{"id":288086,"date":"2026-03-26T20:11:30","date_gmt":"2026-03-26T20:11:30","guid":{"rendered":"https:\/\/en-gb.wordpress.org\/plugins\/kitgenix-document-manager\/"},"modified":"2026-08-31T19:30:36","modified_gmt":"2026-08-31T19:30:36","slug":"kitgenix-document-manager","status":"publish","type":"plugin","link":"https:\/\/tt.wordpress.org\/plugins\/kitgenix-document-manager\/","author":23310025,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.0.0","stable_tag":"2.0.0","tested":"7.1","requires":"6.0","requires_php":"8.1","requires_plugins":null,"header_name":"Kitgenix Document Manager","header_author":"Kitgenix","header_description":"Manage document downloads with stable links, version history, and private file access.","assets_banners_color":"030e48","last_updated":"2026-08-31 19:30:36","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/www.paypal.com\/donate\/?hosted_button_id=KALF36K6JJ9B2","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/kitgenix-document-manager\/","header_author_uri":"https:\/\/kitgenix.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":401,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"kitgenix","date":"2026-03-26 20:11:39","revision":3492128},"1.1.0":{"tag":"1.1.0","author":"kitgenix","date":"2026-05-07 13:17:53","revision":3525572},"1.1.3":{"tag":"1.1.3","author":"kitgenix","date":"2026-05-26 19:53:19","revision":3549711},"2.0.0":{"tag":"2.0.0","author":"kitgenix","date":"2026-08-31 19:30:36","revision":3674872}},"upgrade_notice":{"2.0.0":"<p>Adds signed-link limits\/revocation, lifecycle states and scheduling events, redesigned administration, HTTP Range downloads, stronger attachment-access protection, and additional security hardening. Review the server-protection notes if you use Nginx or existing Media Library files.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3674872,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3674872,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3674872,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3674872,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.1.0","1.1.3","2.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3674872,"resolution":"1","location":"assets","locale":"","width":1928,"height":1098},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3674872,"resolution":"2","location":"assets","locale":"","width":1920,"height":5820},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3674872,"resolution":"3","location":"assets","locale":"","width":1920,"height":1690},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3674872,"resolution":"4","location":"assets","locale":"","width":1920,"height":1776},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3674872,"resolution":"5","location":"assets","locale":"","width":1920,"height":2856},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3674872,"resolution":"6","location":"assets","locale":"","width":1922,"height":1176},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3674872,"resolution":"7","location":"assets","locale":"","width":1189,"height":556}},"screenshots":{"1":"Document library management with stable links, lifecycle status, visibility, file information, search, and filters.","2":"Add\/Edit Document controls for description, visibility, access presets, roles, capabilities, specific users, signed sharing, schedules, and versioning.","3":"Batch Upload for creating multiple document records with shared visibility, category, and versioning defaults.","4":"General Settings for allowed file types, default visibility, serving mode, version behaviour, and import\/export.","5":"Frontend settings.","6":"Shortcode Builder for document links\/cards and card presentation options.","7":"Frontend document-card output with preview\/icon, title, optional description, file metadata, and action button."}},"plugin_section":[],"plugin_tags":[1912,24392,12813,12683,142836],"plugin_category":[],"plugin_contributors":[246171],"plugin_business_model":[],"class_list":["post-288086","plugin","type-plugin","status-publish","hentry","plugin_tags-access-control","plugin_tags-document-library","plugin_tags-document-management","plugin_tags-file-sharing","plugin_tags-secure-downloads","plugin_contributors-kitgenix","plugin_committers-kitgenix"],"banners":{"banner":"https:\/\/ps.w.org\/kitgenix-document-manager\/assets\/banner-772x250.png?rev=3674872","banner_2x":"https:\/\/ps.w.org\/kitgenix-document-manager\/assets\/banner-1544x500.png?rev=3674872","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/kitgenix-document-manager\/assets\/icon-128x128.png?rev=3674872","icon_2x":"https:\/\/ps.w.org\/kitgenix-document-manager\/assets\/icon-256x256.png?rev=3674872","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/kitgenix-document-manager\/assets\/screenshot-1.png?rev=3674872","caption":"Document library management with stable links, lifecycle status, visibility, file information, search, and filters."