=== VanBlaisa Review Intelligence Lite ===
Contributors: vanblaisa
Tags: reviews, testimonials, google reviews, schema, review form
Requires at least: 6.0
Tested up to: 7.0
Requires PHP: 8.0
Stable tag: 1.0.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Collect, moderate, analyse and publish locally owned reviews, plus display connected Google Maps reviews live without storing their content in WordPress.

== Description ==

VanBlaisa Review Intelligence Lite is a standalone review-management, intelligence and display plugin. Add unlimited locally owned reviews manually, collect moderated website submissions, and publish responsive local-review displays with `[vanblaisa_reviews]`.

An optional Google Connected Reviews display uses `[vanblaisa_google_reviews]` to retrieve reviews live in the visitor's browser through Google Maps. Google review content is not imported into WordPress posts, options, transients or schema. Local reviews and Google reviews remain visibly and technically separate.

The Dashboard includes a deterministic Review Intelligence Snapshot and Schema Safety Inspector. These diagnostics evaluate only locally owned WordPress review records for freshness, source coverage, moderation health, display coverage and conservative schema eligibility. They do not analyse or store Google review content and do not use AI, telemetry or a VanBlaisa account.

The Display Builder includes four complete presentations. The saved preset, colours, spacing, typography, responsive columns and slider behaviour apply to both the local and connected Google review shortcodes:

* Trust Grid
* Clean Cards
* Review Spotlight
* Compact Carousel

Every accepted website submission enters Pending moderation. Pending, draft, trashed and legacy Google-import records are excluded from public local-review displays and conservative Review JSON-LD schema. Schema can be disabled and does not guarantee search-engine rich results.

No VanBlaisa account, licence, automatic App registration, telemetry or default public VanBlaisa attribution is required.

Lite information: https://vanblaisa.com/

Support and documentation: https://support.vanblaisa.com/

Commercial Review Intelligence Engine information: https://vanblaisa.com/vanblaisa-review-intelligence-engine/

== External services ==

= Google Maps JavaScript API and Places library =

The optional Google Connected Reviews feature uses the Google Maps JavaScript API and its Places library to retrieve and display Google Maps reviews for one administrator-configured Place ID.

The site administrator supplies and stores a Google Maps browser API key and a Place ID. A browser key is included in the page markup on pages containing the configured Google review shortcode and is used only if the Google review display is loaded. Administrators must use a browser key restricted to authorised HTTP referrers for their website. The Google Cloud project must have Maps JavaScript API, Places API and Places API (New) enabled, with billing active, and the key should be restricted to those APIs.

Click-to-load is the default mode. In this mode, no Google request is made until a visitor chooses to load the connected reviews. Administrators may deliberately enable automatic loading after acknowledging that Google will be contacted when the display loads.

When the display loads, the visitor's browser connects directly to Google. The request includes the browser API key, Place ID and ordinary network/request information available to Google, such as the visitor's IP address, browser or user-agent information, page/referrer information and request timing. Google returns the available Place and review fields directly to that browser for the current page session.

The plugin does not send the returned Google review payload back to WordPress and does not store Google-supplied review text, ratings, authors, author images, dates, source links, place names, aggregate ratings, attributions or response payloads in posts, post meta, options, transients, files, logs or browser storage. Google reviews are displayed separately from locally owned reviews and are excluded from local moderation, intelligence, aggregate ratings and schema.

Google controls service availability, returned content, billing and quotas. The integration displays Google Maps attribution, required author attribution, optional author/profile/review links when Google supplies them, and third-party Place attribution returned by Google.

Google Maps Platform Terms: https://cloud.google.com/maps-platform/terms

Google Places policies and attribution requirements: https://developers.google.com/maps/documentation/places/web-service/policies

Google Privacy Policy: https://policies.google.com/privacy

== Privacy ==

Public-form submissions are stored on the WordPress site for moderation. If the optional email field is enabled, its value is stored as protected, non-public review metadata and is visible only to authorised administrators. It is never included in public review markup, schema or telemetry. Abuse throttling uses a salted one-way HMAC and does not retain the raw source IP address solely for rate limiting.

