic document wrappers through the final wp_kses boundary.
- Restored the Kitsuly.com owner-site document library as a four-column responsive cover grid with modal iframe PDF viewing and open-in-new-tab controls.
- The owner-site document library uses same-origin WordPress uploads and remains disabled on third-party/customer installations.
1.44.10
- Restored normal WordPress page and post content in Kitsuly Native mode after the WordPress.org output-escaping hardening.
- Added the inert HTML template element to Kitsuly’s tightly scoped wp_kses allow-list so responsive live content is no longer stripped.
- Added a hydration state marker to responsive live slots for safer diagnostics without duplicating live forms, IDs or scripts across device trees.
1.44.9
- Restored Visual Builder/storefront text-colour fidelity after the WordPress.org KSES escaping hardening.
- Added a prefixed safe-CSS compatibility layer for Kitsuly-generated visual properties that WordPress 6.6 strips from inline style attributes.
- Added a storefront inheritance guard so nested rich text keeps the Builder-selected colour without overriding deliberately styled child spans.
1.44.8
- Final manual-review sweep against the WordPress Plugins Team email after a clean Plugin Check result.
- Removed the remaining FILTER_CALLBACK request filters and replaced them with explicit sanitising filters while preserving validated JSON/secret semantics.
- Preserved multiline and rich-text behaviour for order notes, coupon descriptions, booking descriptions and social campaign/instruction fields.
- Escaped returned nonce markup used inside generated contact-form and verification HTML.
1.44.7
- Plugin Check cleanup: native WordPress output escaping at generated HTML boundaries, response-stream cleanup, intentional database-query annotations and readme short-description correction.
- Replaced direct temporary-file unlink with wp_delete_file().
- Removed php://output fwrite/fclose usage for generated PNG, XML and PDF responses.
- Added targeted PHPCS rationale for intentional uncached queries against Kitsuly-owned transactional tables and admin-only membership meta lookups.
1.44.6
- Final WordPress.org reviewer-email sweep.
- Removed remaining direct POST and COOKIE superglobal reads from feature code in favour of central sanitising request helpers.
- Added request-local cart/recently-viewed caches so cookie writes no longer mutate the PHP COOKIE superglobal.
- Removed remaining legacy arbitrary-CSS cleanup references from Kitsuly settings/theme code.
- Re-ran prohibited-theme, attribution, REST, request-input, enqueue, external-service, source-distribution, prefixing and storage-growth checks across the complete plugin.
1.44.5
- WordPress.org compliance checkpoint 6: completed external-service, URL, source-distribution, storage-growth and WordPress-facing prefix review.
- Replaced obsolete Sendle legal URLs with current Sendle Support legal-policy URLs and updated the generated public tracking URL to the documented tracking host.
- Removed obsolete T1K1 Kitsuly subpaths from upgrade links.
- Removed the private Kitsuly.com documentation-library runtime from the public directory build.
- Updated external-service disclosures to match the shipped Google, AI, payments, shipping, social, media, QR and Signature Theme catalogue integrations.
- Expanded source-code documentation to state that shipped first-party JS/CSS are the human-readable maintained source and require no hidden build pipeline.
- Abandoned-cart recovery send markers use expiring transients rather than permanent per-message options.
- Confirmed Kitsuly-owned WordPress-facing options, transients, AJAX actions, shortcodes, REST namespaces and hooks use the Kitsuly prefix.
1.44.4
- WordPress.org compliance checkpoint 5: hardened output escaping across admin, storefront, Builder and generated HTML fragments.
- Added a central wp_kses output boundary for Kitsuly renderer fragments, including forms, media, iframe and SVG elements used by the visual storefront.
- Replaced opaque returned-HTML echo paths with escaped/allow-listed output boundaries.
- Template JSON export now uses wp_send_json instead of directly echoing encoded JSON.
- Public catalogue rendering now streams escaped markup directly rather than echoing a complete unescaped document string.
