PluginProbe
Easy Invoice – Invoice Generator, PDF Quotes & Payments / 2.4.4
Easy Invoice – Invoice Generator, PDF Quotes & Payments v2.4.4
2.4.3 2.4.4 2.4.2 2.4.0 2.4.1 2.3.8 2.3.7 2.3.6 2.3.5 2.3.4 2.3.3 2.3.2 2.3.1 2.2.0 2.1.21 2.1.20 2.1.19 2.1.18 2.1.0 2.1.1 2.1.10 2.1.11 2.1.12 2.1.13 2.1.14 All 60 releases
easy-invoice / readme.txt

readme.txt in Easy Invoice – Invoice Generator, PDF Quotes & Payments 2.4.4, at readme.txt

339 lines 37.0 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 === Easy Invoice – Invoice Generator, PDF Quotes & Payments ===
2 Contributors: matrixaddons
3 Tags: invoice, pdf invoice, quotes, billing, payment gateway
4 Requires at least: 6.0
5 Tested up to: 7.1
6 Requires PHP: 7.4
7 Stable tag: 2.4.4
8 License: GPLv2 or later
9 License URI: https://www.gnu.org/licenses/gpl-2.0.html
10
11 Invoices, quotes, PDFs and payments inside WordPress. Unlimited documents, PayPal, credit notes, statements and a REST API — free.
12
13 == Description ==
14
15 **Easy Invoice** turns your WordPress site into your invoicing system. Create invoices and quotes, send them as PDFs, take payment on the invoice page and keep every client's history in one place — with no per-document limits, no watermarks and no trial period.
16
17 It is built for freelancers, consultants, agencies and small businesses that would rather not pay a monthly fee for a separate invoicing service, and for developers who want invoicing that follows WordPress conventions: custom post types, capabilities, hooks, a REST API and coding standards.
18
19 [Live demo](https://try.new/plugins/easy-invoice/) · [Documentation](https://easy-invoice.matrixaddons.com/docs/) · [Product page & Pro pricing](https://matrixaddons.com/plugins/easy-invoice/) · [Support forum](https://wordpress.org/support/plugin/easy-invoice/)
20
21 https://www.youtube.com/watch?v=a_0BnBpl0y0
22
23 = What the free plugin does =
24
25 **Invoices and quotes**
26
27 * Unlimited invoices and quotes, with automatic numbering and your own prefix — numbers stay unique even when two people save at the same moment
28 * Line items with quantities, per-line or global tax, and discounts calculated before or after tax
29 * Convert an accepted quote into an invoice in one click; clone any document
30 * Credit notes against issued invoices; client statements with running balances
31 * Notes, terms, due dates and payment instructions per document; default terms in Settings
32
33 **PDF and print**
34
35 * PDFs are rendered on the server (real, selectable text) with your logo and business details
36 * Nine document designs: default, modern, classic, minimal, corporate, professional, elegant, creative and legacy
37 * Rename any label ("Grand Total", "Net", your language) without touching code
38 * Download from the admin, from the public invoice page, or through the REST API
39
40 **Getting paid**
41
42 * PayPal checkout with a Pay Now button on every invoice
43 * Bank transfer, cheque, cash and any offline method you add (ACH, wire…) — the client sees your instructions, sends a reference and a receipt, and you confirm the payment from the Payments screen
44 * Payment history with partial, paid and overdue states
45 * A custom Pay Now link for any other provider
46
47 **Clients**
48
49 * Unlimited client records with billing details and a complete per-client history
50 * Invoice and quote emails with the PDF attached, from templates you edit
51 * Every emailed link carries a private access key: a document is shown to you, to the signed-in client it belongs to, or to someone with the emailed link — never to whoever guesses a URL
52 * Import from Sliced Invoices or Sprout Invoices in one click, or from CSV files with downloadable templates
53
54 **Localisation**
55
56 * 121 currencies, with symbol, position, decimals and separators set per document
57 * Dates in the site's timezone; translation-ready (text domain `easy-invoice`)
58 * Multisite compatible
59
60 **For developers**
61
62 * REST API for invoices, quotes, clients and PDFs — [API reference](https://easy-invoice.matrixaddons.com/docs/api-reference)
63 * Migration from Sliced Invoices and Sprout Invoices built in
64 * Actions and filters at every step; documents are custom post types you can query
65 * WordPress coding standards, escaped output, prepared SQL, nonce-protected actions
66 * Tested with 10,000 invoices and 10,000 quotes on one site: every admin screen stays under a second
67
68 = Easy Invoice Pro: 26 addons, switch on what you need =
69
70 [Easy Invoice Pro](https://matrixaddons.com/plugins/easy-invoice/) is a separate plugin that adds addons on top of the free one. Each addon has its own on/off switch under **Easy Invoice → Addons**; an addon you leave off loads no code and runs no queries. Pro requires Easy Invoice 2.4.0 or newer.