},{"src":"https:\/\/ps.w.org\/kitgenix-document-manager\/assets\/screenshot-2.png?rev=3674872","caption":"Add\/Edit Document controls for description, visibility, access presets, roles, capabilities, specific users, signed sharing, schedules, and versioning."},{"src":"https:\/\/ps.w.org\/kitgenix-document-manager\/assets\/screenshot-3.png?rev=3674872","caption":"Batch Upload for creating multiple document records with shared visibility, category, and versioning defaults."},{"src":"https:\/\/ps.w.org\/kitgenix-document-manager\/assets\/screenshot-4.png?rev=3674872","caption":"General Settings for allowed file types, default visibility, serving mode, version behaviour, and import\/export."},{"src":"https:\/\/ps.w.org\/kitgenix-document-manager\/assets\/screenshot-5.png?rev=3674872","caption":"Frontend settings."},{"src":"https:\/\/ps.w.org\/kitgenix-document-manager\/assets\/screenshot-6.png?rev=3674872","caption":"Shortcode Builder for document links\/cards and card presentation options."},{"src":"https:\/\/ps.w.org\/kitgenix-document-manager\/assets\/screenshot-7.png?rev=3674872","caption":"Frontend document-card output with preview\/icon, title, optional description, file metadata, and action button."}],"raw_content":"<!--section=description-->\n<p><strong>Kitgenix Document Manager<\/strong> is a WordPress document management and document library plugin for publishing, protecting, replacing, sharing and tracking downloadable files. It adds a managed document layer around WordPress attachments so a document can keep one stable URL while the physical file behind it changes over time.<\/p>\n\n<p>This is useful for policy documents, product manuals, technical downloads, specification sheets, price lists, application forms, certificates, reports, staff resources, membership files and other documents that need more control than a raw Media Library URL.<\/p>\n\n<p>A published document uses a stable route similar to:<\/p>\n\n<pre><code>\/kitgenix-document-manager\/{slug}\/\n<\/code><\/pre>\n\n<p>Replace the current attachment later and the document route can remain the same, so old links in pages, emails, QR codes, bookmarks and external documentation do not need to be replaced.<\/p>\n\n<p>Built by <a href=\"https:\/\/kitgenix.com\/\">Kitgenix<\/a>.<\/p>\n\n<h4>Document Management Features<\/h4>\n\n<ul>\n<li>Stable managed URLs independent of the current physical attachment URL.<\/li>\n<li>Public, Private and Restricted visibility modes.<\/li>\n<li>Access rules using WordPress roles, capabilities and specific user IDs.<\/li>\n<li>Time-limited signed share links for people without a WordPress account.<\/li>\n<li>Optional maximum-use limits on signed links.<\/li>\n<li>Revoke and signing-secret regeneration controls.<\/li>\n<li>Available-from, archive and expiry scheduling.<\/li>\n<li>Optional document version history.<\/li>\n<li>Restore or delete historical versions.<\/li>\n<li>Hierarchical document categories.<\/li>\n<li>Batch upload and bulk administration tools.<\/li>\n<li>Existing Media Library attachment selection.<\/li>\n<li>Frontend document-card and text-link shortcodes.<\/li>\n<li>Admin Shortcode Builder for locating documents and generating markup.<\/li>\n<li>Local aggregate document views\/download analytics.<\/li>\n<li>REST metadata access subject to document permissions.<\/li>\n<li>Single HTTP byte-range support for compatible downloads\/media seeking.<\/li>\n<li>Conditional ETag\/Last-Modified responses for eligible public files.<\/li>\n<li>Attachment access guards for protected managed files.<\/li>\n<li>Site Health test for the dedicated document upload directory.<\/li>\n<li>Settings\/category portability without exporting protected files or share secrets.<\/li>\n<li>Capped local event log for operational diagnostics.<\/li>\n<\/ul>\n\n<h4>Stable WordPress Document Links<\/h4>\n\n<p>The plugin separates the logical document from the current file. Pages and users link to the document's stable endpoint; the document record then decides which attachment is current and whether the requester is allowed to receive it.