- Dynamic storefront CSS is assembled as a string and passed to wp_add_inline_style without echoing runtime values.
1.44.3
- WordPress.org compliance checkpoint 4: request-security and input-sanitisation sweep.
- Added typed GET/POST request readers using PHP filter_input plus WordPress sanitisation.
- Reworked reviewer-flagged admin filters, calendar/range/search inputs, product/builder queries and account actions to avoid raw request reads.
- Centralised uploaded-file normalisation and kept nonce/capability validation at upload handlers.
- Sanitised whole-array policy/privacy/workflow payloads before service boundaries.
- Replaced raw public catalogue/search query reads with filtered request values.
1.44.2
- WordPress.org compliance hardening, part 3: explicit REST permission callbacks added for public storefront reads, authenticated account routes and analytics tracking.
- Authenticated account REST endpoints now require the logged-in customer plus a valid WordPress REST or Kitsuly storefront nonce.
- Analytics visit/engagement routes validate the site analytics token in permission_callback before processing.
- Payment/controller webhooks continue to require cryptographic signature verification; invoice/booking/return/shipment routes retain their existing token/order-ownership checks.
1.44.1
- WordPress.org compliance hardening, part 2: removed direct stylesheet/resource-link output from PHP.
- Google Fonts now load only through WordPress wp_enqueue_style().
- Dynamic CSS/JavaScript continues to use wp_add_inline_style()/wp_add_inline_script() attached to registered handles.
1.44.0
- WordPress.org compliance hardening, part 1: removed plugin-owned customer/social authentication and user creation.
- Customer registration now uses WordPress core registration/login flows.
- Membership signup now requires an already authenticated WordPress account.
- Removed the legacy arbitrary storefront custom-CSS setting from Kitsuly configuration.
- WordPress theme activation remains entirely user-controlled through Appearance -> Themes.
- Public storefront attribution remains opt-in/absent by default.
1.43.99
- Added Settings Site Identity with WordPress media pickers for the global site logo and favicon/site icon.
- Saving Site Identity synchronises WordPress Custom Logo and Site Icon and forces the favicon URL across storefront, login and admin head output.
- Kitsuly native storefront logo fallbacks now receive the saved canonical logo through WordPress custom-logo resolution.
- Added previews, clear controls and responsive settings UI.
1.43.92
- Theme Pack apply now synchronises the active Store Menus assignment with the imported theme shell so stale menus from a previously applied theme cannot override new page links at runtime.
- Theme apply rollback now restores Store Menu sets and assignments if an install transaction fails.
1.43.91
- Theme Pack application now rebinds imported navigation items to the actual site pages created or resolved by the applying theme.
- Fixes renamed menu labels keeping stale URLs/page targets from a previously applied theme.
- Prevents theme-specific pages such as Swimwear or Resort Edit opening an older theme’s page when switching native theme packs.
1.43.90
- Added a Remove action to imported Store Themes so merchants can clean old theme packs out of the Theme Library.
- Active themes are protected from deletion until another theme is applied.
- Removing a theme library entry does not delete store pages, products or media created from that theme.
1.43.88
- Fixed Store Themes Apply buttons not starting because the JavaScript read the wrong data attribute.
- Restored the staged 0–100% theme installation progress overlay for native and imported Kitsuly themes.
1.43.85
- Emergency hotfix rebuilt from the known-stable 1.43.83 base after the 1.43.84 documentation compatibility update could trigger a critical error on some sites.
- Restores documentation cover compatibility with the actual
/wp-content/uploads/kitsuly-sitepack/docs/location using a minimal string-path repair rather than the previous runtime asset resolver. - Keeps Documentation library labels and cards readable on light backgrounds.
1.43.83
- Rebuilt Kitsuly post/article cards so post grids use the full available width, keep landscape media proportions and retain readable high-contrast titles/excerpts across light and dark site palettes.
- Added a native Posts landing page for sites without an existing WordPress posts page, while respecting stores that already use a Blog/Posts page.
