Close Compliance – Accessibility & Privacy

Description

Close Compliance – Accessibility & Privacy connects WordPress to the existing Close service. Developed and maintained by StarNetwork for its Close service at close.co.il. A Close account and a configured site are required. Available service features depend on your account and configuration.

Enter your public site ID, read the service disclosure, explicitly enable the connection, and save. Manage accessibility features, cookie categories, vendors, consent policy versions and document content in the Close dashboard. Optional local settings pass presentation overrides through the standard Close embed; they do not synchronize settings back to your account.

Settings

  • Public site ID: exactly 32 lowercase hexadecimal characters. No password or private API key.
  • Service connection: explicit administrator authorization; disabled by default on a new installation.
  • Script location: head or end of page. Both request deferred execution.
  • Widget language: inherit, Auto, English, Hebrew, Arabic or Russian.
  • Launcher buttons: inherit, both, accessibility only or cookies only.
  • Button appearance: inherit, icons only, text only or text with icons.
  • Desktop and mobile positions: inherit or one of eight logical positions.
  • Cookie popup: inherit, automatic when a choice is needed, or no automatic opening.
  • Cookie popup style: inherit, full-width bar or card.
  • Cookie popup position: inherit, top, bottom or center.
  • Initial detected-service details: inherit, collapsed or expanded.

All presentation settings default to Use Close dashboard settings. Emptying the site ID and saving disconnects the embed.

Compatible with the Close embed

The connector passes validated data-close-params values to the standard service loader. The embed contract was verified against the production runtime on September 17, 2026, including automatic language, launcher visibility, icon/text appearance and cookie interface settings. The complete parameter contract is included in docs/embed-parameters.md.

Automatic consent opening follows the service policy, targeting, configured categories and saved visitor choice. Manual mode does not accept cookies, change existing choices or disable enforcement. Provide a working way to reopen preferences, including when a floating button is hidden. The details setting controls the detected-service list, not category selection.

Purpose of the hosted service

This plugin connects the existing Close platform rather than providing an arbitrary script editor. Close manages registered websites, allowed domains, per-site configuration, accessibility features, consent categories and vendors, policy versions, localized documents and widget presentation centrally. The connector lets an existing Close customer use that configuration in WordPress with defined local presentation overrides, without distributing account secrets or managing a separate copy of their content.

The hosted service is required for these features. Its client runtime is delivered by the fixed HTTPS service endpoint. The plugin does not disguise remote executable code as data, download PHP, install other plugins or implement a private update channel. No standalone runtime or hidden fallback is included.

Lightweight integration

  • One deferred service loader added with WordPress’s script API.
  • No bundled frontend scripts or styles, jQuery, framework, shortcode or code editor.
  • No custom database tables, scheduled tasks, server-side API calls or content rewriting.
  • Native settings form with capability checks, nonce protection, strict allowlists and escaped output.
  • Translatable English administration strings using the close-compliance text domain. WordPress.org language packs provide approved translations for the WordPress user/site language when available. No translation catalogs are bundled.
  • Settings persist on deactivation and are removed on uninstall, including per-site options on multisite.

The loader URL includes the plugin release as its ver parameter for cache invalidation. Close’s manifest controls the hosted runtime version independently.

External service and privacy

Activation alone does not contact Close. A new installation requires both a valid public site ID and the administrator’s explicit Enable the Close service checkbox. The administrator can revoke it without deleting the ID. No service requests are made by this plugin from the WordPress admin page.

Visitors’ browsers request https://cdn.close.co.il/loader.js and then the service manifest, site configuration, executable JavaScript and styles on that CDN. The public site ID selects the site’s configuration. Requests expose normal network data such as IP address and user agent; a referrer may be sent according to the website’s referrer policy. The plugin does not transmit WordPress users, email addresses, post content, database exports, passwords or API secrets.

The hosted widget may use localStorage for accessibility preferences and policy-version-specific cookie choices, and sessionStorage for temporary widget visibility/hints. Service configuration controls visitor-facing behavior, document links and optional integrations. Administrator authorization to connect Close is separate from a visitor’s cookie choices.