<\/p>\n\n<p>This model is particularly useful for frequently revised documents. A \"Product Manual\" or \"Terms and Conditions\" link can remain consistent while administrators replace the actual PDF or Office file as revisions are released.<\/p>\n\n<h4>Public, Private and Restricted Documents<\/h4>\n\n<p>Each document has a visibility mode and can also carry more granular rules. Access can be evaluated using WordPress roles, a required capability, explicitly allowed user IDs or a valid signed share link.<\/p>\n\n<p>The same access decision is applied across the managed delivery endpoint and the plugin's own output paths. The code also includes guards designed to prevent protected managed attachments being casually exposed through Media REST responses or normal attachment permalinks to a visitor who does not have document access.<\/p>\n\n<p>For unauthenticated protected requests, the configured behaviour can send the visitor to login or return a forbidden response according to the site setting.<\/p>\n\n<h4>Signed File Sharing<\/h4>\n\n<p>A signed URL can grant temporary access to a protected document without creating a WordPress account for the recipient. Signed links can have an expiry time and an optional maximum-use count.<\/p>\n\n<p>Administrators can revoke a share link or regenerate the document's signing secret. The signature is bound to document-specific values including the current attachment and document slug, so changing the underlying file affects the validity context rather than creating a permanent backdoor to every future version.<\/p>\n\n<h4>Lifecycle Scheduling<\/h4>\n\n<p>Documents can have an <strong>Available from<\/strong> time, an <strong>Archive at<\/strong> time and an <strong>Expires at<\/strong> time. These fields allow a file to become available automatically or to stop normal access without an administrator having to remember the exact campaign\/compliance deadline.<\/p>\n\n<p>The lifecycle layer can represent states such as Draft, Scheduled, Live, Restricted, Archived or Expired. An hourly WordPress cron event checks scheduled documents so state transitions can be observed even when the document is not being requested continuously.<\/p>\n\n<h4>Version History<\/h4>\n\n<p>When versioning is enabled, replacing a document can retain the superseded attachment as a historical version. Version records can include a label or note, and authorised users can restore an older file or delete old versions.<\/p>\n\n<p>Stores\/sites that do not want historical copies can disable version retention and configure replacement behaviour accordingly.<\/p>\n\n<h4>Document Library Organisation<\/h4>\n\n<p>Documents are stored in a private plugin post type and can be grouped with the plugin's hierarchical document-category taxonomy. The plugin's own admin screens provide search and filters for document status, visibility and file type, together with batch upload and bulk actions.<\/p>\n\n<p>Bulk operations can change visibility, assign or clear categories, archive documents, clear lifecycle schedules or move selected documents to the trash depending on the action chosen.<\/p>\n\n<h4>Frontend Shortcodes<\/h4>\n\n<p>A lightweight link can be rendered with:<\/p>\n\n<pre><code>[kitgenix_document_manager_link slug=\"my-document\"]\n<\/code><\/pre>\n\n<p>A card can be rendered with:<\/p>\n\n<pre><code>[kitgenix_document_manager_document slug=\"my-document\"]\n<\/code><\/pre>\n\n<p>The card shortcode can also display several comma-separated document slugs and supports presentation attributes for button labels\/styles, image size, alignment, target behaviour and the visibility of file metadata\/description.<\/p>\n\n<p>Protected documents are not revealed by the shortcode to visitors who fail the document's access rules.<\/p>\n\n<h4>Local Document Analytics<\/h4>\n\n<p>The plugin records aggregate counts for views\/downloads, signed-link usage and recent daily activity in WordPress metadata. It also retains the most recent access timestamp\/type for administrative reporting.<\/p>\n\n<p>The analytics implementation does not create visitor profiles and does not intentionally store visitor IP addresses, user agents, referrers or tracking cookies. Older daily buckets are pruned while cumulative totals remain available.<\/p>\n\n<h4>File Delivery, Range Requests and Caching<\/h4>\n\n<p>Managed files are served through WordPress after access checks. The endpoint supports single byte-range requests, which can help resumable downloads and seeking in compatible browser-displayed content.