- Added a responsive post-filter sidebar with search, category, tag, month and sort controls plus paginated results.
- Improved the default single-post layout with a comfortable reading width and explicit readable article typography without overriding posts that have a custom Kitsuly Builder layout.
- Applied the post-card fix to every Kitsuly Post Grid / Post Block / Smart Post List / Post Carousel instance, including Releases and Developments pages.
1.43.78
- Migrated WordPress-facing internal hooks, AJAX/admin actions, option keys, metadata keys, shortcodes, REST namespace and Kitsuly-owned table prefixes from the retired three-character internal prefix to the public
kitsuly_prefix. - Added a one-time upgrade migration that preserves existing Kitsuly options, metadata, custom tables, scheduled events and shortcode content when upgrading an existing store, including deactivate/replace/reactivate upgrades.
- Cleared the reported Plugin Check findings covering request sanitisation, nonce/state validation, output escaping, production logging, theme-pack media queries and package structure.
- Reworked WooCommerce migration compatibility so Kitsuly no longer registers third-party shortcode or block declarations; legacy page content is translated through Kitsuly-owned adapter hooks at render time.
1.43.77
- Cleared the Plugin Check findings from the WordPress.org compliance pass: request sanitisation, nonce/static-analysis findings, storefront language attributes and production debug logging.
- Reworked theme-pack media deduplication to use a bounded Kitsuly hash map instead of an attachment meta query, removing the suppress_filters and slow meta-query findings.
- Kept OAuth and verification callbacks protected by their one-time state/token flows while switching query parsing to filtered input handling.
- Removed the unexpected root SOURCE.md file; source/build documentation remains in readme.txt.
1.43.76
- WordPress.org compliance/security release based on v1.43.75.
- Removed arbitrary storefront CSS entry and default public Kitsuly attribution; merchant-controlled design settings continue to generate safe CSS programmatically.
- Reworked dynamic scripts/styles to use WordPress enqueue/inline APIs and hardened request sanitisation, AJAX nonces, REST permissions and webhook verification.
- Removed plugin-driven WordPress theme installation/activation; Theme Adapter now connects only to the WordPress theme the administrator activates from Appearance Themes.
- Corrected Kitsuly ownership URLs, expanded external-service disclosures and documented bundled human-readable JavaScript source.
- Bounded abandoned-cart recovery markers with expiring transients and retained Kitsuly theme-pack imports as native Kitsuly layout/data packages.
1.43.74
- Fixed imported full-site Kitsuly theme pages so published Builder layouts render on normal WordPress pages after theme installation.
- Accelerated Kitsuly theme ZIP imports by deduplicating identical bundled media and avoiding expensive generation of every registered WordPress image size.
- Moved uploaded Kitsuly themes to the top of Store Themes, sorted newest-first.
- Uploaded theme library now displays four cards per row, shows the newest eight initially, and progressively reveals older themes with Show more.
- Added a clearer theme-install overlay, proper apply errors and install detail feedback.
- Theme-pack page creation now validates before committing the active layout and trashes newly created pages if an install cannot complete.
1.43.73
- Rebuilt Social Marketing as a multi-network Campaign Studio with Facebook, Instagram, TikTok, X, LinkedIn and Pinterest tabs and network-shaped live previews.
- Added master campaign propagation with optional per-network custom copy, media and link variants.
- Replaced manual media-URL entry with WordPress Media Library/upload selection. Kitsuly now supplies the public media URL to supported social APIs automatically.
- Added an overlay iframe image editor with crop presets, zoom, repositioning, rotation, resize output and campaign image tags. Edited images are saved as new WordPress Media Library files.
- Added platform-specific validation and TikTok/Pinterest campaign controls.
- Campaign history now preserves and displays the actual provider error returned by the Platform Controller and provides Retry for partial/failed campaigns.
1.43.72
- Reworked Facebook, Instagram, Pinterest, X, LinkedIn and TikTok merchant connections around one-click OAuth sign-in through the private Kitsuly Platform Controller.
