=== M Cookie Consent ===
Contributors: majevski
Author: Vitold Majevski
Author URI: https://majevski.com
Plugin URI: https://majevski.com/m-cookie-consent
Tags: gdpr, cookie consent, consent mode, google analytics, meta pixel
Requires at least: 6.5
Tested up to: 7.0
Requires PHP: 7.4
Stable tag: 1.1.2
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Lightweight GDPR cookie consent with Google Consent Mode v2. Blocks Google Analytics, Tag Manager, Meta Pixel and custom scripts until visitors consent.

== Description ==

M Cookie Consent makes any WordPress site compliant with the EU GDPR/ePrivacy rules and Google's Consent Mode v2 requirements (mandatory for EEA traffic) — without external services, accounts or heavy scripts.

**How it works**

* All configured tracking scripts are printed as inert `type="text/plain"` snippets and only executed after the visitor consents to the matching category. Before consent, not a single request is sent to Google or Meta.
* A tiny inline script sets the Google Consent Mode v2 default state (all seven signals `denied`, `security_storage` granted) in the `<head>` before anything else, and sends `gtag('consent', 'update', …)` when the visitor decides. Google Tag Manager containers automatically receive the granular consent state for every tag inside them.
* The visitor's choice is stored in a single first-party cookie — the plugin itself needs no personal data, no server-side storage and no AJAX, which also makes it fully compatible with full-page caching.
* Accept all, Reject all and per-category choices are offered with equal prominence, as EU regulators require. Consent can be withdrawn at any time via a floating button, the `[m_cookie_settings]` shortcode or any link pointing to `#mcc-settings`.

**Features**

* A modern, polished banner design out of the box — rounded card, accent-colour gradient, cookie icon — plus a "Match my website theme" mode that inherits your theme's font and keeps the banner visually neutral
* Intuitive settings screen with a live banner preview, character counters with recommended limits, and instant format checks on the Google Analytics / Tag Manager / Meta Pixel IDs
* Google Analytics 4, Google Tag Manager, Meta Pixel and custom `<head>` scripts, each gated behind the correct consent category (Necessary / Functional / Analytics / Marketing)
* Google Consent Mode v2: `ad_storage`, `analytics_storage`, `ad_user_data`, `ad_personalization` + `functionality_storage`, `personalization_storage`, `security_storage`
* Choice of full prior blocking (default, safest) or Google's "Advanced" Consent Mode (denied-state pings enabling conversion modelling)
* Automatic re-consent when you change your tracking configuration, plus a manual "ask everyone again" button
* Accessible banner: keyboard operable, focus trap, correct dialog semantics, respects reduced-motion preferences
* Every text is editable and fully translatable with the standard WordPress translation tools
* No jQuery, no build step, no external requests from the plugin itself; ~10 KB of front-end assets

**Why is there no GTM `<noscript>` iframe?**

The classic GTM `<noscript>` iframe would track visitors who have JavaScript disabled — visitors who can never see the banner and therefore can never consent. Omitting it is deliberate and required for compliance.

== Installation ==

1. Upload the `m-cookie-consent` folder to `/wp-content/plugins/`, or install the ZIP via Plugins → Add New → Upload.
2. Activate the plugin.
3. Open the new **M Consent** menu in the WordPress admin sidebar and enter your Google Analytics ID, Tag Manager ID, Meta Pixel ID and/or a custom tracking script.
4. That's it — the banner appears automatically as soon as at least one integration is configured.

== Frequently Asked Questions ==

= Does the banner appear when no tracking service is configured? =

No. If there is nothing to consent to, showing a banner would be noise. Developers can force it with the `mcc_force_banner` filter when the site runs trackers this plugin does not manage.

= Does it work with caching plugins? =

Yes. All consent decisions are made in the visitor's browser; the HTML output is identical for every visitor. After changing tracking settings, purge your page cache so the new configuration reaches every cached page.