<\/p>\n\n<p>Eligible public responses can use ETag and Last-Modified revalidation. Protected responses are handled with private\/no-store style cache controls so a shared intermediary is not encouraged to cache restricted content.<\/p>\n\n<h4>REST and Site Health<\/h4>\n\n<p>A plugin REST route can return permitted document metadata by slug. Permission\/access checks still apply; it is not intended as an anonymous route for enumerating protected documents.<\/p>\n\n<p>The Site Health integration checks the dedicated Document Manager uploads directory and can flag directory\/writability problems that would prevent file management from working correctly.<\/p>\n\n<h4>Settings Portability<\/h4>\n\n<p>Administrators can export\/import plugin configuration and document-category structure as JSON. This portability workflow deliberately does not package the document files themselves, signed-link secrets or analytics history.<\/p>\n\n<h4>Typical Uses<\/h4>\n\n<ul>\n<li>Product manuals and technical PDFs that receive frequent revisions.<\/li>\n<li>Policy, compliance and governance documents with expiry dates.<\/li>\n<li>Member-only or staff-only downloads.<\/li>\n<li>Customer documents restricted by WordPress account\/role.<\/li>\n<li>Temporary secure sharing with an external recipient.<\/li>\n<li>Download libraries organised by document category.<\/li>\n<li>Stable links for QR codes, printed brochures and long-lived email templates.<\/li>\n<\/ul>\n\n<h3>REST API and Developer Hooks<\/h3>\n\n<p>The plugin registers this read-only metadata route:<\/p>\n\n<pre><code>GET \/wp-json\/kitgenix-document-manager\/v1\/doc\/{slug}\n<\/code><\/pre>\n\n<p>For an allowed request, the response includes the document slug, title, modified date, visibility, schedule status, lifecycle state, and stable URL. The endpoint applies Document Manager access checks before returning metadata.<\/p>\n\n<p>Available extension points include:<\/p>\n\n<ul>\n<li><code>kitgenix_document_manager_user_has_document_access<\/code> \u2013 provide a custom access decision after the built-in role\/capability\/user checks have been evaluated.<\/li>\n<li><code>kitgenix_document_manager_share_link_url<\/code> \u2013 filter a generated signed share URL.<\/li>\n<li><code>kitgenix_document_manager_rest_document_response<\/code> \u2013 customise an allowed REST metadata response.<\/li>\n<li><code>kitgenix_document_manager_document_served<\/code> \u2013 runs after a document file has been successfully streamed.<\/li>\n<li><code>kitgenix_document_manager_lifecycle_status_changed<\/code> \u2013 runs when the effective lifecycle state changes after an existing state has previously been observed.<\/li>\n<\/ul>\n\n<p>Internal storage uses the private <code>kitgenix_dm_doc<\/code> post type and the hierarchical <code>kitgenix_dm_cat<\/code> taxonomy. These implementation details are provided for developers and should not be treated as permanent public URLs.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>The plugin contains two external-service\/network behaviours that can occur in wp-admin. They are not used to upload or process your document files.<\/p>\n\n<h4>WordPress.org Plugin API<\/h4>\n\n<p>The shared Kitgenix Hub can request public information about Kitgenix plugins from WordPress.org through WordPress core's <code>plugins_api()<\/code> function. These requests are used for information shown in the Kitgenix admin interface and are cached locally with WordPress transients.<\/p>\n\n<p>Data sent: plugin slugs required to look up public plugin-directory information. The plugin does not intentionally include document contents, document access rules, Document Manager analytics, or visitor information in these API lookups.<\/p>\n\n<p>Service: https:\/\/wordpress.org\/plugins\/\nTerms: https:\/\/wordpress.org\/about\/terms\/\nPrivacy: https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<h4>Google Fonts<\/h4>\n\n<p>The Kitgenix admin interface stylesheet imports the Inter and Manrope font families from Google Fonts. When an authorised administrator opens a plugin screen that loads this stylesheet, the administrator's browser may contact <code>fonts.googleapis.com<\/code> and <code>fonts.gstatic.com<\/code> to retrieve font CSS\/files. As with ordinary web requests, Google may receive technical request information such as the requesting IP address and browser\/network headers.