- Removed the need for merchants to paste social API tokens/secrets into WordPress for brokered social channels.
- Added controller-backed social connection status, connect/reconnect, disconnect and publishing calls.
- Social Marketing now publishes brokered channels through the Kitsuly controller while keeping provider results in the campaign queue.
- Added a controller API contract for social OAuth, destination selection, token refresh and publishing.
1.43.71
- Removed the support-recipient filter that triggered the final Plugin Check hook-prefix warning; support requests now use the fixed Kitsuly support recipient directly.
1.43.70
- Plugin Check hardening sweep: fixed reported output escaping, translation comments, request sanitisation and nonce-verification findings across dashboard, admin, email marketing, account/social login and contact forms.
- Reworked protected digital delivery filesystem operations to use WordPress filesystem/delete/URL APIs while retaining the private Kitsuly vault and 30-minute token delivery flow.
- Converted reported custom-table identifier interpolation to WordPress identifier placeholders and documented intentional uncached transactional queries.
- Hardened mailing-list handlers with explicit capability/nonce checks and sanitized request values, and removed false-positive product-filter exclusion keys.
- Prefixed the support recipient hook and hardened social OAuth redirects/output handling.
1.43.69
- Builder: Single Product now uses a searchable product picker with a normal product dropdown instead of requiring a numeric product ID.
- Builder: Product Grid and Product Results now include Left, Centre, Right and Stretch alignment for the entire product set, including incomplete rows.
- Builder: Selected Single Product previews now reflect the actual chosen product.
1.43.68
- Fixed Product Title being hidden on live Builder-powered product pages by the global WordPress/theme title-suppression rule.
- Product Title now remains visible and uses the exact Product Template typography, colour and spacing settings.
- Breadcrumb typography and colour now propagate to Home, Shop, separators and the current product label instead of being overridden by storefront/theme child styles.
- Updated the Breadcrumb Builder preview so font size, family, weight and colour preview at true element scale rather than through a browser-small tag.
1.43.67
- Made the shared Product Template the single source of truth for every live Kitsuly product page.
- Removed the hidden runtime product-page geometry rewrite that was moving the gallery, metadata, descriptions and purchase controls after the Product Template had already rendered.
- Removed legacy per-product layout classes from Builder-powered product pages so old Classic / Gallery / Split / Cinematic skins can no longer override the published Product Template.
- Product Studio and the Products list now link directly to Edit Product Template, and per-product layout selectors have been removed from the catalogue UI.
- Added Manual Product Canvas and Blank Product Canvas Product Template presets for a clean editable starting point without overwriting an existing published template automatically.
1.43.66
- Added Kitsuly Store Pulse to the native WordPress Dashboard with sales, orders, visitors, abandoned carts, low-stock, Store Health, payment status and store visibility cards.
- Added native quick links to Kitsuly Dashboard, Orders, Products, Builder, Analytics and the storefront.
- Store Pulse supports WordPress drag/collapse behaviour plus a Configure panel with Full/Compact modes and per-card visibility controls.
1.43.65
- Product page responsive lead fix: the right-hand media/gallery/meta stack now remains floated beside the product copy through tablet and narrow-desktop widths, so title, price, purchase controls and description fill the available black/content area on the left and then wrap full-width beneath the media. Mobile stacking now begins only at compact widths.
1.43.64
- Introduced Flow Foundation v1: Desktop is the structural source, with Tablet and Mobile derived from its flow instead of inheriting fragile pixel placement.
- Normal element movement now reorders items in document flow; neighbouring elements move above/below automatically instead of overlapping.
- Added explicit Manual overlap mode with independent 5px X/Y offsets for intentionally layered designs.
- Fields, Rows and Columns are locked to structural flow; Field vertical resizing now uses natural minimum height so adjoining Fields move as complete units with their contents.
- Added one-click “Rebuild Tablet + Mobile safely from Desktop” and safer per-device reset controls.