71
72 **Personal — 16 addons, on as soon as Pro is installed (no licence key needed to use them)**
73
74 * [Recurring Invoices & Subscriptions](https://easy-invoice.matrixaddons.com/docs/recurring-invoices/) — generate and email invoices on any schedule; optional auto-charge through Stripe or PayPal
75 * [Partial Payments & Deposits](https://easy-invoice.matrixaddons.com/docs/addons/partial-payments/) — require a deposit, let clients pay the balance in instalments
76 * [Client Portal](https://easy-invoice.matrixaddons.com/docs/addons/client-portal/) — clients log in to view invoices, download PDFs, see payments and accept or decline quotes
77 * [PDF Toolkit](https://easy-invoice.matrixaddons.com/docs/addons/pdf-toolkit/) — watermarks (PAID, DRAFT, OVERDUE, VOID or your own), custom headers, footers, colours and fonts
78 * [Custom Invoice & Quote Templates](https://easy-invoice.matrixaddons.com/docs/addons/custom-templates/) — a visual builder for your own layouts
79 * [Item Library](https://easy-invoice.matrixaddons.com/docs/addons/item-library/) — saved products and services with price and SKU, inserted in one click
80 * [Bulk Email & Export](https://easy-invoice.matrixaddons.com/docs/addons/bulk-operations/) — email batches of invoices; export selected rows or everything to CSV, Excel or PDF
81 * [Additional Tax Lines](https://easy-invoice.matrixaddons.com/docs/addons/additional-tax/) — unlimited named taxes per invoice (VAT + duty, GST + PST, federal + state)
82 * [Email Enhancements](https://easy-invoice.matrixaddons.com/docs/addons/email-enhancements/) — your own HTML email layout; replies routed by kind
83 * [Secure Links](https://easy-invoice.matrixaddons.com/docs/addons/secure-links/) — signed, expiring document URLs
84 * [Payment Links & QR Codes](https://easy-invoice.matrixaddons.com/docs/addons/payment-links/) — a link or QR code for a fixed or open amount, usable anywhere
85 * [Quote E-Signatures](https://easy-invoice.matrixaddons.com/docs/addons/quote-signatures/) — clients sign when they accept a quote; signature, name, time and connection recorded
86 * [Quote Request Forms](https://easy-invoice.matrixaddons.com/docs/addons/quote-forms/) — WPForms, Gravity Forms, Contact Form 7 or Fluent Forms submissions become draft quotes
87 * [WooCommerce Invoicing](https://easy-invoice.matrixaddons.com/docs/addons/woocommerce/) — an invoice for every paid order; refunds become credit notes
88 * [Reports & Analytics](https://easy-invoice.matrixaddons.com/docs/addons/reports/) — revenue, outstanding balances, per-client performance, month-by-month profit and loss
89 * [Privacy & GDPR](https://easy-invoice.matrixaddons.com/docs/addons/privacy-tools/) — client documents included in WordPress personal-data export and erasure requests
90
91 **Pro payment gateways** (alongside the free PayPal, bank transfer, cheque and cash): Stripe (cards, Apple Pay, Google Pay, Link, 3-D Secure), Square, Authorize.Net, Mollie (SEPA, iDEAL, Bancontact, Klarna), Paystack (cards, bank transfer, USSD, mobile money) and Moneris.