<\/p>\n\n<p>Google Fonts is used for admin-interface typography only; it is not required for document delivery and the plugin does not send document files to Google Fonts.<\/p>\n\n<p>Service: https:\/\/fonts.google.com\/\nGoogle Fonts privacy information: https:\/\/developers.google.com\/fonts\/faq\/privacy\nGoogle Terms: https:\/\/policies.google.com\/terms\nGoogle Privacy Policy: https:\/\/policies.google.com\/privacy<\/p>\n\n<p>The plugin includes links to Kitgenix documentation, support, community\/social pages, WordPress.org reviews\/support, and PayPal donation pages. Those destinations are only contacted if an administrator chooses to open the relevant link; Document Manager does not automatically upload document data to Kitgenix.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Kitgenix Document Manager stores its operational data in the site's own WordPress database and uploads directory.<\/p>\n\n<p>Document analytics are aggregate counters and timestamps. The plugin's analytics implementation does not store visitor IP addresses, user agents, referrers, cookies, or a per-visitor identifier.<\/p>\n\n<p>The local activity log stores a timestamp, event context, outcome, a plain-English note, and an optional event code. It is capped at 100 entries. The log does not intentionally store IP addresses or document file contents.<\/p>\n\n<p>Document access configuration may contain WordPress role names, a required capability, and WordPress user IDs selected by the site administrator. Version attribution uses the WordPress attachment author's existing account\/display-name information.<\/p>\n\n<p>Signed sharing stores a per-document secret, expiry information, maximum-use setting, and use counter in WordPress post meta. The signing secret is not included in the settings\/category export.<\/p>\n\n<p>See <strong>External Services<\/strong> for the network connections made by the admin interface.<\/p>\n\n<h3>Support and Development<\/h3>\n\n<p>Documentation and support resources are available from <a href=\"https:\/\/kitgenix.com\/\">Kitgenix<\/a> and from the plugin's WordPress.org support forum.<\/p>\n\n<p>If the plugin is useful to your site, you can also use the Donate link at the top of this readme to support continued maintenance and development.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate <strong>Kitgenix Document Manager<\/strong> through WordPress, or upload the plugin folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Go to <strong>Kitgenix \u2192 Document Manager<\/strong>.<\/li>\n<li>Add a document and upload a permitted file, or select an existing Media Library attachment.<\/li>\n<li>Choose its visibility and, if required, configure role\/capability\/user access, signed sharing, version history, and lifecycle dates.<\/li>\n<li>Copy the stable document link or use one of the included shortcodes on a page or post.<\/li>\n<li>If a stable document URL returns 404 after activation or migration, visit <strong>Settings \u2192 Permalinks<\/strong> and save the page once to refresh rewrite rules.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20replacing%20a%20document%20change%20its%20public%20link%3F\"><h3>Does replacing a document change its public link?<\/h3><\/dt>\n<dd><p>No. The stable document URL points to the document record rather than directly to a particular attachment. Replacing the current file keeps the same stable URL.<\/p><\/dd>\n<dt id=\"can%20i%20restrict%20documents%20to%20logged-in%20users%3F\"><h3>Can I restrict documents to logged-in users?<\/h3><\/dt>\n<dd><p>Yes. Set the document to a protected visibility mode. You can also narrow access using roles, a required capability, or specific user IDs.<\/p><\/dd>\n<dt id=\"can%20i%20share%20a%20protected%20file%20with%20somebody%20who%20does%20not%20have%20an%20account%3F\"><h3>Can I share a protected file with somebody who does not have an account?<\/h3><\/dt>\n<dd><p>Yes. Generate a signed share link with an expiry date. You can optionally set a maximum-use count, revoke the link, or regenerate the signing secret to invalidate previously issued links.<\/p><\/dd>\n<dt id=\"can%20documents%20automatically%20go%20live%20or%20expire%3F\"><h3>Can documents automatically go live or expire?<\/h3><\/dt>\n<dd><p>Yes. Each document can have an available-from time, archive time, and expiry time. Access checks enforce those lifecycle dates across the stable URL, shortcode output, and plugin REST endpoint.