- Responsive Hero derivation now clears desktop-only eyebrow/title/body/button/media drag offsets and uses safer tablet/mobile copy/media positioning.
- Existing pre-Foundation responsive layouts are rebuilt once from Desktop on upgrade to remove legacy detached positioning.
1.43.62
- Product detail lead rebuilt: compact right-aligned media, 3-column gallery thumbnails, metadata beneath media, 20px top spacing and full-width wraparound long descriptions across legacy and current Product Builder structures.
- Fixed tablet-width Kitsuly admin navigation so submenu labels stay visible instead of collapsing into blank clickable bars.
- Added a three-across quick-action row for the Dashboard / owner utility / Kit Assistant icons on tablet and mobile layouts.
- Hardened WordPress, Documentation and light/dark utility icons so they remain visible and inside the viewport in both light and dark admin themes.
- Switched the admin rail to dynamic viewport sizing with a scroll-safe menu area and protected footer spacing so the bottom utility row no longer sits a few pixels below the visible screen.
1.43.60
- Replaced the obsolete merchant Stripe webhook-secret Store Health check with Platform Controller registration, authentication and reconciliation checks.
- Store Health now reflects the controller payment architecture and explicitly confirms that merchant stores do not need a Stripe
whsec_secret. - Expanded Stripe status in Integrations and Payments to show Stripe account, live mode, controller registration/authentication and reconciliation separately.
1.43.59
- Added storefront customer Google/Facebook account registration and returning social sign-in flows with customer confirmation before account creation.
1.43.58
- Added protected digital-product uploads stored in Kitsuly private server storage.
- Added 30-minute rolling download tokens, account download library, post-purchase buttons and email download links.
- Added Digital Downloads admin reporting and protected proxy delivery for external source URLs.
1.43.57
- Fixed the Visual Builder Product Grid inspector error that could leave the element selected with an “Editor control error” message.
- Added seven switchable product-card presentations: Classic, Editorial, Minimal, Overlay, Horizontal List, Compact Catalogue and Showcase.
- Product Grid, Product Results, Product Carousel, Product List and Product Slider now expose flexible card-content controls for image, title, price, description, brand, collection, tags, SKU, stock, rating, colour swatches, wishlist and action button.
- Added configurable product actions: automatic, Add to cart, Buy now, View product and Subscribe / Register, with custom button text and full-width button support.
- Added card styling controls for image ratio and fit, card/text/price/button colours, card and image corners, padding and typography sizing.
- Added Buy now behaviour that adds eligible simple products to the bag and immediately continues to checkout; option-based products safely fall back to product selection.
- Updated filtered / AJAX-loaded product results and Visual Builder previews so the selected product-card design and content settings remain consistent after live catalogue updates.
1.43.55
- Fixed published Button hover/focus styling so it no longer depends on inline-style text matching.
- Fixed Hero and Hero Slider button hover colours on the live storefront by removing normal-state inline !important conflicts.
- Made Hero Slider button URL controls explicit in both the inline slide editor and dedicated Hero Slider Studio.
- Added normal and hover button colour controls directly to every Hero slide card.
1.43.55
- Added a real File Upload field to Storefront Contact Forms, including drag/click builder support, accepted-file controls and per-field size limits.
- Frontend contact forms now render an actual file chooser, validate uploads securely, save the uploaded file reference with the submission and attach it to notification email.
- Existing support forms using a text field labelled “Screenshot or supporting file” are automatically upgraded to the new upload field so the live support page no longer shows a blank text box.
1.43.53
- Rebuilt the Support screenshot field as a real upload control with an obvious Choose screenshot button, drag/drop, filename display, preview and remove action.
- Added secure screenshot validation for PNG, JPG, WEBP and GIF files up to 8 MB and attachment delivery with support requests.
1.43.52
- Auto Scroller image items now use a full visual image picker with a real preview and a clear Upload image / Media Library action.
- Format Painter now behaves as a true toggle: click once to arm it, click the same paintbrush again to cancel without copying any formatting.
