=== maca Hold ===
Contributors: macas
Tags: maintenance, under construction, coming soon, 503, maintenance mode
Requires at least: 6.0
Tested up to: 7.0
Requires PHP: 7.4
Stable tag: 2.0.10
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

**Privacy:** On activation, deactivation, and uninstall, the plugin sends your site URL, plugin version, WordPress version, PHP version, and locale to Maca at `https://api.maca.se/v1/hold/events.php` so we can improve the plugin and count active installations. If you choose to send deactivation feedback, your selected reason and optional comment are included. No maintenance page content, bypass tokens, or visitor data are transmitted.

Maintenance mode with HTTP 503, customizable page, admin bypass, IP whitelist, secret link, page exceptions, social links, and hero template.

== Description ==

Developed by [macas](https://github.com/maca59).

**maca Hold** shows a maintenance page to public visitors while you work on your site. Logged-in administrators, whitelisted IPs, and secret bypass links can still access the frontend.

= Features =

* Enable or disable maintenance mode with one toggle
* Send proper **HTTP 503** responses with optional **Retry-After** header
* Custom title, subtitle, message, logo, links, footer text, colors, and templates
* **Hero** maintenance template with large headline layout
* **Page exceptions** ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã¢â‚¬Â ÃƒÂ¢Ã¢â€šÂ¬Ã¢â€žÂ¢ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã†â€™Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ€šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Â¦Ãƒâ€šÃ‚Â¡ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¬ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã†â€™Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â‚¬Å¡Ã‚Â¬Ãƒâ€¦Ã‚Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¬ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â keep selected pages public (or force maintenance on selected pages) while the rest of the site is in maintenance
* **Social links** on the maintenance page (icons or text)
* Extra backgrounds, custom background URL, favicon, head code, and custom CSS
* Configurable maximum number of links on the maintenance page
* Bypass for selected user roles
* Optional login icon on the maintenance page
* IP whitelist and secret bypass link
* Scheduled maintenance windows with optional countdown
* Preview the maintenance page before going live
* Import and export settings as JSON
* Compatible with common caching plugins

= Who can still access the site? =

* Logged-in users with selected roles (administrators by default)
* Visitors from whitelisted IP addresses
* Anyone with the secret bypass link
* `/wp-admin` and login remain available
* Pages excluded via page exceptions (when configured)

Source code: https://github.com/maca59/maca-hold

== External services ==

This plugin sends installation telemetry to Maca at `https://api.maca.se/v1/hold/events.php`.

**What is sent:** On activation, deactivation, and uninstall, the plugin sends your site URL, plugin version, WordPress version, PHP version, and locale. If you submit deactivation feedback on the Plugins screen, your chosen reason and optional comment are included.

**When:** Data is sent when you activate, deactivate, or uninstall the plugin.

**Why:** To count active installations and improve maca Hold.

**Service provider:** Maca (api.maca.se). No maintenance page content, bypass tokens, IP whitelist entries, or visitor data is transmitted.

If you install **maca Sec Hub** on the same site, it may read maintenance status through the local REST API route `maca-hub/v1/hold` using a site key stored in WordPress. That traffic stays on your server.

== Installation ==

1. In WordPress admin, go to *Plugins ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã¢â‚¬Â ÃƒÂ¢Ã¢â€šÂ¬Ã¢â€žÂ¢ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã‚Â ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â‚¬Å¡Ã‚Â¬ÃƒÂ¢Ã¢â‚¬Å¾Ã‚Â¢ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â‚¬Å¡Ã‚Â¬Ãƒâ€¦Ã‚Â¡ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã¢â‚¬Â ÃƒÂ¢Ã¢â€šÂ¬Ã¢â€žÂ¢ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã†â€™Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ€šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Â¦Ãƒâ€šÃ‚Â¡ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¬ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â‚¬Å¡Ã‚Â¬Ãƒâ€¦Ã‚Â¡ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã¢â‚¬Â ÃƒÂ¢Ã¢â€šÂ¬Ã¢â€žÂ¢ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã†â€™Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ€šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Â¦Ãƒâ€šÃ‚Â¡ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¬ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã†â€™Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ€šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Â¦Ãƒâ€šÃ‚Â¾ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¢ Add New*, search for **maca Hold**, and click *Install Now* ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã¢â‚¬Â ÃƒÂ¢Ã¢â€šÂ¬Ã¢â€žÂ¢ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã‚Â ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â‚¬Å¡Ã‚Â¬ÃƒÂ¢Ã¢â‚¬Å¾Ã‚Â¢ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â‚¬Å¡Ã‚Â¬Ãƒâ€¦Ã‚Â¡ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã¢â‚¬Â ÃƒÂ¢Ã¢â€šÂ¬Ã¢â€žÂ¢ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã†â€™Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â‚¬Å¡Ã‚Â¬Ãƒâ€¦Ã‚Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¬ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã‚Â¦ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¡ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â‚¬Å¡Ã‚Â¬Ãƒâ€¦Ã‚Â¡ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¬ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã¢â‚¬Â ÃƒÂ¢Ã¢â€šÂ¬Ã¢â€žÂ¢ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã†â€™Ãƒâ€šÃ‚Â¢ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ€šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Â¦Ãƒâ€šÃ‚Â¡ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â¬ÃƒÆ’Ã†â€™Ãƒâ€ Ã¢â‚¬â„¢ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â‚¬Å¡Ã‚Â¬Ãƒâ€¦Ã‚Â¡ÃƒÆ’Ã†â€™ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ‚Â or upload `maca-hold.zip` via *Upload Plugin*
2. Activate the plugin through the **Plugins** screen
3. Open **maca Hold** in the WordPress admin menu
4. Add your IP address to the whitelist and save the secret bypass link
5. Enable maintenance mode when you are ready