92
93 **Professional — 6 more addons, with a Professional licence**
94
95 * [Time Tracking & Project Billing](https://easy-invoice.matrixaddons.com/docs/addons/time-tracking/) — start/stop timer, per-project and per-client entries, one click to invoice lines
96 * [Expense Tracking](https://easy-invoice.matrixaddons.com/docs/addons/expense-tracking/) — billable expenses with receipts and markup, rolled into invoices
97 * [Smart Reminders & Late Fees](https://easy-invoice.matrixaddons.com/docs/addons/smart-reminders/) — a multi-step reminder cadence, automatic late fees and early-payment discounts
98 * [E-Invoicing](https://easy-invoice.matrixaddons.com/docs/addons/e-invoicing/) — Factur-X / ZUGFeRD (EN 16931) PDFs and Peppol UBL for public-sector and EU customers
99 * [Client Language](https://easy-invoice.matrixaddons.com/docs/addons/client-language/) — every document for a client, page, PDF and email, produced in the client's language
100 * [Retainers & Prepaid Credit](https://easy-invoice.matrixaddons.com/docs/addons/retainers/) — record a block of hours or a prepayment and draw it down invoice by invoice
101
102 **Agency — 4 more addons, with an Agency licence**
103
104 * [White-Label & Brand Override](https://easy-invoice.matrixaddons.com/docs/addons/white-label/) — your name, menu, icon, PDF footer and email signature; every upgrade prompt hidden
105 * [Team Members & Audit Log](https://easy-invoice.matrixaddons.com/docs/addons/team-roles/) — Manager, Accountant, Sales and Viewer roles, and a searchable log of every action
106 * [Accounting Sync](https://easy-invoice.matrixaddons.com/docs/addons/accounting-sync/) — QuickBooks Online, Xero and FreshBooks: invoices push out, payment status comes back
107 * [Webhooks & Zapier](https://easy-invoice.matrixaddons.com/docs/addons/webhooks/) — invoice events to any URL, HMAC-signed with retries; drops into Zapier, Make or n8n
108
109 [See plans and pricing](https://matrixaddons.com/plugins/easy-invoice/#pricing) — every Pro plan has a 14-day money-back guarantee. Upgrading keeps every invoice, quote, client and payment the free plugin created.
110
111 = Who uses Easy Invoice =
112
113 * **Freelancers** — quote, invoice and collect payment from one screen
114 * **Agencies and studios** — per-client history, statements, deposits and a client portal
115 * **Shops and B2B sellers** — proper invoices for WooCommerce orders and everything the cart can't bill
116 * **Consultants and service firms** — billed hours, expenses, retainers and e-invoices for larger customers
117
118 = Privacy =
119
120 Easy Invoice stores everything in your own WordPress database and sends nothing to us. The plugin contacts outside services only when you use them: the payment gateway you configure (PayPal in the free plugin), and the WordPress.org update check that every plugin performs. Card details never touch your site — they are handled by the gateway. With the Pro Privacy & GDPR addon, a client's invoices, quotes and payments are included in WordPress's personal-data export and erasure requests.
121
122 = Translations =
123
124 Easy Invoice is translation-ready (text domain `easy-invoice`, `.pot` in `/languages`). Translate it with Loco Translate, Poedit or on [translate.wordpress.org](https://translate.wordpress.org/projects/wp-plugins/easy-invoice/).
125
126 == Installation ==
127
128 1. In your WordPress admin go to **Plugins → Add New**, search for "Easy Invoice", click **Install Now**, then **Activate**. (Or upload the zip under **Plugins → Add New → Upload Plugin**.)
129 2. Open **Easy Invoice → Settings** and enter your business name, address, logo, currency and default terms.
130 3. Under **Settings → Payments**, connect PayPal and/or enable bank transfer, cheque and cash.
131 4. Go to **Easy Invoice → Clients** and add a client, then **Easy Invoice → Invoices → Add New** to create your first invoice. Send it from the invoice screen; the client receives an email with the PDF and a private link.
132
133 **Requirements:** WordPress 6.0 or newer, PHP 7.4 or newer. Any properly coded theme or page builder.
134
135 **Easy Invoice Pro:** install the Pro plugin from your purchase email next to the free one, then switch on the addons you want under **Easy Invoice → Addons**. Pro needs Easy Invoice 2.4.0 or newer.
136
137 == Frequently Asked Questions ==
138
139 = Is the free plugin limited in any way? =
140
141 No. Unlimited invoices, quotes, clients and PDFs, with no watermark and no time limit. Pro adds optional addons; it does not unlock things the free plugin holds back.
142
143 = Which payment methods can clients use? =
144
145 Free: PayPal, plus bank transfer, cheque, cash and offline methods you define yourself (ACH, wire transfer…) — clients send a reference and receipt, you confirm from the Payments screen. Pro adds Stripe, Square, Authorize.Net, Mollie, Paystack and Moneris. You can also put any provider's payment link on the invoice.
146
147 = Are there transaction fees? =
148
149 None from Easy Invoice. Your payment gateway charges its own fees.
150
151 = Can clients pay in instalments, or pay a deposit first? =
152
153 Yes, with the Partial Payments & Deposits addon (Pro, Personal tier).
154
155 = Can I set up recurring invoices? =
156
157 Yes, with the Recurring Invoices & Subscriptions addon (Pro, Personal tier): invoices are generated and emailed on the schedule you set, with optional automatic charging through Stripe or PayPal.
158
159 = Can I customise the invoice design? =
160
161 The free plugin ships nine designs and lets you add your logo, business details, colours and renamed labels. The Pro PDF Toolkit adds watermarks, headers and footers; the Custom Templates addon adds a visual layout builder.
