{"id":309972,"date":"2026-08-27T04:01:19","date_gmt":"2026-08-27T04:01:19","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/waiver-engine\/"},"modified":"2026-08-27T05:22:05","modified_gmt":"2026-08-27T05:22:05","slug":"waiver-engine","status":"publish","type":"plugin","link":"https:\/\/lug.wordpress.org\/plugins\/waiver-engine\/","author":23494773,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.6","stable_tag":"1.1.6","tested":"7.0.4","requires":"6.2","requires_php":"8.0","requires_plugins":null,"header_name":"Waiver Engine","header_author":"Nathaniel Smith","header_description":"Template-driven waiver and contract system with PDF overlay generation and optional third-party booking integrations.","assets_banners_color":"","last_updated":"2026-08-27 05:22:05","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/github.com\/sponsors\/purpleelephant1au","header_plugin_uri":"https:\/\/github.com\/purpleelephant1au\/wp-waiver-engine","header_author_uri":"https:\/\/github.com\/nsmithau","rating":0,"author_block_rating":0,"active_installs":0,"downloads":73,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.1.6":{"tag":"1.1.6","author":"purpleelephant1au","date":"2026-08-27 05:22:05","revision":3668113}},"upgrade_notice":{"1.1.6":"<p>Dependency refresh and prefix consistency updates for WordPress.org review compliance. No database migrations required.<\/p>","1.1.5":"<p>Admin\/runtime\/packaging stability fixes. No database migrations required.<\/p>","1.1.4":"<p>Freemius deployment fix for uninstall handling. No database migrations required.<\/p>","1.1.3":"<p>Fixes UI encoding issues and trims release package size. No database migrations required.<\/p>","1.1.2":"<p>Suppresses dashboard upsell banners in the free package; adds one settings-only Pro link.<\/p>","1.1.1":"<p>WordPress.org compliance and documentation updates. No database migrations required.<\/p>","1.1.0":"<p>Adds migration and handoff tooling for Free-to-Pro transitions and data transfer.<\/p>","1.0.1":"<p>Maintenance release with fixes and documentation updates.<\/p>","1.0.0":"<p>First release. No upgrade steps required for fresh installs.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3668031,"resolution":"128x128","location":"assets","locale":"","width":1057,"height":1057},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3668031,"resolution":"256x256","location":"assets","locale":"","width":1057,"height":1057}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.6"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Template editor with section builder, PDF upload, and field mapping tools.","2":"Frontend waiver form rendered from a published shortcode.","3":"PDF preview modal before final confirmation and submission.","4":"Waiver Entries admin table with filtering, sorting, and PDF access.","5":"Entry detail screen showing captured field data and generated PDF actions.","6":"Settings screen for security options, CAPTCHA, cleanup, and integrations."}},"plugin_section":[],"plugin_tags":[269,264060,601,1764,723],"plugin_category":[40,42,50],"plugin_contributors":[277757],"plugin_business_model":[],"class_list":["post-309972","plugin","type-plugin","status-publish","hentry","plugin_tags-booking","plugin_tags-contracts","plugin_tags-forms","plugin_tags-pdf","plugin_tags-signature","plugin_category-calendar-and-events","plugin_category-contact-forms","plugin_category-media","plugin_contributors-purpleelephant1au","plugin_committers-purpleelephant1au"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/waiver-engine\/assets\/icon-128x128.png?rev=3668031","icon_2x":"https:\/\/ps.w.org\/waiver-engine\/assets\/icon-256x256.png?rev=3668031","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Waiver Engine lets you build waiver and contract forms in the WordPress\nadmin, map form fields to coordinate positions on an uploaded PDF template,\nand automatically generate filled PDFs when visitors submit the form.