<\/p><\/dd>\n<dt id=\"can%20i%20keep%20old%20versions%20when%20i%20replace%20a%20file%3F\"><h3>Can I keep old versions when I replace a file?<\/h3><\/dt>\n<dd><p>Yes. Version history can retain old attachments. Saved versions can have optional labels\/notes and can later be restored or deleted.<\/p><\/dd>\n<dt id=\"can%20i%20display%20several%20documents%20together%3F\"><h3>Can I display several documents together?<\/h3><\/dt>\n<dd><p>Yes. Use the <code>slugs<\/code> attribute on <code>[kitgenix_document_manager_document]<\/code> with a comma-separated list of document slugs.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20support%20pdfs%3F\"><h3>Does the plugin support PDFs?<\/h3><\/dt>\n<dd><p>Yes. PDF is allowed by default and can be served inline when the global serving mode is set to inline. Browser support determines whether a compatible file is displayed or downloaded.<\/p><\/dd>\n<dt id=\"is%20woocommerce%20required%3F\"><h3>Is WooCommerce required?<\/h3><\/dt>\n<dd><p>No. The plugin works without WooCommerce. If WooCommerce is active, the Shop Manager role is granted the Document Manager capability on activation so store managers can be permitted to manage documents.<\/p><\/dd>\n<dt id=\"are%20existing%20media%20library%20files%20fully%20hidden%20from%20their%20original%20url%3F\"><h3>Are existing Media Library files fully hidden from their original URL?<\/h3><\/dt>\n<dd><p>Not necessarily. Existing Media Library attachments remain in their original location. The plugin guards their WordPress REST-media exposure and attachment permalink when access is denied, but an already-known raw uploads URL may still be directly reachable depending on server configuration. See <strong>Security and File Protection<\/strong> above.<\/p><\/dd>\n<dt id=\"what%20is%20included%20in%20settings%20export%2Fimport%3F\"><h3>What is included in settings export\/import?<\/h3><\/dt>\n<dd><p>Plugin settings and document categories. Documents, uploaded files, analytics, and signed-link secrets are intentionally excluded.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20uninstall%20the%20plugin%3F\"><h3>What happens when I uninstall the plugin?<\/h3><\/dt>\n<dd><p>Plugin settings\/log data are removed during uninstall. Document posts and managed attachments are retained by default. If <strong>Delete data on uninstall<\/strong> is enabled before uninstalling, the plugin also deletes its document records and associated current\/version attachments.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.0.0 (31 August 2026)<\/h4>\n\n<ul>\n<li>New: Signed share links now support an optional maximum-use count (0 = unlimited), a one-click \"Revoke link\" action that immediately invalidates the current link, and a \"Regenerate\" action that rotates the signing secret so all previously issued links stop working, even if they have not yet expired. These controls are available from the Documents table, edit modal, and native document editor.<\/li>\n<li>New: Document versions can now include an optional label or note, such as \"2024 policy update\", when replacing a file. The Versions list now also shows who replaced each version and when.<\/li>\n<li>New: Added a unified document lifecycle state \u2013 Draft, Unavailable, Scheduled, Live, Restricted, Archived, or Expired \u2013 displayed as a badge on the Documents table.<\/li>\n<li>New: Added Status, Visibility, and File Type filters to the Documents table alongside the existing search box.<\/li>\n<li>New: Document lifecycle state is now included in the REST metadata endpoint.<\/li>\n<li>New: Added an hourly background lifecycle check that detects state transitions such as a scheduled document becoming live even when nobody visits its link, triggering the new <code>kitgenix_document_manager_lifecycle_status_changed<\/code> hook and a Log tab entry.<\/li>\n<li>New: Added an \"Access preset\" quick-fill control with Public, Logged-in Users, and Administrators Only options above the existing role, capability, and user-ID access fields on Add\/Edit document forms and modals. Presets only pre-fill the existing fields and can still be adjusted before saving.<\/li>\n<li>New: Added \"Archive now\" and \"Clear lifecycle schedule\" bulk actions.<\/li>\n<li>New: Added confirmation prompts before bulk-setting documents to Public or bulk-archiving documents, helping prevent accidental visibility or lifecycle changes.<\/li>\n<li>New: Added a Settings \u2192 Import\/Export card for transferring plugin settings and categories between sites using JSON files. Documents, uploaded files, and analytics are intentionally excluded so private content cannot accidentally be bundled into an export.