162
163 = Can I issue a credit note or a statement? =
164
165 Yes, both are in the free plugin: credit notes are issued against a paid or partly paid invoice from the invoice screen, and a client statement (with running balance) is available from the client record.
166
167 = Are invoice links safe to email? =
168
169 Yes. Since 2.4.0 every invoice and quote link carries a per-document access key. A document is shown only to you, to the signed-in client it belongs to, or to someone opening the emailed link — never to anyone who guesses a URL. Links sent before 2.4.0 show a page that offers to email a fresh link to the address the document was issued to.
170
171 = I see "Page not found" when opening an invoice. =
172
173 Go to **Settings → Permalinks** and click **Save Changes** once — this refreshes WordPress's URL rules. If you use a caching plugin, clear its cache.
174
175 = Can I import data from another invoicing plugin or a spreadsheet? =
176
177 Yes. **Easy Invoice → Import** migrates directly from Sliced Invoices and Sprout Invoices (with a dry-run count first), and accepts CSV files of clients and invoices — download the CSV templates from the same screen. Exporting to CSV, Excel or PDF is part of the Pro Bulk Email & Export addon.
178
179 = Does it work with WooCommerce? =
180
181 The free plugin runs alongside WooCommerce without conflict. The Pro WooCommerce Invoicing addon creates an Easy Invoice invoice for every paid order and turns refunds into credit notes.
182
183 = Does it work on multisite? =
184
185 Yes. Each site keeps its own invoices, clients and settings.
186
187 = Is there a REST API? =
188
189 Yes — invoices, quotes, clients and PDFs, authenticated with WordPress application passwords. See the [API reference](https://easy-invoice.matrixaddons.com/docs/api-reference).
190
191 = How does the Pro addon system work? =
192
193 Pro is one plugin containing 26 addons. Under **Easy Invoice → Addons** you switch each one on or off. The 16 Personal addons work as soon as Pro is installed; Professional and Agency addons need a licence of that tier. An addon you leave off loads no code.
194
195 = What if I update Pro before the free plugin? =
196
197 Pro 2.3.0 needs Easy Invoice 2.4.0. If Pro is updated first it stays inactive with a notice until the free plugin is updated, and the secure links your clients already hold keep working meanwhile.
198
199 = What happens to my data if I stop paying for Pro? =
200
201 Nothing is deleted. Personal addons keep working; Professional and Agency addons pause until the licence is renewed. Every document stays in your database and the free plugin continues to work with it.
202
203 = How do I report a security issue? =
204
205 Please do not open a public forum thread. Report it through the [Patchstack Vulnerability Disclosure Program](https://patchstack.com/database/vdp/8b8da081-d07d-4239-b795-0f0895d186dd), which validates reports and coordinates the fix with us, or use the [contact form](https://matrixaddons.com/contact/).
206
207 = Where do I get help? =
208
209 The [documentation](https://easy-invoice.matrixaddons.com/docs/) covers setup and every addon. Free users: the [WordPress.org support forum](https://wordpress.org/support/plugin/easy-invoice/). Pro customers: priority support from the [account area](https://store.mantrabrain.com/).
210
211 == Screenshots ==
212
213 1. Dashboard — outstanding, paid and overdue at a glance, monthly revenue and recent invoices
214 2. Invoices — filters by status, search, bulk actions and pagination that stays fast with thousands of documents
215 3. Invoice builder — client, line items, taxes and discounts with a live preview of the chosen design
216 4. Public invoice page — what the client sees from the emailed link, with the payment panel open on bank transfer
217 5. Quotes — status filters, conversion to invoice, expiry tracking
218 6. Quote builder — the same editor, with expiry date and acceptance flow
219 7. Payments — every payment with its method and status; an offline payment arrives with the client's reference and receipt for you to confirm or reject
220 8. Clients — records with business name, contact details, statements and balances
221 9. Settings → Payment Methods — PayPal, bank transfer, cheque, cash, and offline methods you add yourself (ACH, wire transfer), each with its own instructions and receipt setting
222 10. Credit notes — correct an issued invoice without editing it away; the credit is recorded against the original
223 11. Client statement — every invoice, payment and credit note in date order with a running balance, exportable as PDF
224 12. Import — bring invoices, quotes, clients and payments from Sliced Invoices, Sprout Invoices or a CSV
225 13. Add-ons — 26 add-ons with their own on/off switches; the ones you leave off add no overhead
226
227 == Changelog ==
228 = 2.4.4 - September 29, 2026 =
229 * Fix: **accepting a quote sent the client to a signed "secure link" even on sites that never switched Secure Links on.** The acceptance response asked for a signed URL whenever Easy Invoice Pro was installed — it tested that the class could be loaded, not that the feature was enabled — and minted a hash for the new invoice on the way. Every other place that can use a signed URL (emails, the shortcode, reminders) already checked the setting; this one now does too.