1.43.51
- Added the new Auto Scroller visual-builder element with seamless multi-line continuous scrolling.
- Auto Scroller items can combine text with Kitsuly icons or WordPress media images, optional links, item sizing and media position.
- Added icon/image rotation angle and continuous spin controls, per-line direction and speed adjustment, global pixel-per-second speed, line/item spacing and optional edge fades.
- Added instant pause-on-hover/focus that resumes from the exact same scroll position.
1.43.50
- Fixed universal Hover & Interaction States preview reliability in the Visual Builder, including buttons after layout/size CSS is applied.
- Fixed standard and custom/silhouette button hover fill, text/icon and border-state parity between Builder and published storefront.
- Hover & Interaction States now starts collapsed, matches the standard inspector-section styling, and auto-enabling a changed hover value is reflected by the toggle immediately.
1.43.48
- Added Builder ordering controls for post, product, service, category and media-driven collection elements.
- Added post category and tag include/exclude filters, including multi-select filtering in Post Grid, Post Carousel, Post Block, Smart Post List and dynamic post galleries.
- Added product category and tag include/exclude filters plus ordering by updated/created date, name, price, stock, SKU, ID or random order for product grids, carousels and service grids.
- Added image/media ordering by selected order, upload date, name or file size for galleries and image-driven carousels.
1.43.48
- Added Firefox/Edge-safe image fallback handling for Kitsuly storefront/admin images, including recovery when a browser selects a broken WordPress srcset derivative.
- Normalised dynamically inserted image and iframe URLs against the current document URL and made Kitsuly preview/document frames load reliably after hidden-panel/menu reflows.
- Rechecked all reordered Kitsuly sidebar routes and callbacks; the current Storefront, Customers, Products, Orders, Payments, Shipping, Marketing, Kitsuly SEO and Settings destinations are registered.
- Hardened Documentation links with canonical HTTPS/trailing-slash targets and an explicit support-page documentation link.
1.43.48
- Restored the missing Bookings admin-page registration so the Products Bookings route opens correctly.
- Removed the large Site SEO hero banner so Site SEO opens directly into its navigation and tools.
1.43.45
- Added native multi-list Email Marketing with Contact Form signup routing, list/source categorisation and legacy subscriber migration.
- Added per-list unsubscribe suppression with a signed storefront unsubscribe confirmation page and List-Unsubscribe mail headers.
- Added Email Marketing draft autosave, list selection, immediate/scheduled delivery, editable campaign history and scheduled-email calendar.
- Added mailing-list delivery and scheduling to Catalogues using the same consent/unsubscribe engine.
- Fixed Visual Builder and storefront button hover text, background and border-state rendering.
1.43.44
- Hardened portable theme imports and Builder rendering against malformed component child data.
- Fixed a theme-pack canvas regression that could leave the Visual Builder blank after applying an imported theme.
- Organised the Builder page selector into Store & Commerce, Current Theme Pages, Other Site Pages and Posts.
1.43.43
- Theme Pack: portable Kitsuly theme ZIPs can now include normal WordPress pages with full responsive Kitsuly Builder layouts.
- Theme Pack: portable contact forms can be bundled with a theme and installed when the theme is applied.
- Theme Pack: media URL remapping now also works inside Hero Slider JSON and multi-image fields.
- Theme Library: imported packs can show their own bundled preview artwork and page/form counts.
- Release lineage remains clean/public; Kitsuly.com private site-pack content is not included.
1.43.41
- Fixed Field, Row, Column and Container background-video playback in both the Visual Builder and published storefront.
- Background type changes now preserve the open inspector section instead of collapsing the editor.
- Added background-video start and finish timecodes (M.SS; 0.02 = two seconds). Blank finish plays to the natural end.
- Added live numeric readouts to range sliders, using percentage, px, degrees, seconds or milliseconds where appropriate.
- Upgraded Format Painter to deep-format matching child elements inside Fields, Rows, Columns and Containers while retaining destination content/data.