  • Service and scope: https://close.co.il/#service-scope
  • Registration: https://my.close.co.il/register
  • Dashboard: https://my.close.co.il/
  • Service use and privacy disclosure, English: docs/privacy.en.html
  • Service use and privacy disclosure, Hebrew: docs/privacy.he.html
  • Service use and privacy disclosure, Arabic: docs/privacy.ar.html
  • Service use and privacy disclosure, Russian: docs/privacy.ru.html
  • Service/privacy contact: support@starltd.net

These self-contained notices are included in the plugin, linked from its settings page, and available without a Close account. They document this integration’s requests, browser storage, disconnection behavior and scope. They do not invent hosting/CDN log retention or claim to describe all account and billing processing. The plugin license and warranty terms are in LICENSE.txt; hosted-service terms are separate.

When connected, the plugin also supplies a localized paragraph in WordPress’s Privacy Policy Guide. The site owner reviews and adapts it before publication. It is never automatically inserted into a public page. Contact the operator for account-specific service terms or additional processing information.

Scope and source

This is a connector to a hosted service. It does not independently remediate accessibility, block arbitrary third-party scripts, scan a website, generate documents, record consent or implement the WordPress Consent API. Configure and verify those service capabilities on the actual website. Other plugins’ scripts and server-side cookies are not automatically controlled by adding the embed.

Close provides initial technical assistance and does not replace accessibility assessment, legal advice or ongoing maintenance. No legal compliance, protection from claims, certification or directory approval is promised.

All plugin source is readable and included under GPLv2 or later; no build step is needed. Externally hosted service code is not bundled. The fixed service URL cannot be edited in the settings. There is no arbitrary code insertion, remote plugin updater or downloaded PHP execution. The external executable JavaScript dependency remains subject to WordPress.org service-integration review.

Installation

  1. Upload the ZIP using Plugins > Add New Plugin > Upload Plugin, then activate it.
  2. Open Settings > Compliance By Close.
  3. Paste the 32-character public site ID from Close.
  4. Choose head/footer loading and optional presentation overrides. Leave inherit selected to preserve dashboard behavior.
  5. Read the service disclosure, check Enable the Close service, and select Save settings.
  6. Remove old manual embeds, clear page/CDN caches, and test the public site.
  7. Verify the widget and consent behavior with the categories, services and documents actually configured for this website.

FAQ

Where are settings managed?

Accessibility features, cookie categories, policy versions, vendors and content stay in Close. This connector stores only connection details and whitelisted presentation overrides. No management API credentials or settings synchronization are used.

Why is Auto different from inheriting?

Inherit omits the parameter and retains the dashboard setting. Auto explicitly sends lang:auto to select the page language, then browser language, then configured fallback, even if the dashboard has a fixed language. An explicit embed language overrides a previously saved widget language.

What do start and end mean?

Start is right for an RTL interface and left for an LTR interface. End is the opposite side. Mobile position is separate from desktop position.

Does hiding the cookie popup approve cookies?

No. consent-banner:manual requests no automatic opening. It does not itself accept cookies, change saved consent or prevent manual preference management. Provide a working way for visitors to reopen preferences.

Does defer block unrelated trackers?

No. It avoids parser-blocking execution of the loader; it does not control unrelated scripts. Test consent behavior with the actual website and service configuration.

Can I paste the whole embed or custom parameters?

No. Paste only the public site ID. The plugin builds parameters from dropdown allowlists and does not accept HTML, JavaScript, private keys, arbitrary URLs or free-form parameters.

How are languages provided?

The English source uses standard WordPress gettext functions and the close-compliance text domain. Approved translations are delivered through WordPress.org language packs when available; untranslated strings use English. This submission ZIP does not bundle PO, MO or POT catalogs. Existing Hebrew, Arabic and Russian translations are maintained separately for contribution to translate.wordpress.org. Visitor widget language is controlled separately by Close. The four local HTML service/privacy notices remain included.

What about caching and optimization?

Purge caches after changing settings, disabling or removing the plugin. If an optimizer changes script order or strips data attributes, exclude the Close loader and service assets from its delay/combination features. Allow the CDN in your CSP where required. Your theme must use wp_head() and wp_footer().

What is stored?

One per-site option named close_compliance_settings with site_id, position, service_enabled and nine presentation selections. Uninstall removes that option. It does not remove the Close account, browser storage or external caches.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Close Compliance – Accessibility & Privacy” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.3.0

  • Prepare the first public directory release under the close-compliance slug.
  • Identify StarNetwork as the developer and operator of the Close service.
  • Use WordPress.org language packs and the close-compliance text domain.
  • Require explicit administrator authorization before connecting the hosted service.
  • Provide validated embed settings and local service/privacy notices in four languages.