<\/p>\n\n<p><strong>Key features:<\/strong><\/p>\n\n<ul>\n<li>Build multi-section waiver\/contract forms<\/li>\n<li>Map form fields to exact coordinate positions on a PDF<\/li>\n<li>Auto-generate filled PDFs on each submission<\/li>\n<li>Admin entry list with pagination, filtering, sorting, and PDF download<\/li>\n<li>Import \/ export template field-to-PDF mappings for easy site migration<\/li>\n<li>Security protections (nonce, honeypot, timing checks, rate limiting, optional CAPTCHA)<\/li>\n<\/ul>\n\n<p><strong>WordPress.org (free) package:<\/strong><\/p>\n\n<p>The version distributed on WordPress.org is fully functional and includes:<\/p>\n\n<ul>\n<li>Unlimited waiver templates<\/li>\n<li>PDF field mapping and PDF generation<\/li>\n<li>Waiver submission capture and admin entry management<\/li>\n<li>Import\/export of template field mappings<\/li>\n<li>Security settings (rate limiting, optional CAPTCHA, PDF cleanup)<\/li>\n<\/ul>\n\n<p><strong>Pro add-on (separate download):<\/strong><\/p>\n\n<p>A premium package is available separately (not from WordPress.org) with\nadditional features:<\/p>\n\n<ul>\n<li>Repeating rows in form sections (per-row PDF output mode)<\/li>\n<li>Admin notification emails with PDF attachments<\/li>\n<li>Submitter email copies with PDF attachments<\/li>\n<li>Amelia Booking integration and booking-linked waiver flows<\/li>\n<\/ul>\n\n<p><strong>Integration architecture:<\/strong><\/p>\n\n<p>The plugin follows an integration-manager pattern (the same approach used\nby WooCommerce add-ons, WPForms, RankMath, and ACF). Each third-party\nintegration lives in <code>includes\/integrations\/<\/code> and is loaded only when its\nhost plugin is active. The core plugin has zero knowledge of Amelia tables\nwhen Amelia is not installed.<\/p>\n\n<h3>Supported PDF formats<\/h3>\n\n<p>This plugin only supports PDF 1.4 or PDF\/A-1b files with:<\/p>\n\n<ul>\n<li>Object streams disabled<\/li>\n<li>Compressed cross-reference streams disabled<\/li>\n<li>No password protection or encryption<\/li>\n<li>Valid, readable pages with fonts embedded where required<\/li>\n<\/ul>\n\n<p>If the file cannot be processed, export or print a new PDF using PDF 1.4 or\nPDF\/A-1b settings and select the converted file instead.<\/p>\n\n<h3>Known issues and improvements<\/h3>\n\n<ul>\n<li>There is currently no validation when a PDF is uploaded to ensure that its\nformat is supported. UI validation is planned for a future release.<\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>This plugin can connect to third-party services when you enable optional\nfeatures. No data is sent unless you configure the feature.<\/p>\n\n<p><strong>Google reCAPTCHA v3 (optional CAPTCHA)<\/strong><\/p>\n\n<p>Used only when you select Google reCAPTCHA v3 under <strong>Waivers &gt; Settings<\/strong>\nand enable CAPTCHA on a template.<\/p>\n\n<ul>\n<li>What it is: Google's invisible bot-detection service.<\/li>\n<li>What is sent: When a visitor submits a waiver form with CAPTCHA enabled,\nthe browser loads Google's reCAPTCHA script and obtains a token. On\nsubmission, the plugin sends that token, your secret key, and the\nvisitor's IP address to Google's verification endpoint to validate the\nrequest.<\/li>\n<li>When: Only during form submission when CAPTCHA is enabled for that template.<\/li>\n<li>Terms of service: https:\/\/policies.google.com\/terms<\/li>\n<li>Privacy policy: https:\/\/policies.google.com\/privacy<\/li>\n<\/ul>\n\n<p><strong>hCaptcha (optional CAPTCHA)<\/strong><\/p>\n\n<p>Used only when you select hCaptcha under <strong>Waivers &gt; Settings<\/strong> and enable\nCAPTCHA on a template.<\/p>\n\n<ul>\n<li>What it is: hCaptcha's invisible bot-detection service.<\/li>\n<li>What is sent: When a visitor submits a waiver form with CAPTCHA enabled,\nthe browser loads hCaptcha's script and obtains a token. On submission,\nthe plugin sends that token, your secret key, and the visitor's IP\naddress to hCaptcha's verification endpoint to validate the request.<\/li>\n<li>When: Only during form submission when CAPTCHA is enabled for that template.<\/li>\n<li>Terms of service: https:\/\/hcaptcha.com\/terms<\/li>\n<li>Privacy policy: https:\/\/hcaptcha.com\/privacy<\/li>\n<\/ul>\n\n<h3>Security<\/h3>\n\n<p>Waiver Engine implements multiple layers of protection against automated\nabuse and bot submissions:<\/p>\n\n<p><strong>1. WordPress Nonce (CSRF protection)<\/strong>\nEvery form submission is validated against a standard WordPress nonce\n(<code>wp_verify_nonce<\/code>). Requests without a valid nonce are rejected with HTTP 403.<\/p>\n\n<p><strong>2. Honeypot Field<\/strong>\nA hidden text input is rendered off-screen (CSS <code>position:absolute; left:-9999px<\/code>)\nand labelled with <code>aria-hidden=\"true\"<\/code>. The field must exist and be completely\nempty. Bots that auto-fill all inputs will be silently rejected.<\/p>\n\n<p><strong>3. Timing Check<\/strong>\nOn page load, the form records a HMAC-SHA256-signed timestamp (using WordPress's\n    wp_salt('nonce') as the key). On submission the signature is verified and the\nelapsed time is checked: submissions faster than 3 seconds or older than 2 hours\nare rejected with HTTP 429. This prevents replay attacks and trivially fast bot\nsubmissions.