Google Connected Reviews is optional. With the default click-to-load mode, the visitor sees a local notice before their browser contacts Google. Automatic mode causes Google to be contacted when a configured Google review display loads. Site owners remain responsible for configuring their privacy and consent systems appropriately.

No local or Google review data is transmitted to VanBlaisa by Lite. See the included privacy and services documentation for more detail.

== Installation ==

1. Upload the `vanblaisa-review-intelligence-lite` folder or install the ZIP in WordPress.
2. Activate VanBlaisa Review Intelligence Lite. No registration or licence is required.
3. On multisite, activate the plugin separately on each site. Network-wide activation is intentionally blocked.
4. Open Review Intelligence → Dashboard.
5. Add local reviews manually or enable the moderated public form.
6. Open Display Builder, choose a preset, configure the shared visual presentation and save it.
7. Add `[vanblaisa_reviews]` to a page or post.
8. Optionally configure Google Connected Reviews and add `[vanblaisa_google_reviews]` to a page. The standard `[vanblaisa_reviews]` shortcode displays locally owned reviews only.

== Shortcodes ==

* `[vanblaisa_reviews]` — locally owned reviews using the saved Display Builder configuration.
* `[vanblaisa_reviews preset="clean-cards" count="8"]` — explicit local-review preset and count.
* `[vanblaisa_reviews_grid]` — Trust Grid alias.
* `[vanblaisa_reviews_list]` — Trust Grid-compatible legacy alias.
* `[vanblaisa_reviews_slider]` — Review Spotlight alias.
* `[vanblaisa_reviews_carousel]` — Compact Carousel alias.
* `[vanblaisa_review_form]` — standalone public review form.
* `[vanblaisa_google_reviews]` — separate live Google Maps review display using the same saved visual configuration while retaining mandatory Google attribution.

When public submissions are enabled, the form can also be placed above or below a local Card or Slider display from Display Builder. It is never injected globally.

== Frequently Asked Questions ==

= What happens when there are no reviews to display? =

The Display Builder includes an Empty review state section. Choose a message, a message with a CTA button, an inline moderated review form, or hide the empty block. CTA mode accepts a full HTTPS destination or an on-page anchor. Form mode requires public submissions to be enabled. The same fallback is used when Google Maps returns no displayable connected reviews.

= Why does the Display Builder preview match the public display? =

The preview runs in an isolated browser frame using the same frontend CSS, JavaScript, renderer classes and responsive viewport rules as the public shortcodes. Use Published local reviews, Sample local reviews, Sample Google reviews and Empty state to verify each presentation. Google-required author and source attribution remains visible even when local-only visibility controls are disabled.


= Is an account or licence required? =

No. Lite works without registration, a licence, Product Manager or the VanBlaisa Intelligence App.

= Are public submissions published automatically? =

No. They are stored as Website submissions in Pending moderation. An authorised administrator must publish them.

= Does Lite import or permanently store Google reviews? =

No. Google Connected Reviews retrieves available reviews live in the visitor's browser and displays them in a separate Google-attributed container. The review payload is not imported into WordPress or included in local schema, aggregate ratings or intelligence.

= When does a visitor's browser contact Google? =

Click-to-load is the default. Google is contacted only after the visitor clicks the load button. A site administrator can deliberately select automatic loading after acknowledging the external request. The `vbril_google_reviews_can_load` filter can be used to integrate with a consent-management system.

= Is the Google browser API key secret? =

No. A browser key is included in the page markup on pages containing the configured Google review shortcode and is sent to Google only when the display is loaded. Restrict it in Google Cloud to authorised website referrers and only the required APIs.