1.43.40
- Builder: completed a code-level sweep of all 180 registered visual-builder components, including explicit save/renderer coverage and deeper editors/previews for the expanded component library.
- Builder: rebuilt shallow interactive elements including Collection Banner, Social Icons, Image Masking, Filterable Gallery, 360 Viewer, Image Hotspots, Lightbox/Modal, Dynamic Gallery, Fancy Chart, carousels, protected content, interactive cards/circles, product compare/quick view and related effects.
- Builder: component names now map more closely to real behaviour, with carousel, modal, filter, hotspot, compare, tooltip, scrolling and gated-content interactions implemented in storefront output where applicable.
- Contact Forms: added complete appearance controls for form, labels, fields, focus state and submit button, plus per-field widths, resizable message-box height and persisted design settings.
- Contact Forms: repaired radio/checkbox layout with neat inline label spacing, left alignment by default, horizontal/vertical layouts and per-field/default alignment controls.
1.43.39
- Builder: Desktop layouts now automatically generate and stay synced to responsive Tablet and Mobile layouts until a device is manually adjusted.
- Builder: Responsive visibility controls moved from Style to Advanced > Responsive.
- Builder: Publishing now reloads the same WordPress page and device view being edited instead of falling back to the default builder page.
1.43.38
- Reordered the Kitsuly sidebar around storefront, customers and commerce workflows.
- Moved Growth tools into Kitsuly SEO and renamed System to Settings.
- Added per-user drag-and-drop sidebar ordering with reset-to-default.
- Dashboard source controls now show dashboard icon + / – badges and toggle widgets on or off.
1.43.37
- Restored reliable sun/moon admin theme icon and tightened the Kitsuly rail footer/support area to remain fully visible within the viewport.
1.43.36
- Builder refinement pass: repaired gradient/image text fill, richer Icon Lists and Styled Tabs, animated/candy-stripe/GIF progress fills, slide editing preview sync and page-switch canvas reset.
- Rebuilt Slide-out Panel editing as a reorderable mini content stack with live panel preview, per-element alignment/padding, trigger styling and custom/half/full-screen widths.
- Expanded the native Builder library with content, dynamic, marketing, creative/media, forms, social and categorized interactive effects.
- Expanded Kitsuly Store elements with richer shopping/product-detail blocks plus booking, availability, service and subscriber/licensing components.
1.43.35
- Added manual customer creation and a manual/expo order workflow with invoice/payment-link delivery.
- Expanded Subscriber management with editable product level, licence level, start/expiry/grace dates, initial and renewal amounts, renewal cycle, status and auto-renew controls.
- Reworked the Kitsuly rail support/footer controls and replaced source-card dashboard plus signs with the Dashboard icon.
1.43.34
- Added a new top-tier Kitsuly SEO area with Product SEO and Site SEO.
- Integrated the complete Kitsuly-branded site SEO engine with audits, bulk optimisation, schema, internal links, media optimisation, performance diagnostics, local keyword ranking, first-party analytics, Search Console and curated sitemaps.
- Added Kitsuly Native SEO as the built-in site metadata engine, while retaining optional compatibility with supported third-party SEO plugins.
1.43.33
- Final Plugin Check naming-convention cleanup for Kitsuly Commerce public extension hooks.
- Retained the existing public hook names for backward compatibility and documented their intentional use for WordPress Coding Standards.
1.43.30
- WordPress Plugin Check hardening pass across security, database, request handling and packaging checks.
1.43.29
- Added Builder Format Painter for like-for-like component styling.
1.43.28
- Moved selected component content controls to the top of the Builder editor and added Page Structure auto-scroll/highlight.
1.43.27
- Updated central licensing information for the Kitsuly Licensing API.
1.43.26
- Added Subscriber Products, recurring/licence foundations, domain binding and central Kitsuly licensing integration.
1.43.25
- Rebuilt the Hero Slider/video background subsystem with clean native video rendering.
For earlier development history, see the release notes supplied with previous Kitsuly builds.