230 * Change: the Secure Links add-on card explains that switching it on adds the setting, and that signing starts when you enable it under Settings → Advanced.
231
232 = 2.4.3 - September 29, 2026 =
233 * Fix: **every A4 document spilled a sliver onto a second page.** The "Download as PDF" button captures the page as shown, and the sheet the designs lay out is exactly A4 — but the capture was given only 288mm of each 297mm page, because a 9mm strip was reserved for the page label. The last 9mm of the sheet, blank or not, became page two. One sheet is now one page; the label for a genuinely multi-page file is drawn inside the sheet's own bottom margin.
234 * Fix: the Creative design drew a sheet about 200px taller than the A4 page it sits on, so even a one-line invoice captured as two pages. Its spacing scale is compressed on the card; the design keeps its proportions.
235 * Fix: where a page's capture stopped short of the foot of the sheet — the last page, or one that broke early at a row — the rest of the page was left unpainted, which some readers show as a black band. Every page is painted white first.
236 * Fix: **PDFs broke onto a second page while a third of the first page sat empty.** Six of the nine designs lay themselves out on a rem spacing scale sized for a screen, and that scale reached the PDF untouched: the print stylesheet sits in the document head, while each design declares its own values further down, so the design always won. The print sheet's values now take precedence, and the spacing scale, display type, line spacing, meta rows and the wrappers between sections are all compressed for paper. A six-line invoice that took two pages in eight of the nine designs now fits on one in all nine; long documents still break where they should and the items table repeats its header.
237
238 = 2.4.2 - September 29, 2026 =
239 * Fix: the invoice and quote builders could fatal instead of rendering when the preview ran before a document existed; the preview now shows a placeholder until there is something to draw.
240 * Fix: **a PayPal payment smaller than the invoice total no longer marks the invoice paid.** When PayPal confirmed less than was requested, the pending record was flipped to "completed" before its amount was corrected, so anything reading the payment at that moment still saw the full balance. The settled amount is written first; the invoice lands on Partially paid with the real balance owed.
241 * Fix: the plugin's own sidebar logo rendered as an empty coloured square — `wp_kses_post()` strips `<svg>`. The mark (and any logo the White-Label addon substitutes) now goes through an SVG-aware allow-list.
242 * Change: the WordPress admin menu uses the plugin's own icon instead of a generic dashicon, drawn so WordPress recolours it with the admin colour scheme.
243 * Fix: **offline payments work in the free plugin.** Choosing "Manual Payment" on an invoice showed no instructions, no receipt upload and recorded nothing — the pieces existed but were never wired together. Bank transfer, cheque and cash are now three proper payment methods: each shows your details and instructions, can ask for the client's transaction reference and a receipt (optional or required), and records a pending payment for you to confirm.
244 * New: **add your own offline payment methods** (ACH, wire transfer, mobile money, a second bank account…) under Settings → Payment Methods → "Add an offline payment method". Each gets its own instructions, reference field and receipt setting, appears in the Pay Now panel, and can be removed again; payments already recorded keep it.
245 * New: **confirm or reject** each submitted offline payment from the Payments screen. The client's reference, note and receipt are shown on the payment row and the payment page; the admin email carries them too. Confirming marks that payment completed and moves the invoice to Paid or Partially paid by its real balance (it used to mark the invoice paid whatever the amount); rejecting keeps the record for the audit trail and leaves the balance owed. The client sees "payment noted — awaiting confirmation" on the invoice page meanwhile.
246 * Security: receipts are stored under random names in a folder that refuses direct requests on Apache, and are only ever served to signed-in staff through the plugin (`admin-post.php?action=easy_invoice_payment_proof`). Receipts are deleted with their payment and on a full uninstall.
247 * Fix: the Payments screen's "Total amount" counted submissions still awaiting confirmation and rejected payments as money received; it now sums confirmed payments only. The status filter gained "Awaiting confirmation" and "Rejected".
248 * Fix: the free payment reminder never ran (it looked for a status nothing writes). Settings → Advanced → "Payment reminder (days after due date)" now emails the Reminder template once to each invoice still owed that many days after its due date; leave it empty to switch it off. Easy Invoice Pro's own reminders take over when Pro is active.