== Frequently Asked Questions ==

= Does this hurt SEO? =

The plugin sends HTTP 503 (Service Unavailable), which tells search engines the downtime is temporary. You can also send a `Retry-After` header.

= What data does maca Hold send externally? =

On activation, deactivation, and uninstall, the plugin sends your site URL, plugin version, WordPress version, PHP version, and locale to `https://api.maca.se/v1/hold/events.php`. If you submit deactivation feedback, your chosen reason and optional comment are included. No maintenance page content, bypass tokens, or visitor data is sent.

= Can I preview the page without enabling maintenance? =

Yes. Use the **Preview maintenance page** button on the settings screen.

= Will wp-admin still work? =

Yes. The WordPress dashboard and login page remain available.

= Can I schedule maintenance? =

Yes. Enable scheduled maintenance and set a start and/or end time.

== Screenshots ==

1. Settings page with status indicator and maintenance toggle
2. Maintenance page shown to visitors

== Upgrade Notice ==

= 2.0.0 =
Unified free release: former Pro features (page exceptions, social links, hero template, backgrounds, custom CSS) are included. No separate maca Hold Pro add-on or license required.

= 1.0.33 =
Author and source links now point to GitHub (maca59); no maca.se URIs in the plugin package.

= 1.0.32 =
Plugin Check fixes: sanitize AJAX toggle input, prefix setting-switch variables, normalize template line endings.

= 1.0.31 =
WordPress.org review fixes: readme, license.txt, Plugin Check compatibility, and translation loading.

== Changelog ==

= 2.0.9 =
* Fix WordPress 6.7+ notice: register updater on init so maca-hold translations are not loaded too early

= 2.0.3 =
* Installation telemetry via api.maca.se and optional deactivation feedback on the Plugins screen
* Smarter site URL resolution for telemetry on proxied and loopback hosts
* Defer activation telemetry to shutdown so request headers and WordPress URL filters are available

= 2.0.0 =
* Merge former maca Hold Pro features into the free plugin (no license required)
* Advanced tab: page exceptions, social links, hero template, extra backgrounds, favicon, head code, custom CSS, max links
* Migrate settings from legacy `maca_hold_pro_settings` on first load
* Hub API reports `extended` status instead of separate Pro add-on

= 1.0.33 =
* Point Author URI and readme links to https://github.com/maca59 (contributor macas)
* Remove maca.se URIs from plugin headers, readme, and translation metadata

= 1.0.32 =
* Plugin Check: sanitize `$_POST['enabled']` in AJAX maintenance toggle
* Plugin Check: prefix setting-switch template variables with `maca_hold_`
* Plugin Check: normalize LF line endings in maintenance templates

= 1.0.31 =
* WordPress.org review: remove load_plugin_textdomain() (directory auto-loads translations)
* Add license.txt, External services section, and contributor slug macas
* Plugin Check: prefix maintenance template variables, enqueue strings.js, phpcs for preview query args
* English REST error messages for maca Sec Hub integration
* Remove unused Pro admin CSS from the free plugin

= 1.0.23 =
* Improve per-page maintenance bypass handling for forced maintenance requests

= 1.0.22 =
* Load add-on maintenance CSS via maca_hold_maintenance_styles filter

= 1.0.21 =
* Add tabbed navigation on the maca Hold settings screen for add-ons

= 1.0.20 =
* Add maca_hold_force_maintenance filter for per-page maintenance

= 1.0.19 =
* Add extension hooks for add-ons: templates filter, maintenance head, and after-links actions

= 1.0.0 =
* Initial release