= Does the public form support multiple instances? =

Yes. Each form has unique control and honeypot IDs while retaining the server-recognised nonce field name.

= What schema does Lite output? =

Lite offers one conservative Review JSON-LD mode using eligible, locally owned, published reviews only. Demonstration, pending, draft, trashed, legacy Google-import and live Google Connected Reviews never enter schema. Schema does not guarantee rich-result eligibility.

= What do the dashboard diagnostics do? =

The Review Intelligence Snapshot and Schema Safety Inspector evaluate only locally stored review records and current Lite settings. They are deterministic, cached briefly, and do not use AI, telemetry or remote scoring.

= Does Lite support multisite network activation? =

No. Version 1.0.1 must be activated separately on each site so review data, permissions and migration remain site-specific. Network-wide activation is blocked with an explanatory message.

= What is included in Pro? =

The Lite versus Pro page explains managed Google Business Profile OAuth workflows, owner replies, advanced presets, deeper intelligence, automation, reporting, agency tools and Intelligence App integration. Lite remains functional without upgrading.

= What happens if I uninstall Lite? =

Deactivation never deletes data. Uninstall retains data by default. When the administrator enabled the explicit delete-data option beforehand and the commercial edition is not active, uninstall permanently deletes Lite-owned local reviews, exact legacy Lite Google-import records and Lite-owned settings, including trashed reviews. Unknown commercial-edition records and settings are retained.

== Screenshots ==

1. Dashboard and local Review Intelligence Snapshot.
2. Local Review Library with reviewer, rating, source, date and moderation status.
3. Display Builder with renderer-backed local and Google desktop, tablet and mobile preview.
4. Trust Grid and Clean Cards responsive Card presentations.
5. Review Spotlight and Compact Carousel Slider presentations.
6. Public review form with pending moderation.
7. Google Connected Reviews configuration and live browser-only display.
8. Schema Safety Inspector for eligible local reviews.

== Changelog ==

= 1.0.1 =
* Renamed the plugin to VanBlaisa Review Intelligence Lite and migrated WordPress-visible identifiers to the VBRIL prefix.
* Replaced permanent Google review importing with a separate live Google Maps review display that does not store Google review content in WordPress.
* Added click-to-load privacy controls, Google attribution and available source links for connected Google reviews.
* Improved Google browser-key diagnostics and compatibility when Google omits optional individual-review links.
* Rebuilt the Display Builder preview in an isolated responsive frame using the exact public renderer, CSS and JavaScript.
* Added verified, dedicated Display Builder persistence so saved styles survive reloads and remain protected from shared legacy/settings-option overwrites.
* Unified connected Google review cards with the saved Display Builder preset, colours, spacing, typography, responsive columns and carousel styling, including a no-network Google sample preview.
* Added configurable empty-review fallbacks: message, CTA button, moderated review form or hidden output for local and connected Google review displays.
* Restricted review administration and non-public review data to administrators and enforced publish capabilities.
* Guarded multisite network activation and completed opt-in uninstall cleanup, including trashed reviews.
* Completed nonce, capability, external-service disclosure and WordPress.org compliance corrections.

= 1.0.0 =
* Final 1.0.0 release candidate with the frontend warning fix, finalized review intelligence snapshot, schema safety inspector, conservative schema parity, and completed public-form hardening.

= 0.1.0-rc2 =
* Centralised complete preset resolution for builder preview, saved displays, explicit shortcodes and aliases.
* Removed legacy review-count precedence and added a safe settings migration.
* Preserved independent unsaved working drafts for all four presets during a builder session.
* Hardened Review Spotlight, Compact Carousel, multiple forms, private email handling and configured success messages.
* Polished mobile Review Library navigation and expanded documentation and privacy disclosures.
* Internal release candidate for human review; not a final WordPress.org release.

= 0.1.0-rc1 =
* Initial isolated Lite validation candidate. Not submitted to WordPress.org.