= Where is consent stored? =

In a single first-party cookie (`mcc_consent`) containing the consent version, a timestamp and the chosen categories. Nothing is stored server-side about individual visitors. A configuration log (what was asked, since when) is kept in the options table for accountability.

= How do visitors change their mind later? =

Via the floating cookie button (on by default), the `[m_cookie_settings]` shortcode, any link with the URL `#mcc-settings`, or `window.mccShowSettings()` from custom code.

= How do I translate the plugin? =

The text domain is `m-cookie-consent`; a POT file ships in `/languages`. Use Loco Translate, Poedit or translate.wordpress.org language packs. Texts you type into the settings override the built-in translations — leave a field empty to keep it translatable.

= Where do I get support? =

Write to pagalba@majevski.com or visit https://majevski.com — support is available in English and Lithuanian.

= Which hooks are available for developers? =

Filters: `mcc_settings`, `mcc_categories`, `mcc_active_categories`, `mcc_get_text`, `mcc_should_load`, `mcc_force_banner`, `mcc_template_path`. JavaScript: a `mcc:consent` CustomEvent fires on `document` after every decision, and a `mcc_consent_update` event is pushed to the `dataLayer`.

== Privacy ==

This plugin sets exactly one functional first-party cookie (`mcc_consent`) to remember the visitor's consent choice. It stores no personal data, sends no data to external services by itself, and only loads third-party tracking after explicit consent. Suggested privacy-policy wording is provided under Settings → Privacy → Policy Guide.

== Changelog ==

= 1.1.2 =
* Fixed: an update that could not be downloaded now says why. WordPress gives a package download five minutes to finish, which is longer than any host allows a single admin request to run, so when the connection to majevski.com stalled the request was cut off before WordPress could report anything and the Plugins screen showed only the browser's own "Connection lost or the server is busy". Downloads of this plugin's releases are now capped at sixty seconds — far more than a release archive needs, and short enough that the real transport error is reported on the screen instead of the request dying silently.
* New: a Site Health check under Tools → Site Health → Status, "M Cookie Consent can reach its update server". It makes the same two calls the installer makes — the release manifest, then the package itself — and prints the exact error when either fails, so a blocked outbound connection is named as such instead of appearing as a failed update.

= 1.1.1 =
* Fixed: new releases now appear on the Plugins screen within an hour instead of up to a day. WordPress only re-checks for updates every 12 hours by default and the release manifest was cached for another 12 — visiting the Plugins screen now forces a fresh check (at most hourly), and the manifest cache lasts one hour.
* New: a "Check for updates" link in this plugin's row on the Plugins screen — click it and, if a newer release exists, the native "update now" link is active immediately.

= 1.1.0 =
* New: automatic update checks against majevski.com. When a newer release is published, WordPress shows its standard update prompt with one-click install; a "View details" popup shows the changelog. The update channel is pinned to https://majevski.com over HTTPS, checks are cached and fail open, and equal or older versions are never offered.

= 1.0.1 =
* Fixed banner text (heading and body) appearing washed out or invisible on themes that colour every heading and paragraph. The banner now enforces its own text colours and can no longer be overridden by the theme.
* The chosen accent and text colours are now written directly onto the banner elements, so they keep working even when a CSS-optimisation or caching plugin removes inline styles.
* Improved readability of the category descriptions in the preferences window (they now follow the chosen text colour).
* Version bump also refreshes the banner styles and script, so the correct colours and the preference toggles always display after an update, even when a browser or caching plugin held an older copy.

= 1.0.0 =
* Initial release: GDPR consent banner with Modern and match-your-theme designs, Google Consent Mode v2, GA4/GTM/Meta Pixel/custom script gating, live admin preview with input validation, full i18n.

== Upgrade Notice ==

= 1.1.0 =
Adds self-hosted update checks: from this version on, new releases appear in the normal WordPress update flow. Install this version manually once — older versions do not know about the update channel yet.