<\/p>\n\n<p><strong>4. IP Rate Limiting<\/strong>\nA sliding-window rate limiter (implemented using WordPress transients) limits how\nmany waivers a single IP address can submit within a configurable time window.\nDefaults to 5 submissions per 15 minutes. Configurable in <strong>Waivers &gt; Settings<\/strong>.\nCan be disabled independently if another rate-limiting layer exists.<\/p>\n\n<p><strong>5. CAPTCHA (optional)<\/strong>\nAn invisible CAPTCHA challenge can be added to waiver forms for additional\nprotection. Supported providers:<\/p>\n\n<ul>\n<li><strong>Google reCAPTCHA v3<\/strong> - invisible scoring model. A score of &gt;= 0.5 is\nrequired. Register your keys at https:\/\/www.google.com\/recaptcha\/admin.<\/li>\n<li><strong>hCaptcha (invisible)<\/strong> - privacy-respecting alternative. Register at\nhttps:\/\/www.hcaptcha.com\/signup-interstitial.<\/li>\n<\/ul>\n\n<p>Configuration steps:<\/p>\n\n<ol>\n<li>Go to <strong>Waivers &gt; Settings<\/strong> and choose a CAPTCHA provider.<\/li>\n<li>Enter the <strong>Site Key<\/strong> (public) and <strong>Secret Key<\/strong> (private) from your\nprovider's dashboard.<\/li>\n<li>Open any template in <strong>Waivers &gt; Templates &gt; Edit<\/strong> and check <strong>Require\nCAPTCHA verification on this form<\/strong>.<\/li>\n<\/ol>\n\n<p>The CAPTCHA toggle defaults to OFF globally. Individual templates also default\nto OFF even when a provider is configured, so you can roll out selectively.<\/p>\n\n<p>Token verification happens entirely server-side via <code>wp_remote_post()<\/code> to the\nprovider's verify endpoint. The secret key is never exposed in browser output.<\/p>\n\n<p><strong>6. PDF File Cleanup<\/strong>\nThe <strong>PDF File Cleanup<\/strong> tool in Settings lets you permanently delete generated\nPDFs older than a chosen number of days. PDFs older than the threshold are\nremoved from disk; database entry records are preserved. This reduces disk\nfootprint and limits the blast radius of any hypothetical file-disclosure issue.<\/p>\n\n<h3>License<\/h3>\n\n<p>Waiver Engine is free software: you can redistribute it and\/or modify\nit under the terms of the GNU General Public License as published by the\nFree Software Foundation, either version 2 of the License, or any later\nversion.<\/p>\n\n<p>Waiver Engine is distributed in the hope that it will be useful, but\nWITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY\nor FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License\nfor more details.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>waiver-engine<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate through the <strong>Plugins<\/strong> screen in WordPress.<\/li>\n<li>Navigate to <strong>Waivers &gt; Templates<\/strong> to create your first waiver template.<\/li>\n<li>Upload a PDF template file, map form fields to PDF coordinates, and\ncopy the <code>[pewave_form id=\"N\"]<\/code> shortcode into any page or post.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20require%20amelia%20booking%3F\"><h3>Does this plugin require Amelia Booking?<\/h3><\/dt>\n<dd><p>No. Amelia integration is optional and is only available in the separate\nPro package. The WordPress.org version works fully for standalone waivers.<\/p><\/dd>\n<dt id=\"where%20are%20submitted%20pdfs%20stored%3F\"><h3>Where are submitted PDFs stored?<\/h3><\/dt>\n<dd><p>Generated PDFs are stored inside the <code>wp-content\/uploads\/pewave-pdfs\/<\/code>\ndirectory on the server. They are served for download through an\nauthenticated admin URL, not directly from disk.<\/p><\/dd>\n<dt id=\"can%20i%20migrate%20template%20mappings%20between%20sites%3F\"><h3>Can I migrate template mappings between sites?<\/h3><\/dt>\n<dd><p>Yes. On the template edit screen, scroll past the Save button to find the\nExport \/ Import section. Export downloads a JSON file containing your field\nschema and PDF coordinate mappings. Import merges those into an existing\ntemplate on another site while preserving its title and other settings.<\/p><\/dd>\n<dt id=\"can%20booking%20confirmation%20emails%20link%20directly%20to%20the%20pre-filled%20waiver%20form%3F\"><h3>Can booking confirmation emails link directly to the pre-filled waiver form?<\/h3><\/dt>\n<dd><p>Yes, in the Pro package with Amelia integration enabled. Append a <code>booking_id<\/code>\nquery parameter to the waiver page URL and ask the customer to confirm using\nthe same booking email they used in Amelia. Optionally include <code>booking_email<\/code>\nas a convenience parameter.