Activation no longer inserts sample leads automatically. A “Load 7 sample leads” button now appears on the dashboard only when the CRM is empty, and only loads data if an administrator clicks it.
Fixed the database table creation SQL to use the exact format dbDelta() requires (removed “IF NOT EXISTS”, which dbDelta cannot parse).
1.7.9
Fixed the Pabbly Terms & Conditions URL in this readme.
All admin-page JavaScript now loads through wp_enqueue_script()/wp_localize_script()/wp_add_inline_script() instead of inline tags.
1.7.8
Limited readme Tags to 5 (WordPress.org requirement).
All database queries now consistently use $wpdb->prepare(); table/column names are escaped or whitelisted.
CSV import now reads the uploaded file via WP_Filesystem instead of fopen()/fread()/fclose().
All internal redirects use wp_safe_redirect(); the one redirect to Facebook’s OAuth screen is intentionally kept as an off-site wp_redirect() and documented as such.
date() calls replaced with gmdate() (WordPress always runs in UTC internally, so displayed times are unaffected).
1.7.7
Updated “Tested up to” to WordPress 7.1.
Database queries: table names are escaped, and the visitor filter now uses one fixed prepared query.
1.7.6
Security: nonce and capability checks on all settings, actions and AJAX handlers; nonce values are now sanitized before verification.
Security: counsellors can only view or change leads assigned to them (ownership check on lead pages, follow-ups, notes and stage changes).
Security: Meta webhook POST requests must carry a valid X-Hub-Signature-256 signature; “Clear log” is now protected against CSRF.
All dynamic output is escaped (esc_html, esc_attr, esc_url, esc_js, wp_kses_post).
Documented the external services (Meta Graph API, WhatsApp click-to-chat, Pabbly Connect) in this readme.
Removed the invalid Plugin URI, updated “Tested up to” to WordPress 7.0, fixed the Contributors list.