<\/li>\n<li>New: Added the <code>kitgenix_document_manager_share_link_url<\/code> developer hook for filtering generated signed-share URLs.<\/li>\n<li>New: Added the <code>kitgenix_document_manager_document_served<\/code> developer hook for responding when a document is successfully delivered.<\/li>\n<li>New: Added the <code>kitgenix_document_manager_rest_document_response<\/code> developer hook for customising REST metadata responses.<\/li>\n<li>New: Added the <code>kitgenix_document_manager_lifecycle_status_changed<\/code> developer hook for responding to document lifecycle transitions.<\/li>\n<li>New: Redesigned the admin interface around the shared Kitgenix design system with a sticky topbar and grouped Documents navigation for All Documents, Categories, and Versions.<\/li>\n<li>New: Added in-page settings search with \"\/\" and Cmd\/Ctrl+K keyboard shortcuts.<\/li>\n<li>New: Added a light\/dark theme toggle for the admin interface.<\/li>\n<li>New: Added quick links to the Kitgenix Hub and other Kitgenix plugins from the shared admin topbar.<\/li>\n<li>New: Added a responsive mobile menu for Kitgenix admin navigation on narrower screens.<\/li>\n<li>New: Added Image Optimizer to the Kitgenix Hub and updated the MultiStore listing to its new \"MultiStore for WooCommerce\" name.<\/li>\n<li>Improved: Stable document links now support HTTP Range requests for resumable downloads, PDF\/video seeking, and download managers.<\/li>\n<li>Improved: Valid single-range requests now return HTTP 206 responses with the appropriate <code>Content-Range<\/code> header.<\/li>\n<li>Improved: Malformed or multi-range requests safely fall back to a full response, while out-of-bounds ranges return HTTP 416.<\/li>\n<li>Improved: Large document files continue to stream from local disk in fixed-size chunks rather than being loaded entirely into PHP memory.<\/li>\n<li>Improved: Reordered the Documents tab so the All Documents list is displayed full-width at the top, with Add Document and Batch Upload moved into stacked full-width cards below instead of the previous cramped two-column layout.<\/li>\n<li>Improved: Redesigned settings and document forms with toggle switches replacing checkboxes, clearer field labels and descriptions, and consistent card headers throughout the admin interface.<\/li>\n<li>Improved: Unified toast notifications, collapsible cards, copy-to-clipboard controls, and table search behaviour through the shared Kitgenix component library.<\/li>\n<li>Improved: The Log tab now displays entries in a searchable, paginated table containing time, context, outcome, and a plain-English note instead of a plain text block.<\/li>\n<li>Improved: Failed document uploads and replacements now report the specific underlying cause, including missing permissions, disk or filesystem permission problems, disallowed file types, and database errors, instead of displaying one generic \"upload failed\" message.<\/li>\n<li>Improved: Upload and replacement failures are now recorded in the Log tab for easier diagnosis.<\/li>\n<li>Improved: Rejected signed document links now distinguish between expired links, links issued before a security-key rotation, and genuinely tampered or invalid links.<\/li>\n<li>Improved: Expired and pre-rotation links are treated as routine conditions requiring a new link, while invalid or tampered links are logged as genuine security concerns.<\/li>\n<li>Improved: Added a reference table to the Log tab explaining what each recorded category means and whether administrator action is required.<\/li>\n<li>Improved: The Support tab is now three focused cards \u2013 a donate card with a collapsible monthly-amount picker, a \"what your support funds\" summary, and a \"get involved\" panel for reviews and plugin links \u2013 replacing the previous stack of donate, trust, and community cards.<\/li>\n<li>Improved: Moved the Log tab directly before Support in the admin navigation for a more logical workflow.<\/li>\n<li>Fix: Resolved an issue where edit-document and edit-category modals could become out of sync between their visible state and the underlying hidden attribute.<\/li>\n<li>Fix: The document card shortcode no longer renders an empty or broken card when a document has no attached file.<\/li>\n<li>Fix: Resolved a markup nesting issue that could cause the Documents tab to render without its sidebar and shift the page layout to the left.