249 * Fix: an invoice whose payment methods were limited to "Manual Payment" before this release now offers the three offline methods instead of nothing.
250 * Change: a brand-new install starts with Bank transfer enabled, so an invoice can be paid from day one; a client can have at most three offline submissions awaiting confirmation on one invoice (filter `easy_invoice_offline_pending_limit`).
251
252 = 2.4.1 - September 15, 2026 =
253 * Fix: on phones the public invoice and quote pages clipped the line-item table's Total column and, in the Modern, Creative and Professional designs, the totals box; every design now fits a 360px screen (narrower screens scroll the table sideways).
254 * Performance: the payment script (and the jQuery it needs) loaded on every front-end page of the site; it now loads on the public invoice page only. Filter `easy_invoice_load_payment_assets` to add pages.
255 * Housekeeping: the changelog in this file now summarises each release; the complete, itemised history lives in changelog.txt inside the plugin folder and on GitHub.
256
257 = 2.4.0 - September 11, 2026 =
258 A large release; read the upgrade notice before updating. The full, itemised list (about 190 entries) is in changelog.txt.
259
260 **Security**
261 * Invoices and quotes were readable, and enumerable, by anyone with the URL, including drafts. Every document now needs a per-document access key (`?ik=` / `?qk=`) carried by emailed links, a signed-in client, or an admin. Links emailed before keys existed show a page offering to email a fresh keyed link to the address the document was issued to; nothing is shown and drafts are never offered.
262 * Payment endpoints, PDF-download nonces, the payment callback, proof-of-payment file names and the migration "skip" link all authorise properly; Pro card gateways no longer bypass the authorisation check. Stored XSS through a client's profile into the builders fixed. Every output is escaped at the point it is printed; all redirects go through `wp_safe_redirect`.
263
264 **New**
265 * Server-side PDF rendering (dompdf, now bundled): real, text-based PDFs in every design, A4 / Letter / Legal, optional PDF attachment on invoice emails, page numbers on multi-page documents.
266 * Credit notes against issued invoices, statements of account per client, and issued invoices can no longer be deleted permanently (trash still works).
267 * REST API at `easy-invoice/v1` (invoices, quotes, clients, PDF download), authenticated and capability-checked; responses never expose access keys.
268 * Cross-border tax: reverse charge and export handling, VAT identifiers for both parties with VIES checking, EN 16931 tax categories.
269 * Import from Sliced Invoices, Sprout Invoices and CSV. Attachments from the media library on invoices and quotes. Client-view tracking (first and latest view, count). Convert-to-invoice on each quote row. Clients search box. Uninstall routine that keeps your data unless told otherwise.
270 * New hooks and filters for addons: `easy_invoice_quote_total`, `easy_invoice_presented_access_token`, `easy_invoice_reports_after_summary`, `easy_invoice_email_headers`, `easy_invoice_client_view_after_details`, `easy_invoice_credit_note_actions`, `easy_invoice_text_setting` and others.
271
272 **Documents and designs**
273 * Every invoice and quote design reset and tidied; the public page is a real WordPress page laid out as an A4 sheet, themeable from `{theme}/easy-invoice/`. "Total Due" in every header; Credit note / Paid / Balance due rows once anything is paid; the "To" block names the contact, phone and VAT number; totals rows read in calculation order; the Legacy design prints Terms & Conditions; Minimal quote markup fixed.
274 * Stock emails rewritten as plain business correspondence; receipts and payment notices correct for partial payments; "Test Template" works; emails sign off with the business name.
275
276 **Fixes (selection)**
277 * Correctness: duplicate invoice, quote and credit-note numbers under concurrent use; negative totals from oversized discounts; line amounts that did not add up to the subtotal; dates defaulting to UTC instead of the site's timezone; taxable state of new lines; "Apply Tax" that could not be switched off; quotes that never expired; acceptance and decline details never saved; quote conversion producing empty lines; customer details dropped on save; attachments that could not be removed.
278 * Payments: overdue and part-paid invoices could not be paid from their page; a part-paid or credited invoice asked for the full amount again; PayPal IPN left invoices unpaid; bank transfer, cheque and cash from emailed links were refused; "Add New Payment" could not record a payment; trashing or restoring payments left the invoice status untouched; failed or refunded payments put issued invoices back to Draft.
279 * Admin: team members could not open any screen; the admin was unusable on phones; Dashboard Edit/View links, the invoice list status filter, Reports totals and date ranges, the "Delete client only" option (it deleted the documents), settings image fields, colours that never rendered, sideways-scrolling lists, keyboard and touch access to row actions, about 140 untranslatable strings.