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.6<\/h4>\n\n<ul>\n<li>Update third-party libraries: Freemius WordPress SDK 2.13.4 and FPDI 2.6.8.<\/li>\n<li>Standardize remaining internal admin identifiers to the <code>pewave<\/code> prefix.<\/li>\n<li>Align script\/style handles in template editor screens to <code>pewave<\/code> naming.<\/li>\n<\/ul>\n\n<h4>1.1.5<\/h4>\n\n<ul>\n<li>Fix admin slug\/label regressions introduced by identifier hardening.<\/li>\n<li>Restore Visual Mapper selector parity and related admin CSS bindings.<\/li>\n<li>Add direct license activation path for unlicensed Pro installs.<\/li>\n<li>Harden Freemius SDK bootstrapping when vendor files are incomplete.<\/li>\n<li>Fix release packaging exclusion bug that removed Freemius templates.<\/li>\n<\/ul>\n\n<h4>1.1.4<\/h4>\n\n<ul>\n<li>Remove uninstall.php so Freemius can track uninstall events; cleanup runs via after_uninstall hook.<\/li>\n<\/ul>\n\n<h4>1.1.3<\/h4>\n\n<ul>\n<li>Fix garbled punctuation in admin and frontend UI strings.<\/li>\n<li>Exclude internal user guides from release ZIPs.<\/li>\n<li>Move premium-only settings UI out of the free package source.<\/li>\n<li>Move uninstall cleanup to uninstall.php; tested up to WordPress 7.0.<\/li>\n<\/ul>\n\n<h4>1.1.2<\/h4>\n\n<ul>\n<li>Suppress Freemius site-wide trial and pricing upsell notices in the WordPress.org free package.<\/li>\n<li>Add a single contextual Pro mention at the bottom of the Settings screen only.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>WordPress.org compliance: removed feature gating and upgrade prompts from the free package.<\/li>\n<li>Moved settings page inline JavaScript to enqueued admin assets.<\/li>\n<li>Documented external CAPTCHA services in readme with terms and privacy links.<\/li>\n<li>Updated FPDF (1.9) and PDF.js (5.7.284) dependencies.<\/li>\n<li>Included composer.json in release packages; corrected repository URL.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added Free-to-Pro handoff detection and in-dashboard migration guidance.<\/li>\n<li>Added full data migration tooling (templates, entries, and key settings export\/import).<\/li>\n<li>Added one-click Free plugin deactivation action from Pro handoff notice with nonce\/capability safeguards.<\/li>\n<li>Refined Freemius premium package\/runtime helpers for single-codebase dual ZIP packaging.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Improvements to form\/template handling and admin workflows.<\/li>\n<li>User guide updates with reorganized flow-based screenshots.<\/li>\n<li>Release tooling and packaging updates for consistent ZIP builds.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial public release.<\/li>\n<li>Custom DB tables (no CPT dependency).<\/li>\n<li>PDF overlay generation via FPDI\/FPDF.<\/li>\n<li>Integration manager architecture for optional third-party integrations.<\/li>\n<li>Security: WordPress nonce validation, honeypot field, HMAC-signed timing\ncheck, IP rate limiting (configurable via Settings), optional CAPTCHA\n(reCAPTCHA v3 or hCaptcha, configurable globally and per-template),\nand manual PDF cleanup tool.<\/li>\n<li>Import \/ export of template field-to-PDF mappings.<\/li>\n<\/ul>","raw_excerpt":"Template-driven waiver and contract system with PDF overlay generation.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/lug.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/309972","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lug.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/lug.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/lug.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=309972"}],"author":[{"embeddable":true,"href":"https:\/\/lug.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/purpleelephant1au"}],"wp:attachment":[{"href":"https:\/\/lug.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=309972"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/lug.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=309972"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/lug.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=309972"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/lug.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=309972"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/lug.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=309972"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/lug.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=309972"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}