<\/li>\n<li>Fix: Number inputs throughout the settings screens are no longer cramped to a fixed 50px width.<\/li>\n<li>Security: Document files are now protected from direct access through WordPress REST media endpoints such as <code>\/wp\/v2\/media\/{id}<\/code> and attachment permalinks, preventing these routes from bypassing the plugin's Private, Restricted, signed-link, and scheduling access controls.<\/li>\n<li>Security: Added a dedicated document-media guard that blocks unauthorised single-item REST requests, excludes inaccessible attachments from REST collection queries, strips file-revealing fields as defence in depth, and returns a 404 response for protected attachment permalinks.<\/li>\n<li>Security: REST and attachment-permalink protection applies to both files uploaded directly through Document Manager and files selected from the existing WordPress Media Library, without moving files or changing their existing URLs.<\/li>\n<li>Security: Added <code>.htaccess<\/code>, <code>web.config<\/code>, and an empty <code>index.php<\/code> file to the plugin's dedicated uploads directory to prevent direct web access and directory listing on Apache, IIS, and compatible web servers.<\/li>\n<li>Security: Documents continue to stream securely from local disk through the plugin rather than being proxied directly through the protected uploads directory.<\/li>\n<li>Security: Nginx installations should configure an equivalent server-level <code>location<\/code> rule because WordPress plugins cannot modify Nginx server configuration directly.<\/li>\n<li>Security: The \"Allowed file extensions\" setting is now intersected with the plugin's fixed, audited extension-to-MIME allowlist when settings are saved.<\/li>\n<li>Security: Administrators are now warned when unsupported file extensions are entered or removed from the configured allowlist.<\/li>\n<li>Security: Dangerous file formats, including SVG, PHP, and other executable types, remain excluded from the permitted document upload types.<\/li>\n<li>Security: Hardened stable-link <code>Content-Disposition<\/code> headers against quote, carriage-return, and line-feed characters.<\/li>\n<li>Security: Added explicit <code>Accept-Ranges<\/code> and <code>X-Content-Type-Options<\/code> headers to document responses.<\/li>\n<li>Security: REST metadata responses for Private, Restricted, or signed-link-only documents now include <code>Cache-Control: private, no-store<\/code>, preventing intermediary caches and CDNs from retaining sensitive document metadata.<\/li>\n<li>Removed: Removed the \"theme button style\" and \"full width button\" options from the document card shortcode and Frontend settings. Document card buttons now use either Outline or Solid styling.<\/li>\n<li>Dev: Renamed frontend document card CSS classes from <code>kgx-dm-*<\/code> to <code>kitgenix-document-manager-*<\/code> for consistency with other Kitgenix plugins. Sites with custom CSS targeting the previous class names will need to update their selectors.<\/li>\n<li>Dev: Refreshed the Kitgenix logo and icon asset set used across the plugin admin interface, Kitgenix Hub, and WordPress admin menu icon.<\/li>\n<\/ul>","raw_excerpt":"Manage WordPress documents with stable links, access control, signed sharing, versions, scheduling and local analytics.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/tt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/288086","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/tt.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/tt.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=288086"}],"author":[{"embeddable":true,"href":"https:\/\/tt.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/kitgenix"}],"wp:attachment":[{"href":"https:\/\/tt.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=288086"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/tt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=288086"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/tt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=288086"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/tt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=288086"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/tt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=288086"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/tt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=288086"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}