280 * Performance: invoice totals are stored (dashboard, lists, reports and statements no longer rebuild every model); admin screens that took 30–40 s on a few thousand invoices open in under a second; the Overdue filter, Add Payment picker and payments totals answered from single queries (10,000-invoice stores: 19 s → 3 s); rewrite rules no longer flushed on every request; the admin loads 47 KB of CSS instead of 2.8 MB.
281 * Packaging: all CDN assets (jsPDF, html2canvas, Chart.js, Select2) bundled; Composer dependencies resolved for PHP 7.4; dead classes, duplicate AJAX registrations and an endpoint that fataled removed; addon descriptions corrected to what is actually implemented.
282
283 = 2.3.8 - August 21, 2026 =
284 * Compatibility - **Tested and confirmed compatible with WordPress 7.1.** "Tested up to" bumped from 7.0. The release was audited against the 7.1 codebase rather than smoke-tested: every WordPress function the plugin calls was resolved against the 7.1 symbol table (no removed or renamed API is used), the plugin's global function, class and constant names were diffed against the 92 functions and 5 classes 7.1 introduces (no redeclaration collisions), and the full plugin tree was scanned with PHPCompatibility for PHP 7.4 through 8.4 (zero issues).
285 * Compatibility - **jQuery UI 1.14.2** ships in WordPress 7.1 (up from 1.13.3). The payment-gateway drag-to-reorder list on Settings -> Payment uses `.sortable()` and `.disableSelection()`; both remain available because core enables `jQuery.uiBackCompat` and still bundles the disable-selection module. The four APIs 1.14 removed (`$.fn._form`, `$.ui.ie`, `$.ui.safeActiveElement`, `$.ui.safeBlur`) are not used anywhere in the plugin.
286 * Compatibility - **The enforced iframed post editor in 7.1 does not affect Easy Invoice.** Invoices and quotes are edited through the plugin's own admin screens; their post types register with `show_ui => false` and the one UI-visible post type does not declare `editor` support, so no plugin JavaScript or CSS reaches across the editor document boundary.
287 * Compatibility - Admin styling verified against 7.1 markup: the `#adminmenu`, `#adminmenuwrap`, `#adminmenuback`, `#wpcontent`, `#wpbody-content` and `#wpfooter` containers the plugin restyles are all still emitted by `wp-admin/admin-header.php` and `menu-header.php` in 7.1, and the persistent admin toolbar change touches `#wpadminbar`, which the plugin does not style.
288 * Compatibility - The REST and media changes in 7.1 (image dimension validation on the sideload endpoint, size-aware encoding quality in attachment responses) are not applicable: the plugin's REST routes are its own (no media, sideload or attachment endpoints) and it calls no attachment or sideload APIs.
289 * Fixed - **Payment-gateway drag-to-reorder relied on incidental script ordering.** The `easy-invoice-settings` script handle is registered in two different places, and WordPress keeps whichever registration runs first while silently discarding the other's dependency array. The registration that wins did not list `jquery-ui-sortable`, so `settings.js` was printed ahead of jQuery UI Sortable and only worked because its code runs inside a DOM-ready callback. The jQuery UI handles are now declared explicitly on that registration, so `wp_scripts` resolves the load order instead of it falling out of enqueue sequence - worth tightening now that 7.1 ships a new jQuery UI build.
290
291 = 2.3.7 - June 29, 2026 =
292 * Fixed - **Invoice and Quote listing "Download PDF" button** could leave the user stranded on a blank `admin-ajax.php?action=easy_invoice_generate_pdf...` page instead of downloading the PDF. Root causes on affected sites included page-cache layers (WP Rocket, LiteSpeed, Cloudflare) replaying stale responses of the intermediate admin-ajax URL, security plugins / WAFs stripping the redirect body, and cross-tab session-cookie behaviour (Safari ITP, `SameSite=Strict`) dropping the WP session between the click and the new tab. Two coordinated changes address this:
293 1. **The button no longer routes through admin-ajax.** The anchor's native href already points directly at `<invoice-permalink>?auto_download_pdf=1`, and the single-page JS renders the PDF from there. Removing the click interceptor collapses three server round-trips into one and sidesteps every intermediate-hop failure mode. No security posture change — the destination is the same public permalink the hop was going to anyway.
294 2. **The server-side download handlers are hardened for any external caller.** `generateInvoicePdf` and `generateQuotePdf` now accept an admin session or a valid per-document access key (`?ik=` / `?qk=`) as alternate authorisation paths when the per-request nonce fails, emit explicit `Cache-Control: no-store` headers to defeat intermediate caching, and fall back to a client-side redirect (`<meta refresh>` + `window.location.replace`) when the server-side redirect can't fire because upstream output already flushed the response headers. Email download links, dashboard widgets, and any other integration calling these endpoints directly benefit from the same hardening.
295
296 = 2.3.6 - June 26, 2026 =
297 * Security - Tightened the capability check on the AJAX payment-update endpoint so only users with the dedicated payment-management permission can change payment records or invoice status. **All sites should update.**
298 * Security - The `[easy_invoice_url]` and `[easy_quote_url]` shortcodes no longer generate per-document access keys for arbitrary visitors. Keys are now produced only when an invoice or quote email is sent; the shortcodes attach an existing key only when the current viewer is the site admin, the bound client, or already holds the key in the page URL.
299 * Fixed - The bound-client authorisation path on quote Accept / Decline and invoice manual-payment submission silently never succeeded for logged-in customers. The guard relied on PHP's `method_exists()` which returns false for `__call`-resolved methods, and both the Invoice and Quote models resolve `getClientId()` that way. Logged-in clients whose email matches the document's bound client are now correctly recognised. (Admin and emailed-link paths were unaffected.)
300 * Note - Emailed `{{invoice_url}}` and `{{quote_url}}` links continue to work unchanged for the legitimate recipient. The shortcode change is invisible for admin embeds on admin-context pages; on public pages the shortcode now renders a plain permalink for visitors who don't already hold a valid key (they can still view the document — only the Accept / Decline / submit-manual-payment paths require the key).
301
302 = 2.3.5 - June 26, 2026 =
303 * Security - Hardened authorisation on the manual-payment submission flow. **All sites should update.**
304 * Improved - Invoice share links emailed to clients (`{{invoice_url}}` in email templates, `[easy_invoice_url]` shortcode) now carry a per-invoice access key. Recipients of these links can submit "I paid by bank transfer / cheque" entries as before — no extra steps for the customer.
305 * Note - Invoice links generated **before** this update will still load and display the invoice and accept online gateway payments (Stripe / PayPal / etc.). The manual-payment submission form appears only after the admin resends the invoice (which produces a new link) or after the client logs in to the WordPress account whose email matches the invoice's bound client. Admins are unaffected — the form is always available from the admin UI.
306 * Fixed - Race condition under high concurrency where two simultaneous invoice (or quote) creates could be assigned the same number. The counter read-check-write is now serialised via a MySQL named lock; the lock auto-releases on connection close so it cannot leak across requests.
307 * Added - License recognition for the new Professional Lifetime and Agency Lifetime SKUs so customers on those plans are correctly placed in their tier and see the matching variant label on the License page.
308
309 Older releases (2.3.4 back to 1.0) are listed in changelog.txt inside the plugin folder and at https://github.com/matrixaddons/easy-invoice/blob/master/changelog.txt.
310
311 == Upgrade Notice ==
312
313 = 2.4.4 =
314 Fixes quote acceptance redirecting clients to a signed "secure link" on sites that never enabled Secure Links.
315
316 = 2.4.3 =
317 PDFs no longer break onto a second page with the first one only part full: the designs are now spaced for paper as well as for the screen.
318
319 = 2.4.2 =
320 Offline payments (bank transfer, cheque, cash) now work end to end, with receipts and a confirm/reject step. Also fixes a PayPal payment smaller than the total marking an invoice paid. Coming from 2.3.x? Read the 2.4.0 notice and back up first.
321
322 = 2.4.1 =
323 Small follow-up to 2.4.0: public documents fit phone screens in every design, and the payment script no longer loads on every front-end page. If you are coming from 2.3.x, read the 2.4.0 notice below and back up first.
324
325 = 2.4.0 =
326 Large release: invoice and quote links now need a per-document access key (old links get a page offering a fresh one); issued invoices can only be trashed; PDFs render on the server; public pages are real WordPress pages (theme overrides: {theme}/easy-invoice/). Update Pro to 2.3.0. Back up first.
327
328 = 2.3.9 =
329 Security release: invoices and quotes were readable and enumerable by anyone with a URL; access is now checked before anything is rendered. Update as soon as possible.
330
331 = 2.3.8 =
332 WordPress 7.1 compatibility release. Verified against the 7.1 codebase and PHP 7.4-8.4, plus a fix for payment-gateway drag-to-reorder script ordering on the Settings screen.
333
334 = 2.1.9 =
335 Important update fixing vendor dependencies. Recommended for all users.
336
337 = 2.0.0 =
338 Major version update with significant improvements. If upgrading from 1.x, please backup your site and run the migration tool when prompted.
339